AI Governance in a Shifting Regulatory Landscape

AI Governance Remains Critical Despite Political Pendulum Swings

As businesses increasingly rely on AI and generative AI for myriad applications, a new body of “AI law” is forming, and some legal requirements are now in effect. AI governance has become a mandatory compliance function that organizations must prioritize immediately rather than postponing until next quarter or next year.

The Patchwork of AI Law

The landscape of AI law is complex and varies widely across jurisdictions. Some regions are enacting new regulations, while others are retracting existing ones. As the political atmosphere shifts, regulatory retrenchment has emerged as a key theme in 2025.

Hardline AI regulatory regimes that previously dominated headlines are now being scaled back. For instance, at the federal level in the U.S., the Trump administration has undone several Biden-era AI executive orders, leading federal agencies to recalibrate their enforcement priorities. Observers note that agencies such as the FTC and SEC are expected to focus primarily on clear cases of fraud rather than pursuing broader or more innovative regulatory actions.

State-Level Developments

At the state level, the Colorado AI Act is currently under scrutiny for potential amendments, including a bill introduced in April 2025. In addition, recent vetoes of high-profile AI bills by the governors of California and Virginia highlight the ongoing tensions in AI legislation. The U.S. House Energy and Commerce Committee has proposed a 10-year moratorium on enforcing state AI laws in a recent draft budget reconciliation bill.

Meanwhile, across the Atlantic, the EU Commission has withdrawn the draft AI Liability Directive and is reportedly considering amendments to the EU AI Act to ease certain requirements.

Emergence of New Regulations

Despite the apparent pullback in certain regulations, the realm of AI governance is not stagnant. Newly enacted state laws in the U.S., particularly in California, Illinois, New York, and Utah, address critical issues such as:

  • Algorithmic discrimination and automated decision-making
  • Disclosure of AI usage
  • Impersonation, digital replicas, and deepfakes
  • Watermarking of AI-generated content
  • Data privacy and biometric data

State attorneys general have reiterated their commitment to enforcing existing laws against unlawful uses of AI, emphasizing that AI regulation remains a pressing concern. Furthermore, the ongoing AI “copyright war” continues to evolve, as various lawsuits in the U.S. and beyond test the boundaries of copyright infringement and fair use in relation to AI training and outputs.

The EU AI Act

Notably, the first requirements of the EU AI Act went into effect in February 2025. Companies utilizing AI within the EU are now subject to an “AI literacy” requirement, mandating measures to ensure a sufficient level of AI literacy among employees or individuals operating or using AI systems. The extraterritorial nature of the AI Act means it also applies to U.S. companies that use AI systems within the EU or produce outputs intended for use in the EU.

Mandatory employee training regarding the responsible use of AI is now a crucial aspect for compliance.

Conclusion

In summary, while there may be a trend towards softening AI regulation in some areas, this is not a universal truth. The importance of enterprise AI governance cannot be overstated. New “AI law” requirements are being implemented, with others on the horizon. Regulatory bodies, state attorneys general, and plaintiffs are keen to apply existing laws to emerging technologies. Additionally, organizations must be mindful of potential self-inflicted issues, such as data leakage, along with the reputational and public relations risks tied to AI-related missteps.

Fortunately, there are common threads within the complex landscape of AI regulation. Established guidance, such as the NIST AI RMF and ISO/IEC 42001:2023, offers valuable insights for responsible AI governance. These frameworks not only assist in compliance but may also provide statutory safe harbors or affirmative defenses under laws like the Colorado AI Act. Leveraging these resources is essential for organizations in navigating the evolving AI landscape.

More Insights

AI Compliance Risks: Safeguarding Against Emerging Threats

The rapid growth of artificial intelligence (AI), particularly generative AI, presents both opportunities and significant risks for businesses regarding compliance with legal and regulatory...

Building Effective AI Literacy Programs for Compliance and Success

The EU AI Act mandates that providers and deployers of AI systems ensure a sufficient level of AI literacy among their staff and others involved in AI operations. This obligation applies to anyone...

Ethics at the Crossroads of AI Innovation

As artificial intelligence (AI) increasingly influences critical decision-making across various sectors, the need for robust ethical governance frameworks becomes essential. Organizations must...

Croatia’s Path to Responsible AI Legislation

EDRi affiliate Politiscope hosted an event in Croatia to discuss the human rights impacts of Artificial Intelligence (AI) and to influence national policy ahead of the implementation of the EU AI Act...

The Legal Dilemma of AI Personhood

As artificial intelligence systems evolve to make decisions and act independently, the legal frameworks that govern them are struggling to keep pace. This raises critical questions about whether AI...

Data Provenance: The Foundation of Effective AI Governance for CISOs

The article emphasizes the critical role of data provenance in ensuring effective AI governance within organizations, highlighting the need for continuous oversight and accountability in AI...

Balancing AI Governance in the Philippines

A lawmaker in the Philippines, Senator Grace Poe, emphasizes the need for a balanced approach in regulating artificial intelligence (AI) to ensure ethical and innovative use of the technology. She...

China’s Open-Source Strategy: Redefining AI Governance

China's advancements in artificial intelligence (AI) are increasingly driven by open-source collaboration among tech giants like Alibaba, Baidu, and Tencent, positioning the country to influence...

Mastering AI Governance: Nine Essential Steps

As organizations increasingly adopt artificial intelligence (AI), it is essential to implement effective AI governance to ensure data integrity, accountability, and security. The nine-point framework...