Developers facing a patchwork of competing AI safety regulations

Policymakers are moving swiftly to regulate agentic AI, creating varying mandates across regions and leaving developers to figure out compliance. Experts explain how the industry can keep pace.

As policymakers race to regulate agentic AI, frontier developers face a patchwork of conflicting regulations and a compliance nightmare, requiring governance of a technology that operates across regions and borders.

The Kill Switch Act (HR 9917), currently pending in the U.S. House of Representatives, and Governor Newsom's Executive Order N-9-26 directing California to explore requiring AI developers to build emergency kill switches and submit to greater independent oversight, are only the latest -- and highest profile -- examples of lawmakers proposing technical modifications to AI models that many experts say do not align with operational realities.

The challenge for the global AI industry is that these two measures are far from the only requirements -- proposed or already enforced -- it must navigate.

Among U.S. federal and state initiatives, the AI Emergency Button Act was recently introduced in the Senate. Meanwhile, state-level action is accelerating: California sponsors a registry of AI state auditors; an Oregon executive order directs criteria for third-party reviews and contract kill switches; Illinois established an AI Cabinet to evaluate shutdown mechanisms; and Virginia launched a rapid-response AI Task Force.

On an international level, European Union AI Act requirements under Article 14 establish mandatory human oversight for high-risk AI, phasing in through 2027. China’s AI Safety and Governance Framework 2.0 mandates "circuit breakers" and "one-click control" for autonomous operations.

Meanwhile, South Korea’s AI Basic Act went into effect in January, and the U.K., Australia, Japan, Taiwan, and Vietnam have all introduced distinct safety controls.

Bhagwat Swaroop, CEO of software developer Sonatype, understands how so many regulations can quickly become ungovernable. "A mix of state laws is manageable if they aim for the same outcomes," he said. "What gets costly is states requiring conflicting technical measures."

As AI safety mandates move from theory to practice, tech experts tell TechTarget how organizations can comply and propose a path forward to set reasonable guardrails for advanced AI models.

Disparate AI safety mandates feel familiar

Enterprises have already had to align their ecosystems with well-intentioned policies that, nonetheless, set competing expectations across regions that no single organization could feasibly meet.

Swaroop recalled, "Security leaders have been through this before. When every state passed its own data breach notification law, companies didn't build 50 compliance programs. They built to the strictest standard and invested in controls that worked everywhere. AI is likely headed the same way, and California's 'floor, not a ceiling' framing says so out loud."

As AI developers consider how they will comply with new AI safety requirements coming online, they have found several useful frameworks to emulate within the AI community and in other industries.

"Some of the strongest guardrails may already exist in the regulatory frameworks governing specific industries," said Andreas Cleve, CEO and co-founder of Corti, a healthcare AI platform. "The FDA already has deep expertise in evaluating technologies based on their risks and intended use and should be capable of overseeing specific applications of AI in the market. Those frameworks can evolve to address AI without starting from scratch."

Sahil Agarwal, field AI security fellow at Anaconda and founder of Enkrypt AI, believes there is a workable middle ground in mandating specific outcomes like incident reporting and independent verification, "and leave the technical detail to standards like NIST's AI Risk Management Framework and OWASP's agentic guidance, which can update faster than law."

"I think the important thing is to focus on platforms that make it easy to follow good practices across implementation, observation and verification," added Albert Ziegler, head of AI at autonomous offensive security provider XBOW.

The need for continuous enforcement

As automated AI agents take on more autonomous workflows, security leaders argue that risk management must evolve alongside capability.

"We have spent enormous energy increasing the horsepower of AI," warned Hitesh Sheth, CEO and president of Vectra AI. "Now we must put equal energy into the braking system."

Experts express concern that any static regulation will fail to establish meaningful guardrails around advanced AI agents, noting that development is moving far too quickly and that systems will move beyond any scheduled certification exercises.

"Annual audits can't keep pace when models, tools and permissions change weekly," explained Agarwal. "A control that passed review in January can be bypassed by March."

"Enforcement is going to have to become much more continuous and evidence-based," said Sheth. "Regulators will increasingly want evidence that organizations evaluated the risk, tested the controls, monitored incidents and can demonstrate what happened when something went wrong."

He added that it's a good sign that California is exploring requirements for independent organizations to verify frontier AI companies' safety frameworks and regularly test whether an emergency shutoff would work. "That moves the conversation from companies saying their systems are safe toward demonstrating that the controls work."

The key to complying with emerging requirements, according to experts, is to focus on demonstrable risks and outcomes rather than technical characteristics that may change dramatically from one model generation to the next.

Where do AI developers go from here?

Regulation can establish a common floor for accountability while the AI industry can bring the technical expertise and speed required to keep controls relevant as technology changes. Independent oversight can help bridge the two by testing whether what companies say they are doing works.

With frontier AI companies acting on a global stage, the compliance question is, "Whose regulations?"   

Agarwal noted that the California requirements could effectively shape standards well beyond state borders. "California can't govern where a model is trained or served, but it can set conditions for doing business in the state," he said. "Global labs are likely to build systems that comply with the strictest rules they face, rather than try to maintain different standards across every market."

Richard Livingston is an editor for TechTarget Cybersecurity, covering news, trends and analysis. Livingston's professional background includes editorial positions in the national defense industry covering the U.S. Army Medical Department, as well as offensive and defensive cyber strategy for military and government audiences.