The AI Rulebook Is Being Written in Real Time — Here's Where Things Stand

AI Legislation

If you've been keeping half an eye on AI policy news lately, you might feel like you're trying to drink from a firehose. In the span of just a few weeks, California signed a landmark workplace AI law, Connecticut's sweeping AI transparency rules took effect, and the EU's AI Act moved into a new enforcement phase. Meanwhile, states across the U.S. are racing to fill a federal void — and the patchwork is getting complicated fast.

For AI creators on platforms like Sunporch, these changes aren't abstract legal theory. They touch the tools you use, the content you publish, and increasingly, the platforms you rely on. Let's break down what's actually happening.

California Just Banned the Robo Boss

The biggest headline of the past week came out of Sacramento. On September 30, 2026, Governor Gavin Newsom signed SB 947 — the No Robo Bosses Act of 2026 — a law that requires human oversight of artificial intelligence systems in the workplace to prevent abuses.

SB 947 bars California employers from relying solely on AI systems, known as automated decision-making systems, to fire or discipline workers. It also mandates human oversight and verification when employers use those systems to assist in termination and disciplinary decisions. It is the first such law in the nation.

Importantly, this isn't an AI ban. The law does not ban AI at work. Employers can still use software to score, rank, and flag staff. What changes is what must happen next: if a machine's output is the main basis for a firing or a disciplinary step, a human has to check it against other evidence, and the worker has to be told in writing.

Though the bill was signed on September 30, 2026, it won't be effective until July 1, 2027. That gives employers — and the broader AI industry — roughly nine months to figure out compliance. It was one of 13 AI bills Newsom signed that day.

For creative professionals, the lesson here is broader than employment law: regulators are zeroing in on automated consequential decisions — moments where AI output directly shapes someone's life without a human in the loop. Expect that scrutiny to expand beyond the workplace.

Connecticut's CART Act Is Now Live

The Connecticut Artificial Intelligence Responsibility and Transparency Act (CART Act) took effect October 1, 2026. This law is one of the most comprehensive state AI frameworks in the country and affects multiple industries simultaneously.

The CART Act includes transparency obligations on covered providers that generate "synthetic digital content," effective October 1, 2026. That's a direct hit for AI-generated media — images, video, audio, and text that's artificially produced. If your platform or the tools you use operate in Connecticut or serve Connecticut users, disclosure requirements now apply.

Connecticut passed the most comprehensive AI legislation in the 2026 session with CT SB 5, which included the creation of a regulatory sandbox, chatbot controls, and a study of independent verification organizations (certified third-party auditors). It also instituted transparency that requires developers to give deployers of an automated system any information required for a deployer to comply with the law.

In plain terms: it's not just enough to follow the rules yourself — under this framework, the companies building AI tools have obligations to help the businesses using them stay compliant, too. That's a notable shift in how liability flows through the AI supply chain.

The U.S. State Patchwork Is Accelerating

Connecticut and California aren't alone. The broader picture of U.S. AI regulation is a fast-moving mosaic. As of October 2026, automated decision-making laws and regulations have been enacted in cities and states across the country, including California, Colorado, Connecticut, and New York City.

Chatbot laws were enacted in Colorado, Connecticut, Georgia, Hawaii, Idaho, Iowa, Nebraska, Oregon, and Washington during 2026. Many of these focus on companion AI products — chatbots designed for emotional support or social interaction — and introduce specific protections for minors and disclosure requirements.

In total, at least 22 states, including Maryland, Minnesota, New York, Kentucky, Vermont, Texas, and Connecticut, have passed legislation that specifically addresses the use of AI by government agencies.

At the federal level, the picture is more fragmented. In June 2026, the Trump Administration issued Executive Order 14409 "Promoting Advanced Artificial Intelligence Innovation and Security," which included requirements for federal agencies to upgrade American systems for advanced AI. But a comprehensive federal AI law remains elusive. On March 20, 2026, the White House released a National Policy Framework for Artificial Intelligence, urging Congress to replace the state-law patchwork with a uniform federal approach — though no such federal law has passed.

The EU AI Act: Phased, Complex, and Now Actively Enforced

While the U.S. scrambles state by state, the European Union has been executing a phased rollout of its landmark AI Act. The picture here is nuanced — not everything kicked in at once, and not everything is as delayed as some headlines suggest.

As of August 2026, the European Commission and national authorities have begun enforcing applicable AI Act provisions. New transparency requirements under Article 50 also apply from August 2, 2026, while enforcement of obligations for general-purpose AI models is active.

However, the most demanding rules for high-risk AI systems got a significant reprieve. The Digital Omnibus was formally adopted as Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026, and entered into force on 27 July 2026. The timeline for many high-risk AI requirements has changed, with Annex III rules now scheduled to apply from December 2, 2027, and certain high-risk AI systems embedded in regulated products from August 2, 2028.

For AI creators whose work touches European audiences, the most immediately relevant rule is Article 50: core user-transparency rules under Article 50 — disclosing AI chatbots and synthetic media to users — are already in effect. If you're publishing AI-generated images, audio, or video for European audiences, labeling and disclosure aren't optional anymore.

The EU has now shifted its focus from AI legislation to AI Act implementation, with the EU AI Board meeting in September 2026 to discuss progress on implementation and wider developments in European and international AI policy.

What This Means for AI Creators

All of this activity might feel distant from the work of making AI art, music, or writing. But here's the through-line: transparency and human oversight are the two values animating nearly every significant AI law passed in 2026, on both sides of the Atlantic.

For creators, that means:

  • Disclosure is becoming the norm. Whether it's the EU's Article 50 or Connecticut's CART Act synthetic content rules, labeling AI-generated work is shifting from a courtesy to a legal requirement in more and more jurisdictions.
  • The tools you use carry obligations too. Under frameworks like the CART Act, the responsibility chain runs from AI developers to deployers to end users. Knowing what your tools are required to disclose matters.
  • The patchwork is real — and complex. There is no single rulebook yet. What's required in Connecticut differs from what's required in Texas, which differs from what's required in Germany. If you're publishing or selling across borders, you need to think about which rules apply.

None of this signals that AI creativity is under threat. Regulators aren't trying to ban AI-generated content — they're trying to ensure people know when they're encountering it, and that humans remain accountable for consequential decisions. For responsible creators, that's a reasonable bar to meet.

The rulebook is still being written. But it's being written fast.

Sources

ai policyai legislationeu ai actai regulationcreator rights