Policy 11 min read

Technology Policy in 2026: Why the Rules Keep Changing

J

Jared Clark

August 26, 2026

Technology policy has become one of those subjects where the news moves faster than the analysis. A rule that felt settled in January can be reversed by March, delayed by June, and reinterpreted by August. That instability isn't an accident of a busy news cycle. It's a symptom of something deeper: nobody has actually decided who gets to govern the most consequential technology of our lifetimes. That fight is being conducted through executive orders, state legislatures, and standards bodies instead of through any single deliberate process.

That's worth sitting with before we get into the specifics. Technology policy isn't chaotic because the technology is confusing. It's chaotic because the authority over it is contested, and contested authority always looks like chaos from the outside.

What Is Technology Policy, Really?

Strip away the jargon and technology policy is just the set of rules, formal and informal, that decide who can build what, who has to disclose what, and who bears the cost when something goes wrong. That's true whether we're talking about social media, biotech, or artificial intelligence. What's changed in the last two years is the pace and the stakes. AI policy in particular has compressed a decade's worth of normal regulatory maturation into a couple of years, and the institutions writing the rules are still discovering what they're regulating while they write.

That's the honest starting point. Most technology policy conversations pretend the rule-writers understand the technology as well as the people building it. They mostly don't, and the smarter ones know it.

Why Everything Feels Like It's Moving At Once

Here's the current picture, and it's worth being specific because vague summaries are exactly what make this space feel more confusing than it is.

The European Union's AI Act, formally Regulation (EU) 2024/1689, entered into force on August 1, 2024 — but it didn't arrive all at once. It's rolling out in stages:

  • August 1, 2024 — the regulation enters into force.
  • February 2, 2025 — Article 5 prohibitions on "unacceptable risk" systems take effect, covering things like social scoring and certain biometric categorization.
  • August 2, 2025 — obligations for general-purpose AI models under Chapter V begin.
  • August 2, 2026 — most high-risk system requirements land.

That's a two-year rollout for a single regulation, and it's the most comprehensive AI law in the world right now.

The United States took a different path entirely:

  • October 2023 — President Biden signs Executive Order 14110, "Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence," the federal government's first real attempt at a governing framework.
  • January 23, 2025 — Executive Order 14179, "Removing Barriers to American Leadership in Artificial Intelligence," is signed, revoking EO 14110 outright.
  • July 23, 2025 — the White House releases "Winning the Race: America's AI Action Plan," reorienting federal policy around speed and deployment rather than the risk-management posture the prior administration had favored.

So within about eighteen months, the federal government's approach to AI didn't evolve. It reversed. That's not normal policy drift. Executive Order 14179 didn't refine the old framework, it deleted it, and that distinction matters more than most coverage gives it credit for.

Meanwhile, states didn't wait for Washington to settle anything. Colorado passed its AI Act, SB 24-205, with an original effective date of February 1, 2026, and lawmakers have already had to delay it once as the practical burden of implementation became clearer than the bill's drafters anticipated. California has moved on multiple fronts at once, layering disclosure and transparency requirements onto frontier model developers rather than waiting for a single comprehensive statute. The result is a patchwork where a company's obligations depend on where its users happen to live, which is a strange way to govern a technology that doesn't respect state lines.

And underneath all of it sits the NIST AI Risk Management Framework, released January 26, 2023, which remains voluntary but has become the de facto vocabulary that both regulators and companies use to describe risk, even when they disagree about what to do with it.

A Comparison: Four Frameworks, Four Philosophies

Seeing these side by side makes the divergence clearer than any narrative summary can.

Framework Governing Authority Approach Key Dates
EU AI Act (Reg. 2024/1689) European Union Binding, risk-tiered, phased In force Aug 1, 2024; prohibitions Feb 2, 2025; GPAI rules Aug 2, 2025; high-risk rules Aug 2, 2026
US Federal (EO 14179) Executive Branch Deregulatory, deployment-first Signed Jan 23, 2025; revoked EO 14110
Colorado AI Act (SB 24-205) State Legislature Binding, algorithmic discrimination focus Originally effective Feb 1, 2026; delayed
NIST AI RMF 1.0 Federal Standards Body Voluntary, vocabulary-setting Released Jan 26, 2023

What strikes me looking at this table is that none of these four are talking to each other. The EU is building a compliance regime. The US federal government is dismantling one. Colorado is trying to write state-level guardrails around a technology that mostly operates outside state borders. And NIST is quietly providing the shared language everyone else borrows without adopting the obligations behind it. That's not four versions of the same policy. It's four different theories of what technology policy is even for.

Who Is Actually Writing These Rules?

Here's a question worth asking plainly: when a technology policy debate lands in front of Congress, a state legislature, or a regulatory agency, who's actually supplying the language of the rule?

More often than people assume, it's the companies being regulated. That's not a conspiracy theory, it's just how technical policymaking works when the regulators don't have the in-house expertise to write rules about systems they don't build. The frontier labs show up with draft language, risk taxonomies, and safety commitments already prepared, and legislators without deep technical staff tend to adopt the framing that's handed to them.

I don't think this makes the resulting rules worthless. But it does mean the question "who benefits from this rule" deserves to be asked every time a technology policy story breaks, right alongside "does this rule actually address the risk." Those two questions don't always have the same answer, and when they diverge, that gap is the real story.

The Pattern Underneath the Headlines

If you zoom out from any single announcement, whether it's a new executive order, a state bill, or a corporate safety pledge, a pattern shows up. Every major actor in this space describes its own preferred posture as the responsible one. The deregulators call oversight an innovation tax. The regulators call deregulation reckless. The companies call their voluntary commitments proof they don't need binding rules at all. Nobody in that argument is lying exactly, but everybody is negotiating from self-interest while using the language of principle.

That's the pattern I keep coming back to: technology policy debates are rarely just about the technology. They're about who gets to hold the authority to decide what's acceptable, and the technology is the terrain the fight happens to be fought on. A recent stretch of AI rulemaking made this visible in miniature: several jurisdictions moved on AI rules within the same news cycle, and none of the announcements acknowledged that the others were happening.

What this means practically is that the pace of technology policy isn't going to slow down just because it's exhausting to track. The incentive structures pushing every actor to move fast, industry racing for market position, governments racing to look responsive, states racing to fill a vacuum the federal government leaves open, aren't going away. If anything, they're accelerating each other.

What This Means For How We Think, Not Just How We Comply

Most technology policy writing stops at the compliance question: what do you have to do, and by when. That matters, but I think there's a second question underneath it that gets less attention: what does it do to a person's ability to think clearly when the rules governing the tools they use change every few months, and the justification for each change is framed as obviously correct by whoever is making it?

Keeping your own judgment intact in an environment engineered to move faster than you can verify is one of the harder disciplines of living through this period. Technology policy is a good test case for that discipline, precisely because it's presented with so much confidence from every direction. The EU is confident its risk-tiered approach is the responsible model. The current US administration is confident that speed is itself the safety strategy. State legislators are confident their patchwork protects residents the federal government won't. All of that confidence is sincere, and most of it can't all be right at once.

In practice, that translates into three checks before acting on any technology policy announcement:

  • Read the primary text, not the press release. Match the announcement against the actual statute, order, or framework section it claims to implement.
  • Confirm the effective date, not the signing date. The EU AI Act alone carries four different dates depending on the obligation; treating "in force" as "in effect" is the most common compliance mistake in this space.
  • Ask who drafted the language. If a rule's vocabulary matches a company's own safety commitments or lobbying position, treat it as informative but not neutral.

I don't think the answer is cynicism about all of it. I think the answer is treating every technology policy claim, including the ones that sound reasonable, as a claim to be checked against its actual text and actual effective dates rather than against its press release. The gap between what a policy announces and what it actually requires, and when, is usually where the real information lives.

Where This Leaves Us

Technology policy right now looks less like a settled field and more like a live argument that different institutions are having in parallel, mostly without acknowledging that the others exist. The EU is building a compliance architecture years in advance. The US federal government reversed its own framework within a year of adopting it. States are filling the gap federal inaction leaves, unevenly and sometimes clumsily. And the vocabulary everyone borrows to talk about risk came from a voluntary standard nobody is required to follow.

I don't think that adds up to a story with a tidy resolution yet. What I'd rather leave you with is the question I keep returning to myself: when the next policy announcement lands, whose interests does the timing serve, and does the substance match the confidence it was delivered with? That question won't resolve the argument, but it's a better place to stand than waiting for someone in authority to tell you the argument is over.

Frequently Asked Questions

What is the difference between the EU AI Act and US AI policy? The EU AI Act, Regulation (EU) 2024/1689, is a binding law with phased, risk-tiered obligations rolling out through August 2026. US federal AI policy currently operates through executive order rather than statute, and it shifted from a risk-management posture under Executive Order 14110 to a deployment-first posture under Executive Order 14179, signed January 23, 2025.

Is the NIST AI Risk Management Framework mandatory? No. The NIST AI RMF 1.0, released January 26, 2023, is voluntary. It has become influential anyway because it supplies much of the shared vocabulary that regulators, companies, and auditors use to describe AI risk, even in jurisdictions where following it isn't required.

Why do state AI laws differ so much from each other? States are largely legislating in the absence of a comprehensive federal AI statute, so each one is building its own definitions, thresholds, and enforcement mechanisms independently. Colorado's SB 24-205 focuses on algorithmic discrimination in consequential decisions, while other states have taken narrower, disclosure-focused approaches. The result is a patchwork that companies operating nationally have to reconcile on their own.

Why does technology policy keep changing so quickly right now? Because the underlying authority to govern AI hasn't been settled, so every administration, legislature, and standards body is asserting its own framework rather than converging on one. Executive Order 14179's revocation of Executive Order 14110 within roughly fifteen months of the latter's signing is a clear example of how quickly federal posture can reverse rather than evolve.

Should companies wait for technology policy to stabilize before acting? The decision rule is simple: check whether the obligation comes from a binding statute or regulation with a fixed effective date, such as the EU AI Act's phased timeline or Colorado's SB 24-205. If it does, treat that date as real no matter how unsettled the broader debate looks, because enforcement doesn't wait for consensus. If the only obligation in play is a voluntary framework, like the NIST AI RMF, there's more room to wait and see which requirements get formalized before building out compliance infrastructure. The risk isn't guessing wrong on the politics; it's missing a hard deadline while waiting for a sense of stability this space isn't going to produce.

Last updated: 2026-08-26

J

Jared Clark

Founder, Prepare for AI

Jared Clark is the founder of Prepare for AI, a thought leadership platform exploring how AI transforms institutions, work, and society.