California's latest AI move did not come through a broad consumer AI statute. It came through procurement.
If you want the official source, California’s executive order is here: Executive Order N-5-26.
In March 2026, Governor Gavin Newsom issued Executive Order N-5-26, directing the state to build a new procurement framework for AI. That may sound narrower than a headline AI law, but it could matter just as much for companies that sell AI tools or services into large buyers.
Procurement is where AI governance gets real
The order points toward a system in which AI vendors may need to make structured representations about how their systems are built, governed, and monitored. That includes familiar pressure points like data handling, bias controls, civil-liberties protections, and related safeguards.
Procurement is where abstract AI principles often become contract obligations. It is easy to talk about responsible AI in marketing language. It is much harder to answer a buyer's concrete questions about training data, oversight, controls, auditability, and remediation.
What legal teams should take from it
Procurement is one of the fastest ways to force operational discipline. Buyers can demand certifications, representations, warranties, and disclosure commitments long before legislatures settle every policy fight.
That means legal departments are no longer just debating AI governance in theory. They are negotiating it in contracts.
The takeaway
For vendors, the lesson is simple: if governance documentation does not exist in a usable form, build it now. For buyers, California offers a practical model for imposing more discipline on higher-risk AI tools without waiting for a perfect statute.
California is not just regulating AI through lawmaking. It is shaping the market through purchasing power. That is often how governance becomes real.
Connecticut has moved from “state to watch” to a state companies may actually need to operationalize against.
If you want the official bill text, Connecticut’s latest substitute text is here: SB 5.
On May 1, 2026, the legislature passed SB 5, a broad AI bill that would place Connecticut among the more aggressive state players in AI governance. The point is not just that another state acted. It is that Connecticut appears to be building a framework that spans multiple AI risk areas at once.
What makes this state move worth watching
A lot of state AI proposals focus on one slice of the problem, usually hiring tools, consumer protection, or deepfakes. Connecticut's approach is broader. It treats AI governance as a cross-functional legal problem rather than a niche product issue.
That matters because it better reflects how organizations actually use AI. AI now touches hiring, customer communications, vendor tools, automated decisions, synthetic media, and internal workflows.
The patchwork problem is getting harder
SB 5 is also another reminder that federal law is not about to simplify the map. States are continuing to legislate, and they are doing it with different definitions, priorities, and enforcement models.
That creates two practical tasks for legal teams. First, they need a real inventory of where AI shows up in the business. Second, they need a governance structure that can absorb state variation without rewriting the whole policy stack every time a legislature moves.
The takeaway
Connecticut’s bill may not become the national template by itself. But it does point toward the future: AI governance that looks more like privacy or employment compliance, meaning state-specific, operationally demanding, and hard to solve with one policy memo.
Connecticut is not the whole story. But it is increasingly part of the real one.
Colorado's AI law is moving again before many companies have even finished mapping the original version.
If you want the official text, the Colorado bill is here: SB26-189.
In May 2026, lawmakers passed SB 26-189, a major rewrite of the state's earlier AI framework. The main shift is from regulating broadly defined “high-risk AI systems” to regulating automated decision-making technology, or ADMT, when it materially influences consequential decisions.
What stands out is how directly the law targets decision environments legal teams already care about: employment, housing, lending, insurance, health care, education, and essential government services. The practical question is less about what a tool is called and more about how it is used when it affects a person in a meaningful way.
The new focus is operational accountability
The revised bill is set to take effect on January 1, 2027. That buys time, but it also makes the compliance direction clearer.
Developers would need to give deployers technical documentation on intended uses, training data categories, limitations, and human-review instructions. Deployers would need to provide consumer notices and, after an adverse outcome, a plain-language explanation of the role the system played. Consumers would also have rights to seek correction of inaccurate data and meaningful human review.
What legal teams should focus on
This is especially important for employment and other high-impact workflows. Recruiting tools, ranking systems, interview-analysis products, and recommendation engines can all end up inside the regulatory frame if they materially influence decisions.
That means the compliance question becomes more concrete: what is the system doing, who is relying on it, what notice is required, and what happens when someone challenges the outcome?
The bigger lesson
Colorado’s rewrite is a useful reminder that state AI compliance is still moving in real time. Static AI policies are going to age badly. Legal and compliance teams need a more flexible operating model that can absorb changing definitions, disclosure duties, and review rights across states.
The takeaway is not that Colorado is backing away from AI regulation. It is that Colorado is trying to make its law more targeted and more workable. For companies using AI in consequential decisions, the safer question is not “do we use AI?” but “can we explain and defend how this system influenced the decision?”
The EU AI Act story in 2026 is no longer about one looming deadline.
It is about figuring out what moved, what did not, and where legal teams should spend compliance time first.
“The AI Act was delayed” is too sloppy to be useful.
Recent reporting indicates that the European Parliament and Council reached agreement on amendments that would postpone some major obligations, especially around high-risk AI uses and watermarking timing, while the European Commission also published draft guidance on transparency obligations that still begin this year.
So the practical question is not whether the AI Act matters less. It is where the immediate compliance pressure now sits.
It is what still appears to hit in 2026 and what can likely be sequenced later.
The short version
Here is the cleanest practical read based on current reporting:
What did not move
core transparency obligations still appear set for August 2, 2026
disclosure expectations for AI systems that interact with people
related user-facing design and notice questions
the need to review where AI-generated or AI-manipulated content appears in products and workflows
What moved later
AI-generated content transparency and some watermarking-related timing reportedly moves to December 2, 2026
Annex III high-risk AI systems reportedly move to December 2, 2027
Annex I product and product-safety high-risk AI systems reportedly move to August 2, 2028
That does not mean companies can relax.
It means they should stop treating every AI Act obligation as if it lands on the same day.
What stayed on the 2026 calendar
The biggest mistake legal teams can make here is hearing “delay” and translating it into “not urgent.”
That would be a bad read.
Even with the reported changes, core transparency obligations still appear positioned to matter starting August 2, 2026.
For many organizations, that means focusing now on systems that interact directly with users and making sure disclosures are not buried in terms or documentation nobody reads.
In plain English, companies should be asking:
Where are users directly interacting with AI systems?
Is the disclosure clear in the interface itself?
Are we treating different user groups appropriately?
Do any product flows involve AI-generated or AI-manipulated content that raises separate transparency issues?
Are product, legal, compliance, and design teams aligned on what the user actually sees?
That is practical work. Not compliance cosplay.
What legal teams should do now
This is the moment for reprioritization, not celebration.
A practical checklist:
map AI systems that directly interact with users
identify where AI-generated or AI-manipulated content appears
review interface-level disclosures instead of relying on buried policies
separate immediate 2026 transparency work from later high-risk build-out
revisit vendor diligence questions and contract language in light of the updated timing
give business teams a clearer timeline so “delay” does not become an excuse for doing nothing
For in-house teams, this is also a communications problem.
If the business hears only that the EU delayed the AI Act, the organization may under-resource work that still appears likely to happen this year.
That misunderstanding can create more risk than the original deadline pressure.
The bigger lesson
The EU AI Act is becoming a sequencing challenge.
That means the winning move for legal teams is not just knowing the rules. It is knowing the order in which the rules matter.
That is what good AI governance looks like in practice.
Not panic.
Not delay theater.
Just disciplined prioritization.
The AI Act still matters in 2026.
The real question now is which part of it is knocking first.
One caution, though: because this area is moving through amendments, guidance, and implementation detail at the same time, legal teams should confirm the latest official timetable before treating any one summary as the final word.