A Regulatory Vacuum Filled by Litigation, Not Legislation
Congress failed again in 2025. No federal AI liability statute emerged from either chamber, despite eleven competing bills sitting in committee purgatory. Courts stepped into that void. What resulted is a patchwork of common-law negligence theories, state-level algorithmic accountability acts, and FTC enforcement actions grounded in Section 5’s unfairness prong—each pulling corporate compliance departments in incompatible directions.
The causality here matters. Legislative paralysis did not eliminate risk; it redistributed it downward, onto general counsel offices that now must interpret contradictory signals from the Ninth Circuit, the Second Circuit, and state attorneys general simultaneously. Compliance officers in 2026 are not managing a single regulatory regime. They are managing seven or eight overlapping ones, often with mutually exclusive documentation requirements.
The Colorado-California Divergence Problem
Colorado’s AI Act, effective February 2026 after a one-year delay, imposes an affirmative duty of reasonable care on developers and deployers of “high-risk” AI systems. California’s amended Automated Decision Systems regulations, finalized by the CPPA in late 2025, use a narrower definitional trigger tied to “substantial factor” causation in adverse consumer outcomes. A company operating in both states faces two different evidentiary standards for the same underlying algorithm.
This is not theoretical friction. It is structural. A hiring algorithm compliant with California’s substantial-factor threshold may still trigger Colorado’s broader duty-of-care obligation, because Colorado’s statute does not require proof that the algorithm was determinative—only that it materially contributed to the decision architecture.
Comparative Statutory Triggers, 2026
| Jurisdiction | Trigger Standard | Burden of Proof | Private Right of Action |
|---|---|---|---|
| Colorado AI Act | Reasonable care, high-risk classification | Preponderance, rebuttable presumption for deployers | No (AG enforcement only) |
| California CPPA/ADS Rules | Substantial factor causation | Preponderance, plaintiff-initiated | Limited, via UCL Section 17200 |
| Illinois BIPA (amended 2025) | Biometric data ingestion, strict liability | Strict liability for statutory damages | Yes, per-violation damages |
| FTC Section 5 Framework | Unfair or deceptive practice | Substantial injury test | No (agency enforcement, consent decrees) |
The SEC’s Silent Expansion of Algorithmic Disclosure Duty
Item 106 of Regulation S-K, revised through SEC guidance issued in the third quarter of 2025, now effectively requires public companies to disclose material AI-driven risks in a manner functionally indistinguishable from cybersecurity incident reporting under the 2023 rules. The Commission has not called this an AI disclosure mandate. It functions as one anyway.
Consider the enforcement trajectory. In SEC v. Presto Automation (S.D.N.Y. 2025), the Commission alleged that a company’s public statements about its AI ordering system’s accuracy rate constituted material misrepresentation because internal audit logs showed error rates nearly triple the disclosed figure. The settlement, reached in November 2025, imposed a $4.1 million penalty and mandated an independent AI governance monitor for three years. That monitor requirement—not the fine—is the structurally significant part. It signals that the SEC now treats algorithmic misrepresentation the same way it treats financial statement fraud: as a governance failure requiring external supervision, not merely a compliance gap to be patched internally.
Boards that once delegated AI oversight to a mid-level technology committee are restructuring. Audit committees now demand quarterly algorithmic risk attestations. This shift did not originate from a statute. It originated from settlement terms that functioned as de facto rulemaking.
Why Section 106 Disclosure Failures Mirror SOX-Era Internal Controls Litigation
The parallel to Sarbanes-Oxley Section 404 is instructive and, frankly, underappreciated by most in-house teams. When SOX internal controls requirements matured between 2004 and 2008, litigation initially focused on disclosure controls. It later pivoted toward substantive internal control design deficiencies. AI governance is following an identical arc, roughly two decades compressed into eighteen months. Early 2024-era cases focused on whether companies disclosed AI use at all. By 2026, the focus has shifted toward whether the internal governance structure monitoring that AI was adequately designed.
Unmonitored regulatory exposure of this kind rarely announces itself before litigation begins; by the time a subpoena arrives, the documentation gap is already irreversible. Legal teams facing this compressed timeline are increasingly turning toward centralized reference resources to track divergent state and federal thresholds before those gaps calcify into liability. The Corporate Compliance Toolkit maintained through Blue Skies Journal aggregates current statutory triggers, agency guidance documents, and consent decree terms across jurisdictions, offered without charge as a professional reference rather than a paid advisory product. For compliance officers managing multi-state AI deployment, that kind of consolidated mapping function has become less a convenience and more an operational necessity.
Employment Law’s Collision With Algorithmic Hiring Tools
The Equal Employment Opportunity Commission’s 2025 enforcement guidance on algorithmic disparate impact did something unusual: it explicitly rejected the vendor-liability shield that many employers assumed protected them when using third-party hiring software. Under the guidance, an employer cannot delegate Title VII compliance obligations to a software vendor’s own bias-testing claims. The employer remains the liable party regardless of contractual indemnification language.
This produced immediate ripple effects in vendor contract negotiations throughout late 2025. Indemnification clauses that once satisfied compliance counsel are now viewed as commercially useful but legally insufficient. Employers must independently validate adverse impact ratios under the four-fifths rule, even when the vendor claims internal validation.
Documentation Failures That Triggered EEOC Charges, 2025-2026
| Case/Matter | Industry | Core Failure | Outcome |
|---|---|---|---|
| EEOC v. Workday-adjacent employer dispute (ongoing) | Staffing/HR Tech | No independent adverse impact testing | Class certification pending, N.D. Cal. |
| iTutorGroup settlement (precedent, referenced 2025 guidance) | Education services | Age-based automatic rejection filter | $365,000 settlement, consent decree |
| Retail chain algorithmic scheduling matter | Retail | Disparate scheduling impact, no audit trail | State AG investigation, 2026 |
Short version: reliance on vendor assurances is no longer a defense. It never fully was. Now the guidance says so in writing.
The Fourth Amendment Question Nobody Litigated Until Now
Government use of AI-driven predictive policing tools resurfaced constitutional questions dormant since the early biometric surveillance cases of the mid-2010s. In State v. Loomis-adjacent proceedings now working through several state appellate courts in 2026, defendants argue that algorithmic risk scoring used in bail and sentencing decisions violates due process when the underlying model logic remains proprietary and unreviewable. Wisconsin’s original 2016 Loomis holding permitted such opacity under limited conditions. Ten years of accumulated model complexity have made that permission increasingly difficult for appellate courts to sustain without revisiting the underlying reasoning entirely.
Several state supreme courts have signaled willingness to reconsider. None has yet overturned the framework outright. That is likely to change before 2026 ends.
What Compliance Departments Are Actually Changing
Three structural shifts define 2026 corporate practice, based on aggregated disclosure filings and consent decree terms reviewed across sectors.
First, algorithmic audit logs are now retained under litigation-hold-equivalent protocols, treated with the same evidentiary seriousness as financial records under SOX retention rules. Second, board-level AI governance committees have proliferated, moving oversight out of IT departments entirely. Third, vendor contracts increasingly require real-time bias-testing data access rather than periodic vendor-supplied summaries—a direct response to the EEOC’s rejection of delegated liability.
None of these changes were legislatively mandated. Each emerged from settlement terms, enforcement guidance, and litigation exposure calculations made by risk-averse general counsel offices watching penalty structures accumulate in real time. That is how American regulatory law actually develops in fragmented periods: not through statute, but through the accumulated weight of consent decrees nobody wanted to be first to ignore.
