Four things happened over the last few weeks. Three of them are about information that already existed somewhere you could not see it. California started requiring the big AI companies to mark the images, video, and audio they generate. A national standards group pulled together nearly a hundred people to write AI security guidance, while a survey showed health organizations fixed only six percent of the risks they had already found. And a poll found that one adult in five keeps quiet with their doctor about the thing that matters most. The fourth one is different, and it is why this issue has four instead of three. It happens in your own meetings, on your own account, and there is a date attached to it.
Signal 1
California Began Requiring Large AI Systems to Mark the Images They Generate, and to Publish a Free Tool for Reading the Mark (August 2, 2026)
On August 2, 2026 the first part of the California AI Transparency Act took effect. The law, SB 942 as amended by AB 853, was originally meant to start on January 1, 2026 and was pushed back to August 2. It applies to companies whose generative AI systems are available to the public in California and have more than one million users a month. Those companies have to publish a free detection tool that accepts uploaded files, links, and automated requests, and that does not keep what people send it. They have to offer a visible label on any image, video, or audio their system makes. They also have to embed a hidden marker in that content recording which system made it, which version, and the date. A company that licenses its system to someone else has to cut off that license within ninety six hours if the marker gets disabled. Penalties are five thousand dollars per violation, with each day counted separately, enforced by the attorney general and other state officials. There is no way for a private individual to sue. The law does not cover AI generated text.
Sources: California Legislature, SB 942 | Morgan Lewis LawFlash, August 3, 2026
What this means for you
The important part here is what the law actually covers. Images, video, and audio, but not text. So a caption you wrote with AI help is not affected. The graphic sitting above that caption is. Issue 020 talked about how proof of good practice is turning into something you can point at. This is the same idea moved inside the file, because the image itself now carries a hidden note saying which AI made it, which version, and on what date. The other thing worth knowing is who the law applies to. Only companies with more than a million users a month, which is why none of it lands on you directly. There is a bill in the state senate, SB 1000, that would remove that cutoff. And more of this is already scheduled. Large platforms have to start showing this information in January 2027, and camera makers have to build it in starting January 2028. Most coaches have more AI-made material out there than they remember. The practical change is that the file now answers the question on its own. A client who wonders whether that graphic was made by AI can find out without asking you. Saying so yourself, once, costs nothing and removes the question before anyone thinks to ask it.
Signal 2
CHAI Pulled Together Nearly a Hundred Leaders on AI Security, While Health Organizations Fixed Six Percent of the Risks They Had Already Found (August 12, 2026)
On August 12, 2026 the Coalition for Health AI announced a Health AI Cybersecurity Work Group, nearly one hundred members meeting every two weeks to produce a defensive playbook, an offensive playbook, and a risk assessment tool by the end of 2026. CHAI gave its reason: the Mythos class of AI models, including the public Fable release on June 9, 2026, which the group says speed up attacks and make stealing health information and running ransomware much easier. A council of fourteen leads the work, with people from Duke Health, Johns Hopkins Health System, Centene, Health-ISAC, the University of Texas Medical Branch, Delaware Valley Community Health, and the AI note-taking company Abridge. Separately, a survey by the security firm Fortified Health Security found that hospitals fixed six percent of the cybersecurity risks they had identified in the first quarter of 2026, down from twenty three percent a year earlier. That six percent is the survey’s number, not CHAI’s.
Sources: CHAI announcement, August 12, 2026 | Healthcare Dive, August 13, 2026
What this means for you
The number worth holding onto is the six percent. Nearly a hundred people getting together to write guidance is a plan for next year. Six percent of known risks actually fixed, down from twenty three percent the year before, is what is happening now. And nobody missed those risks. They were found and written down. They just did not get dealt with. Issue 017 talked about CHAI writing the standards, deciding who meets them, and running the rollouts too. That is worth remembering when you look at who is on this council. One of the fourteen is the security lead at Abridge, a company that sells AI note-taking to medical practices, and the guidance being written covers AI note-taking. Groups like this are usually built that way. It is still a reason to read what they publish rather than the announcement about it. Isaiah Nathaniel from Delaware Valley Community Health said this needs to reach practices of every size, including underserved and lower-resourced communities. That is a fair thing to hold them to when the guidance comes out in December. For a practice of one the useful part is not the playbook, which is months away and written for organizations that employ security staff. It is the reason CHAI gave for calling the group together. Stealing health information got faster and cheaper this year, and a coach working alone is the least likely to notice it happening.
Signal 3
A Survey Published This Week Found One Adult in Five Stays Quiet With a Doctor About the Thing That Matters Most (August 13, 2026)
On August 13, 2026 Deutsches Ärzteblatt published results from a Forsa Institute poll of 1,791 adults, commissioned by BARMER, one of Germany’s largest health insurers, and carried out by telephone in January and February of this year. Eighteen percent said they had held back a health problem from a doctor at least once out of shame, embarrassment, or mistrust. Among adults aged eighteen to twenty nine it was twenty eight percent. Twenty three percent of women said they had held something back, against thirteen percent of men. The hardest subjects to raise were relationship problems at twenty eight percent, sexual health at twenty five, and domestic violence or abuse at twenty. Alongside that, polling by the West Health-Gallup Center on Healthcare in America found that roughly one in four American adults, more than sixty six million people, use AI tools for health information, and that eighteen percent of those who used AI instead of seeing a doctor said they did so because they were too embarrassed to talk to a person.
Sources: Deutsches Ärzteblatt, August 13, 2026 | West Health-Gallup Center on Healthcare in America
What this means for you
This is less about AI than about where things end up. Your client already knows what she is not telling you. She has decided that saying it out loud, to your face, is harder than keeping it to herself. What is different now is that she has somewhere else to put it, available at eleven at night, that does not react to anything she says. Issue 019 covered five chatbots tested on everyday vegetarian and vegan nutrition questions, and all five gave answers that could hurt someone. Those two findings belong next to each other. The questions people are most likely to take to a chatbot are the embarrassing ones, and those are exactly the questions where a wrong answer does the most harm and nobody is there to catch it. Change your intake form rather than your view of chatbots. Add one line asking what she has already looked up or asked an AI about, and what it told her. Ask in writing rather than out loud. A 2026 survey by the digital health platform Doctolib found that almost sixty percent of people who admit holding things back were more honest on a written pre-appointment form than they were face to face. This is not about catching anyone out. It is so you can see the answer she already got and talk about it with her.
Signal 4
Google Will Turn On Meet Note-Taking and Transcription for Meetings With a Third Person, No Sooner Than September 21 (Announced July 16, 2026)
On July 16, 2026 Google announced a third setting for automatic note-taking in the Workspace Admin console. Until now an administrator could turn it on for every meeting or for none. The new option turns it on only once a meeting passes a participant threshold, with the organizer counting toward it. For Business Standard and Business Plus customers the new setting is on by default. For Enterprise Standard, Enterprise Plus, Frontline Plus, and the Google AI Pro for Education add-on it is off by default. Google says nothing changes for users on any plan before September 21, 2026, and describes the rollout to users as starting no sooner than that date. Once it is live, a Meet call that passes the threshold has “Take notes for me” and transcription switched on ahead of time, and both start when the first person joins. Organizations that took part in the Gemini Alpha program may find the setting already on.
Sources: Google Workspace Updates, July 16, 2026 | Google Meet Help Center, “Take notes for me”
What this means for you
Here is the part that matters. The Google Meet Help Center spells out who can stop the note-taking once it has started: the person who set up the meeting, and anyone inside that person’s organization. Your client is not inside your organization. She will see a notice and a pencil icon on her screen, and she can leave the call. She cannot turn it off. Before you picture this happening on every call, it does not. A regular one-to-one session with a client does not reach the threshold. What it reaches is the session with a third person in it. A client who brings her husband. An interpreter. An adult daughter sitting in. Group programs. A call with a referring practitioner. Those are often the sessions where someone brought support because the subject is difficult. Issue 020 made the point that responsibility sits with whoever put the tool in place. Here you did not put anything in place. Someone at Google changed a default setting inside software you already pay for, and all you did was not turn it off. That is the part worth sitting with. Nobody is going to ask your permission, and the setting will not announce itself in the meeting. Whether it reaches you at all comes down to which plan you are on, and that is worth knowing before it reaches you rather than afterwards.
The Pattern
Three of these four are the same story. California made it possible to tell when an image was made by AI. The survey found risks that were spotted and then not fixed. The poll found information a client is holding back and taking somewhere else instead. In each one, somebody could already see the problem clearly. What did not happen was anyone doing much about it. Issue 016 made the argument that the real problem was not being able to see inside these systems at all. That part is genuinely getting better. The fourth one is in this issue because it does not match the other three. It is not happening somewhere else, to an organization bigger than yours. It happens on your own account, in your own meetings, and there is a setting only you can change. The first three will not affect you directly until 2027 or 2028, if ever. The fourth one arrives in about five weeks.
One Thing You Can Do This Week
Two things, both before September 21. First, open your Admin console and look at the automatic note-taking setting. Business Standard and Business Plus are the plans where it is already switched on. If you are a solo coach on Workspace you are your own administrator, so there is nobody else who will check this for you, and if you use a regular Gmail address rather than Workspace there is no console and none of it reaches you. Turn it off if that is what you want, or leave it on because you decided to. Either one is a fine answer. Not knowing which one you have is the part to fix. Second, while you are in there, look for the setting that requires everyone to agree before note-taking, recording, or transcription starts. Google leaves that one switched off. Turning it on is the only control listed that reaches someone outside your organization, which means your client. Then write down the one sentence you will say at the start of a session with a third person in it, before anyone joins. Not a policy. One sentence, in your own words, telling them notes are being taken and where those notes go.