# Understanding AI in a Month 28: What Rules Actually Apply?

Understanding AI in a Month — Day 28 · 2026-10-10

*Full transcript of the spoken edition. A quoted passage is its source read aloud — the source's own words, with numbers and initialisms spoken out — quoted for comment. Each one names its source, and the place in it, beneath it. Where the spoken reading differs from the source's own characters — an initialism spelled out, a number read aloud, punctuation that cannot be spoken — the source's text is printed beside it.*

---

On the second of August, Europe's AI law reached what the law itself calls its general date of application. Six days earlier, on the twenty-seventh of July, an amendment to that law had come into force. It moved the rules for AI used in high-risk areas, like hiring, credit scores and school admissions, from that August to December twenty twenty-seven. For AI that is part of, or is itself, a product already under EU safety law, like a toy or a medical device, the rules moved from August twenty twenty-seven to August twenty twenty-eight. So in one summer, two headlines were both true: Europe's AI rules now apply, and Europe has delayed its AI rules. Today: who decides what ships, and from what date.

The first wrong reading: Europe has put its AI law on hold. It hasn't. Bans on some uses, like social scoring, have applied since February twenty twenty-five. Duties on the makers of general-purpose models, the kind behind chatbots, have applied since August twenty twenty-five, and, as we heard on day seven, since this August the European Commission can fine those makers. A duty to mark AI-generated content, in a form machines can read, applies from August too, though systems already on sale have until December. And the same amendment that moved the high-risk dates added a new ban, applying from December. It covers AI built to make realistic sexual images, video or audio of real, identifiable people without their explicit consent, or child sexual abuse material, and AI that predictably makes it without reasonable safeguards.

The second wrong reading runs the other way: the whole AI Act now applies, and companies are already being punished under it. The law has been in force since the first of August twenty twenty-four. "In force" and "applies" differ, and some of the law doesn't apply until twenty twenty-eight. Nor does "applies" mean anyone has been penalised. The news agency AFP reported that on the first of September the Commission said it had sent requests for information to more than thirty companies in the AI sector: a first use of its new powers, and a preliminary step before a possible formal investigation. No fine has been reported that I could find.

Three ideas, which together answer one question: does this rule bind this product, here, today?

Start with dates. A law has several. It's adopted, published, enters into force, and then applies, sometimes in stages. Europe's data-protection law, the GDPR, entered into force in May twenty sixteen and applied from the twenty-fifth of May twenty eighteen. The AI Act's final article begins:

> This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union

> — *Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), Official Journal of the European Union L, 2024/1689, 12 July 2024, Article 113 'Entry into force and application', first paragraph*

Then: the law applies from the second of August twenty twenty-six, followed by "however" and a list of exceptions. In force means the law exists and its clock is running. Applies means its duties bind.

Why would those dates move? Much of the answer goes back to the seventh of May, nineteen eighty-five. That day, the European Community's Council of Ministers approved what it called a new approach to technical harmonisation and standards: in effect, a new way to write product law. Laws would set only the essential requirements a product must meet. Standards bodies would write the technical detail, and the resolution said:

> these technical specifications are not mandatory and maintain their status of voluntary standards

> — *Council of the European Communities, 'Council Resolution of 7 May 1985 on a new approach to technical harmonization and standards' (85/C 136/01), Official Journal of the European Communities C 136, 4 June 1985, Annex II, under the heading 'GUIDELINES FOR A NEW APPROACH TO TECHNICAL HARMONIZATION AND STANDARDS', the third of its four fundamental principles*

A product built to such a standard is presumed to meet the requirements. A maker can ignore the standard, but then has to prove another way that its product complies. The AI Act is built on that model, so its high-risk rules leaned on standards that weren't finished. The amendment gives its reasons, beginning with this:

> the delayed availability of standards, common specifications, and alternative guidance and the delayed establishment of national competent authorities lead to challenges that jeopardise the effective entry into application of those obligations

> — *Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 (Digital Omnibus on AI), Official Journal of the European Union L, 2026/1744, 24 July 2026, recital 40, second sentence*

It adds that keeping the old date would risk a significant increase in costs. A binding requirement met through a voluntary standard: that's the second idea, an obligation versus a framework. An obligation is a duty in law, with someone empowered to enforce it. The Commission can fine a general-purpose model maker that breaks its duties intentionally or negligently up to three per cent of its worldwide turnover, or fifteen million euros if that's higher. A framework is a document someone writes about how they'll behave. Between the two sits Europe's code of practice for those model makers, published in July twenty twenty-five, which the Commission calls

> a voluntary tool, prepared by independent experts in a multi-stakeholder process, designed to help industry comply with the AI Act’s obligations for providers of general-purpose AI models

> — *European Commission, Shaping Europe's digital future, 'The General-Purpose AI Code of Practice' (https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai), opening paragraph, read 10 October 2026*

Signing it is voluntary. The obligations are not.

The third idea is jurisdiction: whose rules reach you. The AI Act applies to providers that put AI on the European market,

> irrespective of whether those providers are established or located within the Union or in a third country

> — *Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal of the European Union L, 2024/1689, 12 July 2024, under the heading 'Article 2 Scope', paragraph 1, point (a)*

It follows the market, not the headquarters.

In November twenty twenty-five, the Commission proposed a simplification package, the Digital Omnibus. It wanted the high-risk dates tied to the Commission confirming that standards and other support were ready, with fallback deadlines. In March, Parliament voted to swap that for fixed dates, for, it said, predictability and legal certainty. A deal in May, votes in June, signature on the eighth of July, publication on the twenty-fourth, and entry into force three days later; its own text cites legal certainty, with the general date of application imminent. On the second of August, the AI Office inside the Commission took up its powers over general-purpose models: to request documents, evaluate models, order fixes and fine.

As I read it, what moved and what held follows the root. Until a harmonised standard exists, general-purpose model makers may rely on a code of practice to show they comply, though the amendment notes that a code, unlike a standard, gives no presumption of compliance. The high-risk rules' planned stand-ins are on the amendment's list of what was late. The model rules had a finished tool to comply with, and kept their date; the high-risk rules didn't, and moved by a year or more.

The United States shows a different posture. There's no federal statute like the AI Act; the main AI-specific rules have come from states. California's SB fifty-three, signed on the twenty-ninth of September twenty twenty-five, says a large frontier developer

> shall write, implement, comply with, and clearly and conspicuously publish on its internet website a frontier AI framework

> — *California Senate Bill 53, Transparency in Frontier Artificial Intelligence Act, Chapter 138, Statutes of 2025 (approved by the Governor 29 September 2025), section 2, adding Business and Professions Code section 22757.12, subdivision (a)*

At a summit in Seoul in May twenty twenty-four, companies including OpenAI, Google and Meta had made voluntary commitments, among them publishing a safety framework. California made that a duty. The company still writes its framework and may change it, publishing any material change with a justification within thirty days; failing to comply with its own framework can cost up to a million dollars a violation, in a case only the Attorney General can bring.

On the eleventh of December twenty twenty-five, the President signed an executive order telling the Attorney General to set up an AI Litigation Task Force,

> whose sole responsibility shall be to challenge State AI laws inconsistent with the policy set forth in section two of this order

> — *Executive Order 14365, 'Ensuring a National Policy Framework for Artificial Intelligence', signed 11 December 2025, Federal Register 90 FR 58499, published 16 December 2025, section 3 'AI Litigation Task Force'*

> As printed in the source: “whose sole responsibility shall be to challenge State AI laws inconsistent with the policy set forth in section 2 of this order”

The same order ties some broadband money to whether states keep laws it calls onerous. It asks one federal regulator to consider a national disclosure rule that would override state laws, and another to explain when federal law already overrides state laws that make AI alter truthful answers. And it asks for a legislative proposal: one federal framework overriding conflicting state AI laws. As I read it, that shows where the power sits. The order can send lawyers to court, attach conditions to federal money, and ask agencies and Congress to act. It can't strike down a state statute by itself. Separately, in April, the Justice Department joined, on equal-protection grounds, a lawsuit xAI had brought against Colorado's AI law. Colorado, which had already postponed that law once, agreed to a court order barring enforcement, of it or any replacement passed that session, for anything done up to two weeks after the judge rules on xAI's request to block it; in May it replaced the law with one whose duties start in January.

Put side by side: in Europe, Parliament and the member governments bind a market of twenty-seven countries with one law, then move its dates when the machinery isn't ready. In the United States, states write the rules, and the federal government has set out to challenge them in court and with money, while proposing a national law.

One. The second of December, when Europe's new ban applies and AI generators already on sale must mark their output. Watch for a first enforcement step under either.

Two. The first of January, when New York's RAISE Act, rewritten in March around California's framework duty, takes effect, along with Colorado's replacement law. Watch whether the largest developers publish frameworks under New York's.

Three. Before December twenty twenty-seven, watch the EU's Official Journal for harmonised standards for high-risk AI. If they appear, products built to them are presumed to meet the requirements they cover; if not, watch whether the date moves again.

The idea to keep: a rule binds a product only when three things line up. A duty, not just a promise. A reach that covers where the product is sold. And a date that has actually arrived. So ask three things of any new AI rule. Who stands behind it: a law with an enforcer, or only the company's word? Whose market does it reach? And which date is this: in force, applies, or enforced? To read more: Article one hundred and thirteen of the AI Act, and the Commission's Blue Guide to EU product rules. Tomorrow: not every AI is a chatbot.

---

## Sources (25)

- Regulation (EU) 2016/679 (General Data Protection Regulation), Article 99 — Official Journal 4 May 2016
- European Commission, *The "Blue Guide" on the implementation of EU product rules 2022*, Commission notice 2022/C 247/01, Official Journal C 247, section 1.1 — 29 June 2022
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), recital 9; Articles 2, 4, 5, 6, 40, 41, 50, 53, 56, 99, 101, 111 and 113 — signed 13 June 2024; Official Journal 12 July 2024
- European Commission, *The General-Purpose AI Code of Practice* (page and signatory list) — code published 10 July 2025; read 10 October 2026
- California Senate Bill 53, *Transparency in Frontier Artificial Intelligence Act*, Chapter 138, Statutes of 2025, sections 22757.12 and 22757.15 of the Business and Professions Code as added — approved 29 September 2025
- Office of the Governor of California, *Governor Newsom signs SB 53* — 29 September 2025
- Executive Order 14365, *Ensuring a National Policy Framework for Artificial Intelligence*, 90 FR 58499, sections 3 to 8 — signed 11 December 2025; published 16 December 2025
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), recitals 38, 40, 41 and 46, Articles 1 and 4 — signed 8 July 2026; Official Journal 24 July 2026
- European Commission, *Regulatory framework for AI* (AI Act policy page) — read 10 October 2026
- Anthropic, *Responsible Scaling Policy* page (version history) — last updated 14 August 2026; read 10 October 2026
- Council Resolution of 7 May 1985 on a new approach to technical harmonization and standards (85/C 136/01), Official Journal C 136, Annex II — 7 May 1985; published 4 June 1985
- European Commission, proposal COM(2025) 836 (Digital Omnibus on AI), draft Article 113(d) — 19 November 2025
- European Parliament, press release 20260323IPR38829, *Artificial Intelligence Act: delayed application, ban on nudifier apps* — 26 March 2026
- White House, fact sheet on voluntary AI commitments — 21 July 2023
- UK Government, *Frontier AI Safety Commitments, AI Seoul Summit 2024* — May 2024
- Office of the Governor of New York, RAISE Act signing release; New York Senate bill S8828 (Chapter 96 of 2026), section 3 — 19 December 2025; 27 March 2026
- *X.AI LLC v. Weiser*, No. 1:26-cv-01515 (D. Colo.), docket and orders of 24 and 27 April 2026 — filed 9 April 2026; read 10 October 2026
- Colorado General Assembly, SB 26-189 *Automated Decision-Making Technology*, bill page — signed 14 May 2026
- Google DeepMind, *Strengthening our Frontier Safety Framework* — 22 September 2025, updated 17 April 2026
- AFP, *EU questions dozens of companies using new AI powers* (via The Star) — 2 September 2026
- To Vima, *EU Delays ‘High Risk’ AI Rules to 2027 After Tech Pushback*; Help Net Security, *EU begins enforcing AI Act, putting AI models under the microscope* — 19 November 2025; 4 August 2026
- GovTrack, H.R. 5388 status page — read 10 October 2026
- European Commission, press release *Commission starts enforcing AI Act rules and new transparency requirements on 2 August* — 31 July 2026
- The White House, *President Donald J. Trump Unveils National AI Legislative Framework* — 20 March 2026
- Colorado General Assembly, SB 25B-004, bill page — approved 28 August 2025

Understanding Machine, an Ashita Orbis publication. The written edition of this episode, with its figures and its sources, is published beside it.
