From Debate to Deadlines
Much of the AI policy conversation over the past two years has been about what regulation should look like. In 2026, that conversation is being overtaken by a more concrete one: several jurisdictions' AI-specific rules are now reaching their compliance deadlines, shifting the discussion from drafting to actually filing paperwork and changing products.
Who's Actually Covered
The rules that matter most apply narrowly, by design, to a small number of "frontier" model developers — companies training models above specific compute thresholds — plus a separate, broader set of disclosure requirements aimed at any company deploying AI in high-stakes contexts like hiring, lending, or healthcare. Most companies merely using off-the-shelf AI tools for ordinary business tasks fall outside the strictest provisions, despite some of the louder public commentary suggesting otherwise.
What Compliance Actually Looks Like
For covered frontier developers, the core requirements are incident reporting (disclosing serious safety incidents within a fixed window), model evaluation documentation before major releases, and in some jurisdictions, third-party audits of safety testing. For deployers in high-stakes sectors, the emphasis is on disclosure to affected individuals and the ability to explain automated decisions, not on AI development itself.
The Enforcement Reality
Early enforcement has been more about establishing process than issuing large penalties — regulators in this space have generally favored compliance conversations over headline fines in the first deadlines, a pattern consistent with how other new tech regulation has typically rolled out. That's expected to change as the frameworks mature and agencies build out enforcement capacity.
The Practical Read for Businesses
The operational lesson so far isn't "AI is now illegal to use without a license" — it's that companies deploying AI in regulated, high-stakes decisions need a documented basis for those decisions, and the handful of largest model developers face genuinely new reporting obligations. Everyone else's exposure is smaller than the more alarmist coverage has implied, though that could shift as more provisions phase in over the coming year.
The EU AI Act Compliance Calendar
The EU Artificial Intelligence Act is phasing in obligations on a staggered timeline. As of mid-2026:
February 2025 (already in force) — Prohibition on unacceptable-risk AI: social scoring systems, real-time biometric surveillance (with narrow law enforcement exceptions), subliminal manipulation, and exploitation of vulnerable groups are banned outright.
August 2025 (already in force) — General-Purpose AI (GPAI) model obligations: providers of GPAI models (including OpenAI, Anthropic, Google) must maintain technical documentation, comply with copyright law for training data, and publish summaries of training data used. Models classified as systemic-risk GPAIs (those trained with over 10^25 FLOPs) face additional obligations including adversarial testing and incident reporting.
August 2026 (current) — High-risk AI system requirements begin phasing in for systems in healthcare, employment, education, critical infrastructure, and law enforcement. These systems must undergo conformity assessment, maintain risk management documentation, implement human oversight mechanisms, and achieve CE marking for EU market access.
US Federal Activity
The US has taken a more fragmented approach. The October 2023 Executive Order on AI established reporting requirements for frontier AI developers (dual-use foundation models above computing thresholds must report to the government) and directed NIST to develop AI safety guidance. The subsequent NIST AI Risk Management Framework (AI RMF) is voluntary but widely adopted as a baseline by enterprise deployers.
Congress has not passed comprehensive AI legislation equivalent to the EU AI Act. Several bills have been introduced (the Bipartisan AI Transparency Act, the DEFIANCE Act on synthetic sexual imagery, the No AI FRAUD Act on voice/likeness) but none have advanced to a full floor vote. The regulatory patchwork means US-based AI companies face a complex mix of existing sectoral regulations (FTC Act, FCRA for credit, HIPAA for healthcare) rather than a unified AI-specific framework.














































































Commenting is currently unavailable on this article.