AI Governance Institute

AI Governance Compliance

What AI governance compliance actually requires: which obligations apply, what evidence regulators and auditors expect to see, and how compliance fits inside a broader governance program rather than standing in for one.

Compliance is the evidence layer, not the whole program

AI governance compliance means demonstrating, with evidence, that an organization meets its applicable legal and regulatory obligations for AI systems. It is necessary but not sufficient: a program built solely to satisfy the minimum requirements of applicable regulations will have unmanaged risk in every system and context those regulations don't reach. Compliance is what a governance framework produces as a byproduct of actually managing AI risk, not a checklist run in parallel to it.

Which obligations apply

Most organizations face overlapping obligations from multiple sources at once, not a single AI law.

EU AI Act: Binding, risk-tiered obligations for any organization whose AI systems reach EU users, regardless of where the company is based.
State-level US law: Colorado's AI Act, Illinois' BIPA, NYC Local Law 144, and a growing list of state statutes create a patchwork of obligations that varies by sector and geography.
NIST AI RMF: The de facto US voluntary standard, increasingly referenced in procurement requirements and regulatory guidance even where it isn't mandatory.
ISO/IEC 42001:2023: The only certifiable AI management standard, useful for demonstrating compliance posture across multiple jurisdictions at once.

Determining which of these apply to a given system is itself a discipline, multi-jurisdiction compliance mapping, since a single AI system can be subject to different rules depending on where its users are located, what sector it operates in, and what kind of decisions it makes.

What evidence auditors and regulators expect

Compliance claims are only as strong as the evidence behind them. Five artifacts come up in nearly every regulatory inquiry or audit.

AI system inventory and risk classification: A current, owned list of every AI system in use, each assigned a risk tier. It is the first thing a regulator or auditor will ask for.
Documented risk assessments: Evidence that each system was evaluated for bias, reliability, security, and privacy risk before and after deployment.
Audit-ready documentation: Records of approvals, model changes, and monitoring results, accessible, dated, and tied to a named owner.
Human oversight evidence: Proof that human review checkpoints are technically enforced, not just described in a policy document.
Vendor and third-party AI due diligence: Documentation that AI capabilities embedded in vendor tools were identified and assessed, not discovered after an incident.

Where compliance programs fail

Most compliance programs already have policy. What they lack is evidence. Organizations write acceptable-use policies and risk frameworks, then can't produce the underlying records when a regulator or plaintiff's counsel asks for them. Real incidents bear this out: a pre-production approval gate that exists on paper but wasn't enforced produced a full system rollback, and a human review checkpoint that could be technically bypassed let an automated enforcement bug reach thousands of users before anyone caught it. Compliance evidence has to describe controls that are actually enforced in the system, not controls that exist only in a policy document.

Compliance is a moving target

AI regulation is still being written. New regulations and enforcement actions arrive weekly, and a compliance posture that was defensible six months ago may have gaps today. Effective programs treat regulatory monitoring as an ongoing function, not a one-time gap assessment, and revisit their control set whenever a new enforcement action or standard changes what "adequate" looks like in practice.

A minimal AI compliance policy template

A compliance policy for AI needs to answer five questions in writing. This is a starting skeleton, not a substitute for legal review.

  1. Applicable obligations: which regulations apply to which systems, by jurisdiction and use case?
  2. Required evidence: what documentation must exist before a system reaches production?
  3. Review and approval: who signs off before deployment, and what triggers re-review?
  4. Monitoring obligations: what ongoing evidence must be retained after deployment?
  5. Escalation: who is notified, and within what timeframe, if a system fails to meet a compliance requirement?

Every answer needs a named owner and a way to verify it happened, not just a description of intent. See how to audit whether a compliance control is actually enforced.

Find out which obligations apply to you

Use the AI Governance Institute self-assessment to identify which regulations apply to your organization, what evidence you're missing, and where your compliance posture has gaps.

Start the self-assessment →