How to tell which AI rules will actually reach you
Separate the AI governance news that changes nothing for you from the dates and clauses that already bind you, and build the two things every framework asks for.
on this page · 0 / 0 checked
Every few months an AI governance event produces headlines that read as though something changed on Monday. The UN’s Global Dialogue on AI Governance held its first session in Geneva on 6 and 7 July 2026, and its second is scheduled for New York on 3 and 4 May 2027 [1]. If you run a two-person studio that drafts client copy with Claude, or a consultancy that scores inbound leads with a model, the useful question is not what was said in the room. It is which of the rules under discussion anywhere will land on you, in what year, through which document.
That question has a clean answer, and it is not the one the coverage implies. This guide is for solo operators, freelancers and small teams who use commercial AI tools in work that reaches other people. It is not for companies training or shipping their own models, who carry the heavier provider duties and need a lawyer rather than a guide. Nothing here is legal advice. It is a method for sorting the noise from the calendar.
What an intergovernmental process actually produces
Start with the machinery, because the machinery tells you the output. The Global Dialogue was established by General Assembly resolution A/RES/79/325, adopted on 26 August 2025, alongside an Independent International Scientific Panel on AI. It is described as “the United Nations platform where all governments and stakeholders will convene to discuss international cooperation, share best practices and lessons learned”, and it is co-chaired by El Salvador and Estonia [1].
The terms of reference are more revealing than the description. The Dialogue is “convened annually for up to two days in the margins of existing relevant United Nations conferences and meetings”, and what it produces is “a Co-Chair’s summary of each annual Dialogue” [2]. The Scientific Panel that sits beside it produces “one annual policy-relevant but non-prescriptive summary report including thematic briefs as it deems necessary”, with updates to the General Assembly up to twice a year [2]. The Panel launched its preliminary report on 1 July 2026 [3].
Read those phrases in sequence. Two days a year, held in the margins of other meetings, producing a chair’s summary and a report that is non-prescriptive by design. Nothing in that machinery can create an obligation for you, and none of it was built to. Treating it as an early warning of enforcement is a category error, and it is the error most coverage invites.
That does not make the process irrelevant. It makes it a vocabulary factory rather than a rule factory. What gets named in these venues, and which categories governments turn out to agree on, is the input to work that happens elsewhere. The lag is long enough that you will hear the same words from a procurement officer before you hear them from a regulator.
The rules that bind you arrive on a published calendar
While the Dialogue meets annually to produce summaries, the EU AI Act has been arriving on fixed dates that were set years in advance and are published in one table [4]. This is the calendar that determines what you actually have to do.
Prohibitions on certain AI systems and the AI literacy requirements started to apply on 2 February 2025 [4]. The general-purpose AI model rules, the governance framework, the notified body requirements and certain penalty provisions started on 2 August 2025 [4]. The remainder of the Act applies from 2 August 2026, with the exception that providers of AI systems generating synthetic audio, image, video or text content placed on the market before that date have until 2 December 2026 to meet the transparency measures [4]. A further tranche lands on 2 August 2027, covering high-risk AI system requirements, providers of general-purpose models placed on the market before 2 August 2025, and the obligation on Member States to have operational regulatory sandboxes [4].
Now put the two timelines side by side. The Dialogue’s second session sits in May 2027 [1], nine months after the date on which the bulk of the EU obligations began to apply [4]. The forum where the principle gets debated meets after the law implementing that principle is already in force. If you were waiting for the international consensus before doing anything, the deadline you cared about passed while you waited.
The practical instruction is narrow. Track dates from statutes and vendor policies, both of which publish them. Read the summaries from forums as information about what the next statute will be called, not as a countdown.
The category list is the part that travels
The one thing that does move between these documents is the list of situations treated as consequential. Annex III of the EU AI Act names eight categories of high-risk system: biometrics, critical infrastructure, education and vocational training, employment and workers’ management, essential services including credit assessment and insurance pricing, law enforcement, migration and border control, and the administration of justice and democratic processes [6].
Then read the vendor policies you have already agreed to. OpenAI prohibits the “automation of high-stakes decisions in sensitive areas without human review”, and its list of sensitive areas runs through critical infrastructure, education, housing, employment, financial activities and credit, insurance, legal, medical, essential government services, national security, migration and law enforcement [8]. Anthropic applies extra requirements to high-risk use cases including legal interpretation, healthcare decisions, insurance underwriting, financial decisions, employment determinations, housing eligibility and academic admissions [7].
Three documents, three different legal statuses, one recognisable list. That convergence is the actual signal, and it is stable enough to plan around. If your work touches hiring, lending, insurance, housing, education, health or anything a government does to a person, you are inside the category that every framework reaches first, whatever the framework ends up being called. If it does not, most of what you read about AI governance is describing somebody else’s problem.
Your vendor’s terms are stricter than the law, and they bind you today
The document most likely to constrain what you ship this quarter is not a statute. It is the usage policy attached to the account you pay for.
Anthropic’s Usage Policy states that when its products are used “to provide advice, recommendations, or in subjective decision-making directly affecting individuals or consumers, a qualified professional in that field must review the content or decision prior to dissemination or finalization” [7]. It goes further on disclosure: “If model outputs are presented directly to individuals or consumers, you must disclose to them that you are using AI to help produce your advice, decisions, or recommendations. This disclosure must be provided at a minimum at the beginning of each session” [7]. OpenAI’s requirement in the same territory is the ban on automating high-stakes decisions without human review [8].
Compare the enforcement properties. The statute has an application date, a national authority, a procedure and a long tail before anything reaches a business your size. The usage policy applies from the day it is published, has no jurisdictional test, needs no regulator, and is enforced by an account suspension that stops your work the same afternoon. For a small operator, the vendor policy is both the earlier and the sharper instrument.
There is a second-order effect worth naming. Because the vendor policies already encode the human review and disclosure requirements, an operator who complies with the contract is largely doing what the law will ask about the same activity. Compliance work you do to keep your API access is not separate from governance work. It is most of it.
Two capabilities cover most of what any framework will ask
Strip the frameworks down and they ask small teams for the same two things.
The first is disclosure at the point of contact. Article 50 of the EU AI Act, which applies from 2 August 2026, requires providers to ensure that systems intended to interact directly with people are built so that those people are informed they are interacting with an AI system, unless that is obvious [5]. It requires deployers to disclose deepfakes, and to disclose AI-generated text published to inform the public on matters of public interest, with an exemption where the content had human review and a named person or company holds editorial responsibility [5]. It requires the information to be given “in a clear and distinguishable manner at the latest at the time of the first interaction or exposure” [5]. Anthropic asks for the same disclosure at the beginning of each session [7]. One sentence at the top of a chat surface, an email footer, or a byline note satisfies all of these at a cost of an afternoon.
The second is a record of who reviewed what. Both major vendor policies turn on a human being in the loop for consequential output [7][8], and the Article 50 exemption for published text turns on somebody holding editorial responsibility [5]. Each of those is a claim about a person, and a claim about a person is worth nothing if you cannot show it after the fact. A dated line naming the reviewer, stored wherever the work is stored, is enough. Anything more elaborate will not survive contact with a busy week.
Build both while nothing is forcing you to. Retrofitting disclosure into a live product is a design conversation with customers. Adding it before launch is a copy decision.
Twice a year is the right amount of attention
Governance is not a subscription you need to read daily. The Dialogue meets annually [2], the Panel reports annually [2], and the EU dates are fixed years ahead [4]. A calendar reminder every six months matches the rate at which anything relevant changes, and it protects you from the two failure modes at either end, which are rebuilding your product after every headline and discovering an application date after it passed.
What still goes wrong
The biggest gap in this method is the middle of the map. The EU publishes a calendar, and vendors publish policies, and both are easy to read. National and sub-national rules in the rest of the world are neither centralised nor synchronised, and a small operator has no reliable way to monitor them all. The honest position is that you are covering the two largest and most legible sources of obligation and accepting exposure on the rest, which is a defensible trade for a business of a few people and a bad one for a business of a few hundred.
The second problem is role. The EU rules split duties between providers and deployers, and Article 50 puts the heavier marking obligations on providers and the disclosure obligations on deployers [5]. Where a small team sits when it wraps somebody else’s model in its own branded product is a question this guide cannot answer for you, and the answer changes what you owe. If your product is a thin interface over a vendor model, sold under your name, that is the point at which a conversation with a lawyer stops being optional.
Finally, the argument that the UN process cannot bind you is true today and true about that process. It is not a claim that international coordination never produces enforceable rules. The categories being named annually in a chair’s summary [2] are the same categories already sitting in Annex III [6] and in two vendor policies [7][8]. The mechanism is slow and indirect, and it is not nothing. What it is not, is a reason to change anything this quarter.
- 01United Nations — Global Dialogue on AI Governanceun.org
- 02UN — Terms of Reference and Modalities for the Scientific Panel and Global Dialogue (Rev 5, 1 August 2025)un.org
- 03United Nations — Independent International Scientific Panel on AIun.org
- 04EU AI Act — implementation timelineartificialintelligenceact.eu
- 05EU AI Act, Article 50 (transparency obligations for providers and deployers)artificialintelligenceact.eu
- 06EU AI Act, Annex III (high-risk AI systems)artificialintelligenceact.eu
- 07Anthropic — Usage Policyanthropic.com
- 08OpenAI — Usage policiesopenai.com