The consent debate around AI scribes has mostly been about absence: did anyone ask the patient, was a form signed, was a box ticked. A new lawsuit this month reframes it as a presence problem instead, because the record in question was not blank. It said something happened that never did. That case leads this week, alongside a correction worth making to how Colorado's new therapy AI law actually gets enforced, a federal regulator opening the door on generative AI devices, an NHS trust quietly stepping over a regulatory line drawn only a month ago, and a very large number attached to one government's AI ambitions.
1. An AI scribe allegedly invented the patient's consent
A proposed class action filed in San Diego Superior Court claims Sharp HealthCare used Abridge's ambient AI scribe to record exam-room conversations without telling patients or asking permission, then had the software auto-insert a line into the patient portal stating the patient had been advised of the recording and had consented. The lead plaintiff says that conversation never happened. The complaint seeks statutory penalties, punitive damages, injunctive relief and correction of the affected records for a class the filing estimates may exceed 100,000 patients. Sharp began using the tool in April 2026. Source: KPBS Public Media and Becker's Hospital Review, reporting on the filed complaint, 2026.
The number: 100,000. Not the count of people who were recorded without consent, but the count of patient records that now carry a documented statement of consent nobody gave.
The so-what: this is a different failure mode to the one most practices are guarding against. A missing consent form is a gap you can find and close. A false consent statement is a gap that looks closed when it is not, because the record itself asserts the opposite of what happened. If your AI scribe auto-populates a consent or disclosure line into any note or portal message, that line needs the same scrutiny you would give a clinical finding the software generated, not a wave-through because it is administrative text. We worked through the separate legal exposure a signed BAA does not cover in your AI scribe's BAA covers HIPAA, it doesn't cover state consent law, and this case adds a second, sharper version of the same warning: check what the template actually writes, not just whether a template exists.
2. Colorado's therapy AI law and its grace period belong to two different statutes
Coverage of Colorado's AI healthcare rules has tended to blur into one story, so it is worth separating the two laws now that both have been reported on in the same breath. HB 26-1195, the psychotherapy-specific restriction already in force since 12 August 2026, is enforced through licensing board discipline and the Colorado Consumer Protection Act, which permits civil penalties of up to $20,000 per violation for deceptive trade practices and carries no cure period. The 60-day right-to-cure window reported alongside it belongs to a separate law, SB 26-189, Colorado's broader AI Act, which does not take effect until 1 January 2027 and sunsets its own cure provision on 1 January 2030. Source: Snell & Wilmer client alert, 2026, and the Colorado Consumer Protection Act.
The number: two. Two statutes, two enforcement bodies, two timelines, and only one of them gives a practice 60 days to fix a mistake before it becomes a penalty.
The so-what: if a compliance summary you have read implies Colorado's psychotherapy AI restrictions come with a grace period, check which statute it is actually describing before you rely on it. HB 26-1195 does not offer one. We covered the substance of what the law permits and requires at initial contact in Colorado's AI therapy law and the provision the headlines skipped, and this correction sits alongside it: read the enforcement mechanism as carefully as the prohibition, because two adjacent laws from the same legislature do not automatically share one.
3. The FDA opened the door on how it will regulate generative AI devices
On 18 August 2026 the FDA published a discussion paper and opened public docket FDA-2026-N-7874, seeking input from device manufacturers, clinicians and researchers on how to assess, evaluate and monitor generative AI-enabled medical devices across their lifecycle. The paper proposes a two-axis framework for stratifying risk and calibrating premarket evaluation and postmarket monitoring accordingly. Comments close 19 October 2026. Source: FDA press announcement, 18 August 2026.
The number: 19 October. The deadline for the conversation that will eventually decide what "FDA cleared" is even allowed to mean for a generative AI tool.
The so-what: today's clearances for AI clinical tools were built for software that does not keep learning after it ships, and a generative model behaves differently in ways the current framework was not designed to catch. Until this paper becomes a rule, a vendor's "FDA cleared" claim tells you less than it sounds like it does, because the clearance pathway it went through may not have been built for the category of tool it actually is. Our look at how thoroughly AI scribe accuracy actually gets tested before deployment, in the government audit that found all 20 tested scribes made errors, is a useful companion read while this framework is still being written: verification is currently down to the buyer, not the regulator.
4. An NHS trust's new tool sits on the regulated side of a line drawn a month ago
Calderdale and Huddersfield NHS Foundation Trust is reported to be going live on 1 September 2026 with an EPR-embedded clinical decision support tool built around the Anticholinergic Medication Index, flagging anticholinergic medication burden for review in patients aged 65 and over. Source: Nelson Advisors UK HealthTech Pulse, 18 August 2026; the trust's own registration status for the tool has not been independently confirmed this session.
The number: 65. The age threshold the tool is built to watch, in a patient population where anticholinergic burden is a recognised and well-studied prescribing risk.
The so-what: this is a genuinely different category of tool to the ambient scribes that dominated the last two months of NHS AI coverage. MHRA's own worked examples in its 29 July guidance put software that generates insights or recommendations for clinical review on the regulated side of the medical device line, not the exempt side reserved for transcription and summarising. If your practice is evaluating anything that goes beyond writing up what was said in the room and starts suggesting what to do about it, that is the functional test to apply before you ask a vendor for a demo. We set out the full worked distinction in why your AI scribe's regulatory status is set by marketing.
5. The VA nearly doubled its AI-linked EHR contract ceiling
The US Department of Veterans Affairs raised the ceiling on its Oracle Health electronic health record modernisation contract by close to $17 billion, taking it to nearly $27 billion with a potential period of performance running through May 2031. The contract covers Oracle Health's Clinical AI Agent, intended to help clinicians prepare for visits, complete documentation faster and improve reimbursement accuracy. Source: HIT Consultant and Nextgov/FCW, 20 August 2026.
The number: $27 billion. A single government contract ceiling, for AI-linked documentation and reimbursement tooling, running to 2031.
The so-what: this is not a figure an independent practice needs to compete with, but it is worth reading as a signal of where vendor engineering effort goes next. When a contract this size is built around documentation-and-reimbursement AI, the product roadmaps of the tools that eventually reach smaller practices tend to follow the money. Watch for the features that get built for this contract to show up, a year or two later, in the mid-market tools your own practice actually buys.
What this week adds up to
Two of this week's five stories are corrections to a story that was already being told wrong: Colorado does not have one AI healthcare law, it has two, with different enforcement tracks, and the Sharp lawsuit is not a missing-consent story, it is a false-consent one. Both corrections point the same direction. The detail that actually matters is rarely the headline version of a regulation or a complaint, it is the specific mechanism underneath it, and that mechanism is usually one careful reading away from the primary document rather than the summary of it.
Put plainly: if you use an AI scribe, read what it writes into the parts of the record you never proofread, not just the clinical note. If you operate under a state AI law, confirm which statute a given penalty or grace period actually belongs to before you rely on it. And if a tool you are evaluating does anything more than transcribe and summarise, ask the vendor directly whether it has been assessed against the medical device threshold, because that answer is now a one-sentence question with real consequences either way.
If you want a structured, independent read on where your own practice's AI use actually sits against these questions, the AI Opportunity and Growth Assessment benchmarks you against the CARE Framework in two weeks. Or book a 20-minute discovery call and we will work through what this week's stories mean for the tools you already run.
The Clinical AI Briefing
One practical AI insight for healthcare practices every week. No hype. Evidence and outcomes only.