Security

The World Is Drawing Lines Around AI

How to prepare your stack as governments and enterprises define AI boundaries.

Jacob
Nov 2025|7 min read
The World Is Drawing Lines Around AI

TL;DR

AI regulation is a fractured global map. From the EU's comprehensive AI Act to the U.S.'s state-level patchwork, the lines for acceptable AI usage are already being drawn.

  • The EU AI Act is in force now; high-risk systems must be registered by December 2025.
  • In the U.S., focus on "Truth in Advertising"—the FTC is aggressively pursuing companies for overstating AI capabilities ("AI Washing").
  • Navigating this requires proactive governance: adoption of the NIST AI Risk Management Framework is currently the best baseline for global readiness.

I had a conversation last week that I can't shake. A founder friend—smart guy, building a SaaS product with AI-powered features—mentioned casually that he's been thinking about expanding into Europe. "Big market opportunity," he said. "Should be straightforward."

I asked him if he'd looked into the EU AI Act.

He paused. "That's the thing where they're going to regulate AI eventually, right?" "It's already in force," I told him. "Since August 2024. The prohibitions went live in February. Registration requirements hit in December. If you're deploying high-risk AI systems, you've got until August 2026 to be fully compliant."

The look on his face. Like someone just told him there was a test he didn't know about, and it's tomorrow. And here's what scared me: he's not unusual. He's the norm. Most entrepreneurs I know—myself included, if I'm being honest—have only the vaguest sense that AI regulation is happening. We know it's coming. We figure we'll deal with it when we have to.

But the lines are already being drawn. The rules are already on the books. And for a lot of us, "when we have to" is now.

Here's what I've learned, and it's more fractured than I expected.

Europe went first, and they went hard. The EU AI Act is the most comprehensive regulatory framework anywhere. It came into force August 2, 2024. Not proposed. Not "under consideration." In force.

February 2, 2025—a few months ago—the prohibitions took effect. Social scoring systems? Banned. Biometric categorization based on protected characteristics? Banned. If you're doing anything that falls under unacceptable-risk AI, you're already violating the law.

December 2025—next month—high-risk AI systems must be registered in the EU database before you can bring them to market.

August 2026 is when the majority of provisions kick in. And August 2027 is full organizational compliance for all high-risk systems.

The penalties? Up to €35 million or 7% of worldwide annual turnover, whichever is higher. Not "EU revenue." Worldwide turnover. The kind of fine that doesn't just hurt—it ends companies.

The U.S. is going a completely different direction. There's no comprehensive federal framework. Instead, we've got a patchwork of state laws that are multiplying faster than anyone can track them.

In 2024 alone, state lawmakers filed nearly 500 AI-related bills. About 20 became law. Texas passed TRAIGA, requiring businesses to provide high-level AI system information to the state attorney general—training data descriptions, performance metrics, the works. Utah enacted disclosure requirements for AI in regulated professions. California is advancing stricter oversight after federal preemption efforts failed. Connecticut, Illinois, and others are following suit.

In 2025, lawmakers tracked 210 AI bills across 42 states. Only about 9% (roughly 20 bills) actually got enacted, but the ones that did are specific and enforceable: chatbots, healthcare applications, biometric systems. Not broad frameworks—targeted regulations that catch you if you're in the wrong sector.

And then there's the global picture. The OECD AI Principles have become the de facto international standard, adopted by the G20. The UN released a governance framework in September 2024. Japan passed an AI Promotion Bill in February 2025. China has its own approach—labeling requirements for AI-generated content starting September 2025, national standards on AI security taking effect November 2025.

Every region is drawing its own lines. And if you operate internationally—or if you want to—you need to understand all of them.

I keep coming back to specific stories because abstractions don't stick. But consequences do. Replika—the emotional AI companion chatbot—got hit with a €5 million fine by Italy's data protection authority in May 2025. The violations were extensive: no valid legal basis for data processing operations used to train their model, inadequate age verification exposing minors to data collection, insufficient disclosure of how personal data was being used.

This wasn't a slap on the wrist. This was the most significant fine yet for an AI-specific GDPR violation. And in April 2025, Italy reaffirmed its ban on Replika, citing persistent violations and risks to vulnerable users. The message is unmistakable: if you're deploying consumer-facing AI without robust privacy controls, you will face consequences.

The FTC launched "Operation AI Comply" in September 2024, and they've been busy. They went after Evolv Technology for weapon detection AI scanners that failed to accurately distinguish between weapons and harmless objects—despite marketing claims of sophisticated detection. Schools reported failures to detect actual weapons and false alarms triggered by everyday items like laptops and binders. In December 2024, Evolv was forced to ban unsubstantiated claims and allow school customers to cancel their contracts.

They fined investment firms Delphia and Global Predictions for overstating AI integration—claiming AI capabilities that didn't exist. They took action against companies selling AI-generated fake reviews, "AI Lawyer" services that gave flawed legal advice, and AI-powered money-making schemes targeting vulnerable consumers.

The FTC's position is simple: there is no AI exemption from the laws on the books. Truth-in-advertising, consumer protection, anti-discrimination—all of it applies to AI. And they're enforcing it aggressively.

But there's a success story too. A global e-commerce brand achieved compliance by implementing end-to-end data lineage across its AI systems. They gained full visibility into how customer data moved through AI models spanning website interactions, payment processing, and recommendation engines. They ensured AI-driven decisions aligned with customer consent. They maintained compliance with GDPR, CCPA, and emerging regulations. And they built greater customer trust and internal efficiency in the process.

This is the path forward: proactive governance that prevents regulatory exposure while enabling innovation. It's possible. But it requires intentionality.

Here's where it gets uncomfortable.

Sixty-eight percent of European businesses find the EU AI Act difficult to interpret. And as a consequence, businesses unsure of regulatory obligations are expected to invest nearly 30% less in AI over the coming year. Uncertainty is killing innovation.

A small business with €10 million in annual revenue faces up to €400,000 in compliance costs for a single high-risk AI product under the EU AI Act. That's 40% of profits for a company operating on typical margins. Compliance isn't cheap—but non-compliance is catastrophic.

Between June 2024 and May 2025, 157 new financial services regulatory insights relating to AI were published— nearly double the volume from the previous year. The regulatory landscape isn't stabilizing. It's accelerating.

And here's the kicker: 97% of organizations that suffered AI-related incidents lacked proper AI access controls. Sixty-three percent lacked formal AI governance policies. We're flying blind, and we're getting hurt because of it.

The global average cost of data breaches is $4.4 million in 2025. Mega-breaches—those involving 50+ million records—average $375 million. When AI systems fail without proper governance, the consequences are existential.

But there's a flip side. For every $1 invested in generative AI, BDO clients see an average return of $3.70, typically realized within 13 months. The companies that figure out how to do this responsibly are winning. They're moving faster, building trust, and capturing market share while their competitors scramble to catch up.

The difference? Top-down AI initiatives have 18% success rates. Grassroots approaches—where frontline employees actually use AI with proper governance—have 80% success rates. Governance isn't a barrier to innovation. Done right, it's an enabler.

I've spent weeks trying to understand how to navigate this, and two frameworks keep coming up as genuinely useful. The NIST AI Risk Management Framework is the most practically applicable for organizations of any size. It's not theoretical. It's actionable. Four core functions:

Govern—establish clear organizational structures and policies for AI governance. Assign roles for AI development, approval, monitoring, and remediation. You need to know who's responsible for what.

Map—document AI system functions, intended use cases, and data flows before deployment. Trace how models perform in real-world scenarios. Identify edge cases where systems might fail. You can't manage what you don't understand.

Measure—quantify AI system performance, effectiveness, and risks. This includes measuring accuracy, fairness, bias, and alignment with regulatory requirements. You need metrics, not vibes.

Manage—develop strategies for mitigating risks and ensuring systems remain compliant through continuous monitoring, auditing, and improvement. This isn't a one-time check. It's ongoing.

The EU AI Act Compliance Checklist is more specific but equally valuable if you operate in or serve EU customers: First, determine your role. Are you an AI provider (developing systems) or an AI user (deploying systems)? The obligations differ. Second, identify if your AI system is prohibited. Social scoring, emotion recognition in non-medical contexts—these are off-limits, period. Third, classify your system as high-risk if applicable, and document technical specifications, training methodologies, and testing protocols.

Fourth, conduct Data Protection Impact Assessments (DPIAs) for any system processing personal data. This isn't optional for high-risk applications. Fifth, implement mandatory disclosures. If someone is interacting with an AI chatbot, they need to know. If content is AI-generated, it must be labeled. If decisions are automated, that must be transparent. Sixth, establish ongoing compliance monitoring with periodic audits and regulatory review cycles. This never ends.

There are people who saw this coming years ago, and their work is shaping the regulations we're now living under. Kate Crawford—Senior Principal Researcher at Microsoft Research and Research Professor at USC—has been investigating how generative AI exhibits bias and the broader social implications of AI systems for over 20 years. She co-founded the AI Now Institute in 2017, which produces policy research that directly advises global policymakers. Her 2024 research on generative AI bias directly influenced the EU AI Act. If you want to understand why these regulations exist and where they're heading, read her work.

Timnit Gebru—founder of DAIR (Distributed AI Research Institute)—is one of the most influential voices in AI ethics. Her termination from Google in 2020 following publication of research on large language model bias catalyzed broader conversations about AI accountability. Her work prioritizes diversity, equity, and inclusion in AI development, and she's been instrumental in shaping ethical guidelines globally. If you want to understand the equity implications of AI systems and why bias testing matters, follow her.

These aren't academic voices shouting into the void. These are the people whose research is literally being written into law.

Here's where I land: we're at an inflection point. The world is drawing lines around AI. Different lines in different places, but they're being drawn. And the companies that understand where those lines are—that build governance structures proactively rather than reactively—are going to have a massive advantage.

Not just because they'll avoid fines, though that matters. But because they'll move faster. They'll build products that customers trust. They'll enter new markets without last-minute scrambles. They'll attract talent that wants to work on responsible AI. They'll sleep at night knowing they're not one regulatory inquiry away from disaster.

The cost of compliance is real. For a small business, it might be €400,000 for a single high-risk product. That's not nothing. But the cost of non-compliance—fines, operational disruption, reputational damage, lost market access—is substantially higher. And increasingly, it's existential.

I think about my friend who wants to expand into Europe. He's got maybe a year to figure this out before his expansion plans collide with compliance requirements he doesn't understand yet. And the brutal truth is: most entrepreneurs are in the same boat.

We're building in a world where the rules are changing faster than we can track them. Where every region is taking a different approach. Where enforcement is ramping up and regulators are no longer issuing warnings—they're levying penalties that hurt.

And the question isn't whether we like these regulations or think they're fair or wish they were simpler. The question is: What are we going to do about it? Because the lines are already drawn. We just need to learn where they are.