Skip to contentThe Observability LayerSearch

Enterprise handbook · Section 18 of 30

16. Regulatory and standards scope

This table distinguishes regulatory text, official implementation information, supervisory guidance, draft rules, and voluntary technical documentation. Applicability still depends on the entity, jurisdiction, role, decision, and data. This chapter supplies an implementation crosswalk rather than a comprehensive legal opinion.

Evidence table: Instrument or source, Status and verified point, Enterprise action, Related handbook families
Instrument or sourceStatus and verified pointEnterprise actionRelated handbook families
US bank model-risk guidanceSR 26-2, issued 17 April 2026, replaces SR 11-7 and SR 21-8. Its attachment excludes generative and agentic AI from scope. [S31, S32]Document the institution's agent governance standard separately and explain which model-risk disciplines it elects to reuse. Assess any conventional quantitative models inside the workflow on their own terms.H-GOV, H-ASR
EU AI Act / AI OmnibusThe Commission reports entry into force on 27 July 2026 and application of Annex III high-risk rules from 2 December 2027, with high-risk AI embedded in Annex I products from 2 August 2028. [S33]Maintain an obligation-specific calendar. Distinguish those dates from other already applicable provisions and role-specific duties. Obtain the controlling consolidated text before issuing an article-level compliance determination.H-GOV, H-ASR, H-MON, H-FCO
Colorado ADMTThe official bill page identifies SB26-189 as enacted. The Attorney General states the new provisions take effect 1 January 2027. [S34, S35]Classify consequential-decision influence and the developer/deployer role. Implement the relevant notice, review, correction, and evidence workflows after legal applicability review.H-FCO, H-TPR
Colorado implementing rulesThe Attorney General identifies the 11 August 2026 ADMT and chatbot rules as proposed drafts, with comments through 26 October 2026. [S35]Track the final rule. Do not represent a draft-specific requirement as enacted law.H-GOV, H-ASR
California CCPA ADMTFinal regulations section 7200 sets compliance for covered significant-decision ADMT from 1 January 2027. [S36, S41]Assess covered business status, the ADMT use, and applicable exemptions. Review sector/data exemptions individually; avoid assuming all financial-sector processing is exempt.H-FCO, H-DES
US credit adverse-action noticesRegulation B section 1002.9 supplies the governing notification and reasons provisions. [S37]Preserve actual reasons and verify agent-assisted notices against them.H-FCO
NIST agent identity workSeptember project outputs and public-comment summaries support implementation development. They are not a completed certification standard. [S25, S26]Track the DevSecOps demonstration and validate the local identity/delegation design now.H-DES, H-MAS
MCP 2026-07-28Released protocol and authorization documentation; protocol requirements apply to implementations claiming conformance. They are not legislation. [S27, S28]Pin deployed versions and test migration, audience/issuer checks, explicit state, and authorization boundaries.H-RUN, H-TPR
OWASP ACSVoluntary runtime-control interface; inspected repository version 0.1.0. [S29, S30]Establish per-framework hook coverage and bypass tests before claiming enforcement.H-RUN, H-MON, H-TPR
OpenTelemetry GenAI attributesThe inspected registry marks relevant agent/tool operation attributes as Development. [S42]Version the telemetry mapping; supplement it with institution-specific control and effect fields.H-RUN, H-MON

The EU legislative links returned an access/anti-bot limitation during this review. The timeline above is attributed to the Commission's official implementation page; this report does not claim a completed review of the amending or consolidated regulation. Colorado and California draft/final status and dates are stated at the inspected source level. Avoid placing one jurisdiction's record-retention or incident-reporting clock on every enterprise agent.

16.1 Foundational voluntary references

NIST AI RMF 1.0, its Generative AI Profile, the OECD AI Principles, and OWASP agent security guidance supply different forms of context. They are voluntary references; this handbook does not assert certification, complete clause coverage, or legal compliance from using its practices. Record which version and scope the enterprise adopts, and distinguish its internal policy commitments from external duties. [S43, S44, S45, S46, S47]