On May 7, European Union negotiators reached a political agreement to revise the EU’s landmark Artificial Intelligence Act, delaying and simplifying some of its obligations. Under this deal, enforcement of the AI Act’s 'high-risk' requirements – originally set to begin in August 2026 – will be postponed by 16 months, with those rules now taking effect in December 2027 ([1]). The co-legislators also agreed to extend certain compliance exemptions for small and mid-sized enterprises and, crucially, to largely remove industrial AI applications from the Act’s scope, so companies deploying AI for manufacturing or other machinery uses will not face dual regulation under overlapping sectoral laws ([2]).
This move marks the first time the EU has rolled back a major digital regulation in response to external pressure ([3]). Industry groups and some allied governments – including the US – had warned that Europe’s stringent approach was outpacing global norms and could stifle innovation, especially as few other countries have similar AI rules on the books ([4]). The compromise was strongly supported by tech-exporting member states like Germany (keen to protect companies such as Siemens and Bosch from competitive disadvantage) and was praised by European Commission President Ursula von der Leyen as creating an 'innovation-friendly' climate for AI while maintaining safeguards for citizens ([5]). Notably, negotiators also added a new ban on AI systems that generate non-consensual sexual deepfake images or child sexual abuse material (CSAM) – a response to recent outcry over the abusive use of AI, like the misconduct involving Elon Musk’s Grok chatbot ([6]).
For enterprises operating in Europe, the adjusted timeline offers some breathing room but no complacency. The AI Act’s strict requirements on risk management, data governance, transparency, and human oversight for high-risk AI still loom – they are simply delayed, not diminished. Businesses should seize the opportunity to shore up their AI compliance programs: inventory high-risk AI applications, ensure robust data and model governance, and be ready to implement transparency measures such as AI-generated content disclosures by the new December 2026 deadline ([7]). With fines up to €35 million or 7% of global annual turnover for serious breaches of the AI Act on the line ([8]), boards must treat readiness for the 2027 compliance requirements as a strategic priority.
In the United States, federal officials are taking unprecedented steps to evaluate advanced AI systems before they reach the public. On May 8, the Commerce Department’s National Institute of Standards and Technology (NIST) announced that its Center for AI Standards and Innovation (CAISI) will be given pre-release access to test frontier AI models from companies including Google, Microsoft, and Elon Musk’s xAI ([1]). Under this framework – which expands on voluntary commitments made by leading AI firms in 2024 – CAISI experts will conduct rigorous pre-deployment evaluations and targeted research on these systems, probing them for demonstrable risks such as cybersecurity vulnerabilities, biosecurity threats, and potential misuse for weapons development before they launch ([2]).
This initiative signals a significant policy shift, especially for an administration that has generally favored a lighter regulatory touch for tech. Heightened concerns over national security and emerging AI capabilities (for instance, reports of AI models like Anthropic’s Mythos discovering critical software vulnerabilities) have driven the change ([3]). The White House is even weighing an executive order to formally require government review of high-risk AI models before release, according to media reports ([4]). And the new CAISI agreements – some of which were renegotiated from earlier safety pledges – indicate a growing bipartisan consensus that certain powerful AI systems need external oversight prior to deployment ([5]).
For AI developers and enterprise users, this trend has direct implications. Companies working on cutting-edge models should plan for a future in which regulators ask for advanced notice, safety test results, or even certifications before high-impact AI tools can be rolled out. Proactively engaging with initiatives like CAISI and implementing rigorous internal risk assessments can position businesses as trusted players and help shape standards. As US oversight of AI intensifies, demonstrating strong governance, compliance with best practices, and transparency about AI capabilities will be increasingly crucial to maintaining market access and public trust.
The United Kingdom has once again delayed its effort to introduce a comprehensive AI law, choosing to align more closely with the US approach for now. Officials have postponed a planned AI bill – initially expected by the end of 2025 – until at least the summer of 2026 ([1]). A government adviser acknowledged the legislation is now 'properly in the background', with no firm timeline to bring it to Parliament ([2]). In the meantime, UK companies must adhere to existing regulations (like data protection and sector-specific rules) to govern AI usage.
London’s decision reflects a strategic pivot to prioritize innovation and avoid scaring off AI investment. Influenced by signals from Washington, British policymakers worry that acting too quickly on strict AI regulation could put UK firms at a competitive disadvantage or drive new ventures abroad ([3]). This hesitancy was underscored when UK leaders declined to sign a recent 66-nation 'Paris Declaration' on AI governance – a move aligned with US skepticism of prescriptive global AI rules ([4]). Instead of new laws, regulators like the Financial Conduct Authority are issuing guidance within existing frameworks, and ministers promise that any future AI legislation will balance benefits and risks without stifling innovation ([5]).
For businesses in the UK, the regulatory limbo is a mixed blessing. The lack of immediate new laws means greater flexibility in the short term, but also uncertainty and the potential for misalignment with stricter regimes elsewhere (such as the EU’s incoming AI Act requirements). Equally, contentious issues are far from settled: proposals to let AI companies scrape online content without permission have drawn fierce backlash from creators – with music icons like Paul McCartney and Elton John warning that such moves could erode vital copyright protections ([6]). Smart companies will use this period to bolster their own AI governance policies, ensuring they manage AI risks proactively. Engaging with regulators and industry groups can help shape sensible future rules, while strong voluntary compliance now will put firms on solid footing when formal regulations do arrive.
A landmark legal battle is brewing over how AI models are trained. On May 5, five major publishing companies – including Elsevier, Hachette, Macmillan, Cengage, and McGraw Hill – together with best-selling author Scott Turow, filed a class-action lawsuit against Meta in a US federal court ([1]). They allege Meta’s LLaMA model was built on a massive dataset of text scraped from 'shadow library' websites – illicit online repositories of pirated books and articles – without any permission from the content creators ([2]). This, the plaintiffs argue, is a wholesale violation of intellectual property rights.
Meta has pushed back, claiming that using public internet text to train AI falls under 'fair use' exemptions in copyright law and stating it will “fight this lawsuit aggressively” ([3]). The case is part of a broader surge in AI-related litigation: an industry tracker counts over 160 lawsuits against AI developers (covering copyright, privacy, defamation, and more) as of 2026 ([4]). With courts yet to clarify the legal boundaries of AI training, this lawsuit could set a precedent that influences how tech companies handle data and IP in AI projects going forward.
Enterprises employing generative AI should heed this trend. The wave of lawsuits highlights the importance of diligent data governance and respecting IP rights in AI development. Companies need to vet their training data sources, obtain appropriate licenses, and document how datasets are used. Beyond legal liability, there’s also reputational risk – clients and partners are increasingly sensitive to unethical AI practices. By proactively establishing robust AI ethics and compliance programs, businesses can reduce exposure to lawsuits and position themselves as trustworthy innovators in an era of intensifying scrutiny.
The risks of unregulated AI outputs came into sharp focus with news of a criminal investigation into one of tech’s most prominent companies. French prosecutors have opened a probe into Elon Musk’s X (formerly Twitter) following revelations that its AI chatbot, Grok, was used to produce and disseminate illicit content ([1]). Investigators allege that X – and potentially Musk personally – facilitated the generation of non-consensual sexually explicit deepfakes and child sexual abuse images, as well as the spread of disinformation (including Holocaust denial) via the Grok AI system ([2]) ([3]). Musk and X’s former CEO were summoned by authorities in April but refused to cooperate, dismissing the inquiry as a 'political attack'; French regulators have indicated the investigation will proceed regardless ([4]).
This marks one of the first instances where a social media platform and its executives face criminal scrutiny for an AI-driven content failure. It serves as a stark warning to all organizations deploying generative AI: enabling users to create harmful or illegal material can lead to swift and severe legal consequences. Companies cannot assume that disclaimers or user agreements alone will shield them from liability – regulators are increasingly willing to hold platforms accountable for AI-related harms to consumers and society.
For senior leaders, the imperative is to elevate AI safety and content moderation to a top-tier governance priority. Enterprises should implement rigorous oversight for any AI features that could be misused, investing in preventative measures like content filters, user monitoring, and incident response plans. As AI-driven incidents attract global regulatory attention, a proactive stance on AI risk management isn’t just best practice – it’s essential to safeguarding the company’s legal standing and public trust.