The Wild West of AI:
Why Compliance Is the New Frontier and Who Must Lead
AI is moving faster than the laws written to govern it. The companies that build the rules now will shape the industry for a decade. The ones that don’t will be shaped by them.
There is no sheriff in this town yet. AI has arrived, spread across enterprises, governments, and consumer products at a velocity that policy has never been built to absorb and the result is a landscape where the rules are still being written in real time, in courtrooms, in congressional hearings, and in the acceptable use policies of companies that are, themselves, the subject of dispute. Welcome to the wild west of AI compliance.
The stakes are not abstract. In February 2026, the Trump administration ordered federal agencies to immediately cease using Anthropic’s technology the first such action against a domestic AI company in U.S. history after Anthropic refused to waive its own restrictions on mass domestic surveillance and autonomous weapons systems from its government contract. A federal court later granted Anthropic a preliminary injunction, but the episode sent a wave of uncertainty through the entire technology sector. If a company can be designated a national security supply chain risk for maintaining an ethics policy, the compliance landscape just became significantly more complicated for every AI vendor doing business with the government.
“The regulatory honeymoon for artificial intelligence is officially over. For years, businesses deployed AI systems with minimal oversight, operating in a gray zone where innovation outpaced legislation. That era ended in 2025.”
The Compliance Clock Is Running
The pressure is arriving from multiple directions at once. In Europe, the EU AI Act’s Phase Two requirements for high risk systems come into force on August 2, 2026 creating hard transparency mandates and documentation obligations for any company deploying AI in employment decisions, credit scoring, or customer profiling that touches European markets. In the United States, the federal government remains fragmented: a December 2025 Executive Order instructed the Department of Justice to actively challenge state level AI laws it considers burdensome, even as individual states pass their own regulations, creating a compliance patchwork that multi state businesses must somehow navigate simultaneously.
For legal teams, the translation is blunt: this is no longer a future risk to plan for. It is a present operational reality. Companies that began preparation 18 to 24 months ahead of enforcement are absorbing costs gradually and with time to correct course. Those arriving late face implementation costs that can run 60% higher and exposure that no amount of retroactive documentation can fully address.
What makes AI compliance distinctively hard is that it does not map cleanly onto prior regulatory models. GDPR was hard enough. AI introduces new categories of risk — algorithmic bias, model drift, autonomous decision making, data provenance — that existing legal frameworks were not designed to handle. And unlike a privacy policy, an AI system’s behavior is not static: it changes as models are updated, as context shifts, and as agentic systems take on new autonomy. Compliance is not a checkbox. It is a continuous operational discipline.
Anthropic, Ethics, and the Government as Regulator and Client
A defining case study in AI principle vs. state power
No single episode this year has clarified the compliance stakes more sharply than the Anthropic Pentagon dispute. In July 2025, Anthropic signed a $200 million contract with the Department of Defense — the first time a frontier AI model was approved for use on classified government networks. The contract included two restrictions Anthropic had written into its core acceptable use policy: the model could not be used for mass domestic surveillance, and it could not power fully autonomous lethal weapons systems that operate without human oversight.
When the Pentagon later sought to renegotiate those restrictions, Anthropic’s CEO publicly refused. The administration’s response was swift: agencies were directed to cease all use of Anthropic technology, and the Defense Department designated Anthropic a supply chain risk to national security — a label previously reserved for foreign adversaries. Anthropic filed suit in two federal courts. A federal judge, in a March 24 hearing, expressed serious concern that the government may be illegally punishing and retaliating against Anthropic for exercising its free speech rights.
Anthropic drew a line in the sand that most companies never have to draw: it refused to sell its ethics for a government contract. That refusal is now being litigated as a First Amendment issue. The outcome will define what AI companies can and cannot be compelled to do.
The episode is not just a corporate drama. It is a signal about what AI compliance will increasingly look like: companies with deeply held positions on how their models should and should not be used, facing governments that see those positions as operational obstacles. The companies that have thought hardest about their values and built them into enforceable policy will be the ones best positioned to navigate that tension. The ones that have not will bend.
For a detailed legal analysis of the supply chain risk designation and its implications for government contractors, see Mayer Brown’s coverage at mayerbrown.com and the Congressional Research Service brief at congress.gov.
Help Us, Don’t Replace Us
Beneath the governance debate runs a deeper question that compliance frameworks have not yet answered well: what should AI actually be for? The answer most people give, when asked honestly, is not efficiency maximization or cost reduction. It is augmentation. AI that makes people better at what they do. AI that handles the cognitive overhead that exhausts humans, freeing attention for the work that requires judgment, creativity, and connection.
The risk is that compliance pressure accelerates a different outcome. When companies are scrambling to meet documentation requirements, to demonstrate algorithmic accountability, to audit their training data — the temptation is to deploy AI in the most measurable, controllable ways, which are often the most substitutive: replace a human task entirely, document the output, check a compliance box. The more interesting and more valuable applications — AI as a creative collaborator, as a research accelerant, as a tool that helps a compliance analyst actually understand the regulation they are trying to meet — are harder to audit and harder to certify.
The companies that will get AI right are the ones that treat compliance not as a ceiling on what they can do, but as a foundation for doing more of what they should — building systems that are transparent enough to trust and useful enough to matter.
Good compliance frameworks should make room for this. The EU AI Act’s risk based classification system, for all its complexity, does something important: it distinguishes between AI that poses real societal risk and AI that helps a person do their job better. The former needs heavy oversight. The latter should be encouraged, not burdened. The challenge is that most current frameworks are still learning to make that distinction in practice.
When Compliance Opens New Attack Surfaces
Here is a problem that does not get discussed enough: AI compliance, in many of its current forms, requires organizations to expose more data than they would otherwise. Audit trails require logging. Transparency mandates require storing decision pathways. Bias testing requires access to training data. Each of these is a reasonable governance requirement — and each of them creates a new security surface that adversaries can target.
The same AI systems that promise to make businesses more efficient are also aggregating sensitive data at unprecedented scale, connecting previously siloed systems, and making decisions at speeds that outpace human review. A compliance framework that requires transparency about how a model made a decision is only as good as the security around the logs that capture it. And in a world where AI agents are acting autonomously — browsing, writing, executing code, interacting with external APIs — the scope of what needs to be monitored has expanded by an order of magnitude.
This is where observability and security platforms move from infrastructure tooling to compliance infrastructure. The question is no longer just “is my application performing well?” It is “can I prove, to a regulator, an auditor, or a board, that this AI system behaved as intended — and catch it when it didn’t?”
The Platforms Positioned to Lead
A new market opportunity at the intersection of AI, observability, and compliance
The companies that have spent the last decade building telemetry and monitoring infrastructure are now sitting on a significant strategic advantage. They know how to collect signals at scale, make them queryable, and surface anomalies before they become incidents. What they are now doing rapidly is extending those capabilities into the AI layer.
The emerging market opportunity here is not incremental. As AI observability overlaps increasingly with security and compliance budgets, the buying decision shifts from engineering teams to CISOs, General Counsel, and Chief Compliance Officers. The platforms that can speak fluently to all three — that can trace an AI agent’s actions, surface anomalies in model behavior, and produce audit ready logs — will own a category that barely existed eighteen months ago.
Open standards, particularly OpenTelemetry, are becoming the connective tissue. They keep data structured and interoperable, preventing organizations from becoming locked into proprietary formats at exactly the moment when they most need portability — when they are switching models, migrating clouds, or responding to a regulatory examination. The platforms investing in OpenTelemetry compatibility are making a long term bet that the market will reward interoperability over lock in. That bet looks increasingly correct.
Links & Insights
What Comes Next
The companies that will lead through the coming wave of AI compliance are not necessarily the largest, or the most technically sophisticated. They are the ones that treat compliance as a design constraint rather than an afterthought — building governance into their systems the way they build security, not bolting it on afterward. They are the ones that have made explicit choices about what their AI should and should not do, and have the documentation, the monitoring, and the organizational clarity to defend those choices when challenged.
The observability and security platforms — New Relic, Datadog, Dynatrace, CrowdStrike, Splunk, and the next generation of AI native monitoring companies still being built — are now infrastructure for trust, not just performance. The enterprises that can instrument their AI systems comprehensively, demonstrate behavioral consistency to auditors, and detect anomalies before they become incidents will have a genuine competitive advantage in a regulatory environment that is only going to demand more.
And Anthropic’s willingness to fight in court, in public, at real cost to its government business — for the right to maintain ethical limits on its own technology — is, regardless of how one reads the politics, a signal worth taking seriously. The AI companies that survive the coming decade with their reputations intact will be the ones that had the clarity to decide what they stood for before anyone asked them under oath.
Compliance is not the enemy of innovation. The wild west needed law — not to end the frontier but to make it possible for more people to settle there safely. AI needs the same.