SMARTHAUSThe Mathematically Governed AI Fabric
Investors ↗ Twenty minutes

Why now

The rulebook moved twice this year.

In 2026 the two flagship artificial-intelligence laws in the world both moved their own goalposts. One deferred by sixteen months. One was repealed and rewritten by the state that passed it. Anyone who built a control programme against the text of either rebuilt it this year.

SectionWhy Now
Figures as atSeptember 2026
OwnerSMARTHAUS Engineering
Every claimdated and attributed
REGULATIONS CHANGE. THE SHAPE OF A RULE DOES NOT. COLORADO SB 26‑189 14 MAY 2026 EFFECTIVE 30 JUNE 2026 1 JANUARY 2027 ABOUT risk-based framework disclosure and transparency ONE SENTENCE, REWRITTEN BY A PERSON LOCKED · HASHED “a person is told when an automated decision is made about them” THE RULE, RE-PROVED GORECONSTRUCTEDPROVED IN A KERNELCHECKED BY THE ORACLE OPERATIONS CENTER ACTION GATEnew rule · sealed MODEL OUTPUTnew rule · sealed SHIPPED SOFTWAREnew rule · sealed 1RULE RE-PROVED0RETRAINED0REDEPLOYED

What happened in 2026

Not a forecast. A record.

Four things, all of them in the last nine months, all of them verifiable.

14 May 2026

Colorado repealed and replaced its own AI Act

Senate Bill 26‑189 moved the effective date from 30 June 2026 to 1 January 2027 and threw out the risk-based framework entirely — no duty of care against algorithmic discrimination, no deployer obligation to run a risk-management programme. What replaced it is a narrower regime about disclosure and transparency.

A landmark law, repealed by the legislature that passed it, two years after passing it.

27 July 2026

The European Union deferred its high-risk obligations by sixteen months

The Digital Omnibus — Regulation (EU) 2026/1744 — entered into force and moved the Annex III high-risk deadline from 2 August 2026 out to 2 December 2027. For AI embedded in products already covered by product-safety law, the deferral runs to 2 August 2028.

But not everything moved. Article 50 transparency, the general-purpose AI obligations in force since August 2025, and the Article 5 prohibitions in force since February 2025 all stayed exactly where they were. So the date changed for part of the Act and not the rest of it.

Through 2026

Twenty-nine American states legislated

Eighty-four new AI laws across twenty-seven states by mid-year. By 1 July, 109 AI laws and 28 data-centre laws. Five states have comprehensive AI statutes in force or arriving on 1 January 2027 — California, Colorado, Texas, New York and Illinois — sitting on top of forty-odd narrower laws on deepfakes, hiring and chatbots.

There is no federal statute to harmonise any of it.

Ahead

Gartner expects fragmentation to quadruple

By 2030, fragmented AI regulation is forecast to quadruple and extend to 75% of the world's economies. Worldwide spending on AI governance platforms is forecast to pass one billion dollars by then, from $492 million in 2026.

The forecast is not that the rules settle. It is that there are four times as many of them, in three-quarters of the world.

What that does to a control programme

Everything built against the text has to be rebuilt.

Because in almost every product on the market, the rule is text — a paragraph in a policy document, a condition in a configuration file, a classifier trained to recognise the thing, or a map from your estate to a framework.

A classifier has to be retrained

Which is a machine-learning project with no fixed end date, and afterwards you still cannot say what it will do on a case nobody thought of.

A prompt has to be rewritten

And nothing anywhere proves the new wording covers what the old wording covered, or states what either fails to cover.

A framework map has to be redrawn

One major platform's pitch is a knowledge graph fusing global regulatory intelligence with business context. That is a map of a landscape that was redrawn twice this year.

A control that tracks the rulebook inherits every movement of the rulebook.

The other way round

Regulations change. The shape of a rule does not.

A disclosure limit, a lending decision, a sanctions screen, a spending cap, a retention window, an adverse-action test. Every one of them reduces to a bounded decision — a threshold, an arithmetic test, a bounded state machine, an admission or classification call.

The clause moves
a provision is amended, deferred, repealed or replaced
→
One sentence is rewritten
in English, by a person, locked and hashed
→
The rule is re-proved
reconstructed, proved in a kernel, checked back by the oracle
→
Operations Center delivers it
to every runtime holding the old one, wherever it is running
→
The record still joins
back through the proof to the person who wrote the sentence

Nothing is retrained. Nothing is redeployed. The runtime never moves — which matters most at the one seam where it could not move even if you wanted it to, because it is running inside software you already shipped to somebody else's infrastructure.

That is the whole reason the embedded seam works at all, and it is why Operations Center is not a console. It is the mechanism by which a changed rule reaches a runtime you can no longer reach any other way.

How a rule gets proved in the first place →

What this does not do

Stated before you ask.

It does not tell you what the rule should say

Somebody in your organisation reads the clause and writes the sentence. We remove every argument about which sentence was used, and none about whether it was the right one.

It does not make you compliant

Compliance is a judgement made by people and regulators about a whole organisation. This produces the evidence underneath one control. Those are different things and conflating them would be the easiest lie on this site.

It does not cover rules that cannot be made precise

If a rule will not reduce to a bounded decision, nobody can enforce it — not us and not the product you would buy instead. The difference is that we say so inside the package, in a form a machine can check.

Sources

Every claim on this page, with its date.

14 May 2026Colorado SB 26‑189Repeals and replaces the Colorado AI Act; effective date moved to 1 January 2027; risk-based framework removed in favour of disclosure and transparency. Skadden analysis
27 July 2026Regulation (EU) 2026/1744The Digital Omnibus. Annex III high-risk obligations deferred to 2 December 2027; Annex I to 2 August 2028; Article 50, GPAI and Article 5 unchanged. Gibson Dunn · Cooley
Mid-202684 new AI laws in 27 statesAmerican state legislative activity through the first half of 2026. Transparency Coalition
Feb 2026Gartner on regulatory fragmentationFragmented AI regulation forecast to quadruple by 2030 and reach 75% of the world's economies; AI governance platform spend $492M in 2026 passing $1B by 2030. Gartner
Sept 2023–May 20267,246 AI incidents analysed344 enterprise-relevant; 188 autonomous systems causing direct harm with no attacker; 137 real-world damage cases, 65 involving deletion or code destruction. Includes the April 2026 production-database deletion. Cyera research

Third-party figures, linked rather than paraphrased, so you can check them. This page is dated and owned; if something here goes stale, that is our failure and not your discovery.

Start at one seam

The test takes twenty minutes and it does not involve a regulation.

Connect your own coding agent, ask it to do something that writes, deny it, and confirm in your own environment that nothing happened. Then read the record back through the rule to the sentence somebody wrote. If that chain holds, the regulatory argument on this page follows on its own.

Book the twenty minutes