AI Compliance for Frontier Models
Frontier Models is addressed by 50 regulatory updates across 7 jurisdictions and 6 frameworks. This page tracks how regulators worldwide are approaching frontier models in the context of artificial intelligence.
Framework Requirements for Frontier Models
Regulations Covering Frontier Models
European Union(26)
AI Act consultations and implementation guidance for GPAI, sandboxes, and transparency
The Commission has opened or advanced multiple AI Act implementation workstreams for GPAI, high-risk classification, transparency, and regulatory sandboxes, meaning providers and deployers must now align their implementation plans to the emerging guidance rather than wait for finalised national practice.
EU AI Act implementation consultations advance on GPAI, transparency, high-risk classification and sandboxes
The Commission’s AI Act consultations on GPAI, transparency obligations, high-risk classification, sandboxes, and the scientific panel show that the operational rulebook is still being finalized, so affected providers should engage now to shape interpretation.
ESA call for enhanced governance and consistent supervision of frontier AI ICT risks
On 2026-07-31, EBA, EIOPA and ESMA called on EU financial-sector firms and supervisors to tighten governance and supervision of frontier AI-related ICT risks, signaling immediate expectations for stronger control frameworks under existing resilience obligations.
EU AI Office and supervisors call for enhanced governance for frontier AI in financial services
EU financial supervisors and the AI Office are signaling stronger governance and consistent supervision expectations for frontier AI models in the financial sector, so firms should treat this as an immediate AI Act implementation and risk-governance update rather than a future issue.
EU AI Office and Commission implementation guidance for AI Act and GPAI code
The Commission and AI Office have moved from policy design into active AI Act implementation by issuing operational guidance on transparency, GPAI obligations, and governance, making immediate compliance mapping necessary for providers facing Article 50 and GPAI code expectations.
International(11)
NIST AI RMF revision and critical-infrastructure profile development
NIST says the AI RMF is being revised and that a new trustworthy-use profile for critical infrastructure is under development, while the baseline AI RMF 1.0 remains voluntary and headed for review no later than 2028.
NIST signals revision of AI RMF and new critical-infrastructure profile work
NIST’s AI RMF materials state that the framework is being revised and that a new critical-infrastructure trustworthy-AI profile was launched on 2026-04-07, so organizations relying on the RMF should track the revision now for shifting implementation guidance.
NIST SP 1353 AI-enabled CSF analysis and reporting draft
NIST issued the initial public draft of SP 1353 on 2026-08-19 and set comments due by 2026-10-15, so teams using AI for CSF analysis should assess the draft and submit feedback before the close date.
NIST draft misuse-risk guidance targets dual-use foundation models
NIST’s draft guidance on dual-use foundation models may affect model governance and testing workflows, so teams should treat it as an emerging reference for misuse-risk management even though it is not itself an AI RMF update.
NIST generative AI profile remains a key AI RMF companion resource
NIST’s July 26, 2024 Generative AI Profile remains a key companion to AI RMF 1.0, so organizations using GenAI should continue to map controls to the profile’s risk scenarios and governance themes.
US Federal(8)
FTC AI enforcement posture remains active across deceptive claims and AI investments
The FTC’s AI hub and related matters, including Rytr, Workado, and DoNotPay, show that the agency continues to police deceptive AI claims and conduct, so AI product and marketing teams should assume ongoing enforcement scrutiny now.
NIST AI RMF update process tied to White House AI Action Plan
NIST says the AI RMF 1.0 is being revised under the July 23, 2025 White House AI Action Plan, which means organizations relying on the framework should expect updated implementation guidance and profile changes rather than a static reference.
US voluntary AI commitments and frontier AI policy direction
White House voluntary AI commitments remain a benchmark for frontier AI governance, so firms should continue aligning safety testing, provenance, cybersecurity, and information-sharing controls even though the commitments are nonbinding.
FTC seeks public comment on AI accuracy policy statement
On 2026-07-07, the FTC proposed a policy statement on AI accuracy, signaling that claims and system behavior that manipulate expected accuracy may be treated as deceptive under Section 5.
Congressional AI-related bills remain active but are not a single federal AI regime
Several AI-adjacent bills are active in Congress, but they do not create a unified federal AI law, so federal compliance planning remains agency-driven rather than statute-driven.
United Kingdom(2)
FCA, Bank of England and Treasury joint statement on frontier AI models and cyber resilience
The FCA, Bank of England, and HM Treasury said firms must be able to identify, monitor, and manage external AI-related applications, libraries, and services integrated into their networks, raising the bar for cyber and third-party resilience.
FCA Mills Review on how AI will reshape retail financial services
The FCA launched a review of advanced AI’s impact on retail financial services, with feedback due 24 February 2026 and recommendations expected for the FCA Board in summer 2026.
Canada(1)
Singapore(1)
New York(1)
Weekly digest
Leave your email to get each issue in your inbox. Free, no account required.
We use your email only for the digest. Privacy policy