OSHA Machine Guarding and the FCA on Frontier AI (09/08/2026)

September 8, 2026
OSHA Machine Guarding and the FCA on Frontier AI (09/08/2026)
Key Intel / TL;DR
  • Machine guarding under 29 CFR 1910.212 remains one of OSHA's Top 10 most frequently cited standards.
  • The UK Financial Conduct Authority published findings from a multi-firm review of how firms use, test, and prepare for frontier AI models with cyber capabilities.
  • OneTouchPoint agreed to a multi-million dollar settlement over its 2022 ransomware attack, four years after the incident.
  • A rise in anonymous reporting is being read as a signal that workers fear retaliation rather than as a sign the hotline is working.
  • CFIUS published its 2025 annual report to Congress covering the year's foreign investment review activity.

The most-cited item on today’s board is a physical guard on a machine, and the newest is a regulator’s review of frontier AI. Both are the same compliance question asked about different equipment, which is whether the thing that stops somebody getting hurt is actually in place and actually tested. One of them has been on OSHA’s Top 10 for years, which tells you how durable that problem is.

Top 5 Critical Compliance Alerts

1. Machine Guarding Is Still in OSHA’s Top 10

OSHA continues to cite employers frequently under 29 CFR 1910.212, and machine guarding landed on the agency’s list of Top 10 Most Frequently Cited Standards again. A guard is the cheapest, oldest, and most understood control in industrial safety, and it keeps being the citation because guards get removed for maintenance and not put back, or because a machine got modified and the guard no longer fits. The failure is almost never that somebody did not know the rule. JD Supra has the compliance detail.

Operator Note: Walk your floor and look for guards leaning against machines rather than mounted on them, because that is what the citation looks like before it is a citation.

2. The FCA Publishes What It Found on Frontier AI

The UK Financial Conduct Authority released findings from a multi-firm review examining how firms use, test, and prepare for frontier AI models with cyber capabilities. A regulator publishing observations from an actual review is worth more than published guidance, since it describes what supervised firms are really doing instead of what a rule requires. Firms outside the UK should read it as an early view of the questions their own regulators will arrive with. JD Supra has the summary.

3. OneTouchPoint Settles Four Years After the Attack

The Wisconsin mailing and printing vendor OneTouchPoint agreed to a multi-million dollar settlement of class action litigation over its 2022 ransomware attack. Four years from incident to settlement is the number worth carrying into your own reserving, and it is a year longer than the three-year gap in the MCNA settlement we covered last week. A print and mail vendor holds names and addresses for every client it serves, which is why the affected population reaches well past the company itself. HIPAA Journal has the settlement.

Operator Note: Your mailing vendor holds a current list of everybody you communicate with, so it belongs in the same tier of third-party review as anybody touching your clinical or financial systems.

4. Rising Anonymous Reporting Is a Retaliation Signal

An analysis of reporting data argues that a growing share of workers choosing to report anonymously reflects fear of retaliation rather than a healthy hotline. Most programs treat report volume as the metric and read an increase as success, which misses what the shift toward anonymity is telling you about whether people believe the process protects them. The useful measure is the ratio between named and anonymous reports over time. Corporate Compliance Insights has the argument.

5. CFIUS Publishes Its 2025 Annual Report

The Committee on Foreign Investment in the United States released its statutory annual report to Congress covering calendar year 2025 activity, with statistics on filings, reviews, and outcomes. For anybody raising capital or selling a stake, the report is the clearest available read on which sectors and which investor profiles draw scrutiny. Deal timelines get built on assumptions this document either supports or corrects. JD Supra has the analysis.

Additional Compliance Alerts

Regulatory Updates

  • Wisconsin updated its child labor regulations effective June 1: Employers hiring minors need to review hours, permitted occupations, and documentation practices against the new Department of Workforce Development rules. JD Supra

Third-Party Risk and Due Diligence

  • NFI North breach affects almost 50,000 people: Disclosed alongside notices from Nephrology Associates in Kansas and a health fund, in another week of provider-adjacent organizations reporting through their vendors. HIPAA Journal

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Dusten Trounce
Director of Physical Security
Dusten Trounce
The Growth Architect.

A leader defined by a 'bias for action,' Dusten specializes in physical security assessments that impact profitability and facility resilience.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)