California pulls its AI auditor regime forward by a year
Application rules for independent verification organisations are now due 1 May 2027 (from 1 January 2028), and the auditor registry 1 December 2027 (from 1 January 2029).
"Fifty states, fifty rulebooks. Luckily, dinosaurs have long memories."
— Regional Chief-Dino, US & Canada

Introducing Toto-Rex
A dinosaur lost his job to an algorithm, so he set out to understand it: the rules, the regulations, and just enough of the technology to follow them. Focused on the United States and Canada; the federal pivot, the fifty-state patchwork, the agencies and the courts, and Canada's privacy-led path; in plain English, from credible sources. Serious about the learning. Less serious about himself.
The newsletter is coming soon.
No technical background. No shortcuts. Just one word, one rule, and one small victory at a time, written down so you can walk the same path without the late nights and cold coffee.
This is that path, tidied up and shared. Welcome in.
AI news from verified outlets; the United States and Canada first: federal, state, provincial, the agencies and the courts.
Executive Order N-9-26, signed on 18 September 2026, tells the Government Operations Agency, working with the Office of Emergency Services and national experts, to recommend by 16 November how state AI safety law should change. On the list: independent verification organisations auditing frontier developers on site, third-party checking of the safety frameworks and transparency reports those developers already file, wider reporting of loss-of-control incidents, and an emergency shutoff whose effectiveness is independently verified. Nothing is required of any company yet. The order is a two-month policy process, and Sacramento is where most frontier developers live, so its answer will travel.
Read the Governor’s release →Application rules for independent verification organisations are now due 1 May 2027 (from 1 January 2028), and the auditor registry 1 December 2027 (from 1 January 2029).
Crisis protocols for suicide and self-harm, parental controls, notice when safety settings are switched off, and the first state requirement for independent child-safety audits before release.
SB 26-189 replaced the 2024 AI Act with a narrower transparency law: pre-use notices, adverse-outcome explanations and a right to human review, effective 1 January 2027.
The Responsible AI Governance Act bans a short list of intentional harms and rewards firms that follow the NIST framework.
SB 53 makes the largest model developers publish safety frameworks, report incidents and protect whistleblowers.
An executive order directs agencies to challenge state AI rules and tie the question to federal funding. No preemption is law yet.
A proposed ten-year freeze on state AI laws was stripped from the budget bill almost unanimously; the states are not standing down.
Training on lawfully bought books was fair use; keeping a library of pirated ones was not. Reported as the largest copyright settlement in US history.
Cert denied in Thaler v Perlmutter: US copyright protects human authorship, and a prompt alone is not enough.
Overstate what your AI can do and Section 5 still applies; a century-old statute, aimed at a very new claim.
The clearest AI-compliance checklist yet for banks, insurers and fintechs; built on the voluntary NIST RMF.
Digital replicas, human authorship and the training-data fair-use question; the government’s most careful thinking on AI and copyright.
Days after Anthropic’s move, the best-funded lab wants public money; and public markets bring quarterly disclosure.
Orbital datacentres jump from pitch deck to purchase order in the hunt for AI capacity.
A major label acquires the tech to trace whose music an AI was trained on; and who should get paid.
Frontier-model safety disclosures. New York’s answer to California’s SB 53, and proof the patchwork is thickening.
HB 3773 bars discriminatory hiring AI and ZIP-code proxies; on top of the state’s formidable biometric-privacy law.
Sell AI into Europe and its transparency rules follow the product; wherever your company sits.
Models name colours correctly in short lists, then deteriorate sharply as the task gets longer. Toto-Rex relates.
Headlines link to their original outlets; the one-line gists are Toto-Rex's own. Curated 22 September 2026; check the source for the latest.
Open a folder; the desk shows only what you need. Less scrolling, more finding.
The side rail and menus still reach everything; picking a link opens its folder for you.
Each item summarised by Toto-Rex, linked to its original source. US and Canada first: federal, state, provincial, the agencies and the courts.
How this works: every summary is Toto-Rex's own plain-English take, and each card links out to its original source so you can read it yourself. Nothing is reproduced here. Educational only, not legal advice — for your own situation, ask a suitably qualified professional.
Scope. This briefing covers AI compliance, regulation and policy for the United States and Canada — federal executive policy, the state patchwork, the sectoral agencies and the courts; and, for Canada, PIPEDA, Quebec's Law 25, the federal Directive on Automated Decision-Making and the Voluntary Code. The events radar (section 05, below) covers US, Canadian and online events from recognised hosts. It does not try to cover the EU, UK or Asia (see the sister editions), or sector rules that don't touch AI.
Sources. Credible, verifiable sources only: official texts (the Federal Register, NIST, state legislatures, court dockets), established US law firms, recognised legal press such as Bloomberg Law, and peer-reviewed academic journals. Every card links to its primary source.
Depth & timeline. Summaries are short by design; what a thing is and why it matters, then off you go to the original. Current as of 27 September 2026. There is no comprehensive federal AI statute; Texas's TRAIGA and California's SB 53 took effect 1 January 2026, and Colorado's replacement transparency law lands 1 January 2027.
Limitations. Toto-Rex is a dinosaur, not your lawyer. Summaries are his interpretation, they simplify, and the law moves fast; a federal preemption fight could yet reshape the whole map. Check the live source before you act, and take advice for your own circumstances.
Seven numbered stops, from an AI inventory to a running compliance calendar, then across the border into Canada; the fifty-state problem, made walkable. Each expands when you want the detail.
What this is: the path Toto-Rex actually walked to stand up an AI compliance program in the United States, in order; based on the official sources linked in each step, as at 1 July 2026. There is no federal AI statute to point at, so this is a program, not a form. Educational only, not legal advice — for your own setup, consult your lawyers.
Toto-Rex's note: one spreadsheet, one row per tool. If it isn't on the sheet, it doesn't exist; and if it decides something about a person, it gets a gold star and a lot more attention.
Toto-Rex's note: it is a strange country where the most important rulebook is one nobody must follow. He follows it anyway; it is the closest thing to being presumptively fine.
Toto-Rex's note: he keeps a US map with the states he serves shaded in. It looks like a weather chart. Some weeks it behaves like one.
Toto-Rex's note: he keeps a one-page privacy notice that actually matches what the tools do. The gap between the notice and the reality is exactly where the trouble lives.
Toto-Rex's note: ask which agency already regulates you. That is the one that regulates your AI now. The tool is new; the cop on the beat is not.
Toto-Rex's note: he keeps the whole calendar on one page taped above the desk. Compliance is not a mood. It is a recurring appointment.
Toto-Rex's note: if you already meet the EU AI Act and Colorado, Canada is a documentation exercise, not a rebuild. Map Law 25's automated-decision rights onto the explanation and appeal routes you built for the states, name a privacy officer for Quebec, and keep AIDA's ghost out of the roadmap.
Sources. Every date and duty above links to its official source; the Federal Register, NIST, state legislatures, the federal agencies and court dockets; last updated 1 July 2026.
Scope. US AI compliance for a company operating across state lines. Not covered: company formation, tax, employment contracts, and anything bespoke to your situation. For the UK and EU, or Asia, see the sister editions.
Limitations. Toto-Rex is a dinosaur, not your lawyer. This is education, not advice; the law moves fast and the preemption fight could change the picture — always check the linked source, and consult your own professionals before acting.
Pick who you are; the duties and rights change with the seat you sit in.
You are the consumer the state laws were written for. Scope: your rights under state privacy and AI laws; they vary by state, and most cost nothing to use.
Not legal advice. Rights and deadlines vary by state; for anything that matters, consult a lawyer or a legal-aid service.
You deploy other people's AI on your own staff and customers; and the accountability is yours, not the vendor's. Scope: state privacy and AI laws where your users are, plus your sector's agency rules.
Not legal advice. A starting checklist, not a compliance program; size it with your lawyers.
You make the thing; developer duties follow the product across state lines. Scope: state AI statutes, federal agency law, and the EU AI Act if your system or its output reaches the EU.
Not legal advice. Product classification and IP are exactly the questions to put to counsel early, in writing.
You process data or provide AI on other companies' instructions; cloud, SaaS, agencies, IT. Your customers push their duties down to you by contract. Scope: state privacy laws and your agreements.
Not legal advice. Your contract terms are lawyer territory by definition.
You operate across state lines; which means several rulebooks at once. Scope: every state where your users are.
Not legal advice. Multi-state mapping is genuinely fiddly; one workshop with counsel saves ten incident calls.
Your customers or data cross borders. Scope: US state law, the EU AI Act and the EU GDPR, all at once.
Not legal advice. Cross-border scoping is precisely where specialist advice earns its fee.
One more time, because it matters: everything on this desk is education, not legal advice — laws change, they differ by state, and your facts are yours alone. Consult your lawyers before you act. Toto-Rex will still be here when you get back.
Fresh AI uses in the wild; and the rule that walks in behind each one.
This week's front page is about who gets to make the rules; the quieter story is what the software has started to do: browse, book, pay, file. An agent that acts is a different animal from a chatbot that talks; and existing US law already has a view. There is no federal AI statute, but an agent's click is your click: what it buys, you bought; what it promises, you promised. The FTC treats a deceptive automated act as a deceptive act, and the states' consumer laws agree. Toto-Rex's working rule: give an agent the least access it needs, log every step it takes, and keep a human hand on anything that moves money or people. Autonomy transfers work. It never transfers responsibility.
— T.R., from the study corner
How this note works: each morning Toto-Rex picks one focus from the front page (finance, health, agents, hiring) and writes its compliance angle in plain English. The focus rotates; the discipline doesn't. Educational only, never legal advice.
Assistants now complete multi-step tasks (browsing, form-filling, booking) through "computer use" controls. Marvellous, and also a liability surface, because an agent's click is your click. The rule that follows: least privilege, full logs, and human sign-off wherever money moves; and the FTC's deception standard does not care that a machine did it.
Anthropic's research notesStroke and chest X-ray triage tools are cleared and deployed across US hospital systems, flagging urgent cases in minutes; and the FDA's published list of AI-enabled medical devices now runs past a thousand entries. The rule that follows: the FDA regulates medical AI as a device wherever the software meets the definition (Software as a Medical Device), demanding validation, human oversight and a predetermined plan for how the model may change.
FDA · AI-enabled devicesDriverless taxis now run commercially in Phoenix, San Francisco and a growing list of cities. The rule that follows: there is no single federal robotaxi statute. NHTSA sets vehicle-safety standards while each state writes its own testing and deployment rules, so the law changes at every state line. Federalism, at 35 mph.
NHTSA · automated vehiclesAgentic coding tools now draft whole features. The productivity is real, and so are the new risks: license contamination, secrets pasted into prompts, unreviewed changes shipping to production. The rule that follows: keep human review in the merge path, and lean on the NIST framework and the CISA/NSA joint guidance for secure AI.
CISA · secure AI guidanceApplications change weekly; the desk keeps only what is verifiably deployed, linked to its official source. Educational only; not legal advice, and never a product endorsement.
Markets, funding and the rules that referee them; refreshed daily.
OpenAI has confidentially filed for a stock-market listing, days after Anthropic's own move; the world's best-funded AI labs now want public money for the next generation of models and datacentres. For everyone else the prize is rarer than returns: quarterly disclosure. A listed lab must put revenue, risks and governance in writing where regulators, rivals and dinosaurs can read them.
Read it on TechCrunchThe defining money story of American AI is concrete and silicon: hundreds of billions in datacenter and chip commitments from OpenAI, Oracle, Microsoft, Google, Amazon and Meta. Capital expenditure, not model launches, is what shows up on the balance sheets; and the jobs, the power demand and the grid fights follow the money.
Reuters · AIThe Treasury's AI-in-financial-services framework translates the voluntary NIST AI Risk Management Framework into 230 concrete control objectives; the closest thing to a compliance checklist for banks, insurers and fintechs deploying AI. If you run AI in a regulated firm, this is your rulebook's front door.
US TreasuryNo single AI statute for banks: US financial regulators supervise AI through the rules they already have; the CFPB on fair lending, the SEC on disclosure and robo-advice conflicts, and the banking agencies on model risk (the SR 11-7 guidance). Existing law, pointed squarely at new tools.
SEC · on AIThe CFPB's circular is blunt: if an AI model denies someone credit, the lender still owes specific, accurate reasons under the Equal Credit Opportunity Act. “The algorithm decided” is not one of the permitted reasons. Model inventories for US lenders begin here.
CFPB · circularsToto-Rex's standing reminder: this desk reports the money; it does not manage yours. Nothing here is investment, legal or tax advice — markets move faster than dinosaurs, so verify at the source and consult your own advisers.
Where AI meets law, policy and product; straight from the boards that matter.
The federal government hires AI minds for model evaluations, standards and procurement. Security-cleared dinosaurs welcome.
The fastest-growing compliance title of the decade: AI inventories, impact assessments, NIST programs and vendor triage. The IAPP's AIGP is the badge on the door.
The states are the front line, and their attorneys general are staffing up to write and enforce the new rules. Public-interest pay, front-row seat.
The Bay Area and beyond: alignment, interpretability, policy and trust & safety; not just engineering.
eDiscovery, AI governance practices, innovation counsel: the firms are staffing the workflows the book's Part IV describes.
As NIST and ISO/IEC 42001 harden into audit criteria, someone has to test the controls. ISACA's AAIA is the emerging credential.
Toto-Rex re-pins this board every morning from the official sources linked; postings, salaries and closing dates change daily, so always verify on the board itself. No placement fees, no affiliations; he just likes seeing dinosaurs employed.
AI summits, conferences and seminars from credible hosts; across the US, Canada and online.
If you leave the study corner for one thing this year, make it this. The IAPP Global Privacy Summit is the largest gathering of privacy and AI-governance professionals in the world, held in the city where American AI policy is actually written. Thousands of practitioners, regulators and general counsel fill the convention center; and AI governance now runs through nearly every session. If you want to see how the fifty-state patchwork and the federal agencies fit together, this is the room where it gets explained.
Why this one, and why you can trust it: Toto-Rex took no fee, no ticket and no commission to name it; it is simply the most useful and most credible AI-and-privacy gathering on the American calendar, and the AIGP credential was born from the same body. Read on for the full radar below.
Official site & registrationDates, venues and prices change; check them out yourselves before you go. Anything free is marked.
Real cases, real settlements, one fictional lake; and your rights at every turn.
Pick a level of the system. Each opens with one featured overview — Toto-Rex's plain-English summary of how that level governs AI; then notes on the real cases, laws and rules beneath it: what actually happened, what the rules say, what a company should never do, and what you can do about it. Every piece states its scope and links its sources, and none of it is legal advice.
How to read these: the cases, fines and dates are real and each note links its sources so you can verify them yourself; please do. The lake, Nessie and Colin are entirely fictional, and clearly labelled as such. None of this is legal advice, and it does not create any professional relationship; for your own situation, consult your lawyers. Based on the sources as at 7 July 2026; the law moves quickly.
The library. These notes are the public face of Toto-Rex's AI Compliance Library; at version 6.1.1, 187 research documents (about 115,000 words): twelve deep jurisdiction packs (UK, EU, US, Singapore, Hong Kong, mainland China, India, Japan, South Korea, Brazil, Canada, Russia), an EU-27 implementation matrix, a US 50-state & D.C. index, a wider regional atlas, and the policy and evidence templates beneath them. Research cut-off: 13 July 2026.
How it is sourced. The English research edition records 431 unique official-source URLs across 1,160 citations and 2,610 internal links. The library is not re-cut every time this page changes: anything added after the cut-off carries its own last-updated date. Automated structural and citation checks are useful quality controls, but they are not legal or linguistic certification.
What it is not. The library's own label applies here too: general information and customisable templates — not legal advice or certification. English is the controlling edition; official legal texts and their authoritative language versions prevail.
Just enough of the technology to understand the compliance. No coding required.
Fourteen guided tracks from absolute beginner to specialist: step-by-step lessons, graded quizzes, four-depth study notes, flashcards; and a printable certificate when you pass. Every claim carries its source, and the dinosaur does the marking.
Certificates will be a paid option, launching soon.
Toto-Rex is not paid to feature any of these, and there are no affiliate links on this site. Listings point to each provider's official page; details, prices and dates change, so check before you enrol. Anything free is marked.
One term, in plain English. No maths. No jargon.
Toto-Rex's note: always check what an AI tells you against a proper source. Especially names, numbers, and anything you would put your own name to. It is the cheapest insurance you will ever buy.
8–12 terms from the full glossary, refreshed daily. Ignore spaces and hyphens; letters only. Toto-Rex is watching. Supportively.
Talks, interviews and podcasts; builders, regulators, researchers and critics, in their own words.
Opposition to AI is starting to unite America's political left and right. Physicist Max Tegmark, chair of the Future of Life Institute, makes the case against racing to replace human work; a clear snapshot of the public mood regulators are now answering to.
Watch on The Economist's channelThese are external shows Toto-Rex rates. Links go to each show's official page; specific episodes come and go, so browse for the guest you want.
Toto-Rex wants to try them all. Forgive him; he's a dinosaur, picking it up bone by bone.
Grouped by job. Listings link to each tool's official site; none of it is paid placement, and most have a free tier.
Rights, duties, penalties, dated agenda, operational practice and cross-border reach.
The two expert dossiers most relevant to this edition, the United States and Canada, are available here in compact English form. The interactive globe, all fourteen jurisdictions, treaties, comparative models and industry tracker remain in the Global edition.
Everything this site teaches, bound, sourced and indexed.
AI has arrived faster than the law that governs it; and in America that gap is filled not by one statute but by four forces at once: the White House, the states, the agencies and the courts. The book strips away the maths, the hype and the fear: federal policy, the fifty-state patchwork, the NIST framework and the copyright fights, in plain English, built around a practical six-factor framework you can run on any AI system; five factors that follow its life, and a sixth you hold against them all. Written for founders, general counsel, educators, regulators and the professionally curious.
"A working machine asks: who answers for me?". Like everything in the study corner, the book is education, not legal advice. It sets out the law, cases, news and studies as at September 2026, reminds you to check them against the primary sources, and then tells you what the current situation is.
A monthly-ish letter; he aims for once a month, study schedule permitting, and would rather skip an issue than send you filler. Toto-Rex writes it himself, between study sessions and waiting on deliveries. The developments that matter, what the new rules mean, and one tool worth a look. Plain English, no jargon, no commitment.
Sign-up opens soon.
Cheers. See you next month. Probably.
The real thing is still in the workshop.
Toto-Rex is coming to phones. The waitlist opens soon.
Short films, songs about AI and honest tool tests; serious learning, carried lightly.
No technical degree here, and no rush; just one exam at a time. All the new AI can feel overwhelming, and a touch of FOMO is only natural, but once you know what you're aiming for, it's far easier to find your way through. Your pace, your path.
“Who says a T-rex can't reach their toes?” — Toto-Rex, stretching
Everything above is the serious stuff. This is the cherry on top: useless facts, small joys, and a dinosaur with opinions.
He told everyone the "T" in T-Rex stands for Technology. We both know it stands for Tyrannosaurus.
A 25 cm dome of solid bone on its head, evolved for headbutting rivals. And, Toto-Rex suspects, recruitment software.
Roughly how long his lineage survived. He still cannot get a CV past an automated screening filter.
A healthy attitude to a backlog, or a coping mechanism. Possibly both.
Of the Scottish Highlands. Also named Nessie, she runs a flourishing marketing company on the shores of Loch Ness; and is entirely out of his league, which, he notes, has never stopped anyone on a dating app.
Distant relations, technically. They hang about a certain museum looking down on everyone, and they haven't kept up with a single development since the Cretaceous. He visits anyway. Family is family.
The one thing on this site that is not negotiable.
A machine can draft, sort, total and summarise. It cannot care, keep a promise, own a mistake, or read a room. That part of the work was never in the job description. It was always you.
So learn the tools and mind the rules. Then bring what no model can produce: taste, judgement, kindness, and the nerve to ask the obvious question.
“Whatever the algorithm decides, you've got me, buddy.”
Toto-Rex
“The difference between AI and a person is that a person can feel pain. Then again, what would I know? I’m just a dino boy who eats fish.”
Step away from the syllabus. The dinosaur plays a patient game.
He reads more than he lets on.
He may or may not read this. He is usually studying, or waiting on a delivery. But he reads more than he lets on, and he appreciates you stopping by.
The postbox opens soon.
Toto-Rex can make mistakes. Everything here is general information, not legal advice: check the primary source, and take advice from a qualified professional before you act.