Tom Cedoz

Commentary · AI Governance

While Everyone Watched the AI Act

This year’s AI-law headlines read like a retreat: Brussels delayed its deadlines, Colorado repealed its statute, Washington told the states to stand down. Some of that relief is real. For companies that put learning systems into machines, and for anyone hiring across state lines, the dates that bind moved the other way.

AI regulation & litigation· July 25, 2026· By Tom Cedoz

Primary sources are linked where cited — the Official Journal, the Federal Register, state legislative texts, and the Mobley v. Workday filings. Current as of July 25, 2026.

Start with the ledger, because the dates are real.

On January 20, 2025, the White House revoked the 2023 executive order on safe AI. A week later the EEOC took its AI hiring guidance off its website. In December, a new executive order directed the Attorney General to stand up a task force with one job: sue states whose AI laws conflict with a “minimally burdensome national policy framework.” Its first target was Colorado, which had passed the most ambitious AI statute in the country. The Justice Department moved to intervene on April 24 of this year. A federal court suspended enforcement three days later, on a motion the state joined, and by May 14 Colorado had repealed and replaced the statute with something considerably smaller.

Then Brussels joined. On July 24, 2026 — nine days before its biggest deadline arrived — the European Union published the regulation postponing the AI Act’s high-risk obligations. Hiring, credit, and the other standalone high-risk uses moved from August 2026 to December 2027. AI built into regulated products moved to August 2028. The regulation is in force from July 27.

Read that way, 2026 is the year AI regulation blinked. The comfortable takeaway: pressure’s off; revisit it next budget cycle.

For some companies that is exactly right. If your European exposure is a hiring platform or a credit model, a standalone high-risk system in the Act’s Annex III, you just got sixteen months and the budget that comes with them. The relief is real. Take it.

It is also narrower than the headline. The retreat is happening at the layer of headline statutes and agency guidance. At the layers that decide what a company actually pays — product certification, state employment law, discovery — some dates got earlier and the doctrine got sharper.

The date that didn’t move

The delay everyone quoted has a companion almost nobody quoted. The EU’s new machinery regulation applies on January 20, 2027 (the enacted text said the 14th; a corrigendum moved it). Among the machines it treats as high-risk: safety components with self-evolving behavior — machine learning doing a safety function. For those, self-certification is off the table. A notified body has to assess conformity before the CE mark goes on.

The July regulation amended the machinery rules in the same stroke, and the amendment is more interesting than the delay. It moved AI built into machines out of the AI Act’s direct reach and into machinery law, where the AI-specific requirements will arrive as machinery requirements through delegated acts due by August 2028. The notified body does not wait for them. That obligation is already written, and it starts in January.

So a company that builds equipment with a learning function anywhere near a safety system did not get a reprieve this summer. Its date sits about eighteen months ahead of the delayed AI Act deadline it read about, and the constraint that will actually hurt is notified-body capacity, which does not expand because Brussels moved a different date. Add the AI Act’s reach while you’re at it: it applies to an American company that sells into the EU, operates there, or has output used there. The delay changed when. It changed nothing about whether.

So classification is the first question. The July regulation drew a line the engineers should see: AI used solely for quality control, optimization, or non-safety assistance is not a safety component unless its failure endangers health or safety. Whether the model on an inspection head is ensuring a safety function or checking tolerances is a design decision before it is a compliance one. The cheapest conformity assessment is the one you architected your way out of, and that argument has to be made in the product review, early, by someone who has read Annex I.

The docket moved the other way

Derek Mobley applied to more than a hundred jobs through employers running Workday’s screening tools and got past none of them. His lawsuit against Workday — the vendor, not the employers — has produced more usable AI employment law than any statute passed this decade.

In 2024, the court in Mobley v. Workday let discrimination claims proceed on the theory that Workday acts as its customers’ agent: when employers hand the screening function to software, the software company answers under the employment statutes. In 2025, the court preliminarily certified an age-discrimination collective and later expanded it to Workday’s HiredScore AI. This March it held the ADEA protects job applicants, not just employees. In June it kept California fair-employment claims and a disability theory in the case — the algorithm allegedly screens out proxies for illness — and confirmed Workday is directly liable for its own algorithmic decisions; the exposure does not run through its customers.

The order that should reorganize compliance programs, though, is a discovery ruling. In May, the magistrate judge held Workday’s bias-testing data privileged. Lawyers had commissioned the tests and used the results to give legal advice, so the plaintiffs don’t get them. Talking about it publicly waived nothing. The court separated saying you test for bias from showing what the testing found.

Sit with both halves of that. The defendant kept its own audits out of the case because counsel ran them. A company whose audits were run by the product team, or promised in a policy and never run at all, produces everything. The same document is a shield or an exhibit, and which one it becomes was decided years before the subpoena, by whoever set the testing up.

Keep the weight right. This is one district court at the pleading and notice stage, the agent theory has not survived decertification or summary judgment, and the privilege order was a win for the defendant who planned ahead. It is also the first sustained judicial treatment any of this has received, which is why it is what vendors and employers are being advised on now.

Federal enforcers spent 2025 stepping back. This docket did not.

The states that reach you anyway

Illinois amended its Human Rights Act effective January 1, 2026. An employer that uses AI in hiring, promotion, discipline, or discharge violates the Act if the use has a discriminatory effect — no intent required. Notice to candidates is mandatory. Using zip codes as a proxy for a protected class is banned by name.

California’s civil-rights regulations on automated-decision systems took effect October 1, 2025, and among other things require keeping automated-decision records for four years. New York City has required bias audits and candidate notice since 2023, and the rule reaches fully remote roles tied to a New York office. A state comptroller’s audit in December embarrassed the enforcement agency into opening real investigations. Colorado’s replacement statute still requires notice, an explanation after an adverse decision, and human review, with obligations starting January 1, 2027. Texas prohibits only intentional discrimination by AI — and the AI claims that survive, Mobley’s included, are disparate-impact claims.

Enforcement is a separate question. A task force that moved Colorado in seven months is a standing message to every other legislature and attorney general, and some will read it and flinch. Watch what states do next, not what they passed last year.

Michigan and Ohio have enacted nothing. That’s not shelter. A Michigan manufacturer that hires into Illinois is inside the Illinois statute. And where there’s no AI law, the older law applies: in February, Connecticut’s Attorney General put companies on notice that his state’s existing anti-discrimination statutes already reach algorithmic discrimination, and that his office intends to enforce them that way. Every state has those. Title VII and Michigan’s Elliott-Larsen Act never needed an algorithm statute to reach a discriminatory screen — disparate-impact doctrine is more than fifty years old and does not care that the practice is a model.

One program, built like evidence

Nobody can run a Brussels program, a Sacramento program, a Springfield program, and a separate program for the docket. So don’t. The regimes disagree on vocabulary and scope, but they converge on a short list of controls. Build it once, to the strictest version that reaches you, and map the paperwork outward:

  • An inventory of where AI touches decisions about people or safety functions — bought, embedded in tools you already license, or shadow.
  • A risk tier for each use, set by consequence rather than sophistication.
  • Testing for accuracy and disparate impact on a schedule, not once at launch.
  • Human oversight held by someone with authority to override and enough information to explain the decision later.
  • Notice where any regime that reaches you requires it. Notice is cheap; its absence is a statutory violation with your name on it.
  • Vendor terms that allocate testing, audit rights, and indemnity. Mobley makes the vendor your agent; the contract decides what that costs you.
  • Records kept to the longest clock that applies — in California, four years.

And one decision to make with counsel before any of it runs: which testing is privileged and which is built to be produced. Workday made that choice early and it held. Make it after the complaint arrives and it’s an autopsy.

Boards and enterprise buyers will ask for all of this in the vocabulary of NIST’s AI Risk Management Framework or ISO/IEC 42001. Map to them — that’s how procurement reads. But the map is not the program. An elaborate program you don’t run is worse than a modest one you do, because it’s a written record of controls you named and skipped, and discovery finds those. I keep a leaner version of this as a working framework; it fits on two pages on purpose.

What the retreat actually is

It’s a retreat of guidance. Agencies withdrew documents. A legislature withdrew a statute. Deadlines moved. Consequence didn’t retreat — it relocated, into certification queues that open in January, into state statutes with effects tests, into a San Francisco courtroom where the defendant’s audits stayed out of evidence because someone thought about discovery before there was a case.

When the questions come, they won’t be about the framework you named. They’ll be about the one you ran.