
AI Compliance Map — Aug 7–14, 2026: Colorado drafts ADMT rules as Texas builds public-sector controls and Australia maps agent risk
This week's verified map separates proposed Colorado AI-decision rules, Texas public-sector implementation, Australia's non-binding agent-safety framework, and the UK's 9 September data-regulation submission deadline.
The week produced more implementation work than new binding law. Colorado opened a rulemaking that will determine how employers and other deployers explain adverse AI-assisted decisions, Texas published a public-sector implementation map, and Australia released a practical framework for controlling agents that interact across company boundaries. A UK data-regulation call for evidence also creates a near-term response date for AI companies.
Coverage and readout
This map covers actions with a governing timestamp from 5:00 p.m. on 7 August through 5:00 p.m. on 14 August 2026 (UTC-05:00). Three in-window developments cleared the strict inclusion bar, plus one live deadline:
- Proposed Colorado rules: the Attorney General's rulemaking puts notice, data access, human review, and recordkeeping questions around automated decision-making technology into operational detail ahead of a January 2027 start date.
- Texas implementation: the Department of Information Resources has moved the 89th Legislature's public-sector AI framework into training, acceptable-use, inventory, evaluation, and sandbox resources.
- Australian safety guidance: the Australian AI Safety Institute's new research treats interacting agents as a system, with governance requirements changing as control moves from one organization to several or to the open web.
- UK deadline: a Department for Science, Innovation and Technology call for evidence on data regulation and AI closes on 9 September.
No new AI-specific EU, China, or US federal action with a verified governing date inside this window was admitted. No new AI-specific enforcement penalty with a verified primary source was confirmed. Those are coverage results, not claims that no activity occurred anywhere.
Executive action list
- Colorado product, HR, and legal teams: inventory every tool that ranks, scores, recommends, classifies, or infers about people in employment, lending, insurance, housing, education, health care, or essential government services. Test whether your vendor can explain an individual outcome and support a 30-day adverse-outcome notice, data correction, and meaningful human review.
- Texas public-sector teams and suppliers: map each deployment to the applicable state or local entity, training requirement, acceptable-use policy, AI inventory, evaluation path, and heightened-scrutiny review. The DIR page is an implementation resource, not a substitute for reading the underlying bills or rules.
- Agent owners: evaluate interacting agents as one system. Before cross-company deployment, agree on identity, permitted actions, monitoring, escalation, and rollback; in open environments, narrow tools and permissions until the counterparty can be trusted.
- UK policy teams: decide whether to submit operational evidence to DSIT before the 9 September deadline. The call is a policy input opportunity, not a new private-sector compliance duty.
At a glance
| Jurisdiction / action | Status and date | Affected scope | Compliance impact |
|---|---|---|---|
| Colorado ADMT and conversational-AI rulemaking | Proposed; comment process opened 11 Aug 2026 12 | Developers and deployers of covered ADMT used in consequential decisions, plus covered conversational AI services in Colorado | Prepare explainable adverse-outcome notices, data-access and correction workflows, independent human review, and three-year records; the statute is scheduled to take effect 1 Jan 2027 if rulemaking is completed. |
| Texas DIR implementation of 89th Legislature AI laws | Implementation resources; 14 Aug 2026 3 | Texas state and local government organizations, officials, employees, and public-sector AI programs | Check training, acceptable-use, agency-inventory, evaluation, and heightened-scrutiny controls against each government deployment and contract. |
| Australian AI Safety Institute multi-agent research | Non-binding research and guidance; 10 Aug 2026 4 | Organizations whose agents interact internally, with partners or suppliers, or with unknown agents on the open web | Treat the multi-agent system—not each agent alone—as the evaluation unit; set cross-organization safeguards and restrict open-web access. |
| UK DSIT data-regulation call for evidence | Open call; closes 9 Sep 2026 at 11:59 p.m. 5 | Organizations developing, deploying, operating, procuring, or enabling AI and other data-intensive technologies | Decide whether to submit evidence on lawful data use, provenance, governance, and AI supply-chain responsibility; this is a consultation deadline, not a new legal obligation. |
United States: Colorado's draft rules turn AI-assisted decisions into workflows
On 11 August, the Colorado Attorney General's Office opened public comment on draft rules for the Automated Decision-Making Technology Act and the Chatbot Safety Act. The Colorado framework is scheduled to take effect on 1 January 2027, provided the required rulemaking is completed by that date. 12
The statute reaches developers and deployers of covered automated decision-making technology used to materially influence consequential decisions. The covered domains include employment, education, housing, financial and lending services, insurance, health care, and essential government services. Developers must give deployers information about intended uses, training-data categories, known limits, appropriate use, monitoring, human review, and material updates. Developers and deployers must retain compliance records for at least three years. 2
For deployers, the practical work is in the adverse-outcome path. Before using covered ADMT in a consequential decision, a deployer must give clear and conspicuous notice that the technology is being used. If the decision produces an adverse outcome, the deployer must notify the affected consumer within 30 days, explain the role of the technology, provide a route to more information, and explain rights to request personal data, correct inaccurate data, and obtain meaningful human review where commercially reasonable. 2
The draft rules leave the most consequential coverage question open: when does an AI output materially influence a decision? The proposal offers two competing standards. One would likely capture a tool that nudges the decision; the other would leave more room where independent human factors play a substantially larger role. A separate analysis says the draft would presume material influence when an output constrains options or produces a rank, score, classification, recommendation, prediction, or inference that the decision-maker reviews and that aligns with the outcome. 6
The same rulemaking addresses conversational AI services. The proposed framework is especially relevant to recruiting chatbots and other services that may interact with teenagers, because the underlying law covers age estimation, AI disclosure, safeguards for sexual content and simulated emotional dependence, self-harm protocols, and annual reporting. 6
Compliance impact: treat the rulemaking as a design and vendor-management deadline, not a paperwork exercise. Pull a sample adverse decision through the proposed notice and review process now; every missing reason, data field, reviewer authority, or response timestamp identifies a system or contract gap. Written comments intended to influence the hearing draft are due by 5 October 2026, with the public hearing scheduled for 26 October 2026. 6
United States: Texas publishes the public-sector operating layer
The Texas Department of Information Resources said on 14 August that it has developed AI governance, training, and evaluation resources following laws passed by the 89th Texas Legislature. The page links the framework to Senate Bill 1964, House Bill 2818, House Bill 3512, and House Bill 149. 3
The listed implementation layer includes Texas Administrative Code Chapter 219 and an AI Systems Code of Ethics, a model AI Acceptable Use Policy, a Public Sector AI Sandbox, certified AI Awareness Training, an AI Literacy Program, and AI system inventory work under the Information Resources Deployment Review. The underlying bills also establish or direct work on a DIR AI Division, annual awareness training for certain state and local employees and officials, government-use disclosures, consumer protections, a Texas AI Council, and heightened-scrutiny AI rules. 3
Compliance impact: Texas-facing public-sector vendors should ask which government customer owns the deployment, which AI inventory captures it, whether annual training applies to the users, and whether the system falls into a heightened-scrutiny or sandbox path. The immediate signal is operational: procurement, training, governance, and evaluation records need to line up before a public-sector AI service scales.
Australia: agent risk moves from the model to the system
The Australian AI Safety Institute released research on 10 August about AI agents interacting across organizational boundaries. The companion summary from the National AI Centre divides the problem into three settings: one organization controls all agents; several organizations share a governance framework; or an agent interacts with unknown counterparts in an open environment. 47
The research identifies failures that can emerge between otherwise acceptable agents: errors can cascade, groups can reinforce a wrong belief, and agents with different incentives can converge on harmful strategies. It says the control question changes with governance: a single organization can inspect and intervene across its own system; a federated environment needs shared rules, infrastructure, monitoring, and escalation; an open environment requires either tight unilateral restrictions or voluntary standards with trusted peers. 7
The National AI Centre's practical recommendations are direct. Evaluate interacting internal agents together. Agree on safeguards, monitoring, and escalation points before agents cross organizational boundaries. If an agent connects to anonymous people, services, or agents, assume it may be attacked, manipulated, or incompatible; limit what it can access inside the organization and require agreed connection standards. 4
Compliance impact: this is non-binding guidance, but it gives procurement and assurance teams a usable control boundary. Add counterpart identity, permissions, handoff format, monitoring coverage, circuit breakers, incident ownership, and rollback to the pre-production checklist for every agent-to-agent integration.
United Kingdom: a live data-and-AI submission window
The Department for Science, Innovation and Technology is seeking practical examples of how personal and non-personal data regulation interacts with AI and other data-intensive technologies. The call asks about data access, lawful use, provenance, governance across supply chains, automated decision-making, and where existing rules create uncertainty or friction. 5
Compliance impact: policy teams with UK deployments can use the call to put concrete operational problems on the government's record, especially where an AI supply chain makes controller, processor, data provenance, or reuse responsibilities difficult to assign. Responses close at 11:59 p.m. on 9 September 2026. 5
Near-term deadline register
The strict 30-day look-ahead runs through 13 September 2026.
| Date | Item | Type | Who should care |
|---|---|---|---|
| 9 Sep 2026, 11:59 p.m. | UK DSIT call for evidence on data regulation in the age of AI | Consultation deadline; non-binding 5 | AI developers, deployers, operators, procurers, data providers, and compliance teams with UK experience |
| Through 13 Sep 2026 | No other new AI-specific compliance deadline with a verified primary-source date was admitted inside the look-ahead | No confirmed match | Close the Colorado, Texas, and agent-governance evidence gaps above; Colorado's 5 October comment date falls outside this register. |
Coverage note
The strict search covered US federal and key state surfaces, EU and UK government sources, China-related official surfaces, Australia, and other major-jurisdiction regulatory and court sources for the 7–14 August window. No additional AI-specific federal, EU, China, or in-window enforcement action with a verified primary-source date was admitted. A Court of Appeal judgment in R v FGD was checked but excluded because the official judgment date is 4 June 2026, outside this issue's window. 8
The practical pattern is narrow: Colorado is turning AI transparency into workflows, Texas is building the public-sector operating layer, Australia is defining controls for agent interactions, and the UK is asking industry to describe where data rules break under AI's current supply chains.
참고 출처
- 1
- 2Davis Polk — Colorado draft rules
davispolk.com
- 3
- 4
- 5
- 6Fisher Phillips — Colorado proposed rulebookfisherphillips.com
- 7
- 8The National Archives — R v FGD
caselaw.nationalarchives.gov.uk

Global AI Regulation & Compliance Map
Aggregate the latest week's AI bills, court rulings, and regulatory actions from each country, with one-sentence compliance impact
이 콘텐츠는 채널이 자동으로 생성했습니다. 한 문장이면 Neodrop이 당신을 위해 계속 만들어 냅니다.
관련 콘텐츠
- 로그인하면 댓글을 작성할 수 있습니다.
More from this channel›
- AI Compliance Map — Jul 31–Aug 7, 2026: EU transparency rules go live, while AI-agent access and child-safety scrutiny sharpen
- AI Compliance Map — Jul 24–31, 2026: EU timeline reset, Munich copyright ruling, and AI-pricing antitrust risk
- AI Compliance Map - Jul 17-24, 2026
- AI Compliance Map - Jul 10-17, 2026