SEC Proposes E-Delivery, DOJ Targets PPP Loans & FTC Eyes AI (07/16/2026)
- › The SEC proposed Regulation E-Delivery, expanding electronic delivery to satisfy information delivery requirements.
- › The Department of Justice is contacting nonprofits about Paycheck Protection Program loans received years ago, using the civil False Claims Act.
- › The FTC published a proposed policy statement on whether AI companies violate Section 5 when systems pursue hidden objectives.
- › Three more healthcare organizations disclosed data breaches, and two vision care providers settled class actions.
- › 43% of governance, risk, and compliance professionals say AI is making their jobs harder.
Two enforcement signals landed today and both are about attestations you already signed. The Department of Justice is going back years to question Paycheck Protection Program loans, and this time nonprofits are opening the letters. The Securities and Exchange Commission (SEC) proposed a new delivery rule, the Federal Trade Commission (FTC) moved on AI deception, and three more healthcare organizations disclosed breaches. If you certified something to the federal government since 2020, today is a good day to find out whether you can still produce the evidence behind it.
Top 5 Critical Compliance Alerts
1. DOJ Targets Nonprofit PPP Loans Under the False Claims Act
United States Attorney’s Offices, working with the Small Business Administration, are contacting nonprofits about Paycheck Protection Program loans they received years ago, pursuing them under the civil False Claims Act (JD Supra). This follows a $21.3 million settlement with two contractors and two executives that we covered yesterday, and the pattern is now hard to miss: the same statute, a wider net, and a look back at certifications made under emergency conditions.
Operator Note: Pull your PPP file this week. The certification about necessity was made fast in 2020, and the question now is whether you can document what you believed then and why. That is an assessment, and it costs far less than a response.
2. SEC Proposes Regulation E-Delivery
The SEC proposed Regulation E-Delivery, a rule expanding the ability of issuers, broker-dealers, investment advisers, and others to use electronic delivery to satisfy information delivery requirements (SEC). A delivery rule sounds procedural until you remember that delivery is what you have to prove, and proving it electronically means retention, audit trail, and access controls become the compliance evidence.
3. FTC Wants AI Systems to Disclose Deception
On July 1, 2026, the FTC published a proposed policy statement addressing whether AI companies violate the Section 5 prohibition on deceptive acts or practices when they direct their systems’ outputs toward hidden objectives (JD Supra). If you deploy AI that talks to your customers, the obligation is landing on the deployer as much as the developer, and “the vendor built it” has never been a defense that holds up well.
4. Three More Healthcare Organizations Disclose Breaches
Ohio Living, Erlanger Health System in Tennessee, and Heart of America Eye Care each announced data breaches (HIPAA Journal). A senior living operator, a regional health system, and an eye care practice have almost nothing in common operationally, which is the point. Under the Health Insurance Portability and Accountability Act (HIPAA), they carry the same obligation and rarely the same budget.
5. Vision Care Providers Settle Breach Class Actions
Total Vision in California and Naper Grove Vision Care agreed to settlements resolving data breach class action lawsuits (HIPAA Journal). The class action is the second bill, it arrives long after the incident response invoice is paid, and it is the one most small practices never model.
Additional Compliance Alerts
Policy & Governance Updates
- 43% of GRC Professionals Say AI Makes Their Jobs Harder: A new roundup finds nearly half of governance, risk, and compliance professionals reporting AI has added difficulty rather than removed it, and notes leaders use shadow AI more than their employees do. Corporate Compliance Insights
Third-Party Risk & Due Diligence
- C-TPAT Draws Renewed Executive Attention: Geopolitical pressure is pushing supply chain security up the agenda, with renewed interest in the Customs-Trade Partnership Against Terrorism program across industrial and transportation sectors. JD Supra
- An OIG Report Puts China Exporters Under Closer Scrutiny: Oversight findings are prompting more oversight, with six concrete steps exporters should take on due diligence, documentation, and escalation. Corporate Compliance Insights
Regulatory Updates
- SEC Enforcement Under a First Principles Approach: Chairman Atkins continued to emphasize the end of “regulation by enforcement” and a program not centered on record penalties or action counts. JD Supra
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
A leader defined by a 'bias for action,' Dusten specializes in physical security assessments that impact profitability and facility resilience.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.