← The frontier feed · On the rules
On the rules

New rules are coming for AI. Here's the plain version.

An antique field-journal etching: a level brass balance scale on the dark seabed, lit by a small lantern.

In one breathRegulation is turning “we think it's fine” into “show the record.” The companies that make proof a habit will barely feel it.

If you use AI in anything that touches people — money, health, hiring, safety — the rules are changing. The EU AI Act is the big one, and its obligations have been phasing in since 2025, with more arriving through 2026. You don't need to be a lawyer to get the shape of it.

What it actually asks for

Strip away the legal language and it comes down to a few plain demands: know what your model is. Write it down. Track what changed. Keep the record. For the first time, evidence about your AI is required, not optional.

Notice what's new here. It isn't "make your AI perfect." It's <span class="vb-u">"be able to show your work."</span>

Why this is hard the old way

Most AI today enters production on a description — a paragraph nobody proved. When a regulator, or a customer's security team, asks "what is this model, and how do you know?", a paragraph isn't an answer. Scrambling to produce evidence after the fact — that's where the cost actually lives.

The routine version

It gets a lot cheaper if the evidence is produced as you go: a reading before you adopt a model, a record of what changed on each release, proof attached to each and kept in one place. Do that, and the compliance ask stops being a fire drill — the paper trail assembles itself.

That's the whole idea behind how this house works: produce the evidence a buyer or a regulator will ask for before they ask, in a form they can check for themselves.

The takeaway

The rules aren't asking you to be certain. They're asking you to be able to prove what you claim. Start treating proof as routine now, and the deadline is just another Tuesday.

<p class="vb-inline-cta">The longer argument for why this is a category, not a chore → <a href="/thesis">The thesis</a></p>

Provenance — verified in your browser

The bytes of this post were hashed in your browser and match the value bound to a public, dated commit. You did not have to trust us — you just re-checked.

content hash
c0f4ef665a05…184c1db0
sha256 of these bytes = signed content_sha256
git blob
3aa8b46fbe65…866789c3
equals `git hash-object` on the public file
signature
Ed25519 · key 1f9d…7cb
Vulcora signed this ledger entry
record
entry 13 · 2f76db0aca…2d2497
published 2026-07-27

Check it yourself, no code of ours required: git hash-object posts/home/new-rules-for-ai-plain-version.md in a clone of the public post repository must print the git blob above. This binding is tamper-evident, not tamper-proof — GitHub is a trusted third party, not a mathematical guarantee, and we would rather say so than imply something stronger.

One honest answer

Have an AI you're not sure about?

Send us its fingerprint — a short code taken from the file. The name can lie; the fingerprint can't.