And that creates a rather interesting legal problem.
Legislatures are discovering that AI can write, draw, imitate voices, make decisions, generate evidence, screen job applicants, analyze medical information, produce legal briefs, create convincing fake images, and sometimes confidently announce things that are completely untrue.
Kinda like how CNN does business.
Naturally, governments have begun doing what governments traditionally do when technology outruns the law: They are writing laws and creating legislation. Whether those laws actually solve the problems they are intended to solve is another question entirely.
So, this week's Legal Myths Monday takes a look at fifteen common assumptions about AI and fifteen jurisdictions already attempting to answer them.
1. UTAH
Myth: “If I am talking to an AI, the law doesn't care whether I know it is a machine.”
Reality: Not necessarily.
Explanation
Utah was one of the earliest states to impose a specific disclosure requirement on certain uses of generative AI.
The Utah Artificial Intelligence Policy Act requires disclosure in certain regulated-occupation and consumer-protection contexts. A person using generative AI in connection with regulated services must disclose that the person is interacting with AI, including disclosure at the beginning of an oral exchange and before a written exchange.
The law does not mean every conversation with ChatGPT requires a flashing neon sign announcing, “THIS IS A ROBOT.” The obligation depends upon the statutory circumstances.
Related Authority:
Utah Artificial Intelligence Policy Act, Utah Code Ann. tit. 13, ch. 72 (2024).
What this authority is about:
Utah created an Office of Artificial Intelligence Policy and established a regulatory framework dealing with AI, including consumer protection, disclosure, regulatory mitigation, and an AI regulatory-learning laboratory.
How this authority is being applied: Utah's approach is notable because it attempts to regulate AI without simply banning it. The state created a regulatory-mitigation system through which qualifying AI developers can test systems under specified conditions while obtaining temporary relief from certain regulatory requirements.
Potential problem:
Disclosure rules sound simple until someone has to determine when disclosure is legally required, what counts as sufficient disclosure, and how much disclosure becomes so ubiquitous that consumers simply stop noticing it.
At some point, “You are interacting with AI” could become the digital equivalent of the 47-page terms-of-service agreement nobody reads.
Cheeky Reality Check:
Utah didn't outlaw the robot. It simply told the robot to introduce itself.
2. COLORADO
Myth: “If an AI system discriminates, the computer, not the company, is responsible.”
Reality: No. Colorado's law looks to the developer and deployer.
Explanation
Colorado's AI law addresses what happens when a high-risk AI system produces discriminatory outcomes.
The statute places duties on both developers and deployers and requires reasonable care concerning known or reasonably foreseeable risks of algorithmic discrimination.
Related Authority
Colo. Rev. Stat. §§ 6-1-1701 to -1707 (2024), as enacted by S.B. 24-205, Consumer Protections for Artificial Intelligence.
What this authority is about
Colorado's framework focuses particularly on high-risk AI systems used in consequential areas such as employment, financial services, housing, education, insurance, and other decisions affecting individuals.
Among other things, developers must provide information and documentation allowing deployers to conduct impact assessments, and developers must disclose certain known or reasonably foreseeable discriminatory risks.
How this authority is being applied
The principal operative provisions began taking effect in 2026. The law attempts to create a compliance structure rather than waiting for a discriminatory AI system to cause harm and then trying to determine who should have known what.
Potential problem
The difficult question is not necessarily whether discrimination is bad. Everyone agrees on that.
The difficult question is how much responsibility can realistically be assigned to a developer for an AI system after a third party deploys it in circumstances the developer did not anticipate?
The more expansive the liability standard becomes, the more developers may respond by restricting what their systems can do rather than making them more useful.
Cheeky Reality Check
The computer may make the decision but Colorado still knows where the developer lives.
3. CALIFORNIA
Myth: “California tried to regulate AI, so AI companies now have to get government permission before releasing a model.”
Reality: Not under California's enacted frontier-AI law.
Explanation
California's earlier attempt at sweeping frontier-model regulation became nationally controversial. But the law that ultimately took effect was SB 53, the Transparency in Frontier Artificial Intelligence Act.
It focuses heavily on transparency, safety frameworks, reporting, and whistleblower protections rather than requiring the government to approve every AI model before release.
Related Authority
Cal. Bus. & Prof. Code §§ 22757.10–22757.14 (2025).
What this authority is about
SB 53 requires qualifying frontier AI developers to establish and publish AI safety frameworks. Large frontier developers must address catastrophic-risk thresholds, mitigation measures, incident response, and other safety considerations.
The statute also creates reporting mechanisms and protections for covered employees who disclose qualifying safety concerns.
How this authority is being applied
The statute became effective January 1, 2026. Large frontier developers are required to publish their frameworks, and frontier developers have transparency-report obligations concerning new or substantially modified frontier models.
Potential problem
Transparency is useful only to the extent that the information disclosed is meaningful.
A 200-page safety document can technically provide transparency while still leaving an ordinary member of the public with absolutely no idea what the AI actually does.
Cheeky Reality Check
California didn't put a leash on the robot. It made the robot file paperwork explaining why it thinks it needs one.
4. ILLINOIS
Myth: “An employer can use AI to hire, fire, or promote people without telling them.”
Reality: Illinois says AI-assisted employment decisions remain subject to civil-rights law—and notice may be required.
Explanation
Illinois amended its Human Rights Act to specifically address AI in employment.
The statute prohibits employers from using AI in employment-related decisions when the use has the effect of subjecting employees to discrimination based upon protected classifications. It also requires notice to employees when AI is used for specified employment purposes.
Related Authority
775 Ill. Comp. Stat. 5/2-102(L) (2026); 775 Ill. Comp. Stat. 5/2-101(N)–(O).
What this authority is about
The Illinois law expressly defines artificial intelligence and generative AI and applies existing employment-discrimination principles to AI-assisted employment decisions.
How this authority is being applied
The provisions became effective January 1, 2026. The Illinois Department of Human Rights is responsible for adopting implementation rules concerning when notice is required and how that notice must be given.
Potential problem
AI can reproduce discrimination found in the data used to train or operate it. But the reverse problem also exists: a system designed to eliminate human subjectivity can itself become so complicated that an employer may have difficulty explaining exactly why a candidate was rejected.
That creates a familiar legal problem in a new technological costume: Who has to explain the decision when nobody (not even the employer) fully understands the model's reasoning?
Cheeky Reality Check
Illinois has effectively told employers: If the robot is going to reject the applicant, somebody better know why.
5. TENNESSEE
Myth: “Your voice cannot be stolen because a voice isn't your name or image.”
Reality: Tennessee says your voice can be legally protected as part of your identity.
Explanation
Traditional right-of-publicity laws generally focused on a person's name, image, likeness, or similar identifiers.
Generative AI changed the equation because a system can reproduce a person's voice without recording that person saying the new words.
Tennessee responded directly.
Related Authority
Tenn. Code Ann. §§ 47-25-1101 to -1108 (2024), Ensuring Likeness, Voice, and Image Security Act (ELVIS Act).
What this authority is about
The ELVIS Act expanded Tennessee's right-of-publicity protections to include a person's voice and specifically addresses AI-generated replicas.
How this authority is being applied
The statute provides remedies for unauthorized use of protected identity attributes, including AI-generated voice replicas.
Potential problem
The difficult line is between identity theft and artistic expression.
What happens when someone creates an obvious parody of a famous singer? What about commentary, satire, imitation, or an AI-generated character that merely sounds remarkably similar?
The statute contains exceptions and defenses, but the collision between publicity rights and free expression is likely to generate litigation.
Cheeky Reality Check
Apparently, in Tennessee, your voice now has a lawyer.
6. VIRGINIA
Myth: “If AI recommends a criminal sentence, the judge can simply rubber-stamp the recommendation.”
Reality: Virginia requires a human decision-maker.
Explanation
Virginia has specifically addressed AI-assisted criminal-justice decisions.
The law does not permit AI to become the judge, probation officer, or parole authority simply because a computer-generated recommendation looks mathematically impressive.
Related Authority
Va. Code Ann. § 19.2-11.14 (2025).
What this authority is about
The statute provides that decisions concerning pretrial detention or release, prosecution, adjudication, sentencing, probation, parole, correctional supervision, or rehabilitation must be made by the responsible human decision-maker.
AI may provide recommendations or predictions, but the ultimate decision must involve a human.
How this authority is being applied
The statute expressly permits AI-based recommendations while preserving the human decision-maker's authority and allowing challenges or objections permitted by law.
Potential problem
“Human in the loop” sounds reassuring.
But a human decision-maker who routinely accepts a computer's recommendation without meaningful independent consideration may produce little more than human-shaped rubber stamping.
The statute therefore solves the easy problem: keeping a human involved without necessarily answering the harder question: How much independent judgment must the human exercise?
Cheeky Reality Check
Virginia has made one thing clear: The robot may advise the judge but the robot does not get the gavel.
7. NEW JERSEY
Myth: “A deepfake is protected speech simply because nobody was physically impersonated.”
Reality: Not necessarily. New Jersey has criminalized specified deceptive AI-generated audio and visual media.
Explanation
New Jersey enacted legislation specifically addressing deceptive audio and visual media—commonly called deepfakes.
The statute distinguishes unlawful deceptive media from protected criticism, commentary, satire, parody, news reporting, teaching, scholarship, and research.
Related Authority
N.J. Stat. Ann. §§ 2C:21-17.7 to -17.8 (2025).
What this authority is about
The law establishes criminal and civil liability for specified production, solicitation, use, and dissemination of deceptive audio or visual media, particularly when connected to enumerated crimes or other unlawful purposes.
How this authority is being applied
The law became part of New Jersey's criminal and civil-law framework in 2025. It also expressly preserves protections for certain expressive uses and maintains federal § 230 protections for qualifying providers.
Potential problem
The statute must draw a line between a lie designed to deceive and a fake designed to communicate that it is fake.
That sounds easy until satire enters the room.
A realistic parody can be almost indistinguishable from a malicious deepfake, particularly when it is removed from its original context and reposted elsewhere.
Cheeky Reality Check
The law recognizes that a fake can be dangerous. It also recognizes that sometimes the joke is supposed to be fake.
Apparently even New Jersey wants the jury to know the difference.
8. TEXAS
Myth: “Texas has decided that regulating AI means regulating everything AI does.”
Reality: Texas took a more targeted approach.
Explanation
Texas's 2025 Responsible Artificial Intelligence Governance Act identifies specific prohibited uses rather than declaring AI itself unlawful.
Among other things, it addresses intentional manipulation of human behavior, government social scoring, certain biometric-data uses, unlawful discrimination, and certain political-viewpoint-related AI conduct.
Related Authority
Tex. Bus. & Com. Code ch. 551 (2025), Texas Responsible Artificial Intelligence Governance Act, enacted by H.B. 149.
What this authority is about
The legislation establishes substantive restrictions, creates an enforcement structure, establishes an AI council, and creates a regulatory sandbox allowing qualifying AI systems to be tested under controlled circumstances.
How this authority is being applied
The principal provisions took effect January 1, 2026.
The Texas approach is particularly interesting because the law combines restrictions with a regulatory sandbox intended to permit experimentation while temporarily reducing certain regulatory barriers.
Potential problem
Texas illustrates the problem with trying to regulate AI through a list of prohibited conduct: AI changes faster than statutory definitions.
By the time legislators identify “the thing we are worried about,” the technology may have already moved several versions beyond it.
Cheeky Reality Check
Texas didn't tell AI to get off the ranch. It built a fence around certain things AI isn't supposed to do and created a sandbox for the things nobody has figured out yet.
9. NEW YORK
Myth: “If a lawyer uses AI to prepare a legal filing, nobody has to know.”
Reality: New York has considered legislation that would require disclosure.
Explanation
New York Assembly Bill A9097 would require disclosure of generative-AI use to clients, criminal defendants, and courts.
Importantly, this is proposed legislation, not an enacted statewide rule.
Related Authority
N.Y. Assemb. A9097, 2025–2026 Reg. Sess.
What this authority is about
The bill would amend New York procedural law to require specified disclosures when lawyers use generative AI.
How this authority is being applied
As of September 2026, the bill remains in committee rather than being an enacted statewide requirement.
Nevertheless, the proposal demonstrates one direction lawmakers are considering: treating disclosure of AI use as part of professional transparency.
Potential problem
Disclosure can tell the client that AI was used.
It does not necessarily tell the client whether the lawyer actually verified what the AI produced.
Those are two very different things.
Cheeky Reality Check
Telling the court, “Yes, I used AI,” is transparency. Telling the court, “And yes, I actually read what it wrote,” is competence.
10. MARYLAND
Myth: “Government agencies can use AI however they want because the government is the one doing it.”
Reality: Maryland has imposed governance requirements on its own government.
Explanation
Maryland's AI Governance Act requires state agencies to inventory and assess their AI systems and establishes governmental oversight mechanisms.
Related Authority
Md. Code Ann., State Gov't § 3.5-801 et seq. (2024), enacted through S.B. 818, Chapter 496.
What this authority is about
The law establishes requirements concerning governmental AI inventories, assessments, policies, procedures, and oversight.
How this authority is being applied
Maryland maintains a public accounting of state AI use and has created a governance structure for state deployment.
The state has also continued adding AI-specific programs and oversight measures.
Potential problem
Government transparency creates a useful record—but also creates a logistical question:
Who audits the auditors?
If an agency uses an AI system to make recommendations, someone has to evaluate the system, the data, the vendor, the implementation, and the agency's use of the recommendation.
Eventually, the oversight apparatus can become almost as complicated as the technology it is supposed to oversee.
Cheeky Reality Check
Maryland's solution to government AI is apparently: “Sure, government can use the robot. But government has to keep receipts.”
11. EUROPEAN UNION
Myth: “The EU AI Act bans artificial intelligence.”
Reality: No. It regulates AI according to risk.
Explanation
The EU Artificial Intelligence Act is perhaps the most comprehensive AI regulatory framework currently operating.
It does not simply say “AI is illegal.”
Instead, it establishes categories of prohibited practices, general-purpose AI obligations, transparency requirements, and additional obligations for high-risk systems.
Related Authority
Regulation (EU) 2024/1689, 2024 O.J. (L 2024/1689).
What this authority is about
The AI Act prohibits specified AI practices regarded as presenting unacceptable risks, imposes obligations on providers of general-purpose AI models, establishes transparency requirements, and creates additional requirements for high-risk systems.
How this authority is being applied
The Act's provisions are being implemented in stages.
As of August 2, 2026, major portions of the framework—including enforcement powers and transparency obligations—have become applicable. Other high-risk provisions do not apply until later transition dates, including 2027 and 2028.
Potential problem
The EU model demonstrates the problem with comprehensive legislation:
The larger the regulatory framework becomes, the more difficult it becomes for businesses—particularly smaller businesses—to determine exactly which provisions apply to them.
And unlike software, legislation does not update itself when the next model arrives.
Cheeky Reality Check
The EU didn't outlaw AI. It gave AI a regulatory passport, customs inspection, luggage search, and several forms to complete before entering the terminal.
12. CHINA
Myth: “China has no meaningful AI regulation because AI developed too quickly for government regulation.”
Reality: China was regulating generative AI before many Western jurisdictions had enacted AI-specific statutes.
Explanation
China's regulatory model is significantly different from the risk-based European approach.
China has already established rules governing generative AI services offered to the public.
Related Authority
What this authority is about
The rules regulate publicly available generative AI services and impose requirements involving training data, intellectual property, personal information, content moderation, security, transparency, and labeling.
Providers must take measures concerning unlawful content and may face regulatory consequences for violations.
How this authority is being applied
The rules have been in force since August 2023 and operate alongside China's broader cybersecurity, data-security, and personal-information regimes.
Potential problem
A regulatory system that requires AI providers to control generated content creates an obvious technical problem:
Generative AI is probabilistic.
A rule can say “do not produce X.”
The machine still has to determine what X is.
The more expansive the prohibited-content category becomes, the more complicated moderation becomes—and the greater the possibility of both overblocking and underblocking.
Cheeky Reality Check
China solved one AI problem the old-fashioned way: It told the AI what it is allowed to say. The harder part is getting the AI to agree.
13. SINGAPORE
Myth: “Deepfakes become legal if the creator puts a disclaimer on them.”
Reality: A disclaimer can matter, but it is not a universal legal shield.
Explanation
Singapore has enacted legislation addressing digitally manipulated and AI-generated material in the context of online harms.
Its Online Safety (Relief and Accountability) Act specifically recognizes generative AI as a technology capable of producing realistic deceptive depictions.
Related Authority
Online Safety (Relief and Accountability) Act 2025 (Sing.).
What this authority is about
The statute addresses harmful online material and includes provisions dealing with realistic manipulated or generated depictions of individuals.
The statutory framework recognizes that labeling may affect whether a depiction is realistically deceptive to a reasonable person.
How this authority is being applied
The law is part of Singapore's broader online-safety framework, with provisions coming into operation according to commencement orders.
Potential problem
A label can reduce deception.
But it cannot necessarily undo the damage caused when millions of people see the image before they see the label or when the image is copied, cropped, reposted, or stripped of its original context.
Cheeky Reality Check
“AI-generated” may save the label but it doesn't necessarily save the reputation.
14. UNITED KINGDOM
Myth: “Britain has already enacted one giant AI law equivalent to the EU AI Act.”
Reality: The British approach has been considerably more fragmented—and continues to evolve.
Explanation
The United Kingdom has pursued AI regulation through existing regulators, sector-specific legislation, consultations, proposed bills, and targeted amendments rather than simply reproducing the EU's comprehensive AI Act.
One particularly important recent development concerns AI-generated intimate imagery.
Related Authority
Data (Use and Access) Act 2025, c. 18, § 138 (U.K.); Sexual Offences Act 2003 provisions concerning purported intimate images.
What this authority is about
The legislation creates offenses concerning the creation or requesting of purported intimate images of adults without consent or reasonable belief in consent. The statutory concept expressly encompasses images that appear to depict a person but are not authentic photographs or films of that person.
How this authority is being applied
The law provides a direct criminal-law response to one of the most obvious harmful uses of generative AI: creating realistic intimate images of people who never consented to their creation.
At the same time, the UK continues to examine broader questions involving AI and copyright, including AI training on copyrighted material.
Potential problem
The British approach demonstrates a different problem from the EU model. Instead of one comprehensive statute, regulation may emerge from numerous laws and regulators.
That can produce flexibility but also creates a legal scavenger hunt for businesses and citizens trying to determine which rule governs which AI activity.
Cheeky Reality Check
Britain apparently looked at the EU AI Act and said: “That's a lot of legislation. Let's distribute the fun.”
15. AUSTRALIA
Myth: “If AI regulation has not been enacted yet, Australia has no legal position on AI.”
Reality: Australia is building a regulatory framework while simultaneously wrestling with AI, copyright, data centers, and training data.
Explanation
Australia provides an excellent example of the problem you identified at the beginning of this article: legislation frequently arrives after the technology has already changed the legal landscape.
Australia has been developing mandatory AI guardrails while maintaining a voluntary AI Safety Standard and considering copyright reforms concerning AI training.
Related Authority
Australian Department of Industry, Science and Resources, Voluntary AI Safety Standard (2025); Australian Government, “AI in Australia's interests” (July 15, 2026); Copyright and AI consultation and 2026 government report.
What this authority is about
Australia's voluntary AI Safety Standard establishes ten guardrails involving accountability, risk management, transparency, testing, human oversight, and related safeguards.
The Australian government has also announced plans for a mandatory AI framework and standards.
Meanwhile, the government continues to confront the difficult copyright question: Can AI developers train models on copyrighted Australian material without permission or compensation?
How this authority is being applied—or will be applied
The voluntary standard currently provides a framework for organizations using AI.
The government has announced a future mandatory framework, while copyright policy remains under active development.
As of September 2026, Australia is also considering how copyright law should address AI training and whether creators should receive compensation for use of their works.
Potential problem
This may be the most fundamental AI-regulation problem of all:
The law is trying to regulate the training of machines that may have been trained before the law was written.
If lawmakers require permission for every piece of copyrighted material used in training, the administrative burden could be enormous.
If they create broad exceptions, creators may argue that the law has effectively converted their work into free raw material for AI companies.
And if they impose compensation mechanisms, someone has to determine who gets paid, how much, and for what contribution.
Cheeky Reality Check
Australia has discovered the ultimate AI question: Before you regulate what the machine learns, you have to figure out who owns the textbook.
Final Check
The great irony of AI regulation is that legislators are attempting to write permanent rules for a technology that may look completely different by the time the ink dries.
The goal of regulation may be entirely reasonable: protect people from discrimination, fraud, identity theft, manipulation, privacy violations, and other harms.
But legislation can also create compliance costs, conflicting obligations, jurisdictional fragmentation, overbroad restrictions, false confidence, and rules aimed at yesterday's technology.
In other words, government may eventually succeed in regulating AI. The question is whether AI will still be the same thing by the time government catches it.


