Europe started enforcing. Washington is still arguing. Here’s the short version of what changed, and how it might actually show up on your desk.
If you’ve been watching AI headlines this summer, you’ve seen multimillion-euro penalties, new enforcement powers in Brussels, and a running fight in Washington over who gets to regulate what. It can feel like a compliance emergency.
For most small and mid-sized businesses, it isn’t. The takeaway is narrower and considerably more useful than the headlines suggest.
On August 2, the EU AI Act entered enforcement. This means chatbots now have to tell people they are chatbots. AI-generated images, video, and audio need labels and machine-readable marks. Penalties reach €15 million or 3% of global annual turnover.
There’s also a detail that many summaries miss: the heavier high-risk obligations that everyone spent two years preparing for were pushed back to December 2027 and August 2028. If a consultant is quoting you an urgent August deadline for high-risk compliance, they're working from stale material.
There is no comprehensive federal AI law in the United States. At the state level, nearly every state has passed some level of AI legislation around consumer protection and transparency. Colorado repealed its sweeping AI Act and replaced it with a narrower automated-decision-making statute starting January 2027. A federal preemption push – executive orders, a DOJ litigation task force, a bipartisan bill in the House — is live but unresolved, and states are continuing to move their own regulations forward in the meantime.
Nearly every obligation-making headline applies to the companies that build frontier models — not the companies that use them. If you are running Copilot, Claude, ChatGPT, or an AI feature inside your CRM, you are a deployer. That burden sits with your vendor.
What lands on you is this: disclose when a customer is talking to a bot, and keep a human genuinely in the loop on decisions that materially affect people.
Enterprise buyers have added an AI governance section to standard vendor security reviews that can include model provenance, training-data rights, output monitoring, AI subprocessor lists, alignment with the NIST AI Risk Management Framework, or ISO 42001. Two years ago, those questions didn't exist, but today they have real influence on deals.
Enterprise customers carry their own AI obligations. If they can't verify how you govern AI, the risk transfers to them, so they ask before signing. And because so many of them are behind on their own readiness, those requests tend to arrive late and with urgency.
If you are moving upmarket, AI governance stops being compliance overhead and becomes a sales asset.
One counterweight, because there is a great deal of fear-selling in this market: 56% of CEOs told PwC in January that AI has delivered no measurable cost or revenue benefit. Governance should scale with the value you're actually capturing.
The five items above are inexpensive and worth doing regardless. A full ISO 42001 certification only pays for itself if real deals are being gated on it.
© 2026 SVA Consulting
Sources: European Commission (AI Act enforcement, Aug 2026); Digital Omnibus on AI; Tech Policy Press / NYU Center on Technology Policy (state legislation); International AI Safety Report 2026; McKinsey State of AI Trust 2026; PwC Global CEO Survey, January 2026. General information only, not legal advice. Organizations with EU exposure or in regulated sectors should consult counsel.