Frameworks · By region
AI regulations by region.
AI rules arrive through existing regulators before they arrive as statutes. This page groups the frameworks Meilynx maps to by where they apply, so a firm with operations in more than one place can see the full set at once.
United States · federal
Interagency guidance and self-regulatory notices that apply through existing rules rather than an AI statute.
- FINRA 24-09PresetSupervision and recordkeeping obligations for generative AI at broker-dealers.FINRA
- SR 26-2PresetThe interagency model risk guidance that replaced SR 11-7 in April 2026.Federal Reserve · OCC · FDIC
- HIPAA Technical SafeguardsPolicy engineAccess, audit, and integrity controls the policy engine enforces today.US Department of Health and Human Services
- NIST AI RMFPolicy engineGovern, map, measure, and manage functions the policy engine can evidence today.NIST
United States · state
State regulators and legislatures move first: New York on cybersecurity, insurance departments on AI programs, and Illinois, NYC, and Colorado on employment AI.
- NYDFS 500PresetCybersecurity requirements for New York financial services companies, applied to AI systems.New York Department of Financial Services
- NAIC AI BulletinPresetThe insurer AI program expectations adopted in 24 states and DC, with the Colorado, New York, Texas, and Connecticut layers.NAIC and state insurance departments
- HR / Employment AIPresetEvidence for the AI-traffic slice of Illinois HB 3773, NYC Local Law 144, and Colorado SB 26-189.Illinois · New York City · Colorado
European Union
The AI Act phases in through 2027 alongside DORA for financial entities. Both expect records that show the controls operating.
United Kingdom
Sector regulators apply existing rules to AI under the government's principles-based approach. No AI statute yet.
- No UK-specific AI framework is mapped as a preset. UK firms typically evidence AI under the FCA and PRA's existing rules and rely on ISO/IEC 42001 and SOC 2, listed under international standards below.
International standards
ISO/IEC 42001 and SOC 2 travel across borders and are what auditors ask for when no local rule names AI.
- ISO/IEC 42001PresetThe international AI management-system standard, with operating evidence behind each clause.ISO / IEC
- SOC 2PresetTrust Services Criteria evidence for the AI path, and the report Meilynx holds itself.AICPA
- NIST AI RMFPolicy engineGovern, map, measure, and manage functions the policy engine can evidence today.NIST
Presets and policy-engine coverage.
A preset is a curated control bundle that ships in the product today. Policy-engine coverage means the engine enforces the underlying controls and your compliance team scopes them; no curated bundle ships for it yet, and nothing on this page names work that has not shipped.
See exactly what an examiner receives
Download a sample examination package: model inventory, control coverage, a governance policy snapshot, and a SHA-256 integrity hash.