§ Perspective · Educational · October 14, 2026 · about 9 minutes

What AI governance
actually requires.

A plain-language guide to the four questions boards are being asked, and the record that answers them.

By Lindsay Hiebert · Founder · CISSP

Most organizations now use AI in some form. Many use it in dozens of places, some of which nobody has written down. At the same time, four separate developments have turned “how do we govern this” from a good idea into a question a board can be asked to answer on the record.

This guide walks through those four developments in plain language, then explains what they have in common. The short version is this. Each of them, in its own way, asks an organization to show evidence of a working governance system, not to describe one. Knowing what that evidence looks like is most of the work.

Nothing here is legal advice. Dates and details are current as of the review date at the end of the post, and the primary sources are linked so you can check them yourself.

The four developments

1. The EU AI Act is partly live and partly deferred

The EU AI Act entered into force on August 1, 2024. It applies in phases. Three phases already apply today:

  • Since February 2, 2025: prohibited AI practices, and the AI literacy duty in Article 4.
  • Since August 2, 2025: obligations on providers of general-purpose AI models.
  • Since August 2, 2026: transparency duties in Article 50, such as telling people when they are interacting with an AI system and labelling AI-generated content.

In July 2026 the EU adopted the Digital Omnibus on AI, Regulation (EU) 2026/1744, which entered into force on July 27, 2026. It moved only the high-risk tier. Stand-alone high-risk systems listed in Annex III, which include AI used in hiring, credit decisions, education and access to essential services, now apply by December 2, 2027 at the latest. High-risk AI embedded in regulated products, listed in Annex I, applies by August 2, 2028.

The Omnibus also rewrote Article 4. Providers and deployers must now take measures to support the development of AI literacy among their staff and others operating AI on their behalf. The article states that this does not require anyone to guarantee a specific level of literacy for any individual. The duty itself still applies, and it still has to be evidenced. What changed is the benchmark, not the obligation.

What it asks you to show: which AI systems you use and how each is classified, what literacy measures you have taken by role, how your transparency controls work, and who owns each system that could fall into the high-risk tier.

2. Colorado rewrote its AI law around decisions about people

On May 14, 2026, Colorado replaced its original AI Act with SB 26-189, the Automated Decision-Making Technology Act. It takes effect January 1, 2027. The Attorney General enforces it under the state’s consumer protection law. There is no private right of action, and a 60-day cure period is available where the Attorney General agrees a cure is possible, through the start of 2030.

The new law is narrower than the one it replaced. It applies to technology that processes personal data and materially influences a consequential decision about a person in areas such as employment, housing, lending, insurance, health care, education and essential government services. Its duties are practical: tell people before the technology is used in a decision about them, explain an adverse outcome, let them correct the data, provide meaningful human review on request, and keep records for three years. The law also allocates duties between the developer who builds the tool and the deployer who uses it.

The law applies to decisions about Colorado residents regardless of where the company sits. A constitutional challenge is pending, so the date may still move. The records the law asks for are worth keeping either way.

What it asks you to show: an inventory of AI that influences consequential decisions about people, the notices and explanations in place, a human review path, and the contract language that says who produces which records.

3. US bank regulators revised model risk management

On April 17, 2026, the Federal Reserve, the Office of the Comptroller of the Currency and the FDIC jointly issued SR 26-2, Revised Guidance on Model Risk Management. It supersedes SR 11-7, which had governed bank model risk since 2011, and SR 21-8, which covered models used in anti-money-laundering compliance.

Two points matter beyond banking. First, the new guidance is principles-based and risk-tiered. Validation effort follows a model’s materiality rather than a fixed annual calendar, and the definition of a model excludes simple spreadsheet arithmetic and deterministic rule-based software. Second, the guidance treats generative and agentic AI as outside its scope and directs institutions to apply their existing risk management and governance practices to those systems. That leaves the burden of showing how those systems are governed with the institution.

The pattern is worth noticing. The regulator is not prescribing a checklist for AI. It is asking the institution to demonstrate that its own governance reaches the AI it uses. Vendors and fintechs serving banks feel the same expectation through third-party risk reviews.

What it asks you to show: an inventory that distinguishes models from other AI, a documented rationale for how deeply each is validated, aggregate reporting of model risk and open findings to the board, and a clear account of how generative and agentic AI are governed.

4. Delaware’s oversight duty is ready for AI, even if no court has applied it yet

Most large US companies are incorporated in Delaware, so its courts set the practical standard for boards. The relevant rule comes from In re Caremark (1996), affirmed in Stone v. Ritter (2006). Directors breach their duty of oversight if they utterly fail to put a reporting system in place, or if they have one and consciously ignore the red flags it produces. Because this is treated as a matter of good faith, the usual protections against liability for honest mistakes do not cover it.

Marchand v. Barnhill (2019) sharpened the rule. Blue Bell Creameries had no board committee, no protocol and no regular reporting on food safety, its single most critical risk, and people died in a listeria outbreak. The Delaware Supreme Court let the claim proceed. The lesson is that for a mission-critical risk, the board itself must have a monitoring system. The Boeing case applied the same reasoning to aircraft safety in 2021, and the McDonald’s decision in 2023 extended an oversight duty to officers.

No Delaware court has yet applied this to an AI failure. The logic transfers directly, and leading governance commentary now advises boards to treat AI as mission-critical wherever it is central to the product, to regulated decisions, or to safety. In these cases the board record decides the outcome. Plaintiffs begin by requesting minutes, charters and reports, and the question becomes whether the record shows a system that existed and was used.

What it asks you to show: a committee charter or board resolution naming AI oversight, a regular reporting cadence, a register of AI risks with owners, minutes that show questions asked and answered, and a record of how warnings were handled.

What the four have in common

Set the four side by side and the same request appears in each.

The question a board will be askedEU AI ActColoradoSR 26-2Caremark
What AI do we use, and who owns each system?YesYesYesYes
What is each system permitted to do, and who approved that?Yes (high-risk)Yes (consequential decisions)Yes (model use)Yes (reporting system)
Were the people involved prepared for their role?Yes (Article 4)Yes (human review)Yes (validation competence)Implied
Which rule does each control answer to?YesYesYesYes
Can we show this to an outside party with a date on it?YesYes (three-year records)Yes (examiners)Yes (minutes and reports)

None of the four asks for a particular product. All four ask for a record. That is the practical definition of AI governance: the written, dated, owned account of what AI an organization uses, what each system is allowed to do, who agreed, and against which obligation.

The five parts of that record

Here is what the record consists of, in the order most organizations build it.

1. An inventory with owners. Every AI system in use, including the ones adopted by individual teams without a central decision. Each entry carries a named owner, what the system is used for, what data it touches and a risk class. Discovery comes first, because governance cannot reach what nobody has listed.

2. Permissions, written down. For each system, and especially for each agent that can act on its own, a statement of what it is allowed to do without a human, who approved that, and when it was last changed. The threshold at which an agent acts alone is a permission, not a tuning setting, and permissions belong in a record an auditor can find.

3. Readiness by role. Evidence that the people who direct, build, use and review AI were prepared for their part. A director needs to know what to ask. A reviewer under Colorado’s law needs to know what meaningful review involves. A deployer under Article 4 needs to show the measures it took. One general course rarely covers all of these, so the record should show who completed what.

4. Findings tied to obligations. A current list of the gaps, each tied to the specific article, section or guidance it answers to, with an owner and a date. This is what turns a risk conversation into a reportable item.

5. Artifacts an outside party can verify. A board register, a risk report and an acceptable use policy that carry dates and can be checked by someone who was not in the room. Insurers, auditors, customers and courts all ask for this in their own way.

Where security tools fit

Firewalls, AI security platforms and agent guardrails enforce controls and record activity. That work is essential and it feeds the record. A guardrail log shows what an agent did. The governance record shows what it was allowed to do and who agreed. Both are needed, and they answer different questions. Observability describes behavior. Governance assigns responsibility. A board that has both can answer any of the four developments above with the same set of documents.

A practical starting sequence

If your organization has none of this yet, the following order works for most.

  1. Run discovery and build the inventory with owners. Expect to find more AI than anyone listed.
  2. Classify each entry against the EU AI Act tiers and Colorado’s consequential-decision test. The classification determines everything downstream.
  3. Write down permissions for every agent that can act without a person, with an approver and a date.
  4. Put role-based readiness in place and keep the completion records.
  5. Produce the findings list, tie each item to its obligation, and set a reporting cadence to the board or a named committee.
  6. Record the cadence in a charter or resolution, and keep the minutes.

Each step produces something that can be shown. That is the test to apply at every stage. If a step does not leave a dated record with a name on it, it is activity rather than governance.

Where SanctumShield fits

SanctumShield produces this record. It begins with discovery and builds the Board AI Register with named owners. It records each agent’s permissions and autonomy level with the approver and date. It generates the Executive Risk Report and a tailored acceptable use policy, each tied to specific obligations and carrying a Verification URL so an outside party can confirm when and from what the document was produced. SanctumShield Academy provides the readiness layer, with AI governance training by role and a verifiable record of each completion. A free Board AI Register template and a free AI literacy quiz are available for any organization that wants to start today.

Primary sources

Reviewed October 2026. Not legal advice.

§ Why this is a legal question, not a tooling preference

Everything above is an argument about method. Underneath it sits an obligation that does not depend on which method you pick. Documented, dated, demonstrable governance is what the law asks for, and the dates have stopped being in the future.

EU AI Act Article 4 — AI literacy
In force since February 2, 2025. National enforcement began August 2, 2026.
EU AI Act Article 50 — transparency
Applies since August 2, 2026.
Colorado SB 26-189
Effective January 1, 2027.
EU AI Act Articles 12, 14 and 17 — record-keeping, human oversight, quality management
High-risk regime: December 2, 2027 (Annex III) and August 2, 2028 (Annex I).

Read those together and the shape is consistent. Each one asks an organization to produce something — a measure taken, a disclosure made, a record kept, a review performed — and to be able to show it after the fact. None of them names a product, a platform or a link, and nothing here should be read as saying a law requires one. What a law requires is the record. Making that record dated and third-party-verifiable is simply how you let an auditor, an underwriter or a board confirm it without being handed the contents, or being asked to take your word for it.

And literacy is not one obligation among several. It is the one the others rest on. You cannot exercise due diligence over a system you cannot recognise, and you cannot govern an authority you do not understand you have delegated.

That is why Article 4 sits in the opening chapter of the Act, ahead of the risk tiers, and why it applied eighteen months before the high-risk regime does. The duty is to take measures that support the development of AI literacy among the people operating AI on the organization’s behalf — and the useful version of that is matched to the seat. What a director needs to recognise is not what a developer needs to recognise, and neither is what the person pasting a contract into a browser tab needs to recognise. A single org-wide module satisfies the form and misses the point.

What AI Governance Actually Requires — SanctumShield