Skip to main content
Regulome
Search the register
For ProvidersRun the free checker

Showing 36 of 36 articles.

Compliance Guides

Colorado AI Act Compliance Checklist (Built From the SB 26-189 Text)

A checklist for the law as it actually stands after the May 2026 repeal and reenactment, not the 2024 version. Effective January 1, 2027.

10 min read

Compliance Guides

Colorado No Longer Requires an AI Impact Assessment

The impact assessment was the centrepiece of the 2024 Colorado AI Act. SB 26-189 repealed and reenacted the statute without it. Here is what the obligation was, what replaced it, and what to do with the work already done.

6 min read

Compliance Guides

How to Prepare for the Colorado AI Act After the SB 26-189 Rewrite

The statute was repealed and reenacted in May 2026. Preparation built for the 2024 law targets obligations that no longer exist. Five steps for the law as it stands.

8 min read

Compliance Guides

Colorado’s NIST Safe Harbor Was Repealed. Here’s What Replaced It.

The 2024 Colorado AI Act gave a rebuttable presumption of reasonable care to deployers running a NIST AI RMF program. SB 26-189 did not carry it forward. There is no safe harbor in current Colorado law.

6 min read

Industry News

Texas TRAIGA vs Colorado: The Two State AI Laws Have Diverged

Texas never passed the Colorado-style HB 1709. It passed TRAIGA, an intent-based law in force since January 2026 that kept the NIST safe harbor Colorado repealed. Building to one no longer prepares you for the other.

7 min read

Compliance Guides

AI Bias Audit: What It Is, How It Works, and What It Costs in 2026

A complete guide to AI bias audits, what they test, which laws require them, the 5-step audit process, how to choose an auditor, and what to expect on cost and timing in 2026.

9 min read

Compliance Guides

AI Compliance Checklist 2026: 7 Steps Every Business Needs

A practical AI compliance checklist for 2026, covering inventory, risk classification, impact assessments, governance, bias audits, documentation, and ongoing monitoring. Includes Colorado, EU AI Act, and ISO 42001 requirements.

8 min read

Industry News

Colorado AI Act: Readiness Update After SB 26-189

The effective date has moved to January 1, 2027 under SB 26-189. Here’s where organizations stand and what the extended timeline means.

5 min read

Compliance Guides

ISO 42001 Checklist: 48 Requirements for AI Management System Certification

A complete ISO 42001 checklist covering all 48 requirements across 7 phases, from context and leadership through operations, performance evaluation, and improvement. Use this to prepare for certification audits.

9 min read

Regulation Analysis

Virginia HB 2094: Vetoed, What It Means for AI Compliance

Governor Youngkin vetoed Virginia's AI regulation bill on March 24, 2025. Here's what the bill proposed, why it was vetoed, and what Virginia businesses should watch for next.

6 min read

Compliance Guides

Hiring AI Compliance in 2026: The Complete Starter Kit

Which roles to hire first, what skills actually matter, realistic salary ranges, and interview questions that separate genuine AI compliance expertise from resume inflation.

14 min read

Compliance Guides

What to Expect When You Request an AI Bias Audit

A practical walkthrough of the RFQ process for an AI bias audit: what auditors assess, typical timelines and costs, and the right questions to ask.

7 min read

Compliance Guides

NIST AI RMF Explained: A Compliance Team's Field Guide

What the NIST AI Risk Management Framework is, how its four core functions work, and how it maps to the EU AI Act and Colorado requirements.

9 min read

Regulation Analysis

EU AI Act GPAI Rules: What Foundation Model Developers Must Do Now

The general-purpose AI (GPAI) model provisions of the EU AI Act are now in effect. Here's what developers and deployers of foundation models need to know.

11 min read

Enforcement Updates

NYC LL 144 Enforcement: First Fines Issued, What Happened and What It Means

New York City has begun enforcing Local Law 144. We break down the first enforcement actions and what employers need to fix immediately.

6 min read

Compliance Guides

How to Commission a Bias Audit: A Step-by-Step Guide for Employers

If you use AI tools for hiring in NYC or Colorado, you need a bias audit. Here's exactly how to find an auditor, what the process looks like, and how to post results.

14 min read

Compliance Guides

The Human-in-the-Loop Test Under California’s ADMT Rules

California’s ADMT rules require meaningful human oversight for certain automated decisions. Here’s what that actually means in practice and how to build a compliant human review process.

6 min read

Comparison

CCPA ADMT vs. NYC Local Law 144: Two Models for Automated Decision Regulation

California and New York City both regulate automated decision-making, but with fundamentally different approaches. Here’s how they compare and what it means for businesses operating in both.

7 min read

Regulation Analysis

CCPA ADMT Final Rules: What AI Teams Need to Know

California’s Automated Decision-Making Technology rules took effect in 2026. Here’s what the final rules require, who they cover, and what your AI team needs to do to comply.

8 min read

Compliance Guides

Building an AI Governance Program: The Practical Guide for Mid-Size Companies

You don't need a team of 10 to build an effective AI governance program. This guide covers the essentials: policy, inventory, risk assessment, and documentation.

16 min read

Regulation Analysis

The EU AI Act GPAI Code of Practice Finally Drops: What It Means for AI Companies

The EU AI Office has published the General-Purpose AI Code of Practice. Here’s what it requires, who it applies to, and what foundation model developers must do before the August 2025 deadline.

9 min read

Compliance Guides

The Four Core Functions of NIST AI RMF, Walked Step-by-Step

GOVERN, MAP, MEASURE, MANAGE, the NIST AI Risk Management Framework’s four functions form a complete AI governance cycle. Here’s what each means in practice and how to implement them.

10 min read

Regulation Analysis

How ISO 42001 Aligns with the EU AI Act

ISO/IEC 42001 is a candidate harmonized standard for the EU AI Act. Here’s how the two frameworks map to each other and what ISO 42001 certification means for EU AI Act conformity.

6 min read

Compliance Guides

ISO 42001 Certification: What to Expect from the Audit

ISO/IEC 42001 is the first international standard for AI management systems, and certification is now available from accredited bodies. Here’s what the audit process looks like and how to prepare.

8 min read

Regulation Analysis

The EU AI Act High-Risk AI System List, Annotated

Annex III of the EU AI Act lists the specific categories of high-risk AI systems. Here’s every category explained, with practical examples of what falls in and what doesn’t.

11 min read

Compliance Guides

NIST AI RMF vs. ISO 42001: Which Framework Fits Your Organization?

Both NIST AI RMF and ISO 42001 are legitimate AI governance frameworks, but they serve different purposes. Here’s how to choose the right one, and when you might need both.

7 min read

Comparison

EU AI Act vs. UK AI Safety Bill: Where the Rules Overlap

The EU went with a comprehensive AI law. The UK is taking a different path with sector-specific guidance. Here’s how the two approaches compare and what it means for companies operating in both markets.

8 min read

Compliance Guides

The NYC Local Law 144 Bias Audit, Walked Step-by-Step

If you use AI in hiring in New York City, you need an annual bias audit. Here’s exactly how the audit process works, from finding an auditor to publishing the results.

8 min read

Compliance Guides

AIVIRA Obligations for Employers: The Practical Guide

Illinois’ Artificial Intelligence Video Interview Act has been in force since 2020 and class action exposure has grown. Here’s exactly what employers must do before using AI to evaluate video interviews.

7 min read

Regulation Analysis

California AB 2013: Training Data Disclosure Requirements for AI Systems

California AB 2013 requires generative AI providers to post documentation about their training data. Here’s who it covers, what must be disclosed, and what the effective date means for your compliance roadmap.

6 min read

Regulation Analysis

GDPR vs. EU AI Act: Where the Rules Overlap

Both GDPR and the EU AI Act apply to many AI systems. Here’s how they interact, where they duplicate obligations, and what you need to do to satisfy both simultaneously.

9 min read

Comparison

BIPA vs. CUBI: Two Biometric Laws, Two Very Different Enforcement Models

Illinois and Texas both restrict biometric data, but their laws work completely differently. Here’s a side-by-side comparison and what each means for companies operating in both states.

6 min read

Enforcement Updates

Texas AG vs. Meta: The $1.4B Biometric Settlement Explained

In 2024, Meta settled Texas’s biometric privacy lawsuit for $1.4 billion, the largest privacy settlement in US history. Here’s what happened, what Texas proved, and what it means for companies using facial recognition.

7 min read

Enforcement Updates

BIPA Class Actions in 2025: What Employers Need to Know

Illinois BIPA litigation generated billions in settlements. Here’s what happened in 2025, where the law stands after the 2023 Cothron ruling, and what employers must do to limit exposure.

7 min read

Enforcement Updates

Clearview AI GDPR Fines Across Europe: What the Enforcement Pattern Tells Us

Clearview AI has faced GDPR enforcement actions across the EU totaling hundreds of millions of euros in fines. Here’s what the cases reveal about how regulators are approaching AI and biometric data.

6 min read

Regulation Analysis

The Biometric Privacy Law Patchwork, Mapped

Illinois BIPA is the most litigated biometric law, but it’s not alone. Here’s a map of every state biometric privacy law, what each requires, how they differ, and which create the most compliance risk.

8 min read

The weekly digest

Regulation changes, deadlines ahead, and enforcement news from the register. Free, unsubscribe anytime.