US Firms Scramble for AI Audits as Regulators Close In
As the EU AI Act, FTC enforcement and federal guidance converge, American companies are building audit programs — fast, costly, and uneven.
As the EU AI Act, FTC enforcement and federal guidance converge, American companies are building audit programs — fast, costly, and uneven.

Illustration by IMF Alpha editorial · Reviewed by Pedro Marini
It feels familiar: compliance shoots to the top of the to-do list the moment regulators start circling. This time the focus is artificial intelligence — not just chatbots but the models hidden behind loan pricing, resume screening and ad targeting.
Regulatory pressure is coming from three directions. The European Union's AI Act, though European, reaches beyond borders: companies serving Europeans face mandated risk assessments, documentation and, for high-risk systems, independent audits. At home, the Federal Trade Commission plus guidance from NIST and the White House are pushing for more transparency and accountability, even if Congress has not yet produced a single nationwide law.
The predictable result: firms are building audit pipelines now. Retrofitting models after a regulator shows up is expensive and reputationally damaging.
Smaller firms and startups are improvising. Some add human review gates before outputs go public. Others limit deployments to narrower markets to avoid being classified as high risk. Creative workarounds — and not all of them pretty — are already cropping up.
Compliance is not free. The cycle looks a lot like post-2008 banking: an initial shock, then a whole industry of consultants, standards and recurring audit fees. For large tech vendors and cloud providers, compliance becomes an asset — they can spread the cost across customers and sell compliance-as-a-feature.
That, naturally, favors incumbents. Big platforms with deep legal and engineering teams will certify, document and audit faster than a two-year-old fintech. Well-intentioned rules could therefore widen the gap between giants and challengers. Which is ironic, and worth watching.
If you hold AI-heavy names, scan corporate disclosures and proxy statements for language about model governance, third-party audits and incident-response commitments.
Think Sarbanes-Oxley running into Basel. After a systemic shock, rulemakers demand transparency and standardized controls. But unlike banking rules that were narrowly technical and capital-focused, AI rules mix ethics, engineering and sectoral safety. That blend makes compliance messier and more subjective — and harder to audit with a single checklist.
What’s interesting is that small differences in drafting will matter a lot. One regulator’s definition of high risk could decide who survives.
Regulation rarely arrives neatly. Expect a messy patchwork of federal guidance, state proposals and sector-specific rules. The safe play is to prepare — not because every rule will be draconian, but because the cost of not documenting is immediate, visible and reputationally unforgiving.
Pedro Marini

From data marketplaces to GPU demand, a quiet supply shock in training data is shifting winners in the AI race — and not always in predictable ways.

From neural engines in phones to new edge silicon, on-device AI is reshaping hardware economics. Here’s who benefits, who doesn’t, and how investors should think about it.

Smartphones are running LLMs and fraud detection locally. That changes privacy, cost structures, and who controls financial data — fast, but messy.