CMMC Readiness: How to Prepare and Incorporate a Zero Trust Strategy for Your CMMC Scope | October 14th @ 1:00PM ET

Contact Us
Services
Services
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
Sustainability Services
Sustainability Services
AI Governance
AI Governance
About Us
About Us
Leadership Team
Leadership Team
Corporate Social Responsibility
Corporate Social Responsibility
Careers
Careers
Strategic Partnerships
Strategic Partnerships

Exposing The Gap Between AI Regulatory Awareness and AI Regulatory Readiness

Artificial Intelligence

Published: Oct 8, 2026

Most enterprise leaders have some level of awareness of emerging and upcoming AI regulations that may apply to their organization in the near future. Yet, not all have actually started preparing for enforcement of those regulations to take effect.  

That's the finding at the center of one of the five key themes uncovered in Schellman's 2026 State of AI Governance research report around an impending regulatory reckoning. Specifically, AI governance readiness and preparation is not as widespread, common, or consistent as awareness.  

AI Regulatory Awareness vs. AI Compliance Readiness  

According to our research, 84% of manager-level respondents and 94% of directors are aware of state-level regulations that could apply to their organization, and 94% of surveyed organizations operate somewhere with AI regulatory requirements already in effect. 

In tandem with that awareness, 89% of organizations have taken specific action to prepare for U.S. regulations, reflected through develops in their governance programs around policy updates, internal reviews, and documented controls.  

Yet outside of the U.S., that number declines considerably. Only 29% have prepared for EU AI Act compliance and just 12% have taken action on APAC requirements. This data implies that readiness scales with proximity and familiarity but drops sharply once a regulatory framework is unfamiliar, foreign, or still evolving.  

While regional readiness varies, most organizations aren't approaching this without some structure already in place through the adoption of a governance framework. What varies here is which AI governance frameworks organizations are adopting.  

Which AI Governance Frameworks Are Organizations Actually Using? 

Even with regulatory preparedness varying sharply by region, most have already adopted some kind of governance framework to structure their response, but our research shows just how fragmented that adoption still is: 

Rather than most organizations rallying around a single standard, adoption is split nearly three ways between a formal international certification, an established cybersecurity framework, and a homegrown internal approach.  

That fragmentation helps explain why regional readiness varies as much as it does: an internationally recognized certification, a framework built for AI risk, and an internal policy designed around one organization's specific tools don't prepare an organization for the same set of regulatory obligations in the same way.  

It also shows up as a named obstacle in its own right: 24% of organizations say difficulty choosing the right framework is the biggest barrier to advancing their AI governance program.  

Building a Governance Program in Preparation for AI Regulations 

Closing the gap between AI regulatory awareness and readiness requires building a governance program resilient enough to adapt to change without starting over each time a deadline shifts or a new jurisdiction activates. 

That starts with staying current on regulatory activity as it emerges, then mapping each relevant regulation against existing controls to identify where gaps actually sit. From there, the work becomes prioritization: sequencing implementation around the highest-risk and nearest-term requirements, and allocating budget and resources accordingly. The organizations doing this well treat it as an ongoing cycle. 

The distance that remains is between knowing a regulation applies and having a program built to prove compliance with it. The full report includes the complete regional breakdown and a four-stage framework for building a regulatory-ready governance program from the ground up. 

Download The 2026 State of AI Governance Report Here 

About Joe Sigman

Joe Sigman is a Manager with Schellman based in Denver, Colorado. Prior to joining Schellman in 2021, Joe worked as a Senior Associate at a management consulting firm specializing in IT strategy and compliance, solution architecture, and enterprise digital transformation. Joe has led and supported AI Assessments, Cybersecurity Assessments, Information Security Architecture Solutioning, Information Technology Gap Analysis, and Cloud Migration Roadmaps. Joe has over 6 years of experience comprised of serving clients in various industries, including Information Technology, Professional Services, Healthcare, and Energy. Joe is now focused primarily on ISO Certifications for organizations across various industries.