Skip to main content

    Why now

    Regulators are asking for runtime evidence just as agents enter production.

    Between now and 2028, seven frameworks ask regulated institutions for evidence produced while AI work runs. In the same window, agents are beginning to act on production systems that were built around people. Both point at the same change: run AI-enabled work on a governed estate that writes its record as the work happens.

    iTmethods operates that estate. Each customer runs on a dedicated single-tenant instance, in your own cloud account or in infrastructure iTmethods operates. Air-gapped and sovereign deployment are supported.

    The regulatory window

    Seven frameworks now expect evidence produced at runtime.

    The frameworks below carry binding deadlines or live supervisory expectations inside a single window. Regulated industries are being asked for evidence produced at runtime rather than assembled at audit.

    Deferred, not reduced

    EU AI Act

    High-risk AI obligations

    The Omnibus adopted on 6 May 2026 defers both high-risk tranches, Annex III stand-alone systems to 2 December 2027 and Annex I embedded systems to 2 August 2028. The deferral is real. It moves the date the evidence is demanded, not the evidence. The transparency obligations are unmoved. Risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy and post-market monitoring become operational requirements either way. The deadline moved. The work did not.

    In force 2027

    OSFI E-23

    Enterprise model risk management

    OSFI's revised guideline on enterprise-wide model risk management binds federally regulated financial institutions in Canada. AI and ML in scope. Validation, ongoing monitoring and documented effective challenge expected at runtime.

    Live April 2026

    Federal Reserve SR 26-2

    Revised model risk guidance

    SR 26-2, Revised Guidance on Model Risk Management, was issued on 17 April 2026 by the Board of Governors of the Federal Reserve System, the OCC and the FDIC, superseding SR 11-7 and SR 21-8. Footnote 3 places generative and agentic AI outside its scope and directs each banking organization to apply its own risk-management and governance practices to them. Institutions running agentic systems are left to govern them under expectations written for models that do not act.

    Operationalised

    FDA PCCP

    Predetermined Change Control Plans

    FDA's Predetermined Change Control Plan framework is now operational guidance for AI / ML-enabled medical devices. Pre-specified modifications, validation protocols and change-control evidence are submission prerequisites.

    In force 2025

    DORA

    Digital Operational Resilience Act

    EU DORA binds financial entities and their critical ICT third parties. Operational resilience, incident reporting, threat-led penetration testing and third-party risk all extend to AI and agent runtime workloads.

    Standard in adoption

    ISO 42001

    AI Management Systems

    The international AI management system standard. Documented governance of the AI lifecycle: risk, controls, continuous improvement and evidence. Procurement teams at regulated buyers are starting to require it.

    Standard in force

    BCBS 239

    Risk data aggregation

    Basel Committee principles for effective risk data aggregation and risk reporting. As AI moves into the credit, market and operational risk stack, BCBS 239 lineage and data-quality discipline applies to the AI surface too.

    See the full framework map Reign maps to →

    The operational shift

    Agents change what the stack underneath them has to do.

    The enterprise stack was designed for human-driven workflows on SaaS perimeters. Identity for people. Audit logs for clicks. Vendors that train on customer data by default. None of those assumptions hold once autonomous agents start invoking tools, calling models and acting on production systems on behalf of the enterprise.

    Boards have noticed. The mandate landing on CISOs, CIOs and Chief AI Officers is consistent across regulated industries: take control of the data, compute, foundation models and agent runtimes the enterprise depends on, keep them inside a dedicated instance you can answer for, and produce documented evidence for every decision the AI stack makes.

    Answering that means changing how the estate is operated. Hyperscaler primitives and SaaS overlays supply the parts; a governed runtime is an operated thing, held to a service level that stands up to the questions regulators ask.

    Runtime evidence

    A governed estate records AI-enabled work as it happens.

    iTmethods operates the estate through four Reign capabilities. Reign Ops and Reign Gateway are available today; Reign Factory is in beta; Reign Assurance is in co-design development.

    Operate

    Reign Ops

    The managed engineering toolchain and the open source estate, run as a single-tenant dedicated instance and held to your change control. Scanners report findings; your policy determines which findings block a change.

    Build

    Reign Factory

    Governed software delivery on the estate Reign Ops already runs. Available · Beta Release.

    Govern

    Reign Gateway

    Model calls carry an identity, meet policy and land in a record before they reach a provider. The crossing is the product.

    Assure

    Reign Assurance

    Reign prepares; people decide. Reign Assurance is in Co-design development. The page states what is in co-design and what is not.

    Next

    Book a working session to discuss your AI regulatory requirements.