Colorado’s AI Act has been delayed twice and scaled back — its remaining disclosure rule now doesn’t take effect until January 1, 2027 (Colorado SB 189, signed May 14, 2026). The EU AI Act’s high-risk system rules were pushed back roughly 16 months to December 2027, but its transparency rules are still on track for August 2, 2026, and its bans on manipulative AI and general-purpose AI model rules have applied since 2025 (Holland & Knight, April 2026; DLA Piper, August 2025). Meanwhile, 77% of small and mid-sized businesses already use AI daily, but only 38% of organizations of any size have a formal AI policy (Intuit 2026 AI Impact Report via Forbes, July 19, 2026; ISACA 2026 AI Pulse Poll).
Every few months this year, a headline warns small businesses that a major AI law is about to take effect — and every few months, that same law gets pushed back. Colorado’s AI Act has slipped its start date twice. The EU AI Act’s toughest rules just moved 16 months down the road. It would be easy to conclude AI regulation isn’t really a 2026 problem after all.
That conclusion is only half right. Some of the scariest-sounding rules did get delayed. But a few real deadlines are still on the calendar — one of them this week — and the bigger issue has nothing to do with any single law. Most small businesses that use AI every day still couldn’t produce a one-page policy if a customer, an insurer, or a regulator asked for one. Here’s what’s actually delayed, what isn’t, and what to do about that gap regardless of which law eventually lands.
What Actually Got Delayed in 2026
In 2026, two of the most-watched AI laws for small businesses both slipped their compliance dates. Colorado Governor Jared Polis signed SB 189 on May 14, 2026, pushing the state’s AI Act from a June 30, 2026 deadline to January 1, 2027 — while stripping out its duty-of-care and impact-assessment requirements in favor of a narrower disclosure rule (Troutman Pepper, “Colorado Attorney General Delays Enforcement of Colorado AI Act,” April 2026; Clark Hill, 2026). That was the second delay: the law had already moved once, from its original February 1, 2026 start date, when Polis signed SB 25B-004 in August 2025.
Days earlier, on May 7, 2026, EU lawmakers reached political agreement to delay enforcement of the AI Act’s high-risk system rules by roughly 16 months — from August 2026 to December 2027 — as part of a broader simplification package aimed partly at easing the burden on smaller companies (Holland & Knight, “U.S. Companies Face EU AI Act’s Possible August 2026 Compliance Deadline,” April 2026; Travers Smith, 2026). In both cases, regulators cited the same concern: the original requirements — risk assessments, algorithmic discrimination audits, deployer reporting — were built for enterprises with compliance teams, not a five-person shop running a chatbot.
What Didn’t Get Delayed — and What’s Due This Week
Not every AI compliance date moved. The EU AI Act’s ban on manipulative and social-scoring AI practices has applied since February 2, 2025, and obligations for general-purpose AI model providers have applied since August 2, 2025 — neither was touched by May’s delay (DLA Piper, “Latest Wave of Obligations Under the EU AI Act Take Effect,” August 2025). The Act’s transparency rules, which require disclosure when someone is interacting with a chatbot or AI-generated content, are still on track for August 2, 2026 (Forbes, citing Intuit’s 2026 AI Impact Report, July 19, 2026).
Closer to home, the U.S. Federal Trade Commission’s public comment period on a proposed AI accuracy policy statement closes July 31, 2026 — a deadline landing this week for any business whose AI tools make factual claims about products or services (Forbes, July 19, 2026). Separately, 47 states have already enacted their own AI-generated media disclosure laws, each with different standards (Forbes, July 19, 2026). None of that got delayed by anything happening in Colorado or Brussels.
Why the Delays Don’t Actually Buy You Time
Regulatory delays don’t erase the risk the rules were written to catch. In 2026, 77% of small and mid-sized businesses use AI daily, based on Intuit’s AI Impact Report covering more than 34,000 U.S. small and mid-sized businesses — yet only 38% of organizations report having a formal, comprehensive AI policy, up from just 28% in 2025 (ISACA 2026 AI Pulse Poll, 3,400+ digital trust professionals surveyed).
Every delayed deadline gives a small business permission to keep waiting. But the exposure a policy is meant to catch — a chatbot promising something support can’t deliver, an employee pasting a client’s contract into a free AI tool — doesn’t pause just because a legislature did. We’ve covered the unauthorized-tool side of that risk in our guide to shadow AI and what it actually costs a business.
A delayed law isn’t a canceled risk. It’s just a risk with no one checking on it yet.
The 5-Item AI Governance Checklist That Doesn’t Depend on Any Deadline
Building a baseline AI governance habit doesn’t require a legal team or a compliance platform. For most small businesses, the real cost is a few days of staff time to set it up and a few hours a month to keep it current — not a line item on next year’s budget.
- AI tool inventory: list every AI tool actually in use, including the ones employees adopted on their own, not just the ones the company purchased
- A one-page usage policy: plain language on what’s approved, what data can never go into a public tool, and who signs off on a new one
- Vendor documentation: for each AI tool, keep a record of what it does with customer data — the same due diligence we cover in our guide to vetting an AI vendor
- Customer-facing disclosure: if a chatbot or AI-generated content ever talks to a customer, say so somewhere visible — this is exactly what the EU’s still-on-track transparency rule and most state disclosure laws require anyway
- A quarterly review: one recurring 30-minute check that the policy still matches what employees are actually using
Across the AI governance conversations we’ve had with clients heading into the second half of 2026, the gap is rarely a missing document. It’s not knowing which of the five or six AI tools already in use across the team is the one actually touching customer data — the inventory step above is where most businesses find out.
Getting Started
If you don’t know whether your business needs to worry about the EU AI Act, Colorado’s disclosure rule, or neither, that’s exactly the kind of gap our AI Strategy Consulting service is built to close — mapping which rules might realistically apply to you before you spend an afternoon reading legislation that doesn’t.
None of this is legal advice. For anything jurisdiction-specific — especially if you handle EU customer data or operate in a state with its own AI disclosure law — pair a lightweight governance review with your own counsel.
Want a plain-English read on where your business actually stands? A free AI audit with Aifyze walks through your current AI tools and flags the gaps in under an hour.
Frequently Asked Questions
Does the Colorado AI Act still apply to my small business?
In a narrower form. SB 189, signed May 14, 2026, delayed enforcement to January 1, 2027 and stripped out the original duty-of-care and impact-assessment requirements, replacing them with a narrower disclosure-focused rule. It’s worth a quick check against your business, but the compliance lift is now smaller than the original 2024 law envisioned.
Do I need to worry about the EU AI Act if I only operate in the U.S. or Canada?
Usually only if you deploy a high-risk AI system whose output is used by people in the EU, or you provide a general-purpose AI model. Most U.S. and Canadian small businesses fall outside that scope, but customer-facing AI disclosure is becoming standard practice anyway — 47 U.S. states already have their own AI-generated media laws (Forbes, July 19, 2026).
What is the FTC’s proposed AI accuracy policy statement?
It’s a Federal Trade Commission policy statement addressing misleading claims about AI accuracy in marketing and product claims. The public comment period closes July 31, 2026 (Forbes, July 19, 2026) — relevant for any business whose AI tools make factual claims to customers, even indirectly.
Do I actually need a written AI policy with a small team?
Yes, even at five or six people. Only 38% of organizations of any size have a formal AI policy today (ISACA 2026 AI Pulse Poll), which means most small businesses are already behind — and a one-page policy is the cheapest insurance available if a customer, insurer, or partner ever asks how AI is used in your business.
How long does it take to put a basic AI governance policy together?
For most small businesses, a few days of staff time to build the tool inventory and write the policy, then a few hours a month to maintain it. It doesn’t require outside compliance software or legal drafting for a first version.