Key takeaways
- In roughly one month, the EU delayed its AI Act high-risk obligations to December 2027, Colorado replaced its AI law with a lighter one, and a White House order ruled out mandatory federal licensing.
- The rollback removed the deadline, not the expectation: liability still runs through privacy, discrimination, and contract law, none of which were delayed.
- 78% of technology leaders at large firms say AI adoption is outpacing their ability to manage the business risks, and 52% report AI initiatives running without formal approval or oversight (EY, 2026).
- 46% of in-house legal leaders report increased exposure to AI-related litigation at the federal level (Norton Rose Fulbright, 2026), and enterprise buyers still ask how you govern AI in security reviews.
- Five moves make a self-set standard real: separate the floor from the bar, write it on one page, give it an owner and cadence, make it visible, and build the evidence.
In this article
For two years, the instruction to every CEO was the same: get ready to comply. Budget for it, staff for it, put it on the board agenda. Then, inside a single month, the people who write the rules changed their minds on three fronts at once.
In early May, the EU Council agreed to push the AI Act’s high-risk obligations back by sixteen months. The stand-alone high-risk systems that sit closest to real business decisions, the tools that screen job applicants, score credit, and sort people, were set to fall under the full rulebook on 2 August 2026. They now have until 2 December 2027 (EU Council, May 2026). On May 14, Colorado repealed the AI Act it had already passed. The replacement, SB 26-189, drops the three heaviest obligations of the original law, the risk-management programs, the impact assessments, and the duty to use reasonable care to prevent algorithmic discrimination, and it does not take effect until January 1, 2027 (Crowell & Moring). Two days into June, a White House order, Executive Order 14409, stated plainly that it does not authorize any mandatory federal licensing, preclearance, or permitting requirement for new AI models (Perkins Coie).
Three jurisdictions, one direction. The deadline most companies were quietly bracing for is not coming on the schedule they planned around.
The easy read is relief, one fewer line item on the 2026 roadmap. The more useful read is that something just got handed to you, and almost no one is going to pick it up.
What actually got dropped, and why
Start with what eased, precisely, because the precision is the point. None of these moves repealed the idea that AI should be governed. They removed the calendar that was going to force it. The EU still has an AI Act, Colorado still has an AI law, and the federal order leaves every existing privacy, consumer, and employment statute in place. What changed is the timeline and the pressure, not the underlying expectation that a company should know how its models behave.
The stated reason, in every case, was close to the same word: simplification. The EU framed its delay as a move to simplify and streamline the rules. Colorado rewrote its law under pressure that the original would burden the state’s AI industry before it had formed. The federal order put innovation and competitiveness in its title. Whatever you make of the politics, the pattern underneath is clear: the cost of compliance got reweighed against the cost of falling behind, and this month, compliance lost.
That tells you something about how durable the floor is. It moved once, fast, under competitive pressure. It can move again, in either direction, the next time the pressure shifts. A standard that depends on which way the political wind is blowing is not a standard you can build a business on. Which raises the real question the retreat hands you: if the floor is this movable, what were you actually standing on?
The floor and the bar
Two different standards were always at work here, and the retreat just pried them apart so you can see both.
One is the floor. It is the minimum a law forces you to clear, set by someone else, the same for every company in your jurisdiction, enforced by a deadline. The other is the bar. It is the level you hold because trust, liability, and speed depend on it, set by you, different for every company because every company’s exposure is different, enforced by nothing but your own judgment.
For two years the floor and the bar sat stacked on top of each other. The law required roughly what responsible operation required, so clearing the legal minimum and running a sound AI operation looked like the same act. You could not easily tell which of your governance practices existed because the law demanded them and which existed because the business needed them. They were one line.
The retreat separated the two. The floor dropped. The bar, if you understood why you built it, did not move at all. The mistake most companies are about to make is reading the first as the second, because for two years they were the same line on the same chart. They were never the same line. One was set by a legislature reweighing competitiveness. The other is set by what happens inside your business when an automated decision goes wrong.
The bar did not move, and the evidence says so
The pressure to govern AI never came only from regulators, and the part that did not come from regulators did not ease this month. Three forces set your real bar, and a relaxed statute touches none of them.
The first is your own exposure to the gap between adoption and control. AI is going into companies far faster than the governance around it is being built. In EY’s 2026 survey of 500 technology-industry leaders at companies with 5,000 or more employees, 78% said AI adoption is outpacing their organization’s ability to manage the business risks, and 52% reported that AI initiatives inside their own departments run without formal approval or oversight (EY, 2026). These are large, well-resourced firms describing their own operations. If the companies with the most to spend on governance are this far behind, the gap is not a budget problem. It is a priority problem, and a relaxed law just lowered the priority for everyone willing to read it that way.
The second is liability, which does not track the statute at all. When an automated decision denies someone a loan, screens them out of a job, or mishandles their data, the exposure that follows runs through privacy law, discrimination law, and contract, none of which were delayed this month. Norton Rose Fulbright’s 2026 Annual Litigation Trends Survey, a midyear pulse of 135 general counsel and in-house litigation leaders, found 46% reporting increased exposure to AI-related litigation at the federal level and 42% at the state level (Norton Rose Fulbright, 2026). The cases are arriving now, on grounds the repeals do not touch. You still own the outcome of every decision your models make, on exactly the schedule you always did.
The third is the buyer. A late-stage enterprise deal increasingly runs through a security and procurement review, and that review now asks how you govern your AI: what data your models touch, who signs off on a high-stakes automated decision, what you could produce if an output were ever challenged. “The law did not require us to track that” is the answer that stalls the deal while a competitor who can answer it closes. No regulator sets that bar. Your buyer does, and the buyer relaxed nothing this month.
None of these three forces appears in a statute book. All three were the real reason good AI governance mattered, long before the deadline arrived, and all three are exactly where they were in April. When the bar was mandatory, clearing it was table stakes that every company had to pay. Now that it is optional, the company that keeps it high is choosing an edge its competitors are free to skip. Most of them, reading the same headlines about relief, will skip it.
What setting your own standard actually looks like
If the bar is now yours to set, the work is to make it real, because a standard that relied on a deadline to enforce it will quietly decay the moment the deadline is gone. Five moves do most of that work.
First, separate the floor from the bar on paper. Take your AI governance roadmap and sort every practice into two columns: the ones you built only to satisfy a coming law, and the ones you would keep even if no law ever required them, because trust or liability or speed depends on them. The first column is now genuinely optional. The second column is your actual standard. Most teams have never drawn this line, because the law drew it for them. Drawing it yourself, deliberately, is the first real act of setting your own bar.
Second, write the standard down as a standard. A bar that lives in the heads of a few careful people evaporates under the first quarter of real pressure. Name the two or three things you commit to holding above what the relaxed law now requires: human review on the highest-stakes automated decisions, an audit trail you could assemble in days rather than weeks, a named owner for every model running in production. Put them on a single page. The point is not bureaucracy. It is that an explicit standard survives a busy quarter and a change of personnel, and an implicit one does not.
Third, give it an owner and a cadence. Floor-driven governance had a deadline doing the enforcement for you. A bar you set yourself has no deadline, which means it needs a person whose job explicitly includes holding it, and a recurring review where it actually gets checked, or it slides back down to whatever the law now requires. This is also what makes the bar legible to your board, which is increasingly asking what your AI is actually producing and how it is controlled and arriving expecting an answer with an owner’s name attached to it.
Fourth, make the bar visible to the people who reward it. A standard only becomes an advantage when the buyer’s security team and your own board can see it. Decide what is worth saying out loud: a short, plain account of how you govern AI that a salesperson can hand a cautious enterprise buyer, a standing line on the board agenda rather than an answer assembled in a panic the week a question arrives. The same discipline that closes a deal on trust turns a routine deployment into a competitive edge. It turns an efficient AI tool into a reason a customer prefers you, rather than a technical box you merely managed to check. A bar you keep quiet still protects you, but the bar you can show is the one that also wins business.
Fifth, build the evidence, not just the policy. A document that says you govern AI responsibly is worth very little the moment a buyer, a regulator, or a court asks you to prove it. The bar has to produce artifacts: the record of who approved what, the sign-off on the high-stakes call, a check that reads the model’s actual output rather than trusting the model to report on itself. This is the difference between verifying the work and assuming it got done, and it is the part of governance that survives contact with a real challenge. A policy is a promise. Evidence is a position.
The decision
The question the retreat actually puts on the table is what your AI governance was ever for. If it was only ever a way to satisfy a law, then a relaxed law means you can relax too, and banking the saved effort now is a legitimate call. If it was a way to protect the business from its own automated decisions, then nothing changed this month except the single external force that used to make you do it.
Both are real positions. They are not the same wager. One trades a known governance cost for savings now and accepts the exposure that comes with a lower bar. The other holds the line and pays for it, on the bet that trust, liability, and the next buyer’s security review will collect on it later. What you cannot do is hold the second position by accident. The deadline that used to set your standard is gone, and with it the comfortable arrangement where someone else decided how seriously you took this. For two years the rules defined what ready meant. Now that no one is setting that bar for you, the only standard your AI is held to is the one you decide, on purpose, to hold it to.
Questions this article gets
What did the 2026 AI regulatory rollback actually change?
Three things eased in roughly one month, on the timeline and the pressure, not the underlying expectation. In early May the EU agreed to push its AI Act high-risk obligations from 2 August 2026 to 2 December 2027. On 14 May Colorado repealed the AI Act it had passed and replaced it with the lighter SB 26-189, effective 1 January 2027, dropping the risk-management programs, impact assessments, and the duty of reasonable care to prevent algorithmic discrimination. On 2 June a White House order, Executive Order 14409, ruled out any mandatory federal licensing for new AI models. None of these repealed the idea that AI should be governed. They removed the deadline that was going to force it, and they left every existing privacy, consumer, and employment law in place.
Should a company relax its AI governance now that the rules eased?
It depends on what the governance was ever for. If it existed only to satisfy a coming law, a relaxed law is a legitimate reason to relax and bank the saved effort. If it existed to protect the business from its own automated decisions, nothing changed this month except the one external force that used to make you do it. Liability still runs through privacy, discrimination, and contract law, which were not delayed; a Norton Rose Fulbright 2026 survey found 46% of in-house legal leaders reporting more AI-related litigation exposure at the federal level. Buyers still ask how you govern AI in security reviews. The honest answer is that compliance was the floor and the business bar is separate, so relaxing the bar by reflex is a decision, not a default.
How do you set your own AI governance standard?
Five moves. First, sort your AI governance practices into two columns: the ones built only to meet a coming law, and the ones you would keep regardless because trust, liability, or speed depend on them; the second column is your real standard. Second, write it down as a one-page standard, naming the two or three things you commit to holding above what the relaxed law requires. Third, give it an owner whose job includes holding it and a recurring review, because a self-set bar has no deadline enforcing it. Fourth, make it visible to the buyers and the board who reward it. Fifth, build the evidence, the approvals and sign-offs and output checks, not just the policy, because a promise is worth little when someone asks you to prove it.