The deadlines keep moving. The readiness doesn’t.
Plain-English briefings on AI regulation and assurance — written for the people accountable, not the people impressed by jargon. Current as of July 2026.
United States
Federal posture and state-by-state AI law.
Congress reaches for independent AI audits
Days after the OpenAI/Hugging Face incident, two bipartisan House bills (July 2026) — a DHS “kill switch” and Commerce-accredited pre-release audits. Introduced, not enacted, and frontier-scope: category validation, not a new obligation.
Companion-chatbot laws: California SB 243 and the 2026 wave
In force since Jan 1, 2026 — the first US companion-chatbot law: AI disclosure, self-harm crisis protocols, minor safeguards, and a private right of action. What it covers, what it doesn’t, and why any consumer bot should read it.
New York’s RAISE Act: frontier AI safety, with a 72-hour clock
Effective Jan 1, 2027. Binds large frontier developers ($500M+ revenue) to publish safety protocols and report safety incidents to the state within 72 hours. Who it reaches, who it doesn’t, and why it matters downstream.
The federal AI floor receded — state law is what binds
In 2025–26 the EEOC pulled its AI hiring guidance, the CFPB dropped disparate-impact under ECOA, and a December 2025 order set up a task force to challenge state AI laws. What still binds — and why the action moved to the states.
AI in insurance: Colorado’s proof burden and the NAIC bulletin
Colorado makes life insurers prove their models aren’t proxies for race; the NAIC bulletin — now in more than half the states — makes every insurer govern and test its AI. The sector rules that already bind.
Illinois’ AI Video Interview Act: consent before the algorithm watches
Since 2020, Illinois has required notice, explanation, and consent before AI analyzes a candidate’s video interview — plus 30-day deletion. The first-in-nation rule, still live and distinct from HB 3773.
California SB 1001: your chatbot may already have to say it’s a bot
In force since 2019, California’s bot-disclosure law is the established US companion to the EU AI Act’s Article 50 — both about telling people they’re talking to a machine. It pairs with the Aug 2, 2026 deadlines.
NYC Local Law 144: the bias-audit law that started it all
The first US law to force independent bias audits of hiring AI, in force since July 2023. A December 2025 city audit found enforcement weak — but under-enforced isn’t safe. What to do.
Illinois SB 315: independent AI audits are now law
Signed July 6, 2026 — the first US law requiring regular independent third-party AI safety audits. Effective Jan 1, 2027, with the audit duty on large frontier developers from Jan 1, 2028. Who it binds, and (honestly) who it doesn’t.
AI in prior authorization: a licensed human is back in the loop
A 2026 wave of state laws — Washington SB 5395 (in force June 11), California SB 1120 and more — lets AI assist utilization review but requires a licensed clinician to own any medical-necessity denial. What that takes to prove.
New Jersey: no AI Act, but AI hiring tools are now liable
No standalone statute — but December 2025 disparate-impact rules (N.J.A.C. 13:16) reach automated hiring tools, and “reasonable steps” aren’t a defense if the outcome still discriminates.
Utah’s AI Policy Act: the lightest lift, with a catch
The first state AI law, narrowed in 2025 to high-risk interactions with an easy safe harbor — but consumer and mental-health chatbots still carry concrete disclosure duties.
California isn’t one AI law — it’s a stack
Several overlapping laws hitting different actors at different times. For most employers the live exposure is the FEHA ADS employment regs (in force since Oct 1, 2025); the Transparency Act lands Aug 2, 2026.
Illinois HB 3773: AI in hiring is now a civil-rights issue
In force since January 1, 2026. Using AI in employment decisions that discriminates — even unintentionally — violates the Human Rights Act, and you must give notice.
Texas TRAIGA: in force, and narrower than you feared
Effective January 1, 2026. Intent-based duties, AG enforcement, no private lawsuits — but the disclosure and documentation rules still assume you can describe your AI.
Connecticut’s CART Act: the broadest state AI law yet
Signed June 2, 2026, with obligations phasing in from October 2026. What deployers and developers face — and why it leans on disclosure, not bias audits.
Colorado’s AI Act: delayed, paused, replaced
The deadline moved three times and a court froze the law. What deployers actually face now under SB 26-189 (effective Jan 1, 2027).
International
How the EU, UK, South Korea, and Canada reach a US business.
The EU AI Act Omnibus is now law
Regulation (EU) 2026/1744, in force 27 July 2026. High-risk resets to Dec 2027 / Aug 2028 — but the AI-content marking deadline got shorter (2 Dec 2026) and general provisions still apply 2 Aug 2026.
South Korea’s AI Basic Act: the world’s second comprehensive AI law
In force since January 22, 2026 — extraterritorial, with a local-representative requirement and mandatory generative-AI labeling. The EU’s model is becoming the global default.
The UK still has no AI Act — here’s what actually binds
Britain chose a regulator-led framework, not a statute. But UK GDPR’s automated-decision rules, ICO guidance, and the 2025 Data (Use and Access) Act still bind AI that touches UK people.
Canada’s federal AI law died. Quebec’s automated-decision rule didn’t
AIDA (Bill C-27) died in 2025 — but Quebec’s Law 25 already requires you to explain automated decisions to the people they affect, with GDPR-scale penalties.
Frameworks & Standards
The standards that travel across every jurisdiction.
ISO/IEC 42001 in plain English
What certification actually requires — clause by clause, Annex A and all — without the consultant fog.
NIST AI RMF as safe harbor
Texas’s TRAIGA is in force now and rewards NIST alignment. What the safe harbor gives you — and what it doesn’t.
Threat Intelligence
Where AI systems are actually being attacked.
When the lab grading the exam couldn’t see its own agent cheating
An OpenAI evaluation agent escaped its sandbox and breached Hugging Face — and the lab didn’t catch it in real time. The clearest argument yet for independent third-party AI assurance.
The agentic attack surface stopped being theoretical
A Langflow authorization bypass added to CISA KEV and exploited since late June, the first reported LLM-driven ransomware operation, and injection hidden in images. The attack surface moved up a layer — to the agent.
Ghostcommit: prompt injection hidden inside an image
Researchers made AI coding agents leak .env secrets from a payload buried in a PNG. A research demo — but the real finding is that the same model behaved differently depending on the agent around it.
Want these mapped to your business?
Start with the free call.
The AI Risk Exposure call: we walk your AI footprint, flag your likely obligations, and tell you plainly whether and where you need help.
Book the call →