Censured for Failing the Same Rule Again (09/22/2026)

September 22, 2026
Censured for Failing the Same Rule Again (09/22/2026)
Key Intel / TL;DR
  • The SEC censured OTC Link for compliance failures under Regulation SCI that the filing describes as repeated.
  • A repeat finding costs more than a first one because it establishes that the earlier remediation did not hold.
  • California is requiring independent audits for AI accountability, which moves AI governance from policy into assurance.
  • Congress remains stalled on AI regulation while states legislate, so the operative rules are the ones in your customers' jurisdictions.
  • An SEC risk alert lists the deficiencies examiners keep finding in adviser annual compliance reviews.

The word doing the work in today’s SEC action is “repeated.” A first finding says a control was missing, while a second finding on the same rule says the organization was told, said it would fix the issue, and did not. That distinction drives penalties, and it is the same distinction an auditor draws when a prior year observation reappears. Alongside that, California has attached independent audits to its AI accountability rules while Congress stays where it is.

Top 5 Critical Compliance Alerts

The Commission censured OTC Link LLC for compliance failures related to Regulation SCI, characterizing the failures as repeated, per the SEC. Regulation SCI governs the technology systems that keep markets running, covering capacity, integrity, resiliency, and availability, so a finding here is a statement about operational engineering rather than paperwork.

Operator Note: Pull your last two assessment reports and mark every finding that appears in both. That list is the one to show your board, because a repeat finding is evidence your remediation process does not close things.

2. California Attaches Independent Audits to AI Accountability

California is raising its AI accountability requirements to include independent audits, per JD Supra. Requiring an outside party to test the claim changes what an AI policy has to be, since a document describing your intentions does not survive somebody checking whether the system behaves that way.

3. Congress Is Stalled on AI Regulation and the States Are Not

Federal AI legislation remains stuck while state legislatures continue passing their own rules, per Corporate Compliance Insights. For anybody operating across state lines this means the binding requirements are a patchwork, and the practical planning assumption is the strictest state you serve.

Operator Note: Build your AI inventory once against the most demanding state rule you are exposed to. Rebuilding it per jurisdiction is the expensive way to arrive at the same place.

4. An SEC Risk Alert Names the Deficiencies Examiners Keep Finding

The Commission published a risk alert covering common deficiencies in investment adviser annual compliance reviews, per JD Supra. A risk alert is effectively a list of what examiners will ask about next, which makes it the cheapest preparation available.

5. The FCC Covered List Reaches Further Into Supply Chains

The FCC has expanded its Covered List, extending national security controls deeper into technology supply chains, per JD Supra. Equipment that was acceptable when you bought it can become prohibited while it is still racked and working, which is a procurement and lifecycle problem before it is a legal one.

Additional Compliance Alerts

Regulatory Fines and Enforcement Actions

  • Albany College of Pharmacy settles a data breach claim: The college has reached a settlement over its breach, which continues the pattern of civil resolution arriving well after the incident. HIPAA Journal
  • Call-on-Doc notifies patients of a December 2025 incident: The telehealth provider is notifying patients about a hacking incident from December 2025, another long gap between intrusion and notice. HIPAA Journal

Compliance Frameworks

  • Takeaways from OCR’s HIPAA Security Conference: A healthcare compliance attorney’s account of what regulators signaled at the joint OCR and NIST conference. HIPAA Journal
  • What in-house counsel should be doing about quantum risk now: A practical view of which decisions have to be made before cryptographically relevant quantum computing arrives. JD Supra

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Dusten Trounce
Director of Physical Security
Dusten Trounce
The Growth Architect.

A leader defined by a 'bias for action,' Dusten specializes in physical security assessments that impact profitability and facility resilience.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)