AI Regulation 2026: Preparing Your Business for New Rules

Infographic on a four-step AI readiness playbook next to a globe showing how EU, US, UK and China rules differ


Two things changed for businesses in 2026. On 2 August, the European Union switched on the part of its AI Act that most companies actually touch: the duty to tell people when they are dealing with a machine, and to mark AI-generated content. On the same map, the heavy rules for so-called high-risk systems were pushed back by more than a year.

In the United States the direction went the other way. Washington began challenging state AI laws, while states kept passing their own. Colorado scrapped the law it had just written and replaced it with a lighter one. Texas started enforcing a new act on 1 January. California switched on a stack of rules.

This guide explains what is actually in force right now, what was delayed, and what a small or mid-sized business should do about it. No legal background needed. If you want the deeper decision framework behind prioritising this work, see our guide on AI decision making.

Key Takeaways

  • EU transparency duties are live since 2 August 2026. High-risk rules moved to December 2027.
  • Your obligations depend on what your AI does, not on how advanced it is.
  • US state law is the binding layer today, and it is still moving.
  • An inventory of your AI systems is the one task every regime expects.
  • Documentation you keep anyway is cheaper than documentation you reconstruct under audit.

Who this actually applies to

Most companies assume AI rules are aimed at the labs that build the models. That is only half right. The newer laws split responsibility between the developer, meaning whoever builds and supplies the system, and the deployer, meaning whoever puts it to work on real people. If you bought a hiring tool, a support chatbot or a credit-scoring add-on, you are the deployer, and duties land on you.

Three questions decide how much of this matters to your business:

  1. Does your AI talk to people? Chatbots, voice agents and AI-written replies now trigger disclosure duties in the EU and in several US states.
  2. Does it produce synthetic content? Generated images, audio, video or text carry marking and labelling duties.
  3. Does it influence a consequential decision? Hiring, firing, pay, lending, insurance, housing, healthcare, education. This is where the strictest rules sit everywhere.

If you answered no to all three, your exposure is low and general privacy law is your main concern. If you answered yes to the third, treat that system as your priority and work outward from it. Our overview of AI hiring tools shows how quickly one bought tool can pull an ordinary employer into scope.

The EU AI Act: what is live and what was delayed

The EU AI Act sorts systems into risk tiers and attaches duties to each tier. A spam filter sits at the bottom with almost nothing to do. A CV-screening tool sits near the top. In 2026 the two ends of that scale moved in opposite directions.

Live since 2 August 2026: transparency

Article 50, the transparency article, now applies. In plain terms:

  • People must be told when they are interacting with an AI system, unless it is obvious.
  • Synthetic audio, image, video and text must carry machine-readable marking that identifies it as AI-generated.
  • Deepfakes and manipulated media must be disclosed as such.
  • People exposed to emotion recognition or biometric categorisation must be told.

A four-month grace period runs to 2 December 2026 for marking on generative systems that were already on the market before August. National authorities can fine transparency breaches up to 15 million euros or 3% of worldwide annual turnover, whichever is higher (for small and medium enterprises, whichever is lower).

From the same date the European Commission’s AI Office can enforce against providers of general-purpose models: requesting documentation, running its own evaluations and imposing fines. The obligations on those model providers had already applied since August 2025. What arrived in 2026 was the power to act on them.

Delayed to December 2027: the high-risk rules

The chapter everyone was preparing for did not arrive. Under the Digital Omnibus agreement reached on 6 May 2026 and confirmed by member states on 13 May, the duties for Annex III high-risk systems, which cover employment, credit, education, essential services and similar uses, moved from 2 August 2026 to 2 December 2027. High-risk AI embedded in regulated products under Annex I moved to 2 August 2028.

Read the delay as breathing room, not a cancellation. The substance was not softened much: risk management files, data governance, testing records, human oversight and conformity assessment are still coming. Companies that use the extra time to build the evidence trail will have a far cheaper 2027 than those that stop work. Our dedicated guide to EU AI Act compliance walks through the tiers in more detail.

Why a US company still has to care

The Act follows the market, not the server. If your product is placed on the EU market, or its output is used in the EU, you are in scope even with everything hosted in Ohio. That is the same logic that made GDPR a global standard, and it is why many companies build to the EU line once and apply it everywhere. Related duties around where data physically sits are covered in our piece on data localization laws.

The United States: Washington pushes back, states keep legislating

There is still no comprehensive federal AI statute. What exists is enforcement under laws that already applied, plus an active effort to stop states from filling the gap.

Executive Order 14365, signed on 11 December 2025, directed the Attorney General to set up an AI Litigation Task Force to challenge state AI laws, told the Commerce Department to identify state rules it considers onerous, and tied some federal funding decisions to whether a state’s AI framework matches federal policy. It also pushed the FTC and FCC to issue AI-related guidance.

An executive order is not preemption. In the US system, federal law overrides state law when Congress passes it, not when the White House prefers it. Until Congress acts, Colorado’s, California’s and Texas’s rules remain the law where you operate. Plan for the rules on the books, and treat the federal fight as a reason to keep your compliance approach flexible rather than a reason to wait.

Meanwhile the volume keeps rising. Lawmakers in 45 states introduced 1,561 AI-related bills by March 2026, already more than the 1,208 introduced across all of 2025, of which 145 became law.

The state laws that actually bind you

Colorado changed course

Colorado wrote the first broad US AI law, SB 24-205, then never let it take effect. After two delays it was replaced by Senate Bill 26-189, which takes effect on 1 January 2027. The new law drops the duty of care, the mandatory impact assessments and the NIST-based compliance presumption. What survives is disclosure: developers and deployers of automated decision technology must give advance notice when the tool influences a consequential decision in employment, education, housing, finance, insurance, healthcare or government services, and must explain the outcome within 30 days when the result is adverse.

The practical lesson is not about Colorado. It is that a law can be rewritten twice before it ever binds anyone, so build controls that are useful on their own terms rather than tuned to one statute.

California switched on a stack of rules

California moved fastest and narrowest, targeting specific harms instead of a single framework. Effective 1 January 2026:

  • AB 2013 requires public summaries of the data used to train generative systems: sources, whether personal information is included, and licensing status.
  • SB 53 requires the largest frontier developers, above 500 million dollars in annual revenue, to publish how they manage catastrophic risk.
  • SB 243 sets disclosure rules and minor-safety duties for companion chatbots.
  • AB 316 removes “the AI did it on its own” as a legal defence.
  • AB 325 makes shared pricing algorithms usable as evidence of price fixing.
  • AB 489 stops AI tools from implying licensed medical oversight that does not exist.

The California AI Transparency Act (SB 942) was amended by AB 853 and now applies from 2 August 2026, requiring providers of large generative platforms to offer detection tools and provenance disclosure.

Texas took the intent route

The Texas Responsible AI Governance Act (HB 149) has been in force since 1 January 2026. It bans AI built with specific harmful intent, such as inciting self-harm, unlawful discrimination or the production of exploitative material, and it puts extra disclosure and biometric limits on government bodies. The intent standard matters: Texas requires proof of discriminatory purpose rather than disparate impact, which is a lower bar for businesses than the EU model.

The Attorney General enforces it exclusively, with a 60-day cure period, no private lawsuits, and penalties from 10,000 dollars for curable breaches up to 200,000 dollars for uncurable ones. A 36-month regulatory sandbox lets approved companies test systems with enforcement immunity for core testing activity.

Living with the patchwork

You cannot run one policy per state without drowning in it. The workable pattern is a single internal baseline set at the strictest requirement you face, plus thin state overlays for the few duties that are genuinely local, such as California’s training data summaries or Colorado’s adverse-decision notice. A structured risk management framework gives you somewhere to hang those overlays.

The rest of the world in brief

United Kingdom: still no AI act, and none announced. Existing regulators apply existing law. The UK GDPR and the Data (Use and Access) Act 2025 carry most of the weight, with the Information Commissioner’s Office preparing a statutory AI code and sector regulators publishing their own expectations. An AI Growth Lab launched in June 2026 to offer regulatory sandboxes, beginning with legal services.

Canada: the Artificial Intelligence and Data Act lapsed in January 2025 and was not revived. The refreshed national strategy published on 4 June 2026 chose targeted legislation on specific problems, such as deepfakes and surveillance pricing, over one comprehensive act, and funded a Canadian AI Safety Institute to evaluate models. If you sell to the federal government, the Directive on Automated Decision-Making still sets the bar for impact assessments and documentation.

China: labelling of AI-generated and synthetic content has been mandatory since 1 September 2025, alongside earlier rules on deep synthesis and recommendation algorithms. If your service reaches Chinese users, provenance marking is not optional.

Brazil: Bill 2338/2023 passed the Senate and is still working through the Chamber of Deputies. It follows the EU risk-tier model and would create a national oversight body, so treat it as a likely future obligation rather than a current one.

International: the Council of Europe Framework Convention on AI, the first binding international treaty in this area, was ratified by the European Union on 15 May 2026. It sets human rights and rule-of-law expectations that national laws are then expected to reflect.

The duties that repeat everywhere

Look past the individual statutes and the same handful of obligations keeps appearing. Build these once and you cover most of the map.

Tell people what is happening

Disclosure is the single most common duty. Label AI-generated content, say when a chatbot is a chatbot, and keep the notice where the user actually is rather than buried in terms of service. If your teams produce content with AI, a written policy such as our generative AI usage guidelines keeps practice consistent.

Know what your models were trained on

California already requires public training data summaries and the EU expects traceable data lineage for high-risk systems. Record sources, licences, whether personal data is present, and what you removed. Retrofitting this later is the expensive version. A working data governance strategy is what makes it routine.

Test for bias and keep a human in the loop

For anything touching hiring, credit, housing or health, run bias testing before launch and on a schedule, keep version-stamped results, and give people a real route to challenge an outcome. Our piece on AI hiring bias covers what those tests should look for. Being able to explain a decision in plain language is now a compliance asset as much as a technical one, which is why explainable AI has moved from research topic to procurement question.

Handle IP, likeness and privacy properly

Secure permissions for training and output use, log what you used, and align with likeness and publicity rules that several states have tightened. Standard privacy discipline applies on top: minimise, restrict access, set retention. Our guides to privacy compliance and data privacy at work cover the overlap.

Watch monitoring and management tools especially closely

Tools that observe or direct employees attract regulators faster than almost anything else. If you run them, read our coverage of AI employee monitoring and algorithmic management before you expand their use.

A four-step readiness playbook

Start with a map, then turn it into habits. This is the same sequence that works whether you have three AI tools or three hundred.

1. Inventory and classify

List every AI system in use, including the ones bought as features inside other software. For each one record the purpose, what data goes in, what comes out, and which decisions it touches. Then tag it: does it talk to people, generate content, or influence a consequential decision? Shadow tools are the usual blind spot here, and our article on shadow IT in remote teams explains how they accumulate.

2. Control the model lifecycle

Define what gets tested before a system goes live and what gets retested after every meaningful change. Add adversarial testing for anything customer-facing. Write an incident procedure before you need one, covering who is told, how fast, and what gets logged. An automation risk assessment is a practical starting template.

3. Centralise the paperwork

Keep model descriptions, data lineage, test results and change logs in one place your teams can actually find. Publish a short internal policy stack: acceptable use, vendor standards, employee guidance. Most audit pain comes from evidence that exists but cannot be produced. Our AI governance model shows one way to structure it.

4. Assign accountability

Name an owner for each system and a small group that reviews new deployments. Keep an approval trail and a clear escalation path. Larger organisations increasingly formalise this in a role: see our profile of the AI ethics officer. A written AI ethics framework gives that group something to decide against.

What to do in the next 90 days

  1. Finish the inventory. Nothing else works without it, and it usually takes two weeks, not two quarters.
  2. Fix disclosure first. It is the cheapest fix and the one already enforceable. Check every chatbot, generated image and AI-written message.
  3. Pick your highest-risk system and build the full evidence pack for it: purpose, data, tests, oversight, incident plan. Use it as the template for everything else.
  4. Push duties into vendor contracts. You are liable as a deployer; your supplier should be contractually obliged to give you the documentation you need.
  5. Set a review date. Two rules changed inside six months in 2026. Whatever you write today needs a scheduled re-read.

Conclusion

The uncertainty is real, but it is not an excuse to wait. Deadlines moved in 2026 and will move again. The underlying expectations did not: know what your AI systems do, tell people when AI is involved, test the ones that affect lives, and be able to show your work.

Those are also the things that make AI projects work rather than merely legal. An inventory tells you what you are paying for. Testing catches failures before customers do. Documentation is what lets a new hire maintain a system nobody remembers building. That overlap is the practical case for starting now, and it is visible across the wider shifts we track in AI in business operations and future of work legislation.

Found this useful?

Make SmartKeys a preferred source on Google, and our articles will surface more often in your Top Stories, AI Overviews, and AI Mode.

Add as Preferred Source

FAQ

Does my small business actually have to comply with AI regulation in 2026?

Probably yes, but less than you fear. Size thresholds exist only in a few places, such as California’s frontier developer rules. Most duties attach to what the AI does rather than to how big you are. If you run a customer-facing chatbot, publish AI-generated content, or use a tool that helps decide who gets hired, credit or housing, obligations apply to you as the deployer even though someone else built the system. The realistic first step is a short inventory: list your AI tools, note which ones talk to people, generate content or touch consequential decisions, and start with those. A business with no AI in decision-making usually has only disclosure duties to handle.

What exactly changed under the EU AI Act on 2 August 2026?

Two things. First, the transparency duties in Article 50 became applicable: users must be told when they are dealing with an AI system, synthetic content must carry machine-readable marking, deepfakes must be disclosed, and people subject to emotion recognition or biometric categorisation must be informed. A grace period runs to 2 December 2026 for marking on generative systems already on the market. Second, the European Commission’s AI Office gained enforcement powers over providers of general-purpose AI models, including the ability to demand documentation, run evaluations and fine up to 15 million euros or 3% of worldwide turnover. The high-risk chapter did not start on that date.

Why were the EU high-risk rules delayed, and should I stop preparing?

The Digital Omnibus agreement, reached on 6 May 2026 and confirmed by member states on 13 May, pushed the Annex III high-risk obligations from 2 August 2026 to 2 December 2027, and the Annex I product-safety route to 2 August 2028. The main reasons cited were incomplete technical standards and unfinished guidance, which would have left companies unable to demonstrate conformity. You should not stop preparing. The substantive requirements, meaning risk management files, data governance, testing evidence, human oversight and conformity assessment, were largely retained. The delay converts a scramble into a manageable programme, and evidence collected now is evidence you will not have to reconstruct in 2027.

Does the EU AI Act apply to a US company with no European office?

It can. The Act follows the market rather than the location of your servers or staff. If you place an AI system or a general-purpose model on the EU market, or if the output of your system is used inside the EU, you fall within scope. That mirrors how GDPR reached companies with no European presence. In practice many US businesses set one internal baseline that meets EU expectations and apply it everywhere, then add narrow overlays for US state requirements. That is usually cheaper than maintaining two product behaviours, and it removes the risk of an EU customer quietly pulling you into scope.

Did the December 2025 executive order cancel state AI laws?

No. Executive Order 14365 set up an AI Litigation Task Force to challenge state AI laws in court, told the Commerce Department to flag state rules it considers onerous, and linked some federal funding to whether a state’s approach matches federal policy. It did not repeal anything. In the US system, federal preemption normally comes from legislation passed by Congress, not from an executive order. Colorado’s, California’s and Texas’s rules therefore remain enforceable where they apply. The practical takeaway is to comply with the laws currently on the books while keeping your controls flexible enough to survive the litigation and any future federal standard.

Which US state laws should I look at first?

Start with the three that are already operating or imminent. Texas has enforced the Responsible AI Governance Act since 1 January 2026, focused on AI built with harmful intent and enforced solely by the Attorney General with a 60-day cure period. California switched on several targeted laws on 1 January 2026, including training data disclosure under AB 2013, and its AI Transparency Act applies from 2 August 2026. Colorado replaced its original AI Act with Senate Bill 26-189, effective 1 January 2027, which keeps notice and adverse-decision explanation duties but drops the impact assessment mandate. Beyond those, check the states where your customers and employees actually are.

What documentation will regulators and enterprise customers ask for?

Broadly the same pack in every jurisdiction. Expect requests for a description of what each system does and where it is used, a record of the data behind it including sources and licensing, evidence of testing for accuracy and bias with dates and versions, a description of human oversight and how a person can contest an outcome, and an incident log with what happened and how it was fixed. Enterprise buyers now ask for this in procurement long before a regulator does, so a tidy evidence pack shortens sales cycles as well as audits. Keep it in one findable location rather than scattered across tickets and inboxes.

Who is responsible when we buy an AI tool rather than build it?

Both parties, in different ways. The vendor is the developer or provider and owes duties about how the system was built, tested and documented. You are the deployer and owe duties about how it is used: informing affected people, keeping oversight in place, monitoring real-world results and retaining records. You cannot contract your deployer duties away, but you can and should require the vendor to supply what you need to meet them. Ask for model documentation, bias testing results, data provenance summaries and an incident notification commitment in writing before signing, and check that the contract survives a change of ownership at the vendor.

Author

  • Felix Römer

    Felix is the founder of SmartKeys.org, where he explores the future of work, SaaS innovation, and productivity strategies. With over 15 years of experience in e-commerce and digital marketing, he combines hands-on expertise with a passion for emerging technologies. Through SmartKeys, Felix shares actionable insights designed to help professionals and businesses work smarter, adapt to change, and stay ahead in a fast-moving digital world. Connect with him on LinkedIn