Skip to content
Center for AI Oversight
Research & Insights / Research resource
Research resource

The Authorities Register

The laws, cases, regulations, and standards relevant to AI oversight. A shared reference for what institutions govern, who is accountable, and the evidence behind their decisions.

September 2026 edition · Editorial update October 2, 2026

Search by role, sector, and jurisdiction. Each entry separates a source summary from the Center’s oversight interpretation, with a source link and a recorded review date.

Results identify potentially relevant authorities. Applicability depends on the entity, activity, jurisdiction, thresholds, and effective provisions. Corporate oversight precedents are presented for corporate analysis.

Recent changes & dates ahead

Recent changes

October 1, 2026. The first provisions of Connecticut Public Act 26-15 took effect. The register now identifies its phased status.

July 27, 2026. The EU Digital Omnibus on AI amended the AI Act timetable. High-risk dates must be read by the category of obligation.

April 17, 2026. Revised interagency model risk guidance replaced SR 11-7.

Dates ahead

December 2, 2026. The EU AI Act content-marking transition ends for certain systems already on the market before August 2, 2026.

January 1, 2027. Consult the entries for Colorado, California, New York, Illinois, and Connecticut for scheduled provisions and scope.

110 authorities shown. 8 retired or unconfirmed instruments are listed separately below.

Case law and enforcementOversight precedentDelawareDecided

In re Caremark International Derivative Litigation (Del. Ch. 1996)

Source summary & oversight interpretation

Source summary

The Court of Chancery approved a settlement and, in doing so, described a director's duty to attempt in good faith to assure that a reporting system exists. Liability follows a sustained or systematic failure to assure that such a system exists, or conscious disregard of what it reports. The court described a system that lets the board reach informed judgments about both compliance with law and business performance.

The Center’s oversight interpretation

The root of the oversight duty. Directors must make a good-faith effort to assure that a corporate information and reporting system exists, reasonably designed to bring material risks and compliance issues to the board. For material AI risk, the absence of a reporting system is the exposure, not an excuse.

For corporate oversight analysis; relevance depends on governing law, facts, and the decision’s procedural posture.

Jurisdiction
Delaware
Relevant sectors
Cross-sector
Relevant entities
Buyers; Builders; Public companies
Citation
698 A.2d 959 (Del. Ch. 1996)
Source
Court opinion, University of Pennsylvania Law School copy (PDF) ↗
Content review recorded
July 2026
Source link checked
October 2, 2026. Confirms the linked document’s identity; it is not a full re-verification of the entry.
Link to this entry
Case law and enforcementOversight precedentDelawareDecided

Stone v. Ritter (Del. 2006)

Source summary & oversight interpretation

Source summary

The Delaware Supreme Court held that the oversight duty is part of the duty of loyalty: loyalty is not limited to conflicts of interest and also reaches a fiduciary who fails to act in good faith. Good faith is not a separate fiduciary duty. The case involved Bank Secrecy Act and anti-money-laundering compliance at a bank; the claim was dismissed because the bank had a reporting system and the board had received reports.

The Center’s oversight interpretation

Names the two ways an oversight claim is pleaded and sets the standard at bad faith. Directors are liable where they utterly failed to implement any reporting system, or, having one, consciously failed to monitor it. Because the duty sits inside the duty of loyalty, a charter cannot exculpate it, and carelessness is not enough.

For corporate oversight analysis; relevance depends on governing law, facts, and the decision’s procedural posture.

Jurisdiction
Delaware
Relevant sectors
Cross-sector
Relevant entities
Buyers; Builders; Public companies
Citation
911 A.2d 362 (Del. 2006)
Source
Court opinion, Delaware Courts (PDF) ↗
Content review recorded
September 2026
Source link checked
October 2, 2026. Confirms the linked document’s identity; it is not a full re-verification of the entry.
Link to this entry
Case law and enforcementOversight precedentDelawareDecided

In re Citigroup Inc. Shareholder Derivative Litigation (Del. Ch. 2009)

Source summary & oversight interpretation

Source summary

The Court of Chancery dismissed oversight claims against Citigroup's directors over subprime exposure that nearly destroyed the company. Oversight duties are not designed to subject directors, even expert directors, to personal liability for failure to predict the future and to properly evaluate business risk. The rule has held through SolarWinds (2022), ProAssurance (2023) and B. Riley (2026).

The Center’s oversight interpretation

Draws the line between compliance risk and business risk. No oversight liability attaches to a failure to monitor business risk, however large. AI capital spending, vendor concentration and strategy are business risks; the board decides how it will be informed about them and records the decision.

For corporate oversight analysis; relevance depends on governing law, facts, and the decision’s procedural posture.

Jurisdiction
Delaware
Relevant sectors
Cross-sector; Banking
Relevant entities
Buyers; Builders; Public companies
Citation
964 A.2d 106 (Del. Ch. 2009)
Source
Court opinion, reproduced by Justia ↗
Content review recorded
September 2026
Source link checked
October 2, 2026. Confirms the linked document’s identity; it is not a full re-verification of the entry.
Link to this entry
Case law and enforcementOversight precedentDelawareDecided

Marchand v. Barnhill (Del. 2019)

Source summary & oversight interpretation

Source summary

The Delaware Supreme Court held that a complaint adequately alleged that the board of Blue Bell, an ice-cream maker with one line of products, had no board-level system for food safety after a listeria outbreak killed three people: no committee, no protocol, no schedule. The court called food safety essential and mission critical and did not define the phrase. Settled for $60 million in 2020.

The Center’s oversight interpretation

Gave the duty teeth and supplied the phrase 'mission critical.' Where a compliance risk is central to the business, the board must make a good-faith effort, that is, try, to put in place a reasonable board-level system of monitoring and reporting. Nominal compliance with a regulator's rules is not a board-level system. Where AI is the company's product or its core decision, the same expectation applies.

For corporate oversight analysis; relevance depends on governing law, facts, and the decision’s procedural posture.

Jurisdiction
Delaware
Relevant sectors
Cross-sector
Relevant entities
Buyers; Builders; Public companies
Citation
212 A.3d 805 (Del. 2019)
Source
Court opinion, Delaware Courts (PDF) ↗
Content review recorded
July 2026
Source link checked
October 2, 2026. Confirms the linked document’s identity; it is not a full re-verification of the entry.
Link to this entry
Case law and enforcementOversight precedentDelawareDecided

In re Clovis Oncology Derivative Litigation (Del. Ch. Oct. 1, 2019)

Source summary & oversight interpretation

Source summary

A single-drug developer's board received reports that a clinical trial was departing from its FDA-governed protocol and did not act. The Court of Chancery sustained the claim on the red-flags theory.

The Center’s oversight interpretation

Where externally imposed regulations govern a company's mission-critical operations, the board's oversight function must be more rigorously exercised. A board that receives warnings about a regulated core activity and does nothing has a red-flags problem, not a paperwork problem. Reports about a regulated AI use that go unanswered sit in the same place.

For corporate oversight analysis; relevance depends on governing law, facts, and the decision’s procedural posture.

Jurisdiction
Delaware
Relevant sectors
Cross-sector; Pharmaceuticals
Relevant entities
Buyers; Builders; Public companies
Citation
C.A. No. 2017-0222-JRS (Del. Ch. Oct. 1, 2019)
Source
Court opinion, Delaware Courts (PDF) ↗
Content review recorded
September 2026
Source link checked
October 2, 2026. Confirms the linked document’s identity; it is not a full re-verification of the entry.
Link to this entry
Case law and enforcementOversight precedentDelawareDecided

Inter-Marketing Group USA v. Armstrong (Plains All American) (Del. Ch. Jan. 31, 2020)

Source summary & oversight interpretation

Source summary

After a pipeline spill, the Court of Chancery applied a Caremark-style red-flags analysis to the partnership agreement's good-faith standard. It sustained the contract claim against the general partner entity and dismissed the contract claims against the individual directors and the implied-covenant claims.

The Center’s oversight interpretation

The company's own words set the standard the record is measured against. The complaint quoted the company's stated 'primary operational emphasis' on pipeline integrity; the CEO's testimony that it was 'not discussed at the board level' did the rest. A public statement that the board oversees AI is a representation the minutes must support.

For corporate oversight analysis; relevance depends on governing law, facts, and the decision’s procedural posture.

Jurisdiction
Delaware
Relevant sectors
Cross-sector
Relevant entities
Buyers; Builders; Public companies
Citation
C.A. No. 2017-0030-TMR (Del. Ch. Jan. 31, 2020)
Source
Court opinion, Delaware Courts (PDF) ↗
Content review recorded
September 2026
Source link checked
October 2, 2026. Confirms the linked document’s identity; it is not a full re-verification of the entry.
Link to this entry
Case law and enforcementOversight precedentDelawareDecided

Hughes v. Hu (Kandi Technologies) (Del. Ch. Apr. 27, 2020)

Source summary & oversight interpretation

Source summary

The audit committee met sporadically and the board relied entirely on management for financial reporting controls; a restatement followed. The claim was sustained.

The Center’s oversight interpretation

Reliance on management is not a system. Directors may rely in good faith on officers and experts, but Caremark envisions some degree of board-level monitoring, not blind deference to and complete dependence on management. A vendor's assurances about a model are a control to be tested, not a report to be relied on.

For corporate oversight analysis; relevance depends on governing law, facts, and the decision’s procedural posture.

Jurisdiction
Delaware
Relevant sectors
Cross-sector; Public company disclosure
Relevant entities
Buyers; Builders; Public companies
Citation
C.A. No. 2019-0112-JTL (Del. Ch. Apr. 27, 2020)
Source
Court opinion, Delaware Courts (PDF) ↗
Content review recorded
September 2026
Source link checked
October 2, 2026. Confirms the linked document’s identity; it is not a full re-verification of the entry.
Link to this entry
Case law and enforcementOversight precedentDelawareDecided

Teamsters Local 443 v. Chou (AmerisourceBergen) (Del. Ch. Aug. 24, 2020)

Source summary & oversight interpretation

Source summary

The board never asked for reports on a whistleblower's allegations about a subsidiary's drug-safety conduct. The Court of Chancery sustained the claim.

The Center’s oversight interpretation

The mission-critical standard is not confined to one-product companies. A diversified drug distributor was held to it because drug-safety law goes to the central purpose of its business. A diversified company whose AI decides its core regulated activity is in the same position.

For corporate oversight analysis; relevance depends on governing law, facts, and the decision’s procedural posture.

Jurisdiction
Delaware
Relevant sectors
Cross-sector; Pharmaceuticals
Relevant entities
Buyers; Builders; Public companies
Citation
C.A. No. 2019-0816-SG (Del. Ch. Aug. 24, 2020)
Source
Court opinion, Delaware Courts (PDF) ↗
Content review recorded
September 2026
Source link checked
October 2, 2026. Confirms the linked document’s identity; it is not a full re-verification of the entry.
Link to this entry
Case law and enforcementOversight precedentDelawareDecided

Richardson v. Clark (MoneyGram) (Del. Ch. Dec. 31, 2020)

Source summary & oversight interpretation

Source summary

Anti-money-laundering compliance failures under a consent order; the board and its compliance committee met regularly. Dismissed.

The Center’s oversight interpretation

Bad oversight is not bad-faith oversight. A board that had a compliance system, met regularly and received reports was not liable for the system's failures. The duty is a good-faith effort, not a guarantee of results; a board that governs its AI in earnest and still suffers a failure is on this side of the line.

For corporate oversight analysis; relevance depends on governing law, facts, and the decision’s procedural posture.

Jurisdiction
Delaware
Relevant sectors
Cross-sector; Payments and consumer credit; Banking
Relevant entities
Buyers; Builders; Public companies
Citation
2020 WL 7861335 (Del. Ch. Dec. 31, 2020)
Source
Court opinion, Delaware Courts (PDF) ↗
Content review recorded
September 2026
Source link checked
October 2, 2026. Confirms the linked document’s identity; it is not a full re-verification of the entry.
Link to this entry
Case law and enforcementOversight precedentDelawareDecided

Pettry v. Smith (FedEx) (Del. Ch. June 28, 2021)

Source summary & oversight interpretation

Source summary

Dismissed; affirmed by the Delaware Supreme Court in 2022.

The Center’s oversight interpretation

A compliance risk can be real and still peripheral. Illegal cigarette shipments and the resulting fines were an infinitesimal fraction of the overall business, and the board had been updated on the litigation repeatedly. A peripheral AI use gets the board's business judgment, not a mandatory reporting line.

For corporate oversight analysis; relevance depends on governing law, facts, and the decision’s procedural posture.

Jurisdiction
Delaware
Relevant sectors
Cross-sector
Relevant entities
Buyers; Builders; Public companies
Citation
2021 WL 2644475 (Del. Ch. June 28, 2021)
Source
Court opinion, Delaware Courts (PDF) ↗
Content review recorded
September 2026
Source link checked
October 2, 2026. Confirms the linked document’s identity; it is not a full re-verification of the entry.
Link to this entry
Case law and enforcementOversight precedentDelawareDecided

In re The Boeing Co. Derivative Litigation (Del. Ch. Sept. 7, 2021)

Source summary & oversight interpretation

Source summary

After two 737 MAX crashes killed 346 people, the Court of Chancery sustained the information-systems claim in part. Settled for $237.5 million, approved February 2022.

The Center’s oversight interpretation

What a court reads first: the charters. Every committee charter was silent as to airplane safety, management's reports framed safety events as business impact, and the board had no means of receiving internal complaints about safety. For AI, reports must be framed as risk, not results, and the committee that owns a mission-critical use must be named in its charter.

For corporate oversight analysis; relevance depends on governing law, facts, and the decision’s procedural posture.

Jurisdiction
Delaware
Relevant sectors
Cross-sector; Transportation
Relevant entities
Buyers; Builders; Public companies
Citation
2021 WL 4059934 (Del. Ch. Sept. 7, 2021)
Source
Court opinion, Delaware Courts (PDF) ↗
Content review recorded
September 2026
Source link checked
October 2, 2026. Confirms the linked document’s identity; it is not a full re-verification of the entry.
Link to this entry
Case law and enforcementOversight precedentDelawareDecided

Firemen's Retirement System of St. Louis v. Sorenson (Marriott) (Del. Ch. Oct. 5, 2021)

Source summary & oversight interpretation

Source summary

Oversight claims after the Starwood guest-data breach. Dismissed.

The Center’s oversight interpretation

A board that has a system and attends to it prevails, even where the risk is central. The court said cybersecurity has increasingly become a central compliance risk, and dismissed because the board consistently ranked it a primary risk and had a system. The same reasoning protects a board whose AI reporting line is real and used.

For corporate oversight analysis; relevance depends on governing law, facts, and the decision’s procedural posture.

Jurisdiction
Delaware
Relevant sectors
Cross-sector; Cybersecurity
Relevant entities
Buyers; Builders; Public companies
Citation
2021 WL 4593777 (Del. Ch. Oct. 5, 2021)
Source
Court opinion, Delaware Courts (PDF) ↗
Content review recorded
September 2026
Source link checked
October 2, 2026. Confirms the linked document’s identity; it is not a full re-verification of the entry.
Link to this entry
Case law and enforcementOversight precedentDelawareDecided

City of Detroit Police & Fire Retirement System v. Hamrock (NiSource) (Del. Ch. June 30, 2022)

Source summary & oversight interpretation

Source summary

Pipeline safety after the Merrimack Valley gas explosions. Dismissed.

The Center’s oversight interpretation

A functioning safety committee that met five times a year was enough, even for a mission-critical risk that produced a fatal explosion. The benchmark for a schedule is regular and real, not perfect.

For corporate oversight analysis; relevance depends on governing law, facts, and the decision’s procedural posture.

Jurisdiction
Delaware
Relevant sectors
Cross-sector
Relevant entities
Buyers; Builders; Public companies
Citation
2022 WL 2387653 (Del. Ch. June 30, 2022)
Source
Court opinion, Delaware Courts (PDF) ↗
Content review recorded
September 2026
Source link checked
October 2, 2026. Confirms the linked document’s identity; it is not a full re-verification of the entry.
Link to this entry
Case law and enforcementOversight precedentDelawareDecided

Construction Industry Laborers Pension Fund v. Bingle (SolarWinds) (Del. Ch. Sept. 6, 2022)

Source summary & oversight interpretation

Source summary

Oversight claims after the SolarWinds supply-chain attack. Dismissed; affirmed by the Delaware Supreme Court in 2023. The court noted that an extreme hypothetical might one day produce oversight liability for business risk; no case has.

The Center’s oversight interpretation

Guidance is not law, and business risk is not compliance risk. The court called cybersecurity mission critical for an online service provider and still dismissed: SEC guidance does not establish positive law, and absent a statutory or regulatory obligation, how much to spend against criminals is an evaluation of business risk, the quintessential board function. A charter reference and a management briefing defeated the utter-failure theory.

For corporate oversight analysis; relevance depends on governing law, facts, and the decision’s procedural posture.

Jurisdiction
Delaware
Relevant sectors
Cross-sector; Cybersecurity
Relevant entities
Buyers; Builders; Public companies
Citation
2022 WL 4102492 (Del. Ch. Sept. 6, 2022)
Source
Court opinion, Delaware Courts (PDF) ↗
Content review recorded
September 2026
Source link checked
October 2, 2026. Confirms the linked document’s identity; it is not a full re-verification of the entry.
Link to this entry
Case law and enforcementOversight precedentDelawareDecided

In re McDonald's Corp. Stockholder Derivative Litigation (officers) (Del. Ch. Jan. 26, 2023)

Source summary & oversight interpretation

Source summary

The Court of Chancery held that an oversight claim was stated against the former head of human resources over sexual-harassment red flags. The claim against him was later dismissed under Rule 23.1 because the board could impartially consider a demand (March 1, 2023); the officer-duty holding itself stands and was not reviewed on appeal.

The Center’s oversight interpretation

Officers owe the oversight duty within their area of responsibility. The chief legal officer is responsible for legal oversight and for making a good faith effort to establish reasonable information systems in that area. The general counsel, chief risk officer and the executive accountable for AI have exposure of their own, and the record protects them personally.

For corporate oversight analysis; relevance depends on governing law, facts, and the decision’s procedural posture.

Jurisdiction
Delaware
Relevant sectors
Cross-sector
Relevant entities
Buyers; Builders; Public companies
Citation
289 A.3d 343 (Del. Ch. Jan. 26, 2023)
Source
Court opinion, Delaware Courts (PDF) ↗
Content review recorded
July 2026
Source link checked
October 2, 2026. Confirms the linked document’s identity; it is not a full re-verification of the entry.
Link to this entry
Case law and enforcementOversight precedentDelawareDecided

In re McDonald's Corp. Stockholder Derivative Litigation (directors) (Del. Ch. Mar. 1, 2023)

Source summary & oversight interpretation

Source summary

Harassment law at an employer of hundreds of thousands was a central compliance risk; the head of HR's own conduct was the most vibrant of red flags. The claims against the directors were dismissed for failure to state an oversight claim: the board had responded to the red flags it received.

The Center’s oversight interpretation

The map. Central compliance risks require a reporting system; essential and mission-critical risks are a subset of them, described in more intense terms; monitoring anything else is a business judgment. A plaintiff need not plead mission criticality to state a claim. If a red flag concerns a central compliance risk, it is easier to infer that a failure to respond was bad faith.

For corporate oversight analysis; relevance depends on governing law, facts, and the decision’s procedural posture.

Jurisdiction
Delaware
Relevant sectors
Cross-sector; Employment
Relevant entities
Buyers; Builders; Public companies
Citation
291 A.3d 652 (Del. Ch. Mar. 1, 2023)
Source
Court opinion, reproduced by Justia ↗
Content review recorded
September 2026
Source link checked
October 2, 2026. Confirms the linked document’s identity; it is not a full re-verification of the entry.
Link to this entry
Case law and enforcementOversight precedentDelawareDecided

Ontario Provincial Council of Carpenters' Pension Trust Fund v. Walton (Walmart) (Del. Ch. Apr. 2023)

Source summary & oversight interpretation

Source summary

Pharmacy controlled-substance compliance under a DEA settlement. Sustained in part (April 26, 2023); settled for $123 million plus governance terms, approved December 2024.

The Center’s oversight interpretation

Essential and mission critical risks necessarily qualify as central compliance risks, and a company's own public statements can put a risk in that category at the pleading stage. What a company says about its AI, and about the board's oversight of it, becomes evidence of what the board owed.

For corporate oversight analysis; relevance depends on governing law, facts, and the decision’s procedural posture.

Jurisdiction
Delaware
Relevant sectors
Cross-sector; Healthcare providers
Relevant entities
Buyers; Builders; Public companies
Citation
2023 WL 3093500 (Del. Ch. Apr. 26, 2023); see also 294 A.3d 65 (Del. Ch. Apr. 12, 2023)
Source
Court opinion, Delaware Courts (PDF) ↗
Content review recorded
September 2026
Source link checked
October 2, 2026. Confirms the linked document’s identity; it is not a full re-verification of the entry.
Link to this entry
Case law and enforcementOversight precedentDelawareDecided

In re ProAssurance Corp. Stockholder Derivative Litigation (Del. Ch. Oct. 2, 2023)

Source summary & oversight interpretation

Source summary

Oversight claims over underwriting losses. Dismissed.

The Center’s oversight interpretation

Business risks are shades of gray; legal compliance risks are black and white. Underwriting judgment is business risk. An AI underwriting model becomes a compliance risk only through the law that governs the decision it makes, not through the size of the bet.

For corporate oversight analysis; relevance depends on governing law, facts, and the decision’s procedural posture.

Jurisdiction
Delaware
Relevant sectors
Cross-sector; Insurance
Relevant entities
Buyers; Builders; Public companies
Citation
2023 WL 6426294 (Del. Ch. Oct. 2, 2023)
Source
Court opinion, Delaware Courts (PDF) ↗
Content review recorded
September 2026
Source link checked
October 2, 2026. Confirms the linked document’s identity; it is not a full re-verification of the entry.
Link to this entry
Case law and enforcementOversight precedentDelawareDecided

Segway Inc. v. Cai (Del. Ch. Dec. 14, 2023)

Source summary & oversight interpretation

Source summary

The Court of Chancery followed McDonald's on officer oversight and dismissed the claim.

The Center’s oversight interpretation

Cabins the officer duty. An officer must make a good faith effort to monitor central compliance risks within her remit that pose potential harm to the company or others; declining sales and receivables are not such a risk, and liability requires bad faith. Officer-duty language about AI has to respect both limits.

For corporate oversight analysis; relevance depends on governing law, facts, and the decision’s procedural posture.

Jurisdiction
Delaware
Relevant sectors
Cross-sector
Relevant entities
Buyers; Builders; Public companies
Citation
2023 WL 8643017 (Del. Ch. Dec. 14, 2023)
Source
Court opinion, Delaware Courts (PDF) ↗
Content review recorded
July 2026
Source link checked
October 2, 2026. Confirms the linked document’s identity; it is not a full re-verification of the entry.
Link to this entry
Case law and enforcementOversight precedentDelawareDecided

Lebanon County Employees' Retirement Fund v. Collis (AmerisourceBergen) (Del. Dec. 18, 2023)

Source summary & oversight interpretation

Source summary

Opioid distribution under DEA rules. Dismissal reversed; settled for $111.25 million in 2025.

The Center’s oversight interpretation

Red flags in a regulated core activity are judged on the company's own record, not on what another court later found. The Delaware Supreme Court reversed a dismissal that had rested on judicial notice of another court's findings; the Court of Chancery had already found the directors 'wrapped in' red flags.

For corporate oversight analysis; relevance depends on governing law, facts, and the decision’s procedural posture.

Jurisdiction
Delaware
Relevant sectors
Cross-sector; Pharmaceuticals
Relevant entities
Buyers; Builders; Public companies
Citation
311 A.3d 773 (Del. Dec. 18, 2023)
Source
Court opinion, Delaware Courts (PDF) ↗
Content review recorded
September 2026
Source link checked
October 2, 2026. Confirms the linked document’s identity; it is not a full re-verification of the entry.
Link to this entry
Case law and enforcementOversight precedentDelawareDecided

Conte v. Greenberg (Skechers) (Del. Ch. Feb. 2, 2024)

Source summary & oversight interpretation

Source summary

A tax gross-up on executives' aircraft use. Dismissed; affirmed by order January 23, 2025.

The Center’s oversight interpretation

A risk contained to a discrete group of individuals, of relatively minimal magnitude, with no regulation or internal policy violated, is not central. A narrow internal AI use with no rule behind it sits in the same outer ring.

For corporate oversight analysis; relevance depends on governing law, facts, and the decision’s procedural posture.

Jurisdiction
Delaware
Relevant sectors
Cross-sector
Relevant entities
Buyers; Builders; Public companies
Citation
2024 WL 413430 (Del. Ch. Feb. 2, 2024)
Source
Court opinion, Delaware Courts (PDF) ↗
Content review recorded
September 2026
Source link checked
October 2, 2026. Confirms the linked document’s identity; it is not a full re-verification of the entry.
Link to this entry
Case law and enforcementOversight precedentUS federalDecided

In re Abbott Laboratories Infant Formula Shareholder Derivative Litigation (N.D. Ill. Aug. 7, 2024)

Source summary & oversight interpretation

Source summary

Contaminated infant formula. Demand excused on the oversight claim; settled in 2026 for $40 million in plant investment plus reforms.

The Center’s oversight interpretation

The Delaware standard travels. A federal court applying Illinois law, which follows Delaware on demand futility, applied Marchand and Boeing: product safety was externally regulated and essential and mission critical, and there was no committee, schedule or protocol. AI that controls a safety function is the direct analogue.

For corporate oversight analysis; relevance depends on governing law, facts, and the decision’s procedural posture.

Jurisdiction
Illinois (federal court, applying Illinois law)
Relevant sectors
Cross-sector; Medical devices; Healthcare providers
Relevant entities
Buyers; Builders; Public companies
Citation
No. 1:22-cv-05513 (N.D. Ill. Aug. 7, 2024)
Source locator
U.S. District Court, N.D. Ill. (official site) ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
September 2026
Link to this entry
Case law and enforcementOversight precedentUS federalDecided

In re Wells Fargo & Co. Hiring Practices Derivative Litigation (N.D. Cal. Sept. 20, 2024)

Source summary & oversight interpretation

Source summary

The board had no committee charged with direct responsibility to monitor fair-lending compliance. Sustained in part on fair lending, dismissed on hiring; settled with a $100 million borrower-assistance fund plus $10 million, final approval May 2026.

The Center’s oversight interpretation

The template for sorting AI uses within one company. Fair-lending compliance is a mission-critical risk to a bank, as food safety is to an ice-cream company: federal law governs it, borrowers are harmed by it, the bank cannot lend without complying. Diversity hiring, though crucial, was not. An AI credit model and an AI screening tool at the same bank sit in different circles.

For corporate oversight analysis; relevance depends on governing law, facts, and the decision’s procedural posture.

Jurisdiction
California (federal court, applying Delaware law)
Relevant sectors
Banking; Employment; Payments and consumer credit
Relevant entities
Buyers; Public companies
Citation
No. 3:22-cv-05173 (N.D. Cal. Sept. 20, 2024)
Source locator
U.S. District Court, N.D. Cal. (official site) ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
September 2026
Link to this entry
Case law and enforcementOversight precedentDelawareDecided

In re Fox Corp. Derivative Litigation (Del. Ch. Dec. 27, 2024)

Source summary & oversight interpretation

Source summary

Defamation liability after the Dominion litigation. Demand excused; claims proceed.

The Center’s oversight interpretation

Court-made law counts. The common law is just as much the law as statutory law, so liability for what an AI system says or does to a third party (defamation, negligence, product liability) is a compliance risk in the Caremark sense, not only a business risk.

For corporate oversight analysis; relevance depends on governing law, facts, and the decision’s procedural posture.

Jurisdiction
Delaware
Relevant sectors
Cross-sector
Relevant entities
Buyers; Builders; Public companies
Citation
2024 WL 5233229 (Del. Ch. Dec. 27, 2024)
Source
Court opinion, Delaware Courts (PDF) ↗
Content review recorded
September 2026
Source link checked
October 2, 2026. Confirms the linked document’s identity; it is not a full re-verification of the entry.
Link to this entry
Case law and enforcementOversight precedentDelawareDecided

In re Plug Power Inc. Stockholder Derivative Litigation (Del. Ch. May 2, 2025)

Source summary & oversight interpretation

Source summary

Insider-trading policy and SEC comment letters. Dismissed.

The Center’s oversight interpretation

No harm, no claim. Corporate trauma is a predicate to a Caremark claim, and outside central compliance risks a plaintiff will have difficulty rebutting the business judgment rule where directors made a good-faith decision about how much monitoring to assign to a risk. Restates the McDonald's map.

For corporate oversight analysis; relevance depends on governing law, facts, and the decision’s procedural posture.

Jurisdiction
Delaware
Relevant sectors
Cross-sector; Public company disclosure
Relevant entities
Buyers; Builders; Public companies
Citation
C.A. No. 2022-0569-KSJM (Del. Ch. May 2, 2025)
Source
Court opinion, Delaware Courts (PDF) ↗
Content review recorded
September 2026
Source link checked
October 2, 2026. Confirms the linked document’s identity; it is not a full re-verification of the entry.
Link to this entry
Case law and enforcementOversight precedentDelawareDecided

Ritchie v. Baker (Corcept Therapeutics) (Del. Ch. July 22, 2025)

Source summary & oversight interpretation

Source summary

Dismissed.

The Center’s oversight interpretation

A well-informed board defeats the claim on its own record. The complaint itself alleged that the board was well informed about its primary drug through routine briefings. A minuted, scheduled reporting line on a core AI use does the same work.

For corporate oversight analysis; relevance depends on governing law, facts, and the decision’s procedural posture.

Jurisdiction
Delaware
Relevant sectors
Cross-sector; Pharmaceuticals
Relevant entities
Buyers; Builders; Public companies
Citation
C.A. No. 2022-0102-BWD (Del. Ch. July 22, 2025)
Source
Court opinion, Delaware Courts (PDF) ↗
Content review recorded
September 2026
Source link checked
October 2, 2026. Confirms the linked document’s identity; it is not a full re-verification of the entry.
Link to this entry
Case law and enforcementOversight precedentDelawareDecided

Giuliano v. Grenfell-Gardner (Teligent) (Del. Ch. Sept. 2, 2025)

Source summary & oversight interpretation

Source summary

A generic-drug maker whose FDA approval was a condition of revenue had no committee for FDA compliance. Brought directly by the Chapter 11 plan administrator, which is how an insolvency reaches the doctrine. Motion to dismiss denied in substantial part.

The Center’s oversight interpretation

A committee on paper is not enough. A court must look beyond the mere existence of a system to some indicia of effectiveness, and a reporting practice that lets management elect whether to report on a central compliance risk is no system at all. Reporting on a mission-critical AI use cannot be at management's option.

For corporate oversight analysis; relevance depends on governing law, facts, and the decision’s procedural posture.

Jurisdiction
Delaware
Relevant sectors
Cross-sector; Pharmaceuticals
Relevant entities
Buyers; Builders; Public companies
Citation
C.A. No. 2021-0452-KSJM (Del. Ch. Sept. 2, 2025)
Source
Court opinion, Delaware Courts (PDF) ↗
Content review recorded
September 2026
Source link checked
October 2, 2026. Confirms the linked document’s identity; it is not a full re-verification of the entry.
Link to this entry
Case law and enforcementOversight precedentDelawareDecided

Brewer v. Turner (Regions Financial) (Del. Ch. Sept. 29, 2025)

Source summary & oversight interpretation

Source summary

Overdraft practices at a retail bank. The oversight count was sustained against 13 of 22 director defendants and dismissed as to 9; officer claims dismissed; the Delaware Supreme Court refused an interlocutory appeal December 15, 2025.

The Center’s oversight interpretation

Having a system is not the end of the analysis. The bank had an information system, and the claim survived on warnings the board did not act on, in a central compliance area under a CFPB consent order. An AI reporting line that surfaces drift or a rising reversal rate obliges a response.

For corporate oversight analysis; relevance depends on governing law, facts, and the decision’s procedural posture.

Jurisdiction
Delaware
Relevant sectors
Banking; Consumer protection
Relevant entities
Buyers; Public companies
Citation
C.A. No. 2023-1284-KSJM (Del. Ch. Sept. 29, 2025)
Source
Court opinion, Delaware Courts (PDF) ↗
Content review recorded
September 2026
Source link checked
October 2, 2026. Confirms the linked document’s identity; it is not a full re-verification of the entry.
Link to this entry
Case law and enforcementOversight precedentDelawareDecided

Marchner v. Riley (B. Riley Financial) (Del. Ch. Mar. 30, 2026)

Source summary & oversight interpretation

Source summary

Dismissed.

The Center’s oversight interpretation

The most recent restatement of the line. Credit and valuation warnings are quintessential business risks; the doctrine addresses failures to monitor internal corporate compliance with positive law. Warnings about an AI investment's economics do not create oversight liability; warnings about an AI use's legality do.

For corporate oversight analysis; relevance depends on governing law, facts, and the decision’s procedural posture.

Jurisdiction
Delaware
Relevant sectors
Cross-sector; Securities and asset management
Relevant entities
Buyers; Builders; Public companies
Citation
C.A. No. 2025-0164-LWW (Del. Ch. Mar. 30, 2026)
Source
Court opinion, Delaware Courts (PDF) ↗
Content review recorded
September 2026
Source link checked
October 2, 2026. Confirms the linked document’s identity; it is not a full re-verification of the entry.
Link to this entry
Case law and enforcementOversight precedentDelawareDecided

In re The Boeing Co. Derivative Litigation (Del. Ch. Aug. 13, 2026)

Source summary & oversight interpretation

Source summary

Dismissed.

The Center’s oversight interpretation

The ceiling, and the reassurance. After the 2024 door-plug incident the claim was dismissed because the board had a safety committee of directors with engineering and safety expertise, discussed airplane safety at every meeting, and received a management safety report each time. Even for mission-critical operations, Caremark does not demand omniscience. Reports of general operational risk with management's response attached are yellow flags, not red ones. The court warned against recasting the volume of a board's reporting into evidence of disloyalty; a fuller record is a shield.

For corporate oversight analysis; relevance depends on governing law, facts, and the decision’s procedural posture.

Jurisdiction
Delaware
Relevant sectors
Cross-sector; Transportation
Relevant entities
Buyers; Builders; Public companies
Citation
C.A. No. 2024-1210-MTZ (Del. Ch. Aug. 13, 2026)
Source
Court opinion, Delaware Courts (PDF) ↗
Content review recorded
September 2026
Source link checked
October 2, 2026. Confirms the linked document’s identity; it is not a full re-verification of the entry.
Link to this entry
Case law and enforcementOversight precedentCaliforniaDecided

Kanter v. Reed (Cal. Ct. App. 2023)

Source summary & oversight interpretation

Source summary

A derivative action against the directors of Sempra Energy, a California corporation. The Second District (June 2, 2023) looked to Caremark to read the 'reckless disregard' standard of Corporations Code section 204(a)(10), and affirmed dismissal for failure to plead demand futility, over a dissent.

The Center’s oversight interpretation

A California appellate court adopted Caremark as guidance for director oversight claims under California law. A California-incorporated board should assume the Delaware analysis on this page applies, and confirm with counsel; Texas and Nevada have diverged from Delaware since 2024 and need their own confirmation.

For corporate oversight analysis; relevance depends on governing law, facts, and the decision’s procedural posture.

Jurisdiction
California
Relevant sectors
Cross-sector
Relevant entities
Buyers; Builders; Public companies
Citation
92 Cal. App. 5th 191 (2023)
Source locator
California Courts opinions (official site) ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
September 2026
Link to this entry
Case law and enforcementAllegations, not holdingsUS federalPending

Pending derivative suits over a company's use of AI (UnitedHealth; Adobe, Microsoft, Nvidia) (2026)

Source summary & oversight interpretation

Source summary

UnitedHealth: amended consolidated derivative complaint filed in D. Minn. on August 7, 2026 by the Rhode Island state pension fund and Länsförsäkringar (the AI allegations sit alongside Change Healthcare cybersecurity claims); SEIU Pension Plan Master Trust v. Narayen (Adobe), N.D. Cal., filed April 24, 2026; In re Microsoft Corp. Stockholder Derivative Litigation, W.D. Wash., consolidating suits filed from June 30, 2026, with a further suit filed September 9, 2026; Berliner v. Huang (Nvidia), N.D. Ill., filed July 31, 2026. None has been tested on a motion to dismiss. The one derivative suit built on an operational failure alone, over the July 2024 CrowdStrike outage, was voluntarily dropped April 14, 2026 after the companion securities suit was dismissed. All allegations are as pleaded.

The Center’s oversight interpretation

No court has yet decided a board-oversight claim about AI. The four complaints that plead a theory about the AI use itself each have a compliance hook: Medicare coverage rules at UnitedHealth, copyright at Adobe, Microsoft and Nvidia. Each will turn on what the board's minutes show. The UnitedHealth complaint, as reported, alleges post-acute care was cut off in line with a proprietary algorithm's predictions and that roughly 90 percent of the denials members appealed were reversed; if proved, coverage decisions governed by Medicare rules, at the center of a health plan's business, harming the members it serves, would be the first AI use a court applying Delaware law calls mission critical.

Status note Pending. Descriptions are of allegations, not findings. The Center updates this entry as rulings issue.

Jurisdiction
Federal courts (D. Minn.; N.D. Cal.; W.D. Wash.; N.D. Ill.)
Relevant sectors
Cross-sector; Health plans and payers; Public company disclosure
Relevant entities
Buyers; Builders; Model developers; Public companies
Source locator
CourtListener (docket finding aid) ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
September 2026
Link to this entry
Case law and enforcementBinding on respondentsUS federalSettled enforcement orders

SEC settled orders against Delphia (USA) Inc. and Global Predictions Inc. (Mar. 18, 2024)

Source summary & oversight interpretation

Source summary

The SEC announced settled charges against two investment advisers concerning false or misleading representations about their use of AI. Without admitting or denying the findings, the firms consented to censure, cease-and-desist orders, and civil penalties.

The Center’s oversight interpretation

The orders illustrate enforcement of existing securities requirements against claims about AI. They bind the respondents; the Center draws an oversight lesson about the evidence behind an institution’s public statements. They are not a judicial holding imposing an AI-specific board duty.

Jurisdiction
US federal (SEC)
Relevant sectors
Public company disclosure; Securities and asset management
Relevant entities
Public companies; Buyers; Builders
Source
SEC announcement and links to the settled orders ↗
Content review recorded
October 2, 2026
Source link checked
October 2, 2026. Confirms the linked document’s identity; it is not a full re-verification of the entry.
Link to this entry
Regulation and agency guidanceFederal executive directiveUS federalIn force

Executive Order 14179, Removing Barriers to American Leadership in AI (Jan. 23, 2025)

Source summary & oversight interpretation

Source summary

Executive Order 14179 (90 FR 8741) sets federal AI policy and directs development of an AI action plan and review of measures associated with Executive Order 14110.

The Center’s oversight interpretation

Sets the federal posture every federal guidance document on this page lives or dies by. The removals, withdrawals and revisions of 2025 (EEOC, CFPB, SEC, healthcare) trace to it, which is why a board's legal register has to check federal guidance for volatility, not only for content. It imposes no duties on private companies.

Jurisdiction
US federal
Relevant sectors
Cross-sector; Public sector
Relevant entities
Public sector; Buyers; Builders; Model developers
Source
90 FR 8741, Federal Register ↗
Content review recorded
July 2026
Link to this entry
Regulation and agency guidanceNonbinding guidanceUS federalPublished guidance

America's AI Action Plan (July 23, 2025)

Source summary & oversight interpretation

Source summary

The federal AI policy program under Executive Order 14179 section 4: deregulatory actions, infrastructure and export promotion, workforce items, executed through agency implementation.

The Center’s oversight interpretation

Explains why federal AI guidance keeps disappearing rather than accumulating, which protects a board from reading guidance-absence as oversight-absence. Posture only.

Jurisdiction
US federal
Relevant sectors
Cross-sector; Public sector
Relevant entities
Public sector; Buyers; Builders; Model developers
Source locator
whitehouse.gov (official site) ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
Regulation and agency guidanceFederal executive directiveUS federalIn force

Executive Order 14365, Ensuring a National Policy Framework for Artificial Intelligence (Dec. 11, 2025)

Source summary & oversight interpretation

Source summary

Directs a DOJ AI Litigation Task Force to challenge state AI laws on preemption and constitutional grounds and conditions specified federal funds on states not enforcing certain AI regimes.

The Center’s oversight interpretation

Puts a litigation shadow over every US state AI law without erasing any duty. A board relying on a state statute must know it may be contested, and a board ignoring one must know it is live today. The first live action was the xAI challenge to Colorado's 2024 act, with the Department of Justice intervening; a federal court entered a stipulated order staying enforcement and the legislature replaced the act.

Status note Every US state entry on this page carries contest risk under this order. The Center tracks the docket as a standing watch item.

Jurisdiction
US federal
Relevant sectors
Cross-sector
Relevant entities
Buyers; Builders; Model developers
Source locator
Federal Register executive orders index ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
Regulation and agency guidanceBinding where applicableUS federalIn force

OMB Memorandum M-25-21, Accelerating Federal Use of AI (Apr. 3, 2025)

Source summary & oversight interpretation

Source summary

Governs federal agency AI use; replaced M-24-10.

The Center’s oversight interpretation

The most complete oversight architecture written into US law, and binding on federal agencies: a named accountable officer (the chief AI officer), a mandatory inventory of AI use cases, and minimum risk practices tiered by impact. State governments copy it. For a private board it is pattern evidence of what a system looks like when a regulator writes one.

Jurisdiction
US federal
Relevant sectors
Public sector
Relevant entities
Public sector; Buyers
Source locator
OMB memoranda index ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
Regulation and agency guidanceBinding where applicableUS federalIn force

OMB Memorandum M-25-22, Driving Efficient Acquisition of AI in Government (Apr. 3, 2025)

Source summary & oversight interpretation

Source summary

Governs federal AI acquisition: performance-based procurement, lock-in avoidance, data and IP rights terms; replaced M-24-18.

The Center’s oversight interpretation

Procurement as the governance gate. For agencies that build nothing, diligence and contract terms are the instruments of AI control; the memo makes them mandatory. Most private-sector boards are in the same position as Buyers.

Jurisdiction
US federal
Relevant sectors
Public sector
Relevant entities
Public sector; Buyers
Source locator
OMB memoranda index ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
Regulation and agency guidanceBinding where applicableUS federalIn force

OMB Memorandum M-26-04, Unbiased AI Principles for federal LLM procurement (Dec. 11, 2025)

Source summary & oversight interpretation

Source summary

Supplements M-25-21 and M-25-22 with Unbiased AI Principles for federal procurement of large language models.

The Center’s oversight interpretation

Shows procurement conditions being used to reach model behavior. Federal-facing boards are measured against it directly; others see the contractual-control pattern applied to large language models specifically.

Jurisdiction
US federal
Relevant sectors
Public sector
Relevant entities
Public sector; Buyers
Source locator
OMB memoranda index ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
LawBinding where applicableUS federalIn force

FTC Act section 5 (15 U.S.C. § 45): unfair or deceptive AI practices and claims

Source summary & oversight interpretation

Source summary

Prohibits unfair or deceptive acts or practices in or affecting commerce. The Commission has applied it to overstated AI capabilities, misrepresented accuracy or bias testing, and AI deployments causing substantial consumer injury, including the coordinated Operation AI Comply sweep (2024 onward) and a line of health-AI claim cases. Civil penalty and injunction exposure through Commission enforcement; no AI-specific rulemaking required.

The Center’s oversight interpretation

The broadest US exposure base outside employment law, and often the only binding federal anchor for a consumer-facing AI use. The board must be able to see what AI claims the company makes and what its AI does to consumers before the Commission asks. Deceptive capability claims and unfair algorithmic outcomes are practices, and an ungoverned claim is a section 5 fact.

Jurisdiction
US federal
Relevant sectors
Consumer protection; Cross-sector; Healthcare providers
Relevant entities
Buyers; Builders; Model developers
Source
FTC Act, FTC legal library ↗
Content review recorded
July 2026
Link to this entry
LawBinding where applicableUS federalIn force

Title VII of the Civil Rights Act of 1964: algorithmic employment decisions

Source summary & oversight interpretation

Source summary

Prohibits employment discrimination on protected bases under disparate-treatment and disparate-impact theories; both reach algorithmic screening, ranking and promotion tools, and the employer cannot delegate the liability to the tool vendor.

The Center’s oversight interpretation

Disparate-impact liability attaches to outcomes, not intent, and algorithmic tools produce outcomes at scale. The only defense a board can build in advance is evidence that someone tested for disparity and someone was accountable for acting on it. With the EEOC's AI technical assistance removed, the statute itself is the only citable federal employment-AI authority.

Jurisdiction
US federal
Relevant sectors
Employment
Relevant entities
Buyers; Public companies
Source
Title VII text, EEOC ↗
Content review recorded
July 2026
Link to this entry
LawBinding where applicableUS federalIn force

Americans with Disabilities Act, Title I: AI screening and accommodation

Source summary & oversight interpretation

Source summary

Prohibits disability discrimination in employment and requires reasonable accommodation; both duties reach AI screening, assessment and monitoring tools, including proxies such as speech patterns or employment gaps. The duty survives the removal of the EEOC's technical assistance.

The Center’s oversight interpretation

Creates individual-level duties (screen-out and accommodation) that class-level statistics do not satisfy. Oversight must ensure testing covers the individual pathway and that accommodation failures surface to accountable roles. An employer that cannot explain why a tool rejected a candidate cannot show the criteria were job-related.

Jurisdiction
US federal
Relevant sectors
Employment
Relevant entities
Buyers; Public companies
Source
ADA law and regulations (official site) ↗
Content review recorded
July 2026
Link to this entry
LawBinding where applicableUS federalIn force

Fair Credit Reporting Act: algorithmic screening and AI-derived scores

Source summary & oversight interpretation

Source summary

Governs consumer reports used for employment, credit, insurance and housing decisions: permissible purpose, pre-adverse-action and adverse-action notice, accuracy and dispute rights. Algorithmic background screening and AI-derived risk scores supplied by third parties are consumer reports; a private right of action includes statutory damages for willful violations.

The Center’s oversight interpretation

Buying a score does not outsource the liability. The user of a consumer report is a duty-holder, so third-party algorithmic scores must enter the organization through governed intake with adverse-action process attached. Most mid-market employers and lenders draw this row.

Jurisdiction
US federal
Relevant sectors
Employment; Payments and consumer credit; Banking
Relevant entities
Buyers; Data holders
Source
FCRA, FTC legal library ↗
Content review recorded
July 2026
Link to this entry
Regulation and agency guidanceNonbinding guidanceUS federalPublished guidance

DOJ Evaluation of Corporate Compliance Programs, AI revisions (Sept. 2024)

Source summary & oversight interpretation

Source summary

The Criminal Division's guidance to prosecutors on evaluating compliance programs, revised September 2024 to add AI-specific questions. Guidance, not law; it supports how a board frames its program, not a finding that the company stands exposed.

The Center’s oversight interpretation

The rare external instrument whose subject is the existence and quality of an AI governance program itself. Prosecutors deciding charges and resolutions now ask whether the company assesses risks from its own AI use, governs AI in its compliance operations, monitors AI decision-making, and lets employees report AI concerns. A maturity gap is also a prosecution-posture fact.

Jurisdiction
US federal
Relevant sectors
Cross-sector
Relevant entities
Buyers; Builders; Public companies
Source
DOJ ECCP page (official site) ↗
Content review recorded
July 2026
Link to this entry
Regulation and agency guidanceBinding where applicableUS federalIn force

SEC cybersecurity disclosure: Form 8-K Item 1.05 and Regulation S-K Item 106

Source summary & oversight interpretation

Source summary

Item 1.05 requires disclosure of material cybersecurity incidents within four business days of a materiality determination; Item 106 requires annual disclosure of risk-management processes and the board's oversight role.

The Center’s oversight interpretation

AI incidents with a security dimension route through this machinery, and Item 106 makes the board's oversight itself a public disclosure. A weak description of oversight is visible to plaintiffs, not only regulators, and the four-business-day clock is unforgiving in practice.

Jurisdiction
US federal
Relevant sectors
Public company disclosure; Cybersecurity
Relevant entities
Public companies
Source
17 CFR Part 229, eCFR ↗
Content review recorded
July 2026
Link to this entry
Regulation and agency guidanceBinding where applicableUS federalIn force

Regulation S-K Items 105 and 407(h) and Exchange Act Rule 10b-5: statements about AI and about the board's oversight of it

Source summary & oversight interpretation

Source summary

Item 105 requires disclosure of material risk factors; Item 407(h) requires disclosure of the board's role in risk oversight; Rule 10b-5 prohibits material misstatements in connection with any purchase or sale of a security, including private financings. Delaware's duty of candor reaches directors who knowingly disseminate false information (Malone v. Brincat, 1998).

The Center’s oversight interpretation

A business bet stays a business risk, but its disclosure is governed by law. A known material AI risk belongs in the risk factors; the board's role in overseeing risk is a required disclosure; a misstatement is fraud. Eighty-three percent of S&P 500 companies disclosed AI as a risk in 2025 (The Conference Board); 22 percent disclosed board oversight of AI (ISS STOXX, 2025 filings). A plaintiff pleads the first and asks what the minutes show about the second.

Jurisdiction
US federal
Relevant sectors
Public company disclosure
Relevant entities
Public companies
Source
17 CFR Part 229, eCFR ↗
Content review recorded
September 2026
Link to this entry
LawBinding where applicableUS federalIn force

Sarbanes-Oxley section 301: audit committee complaint channels

Source summary & oversight interpretation

Source summary

Audit committees of listed companies must establish confidential, anonymous channels for concerns about accounting and auditing matters.

The Center’s oversight interpretation

The statutory root of the whistleblower architecture. As AI systems touch financial reporting, AI concerns become section 301-adjacent, and an AI reporting channel can anchor to one the audit committee already owns. Boeing (2021) was sustained in part because no internal complaint channel reached the board.

Jurisdiction
US federal
Relevant sectors
Public company disclosure
Relevant entities
Public companies
Source locator
SEC (official site) ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
Regulation and agency guidanceNonbinding guidanceUS federalPublished guidance

Federal Reserve SR 26-2 / OCC Bulletin 2026-13 (with the FDIC), Revised Guidance on Model Risk Management (Apr. 17, 2026)

Source summary & oversight interpretation

Source summary

Interagency model risk management principles superseding SR 11-7 and OCC Bulletin 2011-12: model lifecycle expectations including AI models, most relevant to banking organizations above $30 billion in assets; it does not set forth enforceable standards or prescriptive requirements. Vendor models stay inside model risk management even where a bank cannot fully validate them.

The Center’s oversight interpretation

The supervisor declared its own guidance non-binding and excluded the model classes moving fastest: generative AI and agentic AI are not within its scope. A board that assumes its model-risk function covers those systems should ask. It is evidence of the oversight gap, never a finding of binding non-compliance.

Jurisdiction
US federal
Relevant sectors
Banking
Relevant entities
Buyers; Builders
Source
Federal Reserve SR 26-2 and attached interagency guidance ↗
Content review recorded
September 2026
Source link checked
October 2, 2026. Confirms the linked document’s identity; it is not a full re-verification of the entry.
Link to this entry
Regulation and agency guidanceBinding where applicableUS federalIn force

OCC Heightened Standards (12 CFR Part 30, Appendix D)

Source summary & oversight interpretation

Source summary

Enforceable risk-governance expectations for covered banks above $50 billion in assets.

The Center’s oversight interpretation

The binding governance floor for large banks. Where SR guidance is advisory, this is enforceable: a risk governance structure, board challenge duties and independent risk management, whose perimeter AI risk inherits.

Jurisdiction
US federal
Relevant sectors
Banking
Relevant entities
Buyers
Source
12 CFR Part 30, eCFR ↗
Content review recorded
July 2026
Link to this entry
Regulation and agency guidanceNonbinding guidanceUS federalPublished guidance

Interagency Guidance on Third-Party Relationships: Risk Management (2023)

Source summary & oversight interpretation

Source summary

Lifecycle third-party risk management expectations for banking organizations from the Federal Reserve, FDIC and OCC.

The Center’s oversight interpretation

AI reaches most banks through vendors, so this is the operative supervisory frame for bank AI risk in practice: planning, diligence, contracting, monitoring and termination. It answers the vendor-AI questions the model-risk guidance now declines to.

Jurisdiction
US federal
Relevant sectors
Banking
Relevant entities
Buyers
Source locator
Federal Reserve SR letters index ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
Regulation and agency guidanceNonbinding guidanceUS federalPublished guidance

FFIEC IT Examination Handbook

Source summary & oversight interpretation

Source summary

The examination manual federal and state banking examiners work from.

The Center’s oversight interpretation

Tells a bank board what examiners will ask about IT, security and emerging technology, which is how an assessment finding becomes exam preparation.

Jurisdiction
US federal
Relevant sectors
Banking
Relevant entities
Buyers
Source locator
FFIEC IT Handbook (official site) ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
LawBinding where applicableUS federalIn force

Equal Credit Opportunity Act (15 U.S.C. § 1691) and Regulation B (12 CFR Part 1002): AI credit decisions

Source summary & oversight interpretation

Source summary

Creditors must state specific principal reasons for adverse credit actions. The statute and regulation govern; the CFPB's 2022 and 2023 circulars on algorithmic adverse-action notices were withdrawn May 12, 2025 and are not the source of the duty.

The Center’s oversight interpretation

The oldest explainability mandate in US law. A credit model that cannot yield specific, accurate principal reasons for a denial is non-compliant regardless of accuracy, and fair-lending liability reaches algorithmic underwriting on disparate-impact theories. For a lender this one statute does the work several AI-specific laws do elsewhere.

Jurisdiction
US federal
Relevant sectors
Banking; Payments and consumer credit
Relevant entities
Buyers
Source
Regulation B, CFPB ↗
Content review recorded
July 2026
Link to this entry
LawBinding where applicableUS federalIn force

12 U.S.C. § 1818: enforcement for unsafe or unsound practices

Source summary & oversight interpretation

Source summary

Authorizes cease-and-desist orders, civil money penalties and removals for unsafe or unsound practices.

The Center’s oversight interpretation

The teeth behind every supervisory expectation in banking. Ungoverned AI use that threatens safety and soundness is reachable here with no AI-specific rule anywhere, which is the honest answer to a director who asks what binds the bank absent an AI law.

Jurisdiction
US federal
Relevant sectors
Banking
Relevant entities
Buyers
Source
12 U.S.C. § 1818, U.S. Code ↗
Content review recorded
July 2026
Link to this entry
Regulation and agency guidanceNonbinding guidanceUS federalPublished guidance

FINRA Regulatory Notice 24-09 and the 2026 Annual Regulatory Oversight Report

Source summary & oversight interpretation

Source summary

Technology-neutral rules apply to member firms' generative AI use; supervision of AI-generated work is an examination priority.

The Center’s oversight interpretation

Existing supervision duties reach AI outputs now. A member firm's supervisory system must account for AI-generated work, which is a named examination topic. Posture; the underlying FINRA rules carry any exposure.

Jurisdiction
US federal
Relevant sectors
Securities and asset management
Relevant entities
Buyers
Source
FINRA RN 24-09 (official site) ↗
Content review recorded
July 2026
Link to this entry
Regulation and agency guidanceNonbinding guidanceUS federalPublished guidance

FHFA Advisory Bulletin AB 2022-02, Artificial Intelligence/Machine Learning Risk Management (revised May 2025)

Source summary & oversight interpretation

Source summary

Issued February 10, 2022 and revised May 2025. Supervisory expectations for Fannie Mae, Freddie Mac and Common Securitization Solutions. It does not cover the Federal Home Loan Banks, a scope error common in secondary sources.

The Center’s oversight interpretation

The only standing AI-specific supervisory bulletin among US federal financial regulators after SR 26-2 declared itself non-binding. It writes the full oversight stack as an expectation: a proportionate AI/ML risk structure, defined accountability, an inventory of applications, lifecycle controls and board visibility.

Jurisdiction
US federal
Relevant sectors
Housing finance; Banking
Relevant entities
Buyers
Source locator
FHFA (official site) ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
Standards and principlesNonbinding guidanceInternationalPublished reference

Basel Committee and Financial Stability Board publications on AI in finance

Source summary & oversight interpretation

Source summary

Supervisory direction-of-travel papers on AI in banking.

The Center’s oversight interpretation

The global supervisory community's stated concerns about model risk, third-party concentration and systemic effects preview the next round of domestic expectations for internationally active banks. Horizon, never exposure.

Jurisdiction
Global
Relevant sectors
Banking
Relevant entities
Buyers
Source locator
BIS (official site) ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
Regulation and agency guidanceBinding where applicableNew YorkIn force

NYDFS Cybersecurity Regulation, 23 NYCRR Part 500 (as amended 2023)

Source summary & oversight interpretation

Source summary

Cybersecurity requirements for DFS-licensed financial institutions, materially amended in 2023.

The Center’s oversight interpretation

The binding base beneath the two NYDFS AI letters. Exposure language for a New York licensee needs the regulation, not the letters. Its certification and board-reporting mechanics are oversight structure stated as law: a program approved by a senior governing body, a CISO with direct board reporting, notification to DFS within 72 hours, and an annual compliance certification signed at the top of the house.

Jurisdiction
New York
Relevant sectors
Banking; Insurance; Cybersecurity
Relevant entities
Buyers
Source
NYDFS cybersecurity resource center ↗
Content review recorded
July 2026
Link to this entry
Regulation and agency guidanceNonbinding guidanceNew YorkPublished guidance

NYDFS Industry Letter on Cybersecurity Risks Arising from AI (Oct. 16, 2024)

Source summary & oversight interpretation

Source summary

Interprets 23 NYCRR Part 500 for AI-related cyber risk; guidance over a binding base.

The Center’s oversight interpretation

The first US regulator statement treating AI as a cyber risk multiplier under binding rules. AI-specific threats (deepfake social engineering, AI-enhanced attacks, exposure from AI tools and vendors) enter the Part 500 risk assessment for covered entities.

Jurisdiction
New York
Relevant sectors
Banking; Insurance; Cybersecurity
Relevant entities
Buyers
Source locator
NYDFS industry guidance ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
Regulation and agency guidanceNonbinding guidanceNew YorkPublished guidance

NYDFS Industry Letter, Heightened Cybersecurity Risks Associated with Frontier AI Models (May 21, 2026)

Source summary & oversight interpretation

Source summary

A cybersecurity advisory under Part 500 that states it imposes no new requirements; supplements, and does not supersede, the October 2024 letter.

The Center’s oversight interpretation

Shows the supervisor's AI posture compounding rather than resetting; covered entities should expect examination questions to track the letter sequence.

Jurisdiction
New York
Relevant sectors
Banking; Insurance
Relevant entities
Buyers; Model developers
Source locator
NYDFS industry guidance ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
Regulation and agency guidanceNonbinding guidanceNew YorkPublished guidance

NYDFS Insurance Circular Letter No. 7 (2024): AI and external consumer data in underwriting and pricing (July 11, 2024)

Source summary & oversight interpretation

Source summary

The operative New York insurance-AI instrument: governance, testing for unfair discrimination, third-party oversight.

The Center’s oversight interpretation

Places responsibility for the outcomes of AI use with the board and senior management. Fairness testing of underwriting models and oversight of vendor data are regulator expectations, and the supervisory echo of Colorado's binding regime.

Jurisdiction
New York
Relevant sectors
Insurance
Relevant entities
Buyers
Source locator
NYDFS industry guidance ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
Regulation and agency guidanceNonbinding guidanceUS states (25 states and D.C. as of Aug. 31, 2026)Published guidance

NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers (Dec. 4, 2023)

Source summary & oversight interpretation

Source summary

Model bulletin adopted by state insurance regulators, expecting insurers to maintain a written AIS program. The source edition records the adoption count as of August 31, 2026; consult current state actions.

The Center’s oversight interpretation

One instrument, twenty-six adopting jurisdictions. An insurer's board maps adoption state by state rather than treating insurance AI as unregulated outside New York and Colorado. A written AI systems program with governance, risk management and vendor oversight is the expectation.

Jurisdiction
US states (25 states and D.C. as of Aug. 31, 2026)
Relevant sectors
Insurance
Relevant entities
Buyers
Source locator
NAIC (official site) ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
September 2026
Link to this entry
Regulation and agency guidanceBinding where applicableColoradoIn force

Colorado SB 21-169 (C.R.S. 10-3-1104.9) and amended Regulation 10-1-1: insurers' use of external consumer data, algorithms and predictive models

Source summary & oversight interpretation

Source summary

Prohibits insurers from using external consumer data, algorithms or predictive models that unfairly discriminate, and requires covered insurers (life, private passenger auto, health benefit plans) to maintain a governance and risk-management structure with reporting to the Division of Insurance. Amended Regulation 10-1-1 extends the governance duties to private passenger auto and health benefit plan insurers from October 15, 2025. The proposed quantitative-testing regulation (September 2023 draft) has not been adopted, and Bulletin B-10.004 (October 2024) waived the testing-report requirement for now.

The Center’s oversight interpretation

The closest US regulation to the oversight thesis. A governance structure with board or senior oversight, documented risk management and bias testing is not the compliance method; it is the named legal requirement. A Colorado life insurer's assessment is nearly a statutory read.

Jurisdiction
Colorado
Relevant sectors
Insurance
Relevant entities
Buyers
Source locator
Colorado Division of Insurance (official site) ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
LawBinding where applicableIowaIn force

Iowa HF 2635 (2026): health insurers' use of AI in coverage decisions

Source summary & oversight interpretation

Source summary

Effective July 1, 2026. Insurers and utilization review organizations may use AI in the initial review of prior-authorization requests, but AI may not be the sole basis to deny, delay or downgrade a medical-necessity request, in the California SB 1120 pattern.

The Center’s oversight interpretation

A legal ceiling on algorithmic autonomy in coverage decisions: no unreviewed algorithmic denial of a clinical matter. A payer's board must set the autonomy limit and evidence human review of adverse determinations. With CMS's Medicare Advantage rules and California SB 1120, it establishes the payer pattern.

Jurisdiction
Iowa
Relevant sectors
Insurance; Health plans and payers
Relevant entities
Buyers
Source locator
Iowa Legislature (official site) ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
Regulation and agency guidanceBinding where applicableUS federalIn force

HIPAA Privacy and Security Rules

Source summary & oversight interpretation

Source summary

Use and disclosure limits, minimum necessary, and administrative, technical and physical safeguards for PHI. A Security Rule modernization NPRM (January 2025) is pending, not finalized.

The Center’s oversight interpretation

The binding perimeter for healthcare AI data. Training or running a model on protected health information must fit permitted purposes and safeguard requirements, and no dedicated OCR guidance on AI exists, so HIPAA itself carries the whole duty. Business associate agreements push the same duties into AI vendor contracts.

Jurisdiction
US federal
Relevant sectors
Healthcare providers; Health plans and payers; Health IT
Relevant entities
Data holders; Buyers
Source
HHS HIPAA (official site) ↗
Content review recorded
July 2026
Link to this entry
LawBinding where applicableUS federalIn force

HITECH Act: breach notification and penalties

Source summary & oversight interpretation

Source summary

Breach notification duties and the penalty structure that gives HIPAA enforcement its economics.

The Center’s oversight interpretation

Supplies the incident-consequence arithmetic for healthcare AI: an AI-caused PHI exposure is a notifiable breach with per-record economics, which is what makes healthcare boards fund the safeguards.

Jurisdiction
US federal
Relevant sectors
Healthcare providers; Health IT
Relevant entities
Data holders
Source
HHS HIPAA (official site) ↗
Content review recorded
July 2026
Link to this entry
Regulation and agency guidanceNonbinding guidanceUS federalPublished guidance

FDA final guidance, Predetermined Change Control Plans for AI-enabled device software functions (Dec. 2024)

Source summary & oversight interpretation

Source summary

Manufacturers may pre-authorize planned modifications to AI-enabled device functions, with modification protocols and impact assessments approved in advance. FDA guidance states the agency's current thinking; the binding base is the Federal Food, Drug, and Cosmetic Act and 21 CFR Part 820.

The Center’s oversight interpretation

Lifecycle governance written into market authorization. A PCCP is a regulator-approved change-management envelope, so retraining, drift and update discipline become authorization conditions rather than internal preferences for a device builder. The clearest regulatory embodiment of adaptive-AI oversight in US law.

Jurisdiction
US federal
Relevant sectors
Medical devices
Relevant entities
Builders
Source locator
FDA guidance documents database ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
Regulation and agency guidanceNonbinding guidanceUS federalDraft or proposed

FDA draft guidance, AI-enabled device software functions: lifecycle management and marketing submissions (Jan. 2025)

Source summary & oversight interpretation

Source summary

Draft as of September 2026; finalization is a watch item.

The Center’s oversight interpretation

The forward look at device-AI expectations; citable only as draft and labeled as such. Shows a device builder's board where FDA is heading.

Status note Draft. Finalization checked at each quarterly cycle.

Jurisdiction
US federal
Relevant sectors
Medical devices
Relevant entities
Builders
Source locator
FDA guidance documents database ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
Regulation and agency guidanceNonbinding guidanceUS federalDraft or proposed

FDA draft guidance, Considerations for the Use of AI to Support Regulatory Decision-Making for Drug and Biological Products (Jan. 2025)

Source summary & oversight interpretation

Source summary

Proposes a risk-based credibility assessment: define the question of interest and context of use, assess model risk, and develop credibility evidence proportionate to that risk.

The Center’s oversight interpretation

Sponsors using AI in nonclinical, clinical or manufacturing evidence face an emerging duty to govern model credibility the way they govern data integrity. The only instrument for the pharmaceutical sub-segment; draft, so methodology and posture only.

Status note Draft. Finalization checked at each quarterly cycle.

Jurisdiction
US federal
Relevant sectors
Pharmaceuticals
Relevant entities
Builders; Buyers
Source locator
FDA guidance documents database ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
LawBinding where applicableUS federalIn force

21st Century Cures Act clinical decision support carve-out and FDA CDS guidance

Source summary & oversight interpretation

Source summary

Four criteria determine whether clinical decision support software is device-regulated, turning on whether clinicians can independently review the basis of recommendations. FDA issued revised CDS guidance on January 6, 2026, replacing the 2022 version.

The Center’s oversight interpretation

A classification gate with an explainability core. Opaque recommendations lose the carve-out and become regulated devices, so transparency of basis is a regulatory boundary condition, not a virtue.

Jurisdiction
US federal
Relevant sectors
Medical devices; Health IT
Relevant entities
Builders; Buyers
Source locator
FDA guidance documents database ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
Regulation and agency guidanceBinding where applicableUS federalIn force

HTI-1 decision support intervention transparency (45 CFR 170.315(b)(11)): under revision

Source summary & oversight interpretation

Source summary

Certified health IT must disclose source attributes (training data, logic, performance) for predictive decision support interventions. The HTI-5 NPRM (December 29, 2025) proposes removing the AI model-card elements; comments closed February 27, 2026 and no final rule had issued as of September 2026.

The Center’s oversight interpretation

The only US rule mandating model-card-style disclosure for predictive decision support in certified health IT, and it may be partially rescinded. Reports must neither overstate a rule that may shrink nor drop a rule still in force.

Status note Under revision (HTI-5 NPRM). Final-rule status checked at each quarterly cycle.

Jurisdiction
US federal
Relevant sectors
Health IT
Relevant entities
Builders
Source
90 FR 60970 (HTI-5 NPRM), Federal Register ↗
Content review recorded
July 2026
Link to this entry
Regulation and agency guidanceBinding where applicableUS federalIn force

Section 1557, 45 CFR 92.210: nondiscrimination in patient care decision support tools

Source summary & oversight interpretation

Source summary

Covered entities must make reasonable efforts to identify and mitigate discrimination risk from patient care decision support tools using protected-characteristic inputs; in force with compliance since mid-2025.

The Center’s oversight interpretation

An affirmative, ongoing duty rather than a prohibition: covered healthcare organizations must be looking for tool discrimination. An inventory of decision-support tools and a testing program is the compliance mechanism, with clinician oversight as the mitigation path. The sharpest nondiscrimination instrument in force for providers and payers.

Jurisdiction
US federal
Relevant sectors
Healthcare providers; Health plans and payers
Relevant entities
Buyers
Source
45 CFR Part 92, eCFR ↗
Content review recorded
July 2026
Link to this entry
Regulation and agency guidanceBinding where applicableUS federalIn force

CMS Conditions of Participation (42 CFR Part 482)

Source summary & oversight interpretation

Source summary

Governance, QAPI and patient-safety conditions hospitals must meet for Medicare and Medicaid participation.

The Center’s oversight interpretation

The reason AI cannot escape hospital governance. Any AI-supported process inside a hospital still sits under the governing body, quality and patient-safety conditions, so board accountability for AI-assisted care has participation-level consequence.

Jurisdiction
US federal
Relevant sectors
Healthcare providers
Relevant entities
Buyers
Source
42 CFR Part 482, eCFR ↗
Content review recorded
July 2026
Link to this entry
Regulation and agency guidanceBinding where applicableUS federalIn force

CMS Medicare Advantage coverage and utilization-management rules (42 CFR § 422.101; CMS-4201-F) and February 2024 FAQs

Source summary & oversight interpretation

Source summary

Coverage determinations must rest on individualized medical-necessity review; algorithms may inform but cannot substitute for it. The proposed CY2026 AI guardrails were not finalized.

The Center’s oversight interpretation

The federal payer-autonomy ceiling. An algorithm predicting the length of a post-acute stay cannot be the sole basis for ending coverage; determinations must rest on the individual patient's circumstances. A plan's algorithmic denial pipeline must terminate in individualized human judgment. The UnitedHealth complaint pleads this rule.

Jurisdiction
US federal
Relevant sectors
Health plans and payers
Relevant entities
Buyers
Source
42 CFR Part 422, eCFR ↗
Content review recorded
September 2026
Link to this entry
Standards and principlesNonbinding guidanceUS reference (non-governmental)Published reference

Joint Commission and CHAI, Responsible Use of AI in Healthcare guidance (Sept. 17, 2025)

Source summary & oversight interpretation

Source summary

Voluntary governance elements for healthcare organizations deploying AI.

The Center’s oversight interpretation

The accreditation world's entry into AI governance. Voluntary today, but Joint Commission provenance means the elements (accountable structures, monitoring, education) preview future accreditation expectations, which is the horizon a hospital board wants named.

Jurisdiction
United States
Relevant sectors
Healthcare providers
Relevant entities
Buyers
Source locator
Joint Commission (official site) ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
Standards and principlesNonbinding guidanceUS reference (non-governmental)Published reference

Joint Commission Responsible Use of AI in Healthcare certification (launched June 1, 2026)

Source summary & oversight interpretation

Source summary

Voluntary organization-level certification of AI governance, launched June 1, 2026.

The Center’s oversight interpretation

A recognized healthcare assurance body now certifies AI governance programs at the organization level. A board's own assessment can account for the certification as an assurance artifact.

Jurisdiction
United States
Relevant sectors
Healthcare providers
Relevant entities
Buyers
Source locator
Joint Commission (official site) ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
LawBinding where applicableEuropean UnionIn force

EU Medical Device Regulation (Regulation (EU) 2017/745)

Source summary & oversight interpretation

Source summary

Conformity assessment, clinical evaluation and post-market surveillance for devices on the EU market, interacting with the AI Act's high-risk regime for AI-enabled devices.

The Center’s oversight interpretation

For device builders with EU markets, MDR and the AI Act form a dual regime whose overlap (risk management, technical documentation, post-market surveillance) the board maps once rather than twice.

Jurisdiction
European Union
Relevant sectors
Medical devices
Relevant entities
Builders
Source
MDR, EUR-Lex ↗
Content review recorded
July 2026
Link to this entry
Standards and principlesNonbinding guidanceInternationalPublished reference

WHO, Ethics and Governance of Artificial Intelligence for Health

Source summary & oversight interpretation

Source summary

Six consensus principles (autonomy, well-being, transparency, accountability, equity, sustainability) with governance recommendations for states and institutions.

The Center’s oversight interpretation

International posture for health organizations operating across jurisdictions that want one principled frame over many legal regimes. Posture only.

Jurisdiction
Global
Relevant sectors
Healthcare providers
Relevant entities
Buyers
Source locator
WHO publications (official site) ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
LawBinding where applicableColoradoEnacted, not yet operative

Colorado SB 26-189 (2026): automated decision-making technology, effective Jan. 1, 2027

Source summary & oversight interpretation

Source summary

Signed May 14, 2026, repealing and re-enacting the 2024 Colorado AI Act as a transparency-focused regime for automated decision-making technology after the federal court in X.AI LLC v. Weiser (D. Colo.) approved, on April 24, 2026, the Department of Justice's intervention and the Attorney General's stipulation not to enforce the predecessor act.

The Center’s oversight interpretation

The re-enacted Colorado act. Enacted, not yet operative. A Colorado-touching board plans against January 1, 2027 and cites the enrolled text, never the repealed 2024 act. The developer and deployer split will be a load-bearing distinction between what a Builder's board and a Buyer's board must govern.

Status note Effective January 1, 2027. Enrolled text and the federal docket are re-checked before any client-facing citation.

Jurisdiction
Colorado
Relevant sectors
Cross-sector
Relevant entities
Builders; Buyers
Source
SB 26-189 bill page, leg.colorado.gov (verified) ↗
Content review recorded
July 2026
Link to this entry
LawBinding where applicableColoradoIn force

Colorado Privacy Act: profiling opt-out and data-protection assessments

Source summary & oversight interpretation

Source summary

Consumers may opt out of profiling in furtherance of decisions with legal or similarly significant effects; data-protection assessments are required before such profiling; universal opt-out mechanisms are honored. Enforcement by the Attorney General and district attorneys.

The Center’s oversight interpretation

A legally required pre-deployment assessment for significant-decision profiling is exactly the evidence artifact a board can ask to see by name. It supplies live Colorado duties while the automated-decision act waits for 2027. Connecticut, Virginia and Texas privacy acts carry parallel profiling clauses.

Jurisdiction
Colorado
Relevant sectors
Privacy
Relevant entities
Data holders; Buyers
Source
Colorado AG CPA page (official site) ↗
Content review recorded
July 2026
Link to this entry
Regulation and agency guidanceBinding where applicableCaliforniaPartly in force

California CPPA regulations: automated decision-making technology, risk assessments and cybersecurity audits

Source summary & oversight interpretation

Source summary

ADMT rights (pre-use notice, opt-out, access to logic) with significant-decision compliance from January 1, 2027; mandatory risk assessments with certifications from April 1, 2028; independent cybersecurity audits phasing to 2030.

The Center’s oversight interpretation

The deepest operative US automated-decision regime and a preview of where state law converges: documented risk assessment before consequential automation, explainable logic, consumer redress and audit obligations, each with a date. California-touching consumer businesses measure directly against the calendar.

Status note Dated obligations: January 1, 2027 (ADMT significant decisions); April 1, 2028 (risk-assessment certifications).

Jurisdiction
California
Relevant sectors
Privacy; Cross-sector
Relevant entities
Buyers; Data holders
Source
CPPA regulations page (official site) ↗
Content review recorded
July 2026
Link to this entry
LawBinding where applicableCaliforniaIn force

California Consumer Privacy Act as amended by the CPRA

Source summary & oversight interpretation

Source summary

Access, deletion, correction and opt-out rights and sensitive-data limits reaching personal data used in AI pipelines.

The Center’s oversight interpretation

The data-rights floor under California AI work. Deletion and correction rights constrain training-data handling, and the statute is the enforcement hook the CPPA regulations hang from.

Jurisdiction
California
Relevant sectors
Privacy
Relevant entities
Data holders; Buyers
Source
California AG CCPA page (official site) ↗
Content review recorded
July 2026
Link to this entry
LawBinding where applicableCaliforniaIn force

California AB 2013: generative AI training-data transparency

Source summary & oversight interpretation

Source summary

Developers of generative AI made available in California must publicly post documentation of training datasets, including sources and whether personal or copyrighted data is included; operative January 1, 2026.

The Center’s oversight interpretation

The first US statutory training-data provenance duty in force. Its public-posting mechanic means noncompliance is externally checkable, which regulators and plaintiffs both notice. Provenance becomes a compliance surface, not hygiene.

Jurisdiction
California
Relevant sectors
Cross-sector
Relevant entities
Builders; Model developers
Source locator
California Legislative Information (official site) ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
LawBinding where applicableCaliforniaIn force

California SB 53 (2025): frontier AI safety structures, transparency and incident reporting

Source summary & oversight interpretation

Source summary

Developers above compute or revenue thresholds must publish safety structures, file transparency reports, report critical incidents within 15 days and maintain whistleblower protections; in force January 1, 2026. Consult the statutory thresholds for the relevant category of developer.

The Center’s oversight interpretation

The first binding US frontier regime and the anchor for a model developer's board: a published safety structure, incident reporting on a statutory clock and whistleblower protection. With New York's RAISE Act and Illinois SB 315 it forms a three-state pattern: publish and comply, report and be supervised, be audited.

Jurisdiction
California
Relevant sectors
Cross-sector
Relevant entities
Model developers
Source locator
California Legislative Information (official site) ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
LawBinding where applicableCaliforniaPartly in force

California AI Transparency Act (SB 942, as amended by AB 853)

Source summary & oversight interpretation

Source summary

Covered generative AI providers must offer AI-detection tools and embed disclosures in AI-generated content, operative August 2, 2026; platform duties January 1, 2027; capture-device duties January 1, 2028.

The Center’s oversight interpretation

Synthetic-content transparency as binding law on the provider side. A generative AI builder's board owns detection tools and embedded disclosures as statutory duties from August 2, 2026, with platform and capture-device duties following.

Status note Platform duties January 1, 2027; capture-device duties January 1, 2028.

Jurisdiction
California
Relevant sectors
Cross-sector; Consumer protection
Relevant entities
Builders; Model developers
Source locator
California Legislative Information (official site) ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
LawBinding where applicableCaliforniaIn force

California SB 243 (2025): companion chatbots

Source summary & oversight interpretation

Source summary

Operator duties for companion chatbots; signed October 13, 2025, in force January 1, 2026; annual reporting to the state; private right of action.

The Center’s oversight interpretation

Safety protocols named in a statute are a WHAT the board must mandate, resource and evidence, not a product choice: human-status disclosure, self-harm response with crisis referral, minor protections. A private right of action sharpens the exposure. The lead exemplar of a class of fourteen or more companion-chatbot statutes enacted in 2025 and 2026.

Jurisdiction
California
Relevant sectors
Consumer protection
Relevant entities
Builders
Source locator
California Legislative Information (official site) ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
Regulation and agency guidanceBinding where applicableCaliforniaIn force

California Civil Rights Council FEHA regulations on automated-decision systems in employment (effective Oct. 1, 2025)

Source summary & oversight interpretation

Source summary

Unlawful to use an automated-decision system that discriminates in employment; ADS defined broadly (résumé screeners, targeted advertising, gamified assessments, ranking tools); liability extends to agents acting for the employer; four-year retention of ADS records including selection criteria and outcome data; evidence of anti-bias testing, or its absence, is relevant to liability.

The Center’s oversight interpretation

The most operative state employment-AI regulation in force, and its evidentiary structure is the oversight argument written into law: the presence or absence of anti-bias testing and records is itself the litigated fact. An organization that governed well but recorded nothing is legally exposed. Agent liability makes vendor diligence a liability firewall.

Jurisdiction
California
Relevant sectors
Employment
Relevant entities
Buyers
Source locator
California Civil Rights Department (official site) ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
LawBinding where applicableTexasIn force

Texas Responsible Artificial Intelligence Governance Act (HB 149), effective Jan. 1, 2026

Source summary & oversight interpretation

Source summary

Prohibited uses (behavioral manipulation, social scoring, unconsented biometric identification), disclosure duties in government and healthcare interactions, Attorney General exclusive enforcement, a regulatory sandbox.

The Center’s oversight interpretation

The prohibition-and-disclosure template rather than the assessment-and-audit template. Texas exposure runs through use-case screening (prohibited uses) and interaction disclosure, not program mandates, which matters for multi-state boards mapping what each state asks of them.

Jurisdiction
Texas
Relevant sectors
Cross-sector; Healthcare providers
Relevant entities
Builders; Buyers
Source locator
Texas Legislature Online (official site) ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
LawBinding where applicableIllinoisIn force

Illinois Human Rights Act as amended by HB 3773 (P.A. 103-0804), effective Jan. 1, 2026

Source summary & oversight interpretation

Source summary

Employment discrimination through AI, including zip-code proxies, is a civil rights violation; employers must notify employees of AI use in employment decisions.

The Center’s oversight interpretation

The statutory proxy-discrimination rule. Fairness testing that checks protected classes directly and misses the zip-code pattern the statute names is not enough for an Illinois employer, and the notice duty adds a transparency leg.

Jurisdiction
Illinois
Relevant sectors
Employment
Relevant entities
Buyers
Source locator
Illinois General Assembly (official site) ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
LawBinding where applicableIllinoisIn force

Illinois Biometric Information Privacy Act (740 ILCS 14)

Source summary & oversight interpretation

Source summary

Informed written consent before collecting biometric identifiers, retention schedules, and a private right of action with per-violation statutory damages.

The Center’s oversight interpretation

The class-action engine in the corpus. Any AI pipeline touching face, voice or fingerprint data of Illinois residents carries per-scan exposure with nine-figure precedent behind it, which makes biometric-input inventory a first-pass board question.

Jurisdiction
Illinois
Relevant sectors
Privacy
Relevant entities
Data holders; Buyers
Source locator
Illinois General Assembly (official site) ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
LawBinding where applicableIllinoisIn force

Illinois Artificial Intelligence Video Interview Act (820 ILCS 42)

Source summary & oversight interpretation

Source summary

Employers using AI analysis of video interviews must notify applicants, explain how the AI works and what it evaluates, obtain consent, restrict sharing, destroy the video within 30 days of a request, and, where AI analysis alone determines in-person advancement, report applicant demographic data to the state annually.

The Center’s oversight interpretation

Long-operative and narrow, with one of the few affirmative demographic-reporting duties in US employment-AI law. Notice, explanation, consent and destruction duties governance must institutionalize wherever AI video screening is used.

Jurisdiction
Illinois
Relevant sectors
Employment
Relevant entities
Buyers
Source locator
Illinois Compiled Statutes index (official site) ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
LawBinding where applicableIllinoisEnacted, not yet operative

Illinois AI Safety Measures Act (SB 315, 2026): frontier model audits, phasing in from Jan. 1, 2027

Source summary & oversight interpretation

Source summary

Signed July 6, 2026. Most provisions take effect January 1, 2027; the frontier AI structure and annual third-party audit duties apply from January 1, 2028. Frontier developers meeting both thresholds (revenue above $500 million and training compute above 10^26 operations) owe a published, annually updated frontier AI structure, annual independent third-party safety audits reported to the state, 72-hour and 24-hour incident reporting, and whistleblower protections; Illinois Emergency Management Agency administration, Attorney General enforcement, civil penalties, no private right of action.

The Center’s oversight interpretation

A statutory annual third-party audit duty is an oversight structure requirement in itself: a frontier developer's board owns its existence and its findings. Completes the three-state frontier pattern with California SB 53 and New York's RAISE Act.

Status note Most provisions January 1, 2027; framework and audit duties January 1, 2028.

Jurisdiction
Illinois
Relevant sectors
Cross-sector
Relevant entities
Model developers
Source locator
Illinois General Assembly (official site) ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
LawBinding where applicableUtahIn force

Utah Code 13-75 (SB 226, 2025): generative AI disclosure

Source summary & oversight interpretation

Source summary

Generative AI must disclose non-human status when clearly asked, and proactively in high-risk regulated-occupation interactions; effective May 7, 2025. The separate Utah AI Policy Act (Title 13, Chapter 72, which runs the Office of AI Policy and its learning lab) sunsets July 1, 2027; the Chapter 75 disclosure duties do not.

The Center’s oversight interpretation

A light-touch disclosure exemplar, useful for multi-state disclosure mapping and as evidence that state approaches range from Utah's ask-triggered floor to California's embedded-disclosure regime.

Jurisdiction
Utah
Relevant sectors
Consumer protection
Relevant entities
Buyers; Builders
Source locator
Utah Legislature (official site) ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
LawBinding where applicableConnecticutPartly in force

Connecticut Public Act 26-15 (SB 5), An Act Concerning Online Safety

Source summary & oversight interpretation

Source summary

The act addresses online safety and selected AI uses. Its first provisions took effect October 1, 2026. Other provisions have later effective dates; the act specifies the covered activities, exceptions, and dates section by section.

The Center’s oversight interpretation

Organizations operating in Connecticut need to identify the provisions relevant to their AI activities and record who is responsible for the requirements as each phase takes effect. The duties vary by activity and covered entity.

Status note Partly in force. Read the effective date and scope of each section; October 1, 2026 is not the start date for every duty.

Jurisdiction
Connecticut
Relevant sectors
Cross-sector
Relevant entities
Builders; Buyers
Citation
Connecticut Public Act 26-15 (2026)
Source
Enacted Public Act 26-15, Connecticut General Assembly (PDF) ↗
Content review recorded
October 2, 2026
Source link checked
October 2, 2026. Confirms the linked document’s identity; it is not a full re-verification of the entry.
Link to this entry
LawBinding where applicableNew YorkEnacted, not yet operative

New York RAISE Act (Ch. 699 of 2025, as amended): frontier AI safety protocols

Source summary & oversight interpretation

Source summary

Signed December 2025 and amended by S8828 (signed March 27, 2026). Frontier developers above a $500 million revenue threshold owe safety protocols, 72-hour incident reporting to a new office within the Department of Financial Services, and DFS oversight, effective January 1, 2027.

The Center’s oversight interpretation

The second frontier-actor statute, and the notable divergence is supervisory: New York placed frontier AI under a financial regulator, importing examination culture into AI safety. Incident clocks and an escalation path that ends at a regulator.

Status note Enforcement from January 1, 2027.

Jurisdiction
New York
Relevant sectors
Cross-sector
Relevant entities
Model developers
Source locator
New York State Senate (official site) ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
LawBinding where applicableNew York CityIn force

New York City Local Law 144 of 2021: automated employment decision tools

Source summary & oversight interpretation

Source summary

Automated employment decision tools require an annual independent bias audit, publication of results and candidate notice; enforced from July 5, 2023.

The Center’s oversight interpretation

The first operating bias-audit mandate in the US and a cautionary tale in one row. The duty is real and citable; the New York State Comptroller's December 2025 audit found enforcement largely ineffective. Board language stays honest about both.

Jurisdiction
New York City
Relevant sectors
Employment
Relevant entities
Buyers
Source
NYC DCWP AEDT page (official site) ↗
Content review recorded
July 2026
Link to this entry
LawBinding where applicableMontanaIn force

Montana Right to Compute Act (2025)

Source summary & oversight interpretation

Source summary

Protects computational activity as a baseline while requiring risk management policies for AI that controls critical infrastructure.

The Center’s oversight interpretation

A liberty-framed statute that still lands an oversight duty where AI controls critical infrastructure: risk management policies keyed to recognized standards. The smallest instance of the critical-infrastructure AI pattern.

Jurisdiction
Montana
Relevant sectors
Cross-sector
Relevant entities
Buyers
Source locator
Montana Legislature (official site) ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
Regulation and agency guidanceBinding where applicableUS federalIn force

NHTSA Standing General Order 2021-01 (as amended): crash reporting for automated driving and Level 2 systems

Source summary & oversight interpretation

Source summary

Requires crash-incident reporting for vehicles equipped with automated driving systems and Level 2 driver assistance. The Standing General Order is the operative instrument; structure and exemption material is posture.

The Center’s oversight interpretation

With no federal certification rule for automated driving, the operative federal duty is incident reporting with a regulator attached. An AV builder's board must govern a reporting pipeline whose completeness is legally consequential.

Jurisdiction
US federal
Relevant sectors
Transportation
Relevant entities
Builders
Source locator
NHTSA (official site) ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
Regulation and agency guidanceBinding where applicableUS federalIn force

FCC declaratory ruling (Feb. 2024): AI-generated voice is an 'artificial voice' under the TCPA

Source summary & oversight interpretation

Source summary

Calls using cloned or synthetic voices require the prior express consent the TCPA demands. The ruling applied existing law; no new rule was needed.

The Center’s oversight interpretation

Reaches far beyond telecom. Any organization using AI voice for outbound contact (collections, scheduling, marketing, service callbacks) inherited per-call exposure with statutory damages and a private right of action the day the ruling issued. The board question is who approved AI voice use against a consent inventory.

Jurisdiction
US federal
Relevant sectors
Cross-sector; Telecommunications; Consumer protection
Relevant entities
Buyers; Builders
Source locator
FCC (official site) ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
LawBinding where applicableUS federalIn force

FERPA as applied to AI in education technology

Source summary & oversight interpretation

Source summary

Conditions federal education funding on protecting student education records; disclosure requires consent or a named exception; the school-official exception requires direct control and legitimate educational interest.

The Center’s oversight interpretation

Institutional governance must approve edtech AI data flows against FERPA's exception structure, and an AI vendor training on student data strains the school-official exception to breaking. Procurement of AI tools is a records-governance decision with funding-condition exposure behind it.

Jurisdiction
US federal
Relevant sectors
Education; Privacy
Relevant entities
Buyers; Data holders; Public sector
Source locator
Student Privacy Policy Office, ED (official site) ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
LawBinding where applicableEuropean UnionPartly in force

EU AI Act (Regulation (EU) 2024/1689), as amended by Regulation (EU) 2026/1744

Source summary & oversight interpretation

Source summary

Prohibitions and AI literacy duties in application since February 2, 2025; general-purpose AI provider duties and the penalty regime since August 2, 2025, with fines on general-purpose AI providers (Article 101) from August 2, 2026; transparency duties (Article 50) from August 2, 2026, with generative AI systems already on the market given until December 2, 2026 for content marking. The July 2026 Digital Omnibus (Regulation (EU) 2026/1744, in force July 27, 2026) deferred the high-risk obligations to December 2, 2027 (Annex III) and August 2, 2028 (Annex I).

The Center’s oversight interpretation

The most consequential AI statute in the world and the easiest to miscite: cite per obligation, never as a monolith. The provider and deployer split is the statutory form of the Builders and Buyers distinction; a Buyer board's Article 26 duties differ from a Builder's Chapter III set. Prohibited-practice screening is a governance gate a board must be able to evidence, and workplace emotion recognition reaches ordinary HR technology.

Status note High-risk obligations December 2, 2027 and August 2, 2028. Each obligation's date is tracked separately.

Jurisdiction
European Union
Relevant sectors
Cross-sector
Relevant entities
Builders; Buyers; Model developers
Source
AI Act, EUR-Lex CELEX 32024R1689 ↗
Amending Regulation (EU) 2026/1744 ↗
European Commission implementation overview ↗
Content review recorded
September 2026
Link to this entry
LawBinding where applicableEuropean UnionIn force

EU Digital Omnibus (Regulation (EU) 2026/1744), in force July 27, 2026

Source summary & oversight interpretation

Source summary

Amends Regulation (EU) 2024/1689; published in the Official Journal July 24, 2026. Annex III high-risk obligations apply from December 2, 2027 and Annex I from August 2, 2028; generative AI systems already on the market have until December 2, 2026 to meet the content-marking duty.

The Center’s oversight interpretation

Reset the high-risk calendar every EU AI Act date on this page now anchors to, and added a prohibition on non-consensual intimate imagery and child sexual abuse material. A board planning against the old dates is planning against repealed text.

Jurisdiction
European Union
Relevant sectors
Cross-sector
Relevant entities
Builders; Buyers
Source
Regulation (EU) 2026/1744, Official Journal (PDF) ↗
European Commission explanation of the amended timetable ↗
Content review recorded
September 2026
Source link checked
October 2, 2026. Confirms the linked document’s identity; it is not a full re-verification of the entry.
Link to this entry
LawBinding where applicableEuropean UnionIn force

GDPR Article 22: solely automated decisions

Source summary & oversight interpretation

Source summary

A qualified prohibition on solely automated decisions with legal or similarly significant effects, with narrow exceptions and mandatory safeguards.

The Center’s oversight interpretation

The EU's automated-decision baseline and the root of the global human-review pattern: human intervention, expression of views and contest. Oversight must know which decisions fall inside it before automation is approved. The United Kingdom's regime has diverged since 2025; the two must never borrow each other's language.

Jurisdiction
European Union
Relevant sectors
Privacy
Relevant entities
Buyers; Data holders
Source
GDPR, EUR-Lex CELEX 32016R0679 ↗
Content review recorded
July 2026
Link to this entry
Standards and principlesNonbinding guidanceUS federalPublished reference

NIST AI Risk Management Framework (AI RMF 1.0, Jan. 2023)

Source summary & oversight interpretation

Source summary

NIST AI RMF 1.0 organizes AI risk management into four functions: GOVERN, MAP, MEASURE, and MANAGE. Its categories and subcategories support voluntary risk management.

The Center’s oversight interpretation

A voluntary reference for identifying and managing AI risks. The Center uses GOVERN to examine whether authority, accountability, and reporting are established in practice. The AI RMF does not independently impose a legal duty; any incorporation into law or contract must be assessed separately.

Jurisdiction
United States (voluntary)
Relevant sectors
Cross-sector
Relevant entities
Buyers; Builders; Model developers
Source
NIST AI RMF page (official site) ↗
Content review recorded
October 2, 2026
Source link checked
October 2, 2026. Confirms the linked document’s identity; it is not a full re-verification of the entry.
Link to this entry
Standards and principlesNonbinding guidanceUS federalPublished reference

NIST AI 600-1, Generative AI Profile

Source summary & oversight interpretation

Source summary

Published July 26, 2024. The voluntary Generative Artificial Intelligence Profile extends the AI RMF to generative AI; it is a companion publication rather than a replacement for AI RMF 1.0.

The Center’s oversight interpretation

A companion to the AI RMF that identifies risks particular to generative AI and proposes risk-management actions. The Center uses it to inform the risks that oversight reporting should address.

Jurisdiction
United States (voluntary)
Relevant sectors
Cross-sector
Relevant entities
Buyers; Builders; Model developers
Source
NIST AI 600-1, Generative Artificial Intelligence Profile ↗
Content review recorded
October 2, 2026
Source link checked
October 2, 2026. Confirms the linked document’s identity; it is not a full re-verification of the entry.
Link to this entry
Standards and principlesNonbinding guidanceInternationalPublished reference

ISO/IEC 42001:2023, AI management systems

Source summary & oversight interpretation

Source summary

ISO/IEC 42001:2023 specifies requirements for an AI management system. Certification of a management system is distinct from establishing legal compliance for every AI use. Full text is licensed by ISO.

The Center’s oversight interpretation

A reference for examining an AI management system, including policy, leadership, responsibilities, and management review. Certification scope should be distinguished from the board’s oversight responsibilities.

Jurisdiction
International
Relevant sectors
Cross-sector
Relevant entities
Buyers; Builders; Model developers
Source
ISO/IEC 42001:2023, official scope and publication details ↗
Content review recorded
July 2026
Source link checked
October 2, 2026. Confirms the linked document’s identity; it is not a full re-verification of the entry.
Link to this entry
Standards and principlesNonbinding guidanceInternationalPublished reference

ISO/IEC 38507:2022, Governance implications of the use of AI by organizations

Source summary & oversight interpretation

Source summary

Guidance on the governance implications of the use of AI by organizations. The full standard is licensed by ISO; the linked page describes its scope.

The Center’s oversight interpretation

A reference for governing bodies considering the implications of organizational AI use. It helps distinguish the responsibilities of oversight from the design and operation of the system.

Jurisdiction
International
Relevant sectors
Cross-sector
Relevant entities
Buyers
Source
ISO/IEC 38507:2022, official scope and publication details ↗
Content review recorded
October 2, 2026
Source link checked
October 2, 2026. Confirms the linked document’s identity; it is not a full re-verification of the entry.
Link to this entry
Standards and principlesNonbinding guidanceInternationalPublished reference

ISO/IEC 23894:2023, AI risk management

Source summary & oversight interpretation

Source summary

AI risk management aligned to ISO 31000.

The Center’s oversight interpretation

Bridges AI risk into the enterprise risk machinery boards already run, for organizations whose risk management speaks ISO 31000. Licensed text.

Jurisdiction
International
Relevant sectors
Cross-sector
Relevant entities
Buyers; Builders
Source
ISO Online Browsing Platform (licensed text) ↗
Content review recorded
July 2026
Link to this entry
Standards and principlesNonbinding guidanceUS reference (non-governmental)Published reference

AICPA Trust Services Criteria

Source summary & oversight interpretation

Source summary

Control criteria for security, availability, processing integrity, confidentiality, and privacy. SOC 2 examinations use the Trust Services Criteria; the report’s scope determines what was examined.

The Center’s oversight interpretation

A reference for understanding the scope of a service organization’s assurance report. The Center recommends examining the systems, criteria, period, and exceptions covered before relying on the report for an AI-related decision.

Jurisdiction
United States
Relevant sectors
Cross-sector
Relevant entities
Buyers; Builders
Source
AICPA 2017 Trust Services Criteria, revised points of focus 2022 ↗
Content review recorded
October 2, 2026
Source link checked
October 2, 2026. Confirms the linked document’s identity; it is not a full re-verification of the entry.
Link to this entry
Standards and principlesNonbinding guidanceUS reference (non-governmental)Published reference

COSO Enterprise Risk Management: Integrating with Strategy and Performance (2017)

Source summary & oversight interpretation

Source summary

COSO’s 2017 enterprise risk management publication connects risk with strategy and performance. It is distinct from COSO’s Internal Control: Integrated Framework (2013).

The Center’s oversight interpretation

A reference for bringing AI risk into the institution’s established risk appetite, decision, and reporting processes. The Center’s interpretation concerns the connection between enterprise risk management and AI oversight.

Status note The core reference is the 2017 publication. The companion link identifies COSO guidance on applying enterprise risk management to AI.

Jurisdiction
United States
Relevant sectors
Cross-sector
Relevant entities
Buyers; Public companies
Source
COSO Enterprise Risk Management, 2017 publication and executive summary ↗
COSO companion guidance on AI ↗
Content review recorded
July 2026
Source link checked
October 2, 2026. Confirms the linked document’s identity; it is not a full re-verification of the entry.
Link to this entry
Standards and principlesNonbinding guidanceUS reference (non-governmental)Published reference

NACD board risk oversight guidance

Source summary & oversight interpretation

Source summary

What directors should ask, what reporting they should expect, and how committees should divide risk work.

The Center’s oversight interpretation

When a board brief tells directors what reporting cadence to demand, citing the directors' own association lands better than citing a regulator. Membership-gated; posture only.

Jurisdiction
United States
Relevant sectors
Cross-sector
Relevant entities
Buyers; Public companies
Source locator
NACD (official site; membership gate) ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
Retired instruments & sources not identified (8)

These entries are separate from the current-authority results. Absence statements reflect the recorded review, not a guarantee that no later instrument exists.

Regulation and agency guidanceDo not cite as liveUS federalRetired

Executive Order 14110 (Oct. 30, 2023): rescinded Jan. 20, 2025

Source summary & oversight interpretation

Source summary

The 2023 AI executive order, revoked January 20, 2025.

The Center’s oversight interpretation

Never citable as governing authority. It is listed because it is still cited as live in circulating materials, and because citing a rescinded order in a board paper is the kind of error a plaintiff quotes back.

Jurisdiction
US federal
Relevant sectors
Cross-sector
Relevant entities
Buyers; Builders; Model developers; Public sector
Source locator
Federal Register executive orders index ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
Regulation and agency guidanceDo not cite as liveUS federalRetired

EEOC technical assistance on AI and employment (2022): removed 2025

Source summary & oversight interpretation

Source summary

The EEOC's 2022 technical assistance documents on the ADA and Title VII as applied to algorithmic employment tools were removed from eeoc.gov in 2025; the ADA document no longer resolves and the Title VII companion's status is unresolved.

The Center’s oversight interpretation

Employment-AI consequence language must rest on Title VII and the ADA directly. Any source that still cites this guidance as current is dated on its face, which is a quick credibility test for other people's materials.

Jurisdiction
US federal
Relevant sectors
Employment
Relevant entities
Buyers; Public companies
Source locator
EEOC guidance index (removal is the finding) ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
Regulation and agency guidanceDo not cite as liveUS federalRetired

Federal Reserve SR 11-7 (2011): superseded by SR 26-2

Source summary & oversight interpretation

Source summary

The 2011 model risk management letter, superseded April 17, 2026.

The Center’s oversight interpretation

Citable only as the named predecessor. A generation of bank risk managers still quotes it from memory; a board paper that cites it as current is wrong on its face.

Jurisdiction
US federal
Relevant sectors
Banking
Relevant entities
Buyers
Source
Federal Reserve notice identifying the superseded guidance ↗
Content review recorded
July 2026
Source link checked
October 2, 2026. Confirms the linked document’s identity; it is not a full re-verification of the entry.
Link to this entry
Regulation and agency guidanceDo not cite as liveUS federalRetired

CFPB Circulars 2022-03 and 2023-03 (adverse action and complex algorithms): withdrawn May 12, 2025

Source summary & oversight interpretation

Source summary

Withdrawn at 90 FR 20084.

The Center’s oversight interpretation

Never cite as live. The duties survive in ECOA and Regulation B; the circulars are still cited in circulating compliance materials.

Jurisdiction
US federal
Relevant sectors
Payments and consumer credit; Banking
Relevant entities
Buyers
Source
90 FR 20084, Federal Register ↗
Content review recorded
July 2026
Link to this entry
Regulation and agency guidanceDo not cite as liveUS federalRetired

SEC predictive data analytics proposal (S7-12-23): withdrawn June 12, 2025

Source summary & oversight interpretation

Source summary

The Commission withdrew the proposal with a statement that it will not be finalized.

The Center’s oversight interpretation

Never cite as pending. Adviser-side AI conduct questions route through existing fiduciary and marketing rules and the AI-washing enforcement line.

Jurisdiction
US federal
Relevant sectors
Securities and asset management
Relevant entities
Buyers
Source locator
SEC (official site; withdrawal is the finding) ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
Regulation and agency guidanceNot identifiedUS federalNot identified

Separate HHS OCR guidance on HIPAA and AI: not identified in this edition

Source summary & oversight interpretation

Source summary

The September source register did not identify a separate AI-specific HIPAA guidance instrument. This is a recorded search result, not proof of absence; consult current HHS OCR publications.

The Center’s oversight interpretation

HIPAA obligations remain relevant to AI uses involving protected health information. A reference to a separate AI-specific HIPAA instrument requires the actual issuing source.

Jurisdiction
US federal
Relevant sectors
Healthcare providers
Relevant entities
Buyers; Data holders
Source locator
HHS OCR (official site; absence is the finding) ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
LawDo not cite as liveColoradoRetired

Colorado AI Act (SB 24-205, as amended by SB25B-004): repealed and replaced by SB 26-189

Source summary & oversight interpretation

Source summary

The 2024 act, delayed by SB25B-004, stayed in X.AI LLC v. Weiser, and repealed and re-enacted by SB 26-189 in May 2026.

The Center’s oversight interpretation

Never citable as live. Delayed, stayed in federal court and repealed within thirteen months; the replacement, SB 26-189, takes effect January 1, 2027. Materials that cite the 2024 act are out of date.

Jurisdiction
Colorado
Relevant sectors
Cross-sector
Relevant entities
Builders; Buyers
Source
SB 26-189 bill page, leg.colorado.gov ↗
Content review recorded
July 2026
Link to this entry
LawNot identifiedVirginiaNot identified

Virginia HB 2094 (2025): vetoed proposal

Source summary & oversight interpretation

Source summary

The source register records the March 2025 veto of HB 2094. Consult the legislature’s record for that proposal and any later legislation.

The Center’s oversight interpretation

The vetoed proposal should not be cited as enacted law. Its status does not establish that no other Virginia requirements apply to an AI use.

Jurisdiction
Virginia
Relevant sectors
Cross-sector
Relevant entities
Buyers
Source locator
Virginia LIS (official site) ↗

This link opens a source index or finding aid. Use the title and citation above to locate the instrument.

Content review recorded
July 2026
Link to this entry
Coverage & method

A reference for oversight decisions

Scope

The register covers selected US federal and state authorities, Delaware corporate oversight doctrine and related cases, selected EU instruments, and international standards. It is a curated resource, not an exhaustive jurisdictional survey. The UK, Canada, Australia, Singapore, Latin America, and additional EU sectoral instruments are outside this edition’s coverage.

Legal weight

Statutes and binding rules apply within their stated scope. Judicial decisions depend on governing law and procedural posture. Pending claims are allegations. Guidance and voluntary standards do not independently establish statutory duties; their relevance can also depend on adoption into law, contracts, or other binding requirements.

Sources and interpretation

Direct links identify the underlying instrument where available. A link labeled “Source locator” opens an index or finding aid. “Content review recorded” preserves the entry’s review date; a separate source-link check confirms document identity. The Center’s interpretation is identified separately from the source summary.

Updates and corrections

The September 2026 edition is supplemented by dated editorial updates. Material corrections and effective-date changes can be incorporated between editions. Each entry retains its own review record.

Send a correction or source update →

Center materials are educational and do not constitute legal advice. The program is the governance: the authorities inform the decisions, responsibilities, and evidence it records.

The AI Oversight Brief

A short briefing on a consequential oversight decision.