Most organizations know they need to establish AI governance, but many are struggling with the same question: How do you build a governance program when the regulatory landscape is constantly changing?
Between evolving federal priorities, a growing patchwork of state legislation, and changing industry expectations, it can be difficult to tell which requirements will stick and ultimately shape AI compliance. As a result, many organizations are delaying governance investments until there is more regulatory clarity.
Despite this ongoing uncertainty, organizations that delay establishing AI governance risk being perpetually on the defense, reacting to each new regulatory development instead of building lasting governance capabilities. Rather than designing governance programs around individual laws, leading organizations are staying ahead by building adaptable governance frameworks that can evolve alongside changing requirements. The focus should be less on predicting which regulations will survive and more on establishing the governance structures, accountability mechanisms, risk assessments, and oversight processes that will remain valuable regardless of how the regulatory landscape develops.
Navigating a Shifting Regulatory Landscape
The pace of AI regulation in the United States has accelerated dramatically, creating a complex compliance landscape for organizations developing or deploying AI systems and looking to establish governance. By the end of 2025, all 50 states had proposed at least one AI bill, and more than 145 had been enacted. In 2026, lawmakers in 45 states introduced more than 1,500 additional AI-related bills, exceeding the total legislative activity from just two years earlier.
Colorado is an example of how quickly the landscape can change. Before its AI Act took effect, lawmakers repealed and replaced it with a narrower law focused primarily on transparency and disclosures for automated decision-making systems. Instead of converging around a single regulatory model, states are pursuing a range of approaches, from comprehensive laws governing high-risk AI systems to foundation model regulations and sector-specific requirements addressing algorithmic hiring, AI transparency, deepfakes, and AI-generated voice cloning.
At the same time, the federal approach to AI regulation continues to evolve. In June 2026, the Trump administration issued an executive order establishing a voluntary framework for collaboration with AI developers on certain frontier AI models to strengthen cybersecurity and support secure AI development. Meanwhile, states continue to enact, revise, and introduce their own AI laws, reinforcing the fragmented and rapidly evolving regulatory landscape organizations must navigate. Together, these developments reinforce an important reality. Today’s requirements may not reflect tomorrow’s expectations, and governance programs built around a single law or jurisdiction will quickly become outdated. Instead of trying to predict every regulatory shift, organizations should build adaptable governance capabilities that evolve with the regulatory landscape.
Designing Governance for a Moving Target
The question, then, is what those adaptable governance capabilities should include. While regulatory requirements continue to evolve, the underlying governance expectations remain remarkably consistent. Across jurisdictions, organizations are expected to establish clear accountability, documented oversight, risk assessments, transparency, human oversight, and well-defined decision-making processes. Collectively, these capabilities help ensure AI systems are fair, transparent, accountable, and subject to appropriate human oversight, supporting the responsible development and use of AI regardless of how individual laws change.
Rather than building governance programs around a specific regulation, organizations should establish principles-based governance frameworks that remain effective regardless of which laws ultimately take effect. Organizations that focus on building core governance capabilities will be better positioned to adapt without redesigning their programs each time the regulatory landscape changes.
Establishing the Operating Model Behind Effective AI Governance
Adaptable AI governance requires more than policies and procedures. It requires an operating model that defines how governance decisions are made, who is responsible for making them, and how oversight is embedded into day-to-day business operations.
That starts with establishing clear ownership, creating cross-functional governance committees, documenting AI use cases, maintaining an inventory of AI systems, defining review and approval processes, and embedding governance into existing business operations. These foundational elements create consistency across the organization while providing the flexibility to incorporate new regulatory requirements as they emerge. When governance becomes part of how decisions are made rather than a collection of compliance documents, adapting to regulatory change becomes far more manageable.
Technology plays an important role in AI governance, but technology alone cannot determine whether AI is being used responsibly. Effective governance requires visibility into what AI systems are being used, how they are being used, and the risks they present. Organizations should maintain an inventory of AI systems and evaluate each use case based on its potential impact so governance efforts are proportionate to risk. High-impact AI systems, such as those processing sensitive data, influencing financial or employment decisions, or supporting critical business operations, warrant more rigorous oversight than lower-risk applications.
With AI use cases identified and prioritized, organizations can establish governance processes with clearly defined decision-making authority. Every governance program should assign accountability for evaluating, approving, monitoring, and periodically reassessing AI systems throughout their lifecycle. It should also define who has the authority to approve new use cases, determine acceptable levels of risk, escalate concerns, and oversee ongoing performance.
Without clearly assigned responsibilities, governance becomes fragmented across legal, compliance, security, IT, procurement, and business teams, leading to inconsistent decisions, duplicated effort, and uncertainty about who is ultimately accountable. Effective AI governance depends on a structure that makes accountability clear, consistent, and repeatable.
Going Beyond Traditional Risk Management
Many organizations begin their AI governance journey by looking to existing security, risk, or compliance programs. While those programs provide a strong foundation, AI introduces governance challenges that extend beyond traditional risk management and require new capabilities.
Cybersecurity focuses on protecting systems and information. AI governance must also address how automated decisions are made, what level of human oversight is appropriate, how fairness and transparency are evaluated, and how organizations assess the potential impact AI systems may have on employees, customers, and society.
With AI introducing new operational, legal, and ethical risks, governance must become an ongoing decision-making process rather than a one-time compliance exercise. The objective is not simply to document controls but to establish a repeatable framework for evaluating AI as technology, business objectives, and regulatory expectations continue to evolve.
AI Governance Is Becoming a Business Requirement
Waiting for regulatory clarity also overlooks another important reality. The demand for AI governance is increasingly being driven by customers, procurement teams, business partners, and other stakeholders who want confidence that AI is being developed and used responsibly.
Organizations are beginning to encounter AI governance questions during vendor assessments, procurement reviews, and contract negotiations. Programs such as Microsoft’s Supplier Security and Privacy Assurance (SSPA) Program now require suppliers to provide certifications or other evidence of AI governance, signaling that buyers expect governance to be demonstrated, not simply asserted. Organizations that cannot provide this evidence may find themselves at a disadvantage in competitive procurements and vendor evaluations.
For many organizations, these business expectations will materialize well before formal regulatory enforcement. As a result, AI governance is becoming a competitive differentiator that strengthens customer trust and supports long-term business relationships.
Build on a Proven Governance Framework
The next question is how organizations can operationalize these governance principles in a way that remains sustainable as technology, business priorities, and regulations evolve. Many organizations are finding that established frameworks such as ISO/IEC 42001 provide that foundation. Rather than focusing on compliance with a single regulation, these frameworks establish consistent governance practices for accountability, risk management, oversight, and continual improvement that can be applied across jurisdictions.
Building governance around a recognized framework creates stability in a constantly changing environment. Rather than redesigning governance programs each time new requirements emerge, organizations can incorporate new legal obligations into an established governance model while continuing to mature their governance capabilities over time.
Organizations that are leading in AI governance recognize that it is more than a compliance exercise. They treat governance as the foundation for building trust, strengthening accountability, and enabling the responsible adoption of AI across the business. Achieving that level of maturity requires ongoing investment in people, processes, and technology, along with a commitment to continually review and refine governance as AI capabilities, business priorities, and regulatory expectations evolve.
The regulatory landscape will continue to evolve, and organizations cannot afford to wait for complete clarity before taking action. The strongest approach is to invest now in governance capabilities that will remain valuable regardless of how regulatory requirements develop. Establishing governance structures, defining AI use cases, conducting risk and impact assessments, documenting decisions, and embedding continual oversight creates a foundation that can adapt as expectations change.
Accountability, oversight, risk management, documented decision-making, and continual improvement are not simply compliance requirements. They are the enduring capabilities of responsible AI governance. Organizations that build them today will be better positioned to meet future regulatory obligations, satisfy growing customer expectations, and deploy AI with greater confidence.

