On 14 September 2026, the UK Parliament's Joint Committee on Human Rights published its inquiry report on AI and human rights, recommending dedicated legislation to establish prior approval for high-risk systems, supply chain due diligence and independent oversight. These recommendations do not yet create new obligations for companies. On 16 September 2026, California Governor Gavin Newsom signed legislation on synthetic performer disclosures in advertising, requiring clear disclosure of the synthetic nature of performers in advertisements within scope and specifying advertising media's responsibilities upon receipt of a court order. The provisions will take effect on 1 January 2027. On 17 September 2026, the European Commission proposed the KIDS Act, seeking to restrict AI designs that create emotional dependency in children and the use of memory across conversations, and to introduce pre-market compliance verification. The proposal has implications for chatbot feature configuration, memory management and safety testing, and remains subject to legislative scrutiny. On 18 September 2026, Governor Newsom signed an executive order accelerating the establishment of independent AI evaluation and auditing arrangements and directing the study of legislative amendments on on-site evaluation of frontier models, emergency shutdown and loss-of-control incident reporting. The order does not directly require companies to accept on-site evaluations or install kill switches.
On 14 September 2026, the UK Parliament's Joint Committee on Human Rights (JCHR) published its inquiry report Human Rights and the Regulation of AI, examining AI's implications for equality and non-discrimination, privacy and the right to an effective remedy.
The report recommends dedicated legislation to establish risk-based regulation and independent oversight. These remain parliamentary recommendations and do not create new obligations for companies. It proposes prohibiting AI uses incompatible with human rights protections, with the precise boundaries to be determined through public consultation. Systems posing a high risk to human rights would require approval before being provided or deployed. The proposed due diligence and transparency duties would extend across the supply chain and be allocated according to each participant's role and the level of risk, including explanations of AI's intended use and data sources. Independent oversight could be established through a new body or by expanding the remit of an existing institution. Recommended powers include testing, investigation, restrictions on deployment, mandatory market withdrawal and sanctions.
Companies using AI to analyse customer service calls, assess employee performance and recommend disciplinary action can include appeal handling in pre-launch acceptance testing. Simulated scenarios involving adverse scores caused by transcription errors, dialect recognition bias or missing context can test whether reviewers can examine the original materials, hear the employee's explanation and correct the outcome. Human reviewers should have the authority to independently change scores or withdraw disciplinary recommendations, and record their reasoning for each case. To support dispute investigations, companies can retain linked records of input materials, model and business rule versions, scoring results and human decisions, while limiting access to employee information and its retention period. Procurement requirements should ask suppliers to explain intended use cases, testing limitations and version changes, and specify responsibilities for providing investigation materials and correcting errors. This would enable companies to trace problems to the model, system configuration or business rules. These preparations draw on the report's recommendations on the allocation of responsibilities, transparency and effective human intervention, and can help assess whether existing review procedures can handle real disputes.
On 29 March 2023, the UK Government published the white paper A pro-innovation approach to AI regulation, advocating an initial approach based on non-statutory common principles to guide existing regulators. The JCHR report instead recommends dedicated legislation to strengthen responsibilities across the supply chain and oversight powers. The EU's Artificial Intelligence Act (AI Act), which has entered into force and applies in phases, already establishes differentiated legal obligations according to risk and supply chain roles. Paragraph 208 of the report explicitly suggests drawing on the EU arrangements when designing due diligence obligations, with adaptations to the UK context. Teams operating across regions can use this comparison to assess risk evaluation and supplier information requirements, while checking applicable classifications and responsibility boundaries separately. The parliamentary publication page states that the Government has two months to respond. Key developments to monitor include whether it accepts the recommended legislative scope, prior approval mechanism and oversight powers.
On 16 September 2026, California Governor Gavin Newsom signed False advertising: synthetic performers (SB 1050), establishing disclosure duties for advertisements using synthetic performers and specifying the responsibilities of advertising media.
The law has been signed but is not yet in effect. Under California's ordinary legislative rules, it will take effect on 1 January 2027. A synthetic performer is a digital figure or voice created wholly or partly using generative AI that realistically simulates a human performance but is not recognisable as a specific natural person. Anyone creating and arranging publication of an advertisement that prominently features such a performer must clearly and conspicuously disclose its synthetic nature, including in product demonstrations and narration, using wording substantially similar to the statutory examples. Once an advertising medium is served with a court order finding a violation or prohibiting publication, together with sufficient information to identify the advertisement, it must cease dissemination as soon as commercially reasonable and technically feasible, and stop accepting payment for further dissemination. Exceptions apply where AI is used solely for language translation of a human performer or accessibility features, and to qualifying promotions of expressive works.
When a brand automatically adapts an AI-character product demonstration into short videos, podcast advertisements and multilingual materials, disclosure checks should form part of the release acceptance process for every final version. Teams should verify that the disclosure remains clear and understandable after cropping, voice replacement and audio export; audio-only versions can use an audible disclosure. Acceptance testing should examine the version actually delivered to consumers, linking it to the source materials, generation tools, disclosure wording, approval records and target jurisdictions. Procurement contracts can require producers to disclose the provenance of synthetic characters and voices, deliver finished assets containing the disclosure, and allocate responsibilities for subsequent editing, subcontracting and corrections. Platforms acting as advertising media can also rehearse locating distributed copies by advertisement ID, pausing scheduled placements and stopping acceptance of payments for further placements, with clear procedures for legal teams to notify operations and billing teams after receiving a court order. These arrangements draw on the disclosure and response mechanisms in the newly added Section 17610; the specific approval and recordkeeping methods are implementation recommendations.
Section 17500 of California's existing Business and Professions Code already prohibits false or misleading advertising. SB 1050 builds on this by specifying disclosure duties for certain synthetic performers and making violations enforceable through existing false advertising and unfair competition remedies. Accordingly, even after disclosing a performer's synthetic nature, claims about product efficacy or user experience still require separate verification. China's Measures for Labelling AI-Generated and Synthetic Content, issued by the Cyberspace Administration of China and three other authorities on 14 March 2025 and effective from 1 September 2025, establish requirements for explicit notices, file metadata labels and verification during dissemination for service providers within scope, covering text, images, audio, video and other content. The two regimes differ in the entities covered, content scope and technical requirements. Campaigns across jurisdictions can share asset provenance records while separately configuring consumer-facing disclosures and embedded file labels. In California, subsequent monitoring should focus on how enforcement assesses whether disclosures are clear and conspicuous across advertising formats and whether exceptions apply.
On 18 September 2026, California Governor Gavin Newsom signed Executive Order N-9-26, directing the state government to accelerate the establishment of independent AI evaluation arrangements and study legislative amendments for frontier model safety oversight.
The executive order took effect immediately. It directs the California Government Operations Agency (GovOps) to accelerate the establishment of independent evaluation and auditing arrangements and submit recommendations for legislative amendments by 16 November 2026. Areas for study include on-site evaluations at large frontier developers' laboratories and independent verification of safety frameworks, transparency reports and risk assessments; emergency shutdown mechanisms (kill switches) for frontier models and ongoing verification of their effectiveness; and the inclusion of a broader range of loss-of-control scenarios within critical safety incident reporting. The technical feasibility and potential effectiveness of these measures must be assessed. The order does not directly impose obligations on companies to accept on-site evaluations or install kill switches.
Frontier model developers can test their evaluation readiness through a model update that introduces code execution capabilities. They can provide evaluators with the relevant model version, risk testing, permission configurations and remediation evidence, while agreeing on an isolated test environment, necessary access scope and confidentiality arrangements so that safety conclusions can be independently reviewed. Shutdown exercises should cover the actual execution chain. Teams should separately test closure of model endpoints, revocation of tool credentials and termination of spawned tasks, simulating replicas across regions, queued tasks and automatic retries to identify which activities continue after shutdown and who authorises resumption. Evaluation records can link trigger conditions, the actual scope of termination, unresolved risks and retest results. Companies accessing models through external interfaces can ask suppliers to confirm service suspension notifications, investigation cooperation and business continuity arrangements for taking over affected operations. These deployment preparations draw on the order's focus on independent verification and prevention of loss of control, together with existing model governance provisions. Specific controls should reflect each company's architecture.
Independent verification organizations (SB 813) and Artificial intelligence: auditors: registration (AB 1405), both signed on 9 September 2026, are not yet in effect. They provide for an organisation designation regime and an auditor registration regime, respectively. The executive order brings forward the deadlines for the related government tasks to 1 May 2027 and 1 December 2027. SB 813 makes clear that engaging an independent verification organisation is not a universal prerequisite for AI development, deployment or operation. The statutory application date for AB 1405's prohibition on unregistered persons conducting covered audits remains 1 January 2029. The EU's Artificial Intelligence Act (AI Act), already in force, imposes risk assessment and mitigation obligations on providers of general-purpose AI models with systemic risk. Teams operating across regions can reuse evaluation evidence, but should separately assess the entities covered, evaluation requirements and reporting channels. In California, priorities for monitoring include how the proposed legislative amendments define the powers associated with on-site verification, the scope of shutdown and its trigger conditions.
On 17 September 2026, the European Commission proposed the EU Keeping Internet Digital Spaces Accountable and Trustworthy Act (EU KIDS Act), a proposed regulation covering safety requirements for minors' use of social platforms, online games, AI companions and chatbots.
The proposal seeks to embed child safety in service design and pre-market verification, and remains subject to legislative scrutiny. According to the Commission's official questions and answers, AI companions and chatbots accessible to minors would be prohibited from using designs that simulate human relationships in ways likely to create emotional dependency, and would not be permitted by default to carry children's earlier conversations into later sessions. Chatbots embedded in platforms or games would not be allowed to activate automatically or be proactively promoted to children, and would have to be easy to turn off. Children under 13 would be able to use them only through parental control tools. Providers would also be required to demonstrate compliance before placing services on the market and establish mechanisms to continuously monitor emerging risks and incidents.
Teams operating games with AI-character conversations can prepare by incorporating region, age and parental control status into feature configurations, and testing whether restrictions remain effective after device changes, new logins and version updates. Testing across sessions should cover historical summaries, user profiles and external memory stores. Teams can enter a fictional personal experience in one test conversation, start a new session and check whether the information is automatically retrieved, verifying consistency between interface settings and backend behaviour. Multi-turn tests can also assess whether a character asks users to conceal interactions, discourages real-world relationships or induces guilt when a user leaves. Contracts for third-party conversational services should address memory retrieval controls, data uses, version change notifications and allocation of risk response responsibilities. Records retained for complaint investigations should be managed separately, with limits on access, purpose and retention, to prevent their reuse in personalised conversations. These are deployment preparations based on the proposal. The default restriction on carrying conversation memory forward, as described in the official questions and answers, should not be interpreted as requiring immediate deletion of all chat records.
On 14 July 2025, the Commission published the Guidelines on measures to ensure a high level of privacy, safety and security for minors online, which already recommended safeguards for chatbots embedded in platforms. Those guidelines are a voluntary regulatory reference; the new proposal brings related design restrictions into a dedicated legislative process. On 11 September 2025, the US Federal Trade Commission (FTC) launched an inquiry into companion chatbots, seeking information from seven companies on safety testing, protections for minors and use of conversation data. That action involves information gathering from specified companies. Both initiatives address risks arising from children's sustained interactions with AI, but proposed product design rules and information submission requirements in an inquiry differ in scope and legal function. Teams operating across regions can reuse risk testing materials while separately checking feature configurations and regulatory response requirements. Further EU monitoring should track changes to scope, memory restrictions and implementation arrangements during scrutiny by the European Parliament and the Council of the European Union.
Cite as · AI Governance Weekly · 22 September 2026
If you want both columns delivered together, four times a year, in one quiet email — leave an address. Otherwise just bookmark this page.