The deadlines keep moving. The readiness doesn’t.
Plain-English briefings on AI regulation and assurance — written for the people accountable, not the people impressed by jargon. Current as of July 2026.
Illinois SB 315: independent AI audits are now law
Signed July 6, 2026 — the first US law requiring regular independent third-party AI safety audits. Effective Jan 1, 2027, with the audit duty on large frontier developers from Jan 1, 2028. Who it binds, and (honestly) who it doesn’t.
The agentic attack surface stopped being theoretical
A Langflow authorization bypass added to CISA KEV and exploited since late June, the first reported LLM-driven ransomware operation, and injection hidden in images. The attack surface moved up a layer — to the agent.
Ghostcommit: prompt injection hidden inside an image
Researchers made AI coding agents leak .env secrets from a payload buried in a PNG. A research demo — but the real finding is that the same model behaved differently depending on the agent around it.
AI in prior authorization: a licensed human is back in the loop
A 2026 wave of state laws — Washington SB 5395 (in force June 11), California SB 1120 and more — lets AI assist utilization review but requires a licensed clinician to own any medical-necessity denial. What that takes to prove.
New Jersey: no AI Act, but AI hiring tools are now liable
No standalone statute — but December 2025 disparate-impact rules (N.J.A.C. 13:16) reach automated hiring tools, and “reasonable steps” aren’t a defense if the outcome still discriminates.
Utah’s AI Policy Act: the lightest lift, with a catch
The first state AI law, narrowed in 2025 to high-risk interactions with an easy safe harbor — but consumer and mental-health chatbots still carry concrete disclosure duties.
California isn’t one AI law — it’s a stack
Several overlapping laws hitting different actors at different times. For most employers the live exposure is the FEHA ADS employment regs (in force since Oct 1, 2025); the Transparency Act lands Aug 2, 2026.
Illinois HB 3773: AI in hiring is now a civil-rights issue
In force since January 1, 2026. Using AI in employment decisions that discriminates — even unintentionally — violates the Human Rights Act, and you must give notice.
Texas TRAIGA: in force, and narrower than you feared
Effective January 1, 2026. Intent-based duties, AG enforcement, no private lawsuits — but the disclosure and documentation rules still assume you can describe your AI.
Connecticut’s CART Act: the broadest state AI law yet
Signed June 2, 2026, with obligations phasing in from October 2026. What deployers and developers face — and why it leans on disclosure, not bias audits.
NIST AI RMF as safe harbor
Texas’s TRAIGA is in force now and rewards NIST alignment. What the safe harbor gives you — and what it doesn’t.
ISO/IEC 42001 in plain English
What certification actually requires — clause by clause, Annex A and all — without the consultant fog.
The EU AI Act’s August 2 date, honestly
The date is real — but high-risk obligations were deferred to December 2027. What still bites, and whether it reaches a US company.
Colorado’s AI Act: delayed, paused, replaced
The deadline moved three times and a court froze the law. What deployers actually face now under SB 26-189 (effective Jan 1, 2027).
Want these mapped to your business?
Start with the free call.
The AI Risk Exposure call: we walk your AI footprint, flag your likely obligations, and tell you plainly whether and where you need help.
Book the call →