Skip to main content

AI Compliance · Executive Guide

AI Compliance in 2026: Your Company Already Uses AI — But Who Controls It?

AI has moved from a writing assistant to business infrastructure.

It now influences hiring, customer service, credit decisions, fraud detection, pricing, CRM workflows, internal reporting, software development and autonomous actions. The business question is no longer whether your company uses AI. It is whether you know where AI is operating, what data it receives, what decisions it influences and who can stop it when something goes wrong.

Vladimir Zhemerov

Written by Vladimir Zhemerov

Senior Product Manager & AIO/GEO SpecialistPublished 2026-07-31

Category

AI Compliance · Governance

Reading time

18 min read

Updated

2026-07-31

Audience

Executive · Legal · Security

Interactive · The visibility gap

What the board believes is running, against what is actually running

AI touchpoints in view

3systems in the AI program

The board view counts 3 funded systems. The actual surface is 16 — a gap of 13 that no one has been asked to own. You cannot govern what you cannot see.

  • candidate screening

    CV, demographics

    In the program

  • employee performance analysis

    HR records

    Unowned

  • lead scoring

    CRM, contacts

    Unowned

  • customer support

    customer messages

    In the program

  • call transcription

    voice, PII

    Unowned

  • document summarization

    contracts, internal docs

    Unowned

  • contract review

    legal terms

    Unowned

  • automated reporting

    financials

    In the program

  • code generation

    source code

    Unowned

  • fraud alerts

    transactions

    Unowned

  • dynamic pricing

    commercial terms

    Unowned

  • marketing personalization

    behavioral data

    Unowned

  • CRM updates

    pipeline records

    Unowned

  • email drafting

    client correspondence

    Unowned

  • knowledge search

    internal knowledge

    Unowned

  • agentic workflows

    internal tools, permissions

    Unowned

Board view — 3 systems in the AI program
candidate screening, customer support, automated reporting — funded, named, and each with an owner who can answer for it.
Actual surface — 16 touchpoints, 13 unowned or undeclared
employee performance analysis, lead scoring, call transcription, document summarization, contract review, code generation, fraud alerts, dynamic pricing, marketing personalization, CRM updates, email drafting, knowledge search, agentic workflows — already reading CVs, voice recordings, contracts, transactions and internal permissions without appearing in any AI register.

An AI inventory built only from officially funded projects will usually understate real exposure. The touchpoints listed are the article’s own examples, not a survey.

The short answer

Definition

AI compliance is the system of policies, technical controls, documentation and human accountability used to ensure that artificial intelligence is lawful, secure, fair, explainable and controlled throughout its lifecycle.

It includes AI inventory, risk classification, data governance, vendor due diligence, bias and accuracy testing, human oversight, logging, incident response and continuous monitoring.

AI compliance matters now because adoption has accelerated faster than governance. The Stanford AI Index 2026 reports that 88% of surveyed organizations used AI in 2025, and that 70% used generative AI in at least one business function. At the same time, McKinsey’s 2025 global survey found that nearly two-thirds of organizations had not yet begun scaling AI across the enterprise, while 62% were at least experimenting with AI agents and 23% were already scaling one.

That gap is where risk accumulates.

Key takeaways for executives

  • 01

    AI adoption is already widespread, but AI governance is still immature.

  • 02

    Your company can be responsible for AI output even when the model comes from a third-party vendor.

  • 03

    Bias can occur without explicitly using race, gender, age or disability data.

  • 04

    A human approval button does not automatically create meaningful human oversight.

  • 05

    AI agents create more risk than ordinary chatbots because they can take actions, not just generate text.

  • 06

    The EU AI Act is already applying in phases: three waves bind today, general application and transparency duties arrive on 2 August 2026, and the high-risk waves follow on 2 December 2027 and 2 August 2028.

  • 07

    For most companies the first damage will not be the maximum regulatory fine. It will be a blocked product, a lost enterprise deal, forced remediation, a lawsuit, a data incident or a reputational failure.

  • 08

    Compliance-by-design is usually easier and less disruptive than retrofitting controls after AI is embedded in core workflows.

Why AI compliance has become urgent

AI adoption did not wait for legal teams, procurement processes or risk committees. In many organizations, AI entered through individual employees, browser extensions, SaaS features, CRM plugins, coding assistants and personal subscriptions. Microsoft’s 2024 Work Trend Index found that 78% of AI users were bringing their own AI tools to work — 80% at small and medium-sized companies — and that 52% of people who use AI at work were reluctant to admit using it for their most important tasks.

This creates shadow AI: AI systems, models or features used outside approved security, privacy, procurement and governance processes. The risk is measurable.

Evidence · Shadow AI and breach cost

What ungoverned AI actually costs — and how fast the number moved in one year

IBM Cost of a Data Breach 2026

602 organizations; breaches between March 2025 and February 2026

  • 20%+

    of organizations reported a breach targeting AI models or applications

    Base: all studied organizations

  • 1 in 4

    malicious breaches were AI-enabled — a 56% increase year over year

    Base: malicious breaches — bar drawn at 25%

  • $6M

    average cost of an AI-enabled breach, against a $4.99M global average

    Average cost, not a share — no bar

IBM Cost of a Data Breach 2025

shadow-AI findings, not restated in the 2026 edition

  • 97%

    of organizations breached this way had no proper AI access controls

    Base: organizations reporting an AI-related breach

  • 1 in 5

    organizations reported a breach caused by shadow AI

    Base: all studied organizations — bar drawn at 20%

  • $670,000

    higher average breach cost where shadow-AI levels were high, against low or none

    Cost delta, not a share — no bar

  • 63%

    of breached organizations had no AI governance policy, or were still developing one

    Base: organizations reporting a breach

The finding is not that every employee using a chatbot creates a catastrophe. It is that a company cannot govern what it cannot see.

Percentages describe each stated base, not all organizations, and the bases differ between rows — the groups are nested rather than additive, so the shares must not be summed. Cost figures are averages and deltas rather than shares, which is why they carry no bar. The 2025 and 2026 editions are kept separate because the later report restates the headline AI-breach rate but not the shadow-AI findings.

The hidden governance gap

A board may believe the company has “three AI projects.” In practice, AI may already be shaping candidate screening, employee performance analysis, lead scoring, customer support, call transcription, document summarization, contract review, automated reporting, code generation, fraud alerts, dynamic pricing, marketing personalization, CRM updates, email drafting, knowledge search and agentic workflows connected to internal tools.

An AI inventory that includes only officially funded projects will usually underestimate the real exposure.

What AI compliance actually covers

AI compliance is often misunderstood as a legal review performed shortly before launch. That is too narrow. A mature AI compliance program answers five operational questions.

  1. 01

    Where is AI used?

    Across funded projects, vendor features, pilots and the tools employees brought themselves.

  2. 02

    What can the system affect?

    People, money, rights, confidential data, public statements, business continuity.

  3. 03

    What data and permissions does it receive?

    Inputs, retention, transfers, and what the system is allowed to do with the tools it can reach.

  4. 04

    Who is accountable for its decisions and actions?

    A named business owner, technical owner and risk owner — with authority to pause it.

  5. 05

    What evidence can the company produce after an incident?

    A reconstructable trail: version, source, output, action, reviewer, override, timestamp.

Cybersecurity and privacy are necessary, but neither is sufficient on its own. Cybersecurity asks whether unauthorised users can access or manipulate a system. Privacy asks whether personal data is processed lawfully and appropriately. AI governance must also ask:

  • Is the business purpose legitimate?
  • Does the model create unequal outcomes?
  • Can a decision be explained and reconstructed?
  • Is the system accurate enough for this use case?
  • Can users challenge an adverse decision?
  • Does the human reviewer have real authority?
  • What happens when the vendor changes the model?
  • Can an AI agent send, delete, publish, purchase or pay without approval?
  • Can the company stop the system quickly?

AI compliance is not a policy document. It is an operating model.

The hidden risks companies underestimate

1. Algorithmic bias can exist without protected attributes

A company may remove race, gender, age, disability or religion from a dataset and conclude that discrimination is impossible. That conclusion is wrong. AI systems can reconstruct or approximate protected characteristics through proxy variables.

Interactive · Proxy variables

Remove the protected attribute and a model can still reconstruct it

Variable kept in the model

Nothing protected was collected

ZIP code

Can approximate

  • race
  • national origin

Because

residential segregation is historical and persistent

The correlation is a mechanism, not an accident — which is why a model can rebuild the attribute you deleted.

All eleven mappings

ZIP code
can approximate race, national origin — because residential segregation is historical and persistent
Language
can approximate national origin, ethnicity — because first language tracks migration history
Education
can approximate race, class, age — because access to institutions is unequally distributed
Employment gaps
can approximate sex, disability — because caregiving and illness are unevenly borne
Purchasing behavior
can approximate sex, religion, health status — because what people buy discloses who they are
Location data
can approximate religion, disability, health — because places of worship and clinics are visited, not declared
Device type
can approximate income, age — because hardware is a wealth and generation marker
Income patterns
can approximate race, sex — because pay gaps are inherited by any model trained on pay
Historical salary
can approximate sex, race — because encoding past pay reproduces past discrimination
Healthcare spending
can approximate race — because unequal historical access means unequal spending at equal illness
Credit history
can approximate race, age — because thin files track exclusion from credit, not creditworthiness

When the target variable is the bias

A 2019 study in Science by Obermeyer and colleagues examined a healthcare algorithm that used medical spending as a proxy for health need. Because less money had historically been spent on Black patients at the same level of illness, the algorithm systematically understated their need.

Share of Black patients identified for additional care

  • Algorithm as built

    17.7%

    medical spending used as the stand-in for health need

  • Same algorithm, health-need target

    46.5%

    the label changed, the model did not

Scale 0–50%

Illustrative mappings, not a claim that any given proxy always encodes a protected attribute — the point is that outcomes must be tested, not assumed. The two bars restate published figures from the cited study. Note what the study did not require: the model had no “race” field, and produced a racially unequal result anyway.

Bias can enter through the objective being optimised, historical decisions used as labels, underrepresentation in training data, proxy variables, thresholds, deployment context, feedback loops and uneven error rates across groups.

What the enforcement record already shows

In September 2023 the U.S. Equal Employment Opportunity Commission announced a $365,000 settlement with iTutorGroup. The EEOC alleged the company had programd its application software to automatically reject female applicants aged 55 or older and male applicants aged 60 or older. Strictly, that was a hard-coded filter rather than a trained model — which makes it a strong precedent on automated-decision liability rather than on model bias. The relevant point stands either way: existing anti-discrimination law reaches software that decides about people, with or without a dedicated AI statute.

A model-based action followed. In December 2023 the FTC barred Rite Aid from using facial recognition for surveillance for five years, alleging the retailer deployed the technology from 2012 to 2020 without reasonable safeguards, and that it falsely flagged consumers — particularly women and people of color — as shoplifters. The failure the regulator described was not the algorithm in isolation. It was deployment without testing, thresholds, oversight or redress.

What companies should test

Do not test only aggregate accuracy. Test:

  • false-positive and false-negative rates by relevant group
  • approval, rejection and escalation rates
  • proxy variables
  • outcome disparities
  • threshold sensitivity
  • performance on underrepresented populations
  • whether the business target itself is appropriate

A model can be 92% accurate overall and still be unacceptable for a specific population.

2. AI errors become business liability when they enter a workflow

A single hallucination in an internal draft may be inconvenient. The same hallucination connected to a customer-facing workflow, legal filing, payment system or CRM can become a legal and operational incident.

Interactive · From error to liability

The same hallucination costs nothing, or becomes an incident — the workflow decides

01 · Model output

A fluent, confident statement that is not true

Identical in all three paths

02 · Lands in

A published support channel the customer trusts

03 · Action taken

The customer acts on the information

04 · Exposure

The company is bound by what its chatbot said

Severity Elevated · Binding

A business does not outsource accountability merely by outsourcing the model.

All three paths, side by side

  • Internal draft

    Severity Low · Contained

    Lands in
    An internal document nobody relies on
    Action taken
    The author notices the error and edits it
    Exposure
    Inconvenience — the cost is a few minutes
  • Customer-facing answer

    Severity Elevated · Binding

    Lands in
    A published support channel the customer trusts
    Action taken
    The customer acts on the information
    Exposure
    The company is bound by what its chatbot said
  • Formal filing

    Severity High · Sanctionable

    Lands in
    A court, regulator or auditor
    Action taken
    Fabricated citations enter a formal process
    Exposure
    Sanctions, professional exposure and reputational damage

What the record shows

Path 1 has no case on record — that is the point. The error never left the organization.

  • Customer-facing answer · selected

    Moffatt v. Air Canada, 2024 BCCRT 149

    A customer relied on incorrect bereavement-fare information from Air Canada’s chatbot. The tribunal rejected the idea that the chatbot was a separate entity and held the company responsible for information on its own website.

  • Formal filing

    Mata v. Avianca, Inc., No. 22-cv-1461 (PKC) (S.D.N.Y. 22 June 2023)

    Lawyers submitted nonexistent cases and fabricated quotations generated by ChatGPT. The court imposed $5,000 in sanctions, jointly and severally, on the two lawyers and their firm.

Case summaries are compressed for illustration and are not legal advice. The failure in each is not only that a model was wrong — it is that the output reached a consequential process without adequate verification. A disclaimer that “AI may make mistakes” does not repair a workflow that relies on unverified output.

High-impact places where a fabricated answer stops being harmless include legal analysis, medical guidance, financial recommendations, customer eligibility, contractual terms, tax calculations, compliance reporting, product specifications, safety instructions, fraud accusations and automated account restrictions. Controls should include approved-source retrieval, citations, deterministic validation, confidence or abstention rules, sampling and qualified human review — the same retrieval discipline that separates a demo from an enterprise RAG system.

3. Shadow AI creates privacy, confidentiality and security exposure

Employees often use public AI tools because approved alternatives are slower or unavailable. They may paste contracts, customer records, source code, financial forecasts, HR data, legal correspondence, product roadmaps, credentials and internal incident reports.

This can create problems involving lawful basis for processing, international data transfers, retention, vendor training practices, trade secrets, contractual confidentiality, deletion rights, data-subject access, incident response and intellectual property.

The correct response is not a blanket ban that employees will ignore. A better program combines:

  • approved enterprise AI tools
  • clear data-classification rules
  • prompt-level data loss prevention
  • browser and SaaS discovery
  • role-based access
  • employee training
  • documented exceptions
  • monitoring for unsanctioned AI use

Governance must make the safe path easier than the unsafe path.

4. AI agents create more risk than chatbots

A chatbot produces an answer. An AI agent can produce an action. It may be connected to email, CRM, databases, file storage, code repositories, payment systems, ticketing systems, calendars, cloud infrastructure and internal APIs. That changes the risk model. The OWASP Top 10 for LLM Applications (2025 edition) lists LLM01 prompt injection, LLM02 sensitive information disclosure, LLM05 improper output handling and LLM06 excessive agency among its ten risks. For agentic deployments, OWASP’s separate Top 10 for Agentic Applications (2026) adds agent goal hijack, tool misuse and identity and privilege abuse.

Interactive · Agent blast radius

A chatbot produces an answer. An agent produces an action — select one to see what it can reach

How an injected instruction becomes an action

  1. 01

    Untrusted content — an email, a webpage, a document

  2. 02

    The agent reads it

  3. 03

    The instruction is obeyed as if it were the user’s

  4. 04

    A tool permission is exercised

  5. 05

    A real-world action happens

    This is the damage

The dangerous failure is not a bad answer. It is a bad answer wired to an action.

What the agent is permitted to do

Fourteen actions an agent is routinely wired to. Select one to read its reach; every row is also written out in the table below.

Selected action

send

Systems reached

  • email
  • messaging

Worst realistic outcome

A wrong or confidential message reaches a customer irreversibly

Required control

BOTH

Enforced outside the model. A prompt instruction is not a control.

The full mapping

  • send

    email, messaging

    A wrong or confidential message reaches a customer irreversibly

    BOTH

  • delete

    file storage, databases

    Unrecoverable loss of records

    BOTH

  • pay

    payment systems

    Funds leave the company

    BOTH

  • purchase

    procurement, cards

    Unbudgeted spend and contractual commitment

    BOTH

  • sign

    contract systems

    The company is bound to terms nobody reviewed

    HUMAN APPROVAL

  • publish

    website, social, docs

    A false statement becomes a public position

    BOTH

  • deploy

    cloud infrastructure

    An outage or an insecure configuration goes live

    BOTH

  • merge code

    code repositories

    Unreviewed logic enters the product

    DETERMINISTIC GATE

  • change permissions

    identity and access

    Privilege escalation across systems

    BOTH

  • export data

    databases, storage

    Bulk exfiltration of personal or confidential data

    BOTH

  • create users

    identity systems

    A persistent unauthorised foothold

    BOTH

  • disable security controls

    security tooling

    Detection and prevention silently stop

    BOTH

  • reject a candidate

    recruitment systems

    An unlawful adverse decision about a person

    HUMAN APPROVAL

  • block a customer

    CRM, billing, support

    A customer loses access to a service they pay for

    HUMAN APPROVAL

  • change a price

    commercial systems

    Margin loss or discriminatory pricing

    DETERMINISTIC GATE

Enforced outside the model

  • Permissions
  • Allowlists
  • Rate limits
  • Transaction thresholds
  • Sandboxing
  • Approval gates

Safety-critical restrictions belong in the surrounding system, not in the prompt. A model can be persuaded; a permission boundary, a spend threshold or an approval gate cannot be talked out of its answer.

The OWASP Top 10 for LLM Applications names prompt injection, sensitive information disclosure, improper output handling and excessive agency among the major risks. Outcomes here are realistic worst cases for an over-permissioned agent, not incident statistics.

Prompt instructions are not enough. Safety-critical restrictions should be enforced outside the model through permissions, allowlists, rate limits, transaction thresholds, sandboxing and approval gates — the architecture described in engineering secure AI automation.

5. A famous vendor does not eliminate vendor risk

Using a major AI provider may reduce some infrastructure risk, but it does not make a deployment compliant by default. The provider controls the base model. Your company controls:

  • the business purpose
  • input data
  • system prompts
  • knowledge sources
  • user interface
  • permissions
  • thresholds
  • escalation rules
  • downstream actions
  • retention configuration
  • affected users

Vendor due diligence should examine:

  • whether regulated or high-impact use is permitted
  • whether customer content is used for training
  • data residency and subprocessors
  • retention and deletion
  • model versioning
  • notice of material changes
  • incident notification
  • audit rights
  • intellectual-property terms
  • liability limitations
  • portability and exit options
  • evaluation evidence

A vendor contract can allocate responsibility. It cannot erase it.

Why “human in the loop” is often an illusion

Many organizations believe they have solved AI risk because a person clicks Approve before the system acts. That is not necessarily meaningful human oversight.

In the UK, that test is now written into the statute itself. Section 80 of the Data (Use and Access) Act 2025 replaced Article 22 of the UK GDPR with new Articles 22A–22D from 5 February 2026, and Article 22A(1)(a) provides that a decision is based solely on automated processing if there is no meaningful human involvement in taking it. The Information Commissioner’s Office has long held that a decision does not escape those rules merely because a person “rubber-stamped” it; what matters is the degree and quality of the human review before the final decision. The ICO consulted on updated automated-decision-making guidance between March and May 2026, with final guidance expected during 2026.

Interactive · Oversight diagnostic

Select what is true in your organization — meaningful human review, or a rubber stamp?

COSMETICMEANINGFUL0OVERSIGHT INDEX

Not yet assessed

Toggle the statements below that describe your current review process — the needle moves as you go.

Review is meaningful when

Review is probably cosmetic when

A self-assessment aid, not a legal test. Each red flag cancels one condition, because a control you can name does not count if a structural signal says it cannot bite. Regulators assess the substance of the review, not the presence of an approval button — see the ICO guidance on meaningful human review linked in the sources.

The failure mode has a name: automation bias — the tendency to over-trust an automated recommendation, especially under time pressure.

A practical oversight model

Autonomy should scale down as impact scales up. The four tiers below are a working allocation of autonomy and the minimum controls that make each tier real.

Interactive · Autonomy by risk tier

How much autonomy a system should have, and the minimum controls that make it real

Autonomy scales down as impact scales up. Select a tier to raise it — every tier stays readable either way.

  • Example uses
    Internal ideation, non-sensitive summarization, draft creation
    Appropriate autonomy
    High, but no automatic external action
    Minimum controls
    Approved tools, sensitive-data rules, sample review

    WhyNothing leaves the building and nothing is decided, so speed is worth more than ceremony.

  • Example uses
    CRM enrichment, customer-support drafts, lead recommendations
    Appropriate autonomy
    AI recommends; humans approve material changes or external messages
    Minimum controls
    Accuracy testing, source grounding, logging, periodic fairness review

    WhyThe output reaches a customer or a record of truth, so a person owns the moment it becomes real.

  • Example uses
    Hiring, credit, insurance, healthcare, fraud blocking, significant pricing or eligibility decisions
    Appropriate autonomy
    Low autonomy; qualified human review before adverse action
    Minimum controls
    Impact assessment, legal review, bias testing, complete decision trail, appeal process

    WhyA person’s job, money, health or rights are on the line and the decision must be explainable and appealable.

  • Example uses
    Illegal discrimination, certain manipulative uses, uncontrolled high-impact actions
    Appropriate autonomy
    None
    Minimum controls
    Technical and policy block, executive escalation, documented prohibition

    WhySome uses are not a risk to be managed; they are a line not to cross.

Meter: filled segments = autonomy allowed — 4 high, 3 medium, 1 low, 0 none

“A control is only real when it can change the outcome.”

A working model for allocating autonomy, not a legal classification. Regulatory categories — for example the EU AI Act’s high-risk annexes — are defined by law and may classify a system differently from an internal tier.

AI regulation is no longer hypothetical

AI regulation is developing through several overlapping layers: AI-specific legislation, privacy law, employment law, equality and civil-rights law, consumer protection, cybersecurity, sector-specific rules, product liability, contract law and procurement requirements.

A company may have no dedicated “AI law” in its home jurisdiction and still face substantial AI-related obligations.

Interactive · EU AI Act timeline

Not one compliance date — 6 waves, of which 3 are already binding

1 August 2024· in force

The Act enters into force

Regulation (EU) 2024/1689 becomes law. Almost nothing is immediately enforceable against an ordinary deployer, but the clock starts on every phase below.

2 February 2025· in force

Prohibited practices and AI literacy

Banned AI practices begin applying, together with an obligation to ensure a sufficient level of AI literacy among staff who operate AI systems. This is the first wave that reaches an ordinary company's day-to-day use.

2 August 2025· in force

General-purpose AI models and governance

Obligations for providers of general-purpose AI models begin applying, along with the governance, notification and penalty architecture. Most companies meet this one indirectly — through what their model provider must now document and disclose to them.

2 August 2026· upcoming

General application and transparency duties

The Act becomes generally applicable, including transparency obligations for systems that interact with people or generate synthetic content, and the enforcement powers behind them. Marking obligations for AI-generated content on systems already placed on the market before that date follow on 2 December 2026.

2 December 2027· upcoming

Stand-alone high-risk systems

High-risk rules reach the Annex III use cases — employment, education, biometrics, essential private and public services, law enforcement and similar. This wave was deferred from August 2026 by the AI Omnibus, which entered into force on 27 July 2026; the new date is absolute, with no readiness trigger attached.

2 August 2028· upcoming

High-risk AI inside regulated products

Requirements reach high-risk AI embedded in products already covered by EU product-safety legislation — machinery, medical devices, vehicles and similar regulated categories.

The practical reading: three waves already bind, and the next arrives on 2 August 2026. A company that has not inventoried its AI systems is not preparing for a future obligation — it is already behind one.

Dates reflect the phased application of Regulation (EU) 2024/1689, including the deferral of the Annex III high-risk wave to 2 December 2027 by the AI Omnibus that entered into force on 27 July 2026. Checked against the European Commission’s published timeline on 31 July 2026; positions along the rail are proportional to elapsed time. This is an operating-model summary, not legal advice, and scope depends on your role (provider or deployer), the system category and the market you serve.

The EU AI Act can also affect companies outside the EU when they place systems on the EU market or when AI output is used in the EU. Maximum penalties can reach €35 million or 7% of worldwide annual turnover for certain prohibited practices, and €15 million or 3% for certain other violations.

The more realistic near-term risk for most companies is not the theoretical maximum fine. It is:

  • a product feature being restricted
  • a data-processing practice being challenged
  • an enterprise customer refusing procurement
  • an inability to document decisions
  • forced remediation
  • litigation
  • reputational loss
  • a delayed launch
  • loss of market access

United States

The United States still has no horizontal AI statute and relies instead on existing federal and state law: employment discrimination law, consumer protection, credit and housing law, biometric privacy, state privacy law, healthcare regulation, and tort and contract law. That is not the same as an absence of rules — more than a hundred state AI laws had been enacted by mid-2026.

The state picture is moving quickly, and in more than one direction:

  • New York City

    Local Law 144 requires bias audits and candidate notices for certain automated employment decision tools; enforcement began in July 2023.

  • Illinois

    House Bill 3773 (Public Act 103-0804), amending the Illinois Human Rights Act, took effect on 1 January 2026. It makes it a civil-rights violation to use AI with a discriminatory effect on a protected class, bars ZIP code as a proxy for a protected class, and requires notice when AI is used. Implementing notice rules are still in rulemaking — proposed rules were published in May 2026 and withdrawn in June 2026 for inter-agency coordination.

  • California

    The CPPA's regulations on automated decision-making technology took effect on 1 January 2026, with the core ADMT duties — pre-use notice, opt-out and access rights where ADMT drives significant decisions about finances, housing, education, employment or health care — applying from 1 January 2027, and risk-assessment and cybersecurity-audit duties phasing in through 2030. The Transparency in Frontier Artificial Intelligence Act (SB 53) has applied to large frontier-model developers since 1 January 2026.

  • Colorado

    The opposite of what most timelines still say. The Colorado AI Act (SB 24-205) never took effect: its start date slipped from February to June 2026, a federal court blocked enforcement in April 2026 after a constitutional challenge in which the Department of Justice intervened, and in May 2026 SB 26-189 repealed and reenacted it as a narrower automated-decision regime — dropping the duty of care, high-risk classification and mandatory impact assessments in favour of notice, adverse-outcome explanations and meaningful human review, effective 1 January 2027.

There is also federal pressure on that state layer. In December 2025 an executive order, Ensuring a National Policy Framework for Artificial Intelligence, directed agencies to challenge state AI laws, created a Department of Justice AI Litigation Task Force and tied certain federal funding to the question — while expressly carving out state rules on child safety, AI compute and data-center infrastructure, and state government procurement. An executive order cannot repeal state law by itself, and companies should keep complying with state requirements. But it already has practical effect: the Task Force intervened in the litigation that led a federal court to block Colorado’s AI Act.

The absence of a single federal AI Act does not create a compliance vacuum. It creates a moving target.

United Kingdom, Israel and other markets

The United Kingdom has no general-purpose AI statute and relies on sector regulators and existing law — UK GDPR, the Equality Act, consumer law and industry-specific requirements — alongside targeted instruments such as the Automated Vehicles Act 2024. A private member’s AI regulation bill was debated in the Lords in June 2026 but has not become law. The substantive change for most businesses came through data protection: the automated decision-making rules described above.

Israel likewise has no horizontal AI statute equivalent to the EU AI Act, but privacy, cybersecurity, employment, consumer and contractual rules still apply — and the baseline moved recently. Amendment 13 to the Privacy Protection Law took effect in August 2025, bringing mandatory data protection officers in defined cases, a broader definition of sensitive data and statutory damages without proof of harm. The Privacy Protection Authority issued draft guidelines on applying the law to AI systems in December 2025, a guide for responsible AI use in the public sector followed in May 2026, and the government approved a national AI program in June 2026. Israeli companies serving international customers may in any case fall within EU or U.S. requirements through market access, data processing, contracts and procurement.

The global direction is clear: different jurisdictions use different legal mechanisms, but expectations around accountability, documentation, risk assessment and human oversight are converging.

Why compliance-by-design is cheaper than compliance retrofit

Compliance-by-design does not mean building a large bureaucracy before testing an idea. It means making basic risk decisions while the architecture is still flexible.

Interactive · By design, or by retrofit

Choose the moment you add controls — the same decisions cost differently once AI is load-bearing

COST & DISRUPTION →highlowDEPLOYMENT MATURITY →shape, not a measurement

Compliance-by-design is not a bureaucracy built before the first test. It is making basic risk decisions while the architecture is still flexible. The economic advantage is architectural reversibility — the same control is a decision at the start and a migration at the end.

  • 01 · Design

    Cheapest possible moment — these are decisions, not migrations.

    What adding controls takes here

    • Exclude unnecessary data
    • Select an appropriate vendor
    • Separate read and write permissions
    • Add audit logging
    • Create approval gates
    • Define prohibited actions
    • Build an appeal path
    • Version prompts and models
    • Choose a safer target variable
    • Stop a high-risk use case
  • 02 · Pilot

    Still cheap. Nothing downstream depends on the shape yet.

    What adding controls takes here

    • The same decisions as at design
    • Plus rework of what the pilot already wired up
  • 03 · In production

    Now it is a change program, not a decision.

    What adding controls takes here

    • Changing user journeys
    • Adding missing logs
    • Redesigning approval workflows
    • Renegotiating vendor contracts
  • 04 · Load-bearing

    Every fix now competes with revenue.

    What adding controls takes here

    • Replacing a model
    • Recollecting data
    • Rebuilding embeddings
    • Migrating customer records
    • Revalidating years of decisions
    • Temporarily disabling a revenue-critical feature

A company with an AI inventory, system owners, logs, version history and a kill switch can investigate and correct a problem. A company without them may not even know which system produced the disputed outcome.

The curve is a shape, not a measurement — it carries no units and is not derived from a cost study. The vertical axis is the cost and disruption of adding a control, which is why it has no scale. The figure expresses one claim: the number of dependencies you must unpick grows with deployment maturity.

The core economic advantage is architectural reversibility. A company with an AI inventory, system owners, logs, version history and a kill switch can investigate and correct problems. A company without those controls may not even know which system produced the disputed outcome.

A practical AI compliance framework for businesses

The following ten-step framework is appropriate for organizations that already use AI but do not yet have a mature governance program. Each step produces one artifact — together they are the evidence package.

Interactive · Ten-step framework

Each step produces one artifact — together they are the evidence package

Register → owners → intended use → risk class → data map → vendor matrix → validation report → oversight SOP → decision logs → incident playbook

A starting framework for organizations that already use AI without a mature governance program, not a certification scheme. The counter tracks what you have read, not what your organization has implemented.

Anatomy of the first artifact

Step 1 is where most programs stall, because “build an inventory” is abstract until you see one filled in.

Anatomy of one inventory entry

The fields that turn a list of tools into something you can actually govern

19 fields is not bureaucracy. It is the minimum needed to answer “what happened?” after something goes wrong.

System name · one row of an AI register

Support triage assistant

Vendor
Third-party LLM API provider
Model
Vendor model, version pinned; fallback model approved
Purpose
Classify inbound tickets and draft first responses
Business owner
Head of Customer Operations
Technical owner
Platform engineering lead
Risk / compliance owner
Data protection officer
Users
24 support agents
Data inputs
Ticket text, customer name, order history
Outputs
Category, priority, draft reply
Integrations
Helpdesk, CRM, order database (read-only)
Permissions
Read customer records; draft only; no sendmost often missing
Level of autonomy
Recommends; agent sendsmost often missing
Affected people
Customers awaiting support
Risk classification
Medium
Deployment status
In production since Q1
Retention
Prompts and outputs retained 90 days; no vendor trainingmost often missing
Jurisdictions
EU, UK, Israel
Assessment evidence
DPIA, accuracy test, oversight SOPmost often missing

4 fields most often missing

Permissions, level of autonomy, retention and assessment evidence are the entries organizations skip first — and the four an incident review, a regulator or a customer complaint will ask for. A register without them records that a system exists; it does not describe what the system is allowed to do.

A worked example, not a real client system. Field names follow the article’s inventory guidance; adapt them to your own register rather than adopting them literally.

The minimum evidence package

A company should be able to produce the following for important AI systems:

  • AI inventory entry
  • system card
  • intended-use statement
  • architecture diagram
  • data-flow map
  • vendor assessment
  • privacy or impact assessment
  • threat model
  • accuracy and bias tests
  • human-oversight design
  • release approval
  • logging specification
  • monitoring results
  • incident history
  • model-change history
  • employee training records
  • complaint and appeal process

This evidence is useful not only for regulators. It supports enterprise procurement, investor diligence, insurance, customer trust and faster incident response.

AI compliance is a growth capability, not only a legal defense

Poorly designed compliance slows companies down because every project becomes a custom legal debate. Well-designed governance creates reusable infrastructure:

  • one intake process
  • one risk-classification model
  • one vendor questionnaire
  • standard logging
  • standard approval patterns
  • standard evidence packages
  • clear escalation
  • defined prohibited actions

That can accelerate enterprise sales. Large customers increasingly ask AI vendors and service providers:

  • Which models do you use?
  • Is customer data used for training?
  • Where is data stored?
  • Can you explain decisions?
  • How do you test bias and accuracy?
  • What human oversight exists?
  • What happens when the model changes?
  • Can you produce logs?
  • How do you manage incidents?
  • Which subcontractors have access?

A company that can answer these questions with evidence appears more mature, more trustworthy and easier to buy from. That is the same bar we hold our own AI workflow automation builds to, and it is documented in our security and controls overview.

Final conclusion

AI compliance is not about making AI risk-free. No serious technology program can eliminate every error, bias or security event. The goal is to make AI visible, accountable, testable, reversible and governable.

The first step is not buying a large compliance platform or creating a committee with no operational authority. The first step is a focused AI inventory:

  • What systems exist?
  • Who owns them?
  • What data do they receive?
  • What decisions or actions can they influence?
  • Which use cases could materially affect people, money, rights or business continuity?
  • What evidence exists today?

From there, companies can prioritize the highest-impact systems, implement proportionate controls and build governance into future deployments. The companies that do this early will not merely reduce legal exposure. They will be better positioned to scale AI, pass enterprise procurement, investigate incidents and operate in regulated markets.

The real competitive advantage is not using more AI. It is being able to use AI without losing control.

Frequently asked questions about AI compliance

What is AI compliance?

AI compliance is the set of legal, technical and organizational controls used to ensure that AI systems are lawful, secure, fair, transparent and accountable. It typically includes AI inventory, risk classification, data governance, vendor review, testing, human oversight, logging, monitoring and incident response.

Why is AI compliance important in 2026?

AI use has become widespread while governance remains immature. Companies are deploying generative AI and AI agents across customer service, HR, CRM, reporting and internal operations. At the same time the EU AI Act is applying in phases, state-level U.S. rules are expanding and enterprise customers increasingly require AI-risk evidence.

Does the EU AI Act apply to companies outside Europe?

It can. The EU AI Act may apply to non-EU providers or deployers when they place AI systems on the EU market or when the system's output is used in the European Union. Companies should assess the specific role, system category, market and deployment context rather than relying only on corporate location.

What are the biggest AI compliance risks for businesses?

The most common risks include algorithmic discrimination, inaccurate or fabricated output, privacy violations, confidential-data leakage, prompt injection, excessive agent permissions, weak human oversight, inadequate logging, model drift and third-party vendor risk.

Can AI discriminate without using race or gender data?

Yes. AI can produce discriminatory outcomes through proxy variables such as ZIP code, language, education, employment gaps, spending patterns, location or historical salary. Companies should test outcomes and error rates across relevant groups instead of checking only whether protected attributes are present in the dataset.

Is human-in-the-loop enough for AI compliance?

Not automatically. Human review must be meaningful. The reviewer should understand the recommendation, have access to relevant evidence, possess enough time and competence, and have real authority to reject or override the AI. A routine approval click may be treated as rubber-stamping rather than genuine human oversight.

Who is responsible when a third-party AI tool makes a mistake?

Responsibility is usually shared. The vendor may be responsible for parts of the model or service, but the deploying company remains responsible for its business purpose, data, integrations, user communications, permissions and downstream decisions. Using a well-known provider does not eliminate the need for internal testing and governance.

What is shadow AI?

Shadow AI is the use of AI tools, models, agents or AI-enabled software outside an organization's approved procurement, security, privacy and governance processes. Examples include employees using personal AI accounts, unapproved browser extensions or hidden AI features inside SaaS products.

What should an AI inventory include?

An AI inventory should include the system name, vendor, model, purpose, owner, users, data inputs, outputs, integrations, permissions, level of autonomy, affected people, risk classification, deployment status, retention settings, jurisdictions and links to relevant assessments and test evidence.

What is the fastest way to start an AI compliance program?

Start with a limited inventory of the AI systems that can materially affect people, money, rights, confidential data or business continuity. Assign owners, classify risk, map data and permissions, identify missing controls and prioritize two or three high-impact systems for deeper assessment.

Next step

Do you know where AI is operating inside your business?

Start with a focused AI inventory and risk assessment. Identify the systems, owners, data, permissions and high-impact decisions that require stronger controls before they become expensive to change.

Where this connects

Primary sources & further reading

This article is an operating-model overview, not legal advice or certification guidance. Regulatory dates, enforcement powers and published statistics change; the page is reviewed against the primary sources above. Last fact-checked 31 July 2026.

Not sure what to automate first? Ask me.