GovernAtlas
Report library
Intelligence BriefingsGlobalWeekly

AI Vendor Risk Weekly

Cross-vertical signal report tracking material changes in security, privacy, and governance posture.

Published Jun 13, 2026Updated Jun 19, 2026Current edition

12

curated source records reviewed

11

vendors with material changes

4

high-severity changes

Executive summary

What changed

This edition reviews 12 manually curated public source records across 11 healthcare AI vendors. These records are not machine-detected changes or permanent compliance claims.

4 changes are marked high severity because they affect certifications, regulatory filings, subprocessors, incidents, or material disclosure language.

The most frequently represented framework in this edition is HIPAA. Buyers should review the source evidence and applicability to their own deployment before making a procurement decision.

Key findings

11 vendors show a recorded public posture change in this edition.
4 observations require elevated procurement review.
6 regulations or standards appear across the selected evidence.

Vendor change register

Observed evidence

Ordered by latest observed date

ObservedVendorChangeFrameworkSeveritySource
Jun 21, 2026AbridgeTrust Center UpdatedHIPAAmediumtrust.abridge.com
Jun 18, 2026SukiHIPAA Policy UpdatedHIPAAmediumprivacy policy
Jun 10, 2026NablaEU AI Act Filing PublishedEU AI ActhighEU transparency filing
Jun 9, 2026Nuance DAXFedRAMP Status UpdatedFedRAMPhighMicrosoft Trust Center
Jun 7, 2026DeepScribeONC HTI-1 Disclosure AddedONC HTI-1mediumcompliance disclosure
Jun 5, 2026AugmedixSubprocessor List ChangedHIPAAhighsubprocessor page
Jun 3, 2026Hippocratic AIDisclosure Language ChangedHIPAAhighAI safety disclosure
May 30, 2026AbridgeSecurity Documentation ModifiedHIPAAmediumsecurity page diff
May 30, 2026InfinitusCall Recording Policy UpdatedHIPAAmediumprivacy notice
May 28, 2026Viz.aiEU MDR Language ModifiedEU AI Actmediumregulatory page diff
May 26, 2026HyroUK GDPR Addendum PostedUK GDPRmediumdata processing addendum
May 24, 2026Ambience HealthcareSOC 2 Report Window UpdatedSOC 2mediumtrust center

Regulatory developments

HIPAA6 observations
EU AI Act2 observations
FedRAMP1 observations
ONC HTI-11 observations
UK GDPR1 observations
SOC 21 observations

Sources and methodology

GovernAtlas V1 uses a curated local dataset of public vendor pages, trust centers, security documentation, announcements, certification references, and regulatory disclosures. Observations indicate that public language changed; they do not independently certify legal compliance.

trust.abridge.comprivacy policyEU transparency filingMicrosoft Trust Centercompliance disclosuresubprocessor pageAI safety disclosuresecurity page diff
Browse affected vendors