How to Build a Resilient AI Governance Program in the Era of Evolving Regulation
Artificial Intelligence | ISO 42001
Published: Aug 10, 2026
This article was drafted based on a panel discussion between Schellman's Danny Manimbo, an AI-focused attorney, and an enterprise AI risk management leader. Watch the full conversation here: AI Governance in an Era of Evolving Regulation.
AI regulation and the downstream implications on governance seem to be regularly shifting. States are introducing and rewriting AI bills within the same legislative session. Federal officials are pushing to deregulate at the same time state legislatures are moving in the opposite direction. Even the regulators tasked with enforcement admit they're still working out basic definitions.
For compliance and governance teams, that uncertainty creates a real temptation to wait for the rules to settle before committing to a strategy. The panelists in this discussion made the opposite case, highlighting how the organizations that will be best positioned aren't waiting to build governance programs now that are designed to flex as the legal landscape keeps shifting around them.
A Case Study in Evolving AI Regulation: The Colorado AI Act
Colorado's AI Act is a glaring example of this kind of regulatory uncertainty, demonstrating just how unsettled this space still is. The original bill, SB 24-205, was signed into law but was immediately flagged by the governor as needing revision. A task force was convened, disbanded, and reconvened before a replacement bill, called SB 26-189, finally passed with broad, largely bipartisan support.
The original law leaned on NIST- and ISO-style risk management frameworks, with real compliance burden for both AI developers and the businesses deploying their systems. The revised law features a lighter-touch transparency regime, built around Automated Decision-Making Technology (ADMT).
In addition to the substance changing dramatically, enforcement also shifted. Rather than a standalone AI enforcement mechanism, violations now run through the Colorado Consumer Protection Act, narrowing the available remedies compared to the original bill.
The result is broader applicability, with a shallower compliance burden, and a preview of how quickly a state's flagship AI law can be rewritten in response to industry pushback and consumer group negotiation.
Regulators Are Still Figuring Out AI Governance Enforcement
It's tempting to assume regulators have a clear enforcement roadmap even when the law itself is ambiguous. In practice, that's often not the case. One panelist described a conversation with a market surveillance official responsible for enforcing the EU AI Act's deepfake provisions in Southern Italy, who acknowledged the agency hadn't yet settled on a working definition of "deepfake," let alone an enforcement approach.
This reflects how genuinely new and evolving this subject matter is, even for the people whose job is enforcement. For governance teams, it means official guidance and codes of practice are currently more actionable than the statutory text alone, and that a company's own documented risk judgment carries real weight when the rules haven't been fully operationalized yet.
How to Build a Resilient AI Governance Program
Organizations should stop treating individual regulations as the target. It's best practice to anchor your program to an established management framework instead, such as ISO 42001, and to treat specific state or national laws as overlays on top of that foundation, not the foundation itself.
A resilient program, regardless of jurisdiction, needs a few things to stay constant:
- A real inventory of AI systems and use cases across the business, not just the customer-facing ones.
- Risk-based prioritization, so effort goes toward the highest-impact systems first instead of trying to govern everything simultaneously.
- A documented, deliberative process for evaluating risk and stakeholder impact. Even a qualitative exercise, such as identifying stakeholders, foreseeable harms, and mitigations, and writing it down, demonstrates good-faith governance to a regulator, even short of full framework implementation.
- Clear, singular ownership. Diffused accountability functions the same as no accountability. Someone needs to be the final decision-maker when priorities conflict.
Don't Let AI Governance Become a Silo
AI governance strategies that get stood up as their own island, disconnected from security, privacy, and legal teams that already have relevant infrastructure and institutional knowledge, are programs that typically fail. The solution involves a minimum viable group of stakeholders (product, legal, compliance, trust & safety, privacy) with a clear escalation path, so decisions don't stall out waiting for consensus.
Equally as common are organizations that try to govern every AI use case at once and get stuck. The better approach is the same risk-based prioritization used everywhere else in the framework starting with what matters most and then expanding.
AI Governance Programs: What to Stop Worrying About, and What to Start
When asked directly, both panelists converged on similar advice:
- Stop trying to build a governance program from scratch. Much of what's needed, including incident response, risk assessment, and whistleblowing channels, likely already exists inside security, privacy, or legal functions. The job is extending and adapting those capabilities, not duplicating them. And don't rush toward governing agentic AI systems before you've even governed your basic chatbots.
- Start taking agentic AI seriously as its own category. Once a system can take autonomous action, such as accessing data, executing tasks, and sending communications, the threat model, identity and access management needs, and risk profile change substantially, and most governance programs haven't caught up yet.
- Also worth prioritizing: governing your actual relationships. That means acceptable-use policies for employees, updated client agreements that account for AI-assisted service delivery, and an internal risk management framework that ties it all together.
Moving Forward with AI Governance Strategies
Meaningful federal preemption of state AI laws isn't realistic without a federal law to preempt with, and none currently exists. Until that changes, states will keep filling the gap, sometimes inconsistently. For governance teams, the practical takeaway is the same regardless of which law is in effect this quarter: the specific requirements will keep shifting, but a well-documented, risk-based, cross-functional program is built to survive that churn.
To learn more about how to develop a resilient AI governance roadmap, contact us today. In the meantime, discover additional AI governance insights in these helpful resources:
- AI Regulation Keeps Evolving: How to Develop an AI Governance Framework That Adapts
- 5 AI Governance Practices to Build Trust and Drive Results
- AI Governance and ISO 42001 FAQs: What Organizations Need to Know in 2026
- Understanding ISO 42001: Responsible AI Governance in an Evolving Regulatory Landscape
About Danny Manimbo
Danny Manimbo is a Principal at Schellman based in Denver, Colorado, where he leads the firm’s Artificial Intelligence (AI) and ISO services and serves as one of Schellman’s CPA principals. In this role, he oversees the strategy, delivery, and quality of Schellman’s AI, ISO, and broader attestation services. Since joining the firm in 2013, Danny has built more than 15 years of expertise in information security, data privacy, AI governance, and compliance, helping organizations navigate evolving regulatory landscapes and emerging technologies. He is also a recognized thought leader and frequent speaker at industry conferences, where he shares insights on AI governance, security best practices, and the future of compliance. Danny has achieved the following certifications relevant to the fields of accounting, auditing, and information systems security and privacy: Certified Public Accountant (CPA), Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), Certified Internal Auditor (CIA), Certificate of Cloud Security Knowledge (CCSK), and Certified Information Privacy Professional – United States (CIPP/US).