Why now
The rulebook moved twice this year.
In 2026 the two flagship artificial-intelligence laws in the world both moved their own goalposts. One deferred by sixteen months. One was repealed and rewritten by the state that passed it. Anyone who built a control programme against the text of either rebuilt it this year.
What happened in 2026
Not a forecast. A record.
Four things, all of them in the last nine months, all of them verifiable.
Colorado repealed and replaced its own AI Act
Senate Bill 26‑189 moved the effective date from 30 June 2026 to 1 January 2027 and threw out the risk-based framework entirely — no duty of care against algorithmic discrimination, no deployer obligation to run a risk-management programme. What replaced it is a narrower regime about disclosure and transparency.
A landmark law, repealed by the legislature that passed it, two years after passing it.
The European Union deferred its high-risk obligations by sixteen months
The Digital Omnibus — Regulation (EU) 2026/1744 — entered into force and moved the Annex III high-risk deadline from 2 August 2026 out to 2 December 2027. For AI embedded in products already covered by product-safety law, the deferral runs to 2 August 2028.
But not everything moved. Article 50 transparency, the general-purpose AI obligations in force since August 2025, and the Article 5 prohibitions in force since February 2025 all stayed exactly where they were. So the date changed for part of the Act and not the rest of it.
Twenty-nine American states legislated
Eighty-four new AI laws across twenty-seven states by mid-year. By 1 July, 109 AI laws and 28 data-centre laws. Five states have comprehensive AI statutes in force or arriving on 1 January 2027 — California, Colorado, Texas, New York and Illinois — sitting on top of forty-odd narrower laws on deepfakes, hiring and chatbots.
There is no federal statute to harmonise any of it.
Gartner expects fragmentation to quadruple
By 2030, fragmented AI regulation is forecast to quadruple and extend to 75% of the world's economies. Worldwide spending on AI governance platforms is forecast to pass one billion dollars by then, from $492 million in 2026.
The forecast is not that the rules settle. It is that there are four times as many of them, in three-quarters of the world.
What that does to a control programme
Everything built against the text has to be rebuilt.
Because in almost every product on the market, the rule is text — a paragraph in a policy document, a condition in a configuration file, a classifier trained to recognise the thing, or a map from your estate to a framework.
A classifier has to be retrained
Which is a machine-learning project with no fixed end date, and afterwards you still cannot say what it will do on a case nobody thought of.
A prompt has to be rewritten
And nothing anywhere proves the new wording covers what the old wording covered, or states what either fails to cover.
A framework map has to be redrawn
One major platform's pitch is a knowledge graph fusing global regulatory intelligence with business context. That is a map of a landscape that was redrawn twice this year.
A control that tracks the rulebook inherits every movement of the rulebook.
The other way round
Regulations change. The shape of a rule does not.
A disclosure limit, a lending decision, a sanctions screen, a spending cap, a retention window, an adverse-action test. Every one of them reduces to a bounded decision — a threshold, an arithmetic test, a bounded state machine, an admission or classification call.
Nothing is retrained. Nothing is redeployed. The runtime never moves — which matters most at the one seam where it could not move even if you wanted it to, because it is running inside software you already shipped to somebody else's infrastructure.
That is the whole reason the embedded seam works at all, and it is why Operations Center is not a console. It is the mechanism by which a changed rule reaches a runtime you can no longer reach any other way.
What this does not do
Stated before you ask.
It does not tell you what the rule should say
Somebody in your organisation reads the clause and writes the sentence. We remove every argument about which sentence was used, and none about whether it was the right one.
It does not make you compliant
Compliance is a judgement made by people and regulators about a whole organisation. This produces the evidence underneath one control. Those are different things and conflating them would be the easiest lie on this site.
It does not cover rules that cannot be made precise
If a rule will not reduce to a bounded decision, nobody can enforce it — not us and not the product you would buy instead. The difference is that we say so inside the package, in a form a machine can check.
Sources
Every claim on this page, with its date.
Third-party figures, linked rather than paraphrased, so you can check them. This page is dated and owned; if something here goes stale, that is our failure and not your discovery.
Start at one seam
The test takes twenty minutes and it does not involve a regulation.
Connect your own coding agent, ask it to do something that writes, deny it, and confirm in your own environment that nothing happened. Then read the record back through the rule to the sentence somebody wrote. If that chain holds, the regulatory argument on this page follows on its own.