Every significant claim, traceable.
This guide distinguishes five kinds of statement — regulation (binding), standard (certifiable), practice (recommended), vendor capability (verify before contracting), and Google's own view. The register below is the evidence base; content snapshot August 2026.
Methodology: content synthesized August 2026 from primary sources — regulation texts and official guidance, standards bodies, first-party vendor documentation, published research, and reported incidents. Product capabilities and legal statuses change; verify anything deal-critical against the linked originals. This site is an educational aid, not legal or compliance advice.
Binding law. Dates and duties as enacted; not legal advice.
| Title | Organization | Date |
|---|---|---|
| Regulation (EU) 2024/1689 (AI Act) — implementation timeline | European Union | 2026-08 |
| Digital Omnibus on AI — Regulation (EU) 2026/1744 | European Union | 2026-07 |
| AI Basic Act (effective Jan 22, 2026) — overview | Republic of Korea / Cooley | 2026-01 |
| EO: Ensuring a National Policy Framework for AI | The White House | 2025-12 |
| California SB 53 (frontier AI transparency) explained | Future of Privacy Forum | 2025-10 |
| Guidance on AI-enabled ambient scribing in health and care | NHS England | 2025-04 |
Certifiable or auditable specifications (ISO/IEC family).
| Title | Organization | Date |
|---|---|---|
| ISO/IEC 42001:2023 — AI management systems | ISO/IEC | 2023-12 |
| ISO/IEC 42005:2025 — AI system impact assessment | ISO/IEC | 2025-05 |
Voluntary but load-bearing: NIST, OWASP, MITRE, CSA, analyst frameworks.
| Title | Organization | Date |
|---|---|---|
| NIST AI Risk Management Framework + Generative AI Profile (AI 600-1) | NIST | 2024-07 |
| OECD AI Principles (2024 update) | OECD | 2024-05 |
| OWASP Top 10 for LLM Applications (2025) | OWASP GenAI Security Project | 2024-11 |
| OWASP Top 10 for Agentic Applications | OWASP GenAI Security Project | 2025-12 |
| MITRE ATLAS — adversarial threat landscape for AI | MITRE | 2025-11 |
| CSA AI Controls Matrix v1.1 (247 controls) | Cloud Security Alliance | 2026-07 |
| AI governance needs more than policies (AI TRiSM) | Gartner | 2025-06 |
Empirical findings — cite with their dates; sample sizes matter.
| Title | Organization | Date |
|---|---|---|
| State of AI trust in 2026: shifting to the agentic era | McKinsey | 2026-03 |
| The State of AI (March 2025) | McKinsey | 2025-03 |
| Cost of a Data Breach Report 2025 (shadow-AI findings) | IBM | 2025-07 |
| Cloud & Threat Report: Generative AI 2025 | Netskope | 2025-02 |
| Over 40% of agentic AI projects will be canceled by end-2027 | Gartner | 2025-06 |
| Agentic misalignment: how LLMs could be insider threats | Anthropic (research) | 2025-06 |
| The GenAI Divide: 95% of pilots show no P&L impact (coverage) | MIT / Fortune | 2025-08 |
| FinOps for AI overview | FinOps Foundation | 2026-01 |
Official Google/Google Cloud documentation and announcements.
Microsoft, AWS, OpenAI, Anthropic and others, from their own documentation.
| Title | Organization | Date |
|---|---|---|
| TELUS Fuel iX — ISO 31700-1 certified gen-AI platform | TELUS Digital | 2024-05 |
| Morgan Stanley uses evals to gate its GPT-4 assistant | OpenAI case study | 2024-01 |
| Walmart Element: an LLM-agnostic governed AI platform | Walmart Global Tech | 2024-03 |
| Moderna: from mChat to 750 governed GPTs | OpenAI case study | 2024-04 |
| Microsoft Responsible AI Standard v2 | Microsoft | 2022-06 |
| Purview DSPM for AI / Copilot governance | Microsoft Learn | 2026-08 |
| Entra Agent ID | Microsoft Learn | 2025-05 |
| Amazon Bedrock Guardrails (incl. Automated Reasoning checks) | AWS | 2025-08 |
| Amazon Bedrock AgentCore | AWS docs | 2025-10 |
| OpenAI Model Spec | OpenAI | 2025-02 |
| OpenAI enterprise privacy & security | OpenAI | 2026-08 |
| Claude's Constitution (published in full, CC0) | Anthropic | 2026-01 |
| Responsible Scaling Policy / ASL-3 activation | Anthropic | 2025-05 |
Journalism and case records backing the incidents and examples.