Reference
Regulatory Reference.
Structured summaries of the rules that govern AI systems. Each entry states what the rule is, who it binds, what it requires, and what a reviewer expects to see.
These are reference pages, not commentary. They are reviewed and dated, and every entry links to the primary source.
Model risk management
- SR 26-2 Explained: The Model Risk Guidance Replacing SR 11-7
What SR 26-2 requires, what changed from SR 11-7, why generative AI is carved out, and what examiners expect. Issued April 2026 by the Fed, OCC, and FDIC.
Last reviewed August 24, 2026
- SR 11-7 to SR 26-2: What Changed
The differences between SR 11-7 and SR 26-2, what carried forward unchanged, and what model risk programs need to update.
Last reviewed August 14, 2026
- SR 26-2 and Generative AI: The Carve-Out Explained
SR 26-2 places generative and agentic AI outside the model risk guidance in a single footnote. What it says, what still applies, and the voluntary frameworks banks use to govern these systems.
Last reviewed September 23, 2026
- OCC Bulletin 2026-13: Model Risk Management Guidance for Banks
What OCC Bulletin 2026-13 says, which prior OCC guidance it rescinds, how it relates to SR 26-2, and what the revised model risk framework expects.
Last reviewed August 24, 2026
Cybersecurity
- 23 NYCRR 500.13: Asset Management and Data Retention
What NYDFS Section 500.13 requires for asset inventory and secure disposal of nonpublic information, who it binds, and what examiners expect to see.
Last reviewed September 15, 2026
- NYDFS Industry Letter on Frontier AI Models and Cybersecurity Risk (21 May 2026)
What the NYDFS advisory of 21 May 2026 on frontier AI models asks of regulated entities, its companion guidance, and how it sits within Part 500.
Last reviewed September 15, 2026
Securities
- FINRA Regulatory Notice 24-09: Generative AI Compliance Obligations
The supervision, recordkeeping, and communications obligations that attach when member firms use generative AI and LLMs, and what examiners expect to see.
Last reviewed August 24, 2026
Insurance
- NAIC Model Bulletin on the Use of AI by Insurers, Explained
What the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers expects, which states have adopted it, and what a market-conduct examiner asks for.
Last reviewed September 4, 2026
- Colorado Regulation 10-1-1: External Consumer Data, Algorithms, and Predictive Models in Insurance
What Colorado Regulation 10-1-1 (3 CCR 702-10) requires of life, auto, and health insurers using external consumer data, with the 2025 amendment dates.
Last reviewed September 4, 2026
Employment
- Employment AI Laws: Illinois HB 3773, NYC Local Law 144, and Colorado SB 26-189
What Illinois HB 3773, New York City Local Law 144, and Colorado SB 26-189 require of employers using AI in hiring and promotion, with dates, obligations, and common gaps.
Last reviewed September 4, 2026
European Union
- EU AI Act Obligations and Dates After the Digital Omnibus
Which EU AI Act obligations apply now, which the Digital Omnibus (Regulation (EU) 2026/1744) deferred, and the deployer duties behind each date.
Last reviewed September 4, 2026
- DORA and AI Workloads: What Regulation (EU) 2022/2554 Requires
What DORA has required of EU financial entities since 17 January 2025, and how its ICT risk, incident, and third-party obligations reach an AI workload.
Last reviewed September 4, 2026
Healthcare
- The HIPAA Security Rule and AI Workloads, Explained
What the HIPAA Security Rule requires of covered entities and business associates that route protected health information through AI systems, and what an OCR investigator asks for.
Last reviewed September 5, 2026
- HHS Section 1557 and Patient Care Decision Support Tools, Explained
What 45 CFR 92.210 requires since 1 May 2025: identifying decision support tools that use protected-class inputs, mitigating discrimination risk, and what OCR expects to see.
Last reviewed September 5, 2026
- ONC HTI-1 Decision Support Interventions, Explained
What the HTI-1 decision support interventions criterion (45 CFR 170.315(b)(11)) requires of certified health IT developers, what it means for the organizations that deploy them, and where HTI-5 stands.
Last reviewed September 5, 2026
- State Healthcare AI Laws: Texas, California, Colorado, Explained
What Texas SB 1188 and HB 149, California AB 3030, and Colorado HB 26-1139 require of providers and payers using AI in care and patient communication, with the Joint Commission / CHAI guidance.
Last reviewed September 5, 2026
- FDA's AI-Enabled Device Guidance: PCCP and Lifecycle, Explained
What FDA's final predetermined change control plan guidance (December 2024) and draft lifecycle guidance (January 2025) recommend for AI-enabled device software functions, and what a deploying organization can prepare.
Last reviewed September 5, 2026
This reference summarises publicly available regulatory guidance and is provided for general information. It is not legal advice. Obligations depend on an institution's charter, size, activities, and supervisory relationship. Verify against the primary sources cited on each page and consult counsel before relying on any summary here.