Regulatory Landscape

The forcing function is no longer speculative — it is in force, and it asks for exactly one thing: evidence.

Confidential · June 2026. For discussion with prospective investors and partners. Any figures are illustrative unless sourced.

AI governance is not becoming a discipline because boards want a new committee. It is becoming a discipline because regulators, standards bodies, and sector supervisors are converging on a single demand: show your work. Across every regime below, the underlying ask is the same — an inventory of the AI in use, and a durable, attributable record of how it behaves over time. That is precisely the artifact the Aperture engine produces and the govrn standard attests.

Why the timing is structural, not cyclical

Gartner projects that 75% of the world's economies will operate under AI regulation by 2030 — roughly a quadrupling from today. The cost of compliance is already the binding constraint: Deloitte finds regulatory compliance is the #1 barrier to GenAI adoption, cited by 38% of respondents. Boards have noticed — EY reports Fortune 100 board-level AI-risk oversight rose from 16% to 48% in a single year. The market for governance tooling reflects the pressure, moving from $492M to $1B+ by 2030 (Gartner).

This is the forcing function: regulation is arriving faster than enterprises can manually document their AI estate. Evidence production has to become continuous, because the obligations below do not pause between audits.

The regimes — and the evidence each one demands

RegimeStatusCore obligationThe evidence it requires
EU AI ActIn forceRisk classification, GPAI transparency obligations, technical documentation, post-market monitoringA maintained inventory of systems by risk tier and an ongoing record of behavior — penalties reach 7% of global turnover
NIST AI RMFVoluntary framework, widely referencedMap / Measure / Manage / Govern functionsA repeatable measurement record showing risks are identified, quantified, and tracked
ISO/IEC 42001Certifiable standardAI management system with auditable controlsAn attestable, independently reviewed management record — increasingly a buying requirement
HUD / Fair Housing (tenant screening)Sector enforcementNon-discriminatory automated decisioningAn audit trail of which model decided, on what basis, with what disparate-impact monitoring
SR 11-7 (model risk, finance)Supervisory expectationModel inventory, validation, ongoing monitoringA documented model inventory and continuous performance evidence — independent of the model's builder

The pattern across the table is the point. The EU AI Act wants documentation and post-market monitoring. NIST wants measurement you can repeat. ISO/IEC 42001 wants an auditable management system. HUD and SR 11-7 want an inventory plus a behavioral record tied to specific decisions. None of these is satisfied by a one-time questionnaire. Each demands a living inventory and a time-stamped audit trail — the two outputs govrn is built to generate.

Two of these regimes warrant a precise framing. SR 11-7 is the Federal Reserve / OCC supervisory guidance on model risk management (SR Letter 11-7, 2011); it governs model risk in regulated financial institutions, and applying it to AI/LLM systems is an emerging-but-defensible extension — supervisors increasingly read modern AI as in-scope "models" — not settled, AI-specific regulation. HUD / Fair Housing tenant-screening exposure traces to the Fair Housing Act and HUD's 2024 guidance on the application of the Act to tenant-screening (including algorithmic and AI-assisted screening); treating AI decisioning as a governed surface here is an emerging application of established fair-housing law, not a standalone AI statute. We keep both regimes because they sharpen the thesis — the evidentiary ask is identical — while being explicit that the AI-specific reach is a reasoned extension rather than codified fact.

ISO/IEC 42001 is becoming a buying requirement

The clearest near-term signal is ISO/IEC 42001 moving from "nice to have" to procurement gate. The validation comes from the top of the market: BCG is itself ISO/IEC 42001 certified while drawing 40%+ of its 2025 revenue from AI and tech work, and major hyperscalers have pursued the same certification. When the firms advising the Fortune 500 — and the platforms hosting their workloads — carry the certificate, it stops being a differentiator and becomes table stakes for selling into regulated buyers.

This is where govrn's structural separation matters. The certificate asks for an auditable management system; the durable proof asks for independent attestation — the body that builds is never the body that attests. govrn's six-framework crosswalks (NIST AI RMF, ISO/IEC 42001, EU AI Act, OWASP, ATLAS, CSF 2.0) let one accumulated record answer many regimes at once.

What govrn produces is what every regime demands

The Aperture engine inventories the AI actually in use — including shadow AI — and attributes its cost and usage deterministically, with no model in the measurement path, so the record is reproducible and audit-defensible. The govrn standard then attests that record independently. Inventory plus audit trail plus independent attestation is not a coincidental fit with the regulatory ask. It is the same artifact, described in five different regulatory vocabularies.

See also: Market · Business Model · The Standard and the Engine