Plans
Learn Library

The Whole World Is Writing Rules for AI, and the Bar Is More Specific Than You Think

An educational explainer on how AI rules are being written worldwide: the EU AI Act's risk tiers and penalties, the US patchwork of sectoral regulators, and how companies structure AI compliance roles, maturity levels, and continuous monitoring.

ai-marketingworkflow
2026-09-20SupaMarketers9 min read

A few days ago, a friend of mine who runs a SaaS company messaged me. The heaviest work on his plate this week, he said, wasn't writing code. It was answering questions.

A big European client had sent over a questionnaire — thirty-seven questions. Your product uses AI: where does your training data come from? Can the model's outputs be explained? Who's responsible when things go wrong? Can users switch it off?

If he couldn't answer, he said, the contract wouldn't get signed.

Selling software used to be about features, price, and delivery dates. Now the first thing on the client's list is a wall of questions like these.

Why? Because the whole world is writing rules for AI.

Today I'll walk you through those rules in plain language: what they say, how they're tiered, who enforces them, and what they mean for you.

The EU Swings Hardest

When it comes to regulating AI, the EU moved fastest and hit hardest.

Its AI Act — the EU AI Act — took effect in August 2024, the first AI law anywhere with coverage this broad. The core idea is one phrase: tier by risk.

Think of it like a health checkup report: not every abnormal reading means you get admitted to the hospital. The Act sorts AI systems into tiers and treats each differently.

The most dangerous tier is banned outright. Systems that manipulate people through subliminal techniques, or run social scoring on citizens, are not allowed to exist.

The second tier is high risk: résumé screening in hiring, credit approval. Decisions that genuinely change the course of a life — these are regulated the strictest: a conformity assessment (an official pre-launch audit) before going live, a complete documentation trail, and ongoing monitoring after release.

The third tier, things like chatbots, gets lighter requirements: at minimum, people must know they're talking to an AI, not a human.

Everything else — the everyday use cases — is largely left alone.

And these rules have teeth. The Act's maximum fine: €35 million, or 7% of global annual revenue, whichever is higher.

Let me do the math for you. Say your company's global annual revenue is $1 billion. Seven percent of that is $70 million.

That's not a slap on the wrist. That's a body blow.

And the schedule is already lined up. In February 2025, the ban list landed first. In August 2025, the rules reached the providers of general-purpose AI models. And on the original timetable, from August 2026, obligations for most high-risk systems formally apply.

A net is tightening, mesh by mesh.

The EU, by the way, is no stranger to this game. Its General Data Protection Regulation — GDPR — took effect back in 2018, governing personal data, with a maximum fine of 4% of global revenue or €20 million, whichever is higher. How's that for tough?

What's tougher still: GDPR follows "users," not "nationality." Your company can be headquartered in New York, Tokyo, or Singapore — if your users include Europeans, this law reaches you.

The industry has a name for this phenomenon: the Brussels effect. One law, reaching half the planet.

America Took a Different Road

So what about the United States?

The US never passed one big unifying law. It works in pieces.

The White House issues executive orders to set the broad direction. NIST — the U.S. National Institute of Standards and Technology — released an AI Risk Management Framework (AI RMF) in 2023, teaching companies how to manage AI risk systematically. The rest is handed to sectoral regulators, each minding its own patch: banking regulators oversee the banks' AI, and the agencies overseeing drugs and medical devices oversee the AI those industries use.

One example. Banking has a guide from 2011 called SR 11-7, issued by the Federal Reserve, originally written for credit models. Today, virtually every AI model running inside a bank treats it as the blueprint: from development, validation, and launch through retirement, a complete trail every step of the way.

The states haven't been idle either. California's CCPA, effective in 2020, covers personal data, and its thinking resembles GDPR in more than a few ways.

What does this mean?

It means there's no single standardized answer sheet for doing AI business in the US. If you're in finance, you answer to financial regulators; if you're in healthcare, you answer to the FDA. A patchwork of regulators, each with its own demands.

Three "What-Ifs"

That's the concepts done. You might now be asking: for an actual company, what do these rules look like on the ground?

Let me give you three what-ifs.

Suppose you're a bank. Your model needs documentation from the very first line of code: where the data came from, how it was trained, what the validation results showed, who approved the launch. The day regulators come to inspect — or the model makes a mistake — you can quickly produce a complete set of records and account for every step.

Suppose you're a SaaS company doing business in Europe, like my friend. Your AI features have to be explainable: why the system recommended this content to this user — you need to be able to give the reason. The data processing agreement you sign with clients has to spell out the boundaries of how AI uses data. And users need a switch to turn off AI personalization.

Suppose you work in a government agency, using AI to serve citizens. The bar is higher still: bias testing before launch, so the algorithm doesn't put any particular group at a disadvantage; algorithmic impact assessments; regular public reports that keep you in full view of society.

Notice something? These three scenarios are worlds apart in what they do, but the core is the same: explainable, accountable, monitorable.

That's the real common denominator among the world's regulators. The technology can differ endlessly — those three words are inescapable.

Who Does This Work

So inside a company, who owns all of this?

You'd say: legal, obviously.

Right — but not entirely. It's more like an international flight. It runs on an entire division of labor.

The captain is the board and the CEO. When an AI compliance incident happens these days, the one increasingly called in — and held to account — is the boss personally.

Air traffic control is the legal and compliance team. Their job is to translate the rules: that clause in the statute — which concrete requirements does it translate into for our business?

The ground crew hauling luggage and running checks is the engineering team: configuring access permissions for AI systems — who can touch the model, who can move the data — locked down item by item; doing data lineage tracking, so you know which data a given conclusion was computed from; and building automated tests so compliance checks are embedded in the development process, instead of a manual once-over before launch.

Oh, and a new role has sprung up over the past couple of years: Head of AI Governance. This person stands in the middle — one end connected to the regulatory texts, the other to the engineering team, translating each side's language for the other.

The birth of a new job title usually signals one thing: the job has grown too big to fit inside any existing role.

Maturity Comes in Three Levels

Compliance is compliance, but from company to company the level of practice differs wildly. Roughly three levels.

Level one: firefighting. Nobody tends to it in normal times; when an audit arrives or something breaks, people scramble overnight to backfill documents. Like someone who never gets a checkup and only enters the hospital when it hurts.

Level two: institutionalized. Written processes and policies are in place; compliance checks are being woven into development; many of them run automatically.

Level three: continuous compliance. The entire company's AI systems, as if wearing a 24-hour heart monitor: compliance status watched in real time, and the moment a regulation changes, you can immediately work out where you're affected. You act before the regulators knock, not after.

Why watch this closely? Because AI systems are alive. Models get updated, data flows, regulations change, people rotate. Compliance that gets checked once a quarter and then locked into a drawer — for AI, anyone can see that's useless.

For AI, compliance is a capability that runs continuously. Documents locked in a drawer are not compliance.

One more thing. A class of tools has already emerged on the market, built to do exactly this: watching who in the company is using which AI, whether permissions have gone astray, where the data went, where the risk hides — turning compliance from manually leafing through documents into automated oversight. Even "shadow AI" — employees quietly running customer data through outside AI tools — is visible to them.

Tools solve for efficiency. Direction is yours to set.

Compliance Is the Ticket

Last, some of my own judgment.

A lot of people treat regulation as a cost and dodge it wherever they can. I think that math is done backwards.

The clearer the rules, the better you see where the boundaries are, and the freer you feel to innovate with full effort. Where the rules are vague, nobody dares move — because no one knows which step crosses the line.

And more practically: in heavily regulated industries like finance and healthcare, without compliance you can't even get to the table. In that light, how is compliance a cost? It's the ticket.

The world's rules won't fully converge anytime soon. The EU is the strictest, the US governs in pieces, and other regions move at their own pace. The clumsy way of doing global business is often the easiest way too: build one set of capabilities to the strictest standard, and use it worldwide. Like a restaurant chain whose central kitchen is built to the strictest food-safety standard — so wherever it opens, an inspection holds no fear.

Oh, and my friend? He later went back and completed the answers to all thirty-seven questions, one by one. He told me that after signing the European client, he sent the same Q&A to his other clients — and deals actually got easier to close.

Rules aren't there to be dodged. They're there to get you to the table.

Here's to your AI: may it not only earn a seat at the table, but survive the card check.

Continue reading