Your AI Notes May Not Be Privileged (09/15/2026)
- › Emerging case law shows AI-assisted investigation work can lose attorney-client privilege more easily than teams expect.
- › The PCI Security Standards Council published an information supplement on securing AI systems in payment environments.
- › The SEC's Division of Examinations issued a risk alert on investment adviser annual compliance reviews.
- › LHC Group, a nationwide home health provider, announced a major data breach alongside several other providers.
- › A new report finds a gap between the risks organizations face and the risks internal audit is prepared to address.
An internal investigation is protected because a lawyer directed it for the purpose of giving legal advice, and that protection has always depended on who did the work and why. Putting an AI tool in the middle of that chain raises a question nobody drafted the privilege doctrine to answer, and courts are now answering it case by case.
Top 5 Critical Compliance Alerts
1. Courts Are Deciding When AI Work Loses Privilege
Emerging case law addresses how readily AI-assisted investigation work can fall outside attorney-client privilege, with the analysis turning on who directed the work and whether the tool’s involvement broke the chain that made it legal advice. Investigation teams have adopted these tools quickly because document review is exactly what they are good at, and most of that adoption happened without anybody asking whether the output stays protected. A privilege determination made after the fact is the worst possible time to learn the answer. Corporate Compliance Insights has the case law.
Operator Note: Ask your general counsel now whether AI-assisted review is permitted in a privileged investigation at your organization, and get the answer in writing before the next one starts.
2. The PCI Council Publishes AI Security Guidance
The PCI Security Standards Council released an information supplement covering the security of AI systems, addressing both the use of AI inside payment environments and the securing of AI systems themselves. An information supplement is guidance rather than a requirement, which makes it the clearest available preview of where assessor expectations will settle. Anybody putting a model anywhere near cardholder data should read it as the question list they will eventually be answering. PCI Security Standards Council has the supplement.
3. The SEC Targets Annual Compliance Reviews
The SEC’s Division of Examinations published a risk alert on investment adviser annual compliance reviews, the requirement advisers have carried for years and which examiners are evidently finding thin. A risk alert is the agency telling firms which deficiency it keeps seeing, which makes it a free preview of what an examination will look for. A review conducted by the person who runs the program, on the program they run, is the specific weakness this category tends to produce. Compliance Building has the alert.
Operator Note: Whatever annual review you owe, check whether the person performing it has any independence from the program being reviewed, because that is the first question an examiner asks.
4. LHC Group Announces a Major Breach
The Louisiana-based nationwide home health provider LHC Group announced a major data breach, disclosed alongside notices from Provident Behavioral Health in Missouri and other providers. Home health is the second nationwide provider in this category to disclose in a fortnight, and the pattern is worth naming, since these organizations hold clinical records together with the home addresses and visit schedules of people receiving care. The population affected by a home health breach is unusually easy to locate physically. HIPAA Journal has the disclosure.
5. Internal Audit Is Not Aligned to the Actual Risks
A new report documents a gap between the top risks organizations currently face and the risks that management and audit teams are prepared to address, which describes an assurance function working last year’s plan. Audit plans are set annually and the risk landscape they were set against has moved, particularly on anything involving AI adoption or third-party concentration. The gap itself is the finding, and it belongs in front of the audit committee rather than inside the audit function. Radical Compliance has the report.
Additional Compliance Alerts
Enforcement
- Connecticut fined an earned wage access provider over unlicensed lending: The Banking Department’s consent order treats the advances as small loans requiring a license, which is the regulatory question hanging over that entire product category. JD Supra
Sector Guidance
- Applied behavior analysis providers face growing oversight: New guidance sets out what ABA providers need to know about compliance oversight in a sector that has expanded faster than its regulatory framework. JD Supra
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
A leader defined by a 'bias for action,' Dusten specializes in physical security assessments that impact profitability and facility resilience.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.