---
title: "AI Regulation"
date: 2026-07-12
description: AI regulation has split into incompatible regimes, and the Board's task is not compliance with each but a deliberate position across all of them.
author: Mario Thomas
canonical: https://mariothomas.com/briefings/ai-regulation/
---

## Start here

Two short reads that frame the regulatory moment and set the order to take this briefing in.

### The End of the Single Rulebook

AI regulation is no longer one conversation. The EU AI Act, in force since August 2024 with penalties reaching €35 million or 7% of global turnover, builds a risk-based regime on transparency and trust. The United States has moved the opposite way, with an AI Action Plan that prioritises deregulation and speed. The UK has declined to legislate for AI as such but has rewritten its automated decision-making rules: since February 2026, four statutory safeguards apply to any significant decision taken solely by automated processing. These are not three versions of one rulebook. They are three different bets about where AI value comes from.

The Boards I meet tend to make one of two errors here. The first is treating regulation as a compliance exercise to be delegated: a maze for the legal function to navigate while the strategy proceeds unchanged. The second is assuming that a policy on file is the same as a capability in operation. The UK regime is the sharpest illustration: the law now requires that automated decisions can be explained, contested, and intervened in, and most of the probabilistic systems Boards have already approved cannot deliver that in practice.

The position these articles take is that regulation is a strategic question before it is a legal one. Trust, speed, and control cannot be maximised simultaneously; that is the [AI Sovereignty Trilemma](/blog/ai-sovereignty-board-trilemma/) model, and every architectural and market decision now takes a position on it whether or not anyone names it. Governance done well is not a tax on ambition. It is the trust infrastructure that positions an organisation to deploy faster and more widely than competitors still improvising, and compliance capability itself can become a competitive moat.

Read this briefing to be able to make one judgement: whether the organisation's regulatory position, meaning the standard it runs to, the jurisdictions it depends on, and the capabilities behind the systems it has approved, was chosen deliberately or arrived at by drift. Not choosing is itself a choice, and it is the most common one.

### From the Maze to a Position

Start with the core pieces in [the articles](#core-reading), in order. The sequence opens with the regulatory maze itself: what the EU AI Act requires, tier by tier, and five actions a Board can take now. Its tier table shows the timetable as it stood when that piece was written, and the piece that follows supersedes it. That piece records the deadline that moved: the high-risk obligations deferred to December 2027 and August 2028 six days before the first of them applied, the duties that did not move, and what a Board's reaction reveals about what its governance was anchored to. The sequence then picks up the EU's General-Purpose AI Code of Practice and the American counterpoint, and makes the case for dual-track governance, before stepping back to the structural picture: the Sovereignty Trilemma, and the three strategic stances open to an organisation operating across incompatible regimes.

The wider reading deepens specific fronts. The 2025 retrospective records the year the regimes hardened and then began to flex, the bridge between the Act as written and the deadline that moved. The Reasoning Gap covers the UK's automated decision-making regime and the capability it quietly assumes. The trilemma follow-up records the day the structural argument became a dated event, when a government directive forced a provider to withdraw two frontier models from every customer overnight. The pieces on inherited values, UK energy sovereignty, and automated reasoning extend the argument into ethics, infrastructure, and the standard of assurance regulators are moving toward.

Then go to [Remake](#remake-assets) for the mechanisms that turn the thinking into working apparatus, and finish with [the questions](#faqs), which are the ones directors put to me most often on this subject. If you take one thing away, make it this: the reading order runs from what the rules say to what the organisation's position is, because that is the order in which the Board's judgement has to form.

## Core reading

The core sequence runs from the rules as written, to the deadline that moved, to the transatlantic divergence, to the strategic choice that fragmentation forces on every Board.

1. [Navigating the AI Regulatory Maze: A Boardroom Survival Guide](https://mariothomas.com/blog/eu-ai-act/) (14 minute read, 16 March 2025): The EU AI Act is in force, with fines up to €35 million or 7% of turnover. Boards must comply without losing speed.
2. [The Deadline Moved: What the EU AI Act Deferral Reveals About Boards](https://mariothomas.com/blog/eu-ai-act-deferral/) (10 minute read, 9 August 2026): The EU deferred its AI Act high-risk obligations six days before they applied. What a moving deadline reveals about where Board governance is anchored. Podcast edition: 11 minute listen.
3. [Why Boards Need to Watch the EU's General-Purpose AI Code of Practice](https://mariothomas.com/blog/eu-gpai-code-board-strategy/) (15 minute read, 24 August 2025): The EU's General-Purpose AI Code of Practice marks regulatory divergence: Europe sets transparency guardrails while America deregulates. Boards must now choose between transparency and speed.
4. [AI Sovereignty: A Board's Guide to Navigating Conflicting National Agendas](https://mariothomas.com/blog/ai-sovereignty-board-trilemma/) (15 minute read, 7 September 2025): AI governance is fragmenting into incompatible systems: Europe's transparency, America's scale, China's control. Boards can no longer serve all three; they have to choose.

## Further reading

- [The Reasoning Gap: The Capability the Law Now Demands of Boards](https://mariothomas.com/blog/the-reasoning-gap/) (11 minute read, 3 May 2026): UK law now requires four safeguards for solely automated decisions. Most Boards have approved probabilistic systems that cannot deliver them in operation. Podcast edition: 12 minute listen.
- [The AI Sovereignty Trilemma: When a Frontier Model Vanishes and Reality Bites](https://mariothomas.com/blog/ai-sovereignty-trilemma-reality/) (10 minute read, 14 June 2026): The visible cost of sovereignty deters Boards. The hidden cost of the convenient alternative was never shown, and that is the cost 12 June presented. Podcast edition: 11 minute listen.
- [Ethical AI: When the Model Imposes Values Your Organisation Did Not Choose](https://mariothomas.com/blog/ethical-ai-inherited-values/) (14 minute read, 17 May 2026): A foundation model arrives with a value system its provider built and the Board did not choose. The decision: accept it, reject it, or build. Podcast edition: 15 minute listen.
- [Beyond Regulatory Uncertainty: Thoughts on the UK's AI Sovereignty Challenge](https://mariothomas.com/blog/uk-ai-sovereignty-energy/) (11 minute read, 22 July 2025): Individual AI training clusters will soon need more electricity than whole nations generate. The UK's AI sovereignty ambition meets its energy reality.
- [From Probable to Provable: What Automated Reasoning Means for the Board](https://mariothomas.com/blog/automated-reasoning-explainer/) (13 minute read, 5 April 2026): Automated reasoning gives Boards access to proof, not probability. This article explains what it is, where it already operates, and why it changes governance. Podcast edition: 16 minute listen.
- [The Year AI Grew Up: Five Inflections That Changed the Strategic Calculus in 2025](https://mariothomas.com/blog/the-year-ai-grew-up/) (14 minute read, 30 December 2025): In 2025 Boards stopped asking what AI could do and started treating it as strategic infrastructure investment. Five connected inflections drove that shift. Podcast edition: 19 minute listen.

## Remake

The mechanisms beneath the thinking: the model, diagnostic, methodology, and principle from the Remake Library that turn this briefing into apparatus a Board can use.

- **Model: AI Sovereignty Trilemma**. The proposition that organisations and jurisdictions can optimise their AI posture for trust, speed or control, but not all three simultaneously, forcing deliberate strategic positioning rather than attempting to serve every market at once. [Remake Library](https://mariothomas.com/remake/library/ai-sovereignty-trilemma/)
- **Diagnostic: AI Amnesty Questionnaire**. The structured instrument for running an AI amnesty: ten sections capturing which tools employees actually use, the use cases they serve, the data they touch, the value already created, and the risks encountered, turning unknown unknowns into a governable inventory. [Remake Library](https://mariothomas.com/remake/library/ai-amnesty-questionnaire/)
- **Methodology: AI Amnesty**. The time-boxed programme that brings shadow AI under governance: a declaration window, typically 30 to 45 days, in which employees disclose all AI tool usage without fear of punishment, followed by the post-amnesty roadmap of rapid triage, governance guardrails, pilot launch, and ongoing operations. [Remake Library](https://mariothomas.com/remake/library/#ai-amnesty)
- **Principle: Minimum Lovable Governance**. Governance embedded in how work happens: proportionate to risk, continuous rather than episodic, and used because it works. [Remake Library](https://mariothomas.com/remake/library/minimum-lovable-governance/)

## Questions

The questions directors put to me most often about AI regulation, answered from the articles in this briefing.

### Does the EU AI Act reach us if we are not based in the EU?

For an organisation that serves EU markets, yes: the obligations follow the market, not the registered office, and 450 million consumers make the EU a non-optional market for most organisations serving global markets. The Act's risk-based tiers, phased from February 2025 to August 2028 after the 2026 deferral, determine what each of the organisation's systems must demonstrate, so the first step is [a comprehensive exposure assessment](/blog/eu-ai-act/) that maps every AI system, including those embedded in third-party tools, against those tiers.

### Should we run one global standard or vary our approach by market?

Both are defensible, and so is deliberately specialising in a single regime; what is not defensible is failing to choose. I set out [three strategic stances](/blog/ai-sovereignty-board-trilemma/): principled standardisation works when stakeholders value consistency over optimisation, adaptive localisation when the organisation can carry the complexity without losing its identity, and sovereign specialisation when regional depth matters more than global breadth. The test is which currency the organisation's markets actually reward: trust, speed, or control.

### Will regulation put us at a competitive disadvantage against less regulated rivals?

The argument runs the other way more often than Boards expect. Clear rules give organisations the certainty to invest, the stringent requirements concentrate on high-risk uses while leaving most applications lightly touched, and [compliance capability itself can become a differentiator](/blog/eu-ai-act/): organisations that govern AI efficiently reduce the compliance tax on innovation and earn a trust premium in markets where trust determines access. The organisations at a disadvantage are those paralysed by regulatory uncertainty, not those equipped to navigate it.

### We approved our automated decision systems before the UK rules changed. Are we exposed?

Quite possibly. Since 5 February 2026 the UK regime has required four safeguards for any significant decision taken solely by automated processing: information, representations, human intervention, and the right to contest. Rule-based systems carry that capability on the surface; [probabilistic systems do not](/blog/the-reasoning-gap/), and most were approved on accuracy metrics rather than on evidence they could explain a decision to the person it affected. The Board's move is to inventory approved systems by the character of their decision logic and treat the four safeguards as capability tests, not policy positions.

### How much governance machinery does AI regulation actually require?

Less than the compliance industry suggests. The GPAI Code rewards demonstrable progress and good faith rather than perfection, and the AI Act's tiers build proportionality in. The operating principle I recommend is [Minimum Lovable Governance](/remake/library/minimum-lovable-governance/): documentation proportionate to risk, governance embedded in how work happens rather than bolted on, and Board reporting focused on material risks and opportunities rather than compliance metrics. Most systems need a paragraph, not a dissertation; the discipline is knowing which systems need more.

### What changed for us when the EU deferred the high-risk deadline?

Less than the headlines suggest. The 2026 amendment moved the obligations for standalone high-risk systems, hiring, credit, and education among them, from 2 August 2026 to 2 December 2027, and those for high-risk AI embedded in regulated products to 2 August 2028. The rest held: from 2 August 2026 people must be told when they are interacting with AI, the AI literacy duty has applied since February 2025, and two new prohibitions arrive on 2 December 2026. The more revealing question is [what changed in the organisation's oversight when the date moved](/blog/eu-ai-act-deferral/): anything beyond filing dates means the governance was anchored to the statute, not the systems in production.

### Which of our deployments would count as high-risk under the EU AI Act?

The Act reserves the high-risk tier for systems that can affect people's health, safety, or fundamental rights: in standalone form, the software that screens job applicants, scores credit, or selects students; in embedded form, AI inside regulated products such as machinery, medical devices, and vehicles. By the Act's own design most deployments land in the limited or minimal tiers. The answer takes [an exposure assessment](/blog/eu-ai-act/) that maps every system, including those inside third-party tools, against the tiers, and [a written, defensible determination for each](/blog/eu-ai-act-deferral/). In my experience classification is where organisations are furthest behind, and the deferral bought time to do it properly, not permission to stop.

### Does the UK's choice not to legislate mean we have nothing to comply with?

No. The UK has declined to pass an AI statute and asks its existing regulators, the FCA, ICO, CMA, and Ofcom among them, to govern AI at the point of use, so obligations arrive by sector, not in one Act. Some are already hard law: since 5 February 2026 the UK GDPR, as amended by the Data (Use and Access) Act 2025, has required [four safeguards for any significant decision taken solely by automated processing](/blog/the-reasoning-gap/), with an ICO statutory code on AI in preparation. Beneath it sit directors' duties under the Companies Act 2006, which [never depended on an AI law](/blog/eu-ai-act-deferral/). Less legislation means more judgement, not less obligation.

## References

The legislation, regulatory texts, and research these articles draw on, for directors who want to go to the sources themselves.

- **EUR-Lex** (12 July 2024): [Regulation (EU) 2024/1689 (Artificial Intelligence Act)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689). The full text of the EU AI Act, the risk-based framework this briefing keeps returning to.
- **European Commission** (10 July 2025): [The General-Purpose AI Code of Practice](https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai). The General-Purpose AI Code of Practice in full, with its transparency, copyright, and safety and security chapters.
- **The White House** (23 July 2025): [White House Unveils America's AI Action Plan](https://www.whitehouse.gov/articles/2025/07/white-house-unveils-americas-ai-action-plan/). America's AI Action Plan, the deregulatory counterpoint that created the dual-track governance challenge.
- **legislation.gov.uk** (2025): [Data (Use and Access) Act 2025](https://www.legislation.gov.uk/ukpga/2025/18/contents). The Data (Use and Access) Act 2025, which rewrote the UK's automated decision-making regime.
- **Information Commissioner's Office** (17 December 2024): [Rights related to automated decision making including profiling](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/individual-rights/rights-related-to-automated-decision-making-including-profiling/). The ICO's guidance on rights related to automated decision-making, ahead of its statutory code of practice.
- **Court of Justice of the EU** (7 December 2023): [Case C-634/21 SCHUFA Holding (Scoring)](https://infocuria.curia.europa.eu/tabs/affair?sort=AFF_NUM-DESC&searchTerm=%2522C%252D634%252F21%2522&publishedId=C-634%2F21). The SCHUFA judgment, which sharpened what counts as a solely automated decision.
- **Institute of Directors** (2025): [AI Governance in the Boardroom](https://web.archive.org/web/20251121075957/https://www.iod.com/app/uploads/2025/09/AI-Governance-in-the-Boardroom-1c7612e872fa3fce3f9d6cad78b0b4ba.pdf). The IoD business paper on AI governance, including the expectation that a Board can pause or reverse an AI system.
- **Stanford HAI** (April 2025): [The 2025 AI Index Report](https://hai.stanford.edu/ai-index/2025-ai-index-report). The 2025 AI Index, including the 21% rise in legislative mentions of AI across 75 countries since 2023.
- **Politico** (4 July 2025): [Europe’s top CEOs ask EU to pause AI Act](https://www.politico.eu/article/top-european-ceos-plead-for-pause-in-ai-act/). The letter from 46 European CEOs warning of legal grey zones in the AI Act's implementation.
- **EU AI Champions Initiative** (3 July 2025): [Stop the Clock: an open letter on the EU AI Act](https://aichampions.eu/#stoptheclock). The Stop the Clock letter itself: the European CEOs' July 2025 request to pause the AI Act's obligations, which the Politico report above covers.
- **European Union** (8 July 2026): [Regulation (EU) 2026/1744 of the European Parliament and of the Council](https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng). The 2026 amendment that deferred the high-risk obligations to December 2027 and August 2028, added two prohibitions, and left the transparency duties in place.
- **Anthropic** (12 June 2026): [Statement on the US government directive to suspend access to Fable 5 and Mythos 5](https://www.anthropic.com/news/fable-mythos-access). The 12 June 2026 provider statement on the US directive that suspended two frontier models for every customer, the event the sovereignty piece turns on.
- **UK Government** (8 November 2006): [Companies Act 2006](https://www.legislation.gov.uk/ukpga/2006/46). Directors' duties under the Companies Act 2006, which never depended on an AI statute and underwrite every obligation this briefing describes.

## The ideas beneath this briefing

Ideas I've named and matured writing about AI Regulation: what each one means, and where it started.

- **Adaptive Localisation**: A strategy of running different AI approaches in different markets, tuned to each market's regulatory, cultural, or competitive conditions, deliberately trading consistency for regional advantage. For a Board, choosing this stance means accepting real complexity costs and being ready to answer why the organisation treats one market's rules differently to another's. [Read more](https://mariothomas.com/blog/ai-sovereignty-board-trilemma/)
- **Cultural Sovereignty**: The often-overlooked dimension where American, European and Chinese AI cultures embody different worldviews, disruption, deliberation and harmony, shaping architecture, governance and stakeholder engagement beyond regulation. [Read more](https://mariothomas.com/blog/ai-sovereignty-board-trilemma/)
- **Principled Standardisation**: A strategic stance applying the strictest global standard, typically European, everywhere, betting that trust and consistency create durable advantage in sectors such as healthcare and finance where trust determines access. [Read more](https://mariothomas.com/blog/ai-sovereignty-board-trilemma/)
- **Sovereign Specialisation**: A stance focusing entirely within one sovereignty domain, sacrificing global scale for deep alignment, clear governance, consistent stakeholder expectations and regional dominance. [Read more](https://mariothomas.com/blog/ai-sovereignty-board-trilemma/)
- **Sovereignty Premium**: The value stakeholders place on organisations that transparently manage sovereignty trade-offs rather than pretending they don't exist, manifesting as higher valuations, stronger partnerships and greater regulatory flexibility. [Read more](https://mariothomas.com/blog/ai-sovereignty-board-trilemma/)

All concepts: https://mariothomas.com/glossary/concepts/

## More Board Briefings

More complete resources on AI and emerging technology for the Boards that need the full picture.

- [AI Governance](https://mariothomas.com/briefings/ai-governance/): Governance people route around fails to govern; the task is governing AI the Board cannot fully see without strangling adoption.
- [AI Risk](https://mariothomas.com/briefings/ai-risk/): The AI risks that bite are seldom on the register, and the bill for sovereignty shocks, readiness gaps, verification costs, and model risk arrives later.
- [AI Accountability](https://mariothomas.com/briefings/ai-accountability/): Agency can move to the machine; accountability cannot, and answering for what AI decides now takes capability that policy alone does not supply.
- [AI Infrastructure](https://mariothomas.com/briefings/ai-infrastructure/): AI infrastructure now runs from the power station to the protocol, and energy access decides what an organisation can do with AI.
