Author: Team_Neuralwired

  • FinOps DevOps Integration 2026: Gartner Data Inside

    FinOps DevOps Integration 2026: Gartner Data Inside

    FinOps DevOps Integration Enterprise: 2026 Cost Gap
    Enterprise DevOps · FinOps

    FinOps DevOps Integration Enterprise: 2026 Cost Gap

    Engineering ships the feature. Finance reads the bill two months later. In 2026, that lag is finally getting expensive enough to fix.

    A platform team at a mid-size SaaS company spins up a new GPU cluster on a Friday to hit a launch deadline. Nobody flags the cost. Nobody has to, because the invoice won’t land until the next billing cycle, and by then the team has moved on to the next sprint. This is the gap that FinOps DevOps integration in the enterprise is built to close: the space between the moment engineers make a spending decision and the moment anyone with budget authority actually sees the consequence. In 2026, that gap is no longer a minor accounting nuisance. Cloud waste just rose for the first time in five years, AI workloads are burning budget faster than any team can track manually, and the organizations closing this loop are doing it by moving cost data into the tools engineers already use, not by adding another dashboard nobody opens.

    What FinOps DevOps integration actually means

    FinOps is not a cost-cutting mandate bolted onto engineering. The FinOps Foundation defines it as an operational framework and cultural practice that maximizes the business value of technology through data-driven collaboration between engineering, finance, and business teams. FinOps DevOps integration is the practical version of that idea: building cost visibility directly into the pipelines, pull requests, and deployment gates that DevOps teams already run, instead of asking engineers to check a separate finance dashboard after the fact.

    Put simply, DevOps optimizes for delivery speed. FinOps adds a financial-accountability layer on top of what DevOps ships, so the team building infrastructure can see, in near real time, what that infrastructure costs to run.

    Why 2026 is the inflection point

    Three forces converged over the past eighteen months to push this from “nice to have” to organizational priority. First, AI and GPU workloads introduced usage-based, token-metered billing that doesn’t map cleanly to the per-instance cost models most FinOps tooling was built around. Second, cloud waste reversed direction after years of gradual improvement. Third, the FinOps Foundation’s updated 2026 Framework formally expanded the discipline’s scope beyond public cloud into SaaS, licensing, private cloud, and data center spend, adding a new Executive Strategy Alignment capability in the process.

    Microsoft’s ongoing move away from the traditional Azure Enterprise Agreement structure is adding to the pressure on enterprise cost teams, though the scale of that shift is still being reported primarily through vendor and partner channels rather than Microsoft’s own licensing communications, so treat specific figures around it as directional rather than confirmed.

    Paul Nashawaty, principal analyst at theCUBE Research, framed the shift ahead of FinOps X 2026 in San Diego this way:

    “By 2026, more than 70% of enterprises will embed FinOps practices directly into application development workflows as AI-driven applications increase cloud consumption and complexity.” Paul Nashawaty, Principal Analyst, theCUBE Research · SiliconANGLE, May 26, 2026

    The numbers behind the accountability gap

    The FinOps Foundation’s State of FinOps 2026 report, published February 19, 2026 and drawing on 1,192 respondents representing more than $83 billion in combined annual cloud spend, is the clearest picture available of how fast the discipline’s scope has widened.

    Metric2026 figureSource
    IaaS/PaaS cloud spend wasted29% (up from 27% in 2025)Flexera 2026 State of the Cloud Report
    FinOps practitioners managing AI spend98% (up from 31% in 2024)FinOps Foundation, State of FinOps 2026
    FinOps teams managing SaaS spend90% (up from 65% in 2025)FinOps Foundation, State of FinOps 2026
    FinOps practices reporting into CTO/CIO78% (up 18 points since 2023)FinOps Foundation, via TechTarget
    Average GPU utilization23% (77% sits idle)Harness 2025, via SpendArk
    Organizations with chargeback/showback44%CNCF FinOps Survey 2024, via SpendArk
    Global public cloud spending for 2026 is projected at roughly $1.03 trillion by Forrester, a figure worth treating as one analyst firm’s estimate rather than an industry-wide consensus, since other research houses model the number differently depending on what they count as “cloud.” Even using the conservative end of published waste estimates, that puts wasted infrastructure spend somewhere in the hundreds of billions of dollars globally, which is the scale problem FinOps DevOps integration is trying to solve.

    Flagged for verification A widely circulated claim that “Gartner projects 60% of organizations will fail to control cloud spending without automated governance by 2028” appears repeatedly in vendor blog content but could not be traced to a primary Gartner press release. Gartner’s actual on-record prediction, published May 13, 2025, is that 25% of organizations will report significant cloud adoption dissatisfaction by 2028 due to unrealistic expectations, poor implementation, or uncontrolled costs. Use the verified 25% figure, not the uncredited 60% one.

    Why the disconnect persists

    Here’s the uncomfortable part: the gap isn’t mostly a tooling problem anymore. Research from Harness, reported by TechTarget, found that 52% of engineering leaders say the disconnect between FinOps and developers is directly causing wasted cloud spend, while 62% of developers say they actually want more control over and responsibility for the costs they generate. That’s not a motivation problem. It’s a structural one.

    Fifty-eight percent of respondents in SpendArk’s State of Cloud Waste 2026 report cite fear of production impact as the top reason they don’t act on cost-optimization recommendations, even when the data is sitting right in front of them. Nobody wants to be the engineer who rightsized a service and took down checkout at 2 a.m. Until cost decisions are baked into the same review process as everything else, “I’ll get to it” wins by default.

    This is close to a problem NeuralWired has covered before in a different context: our reporting on why Google’s DORA metrics are failing engineering teams found the same metric-gaming pattern. Teams optimize for what gets measured, not what actually matters, and a cost dashboard nobody is accountable to will get the same treatment a vanity DORA score gets: ignored until someone asks about it directly.

    The value reframe

    Not everyone in the field frames this as a cost problem at all. Tim Crawford, founder of AVOA and a longtime CIO strategic advisor, put it directly:

    “Value is far more valuable as a metric than cost.” Tim Crawford, Founder & CIO Strategic Advisor, AVOA · TechTarget, March 5, 2026
    That’s a genuinely useful corrective inside an article that’s mostly about waste. Chasing the lowest possible bill is easy and often counterproductive. Chasing the highest return per dollar spent is harder to measure but is the actual goal, and it’s the reason the FinOps Foundation keeps insisting the discipline isn’t primarily about cutting costs.

    The AI spend problem nobody built tooling for

    If there’s one number in this entire dataset that should get an engineering leader’s attention, it’s this: average GPU utilization across measured AI workloads sits at 23%, according to Harness data cited in SpendArk’s 2026 report. That means roughly three-quarters of provisioned GPU capacity is sitting idle at any given moment, on hardware that is dramatically more expensive per hour than the compute FinOps teams spent the last decade learning to optimize.

    The share of FinOps practitioners managing AI spend jumped from 31% in 2024 to 98% in 2026. That’s the fastest adoption curve the State of FinOps survey has recorded in its six-year history, and it happened because token-based, usage-metered AI billing simply doesn’t behave like the per-instance cloud costs most tooling and habits were built around. Shared training-run costs, in particular, are notoriously difficult to attribute back to a specific team or product line, which is exactly the kind of allocation problem that breaks a traditional chargeback model.

    We’ve written before about the flip side of this same AI cost pressure, in our coverage of why 70% of AI agent deployments fail. Uncontrolled GPU spend and failed agent rollouts are frequently the same underlying story: infrastructure provisioned ahead of a clear return, with nobody positioned to catch it until the project stalls or the bill arrives.

    The case against: does FinOps actually pay for itself?

    Not every credentialed voice in this space agrees that building a dedicated FinOps function is the right answer. Gartner analyst Lydia Leong has argued, in an analysis still widely cited in industry discussion despite dating to 2023, that many organizations conflate needing to manage cloud costs with needing an entirely new department to do it:

    “For many organizations, there is no reasonable ROI on FinOps, and certainly no sensible business case for building a FinOps team.” Lydia Leong, Analyst, Gartner · CloudPundit, March 31, 2023 (still cited in 2026 industry discussion)
    Her point, dated as the source is, still lands: traditional IT financial management practices can handle a meaningful chunk of this work without a new tooling stack or new job titles, and organizations that skip straight to “we need a FinOps team” sometimes end up with overhead that outpaces the savings.

    The data backs up some of that skepticism. InfoWorld reported that in some cases, a dollar invested in FinOps delivers only about 30 cents in realized savings, citing McKinsey research on why organizations struggle to capture value beyond a FinOps team’s immediate mandate. CloudZero-cited survey data goes further: 71% of cloud financial management teams doubt they’ll fully achieve their expected results, on time or at all.

    Diminishing returns, by the Foundation’s own admission Even the State of FinOps 2026 report acknowledges the easy wins are gone. Practitioners describe having “hit the big rocks of waste” and now facing a high volume of smaller opportunities that each require more effort to capture. Translation: the 20 to 40% savings figures vendors love to cite were real in 2020 to 2024. In 2026, expect smaller, harder-won gains.
    IBM FinOps expert Otto Hillenbrand offers a middle-ground read that’s worth holding onto: We are in the crawl phase of FinOps (ClearTechnologies, September 2025), arguing that most enterprises claiming mature practices are actually doing basic cost optimization without the cross-functional accountability the discipline is supposed to deliver.

    What’s actually closing the gap

    Set the skepticism aside for a moment, because there’s a real, measurable pattern in what’s working. The common thread across every organization that’s actually narrowing the accountability gap is the same: cost data moves into the tools engineers already use, instead of living in a dashboard that requires a separate login and a separate habit.

    • Cost-tagged tickets, not email reports. Teams that automatically generate cost-tagged tickets, routing rightsizing or scheduling recommendations directly into Jira or ServiceNow with one click, see three to four times higher action rates than teams relying on dashboard reviews.
    • Cost as a first-class engineering metric. “Cost per transaction” is increasingly tracked alongside latency and error rate, not as a separate finance concern.
    • Pre-merge cost annotations. Infrastructure-as-code pull requests increasingly carry cost-delta estimates before merge, not after the invoice.
    • Chargeback and showback. Still only at 44% adoption, but it’s the mechanism that actually closes the loop between who spends and who’s accountable.
    Organizations embedding cost gates directly into CI/CD report cloud waste reductions in the 20 to 40% range within six months, though as the diminishing-returns data above shows, that ceiling is getting harder to hit as the obvious waste gets cleared out. Forbes Technology Council’s reporting makes the incentive point explicit: without cost accountability reflected in team-level metrics, even the best visibility tooling struggles to change actual behavior. Dashboards inform. Incentives change behavior. Those are not the same thing, and conflating them is probably the single most common mistake in FinOps rollouts right now.


    FAQ: FinOps DevOps integration in 2026

    What is the difference between FinOps and DevOps?

    DevOps focuses on shortening the software delivery lifecycle through automation, testing, and deployment speed. FinOps adds a financial-accountability layer on top, tracking and optimizing the cost of the resources DevOps provisions. FinOps doesn’t replace DevOps; it extends DevOps principles into cost accountability for cloud resources.

    Why do enterprises need FinOps DevOps integration?

    Enterprises managing $10 million or more in annual cloud spend across AWS, Azure, and GCP routinely lose 20 to 40% of that spend to decisions nobody reviews until the bill arrives weeks later. Integration embeds cost visibility directly into CI/CD pipelines so waste gets caught before deployment, not after invoicing.

    What percentage of cloud spend is wasted in 2026?

    Flexera’s 2026 State of the Cloud Report found an estimated 29% of IaaS/PaaS cloud spend is wasted, up from 27% in 2025. It’s the first increase after five straight years of gradual improvement.

    How does AI spending affect FinOps in 2026?

    The share of FinOps practitioners managing AI spend jumped from 31% in 2024 to 98% in 2026, per the FinOps Foundation’s State of FinOps 2026 report. Average GPU utilization sits at just 23%, meaning most provisioned AI compute goes unused.

    Does FinOps actually save money?

    Results vary widely. Vendor case studies cite 20 to 40% cloud cost reductions, but independent reporting citing McKinsey research found some organizations realize only about 30 cents of savings per dollar invested in FinOps, largely because engineering teams often lack the incentives or data access to act on recommendations.

    Who owns FinOps in an enterprise, engineering or finance?

    Increasingly, engineering. 78% of FinOps practices now report into the CTO/CIO organization, up 18 percentage points since 2023, according to the FinOps Foundation’s State of FinOps 2026 report, reflecting a shift from finance-led reporting to an engineering-embedded discipline.


    What to watch next

    The organizational and structural pieces of FinOps DevOps integration are genuinely maturing this year: adoption is rising, scope has expanded past public cloud, and ownership is shifting into engineering leadership rather than sitting with finance alone. What isn’t true is that the accountability gap itself is closing quickly or completely. The more defensible read is that 2026 is the year the tooling and org structure to close the gap matured, not the year the gap actually disappeared.

    Three things worth tracking over the next six to eighteen months:

    • Whether chargeback and showback adoption moves meaningfully past the current 44%, since that’s the mechanism that turns visibility into actual accountability.
    • Whether AI-specific cost tooling catches up to the 98% of practitioners now managing AI spend, given that token-based billing still doesn’t map cleanly to the models most tools were built for.
    • Whether the “20 to 40% savings” figure vendors cite continues to compress, now that the State of FinOps 2026 report itself acknowledges the easy wins are gone.
    Want the next data-backed breakdown of enterprise infrastructure economics before it hits your feed? Subscribe to The Neural Loop at neuralwired.com/newsletter.

  • Klarna, Replit, Zillow: 12 Companies Whose AI Failed

    Klarna, Replit, Zillow: 12 Companies Whose AI Failed

    What 12 Public AI Failures Teach Enterprises | NeuralWired
    AI Governance / Enterprise AI

    What 12 Public AI Failures Teach Enterprises

  • JPMorgan Kinexys Blockchain Hits $4 Trillion in 2026

    JPMorgan Kinexys Blockchain Hits $4 Trillion in 2026

    JPMorgan Kinexys and the Quiet Rise of Enterprise Web3 in 2026
    Enterprise Blockchain / 2026 Analysis

    JPMorgan Moved $4 Trillion on Blockchain. Nobody Noticed.

  • Microsoft’s AI Emissions Jumped 25%: The ESG Gap

    Microsoft’s AI Emissions Jumped 25%: The ESG Gap

    Microsoft’s AI Emissions Jumped 25%: The ESG Gap
    Sustainability & Enterprise AI

    Microsoft’s AI Emissions Jumped 25% in 2025. Here’s the ESG Gap Nobody’s Filled

    Your ESG dashboard probably looks fine. It’s also probably wrong. On July 9, 2026, Microsoft’s Environmental Sustainability Report confirmed what sustainability teams have quietly suspected for two years: AI infrastructure is now the single biggest driver of corporate carbon growth, and most Scope 3 inventories still don’t itemize it as its own line. Microsoft’s total emissions hit 20.3 million metric tons of CO2 equivalent in fiscal 2025, up 25% from 16.2 million tons the year before. Google and Amazon reported similar jumps the same week. If your company runs LLM API calls at scale and your Scope 3 report doesn’t mention it by name, you have a disclosure problem that’s about to become a legal one.

    The Microsoft Report That Changes the Conversation

    Microsoft has spent years positioning itself as the carbon-neutral pledge leader of Big Tech. Its 2026 Environmental Sustainability Report just complicated that story considerably. Total greenhouse gas emissions reached 20.3 million metric tons of CO2 equivalent in fiscal year 2025, a 25% increase over the 16.2 million tons reported in 2024, according to figures reported by Bloomberg. The company attributed the jump directly to the pace of AI and cloud infrastructure growth, particularly new data center construction.

    The number that should worry every sustainability officer reading this isn’t the headline figure. It’s the breakdown underneath it: Scope 3, indirect emissions from the value chain, made up 85.82% of Microsoft’s total 2025 footprint. Scope 3 is exactly the category most corporate ESG reports fail to capture AI-related emissions under, because it covers everything upstream and downstream of a company’s direct operations, including the cloud services and AI vendors it relies on.

    Why This Isn’t a One-Year Blip This is now a two-year trend, not a single bad report. Bloomberg’s 2024 reporting already showed Google’s emissions rising 48% and Microsoft’s rising 30% due to AI buildout. The 2026 numbers confirm the trajectory held, even as both companies publicly reaffirmed net-zero targets.

    It’s Not Just Microsoft

    If Microsoft’s report stood alone, you could file it under company-specific overspending. It doesn’t stand alone. The same reporting week, Google disclosed a 25% jump in supply chain emissions in its own 2026 sustainability report, and Amazon logged a 16% rise, according to reporting from Bloomberg and industry coverage of the same disclosure cycle.

    Company Metric 2025 Change
    Microsoft Total GHG emissions +25% (20.3M tons CO2e)
    Google Supply chain (Scope 3) emissions +25%
    Amazon Total emissions +16%
    The underlying driver is consistent across all three: data center buildout to serve AI workloads. The International Energy Agency’s April 2026 report puts numbers behind the trend at a global scale. Electricity demand from data centers overall grew 17% in 2025, but electricity consumption from AI-focused data centers specifically surged 50% in the same year. Big Tech’s capital expenditure on data center investment exceeded $400 billion in 2025 and is projected to climb another 75% in 2026, per the IEA’s “Key Questions on Energy and AI” report.

    Why Your ESG Report Probably Doesn’t Count This

    Here’s the uncomfortable part. Most GHG Protocol templates and ESG reporting platforms were built before generative AI usage became material to corporate emissions. If your organization runs thousands of daily LLM API calls, that usage almost certainly isn’t itemized anywhere in your current Scope 3 inventory. It’s buried inside a generic “purchased cloud services” line, if it’s captured at all.

    The scale of the visibility gap is larger than most boards realize. Roughly 70% of companies lack visibility into their own Scope 3 data, despite Scope 3 accounting for close to 90% of all corporate emissions across most industries. And 80% of organizations lack the data integrity required to meet Corporate Sustainability Reporting Directive compliance mandates in the EU, according to sector survey data cited by IrisCarbon.

    “The biggest problem is transparency: emissions can be substantial, but companies share so little data that exact costs remain murky.” Dr. Sasha Luccioni, Co-founder, Sustainable AI Group; former Climate Lead, Hugging Face; TIME100 AI honoree, Masters of Scale, 2026
    Alex de Vries-Gao, founder of Digiconomist and a PhD candidate at VU Amsterdam’s Institute for Environmental Studies, makes the same point from a different angle: the data that would settle these questions already exists, it’s just not being shared consistently.

    “You really have to deep-dive into the semiconductor supply chain to be able to make any sensible statement about the energy demand of AI. If these big tech companies were just publishing the same information that Google was publishing three years ago, we would have a pretty good indicator of AI’s energy use.” Alex de Vries-Gao, Founder, Digiconomist; PhD Candidate, VU Amsterdam, reported May 2026

    How Much Carbon Does One AI Query Actually Produce?

    This is where you need to slow down, because the numbers circulating online are messier than most articles admit. Start with the one statistic that’s genuinely solid: Hugging Face researcher Sasha Luccioni’s peer-reviewed estimate found that training OpenAI’s GPT-3 emitted around 500 tonnes of CO2, roughly equivalent to 500 transatlantic flights between New York and London. That comparison traces to a named researcher, a peer-reviewed methodology, and a specific, disclosed model. It’s the only apples-to-apples “AI training versus flights” figure in the literature that meets that bar.

    A Caveat Worth Repeating The widely circulated “50x a transatlantic flight” framing you may have seen elsewhere applies to speculation about GPT-4, not the verified GPT-3 figure. OpenAI has never officially disclosed GPT-4’s training energy. Independent academic reconstruction using Multi-Level Carbon Accounting methodology estimates roughly 27.4 GWh of usage energy plus 5.4 GWh of infrastructure energy (32.8 GWh total), producing about 15 kilotons of CO2 equivalent, per a peer-reviewed arXiv paper. Other independent estimates for the same training run range as high as 51 to 62 GWh depending on assumptions. Treat any single GPT-4 number you encounter as a modeled estimate, not an official statistic, because that’s exactly what it is.
    Zoom out to the industry level and the range widens further. A peer-reviewed study published in the journal Patterns, hosted on PMC, estimates the global AI systems carbon footprint at somewhere between 32.6 and 79.7 million tons of CO2 in 2025, with a water footprint between 312.5 and 764.6 billion liters. That’s not a typo. A field this young genuinely doesn’t have agreement yet on embodied versus operational emissions, PUE assumptions, or grid carbon intensity, which is exactly why the range is so wide.

    Per-Query Numbers: The One Bright Spot

    Google is one of the few companies that has actually published a per-query figure rather than leaving analysts to reverse-engineer one. Its August 2025 methodology found the median Gemini text prompt consumes about 0.24 watt-hours and produces roughly 0.03 grams of CO2 equivalent, a rare case of proactive disclosure worth crediting. Compare that to the range of estimates floating around for AI queries generally: as low as 0.3 watt-hours by Sam Altman’s public claim, as high as 2.9 watt-hours per the Electric Power Research Institute, and potentially up to 18.9 watt-hours for more complex, GPT-5-class queries. That’s a 60x spread depending on whose number you trust, which tells you how immature standardized measurement still is in this space.

    The Regulatory Clock Is Running

    This stops being a research curiosity and becomes a compliance deadline fast. California’s SB 253 requires U.S. entities with revenues exceeding $1 billion to publicly disclose Scope 1 and Scope 2 emissions starting in 2026, with the first deadline landing August 10, 2026. Scope 3 emissions, the category where AI vendor emissions actually live, become mandatory from 2027.

    In the EU, the Corporate Sustainability Reporting Directive requires large companies to disclose detailed carbon emissions data, and AI providers or deployers operating in Europe may fall under its scope. The European Commission’s 2025 Omnibus proposal narrowed some coverage and adjusted timelines, but it left the underlying direction toward mandatory disclosure intact. Related regulatory momentum is also building around AI transparency more broadly, as covered in our recent piece on the EU AI Act’s explainability requirements.

    If your company relies on third-party LLM APIs at any meaningful scale, you need a measurement methodology now, not in 2027. Auditors reviewing your first Scope 3 disclosure will want prior-year baselines you can’t manufacture retroactively.

    What to Do This Quarter

    1. Ask your AI vendors directly for energy and emissions-per-query disclosures. Google now publishes these. If your vendor can’t produce a number, that gap is itself a disclosure risk worth flagging to your board today.
    2. Separate AI usage out of your “purchased cloud services” catch-all. If it’s buried in a generic line item, you have no baseline to report against when Scope 3 rules take effect in 2027.
    3. Treat model tier as a compliance lever, not just a cost lever. Smaller, more efficient models measurably cut inference energy per task. Which model you route a given workload to is becoming a genuine sustainability decision.
    4. Build your August 10 Scope 1/2 disclosure now if you clear the $1 billion revenue threshold in California. There’s no grace period built into SB 253’s first deadline.
    5. Look at where compute physically runs. Edge and distributed infrastructure choices affect your energy footprint upstream of any AI-specific accounting; our recent breakdown of Gartner’s 2026 edge computing data is a useful starting point for that conversation.

    The Other Side: Is This Overblown?

    Not everyone reads these numbers as a crisis. Urs Hölzle, a Google Fellow and one of the company’s earliest data center architects, has spent years building the infrastructure this article is describing. He doesn’t dispute the scale of the computational problem.

    “AI is a huge computational problem. You need a supercomputer to make a new model like Gemini. And then that supercomputer runs for weeks or months to just build this one model.” Urs Hölzle, Fellow, Google, Latitude Media
    But Hölzle isn’t convinced by the most alarming demand projections, arguing the industry is learning to train and serve models more efficiently at a pace that outstrips the headlines. He points to the IEA’s own figures showing AI and data centers still represent a small slice of projected global electricity growth compared to industrial demand, EVs, and heating and cooling electrification. Christina Shim, Chief Sustainability Officer at IBM, lands in similar territory, arguing for balance over alarm.

    “Raising a flag over AI’s energy use makes sense. It identifies an important challenge and can help rally us toward a collective solution. But we should balance the weight of the challenge with the incredible, rapid innovation that is happening.” Christina Shim, Chief Sustainability Officer, IBM, Fortune, via OilPrice.com
    There’s a real counterargument buried in the efficiency data, too. The IEA itself notes that energy use per AI task has dropped by at least an order of magnitude annually in recent years. If those efficiency gains keep outpacing demand growth, the “AI carbon crisis” framing could look overstated within two to three years. Alex de Vries-Gao pushes back on that optimism with Jevons’ Paradox: historically, efficiency gains increase total resource consumption rather than shrink it, because cheaper, faster AI simply gets used more. Both things can be true at once, and that tension is exactly why this remains an unsettled debate rather than a closed one.

    Our read: this signals a measurement problem more than an ideology problem. Companies aren’t necessarily hiding AI’s carbon cost on purpose. Most simply don’t have a category for it yet. That’s fixable, and the fix starts with the same disclosure discipline that already exists for every other Scope 3 category.


    Frequently Asked Questions

    How much energy does training GPT-4 use?

    No official figure exists. OpenAI has not disclosed exact training energy for GPT-4. Independent researcher estimates range from roughly 32.8 GWh to 62 GWh, based on peer-reviewed Multi-Level Carbon Accounting methodology.

    How much CO2 does AI produce compared to flying?

    The only peer-reviewed direct comparison is for GPT-3: about 500 tonnes of CO2, roughly equal to 500 transatlantic New York to London flights, based on research by Sasha Luccioni. No equivalent verified figure exists for GPT-4.

    Do companies report AI’s carbon emissions in ESG reports?

    Rarely in detail. About 70% of companies lack visibility into Scope 3 data generally, and AI-specific emissions are not yet a standard line item in most corporate greenhouse gas inventories.

    Why did Microsoft’s carbon emissions increase in 2026?

    Microsoft’s fiscal 2025 emissions rose 25% to 20.3 million metric tons of CO2 equivalent, driven mainly by new AI data center construction, according to its July 2026 Environmental Sustainability Report.

    What percentage of global electricity do data centers use?

    About 1.5% in 2024, roughly 415 terawatt-hours, projected to nearly double to around 945 terawatt-hours by 2030, according to the IEA’s “Energy and AI” report.


    Where This Goes Next

    What changed this month isn’t that AI got more carbon-intensive. It’s that the companies building it finally started saying so out loud, in numbers regulators can act on. Microsoft’s 25% jump, echoed by Google and Amazon in the same reporting week, turns a two-year-old trend into an accounting problem every ESG team now has to own. Combine that with California’s August 10 deadline and the EU’s continuing push toward mandatory disclosure, and the gap between “we have a sustainability policy” and “we can actually show our AI vendor’s carbon math” stops being an academic distinction.

    Watch three things over the next six to eighteen months: whether more AI vendors follow Google’s lead in publishing per-query energy figures, whether Scope 3 AI accounting standards start converging under GHG Protocol guidance, and whether the efficiency gains Hölzle points to actually outpace the demand growth Luccioni and de Vries-Gao are warning about. Whichever way that race goes will decide if this is remembered as a 2026 accounting fix or the start of a much longer reckoning.

    Want the next disclosure deadline, regulatory shift, or enterprise AI number before your competitors see it? Subscribe to The Neural Loop at neuralwired.com/newsletter.

  • CISA’s IoT Directive: What 21B Devices Mean in 2026

    CISA’s IoT Directive: What 21B Devices Mean in 2026

    CISA’s IoT Crackdown: What 21 Billion Devices Mean Now Cybersecurity

    CISA’s IoT Crackdown: What 21 Billion Devices Mean Now

    A federal directive, a record-breaking botnet, and a 32-day remediation gap just rewrote the rules for enterprise IoT security. Here’s what CISOs need to act on, and why zero trust alone won’t save them.

    On January 7, 2026, a botnet called RondoDox fired more than 40,000 automated attack attempts at HPE OneView servers in a single four hour window. Not routers. Not smart cameras. A data center management platform running inside government agencies, banks, and industrial manufacturers. Check Point Research caught it live, and CISA added the underlying flaw to its Known Exploited Vulnerabilities catalog the same day.

    That attack is the clearest signal yet that enterprise IoT security has moved past the consumer-gadget stage. The threat now targets the infrastructure running your business, and federal regulators noticed before most private companies did. One month later, CISA issued a binding directive that private-sector security leaders are already treating as the new baseline, whether or not it legally applies to them.

    The scale problem: 21 billion devices and counting

    Ask ten analyst firms how many IoT devices exist right now and you’ll get ten different numbers, because they’re all measuring slightly different things on different dates. The most current, most cited figure comes from IoT Analytics‘ State of IoT 2025 report: roughly 21.1 billion connected IoT devices worldwide by the end of 2025, up 14% year over year, with the installed base projected to hit 39 billion by 2030.

    If you’ve seen the “17 billion devices” figure floating around, that’s not wrong, it’s just old. That number reflects an October 2024 snapshot. By mid-2026, the real count sits closer to the low twenties, and it keeps climbing at double-digit rates every year. Every one of those billions of devices is a potential entry point, and most of them were never designed with security as a priority.

    The headline stat that actually holds up: You may have seen claims that “68% of IoT devices run unpatched firmware.” We couldn’t verify that figure against any named source. What the research does support is more precise and arguably more useful: the IoT Security Foundation found that 60% of IoT security breaches trace back to unpatched firmware, making it the single largest documented cause of compromise, ahead of weak credentials or supply-chain attacks.
    Firmware maintenance is the harder half of that problem. Research from ORDR, citing Forescout telemetry, found that 32% of deployed routers run firmware that will never receive another patch, full stop. The vendor has moved on, the support window has closed, and the device stays plugged in anyway. Forescout’s broader 2026 research puts the average router or switch at 32 vulnerabilities per device, and routers and switches now account for 34% of the most critical vulnerabilities found across enterprise networks.

    MetricFigureSource
    Global connected IoT devices (2025)21.1 billion, +14% YoYIoT Analytics
    Breaches traced to unpatched firmware60%IoT Security Foundation
    Routers running firmware that will never be patched32%ORDR / Forescout
    Average vulnerabilities per router/switch32Forescout
    Edge vulnerabilities fully remediated54% (32-day median)Verizon 2025 DBIR
    Peak DDoS traffic from a hijacked-IoT botnet29.7 TbpsCloudflare, Q3 2025

    Inside CISA’s BOD 26-02

    On February 5, 2026, CISA issued Binding Operational Directive 26-02, “Mitigating Risk From End-of-Support Edge Devices.” It requires federal civilian agencies to find, patch, and eventually rip out any edge device, including IoT edge devices, routers, firewalls, switches, and wireless access points, that no longer receives vendor security updates.

    The timeline is specific and unforgiving:

    • Immediate: Patch where feasible.
    • 3 months (by May 5, 2026): Complete inventory of end-of-support edge devices.
    • 12 months (by February 5, 2027): Decommission those devices.
    • 18 months (by August 5, 2027): Full removal from the network.
    • 24 months (by February 5, 2028): Continuous discovery process in place permanently.
    CISA Acting Director Madhu Gottumukkala didn’t soften the message when the directive dropped: “Unsupported devices pose a serious risk to federal systems and should never remain on enterprise networks.”

    The directive is technically federal-only. In practice, it’s already becoming the industry’s reference clock. CISA, the FBI, and the UK’s National Cyber Security Centre have all publicly urged private companies to adopt the same timeline, and Help Net Security’s breakdown of the order notes the same pattern security teams have seen with prior directives: what starts as a federal mandate becomes an insurance underwriting question within a year.

    If you’re running a regulated business, expect your cyber insurance renewal and your next audit to start asking about edge-device lifecycle management using this exact framework, whether you’re a federal contractor or not.

    The EU has its own clock running in parallel. The Cyber Resilience Act’s 24-hour early warning obligation for actively exploited vulnerabilities kicks in on September 11, 2026, with full security-by-design and lifetime patching requirements following in December 2027. We’ve covered the CRA’s compliance mechanics and deadlines in detail in our EU Cyber Resilience Act deadline explainer, so we won’t repeat it here. What matters for this piece is that two major regulatory regimes are converging on the same conclusion at the same time: the era of shipping IoT hardware and walking away from it is over.

    The breaches that forced the issue

    Regulators don’t move this fast without a body count. 2025 and early 2026 gave them plenty of evidence.

    BadBox 2.0

    Google disclosed this one in July 2025. It’s the largest known botnet built from internet-connected TVs, streaming boxes, and digital photo frames, compromised through outdated firmware and infecting more than a million devices in the United States alone. Nobody bought a hacked photo frame on purpose. The firmware just never got a security update, and an entire product category quietly became attack infrastructure.

    Aisuru and Kimwolf

    This is the botnet pair that broke the DDoS record books. Cloudflare mitigated a 29.7 Tbps attack in Q3 2025, sourced from an estimated 300,000 to 700,000 hijacked routers, DVRs, and IP cameras. Microsoft Azure absorbed a separate 15.72 Tbps flood in October 2025 tied to the same infrastructure. By early 2026, authorities confirmed the combined Aisuru and Kimwolf networks had compromised more than 3 million devices globally, according to reporting from Swif.ai’s IoT security roundup.

    For scale: Mirai, the botnet that defined this entire threat category back in 2016, recruited 600,000 devices using just 60 default credential combinations and still managed a 1.2 Tbps attack that knocked major sites offline. A decade of public warnings, published source code, and industry conferences later, the same playbook, default credentials plus unpatched firmware, just produced an attack 24 times larger.

    RondoDox against enterprise infrastructure

    The HPE OneView campaign matters because of what it targeted, not just how big it was. Consumer routers and cameras are the old story. A data center management platform is the new one. Our read: this is the clearest evidence yet that IoT-botnet tactics have graduated from consumer gadgets to core enterprise infrastructure, and security budgets built around “protect the smart thermostats” haven’t caught up.

    The financial exposure backs that up. Aggregated breach-cost research from Vectra.ai and ORDR puts the average IoT security incident at roughly $330,000, climbing to an average of $10 million per incident in healthcare specifically, where connected medical devices and unpatched firmware collide with regulatory exposure and patient safety.

    Why zero trust breaks down in IoT and OT

    Ask any vendor and zero trust is the answer to everything, including this. Ask the people actually implementing it, and you get a more complicated picture.

    “We all agree: zero trust is necessary. But it’s been hard to implement. It doesn’t matter what you read or which framework you follow. The core issue is that we have a concept with principles and tenets, but not enough guidance on how to implement it.” Morey Haber, Chief Security Advisor, BeyondTrust, via Network World
    Haber’s framing is the industry-consensus version: zero trust works in theory, execution is the bottleneck. The sharper critique comes from people who’ve responded to what happens when it fails.

    “The biggest security incidents in 2026 will stem from compromised identities within supposedly zero trust environments. The illusion of control will persist until identity management becomes contextual and adaptive, powered by AI that can interpret intent, not just credentials.” Ariel Parnes, COO, Mitiga (former IDF Unit 8200 colonel), via SecurityWeek
    Parnes is describing a real gap: zero trust verifies credentials, not intent, and IoT devices generally don’t have the kind of identity infrastructure that makes that verification meaningful in the first place. Most IoT hardware simply can’t run the components a standard zero-trust architecture assumes. No multi-factor authentication. No client certificates. Not enough compute to support continuous verification. You can’t authenticate your way around hardware that was never built to authenticate.

    CSO Online’s analysis of the IoT and OT gap makes the sharpest structural point in the whole debate: zero trust governs access, but it doesn’t model consequence. Two systems can be fully isolated at the network layer, properly segmented, verified access on paper, and still be functionally inseparable through a shared controller, a common protocol translator, or a vendor’s remote update service. You can pass every zero-trust audit and still have a single point of failure nobody mapped.

    Timeline expectations get a reality check too.

    “We will eventually get there, but timelines extend well beyond 2026 due to fundamental structural barriers. Private data exchanges must simultaneously secure data flows across partners’ legacy systems, cloud environments, and on-premise infrastructure, while maintaining operational compatibility with hundreds of exchange participants at varying security maturity levels.” Dario Perfettibile, VP and GM of European Operations, Kiteworks, via SecurityWeek
    Put those three quotes together and you get the honest 2026 state of the industry: zero trust is the right direction, badly under-implemented, structurally mismatched to most IoT hardware, and years away from covering the gap even under optimistic timelines.

    What enterprise security teams should do now

    The Verizon 2025 Data Breach Investigations Report, drawn from more than 22,000 incidents and 12,195 confirmed breaches, found a 34% year-over-year rise in successful vulnerability exploits, with an eightfold jump in exploitation of edge devices and VPN concentrators. Among breaches that started with vulnerability exploitation, edge devices and VPNs accounted for 22%, up from just 3% the year before. Only 54% of edge vulnerabilities were fully remediated in the observation window, and the median time to fix one was 32 days.

    That 32-day number is the one worth pinning to your dashboard. It’s a real industry benchmark you can measure your own remediation SLA against, not a vendor’s aspirational target.

    Given all of that, the realistic model for 2026 isn’t “implement zero trust everywhere.” It’s a two-tier approach: identity-based zero trust for the IT systems that can actually support it, and network-based segmentation with behavioral monitoring for the IoT and OT fleet that can’t. Treating “we did zero trust” as a finished project, when your IoT devices sit entirely outside that perimeter by design, is the exact gap that shows up in next year’s breach report.

    Practical steps that map directly to what’s driving this shift:

    • Inventory first. CISA’s own timeline gives federal agencies three months just to find every end-of-support edge device. If a federal agency needs that long, assume your enterprise network has blind spots too.
    • Benchmark against 32 days. Use the DBIR’s median remediation time as your internal SLA target, and track what percentage of your edge vulnerabilities actually get fully closed, not just acknowledged.
    • Segment what you can’t authenticate. If a device can’t run MFA or a client certificate, it goes on an isolated network segment with active behavioral monitoring, not on the same trust tier as your laptops.
    • Watch the procurement deadline. By January 4, 2027, vendors selling consumer IoT to the U.S. federal government must carry the FCC’s Cyber Trust Mark. That’s a voluntary label today. It becomes a de facto procurement filter in eighteen months, and enterprise buyers will likely start asking for it too.
    For a deeper look at how these device counts are actually measured, our breakdown of Gartner’s edge computing numbers is worth a read. And if your IoT exposure runs through industrial or OT systems specifically, we’ve also mapped the ROI math behind GE and Shell’s industrial IoT deployments, which is a useful counterweight when your CFO asks why security spending on OT devices matters as much as the operational upside.

    Frequently asked questions

    How many IoT devices are there in 2026?

    Estimates vary by firm and methodology, but IoT Analytics reports roughly 21.1 billion connected IoT devices as of the end of 2025, up 14% year over year, with the installed base forecast to reach 39 billion by 2030.

    What percentage of IoT breaches are caused by unpatched firmware?

    Research from the IoT Security Foundation attributes roughly 60% of IoT security breaches to unpatched firmware, making it the single largest documented cause of IoT compromise, ahead of weak credentials or supply-chain attacks.

    What is CISA BOD 26-02?

    CISA Binding Operational Directive 26-02, issued February 5, 2026, requires U.S. federal civilian agencies to inventory, decommission, and replace edge devices, including IoT edge devices, routers, and firewalls, that no longer receive vendor security updates, on a 3-to-24-month timeline.

    Does zero trust work for IoT devices?

    Only partially. Most IoT devices lack the compute power to run standard zero-trust components like multi-factor authentication or client certificates, so security teams typically apply a two-tier model: identity-based zero trust for IT systems, and network-based segmentation and behavioral monitoring for IoT and OT devices that can’t participate directly.


    Where this goes next

    Here’s what’s actually different now. Enterprise IoT security stopped being a device-hygiene checklist item somewhere between the RondoDox campaign and CISA’s February directive, and became a board-level compliance question with a hard clock attached. The 21 billion devices already deployed aren’t getting replaced overnight, the firmware problem isn’t getting solved by a single patch cycle, and zero trust isn’t the finished solution the marketing suggests.

    Over the next 6 to 18 months, watch three things specifically: whether private-sector cyber insurers start writing CISA’s timeline into policy requirements, whether the EU CRA’s September 2026 incident-reporting deadline produces the first wave of public disclosure data on IoT breach frequency, and whether the two-tier zero-trust model becomes the named industry standard or stays an informal workaround.

    The organizations that treat this quarter’s device inventory as a compliance chore will be the ones explaining a breach to their board next year. The ones that treat it as the actual security perimeter it is will just be doing their jobs.

    Want this kind of analysis before it hits your feed? Subscribe to The Neural Loop at neuralwired.com/newsletter.

  • Shopify AR Cuts Return Rates 40% With WebXR (2026)

    Shopify AR Cuts Return Rates 40% With WebXR (2026)

    WebXR Arrives: Browser AR Cuts Retail Returns Up to 40%
    Retail Technology / WebXR

    WebXR Arrives: Browser AR Cuts Retail Returns Up to 40%

  • EU Cyber Resilience Act: IoT Deadline Explained 2026

    EU Cyber Resilience Act: IoT Deadline Explained 2026

    Regulation & Compliance

    The EU Cyber Resilience Act’s IoT Deadline Is Coming, and the Rulebook Isn’t Ready

  • Workday AI Hiring Lawsuit: What HR Must Know in 2026

    Workday AI Hiring Lawsuit: What HR Must Know in 2026

    Mobley v. Workday: Why HR’s AI Hiring Tools Are a Legal Time Bomb
    AI & Employment Law

    Mobley v. Workday: The AI Hiring Lawsuit HR Can’t Ignore

    Derek Mobley applied to more than 150 jobs on Workday’s platform. He got rejected from almost all of them, some in minutes, some at 2 a.m., all by software he never spoke to. Three years later, that rejection pile has turned into the case reshaping how every company in America is allowed to use AI to hire people, and most HR departments still haven’t read the ruling.

    If your company uses an applicant tracking system, a resume screener, or a “candidate scoring” tool built by a vendor, Mobley v. Workday is not background noise. It’s the reason your legal exposure just changed, whether or not anyone told you.

    What Mobley v. Workday Actually Decided

    Filed in February 2023, Mobley v. Workday started as a straightforward discrimination complaint. Derek Mobley, an African American man over 40 with a disclosed disability, alleged Workday’s applicant screening tools rejected him on the basis of race, age, and disability, not the humans who happened to be using the software.

    The legal theory is what made this case different. Mobley didn’t just sue the employers who rejected him. He sued Workday itself, arguing the vendor acted as an “agent” of every employer using its screening tools, and could therefore be held directly liable under federal anti-discrimination law.

    In July 2024, Judge Rita Lin of the Northern District of California let that theory proceed. By May 2025, she certified a collective action under the Age Discrimination in Employment Act, keeping the disparate impact claim alive even after dismissing the intentional discrimination claim. Then, in early 2026, Workday tried a new angle: it argued that a 2024 Supreme Court ruling, Loper Bright Enterprises v. Raimondo, which ended Chevron deference, should invalidate decades of precedent applying age discrimination protections to job applicants, not just existing employees.

    Judge Lin didn’t buy it. She found the EEOC’s longstanding interpretation “persuasive” under a lower legal standard called Skidmore deference, and let the applicant claims move forward.

    Why this matters if you’re not being sued: the “agent” theory means your AI vendor’s exposure and your company’s exposure are no longer separate questions. If the vendor gets sued and loses, the precedent lands on your desk too, whether your contract says the vendor is liable or not.
    There’s a second wrinkle most compliance guides skip. In May 2026, a magistrate judge denied a motion to force Workday to hand over its internal bias-testing data, ruling that because Workday’s lawyers curated the data for legal advice, it was protected by attorney-client privilege. That’s a genuinely uncomfortable fact for anyone selling “just audit everything and publish it” as the safe path. Routing bias testing through counsel can shield results from discovery. It can also sit awkwardly next to public disclosure laws that assume the opposite. More on that tension below.

    The Lawsuits Stacking Up Behind Mobley

    Mobley isn’t an outlier anymore. It’s a template. Three other cases filed in 2026 use variations of the same argument, and each one targets a different weak point in how companies deploy AI screening.

    • Kistler & Bhaumik v. Eightfold AI (filed January 2026): plaintiffs allege Eightfold, used by companies including Microsoft and PayPal, secretly generated “likelihood of success” scores on a 0 to 5 scale without disclosing it, a claim built on the Fair Credit Reporting Act and California’s investigative consumer reporting law rather than discrimination statutes.
    • Swanson v. IBM (filed May 2026): a 24-year IBM employee alleges age discrimination tied to an AI-generated rejection following a 2024 layoff, applying Mobley’s logic to a company’s own internal tool rather than a third-party vendor.
    • Harper v. SiriusXM (filed 2025): alleges screening software used education and home address, essentially race proxies, across roughly 150 applications.
    Notice what’s happening here. These aren’t four versions of the same lawsuit. They’re four different legal theories converging on the same conclusion: courts are willing to treat algorithmic hiring decisions the same way they’d treat a human recruiter’s decisions, and sometimes with less patience.

    The Stanford Study That Broke the “We Passed Our Audit” Defense

    If Mobley is the legal story, a Stanford study published in May 2026 is the data story, and it’s the more damaging one for HR teams who thought a vendor’s compliance certificate meant they were covered.

    Researchers led by Rishi Bommasani at Stanford HAI, alongside Sarah Bana, Kathleen Creel, Dan Jurafsky, and Percy Liang, analyzed more than 4 million job applications from roughly 3 million applicants across 156 large employers, all screened through the same vendor’s algorithm, Pymetrics (now owned by Harver). The paper, “Algorithmic Monocultures in Hiring,” is headed to ACM FAccT in Montreal.

    Here’s the finding that should worry every HR leader relying on a vendor’s own bias report: when the researchers examined outcomes position by position, the legally correct method under the “four-fifths rule” used in U.S. employment law, they found 10.62% of the 1,746 job positions studied showed adverse impact against Black applicants. The vendor’s own published, aggregated audits showed no measurable bias at all.

    “I think the most significant result of our study is how much bias we find in this algorithmic hiring system. The vendor has published aggregated audits that demonstrate that their tools do not demonstrate measurable bias. I was surprised because I thought that their algorithms would be an example of best practice.” Sarah Bana, Digital Fellow, Stanford Digital Economy Lab, via Stanford Digital Economy Lab Q&A
    The study also surfaced something new to the compliance conversation: “systemic rejection.” Among applicants who applied to four positions through the same vendor, 10% were rejected from every single one, a rate the researchers show is statistically inconsistent with independent decisions (a chi-squared value of 18,481, for the statistically inclined). One vendor’s algorithm, used across hundreds of employers, can create a single point of failure that no individual company’s internal audit would ever catch.

    “I don’t think we want to discourage the application of AI in this domain, but recognize the stakes are high and be judicious in the approach.” Rishi Bommasani, Senior Research Scholar, Stanford HAI
    Bommasani’s framing matters. This isn’t an argument to rip out AI screening tools. It’s an argument that the industry’s go-to proof of fairness, a vendor’s own aggregated audit, isn’t proof of anything at the level that actually matters legally: the individual job position.

    The State Law Patchwork HR Teams Are Missing

    While the federal government has pulled back on AI hiring enforcement (the EEOC’s 2023 guidance on AI screening was quietly removed from its website, and an April 2025 executive order directs agencies to deprioritize disparate impact claims generally), states and cities are moving in the opposite direction. If your governance plan is built around federal rules alone, it’s already out of date.

    JurisdictionRuleStatus in 2026
    New York CityLocal Law 144: annual bias audits for Automated Employment Decision ToolsIn force since 2023; enforcement was found weak by state auditors, tighter enforcement promised for 2026
    ColoradoSB 26-189 (replaced the original SB 24-205)Delayed to January 1, 2027; scaled back from a broad duty of care to a narrower notice-and-review regime
    IllinoisAI employment decision disclosure statuteIn effect since January 1, 2026
    CaliforniaCivil Rights Council ADS rules and CPPA ADMT rulesEffective October 2025 and January 2026; make bias testing (or its absence) explicit evidence in discrimination claims
    New York City’s law is the one worth paying closest attention to, and not for the reason most compliance memos suggest. A December 2025 audit by the New York State Comptroller found the city’s own enforcement agency had reviewed 32 companies and identified just one non-compliance issue. Independent auditors reviewing the exact same 32 companies found at least 17. Roughly three-quarters of test calls to the city’s complaint hotline never even reached the right department.

    That’s the “toothless law” era. It’s ending. The Comptroller’s findings came with a public commitment from the city’s consumer affairs department to tighten enforcement in 2026, which means the penalty structure, $500 to $1,500 per violation per day, with each day of non-compliant use counted separately, is about to start getting used the way it was written. A single non-compliant screening tool left unaudited for a month can generate $15,000 to $45,000 in exposure before any per-candidate multiplier even applies.

    Companies covered by NYC’s rule, even if they’re not based there: Local Law 144 applies to any employer or agency using an AEDT to evaluate NYC-based candidates, including remote roles. If you hire remote employees who happen to live in the five boroughs, this law already applies to you.
    For context on how the parallel financial-sector and healthcare rules are moving, including the EU AI Act’s shifting high-risk deadlines and the Fed’s model risk guidance, NeuralWired covered the sector-by-sector explainability requirements in detail in our EU AI Act 2026 explainer. This piece deliberately doesn’t retread that ground; the hiring track runs on its own, older set of laws (Title VII, the ADEA, the ADA) that are largely immune to the federal deregulatory pressure hitting newer AI-specific state statutes.

    What an Actual Governance Framework Looks Like

    Most companies deploying AI hiring tools in 2026 don’t have a governance gap because nobody’s heard of NIST or ISO. They have a gap because the frameworks that exist are voluntary, self-attested, and easy to satisfy on paper while missing the exact problem the Stanford study exposed.

    A framework that actually reduces risk, rather than just producing a policy binder, needs a few specific things:

    • Position-by-position bias testing, not aggregated audits. The Stanford study proves aggregated numbers can hide double-digit adverse impact rates at the individual job level.
    • A documented vendor liability allocation. Mobley shows vendors can be directly liable, and that employers can’t assume the vendor absorbs all the risk just because the contract says so.
    • An inventory of every AEDT actually in use, including tools embedded inside applicant tracking systems that HR may not realize qualify as automated decision tools under NYC or California rules.
    • A deliberate, documented choice about whether bias testing runs through counsel (for privilege protection) or is conducted for public disclosure (as LL144 requires). Doing both without a plan creates contradictions a plaintiff’s attorney will find.
    • Human review checkpoints that are real, not rubber-stamp, since Colorado’s revised law and California’s ADMT rules both lean on documented human oversight as a compliance anchor.
    Roughly 12% of enterprises currently have what researchers classify as “mature” AI governance processes, according to HFS Research and Infosys data cited in industry analysis published in 2026, despite how widely these tools are already deployed. That gap is the story. The tools showed up years before the governance did.

    Why “We Have a Framework” Isn’t the Same as “We’re Safe”

    Here’s the uncomfortable part of this story that vendors selling governance platforms don’t lead with: adopting NIST’s AI Risk Management Framework or getting ISO 42001 certified demonstrates that you have a process. It doesn’t independently verify that anyone actually ran the specific test that matters, position-level adverse impact analysis, on your specific tool, on your specific job postings.

    Our read: the industry has spent three years selling “governance” as a checkbox exercise, and the Stanford study is the first large, methodologically serious dataset to show what happens when the checkbox gets checked but the underlying test never runs. A vendor’s aggregated audit passed. Real candidates still lost out because of their race, at the position level, in over one in ten jobs studied.

    The regulatory landscape isn’t converging around a clean answer either. The EU is delaying high-risk AI obligations, currently expected to shift from August 2026 to December 2027, pending formal adoption of the “Digital Omnibus” package. Colorado gutted its own comprehensive AI law and pushed it back eighteen months. The EEOC pulled its guidance. Meanwhile New York City, Illinois, and California are all tightening in the same window. A framework calibrated to satisfy one jurisdiction won’t satisfy the others, and right now those jurisdictions are moving in opposite directions inside the same country.

    Is a rushed governance rollout actually going to hold up? Probably not, if it’s built to today’s rules rather than to the underlying civil rights statutes (Title VII, the ADEA, the ADA) that Mobley and its sibling cases are actually built on. Those laws aren’t going anywhere, regardless of what happens to any single state’s AI-specific statute.

    FAQ

    Can a company be sued for AI hiring bias?

    Yes. Mobley v. Workday established that an AI vendor can be directly liable for employment discrimination under an “agent” theory, not just the employer using the tool. The case allows disparate impact claims to proceed under the ADEA, ADA, and Title VII based on algorithmic outcomes alone, without proof of intentional bias.

    What is NYC Local Law 144?

    It requires any employer or agency using an Automated Employment Decision Tool on NYC-based candidates to commission an independent bias audit within the prior 12 months, publicly post a summary, and give candidates 10 business days’ notice before use. Penalties run $500 to $1,500 per violation per day.

    Does a vendor’s bias audit guarantee an AI hiring tool is fair?

    Not necessarily. A 2026 Stanford-led study of 4 million job applications found a vendor’s own published, aggregated audit showed no measurable bias, while independent position-by-position analysis, the method U.S. employment law actually applies, found adverse impact against Black applicants in over 10% of individual job positions.

    Is the EEOC still enforcing AI hiring rules in 2026?

    The EEOC’s 2023 guidance on AI hiring discrimination was removed from its website, and a 2025 executive order directs federal agencies to deprioritize disparate impact theories generally. Private litigants can still pursue these claims independently, and state and local laws in New York City, Illinois, and California have separately tightened requirements.


    Where This Goes Next

    Three things are now true that weren’t true two years ago. AI hiring vendors can be sued directly, not just the employers who use their tools. A vendor’s own bias audit is no longer credible proof of fairness on its own. And the regulatory map is fragmenting rather than converging, with federal enforcement receding just as city and state rules tighten.

    Watch three things over the next 6 to 18 months: how NYC’s promised 2026 enforcement crackdown actually plays out once the Comptroller’s findings force DCWP’s hand, whether the Mobley discovery ruling on attorney-client privilege gets tested again as more plaintiffs demand vendor bias data, and whether the EU’s Digital Omnibus delay to December 2027 actually gets formally adopted or falls apart before the original August 2026 deadline.

    If your company runs any AI screening tool and hasn’t run a position-level bias check on it, independent of whatever your vendor handed you, that’s the gap to close first, not the last one.

    Subscribe to The Neural Loop for the stories HR, legal, and compliance teams need before they hit the docket.

  • MakerDAO Sky Governance 2026: $400M No-CEO Vote

    MakerDAO Sky Governance 2026: $400M No-CEO Vote

    How MakerDAO Moved $400M With No CEO or Board Web3 & Enterprise Governance

    How MakerDAO Moved $400M With No CEO or Board

    In October 2022, a organization with no executives and no office voted to put $400 million into US Treasury bonds. By 2026 that position had grown twentyfold, and enterprise governance teams are now quietly copying the mechanics, while ignoring the part that never got fixed.

    The vote that moved $400 million without a signature

    No CEO approved it. No board met to discuss it. No headquarters existed to house the decision. In October 2022, MakerDAO announced a plan to put $500 million into short-term US Treasury bonds and investment-grade corporate bonds, split into $400 million for Treasuries and $100 million for corporate debt. The whole thing was approved through a community-wide vote that ran for months, then executed by a third-party asset manager called Monetalis under a mandate the community itself wrote.

    This is the transaction enterprise readers keep half-remembering when they hear “a DAO managed $400 million with no CEO.” It’s real, it’s dated, and it’s one of the cleanest test cases in existence for whether decentralized governance can handle institutional-scale money. MakerDAO’s head of growth, Nadia Alvarez, put the community’s mood at the time plainly:

    “The 80-20 split between treasuries and bonds remained the favored approach during the voting process. This showcases the opportunity associated with the move, and seeing such adamant support from the community is very exciting.” Nadia Alvarez, Head of Growth, MakerDAO. Source: Decrypt, October 6, 2022
    Four years later, that $400 million seed has become the dominant force in the entire real-world-asset lending category. And it happened without a single executive signing off on the wire transfer. If you run governance, risk, or treasury at an actual company, that should get your attention, not because you should copy it wholesale, but because pieces of it already work better than what you’re running today.

    How a DAO actually approves a nine-figure trade

    Strip away the crypto vocabulary and the process looks less alien than it sounds. It runs in four stages:

    1. Forum debate. Someone proposes the idea on a public discussion board (Discourse). Anyone can argue for or against it, in public, with their name or wallet attached.
    2. Temperature check. A non-binding poll (Snapshot) gauges whether the community actually wants this before anyone spends gas fees on a real vote.
    3. On-chain executive vote. Token holders (MKR at the time, SKY now) vote directly on the blockchain. The vote itself is the approval, there’s no separate signature required.
    4. Delegated execution. A licensed third party, in this case Monetalis, executes the trade inside a policy envelope the vote defined: which assets, what caps, what counterparties.
    That last step is the part most people miss when they describe DAOs as “leaderless.” Someone still has to actually buy the bonds. MakerDAO didn’t eliminate execution authority, it separated it from policy authority, and put a licensed professional in the execution seat instead of an internal executive. A follow-up report from CryptoSlate confirmed the exact structure: the $500 million split into two vehicles, RWA007-A routed through Bank Sygnum and RWA007-B through Baillie Gifford, and within four months the strategy was already generating roughly $2.1 million in fees, more than half of MakerDAO’s entire annualized revenue at the time.

    The part the headline leaves out: a 48-hour delay sits between an executive vote passing and it actually executing on-chain. That window exists specifically so the community can catch and cancel a malicious or mistaken vote before money moves. It’s a circuit breaker built directly into the governance code, something most corporate approval chains still do with a Slack thread and hope.

    From $400M to $8.2B: how far this went

    The 2022 vote wasn’t a one-off experiment. It became the template for what MakerDAO is now. In March 2023, the DAO voted to scale the Treasury strategy from $500 million to $1.25 billion. In August 2024, MakerDAO rebranded entirely to Sky, launched a new stablecoin (USDS) and governance token (SKY, converting from MKR at a fixed 1:24,000 ratio), and split into a network of specialized sub-organizations internally called “Stars,” starting with Spark and, later, a Solana-focused Star called Keel.

    By mid-2026, per an analysis from Token Dispatch, Sky’s total real-world-asset exposure had reached $8.245 billion, which is 52.2% of its own total value locked and, more strikingly, 78% of all real-world assets deployed across DeFi lending, industry-wide. A single protocol that started with a $400 million bond vote now dominates the category it helped invent.

    DAOOnchain treasury (Q1 2026)Rank
    Uniswap$4.8 billion1
    Sky (MakerDAO)$3.9 billion2
    Optimism$2.1 billion3
    Arbitrum$1.7 billion4
    Lido$1.4 billion5
    Onchain treasury figures per DeepDAO tracking, cited via eco.com. Note this measures raw onchain treasury, not total RWA exposure, which is a different (larger) number for Sky. Track the two separately, conflating them is the single most common error in coverage of this space.

    The scale-up brought a genuinely new behavior with it too. Sky’s “Smart Burn Engine” used surplus revenue, largely generated by that Treasury bond yield, to buy back and burn more than $60 million of MKR in 2024 alone. That’s a capital-return policy, functionally a corporate buyback, executed with no CFO and no board resolution behind it. Whether that’s a feature or a warning sign depends entirely on who you ask.

    What enterprise governance teams are actually borrowing

    Corporate treasury and risk teams aren’t rebuilding MakerDAO. They’re taking three specific pieces of it:

    1. The service-provider model

    Governance approves a defined policy envelope, allowable assets, exposure caps, a liquidity floor, and then delegates in-envelope execution to an accountable, licensed third party. That’s directly portable to a corporate treasury committee that wants faster execution without giving up policy control at the board level.

    2. Programmable delay as a circuit breaker

    The 48-hour execution delay is a concrete, auditable mechanism. It’s slower than a lot of corporate decisions, and that’s the point, it buys time to catch an error or a bad actor before funds move, with the entire deliberation visible on a public ledger rather than buried in an inbox.

    3. Transparent, real-time treasury reporting

    Every dollar in Sky’s Treasury position is traceable on-chain, in real time, by anyone. Most companies produce that level of transparency once a quarter, if that.

    Aaron Wright, co-founder of Tribute Labs and one of the lawyers who helped write Wyoming’s DAO LLC statute, has a description of the underlying appeal that sticks:

    “A DAO is a subreddit with a bank account. The energy of the Internet is swarmlike, but there’s no real productive way to channel that. I believe DAOs are that answer.” Aaron Wright, Co-founder, Tribute Labs. Source: Forbes, February 2022
    Wright’s own caveat, from the same interview, matters just as much: DAOs still need a real-world legal wrapper, a Wyoming or Marshall Islands DAO LLC, to sign contracts, hold licenses, or get sued in a normal court. “No headquarters” is true in the romantic sense. It is not true in the sense a general counsel cares about.

    What broke along the way

    The optimistic version of this story stops at “it scaled.” The honest version has to include what governance by token vote has repeatedly failed to prevent.

    The $182 million flash loan attack

    In April 2022, an attacker borrowed roughly $1 billion in a flash loan from Aave, Uniswap, and SushiSwap, used it to instantly acquire majority voting power in Beanstalk Farms, a DeFi lending protocol, and executed a malicious proposal in the same transaction, the same block, transferring the protocol’s liquidity straight to their own wallet. Beanstalk lost $182 million. The attacker walked away with roughly $76 to $80 million in profit. Beanstalk’s response afterward was blunt: it ripped out its on-chain governance module entirely and replaced it with a community-run multisig wallet, quietly admitting that pure token-weighted voting, without a time delay, is a structural liability, not just a Beanstalk problem.

    Voter apathy never actually went away

    The uncomfortable number underneath every DAO success story is participation. Reported turnout figures for 2025 and 2026 vary by protocol but land in a consistent range: some analyses put typical DAO proposal turnout under 2%, others put average engagement closer to 17%, and Ethereum co-founder Vitalik Buterin has separately argued in public commentary that participation in top DAOs frequently dips below 10%, according to reporting on his November 2025 remarks, warning that low turnout leaves protocols vulnerable to being effectively run by a small number of large token holders regardless of what the governance charter says on paper.

    MakerDAO’s own numbers back this up. A 2024 vote on US Treasury bill collateral saw a small block of institutional voters carry more than 70% of all participating MKR. Peer-reviewed and preprint research on DAO governance generalizes the pattern further: across many DAOs, fewer than ten wallets hold more than half of total voting power. “No board” turns out to mean “a smaller, less accountable board,” more often than it means no concentration of power at all.

    The risk the DAO flagged, then walked past anyway

    MakerDAO’s own Endgame governance document, written years before the Treasury strategy scaled to billions, contained a direct warning about the exact assets it went on to buy:

    “The major downside is that they can be seized easily. Anything that can be seized by global powers may be at risk of seizure through legal means.” MakerDAO Endgame governance document. Cited via Token Dispatch, May 2026
    The community read that warning and voted to put roughly $8 billion into US Treasuries anyway. That’s not necessarily a mistake, Treasuries are about as safe an asset as exists, but it’s a real illustration of a structural weakness: a DAO that took months of deliberation to build a large position is also, by design, slow to unwind one if the regulatory ground shifts underneath it.

    A short, ugly history

    EventYearLossRoot cause
    The DAO hack2016~$60M (3.6M ETH)Reentrancy vulnerability in the smart contract
    Compound distribution bug2021~$90M mis-distributedBuggy contract upgrade required emergency governance vote
    Beanstalk flash-loan attack2022$182MInstant governance token acquisition via flash loan, no time delay

    The honest verdict

    Decentralized treasury governance works operationally. MakerDAO proved that a $400 million bet, approved by public vote and executed by a licensed third party, can scale into a multi-billion-dollar institutional position without a CEO ever signing a document. That’s a real, useful, replicable finding.

    What it did not do is solve the participation problem that has haunted DAOs since The DAO itself collapsed in 2016. It built delegated layers instead, service providers, SubDAOs, “Stars”, that increasingly resemble conventional management, just wearing a different legal costume. An independent 2026 assessment of Sky’s SubDAO architecture put it plainly: operational autonomy improved, complexity overhead rose substantially, and roughly the same 10 to 20 percent of token supply engages in governance regardless of what the token is called.

    Our read: the lesson for enterprise governance teams isn’t “flatten your hierarchy.” It’s “separate policy-setting, which can be broad and slow, from execution, which should be delegated to accountable professionals operating inside hard-coded limits.” Borrow the circuit breaker. Borrow the transparency. Don’t borrow the assumption that removing a CEO removes concentrated power, it just moves where that power hides.

    Regulatory context worth tracking if you’re evaluating any of this for actual enterprise use: the GENIUS Act’s OCC rulemaking deadline and MiCA’s final compliance deadline both land around July 2026, pushing stablecoin and DAO-adjacent structures toward provable regulatory compatibility. Any adoption of these patterns in the US or EU needs compliance review built in from the start, not bolted on after.


    Frequently asked questions

    What is a DAO and how does it manage money without a CEO?
    A DAO manages funds through smart-contract-held treasuries controlled by token-holder votes instead of executives. Proposals are debated publicly, voted on-chain, and executed automatically once approved, as MakerDAO did in 2022, moving $400 million into US Treasury bonds via community vote with no CEO or board involved.

    How much money does MakerDAO/Sky manage in 2026?
    As of early 2026, Sky (formerly MakerDAO) holds roughly $3.9 billion in onchain treasury per DeepDAO tracking, with total real-world-asset exposure reported around $8.2 billion, up from the original $400 million Treasury allocation approved in October 2022.

    What is the biggest DAO governance failure?
    Beanstalk Farms lost $182 million in April 2022 when an attacker used a $1 billion flash loan to instantly acquire majority governance voting power, then passed and executed a malicious fund-transfer proposal within a single blockchain transaction, exposing a structural flaw in token-weighted voting without time delays.

    Can a DAO legally hold and invest in US Treasury bonds?
    Yes. DAOs like MakerDAO have done this through licensed third-party asset managers, such as Monetalis, operating under a governance-approved mandate, converting stablecoin reserves to dollars to purchase Treasuries, while typically using a legal wrapper such as a Wyoming DAO LLC for real-world contracting.

    What replaced MakerDAO’s MKR token?
    In August 2024, MakerDAO rebranded to Sky and introduced SKY as its governance token, converting from MKR at a fixed 1:24,000 ratio. MKR still exists and remains convertible, but SKY is now the primary governance and voting asset across Sky’s SubDAO network.


    Where this goes next

    What you now understand that you probably didn’t twenty minutes ago: the “$400M, no CEO” story is real, it’s MakerDAO’s Monetalis Clydesdale vote, and it scaled into the dominant force in DeFi’s real-world-asset category. But scale never fixed the concentration problem underneath it, it just professionalized around it.

    Over the next 6 to 18 months, watch three things: whether Sky’s Keel SubDAO deployment on Solana changes voter participation numbers at all, whether the GENIUS Act and MiCA compliance deadlines push more DAOs toward Wyoming or Marshall Islands legal wrappers, and whether any enterprise consortium actually pilots the service-provider model with a real corporate treasury rather than just talking about it at a conference.

    A quick honest note on search: no legitimate SEO practice, including everything in this piece, guarantees first-page Google rankings within two or three days. Rankings depend on crawl timing, domain authority, competing content, and Google’s own indexing cycle, none of which any single article controls. What this piece does give you is a strong, well-sourced foundation to rank on the merits over time.

    Want breakdowns like this before everyone else covers them? Subscribe to The Neural Loop at neuralwired.com/newsletter.


    Related on NeuralWired: Smart Contract Audit Checklist 2026: Enterprise Edition · BlackRock, Goldman Sachs & the RWA Tokenization Playbook 2026 · JPMorgan & HSBC Lead RWA Tokenization in 2026 · JPMorgan, DeFi vs Banks: The Real Risk Comparison 2026

  • EU AI Act 2026: Why Explainable AI Just Became Law

    EU AI Act 2026: Why Explainable AI Just Became Law

    EU AI Act 2026: Why Explainable AI Just Became Law | NeuralWired
    AI REGULATION / EXPLAINABLE AI

    EU AI Act 2026: Why Explainable AI Just Became Law

    Four different regulators, on four different continents of oversight, just landed on the same word in the same twelve months: explainability. Not “accuracy.” Not “fairness” in the abstract. Explainability, the specific, auditable ability to say why an AI system made the call it made.

    If you run model risk at a bank, compliance at an insurer, or a clinical AI program at a hospital, that convergence is the story of your second half of 2026. The EU AI Act’s transparency rules go live August 2. The Federal Reserve rewrote its bank model guidance in April. State insurance regulators are piloting an actual examiner checklist right now. And the FDA has quietly made “how black-box is this thing” the line between an exempt tool and a regulated medical device.

    None of these four rules say the same thing, cover the same companies, or run on the same clock. Treat them as one checkbox and you’ll miss the one that actually applies to you. Here’s the real map, sector by sector, plus the one credentialed voice arguing the entire premise is built on sand.

    Quick answer, for the skimmers Explainable AI (XAI) went from research niche to binding, examinable requirement across four sectors in a single year. The EU AI Act’s Article 13 transparency rules are enforceable from August 2, 2026, with penalties up to roughly €35 million or 7% of global turnover. U.S. bank regulators’ SR 26-2 (April 2026) covers traditional ML credit models at banks over $30 billion in assets, but explicitly excludes generative AI. Insurance regulators in 25+ U.S. states now require written AI transparency programs under the NAIC Model Bulletin. The FDA treats “how explainable is this model” as a deciding factor in whether a clinical AI tool needs premarket device review. Meanwhile, state-level AI consumer protection law (Colorado) is being rolled back under federal pressure, so the pattern to watch isn’t “AI regulation is coming,” it’s “sector regulators are tightening while state law loosens.”

    The Convergence: Four Regulators, One Word

    This isn’t one law creating a moment. It’s four independent regulatory tracks arriving at the same demand within the same window: EU technology law, U.S. banking supervision, state insurance regulation, and federal medical device policy. That’s the actual news, and it’s why a compliance calendar built around a single deadline will fail you.

    Each track defines “explainable” differently, covers different companies, and enforces on a different timeline. A bank that nails SR 26-2 compliance could still be exposed under the EU AI Act if it serves European customers. An insurer with a clean NAIC governance file could still fail a state-specific rule like New York’s, which goes further by requiring the state’s Department of Financial Services to be able to review vendor AI tools directly and demand audits.

    The EU AI Act’s August 2 Deadline

    Mark the date: August 2, 2026. That’s when Article 13 transparency obligations for high-risk AI systems become enforceable under the EU AI Act. High-risk, per Annex III, includes systems used in credit scoring, insurance pricing, and medical devices, exactly the sectors this article covers.

    The requirement itself is deceptively simple to state and hard to satisfy: systems must be designed so their operation is transparent enough for deployers to interpret outputs and use them appropriately, and providers must disclose the technical characteristics needed to explain what the system produced.

    Miss it, and the penalties aren’t symbolic. Non-compliant high-risk systems face fines up to roughly €35 million (about $38.5 million) or 7% of global annual turnover, whichever is higher. (Cross-check that figure against Article 99 directly before you cite it in a client memo. Secondary sources vary slightly on the exact wording.)

    The catch nobody’s talking about The European Commission’s own guidelines clarifying how to actually satisfy Article 13 were due in Q2 2026. That means companies may be asked to comply with obligations before Brussels has finished explaining what compliance requires. Fixed deadline, moving target.

    SR 26-2: What the Fed Actually Changed for Banks

    On April 17, 2026, the Federal Reserve, the OCC, and the FDIC jointly issued SR 26-2, replacing the 2011-era SR 11-7 as the governing model risk management framework for banks. Here’s the nuance that most coverage is going to flatten: SR 26-2 is a narrowing, not an expansion. Traditional statistical and machine learning credit and fraud models stay fully in scope, subject to validation covering conceptual soundness, outcomes analysis, and ongoing monitoring. Generative and agentic AI models are explicitly carved out as “novel and rapidly evolving” and not yet governed by this letter.

    The threshold that matters for your calendar: SR 26-2 is expected to be most relevant to banking organizations with more than $30 billion in total assets. If you’re under that line, this specific letter isn’t the one keeping you up at night.

    What happens to the GenAI tools your bank is already using to draft adverse-action language or summarize override rationale? Nothing, for now. Regulators say they plan to issue a request for information addressing AI model risk more broadly, including generative and agentic AI, but that’s a future document, not a current rule. Translation: build a parallel, self-governed track for GenAI, because SR 26-2 won’t cover it and nothing else currently does either.

    Insurance: The NAIC Bulletin and the 30-Day Test

    The NAIC Model Bulletin on the Use of AI Systems by Insurers, adopted back in December 2023, has quietly become the operative insurance AI rule in most of the country. As of early 2026, 25 states plus Washington, D.C. have adopted it, up from just 11 states in April 2024. The bulletin requires a written AI Systems (AIS) Program and specifically names the transparency and explainability of outcomes to the impacted consumer as a factor insurers must weigh.

    The real test isn’t whether you have a policy document. It’s whether you could produce a plain-language explanation of an adverse decision, a denied claim or a rate increase, within 30 days of a hypothetical examiner request. Most insurance compliance teams haven’t actually run that drill.

    That drill is about to get formalized. NAIC’s new AI Systems Evaluation Tool, an examiner questionnaire, is being piloted in 12 states from January through September 2026, with wider adoption expected at the NAIC Fall National Meeting. This is the mechanism that turns bulletin language into actual exam findings. It’s not live nationwide yet, but it’s close.

    Healthcare: The FDA’s Black-Box Line

    The FDA hasn’t issued one binding “XAI rule.” Instead, a stack of guidance functions like one: the June 2024 Transparency for Machine Learning-Enabled Medical Devices guiding principles, a predetermined change control plan guidance finalized in December 2024, and a lifecycle management guidance from January 2025.

    For clinical decision support tools specifically, explainability has become the functional dividing line between “exempt software” and “regulated medical device.” The more black-box a CDS algorithm looks, especially when it’s AI-driven, the more likely the FDA is to pull it into premarket device review rather than let it operate as exempt clinical software.

    This isn’t a hypothetical problem waiting to happen. The FDA has already authorized more than 580 AI-enabled medical device models, with roughly 400 of them aimed at helping radiologists catch things like malignant tumors or stroke signs, and a large share of those algorithms remain genuinely black-box, either because they’re proprietary or too complex to fully unpack. Explainability isn’t a future compliance category in healthcare. It’s already sitting inside hundreds of tools making live clinical calls.

    Sector-by-Sector Comparison Table

    Framework Binding or Guidance Effective Date Who It Covers Max Penalty
    EU AI Act, Article 13 Binding law August 2, 2026 High-risk AI: credit, insurance, medical devices ~€35M or 7% global turnover
    SR 26-2 (Fed/OCC/FDIC) Supervisory guidance Issued April 17, 2026 Banks over $30B in assets; traditional ML models only No fixed fine; supervisory action
    NAIC AI Model Bulletin State-adopted guidance Adopted state-by-state since 2023 Insurers in 25 states + D.C. Varies by state insurance code
    FDA AI/SaMD Guidance Guidance, device-triggering Ongoing since June 2024 AI-enabled clinical decision support and diagnostics Non-compliant device pulled from market

    The Counter-Current: Colorado’s Rollback

    Here’s the part of the story that complicates any tidy “regulation is coming” headline. While sector regulators tighten, state-level consumer protection AI law is being walked back, and fast.

    Colorado’s SB 24-205, the most prescriptive state AI law on the books, with a duty of care against algorithmic discrimination, got repealed and replaced by SB 26-189, signed May 14, 2026. The replacement delays the effective date to January 1, 2027 and strips out the duty of care, deployer risk management programs, impact assessments, and several attorney general reporting obligations, swapping in a narrower disclosure-only regime.

    That reversal didn’t happen in a vacuum. On April 9, 2026, xAI sued to block enforcement of Colorado’s law on constitutional grounds, and the Department of Justice moved to intervene on xAI’s side, the first time federal authorities have joined a suit against a state AI law. The root cause traces back to a December 11, 2025 executive order directing the FTC to determine when state AI laws requiring changes to “truthful outputs” are preempted by federal law, and Colorado was named directly.

    Where to actually spend your budget Sector prudential regulators, banking, insurance, EU technology law, FDA, are winning ground on explainability. Broad state consumer-protection AI law is losing ground fast. If you’re deciding where to put compliance headcount this year, follow the sector regulator, not the state legislative headline.

    The Contrarian Case: Cynthia Rudin

    Every regulation covered above assumes the same underlying premise: that a black-box model can be explained well enough, after the fact, to satisfy a regulator or a consumer. Dr. Cynthia Rudin, Duke University’s Interpretable Machine Learning Lab director and a 2025 ACM Fellow, has spent a decade arguing that premise is wrong.

    “You can’t have accountability without transparency.”
    Dr. Cynthia Rudin, Professor of Computer Science, Duke University
    Rudin’s argument, laid out in her widely cited 2019 Nature Machine Intelligence paper, is that a fully faithful explanation of a black-box model would essentially make the black box redundant. In practice, popular explainability tools like SHAP and LIME produce approximations of what a model did, not a true account of it. In an interview, she went further, arguing that fairness itself is impossible to verify without an interpretable model, because you can’t reliably detect bias inside a system you can’t actually read. She also pushed back directly on the assumption that interpretable models sacrifice accuracy, telling one interviewer there’s no real evidence of that tradeoff in high-stakes settings.

    Why this matters for the regulations above: Article 13 and the NAIC bulletin both require systems be “sufficiently transparent,” without mandating that the underlying model actually be interpretable by design. A bank or insurer could, in theory, bolt a SHAP dashboard onto a black-box model and satisfy the letter of these rules while the real decision-making stays opaque. Full legal compliance, without full actual explainability. That gap is the single most useful thing a skeptical reader can take from this piece.

    What Compliance and Engineering Teams Should Do Now

    • Stop treating explainability as one checkbox. Map each AI system against each applicable framework separately: EU exposure, U.S. banking asset threshold, state insurance adoption, and FDA device classification all trigger independently.
    • Re-triage bank models by materiality rather than defaulting to SR 26-2’s predecessor’s uniform annual review cycle, and build a separate governance track for GenAI and agentic tools that the letter doesn’t cover.
    • Run the 30-day drill. Insurers should test, today, whether they can produce a plain-language adverse-decision explanation inside 30 days, not just point to a policy that says they can.
    • Finalize EU “instructions for use” documentation, training data characteristics, accuracy metrics, human oversight measures, before August 2, 2026, for any high-risk system touching EU customers or markets.
    • Classify clinical AI tools early. The more black-box a CDS tool looks, the more likely it lands in FDA’s regulated-device category, so build interpretability in before submission, not after a rejection.
    The budget case is easier than it looks. Global spend on AI governance platforms sits at roughly $492 million in 2026 and is projected to cross $1 billion by 2030, according to Gartner, one of the few AI-adjacent spending categories still expanding while broader “AI ROI” skepticism grows everywhere else.

    “Explainability turns a GenAI output into a defensible, auditable insight.”
    Pankaj Prasad, Senior Principal Analyst, Gartner
    Gartner separately predicts that by 2028, explainability will push LLM observability investment to 50% of GenAI deployments, up from just 15% today, a sign that the generative AI models least suited to today’s explainability tools are exactly where the next wave of tooling spend is heading.


    Frequently Asked Questions

    What is explainable AI (XAI)?
    Explainable AI (XAI) refers to techniques and system designs that let humans understand why an AI model produced a specific output, the reasoning behind a credit denial, an insurance price, or a diagnosis, rather than just the output itself. It’s distinct from a purely accurate but opaque black-box model.

    Why is explainable AI important in finance and healthcare?
    In regulated sectors, AI decisions must be defensible to regulators, auditors, and the people affected. The EU AI Act, U.S. banking guidance (SR 26-2), the NAIC’s insurance bulletin, and FDA medical device guidance all treat opacity as a compliance risk, since unexplainable decisions can’t be audited for bias or error.

    When does the EU AI Act require AI explainability?
    The EU AI Act’s transparency obligations for high-risk AI systems, including those used in credit scoring, insurance pricing, and medical devices, become enforceable August 2, 2026. Non-compliant high-risk systems face penalties up to roughly €35 million or 7% of global turnover.

    Does the U.S. require explainable AI in banking?
    Not through a single binding federal law, but SR 26-2, issued April 2026 by the Fed, OCC, and FDIC, sets validation and transparency expectations for traditional and non-generative AI credit and risk models at banks over $30 billion in assets. Generative and agentic AI are explicitly excluded for now.

    What is the difference between explainability and interpretability in AI?
    Explainability generally means post-hoc techniques describing why a complex black-box model reached a decision. Interpretability means a model is transparent by design, like a decision tree or scoring system. Researcher Cynthia Rudin argues interpretable-by-design models are more trustworthy than explained black boxes.

    Is explainable AI required for insurance companies?
    In the states that have adopted the NAIC’s Model Bulletin on AI Systems, insurers must maintain a written AI governance program that accounts for the transparency and explainability of outcomes to the impacted consumer, particularly for adverse decisions like coverage denials or rate increases.


    Where This Goes Next

    By the time the EU’s implementing guidelines catch up to Article 13’s August deadline, and by the time NAIC’s evaluation tool pilot wraps in September, the “explainability as compliance checkbox” era will be over. What’s replacing it is sector-specific, examinable, and genuinely fragmented. The through-line worth remembering: prudential and safety regulators, banking examiners, insurance commissioners, the FDA, are tightening explainability into binding practice. Broad state consumer-protection AI law is being narrowed under federal pressure. Those two trends are moving in opposite directions at the same time, and that tension, not a single new law, is the real story for the next 12 to 18 months.

    Three things to watch before year-end: whether the European Commission’s Article 13 guidelines land before enforcement does, whether NAIC’s evaluation tool pilot expands beyond its 12 states at the Fall National Meeting, and whether the promised federal RFI on GenAI model risk actually appears, which would be the first sign U.S. banking regulators are ready to bring generative AI inside the SR 26-2 perimeter.

    For more on what happens when AI gets the facts wrong instead of just unexplainable, see NeuralWired’s related coverage of the Deloitte AI hallucination report and FINRA’s 2026 warning, the accuracy half of the same trust problem covered here.

    Get the next one first NeuralWired’s newsletter, The Neural Loop, tracks AI regulation, enterprise deployment, and the stories vendors don’t want covered. Subscribe at neuralwired.com/newsletter.