Insights

The deadlines keep moving. The readiness doesn’t.

Plain-English briefings on AI regulation and assurance, written for the people accountable, not the people impressed by jargon. Current as of August 2026.

United States

Federal posture and state-by-state AI law.

BRIEFING 25

The assurers are getting regulated too

Illinois mandates independent AI audits, California would make auditors enroll with the state, and Virginia is studying a licensing scheme. Three states in one year are regulating who may assure AI, and how.

Read briefing →
BRIEFING 24

No, Arizona didn’t ban AI in medical claims

Headlines say HB 2175 (in force July 1, 2026) banned AI from claim reviews. The enacted text never says “AI.” What it actually requires: a human with independent judgment must own a medical-necessity denial.

Read briefing →
BRIEFING 22

Missouri didn’t ban AI therapy. Something older already did.

The widely-cited Missouri “AI therapy ban” is not law: SB 1019 carries no AI provision and SB 1444 died in committee. What did pass (Vermont Act 156), and the consumer-protection rule that already reaches any AI marketed as a therapist.

Read briefing →
BRIEFING 23

Minnesota’s nudification law has real teeth

Minn. Stat. 325E.91, in force since Aug 1, 2026: up to $500,000 per incident, treble damages, and no intent requirement. The duty is on whoever runs the service, and a company with no Minnesota presence can still be in scope.

Read briefing →
BRIEFING 21

Colorado’s new AI-therapy line: assistant, not therapist

HB 26-1195 (effective Aug 12, 2026) bars AI from therapeutic communication, unsupervised treatment plans, or mental-state detection without a human professional. Who it reaches beyond Colorado, and how to prove a human stays in the loop.

Read briefing →
BRIEFING 20

Congress reaches for independent AI audits

Days after the OpenAI/Hugging Face incident, two bipartisan House bills (July 2026), a DHS “kill switch” and Commerce-accredited pre-release audits. Introduced, not enacted, and frontier-scope: category validation, not a new obligation.

Read briefing →
BRIEFING 19

Companion-chatbot laws: California SB 243 and the 2026 wave

In force since Jan 1, 2026, the first US companion-chatbot law: AI disclosure, self-harm crisis protocols, minor safeguards, and a private right of action. What it covers, what it doesn’t, and why any consumer bot should read it.

Read briefing →
BRIEFING 18

New York’s RAISE Act: frontier AI safety, with a 72-hour clock

Effective Jan 1, 2027. Binds large frontier developers ($500M+ revenue) to publish safety protocols and report safety incidents to the state within 72 hours. Who it reaches, who it doesn’t, and why it matters downstream.

Read briefing →
BRIEFING 17

The federal AI floor receded, state law is what binds

In 2025–26 the EEOC pulled its AI hiring guidance, the CFPB dropped disparate-impact under ECOA, and a December 2025 order set up a task force to challenge state AI laws. What still binds, and why the action moved to the states.

Read briefing →
BRIEFING 16

AI in insurance: Colorado’s proof burden and the NAIC bulletin

Colorado makes life insurers prove their models aren’t proxies for race; the NAIC bulletin, now in more than half the states, makes every insurer govern and test its AI. The sector rules that already bind.

Read briefing →
BRIEFING 15

Illinois’ AI Video Interview Act: consent before the algorithm watches

Since 2020, Illinois has required notice, explanation, and consent before AI analyzes a candidate’s video interview, plus 30-day deletion. The first-in-nation rule, still live and distinct from HB 3773.

Read briefing →
BRIEFING 14

California SB 1001: your chatbot may already have to say it’s a bot

In force since 2019, California’s bot-disclosure law is the established US companion to the EU AI Act’s Article 50, both about telling people they’re talking to a machine. It pairs with the Aug 2, 2026 deadlines.

Read briefing →
BRIEFING 13

NYC Local Law 144: the bias-audit law that started it all

The first US law to force independent bias audits of hiring AI, in force since July 2023. A December 2025 city audit found enforcement weak, but under-enforced isn’t safe. What to do.

Read briefing →
BRIEFING 12

Illinois SB 315: independent AI audits are now law

Signed July 6, 2026, the first US law requiring regular independent third-party AI safety audits. Effective Jan 1, 2027, with the audit duty on large frontier developers from Jan 1, 2028. Who it binds, and (honestly) who it doesn’t.

Read briefing →
BRIEFING 11

AI in prior authorization: a licensed human is back in the loop

A 2026 wave of state laws, Washington SB 5395 (in force June 11), California SB 1120 and more, lets AI assist utilization review but requires a licensed clinician to own any medical-necessity denial. What that takes to prove.

Read briefing →
BRIEFING 10

New Jersey: no AI Act, but AI hiring tools are now liable

No standalone statute, but December 2025 disparate-impact rules (N.J.A.C. 13:16) reach automated hiring tools, and “reasonable steps” aren’t a defense if the outcome still discriminates.

Read briefing →
BRIEFING 09

Utah’s AI Policy Act: the lightest lift, with a catch

The first state AI law, narrowed in 2025 to high-risk interactions with an easy safe harbor, but consumer and mental-health chatbots still carry concrete disclosure duties.

Read briefing →
BRIEFING 08

California isn’t one AI law, it’s a stack

Several overlapping laws hitting different actors at different times. For most employers the live exposure is the FEHA ADS employment regs (in force since Oct 1, 2025); the Transparency Act lands Aug 2, 2026.

Read briefing →
BRIEFING 07

Illinois HB 3773: AI in hiring is now a civil-rights issue

In force since January 1, 2026. Using AI in employment decisions that discriminates, even unintentionally, violates the Human Rights Act, and you must give notice.

Read briefing →
BRIEFING 06

Texas TRAIGA: in force, and narrower than you feared

Effective January 1, 2026. Intent-based duties, AG enforcement, no private lawsuits, but the disclosure and documentation rules still assume you can describe your AI.

Read briefing →
BRIEFING 05

Connecticut’s CART Act: the broadest state AI law yet

Signed June 2, 2026, with obligations phasing in from October 2026. What deployers and developers face, and why it leans on disclosure, not bias audits.

Read briefing →
BRIEFING 01

Colorado’s AI Act: delayed, paused, replaced

The deadline moved three times and a court froze the law. What deployers actually face now under SB 26-189 (effective Jan 1, 2027).

Read briefing →

International

How the EU, UK, South Korea, and Canada reach a US business.

INTL BRIEF · CHINA

China wrote the strictest companion-AI rulebook on earth

In force since July 15, 2026, the first national companion-AI regime anywhere. It makes the provider contact a user’s emergency contact in a crisis, gates model training on consent, and bans designed dependence.

Read briefing →
INTL BRIEF · INDIA

India now requires AI media to label itself

The amended IT Rules, in force since Feb 20, 2026, make platforms label synthetic audio and video, embed provenance, and block tampering, or lose safe harbour. No 10% watermark, and text output is not covered.

Read briefing →
INTL BRIEF

The Omnibus didn’t only delay things. It banned two more

The same regulation that delayed the high-risk rules quietly added two prohibited practices to Article 5, AI-generated NCII and CSAM, live Dec 2, 2026, in the €35M / 7% tier. Audio is in scope, and the provider test is far wider than the deployer test.

Read briefing →
INTL BRIEF

August 2: the EU AI Act gets teeth

The Commission’s GPAI enforcement powers switch on Aug 2, fines up to €15M or 3% of global turnover, AI Office gets exclusive jurisdiction. Plus the 8 concrete Omnibus changes, and what actually reaches a US company.

Read briefing →
INTL BRIEF

The EU AI Act Omnibus is now law

Regulation (EU) 2026/1744, in force 27 July 2026. High-risk resets to Dec 2027 / Aug 2028, but the AI-content marking deadline got shorter (2 Dec 2026) and general provisions still apply 2 Aug 2026.

Read briefing →
INTL BRIEF

South Korea’s AI Basic Act: the world’s second comprehensive AI law

In force since January 22, 2026, extraterritorial, with a local-representative requirement and mandatory generative-AI labeling. The EU’s model is becoming the global default.

Read briefing →
INTL BRIEF

The UK still has no AI Act, here’s what actually binds

Britain chose a regulator-led framework, not a statute. But UK GDPR’s automated-decision rules, ICO guidance, and the 2025 Data (Use and Access) Act still bind AI that touches UK people.

Read briefing →
INTL BRIEF

Canada’s federal AI law died. Quebec’s automated-decision rule didn’t

AIDA (Bill C-27) died in 2025, but Quebec’s Law 25 already requires you to explain automated decisions to the people they affect, with GDPR-scale penalties.

Read briefing →

Frameworks & Standards

The standards that travel across every jurisdiction.

Threat Intelligence

Where AI systems are actually being attacked.

Want these mapped to your business?
Start with the free call.

The AI Risk Exposure call: we walk your AI footprint, flag your likely obligations, and tell you plainly whether and where you need help.

Book the call →