Good Luck With All Those AI Regulation Fines They Are Not Telling You About
ai · September 3, 2026
Businesses are racing to deploy artificial intelligence, but AI regulation, transparency requirements, employment laws, privacy rules, and accountability obligations are catching up. The real AI conversation is shifting from capability to governance.
Everybody wants an AI agent.
Everybody wants automation.
Everybody wants the chatbot, the AI employee, the automated hiring system, the content machine, the lead qualifier, the customer service agent, and the magical workflow that supposedly eliminates half the work.
Cool.
I have another question.
Who is responsible when your AI system does something your business should not have allowed it to do?
That conversation is not nearly as popular.
It should be.
AI has officially entered the part of the technology cycle where governments, regulators, courts, employees, consumers, and attorneys start asking questions.
The questions are changing.
They are no longer simply:
What can artificial intelligence do?
They are becoming:
What are you allowed to do with it?
What must you disclose?
What decisions require human oversight?
What data did you use?
Who approved this system?
How was the decision made?
What happens when the AI gets it wrong?
And my personal favorite:
Who is responsible?
That last question is going to hurt some organizations.
The AI Gold Rush Created an Accountability Problem
Businesses have been encouraged to move fast.
Automate everything.
Replace repetitive work.
Build agents.
Connect your CRM.
Let AI answer customers.
Let AI qualify leads.
Let AI review applications.
Let AI analyze employees.
Let AI create content.
Let AI make recommendations.
Let AI make decisions.
Very little of the marketing around those tools has included another sentence:
Make sure you understand the legal, regulatory, privacy, employment, discrimination, intellectual property, disclosure, and documentation implications before you deploy this.
That part does not sell software very well.
It still matters.
The European Union's AI Act has created one of the world's most significant regulatory frameworks specifically addressing artificial intelligence.
Its penalty structure should get the attention of anyone who still believes AI governance is just corporate paperwork.
Certain violations can carry penalties reaching €35 million or 7 percent of worldwide annual turnover, depending on the violation and circumstances.
Other violations can carry penalties reaching €15 million or 3 percent of worldwide annual turnover.
Read that again.
We are no longer discussing theoretical guidelines about being responsible with technology.
We are discussing actual regulatory exposure.
"But My Business Is in America"
I can already hear somebody saying it.
"We are not in Europe."
Congratulations.
That does not mean you get to ignore AI governance.
The United States does not currently have one giant federal AI law identical to the EU AI Act.
Instead, businesses face something potentially more confusing.
A growing combination of federal enforcement, existing employment and discrimination law, consumer protection law, privacy requirements, state legislation, local rules, industry regulations, and AI-specific requirements.
That means the absence of one giant federal "AI Act" does not mean the absence of legal responsibility.
Your AI does not exist outside the laws already governing your business.
If your company could not legally discriminate without AI, adding an algorithm does not suddenly make discrimination acceptable.
If you could not deceive customers manually, automation does not create a deception exemption.
If certain information must be protected, putting that information into an AI workflow does not magically eliminate your responsibility to protect it.
If your organization has obligations surrounding employment decisions, consumer rights, privacy, records, or accessibility, artificial intelligence does not erase them.
AI changes the mechanism.
It does not automatically eliminate the responsibility.
The Problem Is Shadow AI
Here is where I believe many organizations are far more exposed than leadership realizes.
Employees are already using AI.
Managers are using it.
Marketing teams are using it.
HR departments are using it.
Contractors are using it.
Interns are using it.
Executives are using it.
Somebody probably connected an AI tool to company data six months ago and never told IT.
Someone else pasted confidential information into a chatbot because it saved twenty minutes.
Another person created an automated workflow that sends customer communications.
Another department might be using AI to evaluate resumes.
Nobody documented it.
Nobody classified the risk.
Nobody established an approval process.
Nobody defined what data could be entered.
Nobody determined whether human review was required.
Nobody created an incident response process.
That is Shadow AI.
The organization believes it has five AI systems.
It actually has 47.
Good luck governing something you do not even know exists.
Your AI Policy Cannot Be "Use Common Sense"
That is not governance.
That is hope.
Organizations need to know what AI systems are operating inside their environment.
At minimum, leadership should be able to answer:
- What AI systems are we using?
- What data can those systems access?
- What decisions can those systems influence?
- Which systems interact directly with customers or employees?
- Where is human review required?
- What AI-generated content requires disclosure?
- Who approved each system?
- Who owns the risk associated with it?
- What happens when something goes wrong?
- Can we prove any of this happened?
Number ten is going to become increasingly important.
Because saying:
"We trained everybody."
is different from producing the training records.
Saying:
"Humans review the decisions."
is different from demonstrating the review process.
Saying:
"We have safeguards."
is different from documenting those safeguards.
Organizations are going to discover something compliance professionals have understood forever:
If you cannot demonstrate that the process happened, eventually someone may treat it like it never happened.
The Most Dangerous AI Might Be the Boring AI
Everybody worries about artificial general intelligence taking over humanity.
Meanwhile, Susan from HR connected an AI resume-ranking application to 3,700 job applications.
That might be the more immediate problem.
The biggest organizational AI risks may not come from futuristic robots.
They may come from ordinary systems making ordinary decisions at extraordinary scale.
Hiring.
Scheduling.
Performance evaluations.
Credit decisions.
Insurance.
Housing.
Education.
Customer eligibility.
Healthcare administration.
Public benefits.
Employee monitoring.
Those decisions affect actual people.
Automation allows organizations to make thousands of them very quickly.
That efficiency is powerful.
It also means a flawed process can become a flawed process at scale.
Small Businesses Should Pay Attention Too
Enterprise organizations can hire lawyers, compliance teams, cybersecurity professionals, privacy officers, and AI governance specialists.
Small businesses usually cannot.
That creates an interesting problem.
Small businesses are gaining access to enterprise-level AI capabilities without enterprise-level governance infrastructure.
A ten-person company can now deploy technology that would have required an entire development team several years ago.
That is incredible.
It also means the owner may simultaneously be the CEO, CIO, compliance department, cybersecurity department, AI governance committee, and the person wondering why Stripe sent another email.
That business still needs basic controls.
Not 900 pages of policy.
Not a committee that meets every Thursday to discuss another committee.
A practical system.
Start With an AI Inventory
Before buying another AI tool, figure out what you already have.
Create an inventory.
Document the platform.
Document the purpose.
Document who uses it.
Document what information enters it.
Document what information leaves it.
Document whether customers interact with it.
Document whether employees interact with it.
Document whether it influences decisions about people.
Document whether human approval exists.
Document who owns the system.
Then classify the risk.
Something that generates brainstorming ideas for social media does not carry the same risk as something screening employment candidates.
Treating every AI application exactly the same makes governance unnecessarily complicated.
Treating every AI application like it carries zero risk is worse.
AI Governance Is About Permission
Here is the simplest way I can explain where organizations need to go.
Your AI systems need boundaries.
AI may do this.
AI may recommend this.
AI may draft this.
AI may not decide this.
AI may access this information.
AI may never access that information.
A human must approve this.
This action must be logged.
This incident must be escalated.
That is operational governance.
You are defining authority before the system exercises it.
That becomes even more important as AI agents become capable of taking actions instead of simply producing answers.
There is a massive difference between an AI system that tells you:
"I recommend refunding this customer."
and an AI agent capable of actually issuing the refund.
The second system has authority.
Authority requires controls.
Somebody Needs to Own the AI
This may become one of the most important organizational questions of the next several years.
Who owns AI?
IT?
Legal?
Compliance?
Operations?
Marketing?
Human Resources?
The CEO?
The answer may vary depending on the organization.
One answer should never be acceptable:
Nobody.
Someone needs responsibility for the organization's AI inventory, policies, risk classifications, vendor reviews, employee training, escalation procedures, and governance standards.
You cannot distribute artificial intelligence throughout an organization while centralizing responsibility nowhere.
That is how organizations create accountability gaps.
And accountability gaps have a funny way of becoming expensive.
We Are Entering the Boring Part of AI
The first phase was exciting.
Look what AI can do.
The next phase is less sexy.
Policies.
Governance.
Risk assessments.
Training.
Audit trails.
Permissions.
Documentation.
Human oversight.
Vendor reviews.
Incident response.
Compliance.
I know.
Nobody is making cinematic AI videos about documentation retention.
They probably should.
Because this is where artificial intelligence stops being a toy and becomes infrastructure.
Infrastructure requires governance.
The Question Has Changed
For the last few years, organizations have asked:
How quickly can we implement AI?
That was probably the correct question for the experimentation phase.
It is no longer enough.
The better questions now are:
Where are we using AI?
What authority have we given it?
What risks did that create?
Who is responsible for those risks?
Can we demonstrate that responsible controls exist?
AI adoption without AI governance is not innovation.
It is unmanaged exposure with a really impressive user interface.
So yes.
Keep building.
Keep automating.
Keep experimenting.
Keep finding ways artificial intelligence can make your organization faster, smarter, and more competitive.
I certainly am.
Just remember something.
The same AI system that saves your company thousands of dollars today could create a very different bill tomorrow if nobody bothered to ask what rules applied to it.
Good luck with all those AI regulation fines they are not telling you about.
You might want to start asking questions before somebody else starts asking them for you.
About Anthony Washington Sr.
Anthony Washington Sr. writes about artificial intelligence, leadership, organizational systems, accountability, automation, and the relationship between technology and the people expected to operate within it.
Through 28 Foot Systems, he focuses on practical AI implementation, automation, organizational readiness, and building systems that solve real operational problems without forgetting the humans responsible for them.
Related articles
All articles