This table distinguishes regulatory text, official implementation information, supervisory guidance, draft rules, and voluntary technical documentation. Applicability still depends on the entity, jurisdiction, role, decision, and data. This chapter supplies an implementation crosswalk rather than a comprehensive legal opinion.
| Instrument or source | Status and verified point | Enterprise action | Related handbook families |
|---|---|---|---|
| US bank model-risk guidance | SR 26-2, issued 17 April 2026, replaces SR 11-7 and SR 21-8. Its attachment excludes generative and agentic AI from scope. [S31, S32] | Document the institution's agent governance standard separately and explain which model-risk disciplines it elects to reuse. Assess any conventional quantitative models inside the workflow on their own terms. | H-GOV, H-ASR |
| EU AI Act / AI Omnibus | The Commission reports entry into force on 27 July 2026 and application of Annex III high-risk rules from 2 December 2027, with high-risk AI embedded in Annex I products from 2 August 2028. [S33] | Maintain an obligation-specific calendar. Distinguish those dates from other already applicable provisions and role-specific duties. Obtain the controlling consolidated text before issuing an article-level compliance determination. | H-GOV, H-ASR, H-MON, H-FCO |
| Colorado ADMT | The official bill page identifies SB26-189 as enacted. The Attorney General states the new provisions take effect 1 January 2027. [S34, S35] | Classify consequential-decision influence and the developer/deployer role. Implement the relevant notice, review, correction, and evidence workflows after legal applicability review. | H-FCO, H-TPR |
| Colorado implementing rules | The Attorney General identifies the 11 August 2026 ADMT and chatbot rules as proposed drafts, with comments through 26 October 2026. [S35] | Track the final rule. Do not represent a draft-specific requirement as enacted law. | H-GOV, H-ASR |
| California CCPA ADMT | Final regulations section 7200 sets compliance for covered significant-decision ADMT from 1 January 2027. [S36, S41] | Assess covered business status, the ADMT use, and applicable exemptions. Review sector/data exemptions individually; avoid assuming all financial-sector processing is exempt. | H-FCO, H-DES |
| US credit adverse-action notices | Regulation B section 1002.9 supplies the governing notification and reasons provisions. [S37] | Preserve actual reasons and verify agent-assisted notices against them. | H-FCO |
| NIST agent identity work | September project outputs and public-comment summaries support implementation development. They are not a completed certification standard. [S25, S26] | Track the DevSecOps demonstration and validate the local identity/delegation design now. | H-DES, H-MAS |
| MCP 2026-07-28 | Released protocol and authorization documentation; protocol requirements apply to implementations claiming conformance. They are not legislation. [S27, S28] | Pin deployed versions and test migration, audience/issuer checks, explicit state, and authorization boundaries. | H-RUN, H-TPR |
| OWASP ACS | Voluntary runtime-control interface; inspected repository version 0.1.0. [S29, S30] | Establish per-framework hook coverage and bypass tests before claiming enforcement. | H-RUN, H-MON, H-TPR |
| OpenTelemetry GenAI attributes | The inspected registry marks relevant agent/tool operation attributes as Development. [S42] | Version the telemetry mapping; supplement it with institution-specific control and effect fields. | H-RUN, H-MON |
The EU legislative links returned an access/anti-bot limitation during this review. The timeline above is attributed to the Commission's official implementation page; this report does not claim a completed review of the amending or consolidated regulation. Colorado and California draft/final status and dates are stated at the inspected source level. Avoid placing one jurisdiction's record-retention or incident-reporting clock on every enterprise agent.
16.1 Foundational voluntary references
NIST AI RMF 1.0, its Generative AI Profile, the OECD AI Principles, and OWASP agent security guidance supply different forms of context. They are voluntary references; this handbook does not assert certification, complete clause coverage, or legal compliance from using its practices. Record which version and scope the enterprise adopts, and distinguish its internal policy commitments from external duties. [S43, S44, S45, S46, S47]