AI Compliance for Risk Management
Risk Management is addressed by 50 regulatory updates across 7 jurisdictions and 7 frameworks. This page tracks how regulators worldwide are approaching risk management in the context of artificial intelligence.
Framework Requirements for Risk Management
Regulations Covering Risk Management
US Federal(17)
FDA AI-enabled medical device guidance and lifecycle expectations
FDA’s AI/ML medical device guidance set and device list continue to expand, so AI health-tech teams need to align premarket, transparency, and change-control evidence before new or modified systems are submitted or marketed.
FTC enforcement against deceptive AI claims continues
The FTC’s AI enforcement actions and related press releases show that deceptive AI performance claims remain an active Section 5 risk, so marketing and product teams need substantiation before regulators ask for it.
FTC seeks public comment on AI accuracy policy statement
On 2026-07-07, the FTC proposed a policy statement on AI accuracy, signaling that claims and system behavior that manipulate expected accuracy may be treated as deceptive under Section 5.
Congressional AI-related bills remain active but are not a single federal AI regime
Several AI-adjacent bills are active in Congress, but they do not create a unified federal AI law, so federal compliance planning remains agency-driven rather than statute-driven.
FTC seeks public comment on proposed AI accuracy policy statement
The FTC opened public comment on a proposed policy statement targeting AI accuracy claims, signaling that businesses making AI-performance representations should expect scrutiny over substantiation and deception risk now.
European Union(15)
Commission publishes transparency guidance under the AI Act
The Commission published guidance on Article 50 transparency obligations ahead of the 2 August 2026 applicability date, so providers and deployers now need to operationalize labeling and disclosure workflows rather than wait for enforcement to start.
Digital Omnibus on AI amends the EU AI Act
Regulation (EU) 2026/1744 amends the AI Act and makes the new prohibitions on realistic intimate/deepfake-style synthetic content and the updated Article 50 transparency obligations operative from 2 December 2026, creating immediate implementation work for AI providers and deployers.
ESRB Warning on systemic cyber risks from frontier AI models
The ESRB warned that frontier AI models can collapse defensive time buffers and materially increase systemic cyber risk for EU financial institutions, and it specifically points to ECB-requested action plans due by 31 October 2026 as the near-term trigger for supervisory attention.
CJEU preliminary reference on whether AI-assisted expert reporting is high-risk under the AI Act
A 2026 CJEU reference asks whether software generating automated outcomes or using AI elements in an expert report should be treated as a high-risk AI system under the AI Act, creating interpretive uncertainty for litigation-support tools.
European Commission AI Office implementation guidance and GPAI compliance support
The Commission’s AI Office continues publishing guidance and code-of-practice materials to operationalize AI Act obligations for GPAI providers, creating near-term compliance expectations even before further implementing acts land.
International(10)
ISO/IEC 42001 certification ecosystem expands with new accreditation and audit guidance
ISO/IEC 42001 is increasingly operationalized through new accreditation and certification guidance, so organizations adopting the standard now need to validate which certifiers and audit bodies are recognized.
ISO 42001 explained
ISO’s explainer confirms certification to ISO/IEC 42001 is voluntary, so organizations should treat it as a governance framework rather than a mandatory legal requirement.
ISO/IEC 42001:2023 AI management systems
ISO/IEC 42001:2023 is the current published edition and establishes the baseline requirements for implementing an AI management system, so teams pursuing certification or AI governance alignment should treat it as the operative reference now.
NIST draft misuse-risk guidance targets dual-use foundation models
NIST’s draft guidance on dual-use foundation models may affect model governance and testing workflows, so teams should treat it as an emerging reference for misuse-risk management even though it is not itself an AI RMF update.
NIST generative AI profile remains a key AI RMF companion resource
NIST’s July 26, 2024 Generative AI Profile remains a key companion to AI RMF 1.0, so organizations using GenAI should continue to map controls to the profile’s risk scenarios and governance themes.
United Kingdom(3)
ICO AI and data protection guidance remains active and under review
The ICO says its AI guidance is not statutory but is used for audit and enforcement, and it is under review due to the UK’s newer data legislation, so organizations should treat it as live supervisory guidance.
ICO AI and data protection guidance remains the regulator’s operational baseline
The ICO says its AI guidance is both compliance best practice and the basis for audit/enforcement activity, so organizations processing personal data in AI systems must treat it as current supervisory expectation, not optional advice.
UKAS grants first accreditation for ISO/IEC 42001 certification
UKAS accredited BSI for ISO/IEC 42001 certification, creating a live accredited certification market that materially changes how organizations can seek independent assurance for AI management systems.
Switzerland(2)
FDPIC confirms Swiss data-protection law applies directly to AI
The FDPIC reiterates that the Swiss Federal Data Protection Act applies directly to AI-supported processing, so organizations cannot wait for a separate AI statute before fixing transparency, automated-decision, and human-review controls.
ISO/IEC 42005:2025 published for AI system impact assessments
ISO published ISO/IEC 42005:2025 in May 2025, adding a formal AI system impact-assessment standard that organizations can now use to evidence structured AI governance alongside ISO/IEC 42001.
California(2)
California AI and privacy legislative activity remains active
California’s AI/privacy legislative tracker and related materials show continuing state-level momentum on transparency, governance, and AI-specific consumer rights, so deployers should expect additional California requirements to layer on top of federal obligations.
California SB1159 advances on AI transparency and governance
California SB1159 is moving forward on AI transparency and governance, so organizations should prepare for potential state-level governance, disclosure, or accountability requirements.
Singapore(1)
Weekly digest
Leave your email to get each issue in your inbox. Free, no account required.
We use your email only for the digest. Privacy policy