AI policy and compliance

Regulation, content provenance and watermarking, and what they require of products. Every brief item about AI policy and compliance, newest first, each with its primary source.

Subscribe via RSS Updated · Oct 9, 2026

Where it stands

AI rules this week moved from what regulators require to how vendors enforce it themselves. On October 5 OpenAI set out how it will watermark generated text under EU rules; on October 8 Anthropic published a new Usage Policy (effective November 12) that folds fake accounts, fabricated news sites and influence operations into one deceptive-activity section, and the same day OpenAI disclosed disrupting two influence operations using false-front journalists and a think tank.

Requirements are getting more specific and landing at the product layer: outputs need provenance, hardware control needs an operator who can stop it and a safe state on disconnect, high-risk recommendations need a human in the loop and user notice, and region limits now follow ownership, not just where a company is registered.

What to watch next: enforcement cases once Anthropic's policy takes effect, when EU text watermark detection opens beyond researchers, and whether other vendors adopt similar hardware and ownership clauses.

My advice: manage vendors' usage policies as product requirements, with a pre-launch checklist (high-risk domain or not, hardware control or not, AI-generated content labeled, account identities real) that every new feature goes through.

Darius · Updated Oct 9, 2026

Timeline 3 items

  1. Oct 9 · Fri · 2 items

  2. Oct 6 · Tue · 1 item