June 17, 2026 ·

AI regulation stopped being theoretical this month

The Colorado AI Act commences 30 June 2026 and the EU AI Act is now in enforcement. Why the AI strategy document and the compliance posture are now the same document — and how to build for the principle, not the statute.

On 30 June 2026, the Colorado AI Act commences — the first broad US state law placing concrete obligations on the developers and deployers of high-risk AI systems. It lands in the same quarter that the EU AI Act’s high-risk obligations have moved from announcement to active enforcement. For two years, “AI regulation” was a panel-discussion topic and a slide in the strategy deck. This month it became a date on the calendar with a penalty attached. That is a different kind of thing to plan around.

The detail matters less than the shape, and the shape is consistent across both regimes. If your AI touches a consequential decision about a person — in employment, lending, insurance, housing, healthcare, education, or legal services — you now owe documented diligence: a risk-management programme, impact assessments before deployment, ongoing review for discriminatory outcomes, disclosure to the people affected, and a named route to report problems to a regulator. Colorado attaches civil penalties of up to twenty thousand dollars per violation and a safe harbour for organisations that can show they followed the programme. The EU’s numbers are larger. The structure is the same.

Why this changes buyer behaviour, not just compliance checklists

The interesting effect is upstream of the legal team. Once an AI system in a regulated workflow carries a documentation-and-impact-assessment obligation, the AI strategy document and the compliance posture stop being separate artifacts written by separate teams in separate quarters. They become one document. The question “should we automate this decision?” now arrives with “and can we evidence that it does not discriminate, explain it to the person it affects, and produce that evidence on demand?” attached to it from the start.

Most companies are not organised for that. The AI roadmap lives with a product or engineering leader. The compliance function gets consulted near the end, as a gate. We have watched several clients this quarter discover that a workflow they shipped last year — quietly, sensibly, with good intentions — is now a high-risk system that nobody assessed, documented, or designed to be explainable. None of the fixes were technically hard. All of them required someone senior to own the response, and most organisations do not yet have that person.

The trap of treating this as paperwork

The tempting response is to treat the new obligations as a documentation exercise — write the impact assessment, file the statement, move on. That works right up until a regulator, a journalist, or a litigant asks the question the documentation was supposed to answer: why did the system decide this, for this person, on this day? If the honest answer is “we wrote a policy document but cannot actually replay the decision,” the paperwork was theatre.

Real compliance for an AI system is an engineering property, not a binder. It means the system was built so that every consequential decision is logged with its inputs, the model’s reasoning is reconstructable, the human-oversight step is real rather than rubber-stamped, and the discrimination review runs on actual outputs rather than good intentions. You cannot bolt that on after the fact for a fraction of what it costs to design it in. The companies handling this best put the compliance question at the front of every AI engagement, not the back.

A footnote that matters: the rules themselves are moving

There is a wrinkle worth naming honestly. Colorado has already passed a successor law that repeals and replaces the act taking effect this month, with the replacement landing in January 2027. So you are being asked to comply with a regime that is itself about to change. The lesson is not “wait for it to settle” — it will not settle for years. The lesson is to build for the durable principle underneath the specific statute: that a high-risk AI decision must be documented, explainable, reviewable, and overseen by a human. Every version of every one of these laws asks for that. A system built to satisfy the principle survives the next revision of the rules. A system built to satisfy the exact wording of this month’s statute does not.

Mapping where your AI touches a regulated decision, and turning that into a ranked, costed plan that survives both your CFO and the next version of the law, is exactly what an AI strategy engagement is for. The output is not a compliance binder — it is a roadmap where the regulatory exposure of each opportunity is priced in from the start, so you are deciding what to build with the cost of doing it defensibly already on the table.

The honest counter-argument

If your AI does not touch a consequential decision about a person — an internal summariser, a code assistant, a forecasting tool that informs but does not decide — most of this does not apply to you yet, and you should not let a compliance panic slow down work that carries no regulatory weight. That is a real and large category. The mistake is assuming you are in it without checking. The workflows that quietly became high-risk did so because a tool that started as advisory got promoted into the decision loop without anyone re-asking the question. The cheap move is to map honestly which of your systems are on which side of that line before a regulator does it for you.

What to do in the next 30 days

  • Map where AI touches a regulated decision. Employment, lending, insurance, housing, healthcare, education, legal. Be honest about advisory tools that have crept into the decision itself.
  • Get the compliance owner into the AI roadmap. Not as a final gate — as a standing seat from the first conversation.
  • Test whether you can replay a decision. Pick one live high-risk system and try to reconstruct why it decided something last week. If you cannot, that is your first build.
  • Build for the principle, not the statute. Documented, explainable, reviewable, human-overseen. That survives the next rewrite of the rules; statute-specific hacks do not.

Regulation finally shaping buyer behaviour is, on balance, good news. It rewards the discipline we have argued for all along — readiness before features, an honest map of where AI touches the things that matter, and systems built to be explained rather than just deployed. The companies that resent it as a tax tend to be the ones who skipped that discipline. The ones who already had it are mostly just writing down what they already do.

Not sure which of your AI systems just became high-risk — or whether you could evidence one if a regulator asked? A Cravings AI strategy engagement maps your AI against the regulated-decision line, prices the cost of doing each opportunity defensibly, and hands you a ranked roadmap built for the durable principle, not this month’s exact statute.