Insights

The deadlines keep moving. The readiness doesn’t.

Plain-English briefings on AI regulation and assurance — written for the people accountable, not the people impressed by jargon. Current as of July 2026.

BRIEFING 12

Illinois SB 315: independent AI audits are now law

Signed July 6, 2026 — the first US law requiring regular independent third-party AI safety audits. Effective Jan 1, 2027, with the audit duty on large frontier developers from Jan 1, 2028. Who it binds, and (honestly) who it doesn’t.

Read briefing →
THREAT BRIEF

The agentic attack surface stopped being theoretical

A Langflow authorization bypass added to CISA KEV and exploited since late June, the first reported LLM-driven ransomware operation, and injection hidden in images. The attack surface moved up a layer — to the agent.

Read briefing →
THREAT BRIEF

Ghostcommit: prompt injection hidden inside an image

Researchers made AI coding agents leak .env secrets from a payload buried in a PNG. A research demo — but the real finding is that the same model behaved differently depending on the agent around it.

Read briefing →
BRIEFING 11

AI in prior authorization: a licensed human is back in the loop

A 2026 wave of state laws — Washington SB 5395 (in force June 11), California SB 1120 and more — lets AI assist utilization review but requires a licensed clinician to own any medical-necessity denial. What that takes to prove.

Read briefing →
BRIEFING 10

New Jersey: no AI Act, but AI hiring tools are now liable

No standalone statute — but December 2025 disparate-impact rules (N.J.A.C. 13:16) reach automated hiring tools, and “reasonable steps” aren’t a defense if the outcome still discriminates.

Read briefing →
BRIEFING 09

Utah’s AI Policy Act: the lightest lift, with a catch

The first state AI law, narrowed in 2025 to high-risk interactions with an easy safe harbor — but consumer and mental-health chatbots still carry concrete disclosure duties.

Read briefing →
BRIEFING 08

California isn’t one AI law — it’s a stack

Several overlapping laws hitting different actors at different times. For most employers the live exposure is the FEHA ADS employment regs (in force since Oct 1, 2025); the Transparency Act lands Aug 2, 2026.

Read briefing →
BRIEFING 07

Illinois HB 3773: AI in hiring is now a civil-rights issue

In force since January 1, 2026. Using AI in employment decisions that discriminates — even unintentionally — violates the Human Rights Act, and you must give notice.

Read briefing →
BRIEFING 06

Texas TRAIGA: in force, and narrower than you feared

Effective January 1, 2026. Intent-based duties, AG enforcement, no private lawsuits — but the disclosure and documentation rules still assume you can describe your AI.

Read briefing →
BRIEFING 05

Connecticut’s CART Act: the broadest state AI law yet

Signed June 2, 2026, with obligations phasing in from October 2026. What deployers and developers face — and why it leans on disclosure, not bias audits.

Read briefing →
BRIEFING 04

NIST AI RMF as safe harbor

Texas’s TRAIGA is in force now and rewards NIST alignment. What the safe harbor gives you — and what it doesn’t.

Read briefing →
BRIEFING 03

ISO/IEC 42001 in plain English

What certification actually requires — clause by clause, Annex A and all — without the consultant fog.

Read briefing →
BRIEFING 02

The EU AI Act’s August 2 date, honestly

The date is real — but high-risk obligations were deferred to December 2027. What still bites, and whether it reaches a US company.

Read briefing →
BRIEFING 01

Colorado’s AI Act: delayed, paused, replaced

The deadline moved three times and a court froze the law. What deployers actually face now under SB 26-189 (effective Jan 1, 2027).

Read briefing →

Want these mapped to your business?
Start with the free call.

The AI Risk Exposure call: we walk your AI footprint, flag your likely obligations, and tell you plainly whether and where you need help.

Book the call →