A Season of Careful Steps
There is something quietly reassuring about how AI regulation has been unfolding this year. Instead of one dramatic law settling every question at once, governments across the world are moving in smaller, more deliberate steps, adjusting timelines and revisiting details as real experience with these tools accumulates. It is not always a tidy process, and it rarely makes for a single headline. But it is a genuinely human process, shaped by trial, error, and a slow search for balance.
Europe Reaches a Quiet Milestone
At the start of August, the European Union reached a milestone that had been years in the making, as new transparency obligations under its Artificial Intelligence Act became formally enforceable. The rules apply to a wide range of systems that interact with the public, from customer service chatbots to tools that generate images, audio, and text. It is not a ban or a restriction on what AI can create, but rather an insistence on honesty about what people are encountering, a fairly gentle ask that still marks a genuine shift in how AI is expected to behave in public life.
Chatbots Must Now Say What They Are
Under the new rules, any chatbot or voice assistant designed to interact directly with people must make clear that users are speaking with a machine rather than a human being, unless that fact is already obvious from context. This single requirement touches an enormous number of everyday interactions, from customer support windows to virtual assistants embedded in apps and websites. The idea is simple enough: people deserve to know who, or what, is on the other side of the conversation before they decide how much to trust it or share with it.
Deepfakes Step Into the Light
Alongside chatbot disclosure, the European rules now require that AI-generated or altered content, including deepfakes, be clearly labeled so viewers are not misled about what they are seeing or hearing. Machine readable markings are meant to make this content easier to detect at a technical level, not just a visual one, giving platforms and researchers a way to trace synthetic media even when a label has been stripped away. Providers have been given a short transitional window to build these marking systems properly rather than rushing them into place.
A New Line Against Intimate Image Abuse
One of the more pointed additions to the European framework is a direct prohibition on AI systems built specifically to generate non consensual intimate images of real people, closing a painful and rapidly growing loophole. Tools sometimes described as “nudifying” applications, which digitally alter ordinary photographs to create explicit content without a person’s knowledge or consent, are now squarely against the law. It is a narrow rule in scope, but an important one, reflecting how regulators are increasingly willing to draw firm lines around AI uses that cause direct, personal harm.
The High Risk Rules Take a Longer Road
Not every part of the AI Act arrived on schedule this August. The Act’s toughest provisions, covering so called high risk systems used in hiring, education, credit scoring, and border management, have been pushed back substantially. Standalone systems in these categories now have until December 2027 to comply, while AI embedded in already regulated products, such as medical devices or machinery, has been given until August 2028. For now, these systems remain subject to existing consumer protection and privacy law, just not to the AI Act’s more specialized oversight requirements.
Why Brussels Chose Patience
European officials have framed this delay as a practical adjustment rather than a change of heart, and the reasoning behind it is fairly grounded. Many member states had not yet designated the national authorities responsible for enforcement, and the shared technical standards that high risk compliance depends on were still being finalized. Rather than force companies and regulators alike to work against an unrealistic deadline, lawmakers chose to extend the runway, betting that a slower, better prepared rollout will serve the law’s goals more faithfully than a rushed one.
Across the Atlantic, a More Uncertain Landscape
The regulatory picture in the United States looks noticeably different, shaped less by one unified framework and more by an ongoing tug of war between federal ambition and state initiative. Where Europe has moved through formal legislative negotiation, American AI policy has largely taken shape through a patchwork of individual state laws, executive actions, and court challenges, each pulling the overall direction in a slightly different way. The result is a landscape that feels less settled, but also, in its own way, more responsive to local concerns as they arise.
Washington’s Attempt to Rein In the States
In December of last year, the White House issued an executive order aimed at curbing the growing number of state level AI laws, calling for a more unified national approach and directing federal agencies to challenge state rules seen as overly burdensome. The order arrived after months of public debate, including a failed last minute effort to attach similar preemption language to national defense legislation. Supporters described it as a needed correction against a confusing patchwork; critics saw it as an attempt to sideline protections that states had built carefully and deliberately.
Courts, Not Orders, Will Decide
An executive order, however, cannot simply erase laws passed by state legislatures, and legal experts have been careful to point this out. Only an act of Congress or a ruling from the courts can formally override existing state statutes, which means the disputed laws remain fully enforceable while legal challenges work their way through the system. Companies operating across state lines have largely been advised to keep complying with local requirements in the meantime, rather than assume a federal reversal is guaranteed to arrive.
States Keep Building Anyway
Perhaps the most telling sign of where things actually stand is that state lawmakers have not slowed down at all. If anything, activity at the state level has accelerated this year, with new bills introduced across dozens of legislatures addressing everything from algorithmic hiring decisions to synthetic media disclosure. Rather than waiting to see how the federal debate resolves, many states have continued treating AI oversight as a local responsibility, one that cannot simply pause while larger political questions are sorted out elsewhere.
Companion Chatbots Draw Special Attention
Among all the areas of state AI policy, few have drawn as much focused attention as companion chatbots, the conversational systems designed to build ongoing, emotionally engaged relationships with users. These tools have become remarkably popular, offering companionship, conversation, and a sense of being heard, but they have also raised real concern among lawmakers about emotional dependency, especially among young or vulnerable users. That concern has translated into a wave of new legislation aimed specifically at how these systems are allowed to behave.
A Dozen States, One Shared Instinct
By the middle of this year, roughly a dozen states, including California, Colorado, Connecticut, Georgia, Idaho, Nebraska, New York, Oregon, and Washington, had enacted their own companion chatbot laws, with several more considering similar bills. Though the details vary from state to state, the underlying instinct is remarkably consistent: these systems can feel genuinely personal, and that emotional pull deserves thoughtful guardrails rather than unrestricted design freedom. It is a rare moment of quiet consensus in an otherwise fragmented regulatory environment.
Reminders Meant to Protect
A common thread running through these new laws is a simple requirement that companion chatbots periodically remind users they are speaking with an AI system rather than a person. Some states require this reminder every few hours for all users, while others apply stricter, more frequent reminders specifically when a minor is suspected to be on the other end of the conversation. It is a small intervention, but one meant to gently interrupt the illusion of human connection before it grows too comfortable to question.
When a Chatbot Notices Someone Is Struggling
Several states have gone further, requiring companion chatbot operators to build in ways of recognizing signs of emotional distress, including expressions of suicidal thinking, and to respond by directing users toward real human support such as a crisis line. These crisis intervention requirements reflect a recognition that people sometimes turn to these systems during genuinely difficult moments, and that a well designed response at that point can matter enormously. Lawmakers have been explicit that the goal is not to replace human care, but to point toward it.
Extra Care for Younger Users
Protections for minors run through nearly every state chatbot law passed this year, often going well beyond simple disclosure requirements. Several states now prohibit companion chatbots from engaging in romantic or sexually suggestive conversations with users believed to be underage, or from claiming sentience or emotional attachment in ways that could be misleading to a young person. A few laws also bar chatbots from presenting themselves as licensed mental health professionals, closing a gap that had allowed some tools to imply a level of expertise they simply do not have.
California’s Early and Influential Role
California has often set the pace for this kind of legislation, and its companion chatbot law, enacted last year, was among the first in the country to include a private right of action, allowing individuals to bring their own lawsuits rather than relying solely on state enforcement. The law also requires operators to report annually to the state’s Office of Suicide Prevention on the protocols they use to detect and respond to signs of self harm among users. Other states have since looked to California’s approach as a template, even while adjusting the details to fit their own priorities.
Congress Watches From the Sidelines
At the federal level, progress has been considerably slower, despite genuine interest from lawmakers on both sides of the aisle. Bills addressing chatbot safety for minors, algorithmic transparency, and age verification have been introduced in Congress, but none have yet made it into law, leaving the states to continue filling the gap on their own. This dynamic has become a familiar pattern in American AI policy, where federal conversations move carefully and slowly, while state legislatures act as the more immediate, if uneven, testing ground for new ideas.
A Patchwork With a Purpose
It would be easy to describe the current American landscape as chaotic, and in a narrow legal sense, it is: a business operating nationally may need to track a dozen or more slightly different sets of requirements. But looked at from a different angle, this patchwork also reflects something more hopeful, a genuine, decentralized effort by lawmakers to respond quickly to concerns their constituents are actually raising. The lack of a single federal standard is a real challenge, but it has not stopped meaningful protections from taking shape.
What This Means for Businesses
For companies building or deploying AI systems, compliance now demands close attention to geography as much as technology, since requirements can shift from one state or country to the next.
- Track disclosure rules separately for each state and market
- Build in AI identity notices and clear labeling for synthetic content
- Add crisis response protocols for systems used by minors or vulnerable users
- Treat compliance as a trust building opportunity, not just a legal checkbox
What This Means for Everyday Users
For the person on the other side of the screen, these changes are quietly significant, even if they rarely feel dramatic in the moment. A brief disclosure that you are speaking with AI, a label on a synthetic image, a gentle nudge toward real support during a hard conversation, none of these are flashy interventions, but together they shape a slightly safer, more honest relationship between people and the tools they increasingly rely on. That is, in many ways, exactly the point of regulation done well.
A Few Shared Values, A Long Road Ahead
Taken as a whole, today’s AI regulation news points less to any single landmark law and more to a slow, uneven convergence around a few shared values, even as countries and states keep arriving at them from different directions and at different speeds.
- People deserve to know when they are interacting with a machine
- Children need extra protection from emotionally engaging AI systems
- Synthetic content should never be mistaken for something real
- Vulnerable users deserve a clear path toward real human support
Conclusion
None of this amounts to a finished rulebook, and it was never going to. What emerges instead is a picture of regulators, lawmakers, and companies learning together, in real time, how to live alongside a technology that keeps changing shape. Europe’s willingness to slow down its high risk rules, and America’s willingness to let states experiment ahead of Congress, are both signs of the same instinct: better to get this right slowly than to get it wrong quickly. For now, that patient, imperfect progress may be the most honest kind of reassurance anyone can offer.