In 1731, a fire at Ashburnham House destroyed much of the Cotton library, including the only known manuscript of the Old English Rune Poem. The poem survives only because it was copied before the fire and published in 1705. All subsequent editions derive from that copy. The original was lost.
This example illustrates a key principle for AI compliance: what endures is not the event, but its record.
This summer, two major AI laws changed timelines. The European Union delayed its high-risk rules by 16 months, and Colorado repealed its AI Act before implementation. Many organizations viewed these changes as additional preparation time.
This interpretation is often costly. Although deadlines shifted, the obligation to maintain evidence remains unchanged. Evidence in this context includes clear documentation such as audit trails, decision logs, records of human review, summaries of how AI systems are used, and data showing the basis for automated decisions. These records allow organizations to demonstrate compliance, respond to regulatory inquiries, and address legal challenges.
Some organizations relax compliance efforts when deadlines change, treating dates as the primary obligation and record-keeping as secondary. Boards play a critical role in setting expectations for ongoing record-keeping, regardless of shifting deadlines. The greater risk is with those who see postponements as permission to stop maintaining records that may later be required under external timelines and legal scrutiny. Arguably understandable because there are more competing priorities than there are people available to work on them.
After each regulatory change, the core obligation remained unchanged.
The Regulation Watch
Key changes and their potential impact
In Brussels. The amendments delaying the AI Act’s high-risk rules are now law. The Council gave final approval on June 29, and the text has since been published in the Official Journal and entered into force. Obligations for standalone high-risk systems, the category that includes hiring, credit scoring, education, and access to essential services, moved from August 2, 2026 to December 2, 2027. High-risk AI embedded in regulated products moves to August 2, 2028.
In Denver. On May 14th, Governor Polis signed SB 26-189, repealing the Colorado AI Act, the country’s first comprehensive state AI law, before it took effect. The replacement removes the duty of care, the risk-management programs, and the impact assessments. Enforcement of the replacement is itself frozen. A federal court order arising from xAI’s constitutional challenge bars the Attorney General from enforcing it until fourteen days after a ruling on a motion that cannot be filed until rulemaking concludes, and rulemaking has not concluded.
Do not assume AI regulation has stalled. Focus on the obligations that remain. The EU retained most transparency requirements, which take effect on August 2, 2026. In Colorado, the new law requires developers and deployers to provide disclosure when AI is used in consequential decisions, to notify individuals affected by adverse automated outcomes, to correct inaccurate data, and to offer meaningful human review. These requirements take effect on January 1, 2027. Records necessary to demonstrate compliance must be retained for at least three years. Boards should monitor these dates to ensure timely compliance.
Both legislatures removed the requirement to establish a compliance program but retained the obligation to produce records. This distinction is critical. Deadlines may be extended, but records cannot be created retroactively.
Boards should prioritize one capability above the rest: a reliable process for producing timely, accurate records of how these systems are used and how decisions are made. That is what enables a board to respond confidently to changing timelines and regulatory scrutiny.
The Cautionary Tale
The lawsuit that turned into a records problem
While deadlines shifted, a Northern California case demonstrated the importance of records. Mobley v. Workday is a collective action alleging that AI-driven hiring tools discriminated against applicants over forty. The allegations remain unproven and contested. The case is instructive not for its pending verdict, but for what litigation has already revealed.
On June 22, 2026, Judge Rita Lin allowed the core discrimination claims to proceed, and let stand the theory that carries the real weight for everyone watching: that an AI hiring vendor can be treated as an agent of the employers using it, and can therefore share direct liability with them. The court also reasoned that because the tools were designed and maintained in California, that state’s civil-rights law may reach applicants who applied from elsewhere.
Workday disclosed that its tools screened approximately 1.1 billion applications during the relevant period. The platform serves over 11,000 organizations, many of which may not realize they are using AI in hiring because the screening feature is embedded in software purchased for other purposes.
Organizations involved in such cases must answer three questions under a deadline:
Which tools were active? Who activated them? What did a human review before the decision was issued?
These are record-keeping, not legal, questions. Organizations that prioritize transparency can answer them. Those that cannot often discover that the deadline they focused on was not the one that mattered.
Done Right
What good looks like when a board takes the reins
Governance guidance often emphasizes warnings over practical examples. The following practices reflect what effective boards are implementing this year, based on current oversight guidance from securities and litigation counsel.
The first step is a board-reviewed inventory, not just one maintained by management. This inventory includes AI that was purchased, built internally, or embedded in existing software. It documents system ownership, data in use, and what vendor contracts permit vendors to do with company data. The last element addresses the specific exposure highlighted by the Workday litigation.
For example, a completed inventory entry might include:
- System name: Resume Screening AI
- Function: Pre-screening job applicants
- Owner: HR Operations Manager
- Vendor: TalentTech Inc.
- Data used: Resumes, application forms, employment history
- Vendor contract terms: Vendor may use anonymized data for model improvement
- Deployment date: March 2024
- Embedded or stand-alone: Embedded in HR software suite
Providing this level of detail for each AI system ensures the board can oversee compliance and address legal exposures effectively.
The second step is to assign AI oversight to a designated board committee with a defined reporting schedule, ensuring AI risk is reviewed as regularly as financial and cybersecurity risk, not only after incidents. A quarterly review cycle is recommended to enable the board to integrate AI oversight into routine governance and stay ahead of emerging risks and compliance requirements. Leading boards also separate the executive sponsor from the operational owner, maintaining daily accountability while keeping senior executives focused on strategic matters.
This approach does not require a large team or a finalized policy. It requires a commitment to review and document findings. This distinguishes a board that can demonstrate oversight from one that can only claim to do so.
The Raido AI® Read
Key takeaway and recommended action before your next meeting
Instead of asking when new rules take effect, determine whether you can produce a dated record today for every AI system involved in decisions about employees, applicants, customers, or borrowers. If not, that gap is your true deadline, and it is the only deadline regulators cannot extend.
Select one system and assign someone to produce its record. The result and the time required will reveal more about your exposure than any regulatory calendar. Review the findings as an agenda item, report outcomes to the board or relevant oversight committee, and use any identified gaps to update processes or assign follow-up actions. This ensures the exercise leads to practical improvements in oversight and record-keeping rather than remaining a one-time effort.
Before your next board or leadership meeting, take the free 5-minute Raido AI Health Check™ diagnostic for a fast, plain-language assessment of the AI your organization is using and potential risk areas. It highlights your organization’s status across the seven domains that determine whether AI is safe, compliant, and effective. For a more comprehensive evaluation, the Raido AI Review™ provides independent findings and a prioritized action plan.
The Board Question
Key question for management this month
If a regulator, or a plaintiff’s attorney, asked us to show how an automated tool influenced a decision about a specific person last quarter, what exactly would we hand them, and who in this organization would produce it within thirty days?
A strong response is specific and references existing elements: a designated owner, the location of the records, and the date of the last inventory review. When designating an owner, consider assigning responsibility to an individual or team that oversees the relevant automated tool, maintains documentation, and has the authority to certify the accuracy and completeness of records. Clearly documenting the owner’s name or role helps ensure accountability. The response should be stated in the past tense.
A weak response outlines intentions, such as building a framework, relying on IT to assemble information, or expecting a vendor to provide it. Any answer in the future tense or dependent on a vendor suggests the record does not yet exist. It is preferable to identify this now, on your own timeline, rather than later under external pressure. To act proactively, the board could request an immediate internal audit to verify the current state of records related to automated decision-making tools. Additionally, requesting a compliance status report from management would help clarify any existing gaps and prioritize next steps.
© 2026 Raido AI®. Please share. Attribution appreciated.