Skip to main content
Regulome
Search regulations…⌘K
For ProvidersFree Checker
Vol. I · № 37Regulome · Sunday, 31 May 2026Free to read · No tracking

The Ledger.

A record of AI & compliance regulation, annotated weekly.

Enforcement · Analysis · Guides37 articles · updated weeklyregulome.com/blog
§ CHECKLISTCOMPLIANCE GUIDESPLATE № 366ISO-42001 · 2026REGULOME
▸ Lead · Compliance Guides

ISO 42001 Checklist: 48 Requirements for AI Management System Certification

A complete ISO 42001 checklist covering all 48 requirements across 7 phases—from context and leadership through operations, performance evaluation, and improvement.

·9 min read
Compliance Guides

AI Compliance Checklist 2026: 7 Steps Every Business Needs

A practical AI compliance checklist for 2026—covering inventory, risk classification, impact assessments, governance, bias audits, documentation, and ongoing monitoring.

·8 min read
Compliance Guides

AI Bias Audit: What It Is, How It Works, and What It Costs in 2026

A complete guide to AI bias audits—what they test, which laws require them, the 5-step audit process, how to choose an auditor, and what to expect on cost and timing.

·9 min read
Compliance Guides

Hiring AI Compliance in 2026: The Complete Starter Kit

Which roles to hire first, what skills actually matter, realistic salary ranges, and interview questions that separate genuine AI compliance expertise from resume inflation.

·14 min read
Compliance Guides

Colorado AI Act Compliance Checklist (SB 24-205, Updated for SB 26-189)

Step-by-step checklist to prepare for the Colorado AI Act. Updated May 2026: SB 26-189 moves the effective date to January 1, 2027.

·10 min read
Compliance Guides

How to Prepare for the Colorado AI Act (Updated for SB 26-189)

A practical 5-step preparation guide for Colorado deployers. Updated: effective date moved to January 1, 2027 under SB 26-189.

·8 min read
Regulation Analysis

Virginia HB 2094: Vetoed — What It Means for AI Compliance

Governor Youngkin vetoed Virginia’s AI regulation bill on March 24, 2025. Here’s what the bill proposed, why it was vetoed, and what Virginia businesses should watch for next.

·6 min read
Compliance Guides

What to Expect When You Request an AI Bias Audit

A practical walkthrough of the RFQ process for an AI bias audit: what auditors assess, typical timelines and costs, and the right questions to ask.

·7 min read
Compliance Guides

NIST AI RMF Explained: A Compliance Team’s Field Guide

What the NIST AI Risk Management Framework is, how its four core functions work, and how it maps to the EU AI Act and Colorado requirements.

·9 min read
Compliance Guides

Colorado AI Act: New January 1, 2027 Deadline Under SB 26-189

The Colorado AI Act has been substantially rewritten by SB 26-189. New effective date is January 1, 2027. Here’s what changed and what you need to do.

·8 min read
Regulation Analysis

EU AI Act GPAI Rules: What Foundation Model Developers Must Do Now

The general-purpose AI (GPAI) model provisions of the EU AI Act are now in effect. Here’s what developers and deployers of foundation models need to know.

·11 min read
Enforcement Updates

NYC LL 144 Enforcement: First Fines Issued — What Happened and What It Means

New York City has begun enforcing Local Law 144. We break down the first enforcement actions, the amounts fined, and what employers need to fix immediately.

·6 min read
Compliance Guides

How to Commission a Bias Audit: A Step-by-Step Guide for Employers

If you use AI tools for hiring in New York City or Colorado, you need a bias audit. Here’s exactly how to find an auditor, what the process looks like, and how to post results.

·14 min read
Industry News

Texas AI Bill HB 1709 Update: What It Would Mean for US Businesses

Texas is moving toward its own AI regulation modeled on Colorado. Here’s what the bill proposes, where it stands, and how to prepare if you operate in Texas.

·7 min read
Compliance Guides

Building an AI Governance Program: The Practical Guide for Mid-Size Companies

You don’t need a team of 10 to build an effective AI governance program. This guide covers the essentials: policy, inventory, risk assessment, and documentation.

·16 min read
Regulation Analysis

CCPA ADMT Final Rules: What AI Teams Need to Know

California’s Automated Decision-Making Technology rules are now in force. Here’s what they require, who they cover, and what your AI team must do to comply.

·8 min read
Comparison

CCPA ADMT vs. NYC LL 144: Two Models for Automated Decision Regulation

California and New York City both regulate automated decisions, but with fundamentally different approaches. Side-by-side comparison for employers operating in both.

·7 min read
Compliance Guides

The Human-in-the-Loop Test Under California’s ADMT Rules

California’s ADMT rules require meaningful human oversight for certain automated decisions. Here’s what “meaningful” actually means and how to build a compliant review process.

·6 min read
Compliance Guides

Colorado AI Act Safe Harbor: What NIST AI RMF Alignment Actually Means

Colorado offers a safe harbor to businesses that align with NIST AI RMF. Here’s what that requires in practice and how to document it for enforcement.

·7 min read
Compliance Guides

The Four Core Functions of NIST AI RMF, Walked Step-by-Step

GOVERN, MAP, MEASURE, MANAGE — what each function actually requires in practice and how to implement them in your AI governance program.

·10 min read
Compliance Guides

NIST AI RMF vs. ISO 42001: Which Framework Fits Your Organization?

Both are legitimate AI governance frameworks — but they serve different purposes. Here’s how to choose, and when you might need both.

·7 min read
Compliance Guides

ISO 42001 Certification: What to Expect from the Audit

ISO 42001 is the first certifiable AI management system standard. Here’s what the audit process looks like, what auditors check, and how to prepare.

·8 min read
Regulation Analysis

How ISO 42001 Aligns with the EU AI Act

ISO 42001 is a candidate harmonized standard for the EU AI Act. Here’s how they map to each other and what certification means for EU conformity.

·6 min read
Regulation Analysis

The EU AI Act GPAI Code of Practice Finally Drops

The EU AI Office published the GPAI Code of Practice. Here’s what it requires for Tier 1 and Tier 2 GPAI providers and what foundation model developers must do.

·9 min read
Regulation Analysis

The EU AI Act High-Risk AI System List, Annotated

Every Annex III high-risk AI category explained with practical examples of what’s in scope and what’s not — for compliance teams who need to classify their systems.

·11 min read
Comparison

EU AI Act vs. UK AI Safety Bill: Where the Rules Overlap

The EU went comprehensive. The UK went principles-based. Here’s how the two approaches compare for companies operating in both markets.

·8 min read
Regulation Analysis

GDPR vs. EU AI Act: Where the Rules Overlap

Both apply to most AI systems in the EU. Here’s how they interact, where they duplicate obligations, and how to satisfy both simultaneously.

·9 min read
Enforcement Updates

Clearview AI GDPR Fines Across Europe: What the Enforcement Pattern Tells Us

Clearview AI faced enforcement actions totaling hundreds of millions in fines. Here’s what the cases reveal about how regulators treat AI and biometric data.

·6 min read
Compliance Guides

Impact Assessment Under Colorado SB 24-205: A Step-by-Step Guide

Colorado’s AI Act requires impact assessments before deploying high-risk AI. Here’s exactly what to cover and how to document it for enforcement.

·10 min read
Industry News

Colorado AI Act: Readiness Update After SB 26-189

The effective date has moved to January 1, 2027 under SB 26-189. Here’s where organizations stand and what the extended timeline means.

·5 min read
Compliance Guides

The NYC Local Law 144 Bias Audit, Walked Step-by-Step

From finding an auditor to publishing results — here’s exactly how the NYC LL 144 annual bias audit process works for employers using AI in hiring.

·8 min read
Regulation Analysis

California AB 2013: Training Data Disclosure Requirements

California’s AB 2013 requires GenAI providers to post training data documentation. Here’s who it covers, what must be disclosed, and what to do now.

·6 min read
Compliance Guides

AIVIRA Obligations for Employers: The Practical Guide

Illinois’ AI Video Interview Act has been in force since 2020 and class action risk has grown. Here’s exactly what employers must do before using AI to evaluate video interviews.

·7 min read
Enforcement Updates

BIPA Class Actions in 2025: What Employers Need to Know

Illinois BIPA litigation generated billions in settlements. Here’s the state of play after the Cothron ruling and what employers must do to limit exposure.

·7 min read
Regulation Analysis

The Biometric Privacy Law Patchwork, Mapped

Illinois BIPA is the most litigated biometric law, but it’s not alone. Here’s every state biometric privacy law — requirements, enforcement, and compliance risk.

·8 min read
Enforcement Updates

Texas AG vs. Meta: The $1.4B Biometric Settlement Explained

The largest privacy settlement in US history. Here’s what Texas proved, what Meta did, and what it means for companies using facial recognition.

·7 min read
Comparison

BIPA vs. CUBI: Two Biometric Laws, Two Very Different Enforcement Models

Illinois and Texas both restrict biometric data but use completely different enforcement models. Side-by-side comparison for companies operating in both states.

·6 min read

A weekly edition,
in your inbox.

Every Friday — the week’s new regulations, enforcement actions, and compliance deadlines. Free forever. No tracking pixels.

Cancel any time · No spam · Read by 4,000+ compliance teams