# Regulatory Landscape

**The forcing function is no longer speculative — it is in force, and it asks for exactly one thing: evidence.**

> Confidential · June 2026. For discussion with prospective investors and partners. Any figures are illustrative unless sourced.

AI governance is not becoming a discipline because boards want a new committee. It is becoming a discipline because regulators, standards bodies, and sector supervisors are converging on a single demand: show your work. Across every regime below, the underlying ask is the same — an inventory of the AI in use, and a durable, attributable record of how it behaves over time. That is precisely the artifact the [Aperture engine](02-the-standard-and-engine.html) produces and the [govrn standard](01-executive-summary.html) attests.

## Why the timing is structural, not cyclical

Gartner projects that **75% of the world's economies will operate under AI regulation by 2030 — roughly a quadrupling** from today. The cost of compliance is already the binding constraint: Deloitte finds **regulatory compliance is the #1 barrier to GenAI adoption, cited by 38%** of respondents. Boards have noticed — EY reports Fortune 100 board-level AI-risk oversight rose from **16% to 48% in a single year**. The market for governance tooling reflects the pressure, moving from **$492M to $1B+ by 2030** (Gartner).

This is the forcing function: regulation is arriving faster than enterprises can manually document their AI estate. Evidence production has to become continuous, because the obligations below do not pause between audits.

## The regimes — and the evidence each one demands

| Regime | Status | Core obligation | The evidence it requires |
|---|---|---|---|
| **EU AI Act** | In force | Risk classification, GPAI transparency obligations, technical documentation, post-market monitoring | A maintained inventory of systems by risk tier and an ongoing record of behavior — penalties reach **7% of global turnover** |
| **NIST AI RMF** | Voluntary framework, widely referenced | Map / Measure / Manage / Govern functions | A repeatable measurement record showing risks are identified, quantified, and tracked |
| **ISO/IEC 42001** | Certifiable standard | AI management system with auditable controls | An attestable, independently reviewed management record — increasingly a buying requirement |
| **HUD / Fair Housing (tenant screening)** | Sector enforcement | Non-discriminatory automated decisioning | An audit trail of which model decided, on what basis, with what disparate-impact monitoring |
| **SR 11-7 (model risk, finance)** | Supervisory expectation | Model inventory, validation, ongoing monitoring | A documented model inventory and continuous performance evidence — independent of the model's builder |

The pattern across the table is the point. The EU AI Act wants documentation and post-market monitoring. NIST wants measurement you can repeat. ISO/IEC 42001 wants an auditable management system. HUD and SR 11-7 want an inventory plus a behavioral record tied to specific decisions. None of these is satisfied by a one-time questionnaire. Each demands a living inventory and a time-stamped audit trail — the two outputs govrn is built to generate.

Two of these regimes warrant a precise framing. **SR 11-7** is the Federal Reserve / OCC supervisory guidance on model risk management (SR Letter 11-7, 2011); it governs model risk in regulated financial institutions, and applying it to AI/LLM systems is an emerging-but-defensible extension — supervisors increasingly read modern AI as in-scope "models" — not settled, AI-specific regulation. **HUD / Fair Housing** tenant-screening exposure traces to the Fair Housing Act and HUD's 2024 guidance on the application of the Act to tenant-screening (including algorithmic and AI-assisted screening); treating AI decisioning as a governed surface here is an emerging application of established fair-housing law, not a standalone AI statute. We keep both regimes because they sharpen the thesis — the evidentiary ask is identical — while being explicit that the AI-specific reach is a reasoned extension rather than codified fact.

## ISO/IEC 42001 is becoming a buying requirement

The clearest near-term signal is ISO/IEC 42001 moving from "nice to have" to procurement gate. The validation comes from the top of the market: **BCG is itself ISO/IEC 42001 certified** while drawing **40%+ of its 2025 revenue from AI and tech work**, and major hyperscalers have pursued the same certification. When the firms advising the Fortune 500 — and the platforms hosting their workloads — carry the certificate, it stops being a differentiator and becomes table stakes for selling into regulated buyers.

This is where govrn's structural separation matters. The certificate asks for an auditable management system; the durable proof asks for **independent attestation** — the body that builds is never the body that attests. govrn's [six-framework crosswalks](01-executive-summary.html) (NIST AI RMF, ISO/IEC 42001, EU AI Act, OWASP, ATLAS, CSF 2.0) let one accumulated record answer many regimes at once.

## What govrn produces is what every regime demands

The Aperture engine inventories the AI actually in use — including shadow AI — and attributes its cost and usage deterministically, with no model in the measurement path, so the record is reproducible and audit-defensible. The govrn standard then attests that record independently. Inventory plus audit trail plus independent attestation is not a coincidental fit with the regulatory ask. It is the same artifact, described in five different regulatory vocabularies.

See also: [Market](03-market.html) · [Business Model](04-business-model.html) · [The Standard and the Engine](02-the-standard-and-engine.html)