Three binding California statutes in eight days. On September 9, SB 813 and AB 1405 — the state describes the first as making California the first in the nation to require assessments by independent verification organisations, and the second as requiring third-party audits of AI systems. On the 16th, SB 1050, requiring explicit disclosure on any advertisement using AI-generated performers and barring continued use of one found in violation. Then, on the 18th, a directive that is not a law at all. Newsom ordered two agencies to recommend statutory changes by November 16: external safety evaluators at AI companies, independent verification of the safety frameworks already mandated, a route to requiring a ‘kill switch’, and a wider definition of the incidents companies must report — to cover ‘a range of loss-of-control incidents’. Several mirror SB 1047, which he vetoed in 2024. Existing law sets the reporting bar at 50 deaths, chemical or biological weapons, or $1 billion in damage, which the recent agent-driven hackings do not reach. He has also floated a special session or executive action, and called the new laws ‘the floor, not the ceiling’.
The Whole Story
AI's rules are being written in three places that do not talk to each other: courtrooms applying statutes drafted decades before the technology, legislatures drafting new ones, and executives issuing orders that bypass both. The three move at different speeds and often in opposite directions, and the gap between what is announced and what is enforced has become the most reliable feature of the field.
The courts came first, because plaintiffs did not need a new law. Copyright suits over training data have run since January 2023, when visual artists sued Stability AI and Getty Images followed with a complaint over twelve million photographs; The New York Times sued OpenAI and Microsoft that December. The first US merits ruling, in February 2025, went against the AI company. Then in June 2025 Judge William Alsup drew the line that still governs American copyright practice: training a model on lawfully acquired books is fair use, but downloading pirated copies to do it is not. Anthropic settled the resulting class action for $1.5 billion in September 2025 — the largest copyright settlement on record — and a successor judge approved it in July 2026 at roughly $3,000 a work, expressly reasoning that success at trial was not assured. No court has yet held that unlicensed training is generally unlawful, and the rulings that come closest are elsewhere: a Munich court found in November 2025 that memorising song lyrics exceeds Europe's text-and-data-mining exception, and a Delhi judge found in July 2026 that India's fair-dealing exception stretches the other way, far enough to cover a closed corporate training process.
Running alongside it is an older question the technology has made urgent: when a machine acts, who is answerable? The answer has mostly been the company that deployed it. A Canadian tribunal held Air Canada to what its chatbot told a passenger in February 2024 and rejected outright the submission that the chatbot was a separate legal entity; a US court let a wrongful-death suit against Character.AI proceed in May 2025 by treating the model as a product; a German appeals court ruled in May 2026 that running a chatbot is the operator's own commercial act, whatever probability produced the words. California bars the defence by statute. But that line was drawn under contract, tort and product law, and where a different statute is asked the answer inverts: in August 2026 a federal appeals court held that under America's 1986 anti-hacking law an AI agent is a tool rather than a person, so it is the user, not the company, who reaches into someone else's computers — while pointedly declining to say anything about liability in tort. China has now answered the question wholesale rather than case by case: on 7 September 2026 its Supreme People's Court issued 24 articles of adjudication rules telling every court below it how to decide AI disputes — cloned faces and voices infringe personality rights, a provider that is told its system produced infringing content and is slow to act is liable, and so is a user who prompted for it on purpose. In the meantime the enforcement that exists in the West is being brought under laws that mention neither AI nor agents. The Federal Trade Commission banned Rite Aid from facial recognition in 2023 and opened a sweep against deceptive AI claims in 2024; a state medical board sued a chatbot company for practising medicine without a licence; Florida sued OpenAI and its chief executive for deceptive trade practices; and fifteen attorneys general jointly demanded document preservation and a halt to a category of experiments after one of those experiments escaped.
Legislatures have had a harder time. The EU AI Act entered into force in August 2024 as the world's first comprehensive statute, and has been retreating from its own timetable ever since: in July 2026 the Digital Omnibus amended the Act itself, pushing the high-risk obligations from August 2026 to December 2027 and, for AI inside machinery and toys, to August 2028. The register those obligations depend on does not exist and is not expected before late 2027. Britain has legislated nothing comparable; the instrument it passed in 2026 obliges its data regulator to write an AI code of practice that will not take effect until 2027. In the United States there is no federal statute at all. Colorado passed the first comprehensive state law in May 2024, over its own governor's written reservations; the legislature postponed it twice, xAI sued to enjoin it, the Justice Department intervened against it, a court froze it before it ever applied, and in May 2026 the state repealed and re-enacted it as a narrower regime that does not take effect until 2027. State laws that do bite tend to be narrow ones — a hiring-audit rule in New York City, deepfake and nudification bans — and those are now being met at the courthouse door on First Amendment grounds.
What has filled the vacuum is executive power, and it changes hands. Biden's Executive Order 14110 of October 2023 imposed reporting duties on frontier developers; Trump revoked it on his first day in office. What replaced it works differently: an order of December 2025 directed federal agencies to contest state AI laws, and an order of June 2026 built a federal review gate for the most capable models — voluntary by its own terms, and triggered by a classified benchmark that the NSA director alone applies. The Commerce Department has meanwhile shown it does not need any of this, restricting a company's models through export-control letters issued without notice or comment.
So four questions are open. Whether unlicensed training is lawful is unresolved in the United States and answered opposite ways in Germany and India. Whether a company answers for what its agent does depends, in the United States, on which statute a plaintiff reaches for — and the court that said least about it said so deliberately; China has simply written the answer down. Whether written rules can be enforced is a resource question the EU is about to test with thirty-four compliance staff. And whether a threshold nobody outside an intelligence agency can inspect is a workable basis for a legal obligation is a question the first designation will start to answer.