AI rules are slipping in the U.S., Europe and Brazil at once. In 2026, the buyer is becoming the regulator
A voluntary White House accord, a deferred EU timetable and a postponed Brazilian bill leave enterprises carrying more governance load. What buyers should demand from vendors, and from themselves.
Listen to this article · 6 min
AI-generated narration of the full article.

Look at the three markets La Madre writes for and the same thing is happening in each, for different reasons.
In the United States, the White House announced on September 29 an Accord on Super Intelligence signed by Google, Anthropic, Meta, OpenAI, xAI and NVIDIA. It recommends four layers of control for frontier developers: internal processes to monitor capabilities and alignment, a dedicated internal function overseeing them, an independent external auditor, and an independent board-level committee. It is short, written in “should” language, and has no enforcement mechanism, disclosure requirement or deadline. Supporters in the administration call it a practical approach with more substance than critics admit; critics in Congress argue that voluntary pledges are no substitute for binding rules.
In the European Union, this year’s Digital Omnibus amendment deferred the AI Act’s obligations for Annex III high-risk systems to December 2, 2027, and those for AI embedded in regulated products to August 2028. Transparency obligations under Article 50 still apply from August 2026.
In Brazil, PL 2338/2023, approved by the Senate in December 2024, remains in the Chamber. In August, its rapporteur said the vote would come after the October elections.
This is not a political argument, and we take no side in the debates behind any of these decisions. It is an operational observation. In all three markets, the binding rules that would force vendors to prove how their AI systems are controlled are arriving later than many companies planned for. Meanwhile, the systems are already in production.
Our thesis: the buyer becomes the regulator
Our view, and it is a view rather than a fact: when public rules slip, assurance moves into two places. Contracts, where buyers set the conditions vendors must prove. And internal controls, where companies govern their own use because nobody else will check it in time.
The evidence is already visible. This year’s agent incidents at OpenAI, Anthropic and Meta were disclosed voluntarily, on each company’s own timeline and format. Frameworks are being offered free to regulators because regulators have not finished their own, as EC-Council did with ADG 2.0. Banks such as JPMorganChase and Citi appear among the supporters of NVIDIA’s agent safety work. And procurement questionnaires are starting to ask about agents the way they ask about SSO and audit logs, which we predicted when we argued that every agent needs a file.
What buyers should ask vendors for
The Accord itself gives buyers a useful script. If frontier developers are committing to internal controls, an internal oversight function and independent auditors, enterprise customers can ask to see the results.
- The auditor’s report. Who audits the vendor’s controls, against what, and can you read the summary under NDA?
- Incident disclosure terms. How fast will the vendor tell you about a model behavior incident that could affect your deployment, and in what format? This year’s disclosures came weeks to months after the events.
- Change notification. How much notice before a model version changes or is retired? We called model retirement the new API deprecation; contracts should treat it that way.
- Evaluation evidence for your use, not only general benchmarks.
- A custody map: where prompts, outputs, sessions, memory and logs live, and for how long, as we argued in making custody the first question.
- Containment commitments for agents that execute code or call tools: what runs outside the model to stop a wrong action, a theme of our analysis of this year’s agent incidents.
What buyers should ask of themselves
The more interesting move is to apply the Accord’s four layers to your own company. They are a sensible design for any enterprise running agents with real permissions:
- Internal processes: inventory, evals, approvals
- A named function that owns them
- Independent check: internal audit or third party
- Board or risk committee oversight
Run by the business and ITIndependent of the people who build
The difference is that your version can produce evidence by design. A control that generates its own record, as we discussed in our analysis of EC-Council’s ADG 2.0, is one an internal auditor can actually test. And autonomy granted per action class, as in our ladder for earning agent autonomy, gives a board something concrete to oversee.
For U.S. companies, this is also a matter of where liability lands. With no federal statute setting the standard, the questions after an AI incident will be asked under existing law: consumer protection, sector rules, securities disclosure, contracts. A documented control program is the best answer to all of them.
What would prove this view wrong
If binding rules arrive on schedule in at least two of the three markets, with enforcement and disclosure duties on vendors, the burden would shift back toward regulators and the contract-centered model would matter less. Watch the Chamber’s vote on PL 2338 after the elections, any federal preemption moves in the U.S., and whether the EU timetable holds at December 2027.
The bottom line
Regulation will come, at different speeds in different places. Until it does, the most effective AI regulator a company has is its own procurement and control function. Ask vendors for evidence, apply the same four layers to yourself, and you will be ready for whichever rulebook arrives first.