web analytics
Reference Library

AI Governance

The one-paragraph answer

AI governance is the discipline of running artificial intelligence in a way you can defend to a board, a buyer, an insurer, a regulator, or a court. It is not one law. It is fifteen overlapping frameworks, standards, and rules that all point at the same question: “Do you have an AI management system?” This library answers that question one framework at a time, in plain English, checked against the primary sources rather than against other people's summaries. Where a law has been repealed or a standard superseded, we say so on the page rather than quietly deleting it.

The line-by-line mapping between these frameworks and SRJ's operating artifacts is Appendix L of The AI Risk & Governance Review, Volume III of The Operating Discipline for AI Library.

What changed

Reviewed 14 July 2026

This library is reviewed against primary sources, not secondary summaries. Seven changes since the last pass are material enough that a compliance roadmap built on the old position is now aimed at the wrong target.

  • Repealed The Colorado AI Act is gone. SB 24-205 was repealed by SB 26-189 on 14 May 2026 and never took effect. The duty of care, the impact assessments, and the rebuttable presumption for NIST AI RMF alignment are all removed. A narrower disclosure regime takes effect 1 January 2027. Read what replaced it.
  • Superseded SR 11-7 is no longer the model risk standard. On 17 April 2026 the Federal Reserve, OCC, and FDIC issued revised interagency guidance (SR 26-2 and OCC Bulletin 2026-13), rescinding OCC Bulletin 2011-12. The new guidance is explicitly non-enforceable, states relevance above $30bn in assets, and narrows the definition of a model to complex methods. Read what changed.
  • Now final The EU AI Act Digital Omnibus was adopted. The Council gave final approval on 29 June 2026. Annex III high-risk obligations move to 2 December 2027, embedded-product high-risk to 2 August 2028. Article 50 transparency still applies from 2 August 2026. A new Article 5 prohibition on AI-generated intimate imagery starts 2 December 2026. Read the revised timeline.
  • Deadline Your AI becomes a product on 9 December 2026. The revised EU Product Liability Directive makes software and AI systems strictly liable products. And AI Act non-compliance creates a presumption that your product was defective. The Digital Omnibus deferred the AI Act's obligations to 2027 and 2028. It did not move this deadline. Read what changes in December.
  • New pages NIS2 and DORA now covered. The EU stack is complete: the AI Act, the Cyber Resilience Act, Product Liability, NIS2 (where directors can be personally banned from management), and DORA (which reaches AI vendors through their financial-services customers).
  • Correction “High-risk AI” does not mean an external audit. EU AI Act Article 43(2) routes Annex III points 2 to 8, which is critical infrastructure, education, employment, credit scoring, law enforcement, migration, and justice, to self-assessment under Annex VI, expressly without a notified body. A notified body is required only for biometrics, and only where the harmonised standards are not fully applied. Most published guidance implies otherwise. Read which route applies to you.
  • New page The EU Cyber Resilience Act is now covered. Its reporting duty bites on 11 September 2026 and reaches products already on the market. Its Article 12 route to deemed compliance with EU AI Act Article 15 covers the cybersecurity limb only: accuracy and robustness remain live and must be evidenced independently. Almost every summary of that provision drops the opening clause. Read the Article 12 trap.
  • New Three NIST efforts are frequently confused. The Cyber AI Profile (NIST IR 8596), COSAiS (SP 800-53 control overlays), and the AI RMF Critical Infrastructure Profile are different documents doing different jobs. Read how they fit together. The House Science Committee also advanced ten AI bills on 25 June 2026; four matter, and none is law.

ISO/IEC 42001

The AI Management System Standard

ISO/IEC 22989

AI Vocabulary Standard

NIST AI Risk Management Framework

Govern, Map, Measure, Manage

EU AI Act

The World's First Comprehensive AI Law

EU Cyber Resilience Act

Regulation (EU) 2024/2847, and the Article 12 Trap

EU Product Liability Directive

Directive (EU) 2024/2853. Your AI Is Now a Product.

NIS2 Directive

Directive (EU) 2022/2555. Where Directors Can Be Banned.

DORA

Digital Operational Resilience Act, Regulation (EU) 2022/2554

NYDFS Part 500

23 NYCRR Part 500, the Two AI Letters, and the CEO and CISO Certification

Federal Contractor AI

CMMC Phase II Suspended, DFARS Still Binds, and the Assurance Doom Loop

State Privacy Laws

The Profiling Right That Governs AI Without Using the Word

CETS 225

The Council of Europe Framework Convention on AI, Human Rights, Democracy and the Rule of Law

China AI Regulation

The Intelligent Agent Framework, the Companion-AI Rules, and the Stack Underneath

Global AI Laws

Ten Jurisdictions Beyond the EU, the US, and China

Federal AI Legislation

Pending U.S. AI Bills and the Great American AI Act

SR 11-7 and the 2026 Model Risk Guidance

Superseded April 2026 by SR 26-2 and OCC 2026-13

Director Oversight

The Caremark Line of Cases

Vendor Disclosure

Software Bill of Materials and AI Bill of Materials

AI Tools

The Reference Catalog Behind an AI Tool Inventory

Sources & References

The Complete Bibliography of the AI Governance Reference Library

Ready to see where you stand?

The AI Business Enablement Audit™ measures your organization against every framework in this library and delivers a defensible governance dossier. Start or finish your audit below.

Start or finish your AI Audit →
Schedule a Free AI Consultation