AI Compliance for Frontier Models
Frontier Models is addressed by 50 regulatory updates across 7 jurisdictions and 4 frameworks. This page tracks how regulators worldwide are approaching frontier models in the context of artificial intelligence.
Framework Requirements for Frontier Models
Regulations Covering Frontier Models
European Union(24)
Commission publishes transparency guidance under the AI Act
The Commission published guidance on Article 50 transparency obligations ahead of the 2 August 2026 applicability date, so providers and deployers now need to operationalize labeling and disclosure workflows rather than wait for enforcement to start.
Digital Omnibus on AI amends the EU AI Act
Regulation (EU) 2026/1744 amends the AI Act and makes the new prohibitions on realistic intimate/deepfake-style synthetic content and the updated Article 50 transparency obligations operative from 2 December 2026, creating immediate implementation work for AI providers and deployers.
ESRB Warning on systemic cyber risks from frontier AI models
The ESRB warned that frontier AI models can collapse defensive time buffers and materially increase systemic cyber risk for EU financial institutions, and it specifically points to ECB-requested action plans due by 31 October 2026 as the near-term trigger for supervisory attention.
European Commission AI Office implementation guidance and GPAI compliance support
The Commission’s AI Office continues publishing guidance and code-of-practice materials to operationalize AI Act obligations for GPAI providers, creating near-term compliance expectations even before further implementing acts land.
ESAs support ESRB warning on systemic cyber risks from frontier AI models
On 2026-07-07, the European Supervisory Authorities backed the ESRB’s warning that frontier AI models can create systemic cyber risks for financial markets, elevating AI cyber resilience as a supervisory priority.
International(13)
NIST draft misuse-risk guidance targets dual-use foundation models
NIST’s draft guidance on dual-use foundation models may affect model governance and testing workflows, so teams should treat it as an emerging reference for misuse-risk management even though it is not itself an AI RMF update.
NIST generative AI profile remains a key AI RMF companion resource
NIST’s July 26, 2024 Generative AI Profile remains a key companion to AI RMF 1.0, so organizations using GenAI should continue to map controls to the profile’s risk scenarios and governance themes.
NIST AI RMF development hub remains the authoritative framework source
NIST’s development page serves as the official baseline for AI RMF 1.0 and related resources, so teams should use it as the authoritative source for the framework’s scope and companion materials.
NIST ITL AI Program confirms concept note and agentic AI evaluation work
NIST’s ITL AI Program page reiterates the April 7, 2026 concept note and a related webinar on agentic AI evaluation probes, indicating the next wave of AI RMF work is focused on testing and evaluation infrastructure.
NIST releases concept note for AI RMF Profile on Trustworthy AI in Critical Infrastructure
On April 7, 2026, NIST released a concept note for an AI RMF Profile on Trustworthy AI in Critical Infrastructure, which means critical-infrastructure AI programs should start aligning risk assessments and evaluation workflows to the emerging profile now.
US Federal(5)
FTC seeks public comment on AI accuracy policy statement
On 2026-07-07, the FTC proposed a policy statement on AI accuracy, signaling that claims and system behavior that manipulate expected accuracy may be treated as deceptive under Section 5.
Congressional AI-related bills remain active but are not a single federal AI regime
Several AI-adjacent bills are active in Congress, but they do not create a unified federal AI law, so federal compliance planning remains agency-driven rather than statute-driven.
White House AI Action Plan reference in NIST AI materials
NIST’s AI hub notes it was named in the White House’s July 23, 2025 AI Action Plan, signaling policy direction rather than a direct legal change to the AI RMF itself.
FTC AI enforcement hub
The FTC’s AI hub consolidates current enforcement materials and investigations, signaling that deceptive AI claims, model substantiation, and AI-related process inquiries remain active priority areas.
Bill C-27 / AIDA remains proposed in Canada
Canada’s Artificial Intelligence and Data Act remains proposed legislation within Bill C-27 and has not become law, so teams should treat it as a live monitoring item rather than an immediate compliance deadline.
United Kingdom(3)
FCA, Bank of England and Treasury joint statement on frontier AI models and cyber resilience
The FCA, Bank of England, and HM Treasury said firms must be able to identify, monitor, and manage external AI-related applications, libraries, and services integrated into their networks, raising the bar for cyber and third-party resilience.
FCA Mills Review on how AI will reshape retail financial services
The FCA launched a review of advanced AI’s impact on retail financial services, with feedback due 24 February 2026 and recommendations expected for the FCA Board in summer 2026.
FCA, Bank of England and Treasury issue frontier AI cyber resilience statement
UK authorities issued a joint statement on frontier AI model cyber resilience, so regulated firms and FMIs should now align AI governance with existing operational resilience and cyber controls.
Singapore(2)
Singapore updates its Model AI Governance Framework for Agentic AI
IMDA updated its agentic AI governance framework in May 2026, so organizations using autonomous or multi-agent systems should refresh their control assumptions, human accountability model, and end-user transparency now.
Singapore Model AI Governance Framework for Agentic AI
Singapore released a Model AI Governance Framework for Agentic AI on January 22, 2026, adding practical controls for bounded autonomy, human checkpoints, technical safeguards, and transparency that organizations should adopt before expanding agentic deployments.
California(2)
CA SB1011: Energy: Utility Infrastructure AI Safety, Oversight, and Workforce Protection Act
California SB1011 was set for hearing on May 14, 2026, putting AI safety and oversight obligations for utility infrastructure uses under active legislative review and warranting immediate stakeholder monitoring.
California AB 2169: Social media platforms: artificial intelligence models
California AB 2169 was read a second time and amended on April 23, 2026, signaling continued legislative attention to AI models on social media platforms and the need to track platform-specific obligations.
New York(1)
Weekly digest
Leave your email to get each issue in your inbox. Free, no account required.
We use your email only for the digest. Privacy policy