AI Governance in an Era of Evolving Regulation
Published: Jul 20, 2026
The regulatory landscape for AI is evolving and shifting, bringing downstream implications on governance that can't be ignored. Colorado's AI Act has already been rewritten once before even taking effect. States keep introducing new bills. Federal preemption remains more theory than reality. For companies trying to build AI compliance programs, the environment remains complex.
In this conversation, Schellman's Danny Manimbo is joined by an AI-focused attorney and an enterprise AI risk management specialist to unpack what actually happened with Colorado's AI Act, why regulators themselves are still figuring out how to enforce these laws, and what a governance program should look like when it can't be tied to any single piece of legislation.
If you're responsible for AI governance at your organization or are just curious about what the landscape looks like today, this conversation is worth your time. You'll come away with a clearer picture of why frameworks like ISO 42001 matter more than ever, how to avoid siloing governance across legal, security, and compliance teams, and what to prioritize as agentic AI adoption accelerates.
About Danny Manimbo
Danny Manimbo is a Principal at Schellman based in Denver, Colorado, where he leads the firm’s Artificial Intelligence (AI) and ISO services and serves as one of Schellman’s CPA principals. In this role, he oversees the strategy, delivery, and quality of Schellman’s AI, ISO, and broader attestation services. Since joining the firm in 2013, Danny has built more than 15 years of expertise in information security, data privacy, AI governance, and compliance, helping organizations navigate evolving regulatory landscapes and emerging technologies. He is also a recognized thought leader and frequent speaker at industry conferences, where he shares insights on AI governance, security best practices, and the future of compliance. Danny has achieved the following certifications relevant to the fields of accounting, auditing, and information systems security and privacy: Certified Public Accountant (CPA), Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), Certified Internal Auditor (CIA), Certificate of Cloud Security Knowledge (CCSK), and Certified Information Privacy Professional – United States (CIPP/US).