NextAI+ Praxis--:----UTC
AI Governance Weekly

Europe & US: US Signs Voluntary Frontier AI Accord; California Restricts AI-Based Dismissals, Expands Content Provenance and Requires Clinical AI Bias Monitoring; Bank of England Governor Calls for Continuous Testing and Effective Intervention

6 October 2026
Long read · 13 min
By NextAI+ Praxis

On 29 September 2026, President Trump and executives from six AI companies signed the White House Accord on Super Intelligence, making voluntary commitments on internal controls, internal review, external assessment and board oversight. The accord gives buyers a governance framework against which to request evidence from frontier model providers. On 30 September, California Governor Gavin Newsom signed SB 947, restricting employers’ use of automated systems for disciplinary and termination decisions and requiring human corroboration and notice. The same day, he signed SB 1000, which removes the user threshold for generative AI providers and extends the reach of content provenance verification and latent disclosure rules. He also signed SB 503, requiring clinical decision support system developers to provide healthcare facilities with information about bias risks and requiring those facilities to monitor and mitigate such risks periodically. Also on 30 September, Bank of England Governor Andrew Bailey published an article advocating model testing before and after deployment, learning from incidents, and maintaining effective intervention capabilities, offering a governance reference point for financial institutions assessing autonomous applications.

§ i

US Signs Voluntary AI Accord, Setting Out Four Layers of Controls and Audits

On 29 September 2026, President Donald Trump and executives from Google, Anthropic, Meta, OpenAI, xAI and Nvidia signed the White House Accord on Super Intelligence, making voluntary commitments on internal controls, independent evaluation and board oversight in the training and deployment of frontier models. An Associated Press report confirms the signing date and participants.

The accord has not created binding legal obligations. Its four layers are internal controls, review by an internal team, independent external assessment, and oversight by an independent board committee. Internal controls cover cyber, biological and chemical threats during training and deployment, as well as preventing models from accessing technical systems in unintended ways. An internal team checks that controls work and drives remediation; an external auditor or evaluator verifies them independently; and a board committee receives reports and oversees resolution of identified issues. The text does not prescribe a common audit frequency, evaluator qualifications or a public reporting process. The participating companies commit to regular discussions of standards and best practices. The verifiable text currently available is hosted by the American Presidency Project; a separately published text page on the White House website was not located in this review.

When procuring model services from a signatory, an enterprise can turn the safety commitments into specific evidence requests: which model version, tool permissions and deployment environments the external assessment covers; whether identified issues were remediated; and which results can be shared with customers. A supplier’s signature does not replace verification of the customer’s actual business configuration. For example, after connecting a model to an enterprise code repository and allowing it to run programs, teams should test whether a malicious file can induce it to read credentials, access unauthorised systems or continue a task after authorisation has been revoked. They should also check whether monitoring detects the anomaly and whether a responsible person can intervene promptly. Model developers preparing for assessment can maintain linked records of control settings, tests, failures and remediation retests, while defining the external evaluator’s access and reporting line. Procurement contracts can specify notices of version changes, delivery of assessment materials and cooperation in investigating material issues. These are implementation recommendations based on the four layers: the accord itself gives customers no right to a complete audit report and sets no uniform log retention period.

The Frontier AI Safety Commitments, announced by the UK and Korea on 21 May 2024, already addressed external evaluation, risk thresholds and publication of safety frameworks. The US accord further allocates roles for operating controls, internal review, external verification and board oversight, but does not repeat the Seoul commitments’ express position that a model should not be developed or deployed if risks cannot be sufficiently mitigated. Article 55 of the EU Artificial Intelligence Act (AI Act), by contrast, establishes legal duties for providers of general-purpose AI models with systemic risk concerning model evaluation, risk mitigation, serious incident reporting and cybersecurity. Cross-border developers can reuse test and remediation evidence while checking voluntary commitments and statutory duties separately. The next questions are how signatories will establish evaluator independence, test scope and remediation verification, and what evidence customers can obtain.

§ ii

California Restricts AI-Assisted Dismissals, Requires Human Corroboration and Notice

On 30 September 2026, California Governor Gavin Newsom signed SB 947, Employment: automated decision systems, restricting employers’ use of automated systems in disciplinary and termination decisions and setting duties for human corroboration, employee notice and explanations of relevant data. The Governor’s signing announcement was published the same day.

The law has been signed, and the relevant provisions become operative on 1 July 2027. An automated decision system (ADS) includes algorithmic scores, classifications and recommendations that materially affect individuals; it is not limited to generative AI. New Labor Code Section 1522 prohibits reliance solely on an ADS for a disciplinary or termination decision. If an employer primarily relies on an ADS output, a human must corroborate the decision using the underlying data or other relevant information. If the output cannot be corroborated, or the human reviewer finds it inaccurate, incomplete or misleading, the employer must not use it to make the decision. Section 1524 requires a separate, plain-language written notice when the employee is informed of the decision. The notice must state that an ADS was primarily relied upon, that human corroboration occurred, how to contact a person, the employee’s right to a description of their data and the prohibition on retaliation. The employee may request a meaningful, objective description of their own data used by the system, with other people’s personal information anonymised.

Employers using attendance anomaly scores or performance rankings to inform discipline can first trace how system outputs enter HR approvals and whether reviewers can obtain corroborating material. If an endpoint failure causes an employee to be marked absent without authorisation, for example, the responsible person should check schedules, approved leave and fault records and be able to reject an incorrect result. Acceptance testing should establish whether a failed corroboration blocks the disciplinary workflow, including pausing document generation and notice dispatch and referring a disputed case to an identified decision maker. Procurement terms can require suppliers to provide case-level inputs, outputs and version information so employers can explain the employee data used, rather than supplying only an uncheckable composite score. Notices should be linked to the specific decision, with corroborating evidence, the human conclusion and delivery records retained under appropriate access and retention controls. These are process recommendations for implementing statutory corroboration and notice duties; the law does not impose a uniform log format or retention period.

On 13 October 2025, Newsom vetoed SB 7 on the same subject, citing overly broad notice requirements, unclear definitions and overlap with existing schemes. SB 947 focuses notice on disciplinary or termination decisions that primarily rely on an ADS, bringing these protections into statute. Article 22 of the EU General Data Protection Regulation (GDPR), by comparison, generally restricts decisions based solely on automated processing that produce legal or similarly significant effects, subject to exceptions and safeguards. California expressly covers certain employment decisions with human involvement when the system is primarily relied upon. The two applicability tests are not interchangeable. Cross-border HR teams can share case-level corroboration records while configuring decision authority, notice and rights-response processes for each jurisdiction. California enforcement will clarify what “primarily relies” means and what corroboration is sufficient for a particular disciplinary decision.

§ iii

California Expands AI Provenance Rules, Removes Provider User Threshold

On 30 September 2026, California Governor Gavin Newsom signed SB 1000, amending the California AI Transparency Act (CATA) to broaden the scope of generative AI providers and revise content provenance, verification tools and third-party licensing arrangements.

SB 1000 took effect immediately as an urgency statute. It removes the previous threshold of more than one million monthly visitors or users for covered providers, while retaining the requirement that the system be publicly accessible in California. The separate threshold for large online platforms remains. Sections 22757.2–22757.3 require a free disclosure verification tool that can determine whether image, video or audio content was created or altered by the provider’s system. To the extent technically feasible, providers must also include a latent disclosure: machine-readable provenance information that now distinguishes creation from alteration, apart from statutory minor modifications. The amendment removes the former requirement to offer users a manifest disclosure option. Application of the relevant provisions to systems primarily designed as assistive technology is deferred until 1 January 2029.

Companies offering image generation, video editing or voice-over services to the California public should reassess immediately whether they qualify as covered providers and whether their outputs work with their verification tools. If a user uploads a product photograph, uses AI to change the background and downloads it, for example, acceptance testing can check whether the file correctly records that it was altered, identifies the system version and returns a consistent result when verified by upload or URL. Tests should cover the full generation, editing, export and subsequent transcoding workflow to locate where provenance information may be lost, rather than examining only an original sample. For third-party models or white-label services, contracts can allocate responsibility for embedding disclosures, maintaining the verification interface and fixing compatibility issues. Verification services that process uploaded files should limit access to and retention of personal information. These are implementation recommendations derived from the statutory mechanism. User interfaces should also distinguish “no provenance information detected” from “confirmed human-made,” avoiding conclusions beyond the tool’s verification capability.

SB 942, signed in California on 19 September 2024, established provider disclosure and detection tool rules; SB 1000 revises their coverage and technical mechanism. AB 2713, signed the same day as SB 1000, amends the rules for large online platforms to display and check provenance information. Its relevant platform provisions take effect on 1 January 2027, distinct from SB 1000’s immediate effect. China’s Measures for Labelling AI-Generated Synthetic Content, effective since 1 September 2025, require explicit and implicit labels for covered services and encompass text as well as other content types. Cross-border teams can reuse provenance records and file-flow tests while configuring visible notices, latent fields and verification interfaces separately. California’s removal of a manifest disclosure option is no basis for dropping labels required elsewhere. Future points to watch include interoperability across services and consistency between platform displays and records created at the generation stage.

§ iv

California Requires Clinical AI Bias Disclosure and Periodic Monitoring by Healthcare Facilities

On 30 September 2026, California Governor Gavin Newsom signed SB 503, Health care services: artificial intelligence, placing duties on developers of clinical decision support systems and the healthcare facilities that use them to identify, disclose, monitor and mitigate bias risks.

The law has been signed and takes effect on 1 January 2027 under California’s ordinary legislative effective-date rule. It covers AI systems assisting decisions about the timing of care, diagnosis or treatment. A “bias impact” means an adverse effect on access to care, quality or outcomes based on protected characteristics. Developers must reasonably identify and mitigate relevant risks and provide deploying facilities with information on intended use, an overview of training data, evaluation methods, bias risks and monitoring recommendations, upon request or at initial sale, whichever comes first, with applicable updates after material changes. Healthcare facilities must monitor periodically and take reasonable, proportionate mitigation measures. The enacted text sets no uniform monitoring frequency and does not require all technical materials to be disclosed to patients.

When procuring a diagnostic support system, a hospital can compare the supplier’s information about training populations, performance limits and bias evaluation with its own patient population and intended use. A system may have acceptable overall accuracy but repeatedly miss cases in a particular patient group; acceptance and operational monitoring should identify the disparity and examine whether input quality, model version or use conditions contribute. Procurement acceptance should verify both that the supplied information supports local evaluation and who can pause use, adjust workflows and drive remediation when anomalies arise. Contracts can address delivery of materials after material updates, investigation of affected cases, retesting and allocation of corrective work. Operational records can link necessary model versions, outputs, human actions and later outcomes, subject to access and retention limits for patient information. These are implementation recommendations based on disclosure and periodic monitoring duties. Specific metrics, thresholds and record periods depend on clinical use; a supplier’s claim that it “passed bias testing” does not replace a facility’s own monitoring.

California’s earlier AB 3030 has, since 1 January 2025, required notices and a channel to contact a human for covered generative AI patient communications, with an exception for communications reviewed and approved by licensed healthcare professionals. SB 503 addresses a different issue: delivery of bias information about clinical decision systems and monitoring after deployment. The UK Medicines and Healthcare products Regulatory Agency (MHRA) has implemented new post-market surveillance requirements for medical devices since 16 June 2025, requiring covered manufacturers to track safety and performance proactively. These approaches emphasise, respectively, clinical AI developers’ and healthcare facilities’ responsibility for bias and device manufacturers’ product monitoring duties; their scope and regulated parties differ. Cross-market teams can reuse performance and anomaly investigation materials while checking local responsibility allocations. California’s next practical questions concern what counts as reasonable monitoring and proportionate mitigation, and whether information after material updates enables facilities to reassess the system.

§ v

Bank of England Governor Calls for Continued AI Testing and Effective Intervention

On 30 September 2026, Bank of England (BoE) Governor Andrew Bailey published “Frontier AI and the question of governance”, arguing for testing before and after deployment and the capacity for effective intervention to address frontier models’ implications for financial stability and cybersecurity.

This is a policy commentary, not a new regulatory rule, mandatory testing standard or common shutdown requirement. Bailey argues that policymakers should first identify the risk to be addressed before designing regulatory architecture. Rigorous testing should continue before and after deployment, with lessons from incidents and near misses informing vulnerability detection, scrutiny of safeguards and better deployment standards. He specifically discusses payment networks, financial market infrastructures and banks, and applications in cyber defence, agentic trading and payments. The article stresses that testing cannot eliminate every failure or substitute for future regulation. Its central proposal is to retain the ability to set and revise operating boundaries and intervene effectively; it does not specify who would intervene, what would trigger action or what technical mechanism to use.

For a bank deploying an agent that can generate and submit payment instructions, acceptance testing can separately assess task completion under normal conditions and timely intervention when something goes wrong. In a simulated environment, teams can introduce duplicate payments, incorrect recipients and amounts above authorised limits, then check whether the business interface blocks the instructions and the responsible person can stop subsequent tasks. Intervention tests should verify where an instruction actually stops, not merely whether the interface displays “paused.” Instructions not yet submitted, queued and already completed require distinct controls for blocking, human checks and follow-up. After launch, teams can review unauthorised attempts intercepted by rules, even where no loss occurred, and use them to update tests. Changes to the model, tools or permissions should prompt retesting of relevant controls. Procurement contracts can address version-change notices, investigation materials and cooperation with shutdowns; operational records can connect model versions, task authorisation, tool calls and human actions. These are deployment recommendations informed by the article. It prescribes no uniform test frequency, log period or transaction reversal process.

In a “Growth and regulation” speech on 14 July 2026, Bailey had called for internationally coordinated testing of frontier models before widespread release and extending tests to critical national infrastructure. His latest article further emphasises learning after deployment and the ability to intervene. Article 55 of the EU Artificial Intelligence Act (AI Act), by contrast, imposes duties concerning model evaluation, risk mitigation, serious incident reporting and cybersecurity on providers of general-purpose AI models with systemic risk; applicability must also account for when a model was placed on the market and transitional provisions. Bailey’s article sets out a governance position, while the EU provisions are legal duties; it does not imply an absence of existing regulation in UK finance. Cross-border teams can reuse testing and incident review materials while separately checking their responsibilities as model providers or financial institutions. The next issue is whether the UK translates these proposals into specific deployment standards, supervisory requirements or intervention arrangements.

← Back to AI Governance Weekly

Cite as · AI Governance Weekly · 6 October 2026

§ Recent signalsBack to Governance Weekly→
05 Oct 2026China issues three large-scale model standards, EMEAP flags shared AI dependencies in finance, and Korea opens a UK data protection review.29 Sep 2026The EU adopts data centre ratings, the UK sizes up agentic cyber defence, and the FTC examines platform ad optimisation.28 Sep 2026China publishes on-device AI filings, Korea expands data innovation zones and debates agent privacy, and Japan studies consumer remedies.22 Sep 2026UK lawmakers call for dedicated AI legislation, the EU moves to limit AI companions for children, and California enacts synthetic-performer disclosure.21 Sep 2026China issues AI Safety Governance Framework 3.0 and four security guidelines, consults on secure agent development, and Hong Kong pilots procurement declarations.

One quarterly digest, no weekly drip.

If you want both columns delivered together, four times a year, in one quiet email — leave an address. Otherwise just bookmark this page.