AI Compliance for Data Governance
Data Governance is addressed by 50 regulatory updates across 8 jurisdictions and 9 frameworks. This page tracks how regulators worldwide are approaching data governance in the context of artificial intelligence.
Framework Requirements for Data Governance
Regulations Covering Data Governance
US Federal(12)
FDA AI-enabled medical device and PCCP guidance baseline
FDA’s August 2025 PCCP guidance provides recommendations for planned modifications to AI-enabled devices reviewed through the 510(k), De Novo and PMA pathways.
FDA continues AI-enabled medical device guidance and submissions workflow updates
FDA’s AI-enabled medical device materials show an active draft-guidance and feedback cycle, with public feedback on generative AI-enabled medical devices due by 2026-10-19, so device teams need to prepare submission and validation materials now.
Historical Congressional source: no current AI obligation identified
The linked source is a 1996 Congressional bill record and does not establish a current AI compliance update. It is retained here to explain the correction to the earlier entry.
FDA draft guidance for developers of AI-enabled medical devices
FDA’s January 2025 draft guidance for AI-enabled medical devices puts lifecycle documentation, transparency, maintenance, and bias controls front and center, so device teams should align submissions and post-market processes now.
FDA final guidance on clinical decision support software
FDA’s January 2026 final guidance clarifies when clinical decision support software is outside device regulation and when FDA oversight still applies, so AI health tools must be re-triaged immediately against the final criteria.
International(12)
AICPA SOC 2 resources reaffirm current Trust Services Criteria for AI-enabled services
AICPA’s SOC resources confirm the current Trust Services Criteria baseline and do not create AI-specific rules, but they reinforce that AI-enabled services must still satisfy existing security, privacy, and processing integrity controls in audits.
NIST AI RMF revision and critical-infrastructure profile development
NIST says the AI RMF is being revised and that a new trustworthy-use profile for critical infrastructure is under development, while the baseline AI RMF 1.0 remains voluntary and headed for review no later than 2028.
ISO/IEC 42006:2025 defines requirements for AI management system certification bodies
ISO/IEC 42006:2025 supplements the requirements for bodies auditing and certifying AI management systems against ISO/IEC 42001; the ISO catalog records its publication in July 2025.
ISO AI management-system and adjacent AI standards pipeline expands
ISO’s AI standards pages and draft items show an active pipeline around AI management systems, audit/certification, societal concerns, and privacy protection, so organizations pursuing ISO-based assurance should update their standards watchlist now.
ISO/IEC 42001 certification ecosystem expands with new accreditation and audit guidance
ISO/IEC 42001 is increasingly operationalized through new accreditation and certification guidance, so organizations adopting the standard now need to validate which certifiers and audit bodies are recognized.
Switzerland(11)
Swiss FDPIC guidance on AI and data protection, plus legislative roadmap
The FDPIC has made clear that Switzerland’s data protection law already applies to AI-supported processing and that the federal government is targeting an AI bill by the end of 2026, so organizations should harden transparency and automated-decision controls now.
FDPIC guidance and enforcement focus on AI and data protection
The FDPIC states that the Swiss FADP applies directly to AI-supported processing and is actively pursuing investigations, so organizations using AI with personal data must now evidence transparency, proportionality, purpose limitation, and human review readiness.
FDPIC says Swiss data-protection law applies directly to AI-supported processing
On 2025-05-08, the FDPIC reiterated that Switzerland’s data-protection law already applies directly to AI-supported processing, meaning transparency, purpose limitation, and data-subject rights must be built into current AI operations now.
FDPIC confirms Swiss data-protection law applies directly to AI
The FDPIC reiterates that the Swiss Federal Data Protection Act applies directly to AI-supported processing, so organizations cannot wait for a separate AI statute before fixing transparency, automated-decision, and human-review controls.
ISO/IEC 42005:2025 published for AI system impact assessments
ISO published ISO/IEC 42005:2025 in May 2025, adding a formal AI system impact-assessment standard that organizations can now use to evidence structured AI governance alongside ISO/IEC 42001.
United Kingdom(7)
ICO AI and data protection guidance remains active but under review
The ICO says its AI guidance supports audit and enforcement activity and is under review following the Data (Use and Access) Act 2025, so UK organizations should keep using it as the current baseline while planning for revisions.
ICO AI and data protection guidance remains active and under review
The ICO says its AI guidance is not statutory but is used for audit and enforcement, and it is under review due to the UK’s newer data legislation, so organizations should treat it as live supervisory guidance.
ICO investigation into Grok
The ICO has opened an investigation into Grok, signaling active enforcement scrutiny of AI processing under UK data protection law rather than a purely policy-level review.
ICO guidance on AI and data protection
The ICO’s AI guidance remains the key UK data-protection reference for AI systems, and the page is under review because of the Data (Use and Access) Act coming into force on 19 June 2025.
ICO AI and data protection guidance under review
The ICO says its AI and data protection guidance is under review in light of the Data (Use and Access) Act 2025, so organisations should expect refreshed UK GDPR expectations on AI governance and risk assessment.
Singapore(3)
Singapore updates agentic AI governance framework and PDPC personal-data guidance
Singapore has updated its model AI governance framework for agentic AI and already has advisory guidelines for personal-data use in AI recommendation and decision systems, so organizations should refresh governance, human oversight, and data-use controls now.
Singapore PDPC advisory guidelines on personal data in AI recommendation and decision systems
PDPC finalized advisory guidelines on the use of personal data in AI recommendation and decision systems, clarifying PDPA expectations for training and deployment workflows that use personal data.
Singapore publishes Model AI Governance Framework for Agentic AI
IMDA published Version 1.0 of the Model AI Governance Framework for Agentic AI on 2026-01-22, creating immediate governance expectations for autonomous AI systems that reason and act on their own.
European Union(3)
European Commission AI Office implementation guidance and GPAI compliance support
The Commission’s AI Office continues publishing guidance and code-of-practice materials to operationalize AI Act obligations for GPAI providers, creating near-term compliance expectations even before further implementing acts land.
EDPB adopts final guidance on anonymisation and web scraping for generative AI
The EDPB adopted final guidelines on anonymisation and web scraping for generative AI on 2026-07-08, creating an immediate supervisory reference point for model-training and de-identification practices under the GDPR.
EESC opinion on the AI Omnibus and Digital Omnibus simplification proposals
The EESC backed simplification of the AI Act and digital rulebook while warning that high-risk AI obligations are still expected to become binding as early as August 2026, so firms should not delay compliance planning pending omnibus negotiations.
Canada(1)
Weekly digest
Leave your email to get each issue in your inbox. Free, no account required.
We use your email only for the digest. Privacy policy