On September 15, the European Union’s AI Act moved from theory to practice with its first binding compliance requirement ([1]). Providers of large general-purpose AI models (those trained on more than 10^25 FLOPs of data) were required to submit 'systemic risk' evaluation reports to the European AI Office, documenting safety tests, energy usage, and how they handled copyrighted training data ([2]).
This deadline marks an inflection point for Europe’s sweeping AI regulation. The AI Act – the world’s first comprehensive AI law – now has real teeth, with violations carrying fines up to €35 million or 7% of a company’s global revenue ([3]). The obligation to analyze and disclose risks for powerful AI systems signals that EU regulators are serious about holding companies accountable for the impacts of their algorithms. The new European AI Office is expected to scrutinize these risk filings and could initiate audits or penalties if submissions are incomplete or reveal non-compliance.
For enterprises, the message is clear: the era of 'move fast and break things' in AI is ending in EU markets. Companies using or selling AI systems in Europe must invest in rigorous risk management, transparency, and compliance processes now. The EU’s aggressive approach is likely to influence other jurisdictions, making strong AI governance not just a legal mandate but also a competitive advantage on the global stage.
The UK’s 'pro-innovation' approach to AI governance – emphasizing industry-led cooperation over regulation – faced a major setback this week. The U.S.-based AI firm Anthropic declined a request to provide the UK’s new AI Security Institute with pre-release access to its latest frontier model, Mythos 5.1, for safety testing ([1]). It is the first time a leading AI developer has rebuffed the Institute, which was set up to evaluate high-risk 'frontier' AI systems for potential harms.
UK officials suspect that pressure from Washington played a role in Anthropic’s unprecedented decision ([2]). The incident has prompted fears of a 'protectionist' shift among U.S. AI companies, who may become less willing to share information about advanced models abroad ([3]). Britain’s inability to examine one of the most advanced AI systems (undercutting the core mission of its AI Safety Institute) has raised concerns that voluntary, trust-based oversight is insufficient when national interests are at stake.
In response, British lawmakers are considering a tougher approach. Parliament is debating a 'Superintelligent AI Bill' that would grant regulators explicit legal authority to mandate access to advanced AI models for safety evaluations, even when those models are developed by foreign firms ([4]). For businesses – especially those operating across the US-UK divide – this turn of events is a cautionary tale. What is voluntary in one jurisdiction may rapidly become compulsory in another, and companies must be prepared to navigate diverging AI regulations to avoid regulatory and reputational risks.
With no overarching federal AI law, states like Colorado have begun implementing their own rules, and that patchwork approach is now sparking conflicts. Colorado’s recently passed AI transparency law (taking effect in 2027) requires companies to give notice and explanations when automated systems significantly influence important decisions in areas such as loans, hiring or healthcare ([1]) ([2]). It also obliges businesses to offer consumers a way to request human review of high-stakes algorithmic outcomes, reflecting the rising demand for fairness and accountability in AI-driven services ([3]).
However, federal regulators are pushing back on state-level AI mandates. The U.S. Federal Trade Commission has warned that certain state requirements could be nullified by federal law ([4]). In July, the FTC proposed a policy statement warning that undisclosed modifications to AI outputs (dubbed 'suppression of accuracy') – for instance, altering algorithmic results to reduce bias without informing users – may be deemed an unfair or deceptive practice under the FTC Act ([5]). The U.S. Department of Justice even intervened in an ongoing court case (xAI v. Colorado) to argue that Washington may assert federal preemption over state AI laws, potentially overriding statutes like Colorado’s ([6]).
These state-versus-federal tensions make U.S. AI governance especially challenging for companies ([7]). Until courts resolve the preemption issue, businesses must comply with the new state AI laws while keeping a close eye on federal policy shifts. The momentum of state regulations, plus high-profile federal enforcement actions (for example, the FTC’s $930,000 fine and 20-year compliance order against a company over a so-called AI marketing scheme) ([8]), signals that broader U.S. AI regulation is on the horizon. Forward-looking firms should strengthen their AI governance programs now – adopting robust transparency, risk assessment, and oversight practices – to be prepared for both today’s state rules and tomorrow’s federal standards.
Brazil has made history by becoming the first Latin American country to enact a comprehensive AI law ([1]). On September 16, Brazil’s Chamber of Deputies approved Bill 2338/2023 after years of debate, establishing an “Artificial Intelligence Legal Framework” that mirrors the EU’s risk-based approach to AI governance ([2]).
The law defines categories of AI systems by risk level. At the highest tier, 'excessive risk' applications – deemed too dangerous, such as mass surveillance without legal basis – will be banned outright, while high-risk systems (for example, AI in biometric ID, credit scoring, judicial decisions, or critical infrastructure) must adhere to strict transparency and safety requirements ([3]) ([4]). The provisions will be phased in over a 12- to 24-month implementation period, with key obligations like mandatory risk assessments and bias auditing expected to take effect by 2027–2028 ([5]). Enforcement will fall to Brazil’s National Data Protection Authority (ANPD), leveraging its existing capabilities from the data protection realm ([6]). Non-compliant companies can face fines up to 2% of their Brazilian annual revenue per violation (capped at R$50 million, or around US$10 million) ([7])—a substantial penalty even if it is narrower than the EU AI Act’s global 7% revenue cap for the most serious offenses.
For businesses active in Brazil, the new law is a clear signal to accelerate AI governance efforts ([8]). Companies should promptly identify and categorize their AI systems under the law’s risk tiers, and implement the required disclosures, oversight, and risk mitigation measures for any high-risk AI activities ([9]). Brazil’s move, following major regulatory initiatives in the EU and China, could inspire similar legislation across the region. Multinationals will need adaptive compliance strategies as more countries adopt their own AI regulations, making proactive, robust AI governance a necessity for sustainable operations.
China reinforced its security-centric approach to AI with the introduction of the 'AI Safety Governance Framework 3.0' this week ([1]). Announced on September 14 at the opening of China’s 2026 Cybersecurity Week, the framework—developed by the national cybersecurity standards committee (TC260)—expands AI oversight across the entire development lifecycle, from data and algorithms to models, applications, and even supply chains ([2]).
Framework 3.0 adds more granular risk categories and controls to address cutting-edge technology. Notably, it includes a dedicated focus on the dangers posed by autonomous AI agents and scenarios where AI systems could compromise cybersecurity or operate without human control ([3]). The guidelines also urge the creation of 'flexible, dynamic, and controllable' sandbox environments to test advanced AI systems, ensuring that high-risk innovations can be evaluated and managed safely before wide deployment ([4]). These measures aim to preempt emerging threats from “frontier” AI applications by enforcing safety checks and human oversight from the outset.
While not legally binding, China’s national frameworks often foreshadow mandatory regulations and enforcement practices ([5]). The new framework explicitly emphasizes the 'primary responsibility' of companies to ensure AI safety and ethics, as part of a coordinated governance approach with government and industry bodies ([6]). Companies doing business in China should treat these guidelines as a clear signal of regulatory direction and should strengthen their AI risk management, data governance, and security testing in line with Framework 3.0 to stay ahead of compliance obligations.