Healthcare AI governance training and certification. One day online, Oct 19. | Register now →

Pacific AI Governance Policy Suite: Q3 2026 Release Notes

The most significant regulatory event of the past quarter took effect on 2 August 2026, when Article 50 of the EU AI Act entered into force. This article requires providers to disclose when a person is interacting with an AI system and to label AI-generated content. This major event changed the landscape of transparency obligations.

For the pas quarter the legislative work continues in the USA. At the state level, legislatures moved faster than in any previous quarter we have tracked, particularly on synthetic media, companion chatbots, and AI in healthcare.

This release is our largest single expansion to date: a net addition of 92 instruments across 13 sections. In addition, the updated Policy contains specific structural corrections.

Key Updates in the Q3 2026 Release:

1. Deepfake coverage expands at the US state level

Sixty-five entries related to enacted law regulating deepfake were added. This includes:

  • Election deepfake and synthetic media disclosure: in the absence of comprehensive federal regulation, states have enacted laws regulating deepfakes and synthetic media in political communications and elections. As of now, approximately 30 states require clear visual or audio disclaimers on campaign advertisements that use AI-generated or materially manipulated media. There is a specific time window when restrictions apply, typically ranging from 45 to 90 days before an election. Review Texas Election Code; Minnesota Statutes §609.771; Wisconsin Statutes §11.1303; California AB 2355; Maryland SB 141; Michigan HB 5141; Oregon SB 1571; Utah SB 131; Vermont S 23; Alabama HB 172; Louisiana HB 459.
  • Protections against deepfakes: the state-level restrictions span across all 50 states that govern criminal classifications, civil causes of action against deepfakes and illegal nudification technologies, including Arizona §13-1425, Florida §836.13, Illinois 720 ILCS 5/11-23.5 and 5/11-23.7, Maryland Criminal Law §3-809, Minnesota §617.262 and HF 1606, Nebraska §25-3501, Nevada §200.780, New Hampshire RSA 644:9-a, North Carolina §14-190.5A, Oklahoma §1040.13b, Oregon §163.472, Pennsylvania §3131, Rhode Island §11-64-3, South Dakota §22-21-4, Tennessee §39-17-1906, Utah §76-5b-205, Vermont §2606, Washington §9A.86.030 and Wyoming §6-4-306 and §6-4-307.

2. New clause: US Federal Healthcare Legislation and Regulation

A new clause consolidates federal healthcare law and guidance relevant to AI systems used in clinical, and life-sciences AI. In addition to HIPAA Privacy Rule and HITECH breach notification, fifteen new instruments were added:

  • Patient-rights and emergency care: the Emergency Medical Treatment and Labor Act (EMTALA) and the Patient Self-Determination Act.
  • Healthcare fraud and abuse law: the False Claims Act, the Anti-Kickback Statute, the Stark Law, the Eliminating Kickbacks in Recovery Act, and the Physician Payments Sunshine Act.
  • Accreditation and professional ethics: the Joint Commission’s Comprehensive Accreditation Manual for Hospitals (CAMH) and National Performance Goals (NPG 1, NPG 8, NPG 14, PC, IM); the AMA Code of Medical Ethics and AMA Principles of Medical Ethics; and SAMHSA’s National Behavioral Health Crisis Care Guidance.

Unlike a simple listing update, this is a substantive addition: organizations operating in clinical or payer settings should map the new fraud-and-abuse and FDA-guidance instruments against their existing AI Risk Management and Safety policies.

3. Healthcare AI legislation expanded across eleven new instruments

State activity in healthcare AI has shifted from disclosure requirements toward substantive constraints on clinical and payer decision-making. Additions this quarter:

  • Delaware HB 191 — amends Title 24 of the Delaware Code relating to medical professionals, titles and nonhuman entities. This is currently the most direct statutory treatment of AI impersonation of a licensed medical professional.
  • Rhode Island S 2197, S 2195 and H 7538 — AI in mental health treatment, safety features for AI companion technology, and patient notification of AI use.
  • Illinois SB 3114 (Transparency in Downcoding Act), Iowa HF 2635, Georgia SB 444 and Maryland HB 1563 — utilization review, prior authorization and payer coverage decisions.
  • Louisiana HB 475 — disclosure to patients where AI is used to transcribe medical appointments.
  • Maine LD 2082 / HP 1397 — regulation of AI in providing certain mental health services.

4. Federal deregulation, and two enforcement guidances

Three executive orders were added to US Federal Regulation: Preventing Woke AI in the Federal Government, Accelerating Federal Permitting of Data Center Infrastructure, and Promoting the Export of the American AI Technology Stack.

At the same time, EEOC Guidance on the Use of AI to Assess Job Applicants and Employees and CFPB Guidance on Black-Box Credit Models have been removed from the Suite following their withdrawal.

5. Companion chatbots, conversational AI and AI in classrooms

A distinct legislative cluster emerged this quarter around conversational systems and minors. Added to US State & Local Legislation:

  • Hawaii SB 3001 — disclosure requirements for operators of AI companions.
  • Iowa SF 2417 — requirements and guidelines for conversational AI services.
  • Idaho S 1227, Oklahoma SB 1734 and Utah HB 273 — generative AI and classroom technology in public education.
  • Utah HB 276, Mississippi HB 1723, Illinois HB 4875, California AB 2905 and Kansas SB 2313, the last restricting the use of specified AI platforms including DeepSeek.

6. Medical device and clinical evaluation standards

Four standards and two ethics instruments were added:

  • ISO 14971:2019 (medical device risk management) and IEC 62304 (medical device software lifecycle), added to Frameworks and Standards. These are the device-side companions to ISO/IEC 42001, and a manufacturer of AI-enabled clinical software is typically subject to all three.
  • DECIDE-AI (early-stage live clinical evaluation) and QUADAS-AI (quality assessment of AI-centred diagnostic accuracy studies), completing the clinical AI reporting set alongside CLAIM, TRIPOD-AI, CONSORT-AI and SPIRIT-AI.

7. Scope clarification: frontier models are out of scope

The Scope section now states explicitly that the Suite does not cover governance of models exceeding the 10²⁵ FLOPs training-compute threshold. Models above that threshold are subject to separate and stricter regulatory obligations, including under the EU AI Act GPAI regime and state frontier-model statutes.

If you train above that threshold, this Suite is a necessary but not sufficient basis for your programme.

8. International updates

  • European Union — added the AI Action Plan and the Digital Omnibus on AI.
  • United Kingdom — added the Regulating for Growth Bill.
  • Japan — added the Basic AI Plan and the Principles-Code for Protection of Intellectual Property and Transparency for the Appropriate Use of Generative AI.
  • Saudi Arabia and UAE — superseded entries removed, including the AI Readiness Index and the UAE AI Act.

9. Employment and recruitment

Employment coverage was revised: California AB 1008, Illinois 820 ILCS 42 (Artificial Intelligence Video Interview Act, now cited at code level) and New York S 8831 were added, while California SB 7 and the Final Employment Regulations Regarding Automated Decision Systems were removed.

10. AI Safety Policy: new clause on Additional Safety Controls for Clinical AI

The AI Safety Policy adds a new Section 8, Additional Safety Controls for Clinical AI, for AI systems used in clinical pathways. It requires AI Governance Officer-approved escalation thresholds, and a documented crisis-response protocol — meeting SAMHSA’s National Guidelines for Behavioral Health Crisis Care and the core elements of the Zero Suicide framework.

11. Next Steps & Adoption Guidance

To fully leverage the enhanced Q3 2026 Policy Suite, organizations should:

Review new frameworks and laws:

  • Assign subject-matter leads across clinical, legal compliance and procurement teams to evaluate the new national, federal and state instruments.

Implement technical and organizational measures:

  • Adoption of the Policy Suite alone does not constitute compliance with any applicable law, regulation, or industry standard. Compliance requires a company to implement, maintain, and continuously monitor operational, technical, and organizational measures.

Stay compliant:

  • Incorporate the Q3 2026 additions into your own policy set and, if necessary, conduct AI literacy training reflecting the latest changes.

Certification:

  • Self-Attest: Once the updates are adopted, organizations may contact Pacific AI at info@pacific.ai. We will quide on you for you can obtain a written confirmation of compliance to receive an updated “AI Governance Badge” reflecting Q3 2026 coverage.
  • Prefer hands-on support? Pacific AI’s certification and advisory programs meet organizations at any stage: the 12-Week AI Accelerator, for teams launching an AI governance program or getting their first high-impact AI systems validated and into production; RUAIH Certification Readiness, a focused engagement preparing hospitals and health systems for Joint Commission RUAIH certification across all five standard areas; and Forward Deployed Experts, a 12-month managed service that embeds a dedicated governance lead as a turn-key Center of Excellence for AI Governance.

Reliable and verified information compiled by our editorial and professional team. Pacific AI Editorial Policy.

HTI-5 removes 34 of 60 certification criteria and moves AI testing to every buyer

The HTI-5 proposed rule, Health Data, Technology, and Interoperability: ASTP/ONC Deregulatory Actions To Unleash Prosperity, published at 90 FR 60970 on December 29, 2025, would remove 34 of the 60...