Regulatory and Legal Uncertainty
The regulatory environment for AI is not merely evolving — it is fragmenting across jurisdictions at different rates with different philosophical foundations. Organizations deploying AI agents in 2025 must navigate a patchwork of obligations: the EU AI Act’s phased implementation through 2027, the US OMB’s M-25-22 guidance for federal agencies and sector-specific AI guidance from the FDA, SEC, and CFPB, China’s AI regulations, and emerging requirements in India, Brazil, and the UK. The compliance complexity compounds for multinational organizations operating across multiple regulatory contexts simultaneously.
The challenge is not simply understanding what is required today — it is making architectural and governance decisions now that remain compliant as requirements evolve and harden. An agent designed without explainability mechanisms today may require expensive re-architecture if transparency requirements are mandated in your jurisdiction next year. A deployment without human oversight infrastructure may be non-compliant with EU AI Act requirements that take effect for high-risk AI systems in August 2026.
The Current Regulatory Landscape
EU AI Act establishes a risk-based classification framework. Prohibited practices (social scoring, real-time biometric surveillance) took effect in February 2025. High-risk AI system requirements — including conformity assessments, technical documentation, bias testing, and human oversight mandates — apply from August 2026. General purpose AI model requirements apply from August 2025. For any organization operating in EU markets or processing data of EU residents, the Act creates direct compliance obligations.
OMB M-25-22 (Advancing Responsible AI Acquisition and Use) establishes requirements for US federal agencies procuring or deploying AI, including transparency requirements, impact assessments, and documentation standards. For organizations selling to the US federal government, these requirements effectively extend to vendor AI systems.
ISO 42001 provides an internationally certifiable AI management system standard. Unlike the EU AI Act, certification is voluntary — but it provides a comprehensive governance framework that satisfies the procedural requirements of multiple regulatory regimes simultaneously. ISO 42001 explicitly requires risk assessment, bias testing, performance monitoring, and documented management of AI systems, making it a pragmatic foundation for organizations seeking a single governance framework that travels across jurisdictions.
NIST AI Risk Management Framework provides a voluntary framework (Govern, Map, Measure, Manage) that is increasingly referenced in US regulatory guidance and federal contract requirements.
Concrete Mitigations
Build a regulatory monitoring capability. Assign explicit ownership for tracking AI regulatory developments in every jurisdiction where your organization operates. This is not a one-time analysis — it is an ongoing function. Tools like Thomson Reuters Westlaw AI Tracker, LexisNexis regulatory intelligence feeds, and specialist AI law firms can provide structured monitoring. Brief key stakeholders quarterly on material developments and their implications for current deployments.
Err on the side of good governance practices. The regulatory uncertainty argument cuts both ways: since you cannot predict exactly what will be required, implement the governance practices that are commonly cited across emerging frameworks — explainability, human oversight, bias testing, documentation, and data subject rights. These investments are not wasted if requirements change; they are the foundation of a defensible governance posture regardless of how specific requirements evolve.
Document everything with compliance in mind. Maintain technical documentation for every deployed agent that covers: the model and version used, the training and retrieval data sources, the system prompt and its change history, the evaluation results, the risk assessment, the bias testing results, and the human oversight mechanisms. This documentation is not just good practice — it is a compliance deliverable under the EU AI Act, ISO 42001, and increasingly under sector-specific guidance. Create it as you build, not retroactively.
Pursue ISO 42001 certification as a baseline. ISO 42001 provides a certifiable, internationally recognized framework that covers the procedural requirements most regulatory regimes are converging on. Achieving certification demonstrates due diligence to regulators, customers, and partners in a way that self-attestation cannot. The certification process also identifies governance gaps that self-assessment tends to miss.
Engage legal counsel on liability architecture. Clarify with legal counsel how liability is allocated when an agent makes a consequential error: what duty of care the organization owes, what “due diligence” means in your jurisdiction and use case context, and how your contracts with AI vendors allocate liability for model failures. Document these assessments and ensure that your governance practices are aligned with the due diligence standard your legal team defines.
Participate in standards and regulatory processes. Organizations that participate in comment processes on draft regulations, contribute to standards bodies (IEEE, ISO, NIST), and engage in industry coalitions shape the regulatory environment rather than simply reacting to it. Participation also provides advance visibility into regulatory intent and emerging requirements, enabling proactive rather than reactive compliance investment.
Make It Your Own
Key questions to ask in the context of your organization:
- Have you completed a jurisdiction-by-jurisdiction regulatory mapping for your AI agent deployments, identifying which regimes apply (EU AI Act, OMB M-25-22, sector-specific guidance) and what specific obligations each creates for your highest-risk use cases?
- Is there explicit ownership — a named individual with allocated time and resources — for monitoring AI regulatory developments in each of your operating jurisdictions, with a defined process for briefing decision-makers on material developments?
- Have you built the technical documentation infrastructure that would allow you to produce a complete conformity assessment for each deployed agent within a defined timeframe — including model version, training data provenance, evaluation results, bias testing, and human oversight architecture?
- Have you assessed ISO 42001 certification as a baseline governance framework, and if you have not pursued it, have you documented the alternative governance practices that satisfy its core requirements?
- Have you engaged legal counsel to document your due diligence posture for each high-risk agent deployment — defining what “due diligence” means in your specific use case, jurisdiction, and contractual context?
- Are you participating in the regulatory and standards processes shaping AI governance in your industry — through comment submissions, standards body participation, or industry coalition engagement — so that your compliance investments are informed by emerging requirements rather than surprised by them?