Two things changed for businesses in 2026. On 2 August, the European Union switched on the part of its AI Act that most companies actually touch: the duty to tell people when they are dealing with a machine, and to mark AI-generated content. On the same map, the heavy rules for so-called high-risk systems were pushed back by more than a year.
In the United States the direction went the other way. Washington began challenging state AI laws, while states kept passing their own. Colorado scrapped the law it had just written and replaced it with a lighter one. Texas started enforcing a new act on 1 January. California switched on a stack of rules.
This guide explains what is actually in force right now, what was delayed, and what a small or mid-sized business should do about it. No legal background needed. If you want the deeper decision framework behind prioritising this work, see our guide on AI decision making.
Key Takeaways
- EU transparency duties are live since 2 August 2026. High-risk rules moved to December 2027.
- Your obligations depend on what your AI does, not on how advanced it is.
- US state law is the binding layer today, and it is still moving.
- An inventory of your AI systems is the one task every regime expects.
- Documentation you keep anyway is cheaper than documentation you reconstruct under audit.
Who this actually applies to
Most companies assume AI rules are aimed at the labs that build the models. That is only half right. The newer laws split responsibility between the developer, meaning whoever builds and supplies the system, and the deployer, meaning whoever puts it to work on real people. If you bought a hiring tool, a support chatbot or a credit-scoring add-on, you are the deployer, and duties land on you.
Three questions decide how much of this matters to your business:
- Does your AI talk to people? Chatbots, voice agents and AI-written replies now trigger disclosure duties in the EU and in several US states.
- Does it produce synthetic content? Generated images, audio, video or text carry marking and labelling duties.
- Does it influence a consequential decision? Hiring, firing, pay, lending, insurance, housing, healthcare, education. This is where the strictest rules sit everywhere.
If you answered no to all three, your exposure is low and general privacy law is your main concern. If you answered yes to the third, treat that system as your priority and work outward from it. Our overview of AI hiring tools shows how quickly one bought tool can pull an ordinary employer into scope.
The EU AI Act: what is live and what was delayed
The EU AI Act sorts systems into risk tiers and attaches duties to each tier. A spam filter sits at the bottom with almost nothing to do. A CV-screening tool sits near the top. In 2026 the two ends of that scale moved in opposite directions.
Live since 2 August 2026: transparency
Article 50, the transparency article, now applies. In plain terms:
- People must be told when they are interacting with an AI system, unless it is obvious.
- Synthetic audio, image, video and text must carry machine-readable marking that identifies it as AI-generated.
- Deepfakes and manipulated media must be disclosed as such.
- People exposed to emotion recognition or biometric categorisation must be told.
A four-month grace period runs to 2 December 2026 for marking on generative systems that were already on the market before August. National authorities can fine transparency breaches up to 15 million euros or 3% of worldwide annual turnover, whichever is higher (for small and medium enterprises, whichever is lower).
From the same date the European Commission’s AI Office can enforce against providers of general-purpose models: requesting documentation, running its own evaluations and imposing fines. The obligations on those model providers had already applied since August 2025. What arrived in 2026 was the power to act on them.
Delayed to December 2027: the high-risk rules
The chapter everyone was preparing for did not arrive. Under the Digital Omnibus agreement reached on 6 May 2026 and confirmed by member states on 13 May, the duties for Annex III high-risk systems, which cover employment, credit, education, essential services and similar uses, moved from 2 August 2026 to 2 December 2027. High-risk AI embedded in regulated products under Annex I moved to 2 August 2028.
Read the delay as breathing room, not a cancellation. The substance was not softened much: risk management files, data governance, testing records, human oversight and conformity assessment are still coming. Companies that use the extra time to build the evidence trail will have a far cheaper 2027 than those that stop work. Our dedicated guide to EU AI Act compliance walks through the tiers in more detail.
Why a US company still has to care
The Act follows the market, not the server. If your product is placed on the EU market, or its output is used in the EU, you are in scope even with everything hosted in Ohio. That is the same logic that made GDPR a global standard, and it is why many companies build to the EU line once and apply it everywhere. Related duties around where data physically sits are covered in our piece on data localization laws.
The United States: Washington pushes back, states keep legislating
There is still no comprehensive federal AI statute. What exists is enforcement under laws that already applied, plus an active effort to stop states from filling the gap.
Executive Order 14365, signed on 11 December 2025, directed the Attorney General to set up an AI Litigation Task Force to challenge state AI laws, told the Commerce Department to identify state rules it considers onerous, and tied some federal funding decisions to whether a state’s AI framework matches federal policy. It also pushed the FTC and FCC to issue AI-related guidance.
An executive order is not preemption. In the US system, federal law overrides state law when Congress passes it, not when the White House prefers it. Until Congress acts, Colorado’s, California’s and Texas’s rules remain the law where you operate. Plan for the rules on the books, and treat the federal fight as a reason to keep your compliance approach flexible rather than a reason to wait.
Meanwhile the volume keeps rising. Lawmakers in 45 states introduced 1,561 AI-related bills by March 2026, already more than the 1,208 introduced across all of 2025, of which 145 became law.
The state laws that actually bind you
Colorado changed course
Colorado wrote the first broad US AI law, SB 24-205, then never let it take effect. After two delays it was replaced by Senate Bill 26-189, which takes effect on 1 January 2027. The new law drops the duty of care, the mandatory impact assessments and the NIST-based compliance presumption. What survives is disclosure: developers and deployers of automated decision technology must give advance notice when the tool influences a consequential decision in employment, education, housing, finance, insurance, healthcare or government services, and must explain the outcome within 30 days when the result is adverse.
The practical lesson is not about Colorado. It is that a law can be rewritten twice before it ever binds anyone, so build controls that are useful on their own terms rather than tuned to one statute.
California switched on a stack of rules
California moved fastest and narrowest, targeting specific harms instead of a single framework. Effective 1 January 2026:
- AB 2013 requires public summaries of the data used to train generative systems: sources, whether personal information is included, and licensing status.
- SB 53 requires the largest frontier developers, above 500 million dollars in annual revenue, to publish how they manage catastrophic risk.
- SB 243 sets disclosure rules and minor-safety duties for companion chatbots.
- AB 316 removes “the AI did it on its own” as a legal defence.
- AB 325 makes shared pricing algorithms usable as evidence of price fixing.
- AB 489 stops AI tools from implying licensed medical oversight that does not exist.
The California AI Transparency Act (SB 942) was amended by AB 853 and now applies from 2 August 2026, requiring providers of large generative platforms to offer detection tools and provenance disclosure.
Texas took the intent route
The Texas Responsible AI Governance Act (HB 149) has been in force since 1 January 2026. It bans AI built with specific harmful intent, such as inciting self-harm, unlawful discrimination or the production of exploitative material, and it puts extra disclosure and biometric limits on government bodies. The intent standard matters: Texas requires proof of discriminatory purpose rather than disparate impact, which is a lower bar for businesses than the EU model.
The Attorney General enforces it exclusively, with a 60-day cure period, no private lawsuits, and penalties from 10,000 dollars for curable breaches up to 200,000 dollars for uncurable ones. A 36-month regulatory sandbox lets approved companies test systems with enforcement immunity for core testing activity.
Living with the patchwork
You cannot run one policy per state without drowning in it. The workable pattern is a single internal baseline set at the strictest requirement you face, plus thin state overlays for the few duties that are genuinely local, such as California’s training data summaries or Colorado’s adverse-decision notice. A structured risk management framework gives you somewhere to hang those overlays.
The rest of the world in brief
United Kingdom: still no AI act, and none announced. Existing regulators apply existing law. The UK GDPR and the Data (Use and Access) Act 2025 carry most of the weight, with the Information Commissioner’s Office preparing a statutory AI code and sector regulators publishing their own expectations. An AI Growth Lab launched in June 2026 to offer regulatory sandboxes, beginning with legal services.
Canada: the Artificial Intelligence and Data Act lapsed in January 2025 and was not revived. The refreshed national strategy published on 4 June 2026 chose targeted legislation on specific problems, such as deepfakes and surveillance pricing, over one comprehensive act, and funded a Canadian AI Safety Institute to evaluate models. If you sell to the federal government, the Directive on Automated Decision-Making still sets the bar for impact assessments and documentation.
China: labelling of AI-generated and synthetic content has been mandatory since 1 September 2025, alongside earlier rules on deep synthesis and recommendation algorithms. If your service reaches Chinese users, provenance marking is not optional.
Brazil: Bill 2338/2023 passed the Senate and is still working through the Chamber of Deputies. It follows the EU risk-tier model and would create a national oversight body, so treat it as a likely future obligation rather than a current one.
International: the Council of Europe Framework Convention on AI, the first binding international treaty in this area, was ratified by the European Union on 15 May 2026. It sets human rights and rule-of-law expectations that national laws are then expected to reflect.
The duties that repeat everywhere
Look past the individual statutes and the same handful of obligations keeps appearing. Build these once and you cover most of the map.
Tell people what is happening
Disclosure is the single most common duty. Label AI-generated content, say when a chatbot is a chatbot, and keep the notice where the user actually is rather than buried in terms of service. If your teams produce content with AI, a written policy such as our generative AI usage guidelines keeps practice consistent.
Know what your models were trained on
California already requires public training data summaries and the EU expects traceable data lineage for high-risk systems. Record sources, licences, whether personal data is present, and what you removed. Retrofitting this later is the expensive version. A working data governance strategy is what makes it routine.
Test for bias and keep a human in the loop
For anything touching hiring, credit, housing or health, run bias testing before launch and on a schedule, keep version-stamped results, and give people a real route to challenge an outcome. Our piece on AI hiring bias covers what those tests should look for. Being able to explain a decision in plain language is now a compliance asset as much as a technical one, which is why explainable AI has moved from research topic to procurement question.
Handle IP, likeness and privacy properly
Secure permissions for training and output use, log what you used, and align with likeness and publicity rules that several states have tightened. Standard privacy discipline applies on top: minimise, restrict access, set retention. Our guides to privacy compliance and data privacy at work cover the overlap.
Watch monitoring and management tools especially closely
Tools that observe or direct employees attract regulators faster than almost anything else. If you run them, read our coverage of AI employee monitoring and algorithmic management before you expand their use.
A four-step readiness playbook
Start with a map, then turn it into habits. This is the same sequence that works whether you have three AI tools or three hundred.
1. Inventory and classify
List every AI system in use, including the ones bought as features inside other software. For each one record the purpose, what data goes in, what comes out, and which decisions it touches. Then tag it: does it talk to people, generate content, or influence a consequential decision? Shadow tools are the usual blind spot here, and our article on shadow IT in remote teams explains how they accumulate.
2. Control the model lifecycle
Define what gets tested before a system goes live and what gets retested after every meaningful change. Add adversarial testing for anything customer-facing. Write an incident procedure before you need one, covering who is told, how fast, and what gets logged. An automation risk assessment is a practical starting template.
3. Centralise the paperwork
Keep model descriptions, data lineage, test results and change logs in one place your teams can actually find. Publish a short internal policy stack: acceptable use, vendor standards, employee guidance. Most audit pain comes from evidence that exists but cannot be produced. Our AI governance model shows one way to structure it.
4. Assign accountability
Name an owner for each system and a small group that reviews new deployments. Keep an approval trail and a clear escalation path. Larger organisations increasingly formalise this in a role: see our profile of the AI ethics officer. A written AI ethics framework gives that group something to decide against.
What to do in the next 90 days
- Finish the inventory. Nothing else works without it, and it usually takes two weeks, not two quarters.
- Fix disclosure first. It is the cheapest fix and the one already enforceable. Check every chatbot, generated image and AI-written message.
- Pick your highest-risk system and build the full evidence pack for it: purpose, data, tests, oversight, incident plan. Use it as the template for everything else.
- Push duties into vendor contracts. You are liable as a deployer; your supplier should be contractually obliged to give you the documentation you need.
- Set a review date. Two rules changed inside six months in 2026. Whatever you write today needs a scheduled re-read.
Conclusion
The uncertainty is real, but it is not an excuse to wait. Deadlines moved in 2026 and will move again. The underlying expectations did not: know what your AI systems do, tell people when AI is involved, test the ones that affect lives, and be able to show your work.
Those are also the things that make AI projects work rather than merely legal. An inventory tells you what you are paying for. Testing catches failures before customers do. Documentation is what lets a new hire maintain a system nobody remembers building. That overlap is the practical case for starting now, and it is visible across the wider shifts we track in AI in business operations and future of work legislation.
Found this useful?
Make SmartKeys a preferred source on Google, and our articles will surface more often in your Top Stories, AI Overviews, and AI Mode.
Add as Preferred Source







