AI compliance is meeting the legal, regulatory, and standards-based requirements that apply to an organisation's AI systems. In 2026 that spans binding law (the EU AI Act, GDPR, sector rules like NYC Local Law 144 and the revised Colorado AI Act), sector-specific supervisory expectations (APRA, FCA, MAS, the US Federal Reserve's SR 26-2), and voluntary standards organisations adopt to demonstrate due diligence (ISO/IEC 42001, NIST AI RMF). Compliance is distinct from governance: compliance is meeting external requirements; governance is the broader management capability that includes, but goes beyond, legal compliance.
Run the free AI Health CheckAI Compliance, the activity of meeting legal, regulatory, and contractual obligations that apply to the development, deployment, and use of artificial intelligence systems.
AI compliance is a subset of AI governance. It focuses on identifiable obligations: the EU AI Act, GDPR Article 22, state-level US laws (Colorado AI Act, NYC Local Law 144), sector regulators (APRA, FCA, MAS), and emerging Australian Privacy Act ADM provisions. Compliance teams work from a register of applicable obligations; governance addresses the broader question of how the organisation chooses to use AI even where no specific law applies.
Source: EU AI Act; GDPR; sector regulator guidance
Gartner projects that by 2030, fragmented AI regulation will quadruple and extend to 75% of the world's economies, driving spend on AI-governance platforms toward USD 1 billion. Separately, Gartner has also predicted that AI-related regulatory violations will drive a 30% increase in legal disputes for technology companies by 2028. Both trends point the same direction: more jurisdictions, more rules, and more enforcement activity, not less.
Even enacted regulations keep changing. The EU AI Act entered into force in August 2024, but its Digital Omnibus, finally adopted by the Council on 29 June 2026, postponed standalone high-risk (Annex III) obligations from 2 August 2026 to 2 December 2027, and product-embedded high-risk obligations to 2 August 2028, while leaving the Article 50 transparency duties (chatbot disclosure, deepfake labelling) on their original 2 August 2026 date. The Colorado AI Act has been delayed and rewritten twice since its 2024 enactment, most recently via SB 26-189 (signed May 2026), which pushed its effective date to 1 January 2027 and narrowed its scope considerably. Compliance programs built to track a single fixed rulebook will not survive contact with 2026's regulatory pace; they need to track change, not just requirements.
| Regime | Status | Origin | Scope |
|---|---|---|---|
| EU AI Act | Binding | European Union | Risk-tiered obligations; applies extraterritorially to any provider/deployer whose AI output is used in the EU. |
| NIST AI RMF | Voluntary | United States | Four-function framework (Govern, Map, Measure, Manage); referenced in US federal procurement. |
| ISO/IEC 42001:2023 | Voluntary, certifiable | International | AI management system standard; independently auditable for third-party assurance. |
| GDPR Article 22 | Binding | European Union | Restricts solely-automated decisions with legal or similarly significant effects; requires human-intervention rights. |
| NYC Local Law 144 | Binding | New York City | Annual independent bias audits for automated employment decision tools, plus candidate notice. |
| Colorado AI Act (SB26-189) | Binding from 1 Jan 2027 | Colorado, US | Regulates automated decision-making technology in consequential decisions; substantially narrowed from the original 2024 Act. |
NYC Local Law 144 enforcement has itself been under scrutiny: a December 2025 New York State Comptroller audit found the Department of Consumer and Worker Protection's enforcement to date "ineffective", with employment counsel expecting a stricter enforcement phase to follow rather than assuming the current light-touch pattern continues.
What is AI compliance?
AI compliance is the ongoing practice of ensuring an organisation's AI systems meet applicable laws, regulations, and standards throughout the AI lifecycle, from design and training through deployment and monitoring. It combines binding legal obligations (the EU AI Act, GDPR) with voluntary frameworks (NIST AI RMF, ISO/IEC 42001) that regulators and customers increasingly expect as evidence of due diligence.
What is the difference between AI compliance and AI governance?
AI compliance is meeting the minimum legal obligations that apply to your AI use. AI governance is the broader management capability, covering accountability, oversight, risk management, controls, and reporting, that lets an organisation deploy AI at scale without losing control of it. Compliance is one output of good governance, not a substitute for it: an organisation can be compliant today and still exposed to AI failures regulation has not yet caught up with.
Is there a single global AI law companies must comply with?
No. The EU AI Act is the most comprehensive binding regime and applies extraterritorially to providers and deployers whose AI output is used in the EU. The US has no comprehensive federal AI statute; it relies on sector-specific enforcement, executive orders, and a patchwork of state laws such as Colorado's revised automated-decision law (effective January 2027). The OECD AI Principles and NIST AI RMF are voluntary, non-binding frameworks used internationally.
Does ISO 42001 certification or following the NIST AI RMF make an organisation legally compliant?
Not automatically. Both are voluntary management-system frameworks, not law. They demonstrate structured governance and support, but do not substitute for, compliance with binding regimes like the EU AI Act. No AI-management-system standard has yet been cited in the EU Official Journal as a harmonised standard carrying a legal presumption of conformity, so certification alone does not currently guarantee EU AI Act conformity.
What is the first practical step in building an AI compliance program?
Building and maintaining a complete AI system inventory, cataloguing what AI is used or built, by whom, on what data, and for what purpose, is the necessary first step, since regulatory mapping, risk classification, and gap assessment all depend on knowing what exists. The US federal government follows the same practice: OMB has required agencies to inventory their AI use cases at least annually since 2024.
What happens if a company does not comply with the EU AI Act?
Penalties are tiered by violation severity: up to €35 million or 7% of total worldwide annual turnover, whichever is higher, for prohibited AI practices; up to €15 million or 3% for other high-risk-system violations; and up to €7.5 million or 1% for supplying incorrect or misleading information to authorities. The 7% ceiling exceeds GDPR's 4% maximum.
Last reviewed July 2026