An Operator’s Update on the AI Regulatory Landscape

We’ve spent the last several issues discussing adoption, transformation, and execution inside organizations: mandates for mandates’ sake, readiness gaps that turn out to be infrastructure problems, and the various challenges that come with moving at AI velocity. This week I want to step outside that conversation and look at the broader environment those decisions are sitting inside, because the regulatory picture is finally starting to take shape.

If you were a leader in a company in 2018 when GDPR walked onto the scene, you may remember the rush to comply coupled with the lack of accessible assessment and governance tools to support operational privacy journeys. The law was real, it had an enforcement date, and it applied to any company touching European data regardless of where you were headquartered, but rollout was painful and expensive… and for a lot of companies, it generated a lot of consulting fees. But you could still build your privacy infrastructure once and the rest of the jurisdictions that followed with their own versions (CCPA, Virginia, Colorado, the others) mostly fit inside what you’d already built.

The current AI regulatory landscape is likely not going to work the same way, and understanding why matters for all those durable decisions you’re working so hard to make.

What’s Happening in the US

The federal picture is, to put it charitably, in motion. The current administration’s posture is pro-acceleration: a June 2026 executive order frames AI policy around innovation and national security rather than consumer protection, and the White House has established a litigation task force specifically to challenge state AI laws it considers overly burdensome. The message from Washington is this: move fast, and we will try to keep state governments out of your way.

States, on the other hand, have moved to drive enforcement across a variety of vectors.

As of this spring, lawmakers in 45 states have introduced 1,561 AI-related bills in the current legislative session, more than double the volume from two years ago. Of those, the ones with the most operational bite for business aren’t the ones about deepfakes or chatbot disclosures. They’re the ones about automated decision-making: who gets hired, who gets a loan, and who gets approved for housing or healthcare. Instead of regulating at the foundation layer or application layer, many of these regulations are focusing on the human impact layer, which for technology companies can be an incredibly ambiguous undertaking to scale.

Colorado is perhaps the most instructive story in the US right now. In 2024, Colorado passed the first comprehensive state AI law in the country, a broad framework imposing a duty of care on companies deploying AI in consequential decisions, requiring algorithmic impact assessments, risk management programs, and meaningful steps to prevent discriminatory outcomes. The law was ambitious, it was specific, and it made a lot of compliance teams very nervous.

Then it got delayed. And delayed again. Then, in April 2026, Elon Musk’s xAI filed suit to block it, and the US Department of Justice moved to intervene (the first time the federal government had sought to invalidate a state AI law). A federal court stayed enforcement putting its effective date at risk. And then, while all of that was in motion, the Colorado legislature went back to the drawing board and passed an entirely different law, signing it in May 2026. The replacement strips out the duty of care, eliminates the impact assessment requirements, removes the risk management mandate, and replaces the whole framework with something narrower: notice requirements, disclosure obligations, consumer rights to human review after an adverse decision. It takes effect in 2027, assuming it survives its own litigation.

What happened in Colorado looks like a philosophical shift, but one has to wonder if it was more of a “we need to get something passed” compromise as so much of legislation ends up being watered down to. The original law was trying to prevent harm before it occurred while the replacement is mostly asking companies to tell people when AI affected them and give them a way to appeal. Those are different theories of what the problem is.

California, meanwhile, has gone in a different direction entirely, passing multiple AI laws taking effect in 2026 including disclosure requirements for AI-generated content, training data transparency mandates for large model providers, and layered automated decision-making rules still phasing in. New York City has its own hiring audit requirements that have been enforced for two years. Illinois requires consent before AI evaluates video interviews. In short order, a patchwork quilt of AI regulation has been rolled out over the country.

What’s Happening in Europe

The EU AI Act is the closest thing the world has to a comprehensive AI governance framework, and if you have any customers, employees, or operations in Europe, it applies to you regardless of where your company is incorporated. This extraterritorial reach is the same mechanism that made GDPR enforceable against US companies, and the EU has gotten better at using it.

The majority of the Act’s requirements come into force on August 2, 2026, six weeks from now. That includes transparency rules requiring that AI-generated content be labeled, governance obligations for providers of general-purpose AI models, and enforcement infrastructure across EU member states. The fines aren’t GDPR-scale; they’re larger, up to €35 million or 7% of global annual turnover, whichever is higher, for prohibited AI practices.

The high-risk AI system obligations (the ones that would require conformity assessments, risk management documentation, and human oversight requirements for AI used in hiring, credit scoring, healthcare, and similar consequential decisions) just got pushed back. A Digital Omnibus agreement reached in May 2026 deferred those deadlines by 16 months, moving the Annex III compliance date from August 2026 to December 2027.

But the deferral is not an all-clear. The prohibitions on certain AI practices have been in force since February 2025: no social scoring, no real-time biometric identification in public spaces with narrow exceptions, no manipulative AI systems. The general-purpose AI model obligations have been in force since August 2025. The infrastructure of enforcement is being built now, and as of right now, companies in the EU’s regulatory sandbox have 16 extra months to get ready.

What’s Happening Everywhere Else

This is where the “build to the strictest standard” playbook breaks down, because the rest of the world isn’t building variations of the same thing; they’re building from entirely different starting points.

China has constructed what is effectively a content control and state security framework dressed in the language of AI regulation. The Generative AI Services Management Measures (2023), the synthetic content labeling requirements that took effect in 2025, and the amended Cybersecurity Law that came into force in January 2026 create a closed system: all AI-generated content must be trackable, platforms must implement detection mechanisms, and data localization requirements mean that the data your AI systems use can’t leave Chinese infrastructure. This is a state oversight framework, not a consumer protection one, and the compliance obligations it creates for a multinational operating in China are flatly incompatible with what the EU requires around data portability and user rights.

South Korea passed its AI Basic Act, which took effect in January 2026, applying a risk-based framework to AI systems that affect Korean users and applying it extraterritorially, meaning foreign companies whose AI systems reach Korean consumers are covered. Canada’s Artificial Intelligence and Data Act is still working its way through parliament, taking a risk-based approach modeled loosely on the EU but with its own definitions and enforcement mechanisms, which means companies operating across North America will eventually need to reconcile Canadian requirements with the US state patchwork and whatever federal direction eventually joins the party. Brazil’s risk-based framework passed its Senate in 2024 and has been moving through a longer legislative process since. Japan is relying on voluntary principles rather than binding mandates, at least for now. The UK departed from its earlier commitment to a comprehensive AI statute and is taking a regulator-led, sector-specific approach instead.

Seventy-two countries now have some form of AI policy, and most haven’t translated it into binding law yet.

Why the Privacy Playbook Breaks Here

The GDPR playbook worked because the jurisdictions arguing about privacy were arguing about the same thing: how strictly should companies have to handle personal data? The answer varied, but the fundamental question was shared definition. You could build to the strictest standard and cover almost all of the variables.

AI regulation isn’t working this way. The jurisdictions aren’t arguing about how strictly to apply the same rules; they’re arguing about what harm they’re even trying to prevent.

The EU is trying to protect individuals from algorithmic risk, from AI systems that make consequential decisions about their lives without adequate human oversight or accountability. The US state approach (where it exists) is mostly trying to require transparency and disclosure: tell people when AI affected them, give them information, and give them a way to appeal. China is trying to ensure state control over what AI systems produce and how that content circulates. South Korea is taking a hybrid approach that borrows EU risk-based architecture but applies it extraterritorially in ways the EU itself doesn’t fully do yet.

You cannot build a single governance framework that satisfies all of these simultaneously, because they’re asking for different things from different premises. Building to EU standards doesn’t automatically satisfy China’s content control requirements, and building to China’s requirements would put you in tension with EU data portability rules. And then, if you did the work to build to Colorado’s old framework, you wasted months of compliance work when that framework was replaced with something architecturally different.

What this means practically for operators is that the right question to ask is this:

What underlying operational infrastructure makes you defensible across incompatible frameworks, and lets you adapt as the regulatory landscape continues to change?

What Is a Leader to Do?

The underlying infrastructure requirement turns out to be consistent across all of these frameworks, even where the surface obligations differ. Every jurisdiction that has passed binding AI law (the EU, Colorado, California, South Korea, China) is asking some version of the same foundational questions: whether you know which of your AI systems are making or influencing consequential decisions about real people, whether you can explain what those systems do, whether humans are in the loop for high-stakes outcomes, and whether you can document any of it.

The companies navigating this well built that operational foundation before they needed it, the kind that makes the compliance questions answerable regardless of which jurisdiction is asking.

If you’re an individual contributor who has been deploying AI tools inside your organization: one of the most valuable things you can do right now is map the AI systems you’ve put into production against the question of consequential decisions. Consequential, in the language of most of these laws, means decisions that affect people’s access to employment, housing, healthcare, credit, education, or essential services. If any AI you’ve shipped touches those domains (resume screening, performance evaluation, customer creditworthiness, medical triage, anything in that territory), you are likely inside the scope of multiple regulatory frameworks already, whether or not anyone in your legal team knows it yet. Mapping this is an operational exercise, not a legal one, and it’s much easier to do before an enforcement action than after.

If you’re a leader whose AI mandate has stalled: the regulatory picture is not a reason to keep waiting. The companies with the most exposure right now are the ones with low visibility into what AI systems they’re actually running. If your teams have been deploying AI tools without centralized oversight (which is a lot of organizations), you don’t know what you’re working with. A regulatory audit question you can’t answer is a bigger problem than a compliance gap you’ve identified and are working on. The immediate priority is the inventory, not the compliance program.

If you’re a leader who hasn’t mandated AI adoption yet: the instinct that moving slowly is the safer path from a regulatory standpoint deserves some pushback. The frameworks being built are not aimed at companies that are cautious about AI. They’re aimed at companies that are deploying AI in consequential decisions without adequate oversight. If you’re not deploying, you’re not exposed, but most companies in this category are running more AI than their leadership realizes, because so much of practical AI adoption has been bottoms-up. The regulatory risk is making any governance decision without understanding what you are working with.

Your Takeaway This Week

The rules are being written while the game is being played. Sounds chaotic, but by now I’m sure you’re all used to this game. Colorado rewrote its AI law three times in two years, the EU’s most consequential deadline just moved 16 months, the US federal government is suing states over their own laws, and reasonably speaking, we are still in relatively early innings on the regulatory front while for many still feeling very far behind. The durable move in that environment is to build the operational foundation that lets you respond to wherever the rules land: documented systems, a clear picture of which decisions AI is touching, and humans in the loop where the stakes are high. While that may be less satisfying than a clear finish line, it is also the only truly “durable” framework to apply at this moment.

Leave a Reply

Discover more from Annie Tsai

Subscribe now to keep reading and get access to the full archive.

Continue reading