◆ AI & Medical AI Daily
–
Wednesday · Regulation & Policy

Transparency is flowing backwards: Washington moves to delete AI model cards, Brussels pushes device AI to 2028, and the FDA's only move this week was to quietly refresh a list that carries no legal force

There was no federal press release about an AI medical device this week. The five announcements the FDA newsroom put out on Sept 3 and Sept 4 covered newborn starter nutrition, an accelerated breast-cancer approval, a first drug for Alexander disease and an emergency authorization for New World screwworm in dogs and cats — not one of them about software (FDA Press Announcements). The only move happened where no press release goes: on Sept 4, CDRH refreshed three lists on the same day, one of them "Artificial Intelligence-Enabled Medical Devices" (CDRH New). Set that small act against a longer timeline and an uncomfortable shape appears: the list keeps growing while the rules keep shrinking. The HTI-5 proposal would strike 34 of 60 certification criteria, among them the AI "model card" disclosure duty created only in 2023; the EU's Regulation (EU) 2026/1744 took force on July 27 and pushed high-risk obligations for device-embedded AI out to Aug 2, 2028. Meanwhile the states are stacking in the opposite direction: 84 AI laws in 27 states in the first half of 2026 alone (Transparency Coalition).

01 — Top Stories

Seven items, ordered by who is adding duties and who is removing them
Only move this week FDA CDRHAI-Enabled Device List9/04

The FDA refreshed its AI device list on Sept 4 — it carries no legal force, and it is the only counter still ticking

What

On September 4 the FDA's Center for Devices and Radiological Health refreshed three public lists on the same day: "Artificial Intelligence-Enabled Medical Devices," "Augmented Reality and Virtual Reality in Medical Devices," and "Medical Devices that Incorporate Sensor-based Digital Health Technology" (CDRH New — News and Updates). The AI device list page carries a last-modified stamp of 2026-09-04. For scale: MedTech Dive's tracking database, built on the FDA's March 4, 2026 data refresh, counts more than 1,400 AI-enabled devices authorized since 1995, of which 331 came in 2025 alone — the most in the agency's history.

Why it matters

In a week with no new rule and no press release, a list update is the only public signal that review is still running. Since this year's senior departures, the open question has been whether the agency's AI strategy has slowed (MedTech Dive, 2026-07-29). The cadence of the list answers half of it: the authorization end is still turning. It cannot answer the other half — what a user gets to know about these devices once they are cleared. That half is being shrunk in item 02 below.

Discount this

The FDA says on the page itself that the list "is not a comprehensive resource of AI-enabled medical devices," and that entries are identified mainly by AI-related terms appearing in summary descriptions. The total is a floor, not a picture. The figures "more than 1,400" and "331 in 2025" come from MedTech Dive's secondary tally, downloaded 2026-05-11 over data current to 2025-12-30; we could not obtain a post-Sept 4 total.

Subtracting duties ASTP/ONCHTI-5§170.315(b)(11)

HTI-5: strike 34 of 60 certification criteria, and delete the AI "model card" on the way

What

HTI-5 — formally "Health Data, Technology, and Interoperability: ASTP/ONC Deregulatory Actions To Unleash Prosperity" — was published in the Federal Register on December 29, 2025, proposing to remove 34 of 60 certification criteria and revise seven more. ONC's own summary states plainly that one revision would "reduce the scope of the decision support interventions (DSI) certification criterion to fully remove the artificial intelligence 'model card' requirements" (healthit.gov, HTI-5 Fact Sheet). Since 2023 those model cards have required vendors to disclose training-data provenance, maintenance practice and bias-mitigation measures.

The stated reason

The stated reason is an evidentiary one: "We have no publicly available evidence that transparency requirements… have led to positive impacts on patient care" (Healthcare Dive, 2025-12-23). The same proposal redefines "access" and "use" under the information blocking rule so that autonomous AI systems may retrieve and exchange health data on a user's behalf, and removes or revises several blocking exceptions (Fierce Healthcare, 2025-12-22). Read together the direction is unambiguous: make it easier for AI to reach the data, and no longer require it to say how it was trained.

Discount this

This is still a proposal. The comment period ran 60 days from publication, and as of filing we found no final rule, so the model card duty remains legally in force for now. Vendor reaction skews supportive: Oracle Health said it is "highly encouraged that ASTP/ONC is recognizing the need for regulatory burden reduction" (same Fierce Healthcare report).

Deferring duties European UnionAI Act2026/1744

The EU's delay is now law: high-risk duties for device AI land on Aug 2, 2028 — eight months after standalone systems

What

The Digital Omnibus on AI has completed its passage: Regulation (EU) 2026/1744 was published in the Official Journal on July 24, 2026 and entered into force on July 27. The new timetable moves Annex III standalone high-risk systems to December 2, 2027, and Annex I Section A — products already covered by EU harmonisation legislation, medical devices among them — to August 2, 2028. Device AI sits in the second bucket.

Why it matters

This is no longer a proposed delay but enacted text — the argument over when the AI Act actually bites now has an answer. The clause worth watching is equivalence: the text allows relief where the Medical Device Regulation (EU) 2017/745 already provides comparable protection, but that relief depends on delegated acts the Commission must adopt by August 2, 2027. Which means the real scope of a device manufacturer's obligations currently hangs on a delegated act nobody has written yet.

Discount this

The dates and structure come from a legal-tech blog's reading of the Official Journal text; we did not verify article by article against EUR-Lex. Note also that what is deferred is Chapter III, Sections 1–3 — not the whole Act; earlier provisions such as the Article 50 transparency duties still run on their original schedule.

Window closing FDADocket FDA-2026-N-787410/19

How to review generative AI devices: 40 days left on the docket — and it is "explicitly not" draft guidance

What

The Digital Health Center of Excellence's discussion paper "Considerations for the Regulation of Generative AI-Enabled Medical Devices" was posted on August 19, 2026 under docket FDA-2026-N-7874, with comments due October 19, 2026. It covers risk assessment, premarket evaluation and postmarket monitoring, posing questions under each; respondents need not answer them all. The FDA states in the document that it is "intended for discussion purposes only," is neither draft nor final guidance, and does not convey CDRH's final regulatory expectations (FDA press release).

Why it matters

Law-firm readings go further than the FDA's own wording: Arnold & Porter's September 1 digest describes it as proposing a "competency-based" evaluation framework combining benchmarking with clinical confirmation (Arnold & Porter, Virtual & Digital Health Digest, 2026-09-01). The gap between the two readings is itself the signal: industry is already preparing against a "discussion only" paper as though it were the future standard — which is exactly why the final 40 days of the docket are worth a filing.

Adding duties Connecticut SB 5New York10/01

The state clock: on October 1, two chatbot statutes take effect the same day in Connecticut and New York

What

By the Transparency Coalition's tally, Connecticut's SB 5 and New York's Safe By Design Act both take effect on October 1, 2026: the first a 74-page omnibus covering chatbots, minor protections, parental controls and employment decisions; the second requiring default child-safety settings, parental controls, and AI chatbots switched off by default for minors (Transparency Coalition, 2026-07-22). The same tally lists 14 chatbot safety laws passed in 2026, of which six — Georgia SB 540, Hawaii SB 3001, Nebraska LB 525, Oregon SB 1546, Rhode Island S 2195/H 7350 and Washington HB 2225 — explicitly require protocols for expressions of suicidal ideation or self-harm.

Why it matters

This is the cleanest contrast in the issue. The federal layer is proposing to delete AI provenance disclosure; the state layer passed 84 AI laws across 27 states in the first half of 2026, beating 2025's full-year total of 73 (Transparency Coalition mid-year report, 2026-07-21). The health and mental-health category includes limits on AI in insurance authorization decisions, mandatory review by a licensed professional, and outright bans on AI therapy chatbots. For any digital health product operating across state lines, the compliance centre of gravity is moving from Washington to statehouses.

Discount this

The source is an advocacy group's legislative tracker, not statutory text; verify effective dates and bill numbers against each state's official version. New York S 9051 was still marked "awaiting signature" in that tally and its status may since have changed.

Legislation Senate HELPS. 309722–0

S. 3097 would push HIPAA-grade privacy standards onto the wearables and apps HIPAA never covered

What

The Senate HELP Committee approved the Health Information Privacy Reform Act (S. 3097) 22–0 on July 30, 2026, reporting it out on August 4. The bill directs the HHS Secretary, in consultation with the FTC, to set privacy, security and breach-notification standards "at least commensurate with the existing HIPAA privacy, security, and breach notification rules," over a scope defined as "identifiable data about a person's physical or mental health, their care, or payment for that care, including data never created or received by a provider, health plan, employer, or clearinghouse" — with fitness trackers and health apps named explicitly (Paubox).

Why it matters

This line runs opposite to HTI-5: one strips provenance disclosure from the model, the other extends protection to data HIPAA cannot reach. If both land, the result is data that is protected while the models trained on it need not explain themselves — a combination that matters a great deal for whether medical AI can be audited at all. A unanimous committee vote also says the direction is not especially contested between the parties.

Discount this

The bill is at a very early procedural stage: it still needs floor time in both chambers, and most bills reported out of committee never get a floor vote. The vote count and report date here come from secondary coverage.

Drawing the line MHRAAmbient Voice Technology7/29

The UK cuts AI scribes in half: transcribe and summarise is not a device, "orders without clinician review" is

What

On July 29, 2026 the MHRA set out the regulatory status of ambient voice technology — AI scribes. A product intended only to transcribe clinical conversations, summarise them, draft letters or suggest clinical codes for a clinician to review is not a medical device; device status triggers once the product is designed to support diagnosis, treatment or prevention, or to take automated action such as placing an order without clinician review. MHRA chief executive Lawrence Tallon said the guidance "sets out which functions of ambient voice technologies are deemed medical devices and which are not in order to remove ambiguity" (GOV.UK, 2026-07-29).

Why it matters

This is the most operationally useful line drawn anywhere this quarter: it hangs device status on whether a human reviews the output, not on how large or advanced the model is. For vendors extending scribe products toward "and it places the orders for you," it marks the exact point at which adding that feature moves the product into a different regulatory world. The guidance applies immediately, with no grace period, and the MHRA restates that clinicians remain responsible for reviewing all AI-generated output regardless of classification. Separately, a UK government call for evidence on how data and AI regulation interact closes today, September 9 (Arnold & Porter digest).

02 — Product Analysis

Two things that have already been through the regulatory door, demonstrating two answers to where an LLM may sit

UpDoc(K253281)

Prescription software · insulin management in adults with type 2 diabetes · United States

Function and position. Patients report glucose, symptoms and adherence by voice or text; an LLM layer converts that dialogue into structured data, which feeds an insulin-dosing algorithm bounded by parameters the prescribing clinician sets. Innolitics compiled the regulatory detail from FDA's database: 510(k) pathway (not De Novo), Class II, product code NDC (calculator, drug dose), regulation 21 CFR 868.1890, received 2025-09-29, decision 2025-12-23 (Innolitics).

  • Strength : the architecture is itself the regulatory argument — "conversation on the outside, structured data in the middle, and protocolized clinical decision support on the inside." The LLM is confined to parsing input while deterministic logic decides the dose, which is what let this clear as a 510(k) rather than a De Novo (Innolitics' regulatory breakdown).
  • Strength : the FDA locked the core through a Post-Clearance Change Plan — the decision summary requires that "PCCP changes must preserve deterministic insulin dosing logic and core clinical decision-making," meaning the conversational surface may be revised and the clinical algorithm may not. That gives "the model will be updated" an auditable boundary.
  • Concern : whether this path generalises depends on whether the underlying problem already has a deterministic protocol. Insulin dosing does; differential diagnosis, image interpretation and treatment selection mostly do not. Wrapping an LLM around an existing protocol is clever design, but it also shows that the FDA has not opened a path for a model to make the clinical call itself.
  • Concern : our sources disagree on the date. Innolitics records 2025-12-23 from the FDA database; Manatt's health AI policy tracker places it in late June 2026 and describes it as the first patient-facing large language model SaMD clearance (Manatt Health AI Policy Tracker). We use the former because it carries a K-number, and flag the discrepancy in the editor's note.

Ambient Voice Technology

AI scribes · already deployed at NHS scale · line drawn in the UK

Function and position. It listens in the background of a consultation and produces the note, the referral letter and suggested codes. It is the fastest-deploying category of medical AI precisely because it touches neither diagnosis nor management — it only removes the typing. The MHRA's July 29 guidance draws a precise boundary around exactly that assumption (GOV.UK).

  • Strength : regulatory clarity is itself a commercial advantage. In the UK a product that only transcribes, summarises, drafts and suggests codes for human review is explicitly outside device scope, which removes the cost and calendar of conformity assessment — certainty the same products do not yet have in other jurisdictions (MHRA statement).
  • Concern : the price of the exemption is that the roadmap is pinned by the rule. Every vendor wants to move from writing the note to ordering the test, prescribing the drug and sending the referral, because that is where retention and pricing live; but the MHRA says device status triggers the moment the product acts without clinician review. The feature everyone most wants to add is exactly the one that crosses the line.
  • Concern : not-a-device does not mean not-a-risk. The guidance pushes verification duty entirely back onto clinicians — whatever the classification, the clinician must review and confirm every AI-generated output. When one doctor is reviewing dozens of auto-generated notes a day, that allocation is clean on paper; whether it holds in clinic is a question no published audit data currently answers.

03 — Companies & Competition

Who stands where, on what, against whom
Company Recent state & numbers Position & moat
Oracle Health
EHR incumbent, AI-native record
Publicly backed HTI-5's deregulatory direction, calling it "a major step forward" and saying it is "highly encouraged that ASTP/ONC is recognizing the need for regulatory burden reduction" (Fierce Healthcare, 2025-12-22). The moat is installed base plus certification standing. If the model card duty is struck, the disclosure asymmetry between AI built into the record and AI bolted onto it widens in favour of whoever is already inside. The weakness: that moat rests on a proposal that has not been finalised.
UpDoc
Patient-facing LLM prescription software
K253281 — Class II, 510(k), product code NDC, 21 CFR 868.1890, FDA decision 2025-12-23, with a Post-Clearance Change Plan attached (Innolitics). The moat is the clearance already in hand and the architecture it demonstrates, not the model. Any competitor can copy "conversation outside, determinism inside"; the first mover's advantage is a PCCP the FDA has already accepted, on which further changes can be stacked.
Dexcom / Cadence
Participants in FDA's TEMPO digital health pilot
Dexcom announced participation in the regulatory sprint pilot on 2026-07-22; Cadence, an AI-enabled hypertension management company, became TEMPO's second participant on 2026-08-17. The pilot exempts selected devices from certain premarket requirements in exchange for collecting real-world Medicare data (MedTech Dive; Manatt). The moat is a seat on the list: pilot slots are scarce and come attached to Medicare data linkage. The competition is not similar products but everyone else trying to get onto the same fast lane. The risk is that premarket relief is paid for with a heavier postmarket evidentiary burden.
Ever Fortune.AI
Taiwanese medical AI vendor
Received two new TFDA licences on 2025-12-22: an auto-contouring system for radiotherapy covering 182 organs at risk across head and neck, thorax, abdomen and pelvis, and a computer-aided detection platform for brain dopamine transporter SPECT. The company reports 53 device licences worldwide, including 13 from the US FDA and 22 from Taiwan's TFDA (Biotech-edu, 2025-12-23). The moat is a stack of licences on both tracks: holding both FDA and TFDA clearances means having a track record inside two review logics at once. The weakness is that these figures stop at end-2025, and licence counts are not installations or revenue — neither of which is visible in public sources.

Today's competitive structure is about who can turn uncertainty into somebody else's cost. Oracle is betting there will be fewer rules, UpDoc that architecture can route around them, Dexcom and Cadence that an early pilot seat buys time, Ever Fortune.AI that holding both sets of licences pays. Not one of these is a bet that the product is better — they are all bets on which way the rules fall. Which is why the payment side belongs in the same frame: the RAPID coverage pathway CMS and FDA announced on April 23, 2026 has CMS issue a proposed national coverage determination the same day the FDA authorizes an eligible device; after a 30-day comment period, predictable national Medicare coverage can arrive roughly two months after market authorization, against about a year today. Compress the gap between clearance and payment and you compress the payback period on a regulatory bet.

04 — Taiwan Angle

Taiwan took a third path: pass the framework law first, then wait for the sub-regulations to grow teeth

(1) Taiwan already has an AI framework act, but it states principles rather than duties. The Legislative Yuan passed the AI Basic Act on third reading on December 23, 2025, naming the National Science and Technology Council as the central competent authority with local governments as local authorities. The act requires the government to avoid AI applications that harm citizens' life, body, freedom or property, or create risks to social order, national security or the environment, and directs the Executive Yuan to convene a national AI strategy committee (CNA, 2025-12-23). The Ministry of Digital Affairs lists seven governance principles: sustainable development and wellbeing, human autonomy, privacy protection and data governance, security and safety, transparency and explainability, fairness and non-discrimination, and accountability (moda press release). Set against the other jurisdictions in this issue — the US deleting a specific disclosure duty, the EU deferring the application date of specific duties — Taiwan's position is that it has no specific duties yet to delete or defer.

(2) The gap in scale matters more than the gap in rules. SGS Taiwan's summary of the TFDA list of approved AI/ML medical devices counts 104 items — 37 domestic, 67 imported — from an announcement dated January 22, 2024 (SGS Taiwan). Against the FDA side's cumulative total of more than 1,400 since 1995 and 331 in 2025 alone (MedTech Dive), that is more than one order of magnitude. The practical consequence: Taiwan's review volume is not yet large enough to accumulate its own working standard for what counts as sufficient evidence, so domestic sponsors writing submissions are still, in substance, calibrating against FDA expectations. The TFDA's smart medical device project office and its AI/ML device information and matchmaking platform are the official attempt to close that gap (Ministry of Health and Welfare).

(3) For exporters there are two actionable signals this issue — one loosening, one tightening. The loosening is European: high-risk obligations for device-embedded AI land on August 2, 2028, eight months later than the December 2, 2027 date for standalone high-risk systems, which buys Taiwanese device makers shipping to Europe a longer runway. Do not read it as an exemption: what is actually in scope depends on how the Commission writes the delegated acts due by August 2, 2027 (Regulation (EU) 2026/1744). The tightening is British: the MHRA's line on ambient voice technology applies immediately with no grace period, so any Taiwanese scribe or documentation product aiming at the NHS must first self-assess whether its features cross the "acts without clinician review" boundary (MHRA).

05 — Further Reading

Five pieces that join today's fragments into a line, ordered by what you can do after reading
  1. Health Data, Technology, and Interoperability: ASTP/ONC Deregulatory Actions To Unleash Prosperity — Federal Register (2025-12-29)

    If you read only one primary document, read this one. Secondary coverage tells you 34 criteria were cut; the text tells you what "access" and "use" are redefined to mean under the information blocking rule afterwards — which is the passage that decides whether an autonomous AI agent may lawfully pull a record.

  2. First FDA-Cleared AI Agent and LLM Enabled Device Confirmed — Innolitics

    Its value is not the news but that it lays out the K-number, product code, regulation citation and PCCP conditions in full. Anyone drafting a submission strategy for an LLM-enabled device will come away knowing what "keep the model outside the deterministic core" actually looks like on paper.

  3. TCAI Mid-Year AI Legislation Report: 84 new AI laws enacted in 27 states so far in 2026 — Transparency Coalition (2026-07-21)

    Use it to recalibrate the assumption that state law is noise. It sorts by theme — chatbots, education, health and mental health, consumer rights, frontier model oversight — so you can see at a glance which category has grown dense enough to constitute a real multistate compliance cost.

  4. Virtual & Digital Health Digest — Arnold & Porter (2026-09-01)

    The single widest-scope source behind this issue: US, EU and UK regulatory, enforcement and legislative items sorted by date. The UK section is the one to read — three MHRA outputs (ambient voice, digital mental health, AI Airlock Phase 2 case studies) landed in the same month, denser than any other regulator's output.

  5. EMA and FDA set common principles for AI in medicine development — European Medicines Agency (2026-01-14)

    While transatlantic device regulation diverges, the medicines side is converging: EMA and FDA jointly set out ten guiding principles for good AI practice in drug development. Read in today's context it shows what two regulators do when they actually intend to align — and by contrast, why the device side has not.

06 — References

References
  1. CDRH New — News and Updates. U.S. Food and Drug Administration, 2026-09-04. fda.gov
  2. Artificial Intelligence-Enabled Medical Devices. U.S. Food and Drug Administration, last modified 2026-09-04. fda.gov
  3. Press Announcements(2026-09-03/2026-09-04 條目). U.S. Food and Drug Administration. fda.gov
  4. AI in medtech is booming. Track new devices here. MedTech Dive. medtechdive.com
  5. MedTech Policy and Regulation(含 2026-07-29、2026-08-17、2026-08-19 等條目). MedTech Dive. medtechdive.com
  6. Health Data, Technology, and Interoperability: ASTP/ONC Deregulatory Actions To Unleash Prosperity. Federal Register, 2025-12-29. federalregister.gov
  7. HTI-5 Proposed Rule Fact Sheet. ASTP/ONC, healthit.gov, 2025-12-22. healthit.gov
  8. Trump administration nixes Biden-era health IT policies, including AI 'model cards'. Healthcare Dive, 2025-12-23. healthcaredive.com
  9. HHS' tech office proposes to gut and reset health IT policy. Fierce Healthcare, 2025-12-22. fiercehealthcare.com
  10. Digital Omnibus on AI: Regulation (EU) 2026/1744 Is Published in the Official Journal. NicFab Blog, 2026. nicfab.eu
  11. Considerations for the Regulation of Generative AI-Enabled Medical Devices: Discussion Paper and Request for Feedback(Docket FDA-2026-N-7874). FDA Digital Health Center of Excellence, 2026-08-19. fda.gov
  12. FDA Seeks Public Feedback to Inform Regulatory Approach for Generative AI-Enabled Medical Devices. U.S. Food and Drug Administration, 2026-08. fda.gov
  13. Watershed year for chatbot safety: 14 new state laws passed so far in 2026. Transparency Coalition, 2026-07-22. transparencycoalition.ai
  14. TCAI Mid-Year AI Legislation Report: 84 new AI laws enacted in 27 states so far in 2026. Transparency Coalition, 2026-07-21. transparencycoalition.ai
  15. Text — S.3097, Health Information Privacy Reform Act. Congress.gov, 119th Congress. congress.gov
  16. Senate committee advances privacy bill for non-HIPAA health data. Paubox, 2026-08. paubox.com
  17. MHRA clarifies regulatory status of ambient voice technologies used in the NHS. GOV.UK, 2026-07-29. gov.uk
  18. Virtual & Digital Health Digest. Arnold & Porter, 2026-09-01. arnoldporter.com
  19. First FDA-Cleared AI Agent and LLM Enabled Device Confirmed(UpDoc, K253281). Innolitics. innolitics.com
  20. Manatt Health: Health AI Policy Tracker. Manatt, Phelps & Phillips, 2026-07-30. manatt.com
  21. CMS and FDA Announce RAPID Coverage Pathway to Accelerate Patient Access to Life-Changing Medical Devices. Centers for Medicare & Medicaid Services, 2026-04-23. cms.gov
  22. Holland & Knight Health Dose: September 1, 2026. Holland & Knight, 2026-09-01. hklaw.com
  23. 立院三讀人工智慧基本法 國科會為主管機關. 中央社 CNA, 2025-12-23. cna.com.tw
  24. 立法院三讀通過《人工智慧基本法》 構築我國AI創新與安全治理基石. 數位發展部 moda, 2025-12-24(2026-03-19 更新). moda.gov.tw
  25. TFDA 最新公告:核准應用 AI/ML 技術之醫療器材清單. SGS 台灣, 2024-03-26(公告日 2024-01-22). sgs.com.tw
  26. 食品藥物管理署智慧醫療器材專案辦公室成立. 衛生福利部. mohw.gov.tw
  27. 長佳智能雙AI醫材獲TFDA核准. 台灣光鹽生物科技學苑, 2025-12-23. biotech-edu.com
  28. EMA and FDA set common principles for AI in medicine development. European Medicines Agency, 2026-01-14. ema.europa.eu
Editor's note: (1) There was little federal news on this theme this week — the FDA newsroom issued nothing on AI or software between Sept 2 and Sept 9, and the only AI-device action inside the window was the Sept 4 list refresh. Rather than pad, this issue fills out with important background from the past six weeks, each item explicitly dated; nothing old is written up as though it happened this week. (2) Sources disagree on UpDoc's clearance date: Innolitics records a 2025-12-23 decision from the FDA database, with K253281; Manatt's tracker places it in late June 2026. We use the source carrying a K-number; verify against the FDA 510(k) database before citing. (3) The FDA totals "more than 1,400" and "331 in 2025" are MedTech Dive's secondary tally, downloaded 2026-05-11 over data current to 2025-12-30 — not post-Sept 4 figures; the FDA also states the list is not comprehensive. (4) No final HTI-5 rule was found as of filing; everything described on that rule remains at proposal stage. (5) The dates and structure of Regulation (EU) 2026/1744 come from a legal-tech blog's reading of the Official Journal text, not an article-by-article check against EUR-Lex. (6) State effective dates and bill numbers come from the Transparency Coalition's legislative tracker, an advocacy group's compilation rather than statutory text. (7) The 104-device TFDA AI/ML list figure is from a January 2024 announcement and is very likely out of date; we could not obtain a newer version. (8) Holland & Knight's Sept 1 digest refers to "a major electronic health record company" launching AI features in August without naming it, so we did not supply a name in the company table. (9) No paywalled content was used in this issue.