No blockbuster FDA action landed this cycle, but the regulatory ground kept moving underneath regulated operators. State and federal AI proposals multiplied in the US, several governments abroad advanced governance bills, and the practitioner conversation turned toward how you actually prove an AI system works. Here is what changed and what to do about it.
US state and federal AI law keeps fragmenting
A new federal proposal, the AI AGENT Act, aims to extend consumer-protection rules to AI agents acting on people’s behalf. According to Davis Wright Tremaine, the bill would treat agentic systems through a consumer-protection lens rather than a sector-specific one.
Why it matters: If you deploy agents that transact or make decisions for users, expect disclosure and accountability obligations regardless of your industry. Build the audit trail now so an agent’s actions are traceable to a validated decision path, not a black box.
At the state level, Illinois Governor Pritzker signed a package of laws that includes new AI regulations, per the Breeze Courier. Separately, The American Bazaar reports New York moved to block new large AI data centers, a first among US states.
Why it matters: The patchwork is real. Multistate operators need a compliance baseline that maps to the strictest applicable rule, and infrastructure teams should factor siting restrictions into capacity planning.
POLITICO also reported on Anthropic’s push to shape AI rules state by state, a sign that vendor influence on the regulatory map is only intensifying.
Why it matters: When your suppliers are helping write the rules, read their model documentation with extra skepticism. Vendor claims are a starting point for your own AI validation, not a substitute for it.
Governance and validation practice gets concrete
The more useful signal this cycle came from practice, not politics. Applause published a guide on running AI evaluations, covering how to structure test sets and build defensible confidence in model behavior.
Why it matters: Evals are becoming the evidence layer regulators and auditors will ask for. Treat them like a validation protocol: predefined acceptance criteria, documented datasets, and results you can reproduce, not a one-time demo.
On the enforcement side of that same idea, TechTarget covered “governance as code” for controlling AI agent risk, embedding policy checks directly into the systems that run agents.
Why it matters: Policy that lives in a PDF does not stop a misbehaving agent. Encoding controls where the work happens is the difference between validated and merely documented, and it produces the machine-readable evidence audits increasingly expect.
Meanwhile, Resultsense reported that DeepMind’s Demis Hassabis called for a US-led AI standards body.
Why it matters: A credible standards body would give operators a common yardstick, but until one exists, frameworks like the NIST AI RMF remain your best anchor for defensible governance.
Global governance moves worth tracking
Several jurisdictions advanced governance regimes. Hogan Lovells, via JD Supra, reports Malaysia opened consultation on an AI Governance Bill, while Proactive Investors notes Australia is standing up a central AI office. In the Philippines, the Daily Tribune reports a House panel advanced an AI bill weighing innovation against tighter controls.
Why it matters: For anyone operating or selling across borders, the direction is consistent even as the details differ: documented risk classification, human oversight, and evidence of testing. Global manufacturers should align quality and reliability programs to the common core rather than chasing each statute separately.
The throughline this cycle: rules are multiplying, but the demand underneath all of them is the same, proof that your AI does what you claim.
See how we validate AI systems →
Until the next cycle,
The Third Penguin