What Regulators Are Starting to Expect from AI Governance Programs

AI governance is moving from voluntary principles to regulatory requirements. Explore what regulators increasingly expect, including data governance, risk management, transparency, monitoring, and demonstrable evidence.

What Regulators Are Starting to Expect from AI Governance ProgramsAbstract gradient background blending blue and purple shades with a subtle textured pattern.
Published on
September 18, 2026
Colorful geometric digital background with blue, pink, purple, yellow shapes and a neon grid pattern.
Event Date:
Hosted By:
Register Now

For most of the past few years, AI governance has been shaped more by principle than by requirement. Organizations wrote responsible-AI charters, stood up ethics committees, and drafted policies, largely on their own terms and at their own pace. That era is ending. Concrete regulatory obligations are now arriving, and with them a shift from what organizations think good AI governance should look like to what regulators are prepared to require and enforce. For risk, legal and compliance leaders, the useful question is no longer whether AI governance will be regulated, but what specifically regulators are beginning to expect and how much of it an organization can actually demonstrate today.

The regulatory picture is still forming and varies by jurisdiction, so this isn't a compliance checklist, and none of what follows is legal advice. But across the frameworks taking shape, a consistent set of expectations is emerging. Reading them together is more instructive than tracking any single law, because the common threads reveal what organizations will need to be able to do regardless of which specific regime applies to them.


The Regulatory Landscape Is Moving From Principles to Obligations

The clearest marker of the shift is the EU AI Act, whose obligations are now phasing in on a defined timeline. Transparency duties and the AI Office's oversight of general-purpose AI providers took effect in August 2026, while the more demanding obligations for high-risk AI systems covering uses such as hiring, credit scoring and critical infrastructure phase in over the following period, with major deadlines in late 2027 and 2028. For high-risk systems, the Act contemplates specific requirements including risk management, data governance, logging, human oversight and conformity assessment. Whatever an organization's exposure to the EU regime specifically, it is the most detailed signal available of the direction regulation is heading.

The United States presents a more fragmented but no less consequential picture, driven substantially at the state level. Colorado, for example, enacted and then revised a law addressing AI used in consequential decisions; in its amended form it was signed in May 2026 and is set to take effect in 2027, with enforcement centralized under the state attorney general following rulemaking. Other states are advancing their own measures. The details differ, and timelines continue to move, but the trajectory is unmistakable: obligations attaching specifically to AI systems that make or shape consequential decisions about people. Organizations waiting for a single, settled national standard before acting are likely to find the ground has moved underneath them several times over.

Running alongside the laws are frameworks that increasingly function as the recognized standard of care, notably the NIST AI Risk Management Framework and the ISO/IEC 42001 management-system standard. These aren't statutes, but they're becoming the reference points regulators and courts look to for what reasonable AI governance looks like, and alignment with them is increasingly treated as evidence of diligence. Together, the binding laws and the voluntary frameworks are converging on a similar set of expectations.


The Common Thread: Demonstrable Control

Beneath the specifics, what regulators consistently want is the same thing: the ability to demonstrate control. It is not enough to assert that AI is governed responsibly; organizations are increasingly expected to show it with documentation, evidence and records that stand up to outside scrutiny. This is the throughline connecting otherwise different regimes, and it is where most AI governance programs are least prepared, because demonstrability is far harder than intention.

Several specific expectations recur across frameworks. Regulators expect organizations to know where and how AI is used an accurate inventory of AI systems, not a vague sense that AI is 'in use somewhere.' They expect governance of the data feeding those systems: what it is, where it came from, whether it's accurate, and whether it contains personal or sensitive information that carries its own obligations. They expect risk assessment before deployment, human oversight of consequential decisions, transparency to affected individuals, and monitoring once systems are live. And underlying all of it, they expect records sufficient to prove each of these was actually done.


Why Data Governance Sits at the Center of AI Compliance

A pattern worth drawing out for legal and compliance leaders is how much of what regulators expect ultimately reduces to data. Risk management for an AI system depends on understanding the data it consumes. Transparency about how a decision was made requires knowing what data informed it. Honoring individual rights requires locating a person's data across the systems AI touches. Data governance obligations appear explicitly in the high-risk provisions taking shape, and implicitly nearly everywhere else. An organization that cannot answer basic questions about the data feeding its AI cannot satisfy most of what regulators are beginning to require, however strong its policies look on paper.

This is why treating AI governance as primarily a policy or model-documentation exercise leaves organizations exposed. The obligations that are hardest to meet and most likely to be tested concern the data layer: proving what data a system used, that its use was appropriate, that sensitive information was handled correctly, and that this can be shown across systems that change continuously. Organizations with mature data governance are positioned to demonstrate these things. Those without it face requirements they have no foundation to satisfy.


Preparing for What's Coming

For risk, legal and compliance leaders, the reasonable posture is neither to wait for full regulatory certainty nor to chase every emerging rule individually, but to build toward the common expectations that nearly all of them share. That starts with knowing where AI is used and what data each system consumes, and extends to being able to demonstrate with evidence, not assertion that the data feeding AI is governed, that sensitive information is accounted for, and that issues are detected and resolved on an ongoing basis. Because both the data and the AI landscape change continuously, and because regulators increasingly expect ongoing rather than point-in-time control, this has to be a continuous capability rather than a one-time assessment.

The organizations best positioned for the regulatory environment now taking shape won't be the ones with the most elaborate AI ethics statements. They'll be the ones that can answer, with evidence, what data their AI systems use and whether that use is defensible because that is the question, in one form or another, that regulators across jurisdictions are converging on. AI governance is moving from something organizations describe to something they must prove, and proof rests on the data.

Data Sentinel helps organizations build the demonstrable, data-level foundation that emerging AI regulation increasingly requires continuously discovering, classifying and monitoring the data that feeds AI inside their own environment, and combining technology with managed services so risk, legal and compliance teams can show what data their AI uses, whether it belongs there, and how issues are resolved. Learn more about how we help organizations prepare for what regulators are starting to expect.

arrow icon
September 18, 2026

What Regulators Are Starting to Expect from AI Governance Programs

AI governance is moving from voluntary principles to regulatory requirements. Explore what regulators increasingly expect, including data governance, risk management, transparency, monitoring, and demonstrable evidence.

play icon
Date:
Hosted By:
Register Now

For most of the past few years, AI governance has been shaped more by principle than by requirement. Organizations wrote responsible-AI charters, stood up ethics committees, and drafted policies, largely on their own terms and at their own pace. That era is ending. Concrete regulatory obligations are now arriving, and with them a shift from what organizations think good AI governance should look like to what regulators are prepared to require and enforce. For risk, legal and compliance leaders, the useful question is no longer whether AI governance will be regulated, but what specifically regulators are beginning to expect and how much of it an organization can actually demonstrate today.

The regulatory picture is still forming and varies by jurisdiction, so this isn't a compliance checklist, and none of what follows is legal advice. But across the frameworks taking shape, a consistent set of expectations is emerging. Reading them together is more instructive than tracking any single law, because the common threads reveal what organizations will need to be able to do regardless of which specific regime applies to them.


The Regulatory Landscape Is Moving From Principles to Obligations

The clearest marker of the shift is the EU AI Act, whose obligations are now phasing in on a defined timeline. Transparency duties and the AI Office's oversight of general-purpose AI providers took effect in August 2026, while the more demanding obligations for high-risk AI systems covering uses such as hiring, credit scoring and critical infrastructure phase in over the following period, with major deadlines in late 2027 and 2028. For high-risk systems, the Act contemplates specific requirements including risk management, data governance, logging, human oversight and conformity assessment. Whatever an organization's exposure to the EU regime specifically, it is the most detailed signal available of the direction regulation is heading.

The United States presents a more fragmented but no less consequential picture, driven substantially at the state level. Colorado, for example, enacted and then revised a law addressing AI used in consequential decisions; in its amended form it was signed in May 2026 and is set to take effect in 2027, with enforcement centralized under the state attorney general following rulemaking. Other states are advancing their own measures. The details differ, and timelines continue to move, but the trajectory is unmistakable: obligations attaching specifically to AI systems that make or shape consequential decisions about people. Organizations waiting for a single, settled national standard before acting are likely to find the ground has moved underneath them several times over.

Running alongside the laws are frameworks that increasingly function as the recognized standard of care, notably the NIST AI Risk Management Framework and the ISO/IEC 42001 management-system standard. These aren't statutes, but they're becoming the reference points regulators and courts look to for what reasonable AI governance looks like, and alignment with them is increasingly treated as evidence of diligence. Together, the binding laws and the voluntary frameworks are converging on a similar set of expectations.


The Common Thread: Demonstrable Control

Beneath the specifics, what regulators consistently want is the same thing: the ability to demonstrate control. It is not enough to assert that AI is governed responsibly; organizations are increasingly expected to show it with documentation, evidence and records that stand up to outside scrutiny. This is the throughline connecting otherwise different regimes, and it is where most AI governance programs are least prepared, because demonstrability is far harder than intention.

Several specific expectations recur across frameworks. Regulators expect organizations to know where and how AI is used an accurate inventory of AI systems, not a vague sense that AI is 'in use somewhere.' They expect governance of the data feeding those systems: what it is, where it came from, whether it's accurate, and whether it contains personal or sensitive information that carries its own obligations. They expect risk assessment before deployment, human oversight of consequential decisions, transparency to affected individuals, and monitoring once systems are live. And underlying all of it, they expect records sufficient to prove each of these was actually done.


Why Data Governance Sits at the Center of AI Compliance

A pattern worth drawing out for legal and compliance leaders is how much of what regulators expect ultimately reduces to data. Risk management for an AI system depends on understanding the data it consumes. Transparency about how a decision was made requires knowing what data informed it. Honoring individual rights requires locating a person's data across the systems AI touches. Data governance obligations appear explicitly in the high-risk provisions taking shape, and implicitly nearly everywhere else. An organization that cannot answer basic questions about the data feeding its AI cannot satisfy most of what regulators are beginning to require, however strong its policies look on paper.

This is why treating AI governance as primarily a policy or model-documentation exercise leaves organizations exposed. The obligations that are hardest to meet and most likely to be tested concern the data layer: proving what data a system used, that its use was appropriate, that sensitive information was handled correctly, and that this can be shown across systems that change continuously. Organizations with mature data governance are positioned to demonstrate these things. Those without it face requirements they have no foundation to satisfy.


Preparing for What's Coming

For risk, legal and compliance leaders, the reasonable posture is neither to wait for full regulatory certainty nor to chase every emerging rule individually, but to build toward the common expectations that nearly all of them share. That starts with knowing where AI is used and what data each system consumes, and extends to being able to demonstrate with evidence, not assertion that the data feeding AI is governed, that sensitive information is accounted for, and that issues are detected and resolved on an ongoing basis. Because both the data and the AI landscape change continuously, and because regulators increasingly expect ongoing rather than point-in-time control, this has to be a continuous capability rather than a one-time assessment.

The organizations best positioned for the regulatory environment now taking shape won't be the ones with the most elaborate AI ethics statements. They'll be the ones that can answer, with evidence, what data their AI systems use and whether that use is defensible because that is the question, in one form or another, that regulators across jurisdictions are converging on. AI governance is moving from something organizations describe to something they must prove, and proof rests on the data.

Data Sentinel helps organizations build the demonstrable, data-level foundation that emerging AI regulation increasingly requires continuously discovering, classifying and monitoring the data that feeds AI inside their own environment, and combining technology with managed services so risk, legal and compliance teams can show what data their AI uses, whether it belongs there, and how issues are resolved. Learn more about how we help organizations prepare for what regulators are starting to expect.

Sign up to be notified
about future publications!

Send
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Let's talk

Ready To Discuss Your Data Challenges?

plane white icon