What’s New in AI Compliance: September 2026 Primer
This at-a-glance guide maps the standards, what changed in each during 2026, the industries they touch most, and the controls that keep a program ahead of them. Published September 2026.
Executive Overview
The AI compliance calendar has been rewritten over the past year. The EU deferred its high-risk deadlines, Colorado replaced its AI law, and the federal government began pressing to preempt state rules. Enforcement moved the other way: the European Commission’s powers over general-purpose AI providers took effect in August 2026, Texas has been in force since January, and the data rules (GDPR, HIPAA, CCPA/CPRA, PCI DSS) never moved at all.
Deadline tracking alone cannot keep a program ready, because the first ask rarely comes from a regulator. Auditors want an ISO/IEC 42001 scope and Statement of Applicability that cover the AI already in use. Examiners want evidence of AI activity. Boards want to see what is controlled. Counsel wants the records a legal defense turns on. Traditional security tools were built around destinations and data patterns, and the evidence these parties ask for lives inside the AI interaction instead.
Aurascape produces that evidence continuously. It discovers the AI in the environment, including embedded AI features and agents, classifies sensitive data in motion, enforces policy inline, and preserves conversation-level records of governed interactions. For agent tool calls, the Zero-Bypass MCP Gateway inspects and controls each call within the governed architecture, so agent activity produces the same kind of records as AI use by people.
The guide covers five instruments (the EU AI Act, NIST AI RMF, ISO/IEC 42001, the US state laws, and the data rules), what changed in each during 2026 and who it touches most, a timeline of the dates that matter through 2028, the steps to take today for each instrument, a six-control checklist, and a mapping of what Aurascape produces for each instrument. Read it alongside the companion blog for the full analysis of the year’s regulatory shifts.
Aurascape Solutions
- Discover and monitor AI Get a clear picture of all AI activity.
- Safeguard AI use Secure data and compliancy in AI usage.
- Secure Agentic AI Secure how your teams use AI and build AI agents.
- Copilot readiness Prepare for and monitor AI Copilot use.
- Coding assistant guardrails Accelerate development, safely.
- Frictionless AI security Keep users and admins moving.
- AI Governance & Compliance Move from AI policy to enforceable governance.