Skip to main content Skip to main content
News / Industry Update

AI Transparency Rules Land on Both Sides of the Atlantic This Fortnight

· Source: FTC; Tech Policy Press; European Commission

For the last two years the question about AI regulation was when. Over the next two weeks it becomes now — on both sides of the Atlantic, and in two very different directions.

In the US: a comment clock and a preemption fight

The Federal Trade Commission's proposed policy statement on the "suppression of accuracy in artificial intelligence systems" is open for public comment until July 31, 2026. It sets out a theory under Section 5 of the FTC Act: an AI developer that steers a model's output away from an accurate answer — toward an undisclosed objective — without telling users could be engaged in deception.

The agency's two sitting commissioners, both Republicans, approved the notice on a 2-0 vote. Chairman Andrew Ferguson framed the effort plainly, saying the goal is to hear from businesses and consumers about "the subversion of AI systems for ideological ends."

The part drawing the most attention is not the accuracy theory itself but the preemption claim attached to it. The statement singles out Colorado's Artificial Intelligence Act as a law that could pressure developers to alter outputs to avoid disparate-impact liability, and argues that such a law is impliedly preempted where it conflicts with Section 5. That traces back to EO 14365, the December 2025 executive order that directed the FTC to clarify how its deception authority interacts with state AI rules.

The reactions: skeptical, from more than one side

The legal response has been fast and doubtful — including from quarters that favor light-touch regulation. Writing in Tech Policy Press, Andy Jung, associate counsel at the free-market think tank TechFreedom, argued the FTC "lacks sufficient authority to preempt state AI laws through a simple policy statement." He points to the courts' "presumption against preemption," the fact that Section 5 was deliberately written in general terms and does not occupy the field of consumer protection, and a procedural reality: a genuine preemption effort would require years of Administrative Procedure Act and Magnuson-Moss rulemaking, not a policy statement.

Practitioners have raised a second line of concern: the statement never defines where routine, disclosed safety fine-tuning — which nearly every developer already does — ends and prohibited "ideological steering" begins, leaving "accurate," "objective," and "ideological" to be applied case by case. Several note the novelty cuts against the FTC, since casting a state anti-discrimination requirement as a mandate to "deceive" inverts the usual consumer-protection frame.

Colorado, for its part, is not mounting a defense. Attorney General Philip Weiser — already skeptical of the law — had paused enforcement amid a separate lawsuit from xAI that the Justice Department joined, and the legislature has since repealed and replaced the Act with a narrower version that takes effect in January 2027. The state named in the FTC's statement is already in retreat.

In the EU: enforcement powers switch on

Four weeks after the FTC comment window closes, the European Union's machinery activates. On August 2, 2026, a first wave of the AI Act's Article 50 transparency obligations becomes enforceable: users must be told when they are talking to a chatbot, and deployers must disclose deepfakes and AI-manipulated content of public interest. (The related duty to machine-readably mark AI-generated output was pushed to December 2.) The same date hands the European AI Office its full penalty powers over general-purpose AI model providers — closing a first year in which those obligations existed on paper but could not be fined — with penalties reaching €15 million or 3% of global annual turnover.

The reaction there ran the other way, and it already reshaped the law. Under sustained pressure from industry over unpublished standards and compliance costs, the Digital Omnibus amendments — adopted by the European Parliament on June 16 — delayed the Act's high-risk obligations by roughly a year. But lawmakers deliberately left the transparency duties and the enforcement powers landing on August 2 untouched.

Two bets on the same problem

Both regimes are aimed at the same thing — whether users can trust that an AI system's output is what it appears to be — and betting opposite ways on how to get there. The US frames it as deception, enforced after the fact through existing law, with a deregulatory thrust that would clear away conflicting state rules. The EU writes the disclosure requirements into statute up front and attaches turnover-scaled fines.

What it means if you're just getting in

If you run a small or mid-sized business standing at the edge of this — researching your first AI-powered storefront, your first support chatbot, your first batch of AI-written product copy — half of this genuinely is not your fight. The FTC's deception theory and the preemption battle over it are pointed at the companies that build and steer the large models, not the businesses that use them.

The EU half is a different story, and it is easy to misread as somebody else's problem because it is happening in Brussels. It is not. The AI Act follows the customer, not the company: its obligations attach wherever an AI system's output is used in the EU, regardless of where the business behind it sits. If your storefront takes orders from Europe, you are in scope the same way GDPR pulled in American companies years ago — and the same way accessibility rules already reach a US site because of who visits it, not where it is hosted. From August 2, that means a concrete duty: when your site talks to customers through a chatbot, or shows them a deepfake or AI-manipulated image, you have to disclose it. That is not a reason to stay out of AI. It is a reason to build with tools whose behavior you actually understand, before the obligation arrives rather than after.

Which is the durable lesson under all of it. Strip away the jurisdictional fight and both regimes are enforcing one idea: an AI answer should be accurate, and someone should be able to say where it came from. For a business deciding what to build on, that is the question worth leading with — not "which model scores highest," but "can I trust this output, and can I show a customer why."

That question is the one Thistle Intelligence is built around. The platform turns messy information into answers you can trace back to their source; the quote service it feeds will not serve a line it cannot cite. We are not going to build your storefront. But if you are trying to work out how to bring AI into your business in a way you can stand behind, that is a conversation we are glad to have — and the kind of thing we will keep writing about here.

Sources: Federal Trade Commission · Tech Policy Press · StateScoop · The Colorado Sun · Sidley · European Commission

Stay ahead of the signal

Occasional notes on what we ship and what we're reading. No noise, unsubscribe anytime.