The forcing functions: why AI governance is going mandatory — and it isn't the regulators
The instinct is that regulation forces AI governance. As of mid-2026 the evidence says otherwise: the strongest pull is private-market. Enterprises are being made to prove their AI is governed by their customers' procurement teams, their cyber-insurers, and their own boards — not primarily by statute. The US federal posture turned deregulatory, Colorado repealed its AI Act, and the EU AI Act's high-risk obligations slipped to December 2027. Meanwhile ISO 42001 is showing up in RFPs, insurers are writing "AI security riders," and Texas and California now reward certification with a legal safe harbor. The corrected pitch: win the RFP, lower the premium, shield the board.
The forcing functions are real and mostly private-market — procurement, insurance, and safe-harbor — and they are landing now. But most enterprises still cannot answer the RFP, the underwriter, or the board with an independent, signed attestation. The demand exists; the supply of provable governance does not.
Why governance matters
- Procurement is the #1 lever, and it's live. ISO/IEC 42001 is moving from standard to vendor requirement — the way SOC 2 and ISO 27001 did — with enterprise buyers in finance, health, and government gating vendors on third-party AI-governance attestation. The play is "win the RFP," not "comply with the law." (brightdefense, isms.online)
- Cyber-insurers are the MFA/EDR playbook, replayed. In 2026 carriers introduced "AI Security Riders" requiring documented model-risk assessments, red-teaming, AI-use policies and training as prerequisites to coverage — and are adding AI exclusions where governance is absent. The premium-discount-for-certification phase is the next shoe to drop. (compliancehub, Aon)
- Safe-harbor statutes turn certification into a litigation shield. Texas TRAIGA (in force Jan 1 2026) and California grant a rebuttable presumption for adopting NIST AI RMF or ISO 42001 — a carrot that survives the deregulatory turn precisely because it's an incentive, not a mandate. (verifywise)
- Boards now carry the duty. The Delaware Caremark oversight duty is being extended to AI risk — NIST AI RMF's "Govern" function maps onto the reporting system directors must establish in good faith — while AI-securities suits and an SEC "AI-washing" settlement raise the stakes. Demonstrable governance is the proof, and independent attestation is its cleanest form. (D&O Diary, Harvard Ethics)
- The EU AI Act is real but deferred. GPAI model obligations (in force since Aug 2 2025) and Article 50 transparency + Article 4 AI-literacy bind now; the big high-risk (Annex III) wave slipped to Dec 2 2027 via the Digital Omnibus. Penalties reach €35M / 7%. It matters for EU-facing deals — it is not the 2026 US hammer it is often sold as. (Council of the EU, Gibson Dunn)
- US federal is an anti-tailwind — don't anchor to it. The Dec 2025 executive order is deregulatory and preemption-minded, and Colorado's AI Act was repealed and replaced. Frameworks like NIST AI RMF matter as safe harbor, not as a mandate. (Nat'l Law Review, Crowell)
- The credential is already a trust signal. Anthropic, AWS, Microsoft, OpenAI, CrowdStrike, and BCG are ISO 42001 certified — ~350+ organizations by April 2026. When the buyers, the insurers, and the boards all point at the same credential, holding an independent attestation stops being optional. That convergence is govrn's tailwind.