August 2026 was a quieter month for Canadian AI regulatory activity, but the United States and the European Union both produced developments with direct implications for AI in healthcare. In the US, the FDA opened a public comment process on how it might regulate generative AI-enabled medical devices, including tools built on foundation models and agentic AI; HHS’s Office of Research Integrity issued guidance clarifying how institutions should handle generative AI use in research misconduct investigations; and the American Hospital Association pushed back on claims that AI documentation and coding tools are driving inappropriate increases in Medicare coding intensity. In the EU, transparency and disclosure obligations under the AI Act took effect on August 2 and moved directly into enforcement, introducing new requirements for AI-generated content labelling and AI-interaction disclosure that reach patient-facing chatbots, AI agents, and generative health communications.
Disclaimer: This article is produced for educational and informational purposes only. It summarises publicly available regulatory updates and reflects our interpretation of emerging developments; it does not constitute legal, regulatory, financial, or professional advice, nor should it be interpreted as a statement of regulatory intent. Readers should consult qualified counsel before taking any action based on the information presented here.
US
1) FDA Opens Public Comment on Regulatory Approach for Generative AI-Enabled Medical Devices (August 18, 2026)
The FDA’s Digital Health Center of Excellence (DHCoE), within the Center for Devices and Radiological Health, published a discussion paper outlining potential approaches to regulating generative AI (GenAI)-enabled medical devices, including devices built on foundation models and agentic AI systems. The paper proposes a two-axis framework for assessing device risk; a “competency assessment” model for premarket evaluation that draws a loose analogy to how physicians are trained and evaluated, combining non-clinical device benchmarking with clinical confirmation testing; and several possible approaches to risk-proportionate postmarket monitoring. Rather than issuing binding rules, the FDA poses targeted questions in each of these areas and is inviting feedback from device manufacturers, clinicians, researchers, and the public before shaping a formal regulatory framework.
Comments can be submitted under docket FDA-2026-N-7874 through October 19, 2026.
How it applies to AI in Healthcare:
This is the clearest signal yet of how the FDA may eventually treat foundation-model-based and agentic health AI tools differently from traditional software-as-a-medical-device. Organizations developing or deploying GenAI-enabled clinical tools – including diagnostic support, documentation, and triage systems – have a direct opportunity to shape the eventual framework by submitting comments before the October 19 deadline. Founders working toward FDA clearance should start mapping their device against the proposed two-axis risk model now, since it may foreshadow how premarket submissions for GenAI devices are scoped going forward.
2) HHS Office of Research Integrity Issues Guidance on Generative AI in Research Misconduct Proceedings (August 14, 2026)
ORI released new guidance under the updated Public Health Service Policies on Research Misconduct regulation (42 CFR Part 93) addressing how institutions should handle generative AI use when investigating allegations of research misconduct. The guidance is non-binding but clarifies several points institutions have raised since the regulation was revised in September 2024.
Evidentiary Standards
-
AI detectors alone are not sufficient evidence. ORI recommends against relying solely on the output of automated plagiarism- or manipulation-detection tools as evidence of misconduct, noting these tools may have limited ability to detect plagiarism within AI-generated text.
-
Institutional expertise still governs the standard. A misconduct finding requires a significant departure from the accepted practices of the relevant research community, and institutions – not ORI – determine whether a given use of generative AI meets that bar. Investigation committees must include subject-matter experts in the respondent’s field, and ORI suggests institutions consider adding AI subject-matter expertise as well.
Disclosure and Fabrication
-
Disclosure is protective but not a shield. Researchers should disclose which generative AI tools were used during research, manuscript, and grant preparation. Disclosure can support a defense against misconduct allegations and aid reproducibility, but a disclosed use that departs from community norms can still be found to be misconduct – and undisclosed or inaccurately described AI-assisted data processing may itself be evidence of fabrication or falsification.
-
Hallucinated citations are treated narrowly. Because fabrication findings require the fabricated material to be “data or results,” AI-generated citations that don’t reflect real publications generally won’t, on their own, support a fabrication finding – except in contexts like literature reviews, where the references themselves function as the data.
-
Honest error remains an available defense. AI-driven processes researchers may not directly control – such as a smartphone’s automatic image processing – can factor into an honest-error defense, though the burden of proving honest error sits with the respondent.
ORI Generative AI Guidance Document (PDF)
How it applies to AI in Healthcare:
Any PHS-funded biomedical or behavioral research program using generative AI – for drafting, data processing, literature review, or image analysis – should treat disclosure as standard practice rather than an afterthought. Compliance teams supporting research institutions should evaluate whether their existing research integrity policies address generative AI use, and whether investigation committees are equipped to bring in AI subject-matter expertise when needed.
3) AHA Releases Fact Sheet Countering Claims That AI Drives Improper Medicare Coding Intensity (August 27, 2026)
The American Hospital Association published a fact sheet responding to claims from some commercial insurers that AI documentation and coding tools are inappropriately increasing Medicare coding intensity and associated healthcare costs. The AHA argues that AI tools – including AI scribes – reduce documentation time, improve coding accuracy, expand appointment capacity, and improve staff and patient satisfaction, while providers remain legally, ethically, and contractually obligated to code appropriately regardless of which tools they use.
The fact sheet attributes rising coding intensity primarily to non-AI factors: an aging, higher-acuity patient population (the AHA cites a roughly 5% rise in hospital case-mix index from 2019 to 2024), the continued shift of lower-acuity care into outpatient settings, and periodic updates to coding guidelines and diagnostic code sets. It also points to a body of MedPAC, Department of Justice, and state-level findings involving insurer-side upcoding – including a MedPAC estimate that upcoding contributed to $40 billion in Medicare Advantage overpayments in 2025 – arguing that scrutiny of coding intensity has so far been directed disproportionately at providers rather than payers.
AHA Fact Sheet: Artificial Intelligence and Coding Intensity
How it applies to AI in Healthcare:
This isn’t a regulatory action – it’s an industry association’s advocacy position – but it’s a useful marker of where the billing-AI compliance conversation is heading. Vendors of AI scribe, coding, and documentation tools should expect continued scrutiny of AI’s role in coding intensity from payers, and hospitals deploying these tools should be prepared to show that human validation and existing coding-compliance programs remain in place alongside AI assistance, since using AI does not change a provider’s underlying coding obligations.
EU & UK
1) EU AI Act Transparency Obligations and GPAI Enforcement Take Effect (August 2, 2026)
New transparency obligations under the EU AI Act took effect on August 2, 2026, with enforcement beginning the same day. The rules introduce two categories of disclosure: first, that AI-generated or manipulated content – including deepfake images, audio, and video, as well as AI-generated text published to inform the public on matters of public interest without human review – must be clearly and visibly labelled using machine-readable marks, drawing on a set of standard icons the EU has published for this purpose; and second, that people must be clearly informed when they are interacting with an AI system rather than a person, covering chatbots, AI agents, and avatars. The Commission has also published guidelines and a code of practice to help providers and deployers demonstrate compliance.
Enforcement sits with national market surveillance authorities, the EU AI Office for systems under its supervision, and the European Data Protection Supervisor where EU institutions are the provider or deployer. Penalties can reach €15 million or 3% of global annual turnover for companies, and up to €750,000 for EU institutions, bodies, and agencies, with proportionality considerations built in for SMEs and small mid-cap companies.
European Commission News Announcement
How it applies to AI in Healthcare:
This is likely the most consequential health-AI-adjacent development of the month for any organization operating in or serving the EU market. Patient-facing chatbots, symptom checkers, AI agents used in care coordination, and any AI-generated content used in health communications or patient materials now need clear disclosure that a person is interacting with AI, and any AI-generated or manipulated media used in patient communications needs to carry a machine-readable label. Because enforcement began immediately on August 2, organizations that haven’t already reviewed their patient-facing AI touchpoints against these obligations should treat this as time-sensitive.
Cross-Cutting Themes
Disclaimer: The cross-cutting themes below are analytical observations based on the sources cited in this article and reflect our interpretation of emerging regulatory and policy developments. They do not constitute legal, regulatory, or professional advice, nor should they be interpreted as statements of regulatory intent. Readers may wish to consult qualified advisors regarding the application of any regulatory requirements to their specific circumstances.
- From point-of-entry to lifecycle oversight. Both the FDA’s discussion paper and the EU AI Act’s transparency enforcement extend regulatory attention beyond initial market authorization into how AI systems are monitored, disclosed, and used after deployment – postmarket monitoring for GenAI devices in the US, and ongoing AI-interaction and content-labelling obligations in the EU.
- Disclosure is becoming a default compliance behavior. ORI’s guidance on disclosing generative AI use in research, and the EU’s mandatory labelling of AI-generated content and AI-interaction disclosures, both point toward transparency about AI involvement becoming a baseline expectation rather than an optional best practice.
- Human validation remains the backstop, regardless of AI involvement. ORI’s guidance places the burden of verifying AI-assisted research outputs on researchers, and the AHA fact sheet stresses that AI-assisted coding does not relieve providers of their existing coding compliance obligations – a consistent message that AI tools do not shift accountability away from the humans using them.
- Foundation models and agentic AI are emerging as a distinct regulatory concern. The FDA discussion paper explicitly separates foundation models and agentic AI systems out for special consideration in its proposed framework, reflecting a broader recognition that these architectures carry different risk profiles than earlier generations of AI-enabled software.
Key Considerations for Regulatory Alignment
Disclaimer: This checklist is provided for general informational purposes only and does not constitute legal, regulatory, or professional advice; organizations should consult with their legal and compliance departments to ensure adherence to specific jurisdictional requirements.
For Founders & Business Owners
- Submit comments on the FDA’s discussion paper if relevant. Organizations developing generative AI-enabled medical devices – especially those using foundation models or agentic architectures – have until October 19, 2026 to weigh in on docket FDA-2026-N-7874 before the FDA’s approach solidifies further.
- Audit patient-facing AI touchpoints against EU AI Act transparency rules. Since enforcement began immediately on August 2, any chatbot, AI agent, or AI-generated content used in EU patient communications should already carry the required disclosures and machine-readable labelling.
- Set a disclosure norm for generative AI use in funded research. If your organization conducts or funds PHS-supported biomedical or behavioral research, build generative AI disclosure into manuscript and grant preparation workflows now, ahead of any misconduct inquiry.
- Be ready to substantiate coding-accuracy claims for AI documentation tools. With payers scrutinizing AI’s role in coding intensity, vendors and hospitals using AI scribes or coding assistants should be able to show that human coding review and compliance programs remain intact alongside AI use.
For Compliance & Regulatory Specialists
- Track FDA docket FDA-2026-N-7874 and prepare internal responses. Map your premarket evaluation approach against the FDA’s proposed two-axis risk model and competency-assessment concept ahead of the October 19, 2026 comment deadline.
- Update research misconduct policies and committee composition. Review whether your institution’s research misconduct procedures reflect ORI’s guidance on generative AI, including evidentiary standards for AI-detection tools and the inclusion of AI subject-matter expertise on investigation committees.
- Build or verify an AI-content labelling and disclosure workflow. Confirm your organization has a process for applying machine-readable marks to AI-generated or manipulated content and for disclosing AI interactions, consistent with the EU AI Act’s guidelines and code of practice.
- Monitor the AI-and-coding-intensity debate alongside parallel payer scrutiny. The AHA’s position sits against a backdrop of MedPAC, DOJ, and state-level upcoding findings on the payer side – expect this tension to shape how AI-assisted coding is audited going forward.
Sources
-
FDA Press Announcement: FDA Seeks Public Feedback to Inform Regulatory Approach for Generative AI-Enabled Medical Devices (Released: August 18, 2026)
https://www.fda.gov/news-events/press-announcements/fda-seeks-public-feedback-inform-regulatory-approach-generative-ai-enabled-medical-devices -
ORI Blog: ORI’s Guidance on Generative Artificial Intelligence Released (Released: August 14, 2026)
https://ori.hhs.gov/blog/oris-guidance-generative-artificial-intelligence-released -
ORI Generative Artificial Intelligence Guidance (PDF) (Released: August 2026)
https://ori.hhs.gov/sites/default/files/2026-08/ORI%20Generative%20Artificial%20Intelligence%20Guidance_final.pdf -
AHA News: Fact Sheet Details Why Use of AI Alleviates Burden for Providers and Does Not Improperly Increase Coding Intensity (Released: August 27, 2026)
https://www.aha.org/news/headline/2026-08-27-fact-sheet-details-why-use-ai-alleviates-burden-providers-and-does-not-improperly-increase-coding -
AHA Fact Sheet: Artificial Intelligence and Coding Intensity (Released: August 2026)
https://www.aha.org/fact-sheets/2026-07-31-fact-sheet-artificial-intelligence-and-coding-intensity -
European Commission News: Safer and More Transparent AI (Released: August 2, 2026)
https://commission.europa.eu/news-and-media/news/safer-and-more-transparent-ai-2026-08-02_en




















