Expertise

Global AI Governance

AI governance for companies building or deploying AI across borders. The EU AI Act has been enforceable since August 2, 2026. In the United States there is no federal statute, so the obligations that reach you are state ones. We establish which rules apply to each of your systems and build a single program that satisfies them.

Start here

InScope regulatory report

We test your company's footprint against the privacy and AI governance instruments in force, and set out what applies now, what applies next, and the shortest set of measures that covers them. The first report is free.

Request a report

The EU AI Act: What Applies Now, and What Was Deferred

The AI Act has been enforceable since August 2, 2026. The Commission's AI Office now holds its enforcement powers over general-purpose model providers, with penalties of up to €15 million or 3% of worldwide turnover, and up to €35 million or 7% for prohibited practices. The Article 50 transparency duties apply from the same date, including to systems already on the market. The Digital Omnibus adopted in July 2026 moved the obligations for Annex III high-risk systems to December 2, 2027, and for AI embedded in regulated products to August 2, 2028. That deferral did not touch the transparency or general-purpose rules, which is the part most often misread.

  • Risk classification for each system: prohibited, high risk, transparency only, or outside scope, with the Annex III screening recorded
  • Article 50 disclosure for systems that interact with people, and marking of synthetic content and deepfakes
  • The provider or deployer question, which determines most of what you owe and is frequently answered wrongly
  • General-purpose model documentation, copyright policy and training-data summary, against the Code of Practice
  • Technical documentation, logging and human oversight for high-risk systems, built before December 2027 rather than during it

SourcesAI Act (Reg. (EU) 2024/1689)·Digital Omnibus (Reg. (EU) 2026/1744)·Commission guidance on Article 50·AI Act enforcement framework

The United States: State Law, Not Federal Law

There is still no federal AI statute. Executive Order 14365, signed in December 2025, directs the Department of Justice to challenge state AI laws and conditions certain federal funding on their repeal, and Congress has so far declined to enact preemption. For a company selling into the United States the practical position is unchanged: state obligations apply, and the litigation over them runs alongside. We identify which of them reach your products, and say so plainly when none of them do.

  • California: the ADMT rules under the CCPA regulations, with a compliance date of January 1, 2027
  • California: SB 53, in force since January 2026 for developers training above the 10^26 operations threshold, with penalties up to $1 million per violation
  • California: SB 243, which imposes disclosure and safety duties on companion chatbots and carries a private right of action
  • Colorado: SB 26-189, which repealed and replaced the 2024 AI Act and applies from January 1, 2027
  • Texas: TRAIGA, in force since January 2026, enforced by the Attorney General after a 60-day cure period
  • Illinois: HB 3773, in force since January 2026, making discriminatory AI in employment decisions a civil rights violation and requiring notice to employees

SourcesEO 14365·CCPA ADMT regulations·SB 53·SB 243·Colorado SB 26-189·Texas HB 149·Illinois HB 3773

One Control Set: AI Act, NIST AI RMF, ISO/IEC 42001

The three regimes ask overlapping questions in different vocabularies. Running them as three programs produces three sets of documents that say the same thing. We map one control set across all of them, so a single piece of evidence answers an AI Act technical file, a NIST function and an ISO clause.

  • EU AI Act risk classification and Annex III screening
  • NIST AI Risk Management Framework: govern, map, measure, manage
  • ISO/IEC 42001 management system controls, in the form a certification body will audit
  • One evidence set, so a control is written once and cited three times

SourcesAI Act·NIST AI RMF·ISO/IEC 42001

AI Inventory and Registry

Governance begins with a complete list. We build and maintain an inventory of every AI system you build or buy: purpose, data lineage, model provenance, risk tier and an accountable owner. It is the first thing an enterprise security questionnaire, a certification auditor and a supervisory authority each ask to see.

  • Systems you built, systems you bought, and models reached through someone else's API
  • Data lineage, and the basis on which training or fine-tuning data was obtained
  • Risk tier under the AI Act, with the obligations that follow from it
  • A named owner for each system, which every framework requires and most inventories omit

Impact Assessments and Human Oversight

Deployment at the high-risk tier brings assessment duties: data protection impact assessments under the GDPR, fundamental-rights impact assessments for the deployers Article 27 covers, the risk assessments the CCPA regulations require, and human oversight that can be evidenced. We build these as approval gates inside your development process, so they are completed while the decisions are still open.

  • DPIAs, and fundamental-rights impact assessments where Article 27 applies
  • CCPA risk assessments for the processing the regulations designate
  • Human oversight measures specific enough to be evidenced, rather than a sentence in a policy
  • Incident recording and reporting routes, including serious incident reporting under the AI Act

SourcesAI Act·GDPR·CPPA rulemaking

Phased Deployment

Moving a model from research to general availability rarely happens in one step. We design the sequence and the criteria for widening it: internal pilot, limited release, model card, adversarial testing, and human review at defined points. The aim is that the legal position is settled before the audience grows rather than afterwards.

Dates We Are Working To

These are settled obligations rather than proposals. We use the sequence to plan client work, and we will tell you which of them apply to you and which do not.

  • August 2, 2026: AI Act enforcement powers in force, and Article 50 transparency duties apply
  • December 2, 2026: marking and detection duties reach systems placed on the market before August 2026
  • January 1, 2027: California ADMT compliance date, and Colorado SB 26-189 applies
  • February 2, 2027: watermark detection interoperability under Article 50(2)
  • December 2, 2027: Annex III high-risk obligations, as deferred by the Digital Omnibus
  • August 2, 2028: high-risk obligations for AI embedded in products already covered by EU product-safety law

SourcesAI Act·Digital Omnibus·Commission guidance on Article 50·CPPA regulations·Colorado SB 26-189

Key Questions We Help You Answer

  • ?Are we a provider or a deployer, and is the answer the same for every system we run?
  • ?Which of our systems are high risk under the AI Act, and which need transparency only?
  • ?What did August 2, 2026 require of us that we may already be missing?
  • ?Do the California, Colorado, Texas or Illinois rules reach our products?
  • ?How do we satisfy the AI Act, NIST AI RMF and ISO/IEC 42001 with one control set?
  • ?What documentation will enterprise buyers and certification auditors ask us for?
Your plan

Fractional AI Governance Lead

$920/month

Stands up the program: AI inventory, EU AI Act risk classification, and one control set mapped to NIST AI RMF and ISO/IEC 42001. The AI Sentinel platform is included.

See what's included
Start now

Online intake takes about five minutes.

Prefer a human first? Book a call

Discovery Call

30 min • Video call

Pacific Time (PT) • San Francisco