As US and European laws tighten, organisations must implement robust AI controls that withstand legal scrutiny, moving beyond mere measurement to enforceable oversight amid increasing legal and regulatory scrutiny.
Enterprise AI governance is moving from theory to enforcement. As Trust Insights notes in its latest Data Diaries entry, discipline in measurement is no longer enough on its own; organisations now need controls that would stand up to a regulator, an auditor, or a court. That shift follows a year of rapid legislative change in the United States and Europe, which has made “wait for Washington” an increasingly poor operating assumption.
One of the biggest changes came when the US Senate blocked the proposed 10-year state moratorium on AI regulation on 1 July 2025. That decision left states free to legislate, and several have done so. California’s AB 2013 took effect on 1 January 2026, while SB 942’s operative date was pushed to 2 August 2026 after Governor Gavin Newsom signed AB 853 on 13 October 2025, according to the materials cited by Trust Insights. Texas’ TRAIGA has introduced penalties that can reach $200,000 for an uncurable violation and $2,000 to $40,000 for each continuing day of non-compliance. Illinois’ HB 3773 goes further in employment settings, treating AI-driven discrimination, including the use of zip-code proxies, as a civil-rights issue.
The EU AI Act adds another layer. According to Trust Insights, general-purpose AI obligations have applied since 2 August 2025, while the main fines regime begins on 2 August 2026. Penalties can rise to €35 million or 7% of global turnover for prohibited practices, €15 million or 3% for most breaches, and €7.5 million or 1% for misleading information. That is not a theoretical ceiling; it is now part of the compliance environment companies must design for.
The article argues that the central risk is the illusion of human oversight. Modern systems no longer merely generate text or recommendations; they increasingly classify risk, decide when to escalate, and shape which actions are visible to reviewers. If an agent can escalate on its own, if a human simply approves whatever it presents, and if the audit trail records only what the system chooses to log, then oversight becomes performative rather than real.
That warning is reinforced by litigation. Judge William Alsup gave preliminary approval on 25 September 2025 to the Bartz v. Anthropic settlement, which Trust Insights describes as worth roughly $1.5 billion across about 465,000 to 500,000 pirated works at $3,000 per book, with final approval coming on 14 May 2026. The broader point is operational as much as legal: unlicensed training data can become a direct balance-sheet problem, and contractual indemnities may determine whether the vendor or the buyer bears the cost.
Trust Insights’ practical advice is to govern AI agents as though they were junior staff. That means clear reporting lines, checkpoints, and named responsibility. For agencies, the article suggests offering ISO-aligned governance documentation as a service. For mid-market buyers, it recommends pushing requirements into procurement, including model cards, training-data provenance, structured logs, and audit rights. For enterprise teams, it calls for an AI council, a documented escalation route, a regulator-ready dossier, and a Chief AI Officer with budget authority and direct links to legal, security, and the business units deploying the systems.
The final recommendation is technical as well as organisational: keep structured logs in a database the agent updates in near real time, then review those records as you would the work of a junior employee. The article’s underlying message is blunt. Old governance problems have not disappeared; AI has only made them faster, larger, and harder to ignore.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





