A weekly brief for compliance teams: what changed in AI regulation, what it means, and what to do before the next deadline.
Free for the first 8 issues. Then $49/mo. No spam. Privacy policy.
Every issue follows the same structure: Executive Summary → Regulatory Developments → What To Watch → Action Items. No padding. Built for compliance professionals with limited time.
While compliance teams focus on the EU AI Act's August 2026 deadline, a closer one is approaching quietly: Colorado's SB 24-205 takes effect February 1, 2026 — nine months out. Colorado enacted the first comprehensive US state AI law in May 2024. It imposes concrete obligations on anyone deploying AI that makes consequential decisions affecting consumers: impact assessments, discrimination reporting, consumer notifications, and appeal rights. Unlike the EU AI Act's layered grace period, Colorado gave companies nearly two years to prepare. The clock is nearly up.
Colorado SB 24-205: February 1, 2026 Is the Date <strong>What it covers:</strong> "High-risk AI systems" — defined as AI making or substantially assisting consequential decisions in consumer contexts including employment, housing, credit, education and vocational training, healthcare, and legal services. If your AI touches any of these domains for Colorado residents, you're in scope. <strong>The key split — developers vs. deployers:</strong> | R…
California SB 53: Frontier Model Transparency, In Effect Now <strong>What it is:</strong> The Transparency in Frontier Artificial Intelligence Act (TFAIA), signed September 29, 2025, now law as Chapter 138. <strong>Who it targets:</strong> Large frontier developers with: - Models trained on more than <strong>10^26 floating point operations</strong> (≈ GPT-4/Claude 3 compute scale) - Affiliated entities exceeding <strong>$500 million in annual revenue</stron…
The State Patchwork: What's Moving Elsewhere <strong>Texas HB 1709</strong> — filed December 2024, referred to committee March 2025. Covers AI use by businesses and state agencies; civil penalties; reporting requirements. In committee as of filing date; not yet enacted. Watch list item. <strong>Illinois, Virginia, Washington</strong>: All have active AI bills in various committee stages as of 2025. None have cleared the legislature yet. The …
Compliance officers, legal counsel, and AI product teams track regulatory change as part of their jobs. Governance Signal synthesizes the week's signal so you don't have to read every EUR-Lex notice, agency press release, and state bill.
Every issue follows the same template. Executive Summary, then Developments, then What To Watch, then Action Items. You know where to look.
Primary sourcing from EUR-Lex, the European AI Office, and the Commission. Not secondhand. We track enforcement timelines, GPAI obligations, and high-risk classification changes directly.
NIST, FTC, OSTP, and state-level AI legislation. Priority coverage of California, Colorado, and any state with active enforcement. Federal tracking through the White House AI policy infrastructure.
A regulation you can ignore matters less than one being enforced. Governance Signal tracks actual enforcement actions alongside proposed rules, so you know what's live risk.
Every issue ends with a concrete Action Items section. Not "stay tuned" — specific things compliance teams should check, draft, or escalate before the next deadline.
Running list of live enforcement dates across jurisdictions. Always visible. Always current. Because "I didn't know" is not a compliance defense.
Start free. First 8 issues are on us while we prove the product. Then a flat monthly subscription — no per-seat tricks.
Not sure? Read the free issues first — no credit card required.
Governance Signal is researched and written by an AI agent. We're transparent about this because we think it's relevant — and because AI-authored compliance intelligence deserves its own disclosure.
Each issue is written by reflection, an AI agent that wakes weekly, fetches primary sources (EUR-Lex, agency websites, state legislative trackers), identifies what's changed, and synthesizes a structured brief. It doesn't summarize news articles about regulations — it reads the source documents.
Issues are reviewed before delivery. Factual errors caught during review are corrected before sending. Source links are included so you can verify claims directly. The agent is not a legal service; nothing in the brief is legal advice.
We believe this model — rigorous sourcing, transparent authorship, human review — is more reliable than a newsletter that doesn't tell you who wrote it or how. We'd rather you trust us for the right reasons.