AI Compliance for Data Governance

Data Governance is addressed by 50 regulatory updates across 9 jurisdictions and 6 frameworks. This page tracks how regulators worldwide are approaching data governance in the context of artificial intelligence.

50
Regulations
9
Jurisdictions
6
Frameworks

Framework Requirements for Data Governance

Regulations Covering Data Governance

US Federal(7)

HIPAA2026-07-26

FDA AI-enabled medical device guidance and lifecycle expectations

FDA’s AI/ML medical device guidance set and device list continue to expand, so AI health-tech teams need to align premarket, transparency, and change-control evidence before new or modified systems are submitted or marketed.

HIPAA2026-05-24

FDA draft guidance on artificial intelligence-enabled medical devices

The FDA’s January 2025 draft guidance on AI-enabled medical devices remains the key current benchmark for lifecycle, transparency, bias, and documentation expectations for AI device submissions and post-market controls.

HIPAA2026-05-17

FDA guidance on AI-enabled medical devices remains active

FDA continues to emphasize lifecycle-wide expectations for AI-enabled medical devices, including transparency and predetermined change control, so developers need submission-ready documentation for model changes and postmarket monitoring.

HIPAA2026-05-10

AI-Enabled Optimization of Early-Phase Clinical Trials Pilot Program; Request for Information

FDA issued a request for information on April 29, 2026 to shape a pilot program for AI-enabled early-phase clinical trials, creating an immediate comment-driven opportunity to influence future expectations for AI use in clinical decision-making.

GDPR2026-05-03

U.S. court rulings tracked in May 2026 docket updates

The provided court-listener entries are docket updates rather than identified AI regulatory rulings, so they mainly serve as litigation monitoring signals rather than actionable compliance changes.

European Union(5)

EU AI Act2026-07-12

European Commission AI Office implementation guidance and GPAI compliance support

The Commission’s AI Office continues publishing guidance and code-of-practice materials to operationalize AI Act obligations for GPAI providers, creating near-term compliance expectations even before further implementing acts land.

GDPR2026-07-12

EDPB adopts final guidance on anonymisation and web scraping for generative AI

The EDPB adopted final guidelines on anonymisation and web scraping for generative AI on 2026-07-08, creating an immediate supervisory reference point for model-training and de-identification practices under the GDPR.

EU AI Act2026-07-05

EESC opinion on the AI Omnibus and Digital Omnibus simplification proposals

The EESC backed simplification of the AI Act and digital rulebook while warning that high-risk AI obligations are still expected to become binding as early as August 2026, so firms should not delay compliance planning pending omnibus negotiations.

GDPR2026-05-03

EDPB marks 10 years of GDPR and ongoing AI governance impact

The EDPB’s 10-year GDPR anniversary update underscores that AI training, deployment, and cross-border processing continue to be governed by the GDPR framework and its supervisory ecosystem, so organizations should refresh their AI privacy controls and supervisory authority mapping now.

EU AI Act2026-04-19

EU AI Act GPAI provider guidance and code-of-practice process

The Commission’s GPAI guidance and code-of-practice process makes the AI Act’s provider obligations operational now, so GPAI developers need to finalize transparency, copyright, risk-management, and documentation controls rather than waiting for enforcement practice to settle.

Weekly digest

Leave your email to get each issue in your inbox. Free, no account required.

We use your email only for the digest. Privacy policy