AI regulation · September 2026
Congress will not settle the AI rules before the midterms. Your customers will not wait.
The federal debate is deadlocked. The rules that actually bind a SaaS or cloud provider are being written somewhere else — in state capitols, in Brussels, and in the security questionnaire sitting in your sales pipeline right now.
16 September 2026 · Kenio Shirley
The week the argument broke open
In the second week of September 2026, three researchers left frontier labs citing loss of control over advanced systems, Anthropic's chief executive published an essay arguing the industry should deliberately slow down, and the White House called the whole risk narrative a hoax. Democrats asked the House to delay its recess until safeguards passed. The House left anyway.
Senate Majority Leader John Thune told reporters there is "a way in which Congress can put guardrails around those types of more consequential threats," which is the position of a man describing a bill that does not exist yet. Dozens of AI proposals are pending. Nearly all of them are stalled on the same disagreements they were stalled on a year ago.
No comprehensive federal AI statute will bind you this year. That is a scheduling fact, not a reprieve.
Deadlock is not the same thing as no rules
When Washington stops, the obligation does not disappear — it relocates. OpenAI's chief global affairs officer has a name for the resulting shape: reverse federalism. Get California, New York and Illinois to pass compatible rules and you have a national floor without a national law.
At the same time, money from the same industry funds super PACs pushing Congress toward a single federal framework that would preempt those state laws. A Senate bill co-sponsored by Cruz, Klobuchar and Thune centres on safety testing and incident reporting; state advocates read a preemption mechanism inside it. The precedent is recent — in 2025 a ten-year ban on state AI enforcement was stripped from a larger package on a 99–1 vote after seventeen Republican governors objected.
Both outcomes end in a compliance obligation for you. Preemption gives you one regime to evidence. Deadlock gives you several. Neither gives you none.
The Cruz–Klobuchar–Thune bill is a proposal, not law, and reporting disagrees about how far its preemption language reaches. Treat the shape as directional and your counsel as authoritative.
What already binds a SaaS provider, with Congress doing nothing
State law, first. If you sell into California, New York or Illinois, your exposure is set by whichever of those legislatures moves, on their calendar rather than yours.
The EU AI Act, second. It applies to providers placing systems on the EU market regardless of where they are incorporated, and its transparency and documentation duties are already phasing in. A US-only compliance posture is not a posture for a company with EU customers.
And the enterprise security questionnaire, third — which is the one that will reach you first. Buyers have already added AI sections: which models, hosted where, trained on what, retained how long, disclosed to whom, and what happens when it fails. No legislature had to act for that to become a deal blocker.
Procurement moves faster than Congress, and it has a shorter appeals process.
If you are a platform or cloud provider, you inherit all of it
Your customers' obligations arrive at your door through the shared-responsibility line. When a regulated customer must evidence where inference runs, what is logged, who can reach the data and how quickly an incident is reported, they cannot answer for the layers you operate. They will ask you, and they will ask in writing.
Answering with a diagram will not work. The same failure mode that breaks shared-responsibility claims in a SOC 2 or FedRAMP audit breaks them here: a responsibility matrix says who should have done something and never shows that anybody did.
That is a whole problem of its own, and it is the subject of the companion piece on shared responsibility under audit.
The position: stop tracking the bill, start building the artefacts
Read the live proposals side by side — the Senate safety-testing bill, the state frameworks, the EU AI Act, the NIST AI RMF that buyers cite in questionnaires — and the same five artefacts appear in every one of them. The wording differs. The evidence does not.
| Artefact | What every regime asks | What counts as proof |
|---|---|---|
| Model and vendor inventory | Which models, from which providers, in which product surfaces, at which versions. | A current list produced from the running system, not a spreadsheet maintained by hand. |
| Data-flow record | What customer data reaches a model, where it is processed, whether it trains anything. | Configuration state showing the training and retention settings actually in force. |
| Incident detection and reporting timeline | How fast you detect a serious failure and who you tell within what window. | Dated detection and notification records from real or exercised incidents. |
| Subprocessor disclosure | Every downstream provider touching customer data, with notice terms for changes. | A published list with a change history a customer can diff. |
| Change history | What changed in the system, when, approved by whom. | An immutable record tied to the configuration it changed. |
None of those five are speculative. Four of them you already owe somebody under contracts you have signed. Building them now costs you a quarter of engineering attention. Building them in the ninety days after a rule lands, while a deal is held hostage to the answer, costs considerably more.
Whichever way the preemption fight goes, the company that can produce dated, verifiable state of its own systems is ready and the company with a policy document is not.
Where Keystone helps, and where it does not
Keystone reads your cloud estate and holds hash-chained evidence of what it found and what changed. That covers the infrastructure half of the list: what is running, where, configured how, changed when and by whom — the parts of an AI questionnaire that are really infrastructure questions wearing a new label.
To be plain about the other half: Keystone has no model-governance module, no evaluation harness, no bias or red-team tooling, and no mapping to the EU AI Act. Model risk management is a different discipline and we do not claim it.
This is reporting on a legislative fight, not legal advice. Nothing here interprets a statute for your circumstances.
Kenio Shirley is the founder of Keystone and runs hireken.io. CISSP, CISM. Seventeen years in enterprise technology across 50+ audits covering SOC 2, HITRUST, FedRAMP, PCI DSS, SOX and IRAP.
Sources
- BBC — AI regulation faces political deadlock as calls grow for Congress to act, 15 September 2026
- NBC News — Dire warnings about AI shock Congress, but action is unlikely before the election, 14 September 2026
- Semafor — AI plays sophisticated defense in a broken Washington, 15 September 2026
- Deseret News — AI leaders warn their technology needs to be reined in. Congress isn't sure what its role should be, 16 September 2026
- Who Decides the Future of AI as States Face Federal Preemption, 15 September 2026
- EU AI Act, full text
Evidence beats a policy document
See what it costs to have your estate produce its own proof, continuously.