How AI Regulations are Shaping Up

AI companies asked to be regulated. But laws at the U.S. Federal level — where many big players are headquartered — haven't materialized. Here's a look at what's ahead, and why you shouldn't wait to protect your data to govern AI.

Anthony Woodward

Founder/CEO

September 17, 2026
Get your monthly round-up of the latest news and views at the intersection of data privacy, data security, and governance.

Subscribe to FILED Newsletter

Get your monthly round-up of the latest news and views at the intersection of data privacy, data security, and governance.
Subscribe Now

This month:

  • Frontier AI CEOs call for a slower pace of development and welcome federal rules — while state and international AI laws move ahead without them
  • A voiceprint lawsuit against Walmart and a first-of-its-kind fine against a data broker show regulators treating AI-collected data like any other sensitive data

But first, does an industry asking for a leash actually get one?

If you only read one thing

The AI industry is asking to be regulated. Here's how that's going.

Given that the bulk of today's frontier models — OpenAI, Anthropic, Google DeepMind, Meta — are U.S. companies, the U.S. has greater jurisdiction over model pipelines that other regions (the E.U. for example) cannot cover. But the U.S. Federal government has been slow to adopt AI guardrails.

That may be about to change as this week, calls for regulation escalated as Anthropic and OpenAI CEOs acknowledged a need for both national safety and testing requirements amid snowballing concerns from top researchers.  

Frontier AI companies respond to risks

On September 12, Anthropic CEO Dario Amodei published an essay, "We Must Pace the Frontier," arguing that the industry needs to slow the advancement of model capabilities. His reasoning: AI is now helping build the next generation of AI, and that feedback loop is outrunning the industry's ability to keep it aligned and understood. Anthropic says it is unilaterally committing to the first step of a three-part plan: Giving outside evaluators ongoing, employee-level access to verify safety practices.

That same day, OpenAI CEO Sam Altman posted his agreement, writing: "I agree with Dario that we need to pace the frontier... Committing to having independent evaluators with employee-like access is a great idea, and we will do the same." Elon Musk and Google DeepMind's Demis Hassabis also issued statements in agreement.

Two days later, Altman added support for legislation, saying: "We welcome a federal framework that sets consistent safety requirements for frontier AI." This echoes Anthropic's history of public support for AI regulations.  

Where regulations stand today

Right now, a patchwork of state AI legislation, including in California (where many of the major players are headquartered) have emerged, but regulations are still relatively thin. But newly introduced bills both at the state and federal level show that today's AI regulations are slowly strengthening. Here's where they currently stand:

Currently on the books

At the state level, California's Transparency in Frontier Artificial Intelligence Act (SB 53), in effect since January 1, 2026, requires frontier developers to publish safety practices and report incidents. This act was strengthened by last week’s signing of SB 813 and AB 1405 which together mandate a framework for third-party audits of AI systems. New York's RAISE Act, signed in final form in March 2026, closely tracks California's law and takes effect January 1, 2027; Illinois has a similar law queued up for the same date.

U.S. federal legislation introduced

While movement at the federal level has largely stalled, several bipartisan AI bills have been introduced since July which show potential. Most notable among them is the Frontier Act, which would establish risk-management frameworks and require independent audits for AI models. While its passage before midterms is still uncertain given the federal government's track record on AI policy, it stands a fighting chance of being picked up in 2027.

Other bipartisan bills have been introduced since the end of July, including the AI Kill Switch Act and the Stop Rogue AI Act, but the odds for passage, as of now, seem considerably lower.

What to do when AI outpaces regulation

For now, regulation will continue to outpace AI development and adoption, both for models and the companies that use them — but, as we've said before, that doesn't mean you should wait for them to catch up. In the absence of regulations, today's organizations should stay proactive about protecting themselves from risk through their own AI governance policies and best practices.  

And AI governance starts with data governance, including an inventory of your entire data estate, classification and retention policies, and data minimization. This is what enables monitoring and reducing access to data by unsecured or unknown AI models while also controlling the outputs from the sanctioned ones. From there, tools to detect and monitor unauthorized AI models can help keep AI use in check.

🔎 Privacy and governance

  • Two proposed class actions filed in Illinois federal and state courts accuse Walmart of using an AI-powered interactive voice system to record customer calls and convert callers' voices into biometric templates, without the written consent the Illinois Biometric Information Privacy Act requires. The complaints argue voiceprints are valuable precisely because banks and other institutions already use them to unlock accounts, which is exactly why collecting them without consent matters.
  • Meanwhile, California's privacy regulator opened a new enforcement front. CalPrivacy fined data broker LocateSmarter LLC $116,490 for making it difficult for consumers to opt out of the sale of their personal information, in the agency's first action to combine violations of the CCPA and the Delete Act. The Iowa-based company had required consumers to hand over the last four digits of their Social Security number just to submit an opt-out request — a data-minimization failure a second broker, Cybba, was separately fined $52,400 for days later.

🛡️ Security breaches and legal cases

ShinyHunters claimed to have stolen 50GB of Carhartt customer, employee, and corporate data after failed ransom talks. Security researcher Troy Hunt's analysis found the real number of affected individuals was about 12.9 million — roughly half of what the group claimed, after filtering out millions of synthetic records, including customers "registered" in Benin and Montenegro and birth dates from the early 1900s. A useful reminder that breach disclosures need verification too.

A New York federal judge granted final approval to a $10.5 million settlement resolving claims that insurer Lemonade Inc. negligently exposed 190,000 people's driver's license numbers to cybercriminals.

A California federal judge said this month he'll review Meta's own privacy and use terms to help decide the company's motion to dismiss a proposed class action alleging it secretly captures Facebook users' voiceprints — the same legal theory now aimed at Walmart, above.

🤖 AI governance

Anthropic's September 2026 threat intelligence report found AI misuse shifting beyond cybercrime into surveillance, propaganda, and weapons-related use cases.

California's SB 813 and AB 1405 follow a similar push in Illinois to place transparency and safety requirements on large AI developers.

Reps. Josh Gottheimer and Mike Lawler introduced the bipartisan Stop Rogue AI Act on September 9, which would direct NIST to develop standards for deploying agentic AI securely and give federal agencies the tools and authority to identify and shut down dangerous AI systems on their networks.

The latest from RecordPoint

📖 Read:  

The foundations of AI governance — why "garbage in, garbage out" applies to AI the same way it always applied to data, and what to do about it.

Learn how RecordPoint's AI Governance platform helps organizations register AI systems, govern data pipelines, and stay audit-ready as AI rules multiply.

🎙️ Watch/Listen:  

Why are enterprises hesitating when it comes to AI? — Anthony and Kris talk with AI strategist and ethicist Jason Tan about why enterprises are still sitting on the fence on AI while startups race ahead, the difference between data bias and algorithm bias, and why "human in the loop" isn't optional for high-stakes use cases.

📅 Upcoming:  

IAPP Privacy. Security. Risk. + AI Governance Global 2026: October 8–9, Seattle, WA

AI Gov World Conference 2026: October 13–14, Las Vegas, NV

ARMA InfoCon 2026: October 25-28, Savannah, GA  

bg
bg

Get hooked on FILED

This can be a fast-paced, complex industry and it can get overwhelming. FILED is here to help you navigate it.