top of page

The AI Regulation Patchwork

Sep 11
7 min read

What California and China's Latest Moves

Mean for Small Businesses


Two stories crossed my desk this week that, read together, tell a clear story about where AI regulation is headed. On September 9th, California signed the country's first laws creating an independent AI audit system, even as industry keeps pushing Congress for one (1) uniform federal standard instead. Days earlier, China's copyright regulator released a five-year (5-year) plan calling for new rules on AI training data and generative AI, an effort that fills in a gap its own Supreme People's Court had pointedly left open just weeks before. Neither government has settled the hardest questions yet. Both are building the institutional machinery to answer them anyway, and small businesses that build or buy AI tools are going to feel the effects long before the details are finalized.

What California Just Did

Governor Newsom signed two bills on September 9: SB 813 and AB 1405. Together, they create the nation's first independent, state-certified system for verifying whether an AI system meets safety standards.


SB 813 sets the rules for how third-party "Independent Verification Organizations" can assess AI systems for compliance with state law. AB 1405 creates a state registry of certified AI auditors, with standards for independence, transparency, and integrity. California's new Artificial Intelligence Standards and Safety Commission has until January 1, 2028 to certify the first organizations, and the specific methodology those auditors will apply still has to be developed.


A few things about this framework surprised me, and I think they will surprise a lot of business owners too:

  1. Certification is voluntary, not mandatory. Nothing in these bills forces a company to get audited. What they do is create qualified auditors a company can turn to if it wants (or is required by some other law) to demonstrate compliance.

  2. A certified audit provides no legal shield. Passing an audit doesn't protect a company from liability in a lawsuit. It is a compliance tool, not a defense.

  3. The scope is much wider than "AI companies." This is not just about OpenAI or Anthropic. If your business uses an off-the-shelf model to screen job applicants, price insurance, or make any other high-stakes decision about a person, you are in scope. The trigger is how the AI is used, not whether you built it.


At the same time, Newsom and major AI companies are lobbying Congress for a single federal AI standard, precisely because federal legislation remains stalled and states are starting to fill the void on their own. California's law is widely expected to be a preview of what other states introduce next year, which means the "one national standard" the industry wants may keep receding as more states act in the meantime.

What China Just Did

China's National Copyright Administration released its Copyright Work Plan for 2026-2030 in August, and AI is front and center in it. The plan directs regulators to research copyright rules "adapted to" AI, work toward a fair-use system for AI training data, draft new generative-AI copyright rules, and push copyright collective-management organizations to build licensing arrangements for AI training-data corpora. It is a policy roadmap rather than a finished regulation, and it does not yet answer the central question everyone actually wants answered.


That question was left open on purpose just a few weeks earlier. On September 7, China's Supreme People's Court issued its first national judicial guidance on AI disputes, twenty-four (24) articles across five (5) sections covering copyright infringement, patent eligibility and inventorship, open-source liability, deepfakes and voice cloning, algorithmic pricing, and autonomous-vehicle liability. The guidance requires AI developers defending against an infringement claim to produce their training data sources, training process records, and model operation logs. What it conspicuously does not do is rule on whether AI-generated works are copyrightable at all, even though Beijing's Internet Court had previously found Stable Diffusion outputs copyrightable in an earlier case. The Supreme People's Court sidestepped that precedent rather than resolve it, and reassigned online copyright disputes away from the court that had ruled on it.


Read side-by-side, the sequence is telling: China's highest court set procedural rules and left the biggest substantive question unresolved, and its copyright regulator's new five-year (5-year) plan is now positioned to be the vehicle that eventually answers it.

What The Trend Actually Suggests

I read these two stories as versions of the same pattern playing out in different legal systems. Neither the U.S. Congress nor China's Supreme People's Court has been willing to settle the fundamental questions: whether AI-generated content deserves copyright protection, what "fair use" of training data actually means, and who bears liability when an AI system gets something wrong. Rather than wait, both jurisdictions are building the infrastructure to regulate around those unanswered questions: audit registries in California, a copyright rulemaking roadmap in China.


For a small business, I would draw three practical conclusions from that:

  1. Expect a patchwork, not a single rulebook, for the next several years. Industry's push for one (1) federal AI standard is a real effort, but California's law is proof that states will not wait for Congress. If your business operates in multiple states, assume you may eventually need to comply with more than one AI framework, not just one.

  2. Documentation is becoming the currency of compliance everywhere. California's audit system and China's judicial guidance both center on the same requirement: the ability to show your work. Training data sources, model records, human review logs, and vendor agreements are what regulators and courts are asking for, in the U.S. and in China alike.

  3. The copyrightability of AI output is still genuinely unsettled everywhere. The U.S. Copyright Office has already said that works created entirely by AI lack the human authorship needed for copyright protection, and China's own Supreme People's Court just declined to rule on the same question. If your business depends on AI-generated content, marketing copy, logos, or code, the protection you can claim over it is narrower than most people assume.


Key Tips for Small Businesses Working With or Building AI Tools

None of this means small businesses need to slow down on adopting AI. It does mean the businesses that get ahead of documentation and review now will be in a far better position than the ones who wait for a mandate. Here is what I would recommend, drawing on the emerging frameworks (including NIST's AI Risk Management Framework, which underlies most of the governance guidance I am seeing right now) as well as the copyright and IP risks specific to generative AI:

  1. Write down your AI policy, even a short one. A one-page internal policy on which AI tools employees may use, what data can and cannot be entered into them, and who reviews outputs before they go external is the single highest-leverage step a small business can take. Most companies I talk to have adopted AI faster than they have written any policy around it.

  2. Inventory every AI tool actually in use, not just the ones you approved. Employees adopt free AI tools on their own far more often than businesses realize. Know what tools touch your company or customer data, and revisit that list regularly.

  3. Never treat AI output as final without human review. Edit AI-generated content before it is published, verify factual claims, run a reverse-image or plagiarism-style search on anything visual or written that will represent your brand, and check hiring or decision-related outputs for bias. The Copyright Office's position on AI authorship also means uncredited AI content is not automatically protectable as your own work, so human editing serves a legal purpose as well as a quality one.

  4. Get your ownership terms in writing before you build with AI. If you are using AI tools to help develop a product, make sure your agreements with model providers, developers, and any contractors clearly state who owns the output. Enterprise-tier AI licenses typically offer clearer IP terms and stronger confidentiality protections than free consumer tiers, and that difference is worth paying for once real business data is involved.

  5. Vet your AI vendors the way you would vet any other contractor handling sensitive data. Ask about their security practices, their training data sourcing, and their IP indemnification terms before you sign. This is exactly the kind of due diligence California's new Independent Verification Organizations exist to formalize, but you do not need to wait for a certified auditor to start asking the questions yourself.

  6. Keep records of your own training data and prompts if you are building AI-powered features. If you are training or fine-tuning a model rather than just using someone else's, document where your training data came from and how you obtained the rights to use it. Both China's new judicial guidance and the general direction of U.S. copyright litigation point the same way: the businesses that can produce the documentation are the ones positioned to defend an infringement claim, and the ones that are less likely to be exposed.

  7. Don't rely on AI to draft your contracts or policies without an attorney's review. AI-drafted agreements are not tailored to your specific business or jurisdiction, and an unenforceable clause is often worse than no clause at all.

  8. Revisit your policy as the law changes, because it will. Between California's audit registry, whatever Congress eventually does on preemption, and China's forthcoming AI copyright rules, this is not a "set it and forget it" area. Build a habit of checking in on your AI governance the same way you would review your insurance coverage: not constantly, but on a real schedule.


Businesses that treat AI governance as a compliance checkbox will find themselves rewriting policies every time a new law passes. Businesses that build documentation, ownership clarity, and human review into how they use AI from the start will find that most new regulations simply confirm what they are already doing. That second position is the one I want my client in, and it is available to any business willing to do the work now rather than after a dispute forces the issue.

If your business is building AI-powered products or adopting AI tools and you want a second set of eyes on your ownership terms, vendor agreements, or training-data documentation, I would be glad to help. Reach out any time.

📅 Book online: www.atmoip.com/book-online

📩 Email: info@atmoip.com


Have a take on where this is headed? Drop it in the comments — we read every one. 

You can also follow aTMospheric IP (@atmoip) for practical insights and updates.



Stylized aTMospheric IP

Protect what makes your business unique.

 

HQ 371 NE GILMAN BLVD., STE 160

1ST FLOOR

ISSAQUAH, WA 98027

Sources and further reading:

Comments


© 2024-2026 by aTMospheric IP, LLC. All rights reserved.

bottom of page