The AI Regulation Reality Check
What AI laws actually mean for your business and how to prepare without over-engineering
If you manage AI programs, you have probably attended at least three meetings in the last six months in which someone raised the EU AI Act, and no one in the room could explain precisely what it requires of your organization. You are not alone. Despite being the most significant piece of AI legislation in history, the EU AI Act remains widely misunderstood by the business and technology leaders who will ultimately be responsible for compliance. And in the United States, the regulatory picture is even murkier, with a tug-of-war between state legislatures racing to write AI rules and a federal administration determined to stop them.
Here is the uncomfortable truth that most legal briefings will not tell you. The regulatory landscape for AI is not evolving. It is fractured, contradictory, and in some cases deliberately ambiguous. Waiting for clarity before taking action is itself a strategic risk. But so is over-engineering your compliance program around requirements that may shift substantially before they take effect.
This post offers a product-centric, non-legal view of where AI regulation stands right now, where it is heading, and what actually matters for organizations building and deploying AI systems. The goal is not to replace your legal counsel. It is to help you ask better questions, make better investment decisions, and build governance capabilities that will serve you regardless of how the regulatory winds blow.
The EU AI Act: What Has Actually Happened
The EU AI Act entered into force on August 1, 2024. That much is settled. What remains unsettled is nearly everything else about its practical implementation.
The Act follows a phased timeline, and understanding where we are on that schedule is essential for any planning exercise. Prohibited AI practices and AI literacy obligations became applicable on February 2, 2025. These include bans on social scoring systems, certain forms of real-time biometric identification, and AI systems that exploit vulnerable populations. If your organization was running any of these applications in EU markets, you should have already stopped.
General-purpose AI model obligations kicked in on August 2, 2025. Providers of GPAI models are now required to maintain technical documentation, provide summaries of training content, establish copyright compliance policies, and share information with downstream deployers. For organizations using models from providers like OpenAI, Anthropic, Google or Meta, the practical implication is that your vendors should already be producing this documentation.
The big milestone everyone has been planning for is August 2, 2026, when the full set of obligations for high-risk AI systems was supposed to take effect. But the European Commission’s Digital Omnibus proposal, published in November 2025, effectively proposes to pause these high-risk requirements.
The harmonized technical standards that companies must demonstrate compliance with are not yet ready. The standardization bodies tasked with developing them missed their 2025 deadlines and are now targeting late 2026 at the earliest. Without these standards, asking companies to comply with requirements that lack clear technical benchmarks is premature.
Under the Digital Omnibus proposal, high-risk AI obligations would only take effect after the Commission confirms that adequate compliance support is available. The backstop deadlines would shift to December 2, 2027, for Annex III systems (those used in areas such as recruitment, credit scoring, and emotion recognition) and to August 2, 2028, for Annex I systems (AI embedded in regulated products such as medical devices and machinery). These are not minor adjustments. They represent a potential delay of 16 months or more from the original timeline.
But here is where it gets complicated. The Digital Omnibus is a proposal, not a law. It must pass through the European Parliament and the Council of the EU under the ordinary legislative procedure. Given that members of Parliament are already divided on the proposal, with some welcoming the simplification and others viewing it as capitulation to industry and geopolitical pressure from the United States, the final text could look quite different from the Commission's proposal.
Adding another layer of complexity, the final version of the GPAI Code of Practice was published on July 10, 2025, providing voluntary but influential guidance for developers of foundation models. The Code of Practice offers a framework for demonstrating compliance with the Act’s GPAI obligations, though providers are free to demonstrate compliance through alternative means. Meanwhile, the AI Office became fully operational on August 2, 2025, along with a scientific panel of independent experts tasked with advising on systemic risks posed by GPAI models. The institutional infrastructure is being built while the plane is flying.
On enforcement, the picture is equally uncertain. Member states were required to designate national competent authorities by August 2025, but implementation has been uneven. As of early 2026, only a handful of member states have designated both notifying and market surveillance authorities, while roughly a third have yet to designate any competent authority.
The penalty regime is substantial on paper, with fines of up to 35 million euros or 7 percent of global annual turnover, but enforcement powers for many provisions do not take effect until August 2026 at the earliest. Italy has already moved ahead with its own national AI law, including criminal penalties for deepfakes and specific liability frameworks, signaling that some member states may not wait for full EU-level implementation.
The most prudent approach for businesses is to continue building compliance capabilities against the original timeline while monitoring whether and when the Omnibus passes. Planning for the best case (delayed deadlines) while preparing for the worst case (original timeline holds) is the only defensible strategy.
What the EU AI Act Actually Requires (Without the Legal Jargon)
Strip away the legal complexity, and the EU AI Act asks four fundamental questions about your AI systems. Getting clarity on these questions is more productive than parsing every article and recital.
First, is your AI system doing something that is not allowed? The prohibited practices are narrow but absolute. If you are using AI for social scoring, manipulating people through subliminal techniques, or exploiting the vulnerabilities of specific groups, no amount of governance will make those applications compliant. They must stop.
Second, is your AI system making or materially influencing decisions that significantly affect people’s lives? This is the high-risk question, and it is where most of the compliance work concentrates. The Act identifies specific use cases that qualify as high risk, including AI used in hiring and recruitment, credit and insurance decisions, educational assessment, law enforcement, migration management, and access to essential services. If your AI touches any of these areas, you will eventually need risk management systems, data governance practices, technical documentation, transparency measures, human oversight mechanisms, and accuracy and robustness testing.
Third, does your AI system interact directly with people who might not realize they are dealing with AI? The transparency obligations apply broadly, requiring that people be informed when interacting with AI systems such as chatbots and that AI-generated content be appropriately labeled. Providers of generative AI systems placed on the market before August 2026 would have until February 2027 to implement machine-readable detection or marking for AI outputs, assuming the Digital Omnibus passes.
Fourth, are you providing or deploying a general-purpose AI model? If you are building foundation models or large language models and making them available in EU markets, you already have obligations regarding technical documentation, transparency in training data, and copyright compliance.
The critical insight for product and technology leaders is that these questions map directly to decisions you are already making about your AI systems. Risk classification is not an abstract legal exercise. It is a product design question. The organizations that integrate these considerations into their development workflows will find compliance far less burdensome than those trying to retrofit governance after the fact.
The United States: Innovation First, Regulate Later (Maybe)
If the EU’s approach to AI regulation can be characterized as comprehensive but increasingly uncertain in its implementation, the US approach is fragmented by design and increasingly conflicted at its core.
A deliberate retreat from regulation defines the federal story. On his first day back in office in January 2025, President Trump revoked the Biden administration’s Executive Order 14110, which had established safety testing and reporting requirements for AI systems. The new administration’s posture, articulated through the AI Action Plan released in July 2025, explicitly prioritizes innovation and economic competitiveness over precautionary regulation.
Then came the December 2025 executive order titled “Ensuring a National Policy Framework for Artificial Intelligence,” which escalated the federal position dramatically. The order established a framework to challenge state AI laws that the administration views as inconsistent with federal policy. It directed the Attorney General to create an AI Litigation Task Force with the sole responsibility of contesting state AI laws on constitutional grounds. It instructed the Secretary of Commerce to identify “onerous” state AI laws within 90 days. And it threatened to withhold federal funding from states with AI regulations deemed to conflict with the federal policy of “minimally burdensome” oversight.
The executive order specifically cited the Colorado AI Act as an example of problematic state legislation, claiming the law would “force AI models to produce false results” by requiring them to protect against algorithmic discrimination. This characterization is contested, but the signal was unmistakable. The federal government is prepared to use litigation, leverage over funding, and regulatory preemption to constrain state-level AI regulation.
But here is what product leaders need to understand about the practical reality. Executive orders are not legislation. They guide federal agencies but do not create enforceable law for private companies. Congress has not passed a comprehensive federal AI law that would preempt state legislation, and the constitutional authority to do so rests with Congress, not the executive branch. Legal experts have noted that the executive order would likely not displace existing state AI laws on its own.
Meanwhile, states have been extraordinarily active. All 50 states introduced AI-related legislation in 2025. Several significant laws took effect on January 1, 2026, including California’s Transparency in Frontier AI Act (requiring frontier developers to publish risk frameworks and report critical safety incidents), the Texas Responsible AI Governance Act, and amendments to the Illinois Human Rights Act addressing AI-driven discrimination in employment. Colorado’s comprehensive AI Act, which requires developers and deployers of high-risk AI systems to exercise reasonable care to prevent algorithmic discrimination, takes effect on June 30, 2026, after a delay from its original February date.
The result is a compliance environment that one legal analysis aptly described as a “compliance splinternet.” The same AI feature can be perfectly acceptable in one jurisdiction and legally risky in another. For organizations operating nationally, this patchwork creates genuine operational challenges.
Adding further uncertainty, the executive order specifically exempted certain categories of state AI laws from preemption efforts, including those related to child safety protections, AI compute and data center infrastructure, and state government procurement. This carve-out suggests that even the administration recognizes some state-level AI regulation as legitimate. The boundary between acceptable and unacceptable state regulation remains undefined and will likely be litigated for years.
Existing federal agencies are also finding ways to assert authority over AI within their existing mandates. The FTC has signaled that it views deceptive AI practices as within the scope of its consumer protection authority. The EEOC has emphasized that employment discrimination laws apply to AI-mediated hiring decisions. The SEC has issued guidance on AI-related risks in financial markets. Civil rights regulators at both federal and state levels have made clear that automated systems do not sit outside traditional anti-discrimination frameworks. Even without new legislation, organizations face meaningful regulatory exposure through the application of existing law to AI use cases.
For product leaders, the practical takeaway is this. Do not bet your compliance strategy on the federal government preventing state regulation. The legal and political process required to preempt existing state laws will take years, and the outcome is far from certain. Build your governance capabilities to satisfy the most demanding requirements you face, and you will be well-positioned regardless of how the federal-state dynamic resolves.
Beyond the EU and US: The Global Picture
Organizations operating internationally face an even more complex landscape. A few developments deserve attention.
South Korea passed its Framework Act on the Development of Artificial Intelligence and Establishment of Trust (AI Basic Act) in late 2024, with enforcement beginning in January 2026. It takes a risk-based approach similar in structure to the EU AI Act, with obligations for high-impact AI systems that affect South Korean residents, including requirements for foreign entities to designate domestic representatives.
China continues to build what might be described as a vertical regulatory model, with specific rules targeting algorithmic recommendations, deepfakes, generative AI services, and labeling AI-generated content. An amended Cybersecurity Law referencing AI took effect in January 2026, and a draft comprehensive AI law proposed in 2024 could formalize binding requirements for high-risk systems.
Japan enacted its AI Promotion Act in May 2025, taking a lighter-touch approach that encourages companies to cooperate with government safety measures while empowering the government to publicly name companies that violate human rights through AI. Brazil continues to develop risk-based AI regulation, modeled partly on the EU approach, though its bill remains in the legislative process.
The UK presents an interesting case study in regulatory recalibration. After initially championing a voluntary, “pro-innovation” approach to AI governance, the Labour government has signaled a shift toward more interventionist regulation. The AI Safety Institute is expected to become a statutory body with legally binding evaluation powers for the most capable AI systems. However, a comprehensive AI bill did not materialize in 2025.
At the international level, the United Nations launched two new AI governance bodies at the 2025 General Assembly, and over 72 countries have now launched more than 1,000 AI policy initiatives. The direction is clear, even if the details remain fluid. AI governance is becoming a global expectation, not a regional preference.
One emerging challenge that no current regulatory framework adequately addresses deserves mention. Agentic AI systems that not only answer questions but take autonomous actions in the world are rapidly moving from research concept to commercial deployment. These systems stress-test “human oversight” provisions that were written with predictive and generative AI in mind.
When an AI system autonomously books travel, executes trades, or manages customer interactions across multiple steps, the traditional model of a human reviewing each decision before it takes effect breaks down. Regulators are watching this space closely, and organizations deploying agentic AI would be wise to think carefully about where autonomous action is appropriate and where human checkpoints remain essential. This is a governance question that will only grow more important through 2026 and beyond.
What Actually Matters: A Product Leader’s Framework
With all this regulatory complexity and uncertainty, it is tempting to either panic or procrastinate. Neither response serves your organization well. What serves you is a pragmatic framework for making governance investments that will hold value regardless of how specific regulations evolve.
Here is how I advise organizations to think about regulatory readiness.
Know Your AI Inventory Before Regulators Ask About It
The single most valuable compliance activity you can undertake today is to build and maintain a comprehensive inventory of your AI systems. Every regulatory framework, whether the EU AI Act, the Colorado AI Act, or South Korea’s AI Basic Act, begins with the same question. What AI systems are you operating, and what are they doing?
You cannot assess risk, classify systems, or demonstrate compliance for systems you do not know about. And in most large enterprises, the AI inventory problem is more severe than leaders realize. Shadow AI, models deployed by business units without central oversight, and third-party AI embedded in vendor products create blind spots that regulators will eventually illuminate.
Your inventory should capture what each AI system does and what decisions it influences; what data it uses and where that data comes from; who is affected by its outputs; which jurisdictions those affected individuals are in; and who owns accountability for the system’s performance and compliance. This is not a one-time exercise. It is an ongoing operational discipline.
Classify Risk Based on Impact, Not Technology
Every major regulatory framework uses some form of risk-based classification. The EU AI Act classifies by use case. The Colorado AI Act focuses on “consequential decisions” in domains like employment, education, financial services, healthcare, and housing. The NIST AI Risk Management Framework is organized around potential harms.
The common thread is that risk classification follows from the impact of AI decisions on people, not from the technology's sophistication. A simple rules-based system making credit decisions may carry higher regulatory risk than a complex deep learning model recommending movies.
Build your internal risk classification around impact categories that align with the broadest set of regulatory requirements you might face. This means focusing on whether your AI affects access to employment, credit, housing, education, or healthcare; whether it interacts with vulnerable populations; whether it makes or materially influences decisions with legal or similarly significant effects on individuals; and whether it operates in public safety or law enforcement contexts.
By classifying based on impact, you create a framework that maps naturally to multiple regulatory regimes rather than being tied to any single one.
Build Documentation as a Product Practice, Not a Compliance Afterthought
Documentation requirements appear in virtually every AI regulatory framework. The EU AI Act requires technical documentation for high-risk systems. California’s Transparency in Frontier AI Act requires the publication of risk frameworks. The Colorado AI Act requires impact assessments. And the NIST AI RMF recommends comprehensive risk documentation.
The organizations I see handling this well treat documentation as a product practice rather than a compliance exercise. They integrate model cards and system documentation into their development workflows. They automate as much documentation as possible, generating technical specifications from development environments rather than writing them manually afterward. They maintain living documents that evolve with their systems rather than static snapshots that become obsolete the moment they are completed.
The practical benefit extends beyond compliance. Good documentation accelerates onboarding, supports debugging, and enables more informed decisions about model updates and retirement. It is one of those rare cases where governance genuinely improves operational efficiency.
Invest in Monitoring That Serves Both Operations and Compliance
Continuous monitoring is where governance and operations converge most naturally. Regulators want to know that your AI systems are performing as intended and that you can detect and respond to problems. Your engineering teams want the same thing. The investment in observability infrastructure serves both purposes simultaneously.
At a minimum, your monitoring capabilities should track model performance against established baselines, detect data drift and concept drift that could degrade performance, monitor for bias and fairness metrics across relevant demographic dimensions, log decisions and the inputs that drove them for auditability, and surface anomalies that may indicate adversarial attacks or system failures.
The EU AI Act’s requirements for post-market monitoring of high-risk systems, combined with transparency obligations around system behavior, make this investment increasingly non-optional for organizations operating in regulated markets. But even in the absence of specific regulatory mandates, the operational case for production AI monitoring is compelling. Systems that degrade silently cost more than systems that degrade visibly.
Design for Human Oversight Without Destroying Automation Value
Every major regulatory framework includes some form of human oversight requirement. The EU AI Act mandates that high-risk AI systems be designed to allow effective human oversight. The Colorado AI Act requires that consumers be informed about AI involvement in consequential decisions and have the ability to appeal. And the NIST framework emphasizes human agency throughout the AI lifecycle.
The challenge for product teams is implementing meaningful human oversight without undermining the efficiency gains that justified AI deployment in the first place. The answer is not to insert a human reviewer into every AI decision. It is to design systems with appropriate checkpoints calibrated to the risk level of specific decisions.
For low-risk, high-volume decisions, automated monitoring with exception-based human review is often sufficient. For high-risk decisions affecting individuals’ access to credit, employment, or healthcare, more robust human involvement may be necessary, not necessarily approving every decision, but maintaining the ability to understand, override, and audit AI outputs.
The key design principle is that humans must have sufficient context, time, and authority to intervene when they identify problems. A compliance checkbox that routes decisions through a human who lacks the information or authority to change anything is not meaningful oversight. Regulators will eventually distinguish between genuine oversight and performative compliance.
Prepare for Transparency Demands You Have Not Anticipated
Transparency requirements are expanding faster than most organizations realize. Beyond the EU AI Act’s disclosure obligations, we are seeing transparency demands emerge from multiple directions. Consumers want to know when they are interacting with AI. Employees want to understand how AI affects their work evaluations and career progression. Business partners want visibility into how AI influences the services they receive. Investors and board members want assurance that AI risks are being managed.
Building transparency capabilities now, before they are mandated, creates a competitive advantage. Research consistently indicates that the vast majority of IT professionals believe consumers prefer companies with transparent and ethical AI practices. Organizations that can demonstrate how their AI works, what data it uses, and how it reaches its decisions will be better positioned with customers, regulators, and partners than those scrambling to produce explanations after the fact.
Transparency does not mean exposing proprietary algorithms. It means being able to explain, at an appropriate level of abstraction, what your AI does, why it makes the recommendations or decisions it makes, and what safeguards are in place to prevent harm. This is both a technical capability (explainability tools, model cards, audit trails) and an organizational one (trained staff who can communicate about AI systems to diverse audiences).
The Trap of Over-Engineering
With all of this regulatory activity, there is a real temptation to build massive compliance programs that try to anticipate every possible requirement. This is unnecessary, not because compliance does not matter, but because over-engineering governance can be as damaging as under-investing in it.
Here is what over-engineering looks like in practice. Organizations create exhaustive AI policies that nobody reads or follows. They build approval processes so burdensome that teams route around them, creating exactly the shadow AI problem that governance was supposed to prevent. They invest in compliance infrastructure for regulatory requirements that may never take final form, or may look substantially different when they do.
The better approach is to build governance capabilities that are genuinely useful for managing AI risk, not just responsive to specific regulatory text. If your governance program makes your AI systems more reliable, more transparent, and more accountable, it will serve you well under virtually any regulatory regime. If it exists solely to check compliance boxes, it will be expensive, fragile, and perpetually behind the curve.
This is why I keep returning to the distinction between governance and observability as the two essential pillars of Trusted AI. Governance establishes the guardrails. Observability tells you whether those guardrails are holding. Together, they create a foundation that is adaptable to regulatory change, grounded in operational reality rather than regulatory text.
What to Do Now
If you are looking for a practical starting point, here are the highest-value actions you can take in the next 90 days.
Complete your AI system inventory. If you do not know what AI you are running, you cannot govern it. Prioritize the discovery of AI systems that affect people in regulated domains.
Classify your highest-risk systems. Using the impact-based framework described above, identify the AI applications that pose the greatest risk to individuals and to your organization. These are your governance priorities.
Assess your monitoring capabilities. Can you detect when your AI systems are drifting, degrading, or producing biased outputs? If not, this is a more urgent investment than any compliance documentation.
Engage your legal counsel on jurisdictional exposure. Based on where your AI systems operate and who they affect, which regulatory frameworks apply to you? This is not a question you can answer without legal expertise, but it is one you should be asking now.
Start building documentation practices into development workflows. Do not wait for regulatory deadlines to begin documenting your AI systems. The organizations that integrate documentation into their development process will find compliance far less disruptive than those that treat it as a separate workstream.
Establish clear accountability. Ensure that every AI system has a designated owner who understands they are responsible for its performance, compliance, and outcomes. Diffuse accountabilityat inois accountabilist.
The Regulatory Trajectory Is Clear
Despite the noise and uncertainty around specific regulations, the trajectory is unmistakable. The world is moving toward greater oversight of AI systems, particularly those that affect consequential decisions about people’s lives. The organizations that build governance capabilities now, as a strategic investment rather than a reactive compliance exercise, will be positioned to move faster and with greater confidence as requirements crystallize.
Policy alone cannot deliver Trusted AI. You need continuous visibility into what your AI systems are actually doing. But policy is coming, whether from Brussels, from state capitols, from Beijing, or from your own customers and stakeholders who increasingly expect that the AI systems affecting their lives are governed responsibly.
The question is not whether regulation will affect your AI programs. It will. The question is whether you will be ready when it does, with governance capabilities that are both rigorous enough to satisfy regulators and practical enough actually to work. Build for adaptability, invest in fundamentals, and resist the urge to over-engineer around requirements that remain in flux.
The organizations that get this right will not just be compliant. They will be trusted. And in an AI-first world, trust is the ultimate competitive advantage.


