A Policy Is Not Evidence (08/31/2026)
- › AI governance is moving from written policy to producible evidence, and a policy document is not evidence that anything happened.
- › Self-funded plans and their third-party administrators keep misreading which of them is the covered entity under HIPAA.
- › The SEC is running a sweep against filers who submitted fake Form ADV disclosures.
- › Connecticut fined a licensed student loan servicer over alleged unlicensed small loan activity.
- › The EU's Italian cases carry implications for sanctions and anti-money-laundering programs.
The strongest item today is an argument rather than an enforcement action. AI governance has reached the stage where somebody external asks to see the artifacts, and most organizations have a policy, a committee, and nothing that demonstrates a decision was actually made the way the policy describes.
Top 5 Critical Compliance Alerts
1. AI Governance Has to Produce Evidence on Demand
Practitioners are making the case that a written AI governance policy proves nothing by itself, and that what gets asked for under scrutiny is the record: which model, approved by whom, tested against what, with which exceptions granted and on what basis. Corporate Compliance Insights
Operator Note: This is the same gap we carried on August 25 as the compliance confidence gap, arriving in a newer domain. Run the test now while it costs nothing: pick one AI tool your organization uses and ask for the approval record. If what comes back is the policy that says approvals are required, you have found the finding, and you have found it before a regulator or an acquirer did.
2. Self-Funded Plans Keep Misreading the Covered Entity Line
Counsel are revisiting the covered entity distinction for self-funded health plans and their third-party administrators, which routinely gets assigned to the wrong party. The distinction decides who carries the obligation and who merely handles the data. JD Supra
Operator Note: The pattern is an employer assuming the administrator carries the HIPAA obligation and the administrator assuming it acts only as a business associate, which leaves the plan itself unattended. If your company self-funds, find out in writing which entity is the covered entity, because that answer determines who owes notification when something goes wrong.
3. The SEC Sweeps Fake Form ADV Filers
The Commission is running a sweep against filers who submitted fraudulent Form ADV disclosures. A sweep targets a filing population at once instead of opening individual investigations. Compliance Building
Operator Note: Sweeps are cheap for a regulator and expensive for everyone caught in one, because they are run against data the Commission already holds rather than requiring an investigation to start. Anything you file on a recurring form is queryable in bulk, and the assumption that a filing gets read once by one person has been wrong for several years.
4. Connecticut Fines a Student Loan Servicer
The state regulator fined a licensed student loan servicer over alleged unlicensed small loan activity. The allegation concerns the scope of the license held, not the treatment of borrowers. JD Supra
Operator Note: Holding one license and operating slightly outside it is a common and underrated exposure, particularly for firms that added a product line without revisiting their authorizations. The activity here was not alleged to be harmful, it was alleged to be unlicensed, and that is a much easier case for a regulator to make.
5. The EU’s Italian Cases Reshape Sanctions and AML Expectations
Recent Italian cases carry implications for how sanctions and anti-money-laundering programs are expected to operate across the EU. The cases speak to what supervisors expect a functioning program to demonstrate. Corporate Compliance Insights
Operator Note: Sanctions screening is one of the few compliance functions where the control is genuinely automated end to end, which means the failures are configuration failures and almost never judgement ones. If you screen, the useful question is when somebody last reviewed the match thresholds and the exclusion list, since both drift toward fewer alerts over time and nobody notices a control getting quieter.
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
A leader defined by a 'bias for action,' Dusten specializes in physical security assessments that impact profitability and facility resilience.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.