Regulatory feed
A continuously curated record of every AI rulebook in motion. Filter by jurisdiction; subscribe per-framework to receive Trust Inbox alerts.
EnforcementEU AI Act — core obligations Article 9–17
2026-08-02High-risk system requirements take effect for new placements. Penalties reach €35M or 7% of global turnover. Notified bodies begin conformity assessments. Existing high-risk systems must complete conformity by end of 2026. EU 2024/1689 Art 9–17
ActiveEU AI Act — GPAI obligations
in effect 2026-08-02 phasedGeneral-purpose AI model providers must publish technical documentation, training-data summaries, copyright policies. For systemic-risk GPAI (>10²⁵ FLOPs): mandatory model evaluations, adversarial testing, incident reporting. Art 51–55
StandardISO/IEC 42001:2023 — AI Management System
Q3 2026 audit windowAIMS certification scheme mature; first wave of accredited audits opening. Agentics maps oversight log → 8.x, risk register → 6.x, evidence pack → 9.x. Issued certificates become a procurement signal.
StandardNIST AI RMF + GenAI Profile
rollingGovern / Map / Measure / Manage. GenAI profile (AI 600-1) extends the core with synthetic-content provenance, prompt-injection defense, hallucination governance. Aligns with the EU AI Act on high-risk requirements.
In motionUK AI Regulation Bill
committee stageSector-led approach via CMA, FCA, ICO, MHRA, Ofcom + a central AI Authority. AI Safety Institute keeps testing flagship models. Lighter-touch than the EU AI Act on horizontal duties.
WatchUS — OMB M-24-10 + state AI bills
rollingFederal agencies subject to OMB AI memo: chief AI officers, public inventories, impact assessments. Watch state-level: CA SB 1047 successor, CO SB 24-205, IL HB 5116, NYC Local Law 144. Sectoral guidance from FDA, EEOC, CFPB.
StandardSOC 2 Type II
continuousTrust Service Criteria CC / A / C / PI / P. Agentics aligns CC-series controls automatically from audit logs. Inherits AI-specific controls via the ISO 42001 mapping.
InsuranceISO 8000-9 series · Coalition + Munich Re AI carve-outs
Jan 2026+ISO published three GenAI insurance carve-outs early 2026. Coalition added explicit affirmative AI coverage. Klaimee writing first AI-agent liability policies. Higher trust posture → lower premium. Get an insurance check →
PrivacyGDPR / UK GDPR / CCPA / Quebec L25
in forceDPIA required for systematic large-scale processing. Automated-decision-making rights (Article 22). DSAR workflows must capture AI-derived inferences. CCPA: opt-out of "automated decision-making technology" coming via APRA-style rules.