SEC Proposes E-Delivery, DOJ Targets PPP Loans & FTC Eyes AI (07/16/2026)

July 16, 2026
SEC Proposes E-Delivery, DOJ Targets PPP Loans & FTC Eyes AI (07/16/2026)
Key Intel / TL;DR
  • The SEC proposed Regulation E-Delivery, expanding electronic delivery to satisfy information delivery requirements.
  • The Department of Justice is contacting nonprofits about Paycheck Protection Program loans received years ago, using the civil False Claims Act.
  • The FTC published a proposed policy statement on whether AI companies violate Section 5 when systems pursue hidden objectives.
  • Three more healthcare organizations disclosed data breaches, and two vision care providers settled class actions.
  • 43% of governance, risk, and compliance professionals say AI is making their jobs harder.

Two enforcement signals landed today and both are about attestations you already signed. The Department of Justice is going back years to question Paycheck Protection Program loans, and this time nonprofits are opening the letters. The Securities and Exchange Commission (SEC) proposed a new delivery rule, the Federal Trade Commission (FTC) moved on AI deception, and three more healthcare organizations disclosed breaches. If you certified something to the federal government since 2020, today is a good day to find out whether you can still produce the evidence behind it.

Top 5 Critical Compliance Alerts

1. DOJ Targets Nonprofit PPP Loans Under the False Claims Act

United States Attorney’s Offices, working with the Small Business Administration, are contacting nonprofits about Paycheck Protection Program loans they received years ago, pursuing them under the civil False Claims Act (JD Supra). This follows a $21.3 million settlement with two contractors and two executives that we covered yesterday, and the pattern is now hard to miss: the same statute, a wider net, and a look back at certifications made under emergency conditions.

Operator Note: Pull your PPP file this week. The certification about necessity was made fast in 2020, and the question now is whether you can document what you believed then and why. That is an assessment, and it costs far less than a response.

2. SEC Proposes Regulation E-Delivery

The SEC proposed Regulation E-Delivery, a rule expanding the ability of issuers, broker-dealers, investment advisers, and others to use electronic delivery to satisfy information delivery requirements (SEC). A delivery rule sounds procedural until you remember that delivery is what you have to prove, and proving it electronically means retention, audit trail, and access controls become the compliance evidence.

3. FTC Wants AI Systems to Disclose Deception

On July 1, 2026, the FTC published a proposed policy statement addressing whether AI companies violate the Section 5 prohibition on deceptive acts or practices when they direct their systems’ outputs toward hidden objectives (JD Supra). If you deploy AI that talks to your customers, the obligation is landing on the deployer as much as the developer, and “the vendor built it” has never been a defense that holds up well.

4. Three More Healthcare Organizations Disclose Breaches

Ohio Living, Erlanger Health System in Tennessee, and Heart of America Eye Care each announced data breaches (HIPAA Journal). A senior living operator, a regional health system, and an eye care practice have almost nothing in common operationally, which is the point. Under the Health Insurance Portability and Accountability Act (HIPAA), they carry the same obligation and rarely the same budget.

5. Vision Care Providers Settle Breach Class Actions

Total Vision in California and Naper Grove Vision Care agreed to settlements resolving data breach class action lawsuits (HIPAA Journal). The class action is the second bill, it arrives long after the incident response invoice is paid, and it is the one most small practices never model.

Additional Compliance Alerts

Policy & Governance Updates

  • 43% of GRC Professionals Say AI Makes Their Jobs Harder: A new roundup finds nearly half of governance, risk, and compliance professionals reporting AI has added difficulty rather than removed it, and notes leaders use shadow AI more than their employees do. Corporate Compliance Insights

Third-Party Risk & Due Diligence

  • C-TPAT Draws Renewed Executive Attention: Geopolitical pressure is pushing supply chain security up the agenda, with renewed interest in the Customs-Trade Partnership Against Terrorism program across industrial and transportation sectors. JD Supra
  • An OIG Report Puts China Exporters Under Closer Scrutiny: Oversight findings are prompting more oversight, with six concrete steps exporters should take on due diligence, documentation, and escalation. Corporate Compliance Insights

Regulatory Updates

  • SEC Enforcement Under a First Principles Approach: Chairman Atkins continued to emphasize the end of “regulation by enforcement” and a program not centered on record penalties or action counts. JD Supra

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Dusten Trounce
Director of Physical Security
Dusten Trounce
The Growth Architect.

A leader defined by a 'bias for action,' Dusten specializes in physical security assessments that impact profitability and facility resilience.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)