Library · Launch: payments, secrets, rules, logs

AI regulation & compliance 2026: the EU AI Act, GDPR, Anthropic's terms, and what small businesses should watch for

Builder45 minUpdated: October 2026
86 of 105 in the library

Module: 13. Professional practice | Time: about 25 min reading + 20 min practice


The gist

AI regulation in 2026 is a real maze. The EU AI Act is coming into force in stages, US executive orders get issued and then revoked, GDPR applies to AI with extra requirements, and state-level laws have appeared in the US. If you make money with AI or handle users' data, you need to know the basics so you don't run into a fine or a lawsuit.

This lesson is a practical map of the 5 main jurisdictions and 9 risk areas. No legal jargon, with a step-by-step compliance checklist for small and mid-sized businesses (SMBs).

This is not legal advice. Laws change fast: the dates and provisions below are as of October 2026, based on public sources and lawyers' summaries. Before launching a product, check them against the official texts and, where needed, with a lawyer.

🎨 Picture this: AI regulation is like road signs. Most of the rules are obvious (red = stop; don't deceive the user). Some are strange (for example, in the EU you can't make certain automated decisions without human review). And every country has its own signs. This lesson is your road map, so you don't get a ticket on a sharp turn.


🎯 Decision tree: which laws apply to you

The key question isn't "how do I comply with everything" but "what actually applies to my AI product."

The EU AI Act + GDPR apply if:

  • ✓ You have users in the EU (even if you're based in the US or Latin America)
  • ✓ Your product is accessible from the EU without blocking
  • ✓ You process data of people in the EU

California / NYC / Colorado state laws apply if:

  • ✓ Your product is available in those states
  • ✓ You hire people in NYC using AI tools
  • ✓ You make AI-driven decisions in Colorado (insurance, credit, hiring)

Data localization laws in other countries apply if:

  • ✓ You process data of citizens of a country that requires it (Russia's Federal Law 152-FZ is one example)
  • ✓ The law requires that data to be stored on servers inside that country

Anthropic's terms always apply if you use the Claude API / claude.ai.

🎨 Picture this: traffic rules. On a California highway, California rules apply plus federal rules plus your basic ones (Anthropic's terms are like the driver's handbook for AI). If you drive through several states, check each one.


Key concepts

  • EU AI Act: direct regulation of AI systems in the European Union, by risk level
  • GDPR: the EU's General Data Protection Regulation; it applies to AI through Article 22 (automated decisions) and the right to explanation
  • High-risk AI: a category in the EU AI Act that includes medicine, hiring, credit, education and infrastructure
  • Conformity assessment: a mandatory audit for high-risk AI before deploying it in the EU
  • Right to explanation: the user's right to get an explanation of an AI decision
  • Human-in-the-loop: required human involvement in automated decisions
  • DPA (Data Processing Agreement): a contract with a sub-processor (Anthropic, OpenAI) about how data is handled
  • Sub-processor: a third party that processes data on your behalf
  • Bias audit: checking an AI system for discrimination (mandatory in NYC for AI used in hiring; for other states' requirements, see below)
  • Acceptable Use Policy (AUP): a vendor's list of prohibited uses of its AI

Theory

The EU AI Act: the main regulator of 2026

The EU AI Act took effect in August 2024 and applies in stages: the bans since February 2025, the rules for general-purpose models since August 2025, and the transparency requirements (Article 50) since August 2, 2026. The EU postponed the requirements for high-risk systems (the Digital Omnibus package, in force since July 27, 2026): for systems in Annex III the deadline moved to December 2, 2027, and for systems in Annex I to August 2, 2028. This is direct regulation of AI systems, classified by risk level.

It applies to: any AI system that operates in the EU or serves EU users. Even if you're based elsewhere, if your product is available to an EU user, the act covers you.

4 risk levels:

Risk level Examples What's required
Unacceptable (banned) Social scoring (as in China), manipulating children, real-time biometric mass surveillance Banned outright
High risk Medicine, diagnostics, hiring, lending, education, law enforcement, critical infrastructure Conformity assessment + registration
Limited risk Chatbots, deepfakes, emotion recognition Disclosure: "you're talking to an AI"
Minimal risk Spam filters, game recommendations, basic machine translation No requirements

What you need if you're high risk:

  • A conformity assessment (an audit before deployment), which is a separate, expensive procedure
  • A documented risk management system
  • Data governance + bias testing
  • Built-in human oversight
  • Documentation kept for 10+ years
  • Registration in the EU AI database
  • CE marking on the product

Fines: up to €35M or 7% of global revenue (whichever is higher) for banned practices, and up to €15M or 3% for violating the requirements for high-risk systems. For a small business, a fine like that is devastating.

🎨 Picture this: the EU AI Act is like vehicle certification. A city bike (low risk) needs nothing. A scooter (limited) needs lights and a license plate. A truck carrying hazardous cargo (high risk) needs full certification, logbooks and inspections. Most SMB products are limited risk.

Source: https://artificialintelligenceact.eu/ (check the deadlines and changes against official EU publications)


GDPR + AI: an old law with new teeth

GDPR has been in force since 2018, but AI-specific guidance appeared in 2023-2025. It applies to all personal data of people in the EU: names, emails, IP addresses, behavioral data, biometrics.

What matters for someone building with AI:

Article 22: Automated decision-making:

A user has the right not to be subject to decisions made solely by AI, without human review, if those decisions have legal or similarly significant effects.

It applies when:

  • AI screens job candidates → you need a human review path
  • AI denies credit → there must be a way to appeal
  • AI sets insurance terms → you need an explanation + an appeal

Right to explanation: A user can ask for an explanation of "why the AI decided X about me." That means:

  • Log the key factors behind the AI's decision
  • Prepare an "understandable" explanation (not a black box)
  • Have a process for answering the request (30 days under GDPR)

Data minimization: Don't collect more data than the AI task needs. If viewing history is enough to recommend movies, don't ask for location.

A lawful basis for training data: You need one of:

  • Consent (explicit agreement): the cleanest
  • Contract: the data is needed to perform a contract
  • Legitimate interest: a balancing test (risky for training data)

Fines: up to €20M or 4% of global revenue (whichever is higher).

Source: https://gdpr.eu/


The US: federal rules weakened, state rules grew

The main story of 2025-2026: federal AI regulation weakened, but state-level regulation grew significantly. The relationship between federal and state rules is still contested, so check the current state of things.

Federal status:

  • Biden's Executive Order 14110 (2023) was revoked by Trump in January 2025
  • Voluntary safety-testing commitments by the big AI companies (Anthropic, OpenAI, Google) remain
  • The FTC (Federal Trade Commission) kept its authority over deceptive AI claims and unfair practices

State level (more important for SMBs):

State Law What it requires
California (SB 53) Transparency in Frontier AI Act Transparency for developers of the largest (frontier) models: publishing safety frameworks, incident reports. It doesn't apply directly to small products
Colorado AI Act (2024) High-impact AI consumer protection Anti-discrimination rules for high-impact decisions (hiring, credit, insurance, education). Its effective date was pushed to January 1, 2027 and the law was narrowed (May 2026 amendments); keep an eye on changes
New York City Local Law 144 Automated Employment Decision Tools A bias audit is mandatory if you use AI for hiring in NYC
Illinois BIPA Biometric Information Privacy Act Consent for biometric data, with statutory damages for violations
Texas (HB 2060) AI Advisory Council An inventory of state government AI use, the start of regulation

FTC enforcement (examples from 2023-2025):

  • Rite Aid (2023): banned from using facial recognition for several years because of false matches
  • Cases against companies over "deceptive AI capabilities" claims (the Operation AI Comply sweep, 2024)
  • Orders to delete models trained on data collected without consent

Sources:


China: strict regulation with a different philosophy

It applies to AI services available in China or aimed at Chinese users.

Key rules:

  • Generative AI Measures (2023+): AI services must pass a security review by the CAC (Cyberspace Administration of China) before a public launch
  • Deep Synthesis Provisions: all deepfakes / AI-generated media must be labeled
  • Algorithmic Recommendations Provisions: transparency about recommendation algorithms
  • Data localization: Chinese users' data stays on servers in China

In practice, for a builder outside China:

  • If you're not targeting the Chinese market, it's usually not relevant
  • If you're launching a product in China, you need a Chinese partner + CAC approval

Source: the Cyberspace Administration of China (for English summaries, see the Stanford HAI policy tracker)


Russia and other countries without AI-specific laws

Status as of October 2026: during the review we couldn't confirm a separate AI law in Russia, so check the current situation. General laws apply there:

  • Federal Law 152-FZ "On Personal Data": Russia's rough equivalent of GDPR
    • Data localization (the initial processing of Russian citizens' data must happen on servers in Russia)
    • Consent to processing
    • The right to deletion
  • Federal Law 149-FZ "On Information": general requirements for information systems
  • Discussed in 2025-2026: laws on AI labeling and deepfakes; check whether they've been passed

In practice: if you work with users from Russia, follow 152-FZ. If your users are in other countries, it's usually not relevant. The same logic holds for any country: find out whether it has data localization or personal data rules before you take on its users.

Source: http://www.consultant.ru/document/cons_doc_LAW_61801/ (in Russian)


Latin America: each country has its own data protection law

The names, numbers and status of these laws were checked against official sources in October 2026. Laws change: check them again before you launch.

Country Law Status
Brazil LGPD, Law No. 13,709/2018 (in force since September 18, 2020) + the AI bill PL 2338/2023: passed by the Senate, under review in the Chamber of Deputies as of October 2026 General data protection law; the EU recognized its level of protection as adequate (2026)
Mexico LFPDPPP: a new federal law from 2025 (it replaced the 2010 law) General data protection law
Ecuador LOPDP, the Organic Law on Personal Data Protection (since 2021) General data protection law
Colombia Statutory Law 1581 of 2012 General data protection law
Argentina Law 25,326 on personal data protection (2000) General data protection law; the EU recognized its level of protection as adequate (2003)

In practice: if you're GDPR-compliant, that's a good base, but each country has its own law and its own regulator: check your obligations under the local law, especially if you work with health data.


Anthropic's terms of service: what you have to follow

If you use the Claude API or claude.ai, this is your baseline compliance.

Acceptable Use Policy (prohibited):

  • Weapons (chemical, biological, nuclear, conventional)
  • CSAM (child sexual abuse material) and exploitation
  • Election manipulation / political disinformation
  • Attacks on critical infrastructure
  • Mass surveillance without consent
  • Generating malware
  • Academic fraud (paid-for theses)

Data handling (important for compliance):

Tier Training on your data? Retention
claude.ai Free / Pro / Max Only if the "help improve Claude" setting is on (claude.ai/settings/data-privacy-controls) Up to 5 years with consent, 30 days without it
Team / Enterprise No (default) Configurable
API (default) No (default) See Anthropic's current terms
API + Zero Data Retention No By agreement (for enterprise)

Terms change: before launching a product, check them on Anthropic's website and on the What's current page.

Commercial use: allowed. The output is yours, with restrictions (check the list against Anthropic's current terms):

  • You can't resell direct API access "as is" (you need a value-add layer)
  • You can't claim a human wrote the output where disclosure is required
  • You can't use it for spam / disinformation

Sources:


9 risk areas where SMBs actually get into trouble

# Risk Severity What to do
1 Personal data in prompts without consent HIGH Pseudonymize / get consent / sign a DPA
2 Automated decisions that affect users HIGH Add a human review path (Article 22)
3 Medical/legal/financial advice without a disclaimer HIGH A mandatory disclaimer + a path to a specialist
4 Hiring decisions with AI bias HIGH A bias audit (mandatory in NYC) + human approval
5 Children's data without parental consent HIGH COPPA (US, kids under 13) / GDPR-K compliance
6 Deepfakes without labeling MEDIUM-HIGH Watermark + disclosure are mandatory
7 Cross-border data transfer EU→US MEDIUM SCCs (Standard Contractual Clauses) or the EU-US Data Privacy Framework
8 AI-generated content without disclosure LOW-MEDIUM A "Generated by AI" badge where required
9 Training data without IP rights MEDIUM Use only legitimate sources (for the base model, Anthropic has already taken care of this for you)

🎨 Picture this: the 9 risk areas are like 9 kinds of car accidents. Most are minor (a scratch, insurance covers it). Some are serious (#1, #2, #4 are head-on collisions). Know where the dangerous curves are and don't take them at speed.


A compliance checklist for SMBs (the minimum)

If you're an SMB founder using AI in your product:

This checklist covers the main risks for a small product. Full EU AI Act compliance for high-risk systems is a separate big project with lawyers.


When you need a lawyer (3 trigger points)

You need a lawyer right away:

  • You got a cease-and-desist letter: immediately
  • A regulator sent an inquiry (the ICO in the UK, CNIL in France, the FTC in the US)
  • A customer filed a lawsuit with an AI-related claim

You definitely need a lawyer before launch:

  • AI in the EU/UK with more than 1,000 users
  • A high-risk area: medicine (FDA approval), credit (CFPB), hiring (EEOC)
  • A B2B contract with an enterprise client (they'll require a DPA and a security review)

Low-risk SMB: you can do it yourself with templates:

  • Content generation without personal data
  • AI-powered recommendations inside your own app
  • Internal tools for your team
  • Educational content

🎨 Picture this: a lawyer is like a mechanic. You do the regular oil change (updating your privacy policy) yourself. A major engine overhaul (EU AI Act conformity) goes to a specialist. A crash (a cease-and-desist) means a tow truck and straight to a lawyer.


Ready-made templates (as of October 2026; check the terms on the websites)

  • Anthropic DPA: request it through https://www.anthropic.com/legal (automatic for business accounts)
  • An AI clause for your terms of service: templates from Termly, Iubenda
  • AI privacy policy generators: Iubenda, Termly, PrivacyPolicies.com (paid plans; terms on their websites)
  • EU AI Act self-assessment tool: https://artificialintelligenceact.eu/assessment/
  • Cookie consent for AI tracking: Cookiebot, OneTrust (see their websites for free tiers and terms)

Audience levels: what you personally need

Beginner (personal use, fewer than 100 users):

  • A privacy policy with AI disclosure (a template from a generator)
  • Basic disclaimers
  • You DON'T need a lawyer

Intermediate (an SMB with up to 1,000 customers):

  • The full compliance checklist (the 8/8 items above)
  • A DPA with Anthropic / OpenAI
  • An AI clause in your terms of service
  • A professional privacy policy (a legally reviewed template)
  • Most likely you DON'T need a lawyer, but a one-time review is useful

Professional (1,000+ users or a high-risk area):

  • A full legal review
  • An EU AI Act conformity assessment if applicable
  • An annual bias audit
  • AI liability insurance
  • Risk documentation

The hidden cost of compliance

Amounts depend on the country, the lawyer and the size of the product, so there are no specific figures here: get quotes from lawyers and services. The relative order of costs:

Item Relative cost Frequency
Lawyer review (initial) Medium One-time
Lawyer updates Depends on hours As needed
Bias audit (required in NYC) Medium-high Annual
EU AI Act conformity (high-risk) High Initial + annual update
Documentation maintenance A few hours, regularly Ongoing
AI liability insurance (SMB) Low-medium Annual
Privacy policy generator Low Annual
DPA management tool Zero to low Ongoing

For an SMB, baseline costs are usually much lower than for a high-risk product: the main first-year expenses are a legal review and document templates.


Practice

Step 1: A self-assessment of your AI product

bash
mkdir -p compliance && cd compliance
touch ai-risk-assessment.md

Fill in ai-risk-assessment.md:

markdown
# AI Risk Assessment — [Project name]

## 1. What data do I process?
- [ ] Personal data of people in the EU → GDPR + EU AI Act apply
- [ ] Personal data of US residents → State laws (check CA, NY, CO)
- [ ] Personal data of citizens of countries with localization laws (e.g. Russia, 152-FZ)
- [ ] Health data → HIPAA (US), special category (EU)
- [ ] Children's data (<13 US, <16 EU) → COPPA, GDPR-K
- [ ] Biometric → BIPA (Illinois), special category EU
- [ ] Financial → CFPB (US), PSD2 (EU)

## 2. What AI decisions does my product make?
- [ ] Content generation (usually low risk)
- [ ] Recommendations (limited risk)
- [ ] Automated decisions affecting users (HIGH RISK)
- [ ] Hiring / HR (HIGH RISK + NYC bias audit)
- [ ] Medicine / diagnostics (HIGH RISK + FDA in the US)
- [ ] Credit / finance (HIGH RISK + CFPB)
- [ ] Education (HIGH RISK in the EU)

## 3. Are there EU users?
- [ ] Yes → GDPR + EU AI Act apply
- [ ] No → skip the EU section

## 4. Where is the data stored?
- Server location: __________
- Cross-border transfer: __________
- Sub-processors: Anthropic, OpenAI, __________

Step 2: Create the compliance documents

bash
# Folder structure
mkdir -p compliance/{policies,agreements,audits,logs}

At least 4 files:

bash
# 1. Privacy policy with AI disclosure
touch compliance/policies/privacy-policy.md

# 2. Terms of service with an AI clause
touch compliance/policies/terms-of-service.md

# 3. Sub-processor list (Anthropic, OpenAI, hosting)
touch compliance/policies/sub-processors.md

# 4. Internal audit log
touch compliance/logs/audit-log.jsonl

A minimal privacy-policy.md template:

Type this into the chat
# Privacy Policy

**Last updated:** 2026-XX-XX

## What data we collect
- Email (at sign-up)
- Usage data (how you use the app)
- Content you submit to AI features

## How AI processes your data
We use Anthropic Claude API to power our AI features.
- Your data is sent to Anthropic for processing
- By default, Anthropic does not train on API data (check the current API terms before publishing)
- Data retention at Anthropic: see the current Anthropic terms (a zero-retention agreement is possible for some customers)
- Full Anthropic policy: https://www.anthropic.com/legal/privacy

## Your rights (GDPR/CCPA)
- Right to access your data
- Right to delete your data
- Right to object to automated decisions (Article 22 GDPR)
- Right to explanation of AI decisions
- Contact: [privacy contact your domain]

## Sub-processors
- Anthropic PBC (AI processing) — https://www.anthropic.com/legal
- [Your hosting provider]
- [Other sub-processors]

## Data retention
- Active accounts: while account active
- Deleted accounts: 30 days for technical recovery, then purged
- Backups: 90 days

Step 3: Create an AI decision audit log

Required for high-risk decisions (hiring, credit, medicine). Useful for low-risk ones.

javascript
// audit-logger.js — a simple logger for AI decisions
import { appendFile } from "node:fs/promises";

export async function logAIDecision({
  userId,
  decisionType,
  input,
  aiOutput,
  finalDecision,
  humanReviewer = null,
  factors = [],
}) {
  const entry = {
    ts: new Date().toISOString(),
    user_id_hash: hash(userId), // NOT the raw user ID
    decision_type: decisionType,
    input_summary: redactPII(input),
    ai_output: aiOutput,
    final_decision: finalDecision,
    human_reviewer: humanReviewer,
    factors,
    trace_id: crypto.randomUUID(),
  };

  await appendFile(
    "./compliance/logs/audit-log.jsonl",
    JSON.stringify(entry) + "\n",
    "utf-8"
  );

  return entry.trace_id;
}

function hash(value) {
  return crypto
    .createHash("sha256")
    .update(String(value))
    .digest("hex")
    .slice(0, 16);
}

function redactPII(text) {
  return text
    .replace(/[\w.-]+ AT [\w.-]+ DOT \w+/g, "[EMAIL]")
    .replace(/\b\d{10,}\b/g, "[PHONE]")
    .replace(/\b\d{3}-\d{2}-\d{4}\b/g, "[SSN]");
}

Usage:

javascript
import Anthropic from "@anthropic-ai/sdk";
import { logAIDecision } from "./audit-logger.js";

const client = new Anthropic();

async function evaluateCandidate(application) {
  const response = await client.messages.create({
    model: "claude-sonnet-5-5", // model name as of October 2026; check the current one
    max_tokens: 1000,
    messages: [
      {
        role: "user",
        content: `Evaluate this candidate: ${JSON.stringify(application)}`,
      },
    ],
  });

  const aiRecommendation = response.content.map((b) => (b.type === "text" ? b.text : "")).join("");

  // CRITICAL: human review for hiring decisions
  const finalDecision = await humanReviewerApproves(aiRecommendation);

  await logAIDecision({
    userId: application.candidateId,
    decisionType: "hiring_screening",
    input: application,
    aiOutput: aiRecommendation,
    finalDecision,
    humanReviewer: "[recruiter contact]",
    factors: ["experience", "skills_match", "interview_score"],
  });

  return finalDecision;
}

Step 4: A human-in-the-loop endpoint for appeals

javascript
// appeals-endpoint.js — an endpoint for a user to appeal an AI decision
import express from "express";
import { readFile } from "node:fs/promises";

const app = express();
app.use(express.json());

app.post("/api/ai-decision-appeal", async (req, res) => {
  const { traceId, userId, reason } = req.body;

  // 1. Find the original decision in the audit log
  const auditLog = await readFile(
    "./compliance/logs/audit-log.jsonl",
    "utf-8"
  );
  const originalDecision = auditLog
    .split("\n")
    .filter(Boolean)
    .map(JSON.parse)
    .find((entry) => entry.trace_id === traceId);

  if (!originalDecision) {
    return res.status(404).json({ error: "Decision not found" });
  }

  // 2. Create an appeal ticket for human review
  const appealId = crypto.randomUUID();
  await appendFile(
    "./compliance/logs/appeals.jsonl",
    JSON.stringify({
      ts: new Date().toISOString(),
      appeal_id: appealId,
      original_trace_id: traceId,
      user_id_hash: hash(userId),
      reason,
      status: "pending_human_review",
      sla_deadline: new Date(Date.now() + 30 * 24 * 60 * 60 * 1000), // 30 days GDPR
    }) + "\n",
    "utf-8"
  );

  // 3. Notify the compliance team
  await notifyComplianceTeam(appealId);

  res.json({
    appeal_id: appealId,
    status: "received",
    sla: "30 days per GDPR",
    next_steps:
      "A human reviewer will examine your case and respond within 30 days.",
  });
});

app.listen(3000);

Step 5: An AI disclosure widget for the frontend

html
<!-- ai-disclosure.html — a simple widget for AI-generated content -->
<div class="ai-disclosure">
  <span class="ai-badge">🤖 AI-Generated</span>
  <details>
    <summary>What does this mean?</summary>
    <p>
      This content was generated by an AI system (Claude by Anthropic).
      We use AI to work faster, but a person does
      the final review.
    </p>
    <p>
      <strong>Your rights:</strong>
      <a href="/privacy">Learn more</a> |
      <a href="/ai-appeal">Appeal an AI decision</a>
    </p>
  </details>
</div>

<style>
  .ai-disclosure {
    background: #f0f9ff;
    border-left: 3px solid #0284c7;
    padding: 8px 12px;
    font-size: 13px;
    margin: 8px 0;
  }
  .ai-badge {
    font-weight: 600;
    color: #0c4a6e;
  }
</style>

Step 6: A quarterly compliance review

bash
# Once a quarter: an internal audit
cat > compliance/quarterly-review.md <<'EOF'
# Quarterly Compliance Review — Q[X] 202[Y]

## Checklist
- [ ] Privacy policy is current (any regulatory changes?)
- [ ] Sub-processors list updated (new services added?)
- [ ] Audit log is complete (no gaps?)
- [ ] Appeals SLA met (all within 30 days?)
- [ ] DPA with Anthropic is current
- [ ] Bias metrics checked (if applicable)
- [ ] Incident log empty or incidents resolved

## Findings
- ...

## Action items
- ...

## Next review: [date]
EOF

Tools and resources


Key takeaways

Most SMBs don't need full EU AI Act compliance. If you're in the limited-risk zone (chatbots, content generation, recommendations), a compliance checklist of 8-10 items is enough: privacy policy + disclosure + audit log + a DPA with Anthropic. That's much cheaper than full compliance for high-risk systems.

High-risk decisions (hiring, credit, medicine) require a human in the loop by default. GDPR Article 22 and the Colorado AI Act (from January 1, 2027) require a way to appeal and human review, and the NYC bias audit law requires an independent bias audit for AI used in hiring. Architecturally, it's better to build this in from day 1 than to bolt it on after a regulator shows up.

Anthropic's terms are your baseline compliance. Using the Claude API gives you a solid level of data handling (by default no training on your data; see the current terms for retention). Sign a DPA, list Anthropic as a sub-processor in your privacy policy, and your basic compliance is in place.

You need a lawyer in at least 3 cases: a cease-and-desist letter, a launch in the EU with a large audience, a high-risk area. Everything else you can do yourself with templates from Iubenda/Termly. An SMB with a small audience doesn't need an expensive custom set of documents.


Checklist (✅)


Next lesson

→ Managing an army of agents: logs, oversight, ClickUp and CRM

The mark stays in this browser only and is never sent anywhere. My progress