If Software Screened You for a Job, Loan, or Apartment, 42 States Now Have Questions
Here's a sentence that should make any small business owner sit up straight: a solo investigator running fraud checks out of a home office can face AI-related obligations just as a company with 40,000 employees can — if they use AI to help decide who to trust and who to flag.
AI rules often turn on whether a system helps decide something that affects a real person's job, money, or legal standing — not simply on how big the company is. If your system does that, it may already fall within a state law's scope.
Most people hear "AI regulation" and picture a courtroom drama starring OpenAI, Google, and a Senate committee asking dumb questions about robots. That's the story we've all absorbed. It's also completely wrong for the businesses it's most likely to catch off guard.
The Myth: "That's a Big Tech Problem, Not My Problem"
Let's name the assumption directly, because it's the thing quietly setting up thousands of businesses for a bad surprise: the belief that AI compliance rules only apply if you're the one building the AI, or if you're a massive company using it at huge scale.
It's an understandable mistake. Every headline about AI law features a giant company's name. You never see a news story about a 12-person insurance agency getting flagged for its claims-screening software. So your brain does the normal thing — it files "AI regulation" under "not my category" and moves on.
Here's the problem with that filing system: the laws aren't written around who uses AI. They're written around what the AI is doing. This article is part of a series — start with Deepfake Crypto Scams What Comes Next.
How the Rules Actually Work — It's About the Decision, Not the Company
California and Colorado have both passed rules targeting what they call "consequential decisions" — AI-assisted decisions about lending, healthcare, housing, employment, insurance claims, and legal matters, according to JD Supra. Notice what's missing from that list: any mention of company size, revenue, or industry fame.
Texas jumped in too. Its new AI law, called TRAIGA, took effect January 1, 2026, and it requires businesses deploying AI to show "reasonable care" — including testing the system, documenting how it works, and being able to explain its role when required. That's not a Big Tech requirement. That's a requirement for anyone using AI to touch a person's outcome, full stop.
Under California's new rules for automated decision-making technology, if your AI helps decide something consequential about a person, you generally have to tell them ahead of time, let them opt out, and be ready to explain how the system reached its conclusion. Picture a small property management company using AI software to screen rental applicants for "risk." That company may have a set of legal obligations most people would assume only applies to a tech giant.
Here's where it gets interesting: the definition of "consequential" is deliberately broad. Regulators wrote it that way to cover decisions that can affect a person's opportunities, money, or legal standing. This time, the net can include fraud screening, resume filtering, credit decisions, and identity and facial-matching tools, where an AI system can influence a human judgment call about whether someone is who they claim to be.
Why "We'll Wait and See" Is the Most Expensive Plan Available
There's a second myth hiding inside the first one: the idea that since the rules are still "in flux" (different states, different definitions, no single federal law yet), the smart move is to wait until things settle down before doing anything.
Flip that logic around. Fragmented rules don't mean nothing applies to you right now. They mean several different somethings may already apply to you, depending on where your customers live and what your AI touches. Waiting doesn't dodge the obligation. It just delays when you find out about it — usually at the worst possible moment, like during a lawsuit or an audit. Previously in this series: That Familiar Face Promising You Money Only 0 1 Of Us Can Te.
Businesses should comply with applicable state laws rather than waiting for federal courts to resolve jurisdictional disputes. — Analysis reported by JD Supra
And this isn't hypothetical enforcement. Enforcement actions against companies deploying AI increased noticeably in 2025, and that 42-state attorney general coalition mentioned earlier is a signal that state law offices have identified AI-related violations as an enforcement concern, according to the JD Supra analysis. The gap between "the law is confusing" and "nobody's actually checking" has already closed.
Then there's the money problem. Compliance costs run roughly 17% on top of what a business already spends on its AI systems, per industry estimates. That sounds annoying but manageable — until you learn that reconstructing documentation for a system that's already running in production costs several times more than just writing it down as you build the thing, according to compliance research from Cloud Security Alliance. In other words, "later" isn't free. Later is the expensive version of "now."
The Bridge Closure Nobody Reads the Sign For
Think of it like a bridge that's scheduled to close for construction six months from now. The sign is posted today. Most drivers glance at it, shrug, and keep going — plenty of time, right? Then six months arrive, and suddenly every single driver who ignored the sign is trying to reroute at the same moment, on the same side streets, at rush hour. The people who planned their route in January are already across. Everyone else is stuck in the exact traffic jam they thought they'd avoided by "not worrying about it yet."
AI compliance deadlines work the same way. The businesses mapping out what their AI systems do today — what decisions they touch, who those decisions affect, whether a human can override them — are the ones who'll cross the deadline calmly. Everyone else will be scrambling to reconstruct answers about software that's already live, under a deadline, probably with a lawyer's meter running.
Why Smart People Get This Wrong
If you assumed AI law was a Big Tech issue, you weren't being careless. You were pattern-matching off the news, and the news genuinely does over-cover the giant companies because giant companies make better headlines than a regional insurance firm's claims software. Nobody writes a viral story about mid-size businesses quietly updating their vendor contracts. Up next: That Familiar Face Promising You Money Only 0 1 Of Us Can Te.
But regulators don't write law by headline logic. They write it by asking a much narrower, much more personal question: did an automated system meaningfully affect what happened to a real person? Job, loan, apartment, insurance payout, fraud flag, identity check — if AI touched that decision, the size of the company behind it may matter less than the decision's effect on that person.
What You Just Learned
- 🧠 The rules follow the decision, not the company size — a solo operator using AI for consequential decisions may face obligations similar to those of a huge firm.
- 🔬 "Consequential" is deliberately broad — it covers hiring, lending, insurance, housing, and identity checks, not just headline-grabbing tech products.
- 💡 Waiting costs more, not less — reconstructing documentation for a live system costs multiple times what it costs to record decisions as you build.
- 🧠 Enforcement is active, not theoretical — a 42-state attorney general coalition has signaled coordinated pressure on AI-related cases.
The Question That Actually Matters
Forget asking "does AI regulation apply to my industry?" That question sends you down a rabbit hole of state-by-state legal comparisons that changes every few months anyway. Ask this instead: where in my business does an automated system help decide something about a real person's outcome?
That single question — applied honestly — tells you where to start. If the answer includes hiring screens, fraud flags, claims processing, credit scoring, or identity verification (including facial matching), you may have obligations to map. The first step is identifying where the system affects an outcome and whether a human can review or override it.
AI regulation isn't a club membership for tech giants — it can be triggered by what a system decides about a person, not by the size of the company running it. If your AI touches hiring, lending, claims, or identity checks, start documenting what it does and who it affects.
So here's the reframe worth carrying out of this article: the next time you approve a fraud alert, get flagged for "review needed" on a loan, or have your face scanned to confirm you are who your ID says you are, ask yourself — not "is this company big enough to be regulated," but "can they actually explain how this decision got made about me?" If the answer feels shaky, that's not a hunch. That's the exact gap the new AI laws were built to close.
Ready for forensic-grade facial comparison?
Full forensic reports with detailed similarity scoring. Results in seconds.
Run My First SearchMore Education
3 Seconds of Your Kid's Voice Is All a Scammer Needs
A cloned voice can now fool the person who knows you best. Here's the exact science behind why your ears can't catch it anymore — and the one habit that can.
digital-forensicsThe Fake Call Sounds Exactly Like Mom. Listen for the Pauses Instead.
Researchers used Sir Michael Caine's voice to study what actually makes speech sound "real." Turns out it's not the sound at all — it's your habits.
digital-forensics10 Seconds of Your Voice Is All They Need to Call Your Mom for Money
You'll learn why a scammer only needs 10 seconds of your voice to fake it — and why the "trick" isn't the audio at all, it's the panic.
