Onnex
Your business has the answer.
Let Onnex find it.
LOADING
. . .
Completed
0

ARTICLE

What actually changed in AI regulation this year

The EU AI Act moved, Colorado repealed its own law, and most compliance pages have not noticed

If your AI compliance plan was written before the end of July 2026, some of its dates are wrong. Not slightly wrong. Wrong by more than a year in one case, and pointed at a law that no longer exists in another.

This is a plain account of what actually moved. No advice, because we are a security company and not your counsel, but the dates and the sources are here so you can hand this to somebody who is.

The EU AI Act timeline moved. Most compliance pages have not.

The Digital Omnibus on AI entered into force on 27 July 2026. It pushed back the deadlines that most enterprise compliance programs were built around.

ObligationOriginal dateActual date now
Prohibited practices, AI literacy2 Feb 2025In force since 2 Feb 2025
General-purpose AI model obligations, penalties regime2 Aug 2025In force since 2 Aug 2025
Article 50 transparency: AI-interaction disclosure, synthetic content marking, deepfake disclosure2 Aug 2026Applied 2 Aug 2026. This one held
Machine-readable marking grace period for pre-existing systemsNew2 Dec 2026
Stand-alone Annex III high-risk systems2 Aug 2026Deferred to 2 Dec 2027
High-risk AI embedded in Annex I regulated products2 Aug 2027Deferred to 2 Aug 2028
High-risk systems used by public authorities2 Aug 2030Unchanged

Two things follow from this and they point in opposite directions.

The first is that the transparency obligations under Article 50 are live right now. If you run a system that interacts with people, generates synthetic content or performs emotion recognition, the disclosure duties applied on 2 August 2026. That is this week. It did not get delayed and it received far less attention than the deferrals did.

The second is that the high-risk regime, the expensive one, the conformity assessments and technical documentation and post-market monitoring, gave you an extra sixteen months. Whether your organization treats that as relief or as an invitation to stop preparing is a decision worth making deliberately rather than by drift.

The penalty ceilings did not change. Article 99 still reads 35 million euros or 7% of total worldwide annual turnover, whichever is higher for prohibited practices. 15 million euros or 3% for other operator obligations. 7.5 million euros or 1% for supplying incorrect or misleading information. For small and medium enterprises the lower of the amount or the percentage applies.

Colorado repealed its own AI Act

This is the single most commonly wrong fact in AI compliance material right now, and it is wrong on a lot of vendor pages we checked while writing this.

Colorado's SB 24-205, the Colorado AI Act, passed in 2024 and became the reference point for US state AI regulation. Enforcement was delayed to 30 June 2026. Then, on 14 May 2026, Governor Polis signed SB 26-189, which repealed it entirely and replaced it with a narrower transparency law.

The replacement regulates automated decision making technology in consequential decisions, dropping the high-risk AI system framing altogether. Developers supply technical documentation covering intended uses, training data categories and known limitations. Deployers give pre-use notice, provide adverse-outcome notice within 30 days, keep records for 3 years and enable meaningful human review to the extent commercially reasonable. Consumers get rights to correction and human reconsideration.

Scope is entities doing business in Colorado using such technology for consequential decisions in employment, education, lending, insurance, healthcare and government services. Effective 1 January 2027, subject to pending litigation.

California's frontier law is already in force

SB 53, the Transparency in Frontier Artificial Intelligence Act, took effect on 1 January 2026. It applies to frontier models trained above 10^26 operations, with heavier duties on large frontier developers, defined by affiliate group revenue above $500 million a year.

The obligations are worth knowing even if you are nowhere near that threshold, because they are a reasonable preview of where disclosure regimes are heading. An annual published Frontier AI Framework covering identification and mitigation of catastrophic risk, defined as foreseeable risk of 50 or more deaths or serious injuries, or a billion dollars of property damage. Pre-deployment transparency reports. Critical safety incident reporting to California's Office of Emergency Services within 15 days, or 24 hours where there is imminent risk of death or serious injury. Whistleblower protections. Attorney General enforcement at up to $1 million per violation.

Federal preemption is now actively contested

An Executive Order signed on 11 December 2025, titled Eliminating State Law Obstruction of National Artificial Intelligence Policy, directs a Department of Justice AI Litigation Task Force to challenge conflicting state AI laws, tasks Commerce with identifying onerous state laws, ties broadband funding eligibility to state AI legislation, opens an FCC proceeding on federal disclosure standards intended to preempt state rules, and asks the FTC for a policy statement on how Section 5 applies to AI. It explicitly targets the omnibus AI statutes in California, Colorado, Texas and Utah.

What this means for a compliance plan is uncomfortable but simple: the US state layer is unstable, and building a program that depends on any one state statute surviving in its current form is a bet. Building a program around controls, evidence and auditability is not, because every one of these regimes asks for some version of the same thing.

What has not changed, and is quietly the most useful part

ISO/IEC 42001:2023 remains the certifiable AI management system standard. It is a governance framework rather than a technical control standard, which people routinely misunderstand. Certification tells an auditor you have a management system. It does not tell them your model cannot be prompt-injected.

NIST AI RMF 1.0 remains voluntary, with a Generative AI Profile from July 2024 and a revision currently underway. NIST released a concept note in April 2026 for a profile on trustworthy AI in critical infrastructure, and is separately developing control overlays for securing AI systems that map onto SP 800-53.

SOC 2 still has no AI-specific Trust Services Criteria. AI systems get audited by mapping them onto the existing 2017 criteria. If a vendor offers you a SOC 2 for AI as though it were a separate certification, they are describing a legitimate practice with a misleading name.

In financial services, NYDFS guidance from October 2024 explains how existing 23 NYCRR Part 500 obligations already apply to AI risk. Note the word existing. There is no grace period on a rule you were already subject to.

In healthcare, the ONC HTI-1 final rule sets certification criteria for decision support interventions including predictive ones, requiring certified health IT developers to disclose 31 categories of source attribute information.

The part that actually matters

Every one of these regimes, from Brussels to Sacramento to a New York examiner, converges on the same demand, expressed in different vocabulary.

Show me the evidence.

Not your policy document. Not your vendor's assurance. A record of what your AI system did, what was allowed, what was blocked, on what basis, and who approved the rule that made the decision. Dated, tamper-evident, and readable by somebody who does not work for you.

That is why the tamper-evident audit chain matters more than any individual regulatory checkbox. The dates will keep moving. The Colorado law got repealed. The EU deadlines slipped sixteen months. Federal preemption may unwind some of the state layer entirely.

The requirement to produce evidence is the part that survives all of it.

‹ All articles

Do not take our word for it. Run AI-Sentinel against your own traffic.

Monitor mode goes in non-blocking, in minutes, with zero risk to live workflows. Within days you get a written audit of the prompt injections, extraction attempts and data leaks your current stack is not catching. Then you decide.

The audit is free. The blind spot is not.