California Rewrites Its AI Transparency Law (10/02/2026)
- › California's SB 1000 extends the AI Transparency Act to anyone whose generative AI system is publicly accessible in the state, removing the one-million-user threshold, with immediate effect.
- › Texas hospice and home health company AngMar Management Services says an Interlock ransomware attack exposed data on 35,916 people.
- › Two hospitals settled lawsuits over tracking pixels on their websites and patient portals for $20 to $25 per class member plus monitoring.
- › The EBA's updated third-party risk guidelines replace its 2019 outsourcing rules and reach non-ICT suppliers.
- › State bank supervisors released an AI framework asking institutions for an inventory of AI use cases with named business owners.
California’s first AI transparency law only applied to generative AI providers above a one-million-user threshold, which left out many of the smaller companies building on these tools. SB 1000 removes that threshold, so the obligations now reach anyone whose generative AI system is publicly accessible in California. It took effect immediately, which leaves smaller companies with a compliance question they did not have last week and no runway to answer it.
Top 5 Critical Compliance Alerts
1. SB 1000 Extends California’s AI Transparency Act to Smaller Providers
California’s SB 1000, enacted September 30, overhauls the AI Transparency Act by covering any person who creates a generative AI system publicly accessible in California, dropping the one-million-user threshold, narrowing the media exemption to video games, replacing the “AI detection tool” with a “disclosure verification tool,” and adding a notice-and-remediation process for third-party licensees, per JD Supra. SB 1000 takes effect immediately, while AB 853’s platform requirements start January 1, 2027, and its capture device requirements January 1, 2028.
Operator Note: If you offer any generative AI feature to the public, including one built on another company’s model, have counsel decide this month whether you are now a covered provider. The old threshold was the reason most companies never had to ask.
2. Texas Hospice Company Reports Ransomware Breach Affecting 35,916
AngMar Management Services, a home health and hospice provider in Mansfield, Texas, said an Interlock ransomware attack around July 18 exposed names, Social Security numbers, medical record numbers, insurance details, diagnoses, and prescription data for 35,916 people, per the HIPAA Journal. The attackers claim to have taken 710 GB and posted data in August.
3. Two Hospitals Settle Pixel Tracking Lawsuits
Fairchild Medical Center in California and Boone Health in Missouri settled class actions alleging that Meta Pixel and similar tracking code on their websites and patient portals disclosed patient data without consent, paying $25 and $20 per class member respectively plus a year of identity monitoring, per the HIPAA Journal.
Operator Note: The per-person amounts are small, and the cost is in the litigation that precedes them. Remove third-party tracking from patient portals and any page that reveals a condition or appointment, and keep a record that you did.
4. The EBA Updates Its Third-Party Risk Guidelines
The European Banking Authority published updated guidelines on September 18 replacing its 2019 outsourcing guidelines, extending them to non-ICT third-party services and requiring registers of all third-party arrangements, including ICT subcontractors that support non-ICT services for critical functions, per JD Supra. A two-year transition is expected for existing critical arrangements.
5. State Bank Supervisors Publish an AI Framework
The Conference of State Bank Supervisors released an AI supervisory framework on September 16 for state-chartered banks and state-licensed nonbanks, expecting a documented inventory that “identifies the business owner(s) and purpose” of each AI use case, written acceptable use policies, AI-specific contract terms with vendors, and periodic management reporting, per JD Supra. The framework creates no new legal requirements, but state examiners are expected to use it.
Operator Note: The AI inventory with a named business owner is the item every one of these frameworks asks for first. If you cannot produce one, start there.
Additional Compliance Alerts
Regulatory Updates
- The FTC and states sue Lens.com: The complaint alleges the company misrepresented contact lens prices in search ads and on its website. FTC
- The critical minerals waiver for defense suppliers ends January 1, 2027: Contractors relying on the waiver need to confirm their supply chains. JD Supra
- California’s stay-or-pay law is delayed: The effective date has moved, alongside other changes. JD Supra
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
A leader defined by a 'bias for action,' Dusten specializes in physical security assessments that impact profitability and facility resilience.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.