Category: Technology

NeuralWired’s Technology section covers the developments reshaping how the world builds, deploys, and regulates digital innovation. We report daily on the stories driving global conversation in artificial intelligence, big technology companies, startups and venture funding, cybersecurity, consumer gadgets and devices, and blockchain and cryptocurrency.

Our technology coverage goes beyond product announcements. When a major AI model launches, we explain what it can actually do and where its claims are overstated. When a startup raises a large funding round, we look at whether the business behind it can sustain that valuation. When a cybersecurity breach hits the news, we explain who is affected and what comes next, not just what happened. Each article is built from original research into primary sources, including company statements, technical documentation, regulatory filings, and verified data, and is written by our editorial team rather than generated automatically.

Readers come to this section for daily updates on the technology stories that matter globally, from shifts inside major technology companies to emerging tools changing how people work, communicate, and build. Whether you are a founder, an investor, an engineer, or simply someone trying to understand where technology is heading next, NeuralWired’s Technology coverage is built to keep you informed without wasting your time on hype.

  • CISA’s IoT Directive: What 21B Devices Mean in 2026

    CISA’s IoT Directive: What 21B Devices Mean in 2026

    CISA’s IoT Crackdown: What 21 Billion Devices Mean Now Cybersecurity

    CISA’s IoT Crackdown: What 21 Billion Devices Mean Now

    A federal directive, a record-breaking botnet, and a 32-day remediation gap just rewrote the rules for enterprise IoT security. Here’s what CISOs need to act on, and why zero trust alone won’t save them.

    On January 7, 2026, a botnet called RondoDox fired more than 40,000 automated attack attempts at HPE OneView servers in a single four hour window. Not routers. Not smart cameras. A data center management platform running inside government agencies, banks, and industrial manufacturers. Check Point Research caught it live, and CISA added the underlying flaw to its Known Exploited Vulnerabilities catalog the same day.

    That attack is the clearest signal yet that enterprise IoT security has moved past the consumer-gadget stage. The threat now targets the infrastructure running your business, and federal regulators noticed before most private companies did. One month later, CISA issued a binding directive that private-sector security leaders are already treating as the new baseline, whether or not it legally applies to them.

    The scale problem: 21 billion devices and counting

    Ask ten analyst firms how many IoT devices exist right now and you’ll get ten different numbers, because they’re all measuring slightly different things on different dates. The most current, most cited figure comes from IoT Analytics‘ State of IoT 2025 report: roughly 21.1 billion connected IoT devices worldwide by the end of 2025, up 14% year over year, with the installed base projected to hit 39 billion by 2030.

    If you’ve seen the “17 billion devices” figure floating around, that’s not wrong, it’s just old. That number reflects an October 2024 snapshot. By mid-2026, the real count sits closer to the low twenties, and it keeps climbing at double-digit rates every year. Every one of those billions of devices is a potential entry point, and most of them were never designed with security as a priority.

    The headline stat that actually holds up: You may have seen claims that “68% of IoT devices run unpatched firmware.” We couldn’t verify that figure against any named source. What the research does support is more precise and arguably more useful: the IoT Security Foundation found that 60% of IoT security breaches trace back to unpatched firmware, making it the single largest documented cause of compromise, ahead of weak credentials or supply-chain attacks.
    Firmware maintenance is the harder half of that problem. Research from ORDR, citing Forescout telemetry, found that 32% of deployed routers run firmware that will never receive another patch, full stop. The vendor has moved on, the support window has closed, and the device stays plugged in anyway. Forescout’s broader 2026 research puts the average router or switch at 32 vulnerabilities per device, and routers and switches now account for 34% of the most critical vulnerabilities found across enterprise networks.

    MetricFigureSource
    Global connected IoT devices (2025)21.1 billion, +14% YoYIoT Analytics
    Breaches traced to unpatched firmware60%IoT Security Foundation
    Routers running firmware that will never be patched32%ORDR / Forescout
    Average vulnerabilities per router/switch32Forescout
    Edge vulnerabilities fully remediated54% (32-day median)Verizon 2025 DBIR
    Peak DDoS traffic from a hijacked-IoT botnet29.7 TbpsCloudflare, Q3 2025

    Inside CISA’s BOD 26-02

    On February 5, 2026, CISA issued Binding Operational Directive 26-02, “Mitigating Risk From End-of-Support Edge Devices.” It requires federal civilian agencies to find, patch, and eventually rip out any edge device, including IoT edge devices, routers, firewalls, switches, and wireless access points, that no longer receives vendor security updates.

    The timeline is specific and unforgiving:

    • Immediate: Patch where feasible.
    • 3 months (by May 5, 2026): Complete inventory of end-of-support edge devices.
    • 12 months (by February 5, 2027): Decommission those devices.
    • 18 months (by August 5, 2027): Full removal from the network.
    • 24 months (by February 5, 2028): Continuous discovery process in place permanently.
    CISA Acting Director Madhu Gottumukkala didn’t soften the message when the directive dropped: “Unsupported devices pose a serious risk to federal systems and should never remain on enterprise networks.”

    The directive is technically federal-only. In practice, it’s already becoming the industry’s reference clock. CISA, the FBI, and the UK’s National Cyber Security Centre have all publicly urged private companies to adopt the same timeline, and Help Net Security’s breakdown of the order notes the same pattern security teams have seen with prior directives: what starts as a federal mandate becomes an insurance underwriting question within a year.

    If you’re running a regulated business, expect your cyber insurance renewal and your next audit to start asking about edge-device lifecycle management using this exact framework, whether you’re a federal contractor or not.

    The EU has its own clock running in parallel. The Cyber Resilience Act’s 24-hour early warning obligation for actively exploited vulnerabilities kicks in on September 11, 2026, with full security-by-design and lifetime patching requirements following in December 2027. We’ve covered the CRA’s compliance mechanics and deadlines in detail in our EU Cyber Resilience Act deadline explainer, so we won’t repeat it here. What matters for this piece is that two major regulatory regimes are converging on the same conclusion at the same time: the era of shipping IoT hardware and walking away from it is over.

    The breaches that forced the issue

    Regulators don’t move this fast without a body count. 2025 and early 2026 gave them plenty of evidence.

    BadBox 2.0

    Google disclosed this one in July 2025. It’s the largest known botnet built from internet-connected TVs, streaming boxes, and digital photo frames, compromised through outdated firmware and infecting more than a million devices in the United States alone. Nobody bought a hacked photo frame on purpose. The firmware just never got a security update, and an entire product category quietly became attack infrastructure.

    Aisuru and Kimwolf

    This is the botnet pair that broke the DDoS record books. Cloudflare mitigated a 29.7 Tbps attack in Q3 2025, sourced from an estimated 300,000 to 700,000 hijacked routers, DVRs, and IP cameras. Microsoft Azure absorbed a separate 15.72 Tbps flood in October 2025 tied to the same infrastructure. By early 2026, authorities confirmed the combined Aisuru and Kimwolf networks had compromised more than 3 million devices globally, according to reporting from Swif.ai’s IoT security roundup.

    For scale: Mirai, the botnet that defined this entire threat category back in 2016, recruited 600,000 devices using just 60 default credential combinations and still managed a 1.2 Tbps attack that knocked major sites offline. A decade of public warnings, published source code, and industry conferences later, the same playbook, default credentials plus unpatched firmware, just produced an attack 24 times larger.

    RondoDox against enterprise infrastructure

    The HPE OneView campaign matters because of what it targeted, not just how big it was. Consumer routers and cameras are the old story. A data center management platform is the new one. Our read: this is the clearest evidence yet that IoT-botnet tactics have graduated from consumer gadgets to core enterprise infrastructure, and security budgets built around “protect the smart thermostats” haven’t caught up.

    The financial exposure backs that up. Aggregated breach-cost research from Vectra.ai and ORDR puts the average IoT security incident at roughly $330,000, climbing to an average of $10 million per incident in healthcare specifically, where connected medical devices and unpatched firmware collide with regulatory exposure and patient safety.

    Why zero trust breaks down in IoT and OT

    Ask any vendor and zero trust is the answer to everything, including this. Ask the people actually implementing it, and you get a more complicated picture.

    “We all agree: zero trust is necessary. But it’s been hard to implement. It doesn’t matter what you read or which framework you follow. The core issue is that we have a concept with principles and tenets, but not enough guidance on how to implement it.” Morey Haber, Chief Security Advisor, BeyondTrust, via Network World
    Haber’s framing is the industry-consensus version: zero trust works in theory, execution is the bottleneck. The sharper critique comes from people who’ve responded to what happens when it fails.

    “The biggest security incidents in 2026 will stem from compromised identities within supposedly zero trust environments. The illusion of control will persist until identity management becomes contextual and adaptive, powered by AI that can interpret intent, not just credentials.” Ariel Parnes, COO, Mitiga (former IDF Unit 8200 colonel), via SecurityWeek
    Parnes is describing a real gap: zero trust verifies credentials, not intent, and IoT devices generally don’t have the kind of identity infrastructure that makes that verification meaningful in the first place. Most IoT hardware simply can’t run the components a standard zero-trust architecture assumes. No multi-factor authentication. No client certificates. Not enough compute to support continuous verification. You can’t authenticate your way around hardware that was never built to authenticate.

    CSO Online’s analysis of the IoT and OT gap makes the sharpest structural point in the whole debate: zero trust governs access, but it doesn’t model consequence. Two systems can be fully isolated at the network layer, properly segmented, verified access on paper, and still be functionally inseparable through a shared controller, a common protocol translator, or a vendor’s remote update service. You can pass every zero-trust audit and still have a single point of failure nobody mapped.

    Timeline expectations get a reality check too.

    “We will eventually get there, but timelines extend well beyond 2026 due to fundamental structural barriers. Private data exchanges must simultaneously secure data flows across partners’ legacy systems, cloud environments, and on-premise infrastructure, while maintaining operational compatibility with hundreds of exchange participants at varying security maturity levels.” Dario Perfettibile, VP and GM of European Operations, Kiteworks, via SecurityWeek
    Put those three quotes together and you get the honest 2026 state of the industry: zero trust is the right direction, badly under-implemented, structurally mismatched to most IoT hardware, and years away from covering the gap even under optimistic timelines.

    What enterprise security teams should do now

    The Verizon 2025 Data Breach Investigations Report, drawn from more than 22,000 incidents and 12,195 confirmed breaches, found a 34% year-over-year rise in successful vulnerability exploits, with an eightfold jump in exploitation of edge devices and VPN concentrators. Among breaches that started with vulnerability exploitation, edge devices and VPNs accounted for 22%, up from just 3% the year before. Only 54% of edge vulnerabilities were fully remediated in the observation window, and the median time to fix one was 32 days.

    That 32-day number is the one worth pinning to your dashboard. It’s a real industry benchmark you can measure your own remediation SLA against, not a vendor’s aspirational target.

    Given all of that, the realistic model for 2026 isn’t “implement zero trust everywhere.” It’s a two-tier approach: identity-based zero trust for the IT systems that can actually support it, and network-based segmentation with behavioral monitoring for the IoT and OT fleet that can’t. Treating “we did zero trust” as a finished project, when your IoT devices sit entirely outside that perimeter by design, is the exact gap that shows up in next year’s breach report.

    Practical steps that map directly to what’s driving this shift:

    • Inventory first. CISA’s own timeline gives federal agencies three months just to find every end-of-support edge device. If a federal agency needs that long, assume your enterprise network has blind spots too.
    • Benchmark against 32 days. Use the DBIR’s median remediation time as your internal SLA target, and track what percentage of your edge vulnerabilities actually get fully closed, not just acknowledged.
    • Segment what you can’t authenticate. If a device can’t run MFA or a client certificate, it goes on an isolated network segment with active behavioral monitoring, not on the same trust tier as your laptops.
    • Watch the procurement deadline. By January 4, 2027, vendors selling consumer IoT to the U.S. federal government must carry the FCC’s Cyber Trust Mark. That’s a voluntary label today. It becomes a de facto procurement filter in eighteen months, and enterprise buyers will likely start asking for it too.
    For a deeper look at how these device counts are actually measured, our breakdown of Gartner’s edge computing numbers is worth a read. And if your IoT exposure runs through industrial or OT systems specifically, we’ve also mapped the ROI math behind GE and Shell’s industrial IoT deployments, which is a useful counterweight when your CFO asks why security spending on OT devices matters as much as the operational upside.

    Frequently asked questions

    How many IoT devices are there in 2026?

    Estimates vary by firm and methodology, but IoT Analytics reports roughly 21.1 billion connected IoT devices as of the end of 2025, up 14% year over year, with the installed base forecast to reach 39 billion by 2030.

    What percentage of IoT breaches are caused by unpatched firmware?

    Research from the IoT Security Foundation attributes roughly 60% of IoT security breaches to unpatched firmware, making it the single largest documented cause of IoT compromise, ahead of weak credentials or supply-chain attacks.

    What is CISA BOD 26-02?

    CISA Binding Operational Directive 26-02, issued February 5, 2026, requires U.S. federal civilian agencies to inventory, decommission, and replace edge devices, including IoT edge devices, routers, and firewalls, that no longer receive vendor security updates, on a 3-to-24-month timeline.

    Does zero trust work for IoT devices?

    Only partially. Most IoT devices lack the compute power to run standard zero-trust components like multi-factor authentication or client certificates, so security teams typically apply a two-tier model: identity-based zero trust for IT systems, and network-based segmentation and behavioral monitoring for IoT and OT devices that can’t participate directly.


    Where this goes next

    Here’s what’s actually different now. Enterprise IoT security stopped being a device-hygiene checklist item somewhere between the RondoDox campaign and CISA’s February directive, and became a board-level compliance question with a hard clock attached. The 21 billion devices already deployed aren’t getting replaced overnight, the firmware problem isn’t getting solved by a single patch cycle, and zero trust isn’t the finished solution the marketing suggests.

    Over the next 6 to 18 months, watch three things specifically: whether private-sector cyber insurers start writing CISA’s timeline into policy requirements, whether the EU CRA’s September 2026 incident-reporting deadline produces the first wave of public disclosure data on IoT breach frequency, and whether the two-tier zero-trust model becomes the named industry standard or stays an informal workaround.

    The organizations that treat this quarter’s device inventory as a compliance chore will be the ones explaining a breach to their board next year. The ones that treat it as the actual security perimeter it is will just be doing their jobs.

    Want this kind of analysis before it hits your feed? Subscribe to The Neural Loop at neuralwired.com/newsletter.

  • Shopify AR Cuts Return Rates 40% With WebXR (2026)

    Shopify AR Cuts Return Rates 40% With WebXR (2026)

    WebXR Arrives: Browser AR Cuts Retail Returns Up to 40%
    Retail Technology / WebXR

    WebXR Arrives: Browser AR Cuts Retail Returns Up to 40%

  • EU Cyber Resilience Act: IoT Deadline Explained 2026

    EU Cyber Resilience Act: IoT Deadline Explained 2026

    Regulation & Compliance

    The EU Cyber Resilience Act’s IoT Deadline Is Coming, and the Rulebook Isn’t Ready

  • Workday AI Hiring Lawsuit: What HR Must Know in 2026

    Workday AI Hiring Lawsuit: What HR Must Know in 2026

    Mobley v. Workday: Why HR’s AI Hiring Tools Are a Legal Time Bomb
    AI & Employment Law

    Mobley v. Workday: The AI Hiring Lawsuit HR Can’t Ignore

    Derek Mobley applied to more than 150 jobs on Workday’s platform. He got rejected from almost all of them, some in minutes, some at 2 a.m., all by software he never spoke to. Three years later, that rejection pile has turned into the case reshaping how every company in America is allowed to use AI to hire people, and most HR departments still haven’t read the ruling.

    If your company uses an applicant tracking system, a resume screener, or a “candidate scoring” tool built by a vendor, Mobley v. Workday is not background noise. It’s the reason your legal exposure just changed, whether or not anyone told you.

    What Mobley v. Workday Actually Decided

    Filed in February 2023, Mobley v. Workday started as a straightforward discrimination complaint. Derek Mobley, an African American man over 40 with a disclosed disability, alleged Workday’s applicant screening tools rejected him on the basis of race, age, and disability, not the humans who happened to be using the software.

    The legal theory is what made this case different. Mobley didn’t just sue the employers who rejected him. He sued Workday itself, arguing the vendor acted as an “agent” of every employer using its screening tools, and could therefore be held directly liable under federal anti-discrimination law.

    In July 2024, Judge Rita Lin of the Northern District of California let that theory proceed. By May 2025, she certified a collective action under the Age Discrimination in Employment Act, keeping the disparate impact claim alive even after dismissing the intentional discrimination claim. Then, in early 2026, Workday tried a new angle: it argued that a 2024 Supreme Court ruling, Loper Bright Enterprises v. Raimondo, which ended Chevron deference, should invalidate decades of precedent applying age discrimination protections to job applicants, not just existing employees.

    Judge Lin didn’t buy it. She found the EEOC’s longstanding interpretation “persuasive” under a lower legal standard called Skidmore deference, and let the applicant claims move forward.

    Why this matters if you’re not being sued: the “agent” theory means your AI vendor’s exposure and your company’s exposure are no longer separate questions. If the vendor gets sued and loses, the precedent lands on your desk too, whether your contract says the vendor is liable or not.
    There’s a second wrinkle most compliance guides skip. In May 2026, a magistrate judge denied a motion to force Workday to hand over its internal bias-testing data, ruling that because Workday’s lawyers curated the data for legal advice, it was protected by attorney-client privilege. That’s a genuinely uncomfortable fact for anyone selling “just audit everything and publish it” as the safe path. Routing bias testing through counsel can shield results from discovery. It can also sit awkwardly next to public disclosure laws that assume the opposite. More on that tension below.

    The Lawsuits Stacking Up Behind Mobley

    Mobley isn’t an outlier anymore. It’s a template. Three other cases filed in 2026 use variations of the same argument, and each one targets a different weak point in how companies deploy AI screening.

    • Kistler & Bhaumik v. Eightfold AI (filed January 2026): plaintiffs allege Eightfold, used by companies including Microsoft and PayPal, secretly generated “likelihood of success” scores on a 0 to 5 scale without disclosing it, a claim built on the Fair Credit Reporting Act and California’s investigative consumer reporting law rather than discrimination statutes.
    • Swanson v. IBM (filed May 2026): a 24-year IBM employee alleges age discrimination tied to an AI-generated rejection following a 2024 layoff, applying Mobley’s logic to a company’s own internal tool rather than a third-party vendor.
    • Harper v. SiriusXM (filed 2025): alleges screening software used education and home address, essentially race proxies, across roughly 150 applications.
    Notice what’s happening here. These aren’t four versions of the same lawsuit. They’re four different legal theories converging on the same conclusion: courts are willing to treat algorithmic hiring decisions the same way they’d treat a human recruiter’s decisions, and sometimes with less patience.

    The Stanford Study That Broke the “We Passed Our Audit” Defense

    If Mobley is the legal story, a Stanford study published in May 2026 is the data story, and it’s the more damaging one for HR teams who thought a vendor’s compliance certificate meant they were covered.

    Researchers led by Rishi Bommasani at Stanford HAI, alongside Sarah Bana, Kathleen Creel, Dan Jurafsky, and Percy Liang, analyzed more than 4 million job applications from roughly 3 million applicants across 156 large employers, all screened through the same vendor’s algorithm, Pymetrics (now owned by Harver). The paper, “Algorithmic Monocultures in Hiring,” is headed to ACM FAccT in Montreal.

    Here’s the finding that should worry every HR leader relying on a vendor’s own bias report: when the researchers examined outcomes position by position, the legally correct method under the “four-fifths rule” used in U.S. employment law, they found 10.62% of the 1,746 job positions studied showed adverse impact against Black applicants. The vendor’s own published, aggregated audits showed no measurable bias at all.

    “I think the most significant result of our study is how much bias we find in this algorithmic hiring system. The vendor has published aggregated audits that demonstrate that their tools do not demonstrate measurable bias. I was surprised because I thought that their algorithms would be an example of best practice.” Sarah Bana, Digital Fellow, Stanford Digital Economy Lab, via Stanford Digital Economy Lab Q&A
    The study also surfaced something new to the compliance conversation: “systemic rejection.” Among applicants who applied to four positions through the same vendor, 10% were rejected from every single one, a rate the researchers show is statistically inconsistent with independent decisions (a chi-squared value of 18,481, for the statistically inclined). One vendor’s algorithm, used across hundreds of employers, can create a single point of failure that no individual company’s internal audit would ever catch.

    “I don’t think we want to discourage the application of AI in this domain, but recognize the stakes are high and be judicious in the approach.” Rishi Bommasani, Senior Research Scholar, Stanford HAI
    Bommasani’s framing matters. This isn’t an argument to rip out AI screening tools. It’s an argument that the industry’s go-to proof of fairness, a vendor’s own aggregated audit, isn’t proof of anything at the level that actually matters legally: the individual job position.

    The State Law Patchwork HR Teams Are Missing

    While the federal government has pulled back on AI hiring enforcement (the EEOC’s 2023 guidance on AI screening was quietly removed from its website, and an April 2025 executive order directs agencies to deprioritize disparate impact claims generally), states and cities are moving in the opposite direction. If your governance plan is built around federal rules alone, it’s already out of date.

    JurisdictionRuleStatus in 2026
    New York CityLocal Law 144: annual bias audits for Automated Employment Decision ToolsIn force since 2023; enforcement was found weak by state auditors, tighter enforcement promised for 2026
    ColoradoSB 26-189 (replaced the original SB 24-205)Delayed to January 1, 2027; scaled back from a broad duty of care to a narrower notice-and-review regime
    IllinoisAI employment decision disclosure statuteIn effect since January 1, 2026
    CaliforniaCivil Rights Council ADS rules and CPPA ADMT rulesEffective October 2025 and January 2026; make bias testing (or its absence) explicit evidence in discrimination claims
    New York City’s law is the one worth paying closest attention to, and not for the reason most compliance memos suggest. A December 2025 audit by the New York State Comptroller found the city’s own enforcement agency had reviewed 32 companies and identified just one non-compliance issue. Independent auditors reviewing the exact same 32 companies found at least 17. Roughly three-quarters of test calls to the city’s complaint hotline never even reached the right department.

    That’s the “toothless law” era. It’s ending. The Comptroller’s findings came with a public commitment from the city’s consumer affairs department to tighten enforcement in 2026, which means the penalty structure, $500 to $1,500 per violation per day, with each day of non-compliant use counted separately, is about to start getting used the way it was written. A single non-compliant screening tool left unaudited for a month can generate $15,000 to $45,000 in exposure before any per-candidate multiplier even applies.

    Companies covered by NYC’s rule, even if they’re not based there: Local Law 144 applies to any employer or agency using an AEDT to evaluate NYC-based candidates, including remote roles. If you hire remote employees who happen to live in the five boroughs, this law already applies to you.
    For context on how the parallel financial-sector and healthcare rules are moving, including the EU AI Act’s shifting high-risk deadlines and the Fed’s model risk guidance, NeuralWired covered the sector-by-sector explainability requirements in detail in our EU AI Act 2026 explainer. This piece deliberately doesn’t retread that ground; the hiring track runs on its own, older set of laws (Title VII, the ADEA, the ADA) that are largely immune to the federal deregulatory pressure hitting newer AI-specific state statutes.

    What an Actual Governance Framework Looks Like

    Most companies deploying AI hiring tools in 2026 don’t have a governance gap because nobody’s heard of NIST or ISO. They have a gap because the frameworks that exist are voluntary, self-attested, and easy to satisfy on paper while missing the exact problem the Stanford study exposed.

    A framework that actually reduces risk, rather than just producing a policy binder, needs a few specific things:

    • Position-by-position bias testing, not aggregated audits. The Stanford study proves aggregated numbers can hide double-digit adverse impact rates at the individual job level.
    • A documented vendor liability allocation. Mobley shows vendors can be directly liable, and that employers can’t assume the vendor absorbs all the risk just because the contract says so.
    • An inventory of every AEDT actually in use, including tools embedded inside applicant tracking systems that HR may not realize qualify as automated decision tools under NYC or California rules.
    • A deliberate, documented choice about whether bias testing runs through counsel (for privilege protection) or is conducted for public disclosure (as LL144 requires). Doing both without a plan creates contradictions a plaintiff’s attorney will find.
    • Human review checkpoints that are real, not rubber-stamp, since Colorado’s revised law and California’s ADMT rules both lean on documented human oversight as a compliance anchor.
    Roughly 12% of enterprises currently have what researchers classify as “mature” AI governance processes, according to HFS Research and Infosys data cited in industry analysis published in 2026, despite how widely these tools are already deployed. That gap is the story. The tools showed up years before the governance did.

    Why “We Have a Framework” Isn’t the Same as “We’re Safe”

    Here’s the uncomfortable part of this story that vendors selling governance platforms don’t lead with: adopting NIST’s AI Risk Management Framework or getting ISO 42001 certified demonstrates that you have a process. It doesn’t independently verify that anyone actually ran the specific test that matters, position-level adverse impact analysis, on your specific tool, on your specific job postings.

    Our read: the industry has spent three years selling “governance” as a checkbox exercise, and the Stanford study is the first large, methodologically serious dataset to show what happens when the checkbox gets checked but the underlying test never runs. A vendor’s aggregated audit passed. Real candidates still lost out because of their race, at the position level, in over one in ten jobs studied.

    The regulatory landscape isn’t converging around a clean answer either. The EU is delaying high-risk AI obligations, currently expected to shift from August 2026 to December 2027, pending formal adoption of the “Digital Omnibus” package. Colorado gutted its own comprehensive AI law and pushed it back eighteen months. The EEOC pulled its guidance. Meanwhile New York City, Illinois, and California are all tightening in the same window. A framework calibrated to satisfy one jurisdiction won’t satisfy the others, and right now those jurisdictions are moving in opposite directions inside the same country.

    Is a rushed governance rollout actually going to hold up? Probably not, if it’s built to today’s rules rather than to the underlying civil rights statutes (Title VII, the ADEA, the ADA) that Mobley and its sibling cases are actually built on. Those laws aren’t going anywhere, regardless of what happens to any single state’s AI-specific statute.

    FAQ

    Can a company be sued for AI hiring bias?

    Yes. Mobley v. Workday established that an AI vendor can be directly liable for employment discrimination under an “agent” theory, not just the employer using the tool. The case allows disparate impact claims to proceed under the ADEA, ADA, and Title VII based on algorithmic outcomes alone, without proof of intentional bias.

    What is NYC Local Law 144?

    It requires any employer or agency using an Automated Employment Decision Tool on NYC-based candidates to commission an independent bias audit within the prior 12 months, publicly post a summary, and give candidates 10 business days’ notice before use. Penalties run $500 to $1,500 per violation per day.

    Does a vendor’s bias audit guarantee an AI hiring tool is fair?

    Not necessarily. A 2026 Stanford-led study of 4 million job applications found a vendor’s own published, aggregated audit showed no measurable bias, while independent position-by-position analysis, the method U.S. employment law actually applies, found adverse impact against Black applicants in over 10% of individual job positions.

    Is the EEOC still enforcing AI hiring rules in 2026?

    The EEOC’s 2023 guidance on AI hiring discrimination was removed from its website, and a 2025 executive order directs federal agencies to deprioritize disparate impact theories generally. Private litigants can still pursue these claims independently, and state and local laws in New York City, Illinois, and California have separately tightened requirements.


    Where This Goes Next

    Three things are now true that weren’t true two years ago. AI hiring vendors can be sued directly, not just the employers who use their tools. A vendor’s own bias audit is no longer credible proof of fairness on its own. And the regulatory map is fragmenting rather than converging, with federal enforcement receding just as city and state rules tighten.

    Watch three things over the next 6 to 18 months: how NYC’s promised 2026 enforcement crackdown actually plays out once the Comptroller’s findings force DCWP’s hand, whether the Mobley discovery ruling on attorney-client privilege gets tested again as more plaintiffs demand vendor bias data, and whether the EU’s Digital Omnibus delay to December 2027 actually gets formally adopted or falls apart before the original August 2026 deadline.

    If your company runs any AI screening tool and hasn’t run a position-level bias check on it, independent of whatever your vendor handed you, that’s the gap to close first, not the last one.

    Subscribe to The Neural Loop for the stories HR, legal, and compliance teams need before they hit the docket.

  • MakerDAO Sky Governance 2026: $400M No-CEO Vote

    MakerDAO Sky Governance 2026: $400M No-CEO Vote

    How MakerDAO Moved $400M With No CEO or Board Web3 & Enterprise Governance

    How MakerDAO Moved $400M With No CEO or Board

    In October 2022, a organization with no executives and no office voted to put $400 million into US Treasury bonds. By 2026 that position had grown twentyfold, and enterprise governance teams are now quietly copying the mechanics, while ignoring the part that never got fixed.

    The vote that moved $400 million without a signature

    No CEO approved it. No board met to discuss it. No headquarters existed to house the decision. In October 2022, MakerDAO announced a plan to put $500 million into short-term US Treasury bonds and investment-grade corporate bonds, split into $400 million for Treasuries and $100 million for corporate debt. The whole thing was approved through a community-wide vote that ran for months, then executed by a third-party asset manager called Monetalis under a mandate the community itself wrote.

    This is the transaction enterprise readers keep half-remembering when they hear “a DAO managed $400 million with no CEO.” It’s real, it’s dated, and it’s one of the cleanest test cases in existence for whether decentralized governance can handle institutional-scale money. MakerDAO’s head of growth, Nadia Alvarez, put the community’s mood at the time plainly:

    “The 80-20 split between treasuries and bonds remained the favored approach during the voting process. This showcases the opportunity associated with the move, and seeing such adamant support from the community is very exciting.” Nadia Alvarez, Head of Growth, MakerDAO. Source: Decrypt, October 6, 2022
    Four years later, that $400 million seed has become the dominant force in the entire real-world-asset lending category. And it happened without a single executive signing off on the wire transfer. If you run governance, risk, or treasury at an actual company, that should get your attention, not because you should copy it wholesale, but because pieces of it already work better than what you’re running today.

    How a DAO actually approves a nine-figure trade

    Strip away the crypto vocabulary and the process looks less alien than it sounds. It runs in four stages:

    1. Forum debate. Someone proposes the idea on a public discussion board (Discourse). Anyone can argue for or against it, in public, with their name or wallet attached.
    2. Temperature check. A non-binding poll (Snapshot) gauges whether the community actually wants this before anyone spends gas fees on a real vote.
    3. On-chain executive vote. Token holders (MKR at the time, SKY now) vote directly on the blockchain. The vote itself is the approval, there’s no separate signature required.
    4. Delegated execution. A licensed third party, in this case Monetalis, executes the trade inside a policy envelope the vote defined: which assets, what caps, what counterparties.
    That last step is the part most people miss when they describe DAOs as “leaderless.” Someone still has to actually buy the bonds. MakerDAO didn’t eliminate execution authority, it separated it from policy authority, and put a licensed professional in the execution seat instead of an internal executive. A follow-up report from CryptoSlate confirmed the exact structure: the $500 million split into two vehicles, RWA007-A routed through Bank Sygnum and RWA007-B through Baillie Gifford, and within four months the strategy was already generating roughly $2.1 million in fees, more than half of MakerDAO’s entire annualized revenue at the time.

    The part the headline leaves out: a 48-hour delay sits between an executive vote passing and it actually executing on-chain. That window exists specifically so the community can catch and cancel a malicious or mistaken vote before money moves. It’s a circuit breaker built directly into the governance code, something most corporate approval chains still do with a Slack thread and hope.

    From $400M to $8.2B: how far this went

    The 2022 vote wasn’t a one-off experiment. It became the template for what MakerDAO is now. In March 2023, the DAO voted to scale the Treasury strategy from $500 million to $1.25 billion. In August 2024, MakerDAO rebranded entirely to Sky, launched a new stablecoin (USDS) and governance token (SKY, converting from MKR at a fixed 1:24,000 ratio), and split into a network of specialized sub-organizations internally called “Stars,” starting with Spark and, later, a Solana-focused Star called Keel.

    By mid-2026, per an analysis from Token Dispatch, Sky’s total real-world-asset exposure had reached $8.245 billion, which is 52.2% of its own total value locked and, more strikingly, 78% of all real-world assets deployed across DeFi lending, industry-wide. A single protocol that started with a $400 million bond vote now dominates the category it helped invent.

    DAOOnchain treasury (Q1 2026)Rank
    Uniswap$4.8 billion1
    Sky (MakerDAO)$3.9 billion2
    Optimism$2.1 billion3
    Arbitrum$1.7 billion4
    Lido$1.4 billion5
    Onchain treasury figures per DeepDAO tracking, cited via eco.com. Note this measures raw onchain treasury, not total RWA exposure, which is a different (larger) number for Sky. Track the two separately, conflating them is the single most common error in coverage of this space.

    The scale-up brought a genuinely new behavior with it too. Sky’s “Smart Burn Engine” used surplus revenue, largely generated by that Treasury bond yield, to buy back and burn more than $60 million of MKR in 2024 alone. That’s a capital-return policy, functionally a corporate buyback, executed with no CFO and no board resolution behind it. Whether that’s a feature or a warning sign depends entirely on who you ask.

    What enterprise governance teams are actually borrowing

    Corporate treasury and risk teams aren’t rebuilding MakerDAO. They’re taking three specific pieces of it:

    1. The service-provider model

    Governance approves a defined policy envelope, allowable assets, exposure caps, a liquidity floor, and then delegates in-envelope execution to an accountable, licensed third party. That’s directly portable to a corporate treasury committee that wants faster execution without giving up policy control at the board level.

    2. Programmable delay as a circuit breaker

    The 48-hour execution delay is a concrete, auditable mechanism. It’s slower than a lot of corporate decisions, and that’s the point, it buys time to catch an error or a bad actor before funds move, with the entire deliberation visible on a public ledger rather than buried in an inbox.

    3. Transparent, real-time treasury reporting

    Every dollar in Sky’s Treasury position is traceable on-chain, in real time, by anyone. Most companies produce that level of transparency once a quarter, if that.

    Aaron Wright, co-founder of Tribute Labs and one of the lawyers who helped write Wyoming’s DAO LLC statute, has a description of the underlying appeal that sticks:

    “A DAO is a subreddit with a bank account. The energy of the Internet is swarmlike, but there’s no real productive way to channel that. I believe DAOs are that answer.” Aaron Wright, Co-founder, Tribute Labs. Source: Forbes, February 2022
    Wright’s own caveat, from the same interview, matters just as much: DAOs still need a real-world legal wrapper, a Wyoming or Marshall Islands DAO LLC, to sign contracts, hold licenses, or get sued in a normal court. “No headquarters” is true in the romantic sense. It is not true in the sense a general counsel cares about.

    What broke along the way

    The optimistic version of this story stops at “it scaled.” The honest version has to include what governance by token vote has repeatedly failed to prevent.

    The $182 million flash loan attack

    In April 2022, an attacker borrowed roughly $1 billion in a flash loan from Aave, Uniswap, and SushiSwap, used it to instantly acquire majority voting power in Beanstalk Farms, a DeFi lending protocol, and executed a malicious proposal in the same transaction, the same block, transferring the protocol’s liquidity straight to their own wallet. Beanstalk lost $182 million. The attacker walked away with roughly $76 to $80 million in profit. Beanstalk’s response afterward was blunt: it ripped out its on-chain governance module entirely and replaced it with a community-run multisig wallet, quietly admitting that pure token-weighted voting, without a time delay, is a structural liability, not just a Beanstalk problem.

    Voter apathy never actually went away

    The uncomfortable number underneath every DAO success story is participation. Reported turnout figures for 2025 and 2026 vary by protocol but land in a consistent range: some analyses put typical DAO proposal turnout under 2%, others put average engagement closer to 17%, and Ethereum co-founder Vitalik Buterin has separately argued in public commentary that participation in top DAOs frequently dips below 10%, according to reporting on his November 2025 remarks, warning that low turnout leaves protocols vulnerable to being effectively run by a small number of large token holders regardless of what the governance charter says on paper.

    MakerDAO’s own numbers back this up. A 2024 vote on US Treasury bill collateral saw a small block of institutional voters carry more than 70% of all participating MKR. Peer-reviewed and preprint research on DAO governance generalizes the pattern further: across many DAOs, fewer than ten wallets hold more than half of total voting power. “No board” turns out to mean “a smaller, less accountable board,” more often than it means no concentration of power at all.

    The risk the DAO flagged, then walked past anyway

    MakerDAO’s own Endgame governance document, written years before the Treasury strategy scaled to billions, contained a direct warning about the exact assets it went on to buy:

    “The major downside is that they can be seized easily. Anything that can be seized by global powers may be at risk of seizure through legal means.” MakerDAO Endgame governance document. Cited via Token Dispatch, May 2026
    The community read that warning and voted to put roughly $8 billion into US Treasuries anyway. That’s not necessarily a mistake, Treasuries are about as safe an asset as exists, but it’s a real illustration of a structural weakness: a DAO that took months of deliberation to build a large position is also, by design, slow to unwind one if the regulatory ground shifts underneath it.

    A short, ugly history

    EventYearLossRoot cause
    The DAO hack2016~$60M (3.6M ETH)Reentrancy vulnerability in the smart contract
    Compound distribution bug2021~$90M mis-distributedBuggy contract upgrade required emergency governance vote
    Beanstalk flash-loan attack2022$182MInstant governance token acquisition via flash loan, no time delay

    The honest verdict

    Decentralized treasury governance works operationally. MakerDAO proved that a $400 million bet, approved by public vote and executed by a licensed third party, can scale into a multi-billion-dollar institutional position without a CEO ever signing a document. That’s a real, useful, replicable finding.

    What it did not do is solve the participation problem that has haunted DAOs since The DAO itself collapsed in 2016. It built delegated layers instead, service providers, SubDAOs, “Stars”, that increasingly resemble conventional management, just wearing a different legal costume. An independent 2026 assessment of Sky’s SubDAO architecture put it plainly: operational autonomy improved, complexity overhead rose substantially, and roughly the same 10 to 20 percent of token supply engages in governance regardless of what the token is called.

    Our read: the lesson for enterprise governance teams isn’t “flatten your hierarchy.” It’s “separate policy-setting, which can be broad and slow, from execution, which should be delegated to accountable professionals operating inside hard-coded limits.” Borrow the circuit breaker. Borrow the transparency. Don’t borrow the assumption that removing a CEO removes concentrated power, it just moves where that power hides.

    Regulatory context worth tracking if you’re evaluating any of this for actual enterprise use: the GENIUS Act’s OCC rulemaking deadline and MiCA’s final compliance deadline both land around July 2026, pushing stablecoin and DAO-adjacent structures toward provable regulatory compatibility. Any adoption of these patterns in the US or EU needs compliance review built in from the start, not bolted on after.


    Frequently asked questions

    What is a DAO and how does it manage money without a CEO?
    A DAO manages funds through smart-contract-held treasuries controlled by token-holder votes instead of executives. Proposals are debated publicly, voted on-chain, and executed automatically once approved, as MakerDAO did in 2022, moving $400 million into US Treasury bonds via community vote with no CEO or board involved.

    How much money does MakerDAO/Sky manage in 2026?
    As of early 2026, Sky (formerly MakerDAO) holds roughly $3.9 billion in onchain treasury per DeepDAO tracking, with total real-world-asset exposure reported around $8.2 billion, up from the original $400 million Treasury allocation approved in October 2022.

    What is the biggest DAO governance failure?
    Beanstalk Farms lost $182 million in April 2022 when an attacker used a $1 billion flash loan to instantly acquire majority governance voting power, then passed and executed a malicious fund-transfer proposal within a single blockchain transaction, exposing a structural flaw in token-weighted voting without time delays.

    Can a DAO legally hold and invest in US Treasury bonds?
    Yes. DAOs like MakerDAO have done this through licensed third-party asset managers, such as Monetalis, operating under a governance-approved mandate, converting stablecoin reserves to dollars to purchase Treasuries, while typically using a legal wrapper such as a Wyoming DAO LLC for real-world contracting.

    What replaced MakerDAO’s MKR token?
    In August 2024, MakerDAO rebranded to Sky and introduced SKY as its governance token, converting from MKR at a fixed 1:24,000 ratio. MKR still exists and remains convertible, but SKY is now the primary governance and voting asset across Sky’s SubDAO network.


    Where this goes next

    What you now understand that you probably didn’t twenty minutes ago: the “$400M, no CEO” story is real, it’s MakerDAO’s Monetalis Clydesdale vote, and it scaled into the dominant force in DeFi’s real-world-asset category. But scale never fixed the concentration problem underneath it, it just professionalized around it.

    Over the next 6 to 18 months, watch three things: whether Sky’s Keel SubDAO deployment on Solana changes voter participation numbers at all, whether the GENIUS Act and MiCA compliance deadlines push more DAOs toward Wyoming or Marshall Islands legal wrappers, and whether any enterprise consortium actually pilots the service-provider model with a real corporate treasury rather than just talking about it at a conference.

    A quick honest note on search: no legitimate SEO practice, including everything in this piece, guarantees first-page Google rankings within two or three days. Rankings depend on crawl timing, domain authority, competing content, and Google’s own indexing cycle, none of which any single article controls. What this piece does give you is a strong, well-sourced foundation to rank on the merits over time.

    Want breakdowns like this before everyone else covers them? Subscribe to The Neural Loop at neuralwired.com/newsletter.


    Related on NeuralWired: Smart Contract Audit Checklist 2026: Enterprise Edition · BlackRock, Goldman Sachs & the RWA Tokenization Playbook 2026 · JPMorgan & HSBC Lead RWA Tokenization in 2026 · JPMorgan, DeFi vs Banks: The Real Risk Comparison 2026

  • EU AI Act 2026: Why Explainable AI Just Became Law

    EU AI Act 2026: Why Explainable AI Just Became Law

    EU AI Act 2026: Why Explainable AI Just Became Law | NeuralWired
    AI REGULATION / EXPLAINABLE AI

    EU AI Act 2026: Why Explainable AI Just Became Law

    Four different regulators, on four different continents of oversight, just landed on the same word in the same twelve months: explainability. Not “accuracy.” Not “fairness” in the abstract. Explainability, the specific, auditable ability to say why an AI system made the call it made.

    If you run model risk at a bank, compliance at an insurer, or a clinical AI program at a hospital, that convergence is the story of your second half of 2026. The EU AI Act’s transparency rules go live August 2. The Federal Reserve rewrote its bank model guidance in April. State insurance regulators are piloting an actual examiner checklist right now. And the FDA has quietly made “how black-box is this thing” the line between an exempt tool and a regulated medical device.

    None of these four rules say the same thing, cover the same companies, or run on the same clock. Treat them as one checkbox and you’ll miss the one that actually applies to you. Here’s the real map, sector by sector, plus the one credentialed voice arguing the entire premise is built on sand.

    Quick answer, for the skimmers Explainable AI (XAI) went from research niche to binding, examinable requirement across four sectors in a single year. The EU AI Act’s Article 13 transparency rules are enforceable from August 2, 2026, with penalties up to roughly €35 million or 7% of global turnover. U.S. bank regulators’ SR 26-2 (April 2026) covers traditional ML credit models at banks over $30 billion in assets, but explicitly excludes generative AI. Insurance regulators in 25+ U.S. states now require written AI transparency programs under the NAIC Model Bulletin. The FDA treats “how explainable is this model” as a deciding factor in whether a clinical AI tool needs premarket device review. Meanwhile, state-level AI consumer protection law (Colorado) is being rolled back under federal pressure, so the pattern to watch isn’t “AI regulation is coming,” it’s “sector regulators are tightening while state law loosens.”

    The Convergence: Four Regulators, One Word

    This isn’t one law creating a moment. It’s four independent regulatory tracks arriving at the same demand within the same window: EU technology law, U.S. banking supervision, state insurance regulation, and federal medical device policy. That’s the actual news, and it’s why a compliance calendar built around a single deadline will fail you.

    Each track defines “explainable” differently, covers different companies, and enforces on a different timeline. A bank that nails SR 26-2 compliance could still be exposed under the EU AI Act if it serves European customers. An insurer with a clean NAIC governance file could still fail a state-specific rule like New York’s, which goes further by requiring the state’s Department of Financial Services to be able to review vendor AI tools directly and demand audits.

    The EU AI Act’s August 2 Deadline

    Mark the date: August 2, 2026. That’s when Article 13 transparency obligations for high-risk AI systems become enforceable under the EU AI Act. High-risk, per Annex III, includes systems used in credit scoring, insurance pricing, and medical devices, exactly the sectors this article covers.

    The requirement itself is deceptively simple to state and hard to satisfy: systems must be designed so their operation is transparent enough for deployers to interpret outputs and use them appropriately, and providers must disclose the technical characteristics needed to explain what the system produced.

    Miss it, and the penalties aren’t symbolic. Non-compliant high-risk systems face fines up to roughly €35 million (about $38.5 million) or 7% of global annual turnover, whichever is higher. (Cross-check that figure against Article 99 directly before you cite it in a client memo. Secondary sources vary slightly on the exact wording.)

    The catch nobody’s talking about The European Commission’s own guidelines clarifying how to actually satisfy Article 13 were due in Q2 2026. That means companies may be asked to comply with obligations before Brussels has finished explaining what compliance requires. Fixed deadline, moving target.

    SR 26-2: What the Fed Actually Changed for Banks

    On April 17, 2026, the Federal Reserve, the OCC, and the FDIC jointly issued SR 26-2, replacing the 2011-era SR 11-7 as the governing model risk management framework for banks. Here’s the nuance that most coverage is going to flatten: SR 26-2 is a narrowing, not an expansion. Traditional statistical and machine learning credit and fraud models stay fully in scope, subject to validation covering conceptual soundness, outcomes analysis, and ongoing monitoring. Generative and agentic AI models are explicitly carved out as “novel and rapidly evolving” and not yet governed by this letter.

    The threshold that matters for your calendar: SR 26-2 is expected to be most relevant to banking organizations with more than $30 billion in total assets. If you’re under that line, this specific letter isn’t the one keeping you up at night.

    What happens to the GenAI tools your bank is already using to draft adverse-action language or summarize override rationale? Nothing, for now. Regulators say they plan to issue a request for information addressing AI model risk more broadly, including generative and agentic AI, but that’s a future document, not a current rule. Translation: build a parallel, self-governed track for GenAI, because SR 26-2 won’t cover it and nothing else currently does either.

    Insurance: The NAIC Bulletin and the 30-Day Test

    The NAIC Model Bulletin on the Use of AI Systems by Insurers, adopted back in December 2023, has quietly become the operative insurance AI rule in most of the country. As of early 2026, 25 states plus Washington, D.C. have adopted it, up from just 11 states in April 2024. The bulletin requires a written AI Systems (AIS) Program and specifically names the transparency and explainability of outcomes to the impacted consumer as a factor insurers must weigh.

    The real test isn’t whether you have a policy document. It’s whether you could produce a plain-language explanation of an adverse decision, a denied claim or a rate increase, within 30 days of a hypothetical examiner request. Most insurance compliance teams haven’t actually run that drill.

    That drill is about to get formalized. NAIC’s new AI Systems Evaluation Tool, an examiner questionnaire, is being piloted in 12 states from January through September 2026, with wider adoption expected at the NAIC Fall National Meeting. This is the mechanism that turns bulletin language into actual exam findings. It’s not live nationwide yet, but it’s close.

    Healthcare: The FDA’s Black-Box Line

    The FDA hasn’t issued one binding “XAI rule.” Instead, a stack of guidance functions like one: the June 2024 Transparency for Machine Learning-Enabled Medical Devices guiding principles, a predetermined change control plan guidance finalized in December 2024, and a lifecycle management guidance from January 2025.

    For clinical decision support tools specifically, explainability has become the functional dividing line between “exempt software” and “regulated medical device.” The more black-box a CDS algorithm looks, especially when it’s AI-driven, the more likely the FDA is to pull it into premarket device review rather than let it operate as exempt clinical software.

    This isn’t a hypothetical problem waiting to happen. The FDA has already authorized more than 580 AI-enabled medical device models, with roughly 400 of them aimed at helping radiologists catch things like malignant tumors or stroke signs, and a large share of those algorithms remain genuinely black-box, either because they’re proprietary or too complex to fully unpack. Explainability isn’t a future compliance category in healthcare. It’s already sitting inside hundreds of tools making live clinical calls.

    Sector-by-Sector Comparison Table

    Framework Binding or Guidance Effective Date Who It Covers Max Penalty
    EU AI Act, Article 13 Binding law August 2, 2026 High-risk AI: credit, insurance, medical devices ~€35M or 7% global turnover
    SR 26-2 (Fed/OCC/FDIC) Supervisory guidance Issued April 17, 2026 Banks over $30B in assets; traditional ML models only No fixed fine; supervisory action
    NAIC AI Model Bulletin State-adopted guidance Adopted state-by-state since 2023 Insurers in 25 states + D.C. Varies by state insurance code
    FDA AI/SaMD Guidance Guidance, device-triggering Ongoing since June 2024 AI-enabled clinical decision support and diagnostics Non-compliant device pulled from market

    The Counter-Current: Colorado’s Rollback

    Here’s the part of the story that complicates any tidy “regulation is coming” headline. While sector regulators tighten, state-level consumer protection AI law is being walked back, and fast.

    Colorado’s SB 24-205, the most prescriptive state AI law on the books, with a duty of care against algorithmic discrimination, got repealed and replaced by SB 26-189, signed May 14, 2026. The replacement delays the effective date to January 1, 2027 and strips out the duty of care, deployer risk management programs, impact assessments, and several attorney general reporting obligations, swapping in a narrower disclosure-only regime.

    That reversal didn’t happen in a vacuum. On April 9, 2026, xAI sued to block enforcement of Colorado’s law on constitutional grounds, and the Department of Justice moved to intervene on xAI’s side, the first time federal authorities have joined a suit against a state AI law. The root cause traces back to a December 11, 2025 executive order directing the FTC to determine when state AI laws requiring changes to “truthful outputs” are preempted by federal law, and Colorado was named directly.

    Where to actually spend your budget Sector prudential regulators, banking, insurance, EU technology law, FDA, are winning ground on explainability. Broad state consumer-protection AI law is losing ground fast. If you’re deciding where to put compliance headcount this year, follow the sector regulator, not the state legislative headline.

    The Contrarian Case: Cynthia Rudin

    Every regulation covered above assumes the same underlying premise: that a black-box model can be explained well enough, after the fact, to satisfy a regulator or a consumer. Dr. Cynthia Rudin, Duke University’s Interpretable Machine Learning Lab director and a 2025 ACM Fellow, has spent a decade arguing that premise is wrong.

    “You can’t have accountability without transparency.”
    Dr. Cynthia Rudin, Professor of Computer Science, Duke University
    Rudin’s argument, laid out in her widely cited 2019 Nature Machine Intelligence paper, is that a fully faithful explanation of a black-box model would essentially make the black box redundant. In practice, popular explainability tools like SHAP and LIME produce approximations of what a model did, not a true account of it. In an interview, she went further, arguing that fairness itself is impossible to verify without an interpretable model, because you can’t reliably detect bias inside a system you can’t actually read. She also pushed back directly on the assumption that interpretable models sacrifice accuracy, telling one interviewer there’s no real evidence of that tradeoff in high-stakes settings.

    Why this matters for the regulations above: Article 13 and the NAIC bulletin both require systems be “sufficiently transparent,” without mandating that the underlying model actually be interpretable by design. A bank or insurer could, in theory, bolt a SHAP dashboard onto a black-box model and satisfy the letter of these rules while the real decision-making stays opaque. Full legal compliance, without full actual explainability. That gap is the single most useful thing a skeptical reader can take from this piece.

    What Compliance and Engineering Teams Should Do Now

    • Stop treating explainability as one checkbox. Map each AI system against each applicable framework separately: EU exposure, U.S. banking asset threshold, state insurance adoption, and FDA device classification all trigger independently.
    • Re-triage bank models by materiality rather than defaulting to SR 26-2’s predecessor’s uniform annual review cycle, and build a separate governance track for GenAI and agentic tools that the letter doesn’t cover.
    • Run the 30-day drill. Insurers should test, today, whether they can produce a plain-language adverse-decision explanation inside 30 days, not just point to a policy that says they can.
    • Finalize EU “instructions for use” documentation, training data characteristics, accuracy metrics, human oversight measures, before August 2, 2026, for any high-risk system touching EU customers or markets.
    • Classify clinical AI tools early. The more black-box a CDS tool looks, the more likely it lands in FDA’s regulated-device category, so build interpretability in before submission, not after a rejection.
    The budget case is easier than it looks. Global spend on AI governance platforms sits at roughly $492 million in 2026 and is projected to cross $1 billion by 2030, according to Gartner, one of the few AI-adjacent spending categories still expanding while broader “AI ROI” skepticism grows everywhere else.

    “Explainability turns a GenAI output into a defensible, auditable insight.”
    Pankaj Prasad, Senior Principal Analyst, Gartner
    Gartner separately predicts that by 2028, explainability will push LLM observability investment to 50% of GenAI deployments, up from just 15% today, a sign that the generative AI models least suited to today’s explainability tools are exactly where the next wave of tooling spend is heading.


    Frequently Asked Questions

    What is explainable AI (XAI)?
    Explainable AI (XAI) refers to techniques and system designs that let humans understand why an AI model produced a specific output, the reasoning behind a credit denial, an insurance price, or a diagnosis, rather than just the output itself. It’s distinct from a purely accurate but opaque black-box model.

    Why is explainable AI important in finance and healthcare?
    In regulated sectors, AI decisions must be defensible to regulators, auditors, and the people affected. The EU AI Act, U.S. banking guidance (SR 26-2), the NAIC’s insurance bulletin, and FDA medical device guidance all treat opacity as a compliance risk, since unexplainable decisions can’t be audited for bias or error.

    When does the EU AI Act require AI explainability?
    The EU AI Act’s transparency obligations for high-risk AI systems, including those used in credit scoring, insurance pricing, and medical devices, become enforceable August 2, 2026. Non-compliant high-risk systems face penalties up to roughly €35 million or 7% of global turnover.

    Does the U.S. require explainable AI in banking?
    Not through a single binding federal law, but SR 26-2, issued April 2026 by the Fed, OCC, and FDIC, sets validation and transparency expectations for traditional and non-generative AI credit and risk models at banks over $30 billion in assets. Generative and agentic AI are explicitly excluded for now.

    What is the difference between explainability and interpretability in AI?
    Explainability generally means post-hoc techniques describing why a complex black-box model reached a decision. Interpretability means a model is transparent by design, like a decision tree or scoring system. Researcher Cynthia Rudin argues interpretable-by-design models are more trustworthy than explained black boxes.

    Is explainable AI required for insurance companies?
    In the states that have adopted the NAIC’s Model Bulletin on AI Systems, insurers must maintain a written AI governance program that accounts for the transparency and explainability of outcomes to the impacted consumer, particularly for adverse decisions like coverage denials or rate increases.


    Where This Goes Next

    By the time the EU’s implementing guidelines catch up to Article 13’s August deadline, and by the time NAIC’s evaluation tool pilot wraps in September, the “explainability as compliance checkbox” era will be over. What’s replacing it is sector-specific, examinable, and genuinely fragmented. The through-line worth remembering: prudential and safety regulators, banking examiners, insurance commissioners, the FDA, are tightening explainability into binding practice. Broad state consumer-protection AI law is being narrowed under federal pressure. Those two trends are moving in opposite directions at the same time, and that tension, not a single new law, is the real story for the next 12 to 18 months.

    Three things to watch before year-end: whether the European Commission’s Article 13 guidelines land before enforcement does, whether NAIC’s evaluation tool pilot expands beyond its 12 states at the Fall National Meeting, and whether the promised federal RFI on GenAI model risk actually appears, which would be the first sign U.S. banking regulators are ready to bring generative AI inside the SR 26-2 perimeter.

    For more on what happens when AI gets the facts wrong instead of just unexplainable, see NeuralWired’s related coverage of the Deloitte AI hallucination report and FINRA’s 2026 warning, the accuracy half of the same trust problem covered here.

    Get the next one first NeuralWired’s newsletter, The Neural Loop, tracks AI regulation, enterprise deployment, and the stories vendors don’t want covered. Subscribe at neuralwired.com/newsletter.
  • Boeing AR Training ROI 2026: The Real Data Behind It

    Boeing AR Training ROI 2026: The Real Data Behind It

    Enterprise XR / Workforce Training

    Boeing’s AR Training Cut Time 75%, Not 40%

    Boeing’s aircraft technicians used to learn wiring installation from paper diagrams up to 20 feet long. Now a HoloLens headset walks them through it. The result, according to Boeing’s own training leadership, was a real cut in training time. But the number you’ve probably seen quoted, a tidy “40% faster,” doesn’t actually trace back to Boeing at all. If you’re building the business case for enterprise AR training ROI right now, that distinction is the difference between a defensible budget request and a number your CFO’s team unravels in five minutes.

    This piece separates what Boeing, PwC, and a new 2025 Forrester study commissioned by Meta can actually support from what’s marketing copy dressed up as data. It also covers the part most vendor content skips: the same year enterprise training ROI got its best evidence yet, Meta and Microsoft both quietly killed their flagship enterprise VR collaboration products. Knowing where that line sits is the actual job.

    The Boeing Numbers, Untangled

    Search “Boeing AR training” and you’ll land on a handful of stats that get repeated so often they’ve stopped sounding like claims and started sounding like facts: 40% faster, 75% less training time, 90% first-attempt accuracy. They don’t all come from the same place, and treating them as one unified statistic is the single most common error in coverage of this topic.

    Two figures actually hold up. Boeing’s HoloLens-based wiring-harness training program, which replaced instructor-led walkthroughs of a roughly 50-step procedure with a 3D holographic overlay, has been credited with a 75% reduction in per-technician training time, a figure that’s circulated in trade press since roughly 2018. Separately, Boeing’s Chief Technologist for Training and Professional Services, Pete Boeskov, has attributed a 30 to 33% improvement in wiring speed and accuracy to the same AR system replacing those long paper diagrams.

    The “40% faster” figure and the claim that VR pushed first-attempt accuracy to 90% (versus 50% with manuals) show up almost exclusively on vendor marketing pages, not on anything Boeing has published or a Boeing executive has said on the record. That doesn’t make them false. It means nobody’s shown their work.

    Why this matters for your build: Boeing’s own stated motivation for scaling this program is a projected shortage of roughly 769,000 new aviation maintenance technicians needed globally through 2038, from its Pilot and Technician Outlook. That’s a workforce-demand number, not a training-efficacy number, and the two get blended constantly in secondary coverage. Keep them separate.

    Boeing built a scalable “xR Learning Framework” to deliver training through mobile and AR/VR devices, after an internal survey drawing more than 40,000 employee responses ranked technical-development-program improvement as a top organizational priority. Pete Boeskov, Chief Technologist for Training and Professional Services, Boeing, via Field Service USA

    The 219% ROI Figure, and Its Asterisk

    The newest, and most quoted, number in this space comes from a Forrester Consulting Total Economic Impact study, published in mid-2025. Forrester interviewed six decision-makers across four organizations using Meta Quest for training, then modeled a composite 10,000-employee company with 3,300 workers trained via VR. The headline result: 219% ROI over three years, $6.1 million in benefits against $1.9 million in costs, $4.2 million in net present value, and payback in under six months.

    The mechanism behind that number is worth knowing if you’re the one presenting it upward. Task-worker training time fell roughly 75%. Training time for knowledge workers fell about 50%. Onboarding sped up by 25%. Travel and in-person training costs dropped around 50%, worth an estimated $1.6 to $1.7 million over three years.

    Here’s the part that belongs in your slide, not just your footnote: Meta commissioned and paid for this study. Forrester’s TEI methodology is independently recognized and has a real track record, but a recognized methodology applied to a customer sample the vendor helped select is not the same thing as an independent, randomized study. Use the number. Just don’t present it as neutral.

    PwC’s Break-Even Math

    If Forrester gives you the headline, PwC’s 2020 study gives you the number your finance team will actually ask for: the headcount at which VR training stops being a cost center. PwC compared classroom, e-learning, and VR delivery of the same unconscious-bias and inclusive-leadership course, built with Talespin, across 12 US office locations between February 2019 and January 2020. VR learners finished up to 4 times faster than classroom learners and 1.5 times faster than e-learners. On cost, VR reached parity with classroom training at 375 trained learners, and became roughly 52% cheaper than classroom training once an organization hit 3,000 learners.

    That 375-learner threshold is arguably more useful than any ROI percentage, because it turns an abstract “does this work” question into a concrete one: does your organization actually train that many people on the same material. If the answer is yes, the PwC data supports the investment. If you’re training 40 people once, it doesn’t.

    What Walmart, Bank of America, and Intel Actually Report

    Beyond Boeing and the Forrester composite, several named enterprise deployments have public, attributable figures, compiled in VR.org’s April 2026 rundown of the category.

    CompanyDeploymentReported result
    Walmart1M+ employees trained via VR; Pickup Tower module8 hours to 15 minutes training time; 30% higher satisfaction
    Bank of America50,000+ employees, Strivr platformScaled soft-skills and procedural training
    IntelVR safety training program300% ROI, measured over five years
    Accenture“Nth Floor” persistent VR campus, Meta QuestOnboarding and internal collaboration
    Notice the pattern: the biggest, cleanest numbers cluster around task-specific, repeatable, physical procedures. Wiring a harness. Restocking a pickup tower. Running a safety drill. That’s not an accident, and it’s the thread that ties directly into where this whole category runs into trouble.

    Why Meta Just Shut Down Its Own VR Meeting Product

    Here’s the story that rarely makes it into the same article as the ROI numbers above. In February 2026, Meta shut down Horizon Workrooms, its enterprise VR meeting and collaboration product, exiting the enterprise-collaboration category entirely. The following month, Meta made Horizon Worlds mobile-only and pulled it from the Quest Store. Microsoft made a nearly identical call, retiring the Immersive Space view in Teams and shutting down Mesh across web, PC, and Quest in December 2025.

    Meta’s Reality Labs division has now lost roughly $88 billion cumulatively since 2019, including about $19.2 billion in 2025 alone.

    The distinction that actually matters: the same company reporting a 219% ROI on task-specific training just walked away from enterprise VR meetings. Those are two different product categories with two different evidence bases, and conflating them is how a training budget gets killed by an unrelated headline about the “metaverse dying.” Training that replaces a physical, repeatable, high-stakes procedure has real data behind it. Training that replaces a Zoom call does not, and both Meta and Microsoft have now said so with their product roadmaps, not just their press releases.

    The Novelty Effect Problem Nobody’s Marketing Deck Mentions

    Every headline number in this piece so far measures completion speed, test scores, or cost. None of them, including PwC’s and Forrester’s, measure whether the learning actually sticks weeks or months later. That gap has a name in the academic literature: the novelty effect.

    A peer-reviewed 2023 study by researcher Josef Wolfartsberger, published in Computers in Industry, ran a direct comparison of VR-based training against traditional on-the-job training for industrial assembly tasks, measuring assembly time, error rate, and hints required. The result complicates the “VR trains people dramatically faster” story: outcomes were broadly comparable between the two methods.

    VR training functions best as a useful addition to, rather than a replacement for, existing industrial training methods. Josef Wolfartsberger, in Computers in Industry, 2023
    That finding lines up with a broader pattern documented in a 2024 systematic review published in Technology, Knowledge and Learning, which synthesizes controlled studies referencing researchers including Guido Makransky and Richard Mayer. The pattern: VR engagement and enjoyment don’t reliably translate into durable skill retention once the novelty of the medium itself wears off. None of the vendor-commissioned studies driving the current ROI conversation, PwC’s included, report learning outcomes measured more than a few weeks post-training, which is exactly the window where researchers say novelty-driven gains are most likely to be inflated.

    When XR Training Actually Makes Sense

    Jeremy Bailenson, founding director of Stanford’s Virtual Human Interaction Lab and a co-founder of Strivr (worth disclosing: he has a commercial stake in this category), has offered a scoping framework that cuts through most of the noise. Training justifies VR when the task is dangerous, difficult or impossible to stage physically, expensive to repeat, or rare, the “DDER” test. Pilot training is the canonical example: a mistake in the real world is catastrophic, so simulating it isn’t optional, it’s the only responsible option.

    Bailenson has also been blunt about the ceiling on this technology. In a 2023 talk that’s still the clearest public version of his view, he’s noted VR “is not the next smartphone,” meaning it’s a tool for specific high-stakes scenarios, not a general-purpose daily device.

    Run Boeing, Walmart’s Pickup Tower module, and Intel’s safety training through the DDER filter and they all pass cleanly: physically hazardous, expensive to stage repeatedly with real equipment, or both. Run Horizon Workrooms and Microsoft Mesh through the same filter and they fail it. A meeting isn’t dangerous, difficult to stage, expensive to repeat, or rare. It’s a meeting.

    FAQ

    Does Boeing actually use augmented reality for training?

    Yes. Boeing uses Microsoft HoloLens-based AR to guide aircraft technicians through wiring-harness installation, replacing paper diagrams that ran up to 20 feet long. Improvements in wiring speed and accuracy have been attributed directly to Boeing’s Chief Technologist for Training, Pete Boeskov.

    What is the actual ROI of enterprise VR training?

    A 2025 Forrester Consulting study commissioned by Meta found enterprise VR training delivered 219% ROI over three years, with payback in under six months, driven mainly by faster onboarding and lower travel and instructor costs. It’s vendor-commissioned, not an independent study.

    At what company size does VR training pay for itself?

    PwC’s research found VR training reaches cost parity with classroom training at roughly 375 trained learners, and becomes about 52% cheaper than classroom training once an organization trains 3,000 people on the same material.

    Is the metaverse dead for business training?

    No. Task-specific enterprise training, aviation maintenance, industrial assembly, safety drills, continues to show measurable results even as Meta and Microsoft both shut down their enterprise VR meeting products (Horizon Workrooms and Mesh) in late 2025 and early 2026.


    Where This Goes Next

    The evidence for task-specific, hands-on XR training is genuinely strong, and it’s getting stronger with each new deployment. The evidence for VR as a general collaboration or meeting layer has now failed twice in the market, in 2021 to 2023 and again with the Horizon Workrooms and Mesh shutdowns. Those are two different bets with two different track records, and the next 6 to 18 months will likely sharpen that split further rather than blur it.

    Three things worth watching: whether Forrester or a comparable firm publishes a training-ROI study that isn’t vendor-commissioned, whether any of the current studies extend their measurement window past a few weeks to actually test the novelty-effect concern, and whether headset prices, already down roughly 60% since 2016, fall far enough to make fleet-scale deployment viable for mid-market companies, not just Boeing and Walmart-sized organizations.

    If you’re building a business case internally, the honest version is short: task-specific, high-stakes, hard-to-repeat training has real, replicated numbers behind it. Everything else in this category is still an open question, whatever the demo reel implies.

    Want research briefs like this before they’re common knowledge? Subscribe to The Neural Loop at neuralwired.com/newsletter.