Deferred, not reducedEU AI Act
High-risk AI obligations
The Omnibus adopted on 6 May 2026 defers both high-risk tranches, Annex III stand-alone systems to 2 December 2027 and Annex I embedded systems to 2 August 2028. The deferral is real. It moves the date the evidence is demanded, not the evidence. The transparency obligations are unmoved. Risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy and post-market monitoring become operational requirements either way. The deadline moved. The work did not.
In force 2027OSFI E-23
Enterprise model risk management
OSFI's revised guideline on enterprise-wide model risk management binds federally regulated financial institutions in Canada. AI and ML in scope. Validation, ongoing monitoring and documented effective challenge expected at runtime.
Live April 2026Federal Reserve SR 26-2
Revised model risk guidance
SR 26-2, Revised Guidance on Model Risk Management, was issued on 17 April 2026 by the Board of Governors of the Federal Reserve System, the OCC and the FDIC, superseding SR 11-7 and SR 21-8. Footnote 3 places generative and agentic AI outside its scope and directs each banking organization to apply its own risk-management and governance practices to them. Institutions running agentic systems are left to govern them under expectations written for models that do not act.
OperationalisedFDA PCCP
Predetermined Change Control Plans
FDA's Predetermined Change Control Plan framework is now operational guidance for AI / ML-enabled medical devices. Pre-specified modifications, validation protocols and change-control evidence are submission prerequisites.
In force 2025DORA
Digital Operational Resilience Act
EU DORA binds financial entities and their critical ICT third parties. Operational resilience, incident reporting, threat-led penetration testing and third-party risk all extend to AI and agent runtime workloads.
Standard in adoptionISO 42001
AI Management Systems
The international AI management system standard. Documented governance of the AI lifecycle: risk, controls, continuous improvement and evidence. Procurement teams at regulated buyers are starting to require it.
Standard in forceBCBS 239
Risk data aggregation
Basel Committee principles for effective risk data aggregation and risk reporting. As AI moves into the credit, market and operational risk stack, BCBS 239 lineage and data-quality discipline applies to the AI surface too.