TL;DR Sam Altman and Dario Amodei briefed the UN Security Council on September 23 and asked for shared AI testing standards, while the US rejected global governance. Colorado's proposed ADMT rules are open for comment through October 26. The UK still has no AI bill. British Columbia sued OpenAI and Sam Altman over the Tumbler Ridge shooting. Three enterprise actions at the bottom.
Corrected October 1, 2026. The first version of this roundup stated as fact that Colorado published a revised draft on September 23, described a UK AI Regulation and Safety Bill at Lords committee stage, and gave a different theory of the BC lawsuit. The Colorado Attorney General only said interim revisions were expected by September 23, and we could not confirm one was posted. We found no source for the UK bill, and the BC description did not match the reporting. The sections below are rewritten from sources we could check.
Four AI policy stories landed in seven days. Two of them carry dates you can put on a calendar: October 26 for Colorado comments and January 1, 2027 for the Colorado statute.
Story 1: OpenAI and Anthropic at the UN Security Council (September 23)
On September 23 the UN Security Council held a session titled "Artificial Intelligence and International Security". France, which chaired the Council in September, called the meeting, and Foreign Minister Jean-Noel Barrot presided. Sam Altman spoke in the chamber. Dario Amodei appeared by video.
Amodei said that if managed poorly, AI could be a risk to humanity as a whole. Altman and Amodei asked for shared standards to test AI systems and for a way for states to report serious incidents to each other. Altman said major decisions should not be made by labs in San Francisco alone.
The United States did not go along. Reporting from CNBC, Bloomberg and others describes the US answering with a flat refusal of "global governance" of AI, and President Trump had criticized what he called a "globalist scheme" to control AI in his UN remarks that week. The coverage we reviewed reports no resolution or formal document adopted.
For enterprise AI governance teams the useful reading is the opposite of "international rules are coming". The two most prominent frontier labs are asking for international coordination, and the largest AI market is refusing it. Expect fragmentation: EU rules, US state rules and voluntary industry commitments, not one global standard. Plan against the rules that bind you, which are the ones in Stories 2 and 4.

Story 2: Colorado Proposed ADMT Rules (comments open to October 26)
Colorado's Attorney General filed proposed rules on August 11, 2026 to implement SB 26-189 (the Automated Decision-Making Technology Act) and HB 26-1263 (the chatbot safety law). Three documents went to the Secretary of State: the proposed rules, a notice of rulemaking hearing, and a statement of basis and purpose. They are posted on the Attorney General's rulemaking page at coag.gov/ai.
The Attorney General's notice said stakeholders could submit comments by September 4 to be considered in interim revisions, which the office expected to post by September 23. We could not confirm that a revised draft was actually published, so check coag.gov/ai for the current version. Written comments close at 11:59 PM on October 26, 2026, and the hybrid rulemaking hearing is the same day, starting at 10 a.m. at the Department of Law in Denver with remote participation available. SB 26-189 itself takes effect January 1, 2027, and the Attorney General's rules are due by the same date.
What the proposed rules would add to the statute:
- A disclosure is due within 30 days after the technology materially influences an adverse outcome, covering the decision, the purpose of the tool, and the roles of the tool and any human reviewers.
- A business has 10 days to acknowledge a consumer's request for human review and 45 days to complete it.
- The human reviewer cannot be the person who made the original decision or that person's subordinate.
- A disclosure after an adverse outcome has to state the specific principal reasons for it.
The statute covers consequential decisions in employment, housing, credit, insurance, health care, education and essential government services.
These are proposals. The text can change before and after the October 26 hearing, so treat the items above as the direction of travel, not final obligations. We read the rules through law firm and compliance summaries of the Attorney General's filing, not line by line from the filing itself.
Connecticut's CART Act requirements took effect October 1 and are covered in our Connecticut CART Act guide.
Story 3: UK Still Has No AI Bill, but Pressure Is Building (September 2026)
The UK has not passed or introduced a frontier AI bill. Labour's 2024 manifesto promised binding regulation of "the handful of companies developing the most powerful AI models", and no bill had followed by September 2026. Several things moved in September:
- Peers proposed an amendment to the Cyber Security and Resilience Bill that would give the government last-resort emergency powers to shut down AI systems or datacentres that threaten national security, public safety or critical infrastructure. Liberal Democrat peer Tim Clement-Jones tabled it, with co-sponsors including Conservative peer Dido Harding and crossbencher Beeban Kidron. It was reported on September 2 and is an amendment, not law.
- The Lords debated "AI: Human Extinction" on September 15.
- OpenAI urged the UK to pass frontier AI legislation, reported around September 15.
- The Joint Committee on Human Rights published "Human Rights and the Regulation of AI" on September 14, calling for a new AI bill.
- The government indicated it would not back a private member's superintelligence bill, while leaving open narrower measures aimed at national security risks.
The AI Security Institute tests advanced models, but today only with the developer's cooperation. That is the gap peers keep raising. For enterprise buyers the practical point is that UK evaluation of frontier models is voluntary for now, so a vendor's willingness to share evaluation results is a procurement question, not a legal one. Our UK AI regulation overview covers what applies today.
Story 4: British Columbia Sues OpenAI (September 21)
British Columbia sued OpenAI and its chief executive Sam Altman in the US District Court for the Northern District of California, in San Francisco. Coverage is dated September 22. We reported the filing as September 21 in our earlier article on the lawsuit.
The suit concerns the February 10, 2026 school shooting in Tumbler Ridge that killed eight people. According to the complaint as reported, the shooter's ChatGPT conversations about gun violence were flagged in June 2025, OpenAI's safety team recommended contacting police, and company leadership decided the material did not meet its threshold for referral to law enforcement. The claims reported are negligence and product liability for failing to alert authorities.
BC is seeking damages for the costs of the emergency response and community recovery, and a court order requiring OpenAI to change how it identifies and handles conversations that may signal a risk of violence. OpenAI disputes the allegations and says the activity did not meet its threshold at the time. British Columbia Attorney General Niki Sharma called the action "an important step toward seeking justice for the families, students, educators and community members whose lives were forever changed."
These are allegations in a complaint, not findings. For enterprise AI teams the practical question is not the headline, it is what your vendor does when a user's conversation signals danger, and what your contract says about it. See Action 3 below.
What We Could Not Verify
A weekly roundup is only useful if you know which lines to trust. Three limits apply to this one.
First, we did not read the Colorado Attorney General's proposed rules line by line, and we could not confirm whether the interim revised draft expected by September 23 was published. The 10-day, 45-day and reviewer-independence details come from law firm and compliance summaries that agree with each other, and the filing dates come from the Attorney General's rulemaking page as quoted in those summaries. Read the primary text at coag.gov/ai before you build to it.
Second, we did not read the BC complaint. The June 2025 flag, the safety team recommendation and the leadership decision come from news coverage of the filing, and OpenAI disputes them.
Third, we found no source for several details in our first version, including who else testified at the UN session and what the UK's foreign minister said. We removed them rather than guess.
Three Enterprise Actions This Week
Action 1: Read the Colorado proposed rules and map your decision inventory.
If you use automated tools in hiring, performance management, compensation, credit or housing decisions that affect Colorado residents, list every consequential decision in scope, the tool used, its data inputs, and whether you have a documented human review process that could meet a 10-day acknowledgement and 45-day completion timeline with a reviewer who is not the original decision maker. The rules are still proposals, so build the process to be adjustable. If the rules create operational problems for you, the comment window closes October 26.
Action 2: Add model evaluation sharing to your vendor checklist.
Evaluation of frontier models by the UK AI Security Institute is voluntary today. For any frontier model vendor you are procuring or renewing, ask whether they share pre-deployment evaluation results with government institutes and whether summaries can be shared with you under NDA. A vendor with a clear answer is easier to govern. A vendor without one is telling you something.
Action 3: Ask your AI vendor about threat escalation and legal holds.
The BC complaint alleges a flagged conversation was not escalated. Ask each AI provider you use how it decides when to refer a threatening conversation to law enforcement, what log data it retains and for how long, and what triggers a litigation hold. Have legal confirm whether your agreement requires the vendor to notify you before producing your users' interaction data in a third-party legal proceeding. Most enterprise agreements cover this to protect the vendor, not you.
What to Watch Next Week
Colorado comments and the rulemaking hearing are on October 26. California's Adam's Law (SB 1119, signed September 10) takes effect January 1, 2027, with most operator obligations starting July 1, 2027, so Q4 2026 is the vendor risk assessment window for anyone deploying companion chatbots that children can use.
In the BC case, the early docket filings will show how OpenAI answers the negligence and product liability claims. The antitrust suit filed September 19 against Anthropic, OpenAI, Google and SpaceXAI is covered in our separate article.
Related Reading
- British Columbia OpenAI ChatGPT Shooting Log Disclosure
- Colorado Chatbot Safety Act HB-1263 Compliance
- Connecticut CART Act: 3 Obligations Live October 1
- Multi-State AI Compliance Strategy
- UK AI Regulation 2026: Post-Brexit What Applies
- AI Vendor Contract Red Flags
- AI Slowdown Antitrust Suit: 3 Checks for Enterprise Vendor Contracts
