Shawn Levy Reads AI Regulations Every Day: What IT Experts Say You Must Do Before Integrating AI in Your Business

Shawn Levy speaking at the Breakthrough Prize Ceremony about AI and the future of filmmaking

Photo : Gage Skidmore from Surprise, AZ, United States of America / Wikimedia

Daniel Daniel MillerInformation Technology
7 min read July 26, 2026

When one of Hollywood's most commercially successful directors says he spends part of every day studying AI regulations, it is worth paying attention — especially if you run a business that has been eyeing AI tools to cut costs or expand output in 2026.

In April 2026, Shawn Levy told Variety something that stopped the entertainment world short. The director of Deadpool & Wolverine and the upcoming Star Wars: Starfighter (releasing May 2027 with Ryan Gosling) has not used AI in any meaningful way in his creative process yet. But he spends significant time every single day tracking regulatory options surrounding it. "I spend a part of everyday trying to increase my fluency around the regulatory options surrounding [AI]," Levy said at the Breakthrough Prize Ceremony.

For most business owners, the instinct runs in the opposite direction: deploy first, figure out the compliance later. Levy's approach — understand regulation before adoption — is precisely what IT consultants have been urging corporate clients to follow for over a year. Here is what they say you need to know.

Why a Hollywood Director's Regulatory Vigilance Is the Right Business Model

The entertainment industry may seem disconnected from your office's software stack, but Levy's caution is grounded in a real and rapidly hardening legal terrain. As of 2026, businesses that integrate AI tools for content creation, customer communication, or data processing face a layered set of requirements at the state, federal, and international levels that most small business owners are not yet aware of.

The EU AI Act — fully enforceable since August 2025 — classifies AI systems by risk level. High-risk applications, which include content moderation tools, HR screening software, and customer-facing decision systems, now require mandatory conformity assessments and documented human oversight. In the United States, the Federal Trade Commission has expanded its enforcement of Section 5 unfair or deceptive practices to cover undisclosed AI-generated content, with penalties reaching $51,744 per violation as of 2026. California's AB 2013, requiring disclosure of training datasets used by generative AI systems sold commercially, took effect in January 2026, adding another compliance obligation for any business operating in the state or serving California consumers.

"The regulatory landscape shifted in under 18 months from advisory guidelines to enforceable law," notes the IT compliance perspective most small businesses are slow to absorb. "Most owners think they are simply choosing a productivity tool. They are actually entering a compliance obligation with real financial exposure."

Levy manages $200 million productions and navigates guild agreements with SAG-AFTRA and the WGA, both of which contain specific AI provisions. He understands that integration without fluency is a liability, not a shortcut. The same principle applies to a 15-person marketing agency or a regional law firm.

Three Hidden Risks That Surface Without IT Guidance

What does AI adoption look like when it happens without professional guidance? IT consultants see three failure patterns repeatedly in 2026.

Data exposure through third-party AI vendors. Many cloud-based AI tools train on user-uploaded content by default unless explicitly opted out in account settings buried in the dashboard. If your business processes personal data — customer emails, financial records, medical intake forms — uploading that content to a non-compliant AI service can constitute a CCPA violation carrying fines of up to $7,500 per intentional violation, or a HIPAA breach triggering penalties between $1,000 and $50,000 per incident.

Contract ambiguity on AI-generated deliverables. When your team uses AI to draft marketing copy, generate code, or create design assets for clients, the copyright ownership question becomes legally complex. Under current U.S. Copyright Office guidance as of 2026, purely AI-generated works remain largely unprotectable. Whether your team's use of AI qualifies as sufficient human authorship — and how that is documented in your client contracts — determines whether you can legally claim or transfer the rights to what you deliver.

Vendor lock-in and dependency failure. IT consultants consistently flag businesses that adopt AI tools rapidly across departments without an architecture review. When a vendor shuts down, changes pricing, or gets acquired, businesses with fragmented, tool-specific AI dependencies face migration costs of $50,000 to $200,000 — comparable to a full software overhaul. A structured integration plan with a qualified IT consultant builds exit provisions into vendor agreements before you are ever locked in.

Levy's point about embracing AI "rather than fearing it" is not a call to ignore these risks. It is a call to understand them well enough to move forward responsibly — which is the core service an IT consultant provides.

A Concrete Case: What Happens When the Compliance Step Gets Skipped

Consider a 22-person marketing agency in Chicago that handles campaigns for healthcare and financial services clients. In early 2026, management decides to integrate an AI video generation platform and an AI copywriting tool to absorb production volume without adding headcount. The tools look clean, the pricing is competitive, and the integration is completed in two weeks.

Without an IT consultation beforehand, the risk exposure unfolds quietly.

The AI video tool they selected stores uploaded client footage for model training by default. This disclosure is buried in section 14 of the terms of service. Several of the agency's healthcare clients have HIPAA Business Associate Agreements that prohibit sharing protected health information with unvetted third parties. Since the AI vendor has not executed a BAA with the agency, every campaign video that contains patient-adjacent information creates a potential HIPAA violation — starting at $1,000 per incident, scaling to $50,000 if federal auditors find evidence of negligence.

The AI copywriting tool they deploy does not automatically disclose when content is AI-generated. The FTC's 2025 enforcement guidance requires material disclosure in regulated categories, including financial products and health claims. Several of the agency's financial services client campaigns qualify. If undisclosed AI copy runs in a regulated financial advertisement and the FTC flags it, the client absorbs the regulatory penalty — and the agency absorbs the client's indemnification claim.

If the agency had brought in an IT consultant before signing either SaaS agreement, the engagement would have covered three things: auditing each vendor's data retention and subprocessor policies, identifying the missing disclosure architecture, and estimating the cost of a compliant integration. That consultation, for a business of this size, typically runs between $1,500 and $4,000. The avoidable liability exposure runs to six figures.

The if/then logic is direct: if your business handles regulated data or produces content for regulated industries, then every AI vendor you add requires a Data Processing Agreement review before the first upload — not after the first campaign goes live.

What the AI Regulatory Landscape Requires Right Now

According to the NIST AI Risk Management Framework, released and updated through 2026, organizations adopting AI should apply four core functions across all deployments: map the risk context, measure the potential impact, manage risk with documented controls, and govern the process with clear accountability and audit trails. Most small businesses have operationalized none of these four functions.

The areas where IT consultants focus compliance audits in 2026 follow this structure directly:

Vendor due diligence. Evaluating an AI vendor means reviewing their EU AI Act conformity documentation, SOC 2 Type II attestation, and data processing agreements — not their feature comparison page. IT consultants have these frameworks ready as checklists and apply them against vendor contracts before signature.

Disclosure architecture. Any customer-facing AI application that could reasonably be mistaken for human-generated output needs an explicit disclosure layer. This includes chatbots, AI-drafted client documents, and AI-generated creative assets used in any commercial context.

Audit trails for regulated decisions. In industries where AI assists with loan applications, HR screening, or healthcare triage, the decisions must be explainable and logged. Building that audit infrastructure before regulators request it is significantly cheaper than reconstructing it under inquiry.

Exit planning. Every AI tool integration should include vendor exit terms, covering data deletion timelines and portability protocols, written into the contract before deployment begins.

The Right Starting Point for Any Business Considering AI Tools

Shawn Levy's approach to Star Wars: Starfighter's eventual AI integration is not passive. He is actively building fluency so that when the regulatory environment stabilizes enough for responsible deployment at scale, he will be ready to act without scrambling to catch up on the rules. That same posture — informed before activated — is available to any business through an IT consultation.

The practical entry point is an AI readiness audit: a structured engagement where an IT consultant reviews your existing workflows, identifies which planned or current AI tools carry regulatory exposure, and surfaces gaps in your vendor agreements and data handling practices. For most businesses with 10 to 50 employees, a thorough audit takes one to two days and costs between $800 and $3,000 depending on the complexity of the data environment.

Levy put the instinct plainly: embrace AI, do not fear it — but earn the confidence to embrace it through genuine fluency. For the rest of us, that fluency starts with a conversation with an IT specialist who already knows the regulatory terrain.

This article is for informational purposes only and does not constitute legal, regulatory, or compliance advice. Consult a qualified IT compliance professional for guidance specific to your business situation.

Advantages

Quick and accurate answers to all your questions and assistance requests in over 200 categories.

Thousands of users have given a satisfaction rating of 4.9 out of 5 for the advice and recommendations provided by our assistants.