Pillar Guide · P5 Compliance & Governance · The Framework Layer

AI Compliance and Governance:
The Complete Enterprise Guide (2026)

AI compliance and governance have moved from legal afterthought to board-level priority. This pillar maps the full landscape — every major framework, every risk dimension, the complete governance lifecycle, and the six failures that consistently bring enterprises to grief. The parent page for every compliance and governance article in the HexTyx library.

P1 — Attack Vectors P2 — Agentic AI P3 — RAG Security P4 — Security Program P5 — Compliance P6 — Industry Verticals

Compliance vs Governance — The Key Distinction

Many organisations pursue AI compliance without AI governance. They document controls for an audit, pass the review, and then continue operating AI systems that are inconsistently managed, improperly tested, and inadequately monitored. Compliance becomes a quarterly exercise rather than an operational posture.

AI compliance is about demonstrating that specific external requirements are met — regulatory, contractual, or certification-based. AI governance is about controlling AI systems throughout their full lifecycle: who approves deployment, how risk is measured, what testing is required, how incidents are handled, and how vendors are managed. Compliance is one output of effective governance. An organisation with strong governance generates audit evidence as a natural byproduct.

The Five Pillars of AI Compliance

Risk Management

Identify, classify, and treat AI-specific risks across security, privacy, regulatory, and operational dimensions

Risk management is the foundation — without it, controls are applied inconsistently and priorities are set arbitrarily. Every AI system should be classified by data sensitivity, automation level, and business impact before any controls are designed.

Security & Assurance

Demonstrate through testing and monitoring that AI systems are resilient against the attacks they will actually face

Security assurance converts governance from documentation to evidence. Auditors, enterprise customers, and regulators increasingly ask for test results, not just policies. Red team exercises, prompt injection testing, and RAG security assessments are the evidence base.

Privacy & Data Governance

Govern what personal information AI systems collect, process, store, and share — and support all applicable consumer rights

AI systems generate new categories of personal information (inferences, profiles, behavioural patterns) that many compliance programmes haven't yet accounted for. GDPR, CCPA, and state privacy laws all apply to these AI-generated data types.

Regulatory Compliance

Meet the specific legal and industry obligations applicable to your AI systems based on geography, sector, and use case

No single framework covers everything. Most enterprises need to address multiple frameworks simultaneously — global standards, data privacy laws, and industry-specific regulations. The correct approach: build a governance foundation first, then map it to each applicable framework.

Accountability & Oversight

Assign clear ownership for every AI system and create the reporting structures that keep boards, executives, and auditors informed

When an AI incident occurs, accountability determines response speed. When auditors review controls, ownership documentation determines whether evidence can be produced. When boards ask about AI risk, oversight structures determine whether accurate information reaches them.

Major AI Compliance Frameworks

️ NIST AI RMF

The most widely referenced AI governance framework in US enterprise procurement. Four functions: Govern, Map, Measure, Manage. Provides a comprehensive risk management vocabulary.

When required: US federal contracts, enterprise B2B sales, foundational governance baseline
Implementation guide →

🇪🇺 EU AI Act

Risk-based regulation: Prohibited, High-Risk, Limited Risk, and Minimal Risk tiers. High-risk systems face extensive compliance requirements. In force across the EU from 2025.

When required: Any AI deployed in Europe or serving EU users
Compliance guide →

ISO 27001

Information security management system standard. Covers AI as part of broader information security governance. Required by many enterprise customers as a procurement prerequisite.

When required: Enterprise B2B sales, European customers, formal ISMS certification
AI implementation guide →

SOC 2

Trust Services Criteria covering security, availability, confidentiality, and privacy. Enterprise SaaS customers require SOC 2 Type II. Increasingly includes AI-specific criteria.

When required: SaaS companies selling to enterprises, US B2B market
SOC 2 for AI products →

Privacy Frameworks

GDPR (EU, 72-hour breach notification), CCPA/CPRA (California, AI inferences as personal information), and expanding US state privacy laws — all apply when AI processes personal data.

When required: Any AI processing personal data of EU or US residents
GDPR + AI guide →

Industry Regulations

FedRAMP (government cloud), PCI DSS v4 (payment environments), HIPAA (healthcare), DORA (EU financial services) — each sector adds its own AI-specific obligations on top of general frameworks.

When required: Industry-specific deployments
Industry compliance guide →

The AI Governance Lifecycle

Stage 1

Design

Use-case approval, risk assessment, data review, vendor evaluation. Governance starts before a line of code is written.

Stage 2

Development

Security controls integrated into the build. Documentation created. Testing procedures defined.

Stage 3

Validation

Red teaming, security testing, compliance review. Fixes before deployment, not after.

Stage 4

Deployment

Approval workflows, monitoring setup, risk acceptance documented. No deployment without owner sign-off.

Stage 5

Operations

Continuous monitoring, incident response readiness, audit evidence collection. Governance as ongoing practice.

Stage 6

Retirement

Data deletion, archive management, risk closure. GDPR and CCPA deletion obligations extend to AI storage.

The Six Most Common Governance Failures

No AI inventory

Unknown systems cannot be governed, tested, or monitored. Most organisations deploying AI at scale have significantly more AI usage than their governance team is aware of — especially shadow AI.

No risk classification

Without risk tiers, controls are applied inconsistently — over-engineered for low-risk systems, under-engineered for high-risk ones. Risk classification is the prerequisite for proportionate governance.

No security testing

AI vulnerabilities remain undiscovered until exploited in production. Auditors and enterprise customers are now asking for test results, not just policies. Testing evidence is the gap most organisations discover during enterprise procurement reviews.

No vendor assessment

Third-party AI providers handling sensitive data without contracts, data retention reviews, training data policies, or security certifications. Third-party risk is the fastest-growing category in AI governance failures.

No monitoring

AI incidents go undetected because no one is watching prompt logs, output logs, or agent behaviour. The median time to detect an AI incident in an unmonitored deployment is measured in weeks — not hours.

No accountability

No designated owner for AI systems means no one responds when something goes wrong, no one collects audit evidence, and no one updates controls as systems change. Every AI system needs a named owner.

Benchmark Your AI Compliance Posture

The HexTyx AI Security Assessment evaluates your governance readiness, security controls, compliance gaps, and agent security — mapped to NIST AI RMF and major frameworks. Free, 10 minutes.

Enterprise AI Compliance Checklist

Governance Foundation

AI inventory complete and current
Risk classifications applied to all systems
Policies documented and communicated
Ownership assigned per system

Security & Testing

AI security testing completed pre-deployment
Prompt injection testing with documented results
Agent security and RAG access control validated
Runtime monitoring active

Privacy & Data

Personal data mapped across all AI storage
AI-generated inferences classified as PI
Retention and deletion policies defined
Consumer rights infrastructure in place

Frameworks & Vendors

Applicable regulations identified and mapped
Audit evidence collected and retained
Third-party AI vendors assessed
DPAs executed with all AI vendors handling PI

Frequently Asked Questions

What is AI compliance?
AI compliance refers to the processes, controls, policies, and evidence organisations use to demonstrate that AI systems meet legal, regulatory, contractual, and organisational requirements. It is distinct from traditional software compliance because AI systems generate inferences, operate autonomously, and create new categories of personal information — all of which trigger obligations that were not contemplated when most compliance frameworks were written.
Which compliance framework should I start with?
Start with NIST AI RMF as your governance foundation — it provides the most comprehensive structure for AI risk management and is widely referenced in US enterprise procurement. Then layer on the frameworks applicable to your situation: EU AI Act if you operate in Europe, ISO 27001 if you sell to enterprise customers, SOC 2 if you're a SaaS company, and industry-specific requirements (HIPAA, PCI DSS, FedRAMP) based on your sector.
How often should AI compliance be reviewed?
AI systems change more frequently than traditional software — model updates, new integrations, expanded data sources, and new features all change the risk profile. Minimum cadence: monthly AI inventory check; quarterly permission review, vendor review, and policy review; semi-annual full security assessment; annual comprehensive governance review. Any significant change (new model version, new data sources, new agent capabilities) triggers an immediate review regardless of the regular schedule.

Explore the Compliance Deep-Dives

Global Frameworks
EU AI Act Compliance →
Global Frameworks
NIST AI RMF Guide →
AI Governance
AI Governance for CISOs →
Industry Compliance
FedRAMP for AI Systems →
Privacy
CCPA + US Privacy Laws →
Full Library
All 16 Compliance Guides →