AI Compliance for Data Governance
Data Governance is addressed by 50 regulatory updates across 9 jurisdictions and 6 frameworks. This page tracks how regulators worldwide are approaching data governance in the context of artificial intelligence.
Framework Requirements for Data Governance
Regulations Covering Data Governance
International(17)
ISO/IEC 42001 certification ecosystem expands with new accreditation and audit guidance
ISO/IEC 42001 is increasingly operationalized through new accreditation and certification guidance, so organizations adopting the standard now need to validate which certifiers and audit bodies are recognized.
ISO 42001 explained
ISO’s explainer confirms certification to ISO/IEC 42001 is voluntary, so organizations should treat it as a governance framework rather than a mandatory legal requirement.
ISO/IEC 42001:2023 AI management systems
ISO/IEC 42001:2023 is the current published edition and establishes the baseline requirements for implementing an AI management system, so teams pursuing certification or AI governance alignment should treat it as the operative reference now.
ISO AI governance toolkit expands around ISO/IEC 42001 and ISO/IEC 42005
ISO’s package page shows 42001 as part of a broader AI governance toolkit alongside ISO/IEC 42005:2025, so organizations should track adjacent standards that may shape documentation and impact assessment expectations.
ISO/IEC 42001:2023 remains the reference AI management system standard
ISO confirms that ISO/IEC 42001:2023 remains the baseline standard for establishing and continually improving an AI management system, so teams should keep certification and control mappings anchored to this version.
Switzerland(9)
FDPIC confirms Swiss data-protection law applies directly to AI
The FDPIC reiterates that the Swiss Federal Data Protection Act applies directly to AI-supported processing, so organizations cannot wait for a separate AI statute before fixing transparency, automated-decision, and human-review controls.
ISO/IEC 42005:2025 published for AI system impact assessments
ISO published ISO/IEC 42005:2025 in May 2025, adding a formal AI system impact-assessment standard that organizations can now use to evidence structured AI governance alongside ISO/IEC 42001.
FINMA guidance on governance and risk management when using artificial intelligence
FINMA’s 18 December 2024 guidance says supervised institutions must adapt governance and controls to the materiality and probability of AI risks, including operational, model, data, IT/cyber, third-party, legal, and reputational risks.
FDPIC AI and data protection guidance
The FDPIC states that Switzerland’s FADP applies directly to AI-supported processing and expects manufacturers, providers, and users to be transparent about purpose, functionality, and data sources.
FDPIC guidance on AI and data protection
The FDPIC’s AI guidance states that the Swiss FADP applies directly to AI-supported processing and requires transparency about purpose, functionality, and data sources, which elevates compliance expectations for AI deployments in Switzerland.
US Federal(7)
FDA AI-enabled medical device guidance and lifecycle expectations
FDA’s AI/ML medical device guidance set and device list continue to expand, so AI health-tech teams need to align premarket, transparency, and change-control evidence before new or modified systems are submitted or marketed.
FDA draft guidance on artificial intelligence-enabled medical devices
The FDA’s January 2025 draft guidance on AI-enabled medical devices remains the key current benchmark for lifecycle, transparency, bias, and documentation expectations for AI device submissions and post-market controls.
FDA guidance on AI-enabled medical devices remains active
FDA continues to emphasize lifecycle-wide expectations for AI-enabled medical devices, including transparency and predetermined change control, so developers need submission-ready documentation for model changes and postmarket monitoring.
AI-Enabled Optimization of Early-Phase Clinical Trials Pilot Program; Request for Information
FDA issued a request for information on April 29, 2026 to shape a pilot program for AI-enabled early-phase clinical trials, creating an immediate comment-driven opportunity to influence future expectations for AI use in clinical decision-making.
U.S. court rulings tracked in May 2026 docket updates
The provided court-listener entries are docket updates rather than identified AI regulatory rulings, so they mainly serve as litigation monitoring signals rather than actionable compliance changes.
United Kingdom(6)
ICO AI and data protection guidance remains active and under review
The ICO says its AI guidance is not statutory but is used for audit and enforcement, and it is under review due to the UK’s newer data legislation, so organizations should treat it as live supervisory guidance.
ICO investigation into Grok
The ICO has opened an investigation into Grok, signaling active enforcement scrutiny of AI processing under UK data protection law rather than a purely policy-level review.
ICO guidance on AI and data protection
The ICO’s AI guidance remains the key UK data-protection reference for AI systems, and the page is under review because of the Data (Use and Access) Act coming into force on 19 June 2025.
ICO AI and data protection guidance under review
The ICO says its AI and data protection guidance is under review in light of the Data (Use and Access) Act 2025, so organisations should expect refreshed UK GDPR expectations on AI governance and risk assessment.
Family Court endorses secure AI use for judgment summaries
The Family Court published a judgment noting that secure Judicial Copilot summaries were useful for parents with learning difficulties, underscoring that courts will scrutinize AI use but may accept it when carefully controlled and beneficial.
European Union(5)
European Commission AI Office implementation guidance and GPAI compliance support
The Commission’s AI Office continues publishing guidance and code-of-practice materials to operationalize AI Act obligations for GPAI providers, creating near-term compliance expectations even before further implementing acts land.
EDPB adopts final guidance on anonymisation and web scraping for generative AI
The EDPB adopted final guidelines on anonymisation and web scraping for generative AI on 2026-07-08, creating an immediate supervisory reference point for model-training and de-identification practices under the GDPR.
EESC opinion on the AI Omnibus and Digital Omnibus simplification proposals
The EESC backed simplification of the AI Act and digital rulebook while warning that high-risk AI obligations are still expected to become binding as early as August 2026, so firms should not delay compliance planning pending omnibus negotiations.
EDPB marks 10 years of GDPR and ongoing AI governance impact
The EDPB’s 10-year GDPR anniversary update underscores that AI training, deployment, and cross-border processing continue to be governed by the GDPR framework and its supervisory ecosystem, so organizations should refresh their AI privacy controls and supervisory authority mapping now.
EU AI Act GPAI provider guidance and code-of-practice process
The Commission’s GPAI guidance and code-of-practice process makes the AI Act’s provider obligations operational now, so GPAI developers need to finalize transparency, copyright, risk-management, and documentation controls rather than waiting for enforcement practice to settle.
California(2)
California AB2575 health care services artificial intelligence
California AB2575 was introduced to regulate AI in health care services, adding to the state’s growing AI governance patchwork and requiring ongoing monitoring by health-sector operators.
CA SB1159: Artificial intelligence: transparency and governance
California SB1159 was read first time and held at desk on May 4, 2026, signaling an active transparency-and-governance proposal that could impose new documentation and disclosure expectations for AI systems.
Singapore(2)
Singapore PDPC advisory guidelines on personal data in AI recommendation and decision systems
PDPC finalized advisory guidelines on the use of personal data in AI recommendation and decision systems, clarifying PDPA expectations for training and deployment workflows that use personal data.
Singapore publishes Model AI Governance Framework for Agentic AI
IMDA published Version 1.0 of the Model AI Governance Framework for Agentic AI on 2026-01-22, creating immediate governance expectations for autonomous AI systems that reason and act on their own.
New York(1)
Weekly digest
Leave your email to get each issue in your inbox. Free, no account required.
We use your email only for the digest. Privacy policy