Most roadmaps still treat compliance as a box at the end, something legal handles after the product is built. For AI in 2026, that instinct is doubly wrong, and for a reason that would surprise anyone who stopped following the news in 2024. The rules did not march steadily toward you. They lurched backward. And the duties they were supposed to impose stayed almost exactly where they were.

You do not need to become a lawyer. You need a current map, because the one from eighteen months ago is now misleading in ways that will cost you.

The statutes retreated

Start with what died. Canada’s Artificial Intelligence and Data Act, the centerpiece of Bill C-27, never became law: it died on the order paper when Parliament was prorogued on January 6, 2025, and Ottawa has since signaled it will not be revived as drafted. South of the border, one of the first acts of the new administration in January 2025 was to rescind the previous executive order on AI and replace it with one titled “Removing Barriers to American Leadership in Artificial Intelligence,” whose stated policy is to “sustain and enhance America’s global AI dominance.” Even the marquee state law softened: Colorado passed the first comprehensive US state AI act in 2024, then, weeks before it was due to take effect, amended it (SB 189, May 2026) to push the start to 2027 and remove the duty of care, the impact assessments, and the risk-management programs, leaving mostly disclosure. If your mental model is “regulation is tightening, brace for the clampdown,” the last eighteen months say otherwise.

The obligations did not

Here is the twist that matters for a roadmap. The statutes retreated, but the obligations migrated. They moved into two places that do not depend on a vote. The first is voluntary frameworks that have hardened into de facto standards. NIST’s AI Risk Management Framework, and its generative-AI profile (NIST AI 600-1, published July 2024), lay out a dozen risk areas and a long catalog of concrete actions; no one is forced to adopt them, and serious buyers increasingly expect them anyway. Canada’s answer to AIDA’s collapse has the same shape: a Voluntary Code of Conduct on Advanced Generative AI Systems, signed by dozens of companies, committing them to outcomes like accountability, transparency, and human oversight. The second place is extraterritorial law. The EU AI Act reaches any model placed on the EU market no matter where it was built, and it is not theoretical: its rules for general-purpose models began applying on August 2, 2025. The high-risk deadlines then moved the other way. In late June 2026 the Council gave the Digital Omnibus on AI its final approval, so the delay is now adopted law rather than a pending proposal: the main high-risk obligations (Annex III) apply from December 2, 2027 and the product-embedded rest from August 2, 2028, leaving mostly the transparency duties on the original 2026 date. The deadlines slid; the substance did not. For high-risk systems the Act still asks for the unglamorous list in full: risk assessment, documented datasets, activity logging, technical documentation, human oversight, and demonstrated robustness.

The statutes you could wait out. The paperwork you cannot, because it is now the price of selling into the strictest market you touch.

Why this is harder than a single law

A single binding statute is, in a strange way, the easy case: you read it, you comply, you wait for the deadline. What replaced it is messier. Obligations now arrive through procurement questionnaires, enterprise security reviews, the strictest jurisdiction you sell into, and whichever framework your largest customer decided to standardize on. There is no one deadline to manage, which means there is no moment when you are safely finished. The teams that struggle in this environment are not the ones with the most ambitious AI. They are the ones who read the headlines about deregulation, decided the pressure was off, and stopped keeping records.

What to do now

The cheap insurance has not changed, only its justification. Build the paperwork as you build the product: a short, living record of what each system does, what data it runs on, how you evaluate it, and where a human stays in the loop. Flag your high-impact uses early. Pick one framework, with NIST the safe default in North America, and keep your documentation in its shape, so you can answer a customer’s security review or an EU obligation without a fire drill. None of this slows a disciplined team down, because it is mostly writing down what you should know anyway. The only thing that changed is the reason: you are now doing it for durability and portability across a shifting landscape, not to satisfy one law that might not survive the next session of Parliament.