Exposing The Gap Between AI Regulatory Awareness and AI Regulatory Readiness
Published: Oct 8, 2026
Most enterprise leaders have some level of awareness of emerging and upcoming AI regulations that may apply to their organization in the near future. Yet, not all have actually started preparing for enforcement of those regulations to take effect.
That's the finding at the center of one of the five key themes uncovered in Schellman's 2026 State of AI Governance research report around an impending regulatory reckoning. Specifically, AI governance readiness and preparation is not as widespread, common, or consistent as awareness.
AI Regulatory Awareness vs. AI Compliance Readiness
According to our research, 84% of manager-level respondents and 94% of directors are aware of state-level regulations that could apply to their organization, and 94% of surveyed organizations operate somewhere with AI regulatory requirements already in effect.
In tandem with that awareness, 89% of organizations have taken specific action to prepare for U.S. regulations, reflected through develops in their governance programs around policy updates, internal reviews, and documented controls.
Yet outside of the U.S., that number declines considerably. Only 29% have prepared for EU AI Act compliance and just 12% have taken action on APAC requirements. This data implies that readiness scales with proximity and familiarity but drops sharply once a regulatory framework is unfamiliar, foreign, or still evolving.
While regional readiness varies, most organizations aren't approaching this without some structure already in place through the adoption of a governance framework. What varies here is which AI governance frameworks organizations are adopting.
Which AI Governance Frameworks Are Organizations Actually Using?
Even with regulatory preparedness varying sharply by region, most have already adopted some kind of governance framework to structure their response, but our research shows just how fragmented that adoption still is:
- 23% of organizations have already implemented ISO 42001
- 28% report having the NIST AI Risk Management Framework (NIST AI RMF) in place,
- 36% have built a proprietary or internal AI governance framework instead of adopting an external standard
Rather than most organizations rallying around a single standard, adoption is split nearly three ways between a formal international certification, an established cybersecurity framework, and a homegrown internal approach.
That fragmentation helps explain why regional readiness varies as much as it does: an internationally recognized certification, a framework built for AI risk, and an internal policy designed around one organization's specific tools don't prepare an organization for the same set of regulatory obligations in the same way.
It also shows up as a named obstacle in its own right: 24% of organizations say difficulty choosing the right framework is the biggest barrier to advancing their AI governance program.
Building a Governance Program in Preparation for AI Regulations
Closing the gap between AI regulatory awareness and readiness requires building a governance program resilient enough to adapt to change without starting over each time a deadline shifts or a new jurisdiction activates.
That starts with staying current on regulatory activity as it emerges, then mapping each relevant regulation against existing controls to identify where gaps actually sit. From there, the work becomes prioritization: sequencing implementation around the highest-risk and nearest-term requirements, and allocating budget and resources accordingly. The organizations doing this well treat it as an ongoing cycle.
The distance that remains is between knowing a regulation applies and having a program built to prove compliance with it. The full report includes the complete regional breakdown and a four-stage framework for building a regulatory-ready governance program from the ground up.
About Joe Sigman
Joe Sigman is a Manager with Schellman based in Denver, Colorado. Prior to joining Schellman in 2021, Joe worked as a Senior Associate at a management consulting firm specializing in IT strategy and compliance, solution architecture, and enterprise digital transformation. Joe has led and supported AI Assessments, Cybersecurity Assessments, Information Security Architecture Solutioning, Information Technology Gap Analysis, and Cloud Migration Roadmaps. Joe has over 6 years of experience comprised of serving clients in various industries, including Information Technology, Professional Services, Healthcare, and Energy. Joe is now focused primarily on ISO Certifications for organizations across various industries.