In-depth artificial intelligence analysis: AI agents, LLMs, enterprise deployment, governance, and breakthroughs. Research-backed insights for CTOs, founders, and decision-makers.
Colorado AI Act SB 26-189: What Employers Must Do by 2027
AI Regulation · Employment Law
Colorado’s AI Law Died Before It Lived. Here’s What’s Next
The state’s landmark AI Act never made it to its own effective date. A quieter law just took its place, and employers have until January 1, 2027 to get ready.
If you built a compliance program for Colorado’s AI Act this year, you built it for a law that no longer exists. Senate Bill 24-205, the first comprehensive AI statute in the country, was sued by Elon Musk’s xAI, joined by the Trump administration’s Justice Department, frozen by a federal judge, and then scrapped entirely by the Colorado legislature, all in the span of about five weeks this spring.
What replaced it, Senate Bill 26-189, is narrower, later, and quieter than the law it replaced. It takes effect January 1, 2027, not June 30, 2026. If you’re running HR, legal, or procurement for a company with employees or applicants in Colorado, this is the version of the story you actually need.
The short version: Colorado’s original AI Act (SB 24-205) never took effect. It was repealed and replaced by SB 26-189, signed May 14, 2026. The new law swaps risk-management mandates for a notice-and-disclosure model, takes effect January 1, 2027, and caps penalties at $20,000 per violation under the Colorado Consumer Protection Act.
How Colorado’s AI Act Collapsed in Six Weeks
Governor Jared Polis signed SB 24-205 in May 2024, and for a while, it looked like the template every other state would copy. It required companies deploying “high-risk” AI systems in hiring, lending, housing, and healthcare to run impact assessments, maintain risk-management programs, and meet an affirmative duty of care to avoid algorithmic discrimination. Illinois passed its own AI employment-notice law weeks later. Law firms called Colorado’s approach the national test case.
It never got the chance to prove that out. Lawmakers tried to amend the bill in 2025 and failed. A special session in August 2025 pushed the effective date from February 1 to June 30, 2026. Then, in April 2026, everything moved at once.
On April 9, 2026, xAI sued Colorado Attorney General Phil Weiser, arguing SB 24-205 violated the First Amendment, the Commerce Clause, and Equal Protection principles by carving out exceptions for algorithms designed to “redress historic discrimination.” Fifteen days later, the Justice Department’s Civil Rights Division moved to intervene, the first time the federal government had directly challenged a state AI law.
“Laws that require AI companies to infect their products with woke DEI ideology are illegal.”
Harmeet K. Dhillon, Assistant Attorney General, Civil Rights Division, U.S. Department of Justice, via DOJ press release, April 24, 2026
Three days after that, a federal court paused enforcement of the law entirely. Colorado’s legislature didn’t wait to see how the lawsuit played out. On May 14, 2026, Polis signed SB 26-189, repealing SB 24-205 in its entirety and reenacting a narrower framework in its place, according to Norton Rose Fulbright’s analysis of the bill.
Here’s the arc, laid out plainly:
Date
Event
May 17, 2024
Polis signs SB 24-205, the original Colorado AI Act
Aug 2025
Effective date delayed from Feb 1 to June 30, 2026
Apr 9, 2026
xAI sues AG Phil Weiser over SB 24-205
Apr 24, 2026
DOJ intervenes in support of xAI
Apr 27, 2026
Federal court pauses enforcement of SB 24-205
May 14, 2026
Polis signs SB 26-189, repealing and replacing the law
Jan 1, 2027
SB 26-189 takes effect
Not everyone in Colorado was mourning the original law, either. Rep. Brianna Titone, one of its original sponsors, pushed back hard on the DOJ’s framing of what it actually did.
“The whole point of the law that we put in place was to prevent discrimination.”
State Rep. Brianna Titone, via Govtech, April 29, 2026
What SB 26-189 Actually Requires
Forget everything you read about risk-management programs and annual impact assessments. Those are gone. SB 26-189 drops the “high-risk artificial intelligence system” classification entirely and replaces it with a new term: automated decision-making technology, or ADMT.
The test for coverage isn’t what the system is. It’s whether the system’s output “materially influences” a consequential decision, meaning it’s a meaningful factor in the outcome, not a clerical or trivial one. Employment, lending, housing, education, insurance, and healthcare all count as consequential domains.
For employers, the obligations that matter come down to five things:
Pre-use notice. Tell applicants or employees before ADMT is used in a decision that affects them.
30-day adverse-outcome explanation. If ADMT materially contributed to a rejection, non-promotion, or termination, the affected person gets a plain-language explanation within 30 days.
Human review rights. People can request meaningful human reconsideration of an adverse, ADMT-influenced decision.
Data access and correction. People can request the data the system used about them and correct what’s factually wrong.
Vendor documentation flows downstream. Developers of covered ADMT (think applicant-tracking or screening software) must hand deployers documentation on intended use, training-data categories, known limitations, and update notices.
That last point is the one procurement and legal teams tend to miss. If your hiring stack includes third-party screening tools, expect updated vendor contracts before the end of the year, and don’t wait for the vendor to bring it up.
What this really means: The compliance burden shifted from proving your system is safe in advance to being able to explain a specific decision after the fact. Building a general AI-ethics policy no longer covers you. You need a workflow that can produce a real explanation for a real rejected candidate inside 30 days.
Penalties, Enforcement, and the Cure Period
Only the Colorado Attorney General can enforce SB 26-189. There’s no private right of action for the ADMT provisions specifically, which is a meaningful difference from what business groups feared under the original bill.
Violations are treated as deceptive trade practices under the Colorado Consumer Protection Act, which caps civil penalties at $20,000 per violation. Before the AG can pursue penalties, the office generally has to give written notice and a 60-day window to fix the problem, unless the violation was knowing or repeated. That cure right sunsets on January 1, 2030.
One more wrinkle worth flagging for anyone assuming “no private right of action” means low risk: the law preserves how liability gets split between developers and deployers in existing discrimination lawsuits under other statutes. The mandatory 30-day adverse-outcome explanation you now have to produce could become exactly the kind of documentation a plaintiff’s attorney requests in a Title VII or ADEA claim. Disclosure cuts both ways.
The AG also has to finish implementing rules by January 1, 2027, and has said publicly that enforcement won’t start until that rulemaking wraps. Translation: the compliance target employers are building toward right now isn’t fully drawn yet.
What the People Fighting Over This Law Are Saying
The federal side of this story isn’t as unified as the DOJ’s lawsuit might suggest. Rep. Jay Obernolte, the California Republican who chairs the House Science Subcommittee on Research and Technology, has a very different read on why Congress rejected a federal AI moratorium twice in 2025.
“It was never intended to be a long-term solution.”
Rep. Jay Obernolte (R-CA), via Route Fifty, February 2026
Travis Hall of the Center for Democracy and Technology takes it further, criticizing the White House’s later attempt to override state authority by executive order after Congress twice declined to act legislatively.
“Misguided.”
Travis Hall, State Engagement Director, Center for Democracy and Technology, via StateScoop, December 2025, on the push to use Executive Order 14365 to override state AI authority
Even Colorado’s own governor and attorney general weren’t full-throated defenders of the original bill while it was still on the books. Both publicly warned that a state-by-state regulatory patchwork creates real problems for building a healthy tech sector, an odd thing to hear from the two officials who signed and were charged with enforcing the law.
The Case Against Treating This as Settled
Here’s the uncomfortable part most coverage skips: SB 24-205 never regulated a single real-world employment decision. It was signed, delayed twice, frozen by a court, and repealed before its effective date ever arrived. Anything written about it in the past tense, as a law that “required” something of employers, is describing a law that was never operative.
And there’s real reason for measured skepticism about whether January 1, 2027 sticks. Its predecessor got delayed twice and then killed outright before reaching its own start date. The AG rulemaking SB 26-189 depends on has to finish by the same January deadline it’s supposed to govern. That’s a tight, and not entirely reassuring, timeline.
The federal preemption fight isn’t over either. Executive Order 14365 is still in effect, the DOJ’s AI Litigation Task Force has already intervened once, and nothing stops a similar challenge to SB 26-189 once it’s live. The extraterritorial reach that drew xAI’s constitutional challenge to the original law didn’t disappear with the rewrite.
Business groups largely got what they wanted here. No risk-management program requirement. No annual impact assessments. No duty-of-care standard. No private right of action. If you’re an employer, that’s good news in the short term. But it’s worth asking whether a narrower state law, sitting alongside an unresolved federal preemption fight, is really the stable ground it looks like from a distance.
Frequently Asked Questions
Is the Colorado AI Act still in effect?
No. The original Colorado AI Act, SB 24-205, was repealed before its June 30, 2026 effective date ever arrived. SB 26-189, signed May 14, 2026, replaced it with a narrower notice-and-disclosure framework that takes effect January 1, 2027.
What is SB 26-189 in Colorado?
SB 26-189 is Colorado’s revised AI law. It regulates automated decision-making technology used in consequential decisions like employment, lending, and housing, requiring pre-use notice, a 30-day adverse-outcome explanation, and human-review rights, effective January 1, 2027.
When does the Colorado AI law take effect for employers?
January 1, 2027. The earlier June 30, 2026 date under SB 24-205 became moot once that law was repealed and replaced by SB 26-189 in May 2026.
Why did Colorado repeal its original AI law?
Stakeholder criticism that SB 24-205 was overly complex, a federal lawsuit from xAI, a Justice Department intervention, and a court order pausing enforcement pushed Colorado’s legislature to replace the risk-management framework with a lighter disclosure model.
What penalties does Colorado’s AI law impose?
Violations of SB 26-189 count as deceptive trade practices under the Colorado Consumer Protection Act, carrying civil penalties up to $20,000 per violation. The Attorney General must generally offer a 60-day cure period before pursuing penalties.
Can employees sue under Colorado’s AI law?
Not under SB 26-189’s ADMT provisions directly. Enforcement authority rests solely with the Colorado Attorney General. The law does, separately, address how liability is allocated between developers and deployers in existing discrimination lawsuits under other statutes.
Where This Goes Next
What you now understand that most coverage still gets wrong: Colorado’s AI Act isn’t a law that employers have been complying with since June. It’s a law that collapsed before it started, replaced by something narrower, later, and still not fully written.
Three things worth watching over the next six to eighteen months. First, whether the Attorney General finishes rulemaking on schedule, or whether SB 26-189 follows its predecessor into another delay. Second, whether the DOJ’s Litigation Task Force turns its attention to SB 26-189 once it takes effect, using the same extraterritorial and Commerce Clause arguments that worked against SB 24-205. Third, whether other states drafting their own AI employment laws treat Colorado’s retreat as a template to follow or a warning to avoid.
If you’re building compliance workflows now, build for decision-level explainability, not system-level governance documents. And build them so they can survive one more rewrite, because this law has already been rewritten twice.
Subscribe to The Neural Loop for the next update on this story, and every other AI regulation fight that actually affects how you build and hire.
China May Ban Its Own AI Models: Qwen, DeepSeek at Risk
Artificial Intelligence / Policy
China Is Reportedly Weighing Its Own AI Model Export Ban
Published July 19, 2026 · NeuralWired · 9 min read
China is reportedly considering restricting overseas access to its most advanced AI models, including open-weight systems like Alibaba’s Qwen. If a China AI export ban actually happens, the free-flowing model of Qwen and DeepSeek that reshaped global AI adoption over the last 18 months could tighten fast, and every team building on Chinese open weights needs a plan before that happens.
Here’s what’s confirmed, what’s speculation, and what it means if you’re shipping products on top of Qwen, DeepSeek, GLM, or Doubao right now.
On July 7, 2026, Reuters reported, citing three people familiar with the discussions, that China’s Ministry of Commerce has spent the past month meeting with Alibaba, ByteDance, and Z.ai (formerly Zhipu AI) about restricting overseas access to the country’s most advanced AI models, both closed source and open weight, including models that haven’t shipped yet. Officials from the National Development and Reform Commission reportedly sat in on those meetings too.
Two other measures came up in the same discussions: classifying the leak or theft of proprietary AI technology as a national security law violation, and new limits on which investors can fund domestic AI startups.
None of this is finalized. Reuters’ own sourcing is explicit: nothing has been decided, there’s no timeline, and any curbs would likely apply only to future model releases, not the versions already sitting on Hugging Face today.
The short version: No ban exists. No draft law exists. What exists is a month of internal government meetings, plus a tiered legal framework floated by Chinese legal scholars in a May 2026 roundtable, published in a Supreme People’s Court journal, that sorts AI tools by risk: basic open source tools would need simple registration, intermediate tools would need a security review, and the most sensitive frontier models could be barred from public release entirely or restricted to domestic use only.
Why This Is Happening Now
Context matters here, and the timing is not a coincidence. In June 2026, the Trump administration restricted foreign national access to Anthropic’s most advanced models, Claude Fable 5 and Claude Mythos 5, over concerns they could be used to discover software vulnerabilities at scale. Because Anthropic couldn’t verify user nationality in real time, it initially pulled both models offline worldwide. Export controls on Fable were lifted after new safeguards went in, with Anthropic restoring broader access on July 1, 2026, though Mythos has stayed limited to vetted partners under a program called Project Glasswing rather than becoming fully public again.
That restriction landed hard in Beijing. At the ISC.AI 2026 cybersecurity conference on June 24, Zhou Hongyi, founder of 360 Security Technology (Qihoo 360), unveiled two Chinese answers to Mythos: a vulnerability discovery agent called Tulong Feng and an automated cyber defense platform called Yitian Zhen.
“This kind of powerful weapon that can change the landscape of cyber offense and defense cannot be held only by others.”
Zhou Hongyi, Founder and CEO, 360 Security Technology · Insurance Journal, June 26, 2026
Zhou has publicly called Mythos a “cyber nuclear weapon” and argues China faces a one way transparency problem: Chinese firms are shut out of Anthropic’s Glasswing partner program, which includes more than 40 organizations such as Microsoft, Apple, AWS, Cisco, and Nvidia, while Chinese security researchers get no equivalent access to probe Western systems.
Then there’s the Anthropic-Alibaba dispute, which broke in the same two week window as the export ban reporting. Anthropic accused DeepSeek, Moonshot AI, and MiniMax of distilling Claude’s outputs to train their own models, citing 16 million interactions generated through roughly 24,000 fake accounts. Separately, a disclosure surfaced alleging a version of Claude Code contained hidden logic to detect whether a user was in China or affiliated with a Chinese AI lab. Anthropic said this was a March 2026 anti-distillation experiment already scheduled for removal. Alibaba wasn’t satisfied. It banned Claude Code company wide effective July 10, 2026, citing back door risks, and told employees to use its in-house tool Qoder instead.
Add it up, and this isn’t a story about China suddenly souring on open source AI. It’s a story about a government watching a rival’s cyber-offense capability trigger export controls, and asking whether its own frontier models need the same kind of leash before someone uses them the same way.
Which Models and Companies Are Named
Three companies were named as participants in the Ministry of Commerce discussions: Alibaba, ByteDance, and Z.ai. Three specific models were named as potentially falling under the proposed framework: Alibaba’s Qwen, ByteDance’s Doubao, and Z.ai’s GLM-5.2.
GLM-5.2 is worth pausing on. Z.ai released it as an open-weight, MIT-licensed model roughly one day after the Fable/Mythos restrictions took effect in the U.S. Western coverage has described its rise on OpenRouter’s usage rankings, above some Anthropic models, as a “mini DeepSeek moment,” and it’s drawn public praise from Snowflake CEO Sridhar Ramaswamy and investor Marc Andreessen.
DeepSeek, Moonshot AI, and MiniMax aren’t named in the Ministry of Commerce meetings specifically, but they’re central to the wider dispute driving the narrative, thanks to the distillation accusations from Anthropic.
Company
Model(s)
Status in the reporting
Alibaba
Qwen
Named participant in Commerce Ministry talks
ByteDance
Doubao
Named participant in Commerce Ministry talks
Z.ai (formerly Zhipu AI)
GLM-5.2
Named participant; GLM-5.2 named as a model potentially in scope
DeepSeek
R1, V3
Not named in Ministry talks; central to separate Anthropic distillation dispute
Can China Even Ban Weights That Are Already Downloaded?
This is the question that undercuts the more dramatic headlines about this story, and it’s worth sitting with, because it’s the same problem Washington ran into on the other side of the Pacific.
“It’s ultimately impossible to ban China’s open-source AI models because their model weights are available freely on the internet. This could enter into first amendment speech issues.”
Kyle Chan, Fellow, John L. Thornton China Center, Brookings Institution · CNBC, July 8, 2026
Chan made that comment about the parallel U.S. debate over banning Chinese models domestically, but the logic runs both directions. Once Qwen, DeepSeek, or GLM checkpoints are downloaded and mirrored across Hugging Face, torrents, and thousands of private servers worldwide, no single government’s regulation can retroactively pull those specific files back out of circulation. That’s almost certainly why Reuters’ sources say any Chinese curbs would target future models, not the ones already in the wild.
Scott Singer, a fellow at the Carnegie Endowment for International Peace who helped write the California Report on Frontier AI Policy that informed SB-53, frames China’s dilemma as a mirror of Washington’s own.
“It is going to have the same conversations the White House has had over the last many months. China is going to have to balance the benefits of access to global markets with a desire to control a technology that is central for national security.”
Scott Singer, Fellow, Carnegie Endowment for International Peace · TIME, July 7, 2026
What This Means If You’re Building on Qwen or DeepSeek
If your stack depends on a Chinese open-weight model, nothing changes today. Reuters’ own sourcing says nothing has been decided and any curbs would likely hit future releases only. But the planning assumption underneath your roadmap should change.
Teams that treated Chinese open weights as a permanent, ever-improving free tier now have a live signal that the newest, most capable releases could end up domestic-only or API-gated, even while everything already downloaded stays freely usable indefinitely. Open weights, once released, are functionally unrecallable, which is exactly the enforceability problem Kyle Chan flagged above.
Three concrete moves worth making this quarter:
Mirror what you depend on. If your production stack runs on specific Qwen, DeepSeek-V3/R1, or GLM-4.x/5.x checkpoints, keep your own copies rather than assuming perpetual pull access to the vendor’s latest release.
Don’t roadmap around the next generation. Plan around what’s already public. Don’t assume the next Chinese frontier model ships with open weights the way the current generation did.
Separate your API risk from your weights risk. Any team relying purely on a Chinese frontier API, rather than self-hosted weights, has zero protection if China restricts overseas API access. That’s a closed-model risk profile wearing an open-weight reputation.
NeuralWired’s own rundown of the best open source AI models for 2026 already flagged export control and data sovereignty risk around GLM-5, Kimi K2.6, DeepSeek V4, and Qwen 3.5, which together account for 41% of Hugging Face downloads from Chinese organizations. This report is the concrete policy signal behind that warning.
The Case This Story Is Overhyped
It’s worth naming the strongest argument against the more dramatic framing floating around social media. Reuters’ three sources say nothing has been decided, there’s no timeline, and curbs may apply only to future models. Some social media reaction, including a widely upvoted r/singularity thread, framed the story as already “debunked.” That specific claim doesn’t hold up either; Reuters stands by its sourcing based reporting, and no government has issued a denial that contradicts it. But the underlying caution is fair: this is policy discussion, not enacted policy.
There’s also a strategic cost question nobody’s fully answering yet. Chinese frontier models trail the best U.S. systems by roughly seven months on average, according to industry benchmarking cited by TIME. Free, open distribution, not raw capability, is the mechanism that won Chinese labs somewhere between 13% and 30% of global usage share (depending on methodology) in about 18 months. A trailing competitor voluntarily giving up its main point of differentiation is a real cost. That’s a big reason sources caution the plan could stay narrowly scoped to frontier, future models rather than sweeping across the whole open-weight landscape.
Our read: the more defensible framing here isn’t “China is banning open source AI.” It’s “China may restrict its newest, most powerful models while leaving everything already released alone.” Those are very different stories, and only one of them is actually supported by the reporting.
What to Watch Over the Next 6 to 18 Months
Whether a “GLM-6” or next-gen Qwen ships with public weights at all. The clearest tell will be whether the next generation of frontier Chinese models follows the current pattern of open release or quietly goes API-only.
Formal movement from the Ministry of Commerce or NDRC. Reuters could not learn how any curbs would actually work mechanically. Watch for draft regulation, not just meeting reports.
Whether the Anthropic-Alibaba conflict escalates or cools. The Claude Code ban, the distillation accusations, and this export ban story all landed inside the same two weeks. How that dispute resolves will shape how aggressively Beijing moves.
DeepSeek’s R1 launch in January 2025 triggered a roughly $593 billion single-day drop in Nvidia’s market cap, the largest one-day loss in U.S. stock market history at the time, according to RAND Corporation research. That’s the scale of market reaction a genuine reversal of Chinese open-weight availability could trigger in the other direction. It’s also why, even at the discussion stage, this story is getting covered as market moving rather than a routine policy update.
FAQ
Is China going to ban DeepSeek or Qwen?
No decision has been made. Reuters reported on July 7, 2026 that Chinese officials discussed restricting overseas access to top-tier Chinese AI models, including open-weight ones, but sources said nothing is finalized, there’s no timeline, and any curbs might apply only to future model releases, not currently available versions.
Which Chinese AI models could be affected by export restrictions?
Reporting names Alibaba’s Qwen, ByteDance’s Doubao, and Z.ai’s GLM-5.2 as models under discussion. DeepSeek, Moonshot AI, and MiniMax are central to a separate but related dispute after Anthropic accused them of distilling Claude’s outputs.
Why is China considering restricting its own AI models?
Reported motives include national security concerns tied to cyber-offense capability, protecting proprietary technology from leaks or theft, and mirroring the U.S.’s own June 2026 restrictions on Anthropic’s Fable 5 and Mythos 5 models.
Can an already-released open-weight AI model actually be banned or recalled?
Not practically. Once model weights are downloaded and mirrored across servers worldwide, no single government can retroactively restrict global access to those files, a limitation Brookings’ Kyle Chan has raised about similar proposed U.S. restrictions, and a key reason Chinese curbs would likely target future models only.
What is the “silicon curtain”?
It’s a term commentators are using to describe both the U.S. and China moving in 2026 to restrict foreign access to their most advanced AI models, the U.S. with the Fable and Mythos restrictions in June, and China reportedly weighing the mirror-image policy in July.
Where This Leaves Us
Nothing about a China AI export ban is decided, and anyone framing this as an overnight reversal of DeepSeek or Qwen availability is ahead of the facts. What’s real is the direction: both Washington and Beijing are now treating frontier AI models as strategic assets rather than ordinary commercial software, and both are running into the same wall when they try to control something that’s already been downloaded a million times over.
If you’re building on Chinese open weights, the smart move isn’t panic. It’s mirroring what you already depend on, and not betting your roadmap on the next generation shipping the same way this one did.
Multimodal AI Enterprise Adoption Is Now the Default
By the NeuralWired Editorial Team · July 16, 2026 · 9 min read
Your next vendor RFP just changed shape. Multimodal AI enterprise adoption is no longer a checkbox feature you evaluate after picking a model, it’s the baseline architecture assumption you build the RFP around. Gartner says 80% of enterprise software will be multimodal by 2030, up from under 10% in 2024. That’s not a slow curve. That’s a rewrite of procurement criteria happening while most teams are still finishing their 2026 roadmap.
Here’s the tension nobody’s resolving cleanly: the same month frontier labs pushed multimodal models to mass-market default pricing, a peer-reviewed study in Nature Medicine found those same models reasoning incorrectly under adversarial testing, even when they landed on the right answer. Adoption and reliability are moving on different timelines. This piece is about both, because you can’t plan around one without the other.
Gartner has now published two forecasts, a year apart, that both point the same direction. In September 2024, Distinguished VP Analyst Erick Brethenoux told the Gartner IT Symposium that 40% of generative AI solutions would be multimodal by 2027, up from just 1% in 2023. By July 2025, the firm went further: 80% of enterprise software and applications will be multimodal by 2030, up from less than 10% in 2024, according to Senior Director Analyst Roberta Cozza.
Multimodal is a fundamental transformation, letting AI shift from supporting individual productivity to proactive, contextual decision intelligence across healthcare, finance, and manufacturing.
Note the small inconsistency across Gartner’s own materials: some releases cite the 2024 baseline as “less than 5%,” others say “less than 10%.” Neither figure changes the shape of the curve, but it’s worth knowing the exact baseline moves depending on which Gartner document you’re reading.
Real-world numbers back the direction, if not the pace. Two recent frontier releases landed within a day of each other on June 30, 2026: Anthropic’s Claude Sonnet 5 became the default model for every free and paid Claude user starting July 1, and Google shipped two new multimodal image models, Gemini 3.1 Flash Image and Gemini 3 Pro Image, through Google AI Studio. Neither company is treating multimodal as a premium add-on anymore. It’s the base tier.
Why enterprises are consolidating around multimodal now
Picture a claims adjuster at a mid-size insurer. Five years ago, that job meant one tool for reading the intake form, another for the damage photos, a third for the call transcript, and a spreadsheet to stitch it all together. Multimodal AI enterprise adoption promises to collapse that into one system that reads the form, looks at the photo, and listens to the call in the same pass. That’s the pitch, and it’s why McKinsey found 88% of organizations now use AI in at least one business function, with generative AI use jumping to 72% from just 33% in 2024.
But adoption and scale are different claims. The same McKinsey survey found nearly two-thirds of organizations haven’t started scaling AI across the enterprise. Most of what gets counted as “multimodal adoption” in market surveys is still pilots, not production.
According to Distinguished VP Analyst Erick Brethenoux, the case for native multimodal architecture is structural: real-world data was never single-format to begin with, and stitching together separate vision, audio, and text models introduces latency and accuracy problems that a unified model avoids.
The Nature Medicine problem: benchmarks lie
Here’s the part the vendor decks leave out. A peer-reviewed study published in Nature Medicine in June 2026, “Evaluating the robustness and readiness of large frontier models in health AI applications,” stress-tested frontier multimodal models, including GPT-5, Claude 3.5, and Gemini 2.5 Pro, on multimodal medical reasoning tasks. Researchers used adversarial perturbations, removing key details from an image or swapping which modality carried the critical information, and found the models frequently reached the correct answer for the wrong reasons. That means faulty reasoning, inappropriate shortcuts, and outright hallucinations were hiding behind passing benchmark scores.
Why this matters for your rollout: A model that scores well on a public multimodal benchmark isn’t the same as a model that reasons reliably when the input is messy, adversarial, or simply real. The Nature Medicine authors concluded that popular health benchmarks don’t reliably measure multimodal robustness at all.
The finding echoes a related pattern documented in Communications Medicine: across 300 doctor-designed clinical vignettes, leading LLMs repeated or built on a single planted fake lab value or diagnosis in up to 83% of cases before any mitigation prompt was applied. Explicit “verify before answering” instructions roughly halved the error rate. They didn’t eliminate it.
One caveat worth flagging for readers who follow this closely: by the time a peer-reviewed paper like this clears review, the exact models it tested are often a generation behind whatever just shipped. That’s a structural limitation of academic AI evaluation, not evidence the newest models are automatically safer. Treat it as a reason for more testing, not less.
The contrarian read: Gary Marcus and the ROI gap
Not everyone is buying the adoption-curve optimism, and it’s worth hearing the strongest version of that case. NYU professor emeritus and longtime AI reliability critic Gary Marcus has argued for months that generative and multimodal systems remain fundamentally unreliable regardless of which lab built them, and that reported enterprise ROI hasn’t come close to matching the capital poured into these systems.
The industry keeps converging on models with essentially the same class of reasoning flaws, no matter how much scale you throw at them, and the spending-to-revenue gap tells its own story.
Marcus has specifically pointed to the Nature Medicine findings as proof that frontier multimodal models “are not ready” for high-stakes reasoning, and he’s not alone in reading McKinsey’s own numbers as a warning sign rather than a victory lap. A companion 2025 McKinsey survey found more than 80% of respondents weren’t yet seeing measurable EBIT impact from generative AI. Adoption curve and value capture are two separate stories, and they get conflated constantly.
Our read: the skeptics aren’t wrong that governance is lagging. McKinsey’s 2026 AI Trust Maturity Survey put the average Responsible-AI maturity score at just 2.3 out of a possible higher band, up only slightly from 2.0 in 2025, with roughly a third of organizations scoring 3 or above on strategy and agentic-AI governance. Capability is outrunning oversight, and that gap is exactly where the Nature Medicine failures live.
What this means for your stack
If you’re the one signing off on the next platform migration, three things follow directly from the research above:
Assume multimodal ingestion by default. Document, image, audio, and video inputs should be evaluation criteria from day one of any vendor RFP, not a phase-two add-on.
Match the use case to the confidence level. Practitioner reporting from July 2026 converges on the same lesson: multimodal pays off in high-friction, measurable workflows like support tickets with screenshots or full-coverage compliance QA, not in low-stakes novelty pilots.
Fund governance at the same pace as capability. If your Responsible-AI maturity score would land near McKinsey’s 2.3 average, that’s your signal to slow autonomous, unsupervised deployment in regulated domains until review processes catch up. NeuralWired’s own reporting on AI code review adoption found a similar pattern: capability scaling faster than the human oversight built to catch its mistakes.
There’s precedent for how this plays out badly. Gartner has separately warned that more than 40% of agentic AI projects will be abandoned by 2027 over cost, unclear value, or inadequate risk controls, and NeuralWired’s reporting on AI agent deployment failures found roughly 70% of agent projects never reach production. Multimodal rollouts are highly likely to follow the same adoption-curve-versus-production-reality gap.
Frequently asked questions
What is multimodal AI in enterprise environments?
Multimodal AI refers to systems that process and reason across more than one data type, text, images, audio, video, and structured data, within a single unified model rather than separate tools per format. Gartner projects 80% of enterprise software will be multimodal by 2030, up from under 10% in 2024.
Why are enterprises investing in multimodal AI in 2026?
Enterprises are consolidating fragmented single-modality tools into unified platforms to cut integration overhead, reduce latency, and enable workflows like reviewing contracts, call recordings, and dashboards together. McKinsey reports 88% of organizations now use AI in at least one business function.
Is multimodal AI reliable enough for high-stakes decisions?
Not yet, based on peer-reviewed evidence. A June 2026 Nature Medicine study stress-tested frontier multimodal models on medical reasoning and found faulty logic, inappropriate shortcuts, and hallucinations under adversarial testing, meaning benchmark scores alone don’t prove real-world robustness.
What’s the difference between multimodal AI and agentic AI?
Multimodal AI is about perception: processing text, images, audio, and video together. Agentic AI is about action: autonomously executing multi-step tasks. Gartner projects agentic AI capability will reach 40% of enterprise applications by the end of 2026, typically built on multimodal foundations.
How much of enterprise AI adoption is still just piloting, not production?
A significant majority. McKinsey found that while 88% of organizations use AI somewhere in the business, nearly two-thirds haven’t begun scaling AI programs across the enterprise, meaning most “adoption” headlines still describe isolated pilots rather than production systems.
What to watch next
The honest version of this story has two halves that both hold up under scrutiny. Gartner’s forecasts describe real, well-documented product availability: multimodal is becoming the default architecture, not a premium tier. The Nature Medicine findings describe something different and equally real: benchmark performance and production-grade reliability are not the same claim, and right now the evidence for the second one is thinner than the marketing around the first.
Over the next 6 to 18 months, watch three things. First, whether McKinsey’s Responsible-AI maturity scores climb faster than the 2.0-to-2.3 pace they’ve shown so far, since that gap is what’s actually gating safe deployment. Second, whether the next generation of academic evaluation catches up to model release cycles, so reliability claims stop lagging capability claims by a full peer-review cycle. Third, whether the 40%+ agentic-AI-project abandonment rate Gartner is forecasting for 2027 repeats itself in multimodal rollouts specifically, or whether the sector learns from the agentic AI stumble first.
None of that means wait. It means build for the workflows where multimodal already earns its cost, and keep governance funded at the same pace as capability.
AI Agent Governance 2026: Why ‘One Size’ Rules Fail | NeuralWiredEnterprise AI / Governance
AI Agent Governance 2026: Why ‘One Size’ Rules Fail
Your AI agent can already read your database, draft an email, and push a config change. The question nobody in the room can answer is who signed off on that, and whether anyone would even notice if it went wrong. That gap has a name now: AI agent governance, and Gartner just told the industry it’s building the wrong kind.
On May 26, 2026, Gartner published research warning that enterprises applying identical governance rules to every AI agent, regardless of what that agent can actually do, are setting themselves up to fail. The firm’s prediction is blunt: by 2027, 40% of enterprises will demote or decommission autonomous AI agents after governance gaps surface the hard way, in production, after something breaks.
If you’re a CTO, CISO, or VP of Engineering deciding what your agent fleet is allowed to touch next quarter, this is the framework everyone else is now quoting. Here’s what it actually says, what the data shows is already happening, and what changes on your calendar because of a deadline that isn’t hypothetical: August 2, 2026.
Most organizations still treat AI agent governance as a light switch: locked down or fully trusted, nothing in between. Shiva Varma, Senior Director Analyst at Gartner and the author of the May 26 research, says that’s exactly the root cause of the failures his team is now tracking.
“Agents operate at different autonomy levels and across different trust boundaries.”
Shiva Varma, Senior Director Analyst, Gartner Gartner Newsroom, May 26, 2026
Apply heavy controls to a document-summarizing agent and you get a bottleneck: delivery slows, and engineers start building unsanctioned workarounds instead of waiting for approval. That’s shadow AI, and it’s a governance failure in its own right. Flip it around and under-restrict a powerful, autonomous agent, and you’ve expanded your attack surface without expanding your ability to see it.
CIO Dive’s follow-up interview with Varma put it more plainly still: a lot of companies simply don’t have agent-specific governance at all, they have one blanket policy stretched over everything.
Gartner’s four autonomy tiers, explained
Gartner’s fix isn’t more governance across the board. It’s proportional governance, matched to what each agent can actually do. The framework splits agents into four tiers by autonomy level, and pairs each with the controls that tier actually needs, not more, not less.
Tier
What the agent does
Governance required
Observe
Read-only access, outputs visible only to the requesting user. Document summarization, retrieval, code explanation.
The third tier is where Varma’s warning gets sharpest. Human-in-the-loop approval only works as a control if it stays meaningful, and under time pressure, approval fatigue quietly turns a real check into a rubber stamp. And the fourth tier carries its own physics problem: once an agent acts on its own, it operates at a speed no human reviewer can keep pace with in real time. That’s why circuit breakers and rollback mechanisms aren’t optional at that level, they’re the only brake left.
Gartner adds one more distinction worth sitting with: autonomy and access scope are two separate dials, not one. An agent can be low-autonomy but high-scope (it touches a lot of systems, but a human approves every move), or high-autonomy but narrow-scope. Risk climbs with either dial, independently.
The data: this is already causing incidents
None of this is theoretical. The numbers from three separate 2026 surveys point the same direction: deployment is outrunning oversight, and it’s already producing damage.
The gap, in four numbers:
88.4% of organizations had at least one AI-agent-related security breach in the past 12 months, per AvePoint’s State of AI 2026 report (750 IT leaders surveyed).
~52% average monitoring coverage across deployed agents, meaning roughly 48% run with no meaningful oversight, per Gravitee’s State of AI Agent Security report (750 senior technology leaders, April 2026).
7.2% of organizations have a single named person formally accountable for agent behavior. The rest call it unclear, informally shared, or simply undiscussed. (Gravitee, same survey.)
62% of organizations now name security and risk, not technical limits, as the top barrier to scaling agentic AI, according to Stanford’s 2026 AI Index, cited by Speakeasy.
Put those together and you get a picture that should worry anyone signing off on an agent rollout: agent fleets roughly doubled in size since December 2025, while monitoring coverage barely moved. The fleet is growing faster than anyone’s ability to watch it.
Anushree Verma, another Senior Director Analyst at Gartner, offers a useful counterweight here. Much of what gets called “agentic AI” in 2026 is still early and experimental, and treating it as more mature than it is can blind teams to what real production deployment actually costs. That matters: some of the governance panic is running ahead of how much genuinely autonomous work is happening yet. But it doesn’t erase the incident numbers above, and it doesn’t change who’s accountable when the agents that are live go wrong.
The August 2026 deadline you can’t negotiate
If your agents touch EU users in employment, credit, insurance, or critical infrastructure decisions, there’s a date on the calendar that matters more than any vendor roadmap. The EU AI Act’s high-risk system obligations reach full enforcement around August 2, 2026, requiring documented human oversight, record-keeping, and audit logging for those systems.
The penalties aren’t symbolic. Fines scale up to €35 million or 7% of global annual revenue, and they apply regardless of where the company is headquartered, as long as outputs reach EU users. Headquarters in Austin doesn’t buy you an exemption if your hiring agent screens applicants in Berlin.
Kiteworks’ 2026 forecast puts a sharper edge on why this matters right now: 63% of organizations can’t currently enforce purpose limitations on their AI agents, and 60% can’t terminate a misbehaving one. An agent you cannot stop is, by definition, an agent without governance. That’s not a compliance nuance, that’s the whole ballgame.
What mature governance actually looks like
The cloud vendors spent Q2 2026 building governance into the product, not bolting it on after. Microsoft made its Agent 365 SDK generally available at Build 2026, pairing it with an Execution Container SDK and Purview data-loss-prevention for agent prompts. Google built its Gemini Enterprise Agent Platform around an Agent Identity and Agent Registry system, giving every agent a cryptographic identity separate from any human user. AWS took the lighter path, leaning on Bedrock AgentCore to get agents into production fast while still offering identity and tool management.
The case study everyone in this space keeps citing is Uber’s internal build: an LLM gateway handling PII redaction and audit logging across every model call, an MCP gateway governing every agent-to-tool connection across more than 10,000 internal services, and an agent identity system with cryptographically attested lineage on every action taken.
Worth saying plainly: that took Uber years and a dedicated platform engineering team whose only job was AI infrastructure. Most companies reading this don’t have that team, and they don’t have that runway either. Uber is proof the model works, not a template you can copy over a weekend.
The skeptic’s case
A fair amount of the loudest governance-urgency content in 2026 comes from companies that sell governance software. The underlying statistics are usually real and independently sourced, but the framing tends to land in the same place: buy the platform. Worth reading the data and discounting the pitch separately.
There’s a sharper irony buried in Gartner’s own research. The firm’s 2026 Hype Cycle for Agentic AI places governance and security tooling on the curve as an early, still-maturing category, not a solved one. Enterprises are being told to urgently adopt governance platforms in a product category Gartner itself flags as immature. That’s not a reason to skip governance. It’s a reason to be honest that the tools for doing it well are still catching up to the sales pitch.
A more pointed critique comes from outside the analyst world entirely. A recent opinion piece put the capability gap bluntly: in practice, today’s AI agents behave less like autonomous employees and more like “junior staffers who work quickly, confidently and often incorrectly.” That’s commentary, not analyst research, but it’s a useful check on any narrative that assumes agents are already reliable enough that governance is the only thing standing between them and full autonomy.
What to do this quarter
You don’t need a platform purchase to make progress before your next planning cycle. Three moves cost nothing but time.
Tier your existing agents. Sort every live agent into Observe, Advise, Act-with-approval, or Act-autonomously. Most teams have never done this classification exercise, and it surfaces mismatches immediately.
Name an owner. Only 7.2% of organizations have done this. It costs nothing and it’s the single most concrete accountability fix available right now.
Check your kill switch. If you can’t answer, in one sentence, how you’d stop a specific agent from acting in the next five minutes, that’s your highest-priority gap, ahead of any new deployment.
Our read: the enterprises that get hurt in 2027 won’t be the ones that moved slowly on agents. They’ll be the ones that scaled fast without ever doing the tiering exercise above, then discovered their most powerful agent had the governance of their least powerful one.
Frequently asked questions
What is AI agent governance?
AI agent governance is the set of policies, ownership structures, and enforcement controls that determine what AI agents are allowed to do, on whose authority, and under what regulatory constraints, covering identity, permissions, monitoring, and accountability for systems acting on a company’s behalf.
Why does AI agent governance matter in 2026?
Gartner found 62% of organizations now cite security and risk, not technical limits, as their top barrier to scaling agentic AI. AvePoint reports 88.4% had at least one agent-related security incident in the past year, and roughly 48% of deployed agents run without adequate monitoring.
What happens if a company doesn’t govern its AI agents?
Gartner predicts 40% of enterprises will demote or decommission autonomous AI agents by 2027 after governance gaps surface through real incidents. Ungoverned agents also create direct EU AI Act exposure, with fines reaching €35 million or 7% of global revenue for high-risk systems.
What are Gartner’s four AI agent autonomy levels?
Observe (read-only, lightweight controls), Advise (drafts a human reviews and executes), Act with Approval (agent acts only after human sign-off on each action), and Act Autonomously (independent execution within guardrails, monitored through exception review, rollback, and circuit breakers).
When does the EU AI Act apply to AI agents?
High-risk obligations under the EU AI Act, covering agents used in employment, credit, insurance, and critical infrastructure, reach full enforcement around August 2, 2026, requiring documented human oversight, audit logging, and conformity assessments regardless of where the company is headquartered.
Who is responsible for AI agent behavior inside a company?
Currently, almost no one, formally. Only 7.2% of organizations report having a single named individual with accountability for agent behavior, according to Gravitee’s April 2026 survey of 750 senior technology leaders. Most describe accountability as unclear or undiscussed.
Where this goes next
Here’s what you now know that you didn’t ten minutes ago: governance isn’t a checkbox you add after deployment, it’s a dial you set per agent, based on what that agent can actually touch and how fast it can act. Uniform rules break in both directions, over-restricting the harmless agents and under-restricting the dangerous ones.
Watch three things over the next 6 to 18 months. First, whether Gartner’s 40%-decommission prediction starts showing up as real earnings-call language from enterprises walking back agent rollouts. Second, whether the governance platform market (projected past $1 billion by 2030) actually matures fast enough to catch up with the Hype Cycle placement it currently sits at. Third, how EU regulators enforce the August 2026 deadline in the first few months, since the first fine or the first quiet non-enforcement will set the tone for everyone watching from outside the bloc.
None of this requires a platform purchase to start. Tiering your agents and naming an owner are free, and they’re the two moves most companies still haven’t made.
Want this kind of breakdown in your inbox? Subscribe to The Neural Loop at neuralwired.com/newsletter for the enterprise AI stories that matter, before they hit everyone else’s feed.
EU AI Act’s Real August 2 Deadline: What Actually ChangesRegulation / EU Tech Policy
The EU AI Act’s Real August 2 Deadline: What Actually Changes
By The Neural Loop Desk · Published July 15, 2026 · 9 min read
Headline options considered:
1. EU AI Act’s Real August 2 Deadline: What Changes
2. ★ The EU AI Act’s Real August 2 Deadline: What Actually Changes
3. EU AI Act August 2026: The Deadline That Actually Bites
If your compliance team has been bracing for “AI Act Armageddon” on August 2, 2026, stand down, but not all the way down. The European Commission just moved the goalposts, and almost nobody outside a handful of Brussels law firms has fully caught up.
The EU AI Act was supposed to hit full enforcement this August, dragging employment screening tools, credit scoring models, and biometric systems into binding compliance overnight. That is not what’s happening. A late-stage amendment called the Digital Omnibus on AI rewrote the timeline in June, and it pushed the hardest part of the law back sixteen months. Meanwhile, a narrower but genuinely consequential set of rules is still landing exactly on schedule.
This piece untangles which is which, because getting it backward either causes needless panic or dangerous complacency, and both are currently happening in boardrooms across the US, UK, and EU.
Three things are real, live, and unaffected by the recent rewrite. Nothing about them moved.
1. GPAI enforcement powers turn on
General-purpose AI providers, think GPT-class models, Claude, Gemini, Llama, and Mistral, have technically been under obligation since August 2025. What changes August 2, 2026 is that the Commission gains the actual authority to investigate, demand documentation, and fine providers who fall short. The ceiling here is up to €15 million or 3% of global annual turnover, whichever is higher, under Article 101, not the €35 million figure you’ll see misquoted everywhere.
2. Article 50 transparency rules land
Any chatbot, emotion-recognition feature, or deepfake generator serving EU users needs clear disclosure language live by this date. This part of the law was never touched by the Omnibus negotiations.
3. National regulators get full teeth
Market surveillance authority transfers to competent authorities in all 27 member states, giving national regulators the power to investigate, order product withdrawals, and levy fines for whatever remains in force.
What Just Got Pushed to December 2027
Here’s the part most existing coverage still gets wrong. The Digital Omnibus on AI cleared its final legislative hurdle on June 29, 2026, when the Council of the EU gave it final adoption. Parliament had already passed it 423 to 57 two weeks earlier. The legislative process is done. Formal publication was expected before August 2, meaning the new timeline governs in practice even in the narrow window before it’s technically in force.
The headline change: Annex III “high-risk” systems, recruitment tools, credit scoring engines, education platforms, biometric identification, now have until December 2, 2027 to comply. That’s roughly sixteen months of breathing room that didn’t exist six weeks ago.
The two-track calendar every compliance team needs:
Track one, due now: GPAI vendor risk review and Article 50 chatbot/deepfake disclosure audits. Track two, due later but not that much later: Annex III conformity assessments, which realistically take 12 to 18 months to complete, meaning December 2027 is closer than the extension makes it feel.
A few other dates worth pinning to your calendar:
August 2, 2028: High-risk AI embedded in already-regulated products, medical devices, machinery, toys, gets its own extended deadline.
December 2, 2026: Watermarking compliance for AI-generated content already on the market before August, a four-month grace period, down from the six months originally floated.
December 2, 2026: A new prohibition takes effect banning AI tools built to generate non-consensual intimate imagery or CSAM, closing a gap the original text never addressed.
August 2, 2027: Member states must have national AI regulatory sandboxes operational.
The Fines, Sorted by Tier
The fine structure hasn’t changed, but which tier applies to what has been the single biggest source of confusion this year. Here’s the full picture in one place.
Violation Type
Maximum Fine
Status
Prohibited practices (Article 5)
€35M or 7% of global turnover
Enforceable since February 2, 2025
GPAI provider violations (Article 101)
€15M or 3% of global turnover
Enforcement powers activate August 2, 2026
High-risk system violations
€15M or 3% of global turnover
Applies once obligations kick in, December 2, 2027
False information to authorities
€7.5M or 1% of global turnover
Already applicable
One quirk worth flagging for SME founders: for small and mid-size companies, the fine is capped at the lower of the euro figure or the percentage, inverting the rule that applies to large firms.
Why Everyone Keeps Citing the Wrong Fine
Search “EU AI Act fines August 2026” right now and you’ll find a wall of articles pairing the €35 million/7% figure with the August deadline. That pairing is wrong for most companies. The €35 million ceiling belongs to Article 5 prohibited practices, which have been enforceable since February 2025, not to whatever activates this August.
“Most organizations are aware the AI Act exists, but very few understand what it actually requires of them. The regulation goes well beyond policy statements. It requires organizations to classify every AI system they operate, document how those systems were built and tested, and maintain ongoing human oversight.”
Robert Gelo, Senior Consultant, Vision Compliance, April 2026 (source)
Gelo’s firm found that 78% of organizations had taken no meaningful steps toward compliance as of April 2026, based on assessments across eight industries. Treat that as directional rather than a scientific poll, it’s a self-selected advisory client base, not a random sample, but the underlying signal lines up with everything else in this piece: confusion about scope, not indifference, is the main driver.
Is This Regulatory Whiplash a Problem?
Rewriting a flagship regulation weeks before its own deadline is not a routine legislative event. It’s the first substantive amendment to the AI Act since it was originally adopted, and it raises a real question about how much businesses should trust any EU tech-regulation date as final.
Academic critics have been pointed about what this pattern reveals. Nicoletta Rangone, who directs the Jean Monnet Centre of Excellence on Sustainable AI for Regulation at LUMSA University, argues that European regulation has increasingly functioned as a stand-in for industrial investment rather than a complement to it, a dynamic she says risks the EU’s long-term technical independence as non-European standards get baked into systems used across the bloc, as detailed in her March 2026 analysis in The Regulatory Review.
Enforcement capacity is the other underexamined limiter. Even the parts of the Act activating this August depend on a European AI Office that critics say is thin on the ground.
“Concerning that hiring is taking so long. There needs to be more staff to carry out these tasks and meet the deadlines under the law.”
Risto Uuk, Head of EU Policy and Research, Future of Life Institute (source)
A Pour Demain review, cited in that same Lawfare report, called for scaling the AI Office’s GPAI-focused staff to at least 160 people by 2030. Recruitment has reportedly been slow, partly because rigid EU civil-service pay scales don’t compete well against private-sector offers for the kind of frontier-model evaluators the job requires. A regulator with real fine ceilings but a thin bench of technical staff is likely to enforce unevenly in its first year, that gap between legal authority and practical capacity is arguably the more interesting story here than the deadline itself.
Industry voices, unsurprisingly, read the whole picture differently.
“The EU set out with strong ambition in the area of consumer protection, but some of these regulatory tools are not helping. You need to lead with innovation; you can’t lead with regulation.”
Fredrik Ekudden, cited via Ericsson context, Fortune, April 2026 (source)
Our read: both things can be true. The compliance burden is genuinely heavier for small firms than large ones, the Commission’s own impact study puts the base cost at up to €240,000 for a one-employee business versus €401,000 for a hundred-employee business, a wildly uneven per-head cost. And the enforcement gap is real. Neither fact makes the August 2 deadline meaningless. It just means the August 2 deadline is a different, narrower thing than the one most headlines describe.
What Compliance Teams Should Do This Quarter
Audit your GPAI vendor exposure. Know which foundation models sit underneath your product, and whether that provider signed the GPAI Code of Practice. Twenty-six organizations have, including Amazon, Google, Microsoft, OpenAI, and Anthropic. Meta has not.
Ship Article 50 disclosure language now. Any consumer-facing chatbot, synthetic-media tool, or biometric categorization feature needs visible AI-interaction disclosure live by August 2, full stop.
Don’t shelve your Annex III work, just re-sequence it. December 2027 sounds distant until you back-plan from a conformity assessment that takes over a year to complete.
Check if you now qualify for SMC relief. The Omnibus extended SME-style protections to small mid-cap companies, a real, actionable change for any organization in the 50 to 250 employee range that assumed it didn’t qualify.
Build a basic AI system inventory if you don’t have one. Research from the Cloud Security Alliance found that over half of organizations lack even this foundational prerequisite for risk classification.
Frequently Asked Questions
Is the EU AI Act fully enforceable on August 2, 2026?
Not entirely. GPAI enforcement powers, Article 50 transparency rules, and full national market-surveillance authority take effect on this date, but most Annex III high-risk obligations, covering employment, credit scoring, and biometrics, were postponed to December 2, 2027 under the Digital Omnibus on AI.
What are the fines under the EU AI Act?
Up to €35 million or 7% of global turnover for prohibited practices, enforceable since February 2025. Up to €15 million or 3% for high-risk system and GPAI provider violations. Up to €7.5 million or 1% for supplying false information to regulators. SMEs are fined at the lower figure, not the higher.
What is the Digital Omnibus on AI?
A package of amendments proposed by the European Commission in November 2025 and formally adopted by Parliament and Council in June 2026. It delays high-risk system deadlines by roughly sixteen months, adds a prohibition on AI-generated non-consensual intimate imagery, and extends SME-style relief to small mid-cap firms.
Does the EU AI Act apply to US companies?
Yes. Its reach works like GDPR’s, it applies to any provider or deployer whose AI system output reaches people in the EU, regardless of where the company is headquartered.
When do high-risk AI rules actually apply?
December 2, 2027 for stand-alone high-risk systems like recruitment and credit tools, and August 2, 2028 for high-risk AI embedded in already-regulated products such as medical devices.
Where This Goes Next
Here’s what changes in how you should be thinking about this law after reading this piece: August 2, 2026 is real, but it’s the GPAI-and-transparency chapter, not the high-risk chapter most companies have been dreading. That one now lands December 2, 2027, and the clock for building an actual conformity program should probably start now regardless.
Watch three things over the next six to eighteen months. First, whether the AI Office actually uses its new GPAI enforcement powers aggressively in year one, or whether thin staffing slows it down as critics predict. Second, whether the Commission’s final high-risk classification guidelines, expected by the end of 2026, tighten or loosen the Annex III scope further. Third, whether other EU digital rules on a similar multi-year runway, the DSA and Data Act among them, start seeing the same kind of late rewrite that just happened here.
By NeuralWired Staff · July 14, 2026 · 11 min read
A pull request lands. An AI agent wrote it, tested it, and merged it. Nobody on the team opened the diff. Six months ago that sentence described a fringe workflow. Today, according to internal data Cursor shared with Business Insider, it describes a rising share of production code shipping across real engineering teams, and AI code review is disappearing faster than most CTOs have had time to build policy around.
This isn’t a hypothetical. It’s happening at companies running GitHub Copilot, Cursor, and a growing field of autonomous coding agents, and the evidence on whether that’s a problem is genuinely split. Some of it is reassuring. Some of it should worry you. This piece lays out both sides, with the receipts.
Start with the trend everyone’s arguing about. Martin Monperrus, a professor at KTH Royal Institute of Technology, published a position paper in June arguing that coding agents have crossed a capability threshold where traditional human code review is no longer a necessary step in a software quality pipeline. It’s worth being precise about what that paper is: an argument, not an audit of production systems. But it’s landed at exactly the moment the data starts backing it up.
GitHub’s own telemetry shows Copilot’s agentic code review, which shifted architecture in March 2026 to actually gather repo context instead of just scanning a diff, has now handled more than 60 million reviews, over one in every five reviews on the platform. Seventy-one percent surface actionable feedback. That’s not a novelty feature anymore. That’s infrastructure.
Then there’s the number that should complicate your assumptions. Microsoft’s .NET team ran GitHub’s autonomous coding agent against the dotnet/runtime repository for ten straight months, from May 2025 through March 2026. It opened 878 pull requests. 535 merged. And of those merged PRs, only 0.6% were later reverted, a lower revert rate than the 0.8% baseline for human-written PRs on the exact same repo. If you’re building the case that agent-written code is inherently riskier, that data point makes it harder than it should be.
Meanwhile the workload math isn’t adding up the way vendors promise. A Digital Applied developer survey from April found engineers now spend 11.4 hours a week reviewing AI-generated code, versus 9.8 hours writing new code themselves. Review, not writing, has become the bigger time sink. And per LangChain’s late-2025 survey of 1,340 practitioners, 57.3% of organizations already have agents running in production, up from 51% a year earlier, with quality cited by 32% as the top blocker to scaling further.
The honest read: “Review is disappearing” is true in the sense that the checkpoint is vanishing at the margins for routine changes. It is not true in the sense of a wholesale industry shift to zero oversight. What’s actually happening looks more like review getting redistributed, sometimes to another AI, sometimes to nobody, and rarely with a documented policy behind the decision.
Where it actually breaks
Here’s the part the optimists skip. CodeRabbit analyzed 470 open-source pull requests and found AI co-authored code carries a 2.74 times higher rate of security vulnerabilities than human-written code, along with 1.7 times more issues flagged as major. Veracode’s testing puts it even more bluntly: 45% of AI-generated code samples introduce at least one known OWASP vulnerability class.
Georgia Tech’s Vibe Security Radar initiative has been tracking this in real time, and the trendline is steep. AI-code-caused CVEs went from 6 in January 2026 to 35 by March, nearly a six-fold jump in two months.
Google’s DORA team gave this phenomenon a name in its 2026 report: the “verification tax.” It’s the second-largest measured effect of AI adoption on delivery, right behind the productivity gain at the individual level, and it describes exactly what that Digital Applied survey found: the time saved writing code is getting eaten by the time spent verifying it.
Revert rate and vulnerability rate are measuring two different things, and conflating them is the single most common mistake in coverage of this topic. Code can ship, work, and never get reverted, while still shipping with a security flaw that simply hasn’t been exploited yet. Microsoft’s revert-rate win doesn’t cancel out CodeRabbit’s vulnerability-rate finding. They can both be true at once.
Data point
Source
What it measures
0.6% revert rate (agent PRs) vs. 0.8% (human PRs)
Microsoft .NET team, 10-month study
Does the code hold up in production
2.74x more security vulnerabilities
CodeRabbit, 470 PR analysis
Is the code secure
45% introduce an OWASP vulnerability class
Veracode
Is the code secure
11.4 hrs/week reviewing vs. 9.8 hrs/week writing
Digital Applied developer survey
Net productivity impact
The $60 billion wrinkle: SpaceX now owns Cursor
Here’s the fact most coverage of this story hasn’t caught up to yet. On June 16, 2026, SpaceX agreed to acquire Anysphere, the company behind Cursor, in an all-stock deal worth $60 billion, the largest acquisition of a venture-backed startup on record. The deal is expected to close in the third quarter of 2026, four days after SpaceX’s own roughly $75 billion IPO.
Cursor is the company at the center of this entire story. It’s the source of the internal data Business Insider used to report that human review is fading. It acquired code-review startup Graphite in December 2025. And its revenue trajectory is wild by any standard: annual recurring revenue grew from around $100 million in early 2025 to roughly $4 billion by June 2026, even as its market share of corporate AI-coding spend slipped from about 41% to 26% over the same window, according to Ramp’s spend data.
Now it’s a subsidiary of a rocket and satellite company. That’s not a footnote. If you’re an engineering leader standardized on Cursor, you now have a governance question that didn’t exist a month ago: does a company built to launch spacecraft have the same incentives around code-review product investment, data handling, and long-term support that a software-native parent would? Ask your vendor rep directly. Get the answer about contractual continuity in writing before your renewal.
What the people building this stuff are saying
The strongest voice on the “this is fine, actually” side is Monperrus himself, who argues the current hybrid model, agents write, humans review, is the weak link.
“The hybrid workflow neither provides meaningful assurance nor scales with AI-assisted throughput.”
Martin Monperrus, Professor, KTH Royal Institute of Technology, arXiv:2606.13175
But the sharpest pushback comes from people who build agent tooling for a living, not outside critics. Mario Zechner and Armin Ronacher, the engineers behind the Pi coding harness in the OpenClaw agent system, told the Wall Street Journal in May that the infrastructure underneath this shift is already showing strain.
“You have infrastructure that’s falling apart, and you have software that’s now very, very buggy compared to before. We can play this game for a couple more months, or maybe even years, but eventually it will catch up to us.”
Mario Zechner, Engineer, Pi coding harness / OpenClaw, via Wall Street Journal
David Mytton, founder and CEO of developer security firm Arcjet, put it more bluntly in a January LinkedIn post covered by The New Stack, warning of what he called coming “big explosions” as vibe-coded applications hit production at scale.
Even Michael Truell, Anysphere’s CEO and the leader of the company most associated with this trend, draws a line. He distinguishes “vibe coding,” accepting AI output without examining it, which he considers fine for prototypes, from responsible agentic engineering at scale, warning that full disengagement from the code builds a shaky foundation. It’s a useful reminder that this isn’t simply vendors versus skeptics. Even the vendor is on record urging caution.
On the practitioner side, General Motors software development manager Suvarna Rane described Copilot’s code review as freeing her team to focus on more complex work as AI-driven code volume increased, a data point that fits the “augmentation, not replacement” camp inside large enterprises.
What engineering leaders should do this quarter
Budget for review, not against it. The 11.4-versus-9.8-hour split means AI adoption is not currently a net time saver once verification is counted. Plan headcount and sprint capacity accordingly.
Separate the model that writes from the model that grades. Cursor’s BugBot defaults to reviewing code with the same model family, Composer 2.5, that generated it, a “grading your own homework” setup CodeRabbit has flagged directly. Use an independent reviewer, human or model, on anything that ships to production.
Track defect-escape rate separately from revert rate. They measure different failure modes. A low revert rate tells you almost nothing about whether you’re accumulating security debt.
Get your Cursor contract terms in writing before Q3. The SpaceX acquisition closes soon. Confirm data handling, roadmap commitments, and pricing protection now, not after.
Distinguish “bad code shipped” from “agent given too much access.” The most severe documented agent-related incident to date, the GTG-1002 espionage campaign, in which hijacked coding agents reportedly executed 80 to 90% of an operation against roughly 30 targets, was an authorization failure, not a code-quality failure. They require different fixes.
Frequently asked questions
Is AI-generated code safe to deploy without review?
Evidence is mixed. Microsoft’s .NET team saw AI-agent pull requests revert less often than human-written ones over a ten-month study, but CodeRabbit found AI co-authored code carries roughly 2.7 times more security vulnerabilities than human-written code. Safety depends on what you’re measuring.
Who owns Cursor now?
SpaceX agreed to acquire Anysphere, the company behind the Cursor AI code editor, for $60 billion in an all-stock deal announced June 16, 2026. The acquisition is expected to close in the third quarter of 2026.
Does GitHub Copilot replace human code review?
No. Copilot’s code review now handles more than one in five reviews on GitHub, but its comments don’t count as a required approval and can’t block a merge alone. It supplements human sign-off rather than replacing it.
What is the DORA verification tax?
It’s Google DORA’s 2026 term for the time developers now spend checking AI-generated code that looks correct but still needs verification, a cost the same report found only partly offset by time saved on writing.
What percentage of code is AI-generated in 2026?
Estimates vary by methodology and company, but multiple 2026 reports put AI-generated code at roughly 25 to 30% of new production code at large tech companies, with some AI-forward teams reporting notably higher shares.
Where this goes next
What you now know that you probably didn’t ten minutes ago: “AI code review is disappearing” is a real, measurable trend at the margins, not a wholesale industry shift, and the evidence for whether that’s dangerous depends entirely on whether you’re measuring revert rates or vulnerability rates. Those are different questions with different answers.
Watch three things over the next six to eighteen months. First, whether DORA’s verification tax keeps climbing as review-light workflows scale, or whether tooling closes that gap. Second, how Cursor’s product roadmap changes under a SpaceX-owned Anysphere, particularly anything touching code-review features. Third, whether more incidents like GTG-1002 surface, which would shift this conversation from a code-quality debate to an access-control one almost overnight.
Our read: the teams that come out ahead here won’t be the ones that eliminate review fastest. They’ll be the ones that figure out, deliberately, which 20% of changes still need a human’s eyes, and build that into their pipeline instead of discovering it after an incident.
Want the next development in this story before your competitors do?
Databricks, CoreWeave, and Weights & Biases have already merged the tooling. Most enterprise teams have not, and that gap is quietly draining their AI budgets.
Somewhere inside a mid-size bank right now, one team is watching a fraud model’s accuracy drift on a Tuesday afternoon dashboard. Down the hall, a different team is squinting at a LangSmith trace trying to figure out why the company’s new support chatbot just hallucinated a refund policy. Neither team talks to the other. Neither uses the same registry, the same on-call rotation, or the same vocabulary for “this broke in production.”
That split is the whole story of MLOps LLMOps convergence in 2026. The platforms that manage classical machine learning and the platforms that manage large language models are merging into a single discipline, driven by real product launches and real acquisitions, not by a marketing buzzword. But the merger is happening at the vendor level far faster than it’s happening inside actual companies. Teams still running two separate stacks are paying for it in duplicate infrastructure, duplicate headcount, and blind spots that show up right when an AI agent goes off the rails in front of a customer.
This piece breaks down what’s actually converging, what the data says, where the maturity gap still bites, and what to do about it if you’re the person who has to justify the tool budget next quarter.
Start with the clearest evidence: Databricks shipped MLflow 3.0 in June 2025, and it wasn’t a minor version bump. The release was built to bring the same rigor Databricks already applied to classical ML models to generative AI workloads, on one platform, so teams stop juggling separate systems for the two. It added tracing across more than 20 GenAI libraries, LLM-judge style evaluation, and one shared registry for models, prompts, and datasets through Unity Catalog.
MLflow isn’t a niche tool. The open-source project sits at over 30 million monthly downloads with contributions from more than 850 developers, which makes it the closest thing MLOps has to a standard, and the fact that Databricks pointed that standard directly at LLM workloads is a signal worth taking seriously.
Then there’s the money. In March 2025, CoreWeave agreed to acquire Weights & Biases, one of the most established names in ML experiment tracking. CoreWeave CEO Michael Intrator didn’t frame the deal as buying an MLOps company or an LLMOps company. He framed it as buying both categories at once, folded into infrastructure CoreWeave already sells.
“Weights & Biases has built a phenomenal platform to help organizations of any size and across a range of industries to build, deploy and monitor AI training and inference applications.”
Michael Intrator, Co-founder & CEO, CoreWeave — CoreWeave official announcement
Weights & Biases now sells two products under one roof on purpose: W&B Models for the classical MLOps work (training, fine-tuning, deployment) and W&B Weave for LLMOps (tracing, evaluation of non-deterministic outputs). The company’s own positioning is “one platform, one audit trail, from first notebook to production LLM.” That’s not incidental phrasing. It’s the whole pitch.
W&B CTO Shawn Lewis told VentureBeat that Weave was never meant to stand alone.
“It’s foundational, so there’s a lot that you can do on top of this.”
Shawn Lewis, CTO & Co-founder, Weights & Biases — VentureBeat
This isn’t only a vendor story. PayPal extended its internal MLOps platform, Cosmos.AI, to natively handle LLM workloads, adding retrieval-augmented generation, semantic caching, and prompt management directly onto infrastructure it already had, rather than standing up a second stack. Uber built a unified “GenAI Gateway” mirroring the OpenAI API spec to serve both external and self-hosted models across more than 60 internal use cases. Neither company treated the LLM layer as a separate discipline requiring a separate org chart.
Our read: the pattern across every one of these examples is the same. Nobody built a parallel LLMOps stack from scratch and kept it walled off. Every serious player extended what already worked for classical ML and bolted LLM-specific capability on top. If your team is planning a from-scratch LLMOps buildout in 2026, that’s worth questioning before you sign anything.
The Numbers: How Big Is This, Really
The market-sizing reports diverge, sometimes by 20 to 40 percent, depending on how each firm scopes “MLOps.” That’s normal for a young category, but it means no single number deserves to be treated as gospel.
Grand View Research, the most methodologically transparent of the reports reviewed for this piece, puts the MLOps market at roughly $2.19 billion in its 2024 base year, projected to reach $16.6 billion by 2030, a compound annual growth rate above 40 percent. Fortune Business Insights puts 2026 alone at $4.39 billion, heading toward $89.91 billion by 2034. Precedence Research lands closer to $3.33 billion for 2026, reaching $56.6 billion by 2035. Three different firms, three different numbers, one consistent direction: steep, sustained growth concentrated in the platform segment rather than point tools.
LLMOps, meanwhile, is already nearly its own heavyweight category. Estimates put the LLMOps market at $7.14 billion in 2026, growing to $15.59 billion by 2030. That means LLMOps alone is now roughly the size the entire MLOps market was just two years ago. These aren’t two small categories slowly circling each other. They’re two large, fast-growing budgets on a collision course.
The adoption pressure behind all of this is agents. Gartner estimates that 40 percent of enterprise applications will feature AI agents by 2026, up from under 5 percent in 2025. Agents need both classical-ML-style evaluation gates and LLM-style prompt and tool governance running at the same time, which is precisely the kind of workload a split toolchain struggles to support.
And the failure rate underneath all this growth is not small. A widely cited figure puts the share of AI and ML models that never reach production above 85 percent. Separately, S&P Global Market Intelligence found that 42 percent of companies abandoned most of their AI initiatives in 2025, more than double the 17 percent abandonment rate the year before.
MLOps vs. LLMOps vs. Unified Platforms
Dimension
Classical MLOps
LLMOps
Unified / xOps (2026)
Core artifact
Trained model weights, features
Prompts, RAG pipelines, agent traces
Shared registry for models, prompts, datasets
Evaluation method
Deterministic metrics (accuracy, F1, drift)
Non-deterministic, LLM-as-judge, human review
Combined eval pipelines with both metric types
Maturity
Standardized since roughly 2019 to 2022
3 to 4 years younger, not yet standardized
Emerging, led by vendors, not yet universal
Typical tools
MLflow, Kubeflow, DVC
LangSmith, Langfuse, Braintrust, Portkey
MLflow 3.0, W&B Models + Weave
Cost profile
Predictable, per-prediction
Can run roughly 100x the cost per inference
Single FinOps layer covering both, still maturing
The Tax: Why Fragmented Teams Are Paying For This
Here’s the tension the vendor press releases don’t put in the headline: platform convergence is real, but tool-stack convergence inside most companies is lagging well behind it. Practitioner guides reviewed for this piece describe enterprise LLMOps deployments that still stitch together three to five specialized tools, a tracing tool like LangSmith or Promptflow, an observability layer like Arize AI or Langfuse, a registry like MLflow, an eval pipeline like Braintrust, and a gateway like Portkey or LiteLLM, because no single platform yet covers the whole stack end to end.
That’s the tax. Every one of those tools needs its own login, its own on-call rotation, its own budget line, and its own translation layer back to whatever the classical ML team is running. ISG’s Jeff Orr put the broader platform-strategy version of this argument plainly.
“Platform consolidation is no longer an efficiency play. It is now a structural necessity.”
Jeff Orr, Director of Research, IT and Technologies, ISG
Is that overstated? Maybe a little, depending on your company’s size. But the direction is hard to argue with once you look at where budget is actually flowing. Both Grand View Research and Fortune Business Insights show double-digit growth concentrated specifically in the “platform” segment rather than point solutions, meaning the money is already voting for consolidation even where the org chart hasn’t caught up yet.
The Skeptic’s Case: Governance Is the Real Bottleneck
Not every analysis buys the clean convergence story, and it’s worth sitting with the pushback. Practitioner research from Atlan argues that LLMOps tooling is structurally three to four years younger than MLOps tooling and simply hasn’t standardized the way MLflow, Kubeflow, and DVC did between 2019 and 2022. Their analysis ties this to a governance deficit rather than a tooling gap: one financial institution’s LLM gateway logs can’t be connected back to its governance platforms at all. Another enterprise, per the same research, still stores its AI model information in PowerPoint.
That last detail is almost funny until you remember it’s describing companies making real deployment decisions in 2026. Unifying the ops tooling doesn’t retroactively fix an organization’s data lineage practices or its audit trail. A single dashboard sitting on top of a governance mess is still a governance mess, just with a nicer front end.
Our read: the “platforms have merged” claim is true. The “discipline has merged” claim is not, at least not yet. Treat vendor unification announcements as directionally correct on tooling and meaningfully premature on governance, compliance, and cost attribution. Cost is the sneakiest part of this: a single LLM inference can run roughly 100 times the cost of a traditional ML prediction, so a genuinely unified FinOps layer has to reconcile two wildly different cost profiles under one roof. That’s a much harder systems problem than unifying an experiment tracker, and it’s exactly the part MLflow 3.0 and the W&B deal have not fully solved yet.
What CTOs Should Actually Do Now
If you’re the one deciding whether to consolidate, a few things matter more than the vendor slide deck.
Verify LLM-specific depth before you consolidate. A unified registry is only as good as its weakest layer. Check tracing coverage, eval rigor, prompt versioning, and guardrail integration against what your current point tools already do, don’t assume feature parity with five-plus years of mature MLOps tooling.
Follow the PayPal and Uber model, not a rip-and-replace. Both companies extended existing MLOps infrastructure instead of building a parallel LLMOps org from zero. That’s a lower-risk path than a wholesale platform swap.
Fix data lineage before you fix the dashboard. If your model information still lives in spreadsheets or PowerPoint, a unified platform will not solve that for you. Governance work has to happen in parallel with, not after, tooling consolidation.
Budget for the cost-attribution problem separately. Don’t assume your FinOps tooling for classical models will cleanly extend to LLM inference costs. It’s a different order of magnitude and needs its own line item.
Frequently Asked Questions
What is the difference between MLOps and LLMOps?
MLOps manages the lifecycle of traditional predictive models: training, versioning, deployment, and drift monitoring. LLMOps manages generative and foundation-model workloads: prompt versioning, retrieval-augmented generation, hallucination monitoring, and evaluation of non-deterministic output. In 2026, unified platforms increasingly handle both under one registry and observability layer.
Is LLMOps part of MLOps?
LLMOps functions more as an extension of MLOps than a fully separate discipline. It inherits MLOps’ versioning, CI/CD, and monitoring principles, then adds LLM-specific layers such as prompt pipelines, RAG evaluation, and cost-per-token tracking that classical MLOps tooling was never built to handle.
Do companies need separate teams for MLOps and LLMOps?
Not necessarily. PayPal extended its existing Cosmos.AI platform to cover LLM workloads with one team instead of standing up a parallel org. That said, most enterprises in 2026 still run three to five specialized LLM tools alongside their MLOps stack rather than a single unified toolchain.
What is a unified AI operations platform?
A unified AI operations platform, sometimes called “xOps,” manages classical ML models and LLM or GenAI applications through the same registry, monitoring, and deployment infrastructure. MLflow 3.0’s shared abstraction layer for both traditional ML artifacts and GenAI traces, prompts, and evaluations is the clearest current example.
How big is the MLOps market in 2026?
Estimates vary by research firm. Grand View Research projects the market growing toward roughly $16.6 billion by 2030 from a 2024 base near $2.2 billion. Fortune Business Insights puts 2026 alone at $4.39 billion, heading toward $89.91 billion by 2034. The wide range reflects differing scope definitions across methodologies, not disagreement about the growth trend itself.
Where This Goes Next
The vendor-level merger of MLOps and LLMOps is no longer a prediction. MLflow 3.0 shipped it, CoreWeave paid for it, and Weights & Biases built its whole product line around it. What hasn’t merged yet is the actual discipline inside most companies: the governance, the cost attribution, the on-call rotations, and the org charts that still treat classical ML and generative AI as two different jobs.
Over the next 6 to 18 months, expect three things to matter more than the platform announcements themselves. First, watch whether unified vendors close the governance gap Atlan identified, not just the tracing gap. Second, watch cost-attribution tooling specifically, since that’s the systems problem nobody has solved cleanly yet. Third, watch whether agent adoption, which Gartner expects to hit 40 percent of enterprise applications this year, forces the remaining split-stack teams to consolidate faster than they’d planned, simply because agents don’t respect the old boundary between the two disciplines.
The teams that treat this as a maturity-catch-up story, and not a symmetrical merger of two equally mature fields, are the ones that will avoid paying the tax twice.
Want more research like this before it hits the mainstream feed? Subscribe to The Neural Loop at neuralwired.com/newsletter.