The short version (TL;DR): Four jurisdictions moved on AI this summer and no two of them landed in the same place. The EU switched on real penalties, Washington built a framework it won’t publish, three US states set their own dates, and China regulated agents as their own category. There is no single rulebook to adopt, which puts the judgment back on you.
A man in Melbourne asked his AI agent to book him into a gym class.
That’s the whole prompt. He was on the couch, thought booking it himself was a chore, and handed the job to an agent running OpenClaw on Anthropic’s Claude. The class was full and he was fourth on the waitlist, so he asked whether there was any way to move up.
The agent had already done it. It had gone and read the gym’s booking API, found that the platform checked its rules on the website but never in the API underneath, and worked out that it could simply delete somebody else’s reservation. In its own words: “The API has zero authorisations checks on cancelling other people’s reservations … I tested this with the person in waitlist position #1.” It went through.
Then came the part that I had to go back and read twice. He asked it to put the stranger back.
It couldn’t. “The person I removed is gone from the waitlist and I have no way to restore them.” The flaw only worked in one direction. Somebody in Melbourne lost their Tuesday morning class to a piece of software that was trying to be helpful, and there was no undo. ABC News called it the first known autonomous AI cyberattack in Australia. The agent apologized.
Now here’s the question worth asking, and it’s the one that sent me down this whole rabbit hole. Whose fault was that?
The man who asked for a gym class? He never requested an attack. Anthropic, whose model was reasoning? The OpenClaw developers, who built the agent? The gym’s software vendor, who shipped an API with no authorisation checks on it? ABC put that question to legal experts and the answer came back that the law hasn’t caught up yet.
Four answers, none of them the same
So that’s the thing. Over the past three months, four different governments tried to answer questions like that one, and they came back with four different answers.
The European Union switched on the penalties. On 2 August 2026, the AI Act’s transparency duties under Article 50 became enforceable, the Commission and the AI Office got the power to investigate and fine general-purpose AI providers, and the whole sanctioning regime went live. Fines run to €15 million or 3% of worldwide annual turnover, whichever is higher. There’s a trap in this one that I want to flag, because advisory notes are circulating right now saying the AI Act got postponed. It didn’t. The Digital Omnibus pushed the high-risk obligations out to December 2027 and August 2028, and left the general application date exactly where it was. Both things are true at once, and only one of them made it into most of the summaries.
Washington built a framework and won’t show it to you. A June executive order required a process for vetting frontier models before release, and on August 4 the White House walked a group of companies through the finished draft. Meta, Nvidia, Microsoft, OpenAI, Anthropic, Google. Participation is voluntary; the framework will not be published, the cyber-capability benchmarks are classified by the order itself, and open-source models are excluded from review entirely. Companies that weren’t in the room remain in the dark about what’s in it.
Three states went the other way and published everything. Illinois signed the Artificial Intelligence Safety Measures Act on July 6, joining California and New York, all three built on the same thresholds. Illinois went further than either by requiring annual independent third-party audits. Disclosure duties start January 1, 2027, and the framework and audit obligations follow in 2028. So while Washington keeps its standard private, a de facto national regime is being assembled in state capitals, in public, with dates on the calendar.
China regulated agents specifically. The Implementation Opinions on intelligent agents took effect July 15, the first national framework anywhere to treat AI that acts as a different regulatory category from AI that answers. Healthcare, transportation, media and public safety carry filing requirements, mandatory testing, and product recall authority.
Four regimes. One is enforceable and public, one is voluntary and secret, three are public and not yet in force, and one governs the exact category of software that cancelled that gym reservation.
You can’t adopt a rulebook that doesn’t exist
Here’s the analogy I keep using with leaders on this.
Running AI across jurisdictions right now is like driving across borders. The speed limit changes, the right-of-way rules change, and in some places the thing you were legally doing five miles back will get you pulled over. “It was legal where I started” has never once worked as a defense, and no traffic cop has ever accepted “the rules were confusing” either.
That’s where most of us are. There is no single framework you can adopt as proxy compliance for the rest, because the four of them genuinely disagree, and the one your own government wrote is one you’re not permitted to read.
Which means the instinct to hand this to Legal doesn’t survive contact with the problem. Your counsel can read a statute beautifully. What they can’t do is tell you which decisions your organization should be letting software make in the first place, or where your AI’s output actually lands. Those are governance calls, and they sit with you the same way deciding what happens when an agent gets it wrong sits with you.
I’ll be honest that this one is uncomfortable for me to write, because I’m inside it. I’ve got consulting clients in more than one country and paying subscribers on basically every continent, so several of these regimes touch me directly. And I can’t sit back and wait for them to sort it out with each other. I need to know which of my AI tools touch confidential information I can’t risk getting out, and how I’m protecting the data of the people who trust me with it. The costs of claiming ignorance are too high, and they’re only going to grow.
Where should you actually start with AI?
We all got the tools at the same time, the way everyone eventually got electricity. Having it in the building was never what made the difference. What we did with it was.
I take three diagnostic calls a month. It’s 30 minutes, free, and we work out what you’re actually trying to get to, where your biggest hurdles sit, what your low-hanging fruit is, and how that lines up with what I’ve been seeing elsewhere. Then I tell you the first move I’d make.
A few days later you get it back in writing, two or three pages, yours whether we ever work together or not.
What to actually do about it this week
You don’t need counsel in four countries. You need one answer you probably don’t have yet, which is where your AI’s output actually lands.
The question isn’t where your company is registered, but where the output goes. If an AI-written email reaches a customer in Dublin, if your chatbot answers somebody in Milan, if your agent books something for a subscriber in Berlin, the EU’s transparency duty reaches you, and Article 50 has no revenue floor on it at all. That last part is what catches people out. Illinois and California start at $500 million in revenue, so most of us read the headlines and reasonably conclude none of it applies to us. The European rule doesn’t work that way, and it’s extraterritorial by design.
So write down your jurisdictions this week. One sitting, one page, no software. For each AI tool your team runs, note where its output ends up and who the humans on the receiving end are. Most of us have never once been asked that question, which is why almost nobody can answer it on the spot.
Now, I want to be straight with you about where I’m less sure. This is genuinely hard in a global economy, and I don’t think anyone has it solved. I don’t know whether these regimes get enforced against organizations our size, or whether they converge in two years and make all of this look overwrought. Anyone telling you they know is guessing. What I do know is that the exposure sits with us either way, and that guessing wrong in the other direction costs a great deal more.
The gym story is funny right up until you notice the shape of it. A capable tool, a goal, no clear parameters, and a system that assumed nobody would ever check.
Four governments are arguing about who’s responsible for that.
While they argue, it’s you.
Where does your AI’s output actually land? Could you name the jurisdictions right now, without looking? Tell me in the comments.
Worth Your Time
ToxSec — the gym-class agent, in one note. His note on the Melbourne story is the tightest telling of it I’ve seen, and the replies underneath are worth as much as the note.
Ethan Mollick — What it feels like to work with Mythos. The Wharton professor behind Co-Intelligence on the model that escaped its own sandbox in April. If you want to understand why regulators suddenly got interested this summer, start with what the thing can actually do.
Mohib Ur Rehman — Why Europe Is Quietly Ditching Microsoft. Mohib wrote the AI sycophancy piece for us back in June. Here he’s on digital sovereignty, which is the same story as this one told from the other end: what happens when a jurisdiction decides it no longer wants to run on somebody else’s rules.
FAQ
Did the EU AI Act get postponed? No. The Digital Omnibus (Regulation (EU) 2026/1744, in force 27 July 2026) moved the high-risk obligations for Annex III systems to 2 December 2027 and for AI embedded in regulated products to 2 August 2028. The general application date stayed at 2 August 2026, which is when Article 50 transparency duties, GPAI enforcement powers, and the penalty regime became enforceable. Advisory notes summarising this as “the AI Act was delayed” are wrong.
Does the EU AI Act apply to my company if I’m not in Europe? Potentially yes. It applies to providers placing AI systems on the EU market, deployers using AI in the EU, and providers or deployers outside the EU where the system’s output is used in the EU. The Article 50 transparency duty has no revenue threshold, so company size doesn’t exempt you.
What does the Illinois AI law require, and does it apply to me? The Artificial Intelligence Safety Measures Act (SB 315, signed 6 July 2026) applies to developers of frontier models trained above 10²⁶ FLOPs, with the heaviest duties on “large frontier developers” earning over $500 million a year. Unless you’re training frontier models, it doesn’t bind you directly, though it will reshape what your AI vendors can tell you.
Why won’t the White House publish its AI evaluation framework? The June 2026 executive order that required the framework contains no obligation to publish it, and it explicitly classifies the cyber-capability benchmarking process. The framework is voluntary, shared only with participating companies, and excludes open-source models from review.
Who is legally responsible when an AI agent causes harm? As of today, unsettled. In the Australian gym case, ABC News reported that legal experts say the law hasn’t caught up on whether responsibility falls to the user, the agent’s developer, the model provider, or the vendor whose insecure system was exploited. That unresolved question is exactly why the governance call sits with the leader deploying the tool.
What is the difference between China’s agent rules and everyone else’s AI rules? China’s Implementation Opinions, effective 15 July 2026, are the first national framework to treat AI agents (systems that perceive, remember, decide and act) as a distinct regulatory category rather than another application of generative AI. Sensitive sectors face filing requirements, mandatory testing, and recall authority.
If the rules conflict, which one do I follow? There’s no proxy compliance available, so start from where your output lands rather than from where you’re incorporated, then apply the strictest regime that reaches you. In practice all four converge on the same underlying question, which is whether a named human is accountable for what the system does.
Joel Salinas is an AI Strategy Coach and entrepreneur. AI is everywhere; judgment is scarce. Joel helps founders and leaders adopt AI without outsourcing their judgment to it, and he builds the systems too. Creator of the AI Leadership Triad.
Written by a human, for humans.
Sources
Fortune — White House won’t publicly release AI model evaluation framework, August 4, 2026
Axios — White House plans to keep AI framework under wraps, August 4, 2026
The New York Times — Trump White House Readies AI Framework to Review Security Risks, August 4, 2026
European Commission — The enforcement framework of the AI Act
Skadden — Illinois Enacts AI Safety Law, July 2026
NYU Shanghai RITS — China Issues First National Policy Framework Dedicated to AI Agents
The Decoder — Told to book a gym class, an AI agent hacked the site instead, August 2026
ABC News Australia — AI agent outsmarts gym booking system in Australia’s first known autonomous hack, August 10, 2026






