AI Regulation in International
International has 85 tracked AI regulatory updates across 8 frameworks. This page provides an overview of the current regulatory landscape, upcoming deadlines, and recent enforcement activity.
Upcoming Deadlines
Estimated deadline for adoption of Conference of the Parties rules of procedure after entry into force
Council of Europe AI Framework Convention publishedFormal AI RMF review expected no later than 2028
NIST AI RMF revision and critical-infrastructure profile developmentRecent Regulatory Updates
AICPA SOC 2 resources reaffirm current Trust Services Criteria for AI-enabled services
AICPA’s SOC resources confirm the current Trust Services Criteria baseline and do not create AI-specific rules, but they reinforce that AI-enabled services must still satisfy existing security, privacy, and processing integrity controls in audits.
NIST AI RMF revision and critical-infrastructure profile development
NIST says the AI RMF is being revised and that a new trustworthy-use profile for critical infrastructure is under development, while the baseline AI RMF 1.0 remains voluntary and headed for review no later than 2028.
ISO/IEC 42006:2025 defines requirements for AI management system certification bodies
ISO/IEC 42006:2025 supplements the requirements for bodies auditing and certifying AI management systems against ISO/IEC 42001; the ISO catalog records its publication in July 2025.
ISO AI management-system and adjacent AI standards pipeline expands
ISO’s AI standards pages and draft items show an active pipeline around AI management systems, audit/certification, societal concerns, and privacy protection, so organizations pursuing ISO-based assurance should update their standards watchlist now.
NIST signals revision of AI RMF and new critical-infrastructure profile work
NIST’s AI RMF materials state that the framework is being revised and that a new critical-infrastructure trustworthy-AI profile was launched on 2026-04-07, so organizations relying on the RMF should track the revision now for shifting implementation guidance.
NIST SP 1353 AI-enabled CSF analysis and reporting draft
NIST issued the initial public draft of SP 1353 on 2026-08-19 and set comments due by 2026-10-15, so teams using AI for CSF analysis should assess the draft and submit feedback before the close date.
ISO/IEC 42001 certification ecosystem expands with new accreditation and audit guidance
ISO/IEC 42001 is increasingly operationalized through new accreditation and certification guidance, so organizations adopting the standard now need to validate which certifiers and audit bodies are recognized.
ISO 42001 explained
ISO’s explainer confirms certification to ISO/IEC 42001 is voluntary, so organizations should treat it as a governance framework rather than a mandatory legal requirement.
ISO/IEC 42001:2023 AI management systems
ISO/IEC 42001:2023 is the current published edition and establishes the baseline requirements for implementing an AI management system, so teams pursuing certification or AI governance alignment should treat it as the operative reference now.
NIST draft misuse-risk guidance targets dual-use foundation models
NIST’s draft guidance on dual-use foundation models may affect model governance and testing workflows, so teams should treat it as an emerging reference for misuse-risk management even though it is not itself an AI RMF update.
NIST generative AI profile remains a key AI RMF companion resource
NIST’s July 26, 2024 Generative AI Profile remains a key companion to AI RMF 1.0, so organizations using GenAI should continue to map controls to the profile’s risk scenarios and governance themes.
NIST AI RMF development hub remains the authoritative framework source
NIST’s development page serves as the official baseline for AI RMF 1.0 and related resources, so teams should use it as the authoritative source for the framework’s scope and companion materials.
NIST ITL AI Program confirms concept note and agentic AI evaluation work
NIST’s ITL AI Program page reiterates the April 7, 2026 concept note and a related webinar on agentic AI evaluation probes, indicating the next wave of AI RMF work is focused on testing and evaluation infrastructure.
NIST releases concept note for AI RMF Profile on Trustworthy AI in Critical Infrastructure
On April 7, 2026, NIST released a concept note for an AI RMF Profile on Trustworthy AI in Critical Infrastructure, which means critical-infrastructure AI programs should start aligning risk assessments and evaluation workflows to the emerging profile now.
ISO AI governance toolkit expands around ISO/IEC 42001 and ISO/IEC 42005
ISO’s package page shows 42001 as part of a broader AI governance toolkit alongside ISO/IEC 42005:2025, so organizations should track adjacent standards that may shape documentation and impact assessment expectations.
Applicable Frameworks
Key Topics
Weekly digest
Leave your email to get each issue in your inbox. Free, no account required.
We use your email only for the digest. Privacy policy