The Wild West Inside Your Company
Wade Wyant
on
August 1, 2026
The EU just gave companies an extra sixteen months to comply with its AI accountability law. If your reaction to that sentence is relief, keep reading.
Article 86 of the EU Artificial Intelligence Act was originally set to apply on August 2, 2026. Six weeks ago, the EU formally pushed that deadline back to December 2, 2027, through a package called the Digital Omnibus on AI. The delay does not mean the law went away. It means the clock restarted with a longer fuse.
“The law did not go away. The clock just restarted with a longer fuse.”
What the Law Actually Requires
Article 86 gives any person affected by an AI-assisted decision the legal right to demand a clear explanation of how the AI was involved in that decision and what the main factors were. The company deploying the AI has to produce that explanation. Not the vendor. Not the platform. The business that used the tool.1
This applies to decisions that produce legal effects or significantly adverse consequences. The EU is not asking you to explain why your AI suggested a new vendor or helped you set a price. It is asking you to explain decisions that affect people directly: hiring and firing, credit scoring, insurance eligibility, healthcare, education, and access to essential services. The EU groups these use cases under Annex III, which is the law’s official register of high-risk AI applications. Think of it as the EU’s list of the situations where AI errors can do the most damage to a real person’s life. Government security and certain law enforcement functions carry exemptions. Everything else on that list does not.
Here is something I want to give the EU credit for: I think they found the right scope. Most regulation either misses the real problem or overcorrects into something unworkable. Article 86 is targeted. The EU looked at where AI errors cause the most human damage, drew the line there, and left business strategy decisions alone. That is a balance I respect, even as an American who generally thinks European regulators overreach.
“The EU focused on where AI errors cause the most human damage. That is the right place to draw the line.”
The Audit Trail Nobody Built
Here is the uncomfortable question the law is really asking: if you had to produce that explanation today, could you?
Think about what the average leader does with AI. They open a browser tab. They paste something in. They get a response. They close the tab. The conversation is gone. There is no record of what was asked, what was said, what version of the model was running, or what data it drew from. The decision gets made. The trail evaporates.
Now think about email. Email has been through the legal and regulatory wringer for decades. Every corporate attorney knows exactly how to handle a subpoena for email. Companies have retention policies, legal hold procedures, discovery tools, and accepted industry standards. Whether a company retains email for one year or seven, there are frameworks, there is precedent, and there are answers. If you are subpoenaed for email, you know what to hand over.
Your AI has none of that. If you were subpoenaed for your employees’ AI conversations today, how would you produce them? If those conversations happened on personal free accounts, you cannot produce them at all. And even if you had enterprise accounts that automatically save conversation history, you still could not answer the questions a subpoena would require: At what point did the AI’s output shape the outcome, and at what point did the human’s own judgment take over? What weight did the AI carry in the final call? Can you show the original prompt alongside the response, in sequence, in full context? Most companies cannot answer any of those questions.
“If you were subpoenaed for your employees’ AI conversations today, what would you hand over?”
The United States Is Not Waiting
The EU delay does not mean American companies are off the hook at home.
Forty-five states have introduced AI-related legislation in 2026 alone, building on 145 bills enacted into law in 2025.2
Colorado passed the first comprehensive state AI law in the United States, requiring documentation of AI decision-making processes and transparency disclosures for high-risk systems. California has multiple active AI statutes covering employment and transparency. New York City already requires annual independent bias audits for any automated tool used in hiring decisions. Illinois mandates written notice and consent before AI can analyze a video job interview.
There is no comprehensive federal law yet. That is not a safe harbor. It is a patchwork of state requirements that vary by geography and industry, change every quarter, and are impossible to track without a governance layer already in place. The federal question is when, not if. I have never seen Washington ignore something this consequential at the state level for long.
The Mistake Companies Keep Making
When AI governance comes up, most companies do one of two things. They hand it to IT, or they table it.
Handing it to IT is the wrong move, and here is the analogy I use: if a problem is in the brain, you do not go straight to the neurosurgeon. Sometimes what you need is a therapist. AI governance is a leadership strategy problem with technical components. IT departments are stretched, and they were never built for this kind of work. Executive ownership is not optional.
Tabling it is worse. The leaders treating this as a future problem are the ones who will be scrambling when the December 2027 deadline arrives, or when the first subpoena does, with no documentation to show.
Three Things. That Is It.
An AI strategy you maintain. Not one you write once and forget. AI strategy is not evergreen. You have to return to it, update it, and align it to the regulatory environment as it changes. The EU delay gave you more time. It did not give you permission to stop.
AI enablement for your people. Your team is using AI right now with no guidance on what documentation matters or what tools are approved for which purposes. That gap between what you intend and what is actually happening is where your legal exposure lives.
A governance layer that creates an audit trail. You need to know what AI tools are operating inside your company, what they were asked, and what they produced. Right now, most companies have none of this.
Private AI, built and governed correctly, does all three. REDEGADES.AI is a Decision Alignment Layer. It tracks what goes in and what comes out. It connects AI output to actual decisions and builds the audit trail that the US state laws already on the books demand, and that federal legislation will eventually require. The companies that build with governance baked in will be ready when that moment arrives. Everyone else will be improvising.
“AI strategy is not evergreen. You have to return to it. Water it. Feed it. Or it dies.”
You are not subject to EU law. But you are watching an early version of what is likely headed here. Every state that has moved on AI accountability is reading the same playbook the EU wrote. Build the governance layer now, while it is a choice. Wait, and you will build it under a deadline someone else set.
1. EU Artificial Intelligence Act. “Article 86: Right to Explanation of Individual Decision-Making.” Applicability date: December 2, 2027 (as amended by the Digital Omnibus on AI, formally adopted June 29, 2026). https://artificialintelligenceact.eu/article/86/.
2. Multistate.ai. “State AI Legislation Tracker 2026.” https://www.multistate.ai/artificial-intelligence-ai-legislation. See also: Baker Botts. “U.S. Artificial Intelligence Law Update: Navigating the Evolving State and Federal Regulatory Landscape.” January 2026. https://www.bakerbotts.com/thought-leadership/publications/2026/january/us-ai-law-update.
3. Peter Douglas. “Understanding Right to Explanation and Automated Decision-Making in Europe’s GDPR and AI Act.” TechPolicy.Press. September 19, 2025. https://www.techpolicy.press/understanding-right-to-explanation-and-automated-decisionmaking-in-europes-gdpr-and-ai-act/.
4. EU Digital Omnibus on AI. Council of the EU final approval: June 29, 2026. European Parliament endorsement: June 16, 2026. See: Travers Smith. “EU agrees to delay key AI Act compliance deadlines.” https://www.traverssmith.com/knowledge/knowledge-container/eu-agrees-to-delay-key-ai-act-compliance-deadlines/.









