Skip to content

AI Governance Framework Updates

The AI governance landscape is moving fast. This page tracks the dates, amendments, and revisions that actually affect compliance programs, grouped by framework. For the full framework guides, see the frameworks overview.

How we use this page

Entries are written as dated, load-bearing facts that change how you should run your program. If an update just adds a new sample document or reference, we do not track it here — we update the framework guide directly.

EU AI Act

  • 2024-07-12 — EU AI Act published in the Official Journal of the European Union.
  • 2024-08-01 — Regulation entered into force; the phased application timeline begins.
  • 2025-02-02 — Prohibited AI practices (Article 5) and AI literacy (Article 4) apply.
  • 2025-08-02 — General-purpose AI (GPAI) obligations begin to apply for new models.
  • 2026-07-12 — CEN/CENELEC approve EN 18286:2026, the quality management system standard for EU AI Act regulatory purposes and the first JTC 21 AI Act standard to reach final approval. Presumption of conformity attaches once EN 18286:2026 is cited in the Official Journal of the European Union (not yet cited). See the EN 18286 guide.
  • 2026-07-24 — Digital Omnibus on AI published in the Official Journal as Regulation (EU) 2026/1744 (adopted by the European Parliament 16 June, Council 29 June 2026), in force from 27 July 2026. It defers the high-risk deadlines (Annex III to 2 December 2027, Annex I to 2 August 2028) and adds new Article 5(1)(ba)/(bb) prohibitions.
  • 2026-12-02(Omnibus application date) New Article 5 NCII/CSAM prohibitions apply; legacy synthetic-content systems must meet Article 50(2) marking.
  • 2027-12-02(deferred from 2 August 2026 by the Omnibus) Standalone Annex III / Article 6(2) high-risk obligations apply.
  • 2028-08-02(deferred from 2 August 2027 by the Omnibus) Annex I / Article 6(1) product-safety high-risk obligations apply.

See the EU AI Act guide and the How to comply with the EU AI Act step-by-step.

ISO/IEC 42001

  • 2023-12 — ISO/IEC 42001:2023 published — first certifiable international management system standard for AI.
  • 2024 onwards — early accredited certification bodies begin offering ISO 42001 audits under IAF signatory schemes (ANAB programs opened 2024).
  • 2025ISO/IEC 42006:2025 published: the requirements for bodies auditing and certifying AI management systems. Accreditation bodies begin transitioning their ISO 42001 certification programs onto it.
  • 2026-01 — first UKAS-accredited ISO/IEC 42001 certifications; accreditation coverage continues to broaden.
  • 2026 — CEN/CENELEC adopt the standard as EN ISO/IEC 42001:2026. A European Standard, but not the AI Act QMS route: the Article 17 quality management system standard is the bespoke EN 18286, whose Annex C maps its clauses to this EN edition. See EN 18286 vs ISO 42001.

See the ISO 42001 guide and the How to comply with ISO 42001 step-by-step.

ISO/IEC 27701

  • 2019 — ISO/IEC 27701:2019 published as a privacy extension to ISO 27001/27002.
  • 2025ISO/IEC 27701:2025 published: the revised edition this documentation cites; the 2019 edition is withdrawn. Programs built on the 2019 extension model should plan the transition.

See the ISO 27701 guide.

NIST AI RMF

  • 2023-01-26 — AI Risk Management Framework 1.0 (NIST.AI.100-1) published.
  • 2023 — AI RMF Playbook published with categories and subcategories.
  • 2024-07 — NIST AI 600-1 Generative AI Profile published as the first cross-sectoral companion to AI RMF 1.0.
  • 2025-12-16 — NIST releases the preliminary draft Cyber AI Profile (NIST IR 8596), a CSF 2.0 profile for AI-related cyber risk across three focus areas (securing AI systems, AI-enabled cyber defense, thwarting AI-enabled attacks); companion SP 800-53 control overlays for securing AI systems are in development.

See the NIST AI RMF guide and the How to comply with NIST AI RMF step-by-step.

OWASP Top 10 for LLM / Agentic

  • 2023-08 — OWASP Top 10 for LLM Applications v1.0 published.
  • 2024-11-18 — OWASP Top 10 for LLM Applications 2025 (v2.0) released by the OWASP GenAI Security project.
  • 2025-12-09 — OWASP GenAI Security Project announces the Top 10 for Agentic Applications 2026, the first published Agentic Top 10.

See the OWASP for AI hub, the OWASP Top 10 for LLM, and the OWASP Top 10 for Agentic.

Singapore MGF for Agentic AI

  • 2026-05-20 — IMDA publishes the Model AI Governance Framework for Agentic AI v1.5 (updated 5 June 2026): voluntary best-practice guidance structured around four dimensions applied as an iterative loop.

See the Singapore MGF for Agentic AI guide.

GDPR and EU data-protection guidance on AI

  • 2018-05-25 — GDPR enters into application.
  • 2024-12-17EDPB Opinion 28/2024 on AI models: model anonymity, legitimate interest as a legal basis for AI development, and the consequences of unlawfully processed training data.
  • AI systems processing personal data must comply with GDPR in parallel with the EU AI Act. See EU AI Act vs GDPR.

Cyber Resilience Act

  • 2024-11-20 — The Cyber Resilience Act (Regulation (EU) 2024/2847) is published in the Official Journal; it enters into force on 10 December 2024.
  • 2025-11-28 — Commission Implementing Regulation (EU) 2025/2392 adopted: the technical descriptions of the important and critical product categories that determine each product's conformity-assessment tier.
  • 2026-06-11 — Chapter IV (Articles 35–51) applies: the machinery for notifying conformity assessment bodies stands up ahead of the product deadlines.
  • 2026-07-27 — The Commission publishes non-binding practical guidance on CRA implementation (C(2026) 5252): scope, substantial modification, support periods, and reporting obligations, with worked examples and particular attention to microenterprises and small enterprises.
  • 2026-09-11Article 14 reporting applies: manufacturers report actively exploited vulnerabilities and severe incidents to the coordinator CSIRT and ENISA via the single reporting platform (24-hour early warning, 72-hour notification, final report). Applies to all in-scope products, including those placed on the market before 11 December 2027.
  • 2027-12-11 — The remaining manufacturer duties apply. Products placed on the market before this date are caught only on substantial modification (Article 14 excepted). No harmonized standard has yet been cited in the Official Journal; the EN 40000 series is still in drafting under standardization request M/606.

See the Cyber Resilience Act guide.

NIS2

  • 2023-01-16 — NIS2 Directive (EU) 2022/2555 entered into force.
  • 2024-10-17 — Member State transposition deadline. National laws now apply to essential and important entities.

See the NIS2 guide.

DORA

  • 2023-01-16 — DORA (Regulation (EU) 2022/2554) entered into force.
  • 2025-01-17 — DORA applies to financial entities in the EU.

See the DORA guide.

How to track framework changes in Modulos

Modulos tracks framework versions and notifies projects when regulatory updates affect them, so you can assess impact before deadlines.

Disclaimer

This page is for general informational purposes and does not constitute legal advice. Confirm dates and obligations with official sources and qualified counsel.