The Platform PM
Field Guide

AI governance and model risk

Trace an AI use case from proposal to retirement, tell which rules reach it (EU AI Act, US states, bank model risk), build the evidence auditors and customers ask for, budget the program and know who pays when an AI decision goes wrong.

Last updated October 2026

The industry on one page

The parties. Your company builds AI or buys it from model providers, and its governance team approves and monitors each use. Regulators set the rules, auditors test the evidence and customers ask for proof. Most of the obligations, and most of the liability, land on the company using the AI.

Picture a regional lender in the US with about 3,000 staff, roughly $40 billion in assets and some customers in the EU. Its underwriters want an assistant that summarizes loan files and drafts the letters telling applicants why they were turned down. The lender won't build a model. It buys one from a lab such as OpenAI, Anthropic or Google through the cloud it already uses, and the model providers in the diagram also include every software vendor that has added AI to a product the lender pays for. So your company builds AI or buys it from model providers, and its governance team approves and monitors each use. At the lender that team is model risk management, the bank function that has validated credit and pricing models for years, working with legal, compliance, privacy and security. Regulators set the rules: the EU for anyone whose AI touches people there, US states for hiring, insurance and consumer decisions, and sector supervisors such as the bank regulators. Auditors test the evidence, from internal audit to an outside assurance firm or a certification body. And customers ask for proof, through contracts and questionnaires, which is how most B2B software companies first meet AI governance. Most of the obligations, and most of the liability, land on the company using the AI, so most of the work lands there too.

The work itself is a set of moves banks have run since 2011, when US supervisors issued their model risk guidance: list every model, sort them by risk, have someone independent challenge each one in proportion to that risk, watch them in production and retire them on purpose. Insurers, regulators in Canada and the EU, the ISO standard and enterprise buyers now copy that shape, even though the US bank regulators stopped applying it to generative AI in April 2026.

If you only remember a few things:

  1. Inventory: build the list of AI you run from purchasing records and security tools as well as intake forms, because most of it arrives as features inside software you already bought or as staff on personal accounts. Very few companies have a complete list, and every rule assumes you do. See How a use case gets approved, step by step.
  2. Tiering: sort each use case into a risk tier before deciding how much to test it, and keep the low tier fast. Independent testing and re-testing are most of the cost, so the tier sets the bill, and a slow approval sends people to unapproved tools. See A year of governance at the lender.
  3. Liability: assume the obligations and the liability are yours when you use the AI, and keep the evidence that you were careful: the record, the approval, the tests and the logs. Model makers cap what they owe at about a year of fees. If you sell a tool that scores or ranks people, courts now reach you as well, as Liability allocation shows.
  4. Monitoring: plan to re-test every time a vendor changes or retires the model under a live use case, and budget for that once or twice a year. The same model name can answer differently from one month to the next, and retirement notices can be as short as two months.
  5. Rules: comply with what's already in force instead of waiting for the EU's high-risk deadline, which has slipped to the end of 2027. State hiring and insurance rules, EU transparency duties and credit notices apply now, and a US bank's model risk guidance no longer covers its generative AI. See How the rules work.
  6. Buying: buy what the people checking your work ask for. A B2B AI vendor needs a certification and a library of questionnaire answers; a bank extends the model risk tools it has. A vendor's certificate covers its own management system and says nothing about how you use its model, as AI governance software: what's real explains.

This guide is the governance layer across the other AI guides, and I don't repeat them. What labs owe under the EU AI Act, their indemnities and retirement notices are in Models and inference; evals and agent security in AI agents: orchestration platforms; compliance programs and consent orders in Identity and trust; and how a leader adopts AI, Reg B notices included, in Becoming AI native.

The main players

These are the companies behind the diagram's parties, layer by layer, in no particular order.

Model providers

What they do
Sell the models and AI features a company governs; certify their own management systems
Main players
OpenAI, Anthropic, Google, Microsoft, AWS, IBM (Granite)
What they control
Model versions, retirement dates, what they disclose, usage policies, liability caps

AI governance suites

What they do
Registry of AI use cases, intake, risk assessments, rule packs, evidence
Main players
IBM (watsonx.governance), ServiceNow (AI Control Tower), OneTrust, SAP, Microsoft (Purview)
What they control
The inventory and the approval workflow

Independent governance specialists

What they do
The same jobs, sold on their own
Main players
Truyo, Credo AI, Holistic AI, Airia, Monitaur, Saidot (Finland)
What they control
Rule libraries and assessments for teams with no system of record yet

GRC and compliance automation

What they do
Governance, risk and compliance suites with AI modules; ISO 42001 as one more framework
Main players
AuditBoard (Hg), Archer, MetricStream, Diligent, Vanta, Drata
What they control
Controls mapping, audit evidence, trust centers

Bank model risk tools

What they do
Model inventories, validation workflow, documentation
Main players
SAS, ValidMind, IBM (OpenPages), in-house builds and Excel
What they control
The model inventory examiners read

AI security and shadow-AI discovery

What they do
Find AI in use on the network and in SaaS, filter prompts, red team
Main players
Netskope, Palo Alto Networks, Cisco, Check Point, SentinelOne, Microsoft
What they control
The telemetry that finds unapproved AI

Assurance and certification

What they do
Independent reviews, attestations, ISO 42001 certificates
Main players
PwC, Deloitte, KPMG, Schellman, BSI
What they control
What a certificate or an assurance report means

Insurers

What they do
Cover or exclude AI losses
Main players
Munich Re, Armilla (a Lloyd's coverholder), AIUC; AIG and W. R. Berkley on exclusions
What they control
Whether an AI loss is paid

How they make money, and who's moving:

  • Model providers sell models and AI features and treat governance as a sales requirement: AWS, Anthropic, Microsoft, Google and IBM certified parts of their AI work to ISO/IEC 42001 between November 2024 and 2025. Their terms push decision risk down, with usage policies requiring human review for credit, employment, insurance, housing and health decisions, and liability capped at about 12 months of fees.
  • Suites sell governance inside a platform the buyer already has. IBM lists watsonx.governance on AWS at $42,000 a year for five use cases and topped Gartner's first ranking of the category in 2026. ServiceNow includes AI Control Tower in its base tier, meters use in consumption units and bought Traceloop, an LLM observability company, for a reported $60-80 million in March 2026. None of the suites reports AI governance revenue separately.
  • Independents are small next to the suites. Credo AI raised $21 million at a $101 million valuation in July 2024 and prices per AI use case. Airia announced $100 million in September 2025, half of it committed by a co-founder rather than paid in. Truyo, which started in privacy-rights automation, was one of three Leaders in Gartner's 2026 ranking, and Holistic AI, in London, its only Challenger.
  • GRC and compliance automation added AI by acquisition or as a framework. Hg agreed to take AuditBoard private for more than $3 billion in May 2024, and AuditBoard agreed to buy FairNow, an AI registry, in October 2025. Vanta, valued at $4.15 billion in July 2025, has offered an ISO 42001 framework since March 2024.
  • Bank model risk tools sell to the chief risk officer. SAS says Chartis, a risk-technology analyst, has rated it top in model risk management 11 years running; ValidMind raised an $8.1 million seed in 2024.
  • Security vendors bought nearly every standalone AI runtime-security startup in 2025, from Palo Alto Networks buying Protect AI (reported at $650-700 million) to SentinelOne closing Prompt Security for about $134 million. They sell shadow-AI discovery inside web-security seats; Netskope reported $811 million of annual recurring revenue for its 2026 fiscal year, up 31%.
  • Assurance firms sell reviews and opinions: PwC launched "Assurance for AI" in the US in June 2025 and Deloitte expanded its AI assurance services in August 2026. Schellman says it was the first certification body accredited for ISO 42001 in the US, and BSI was the first in the UK.
  • Insurers are moving both ways: generative-AI exclusions entered standard US liability forms in January 2026, while Armilla offers AI cover up to $25 million (as it reports).

As of October 2026. Most private-company figures are self-reported or from press coverage, and analyst placements are reported by the vendors, so treat the list as a map to check.

Back to the lender. The request for the underwriting assistant goes into ServiceNow's AI Control Tower, where the governance team logs it against the bank's model inventory in SAS. Netskope, the lender's web-security tool, had already shown underwriters pasting loan files into personal chatbot accounts, which is partly why the request exists. The model comes from a lab through the lender's cloud, with Amazon Bedrock Guardrails filtering personal data out of prompts. An outside firm red teams the assistant, a fair-lending specialist tests the letters, the risk committee approves it with conditions, and internal audit later checks them. One use case touches six or seven companies, and only the lender's own record ties them together (the vendors in the story are illustrative).

How a use case gets approved, step by step

One AI use case, from proposal to retirement. The riskier the use, the more testing and oversight it gets before launch. After launch the model can change under you, through drift or a vendor's update, so monitoring never ends until the use case is retired.

Here's the lender's assistant, from proposal to retirement. The riskier the use, the more testing and oversight it gets before launch. After launch the model can change under you, through drift or a vendor's update, so monitoring never ends until the use case is retired.

  1. Proposed. A business owner submits the use case: purpose, users, data, which decisions it touches, which vendor and model. It gets an ID, an owner and a status in the inventory. Someone also has to find the AI already in use (SaaS features, browser extensions, personal accounts), and that list usually comes from security tools. What can go wrong: most AI never gets proposed. In a 2026 survey by OneTrust, which sells governance software, a third of companies said staff used unapproved AI because the approved route was too slow, so a slow intake creates the shadow AI it's meant to catch.
  2. Assessed. The use case is risk tiered. Is it prohibited? High-risk under the EU AI Act (credit scoring is, from December 2, 2027)? A consequential decision under a state law? How material is it, by exposure (how many decisions, how much money) and purpose? Then come impact assessments (the EU's fundamental rights assessment for credit scoring, a GDPR assessment, or ISO/IEC 42005), vendor due diligence on data use and notice of model changes, and legal review. The exception on the diagram, Blocked, happens here: the use is prohibited, such as emotion recognition at work in the EU, or too risky for the controls on offer. In a US bank there's an extra fork: under the April 2026 guidance a generative AI assistant isn't a "model", so it goes to a separate AI register. What can go wrong: the use case is under-tiered and grows quietly; the same tool counts as a model under one definition and not another; a rejected use case carries on through personal accounts.
  3. Validated. The use case is tested: task evals on real loan files with known answers, bias tests on the draft letters, red teaming for prompt injection and data leaks, and a sample of outputs checked by people. In banks this is "effective challenge", critical review by people with the expertise, independence and standing to force a change. A foundation model can't be validated like a credit score; one large bank's AI head told Risk.net "You cannot validate a foundation model", so the work shifts to testing behavior. What can go wrong: validation becomes box-ticking; the vendor won't share what proper testing needs; tests pass and nobody records which model version they ran on.
  4. Deployed. The use case is approved, usually with conditions: a human reviews each letter, volumes are capped, monitoring thresholds and a review date are set. Launch brings the notices (adverse-action reasons under Reg B, an AI disclosure under EU Article 50 for a chatbot), user training and logging; EU deployers of high-risk systems keep logs for at least six months. US bank guidance lets a model go live before validation finishes when the need is urgent, with limits and closer monitoring. What can go wrong: the conditions never get closed; the human reviewer approves everything; the conditional launch becomes permanent.
  5. Monitored. The use case is watched: quality and drift metrics, how often underwriters override the draft, complaints, incidents, cost, and the vendor's change and retirement notices. That's the diagram's note, because models change under you. In a 2023 study, GPT-4's accuracy at identifying prime numbers fell from 84% to 51% between its March and June versions; critics said that measured a shift in default answers, but the same model name behaved differently either way. Lab retirement notices run from about 60 days to six months, and every change means re-testing and sometimes re-approval. What can go wrong: the vendor retires the model and nobody re-tests; an incident isn't escalated (in the same OneTrust survey, only 27% of companies said they had slowed or paused a deployment in response to AI incidents).

Retired is the other exception, when the use case is replaced or failed. The owner tells users, switches to a fallback, archives the model version, prompts, eval results and logs, and watches for effects downstream. Canada's OSFI E-23 is the only regulator text I found that spells this out, down to keeping the retired model as a benchmark or fallback, which is impossible for a vendor model you never held. Records outlive the model: EU deployer logs, California's four-year rule for hiring data, any court order to reproduce a decision.

Cheat sheet: which rules reach which use (October 2026)

Credit decisions (US)

In force now
Reg B adverse-action reasons; state fair-lending law; FCRA notices
Coming
Colorado (January 1, 2027, may slip); California automated-decision rules (January 1, 2027)
Who carries it
The lender

Credit scoring or life and health insurance pricing (EU)

In force now
GDPR automated-decision rights; Article 50 if a chatbot faces customers
Coming
High-risk duties and a fundamental rights impact assessment (December 2, 2027)
Who carries it
Deployer: oversight, logs, assessment. Provider: conformity

Hiring and promotion

In force now
NYC bias audits; Illinois; California's rule treating vendors as agents; Connecticut's "AI is not a defense"; federal statutes through private suits
Coming
California and Colorado (January 1, 2027); Connecticut notices (October 1, 2027); EU (December 2, 2027)
Who carries it
The employer, and the vendor as its agent

Insurance pricing and claims (US)

In force now
NAIC bulletin in about 25 states; Colorado's regulation; New York guidance; state limits on AI-only prior-authorization denials
Coming
NAIC evaluation tool
Who carries it
The insurer

Customer chatbot

In force now
EU Article 50 disclosure; FTC deception rules; the Air Canada ruling
Coming
EU marking grace ends December 2, 2026
Who carries it
The company running it

Health care decision support (US)

In force now
HHS rule on discrimination in patient care tools; FDA change plans for AI devices
Coming
Who carries it
The hospital or insurer

Internal assistant, no decision about a person

In force now
Company policy, vendor terms, customer contracts; in a US bank, "broader risk management"
Coming
OSFI E-23 for Canadian banks and insurers (May 1, 2027)
Who carries it
The company

Which tier does a use case need? Five questions

  1. About a person? Credit, hiring, insurance, housing and health care are where almost every rule and lawsuit sits. A tool drafting marketing copy and a tool ranking applicants can run on the same model and need very different treatment.
  2. On a list? Check the EU's prohibited practices and high-risk categories, the state laws on hiring and insurance, and your sector's rules. A prohibited use stops at assessment; a listed one goes to the top tier.
  3. Your role? Under the EU AI Act, putting your name on a system, changing it substantially or using a general-purpose model for a high-risk purpose makes you its provider, with every provider duty. In the US a vendor whose tool screens or ranks people can be sued as its customer's agent.
  4. How exposed? Banks score materiality from exposure and purpose, and that works anywhere. Re-tier when volume grows.
  5. Can you show it? If you can't produce the inputs, outputs and approval for one applicant two years later, or re-run your tests on a new model version within the vendor's notice period, the use case needs more control before launch.

My defaults: three tiers. The top tier is anything that makes or shapes a decision about a person or sits on a regulator's list: independent testing and bias testing before launch, a named reviewer with authority to override, logs kept as long as the longest rule that applies, re-testing on every model change and a yearly review. The middle tier covers customer-facing tools that decide nothing: team testing, a governance review, an AI disclosure and monitoring. The low tier is internal productivity on approved vendors: a register entry, an acceptable-use policy and a self-serve intake that takes a day, because a slow lane sends people to personal accounts. I'd record the vendor and model version on each use case, so a retirement notice tells me which ones to re-test.

The primitives

01

Entity and identity

What is the unit of record, and how do we know it is the same one?

The governed unit depends on who's asking. US bank guidance governs a "model", which the April 2026 text narrowed to complex quantitative methods built on statistical, economic or financial theory, leaving out spreadsheet arithmetic, deterministic rules and generative AI. Canada's OSFI E-23 widens "model" to include AI and machine learning methods and judgment-based tools. The UK's PRA covers vendor models "regardless of technology". The EU AI Act, NIST and ISO 42001 talk about an "AI system", and most company registers track a use case. I'd key the register on the use case (purpose, users, data, decisions affected) and link models, vendors, prompts and datasets to it, because one model serves many use cases and one use case can swap models.

Roles carry identity too. Banks name a model owner, developer, validator and user. The EU separates the provider, who places a system on the market under its own name, from the deployer, who uses it professionally, and those roles attach per system and can flip. US law keys on the decision-maker's legal role (creditor, employer, insurer, health care provider) and now pulls vendors in as the employer's "agent" (Workday, California's rules), as a consumer reporting agency (a theory in a 2026 suit against Eightfold) or under housing law (SafeRent). For each use case I'd write down which entity decides and which vendor a court could call its agent.

More on Entity and identity →

02

State and lifecycle

What states exist, and what moves an entity between them?

A use case moves through discovered, proposed, in assessment, approved with conditions, live, under review or suspended, changed and re-validated, retired and archived. The April 2026 US guidance is silent on retirement; Canada's E-23 has an explicit decommissioning stage. Vendors run their own states on their own clocks (active, legacy, deprecated, retired, meaning slightly different things at each lab and cloud), and those states drive yours.

Laws have lifecycles too: Colorado's AI Act was enacted in 2024, delayed, paused by a court stipulation, then repealed and replaced in May 2026. Most AI lawsuits in 2026 sit between discovery and class certification, and an ISO 42001 certificate lasts three years, with a surveillance audit each year.

More on State and lifecycle →

03

System of record and ledger

Who owns the truth, and how do systems reconcile?

The inventory is the ledger. US bank guidance wants enough information to understand model risk "at the individual and aggregate levels", and E-23 lists required fields. The fields I'd keep:

FieldWhy it matters
ID, name, ownerSomeone answers for it
Purpose, users, decisions affectedSets the tier and which rules apply
Vendor, model and versionTells you what to re-test when a vendor changes something
Data usedPrivacy and bias questions
Approval, conditions, review dateWhat was agreed and when it expires
Validation dates, findings, open exceptionsUS guidance asks banks to track "recommendations, responses, and exceptions"
Monitoring metrics and incidentsEvidence it still works
Retirement date and archive locationWhat you'd show a court later

Even banks keep it in modest tools: in Deloitte's 2025 survey of 87 banks in Europe, the Middle East and Africa, 24% still used Excel as their main model risk tool. The evidence itself lives in eval runs, traces, tickets and logs.

Litigation turns these records into evidence. Cigna produced about 2.1 million pages in a suit over its claim-review algorithm, and Workday was ordered to produce its federal equal-employment reports. Retention rules set the floor: six months for EU deployer logs of high-risk systems, four years for automated hiring data in California. The test I'd use: if a court asked for every input and output for one applicant from 2024, could we produce them?

More on System of record and ledger →

04

Rules and policy

What logic decides outcomes, and who can change it?

The policy stack runs from an AI policy and an acceptable-use policy down to tiering rules, an approval matrix and vendor standards; in a bank it sits next to the model risk policy. The operational pieces lag: in a 2026 survey by Schellman, which sells ISO 42001 audits, 44% of US companies with 500 or more staff had incident procedures specific to AI.

Tiering combines an outside screen with an inside score. US bank guidance measures materiality as exposure plus purpose, with inherent risk on top; E-23's inherent risk rating sets review intensity, documentation, the approver and monitoring; the EU tiers by use.

The binding rule often sits in a consent order or a contract instead of a statute. Massachusetts' settlement with Earnest, a student lender, requires an AI inventory, risk assessments, testing, documentation and an oversight team, which reads like a bank model risk program. Labs' usage policies require human review in credit, employment, insurance, housing and health, and customer contracts add their own conditions on top.

More on Rules and policy →

05

Effective dating

Which version of the rule applied at that moment?

Dates I'd keep on a calendar as of October 2026:

ChangeEffectiveStatus (Oct 2026)
EU AI Act prohibited practicesFebruary 2, 2025In force; no fines found
California rules on automated hiring decisionsOctober 1, 2025In force
SR 26-2 replaces SR 11-7 for US bank model riskApril 17, 2026In force; not enforceable; excludes generative and agentic AI
Colorado insurance AI rules, auto and health complianceJuly 1, 2026In force
Disparate impact removed from Reg BJuly 21, 2026In force
EU Article 50 transparency dutiesAugust 2, 2026In force
Connecticut: relying on AI is no defense to discriminationOctober 1, 2026In force
EU marking grace ends; new prohibition on generated intimate imagesDecember 2, 2026Upcoming
Colorado's replacement AI law; California automated-decision complianceJanuary 1, 2027Upcoming; Colorado may slip
OSFI E-23 for Canadian banks and insurersMay 1, 2027Upcoming
Connecticut pre-decision notices in employmentOctober 1, 2027Upcoming
EU high-risk duties for Annex III uses (credit, hiring, insurance pricing)December 2, 2027Upcoming; moved from August 2, 2026
EU high-risk duties for regulated productsAugust 2, 2028Upcoming; moved from August 2, 2027

Dates here slip often: Colorado's moved twice, the EU's high-risk date by 16 months, and the Commission's guidelines on classifying high-risk systems, due by February 2, 2026, came out as a draft in May. Vendors' retirement dates are often "not sooner than" dates.

More on Effective dating →

06

Interfaces and standards

What format and protocol do counterparties speak?

StandardWhat it isWho asks for it
NIST AI RMF and its generative AI profile (2024)Voluntary US framework; inventory is GOVERN 1.6; under revision, no 2.0 by October 2026US buyers and regulators, as shared language
ISO/IEC 42001Certifiable AI management systemEnterprise procurement
ISO/IEC 42005 and 42006 (2025)Guidance for impact assessments; rules for the bodies that certify to 42001Assessment teams; buyers checking a certificate
CSA AI-CAIQ and STAR for AIA standard AI questionnaire; Level 1 self-assessed, Level 2 validated and requiring 42001 (from November 20, 2025)Enterprise buyers
SIG questionnaireShared Assessments' vendor questionnaire: 128 questions (Lite), 627 (Core), 1,936 (Detail)Enterprise buyers
SOC 2No AI-specific criteria found by October 2026; AI systems are scoped into ordinary reportsEnterprise buyers
NYC bias auditImpact ratios by sex, race and ethnicity, and their intersectionsNYC employers
EU code on marking AI content (June 10, 2026)Voluntary layered marking, such as metadata plus a watermark, and a common EU iconEU regulators

The interface that matters most is the crosswalk between frameworks (NIST publishes one to ISO/IEC 23894), and vendors sell "map once, comply many". Questionnaires still travel as spreadsheets and portal forms. Model cards, labs' system cards and the EU's technical file describe a model, and none of them is a validation report.

More on Interfaces and standards →

07

Networks and counterparties

Who sits between us and the outcome, and what do they want?

Inside the company, banks use the "three lines" model, and other companies copy it loosely:

LineIn a bankElsewhere
1st: build and runModel owner, developer, userProduct owner and the ML or platform team
2nd: challengeModel risk management: validation, policy, inventory oversightAI governance office, often in privacy, risk or legal
3rd: check the checkersInternal audit, which evaluates the program without redoing validationInternal audit if there is one; a certification body for 42001

Outside banks, privacy teams and legal or compliance teams each own AI governance in about a fifth of companies, ahead of IT, in the IAPP's 2025 survey. Around the company sit labs and clouds, SaaS vendors with AI inside, assurance firms, certification bodies and their accreditors, regulators, customers' procurement teams, plaintiffs' lawyers and insurers. Supply is concentrated: in the Bank of England and FCA's 2024 survey, the top three model providers made up 44% of all the model providers UK financial firms named.

More on Networks and counterparties →

08

Regulatory layering

Jurisdiction × activity × entity type: is it a license or a certification?

US bank

Sector layer
SR 26-2 (generative AI out); third-party risk guidance; fair lending
Horizontal layer
State laws; EU AI Act if it serves people in the EU
Voluntary and contractual layer
Examiners' expectations; ISO and NIST as language

EU bank

Sector layer
Financial-services governance, which the AI Act accepts for most quality and monitoring duties
Horizontal layer
AI Act; GDPR
Voluntary and contractual layer

US insurer

Sector layer
NAIC bulletin or state rules (Colorado, New York)
Horizontal layer
State privacy and anti-discrimination law
Voluntary and contractual layer
Vendor audit rights

US employer

Sector layer
Federal anti-discrimination statutes
Horizontal layer
NYC, Illinois, California, Colorado, Connecticut
Voluntary and contractual layer
Vendor contract

B2B AI vendor

Sector layer
Its customers' sector rules, flowed down by contract
Horizontal layer
EU provider duties if its system is high-risk
Voluntary and contractual layer
Questionnaires, ISO 42001, AI addenda

One hiring decision in New York by a company based in the EU can touch the AI Act, GDPR, three federal statutes, state and city human-rights law, the city's bias-audit law, FCRA and the vendor's contract.

More on Regulatory layering →

09

Exceptions and reversals

What goes wrong, and how is it undone?

ExceptionWho starts itWhat happens
Use before validationThe business, for urgent needAllowed under US bank guidance with limits and closer monitoring; the conditions may never close
Out of scope by definitionThe guidanceA US bank's generative AI isn't a "model"; each bank decides whether to validate it anyway
Use beyond intended purposeThe businessNew analysis; in the EU, repurposing into a high-risk use makes you the provider
Vendor won't share internalsThe vendorBehavior tests, outcome monitoring, contract terms on change notice and audit
Forced change from outsideLab retirement, cloud auto-upgrade, a settlementUnplanned re-testing and re-approval
Rejected use caseThe governance teamOften continues on personal accounts
IncidentMonitoring, a complaint, a regulatorContain, notify, find the cause; EU high-risk providers report serious incidents within 15 days
Rule reversedA government or courtCFPB circulars withdrawn, EEOC guidance removed, an FTC order set aside, Illinois rules withdrawn, Italy's fine on OpenAI annulled

A rule withdrawn in Washington doesn't remove the statute behind it, and states and private plaintiffs can still sue.

More on Exceptions and reversals →

10

Liability allocation

When it fails, who pays?

FailureWho absorbs itMechanism
Biased screening or scoring of peopleThe deployer by default; increasingly the vendor that scoresAnti-discrimination law; California's "agent" rule; Connecticut's no-defense rule; Workday and SafeRent
Automated denial without real human reviewPatients first, then the insurer in litigationContract and good-faith claims; state laws requiring physician review
Chatbot misstatementThe company running itAir Canada
Misleading claims about an AI productThe vendorFTC and state attorneys general (Pieces, accessiBe, DoNotPay)
Vendor model changed or retiredThe deployerNotice periods, no compensation
Discrimination claim tied to a vendor's toolSplit by contractVendor caps of about 12 months of fees; whether discrimination is carved out isn't public
AI loss outside insurance coverThe insured companyGenerative-AI exclusions in liability forms since January 2026

The law reaches whoever makes or shapes the decision about a person: the deployer by default, and more and more the application vendor whose tool scores, ranks or screens. Model labs sit behind usage policies and caps of about a year of fees, and I found no case where a lab was held liable for a deployer's decision about a person. So the evidence splits: the deployer keeps the inventory, oversight design, notices, outcome monitoring and records; the vendor keeps testing, documentation and intended-use limits; contracts decide who pays between them. Vendors' certificates don't move this: AWS says customers aren't "automatically certified by association" with its ISO 42001 certificate.

More on Liability allocation →

What's different here

How the money moves

A company pays for governance in three places: people, tools and outside reviewers. Published tool prices, as of October 2026:

Pricing modelExamplePrice
Per AI use caseIBM watsonx.governance on AWS Marketplace$42,000 a year for 5 use cases, 25 concurrent users and 12,000 evaluations; about $16,000 per extra use case
Per use case, private offerCredo AI on AWS MarketplaceNot public; 12-36 month terms
Included in a platform tier, plus consumptionServiceNow AI Control TowerIn the base tier; usage metered in "Assists" with no published value per action
Per userMicrosoft Agent 365$15 a user a month
Runtime guardrails, per callAmazon Bedrock Guardrails; Google Model Armor$0.10-0.17 per 1,000 text units; $0.10 per million tokens after 2 million free
Compliance automation or GRC subscriptionVanta, Drata, AuditBoard, OneTrustMedians of about $12,000-46,000 a year in Vendr's buyer data, which leans mid-market
ISO 42001 certification auditAccredited certification bodiesRoughly $20,000-80,000 at first, $8,000-40,000 a year after (consultancies' ranges)

Per-call controls cost cents and the workflow tens or hundreds of thousands a year, so vendors earn on workflow and evidence, and per-use-case pricing grows the bill as you register the shadow AI you find.

A year of governance at the lender

My assumptions, stated plainly because almost none of these prices are published: the lender has about 3,000 staff, some EU customers, about 130 models in its inventory (the average for a medium-sized bank in Deloitte's survey), and 30-50 AI use cases including vendor features, 5-10 of them high-risk (credit, claims, hiring, customer chat). Loaded costs run $150,000-350,000 a year per person depending on the role.

LineWhat it coversA year
PeopleA head of AI governance; 1-3 analysts for intake, inventory, assessments and questionnaires; 1-3 extra validators; part of legal, privacy and security (3.5-8.5 people in all)$0.7-2.3 million
ToolsPlatform or module for about 40 use cases ($50,000-400,000); a framework add-on ($10,000-60,000); runtime guardrails (a few thousand dollars); AI monitoring ($20,000-150,000)$85,000-615,000
Audits and assuranceISO 42001 if pursued ($75,000-200,000 in year one); an outside review of 2-5 high-risk systems ($100,000-500,000); bias audits ($15,000-60,000 per tool)$150,000-800,000
TotalAbout $0.9-3.7 million

What the table says:

  • It's mostly people. Salaries are 60-75% of the total in most scenarios and tools 10-25%, so a tool choice matters for how much an analyst gets through more than for its licence.
  • A bank pays the increment. The lender already runs model risk management, so it pays for the extra validators and assessments. A company without that function builds from zero, and year one costs more if consultants do the discovery and write the policies.
  • The tier sets the bill. By a separate rough estimate, one top-tier generative AI use case costs about $200,000 to $1 million to govern in year one, model bill included: internal time across the stages, outside validation and red teaming ($40,000-250,000), bias testing, monitoring, and one or two re-validations after forced vendor changes ($20,000-120,000 each). A low-tier use case on self-serve intake might cost 5-10% of that. The two estimates rest on different assumptions and don't add up neatly: the program figure spreads people across all use cases and leaves out the model bill.

What customer AI reviews cost a vendor

Picture an HR software company that sells an AI feature ranking job applicants to large employers. Every big customer sends a security review that now asks about AI: whether the vendor trains on customer data, which sub-processors and labs it uses, where a human is in the loop, how much notice it gives of model changes. A typical review runs about 100 questions in data from SecurityPal, which sells questionnaire services. My assumptions for a Series C vendor with 250 enterprise reviews a year, all estimates:

LineAssumptionA year
Answering questionnaires250 reviews × 8-20 hours × $100-150 an hour$200,000-750,000
AI addendum and privacy terms60 deals × 4-10 hours of legal time × $200-400 an hour$48,000-240,000
Trust center and compliance automationA median subscription$20,000-25,000
ISO 42001, year oneConsultancies' ranges$75,000-200,000
Penetration test or AI red team for the evidence packAssumption$30,000-150,000
TotalAbout $375,000-1.4 million

Questionnaire cost grows with the number of deals, while a certificate is a fixed cost that cuts the effort per deal. That's the case compliance-automation vendors make, and the reason certification has spread among AI vendors faster than among the companies that buy from them. Delay matters less per deal than people fear (a three-week delay on a $50,000 deal defers about $2,900), though across 250 reviews it becomes real money.

Where the dollar goes

  • Consultants and assurance firms take the biggest pool. IBM's generative AI book of business passed $12.5 billion through 2025, and about four-fifths of it was consulting.
  • GRC and compliance automation is the best-funded part of the market: Vanta at $4.15 billion, AuditBoard at more than $3 billion.
  • Security and data platforms paid roughly $130-700 million each for AI security startups in 2025, and Veeam $1.725 billion for Securiti AI.
  • Independent governance specialists come last. Gartner sizes the whole category of dedicated platforms, suites included, at under half a billion dollars in 2026.

Who holds the power

  • Examiners and sector regulators hold the most power over banks, insurers and lenders, and it's shifting. US bank supervisors narrowed their guidance and made it unenforceable, while Canada's widened it to AI across banks and insurers, and the EU accepts bank governance for most AI Act duties.
  • Courts in discovery and class certification have the most practical power over companies using AI in decisions about people, because they force disclosure of how a model was designed and tested: Workday, UnitedHealth, Cigna, Humana.
  • State attorneys general are the most active US enforcers on AI decisions: Massachusetts against Earnest, Texas against Pieces Technologies, and AG-only enforcement in the Colorado, Connecticut and Texas statutes.
  • Enterprise buyers' procurement teams hold the most day-to-day power over B2B AI vendors. Their questionnaires and AI addenda decide deals faster than any law, and they increasingly ask for certificates.
  • Labs and clouds hold the clock: retirement dates, aliases that move silently, weights and training data they won't share. A deployer can negotiate notice and evidence.
  • The governance team holds the approval pen, and its power depends on what US bank guidance calls "organizational standing and influence to effect any change". Where it's slow, the business routes around it.
  • Security teams own the discovery telemetry and so hold the real list of shadow AI, while governance owns the register. I'd expect turf fights.
  • Certification bodies and analysts decide what a certificate means and who makes the shortlist, and insurers are starting to set terms of their own.

US federal agencies lost power over disparate impact in 2025-2026, and the EU gained it on paper from August 2026, with high-risk enforcement still more than a year away.

How the rules work

EU AI Act. It sorts uses into four tiers. Prohibited practices, banned since February 2, 2025, include social scoring, manipulative techniques causing significant harm, emotion recognition at work and in education, and untargeted scraping for facial recognition databases, with fines up to €35 million or 7% of worldwide turnover. High-risk uses include employment, education, credit scoring, life and health insurance pricing, biometrics and critical infrastructure (Annex III), plus AI inside regulated products (Annex I). Article 50 transparency duties cover chatbots, synthetic content and deepfakes, and the rest is minimal risk.

The Digital Omnibus (Regulation (EU) 2026/1744, in force since July 27, 2026) moved Annex III high-risk duties from August 2, 2026 to December 2, 2027, and Annex I to August 2, 2028. Article 50 kept August 2, 2026, with a grace period to December 2, 2026 for machine-readable marking on systems already on the market. The omnibus also added a prohibition, from December 2, 2026, on AI that generates non-consensual intimate images or child sexual abuse material.

Most high-risk duties sit with the provider: risk management, documentation, a quality management system, conformity assessment (for credit and hiring, the provider's own internal check), registration, post-market monitoring and serious-incident reports. The deployer, the lender in our example, must follow the instructions, assign competent human oversight, check its input data, monitor, keep logs for at least six months and tell people when a high-risk system is used in decisions about them. Public bodies and deployers doing credit scoring or life and health insurance pricing also owe a fundamental rights impact assessment, and can reuse a GDPR assessment for it. A deployer that rebrands a system, modifies it substantially or repurposes a general-purpose model for a high-risk use becomes its provider. Breaching the deployer or Article 50 duties can cost up to €15 million or 3% of turnover (the lower of the two for small companies). As of October 9, 2026 no AI Act fine had been found, and the Commission's guidelines on what counts as high-risk were still a draft.

US banks. On April 17, 2026 the Federal Reserve (SR 26-2), the OCC (Bulletin 2026-13) and the FDIC replaced the 2011 guidance, SR 11-7, with 12 pages. The new text says it doesn't set enforceable standards and that not following it "will not result in supervisory criticism", though unsafe or unsound practices can still be acted on. It's "most relevant" for banks above $30 billion in assets, drops fixed validation cycles and detailed independence rules, keeps effective challenge, and keeps vendor models in scope even when the vendor won't share code or data. Footnote 3 says generative and agentic AI models "are not within the scope of this guidance", and that the bank's broader risk management should guide controls for them.

For the lender's assistant, that means no supervisory guidance requires a model risk validation of it any more. The lender can still run it through model risk management, as some large banks reportedly did by default for generative AI, Copilot included, before the change. Either way the assistant needs controls under the bank's general risk framework, and examiners can still act on unsafe practices. The agencies promised a request for information on AI, generative and agentic included, "in the near future"; none had appeared in the Federal Register by mid-September 2026. Vendor AI relationships now fall under the guidance on outside vendors, whose replacement the agencies proposed on September 11, 2026, with comments due November 10. Banks elsewhere doubt the fit too: only 29% in Deloitte's survey thought their frameworks fully adequate for AI.

Canada and the UK. OSFI's E-23 was finalized on September 11, 2025 and takes effect on May 1, 2027. It covers every federally regulated bank, insurer and trust and loan company, defines models to include AI and machine learning, requires an inventory of models with more than negligible risk, lets the risk rating drive review and approval, and ends with decommissioning; generative AI isn't named. The UK's PRA SS1/23, in force since May 17, 2024, applies to banks with internal-model approval, covers vendor models regardless of technology and names a senior manager as responsible.

US credit. The Reg B rules on adverse action (specific principal reasons, within 30 days) didn't change. The CFPB's final rule effective July 21, 2026 removed the disparate-impact "effects test" from Reg B, over about 64,500 comments. Disparate treatment and proxies remain unlawful, and state fair-lending law still reaches disparate impact, which is how Massachusetts reached Earnest.

US hiring. An April 2025 executive order told agencies to eliminate disparate-impact liability "to the maximum degree possible", and the EEOC withdrew its AI guidance under Title VII and the ADA. The statutes and private suits are unchanged, and the action moved to cities and states. New York City has required an independent bias audit less than a year old, a public summary of impact ratios and notice to candidates since July 2023. Illinois made discriminatory AI in employment decisions a civil-rights violation from January 1, 2026. California's rules, from October 1, 2025, treat a vendor that screens or ranks for an employer as its agent and require four years of records. Connecticut makes relying on AI no defense to a discrimination claim from October 1, 2026. Colorado replaced its 2024 AI Act with a narrower law effective January 1, 2027 (notice, an explanation of adverse outcomes within 30 days, correction and human review), and enforcement is paused by agreement in a suit xAI brought and the Justice Department joined.

US insurance and health care. The NAIC's model bulletin of December 2023 asks insurers for a written AI program, governance and vendor oversight with audit rights, and about 25 states had adopted it by mid-2026, by law-firm and vendor counts. Colorado's regulation is binding for life, auto and health insurers. No enforcement under an adopted bulletin had been reported by early 2026. In health care, an HHS rule has required hospitals and insurers since May 1, 2025 to make reasonable efforts to find and reduce discrimination in patient care decision tools, and at least seven states passed laws in 2026 barring AI as the sole basis for prior-authorization denials.

The FTC and preemption. The FTC's 2023 order against Rite Aid faulted it for not asking its two vendors how their facial recognition was tested. Since 2025 the FTC has kept bringing AI deception cases and set aside a broader order against Rytr. No federal law preempted state AI laws by October 9, 2026: a December 2025 executive order set up a Justice Department task force against them, and a House draft would preempt state rules on model development for three years. Even that draft leaves rules on use alone, so I'd expect the deployer-facing laws to stay.

What mistakes cost

Let's say an employer with 5,000 staff and 60,000 applicants a year, hiring in New York City, Illinois, California, Colorado and Connecticut, buys the HR software company's ranking feature, which runs on a lab's model. My rough arithmetic, on stated assumptions:

  • Running it properly: the module at $50,000-250,000 a year, a bias audit at perhaps $10,000-60,000 a year (no prices are published), and $20,000-100,000 once for notices, opt-outs and four-year record keeping. The lab's share is a fraction of a cent per applicant.
  • If the tool skews against applicants over 40: New York City penalties of $500-1,500 per violation, each day without an audit counting separately; damages under Illinois law; and, if a court accepts the theory that the vendor is a consumer reporting agency, $100-1,000 per willful violation, a theoretical $6-60 million on 60,000 applicants. Real settlements have been far smaller: iTutorGroup paid $365,000 to more than 200 applicants, about $1,800 each, and SafeRent $2.3 million. Defense through class certification could run from the high six figures to the low eight.
  • Who pays: the employer always, because it made the decision, and in Connecticut relying on the tool is no defense. The HR software company is now a defendant in its own right; its contract probably caps its liability at 12 months of fees, $50,000-250,000 here, unless discrimination claims are carved out, which I found no public data on. The lab pays close to nothing, since its usage policy required human review, and general liability insurance increasingly excludes AI.

The record so far:

CaseWhat happenedWho paid
EEOC v. iTutorGroup, September 2023Software rejected women aged 55 and over and men aged 60 and overThe employer: $365,000 and monitoring
FTC v. Rite Aid, December 2023Thousands of false facial-recognition matches; no testing before launchThe deployer: a five-year ban and deleted models, no money
Texas v. Pieces Technologies, September 2024A health AI vendor claimed a "critical hallucination rate" below 0.001%The vendor: five years of accuracy disclosures, no money
Louis v. SafeRent, November 2024Tenant-screening scores challenged under the Fair Housing Act, though landlords made the final callThe vendor: $2.3 million and no scores for voucher holders for five years
Italy's data protection authority, 2024-2025GDPR fines of €15 million on OpenAI and €5 million on Replika's makerOpenAI's fine was annulled by a Rome court in March 2026
Massachusetts v. Earnest, July 2025AI underwriting models with alleged disparate impact on Black, Hispanic and non-citizen applicantsThe lender: $2.5 million and a governance program
Mobley v. Workday, ongoingApplicants allege age, race and disability bias in Workday's screening toolsNobody yet. On June 22, 2026 the court held Workday can be directly liable under California's FEHA for its own conduct on employers' behalf, rejected its argument that its liability depends on its customers', let disability proxy claims proceed and struck some new race claims. No liability finding or settlement
UnitedHealth, Humana, Cigna, 2023 onwardSuits over algorithms used in claim denialsPending: claims survived dismissal; Cigna's class-certification motion is due October 29, 2026

Regulators' payments in AI cases have been small, from nothing to $2.5 million. The cost so far is defense, remediation and multi-year compliance programs, and the evidence a company kept is what lowers both. Shadow AI has a price too: in IBM's 2025 breach study, companies with heavy shadow-AI use paid about $670,000 more per breach, a correlation but a large one.

AI governance software: what's real

My view as of October 2026: governance software is being folded into platforms companies already own, and what to buy depends on who checks your work. A bank buys for examiners, a B2B AI vendor for its customers' procurement teams, a large enterprise for its board. Most of the money in a program goes to people and outside reviewers, so a tool earns its place by how much an analyst gets through in a week.

What's on offer

  • AI governance platforms hold the registry of use cases, run intake and assessments, ship rule packs aligned to NIST and the EU AI Act, and collect evidence. Suites and independents both sell them.
  • GRC suites and compliance automation add AI as one more module or framework. AuditBoard, Archer, MetricStream and Diligent added AI governance modules; Vanta and Drata sell ISO 42001 in the same subscription as SOC 2, which one research firm called a natural upsell.
  • Existing model risk tools are what most banks use: in Deloitte's 2025 survey, over half governed AI in their existing tools rather than a dedicated platform.
  • Security and cloud controls cover discovery and runtime: shadow-AI discovery in web-security products, prompt filters priced in cents, compliance templates in Microsoft Purview.

Consolidation follows the same line. Platforms bought discovery and runtime telemetry (AuditBoard and FairNow, ServiceNow and Traceloop, Veeam and Securiti AI, and the 2025 security deals), and no standalone AI governance specialist had been bought at scale by October 2026. No suite publishes AI governance revenue, so the folding shows in products and deals more than in money.

How big the market is

Gartner, an analyst firm, said in February 2026 that spending on dedicated AI governance platforms would reach $492 million in 2026 and pass $1 billion by 2030. Forrester, another analyst firm, counts governance features built into AI software in general and puts its figure more than ten times higher by 2030. The estimates differ because they measure different things, and Gartner's own forecasts don't all agree either. I'd quote one figure only with its definition and wouldn't size a business on any of them. No survey I've seen separates what drives purchases: regulation, customers or insurers.

What the analyst rankings say

Gartner's first Magic Quadrant for AI governance platforms (its chart is dated May 2026) put two suites, IBM and ServiceNow, among the Leaders next to Truyo, an independent with roots in privacy software. Holistic AI was the only Challenger; OneTrust, Credo AI and Airia were among the Visionaries; SAP topped the Niche players. Forrester's 2025 Wave named Credo AI and IBM as Leaders. Banks read Chartis, which rates SAS a leader in model risk and AI governance. Every placement here comes from the vendors' own announcements, because the reports are paywalled.

Who buys what

BuyerWhat drives spending nowWhat they buy
Bank, insurer or lenderExaminers and existing rules (model risk, fair lending, NAIC)Extensions to model risk tools, validators, a GRC module
Large company outside financeBoard risk, EU AI Act readiness, AI sprawl across vendorsSuite modules from ServiceNow, OneTrust, Microsoft or IBM
B2B AI vendorCustomer questionnaires, ISO 42001, insurersCompliance automation, a certification audit, a trust center

Standalone platforms sell best where a team has no system of record yet.

What a certificate proves

ISO/IEC 42001 certifies an AI management system: policies, roles, a risk process, impact assessments and a set of controls. It doesn't certify a model's safety or fairness, and it isn't EU AI Act conformity. Many of the companies enterprises buy AI from have one: AWS (Bedrock and other services, November 2024), Google (Google Cloud, Workspace and the Gemini app), Microsoft (365 Copilot in 2025, recertified in 2026 with Copilot Studio added), Anthropic (January 2025), IBM (its Granite models, 2025), KPMG (late 2025, ahead of the rest of the Big Four) and others such as Snowflake. ISO doesn't publish a count of certificates for this standard.

Check three points on any certificate:

  • Scope. Certificates cover named services or systems, and AWS says customers aren't certified by association.
  • Issuer. The certification body should be accredited (ANAB in the US, UKAS in the UK). ISO/IEC 42006, the rules for certifying to 42001, only came out in July 2025, so earlier certificates were issued without AI-specific rules for the auditors.
  • What it replaces. CSA's STAR for AI Level 2 requires 42001, so the certificate can stand in for a long questionnaire. SOC 2 has no AI-specific criteria and says little about AI unless the AI system was scoped in.

Banks barely mention ISO 42001, and it doesn't appear among the drivers in Deloitte's model risk survey, so certification is mostly something vendors buy to sell.

Questions to ask a governance vendor

  1. What's your pricing unit (use case, user, evaluation, consumption), and what happens to the bill when we register the vendor features and shadow AI we find?
  2. Where does the inventory come from: forms, procurement data, cloud and security connectors? Show us discovery of an AI feature we didn't know about.
  3. Do you store the evidence or link to it in our eval, ticketing and logging tools, and can we export the full history if you're acquired?
  4. Which rule packs do you maintain, who updates them when dates move, and how long did your EU AI Act pack take to reflect the July 2026 delay?
  5. Can a model owner finish a low-tier intake in a day?

What usually goes wrong

SymptomLikely causeFirst thing to check
Audit finds AI that isn't in the inventoryIntake forms only; vendor features and personal accounts missedProcurement records and security discovery against the register
People use unapproved tools after a rejection or a long waitIntake too slow, or the low tier too heavyTime from request to decision, by tier
Validation reports say little about the foundation modelBank methods applied to a model you can't inspectBehavior tests on your own data, and what they cover
Answers changed with no release on your sideThe vendor updated or retired the modelPinned versions; vendor change notices; re-test records
Conditional approvals never closeNo owner or date for the conditionsThe exception register and its ages
Human review approves everythingReviewers without time, training or authorityOverride rates by reviewer
A regulator or court asks for a decision you can't reproduceLogs and versions not kept after retirementRetention by rule; the archive
A customer rejects your evidenceA certificate with narrow scope or from an unaccredited bodyThe certificate's scope and issuer
An AI loss isn't coveredGenerative-AI exclusions in the policyExclusion wording; whether dedicated AI cover is needed

Words that mean something else here

TermWhat you'd assumeWhat it means here
ModelThe weights behind an APIIn US bank guidance, a complex quantitative method based on statistical, economic or financial theory, with generative AI excluded; in Canada, AI and judgment tools included. Ask "under which definition?"
ValidationA held-out test setIn banks, an independent review of conceptual soundness, outcomes and ongoing monitoring
Effective challengeSomeone reviewed itCritical review by experts with the independence and authority to force a change
ProviderThe model labIn the EU, whoever places a system on the market under its name, which can be a bank that built it or a deployer that rebranded one
DeployerWhoever ships the codeIn the EU, the professional user of a system; in Colorado and Connecticut, whoever uses it for consequential decisions
AgentSoftware that calls toolsIn Workday and California's rules, a vendor acting for an employer, and liable as one
Bias auditAny fairness testIn New York City, a specific impact-ratio calculation by an independent auditor
Disparate impactUnfair resultsA legal theory still in the anti-discrimination statutes and many state laws, removed from Reg B and deprioritized federally
Human in the loopA person clicks approveIn EU law, a competent, trained person with authority to override; token review doesn't count
CertifiedSafeISO 42001 certifies a management system; SOC 2 is an attestation report; STAR for AI Level 1 is a self-assessment
Conformity assessmentAn outside auditFor most high-risk uses, the provider's own internal check

What surprised me

Placeholders in your voice, drafted from the research and the earlier guides. Rewrite each with your own moment.

The definition. In identity and trust a customer was a customer. Here the same AI assistant is a "model" to a Canadian bank supervisor, isn't one to a US bank supervisor, and is an "AI system" in the EU.

The retreat. In payments the rules only seemed to pile up. Here US agencies withdrew guidance in 2025 and 2026, and the liability moved to states, class actions and customers' contracts.

The certificate. In cloud security a SOC 2 report answered most of a buyer's questions. Here a lab's ISO certificate covers its own management system, and its customers get none of it by association.

The vendor in court. In AI coding agents the vendor's terms put the risk on the user. Here a court let job applicants pursue the HR software vendor directly, alongside the employers that used it.

Sources

Undated entries were read on October 9, 2026; "search result" means seen only as a search snippet or summary. Company figures are self-reported unless they come from a filing or a regulator. Analyst placements are as reported by the vendors, and vendor surveys cover the vendor's own respondents.

US bank regulators

Canada and the UK

EU AI Act

US federal agencies and preemption

US states and cities

Courts and settlements

Standards and certification

Surveys and research

Market, analysts and companies

Insurance

Reused from earlier guides on this site

Field Guides are learning notes, not legal or compliance advice. Rules and fees change; check the cited primary sources before you act on anything here.