AI Compliance Frameworks: What’s New and What Matters
The AI compliance calendar was rewritten this year. Deadlines slipped, enforcement began, and one requirement stayed constant: evidence. These are the four records worth building either way.
Mark McLaughlin, Product Marketing Manager | Aurascape
September 10th, 2026 | 🕐 5 minute read
Introduction
The AI compliance calendar has been rewritten over the past nine months. The EU pushed its high-risk obligations back more than a year. Colorado overhauled its AI law. The federal government built a task force to challenge state AI statutes in court. It’s hard to keep track of all the changes.
Here is what changed, what did not, and the four records worth building either way.
Prefer a short PDF primer version? Read it here.
What changed
Three shifts stand out:
- The EU AI Act’s high-risk deadlines are officially deferred: The Digital Omnibus package was adopted at the end of June (Council final approval, June 29), signed July 8, and in force from July 27, 2026. Standalone high-risk AI obligations now apply from December 2, 2027. High-risk AI embedded in regulated products gets until August 2, 2028. These dates are law now, not proposals.
- Colorado replaced its AI act: A federal court stayed enforcement of the original Colorado AI Act in April, and the state enacted a narrower replacement, SB 26-189, effective January 1, 2027. The replacement drops the risk-management programs and annual impact assessments the original required. The attorney general has said they will not enforce the replacement until rulemaking finishes.
- The federal government turned against state AI laws: A December 2025 executive order set preemption efforts in motion. A Department of Justice task force to challenge state AI statutes followed in January, the White House released a national AI legislative framework in March, and on July 1 the FTC proposed a policy statement treating some state-mandated changes to AI outputs as deceptive. Congress has declined to pass preemption twice. The state laws stand, now with a federal effort working to unwind them.
It is tempting to wait for the churn to settle before building the compliance program. Build it anyway: the evidence these laws ask for barely changes between versions, and it only accumulates from the day you start collecting it.
What took effect
Four things became effective as planned:
- EU enforcement went live: On August 2, 2026, the European Commission’s enforcement powers over general-purpose AI providers took effect. The Commission can now demand documentation, run technical evaluations, restrict a model from the EU market, and issue fines up to 15 million euros or 3% of global turnover, whichever is higher. That enforcement reaches the model providers rather than the enterprises deploying their models, unless the enterprise is itself a provider. It still matters to your program because your deployer obligations under the Act were deferred, not erased. The Act’s transparency obligations began applying in August 2026, and some touch deployers of specific system types directly; systems already on the market before August 2 have a grace period to December 2, 2026, for the provider-side content-marking duty.
- Texas is in force: The Texas Responsible Artificial Intelligence Governance Act took effect January 1, 2026. Its prohibitions are narrow and it allows a 60-day cure period, but penalties scale from roughly $10,000 for an uncured curable violation to $200,000 for an uncurable one, with separate daily penalties for continuing violations. It also gives a voluntary framework legal weight: a defense is available when a violation is caught through channels such as internal review backed by substantial compliance with NIST’s Generative AI Profile of the AI Risk Management Framework (AI RMF) or another recognized framework.
- New York kept legislating: The RAISE Act, enacted in December 2025 days after the preemption order, overhauled by amendment in March, and effective January 1, 2027, targets frontier model developers rather than the enterprises deploying their models. It will not bind most enterprise programs directly. It does show states are still legislating while Washington litigates.
- The data rules never moved: GDPR, HIPAA, CCPA/CPRA, and PCI DSS each keep governing their own regulated data when it moves into an AI prompt. A clinician at a covered entity summarizing patient notes in an AI tool is a HIPAA question. A developer moving cardholder data through a coding assistant is a PCI DSS question. None of this waited for an AI law, and none of it got deferred. That risk is immediate, because the data was already regulated and AI gave it a new way to move.
The first ask will not come from a regulator
Long before December 2027, four other parties can ask you to prove your AI program works:
| Who arrives | What they ask for |
|---|---|
| Your auditor | ISO/IEC 42001 certification starts with scope: which AI systems the management system covers. Its Statement of Applicability then declares which controls apply and why. Unknown AI use inside that scope undermines both. |
| Your examiner | Evidence of AI activity behind the program: which tools are in use, at what risk, with what data exposure. |
| Your board | The evidence view of AI governance: what is in use, what is controlled, and what an examiner could review. Walking in with records makes it a short conversation. |
| Your laywer | The Texas defense turns on evidence: internal review that catches issues, backed by substantial compliance with NIST’s Generative AI Profile. The time to start producing it is before anyone asks. |
This is already happening for regulated organizations. The Police Credit Union prepared for NCUA examination expectations around AI by mapping its controls to applicable requirements and guidance: GLBA, FFIEC guidance, Reg P, NCUA Part 748, and the NIST AI RMF. That preparation ran on evidence of AI activity: which tools were in use, at what risk, with what data exposure.
Auditors, examiners, boards, and counsel arrive earlier, and they arrive asking for records. If your AI security program stands up to inquiries from these four parties, there’s a solid chance you will be prepared by the time deadlines arrive.
Four proofs that hold up across frameworks
Look past the acronyms for a second, and the same evidence keeps being asked for across NIST AI RMF, ISO/IEC 42001, the EU AI Act, the state statutes, and the data regimes. Four proofs put a program in a defensible position for each:
- An inventory of the AI in use: Not the approved list. The real one, including the AI features that switched on inside sanctioned SaaS apps and the tools nobody registered.
- Control over regulated data at the interaction: The ability to detect regulated data moving toward an AI tool and apply policy before it lands there.
- Records of AI activity: Interaction-level records: what was asked, what came back, what data was involved, which policy decision fired. Producible on demand.
- Accountable oversight: Named owners, documented decisions, and a way for the people who hold the obligation to reach the evidence themselves.
The processes behind these proofs are still uneven. The World Economic Forum’s 2026 Global Cybersecurity Outlook found that 40% of surveyed organizations review AI tools periodically before deployment, 24% review only once, and roughly one-third still lack any process to validate AI security before deployment.
The deadlines moving may matter less than it seems. When a legislative date moves, these four proofs still stand, and an organization that can produce them has its foundation in place whenever the deadlines do kick in.
The blind spot the frameworks share: Agents
The statutes also trail the technology, and nowhere more than with agents.
The major frameworks center on human accountability, and the EU AI Act requires human oversight for high-risk systems. What none of them yet prescribes are detailed controls for tool-using agents acting with delegated authority. Agents act through tool calls: machine-to-machine requests, including over the Model Context Protocol (MCP), that read data and take actions in external systems. Much of that work completes with no human reviewing it in the moment.
One of the first governance frameworks written specifically for agents, from Singapore’s Infocomm Media Development Authority, arrived in January 2026 and was updated in May. It is voluntary, and it is one framework in one jurisdiction. Others are moving: NIST launched an AI Agent Standards Initiative in February, and the UK has published agentic-AI security guidance, but none of it binds anyone yet. Until the frameworks catch up, the reliable place to control agent activity is your own architecture: layered controls, with an enforcement point in the path of the tool call itself, able to produce the same four proofs for agents that you produce for AI use by people.
Where Aurascape fits
Aurascape is built to produce these proofs continuously, so you always have them at hand.
| The proof | How Aurascape produces it |
|---|---|
| AI inventory | Discovers the AI in your environment, including embedded AI features inside SaaS apps and AI agents. |
| Data control at the interaction | Classifies sensitive data in motion and enforces policy inline, from coaching a user to redacting or blocking a request, before regulated data reaches the AI tool. |
| Records of AI activity | Dcodes the entire AI interaction and preserves conversation-level records of governed interactions: what was asked, what was returned, and which policy fired. |
| Accountable oversight | Keeps that evidence reachable by the compliance and legal people who own the obligation, through role-based access. |
For agent tool calls, the Zero-Bypass MCP Gateway inspects and controls each call within the governed architecture, producing the same kind of records for agents as for AI use by people.
No platform makes an organization compliant. Compliance is a legal and organizational determination. What the platform does is run the controls and keep the records your compliance and legal teams use to show the program is real.
The world of AI compliance is moving quickly, and it can be hard to keep track of all the changes. Build the AI governance program that produces evidence every day, so you are prepared. Book a demo to see how Aurascape discovers AI activity, applies policy, and gives you the records to demonstrate governance.
Aurascape Solutions
- Discover and monitor AI Get a clear picture of all AI activity.
- Safeguard AI use Secure data and compliancy in AI usage.
- Secure Agentic AI Secure how your teams use AI and build AI agents.
- Copilot readiness Prepare for and monitor AI Copilot use.
- Coding assistant guardrails Accelerate development, safely.
- Frictionless AI security Keep users and admins moving.
- AI Governance & Compliance Move from AI policy to enforceable governance.