Policy

Schellman Warns Firms Delaying AI Governance Fall Behind

As US states introduce over 1,500 AI bills in 2026, compliance expert Danny Manimbo warns that companies delaying AI governance until regulations clear up are risking their competitive edge.

Unite.AI1 day agoPolicy
Image: Unite.AI

The regulatory environment for artificial intelligence in the United States is shifting rapidly, making waiting for final rules a losing strategy for businesses. By the end of 2025, all 50 states had proposed at least one AI bill, with more than 145 enacted into law. The legislative push accelerated dramatically in 2026, when lawmakers across 45 states introduced over 1,500 additional AI-related bills. At the federal level, the Trump administration issued an executive order in June 2026 to establish a voluntary framework for collaborating with developers on frontier AI models to bolster cybersecurity.

This fragmented landscape means compliance targets are constantly moving. For example, Colorado lawmakers repealed and replaced their original AI Act before it even took effect, pivoting to a narrower law focused on disclosures and transparency for automated decision-making systems. According to Danny Manimbo, a managing principal at compliance firm Schellman, organizations cannot afford to wait for these state and federal laws to settle. Instead of reacting to individual pieces of legislation, companies must build flexible governance frameworks that can adapt to changing rules.

Commercial pressures are also outpacing formal legislation. Major enterprises are already demanding proof of AI governance during procurement. For instance, Microsoft's Supplier Security and Privacy Assurance (SSPA) Program now requires suppliers to provide certifications or concrete evidence of AI oversight. To establish a stable foundation amid this uncertainty, Manimbo recommends that organizations adopt recognized international standards, such as the ISO/IEC 42001 framework, which establishes consistent practices for risk management, accountability, and continuous improvement.

Implementing an effective operating model requires defining clear ownership, maintaining an inventory of AI systems, and establishing cross-functional committees. High-impact use cases, such as those involving sensitive data, hiring, or financial decisions, require more rigorous oversight than low-risk applications. By embedding these repeatable processes into daily operations, businesses can satisfy both evolving legal mandates and immediate customer expectations.

This is our own summary of reporting by Unite.AI

More in Policy