Skip to main content
AI Regulation
Board Briefing

AI Regulation

AI regulation has split into incompatible regimes, and the Board's task is not compliance with each but a deliberate position across all of them.

10 articles 6 audio Updated 9 August 2026

Start here

Two short reads that frame the regulatory moment and set the order to take this briefing in.

Start with this

The End of the Single Rulebook

AI regulation has fragmented into competing regimes, and the real exposure is a position the Board never chose.

2 minute read · Read →

Then read this

From the Maze to a Position

The core reads move from the rules, to the deadline that moved, to the divergence, to the choice; the rest deepens each front in turn.

2 minute read · Read →

Core reading

The core sequence runs from the rules as written, to the deadline that moved, to the transatlantic divergence, to the strategic choice that fragmentation forces on every Board.

  1. Navigating the AI Regulatory Maze: A Boardroom Survival Guide

    The EU AI Act is in force, with fines up to €35 million or 7% of turnover. Boards must comply without losing speed.

    14 minute read · 16 March 2025

  2. The Deadline Moved: What the EU AI Act Deferral Reveals About Boards

    The EU deferred its AI Act high-risk obligations six days before they applied. What a moving deadline reveals about where Board governance is anchored.

    10 minute read · 9 August 2026

    Read the article →or listen to the podcast version → 11 minute listen

  3. Why Boards Need to Watch the EU's General-Purpose AI Code of Practice

    The EU's General-Purpose AI Code of Practice marks regulatory divergence: Europe sets transparency guardrails while America deregulates. Boards must now choose between transparency and speed.

    15 minute read · 24 August 2025

  4. AI Sovereignty: A Board's Guide to Navigating Conflicting National Agendas

    AI governance is fragmenting into incompatible systems: Europe's transparency, America's scale, China's control. Boards can no longer serve all three; they have to choose.

    15 minute read · 7 September 2025

Further reading

Remake

The mechanisms beneath the thinking: the model, diagnostic, methodology, and principle from the Remake Library that turn this briefing into apparatus a Board can use.

Questions

The questions directors put to me most often about AI regulation, answered from the articles in this briefing.

Does the EU AI Act reach us if we are not based in the EU?

For an organisation that serves EU markets, yes: the obligations follow the market, not the registered office, and 450 million consumers make the EU a non-optional market for most organisations serving global markets. The Act’s risk-based tiers, phased from February 2025 to August 2028 after the 2026 deferral, determine what each of the organisation’s systems must demonstrate, so the first step is a comprehensive exposure assessment that maps every AI system, including those embedded in third-party tools, against those tiers.

Should we run one global standard or vary our approach by market?

Both are defensible, and so is deliberately specialising in a single regime; what is not defensible is failing to choose. I set out three strategic stances: principled standardisation works when stakeholders value consistency over optimisation, adaptive localisation when the organisation can carry the complexity without losing its identity, and sovereign specialisation when regional depth matters more than global breadth. The test is which currency the organisation’s markets actually reward: trust, speed, or control.

Will regulation put us at a competitive disadvantage against less regulated rivals?

The argument runs the other way more often than Boards expect. Clear rules give organisations the certainty to invest, the stringent requirements concentrate on high-risk uses while leaving most applications lightly touched, and compliance capability itself can become a differentiator: organisations that govern AI efficiently reduce the compliance tax on innovation and earn a trust premium in markets where trust determines access. The organisations at a disadvantage are those paralysed by regulatory uncertainty, not those equipped to navigate it.

We approved our automated decision systems before the UK rules changed. Are we exposed?

Quite possibly. Since 5 February 2026 the UK regime has required four safeguards for any significant decision taken solely by automated processing: information, representations, human intervention, and the right to contest. Rule-based systems carry that capability on the surface; probabilistic systems do not, and most were approved on accuracy metrics rather than on evidence they could explain a decision to the person it affected. The Board’s move is to inventory approved systems by the character of their decision logic and treat the four safeguards as capability tests, not policy positions.

How much governance machinery does AI regulation actually require?

Less than the compliance industry suggests. The GPAI Code rewards demonstrable progress and good faith rather than perfection, and the AI Act’s tiers build proportionality in. The operating principle I recommend is Minimum Lovable Governance: documentation proportionate to risk, governance embedded in how work happens rather than bolted on, and Board reporting focused on material risks and opportunities rather than compliance metrics. Most systems need a paragraph, not a dissertation; the discipline is knowing which systems need more.

What changed for us when the EU deferred the high-risk deadline?

Less than the headlines suggest. The 2026 amendment moved the obligations for standalone high-risk systems, hiring, credit, and education among them, from 2 August 2026 to 2 December 2027, and those for high-risk AI embedded in regulated products to 2 August 2028. The rest held: from 2 August 2026 people must be told when they are interacting with AI, the AI literacy duty has applied since February 2025, and two new prohibitions arrive on 2 December 2026. The more revealing question is what changed in the organisation’s oversight when the date moved: anything beyond filing dates means the governance was anchored to the statute, not the systems in production.

Which of our deployments would count as high-risk under the EU AI Act?

The Act reserves the high-risk tier for systems that can affect people’s health, safety, or fundamental rights: in standalone form, the software that screens job applicants, scores credit, or selects students; in embedded form, AI inside regulated products such as machinery, medical devices, and vehicles. By the Act’s own design most deployments land in the limited or minimal tiers. The answer takes an exposure assessment that maps every system, including those inside third-party tools, against the tiers, and a written, defensible determination for each. In my experience classification is where organisations are furthest behind, and the deferral bought time to do it properly, not permission to stop.

Does the UK’s choice not to legislate mean we have nothing to comply with?

No. The UK has declined to pass an AI statute and asks its existing regulators, the FCA, ICO, CMA, and Ofcom among them, to govern AI at the point of use, so obligations arrive by sector, not in one Act. Some are already hard law: since 5 February 2026 the UK GDPR, as amended by the Data (Use and Access) Act 2025, has required four safeguards for any significant decision taken solely by automated processing, with an ICO statutory code on AI in preparation. Beneath it sit directors’ duties under the Companies Act 2006, which never depended on an AI law. Less legislation means more judgement, not less obligation.

References

The legislation, regulatory texts, and research these articles draw on, for directors who want to go to the sources themselves.

EUR-Lex

Regulation (EU) 2024/1689 (Artificial Intelligence Act)

The full text of the EU AI Act, the risk-based framework this briefing keeps returning to.

European Commission

The General-Purpose AI Code of Practice

The General-Purpose AI Code of Practice in full, with its transparency, copyright, and safety and security chapters.

The White House

White House Unveils America's AI Action Plan

America’s AI Action Plan, the deregulatory counterpoint that created the dual-track governance challenge.

legislation.gov.uk

Data (Use and Access) Act 2025

The Data (Use and Access) Act 2025, which rewrote the UK’s automated decision-making regime.

Information Commissioner's Office

Rights related to automated decision making including profiling

The ICO’s guidance on rights related to automated decision-making, ahead of its statutory code of practice.

Court of Justice of the EU

Case C-634/21 SCHUFA Holding (Scoring)

The SCHUFA judgment, which sharpened what counts as a solely automated decision.

Institute of Directors

AI Governance in the Boardroom

The IoD business paper on AI governance, including the expectation that a Board can pause or reverse an AI system.

Stanford HAI

The 2025 AI Index Report

The 2025 AI Index, including the 21% rise in legislative mentions of AI across 75 countries since 2023.

Politico

Europe’s top CEOs ask EU to pause AI Act

The letter from 46 European CEOs warning of legal grey zones in the AI Act’s implementation.

EU AI Champions Initiative

Stop the Clock: an open letter on the EU AI Act

The Stop the Clock letter itself: the European CEOs’ July 2025 request to pause the AI Act’s obligations, which the Politico report above covers.

European Union

Regulation (EU) 2026/1744 of the European Parliament and of the Council

The 2026 amendment that deferred the high-risk obligations to December 2027 and August 2028, added two prohibitions, and left the transparency duties in place.

Anthropic

Statement on the US government directive to suspend access to Fable 5 and Mythos 5

The 12 June 2026 provider statement on the US directive that suspended two frontier models for every customer, the event the sovereignty piece turns on.

UK Government

Companies Act 2006

Directors’ duties under the Companies Act 2006, which never depended on an AI statute and underwrite every obligation this briefing describes.

Concepts

The ideas beneath this briefing

Ideas I’ve named and matured writing about AI Regulation: what each one means, and where it started.

Adaptive Localisation

A strategy of running different AI approaches in different markets, tuned to each market's regulatory, cultural, or competitive conditions, deliberately trading consistency for regional advantage. For a Board, choosing this stance means accepting real complexity costs and being ready to answer why the organisation treats one market's rules differently to another's.

Read the article →

Cultural Sovereignty

The often-overlooked dimension where American, European and Chinese AI cultures embody different worldviews, disruption, deliberation and harmony, shaping architecture, governance and stakeholder engagement beyond regulation.

Read the article →

Principled Standardisation

A strategic stance applying the strictest global standard, typically European, everywhere, betting that trust and consistency create durable advantage in sectors such as healthcare and finance where trust determines access.

Read the article →

Sovereign Specialisation

A stance focusing entirely within one sovereignty domain, sacrificing global scale for deep alignment, clear governance, consistent stakeholder expectations and regional dominance.

Read the article →

Sovereignty Premium

The value stakeholders place on organisations that transparently manage sovereignty trade-offs rather than pretending they don't exist, manifesting as higher valuations, stronger partnerships and greater regulatory flexibility.

Read the article →

More Board Briefings

More complete resources on AI and emerging technology for the Boards that need the full picture.

I use cookies to understand how my website is used. This data is collected and processed directly by me, not shared with any third parties, and helps me improve my website. See my privacy and cookie policies for more details.