Weekly AI Governance Brief: 7–13 September 2026
Bringing you the latest developments in the AI Governance world.
UK commission proposes lifecycle regulation for healthcare AI
On 10 September, the UK's National Commission into the Regulation of AI in Healthcare published its recommendations for a future regulatory framework.
The Commission was established to advise government on regulation covering AI-enabled medical devices and the wider governance issues associated with their deployment. Its report identifies a central difficulty with applying conventional medical-device regulation to AI: software and AI products may evolve over time, and their performance can depend significantly on the environment in which they are deployed.
One of the Commission's central proposals is a staged authorisation pathway for appropriate AI-enabled medical devices. Under the model, an initially limited deployment could be authorised on the basis of early evidence and agreed risk controls. The scope could then expand once predetermined evidence thresholds concerning performance and safety are satisfied.
The report explicitly presents this as an alternative to regulatory models weighted toward a single pre-market approval point. It recommends stronger use of real-world evidence, post-market surveillance, and continuing assessment over a device's lifecycle.
The Commission also proposes stronger monitoring infrastructure. AI-enabled medical devices should be traceable after deployment, including by version, while manufacturers should monitor performance and report changes capable of causing harm.
A separate recommendation concerns dependencies on general-purpose models. Manufacturers should disclose where a medical product depends on an underlying general-purpose AI model and identify associated risks, mitigations and continuity arrangements through regulatory submissions or procurement processes.
The Commission also recommends enhanced enforcement mechanisms for the MHRA. These could include faster communication of safety signals and financial penalties for manufacturers that breach legal requirements in ways that place patients at risk.
Why this matters
The proposed framework treats AI regulation as an ongoing governance process rather than a decision concentrated at market entry.
That distinction is particularly relevant for systems whose behaviour or performance may shift after deployment. Staged authorisation and post-market surveillance would allow regulatory confidence to develop alongside real-world evidence rather than depending entirely on pre-deployment testing.
The recommendation on general-purpose model dependencies adds another governance layer. A healthcare product may incorporate technology controlled by a separate upstream provider, creating dependencies that extend beyond the immediate medical-device manufacturer. Requiring disclosure of those relationships would make such dependencies more visible to regulators and procuring healthcare organisations.
The proposals remain recommendations rather than final government policy. A separate government response is expected.
California expands AI assurance and child-safety obligations
On 9 and 10 September, the state of California enacted several AI-related laws strengthening both independent assurance and operational safeguards for child-facing systems.
Senate Bill 813 establishes a framework for independent verification organisations assessing AI systems and models against California legal requirements, while Assembly Bill 1405 creates a state registry for AI auditors and introduces standards concerning auditor independence, transparency and integrity.
The measures formalise third-party AI assurance as part of the state's compliance infrastructure. External assessment is no longer treated simply as a voluntary technical practice: California is also setting requirements for the organisations conducting those assessments and the conditions under which their work should be considered credible.
A separate package of child online-safety legislation extends this approach to companion chatbots. SB 1119 introduces protections for children interacting with these systems, including crisis protocols where a child expresses suicidal ideation, parental controls and notifications when safety settings are disabled.
The legislation also requires independent child-safety audits and annual risk assessments, creating recurring governance obligations throughout deployment. The broader package includes measures addressing digitally altered and AI-generated sexual exploitation material involving minors and the use of K-12 pupil information in AI systems.
Why this matters
Together, the measures show California developing AI governance around both who provides assurance and how assurance is maintained after deployment.
The auditor framework seeks to establish credible independent oversight, while the companion-chatbot rules apply recurring assessment and operational safeguards to a specific context involving vulnerable users. Governance therefore extends beyond documentation or initial testing to include continuing risk assessment and responses to foreseeable harms.
For organisations, the significance is that third-party evaluation is becoming more closely connected to formal compliance structures, while certain AI use cases are beginning to attract ongoing obligations rather than one-off assessments.
Looking ahead
The developments of 7–13 September point toward a broader shift from one-off AI assessment toward continuous assurance.
Across California and the UK healthcare proposals, regulators are placing greater emphasis on independent evaluation, post-deployment monitoring and recurring risk assessment. At the same time, governance responsibilities are expanding beyond developers to include auditors, deployers, procuring organisations and regulators.
The direction is increasingly clear: demonstrating compliance at launch may not be enough. Organisations may also need to show that AI systems remain safe, monitored and accountable throughout their operational lifecycle.
Sources
UK National Commission recommendations on AI regulation in healthcare: https://www.gov.uk/government/publications/national-commission-into-the-regulation-of-ai-in-healthcare-recommendations-for-a-future-regulatory-framework/national-commission-into-the-regulation-of-ai-in-healthcare-recommendations-for-a-future-regulatory-framework
MHRA announcement accompanying the healthcare AI recommendations: https://www.gov.uk/government/news/independent-commission-led-by-nhs-doctors-sets-out-blueprint-to-accelerate-safe-ai-adoption-in-healthcare
California child-safety and companion-chatbot legislation: https://www.gov.ca.gov/2026/09/10/governor-newsom-signs-the-strongest-child-safety-chatbot-and-social-media-laws-in-the-nation/
California independent AI audit and verification legislation: https://www.gov.ca.gov/2026/09/09/governor-newsom-signs-first-in-the-nation-ai-safeguards-to-protect-californians-calls-on-the-federal-government-to-do-its-part/