AI compliance and governance have moved from legal afterthought to board-level priority. This pillar maps the full landscape — every major framework, every risk dimension, the complete governance lifecycle, and the six failures that consistently bring enterprises to grief. The parent page for every compliance and governance article in the HexTyx library.
Many organisations pursue AI compliance without AI governance. They document controls for an audit, pass the review, and then continue operating AI systems that are inconsistently managed, improperly tested, and inadequately monitored. Compliance becomes a quarterly exercise rather than an operational posture.
AI compliance is about demonstrating that specific external requirements are met — regulatory, contractual, or certification-based. AI governance is about controlling AI systems throughout their full lifecycle: who approves deployment, how risk is measured, what testing is required, how incidents are handled, and how vendors are managed. Compliance is one output of effective governance. An organisation with strong governance generates audit evidence as a natural byproduct.
Risk management is the foundation — without it, controls are applied inconsistently and priorities are set arbitrarily. Every AI system should be classified by data sensitivity, automation level, and business impact before any controls are designed.
Security assurance converts governance from documentation to evidence. Auditors, enterprise customers, and regulators increasingly ask for test results, not just policies. Red team exercises, prompt injection testing, and RAG security assessments are the evidence base.
AI systems generate new categories of personal information (inferences, profiles, behavioural patterns) that many compliance programmes haven't yet accounted for. GDPR, CCPA, and state privacy laws all apply to these AI-generated data types.
No single framework covers everything. Most enterprises need to address multiple frameworks simultaneously — global standards, data privacy laws, and industry-specific regulations. The correct approach: build a governance foundation first, then map it to each applicable framework.
When an AI incident occurs, accountability determines response speed. When auditors review controls, ownership documentation determines whether evidence can be produced. When boards ask about AI risk, oversight structures determine whether accurate information reaches them.
The most widely referenced AI governance framework in US enterprise procurement. Four functions: Govern, Map, Measure, Manage. Provides a comprehensive risk management vocabulary.
Risk-based regulation: Prohibited, High-Risk, Limited Risk, and Minimal Risk tiers. High-risk systems face extensive compliance requirements. In force across the EU from 2025.
Information security management system standard. Covers AI as part of broader information security governance. Required by many enterprise customers as a procurement prerequisite.
Trust Services Criteria covering security, availability, confidentiality, and privacy. Enterprise SaaS customers require SOC 2 Type II. Increasingly includes AI-specific criteria.
GDPR (EU, 72-hour breach notification), CCPA/CPRA (California, AI inferences as personal information), and expanding US state privacy laws — all apply when AI processes personal data.
FedRAMP (government cloud), PCI DSS v4 (payment environments), HIPAA (healthcare), DORA (EU financial services) — each sector adds its own AI-specific obligations on top of general frameworks.
Use-case approval, risk assessment, data review, vendor evaluation. Governance starts before a line of code is written.
Security controls integrated into the build. Documentation created. Testing procedures defined.
Red teaming, security testing, compliance review. Fixes before deployment, not after.
Approval workflows, monitoring setup, risk acceptance documented. No deployment without owner sign-off.
Continuous monitoring, incident response readiness, audit evidence collection. Governance as ongoing practice.
Data deletion, archive management, risk closure. GDPR and CCPA deletion obligations extend to AI storage.
Unknown systems cannot be governed, tested, or monitored. Most organisations deploying AI at scale have significantly more AI usage than their governance team is aware of — especially shadow AI.
Without risk tiers, controls are applied inconsistently — over-engineered for low-risk systems, under-engineered for high-risk ones. Risk classification is the prerequisite for proportionate governance.
AI vulnerabilities remain undiscovered until exploited in production. Auditors and enterprise customers are now asking for test results, not just policies. Testing evidence is the gap most organisations discover during enterprise procurement reviews.
Third-party AI providers handling sensitive data without contracts, data retention reviews, training data policies, or security certifications. Third-party risk is the fastest-growing category in AI governance failures.
AI incidents go undetected because no one is watching prompt logs, output logs, or agent behaviour. The median time to detect an AI incident in an unmonitored deployment is measured in weeks — not hours.
No designated owner for AI systems means no one responds when something goes wrong, no one collects audit evidence, and no one updates controls as systems change. Every AI system needs a named owner.
The HexTyx AI Security Assessment evaluates your governance readiness, security controls, compliance gaps, and agent security — mapped to NIST AI RMF and major frameworks. Free, 10 minutes.