← Back to articles
Governance5 MIN READ

AI Regulation Is Fragmenting Fast. Is Your Business Ready?

A wave of AI regulations across states and countries is creating real compliance complexity for SMBs that buy, use, or build with AI tools. Here's what to watch.

Alex Followell
Alex Followell
2026-07-17 · 5 min read
TL;DR

AI regulation is no longer a future problem. It's here now, and it's fragmented across dozens of jurisdictions with conflicting rules. The EU AI Act is already in force, US states are passing their own laws at different speeds, and businesses caught in the middle face real legal and operational exposure. If you're using AI in hiring, customer service, or automated decision-making, you likely have compliance obligations you haven't mapped yet.

Why Is AI Regulation Suddenly a Problem for Small Businesses?

Most SMB operators assume AI regulation is a big-company issue. It isn't. If you're using AI tools in hiring, credit decisions, customer communications, or any automated workflow that touches personal data, you're already inside the regulatory perimeter in several jurisdictions. The rules are arriving faster than most operators realize, and they don't exempt you for being small.

The EU AI Act became enforceable in 2024 and is the most comprehensive AI law in effect anywhere in the world. It classifies AI systems by risk level and imposes obligations on anyone who deploys them, not just the companies that build them. If you're selling into Europe or processing data about European residents, this applies to you.

At the same time, the US has no single federal AI law yet. What it has instead is a patchwork: more than 40 states introduced AI-related legislation in 2024, with Colorado, Texas, and Illinois among the states that have passed or are advancing laws that directly affect how businesses can use automated decision-making.

What Does Regulatory Fragmentation Actually Mean for an Operator?

Fragmentation means the same tool, used the same way, might be compliant in one state and non-compliant in another. It means you can't rely on a single policy document. It means your AI vendor's terms of service don't protect you if the liability lands on the deployer, which in most frameworks, it does.

Here's a concrete example. Illinois has had the Artificial Intelligence Video Interview Act since 2020, requiring employers to notify candidates when AI is used to analyze video interviews and to get consent. If you're using an AI hiring tool without those disclosures in place, you're exposed in Illinois regardless of what the tool vendor told you.

Colorado's SB 205, signed in 2024, goes further: it requires deployers of high-risk AI systems to conduct impact assessments and disclose AI use to affected individuals. "High-risk" includes consequential decisions about employment, credit, housing, and healthcare.

The compliance obligation isn't just on the AI company. It's on you, the business deploying the tool.

Which Regulations Should SMBs Actually Pay Attention To?

Here's a quick-reference map of what's live or advancing that matters most for US-based SMBs:

| Jurisdiction | Law / Framework | Status | Key Obligation for Deployers | |---|---|---|---| | EU | EU AI Act | In force (2024) | Risk classification, transparency, human oversight for high-risk systems | | Illinois | AI Video Interview Act | In force (2020) | Consent and disclosure for AI in hiring interviews | | Colorado | SB 205 | Signed 2024 | Impact assessments, disclosure for consequential AI decisions | | Texas | HB 1709 (TX AI Act) | Advancing | Similar to Colorado: deployer obligations for high-risk AI | | California | Multiple bills (AB 2013, SB 1047 variants) | Mixed outcomes | Transparency, safety testing, data disclosure | | Federal (US) | No comprehensive law yet | Ongoing | Executive orders in place; sector-specific rules (EEOC, CFPB) apply |

This table will be outdated within months. That's the point. The landscape is moving faster than any single compliance checklist can track.

What Are the Actual Business Risks If You Ignore This?

The risks aren't purely theoretical. Three categories matter most right now:

Legal liability. As deployers, not just builders, businesses can face enforcement actions, civil suits, and regulatory fines. The EEOC has already issued guidance on AI in hiring and made clear that Title VII applies regardless of whether a human or an algorithm made the discriminatory decision.

Vendor dependency risk. If your AI vendor changes their model, their data practices, or their terms of service, your compliance posture changes with them. Most SMBs have no visibility into this. Fewer than 20% of companies have formal processes for reviewing AI vendor compliance, according to Gartner's 2024 AI governance survey.

Reputational exposure. Customers and employees are increasingly aware of AI use. An undisclosed AI system in hiring or customer service, once surfaced, becomes a PR problem that no legal settlement fully fixes.

Does AI Regulation Actually Help Businesses in Any Way?

Yes, and it's worth saying clearly. Regulation creates a floor. It pushes vendors to build more auditable, explainable tools. It creates standards that make it easier to evaluate competing products. Businesses that invest in governance now will have a structural advantage over competitors scrambling to retrofit compliance later.

The operators who benefit most from incoming regulation are the ones who treat governance as a workflow problem, not a legal problem. Meaning: documented processes, vendor review checklists, and clear internal policies about where AI can and can't be used. These aren't expensive to build. They're mostly just structured thinking written down.

How Should a Small Business Actually Respond to This?

The honest answer is that most SMBs don't need a compliance department. They need three things: an inventory of where AI is in use, a basic risk assessment for each use case, and a vendor review process that doesn't rely solely on the vendor's self-reporting.

The biggest mistake we see is operators assuming the AI tool vendor handles compliance. They don't. They build the tool. You deploy it. In most regulatory frameworks, the deployer carries primary liability for how it's used.

Start with your highest-stakes AI use cases: hiring, customer credit or financing decisions, health-related recommendations, or anything with automated outcomes that significantly affect individuals. Those are the areas regulators are targeting first, and they're the areas where the legal exposure is real today, not hypothetical.

What We'd Actually Do

  • Audit your AI tool stack this week. List every AI-enabled tool in use across hiring, customer service, finance, and operations. For each one, identify whether it makes or influences consequential decisions about individuals. That's your risk inventory.
  • Pull the terms of service for your top three AI vendors and look for indemnification language. Most vendor agreements place compliance responsibility on you as the deployer. Know what you've agreed to before a regulator asks.
  • Set a calendar reminder every 90 days to check your highest-risk jurisdictions. Colorado, Texas, and California are all moving legislation right now. If you operate nationally or sell into Europe, this isn't optional. Regulation is being written on a faster cycle than most business planning cycles.

If you want to build a real AI governance framework for your business, not just a checklist, that's exactly the kind of work we do inside the community and through the agency. Start at skool.com/aiforbusiness.

FAQ

Does AI regulation apply to small businesses or just large enterprises?

It applies to any business deploying AI in covered use cases, regardless of size. Laws like the Colorado SB 205 and Illinois AI Video Interview Act don't include SMB exemptions. If you're using AI in hiring, customer decisions, or automated workflows that affect individuals, you likely have obligations already in force in certain states.

Who is liable when an AI tool violates a regulation, the vendor or the business using it?

In most frameworks, the deployer carries primary liability. The vendor builds the tool; you decide how and where to use it. Most vendor agreements reinforce this. Before deploying any AI tool in a high-stakes use case, read the terms of service carefully and understand what indemnification, if any, the vendor actually provides.

What's the fastest way for an SMB to start getting compliant with AI regulations?

Start with an inventory: list every AI tool in use and flag any that influence consequential decisions about people, hiring, credit, healthcare, or housing. Those are the highest-risk areas regulators are targeting first. From there, a basic written policy on AI use and a vendor review process gets you most of the way to a defensible governance posture.

JOIN THE COMMUNITY

Want this running in your business?

The Skool community is where we show the full builds, share the templates, and help you implement. Three tiers, from team training to fractional AI expert.

  • Weekly Q&A with Alex and Cameron
  • Templates and frameworks you can steal
  • Real builds, running in real businesses
Join skool.com/aiforbusiness