The gist
AI regulation in 2026 is a real maze. The EU AI Act is coming into force in stages, US executive orders get issued and then revoked, GDPR applies to AI with extra requirements, and state-level laws have appeared in the US. If you make money with AI or handle users' data, you need to know the basics so you don't run into a fine or a lawsuit.
This lesson is a practical map of the 5 main jurisdictions and 9 risk areas. No legal jargon, with a step-by-step compliance checklist for small and mid-sized businesses (SMBs).
This is not legal advice. Laws change fast: the dates and provisions below are as of October 2026, based on public sources and lawyers' summaries. Before launching a product, check them against the official texts and, where needed, with a lawyer.
🎯 Decision tree: which laws apply to you
The key question isn't "how do I comply with everything" but "what actually applies to my AI product."
The EU AI Act + GDPR apply if:
- ✓ You have users in the EU (even if you're based in the US or Latin America)
- ✓ Your product is accessible from the EU without blocking
- ✓ You process data of people in the EU
California / NYC / Colorado state laws apply if:
- ✓ Your product is available in those states
- ✓ You hire people in NYC using AI tools
- ✓ You make AI-driven decisions in Colorado (insurance, credit, hiring)
Data localization laws in other countries apply if:
- ✓ You process data of citizens of a country that requires it (Russia's Federal Law 152-FZ is one example)
- ✓ The law requires that data to be stored on servers inside that country
Anthropic's terms always apply if you use the Claude API / claude.ai.
Key concepts
- EU AI Act: direct regulation of AI systems in the European Union, by risk level
- GDPR: the EU's General Data Protection Regulation; it applies to AI through Article 22 (automated decisions) and the right to explanation
- High-risk AI: a category in the EU AI Act that includes medicine, hiring, credit, education and infrastructure
- Conformity assessment: a mandatory audit for high-risk AI before deploying it in the EU
- Right to explanation: the user's right to get an explanation of an AI decision
- Human-in-the-loop: required human involvement in automated decisions
- DPA (Data Processing Agreement): a contract with a sub-processor (Anthropic, OpenAI) about how data is handled
- Sub-processor: a third party that processes data on your behalf
- Bias audit: checking an AI system for discrimination (mandatory in NYC for AI used in hiring; for other states' requirements, see below)
- Acceptable Use Policy (AUP): a vendor's list of prohibited uses of its AI
Theory
The EU AI Act: the main regulator of 2026
The EU AI Act took effect in August 2024 and applies in stages: the bans since February 2025, the rules for general-purpose models since August 2025, and the transparency requirements (Article 50) since August 2, 2026. The EU postponed the requirements for high-risk systems (the Digital Omnibus package, in force since July 27, 2026): for systems in Annex III the deadline moved to December 2, 2027, and for systems in Annex I to August 2, 2028. This is direct regulation of AI systems, classified by risk level.
It applies to: any AI system that operates in the EU or serves EU users. Even if you're based elsewhere, if your product is available to an EU user, the act covers you.
4 risk levels:
| Risk level | Examples | What's required |
|---|---|---|
| Unacceptable (banned) | Social scoring (as in China), manipulating children, real-time biometric mass surveillance | Banned outright |
| High risk | Medicine, diagnostics, hiring, lending, education, law enforcement, critical infrastructure | Conformity assessment + registration |
| Limited risk | Chatbots, deepfakes, emotion recognition | Disclosure: "you're talking to an AI" |
| Minimal risk | Spam filters, game recommendations, basic machine translation | No requirements |
What you need if you're high risk:
- A conformity assessment (an audit before deployment), which is a separate, expensive procedure
- A documented risk management system
- Data governance + bias testing
- Built-in human oversight
- Documentation kept for 10+ years
- Registration in the EU AI database
- CE marking on the product
Fines: up to €35M or 7% of global revenue (whichever is higher) for banned practices, and up to €15M or 3% for violating the requirements for high-risk systems. For a small business, a fine like that is devastating.
Source: https://artificialintelligenceact.eu/ (check the deadlines and changes against official EU publications)
GDPR + AI: an old law with new teeth
GDPR has been in force since 2018, but AI-specific guidance appeared in 2023-2025. It applies to all personal data of people in the EU: names, emails, IP addresses, behavioral data, biometrics.
What matters for someone building with AI:
Article 22: Automated decision-making:
A user has the right not to be subject to decisions made solely by AI, without human review, if those decisions have legal or similarly significant effects.
It applies when:
- AI screens job candidates → you need a human review path
- AI denies credit → there must be a way to appeal
- AI sets insurance terms → you need an explanation + an appeal
Right to explanation: A user can ask for an explanation of "why the AI decided X about me." That means:
- Log the key factors behind the AI's decision
- Prepare an "understandable" explanation (not a black box)
- Have a process for answering the request (30 days under GDPR)
Data minimization: Don't collect more data than the AI task needs. If viewing history is enough to recommend movies, don't ask for location.
A lawful basis for training data: You need one of:
- Consent (explicit agreement): the cleanest
- Contract: the data is needed to perform a contract
- Legitimate interest: a balancing test (risky for training data)
Fines: up to €20M or 4% of global revenue (whichever is higher).
Source: https://gdpr.eu/
The US: federal rules weakened, state rules grew
The main story of 2025-2026: federal AI regulation weakened, but state-level regulation grew significantly. The relationship between federal and state rules is still contested, so check the current state of things.
Federal status:
- Biden's Executive Order 14110 (2023) was revoked by Trump in January 2025
- Voluntary safety-testing commitments by the big AI companies (Anthropic, OpenAI, Google) remain
- The FTC (Federal Trade Commission) kept its authority over deceptive AI claims and unfair practices
State level (more important for SMBs):
| State | Law | What it requires |
|---|---|---|
| California (SB 53) | Transparency in Frontier AI Act | Transparency for developers of the largest (frontier) models: publishing safety frameworks, incident reports. It doesn't apply directly to small products |
| Colorado AI Act (2024) | High-impact AI consumer protection | Anti-discrimination rules for high-impact decisions (hiring, credit, insurance, education). Its effective date was pushed to January 1, 2027 and the law was narrowed (May 2026 amendments); keep an eye on changes |
| New York City Local Law 144 | Automated Employment Decision Tools | A bias audit is mandatory if you use AI for hiring in NYC |
| Illinois BIPA | Biometric Information Privacy Act | Consent for biometric data, with statutory damages for violations |
| Texas (HB 2060) | AI Advisory Council | An inventory of state government AI use, the start of regulation |
FTC enforcement (examples from 2023-2025):
- Rite Aid (2023): banned from using facial recognition for several years because of false matches
- Cases against companies over "deceptive AI capabilities" claims (the Operation AI Comply sweep, 2024)
- Orders to delete models trained on data collected without consent
Sources:
- https://leginfo.legislature.ca.gov/
- https://www.nyc.gov/site/dca/about/automated-employment-decision-tools.page
- https://www.whitehouse.gov/
China: strict regulation with a different philosophy
It applies to AI services available in China or aimed at Chinese users.
Key rules:
- Generative AI Measures (2023+): AI services must pass a security review by the CAC (Cyberspace Administration of China) before a public launch
- Deep Synthesis Provisions: all deepfakes / AI-generated media must be labeled
- Algorithmic Recommendations Provisions: transparency about recommendation algorithms
- Data localization: Chinese users' data stays on servers in China
In practice, for a builder outside China:
- If you're not targeting the Chinese market, it's usually not relevant
- If you're launching a product in China, you need a Chinese partner + CAC approval
Source: the Cyberspace Administration of China (for English summaries, see the Stanford HAI policy tracker)
Russia and other countries without AI-specific laws
Status as of October 2026: during the review we couldn't confirm a separate AI law in Russia, so check the current situation. General laws apply there:
- Federal Law 152-FZ "On Personal Data": Russia's rough equivalent of GDPR
- Data localization (the initial processing of Russian citizens' data must happen on servers in Russia)
- Consent to processing
- The right to deletion
- Federal Law 149-FZ "On Information": general requirements for information systems
- Discussed in 2025-2026: laws on AI labeling and deepfakes; check whether they've been passed
In practice: if you work with users from Russia, follow 152-FZ. If your users are in other countries, it's usually not relevant. The same logic holds for any country: find out whether it has data localization or personal data rules before you take on its users.
Source: http://www.consultant.ru/document/cons_doc_LAW_61801/ (in Russian)
Latin America: each country has its own data protection law
The names, numbers and status of these laws were checked against official sources in October 2026. Laws change: check them again before you launch.
| Country | Law | Status |
|---|---|---|
| Brazil | LGPD, Law No. 13,709/2018 (in force since September 18, 2020) + the AI bill PL 2338/2023: passed by the Senate, under review in the Chamber of Deputies as of October 2026 | General data protection law; the EU recognized its level of protection as adequate (2026) |
| Mexico | LFPDPPP: a new federal law from 2025 (it replaced the 2010 law) | General data protection law |
| Ecuador | LOPDP, the Organic Law on Personal Data Protection (since 2021) | General data protection law |
| Colombia | Statutory Law 1581 of 2012 | General data protection law |
| Argentina | Law 25,326 on personal data protection (2000) | General data protection law; the EU recognized its level of protection as adequate (2003) |
In practice: if you're GDPR-compliant, that's a good base, but each country has its own law and its own regulator: check your obligations under the local law, especially if you work with health data.
Anthropic's terms of service: what you have to follow
If you use the Claude API or claude.ai, this is your baseline compliance.
Acceptable Use Policy (prohibited):
- Weapons (chemical, biological, nuclear, conventional)
- CSAM (child sexual abuse material) and exploitation
- Election manipulation / political disinformation
- Attacks on critical infrastructure
- Mass surveillance without consent
- Generating malware
- Academic fraud (paid-for theses)
Data handling (important for compliance):
| Tier | Training on your data? | Retention |
|---|---|---|
| claude.ai Free / Pro / Max | Only if the "help improve Claude" setting is on (claude.ai/settings/data-privacy-controls) | Up to 5 years with consent, 30 days without it |
| Team / Enterprise | No (default) | Configurable |
| API (default) | No (default) | See Anthropic's current terms |
| API + Zero Data Retention | No | By agreement (for enterprise) |
Terms change: before launching a product, check them on Anthropic's website and on the What's current page.
Commercial use: allowed. The output is yours, with restrictions (check the list against Anthropic's current terms):
- You can't resell direct API access "as is" (you need a value-add layer)
- You can't claim a human wrote the output where disclosure is required
- You can't use it for spam / disinformation
Sources:
9 risk areas where SMBs actually get into trouble
| # | Risk | Severity | What to do |
|---|---|---|---|
| 1 | Personal data in prompts without consent | HIGH | Pseudonymize / get consent / sign a DPA |
| 2 | Automated decisions that affect users | HIGH | Add a human review path (Article 22) |
| 3 | Medical/legal/financial advice without a disclaimer | HIGH | A mandatory disclaimer + a path to a specialist |
| 4 | Hiring decisions with AI bias | HIGH | A bias audit (mandatory in NYC) + human approval |
| 5 | Children's data without parental consent | HIGH | COPPA (US, kids under 13) / GDPR-K compliance |
| 6 | Deepfakes without labeling | MEDIUM-HIGH | Watermark + disclosure are mandatory |
| 7 | Cross-border data transfer EU→US | MEDIUM | SCCs (Standard Contractual Clauses) or the EU-US Data Privacy Framework |
| 8 | AI-generated content without disclosure | LOW-MEDIUM | A "Generated by AI" badge where required |
| 9 | Training data without IP rights | MEDIUM | Use only legitimate sources (for the base model, Anthropic has already taken care of this for you) |
A compliance checklist for SMBs (the minimum)
If you're an SMB founder using AI in your product:
This checklist covers the main risks for a small product. Full EU AI Act compliance for high-risk systems is a separate big project with lawyers.
When you need a lawyer (3 trigger points)
You need a lawyer right away:
- You got a cease-and-desist letter: immediately
- A regulator sent an inquiry (the ICO in the UK, CNIL in France, the FTC in the US)
- A customer filed a lawsuit with an AI-related claim
You definitely need a lawyer before launch:
- AI in the EU/UK with more than 1,000 users
- A high-risk area: medicine (FDA approval), credit (CFPB), hiring (EEOC)
- A B2B contract with an enterprise client (they'll require a DPA and a security review)
Low-risk SMB: you can do it yourself with templates:
- Content generation without personal data
- AI-powered recommendations inside your own app
- Internal tools for your team
- Educational content
Ready-made templates (as of October 2026; check the terms on the websites)
- Anthropic DPA: request it through https://www.anthropic.com/legal (automatic for business accounts)
- An AI clause for your terms of service: templates from Termly, Iubenda
- AI privacy policy generators: Iubenda, Termly, PrivacyPolicies.com (paid plans; terms on their websites)
- EU AI Act self-assessment tool: https://artificialintelligenceact.eu/assessment/
- Cookie consent for AI tracking: Cookiebot, OneTrust (see their websites for free tiers and terms)
Audience levels: what you personally need
Beginner (personal use, fewer than 100 users):
- A privacy policy with AI disclosure (a template from a generator)
- Basic disclaimers
- You DON'T need a lawyer
Intermediate (an SMB with up to 1,000 customers):
- The full compliance checklist (the 8/8 items above)
- A DPA with Anthropic / OpenAI
- An AI clause in your terms of service
- A professional privacy policy (a legally reviewed template)
- Most likely you DON'T need a lawyer, but a one-time review is useful
Professional (1,000+ users or a high-risk area):
- A full legal review
- An EU AI Act conformity assessment if applicable
- An annual bias audit
- AI liability insurance
- Risk documentation
The hidden cost of compliance
Amounts depend on the country, the lawyer and the size of the product, so there are no specific figures here: get quotes from lawyers and services. The relative order of costs:
| Item | Relative cost | Frequency |
|---|---|---|
| Lawyer review (initial) | Medium | One-time |
| Lawyer updates | Depends on hours | As needed |
| Bias audit (required in NYC) | Medium-high | Annual |
| EU AI Act conformity (high-risk) | High | Initial + annual update |
| Documentation maintenance | A few hours, regularly | Ongoing |
| AI liability insurance (SMB) | Low-medium | Annual |
| Privacy policy generator | Low | Annual |
| DPA management tool | Zero to low | Ongoing |
For an SMB, baseline costs are usually much lower than for a high-risk product: the main first-year expenses are a legal review and document templates.
Practice
Step 1: A self-assessment of your AI product
mkdir -p compliance && cd compliance
touch ai-risk-assessment.mdFill in ai-risk-assessment.md:
# AI Risk Assessment — [Project name]
## 1. What data do I process?
- [ ] Personal data of people in the EU → GDPR + EU AI Act apply
- [ ] Personal data of US residents → State laws (check CA, NY, CO)
- [ ] Personal data of citizens of countries with localization laws (e.g. Russia, 152-FZ)
- [ ] Health data → HIPAA (US), special category (EU)
- [ ] Children's data (<13 US, <16 EU) → COPPA, GDPR-K
- [ ] Biometric → BIPA (Illinois), special category EU
- [ ] Financial → CFPB (US), PSD2 (EU)
## 2. What AI decisions does my product make?
- [ ] Content generation (usually low risk)
- [ ] Recommendations (limited risk)
- [ ] Automated decisions affecting users (HIGH RISK)
- [ ] Hiring / HR (HIGH RISK + NYC bias audit)
- [ ] Medicine / diagnostics (HIGH RISK + FDA in the US)
- [ ] Credit / finance (HIGH RISK + CFPB)
- [ ] Education (HIGH RISK in the EU)
## 3. Are there EU users?
- [ ] Yes → GDPR + EU AI Act apply
- [ ] No → skip the EU section
## 4. Where is the data stored?
- Server location: __________
- Cross-border transfer: __________
- Sub-processors: Anthropic, OpenAI, __________Step 2: Create the compliance documents
# Folder structure
mkdir -p compliance/{policies,agreements,audits,logs}At least 4 files:
# 1. Privacy policy with AI disclosure
touch compliance/policies/privacy-policy.md
# 2. Terms of service with an AI clause
touch compliance/policies/terms-of-service.md
# 3. Sub-processor list (Anthropic, OpenAI, hosting)
touch compliance/policies/sub-processors.md
# 4. Internal audit log
touch compliance/logs/audit-log.jsonlA minimal privacy-policy.md template:
# Privacy Policy **Last updated:** 2026-XX-XX ## What data we collect - Email (at sign-up) - Usage data (how you use the app) - Content you submit to AI features ## How AI processes your data We use Anthropic Claude API to power our AI features. - Your data is sent to Anthropic for processing - By default, Anthropic does not train on API data (check the current API terms before publishing) - Data retention at Anthropic: see the current Anthropic terms (a zero-retention agreement is possible for some customers) - Full Anthropic policy: https://www.anthropic.com/legal/privacy ## Your rights (GDPR/CCPA) - Right to access your data - Right to delete your data - Right to object to automated decisions (Article 22 GDPR) - Right to explanation of AI decisions - Contact: [privacy contact your domain] ## Sub-processors - Anthropic PBC (AI processing) — https://www.anthropic.com/legal - [Your hosting provider] - [Other sub-processors] ## Data retention - Active accounts: while account active - Deleted accounts: 30 days for technical recovery, then purged - Backups: 90 days
Step 3: Create an AI decision audit log
Required for high-risk decisions (hiring, credit, medicine). Useful for low-risk ones.
// audit-logger.js — a simple logger for AI decisions
import { appendFile } from "node:fs/promises";
export async function logAIDecision({
userId,
decisionType,
input,
aiOutput,
finalDecision,
humanReviewer = null,
factors = [],
}) {
const entry = {
ts: new Date().toISOString(),
user_id_hash: hash(userId), // NOT the raw user ID
decision_type: decisionType,
input_summary: redactPII(input),
ai_output: aiOutput,
final_decision: finalDecision,
human_reviewer: humanReviewer,
factors,
trace_id: crypto.randomUUID(),
};
await appendFile(
"./compliance/logs/audit-log.jsonl",
JSON.stringify(entry) + "\n",
"utf-8"
);
return entry.trace_id;
}
function hash(value) {
return crypto
.createHash("sha256")
.update(String(value))
.digest("hex")
.slice(0, 16);
}
function redactPII(text) {
return text
.replace(/[\w.-]+ AT [\w.-]+ DOT \w+/g, "[EMAIL]")
.replace(/\b\d{10,}\b/g, "[PHONE]")
.replace(/\b\d{3}-\d{2}-\d{4}\b/g, "[SSN]");
}Usage:
import Anthropic from "@anthropic-ai/sdk";
import { logAIDecision } from "./audit-logger.js";
const client = new Anthropic();
async function evaluateCandidate(application) {
const response = await client.messages.create({
model: "claude-sonnet-5-5", // model name as of October 2026; check the current one
max_tokens: 1000,
messages: [
{
role: "user",
content: `Evaluate this candidate: ${JSON.stringify(application)}`,
},
],
});
const aiRecommendation = response.content.map((b) => (b.type === "text" ? b.text : "")).join("");
// CRITICAL: human review for hiring decisions
const finalDecision = await humanReviewerApproves(aiRecommendation);
await logAIDecision({
userId: application.candidateId,
decisionType: "hiring_screening",
input: application,
aiOutput: aiRecommendation,
finalDecision,
humanReviewer: "[recruiter contact]",
factors: ["experience", "skills_match", "interview_score"],
});
return finalDecision;
}Step 4: A human-in-the-loop endpoint for appeals
// appeals-endpoint.js — an endpoint for a user to appeal an AI decision
import express from "express";
import { readFile } from "node:fs/promises";
const app = express();
app.use(express.json());
app.post("/api/ai-decision-appeal", async (req, res) => {
const { traceId, userId, reason } = req.body;
// 1. Find the original decision in the audit log
const auditLog = await readFile(
"./compliance/logs/audit-log.jsonl",
"utf-8"
);
const originalDecision = auditLog
.split("\n")
.filter(Boolean)
.map(JSON.parse)
.find((entry) => entry.trace_id === traceId);
if (!originalDecision) {
return res.status(404).json({ error: "Decision not found" });
}
// 2. Create an appeal ticket for human review
const appealId = crypto.randomUUID();
await appendFile(
"./compliance/logs/appeals.jsonl",
JSON.stringify({
ts: new Date().toISOString(),
appeal_id: appealId,
original_trace_id: traceId,
user_id_hash: hash(userId),
reason,
status: "pending_human_review",
sla_deadline: new Date(Date.now() + 30 * 24 * 60 * 60 * 1000), // 30 days GDPR
}) + "\n",
"utf-8"
);
// 3. Notify the compliance team
await notifyComplianceTeam(appealId);
res.json({
appeal_id: appealId,
status: "received",
sla: "30 days per GDPR",
next_steps:
"A human reviewer will examine your case and respond within 30 days.",
});
});
app.listen(3000);Step 5: An AI disclosure widget for the frontend
<!-- ai-disclosure.html — a simple widget for AI-generated content -->
<div class="ai-disclosure">
<span class="ai-badge">🤖 AI-Generated</span>
<details>
<summary>What does this mean?</summary>
<p>
This content was generated by an AI system (Claude by Anthropic).
We use AI to work faster, but a person does
the final review.
</p>
<p>
<strong>Your rights:</strong>
<a href="/privacy">Learn more</a> |
<a href="/ai-appeal">Appeal an AI decision</a>
</p>
</details>
</div>
<style>
.ai-disclosure {
background: #f0f9ff;
border-left: 3px solid #0284c7;
padding: 8px 12px;
font-size: 13px;
margin: 8px 0;
}
.ai-badge {
font-weight: 600;
color: #0c4a6e;
}
</style>Step 6: A quarterly compliance review
# Once a quarter: an internal audit
cat > compliance/quarterly-review.md <<'EOF'
# Quarterly Compliance Review — Q[X] 202[Y]
## Checklist
- [ ] Privacy policy is current (any regulatory changes?)
- [ ] Sub-processors list updated (new services added?)
- [ ] Audit log is complete (no gaps?)
- [ ] Appeals SLA met (all within 30 days?)
- [ ] DPA with Anthropic is current
- [ ] Bias metrics checked (if applicable)
- [ ] Incident log empty or incidents resolved
## Findings
- ...
## Action items
- ...
## Next review: [date]
EOFTools and resources
- EU AI Act official: the text of the law + a self-assessment tool
- GDPR full text: an overview + how it's applied
- NYC Bias Audit Law: requirements for hiring AI
- California AI laws: SB 53 + other state laws
- Anthropic Legal: terms of service, privacy policy, DPA
- Anthropic Acceptable Use Policy: what's not allowed
- 152-FZ Russia: Russia's data protection law (in Russian)
- Bradley AI Law Tracker: overviews of new AI laws by US state
- Stanford HAI Policy: an academic tracker of global AI policy
- Iubenda: a privacy policy generator with AI clauses
- Termly: an alternative generator
- Cookiebot: cookie consent with AI tracking disclosure
Key takeaways
Most SMBs don't need full EU AI Act compliance. If you're in the limited-risk zone (chatbots, content generation, recommendations), a compliance checklist of 8-10 items is enough: privacy policy + disclosure + audit log + a DPA with Anthropic. That's much cheaper than full compliance for high-risk systems.
High-risk decisions (hiring, credit, medicine) require a human in the loop by default. GDPR Article 22 and the Colorado AI Act (from January 1, 2027) require a way to appeal and human review, and the NYC bias audit law requires an independent bias audit for AI used in hiring. Architecturally, it's better to build this in from day 1 than to bolt it on after a regulator shows up.
Anthropic's terms are your baseline compliance. Using the Claude API gives you a solid level of data handling (by default no training on your data; see the current terms for retention). Sign a DPA, list Anthropic as a sub-processor in your privacy policy, and your basic compliance is in place.
You need a lawyer in at least 3 cases: a cease-and-desist letter, a launch in the EU with a large audience, a high-risk area. Everything else you can do yourself with templates from Iubenda/Termly. An SMB with a small audience doesn't need an expensive custom set of documents.
Checklist (✅)
Next lesson
→ Managing an army of agents: logs, oversight, ClickUp and CRM
The mark stays in this browser only and is never sent anywhere. My progress