California AI Laws: Who Must Comply, and by When

California AI laws compliance calendar with key 2026 and 2027 dates circled

Key takeaways

  • California AI laws are a portfolio of targeted statutes and agency rules, not one act, and at least a dozen already bind businesses in 2026.
  • Your obligations depend on your role: frontier developer, generative AI provider, chatbot operator, employer, CCPA-covered business, platform or state vendor.
  • The next hard deadline under California AI laws is 1 January 2027, when the CCPA automated decision-making rules and new platform duties under the AI Transparency Act apply.
  • Governor Newsom signed four more AI bills on 9 and 10 September 2026, and about 30 AI bills await his decision until 30 September 2026.
  • A federal push to preempt state AI laws has not stopped any California AI statute so far, so plan to comply and keep your controls portable.

California AI laws now reach far beyond the frontier labs of Silicon Valley. A retailer screening job applicants, a lender scoring credit, a media company generating images and a startup running a companion chatbot can each fall under a different statute, a different regulator and a different deadline. There is no single California AI act to read. The state has layered targeted laws, privacy regulations, civil rights rules and executive orders, and it keeps adding to them: the Governor signed four more AI bills in the week this guide was written. This guide maps the California AI laws that matter to businesses by role and by date. It covers what is already enforceable, what applies from 1 January 2027, what was signed in September 2026, what is still pending, and how to build one control set that also serves Colorado, Texas and the EU AI Act. Facts were last verified on 11 September 2026.

California AI laws at a glance: a portfolio, not one act

California tried the single-statute route once. In September 2024 Governor Gavin Newsom vetoed SB 1047, which would have imposed safety testing and shutdown capabilities on the largest models. A year later he signed its narrower successor, SB 53, and the Legislature kept legislating one use case at a time. The result is a regime built from three layers:

  1. Statutes passed by the Legislature and enforced mostly by the Attorney General, sometimes with a private right of action.
  2. Agency regulations, chiefly the California Privacy Protection Agency (CPPA) rules on automated decisionmaking technology (ADMT) and the Civil Rights Council rules on automated-decision systems in employment.
  3. Executive orders, such as N-5-26 on AI procurement, which bind state agencies and, through contracts, their vendors.

AI Sigil’s regulatory mapping of California counts roughly 35 instruments and 110 discrete obligations. Most businesses touch only a handful. The table below lists the California AI laws that reach the widest set of companies. <table header-row=”true”> <tr> <td>Law</td> <td>Who it reaches</td> <td>Status</td> <td>Enforcement and penalty</td> </tr> <tr> <td>SB 53, Transparency in Frontier AI Act</td> <td>Developers of frontier models</td> <td>In force since 1 January 2026</td> <td>Attorney General, up to \$1,000,000 per violation</td> </tr> <tr> <td>AB 2013, training data transparency</td> <td>Developers of generative AI offered to Californians</td> <td>In force since 1 January 2026</td> <td>Attorney General</td> </tr> <tr> <td>SB 942 as amended by AB 853, AI Transparency Act</td> <td>Generative AI providers with over 1 million monthly users; platforms from 2027</td> <td>Operative since 2 August 2026</td> <td>Attorney General and local counsel, \$5,000 per violation per day</td> </tr> <tr> <td>SB 243, companion chatbots</td> <td>Operators of companion chatbots</td> <td>In force since 1 January 2026</td> <td>Private right of action, \$1,000 per violation</td> </tr> <tr> <td>CCPA regulations on ADMT and risk assessments</td> <td>CCPA-covered businesses</td> <td>Effective 1 January 2026; ADMT compliance by 1 January 2027</td> <td>CPPA and Attorney General, up to \$7,500 per violation</td> </tr> <tr> <td>FEHA automated-decision system regulations</td> <td>Employers with five or more employees, and their agents</td> <td>In force since 1 October 2025</td> <td>Civil Rights Department and private lawsuits</td> </tr> <tr> <td>AB 316</td> <td>Anyone who develops, modifies or uses AI</td> <td>In force since 1 January 2026</td> <td>Civil courts</td> </tr> </table> The global picture sits in our guide to AI laws in 2026. This article stays on California AI laws, where the pace of change is the real compliance problem.

Which California AI laws apply to you? A triage by role

Most compliance questions about California AI laws start in the wrong place, with the list of bills. Start with your role instead, because each of the California AI laws is written around a specific actor and a specific trigger.

  • Frontier developer. You trained, or started training, a foundation model with more than 10^26 floating-point operations. SB 53 applies, and if your annual revenue also exceeds \$500 million you are a large frontier developer with extra duties. Brookings estimates that five to eight companies are in scope. See what counts as a frontier model.
  • Generative AI provider. Your image, video or audio generator is publicly accessible in California and has more than one million monthly visitors or users, so the AI Transparency Act applies. If you release any generative AI system to Californians, the AB 2013 training data disclosure applies whatever your size.
  • Companion chatbot operator. Your chatbot offers adaptive, human-like conversation capable of sustaining a relationship. SB 243 applies today, and SB 1119 adds child-safety audits from 2027.
  • Employer. You have five or more employees and use an automated-decision system in hiring, promotion, pay or termination. The FEHA regulations apply, and the tool vendor can be treated as your agent. Our automated employment decision tools guide compares them with New York City, Colorado, Illinois and the EU.
  • CCPA-covered business. You meet the CCPA thresholds and use ADMT for a significant decision about consumers, applicants or employees. The CPPA rules apply from 1 January 2027.
  • Healthcare organization. SB 1120 governs AI in utilization review, AB 3030 requires disclaimers on generative AI patient communications, and AB 489 bars AI from implying a healthcare license.
  • Large platform or hosting service. From 1 January 2027, AB 853 requires provenance detection and bars knowingly hosting non-compliant generators.
  • State vendor. Executive Order N-5-26, signed on 30 March 2026, directs agencies to build AI vendor certifications into procurement (Ropes & Gray).
  • Everyone. AB 316 removes “the AI acted autonomously” as a defense in civil suits, and SB 1001 still requires bots to disclose themselves when used to sell or to influence a vote.

A company based outside the state is not exempt. California AI laws attach to users, consumers and employees in California, so a European provider with Californian users or staff can be in scope without an office there.

In force today: the California AI laws you can be audited on now

Five California AI laws carry most of the weight for a typical enterprise today, each with its own trigger, regulator and paper trail.

SB 53, the Transparency in Frontier AI Act

Signed on 29 September 2025 and in force since 1 January 2026, SB 53 turned voluntary safety commitments into published ones. A large frontier developer must publish a frontier AI framework explaining how it identifies and mitigates catastrophic risk, aligned with national and international standards and reviewed at least annually. Every frontier developer must publish a transparency report when it releases a new or substantially modified frontier model. Critical safety incidents go to the Office of Emergency Services within 15 days of discovery, or within 24 hours when there is an imminent risk of death or serious injury. Whistleblower channels and anti-retaliation protections are mandatory, and the Attorney General can seek civil penalties of up to \$1,000,000 per violation, according to Brookings. Catastrophic risk is defined narrowly: death or serious injury to 50 or more people, more than \$1 billion in damage, expert help with chemical, biological, radiological or nuclear weapons, or a model evading its developer’s control. For European readers the closest analogue is the Safety and Security chapter of the EU GPAI Code of Practice, which covers general-purpose AI with systemic risk from a lower threshold of 10^25 FLOPs, so an EU framework already holds most of the SB 53 material.

AB 2013, training data transparency

Since 1 January 2026, a developer of a generative AI system or service made available to Californians must post documentation of its training data on its website: dataset sources and owners, types of data, whether copyrighted or personal information is included, whether synthetic data was used, collection periods and cleaning steps. The duty reaches back to systems released or substantially modified since 1 January 2022, and each substantial modification needs an update before release. xAI sued, arguing that the law destroys trade secrets and compels speech. On 4 March 2026 a federal judge denied its request for a preliminary injunction, and the case continues (IAPP). Among the California AI laws, AB 2013 is the one closest to an EU duty: the public summary of training content that GPAI providers owe under Article 53 of the AI Act.

SB 942 and AB 853, the California AI Transparency Act

The Act, the most technical of the California AI laws, became operative on 2 August 2026, after AB 853 moved the original 1 January 2026 date. A covered provider, meaning a generative AI system with more than one million monthly visitors or users that is publicly accessible in California and produces image, video or audio content, must:

  • offer a free public detection tool that tells anyone whether content came from its system;
  • give users the option of a visible (manifest) disclosure that is permanent or extraordinarily difficult to remove;
  • embed a latent disclosure in every output, identifying the provider, the system and version, and the time of creation;
  • require licensees by contract to keep disclosures intact, and revoke a license within 96 hours of discovering a breach.

From 1 January 2027, large online platforms must detect and display provenance data, and hosting platforms may not knowingly offer non-compliant generators. Capture-device makers follow on 1 January 2028. Penalties reach \$5,000 per violation, with each day counted separately (Morgan Lewis). The design mirrors the marking duty in EU AI Act Article 50, so one provenance pipeline can serve California AI laws and the EU regime alike.

SB 243, companion chatbots

In force since 1 January 2026, SB 243 requires operators of companion chatbots to disclose that the bot is artificial when a reasonable person could be misled, to maintain protocols that detect suicidal ideation and refer users to crisis services, and to publish those protocols. For users known to be minors, operators must disclose AI use, remind them at least every three hours to take a break, and take reasonable measures against sexually explicit content. From 1 July 2027 operators report annually to the Office of Suicide Prevention. Anyone injured can sue for the greater of actual damages or \$1,000 per violation (Mayer Brown).

The FEHA automated-decision system regulations

Since 1 October 2025, the Civil Rights Council regulations make it unlawful to use an automated-decision system that discriminates on a protected basis, whether intentionally or through disparate impact. Employers must keep ADS records, including dataset descriptors, scoring outputs and audit findings, for four years. Anti-bias testing, or its absence, is relevant evidence in a claim, and a vendor acting on the employer’s behalf can be treated as its agent (Jackson Lewis). That agency rule, rare among California AI laws, turns vendor due diligence into a legal necessity rather than good practice.

The CCPA ADMT rules: the window that closes on 1 January 2027

The CPPA regulations on ADMT, risk assessments and cybersecurity audits were approved on 22 September 2025 and took effect on 1 January 2026, but their heaviest duties phase in. ADMT means technology that processes personal information to replace, or substantially replace, human decision-making. When a business uses it for a significant decision, meaning one about financial or lending services, housing, education, employment or healthcare, it must by 1 January 2027:

  • give a pre-use notice explaining the purpose, how the technology works and the consumer’s rights;
  • offer an opt-out unless an exception applies, for example a route to appeal to a human reviewer;
  • answer access requests about the logic of the ADMT and how its output was used.

Risk assessments are required before processing that presents significant risk: selling or sharing personal information, processing sensitive personal information, using ADMT for a significant decision, drawing automated inferences from systematic observation, or training ADMT. Processing that began before 2026 and continues must be assessed by 31 December 2027, and a first attestation with summary information is due to the CPPA by 1 April 2028. Assessments are kept for as long as the processing continues or five years after completion, whichever is later (Morrison Foerster). Annual cybersecurity audits follow, with first certifications due on 1 April 2028 for businesses above \$100 million in revenue, in 2029 for those between \$50 million and \$100 million, and in 2030 below that. Violations cost up to \$7,500 each. Of all the California AI laws, this is the one most likely to catch a European group with Californian customers or staff, because the CCPA thresholds are revenue and data-volume tests rather than AI tests. A CCPA risk assessment covers much of the ground of an AI impact assessment or a DPIA, so build the template once and reuse it.

What Newsom signed in September 2026, and what is still pending

The 2026 legislative session closed on 31 August with about 30 AI-related bills sent to the Governor, who has until 30 September 2026 to sign or veto them. A bill he does not act on becomes law without his signature (Transparency Coalition). Four AI bills were signed in the week this guide was written, and they change the California AI laws in a direction every compliance team should notice: from disclosure towards third-party verification. Signed on 9 September 2026. SB 813 creates a framework for independent verification organizations that assess AI systems and models for compliance with state law. AB 1405 creates a state registry of AI auditors with independence, transparency and integrity standards, and press reports indicate that registration becomes mandatory for covered AI audits from 2029 (Office of the Governor). Together they build the market for third-party assurance of compliance with California AI laws, which is where AI audit evidence will be tested. Signed on 10 September 2026. SB 1119 extends the companion-chatbot rules for children: annual documented child-safety risk assessments, parental tools, independent child safety audits whose reports go to the Attorney General within 90 days, a public Attorney General report from 2028, and a private right of action for children and parents. SB 867 imposes a four-year moratorium on toys with companion chatbots for children under 16 (CalMatters). Unless a bill says otherwise, a California statute takes effect on 1 January of the following year, so plan for 1 January 2027. Still pending on 11 September 2026. Bills that would add to the California AI laws, and still await a decision, include:

  • SB 947, the No Robo Bosses Act: no sole reliance on automated systems to discipline or fire workers, with human review and notice (proposed start 1 July 2027);
  • AB 1609: disclosure when consumers deal with customer-service chatbots at large businesses;
  • SB 1000 and AB 2713: amendments to the AI Transparency Act for providers and platforms;
  • SB 503, AB 2575, AB 1979 and SB 903: AI in clinical decision support, patient care and psychotherapy;
  • SB 951 and AB 1883: AI in layoff notices and workplace surveillance;
  • SB 574: duties for attorneys who use generative AI.

The proposed dates for each are in the Wiley session summary. Treat the list as a watch list and check it again after 30 September.

California AI laws by date: the compliance calendar

The dates below turn California AI laws into a planning tool. Anything earlier than today is already enforceable. Colorado’s reworked statute also lands on 1 January 2027, as our Colorado AI Act guide explains, which makes that date the natural target for a multi-state program. <table header-row=”true”> <tr> <td>Date</td> <td>What applies</td> <td>Who</td> </tr> <tr> <td>1 October 2025</td> <td>FEHA automated-decision system regulations</td> <td>Employers with five or more employees</td> </tr> <tr> <td>1 January 2026</td> <td>SB 53, AB 2013, SB 243, AB 316, AB 489; CCPA regulations effective, risk assessments for new processing</td> <td>Frontier and generative AI developers, chatbot operators, CCPA businesses</td> </tr> <tr> <td>2 August 2026</td> <td>AI Transparency Act core duties</td> <td>Generative AI providers over 1 million monthly users</td> </tr> <tr> <td>30 September 2026</td> <td>Deadline for the Governor on pending AI bills</td> <td>Watch list</td> </tr> <tr> <td>1 January 2027</td> <td>CCPA ADMT notice, opt-out and access; AB 853 platform and hosting duties; SB 1119, SB 867, SB 813 and AB 1405 expected to take effect</td> <td>CCPA businesses, platforms, chatbot operators, toy makers</td> </tr> <tr> <td>1 July 2027</td> <td>First SB 243 annual report to the Office of Suicide Prevention</td> <td>Chatbot operators</td> </tr> <tr> <td>31 December 2027</td> <td>Risk assessments for processing begun before 2026</td> <td>CCPA businesses</td> </tr> <tr> <td>1 January 2028</td> <td>Capture-device disclosures; first annual Attorney General report on SB 1119 audits</td> <td>Device makers, chatbot operators</td> </tr> <tr> <td>1 April 2028</td> <td>CPPA risk assessment attestation; first cybersecurity audit certifications</td> <td>CCPA businesses, revenue over \$100 million</td> </tr> <tr> <td>2029</td> <td>AI auditor registration (AB 1405, as reported); cybersecurity audits for mid-size businesses</td> <td>Auditors; revenue \$50 million to \$100 million</td> </tr> <tr> <td>1 April 2030</td> <td>Cybersecurity audits for smaller businesses</td> <td>CCPA businesses, revenue under \$50 million</td> </tr> </table>

The federal preemption question: plan to comply anyway

On 11 December 2025 President Trump signed Executive Order 14365. It set up a Department of Justice AI Litigation Task Force, created on 9 January 2026, to challenge state AI laws, asked the Commerce Department to identify “onerous” state laws by 11 March 2026, tied part of the BEAD broadband funding to that review, and called on Congress to preempt state rules (King & Spalding). California AI laws were at the center of that debate. The practical effect on California AI laws has so far been limited. The Task Force’s first move was to join xAI’s lawsuit against the Colorado AI Act in April 2026, a case overtaken when Colorado rewrote its law in May. No federal suit against a California AI statute had been reported by mid-2026, and Congress has not enacted a moratorium on state AI laws. Two further points argue for compliance. Several of the California AI laws carry private rights of action (SB 243, SB 1119 and FEHA) that do not depend on the Attorney General. And an executive order cannot repeal a state statute; only Congress or a court can displace it. Governor Newsom framed the September signings as filling a federal gap in AI rules and called on Washington to legislate. For a compliance team, the sensible posture is to comply, document, and keep controls portable, so that a change in one jurisdiction changes a mapping rather than a program. Our TRAIGA guide covers the Texas side of the same question.

One control set for California, Colorado, Texas and the EU AI Act

Companies that sell in the United States and Europe do not need a California program, a Colorado program and an EU program. They need one control set with jurisdiction mappings. The table shows how the main California AI laws line up with the EU AI Act. <table header-row=”true”> <tr> <td>Control</td> <td>California hook</td> <td>EU AI Act hook</td> </tr> <tr> <td>AI system inventory with jurisdiction tags</td> <td>Scoping for every California AI law</td> <td>Article 6 classification, Article 49 registration</td> </tr> <tr> <td>Automated-decision notices, opt-out and human review</td> <td>CCPA ADMT rules, FEHA regulations</td> <td>Article 26(11) information, Article 86 explanation</td> </tr> <tr> <td>Content provenance and marking</td> <td>SB 942 and AB 853</td> <td>Article 50(2)</td> </tr> <tr> <td>Chatbot and bot disclosure</td> <td>SB 243, SB 1001</td> <td>Article 50(1)</td> </tr> <tr> <td>Bias testing and decision records</td> <td>FEHA regulations, four-year retention</td> <td>Article 10, Articles 12 and 26(6) logs</td> </tr> <tr> <td>Safety framework and incident reporting</td> <td>SB 53</td> <td>Article 55, Article 73</td> </tr> <tr> <td>Training data summary</td> <td>AB 2013</td> <td>Article 53(1)(d)</td> </tr> <tr> <td>Risk or impact assessment</td> <td>CCPA risk assessments, SB 1119</td> <td>Article 9, Article 27</td> </tr> <tr> <td>Vendor and licensee clauses</td> <td>SB 942 licensee duties, FEHA agency rule</td> <td>Article 25 value chain</td> </tr> </table> Colorado and Texas slot into the same rows as the California AI laws. Colorado’s SB 26-189, signed in May 2026, reworked its AI Act into an automated-decision disclosure regime from 1 January 2027, which the notices row covers. Texas TRAIGA, in force since 1 January 2026, is mostly a list of intent-based prohibitions plus disclosure duties for government agencies, which the inventory and a prohibited-use screen cover. This is the model AI Sigil runs: 28 regulatory frameworks across four regions, California included, mapped to one obligation library.

The evidence file: records California AI laws make producible

Each of the California AI laws creates records that a regulator, a court or a plaintiff can demand. Assign an owner to each record before the first request arrives. <table header-row=”true”> <tr> <td>Record</td> <td>Law</td> <td>Timing or retention</td> </tr> <tr> <td>Frontier AI framework and transparency reports</td> <td>SB 53</td> <td>Framework reviewed at least annually; report at each release; redacted material kept five years</td> </tr> <tr> <td>Critical safety incident reports</td> <td>SB 53</td> <td>15 days, or 24 hours if the risk is imminent</td> </tr> <tr> <td>Training data documentation</td> <td>AB 2013</td> <td>Before release and before each substantial modification</td> </tr> <tr> <td>Latent disclosure specification, detection tool, license clauses, revocation log</td> <td>SB 942 and AB 853</td> <td>Continuous; revocation within 96 hours</td> </tr> <tr> <td>Crisis referral counts and suicide-prevention protocols</td> <td>SB 243</td> <td>Annual report from 1 July 2027</td> </tr> <tr> <td>ADS inputs, outputs, scoring and bias audits</td> <td>FEHA regulations</td> <td>Four years</td> </tr> <tr> <td>ADMT notices, opt-out and access logs</td> <td>CCPA regulations</td> <td>From 1 January 2027</td> </tr> <tr> <td>Risk assessments</td> <td>CCPA regulations</td> <td>While processing continues or five years, whichever is later</td> </tr> <tr> <td>Child safety risk assessments and audit reports</td> <td>SB 1119</td> <td>Annual; audit report to the Attorney General within 90 days</td> </tr> </table> Incident records deserve the most care, because the SB 53 clock, like the one in Article 73 of the EU AI Act, starts at discovery. Our AI incident reporting guide sets out a triage that works for both.

A 90-day plan for your California AI laws program

Days 1 to 30: inventory and applicability. List every AI system, flag those that reach Californian users, consumers or employees and therefore fall under California AI laws, and record your role for each against the triage above. Most organizations find unregistered tools at this stage, and our shadow AI guide covers discovery. Days 31 to 60: close the 1 January 2027 gaps. Draft ADMT pre-use notices, build the opt-out and access workflow, run the risk assessments that ADMT triggers, and check provenance detection if you host content. Chatbot operators should scope SB 1119 audits now, because the audit market that SB 813 and AB 1405 create will be busy. Days 61 to 90: evidence and monitoring. Assign owners to every record in the evidence table, set review dates, and keep a watch list for the bills pending until 30 September and for federal litigation. Map controls to a recognized framework such as the NIST AI RMF, the obvious national standard for the alignment SB 53 asks frontier frameworks to show.

FAQ

Does California have an AI act like the EU AI Act? No. California AI laws are targeted statutes such as SB 53, AB 2013, SB 942 and SB 243, plus privacy regulations under the CCPA and civil rights regulations under FEHA. The closest thing to an omnibus bill, SB 1047, was vetoed in 2024. The practical consequence is that there is no single scope test: each law has its own trigger, so applicability has to be checked law by law against your role. Do California AI laws apply to companies based outside California? In most cases, yes. California AI laws attach to Californian users, consumers and employees rather than to where a company is incorporated. A European generative AI provider with over one million monthly users in California, or an employer whose Californian staff are screened by an automated tool, can be in scope without a local office. Which California AI laws apply to employers? Three sets of California AI laws matter. The FEHA automated-decision system regulations, in force since 1 October 2025, prohibit discriminatory outcomes and require four years of records. The CCPA ADMT rules require notices, opt-outs and access rights for significant employment decisions from 1 January 2027. SB 947, pending until 30 September 2026, would bar relying solely on automated systems to discipline or fire workers. When do the CCPA ADMT rules take effect? The regulations took effect on 1 January 2026, but a business already using ADMT for significant decisions must meet the ADMT requirements by 1 January 2027. Risk assessments for processing that began before 2026 are due by 31 December 2027, with a first attestation to the CPPA by 1 April 2028. Which California AI laws did Newsom sign in September 2026? On 9 September 2026 he signed SB 813, on independent verification organizations, and AB 1405, a registry of AI auditors. On 10 September he signed SB 1119, on child safety for companion chatbots with independent audits, and SB 867, a four-year moratorium on companion-chatbot toys for children under 16, alongside several child online safety bills. Can the federal government override California AI laws? Only Congress or a court can displace California AI laws, as with any state statute. Executive Order 14365 created a DOJ task force to challenge state AI laws and linked some federal funding to a review of them, but by mid-2026 no federal suit against a California AI statute had been reported and Congress had not passed a moratorium. Private rights of action under SB 243, SB 1119 and FEHA do not depend on state enforcement.

Conclusion

California AI laws reward the companies that stop reading them bill by bill. Their obligations fall into a small number of patterns: disclose, assess, keep records, test for bias, report incidents. The same patterns recur in Colorado, Texas and the EU AI Act. The next deadline, 1 January 2027, is close enough to plan for now and far enough away to meet if you start with an inventory this quarter. AI Sigil maps California AI laws alongside the EU AI Act and 26 other national and state AI laws in a single obligation library, so a new signing becomes a mapping update rather than a new project. If you are scoping your obligations under California AI laws, start with the inventory and the calendar above, and check the pending list again after 30 September.

California AI Laws: Who Must Comply, and by When

California AI laws explained by role and date: SB 53, SB 942, SB 243, CCPA ADMT, FEHA rules and the bills Newsom signed in September 2026.

TRAIGA Compliance: The Texas AI Law, Operationalized

TRAIGA has been in force since January 2026. What the Texas AI law prohibits, how the NIST AI RMF safe harbour works, and the evidence you need to rely on it.

Vendor Due Diligence for AI: 12 Questions Checklists Miss

Standard vendor due diligence was built for a pre-AI supply chain. Here are the 12 AI-specific questions to add, and the legal duty behind them.

Model Risk Management for AI and Machine Learning

Model risk management is being rewritten for AI. See how SR 26-2, the EU AI Act, ISO 42001 and NIST AI RMF reshape MRM for machine learning and GenAI.

Policy Management Software: The AI-Era Buyer’s Guide

Policy management software must now prove AI policies work, not just that staff signed them. Evaluation criteria, EU AI Act duties and buying traps.

Human Oversight Under the EU AI Act: Article 14 in Practice

Human oversight is an EU AI Act Article 14 obligation, not a principle. What providers must build, what deployers must staff, and when it applies.