AI Compliance for Cybersecurity
Cybersecurity is addressed by 50 regulatory updates across 8 jurisdictions and 8 frameworks. This page tracks how regulators worldwide are approaching cybersecurity in the context of artificial intelligence.
Framework Requirements for Cybersecurity
Regulations Covering Cybersecurity
International(21)
ISO/IEC 42001 certification ecosystem expands with new accreditation and audit guidance
ISO/IEC 42001 is increasingly operationalized through new accreditation and certification guidance, so organizations adopting the standard now need to validate which certifiers and audit bodies are recognized.
ISO/IEC 42001:2023 AI management systems
ISO/IEC 42001:2023 is the current published edition and establishes the baseline requirements for implementing an AI management system, so teams pursuing certification or AI governance alignment should treat it as the operative reference now.
NIST draft misuse-risk guidance targets dual-use foundation models
NIST’s draft guidance on dual-use foundation models may affect model governance and testing workflows, so teams should treat it as an emerging reference for misuse-risk management even though it is not itself an AI RMF update.
NIST ITL AI Program confirms concept note and agentic AI evaluation work
NIST’s ITL AI Program page reiterates the April 7, 2026 concept note and a related webinar on agentic AI evaluation probes, indicating the next wave of AI RMF work is focused on testing and evaluation infrastructure.
NIST releases concept note for AI RMF Profile on Trustworthy AI in Critical Infrastructure
On April 7, 2026, NIST released a concept note for an AI RMF Profile on Trustworthy AI in Critical Infrastructure, which means critical-infrastructure AI programs should start aligning risk assessments and evaluation workflows to the emerging profile now.
US Federal(14)
Congressional AI-related bills remain active but are not a single federal AI regime
Several AI-adjacent bills are active in Congress, but they do not create a unified federal AI law, so federal compliance planning remains agency-driven rather than statute-driven.
NIST AI RMF 1.0 overview and playbook update signal
NIST’s AI RMF overview confirms the framework remains AI RMF 1.0 and says the Playbook will be enhanced, so the current change is to supporting materials rather than the base framework.
NIST AI RMF critical infrastructure profile concept note
On 2026-04-07 NIST released a concept note for a trustworthy AI in critical infrastructure profile, indicating active profile development that regulated operators should monitor now.
White House AI Action Plan reference in NIST AI materials
NIST’s AI hub notes it was named in the White House’s July 23, 2025 AI Action Plan, signaling policy direction rather than a direct legal change to the AI RMF itself.
FISA Amendments Act extension enacted
Congress enacted a law extending the authorities of Title VII of FISA through 2026-04-30, so organizations reliant on US intelligence-collection authorities should refresh legal and vendor-risk assumptions before the extension lapses.
Switzerland(5)
FINMA guidance on governance and risk management when using artificial intelligence
FINMA’s 18 December 2024 guidance says supervised institutions must adapt governance and controls to the materiality and probability of AI risks, including operational, model, data, IT/cyber, third-party, legal, and reputational risks.
FINMA guidance on AI governance and risk management
FINMA’s AI guidance highlights operational, model, cyber, data-quality, third-party, legal, and reputational risks, so Swiss financial institutions should formalize AI governance and oversight now.
BSI publishes G7 SBOM for AI guidance
BSI released a G7-developed guideline setting minimum requirements for a Software Bill of Materials for AI, so organizations should tighten AI component inventory and supply-chain traceability practices.
FINMA Guidance on Governance and Risk Management When Using Artificial Intelligence
FINMA published AI governance guidance on December 18, 2024, making governance, model risk, data quality, cyber risk, third-party dependence, and legal/reputational risk explicit supervisory priorities for Swiss financial institutions using AI.
FINMA Guidance on AI Governance and Risk Management
FINMA’s AI supervisory guidance highlights operational, model, data, cyber, third-party, legal, and reputational risks, so Swiss financial institutions should treat AI governance as an immediate supervisory issue.
European Union(4)
Digital Omnibus on AI amends the EU AI Act
Regulation (EU) 2026/1744 amends the AI Act and makes the new prohibitions on realistic intimate/deepfake-style synthetic content and the updated Article 50 transparency obligations operative from 2 December 2026, creating immediate implementation work for AI providers and deployers.
ESRB Warning on systemic cyber risks from frontier AI models
The ESRB warned that frontier AI models can collapse defensive time buffers and materially increase systemic cyber risk for EU financial institutions, and it specifically points to ECB-requested action plans due by 31 October 2026 as the near-term trigger for supervisory attention.
ESAs support ESRB warning on systemic cyber risks from frontier AI models
On 2026-07-07, the European Supervisory Authorities backed the ESRB’s warning that frontier AI models can create systemic cyber risks for financial markets, elevating AI cyber resilience as a supervisory priority.
ESAs publish first annual report on DORA major ICT-related incidents
On 2026-06-03, the EBA, EIOPA and ESMA published their first annual overview of major ICT-related incidents under DORA, underscoring that borderless ICT and AI-driven risks now require financial entities to tighten cybersecurity and incident-reporting readiness.
United Kingdom(2)
FCA, Bank of England and Treasury joint statement on frontier AI models and cyber resilience
The FCA, Bank of England, and HM Treasury said firms must be able to identify, monitor, and manage external AI-related applications, libraries, and services integrated into their networks, raising the bar for cyber and third-party resilience.
FCA, Bank of England and Treasury issue frontier AI cyber resilience statement
UK authorities issued a joint statement on frontier AI model cyber resilience, so regulated firms and FMIs should now align AI governance with existing operational resilience and cyber controls.
California(2)
CA SB1011: Energy: Utility Infrastructure AI Safety, Oversight, and Workforce Protection Act
California SB1011 was set for hearing on May 14, 2026, putting AI safety and oversight obligations for utility infrastructure uses under active legislative review and warranting immediate stakeholder monitoring.
California SB 1011: Utility Infrastructure AI Safety, Oversight, and Workforce Protection Act
California SB 1011 was set for hearing on May 4, 2026, so utility and critical infrastructure operators using AI should expect potential new safety, oversight, and workforce requirements.
France(1)
Weekly digest
Leave your email to get each issue in your inbox. Free, no account required.
We use your email only for the digest. Privacy policy