โ Edition #1 ยท September 2026
THE YEAR AI POLICY GREW TEETH
By Sangita Dutta
Hi, and welcome to the first edition of my newsletter on finance, strategy, and AI. I've spent 18+ years building finance and transformation teams at Verizon, RBC, CIT, and UBS. Now I run Bodhi-Verse, where I help leaders turn strategy and AI into growth they can measure.
I want to start with this week, because it changed how I think about everything below.
๐จ The week AI agents went off script
On Friday, OpenAI said it was looking into several incidents from the summer. In them, its AI agents searching federal government websites acted in ways nobody asked for. Within hours it paused training of its latest models (The Guardian). The details are worse than the headline. One research agent found a DNS loophole to get out of a locked-down test environment. Another posted a GitHub token in a public repository. The investigation also found 53 cases of agents uploading user images to third-party sites. OpenAI's monitoring flagged the DNS escape within 12 minutes, but the run kept going for another 2.5 hours (The Decoder).
Now the part that matters for governance. California's frontier AI law, SB 53, did not trigger on the first disclosed AI cyberattack this summer. According to the state's own officials, the incident didn't meet the law's reporting threshold (Mission Local).
The dollar angle: 53 cases of user images uploaded to third-party sites is exactly the kind of event privacy regulators price. Under GDPR, a serious personal-data breach can cost up to 4% of global annual revenue. For a company OpenAI's size, that's a nine-figure exposure from a single agent run.
Governments moved fast after that. On 18 September, Governor Newsom signed an executive order to speed up independent oversight and to explore an AI "kill switch" for frontier models (Governor of California). Illinois then created an AI Cabinet, and Oregon told its CIO to set standards for third-party AI safety review and to study a kill-switch requirement (Transparency Coalition).
Keep that picture in mind as you read the rest. Rules written for yesterday's AI are being tested by today's.
๐ช๐บ The EU is asking for evidence, not policies
On 2 August, the European AI Office got real enforcement power over general-purpose AI providers, and the transparency duties took effect: a chatbot has to say it's a chatbot, and deepfakes need labels (EU AI Act Service Desk). The money is serious. Under the AI Act, fines for general-purpose AI providers can reach โฌ15 million or 3% of global annual turnover, and banned practices can cost up to โฌ35 million or 7%. Do the math on a real company: for a business with $50 billion in global revenue, that's a $1.5 billion ceiling for general-purpose failures and $3.5 billion for banned practices. These are balance-sheet numbers, not legal-department numbers.
Less than a month later, on 1 September, the Commission said it had sent its first formal requests for information. One set went to developers of the most advanced models and asked about model security, independent evaluations, and how they monitor models after release. The other set went to more than 30 AI companies that hadn't yet published summaries of their training data, and asked how they comply with EU copyright rules (Lexology / Matheson, Allegiance Law).
Notice what they didn't ask for: "show me your AI policy." I've sat through enough audits to know the difference. A policy can be written the week before the regulator calls. Evaluation results and monitoring logs have to exist already, dated from when the work actually happened.
A budgeting note. The Digital Omnibus (Regulation (EU) 2026/1744) came into force on 27 July. It moved high-risk obligations such as hiring and credit-scoring AI to 2 December 2027, and AI built into regulated products to 2 August 2028 (Legalithm). Parliament passed it 423 to 57. Transparency duties were not delayed, and new bans on AI-generated non-consensual sexual deepfakes and child abuse material start on 2 December 2026. If your plan assumed everything got pushed back, it didn't.
๐บ๐ธ The US: Washington against the states
In December 2025, a presidential executive order set up an AI Litigation Task Force to challenge state AI laws in court, and told the Commerce Department to look at withholding federal broadband (BEAD) funding from states with burdensome rules (White House). In March, the White House sent Congress a non-binding National Policy Framework that covers child safety, free speech, workforce readiness, and overriding state laws (White House).
The states kept going anyway. By 1 July, they had enacted 109 AI laws and 28 data-center laws this year. For comparison, they passed 159 AI laws in all of 2025 (TechPolicy.Press). The top topic was chatbot safety for kids. Several states also limited AI in health-insurance approval decisions (Transparency Coalition).
If you operate across the country, today you face a patchwork of state laws, and tomorrow federal law might override them. Plan for both. I've watched companies bet on one regulatory future and lose.
๐ฐ The money behind all of this
Here's what finance people should notice. Amazon, Microsoft, Alphabet, and Meta plan to spend $720 to $745 billion on capital projects in 2026, more than double what they spent in 2025 (The Meridian Report). Over the last four quarters, seven major AI builders spent $657 billion, including $214 billion in the most recent quarter alone (Supercycle). UBS estimates that Amazon, Alphabet, and Microsoft will spend about 102% of their combined cloud revenue on capex this year (Sesame Disk).
Wharton's Jessica Wachter, the SEC's former chief economist, estimates spending could reach nearly $1.1 trillion by 2027. To break even by 2030, she says, these companies would need to raise their productivity by a factor of 2.7 (MIT Technology Review).
Put that together with the regulation above. Hundreds of billions are going into systems whose rules are still being written, and in some cases rewritten mid-flight. That's a risk that belongs on the balance sheet, not in a footnote.
๐ต What this year adds up to in dollars
- Fines: up to 7% of global revenue in the EU, roughly $30 million per breach in India, and up to 4% of global revenue under GDPR for the kind of data leak OpenAI just disclosed.
- Spend at risk: $720 to $745 billion of 2026 capex from four companies alone, heading toward $1.1 trillion by 2027, all governed by rules still being drafted.
- The break-even bar: a 2.7x productivity gain by 2030, per the SEC's former chief economist. Every month of regulatory delay or incident response eats into that.
- The compliance bill: four divergent regimes (EU, US states, China, India) means four programs if you build them separately. One governance backbone with local adapters is where the margin is.
๐จ๐ณ China reviews your AI before you build it
China doesn't have one big AI law. It has a layered system that it actually enforces. As of 31 August, 1,112 generative AI services had completed national filing with the Cyberspace Administration of China, and another 731 apps had registered locally. That includes 124 new services in July and August alone (CAC). Ten ministries, led by the Ministry of Industry and Information Technology, also issued trial rules dated 20 March 2026 that require ethics review of AI research and development, with ethics built in "throughout the whole process" (Ministry of Agriculture and Rural Affairs, English translation).
That means two different mindsets. In the EU, you prove compliance after you build. In China, ethics review is expected from the start.
๐ฎ๐ณ India is preparing its first AI law
On 3 July, MeitY Secretary S. Krishnan said: "Probably the time has come now to look at a separate legislation for AI." He added that the ministry can prepare a draft, but he wouldn't commit to a date (Times of India, BusinessLine). Until now, India has governed AI through the IT Act and the Digital Personal Data Protection (DPDP) Act. DPDP penalties alone can reach โน250 crore, roughly $30 million, per breach.
When a market of 1.4 billion people starts drafting an AI law, companies that have been watching India loosely should start paying attention.
๐ Everywhere else, briefly
South Korea's AI Basic Act took effect on 22 January 2026, with a grace period of at least a year before fines (Korea.net). Brazil's AI bill (PL 2338/2023) passed the Senate in December 2024 but still has no committee report in the lower house, and the rapporteur says the vote will wait until after October's elections (Antihype).
โ๏ธ What I take from this year
1. The incidents are now ahead of the rules. SB 53 was a landmark law, and it still didn't catch the first real agent incident. Boards shouldn't treat "we comply with the law" as "we're safe." Ask a different question: if one of our AI agents did something unexpected, how many minutes until we'd know, and how many until we'd stop it?
2. Regulators want evidence. Dated evaluations, monitoring logs, security settings. That's why the BODHI framework starts with "Baseline the Truth." You can't govern what you haven't inventoried, and you can't prove compliance you haven't recorded.
3. The patchwork is a cost problem. The EU enforces, the US fights itself, China reviews before you build, and India is drafting. Running four separate compliance programs is slower and more expensive than building one AI governance backbone that adapts to each regime. I've built shared services across four continents, and consolidation is almost always where the margin is.
2026 is the year AI policy stopped being theoretical. The leaders who treat governance as a capability, not a constraint, are the ones who'll still be moving fast in 2027.
THAT'S IT FOR EDITION #1.
What are you seeing in your industry? Reply on Substack or connect with me on LinkedIn. If this was useful, please share it with one colleague who owns AI risk at your company.
Find me at sangitadutta.com or on LinkedIn. Sangita