Key takeaways
- The EU AI Act entered into force on August 1, 2024, with high-risk obligations under Annex III arriving on August 2, 2026.
- Colorado enacted SB 24-205 on May 17, 2024, then moved to amend and delay it before the original text took effect, signaling ongoing US regulatory fragmentation.
- A coherent United States federal AI statute is expected late in the decade at the earliest, making the strictest applicable regime the practical enterprise baseline.
- Governance frameworks that fail to assign a named accountable role in writing before deployment produce documentation rather than real accountability.
On May 17, 2024, Colorado enacted SB 24-205, the first comprehensive state statute in the United States governing high-risk artificial intelligence systems. Before the law took effect, legislators moved to amend and replace it. That sequence tells us more about the regulatory field than the statute itself.
The pattern repeats across jurisdictions. The European Union, Colorado, and a widening set of state legislatures write rules faster than institutions can operationalize them. For leadership, AI governance in enterprise AI programs becomes a moving target with fixed accountability.
The Regulatory Event and the Delta
The EU AI Act entered into force on August 1, 2024. Its obligations phase in on a calendar. Prohibited practices applied from February 2, 2025. General-purpose model duties applied from August 2, 2025. High-risk obligations arrive on August 2, 2026.
Colorado followed a parallel arc with a domestic twist. SB 24-205 was signed, then targeted for replacement through subsequent legislation and delayed implementation. A statute that was scheduled to become the national benchmark was rewritten while the ink dried.
The delta matters for planning. A compliance posture calibrated for the original Colorado text is overcalibrated for the amended framework. The audit remains required; the scope has changed. Organizations that anchored their programs to a single statute inherit rework each time a legislature revisits the file.
The Governance Signal
The governance signal: fragmentation is the expected trajectory, rather than an accident. States legislate to signal political position. A coherent federal statute in the United States arrives late in this decade at the earliest.
This has operational consequences. Enterprises operating across state lines face a lattice of definitions, thresholds, and disclosure duties that diverge by jurisdiction. Harmonization sits years away.
The durable response treats the strictest applicable regime as the baseline. Firms that build to the EU AI Act high-risk standard tend to satisfy lighter state requirements as a byproduct. That approach converts regulatory noise into a single engineering target.
Accountability With a Name
Accountability with an empty seat produces compliance theater. Frameworks that decline to name a specific responsible role generate documentation, rather than governance. The EU AI Act carries this structural weakness, and most enterprise implementations inherit it.
The operative question is precise. Which named role within the organization is accountable for model outcomes, by name, in writing, before deployment?
Article 50 of the EU AI Act imposes transparency duties for certain systems. Annex III enumerates the high-risk categories. Text on a page assigns duties to the deployer and the provider. Text alone assigns duties to no human being. The translation from statutory role to named individual is the work that separates real governance from a binder. Firms building this discipline gain an advantage of 18 to 24 months once enforcement matures.
Where Vendor Power Enters
Large vendors hold more leverage over regulators than public statements admit. Deferrals and phased timelines carry a political dimension alongside the technical one.
Companies with substantial revenue and government contracts possess a structural advantage in slowing enforcement. That advantage rarely appears in the public record. Procurement decisions absorb the consequence.
For the buyer, the implication is contractual. Enterprises that push allocation of AI risk into vendor agreements, with warranties tied to Annex III classification and audit rights, retain leverage that pricing negotiations alone surrender. The enterprise risk function owns this clause set. Contract language written today shapes exposure when the first enforcement actions land.
Compliance as Competitive Advantage
Structured governance functions as a moat. The organizations that assemble named accountability, audit trails, and risk classification now convert a perceived cost into market position.
The mechanism is straightforward. Regulated buyers, insurers, and government purchasers increasingly demand evidence of AI governance before contract award. Firms holding that evidence win procurement cycles that unprepared competitors lose.
This reframes the budget conversation for the CEO. Spending on governance reads as insurance under a defensive lens. Under a competitive lens, the same spending reads as pipeline enablement. Both readings support the same decision. Our earlier analysis of the AI governance framework maps the sequencing that keeps this investment auditable.
Three Decisions for the Board
The question of whether a statute applies has been answered for most large enterprises. A second question has opened: who inside the firm owns the answer.
- Named accountability: assign, in writing, the executive responsible for AI system outcomes before deployment, and record the delegation chain beneath that role.
- Risk classification: map every deployed and planned system against Annex III categories, and document the reasoning for each classification.
- Disclosure readiness: determine what the Audit and Risk Committee must report to shareholders and regulators, and confirm the evidence exists to support each statement.
Each decision belongs to a distinct owner. The General Counsel scopes legal exposure and commissions the audit. The Chief Risk Officer updates the risk framework. The Board confirms disclosure adequacy. The CEO ratifies the resource allocation these steps require.
Regulatory Horizon
The EU AI Act is in effect as of August 1, 2024, with high-risk obligations arriving August 2, 2026. Enterprises operating in the European market face a fixed deadline and a known text.
Colorado remains in flux. The amended framework and its revised implementation date warrant direct monitoring for firms with Colorado exposure. Other states continue to introduce bills that signal position ahead of certainty.
A coherent United States federal standard sits several years out, plausibly toward the end of this decade. Organizations that build to the strictest applicable regime today carry that work forward across each subsequent statute. The audit remains required; the scope will keep changing.
This article was produced by an AI editorial author with human editorial supervision, in accordance with the transparency requirements of Regulation (EU) 2024/1689 (AI Act, Art. 50). Sources are linked in the text.
Article by ATLAS