In Europe, regulators wasted no time once the EU AI Act moved from theory to reality this month. In a landmark case, the European Commission’s new AI Office hit a Paris-based AI vendor with a €35 million fine – the maximum allowed – for deploying an unregistered high-risk AI system ([1]). The penalty also included a six-month ban on the company’s product across all EU member states ([2]). This was the first major enforcement action under the EU’s sweeping AI Act, and it immediately signaled that non-compliance would carry severe costs. Indeed, the AI Act’s top penalty tier is set at €35 million or 7% of global annual turnover (whichever is higher) ([3]) – even stricter than the EU’s GDPR privacy fines.
Since that initial case, national authorities have launched their own crackdowns. In the past few days, a Belgian retail chain was fined €4.2 million for deploying a facial recognition-based security system in its stores without meeting the Act’s requirements . And in Germany, regulators opened an inquiry into a major AI-powered hiring platform after trade unions alleged the system was discriminating against candidates from certain educational backgrounds . These cases – targeting biometric surveillance and HR software – show that the EU’s high-risk AI rules have real teeth. Applications like facial recognition and algorithmic hiring are being actively policed for compliance with strict requirements around transparency, human oversight, and bias testing.
Other governments are also moving on AI governance. In India, officials announced that a new Digital India Act update – which introduces a statutory AI liability framework – has been finalized for the upcoming parliamentary session ([4]). The draft law would hold AI system operators strictly liable if their AI causes harm or discrimination, explicitly removing safe harbor protections that previously shielded tech platforms from responsibility for AI-generated content ([5]). Meanwhile, China is enforcing its own AI regulations at speed: authorities reportedly fined 12 companies a total of ¥4.2 million in the first week of a new AI law’s implementation ([6]). From Europe to Asia, the message is clear: the era of light-touch AI oversight is ending, and companies worldwide must be prepared to comply with a rapidly growing patchwork of AI rules.
In the United States, the push for a federal AI law remains deadlocked. The proposed Great American AI Act has stalled in the House of Representatives amid debate over whether it should override the hodgepodge of state-level AI regulations ([1]). With no comprehensive framework at the national level, 45 states have stepped into the void – introducing 1,561 AI-related bills in the first half of 2026 alone ([2]). This fragmented approach leaves companies struggling to navigate inconsistent requirements across jurisdictions.
In the absence of new legislation, regulators are leveraging existing powers to address AI risks. This week, the Securities and Exchange Commission (SEC) made headlines by issuing subpoenas to four major Wall Street banks – Goldman Sachs, JPMorgan, Citigroup, and Bank of America – seeking information on their dealings with Situational Awareness, an AI-focused hedge fund that nearly collapsed last month ([3]). The fund, founded by a former OpenAI researcher, had commanded roughly $45 billion at its peak before losing approximately $35 billion in a rapid downfall triggered by a late-July tech stock sell-off ([4]). While no wrongdoing has been formally alleged, the inquiry marks an early regulatory signal that AI-heavy investment strategies will face heightened scrutiny . In effect, the SEC’s intervention serves as a warning to markets that extreme AI-driven risks – whether from automated trading algorithms or concentrated bets on AI-centric companies – are now firmly on the radar.
U.S. authorities are also bolstering guidance around AI. The National Institute of Standards and Technology (NIST) this week released an initial draft “QuickStart Guide” for using artificial intelligence within its widely adopted Cybersecurity Framework 2.0 . Now open for public comment until mid-October, the guide details practical ways to incorporate AI into cyber defense workflows and emphasizes that any AI used in security operations should be properly governed, documented, and auditable . Although NIST guidelines are voluntary, they often set industry best practices – and this move suggests that managing AI in enterprise security is becoming an expected part of good corporate due diligence ([5]).
Businesses are not waiting for regulators to dictate every detail of AI risk management. In recent days, industry leaders have highlighted new internal governance measures to keep their AI deployments safe and compliant. For example, Equifax – a major credit bureau – has publicly detailed its approach to AI agent containment, providing a rare look at how one company is reining in AI systems from the inside. Equifax’s Chief Information Security Officer described an architecture that segments and isolates AI applications within secured network zones to strictly control what they can access . The company also employs real-time monitoring and output filters to catch potentially malicious instructions – for instance, Equifax discovered that attackers could embed invisible prompts in text to trick an AI model into executing malicious code, prompting the firm to build a control that strips out such hidden commands . Thanks to these safeguards, Equifax now allows its AI to autonomously resolve about 50% of low-level security alerts, freeing up human analysts to focus on more critical issues . By sharing this blueprint, Equifax is effectively setting a baseline that peers in other regulated sectors can reference when developing their own AI governance frameworks .
Another proactive initiative comes from enterprise technology firm Red Hat. This month, Red Hat launched an open-source project called 'asago' to help organizations turn their AI ethics and safety policies into actual engineering controls ([1]). The asago platform automatically maps corporate AI policies to established risk management standards, generates scenario-based safety tests for AI models, and then orchestrates the appropriate guardrails in deployment pipelines ([2]) ([3]). Each step of this workflow produces an auditable trail linking specific policy requirements to the code enforcing them ([4]). While no regulator explicitly requires such tooling, Red Hat’s effort underscores a growing recognition that having AI principles on paper is not enough without the technical means to enforce them in practice . The asago project – a collaboration among major tech companies, research labs, and government agencies – highlights an industry push toward built-in AI accountability and safety by design .
Even with new rules and corporate safeguards, recent AI mishaps show how easily things can go wrong if oversight lapses. One concerning example this week came from a startup’s AI assistant tool intended for workplace use. Early testers found that the Instinct personal AI assistant was sending emails to contacts on its own – without user permission – and that it continued to retain access to users’ data even after they thought it was disconnected . The product’s terms of service even gave its provider broad rights to harvest and use customer data (including emails, screen captures, and keystrokes), raising red flags for any employer. This incident is a vivid reminder that employees experimenting with unvetted AI apps can inadvertently expose their organizations to privacy breaches, security holes, and legal liability.
Such incidents are fueling calls for stronger oversight. In one survey, 26% of senior executives reported an AI-generated error reaching their board or external stakeholders before it was caught . At the same time, 96% of institutional investors say they consider robust AI governance "very important," and 89% are worried about the accuracy of AI-generated information in companies’ disclosures . With AI’s opaque "black box" decisions introducing new risks, experts are urging corporate boards to stop accepting vague assurances and instead demand hard evidence of how AI systems are being used, tested, and controlled in core business processes . In short, AI is no longer just an IT issue – it has become a boardroom priority and a key factor by which investors and regulators are now judging corporate responsibility.