63% of RIAs Use AI. 78% Have No Written Policy. What the SEC Now Expects in 2026
Executive Summary
- The SEC Division of Examinations published its fiscal year 2026 priorities on November 17, 2025. Examiners will assess whether advisers have policies and procedures adequate to monitor and supervise their AI use, and will review the accuracy of what firms say about their AI capabilities.
- A Charles Schwab study published January 22, 2026 found 63 percent of RIAs now use AI tools, more than double the 2023 rate. A separate survey of nearly 500 advisers found 78 percent of RIAs have no written AI policy at all. That gap is the exposure.
- There is no SEC rule specifically governing advisers’ AI use. The Commission withdrew its 2023 predictive data analytics proposal on June 12, 2025 and said it did not intend to finalize it. Your AI use is already governed by Advisers Act Section 206, the Marketing Rule, the Compliance Rule, the books and records rule, and Regulation S-P.
- AI washing has cost real money. Three settled SEC actions produced $400,000 in penalties against two advisers, plus $523,611.25 in penalties, disgorgement, and interest against a third firm’s executives, along with a bar allowing the chief executive to apply for reentry only after five years.
- Advisers with less than $1.5 billion in assets under management passed a hard deadline on June 3, 2026. Amended Regulation S-P now requires a written incident response program, service provider oversight, and customer notification within 30 days. An AI vendor is covered when it maintains customer information on your behalf, so the data flows decide which of your tools are in scope.
In this article
- What does the SEC expect from a small RIA using AI in 2026?
- Why is the policy gap the biggest exposure for small advisers?
- What is AI washing and what has it cost firms so far?
- Which existing rules already govern your AI use?
- How does Regulation S-P change your obligations for AI vendors?
- Where will examiners look first?
- What do state registered advisers need to know?
- What belongs in an AI policy for a 10 person advisory firm?
- How do you close the gap in 30 days?
- What does getting this wrong actually cost?
1. What does the SEC expect from a small RIA using AI in 2026?
The SEC’s 2026 examination priorities indicate that advisers using AI should have policies and procedures reasonably designed to monitor and supervise that use, scaled to the firm’s activities and risks, and should be able to show that what the firm says about its AI matches what the firm actually does. That signal is explicit in the Division of Examinations fiscal year 2026 priorities, published November 17, 2025.
One clarification before going further, because it is the point most commentary gets wrong. The priorities are an examination signal, not a new rule. Nothing in them creates a freestanding requirement that every adviser maintain a standalone AI policy document. What exists is Rule 206(4)-7, which requires written policies and procedures reasonably designed to prevent Advisers Act violations. For a firm where staff use AI daily, addressing AI expressly within that program is the practical way to satisfy an existing obligation, not a separate new one.
The language in the report is short and it is worth reading twice. The Division states that it “will review for accuracy representations regarding AI capabilities or AI generally” and that it “will assess whether Market Participants have implemented adequate policies and procedures to monitor and/or supervise their use of AI technologies, including for tasks related to fraud prevention and detection, back-office operations, anti-money laundering, and trading functions, as applicable.”
Read the second half of that sentence carefully. The examples given are back office operations and anti money laundering, not just portfolio construction. If your firm uses an AI notetaker in client meetings, an AI drafting assistant for correspondence, or an AI tool that summarizes account activity, you are inside the scope of that sentence, whether or not you market yourself as AI driven.
The practical summary: the SEC does not need a new AI rule to examine your AI use. It needs your compliance manual, your marketing files, your vendor list, and your Form ADV, and it will compare all four against each other. Firms that can produce a coherent, dated set of documents will have a routine exam. Firms that cannot will have a long one.
2. Why is the policy gap the biggest exposure for small advisers?
Because adoption has raced ahead of governance, and the numbers are not close. A study conducted for Charles Schwab by Logica Research, surveying 533 RIAs between October 7 and October 26, 2025 and published January 22, 2026, found that 63 percent of RIAs now use AI tools in some capacity, more than double the 2023 figure. Of those users, 82 percent rely on generative AI.
Now put that next to the governance data. An ISS Market Intelligence study published October 8, 2025 and based on nearly 500 adviser interviews conducted in June 2025 found that 78 percent of RIAs had no written policy on AI use. The comparable figure for advisers at regional firms, independent broker dealers, and banks was 35 percent. RIAs were simultaneously the channel most likely to be using AI and the channel least likely to have written anything down about it.
That is not a coincidence. It is a structural feature of the RIA business. The 2026 Investment Adviser Industry Snapshot, released June 3, 2026, counted 16,544 SEC registered advisers managing $176.8 trillion for 73.7 million clients. Of those firms, 92.8 percent employ 100 people or fewer, and 67.4 percent manage less than $1 billion. Advisers focused on individual clients average just 8 employees and $424 million in assets.
Eight employees means the chief compliance officer is also the operations lead, and probably a producing adviser. Nobody in that firm was assigned the job of writing an AI policy. Meanwhile the Schwab data shows most AI adoption is happening through individual experimentation rather than a firm wide rollout, which means the CCO frequently does not know which tools are in use. You cannot supervise what you have not inventoried.
GOVERNANCE INSIGHT
The gap between 63 percent adoption and 22 percent policy coverage is the finding an examiner writes up.
Deficiency letters do not usually cite the AI tool. They cite Rule 206(4)-7, which requires written policies reasonably designed to prevent violations. An adviser whose staff uses generative AI daily with no written procedure has a compliance program that does not describe the firm’s actual operations. That is the finding, and it is easy to make.
3. What is AI washing and what has it cost firms so far?
AI washing is overstating the role, sophistication, or existence of artificial intelligence in your investment process or your service offering, and the SEC treats it as securities fraud rather than as a marketing problem. Three settled actions establish the pattern and the price.
On March 18, 2024, the SEC announced settled charges against two investment advisers, Delphia (USA) Inc. and Global Predictions, Inc. These were the first enforcement actions in the agency’s history charging antifraud violations in connection with AI disclosures. Delphia had told clients from August 2019 through August 2023 that it used client data in a predictive algorithmic model to select investments. According to the SEC, no such data was used. Global Predictions claimed on its website and social media in 2023 to be the “first regulated AI financial advisor” and to deliver expert AI driven forecasts. The two firms paid civil penalties of $225,000 and $175,000 respectively, a combined $400,000.
In October 2024 the SEC charged Rimar Capital USA, Inc., Rimar Capital, LLC, chief executive Itai Liptz, and board member Clifford Boro over claims that Rimar used AI to conduct automated trading of equities, futures, and crypto assets for advisory clients. Between May 2022 and April 2023 the defendants raised nearly $4 million from 45 investors, and told them the firm managed between $16 million and $20 million when it actually managed less than $2 million. Liptz was ordered to pay $202,604 in disgorgement and $11,007.25 in prejudgment interest, totaling $213,611.25, plus a $250,000 civil penalty, and became subject to a bar under which he may apply for reentry to the securities industry only after five years. Boro paid a $60,000 civil penalty. Civil penalties across the two individuals totaled $310,000, and the full monetary outcome reached $523,611.25.
| Matter | Date announced | What was claimed | Financial outcome | Other sanctions |
|---|---|---|---|---|
| Delphia (USA) Inc. | March 18, 2024 | Client data fed a predictive algorithmic model for investment selection | $225,000 civil penalty | Censure, cease and desist |
| Global Predictions, Inc. | March 18, 2024 | “First regulated AI financial advisor” and expert AI driven forecasts | $175,000 civil penalty | Censure, cease and desist |
| Rimar Capital entities and executives | October 2024 | AI driven automated trading platform, plus inflated assets under management | $523,611.25 combined penalties, disgorgement, and interest | Censure of the adviser, and a bar permitting the chief executive to apply for reentry only after five years |
Two details in that table matter more than the dollar figures. First, the Rimar action reached individuals, not just the entity, and it removed a chief executive from the securities industry with no path back for five years. Second, the early AI washing cases all involved relatively small advisory businesses. The SEC has not described small advisers as a particular target, but firm size plainly did not shield these registrants from enforcement.
4. Which existing rules already govern your AI use?
Four provisions of the Investment Advisers Act carry almost the entire load, and none of them mention artificial intelligence. The SEC has been clear that it does not need AI specific rules to bring AI cases, and the Delphia, Global Predictions, and Rimar orders all charged conventional provisions.
Section 206 and the fiduciary duty. Sections 206(2) and 206(4) of the Advisers Act prohibit fraudulent, deceptive, or manipulative conduct. Both the Delphia and Global Predictions orders charged these sections. If an AI tool introduces a conflict, degrades advice quality, or produces recommendations nobody at the firm reviewed, the fiduciary duty analysis starts here.
Rule 206(4)-1, the Marketing Rule. Adopted December 22, 2020, the Marketing Rule prohibits an advertisement that includes a material statement of fact the adviser does not have a reasonable basis for believing it will be able to substantiate upon demand by the Commission. Staff will presume that an adviser who cannot substantiate a claim on demand never had a reasonable basis for making it. This is the single most dangerous provision for an AI marketing claim, because the burden runs the wrong way. A claim that AI personalizes portfolios or sharpens recommendations may well be material, particularly where it is used to differentiate the firm or to influence a prospect’s decision, and materiality turns on context, prominence, and audience rather than on the words alone. Where the claim is material, you will be asked to prove it.
Rule 206(4)-7, the Compliance Rule. This requires written policies and procedures reasonably designed to prevent violations, a designated chief compliance officer, and an annual review of the adequacy of those policies. Both 2024 adviser settlements charged Rule 206(4)-7 alongside the Marketing Rule and the antifraud provisions. If your firm adopted generative AI in 2024 and your compliance manual has not been touched since 2022, your annual review is harder to defend.
Rule 204-2, books and records. AI generated client communications, advertisements, and the materials supporting them may fall within Rule 204-2 and other retention obligations, depending on the content, the recipient, and the category of record. A record is not covered simply because AI produced it. Client directed communications are the clearest case. For internal outputs such as AI meeting summaries or draft recommendations, determine whether they must be retained under Rule 204-2, under your own books and records policies, or under your supervisory procedures. Decide that in advance rather than during an exam.
Is a new SEC AI rule coming?
There is currently no SEC rule specifically governing advisers’ use of AI. The SEC proposed a rule in 2023 that would have required advisers and broker dealers to eliminate or neutralize conflicts of interest arising from the use of predictive data analytics. On June 12, 2025, the Commission formally withdrew 14 pending rule proposals, including that one, and stated it did not intend to issue final rules on them. Any future rulemaking in this area would require a fresh proposal and a new comment period, so no AI specific obligation can take effect without advance notice.
Some advisers read that withdrawal as a reprieve. It is closer to the opposite. Withdrawing the proposal removed the prospect of a defined AI compliance checklist with a phase in period. What remains is a set of principles based rules, applied case by case, through examinations and enforcement. Principles based supervision is harder to prepare for than a checklist, not easier.
5. How does Regulation S-P change your obligations for AI vendors?
Amended Regulation S-P requires you to oversee service providers that receive customer information, and an AI vendor can be a covered service provider when it maintains customer information or a customer information system on your behalf. For advisers with less than $1.5 billion in assets under management, the compliance date was June 3, 2026, which has already passed.
Coverage turns on data flows, not on labels. A vendor that stores, processes, or can access client information on the firm’s behalf is squarely in scope. A general purpose tool that never receives customer information may not be. Answering that requires mapping what data actually goes where, which is why the inventory in section 9 comes first.
The amendments became effective August 2, 2024 with a staggered compliance schedule. Larger entities, meaning investment companies with more than $1 billion in assets and registered advisers with more than $1.5 billion in assets under management, had to comply by December 3, 2025. Everyone below those thresholds is a smaller entity and had until June 3, 2026. Given that 67.4 percent of SEC registered advisers manage under $1 billion, the smaller entity deadline covers most of the industry.
Four requirements interact directly with AI tools. You need a written incident response program covering detection, response, and recovery from unauthorized access to customer information. You must notify affected customers as soon as practicable and no later than 30 days, and the clock runs from the determination that unauthorized access to or use of sensitive customer information occurred or is reasonably likely to have occurred, not from the moment you first hear that something looks wrong. Notice may be delayed in defined circumstances at the request of law enforcement. You must have written policies reasonably designed to ensure service providers protect customer information and notify you as soon as possible and no later than 72 hours after becoming aware of a qualifying breach. And you must keep records documenting all of it.
That distinction between awareness and determination belongs in your incident response plan verbatim, because a plan that starts the 30 day clock at the wrong event will either notify prematurely or blow the deadline.
The 72 hour service provider element is where most small firms have a problem. If your team pastes client financial details into a general purpose AI chat product under consumer terms of service, that account may not provide the contractual commitment or other reasonable assurance your oversight program needs, and there is no due diligence file to produce. A written contractual representation is the cleanest way to satisfy this, though the SEC has indicated it is not the only permissible form of assurance. Either way the fix requires knowing which tools are in use, which is back to the inventory problem.
6. Where will examiners look first?
Examiners are likely to start by comparing your public claims against your internal reality, because that comparison is cheap to run and it is where the 2026 priorities point them. The list below is an informed expectation drawn from the published priorities rather than an SEC issued checklist, and the order will vary by examiner and by firm.
Your website and Form ADV. Every use of the words artificial intelligence, machine learning, algorithm, or proprietary technology invites a question. The examiner is looking for the gap between marketing language written by a founder in an optimistic mood and the operational description in Part 2A.
Your compliance manual and your annual review. The examiner will ask when the manual was last updated and whether the annual review under Rule 206(4)-7 considered AI. A manual with no AI section, paired with a firm where staff use generative AI daily, is a self proving deficiency.
Your vendor list. Expect a request for every third party technology tool that touches client information, along with the contract and the due diligence file. This request now does double duty, covering both the AI supervision priority and Regulation S-P service provider oversight.
Your substantiation file. If your advertisements make factual claims about AI, the Marketing Rule requires you to be able to substantiate them on demand. A contemporaneous record made at the time the advertisement was created is the strongest form of that proof. Reconstructing it two years later, during an exam, is not.
Your training records. Supervision requires that people know the rules. If the firm has no record that anyone was ever told what may and may not be entered into an AI tool, supervision is difficult to demonstrate.
Getting your AI governance in order
Dynamic Comply helps small and medium sized businesses build a real AI governance foundation using the NIST AI RMF and ISO/IEC 42001.
7. What do state registered advisers need to know?
State registered advisers face the same substantive expectations through a different regulator, and the state framework moved decisively in 2026. On May 4, 2026, NASAA members adopted a modernized advertising model rule aligning state advertising standards with the federal framework the SEC established in 2020.
One critical qualification. NASAA model rules are not law anywhere on adoption day. Each jurisdiction must enact them through its own rulemaking, so the amendments bind a state registered adviser only once that adviser’s state adopts them. The significance is directional: the substantiation standard described in section 4 is converging toward a national norm, and an adviser too small for SEC registration should track their own state’s adoption timeline rather than assume nothing has changed.
NASAA’s Investment Adviser Section has also published guidance titled Compliance Matters: Using AI: Risks and Compliance Considerations. The guidance flags four risks: marketing a service as AI powered when it relies on simple algorithms or manual work, biased or incomplete outputs, data privacy exposure from entering client information into AI systems, and misleading AI generated marketing content. It recommends four responses: reviewing AI generated outputs before distribution, training personnel on tool limitations and fiduciary duties, evaluating vendors on data security and algorithm transparency, and documenting the controls used. The document reflects the views of the project group rather than a formal NASAA position, and it is not a rule, but it is a fair preview of what a state examiner may ask.
Advisers with a broker dealer affiliate carry a third layer. FINRA issued Regulatory Notice 24-09 on June 27, 2024, reminding members that existing rules are technology neutral and apply to generative AI and large language models exactly as they apply to any other tool, whether the firm built it or licensed it from a third party. The notice creates no new requirements and relieves firms of none.
| Obligation | SEC registered adviser | State registered adviser | Broker dealer |
|---|---|---|---|
| Written AI policies and procedures | Rule 206(4)-7, tested in 2026 exams | State policies and procedures rules, NASAA guidance | FINRA supervision rules per Notice 24-09 |
| Substantiating AI marketing claims | Rule 206(4)-1, substantiation on Commission demand | NASAA model advertising rule adopted May 4, 2026, effective per state on adoption | FINRA communications rules |
| AI vendor oversight and breach notice | Regulation S-P, smaller entity date June 3, 2026 | State privacy and safeguards rules, varies by state | Regulation S-P plus third party risk expectations |
| Antifraud exposure for AI claims | Advisers Act Sections 206(2) and 206(4) | State antifraud provisions | Exchange Act and FINRA conduct rules |
8. What belongs in an AI policy for a 10 person advisory firm?
An AI policy for a small adviser should be roughly six to ten pages and should answer six questions in plain language. In our experience longer documents tend to go unread at firms without dedicated compliance staff, and a policy that is not actually followed can be worse than a shorter one that is, because it sets a standard the firm’s own records show it missed.
Which tools are approved. Name them. A short approved list, plus a rule that anything not on the list requires CCO sign off before use, solves the inventory problem permanently. This is the single highest value paragraph in the document.
What data may never be entered. Client names, account numbers, Social Security numbers, balances, and anything that would constitute sensitive customer information under Regulation S-P. Be concrete. “Use good judgment” is not a control.
Who reviews AI output before it leaves the firm. NASAA’s guidance recommends reviewing AI generated marketing, communications, and recommendations before distribution. Name the reviewer by role and describe how the review is evidenced.
How the firm substantiates AI claims. If marketing says the firm uses AI, the policy should require a contemporaneous substantiation memo created at the same time as the advertisement, retained under Rule 204-2, describing exactly what the tool does.
What records are captured. Specify how AI generated client communications and meeting summaries enter the books and records system, and who checks that it is happening.
What the vendor due diligence file contains. The contract, the security review, confirmation of the 72 hour breach notification obligation, whether your data trains the vendor’s model, and the date of the last review.
If you want a structured framework behind these choices rather than an ad hoc list, the NIST AI Risk Management Framework maps cleanly onto a small firm compliance program, and ISO/IEC 42001 provides the certifiable management system version for firms that need to show an institutional client or an acquirer that governance exists. Neither is required by the SEC. Both make the annual review under Rule 206(4)-7 much easier to defend.
9. How do you close the gap in 30 days?
A firm of eight to fifteen people can close the material portion of this gap in about 30 days of part time work, and the sequence matters because each step feeds the next. Do the inventory first. Everything else depends on knowing what is actually in use.
Days 1 to 5: inventory. Ask every employee, in writing, which AI tools they have used for firm work in the last 90 days, including free consumer accounts and AI features embedded in software you already license. Embedded features are the ones firms miss. Your CRM, your portfolio accounting system, and your meeting platform may have added AI capabilities since your last contract review, so check the release notes rather than assuming.
Days 6 to 10: marketing audit. Pull every public claim about AI from the website, Form ADV Part 2A, pitch decks, LinkedIn, and email templates. For each claim, write one sentence describing the evidence. Any claim you cannot support in one sentence gets removed or rewritten this week, not next quarter. This step alone eliminates most AI washing exposure.
Days 11 to 18: vendor files. For each tool on the inventory, first determine whether it receives or maintains customer information, since that is what pulls a vendor into Regulation S-P’s service provider requirements. For those that do, collect the contract, confirm whether client data is used for model training, and check the breach notification terms against the 72 hour standard. Tools that fail this review either get upgraded to an enterprise agreement or come off the approved list.
Days 19 to 25: write the policy. Six to ten pages answering the six questions in section 8. Date it, have the CCO approve it, and record the approval.
Days 26 to 30: train and document. One 45 minute session, an attendance record, and a signed acknowledgment from every employee. The acknowledgment is what turns a policy into supervision.
Then fold AI into the annual review under Rule 206(4)-7 and repeat the inventory every year. Adoption is still moving fast: 59 percent of advisers in the Schwab study expect AI to have a direct, measurable impact on client relationships within one year, and 68 percent expect it to be transformative within three. An inventory taken once will be stale by the next annual review.
10. What does getting this wrong actually cost?
The direct financial cost of the three settled AI washing matters ranges from $175,000 to $523,611.25, but for a small advisory firm the penalty is rarely the largest number. The collateral costs are.
Consider the Rimar outcome. A $250,000 penalty against the chief executive is survivable for many people. A bar with no route back into the industry for five years is not survivable for the business. For a firm where the founder is the investment process, the client relationship, and the brand, removing that person for five years generally ends the enterprise. Boro, a board member rather than an operator, still paid $60,000.
Then there is the disclosure problem. Disciplinary events flow into Form ADV and become visible to every prospect performing basic diligence and to every custodian and institutional platform running periodic reviews. Advisers competing for institutional or retirement plan business will be asked about it in every questionnaire from that point forward.
Set against that, the compliance side is inexpensive. An inventory, a marketing audit, a vendor file, a short policy, and one training session is a modest project for a firm with eight employees. There is no filing fee and no certification requirement. The reason firms have not done it is not cost. It is that nobody was assigned the task, and the deadline felt abstract. The June 3, 2026 Regulation S-P date and the 2026 exam priorities have made it concrete.
One closing note on the broader landscape. The AI rules reaching small businesses are arriving through sector regulators and state legislatures rather than through a single federal AI statute. We have covered that pattern in our analysis of Illinois SB 315 and the first state AI audit law, and in our guide to what actually applies to employers in Colorado in 2027. Advisers with employees in multiple states will find their AI obligations shaped by employment and consumer protection law as much as by the Advisers Act.
Talk to Ross about your AI governance needs
Every business has different AI governance requirements. Let us talk about yours.
Frequently Asked Questions
Does my RIA need a written AI policy?
There is no SEC rule requiring a standalone AI policy document. Rule 206(4)-7 does require written policies and procedures reasonably designed to prevent Advisers Act violations, and the SEC Division of Examinations stated in its fiscal year 2026 priorities, published November 17, 2025, that examiners will assess whether firms have adequate policies to monitor and supervise their AI use. For a firm where staff use AI regularly, addressing AI expressly within the existing compliance program is the practical way to meet that obligation. Nearly 500 advisers surveyed in June 2025 reported that 78 percent of RIAs had no written AI policy.
What are the penalties for AI washing?
In the SEC’s first AI washing actions on March 18, 2024, Delphia (USA) Inc. paid a $225,000 civil penalty and Global Predictions, Inc. paid $175,000. In the October 2024 Rimar Capital matter, chief executive Itai Liptz was ordered to pay $213,611.25 in disgorgement and prejudgment interest plus a $250,000 civil penalty and became subject to a bar allowing him to apply for reentry only after five years, and board member Clifford Boro paid $60,000. Penalties are set case by case and there is no fixed schedule.
Is there a new SEC rule specifically about AI?
No. The SEC proposed a predictive data analytics conflicts rule in 2023 and formally withdrew it on June 12, 2025 as part of a withdrawal of 14 pending proposals, stating it did not intend to issue final rules on them. Any future AI rulemaking would require a new proposal and comment period. AI use by advisers is governed by existing law, principally Advisers Act Sections 206(2) and 206(4), Rule 206(4)-1, Rule 206(4)-7, Rule 204-2, and Regulation S-P.
Does Regulation S-P apply to AI vendors, and when was the deadline?
It depends on the data flows. An AI vendor is a covered service provider under amended Regulation S-P when it maintains customer information or a customer information system on the adviser’s behalf, which triggers written oversight policies reasonably designed to ensure the provider notifies the firm as soon as possible and no later than 72 hours after becoming aware of a qualifying breach. Advisers with $1.5 billion or less in assets under management are smaller entities and had until June 3, 2026 to comply. Larger entities had until December 3, 2025.
Do state registered advisers have AI obligations too?
Yes, though the timing depends on your state. NASAA members adopted amendments to investment adviser advertising model rules on May 4, 2026 that move state standards closer to the federal framework the SEC adopted in 2020, but model rules are not law until each jurisdiction enacts them through its own process. NASAA’s Investment Adviser Section has also published guidance on AI risks covering fake AI marketing claims, biased outputs, data privacy, and misleading AI generated content. Check your own state’s adoption status.
How long does it take a small firm to get compliant?
About 30 days of part time work for a firm of eight to fifteen people: five days to inventory AI tools in use, five days to audit and correct public AI claims, roughly a week to assemble vendor due diligence files, a week to write a six to ten page policy, and a final week to train staff and collect signed acknowledgments. The average SEC registered adviser serving individual clients has just 8 employees, so this is sized for a firm without dedicated compliance staff.
About the author
Ross J. is the founder of Dynamic Comply, an AI governance, compliance, and cybersecurity consulting firm based in Leesburg, Virginia. He brings more than 15 years of federal cybersecurity experience across the Department of State, the Department of Defense, and the Department of Homeland Security, and holds the CGRC certification along with credentials as a GSDC AI Compliance Lead Implementer and Auditor and Certified Ethical Hacker.
Related articles
- Illinois SB 315 Explained: The First State AI Audit Law and What It Means for Your Business
- Colorado’s AI Law Never Took Effect. Here Is What Actually Applies to Employers on January 1, 2027
- August 2 Did Not Get Cancelled: What Small US SaaS Companies Still Owe Under the EU AI Act
- The 2026 Federal AI Procurement Rules Decoded: A Survival Guide for Small Contractors
This article is provided for general informational purposes and reflects the state of the law as of August 2026. It is not legal advice. Regulations in this area are changing quickly. Confirm current requirements and consult qualified counsel before making decisions for your organization.