saturday, september 5, 2026 · the day's ai, attributed published by trilot llc · wyoming
guide · running the business

Which AI rules actually reach a business your size

Frontier-AI regulation is aimed at the labs, but a narrow slice of disclosure duties and vendor terms lands on you, and you can settle it in an afternoon.

Published 2026-09-05 · Updated 2026-09-05 · Read 9 min · Reviewed by Rami Steitieh

Verified 2026-09-05 · Rami
on this page · 0 / 0 checked

In July 2026 the chief executive of Google DeepMind published a proposal for a new Standards Body that would review the most capable AI models before release, funded mostly by industry, and modelled on “a federally overseen public-private partnership or self-regulatory organisation, much like the Financial Industry Regulatory Authority (FINRA)” [1]. If you run a two-person studio, a consultancy, or a freelance practice, nothing in it changed anything you do on Monday. That is the normal outcome for frontier-AI policy news, and it will be the normal outcome for the next proposal too.

The rules that do reach you arrive by two quieter routes. One is a short list of disclosure duties that apply to anyone who puts AI output in front of another person, regardless of size. The other is the usage policy of the vendor whose account you already pay for, which you agreed to and probably have not read. Both are already in force. Neither made headlines. This guide is for people who use AI tools built by someone else. It is not for anyone training or placing a model on a market, and not for anyone using AI to screen job applicants, price credit, or make medical, educational, or insurance decisions. Those uses sit in a heavier tier and need a lawyer rather than a guide.

Almost every rule you read about is aimed at the model, not at you

Read the Hassabis proposal closely and the scope is explicit. A model qualifies as “Frontier-class” if it “meets certain thresholds on a set of benchmarks determined by the Standards Body and regularly updated”, the organisations holding such models “would be deemed ‘Frontier Labs’”, and those labs “would voluntarily share models with the Standards Body for review up to 30 days before release” [1]. Funding, he writes, “would need to be substantial and likely mostly come from industry, in order to attract world-class technical talent” [1]. Nothing in it reaches a person who buys a subscription.

A version of that split runs through the law already on the books. The EU AI Act’s transparency chapter hangs some duties on the provider of an AI system and others on the deployer that uses one, and the two lists are different [4]. The rules for high-risk AI systems listed in Annex III do not apply until 2 December 2027 [2].

This is worth internalising because policy coverage is written for a general audience and rarely says who is bound. A headline about a watchdog with the standing to hold up a release is describing an arrangement between governments and the small set of organisations whose models clear the benchmark thresholds [1]. Your exposure to that fight is real, but it runs through model availability, not through compliance, and the response is different. More on that below.

The disclosure rules that do reach you went live on 2 August 2026

On 2 August 2026 “the majority of rules of the AI Act come into force and enforcement starts for applicable rules”, including the transparency rules, at both national and EU level [2]. The part that lands on a small operator is Article 50, and it is short enough to read in one sitting.

Three duties matter. An AI system intended to interact directly with people must be designed so those people are informed they are interacting with an AI, unless that is obvious “from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use”; the Act writes that one for providers [4]. Deployers of a system that generates or manipulates image, audio, or video content “constituting a deep fake” must disclose that it was artificially generated or manipulated, a deep fake being content that resembles existing persons, objects, places, entities, or events and would falsely appear authentic [4]. And deployers of a system that generates text “published with the purpose of informing the public on matters of public interest” must disclose that too, unless the content “has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility” for it [4]. In each case the information must be given “in a clear and distinguishable manner at the latest at the time of the first interaction or exposure” [4].

Three details catch people out. The first is scope. The Act reaches “providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union” [3]. A freelancer in Ohio with a client in Dublin is inside the transparency rules for that work if the output is used there.

The second is the editorial-review carve-out on generated text. It is not a formality. It exists so that a person stands behind the published words, which means it applies when you actually read and take responsibility for what you ship, and not when you paste and publish.

The third is that the chatbot duty is written for providers rather than deployers [4]. If you assemble an assistant on top of somebody else’s model and put it in front of your own customers under your own name, working out which hat you are wearing is a question for a lawyer, not a guide. The cheap move is to disclose either way, because your vendor’s terms may require it regardless of what the Act says about you [5]. A line at the top of a chat window and a standing note on generated images cost an afternoon, and the fix is trivial in advance and awkward under a client’s procurement questionnaire.

Your vendor’s usage policy binds you faster than any statute

The rule most likely to cost you something in the next year is not a law. It is the usage policy attached to the account you already have, because your vendor can enforce it tomorrow by closing your access, with no legislature involved.

Anthropic’s usage policy, effective 15 September 2025, requires that “all consumer-facing chatbots, including any external-facing or interactive AI agent, must disclose to users that they are interacting with AI rather than a human”, at a minimum at the beginning of each chat session [5]. It also names a set of high-risk domains, among them legal, healthcare, insurance, finance, employment and housing, academic testing, accreditation and admissions, and media or professional journalistic content. In those domains “a qualified professional in that field must review the content or decision prior to dissemination or finalization”, and where model outputs are presented directly to individuals or consumers, “you must disclose to them that you are using AI to help produce your advice, decisions, or recommendations” [5].

OpenAI’s usage policies, effective 29 October 2025, are shaped differently. They carry no equivalent blanket disclosure requirement, but they prohibit “automation of high-stakes decisions in sensitive areas without human review”, listing critical infrastructure, education, housing, employment, financial activities and credit, insurance, legal, and medical among others, and they prohibit “provision of tailored advice that requires a license, such as legal or medical advice, without appropriate involvement by a licensed professional” [6].

Read those two side by side and the practical lesson is that the obligations differ by vendor, so the answer to whether you must disclose depends on which account is behind the feature. If a client-facing assistant runs on Claude, the disclosure line is contractual, not optional, whatever the law where you live says [5]. If you switch that assistant to a different vendor, the duty changes shape, and you have to re-read rather than assume.

The regulation you will actually feel is a model being retired

The operational risk from all of this is not a fine. It is that a model your work depends on stops answering. That happens routinely, on published schedules, and it is the one part of the frontier-AI story with hard dates you can plan against.

Anthropic provides “at least 60 days’ notice before model retirement for publicly released models”, and sorts models into active, legacy, deprecated, and retired, with requests to retired models failing outright [7]. Several have already gone: claude-3-7-sonnet-20250219 retired on 19 February 2026, claude-sonnet-4-20250514 and claude-opus-4-20250514 on 15 June 2026, and claude-opus-4-1-20250805 on 5 August 2026 [7]. OpenAI’s notice periods are tiered instead: at least 6 months for generally available models, at least 3 months for specialised variants such as chat, Codex, and deep research builds, and preview models “may be retired with much shorter notice, such as 2 weeks”, with safety or compliance concerns allowed to move faster still [8]. Its published schedule retires gpt-3.5-turbo-0125 and gpt-4-0613 on 23 October 2026, and the gpt-5-2025-08-07, gpt-5-pro-2025-10-06, o3-2025-04-16 and o3-pro-2025-06-10 snapshots on 11 December 2026 [8].

Those two policies are not equivalent, and the difference should shape where you pin things. A workflow pinned to a dated model ID on a 60-day clock needs a standing check [7]. A workflow on a preview model may get as little as 2 weeks [8]. The failure mode is quiet: an automation in Zapier or n8n that has run untouched for a year returns an error, and the person who wrote the prompt has forgotten what it assumed.

calculator
What one forced model swap costs you
per migration

automations × re-test hours × your rate. Notice runs from at least 60 days at Anthropic [7] to at least 6 months for generally available OpenAI models and as little as 2 weeks for previews [8]. Computed in the page; nothing is sent anywhere.

One page listing where AI touches a person’s outcome

Everything above collapses into a single document, and it does not need to be a policy. A page in Notion is enough. For each place AI output leaves your business, write four things: what the workflow is, who sees the output, which vendor and which exact model ID produces it, and whether a human reads it before anyone else does.

That page answers the questions that actually get asked. A client’s procurement form wants to know whether AI touched the deliverable and whether a person reviewed it. Article 50 wants to know whether the recipient was told [4]. Your vendor’s policy wants to know whether a qualified person reviewed anything in a high-risk domain [5][6]. The deprecation pages want a list of model IDs to check against [7][8]. One table answers all four, and building it takes less time than reading a single law-firm briefing about the law.

The version that fails is the one written in vendor names instead of model IDs. “We use ChatGPT” tells you nothing when a named snapshot retires on a named date [8]. Write down the string your code or your automation actually sends.

checklist
Your AI compliance page, in one afternoon
0 of 7 · saved in this browser only

Three signals worth watching, and the rest is noise

Most frontier-AI policy coverage is proposals about proposals. Three things are worth a calendar reminder, and they are the ones that change your work rather than the news cycle.

The first is whether a lab actually submits a model to an external review it does not control. Hassabis frames the initial sharing as voluntary, but writes that “once the assessment protocol is shown to be effective and robust, formalisation could quickly follow, meaning that Frontier Models would be required to pass it to be deployed in the US market” [1]. The signal is not another framework. It is a real submission, and then a release date that moves because of one.

The second is your vendors’ usage policies changing. Both carry effective dates on the page [5][6]. A policy change can make a feature you shipped last quarter non-compliant with your own account terms, and the only notice you get is a page that quietly says a new date.

The third is the deprecation pages [7][8]. Check them quarterly. They are the only source in this guide that will reliably break something you own.

What still goes wrong

The dates move. The Commission’s own implementation timeline says it “takes into account the AI Act amendments introduced by Digital Omnibus on AI”, and the Annex III high-risk rules apply from 2 December 2027 [2]. Anything in this guide with a future date should be re-checked against the source rather than trusted from memory, and a guide that told you the schedule was settled would be lying.

Disclosure duties are also easier to state than to apply at the edges. Article 50 waives the interaction disclosure where the AI is obvious to a reasonably well-informed, observant and circumspect person, and waives the text disclosure where the content went through human review or editorial control with someone holding editorial responsibility [4]. Both are judgement calls, and a judgement call is exactly the thing a regulator and a client can disagree with you about after the fact. Where the cost of disclosing is one sentence, disclose and stop thinking about it.

The last gap is the one this guide cannot close. If your work sits inside a high-risk category, screening candidates, deciding creditworthiness, or supporting a clinical or educational decision, none of the above is your compliance plan, and both vendor policies name those domains specifically [5][6]. Get advice from someone who will put their name on it. For everyone else, the honest summary is that frontier-AI regulation is a spectator sport with a small entry fee, and the fee is a disclosure line and a list of model IDs.

sources
  1. 01Demis Hassabis — A framework for frontier AI and the dawning of a new agedemishassabis.substack.com
  2. 02European Commission AI Act Service Desk — Implementation timelineai-act-service-desk.ec.europa.eu
  3. 03Regulation (EU) 2024/1689 (AI Act), Article 2 — Scopeartificialintelligenceact.eu
  4. 04Regulation (EU) 2024/1689 (AI Act), Article 50 — Transparency obligationsartificialintelligenceact.eu
  5. 05Anthropic — Usage Policyanthropic.com
  6. 06OpenAI — Usage policiesopenai.com
  7. 07Anthropic — Model deprecationsplatform.claude.com
  8. 08OpenAI — Deprecationsdevelopers.openai.com
next guide
Brief an AI like a freelancer, and manage it like one
9 min · verified 2026-09-05
related guides