---
title: "Halfway Through 2026, AI Regulation Is No Longer Theoretical"
description: "The second half of 2026 brings hard deadlines, so if you're still treating AI laws as a planning exercise, it's time to start operationalizing them. On both sides of the Atlantic, rules are landing, t..."
url: https://kaynemcgladrey.com/blog/halfway-through-2026-ai-regulation-is-no-longer-theoretical/
date: 2026-08-10
modified: 2026-08-10
author: "Kayne"
image: https://kaynemcgladrey.com/wp-content/uploads/2026/08/theatre.webp
categories: ["Blog"]
type: post
lang: en
---

# Halfway Through 2026, AI Regulation Is No Longer Theoretical

The second half of 2026 brings hard deadlines, so if you’re still treating AI laws as a planning exercise, it’s time to start operationalizing them. On both sides of the Atlantic, rules are landing, though they arrive in different shapes. The US is building a patchwork of federal directives and state laws. The EU is phasing its AI Act in layers, activating transparency rules while pushing high-risk obligations further down the road.

This is terrain mapping, not legal advice; if you’re a CISO and aren’t friends with your general counsel, you should fix that.

### The US Picture: Federal Signals and State Noise

President Trump signed an executive order on June 2, 2026 titled [Promoting Advanced AI Innovation and Security](https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/). It creates two oversight mechanisms and sharpens criminal enforcement, all without imposing direct compliance burdens on most businesses:

- Developers of frontier models can volunteer for 30-day pre-release reviews
- The US Department of Treasury, NSA, and CISA must establish an AI Cybersecurity Clearinghouse (the platform launched July 14 under the name [Gold Eagle](https://www.whitehouse.gov/releases/2026/07/white-house-launches-gold-eagle-initiative-for-unprecedented-cybersecurity-vulnerability-coordination/))
- Criminal enforcement priorities focus on the Computer Fraud and Abuse Act and wire fraud statutes

Real pressure is at the state level, where the US is taking the same fifty-state approach to AI that it took to privacy and data breach notification laws. Definitions, thresholds, and enforcement mechanisms vary from state to state and often overlap. Compliance officers will need to know exactly where their customers live to determine applicable notices.

Connecticut, Colorado, and Illinois lead the charge with distinct obligations:

- [Connecticut (SB 5)](https://legiscan.com/CT/bill/SB00005/2026): automated employment decision tool (AEDT) [disclosure requirements](https://kaynemcgladrey.com/blog/liability-shifts-hourly-nudges-and-the-tobacco-style-warning-in-connecticuts-new-ai-law/) for employment decisions start October 1, 2027. Subscription providers must also disclose material limitations before charging fees. Employment technology violations before December 31, 2027, get a 60-day cure period.
- [Colorado AI Data and Model Act (CADMA)](https://leg.colorado.gov/bills/SB26-189): [Revised](https://kaynemcgladrey.com/blog/ai-wins-in-colorado-legislature/) SB 26-189 focuses on disclosure for consequential decisions in housing, lending, and healthcare. Effective January 1, 2027.
- [Illinois](https://legiscan.com/IL/bill/SB0315/2025): The third state with a frontier model safety law. Large frontier developers earning over $500 million annually must retain independent third parties for annual audits starting January 1, 2028.

Nearly 100 chatbot bills appeared across 34 states in 2026, and thirteen states enacted laws requiring AI disclosure and protections for minors. Operators must tell users they are speaking with a bot. Some states prohibit chatbots from claiming to be licensed mental health professionals. Many laws exempt routine customer service tools.

### The EU Picture: Rules Ready, Institutions Waiting

Article 50 of the EU AI Act started applying August 2, 2026. Providers must disclose when humans interact with AI systems, synthetic content requires machine-readable marking, and emotion recognition systems must inform individuals. Administrative fines reach 15 million euros or 3 percent of global annual turnover.

But the high-risk obligations missed this window. Biometrics, employment, and border management rules were due on August 2, but got pushed to December 2, 2027 via the Digital Omnibus package. Member states hadn’t designated national enforcement authorities, and technical standards remained unfinished. For a deeper look at the Digital Omnibus delay and what it actually means, see [this prior analysis](https://kaynemcgladrey.com/blog/the-eu-ai-act-delay-that-wasnt-a-loophole/).

The EU AI Act rolls out in phases:

- Prohibited practices and AI literacy began February 2025
- General-purpose AI rules followed in August 2025
- Transparency requirements took effect August 2, 2026
- High-risk obligations land December 2027

Transparency works even without full governance, but accountability needs a forum. For example, Australia ran [an automated welfare debt recovery scheme](https://www.bbc.com/news/world-australia-66130105) between 2016 and 2019 that used income averaging to calculate debts while shifting the burden of disproving them onto recipients. The scheme recovered roughly 1.76 billion Australian dollars in debts, which were later found to be unlawfully raised, with repayment and compensation eventually exceeding 2.4 billion Australian dollars. The reason was that no competent body existed to compel evidence or stop the scheme while it was running. A royal commission later described the process as “neither fair nor legal”.

So that we’re not doing compliance theater again, every high-risk deployment should have an institutional forum in place before it goes live, one that can demand explanations and order remediation.

### How the Jurisdictions Stack Up

The US and EU share a common worry about AI risks, but they diverge sharply on structure and philosophy. The table below summarizes where things stand as of August 2026.

| Dimension | United States (H2 2026) | European Union (H2 2026) |
| --- | --- | --- |
| **Approach** | Fragmented: Federal EO + fifty-state patchwork (mirroring privacy law trajectory) | Unified single framework, phased rollout |
| **Key 2026 Action** | Trump AI EO (June 2): Voluntary pre-release review, AI Cyber Clearinghouse | AI Act transparency (Aug 2): chatbot disclosure, synthetic content marking |
| **Transparency** | State chatbot laws (13 states enacted); CT AEDT disclosure | Article 50: AI interaction disclosure, biometric processing notice |
| **Enforcement** | State AGs (CT, CO, IL); no private right of action | Admin fines up to EUR 15M or 3% global turnover; national authorities pending |
| **Timing Gaps** | CT AEDT (Oct 2027), CO CADMA (Jan 2027), IL audits (Jan 2028) | High-risk obligations delayed 16 months because institutions weren’t ready |
| **Core Problem** | Overlapping state-by-state burden, inconsistent definitions | Statutory ambition outpacing enforcement capacity |

The Brussels Effect often pushes companies to adopt one global standard for transparency rather than maintaining separate versions. But the EU’s strongest protections stop at its border, particularly for migration tech deployed in third countries.

Neither jurisdiction is going to be done with AI laws soon. The US will keep layering on state laws, exactly as it did with privacy, until compliance becomes a fifty-state exercise. The EU is going to be sixteen months late in standing up the institutions its high-risk rules depend on. Organizations operating across both regions face a moving target where definitions shift, timelines change, and enforcement mechanisms differ. Awareness isn’t compliance, but it is the prerequisite.
