The rules moved from hypothetical to enforceable. This is the map: US federal and state law, the EU AI Act, and the rest of the world. Each entry links to our plain-English breakdown, updated as the law moves.
Find out where you standWhat the federal posture actually requires, and the gap it leaves for AI.
The patchwork that decides what applies where you operate.
Where the sharpest enforcement pressure is landing right now.
If you touch users abroad, these reach you.
The frameworks you get measured against, and the threats that prove why.
That is exactly what a free AI Risk Exposure call is for. Thirty minutes, no deck, and you will know which rules apply to what you have built.
Find out where you standIt depends on where you operate and what your AI does. Most US deployers are touched by at least one state law plus the federal model-risk and NIST expectations, and anyone serving EU users falls under the EU AI Act. This tracker groups the rules by jurisdiction so you can find yours, and a short assessment call will map exactly which ones reach you.
No. SR 11-7 was superseded in April 2026. The replacement guidance is narrower, applies only to the largest banks, and expressly excludes generative and agentic AI, which leaves a real governance gap. Our full breakdown is linked in the US Federal section above.
ISO/IEC 42001 is the international standard for an AI management system. It is becoming the reference point buyers and regulators use to judge whether your AI is governed. Whether you need certification depends on your customers and risk exposure; our plain-English guide, linked above, walks through it.
Sentinel Assurance Group provides independent, third-party AI assurance: governance assessments, ISO/IEC 42001 readiness, and AI red-teaming, delivered with ISO/IEC 17025 laboratory discipline. We do not sell the software that enforces your controls; we independently prove they work. Book a free AI Risk Exposure call to start.