EU AI Omnibus, DOJ Declination & Colorado ADMT (08/01/2026)
- › The EU AI Act Digital Omnibus entered into force July 30 and pushed most high-risk obligations from August 2026 to December 2027 or August 2028.
- › DOJ issued its first healthcare declination under the new corporate enforcement policy, and published what earned it.
- › Colorado's AI Act was rewritten around automated decision-making technology and now takes effect January 1, 2027.
- › CMS proposed sweeping restrictions on remote patient monitoring, including an outsourcing ban, one year after expanding it.
- › The FCC extended Covered List prohibitions to devices containing certain logic-bearing components and put obligations on online marketplaces.
Two AI compliance deadlines moved this week and one enforcement precedent landed. The EU AI Act Digital Omnibus entered into force July 30 and pushed most high-risk obligations out by more than a year, Colorado rewrote its AI Act and reset the clock to January 2027, and DOJ published exactly what a healthcare company did to avoid criminal charges. If your 2026 compliance calendar was built around an August 2 EU deadline, it needs rework before Monday.
Top 5 Critical Compliance Alerts
1. EU AI Act Digital Omnibus Resets the High-Risk Timeline
The final text of the Digital Omnibus on AI was published in the Official Journal and entered into force July 30, 2026, amending Regulation (EU) 2024/1689. High-risk obligations under Article 6(2) move from August 2, 2026 to December 2, 2027, and systems covered by existing EU harmonization laws move to August 2, 2028. The package also adds prohibitions on systems generating non-consensual intimate imagery and child sexual abuse material effective December 2, 2026, creates a small mid-cap category (under 750 employees and €150M turnover) with access to simplified tools and regulatory sandboxes, and centralizes enforcement in the AI Office. JD Supra
Operator Note: Extra time is only worth something if you use it to finish the AI inventory. Start with a written list of every model in production, who owns it, and what decision it touches.
2. DOJ Declines Its First Healthcare Prosecution Under the New Policy
On July 29, DOJ declined to bring criminal healthcare fraud charges against Campus Eye Management and its parent holding company, the first healthcare declination under the department-wide Corporate Enforcement Policy. The underlying conduct ran from 2015 through March 2023 and involved medically unnecessary diagnostic eye tests and kickbacks to referring ophthalmologists, with roughly $1 million in fraudulent Medicare reimbursements. The company earned the declination through timely self-disclosure, full cooperation, and a rebuilt compliance program with ongoing risk assessments, new compliance staff, and training. It still paid $1 million in restitution, and the founder was separately indicted on seven counts. JD Supra
Operator Note: Self-disclosure only pays when the compliance program is already credible. Build the risk assessment cadence now, because it is the evidence you will point to later.
3. Colorado’s AI Act Narrows to Automated Decision-Making Technology
The amended Colorado AI Act takes effect January 1, 2027. The revised statute drops the broad “artificial intelligence system” definition in favor of automated decision-making technology, defined as technology that processes personal data and uses computation to generate output for decisions affecting individuals, and limits application to consequential use cases in education, employment, housing, finance, insurance, healthcare, and government services. Obligations still fall on both developers and deployers, with no small-business exemption. JD Supra
Operator Note: No size exemption means a 12-person firm using an AI resume screener in Colorado is a deployer. Check your HR and lending tools against the seven covered categories.
4. CMS Proposes to Restrict Remote Patient Monitoring
The CY 2027 Proposed Rule reverses direction on remote patient monitoring (RPM) and remote therapeutic monitoring (RTM), adding an outsourcing ban and reimbursement restrictions. The CY 2026 Physician Fee Schedule had gone the other way a year earlier, lowering the 16-day data transmission threshold, adding shorter-duration treatment management codes, and creating new billing pathways. Practices that built revenue around the 2026 expansion need to model the 2027 version before it finalizes. JD Supra
Operator Note: An outsourcing ban is a vendor contract problem before it is a billing problem. Pull your remote patient monitoring service agreements and check the termination terms now, while the renewal still gives you room to negotiate.
5. FCC Extends Covered List Rules to Components and Marketplaces
On July 23, the FCC released a Third Report and Order extending Covered List prohibitions to devices containing certain logic-bearing hardware components, and imposing compliance obligations on online marketplaces that sell them. The order continues the Commission’s work on national security risk in the communications supply chain, and it moves the burden down to component level and out to the sales channel. JD Supra
Operator Note: Component-level rules mean your bill of materials is now a compliance artifact. If you buy cameras, access control panels, or networking gear through a marketplace, ask your supplier for component sourcing in writing.
Additional Compliance Alerts
Compliance Frameworks
- CCPA and CPRA programs still fail on the same points: Enforcement over the past year shows that a privacy policy, a cookie banner, and a request process are the paperwork, and organizations keep getting caught on what happens after the request arrives. JD Supra
Regulatory Updates
- DOL proposes an ERISA electronic disclosure safe harbor: A July 23 proposed rule would create an optional safe harbor letting group health plan administrators satisfy disclosure requirements electronically. JD Supra
- EEOC votes to propose rescinding the EEO-1 report: On July 21 the Commission voted 2-1 to publish a proposed rule ending the workforce demographic reporting regime in place since 1966, which leaves employers deciding whether to keep collecting the data. JD Supra
- FCC Enforcement Monitor covers July actions: This month’s issue includes proposed $25,000 fines against eight companies for failing to respond to Commission inquiries. JD Supra
Third-Party Risk & Due Diligence
- Health-ISAC warns of rising ShinyHunters attacks on healthcare: The information sharing center flagged an increase in successful data theft against health sector organizations by the group, which is the same actor behind this week’s Brinks Home Salesforce breach. HIPAA Journal
Policy & Governance Updates
- Employees are already using AI whether the policy exists or not: Adoption has happened. The governance question left for most businesses is whether an acceptable use policy, data handling rules, and a sanctioned tool list exist yet. JD Supra
- A rarely tested Virginia privacy statute draws retailer scrutiny: Plaintiffs are testing a statute with statutory damages that imposes notice and consent obligations on retailers sharing or selling in-store customer data. JD Supra
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
A leader defined by a 'bias for action,' Dusten specializes in physical security assessments that impact profitability and facility resilience.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.