Regulators did not wait for agentic AI to be well-defined before regulating it, and they will not wait for your control catalog to be finished before examining it. The instruments in this Part were almost all drafted for models (things that score, classify, and predict) and are now being applied to agents: things that, in the words of the FCA's Chief Executive, "don't just support financial decisions, but coordinate and transact" (fca.org.uk/news/speeches/rethinking-regulation-age-ai, T2). The good news for the Chief AI Risk Officer is that the obligations converge far more than the instruments' page counts suggest. The less good news is that examiners will expect you to have noticed.
This Part maps each regime three ways: what it demands, how agents change the analysis, and which control families in this Compendium satisfy it (GOV governance, DES design-time, EVL pre-deployment evaluation, RUN runtime, MON monitoring, MAS multi-agent, TPR third-party, ASR assurance, FCO fairness and customer outcomes). The Part closes with the master obligation-to-control-family table and the regulatory coverage map.
A structural observation across the cited frameworks: these instruments operate at different altitudes, a principles layer (OECD, EU HLEG), a process layer (NIST AI RMF), an auditable management-system layer (ISO/IEC 42001, the only certifiable member), and above them the binding layer (EU AI Act, state statutes, banking supervision) where the risk-tiering actually lives: "the risk-tiering lives in the regulation, not the frameworks" (see the primary sources below). Build once at the process/management-system layer; evidence many times at the binding layer.
V.1 EU AI Act (Regulation 2024/1689): high-risk systems and GPAI
What it demands. The AI Act regulates by risk tier: unacceptable-risk practices banned outright (Article 5); high-risk systems subject to the heavy obligations of Articles 6–49, conformity assessment, technical documentation, human oversight, transparency, post-market monitoring; limited-risk systems subject to transparency duties only (Article 50); minimal-risk largely unregulated; plus a parallel regime for general-purpose AI models (Articles 51–55) (artificialintelligenceact.eu, T1). For a financial institution the decisive trigger is Annex III's high-risk list, which expressly reaches "access to essential private services" including credit scoring and insurance pricing (artificialintelligenceact.eu, T1). The Commission has issued draft guidelines on Article 6 high-risk classification (digital-strategy.ec.europa.eu/en/policies/guidelines-ai-high-risk-systems, T1): the first place to look when deciding whether an agentic workflow is in scope.
The obligations most relevant to this Compendium, at the article level the cited research supports:
- Article 11 and Annex IV: technical documentation for high-risk systems (artificialintelligenceact.eu/article/11, T1).
- Article 14: human oversight for high-risk systems (binding_regulation_EU_US crosswalk).
- Article 15: accuracy, robustness and cybersecurity (artificialintelligenceact.eu/article/15, T1).
- Article 16: provider obligations, including accessibility (ai-act-service-desk.ec.europa.eu/en/ai-act/article-16, T1).
- Article 18: multi-year documentation retention (binding_regulation_EU_US crosswalk).
- Article 43: notified-body conformity assessment for some high-risk systems (binding_regulation_EU_US crosswalk).
- Article 50: transparency: notice of AI interaction, labeling of AI-generated content (artificialintelligenceact.eu, T1).
- Articles 51–55: GPAI providers: technical documentation, a sufficiently detailed training-data summary, an EU copyright compliance policy; a stricter regime for GPAI models with systemic risk (artificialintelligenceact.eu, T1).
- Article 72: post-market monitoring by providers and a post-market monitoring plan for high-risk systems (ai-act-service-desk.ec.europa.eu/en/ai-act/article-72, T1).
- Article 73: serious-incident reporting on the order of 15 days (binding_regulation_EU_US crosswalk).
- Article 99: fines up to EUR 35M or 7% of global turnover (binding_regulation_EU_US crosswalk).
Timeline caution: the 2026 Digital Omnibus. On 7 May 2026 the Council presidency and Parliament negotiators reached provisional agreement on the "Digital Omnibus on AI," the first amendment package to the Act. Under the provisional summary below; consult Official Journal text before relying on these dates: Annex III high-risk obligations postpone to 2 December 2027; Annex I product-regulated high-risk obligations to 2 August 2028; Article 50(2) synthetic-content marking keeps its 2 August 2026 application date but gains a transitional period to 2 December 2026 for systems already on the EU market, while Article 50(1), (3) and (4) transparency duties apply from 2 August 2026 with no transition; and two new Article 5 prohibitions are added (CSAM and non-consensual intimate imagery generation) (consilium.europa.eu/en/press/press-releases/2026/05/07/artificial-intelligence-council-and-parliament-agree-to-simplify-and-streamline-rules, T1, provisional claim). Plan to the amended dates; do not book the relief as final until the OJ text lands.
How agents change the analysis. Three shifts. First, classification: an agentic system that orchestrates a credit or insurance-pricing decision is not a peripheral chatbot. It sits squarely in Annex III territory, and the "material influence" question gets harder when the agent decomposes the decision across tools and sub-agents. Assess the workflow, not the model. Second, the GPAI value chain: most financial-enterprise agents are built on third-party GPAI models, so Articles 51–55 obligations sit with your model provider while Articles 6–49 deployment obligations sit with you, meaning your vendor diligence (TPR) must capture the provider's GPAI documentation as an input to your own Annex IV file. Third, human oversight and post-market monitoring were written for systems with stable input-output behavior; an agent that plans, calls tools, and retains memory requires oversight designed at the action level (RUN) and monitoring designed at the trajectory level (MON), not a quarterly performance report. Article 50 also bites customer-facing agents directly: the customer must know they are dealing with AI, and agent-generated content must be labeled on the Act's timeline.
Control families. GOV (risk-management system, accountability), DES (data governance, Annex IV documentation inputs), EVL (Article 15 accuracy/robustness testing, conformity-assessment evidence), RUN (Article 14 human oversight modes, action-level gating), MON (Article 72 post-market plan, Article 73 incident clocks), TPR (GPAI provider diligence, Articles 51–55 artifacts), ASR (conformity assessment, Article 18 retention), FCO (Article 50 customer transparency).
V.2 NIST AI RMF 1.0 and the GenAI Profile (AI 600-1)
What it demands. Nothing. It is voluntary. What it provides is the de facto US process reference: four functions, GOVERN (cross-cutting), MAP, MEASURE, MANAGE, decomposed into categories and subcategories, seven trustworthiness characteristics (valid and reliable, safe, secure, accountable and transparent, explainable, privacy-enhanced, fair, explicitly interrelated and in tension), and an explicit lifecycle from Plan & Design through Operate & Monitor with TEVV (test, evaluation, verification, validation) running throughout (risk_management_frameworks crosswalk, citing T1 NIST AI RMF 1.0 source excerpt). The companion AI 600-1 GenAI Profile extends the same four functions with generative-AI-specific suggested actions across twelve risk categories, including confabulation, information security, and value-chain inheritance (risk_management_frameworks crosswalk, citing T1 NIST AI 600-1 source excerpt).
Why a voluntary framework earns a section in a regulatory mapping. Two reasons. US banking supervisors examine AI programs against some coherent framework, and the RMF is the one their own agencies cite. And US state law has begun incorporating it by reference: Colorado's original SB 24-205 explicitly accepted the NIST AI RMF as one route to risk-management-program compliance (leg.colorado.gov/bills/sb24-205, T1), a template roughly fifteen other states were considering as of mid-2026 (same source). Even after Colorado's 2026 pivot (Section V.7), the RMF-as-safe-harbor pattern is the likely shape of future US state law.
How agents change the analysis. The RMF's contextual, non-tiered approach ("risk treated contextually via MAP/MEASURE": risk_management_frameworks crosswalk) actually fits agents better than tier-based regimes: autonomy level, tool blast radius, and reversibility become MAP inputs rather than awkward exceptions. The GenAI Profile's value-chain-inheritance and confabulation categories are the closest thing US guidance offers to named agentic failure modes. The gap: RMF 1.0 predates the agentic risk surface, sabotage evaluation, multi-agent emergence, and delegation-chain identity have no subcategories, so your MAS controls will map to the RMF only at the function level. [practice guidance: not directly source-backed]: profile your agent program to the RMF at subcategory level anyway; examiners reward the traceability even where the fit is loose.
Control families. GOVERN maps to GOV; MAP to DES and GOV; MEASURE to EVL and MON (TEVV is the EVL family's organizing idea); MANAGE to RUN and MON. The GenAI Profile's value-chain categories map to TPR.
V.3 The ISO/IEC suite: 42001, 23894, 42005, 42006
What it demands. ISO/IEC 42001:2023 is the certifiable AI management system (AIMS) standard, an Annex SL management system (Clauses 4–10, PDCA) plus an Annex A control set (approximately 38 controls across 9 objectives, structural knowledge secondary-sourced because the normative text is paywalled), covering AI policy, impact assessment, lifecycle processes, data for AI, third-party relationships, and responsible use (risk_management_frameworks crosswalk, citing T1 ISO/IEC 42001 source excerpt). Its distinctive property in this cohort: it is "the only certifiable member — accredited audit against clauses + Annex A" (see the framework comparison tables), which is precisely why enterprise procurement increasingly demands "ISO 42001 certified or roadmap" (same source).
The companions: ISO/IEC 23894 (AI risk-management guidance), ISO/IEC 42005 (AI system impact assessment), and ISO/IEC 42006 (requirements for bodies auditing and certifying AIMS), are named here at instrument level only; the cited research pack for this Part does not carry their texts, and their clause-level content is therefore not cited. [practice guidance: not directly source-backed]: treat 23894 as the risk-process elaboration behind 42001 Clause 6, 42005 as the method behind your DES impact-assessment control, and 42006 as the reason to check your certifier's accreditation before paying for a certificate, Part IV (Assurance) develops the 42006/17021 certification chain.
How agents change the analysis. A management system certifies the organization's process, not the agent's behavior. An ISO 42001 certificate over an agentic estate is meaningful only if the AIMS scope statement actually encloses the agents (their tools, their autonomy levels, their model suppliers) and if the Annex A impact-assessment and lifecycle controls are executed per agentic workflow, not per underlying model. The paywalled-normative-text problem noted in the crosswalk also means your second line should verify claimed clause mappings against a licensed copy rather than vendor marketing.
Control families. GOV (the AIMS itself: policy, roles, management review), DES (impact assessment, data-for-AI controls), TPR (third-party relationship controls), ASR (internal audit under Clause 9, certification evidence, the 42006 audit chain).
V.4 US banking supervision: SR 11-7 / OCC 2011-12 model risk, and the 2026 interagency revision
What it demands. SR 11-7, the Federal Reserve's Supervisory Guidance on Model Risk Management (federalreserve.gov/boarddocs/srletters/2011/sr1107.htm, T1), adopted in substance by the OCC as Bulletin 2011-12 and by the FDIC via FIL-22-2017 (fdic.gov/news/inactive-financial-institution-letters/2017/adoption-supervisory-guidance-model-risk-management, T1), is the constitution of bank model governance: model inventory, development and implementation standards, independent validation, ongoing monitoring, effective challenge, and governance proportionate to model materiality. This Compendium speaks SR 11-7 vocabulary throughout by design.
The load-bearing 2026 development: the agencies have revised the interagency guidance. The Federal Reserve issued SR 26-2, "Revised Guidance on Model Risk Management" (federalreserve.gov/supervisionreg/srletters/sr2602.htm and federalreserve.gov/supervisionreg/srletters/sr2602.pdf, both T1), the OCC issued the parallel Bulletin 2026-13 (occ.gov/news-issuances/bulletins/2026/bulletin-2026-13.html, T1), and the FDIC announced the interagency revision via FIL-15-2026 (fdic.gov/news/financial-institution-letters/2026/agencies-revise-interagency-model-risk-management-guidance, T1). the cited research pack carries the issuance records, not an analyzed diff of the revised text; institutions should read SR 26-2 directly and re-baseline their MRM policy against it rather than against 2011-era summaries. [practice guidance: not directly source-backed]: expect examiners to ask, within the first exam cycle after adoption, how your definition of "model" and your validation standards apply to LLM-based and agentic systems.
How agents change the analysis. SR 11-7's triad (development, validation, governance) survives contact with agents, but each leg stretches. Inventory: an agent is not one model; it is a composition of a foundation model, prompts, tools, memory, and orchestration logic, any of which can change independently, inventory the composition and version it as a unit. Validation: point-estimate accuracy testing does not validate a system whose behavior depends on trajectory; validation must include the evaluation regimes of Part III.B (EVL), and "effective challenge" must include challenge of the evaluation's validity. Ongoing monitoring: vendor model updates arrive on the provider's schedule, not yours, a change-management trigger SR 11-7 always contemplated for vendor models but that agents make routine (TPR). Governance: autonomy itself becomes a risk-appetite parameter the board must own (Part II).
Control families. GOV (MRM policy extension to agents, inventory, risk appetite for autonomy), EVL (independent validation, effective challenge), MON (ongoing monitoring, performance-drift response), TPR (vendor model risk, upstream change management), ASR (validation reports, internal audit of MRM).
V.5 DORA: EU digital operational resilience
What it demands. The Digital Operational Resilience Act binds EU financial entities to a harmonized regime across ICT risk management, ICT incident classification and reporting, digital operational resilience testing, and management of ICT third-party risk, including oversight of critical ICT providers. That description is offered at instrument level: the cited research pack for this Part does not carry DORA's text, so no article numbers are cited here. [practice guidance: not directly source-backed] for the clause-level detail.
What the cited research does carry is the analytical bridge: the AI Resilience Gap argument for "bringing artificial intelligence inside the operational resilience perimeter" (arxiv.org/abs/2607.07359, T2), the observation that AI systems, and agentic systems especially, have been managed as model risk while their failure modes have become operational risk. The FCA's 2025 statistic that "98% of operational incidents reported to us related to technology and cyber issues" (fca.org.uk/news/speeches/rethinking-regulation-age-ai, T2) is the supervisory mood music: regulators now treat technology failure as the dominant operational-incident class, and an autonomous agent with tool access is a technology failure mode with agency.
How agents change the analysis. Under a DORA lens, an agentic system is simultaneously: an ICT asset that must be inventoried and risk-managed; an incident generator whose anomalous actions must be classifiable and reportable on regulatory clocks; a resilience-testing subject, adversarial testing of agents (Part III.B red-teaming) is the natural analogue of threat-led penetration testing; and a concentration of third-party risk, since a handful of frontier model providers now sit upstream of many institutions' agents at once. Kill switches, budget guards, and degradation-to-manual paths (RUN) are resilience controls in the DORA sense, not just safety controls: the institution must be able to operate through the loss or misbehavior of its agents.
Control families. RUN (containment, kill switches, fallback-to-manual), MON (incident detection, classification, regulatory reporting), EVL (resilience and adversarial testing), TPR (critical ICT/model-provider dependency management, exit strategies), GOV (management-body accountability for ICT risk).
V.6 SEC and FINRA: US securities and broker-dealers
What it demands. FINRA's position is deliberately technology-neutral: Regulatory Notice 24-09 "reminds members of regulatory obligations when using generative artificial intelligence and large language models" (finra.org/rules-guidance/notices/24-09, T1), the existing rulebook (supervision, communications with the public, books and records, suitability) applies to AI-assisted activity with no AI carve-out. FINRA has tracked the technology since its 2020 report on AI in the securities industry (finra.org/sites/default/files/2020-06/ai-report-061020.pdf, T1) and treats GenAI as a standing examination theme in its Annual Regulatory Oversight Reports for 2024 (finra.org/rules-guidance/guidance/reports/2024-finra-annual-regulatory-oversight-report, T1) and 2026, the latter with a dedicated "GenAI: Continuing and Emerging Trends" section (finra.org/rules-guidance/guidance/reports/2026-finra-annual-regulatory-oversight-report/gen-ai, T1). On the investor-protection side, the SEC's Office of Investor Education has flagged AI-themed investment fraud (investor.gov investor alert on artificial intelligence and fraud, T1): relevant both to what your agents must not do and to the fraud environment your surveillance functions face.
How agents change the analysis. Technology-neutrality cuts against you here: if an agent drafts client communications, executes or recommends transactions, or summarizes research, every applicable rule attaches as if a registered person had done it, and the firm's supervisory system must actually supervise it. Concretely: agent outputs to customers are communications subject to content standards and approval workflows; agent actions are business records subject to retention; and an agent embedded in a registered rep's workflow raises the question of whether supervision covers the human, the agent, or the composite. [practice guidance: not directly source-backed]: treat every customer-facing agent action as passing through the same supervisory control points as human activity, pre-use approval of templates and tools (RUN gating), post-hoc surveillance sampling of trajectories (MON), and books-and-records capture of the full action log, not just the final output.
Control families. GOV (supervisory system design, WSPs updated for agents), RUN (communication approval gates, tool restrictions), MON (surveillance, books-and-records capture of trajectories), FCO (customer-communication fairness and accuracy), EVL (pre-deployment testing of customer-facing behavior).
V.7 Colorado, from SB 24-205 to the SB 26-189 ADMT Act (and the wider US state map)
What it demanded, then demands. Colorado's SB 24-205 (signed May 2024) was the first comprehensive US state high-risk AI law: reasonable-care duties against algorithmic discrimination, developer documentation duties, deployer risk-management programs (NIST AI RMF explicitly acceptable), impact assessments, consumer notice, explanation, correction and appeal rights, and 90-day attorney-general discrimination notifications, with AG-exclusive enforcement (leg.colorado.gov/bills/sb24-205, T1; enrolled text at content.leg.colorado.gov/sites/default/files/2024a_205_signed.pdf, T1; effective-date delay history in leg.colorado.gov/bills/sb25b-004, T1).
On 14 May 2026, SB 26-189 repealed and reenacted SB 24-205, refocusing the law from "high-risk AI systems" to "covered automated decision-making technology" (Covered ADMT) that materially influences consequential decisions (the same enumerated domains, expressly including financial services and insurance) effective 1 January 2027 (leg.colorado.gov/bills/sb26-189, T1). Two changes matter most for this Compendium. Scope broadened: ADMT "requires no inference. A system that merely checks whether an answer falls within an acceptable range qualifies" (leg.colorado.gov/bills/sb26-189 source excerpt), so rule-based components of an agentic workflow are captured, not just the model. Obligations narrowed: the reasonable-care duty, mandatory deployer risk-management programs, and annual impact assessments were eliminated; what remains is a notice-and-rights model, developer documentation to deployers (intended and known-harmful uses, training-data categories, limitations, human-review instructions, material-update notices, three-year record retention) and deployer duties of pre-use notice, post-adverse-decision notice, and a statutory right to "meaningful human review" after an adverse decision, AG-enforced with no private right of action (leg.colorado.gov/bills/sb26-189, T1; binding_regulation_EU_US crosswalk).
Adjacent state instruments in the cited research. Colorado insurance regulation 3 CCR 702-10 imposes governance and risk-management framework requirements on life, private-passenger auto, and health insurers' use of external consumer data, algorithms, and predictive models (sos.state.co.us 3 CCR 702-10, T1), for insurers, this sectoral rule survives regardless of the ADMT Act's arc. Maine P.L. 2025 ch. 294 requires disclosure in consumer transactions involving AI (maine.gov/pfr/consumercredit/laws_rules/new/pl294.pdf, T1). Connecticut PA 23-16 established public-sector AI inventory and impact-assessment duties (cga.ct.gov 2023 PA 23-16, T1). Illinois's SB 315 frontier-developer safety bill (compute-plus-revenue threshold, 72-hour critical-safety-incident reporting, annual third-party audits from 2027) appears in the binding-regulation crosswalk but remains provisional claim pre-enrollment; cite it as direction-of-travel, not law. The crosswalk's structural headline is worth internalizing: the EU is risk-tiered and ex-ante; Colorado pivoted to notice-and-consumer-rights; Illinois went frontier-developer safety, and every US instrument in the cohort is publicly enforced with no private right of action (binding_regulation_EU_US crosswalk).
How agents change the analysis. The ADMT Act's no-inference scope means the entire agentic decision pipeline (retrieval steps, threshold checks, tool calls) can qualify as covered technology when it materially influences a lending, insurance, or account decision about a Colorado consumer. The "meaningful human review" right is a runtime and customer-outcome obligation: someone with authority and information must actually be able to review and change the adverse outcome, which forecloses fully-autonomous adverse decisioning in covered domains. And the developer-documentation duties make Colorado a TPR checklist: if your model or agent-platform vendor markets for consequential-decision use, their statutory documentation package is an artifact your vendor-diligence file should demand.
Control families. FCO (pre-use and adverse-decision notices, meaningful human review, discrimination outcomes), RUN (human-review interposition on adverse decisions), TPR (developer documentation intake, material-update notifications), MON/ASR (three-year decision records), GOV (multi-state obligation tracking as the template spreads).
V.8 GDPR Article 22 and the automated-decision family
What it demands. GDPR Article 22 governs decisions based solely on automated processing that produce legal or similarly significant effects: the canonical interpretive source in the cited research being the Article 29 Working Party's Guidelines on Automated Individual Decision-Making and Profiling, WP251rev.01 (ec.europa.eu/newsroom/article29/items/612053, T1). The ICO's Guidance on AI and Data Protection carries the same regime into UK GDPR practice (ico.org.uk guidance on AI and data protection, T1). Detail beyond that (the precise contours of "solely automated," the human-intervention, expression-of-view, and contestation rights) should be taken from WP251 directly; this Part states them at instrument level. [practice guidance: not directly source-backed] where implementation detail below exceeds the cited texts.
The same design pattern recurs across jurisdictions in the cited research: Canada's Directive on Automated Decision-Making for federal government systems (tbs-sct.canada.ca Directive on ADM, T1; scope guide at canada.ca guide-scope-directive-automated-decision-making, T1), and, for US credit specifically, Regulation B, 12 CFR Part 1002, implementing the Equal Credit Opportunity Act, including the Section 1002.9 adverse-action notification requirements (ecfr.gov 12 CFR Part 1002, T1). Part VI develops the adverse-action and explainability thread; it is flagged here because Article 22, the Colorado ADMT human-review right, and Regulation B notifications are the same obligation shape in three legal systems: when the machine decides against the customer, a human-facing explanation and a route to human reconsideration must exist.
How agents change the analysis. The "solely automated" question becomes genuinely hard with agents. Inserting a human somewhere in an agentic pipeline does not defeat Article 22 unless the human involvement is meaningful, and an agent that assembles the entire decision file, drafts the recommendation, and queues it for one-click approval invites the argument that the human is ceremonial. Design the human checkpoint with real authority, real information, and a measured override rate (RUN), and log it (MON), or assume the decision is solely automated and build the Article 22 rights machinery instead. Agent memory adds a second wrinkle: profiles accreted across sessions are profiling under the Guidelines' subject matter, pulling agents' persistent state into data-protection scope (DES data governance).
Control families. RUN (meaningful human intervention points), FCO (explanation, contestation, adverse-action notices), DES (profiling and memory data governance, DPIA-class assessment), MON (decision and override logging as rights-response evidence).
V.9 UK and APAC pointers
United Kingdom. The UK's non-statutory, regulator-led model is documented in the government's initial guidance to regulators on implementing the AI regulatory principles (assets.publishing.service.gov.uk implementing-the-UK-AI-regulatory-principles, T1), with the ICO supplying the data-protection arm (ico.org.uk guidance on AI and data protection, T1; ICO response to the generative-AI consultation series, T1). For financial services the posture-setting text is FCA Chief Executive Nikhil Rathi's June 2026 speech at techUK's "Agents of Change" conference: with "more than 80% of financial services firms" already adopting AI, the FCA's line on agentic systems is that "accountability for regulated activities and outcomes must remain clear" (fca.org.uk/news/speeches/rethinking-regulation-age-ai, T2). Read against the Senior Managers regime, the implication for this Compendium is direct: autonomy in the agent does not move accountability off the named humans, so every control family must produce evidence attributable and reviewable by the humans who remain liable, the FCA has pre-committed to rejecting "the agent did it" as a defense.
APAC and Canada. Australia's OAIC has issued privacy guidance on both developing and training generative AI models (oaic.gov.au guidance on privacy and developing and training generative AI models, T1) and on deploying commercially available AI products (oaic.gov.au guidance on privacy and commercially available AI products, T1): a developer-side/deployer-side split that maps cleanly onto the TPR-versus-DES boundary in this catalog. Canada's federal Bill C-27, carrying the Artificial Intelligence and Data Act (parl.ca bill 44-1/c-27, T1; Charter Statement at justice.gc.ca, T1), and the in-force Directive on Automated Decision-Making (Section V.8) mark Canada's two tracks. [practice guidance: not directly source-backed]: for regional subsidiaries, treat these regimes as notice-, privacy-, and accountability-shaped rather than conformity-assessment-shaped, your EU AI Act evidence pack will over-satisfy them, but check local privacy specifics through DES data-governance controls.
V.10 The master mapping: obligation → control families → evidence
The table below is the examiner-facing summary of this Part: each recurring obligation, stated at the level the cited research supports, the control families that discharge it, and the evidence an examiner or internal audit accepts. A single well-built control program covers every row: the divergence across regimes, as the comparison below illustrates, "is in enforceability and proof, not in what counts as trustworthy" (see the framework comparison tables).
Read the policy landscape
Control themes across laws and frameworks
Select a document or document group to explore the original report’s qualitative mapping.
EU AI Act
Laws, supervisory guidance, standards, and voluntary frameworks have different force. A mark here describes editorial emphasis, not an applicable legal duty.
Read the complete mapping as text
EU AI Act
NIST AI RMF
ISO/IEC 42001 suite
SR 11-7 / OCC 2011-12
DORA
SEC/FINRA
Colorado AI Act
GDPR Art. 22
Explore the complete reference diagram
The original keeps its full size. Scroll within the frame to inspect it, or open it separately.
Qualitative synthesis · historical mappingSource edition: July 2026 · adapted September 7, 2026
Figure 5. Regulatory coverage map.
| # | Obligation | Regime anchors (as cited in this Part) | Control families | Regulator-ready evidence |
|---|---|---|---|---|
| 1 | Risk-management system / program for AI over its lifecycle | EU AI Act high-risk regime (Arts 6–49); NIST AI RMF GOVERN–MAP–MEASURE–MANAGE; ISO/IEC 42001 AIMS; SR 11-7 / SR 26-2 MRM | GOV, DES | Approved AI/MRM policy incl. agents; risk appetite statement w/ autonomy limits; RMF profile; AIMS scope + Statement of Applicability |
| 2 | Inventory and classification of AI systems / models / agents | SR 11-7 model inventory; EU AI Act Art 6 + Annex III classification (Commission Art 6 guidelines); Colorado ADMT coverage analysis | GOV | Composition-level agent inventory (model+prompts+tools+memory versions); classification memos per workflow; periodic attestation |
| 3 | Pre-deployment testing: accuracy, robustness, cybersecurity | EU AI Act Art 15; SR 11-7 / SR 26-2 independent validation; NIST TEVV; DORA resilience testing (instrument level) | EVL | Validation reports w/ effective challenge; red-team and adversarial test results; eval-validity review; go/no-go gate records |
| 4 | Technical documentation | EU AI Act Art 11 + Annex IV; GPAI docs Arts 51–53; Colorado ADMT developer documentation package | DES, ASR, TPR | Annex IV-style system file per agent workflow; vendor GPAI/ADMT documentation intake records; version history |
| 5 | Human oversight / meaningful human review | EU AI Act Art 14; Colorado SB 26-189 "meaningful human review"; GDPR Art 22 human intervention (WP251); FCA accountability posture | RUN, GOV, FCO | Oversight-mode design per autonomy tier; approval-gate logs; override-rate metrics evidencing non-ceremonial review |
| 6 | Customer transparency and notice | EU AI Act Art 50; Colorado pre-use + adverse-decision notices; Maine P.L. ch. 294 disclosure; Reg B §1002.9 adverse action | FCO, RUN | Notice templates + delivery logs; AI-content labeling config; adverse-action letter samples w/ principal reasons |
| 7 | Logging, records, retention | EU AI Act Art 18; Colorado 3-year decision records; FINRA books-and-records (Notice 24-09 reminder of existing rules) | MON, ASR | Trajectory-level action logs (WORM where required); retention schedule mapped to longest applicable clock; retrieval test results |
| 8 | Post-market / ongoing monitoring | EU AI Act Art 72; SR 11-7 / SR 26-2 ongoing monitoring; FINRA supervision & surveillance | MON | Post-market monitoring plan; drift/anomaly dashboards; surveillance sampling records of agent trajectories |
| 9 | Incident detection and reporting | EU AI Act Art 73 (~15 days); DORA incident regime (instrument level); Colorado AG notification lineage (SB 24-205 90-day); IL SB 315 72-hour (caution: provisional claim) | MON, GOV | Incident classification procedure w/ per-regime clocks; incident register; regulator notification drill records |
| 10 | Third-party / GPAI / vendor model risk | EU AI Act Arts 51–55 value chain; SR 11-7 vendor model provisions; DORA ICT third-party risk (instrument level); OAIC deployer-side guidance | TPR | Vendor diligence file incl. provider safety/GPAI artifacts; upstream change-notification SLAs; concentration analysis; exit plan |
| 11 | Independent assurance, audit, certification | EU AI Act Art 43 notified bodies; ISO/IEC 42001 certifiability (42006 chain); SR 11-7 effective challenge + internal audit | ASR | Certification/conformity records; internal-audit workpapers over the agent estate; validation independence evidence |
| 12 | Non-discrimination and fair customer outcomes | Colorado ADMT lineage + 3 CCR 702-10 (insurers); Reg B / ECOA; GDPR/ICO fairness expectations | FCO, EVL, MON | Disparate-impact testing results on agentic decision flows; fairness monitoring reports; remediation records (developed in Part VI) |
| 13 | Operational resilience incl. loss-of-agent scenarios | DORA (instrument level); FCA operational-incident posture ("98% … technology and cyber"); AI Resilience Gap analysis | RUN, MON, MAS, TPR | Kill-switch and budget-guard test evidence; degradation-to-manual runbooks; resilience-test reports covering multi-agent failure modes |
| 14 | Multi-agent and autonomy-specific governance | No regime names it yet: nearest hooks: Art 14 oversight, SR 26-2 MRM revision, FCA agentic accountability speech | MAS, GOV, RUN | Autonomy-ladder policy; inter-agent authentication/delegation design docs; MAS control test results: hold as forward evidence |
Reading the map. Rows 1–12 show heavy convergence: govern, document, test, oversee, notify, log, monitor, report, assure. Rows 13–14 are where agents outrun the instruments: resilience regimes reach agents only by analogy, and no binding instrument yet speaks to multi-agent emergence or delegation chains. That is not a reason to defer the MAS family; it is the reason to build it now, because when the guidance arrives (the SR 26-2 revision cycle and the FCA's posture are the leading indicators in this corpus), the institutions with trajectory-level evidence already on file will be the ones setting the examiner's baseline rather than chasing it.
Sources for Part V. artificialintelligenceact.eu (T1), https://artificialintelligenceact.eu/; artificialintelligenceact.eu/article/15 (T1), https://artificialintelligenceact.eu/article/15/; artificialintelligenceact.eu/article/11 (T1), https://artificialintelligenceact.eu/article/11/; ai-act-service-desk.ec.europa.eu/en/ai-act/article-16 (T1), https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-16; ai-act-service-desk.ec.europa.eu/en/ai-act/article-72 (T1), https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-72; digital-strategy.ec.europa.eu/en/policies/guidelines-ai-high-risk-systems (T1), https://digital-strategy.ec.europa.eu/en/policies/guidelines-ai-high-risk-systems; consilium.europa.eu/en/press/press-releases/2026/05/07/artificial-intelligence-council-and-parliament-agree-to-simplify-and-streamline-rules (T1, provisional claim), https://www.consilium.europa.eu/en/press/press-releases/2026/05/07/artificial-intelligence-council-and-parliament-agree-to-simplify-and-streamline-rules/; federalreserve.gov/boarddocs/srletters/2011/sr1107.htm (T1), https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107.htm; federalreserve.gov/supervisionreg/srletters/sr2602.htm (T1), https://www.federalreserve.gov/supervisionreg/srletters/SR2602.htm; federalreserve.gov/supervisionreg/srletters/sr2602.pdf (T1), https://www.federalreserve.gov/supervisionreg/srletters/SR2602.pdf; occ.gov/news-issuances/bulletins/2026/bulletin-2026-13.html (T1), https://www.occ.gov/news-issuances/bulletins/2026/bulletin-2026-13.html; fdic.gov/news/financial-institution-letters/2026/agencies-revise-interagency-model-risk-management-guidance (T1), https://www.fdic.gov/news/financial-institution-letters/2026/agencies-revise-interagency-model-risk-management-guidance; fdic.gov/news/inactive-financial-institution-letters/2017/adoption-supervisory-guidance-model-risk-management (T1), https://www.fdic.gov/news/inactive-financial-institution-letters/2017/adoption-supervisory-guidance-model-risk-management; finra.org/rules-guidance/notices/24-09 (T1), https://www.finra.org/rules-guidance/notices/24-09; finra.org/rules-guidance/guidance/reports/2026-finra-annual-regulatory-oversight-report/gen-ai (T1), https://www.finra.org/rules-guidance/guidance/reports/2026-finra-annual-regulatory-oversight-report/gen-ai; finra.org/rules-guidance/guidance/reports/2024-finra-annual-regulatory-oversight-report (T1), https://www.finra.org/rules-guidance/guidance/reports/2024-finra-annual-regulatory-oversight-report; finra.org/sites/default/files/2020-06/ai-report-061020.pdf (T1), https://www.finra.org/sites/default/files/2020-06/ai-report-061020.pdf; investor.gov/introduction-investing/general-resources/news-alerts/alerts-bulletins/investor-alerts/artificial-intelligence-fraud (T1), https://www.investor.gov/introduction-investing/general-resources/news-alerts/alerts-bulletins/investor-alerts/artificial-intelligence-fraud; leg.colorado.gov/bills/sb26-189 (T1), https://leg.colorado.gov/bills/sb26-189; leg.colorado.gov/bills/sb24-205 (T1), https://leg.colorado.gov/bills/sb24-205; content.leg.colorado.gov/sites/default/files/2024a_205_signed.pdf (T1), https://content.leg.colorado.gov/sites/default/files/2024a_205_signed.pdf; leg.colorado.gov/bills/sb25b-004 (T1), https://leg.colorado.gov/bills/sb25b-004; sos.state.co.us/ccr/generaterulepdf.do?ruleversionid=12182&filename=3%20ccr%20702-10 (T1), https://www.sos.state.co.us/CCR/GenerateRulePdf.do?ruleVersionId=12182&fileName=3%20CCR%20702-10; maine.gov/pfr/consumercredit/laws_rules/new/pl294.pdf (T1), https://www.maine.gov/pfr/consumercredit/laws_rules/new/pl294.pdf; cga.ct.gov/2023/act/pa/pdf/2023pa-00016-r00sb-01103-pa.pdf (T1), https://www.cga.ct.gov/2023/act/Pa/pdf/2023PA-00016-R00SB-01103-PA.PDF; ec.europa.eu/newsroom/article29/items/612053 (T1), https://ec.europa.eu/newsroom/article29/items/612053; ecfr.gov/current/title-12/chapter-x/part-1002 (T1), https://www.ecfr.gov/current/title-12/chapter-X/part-1002; tbs-sct.canada.ca/pol/doc-eng.aspx?id=32592 (T1), https://www.tbs-sct.canada.ca/pol/doc-eng.aspx?id=32592; canada.ca/en/government/system/digital-government/digital-government-innovations/responsible-use-ai/guide-scope-directive-automated-decision-making.html (T1), https://www.canada.ca/en/government/system/digital-government/digital-government-innovations/responsible-use-ai/guide-scope-directive-automated-decision-making.html; parl.ca/legisinfo/en/bill/44-1/c-27 (T1), https://www.parl.ca/legisinfo/en/bill/44-1/c-27; justice.gc.ca/eng/csj-sjc/pl/charter-charte/c27_1.html (T1): https://www.justice.gc.ca/eng/csj-sjc/pl/charter-charte/c27_1.html; assets.publishing.service.gov.uk/media/65c0b6bd63a23d0013c821a0/implementing_the_uk_ai_regulatory_principles_guidance_for_regulators.pdf (T1), https://assets.publishing.service.gov.uk/media/65c0b6bd63a23d0013c821a0/implementing_the_uk_ai_regulatory_principles_guidance_for_regulators.pdf; ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection (T1), https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/; ico.org.uk/about-the-ico/what-we-do/our-work-on-artificial-intelligence/response-to-the-consultation-series-on-generative-ai (T1), https://ico.org.uk/about-the-ico/what-we-do/our-work-on-artificial-intelligence/response-to-the-consultation-series-on-generative-ai/; oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/guidance-on-privacy-and-developing-and-training-generative-ai-models (T1), https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/guidance-on-privacy-and-developing-and-training-generative-ai-models; oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/guidance-on-privacy-and-the-use-of-commercially-available-ai-products (T1), https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/guidance-on-privacy-and-the-use-of-commercially-available-ai-products; fca.org.uk/news/speeches/rethinking-regulation-age-ai (T2), https://www.fca.org.uk/news/speeches/rethinking-regulation-age-ai; arxiv.org/abs/2607.07359 (T2), https://arxiv.org/abs/2607.07359; plus the framework comparison tables (covering the EU AI Act, Colorado SB 26-189, Illinois SB 315 (provisional claim), NIST AI RMF 1.0, NIST AI 600-1, ISO/IEC 42001, OECD AI Principles, and the EU HLEG Guidelines).