Thought Leaders

Can You Defend What Your AI Just Did?

mm
Add Unite.AI to your preferred sources on Google

Regulatory Deadlines for AI Keep Slipping, but the Need for AI Accountability Remains 

For two years, the regulatory conversation around enterprise AI has been organized around deadlines. The EU AI Act’s high-risk provisions were set to take effect on August 2. Colorado’s first-in-the-nation AI law was going to take effect on June 30. Washington was finally going to settle the question of who gets to regulate what. 

So, are we seeing progress against those deadlines? Sort of. 

In the span of about six weeks this spring, the EU agreed to defer the Annex III high-risk obligations to December 2027, and product-embedded high-risk systems to August 2, 2028. In Colorado, a federal court order stopped the state attorney general from enforcing the original act, replacing it with a narrower notice-based framework effective January 1, 2027. On June 2, the White House signed an AI executive order that took a deliberately pro-innovation posture, favoring voluntary collaboration with frontier developers over any mandatory licensing or pre-clearance requirement for AI models. 

Slipping Timelines and the Illusion of Regulatory Relief

The important point for enterprises is that shifting deadlines have not made AI accountability disappear. In Europe, even as some high-risk requirements moved, obligations around transparency, AI literacy, synthetic content and enforcement continued to advance. Colorado tells a similar story: lawmakers stripped away some of the law’s most burdensome compliance requirements, but preserved the fundamentals like disclosing when AI is involved, explaining adverse decisions, correcting bad data and providing a path to human review.

That is a useful signal of where regulation may ultimately converge. Policymakers can disagree over impact assessments, licensing regimes and which level of government should set the rules. But the ability to explain what an AI system did, document how it reached an outcome and give people meaningful recourse is proving much harder to legislate away. A bank still needs to explain an AI-influenced lending decision. A hospital still needs a record of how an AI-assisted recommendation was reached. A company still needs to know what happens when an automated system produces an outcome it has to defend.

If anything, the growing availability of open models makes that responsibility more important. The more control an enterprise has over how and where a model runs, the harder it becomes to treat accountability as someone else’s problem. If an organization cannot reconstruct, explain and defend what its AI systems are doing, regulatory delays offer only temporary relief.

If you’re a Chief AI Officer, Head of Model Risk Management, or have other responsibilities pertaining to AI use within a regulated industry, and have lived through any other era of innovation and regulation, you know that the former always outpaces the latter – and real accountability is determined by what your organization does in deployment, absent or inclusive of regulatory requirements.  

The AI Trust-Verification Gap: Why Market Risk Outpaces Compliance

Accountability is defined by the decisions made without oversight and it compounds in both directions. Though enterprise AI accountability is often mistaken for a consequence-based concept invented by regulators, it is created the moment a company deploys, whether or not anyone has yet named an enforceable consequence. And deployment is accelerating far faster than any compliance calendar – fastest of all now that autonomous agents are moving into production, taking actions, touching data, and making decisions at a speed no human reviewer can match. Gartner expects 40% of enterprise applications to include task-specific AI agents by the end of this year, up from less than 5% in 2025.  

That’s why the most telling signal in enterprise AI right now isn’t coming from regulators – it’s coming out of boardrooms and showcased on the careers pages of enterprises across industries. Board-level oversight of AI has climbed 84% in public-company disclosures and Forrester projects that 60% of the Fortune 100 will appoint a dedicated head of AI governance this year. Morgan Stanley and BlackRock have started factoring AI governance maturity into how they value companies. None of that is a response to a statute. It’s a response to risk that companies already adopting AI are acknowledging in everything from how their business is managed and operated to their job postings.  

Stanford’s 2026 AI Index found that security and risk – not model quality or cost – is now the single biggest barrier to scaling agentic AI, cited by 62% of organizations and outranking technical limitations and regulatory uncertainty by a wide margin. That distance – between what a system does and what its owner can actually prove about it – is the AI trust-verification gap, and it does not close on a regulator’s timeline. 

The pattern of innovation outpacing regulation is the same pattern we saw with cloud adoption, the advent of encryption, and with the cybersecurity industry writ large over the last three decades – the media covers it, regulators acknowledge it, and every industry grapples with the real-world implications and unique scenarios as they move from reluctance to experimentation and ultimately to varying degrees of enterprise adoption. With cloud computing, AWS launched in 2006, and enterprises were migrating sensitive data and core systems for the better part of a decade before the compliance scaffolding caught up. FedRAMP didn’t arrive until 2011, the industry had to invent the “shared responsibility model” to assign accountability the contracts hadn’t, and GDPR didn’t put real teeth into data handling until 2018. Cybersecurity followed the same arc: PCI DSS wasn’t formalized until 2004, well after card data was already moving online; breach-notification law began with a single California statute in 2003 and remains a state-by-state patchwork today; and the SEC didn’t require companies to disclose material cyber incidents until 2023. In both cases the accountability was real long before the rule was, and it was the market, customers, auditors, insurers, and the occasional very public breach, that enforced it on the firms that pretended otherwise.

From Pilot Capability to Outcome Defensibility in Production

Speed and capability were what got AI into enterprise pilots and just like every other major tech innovation, that’s been out of necessity. But they are not enough to get AI into production inside highly regulated environments with complex data sets and workflows – banks, insurers, critical infrastructure, defense programs – environments where someone eventually has to put an AI-driven decision in front of a regulator, a board, or a plaintiff’s attorney and defend it. In those rooms, “the model is very capable” is not an accountable answer.  

That distinction has become the real dividing line, and more enterprises are realizing it’s an architecture problem before it’s a policy problem. You cannot audit a black box into accountability after the fact. Explainability, traceability, and a clear chain of ownership are either built into the system or they don’t exist and the organizations learning this the hard way are the ones that deployed first and asked about accountability second. Gartner predicts that by 2027, 40% of enterprises will have to demote or decommission autonomous agents specifically because of governance gaps they discovered only after something went wrong in production. 

The Klue breach from earlier this summer serves as a prime example that only grew more instructive as it unfolded. Klue is an AI-driven competitive-intelligence platform, and the attackers didn’t defeat sophisticated defenses, they used a single integration credential, issued in 2022 for a pilot that was later abandoned and never revoked, to authenticate into customers’ CRM connections and pull records through automated queries. What started as a handful of disclosures grew to implicate multiple companies. Even after the original attacker began cooperating, a second group emerged claiming the same stolen data and running its own extortion campaign.  

The exposure wasn’t a model failure or a clever zero-day; it was a trusted, automated access path that no one was actively accountable for, and one that kept generating consequences long after the incident was supposedly “resolved.” As enterprises wire AI and its agents into more of their systems, every one of those connections becomes the same question waiting to be asked: who owns it, who is watching it, and who answers for it when it moves faster than anyone can supervise? 

Regulators are moving dates precisely because of this underlying problem. How you make these systems legible, testable, and accountable is genuinely hard, and the standards and tooling aren’t fully baked. But that’s not a reason to wait, instead it’s the clearest possible signal of what must be prioritized immediately. The enterprises treating the extra runway as permission to delay will spend 2027 doing under duress what their competitors are doing right now by choice. 

The definition of success in enterprise AI deployment needs to shift from pilot capability to outcome defensibility. In practice, that means passing three tests on every decision path where AI is involved: a durable record of what the system did, an explanation a non-engineer can follow, and a route for the person affected to contest the result. That is not a framework anyone invented in a vendor deck but nearly line for line what survived Colorado’s deregulation. 

Asking whether AI is trustworthy in the abstract was a philosophical debate in 2025. Now and beyond, enterprises need to be able to answer the question of whether they can defend the outcomes AI delivers, and prove it every time to anyone who asks. 

The deadlines may be pushed out and more extensions may persist, but unlike regulators, the market, and the customers your business ultimately serves, don’t grant extensions or entertain excuses.  

Stefanos Poulis, PhD is Chief Technology Officer at Seekr. He is an AI innovator, scientist, and engineer. He has led teams by providing the vision and execution of AI technologies in search, NLP, conversational AI, and recommendation. He develops algorithms to help machines learn from humans.