Ethics

AI Laws Are Coming — And I'm Not Ready

Instrumentation to satisfy disclosures, consent, and risk reporting before letters arrive.

Jacob
Nov 2025|7 min read
AI Laws Are Coming

TL;DR

AI regulation is no longer theoretical—major laws like the EU AI Act and Colorado's AI Act are moving into enforcement phases with penalties up to 7% of global turnover.

  • Exposure: Most companies are using "high-risk" AI in hiring, pricing, or operations without realizing they are legally covered.
  • The Fix: Companies must immediately inventory their AI stack, audit for bias, and maintain rigorous documentation to avoid liability.

I've been staring at this document for twenty minutes now. It's a summary of AI regulations - the EU AI Act, Colorado's new law, California's transparency requirements, a dozen other policies phasing in between now and 2027. Fines up to EUR 35 million. Criminal penalties. Bias audits. Documentation requirements. Words like "consequential decisions" and "high-risk systems" that sound abstract until you realize they're talking about the tools you're already using.

And the thought that keeps circling back is: I should have seen this coming.

Of course laws were coming. We've been moving fast and breaking things for years now, spinning up AI tools that make decisions about people's lives - who gets hired, who gets a loan, whose resume even gets read by a human. Did we really think regulators would just let that continue unchecked?

But here's what terrifies me: I don't think most of us have any idea how exposed we are.

Eighty-eight percent of organizations are using AI in at least one business function. That number is from a McKinsey survey published last month. Eighty-eight percent. And most of these companies aren't Google or Microsoft with armies of compliance officers and ethics boards. They're regular businesses using ChatGPT for customer service, AI resume screeners for hiring, algorithmic tools for pricing or marketing or operations.

And starting next year -- literally in a few months -- many of these uses will fall under new laws. The EU AI Act becomes enforceable in stages throughout 2025 and 2026. Colorado's law kicks in February 2026. California's automated decision-making rules start January 2027. Even Texas passed a law requiring state agencies to disclose AI use and banning "manipulative AI," with penalties up to $200,000 per violation.

You don't have to be an AI company to be affected. If you use a third-party hiring tool that screens resumes with AI, you're covered. If your marketing software uses AI to segment customers or personalize offers, you might be covered. If you're using AI anywhere that touches employment, lending, housing, healthcare, or what the laws call "consequential decisions" -- you're almost certainly covered.

And the penalties aren't theoretical. The FTC already fined DoNotPay nearly $200,000 for overstating its AI lawyer capabilities. The SEC hit two investment advisers with $400,000 in fines for falsely claiming to use AI in their strategies. A court refused to dismiss an age discrimination suit against Workday, suggesting that companies can't just "farm out" hiring decisions to avoid liability.

The enforcement is already happening. And most of us haven't even started preparing.

It's not the fines, honestly. It's that I'm not sure I could even answer the basic questions right now.

What AI tools are we using? I could list the obvious ones, but what about the AI embedded in other software we've subscribed to? What about the tools individual team members are using that I don't even know about?

Where is AI touching consequential decisions? We use it for content generation, sure. But marketing copy that influences purchases -- is that consequential? Customer service responses that determine refunds or account access? Where's the line?

How do we know our AI tools aren't biased? We don't train the models ourselves. We're using APIs and SaaS products built by other companies. Are they testing for bias? Do we even have the right to audit them? And if we discover bias, then what?

Research suggests over 70% of IT leaders rank AI regulatory compliance as a top-three challenge. Gartner predicts AI-related legal disputes could rise 30% by 2028, with "illegal AI decisions" potentially incurring over $10 billion in remediation costs by 2026. These aren't abstract corporate problems -- they're existential risks for small companies with limited legal budgets and no compliance infrastructure.

Should we be using these tools the way we've been using them? Setting aside regulation for a moment -- should we be letting AI make or influence decisions about people's lives without really understanding how it works? Without knowing if it's fair? Without clear human oversight?

Part of me says, "We're just trying to survive as a business. We need efficiency. We can't afford not to use these tools." That's true; the economics are real. But that's exactly the kind of rationalization that gets people into trouble -- "everyone else is doing it," "we have to move fast," "we can't afford to slow down."

The new laws force us to think longer-term: not just "does this tool work?" but "does this tool work fairly? Can we explain its decisions?" They're uncomfortable questions that slow us down, but maybe that's the point.

First, inventory everything. Make a list of every AI tool you use, what it does, and where it touches decisions about people. You can't manage what you can't see.

Second, ask the uncomfortable questions. For each tool: Could this harm someone if it's wrong? How would we know if it's biased? Is there a human reviewing its output? Can we explain to a customer or regulator how this works? If the answer is "I don't know," that's a red flag.

Third, document everything. Regulations obsess over documentation -- model cards, risk assessments, decision logs, human oversight records. It feels like bureaucracy, but it forces clarity about how and why you're using AI.

Fourth, treat AI like any other vendor risk. Vet providers for fairness and transparency. Ask: How do you test for bias? What documentation can you provide? What happens if there's a problem? If they can't answer, maybe don't use that tool for high-stakes decisions.

And finally, get help. Legal counsel, compliance consultants, frameworks like NIST's AI Risk Management guide -- use them.

I'm scared, overwhelmed, and behind. But maybe this is necessary. Maybe being forced to slow down will help us build something more thoughtful and sustainable. Fifty-eight percent of executives in a recent PwC survey said that responsible AI practices improve ROI and efficiency. Doing this right isn't just about avoiding fines -- it might make us better.

Ignoring these laws isn't an option. The laws are coming; many are already here. The question isn't whether we're ready. It's: What are we going to do about it? We still have time. Not much. But enough to start.

What AI tools are you using that you haven't fully thought through? Where are the gaps in your understanding? These aren't rhetorical questions -- they're the ones I'm asking myself every day now.