AI Compliance for Risk Management
Risk Management is addressed by 50 regulatory updates across 9 jurisdictions and 10 frameworks. This page tracks how regulators worldwide are approaching risk management in the context of artificial intelligence.
Framework Requirements for Risk Management
Regulations Covering Risk Management
US Federal(22)
FDA AI-enabled medical device and PCCP guidance baseline
FDA’s August 2025 PCCP guidance provides recommendations for planned modifications to AI-enabled devices reviewed through the 510(k), De Novo and PMA pathways.
SEC announces internal AI task force
The SEC announced an internal AI task force on 1 August 2025 to coordinate responsible AI adoption across the agency; the announcement does not introduce a new external compliance obligation.
FTC AI enforcement actions on deceptive claims and substantiation
These records cover separate FTC proceedings concerning AI claims, an AI companion chatbot inquiry, and the later setting aside of the Rytr order; they do not establish a common new compliance deadline.
FTC AI enforcement posture remains active across deceptive claims and AI investments
The FTC’s AI hub and related matters, including Rytr, Workado, and DoNotPay, show that the agency continues to police deceptive AI claims and conduct, so AI product and marketing teams should assume ongoing enforcement scrutiny now.
FDA continues AI-enabled medical device guidance and submissions workflow updates
FDA’s AI-enabled medical device materials show an active draft-guidance and feedback cycle, with public feedback on generative AI-enabled medical devices due by 2026-10-19, so device teams need to prepare submission and validation materials now.
European Union(10)
AI Act consultations and implementation guidance for GPAI, sandboxes, and transparency
The Commission has opened or advanced multiple AI Act implementation workstreams for GPAI, high-risk classification, transparency, and regulatory sandboxes, meaning providers and deployers must now align their implementation plans to the emerging guidance rather than wait for finalised national practice.
EU AI Act implementation consultations advance on GPAI, transparency, high-risk classification and sandboxes
The Commission’s AI Act consultations on GPAI, transparency obligations, high-risk classification, sandboxes, and the scientific panel show that the operational rulebook is still being finalized, so affected providers should engage now to shape interpretation.
EBA, EIOPA and ESMA call for enhanced governance over frontier AI ICT risks in EU financial services
On 2026-07-31, the EU supervisory authorities called for stronger governance and consistent supervision to mitigate ICT risks from frontier AI models in the financial sector, signaling that firms should tighten controls now rather than wait for formal rule changes.
ESA call for enhanced governance and consistent supervision of frontier AI ICT risks
On 2026-07-31, EBA, EIOPA and ESMA called on EU financial-sector firms and supervisors to tighten governance and supervision of frontier AI-related ICT risks, signaling immediate expectations for stronger control frameworks under existing resilience obligations.
EU AI Office and supervisors call for enhanced governance for frontier AI in financial services
EU financial supervisors and the AI Office are signaling stronger governance and consistent supervision expectations for frontier AI models in the financial sector, so firms should treat this as an immediate AI Act implementation and risk-governance update rather than a future issue.
International(6)
AICPA SOC 2 resources reaffirm current Trust Services Criteria for AI-enabled services
AICPA’s SOC resources confirm the current Trust Services Criteria baseline and do not create AI-specific rules, but they reinforce that AI-enabled services must still satisfy existing security, privacy, and processing integrity controls in audits.
NIST AI RMF revision and critical-infrastructure profile development
NIST says the AI RMF is being revised and that a new trustworthy-use profile for critical infrastructure is under development, while the baseline AI RMF 1.0 remains voluntary and headed for review no later than 2028.
ISO/IEC 42006:2025 defines requirements for AI management system certification bodies
ISO/IEC 42006:2025 supplements the requirements for bodies auditing and certifying AI management systems against ISO/IEC 42001; the ISO catalog records its publication in July 2025.
ISO AI management-system and adjacent AI standards pipeline expands
ISO’s AI standards pages and draft items show an active pipeline around AI management systems, audit/certification, societal concerns, and privacy protection, so organizations pursuing ISO-based assurance should update their standards watchlist now.
NIST signals revision of AI RMF and new critical-infrastructure profile work
NIST’s AI RMF materials state that the framework is being revised and that a new critical-infrastructure trustworthy-AI profile was launched on 2026-04-07, so organizations relying on the RMF should track the revision now for shifting implementation guidance.
Switzerland(4)
Swiss FDPIC guidance on AI and data protection, plus legislative roadmap
The FDPIC has made clear that Switzerland’s data protection law already applies to AI-supported processing and that the federal government is targeting an AI bill by the end of 2026, so organizations should harden transparency and automated-decision controls now.
FINMA sets governance and risk-management expectations for AI use in Swiss financial institutions
FINMA’s 2024 guidance states that Swiss financial institutions using AI must identify, limit, control, and monitor AI-related risks within their existing supervisory framework, so firms should immediately test whether their governance and model-risk controls are adequate.
FDPIC guidance and enforcement focus on AI and data protection
The FDPIC states that the Swiss FADP applies directly to AI-supported processing and is actively pursuing investigations, so organizations using AI with personal data must now evidence transparency, proportionality, purpose limitation, and human review readiness.
FDPIC says Swiss data-protection law applies directly to AI-supported processing
On 2025-05-08, the FDPIC reiterated that Switzerland’s data-protection law already applies directly to AI-supported processing, meaning transparency, purpose limitation, and data-subject rights must be built into current AI operations now.
Singapore(2)
Singapore updates agentic AI governance framework and PDPC personal-data guidance
Singapore has updated its model AI governance framework for agentic AI and already has advisory guidelines for personal-data use in AI recommendation and decision systems, so organizations should refresh governance, human oversight, and data-use controls now.
Singapore updates its Model AI Governance Framework for Agentic AI
IMDA updated its agentic AI governance framework in May 2026, so organizations using autonomous or multi-agent systems should refresh their control assumptions, human accountability model, and end-user transparency now.
United Kingdom(2)
FCA confirms no new AI-specific rules for financial services
The FCA says it is not planning AI-specific regulation and will rely on existing frameworks such as Consumer Duty and SM&CR, so firms should focus on fitting AI governance into current control regimes rather than waiting for a new rulebook.
ICO AI and data protection guidance remains active but under review
The ICO says its AI guidance supports audit and enforcement activity and is under review following the Data (Use and Access) Act 2025, so UK organizations should keep using it as the current baseline while planning for revisions.
California(2)
California AI bills on healthcare, employment, and transparency
California state AI bills AB2575, SB947, SB503, AB1979, and SB1159 advanced in late August 2026, signaling continued movement on healthcare AI, automated decision systems, and AI transparency/governance.
California 2026 AI bills on employment, health care, and agentic AI
California has introduced multiple AI bills affecting employment, health care, labor impacts, and agentic AI, and several were already set for hearing or suspense-file consideration as of early August 2026, so employers and AI vendors should review them immediately.
Colorado(1)
Canada(1)
Weekly digest
Leave your email to get each issue in your inbox. Free, no account required.
We use your email only for the digest. Privacy policy