Navigating 2026 AI Risk Regulations
2026 AI regulation moved its hardest deadline and switched on its enforcement at the same time. The EU Digital Omnibus deferred high-risk AI obligations to December 2027 and August 2028, while general applicability, Article 50 transparency and general-purpose AI penalties took effect on 2 August 2026. Korea's AI Framework Act, four separate California regimes, Texas TRAIGA and Illinois HB 3773 are all already in force. This guide covers what applies where, and maps each obligation to the evidence it requires, which for agentic systems comes down to knowing what your agents can actually reach.

On 2 August 2026 the EU AI Act became generally applicable, and the part everyone had been preparing for did not arrive.
Five days earlier, Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force. It pushed the high-risk provider and deployer obligations in Chapter III to 2 December 2027 for Annex III standalone systems and 2 August 2028 for Annex I embedded-product systems. What did arrive on 2 August was everything else: Article 50 transparency duties, the full market surveillance apparatus, the notified body and conformity assessment machinery, the EU database, and the penalty regime, including AI Office enforcement of general-purpose AI with fines up to the higher of 15 million euro or 3 percent of worldwide annual turnover.
The deadline moved. The enforcement did not. That combination is the defining feature of AI regulation in 2026, and it is not unique to Europe.
The EU delayed the engineering work and switched on the enforcement
Regulation (EU) 2026/1744 was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It is binding law, not a proposal, and a lot of commentary written in May and June 2026 still describes it as pending. Recital 40 sets the new application dates for Chapter III Sections 1, 2 and 3 explicitly.
Article 15 is the clause AppSec teams should read. It requires high-risk systems to achieve appropriate levels of accuracy, robustness and cybersecurity and to perform consistently across the lifecycle. Article 15(5) names the AI-specific attack classes the technical solutions must prevent, detect, respond to, resolve and control for: data poisoning, model poisoning, adversarial examples and model evasion, confidentiality attacks, and model flaws. Accuracy metrics have to be declared in the instructions for use. Systems that keep learning after deployment must eliminate or reduce the risk of biased-output feedback loops.
Article 15 now sits behind the December 2027 and August 2028 dates. Do not read that as breathing room, for two reasons.
There is no shortcut available yet. No CEN-CENELEC JTC 21 deliverable has been cited in the Official Journal, so there is no Article 40 presumption of conformity. The standard for Article 15 cybersecurity, prEN 18282, was still at enquiry stage in mid-2026, and the extended standardisation request runs to 28 February 2027.
And the alternative route has an earlier deadline. CRA Article 12 deems a product with digital elements that is also a high-risk AI system compliant with AI Act Article 15 where it meets the essential cybersecurity requirements in CRA Annex I Part I, its processes meet Annex I Part II, and the achievement is demonstrated in the CRA declaration of conformity. The CRA applies in full on 11 December 2027, before the Annex I AI Act date. If you were planning to use the CRA bridge, your real deadline is the CRA's.
For general-purpose model providers, enforcement is already live. Article 53 obligations have applied since 2 August 2025. Article 55 applies to models presumed to carry systemic risk above 10^25 FLOP of cumulative training compute, and requires state-of-the-art evaluation including adversarial testing, serious incident reporting to the AI Office without undue delay, and adequate cybersecurity protection for the model and its physical infrastructure across the lifecycle, explicitly including model and weight theft. The GPAI Code of Practice, published 10 July 2025, operationalises this through a Safety and Security Framework and per-model Safety and Security Model Reports, with named risk categories that include cyber offence. The Commission page listed 21 signatories as of 31 July 2026.
One thing quietly disappeared: the AI Liability Directive was formally withdrawn in October 2025. Civil liability for AI now runs through the revised Product Liability Directive (EU) 2024/2853, transposition due 9 December 2026, which treats software including AI systems as a product.
The United States has enforcement activity without a federal statute
There is no federal AI statute and no statutory preemption of state AI law as of August 2026. The Senate stripped a proposed ten-year state moratorium by 99 to 1 in summer 2025, and preemption language was dropped from the FY2026 NDAA on 4 December 2025.
What exists is executive strategy. EO 14179 (23 January 2025) revoked EO 14110. America's AI Action Plan (July 2025) directed NIST and CAISI to establish AI incident response standards and told CISA to modify its cybersecurity playbooks to cover AI systems. EO 14365 (11 December 2025) created an AI Litigation Task Force and directed Commerce, the FCC and the FTC to act against state AI laws. It does not nullify any state law. The Task Force has taken one visible action: intervening in xAI's challenge to the Colorado AI Act, which produced a stipulated stay of enforcement on 27 April 2026.
Meanwhile the states legislated anyway. The rules that actually bind in 2026:
Colorado replaced its AI Act rather than defending it. SB 24-205 never took effect. It was delayed, stayed by the federal court order, then repealed and reenacted by SB 26-189, signed 14 May 2026. The new framework is notice and explanation rather than impact assessment: developers of covered automated decision-making technology used in consequential decisions must give deployers technical documentation covering intended uses, categories of training data and known limitations. Note a live discrepancy on timing. The legislature's bill page states 12 August 2026, while several law firm analyses put substantive duties at 1 January 2027. Check the enrolled text before planning against either.
Texas TRAIGA (HB 149) took effect 1 January 2026, intent-based rather than disparate-impact, with no impact assessments. The provision worth noting: TRAIGA gives an affirmative defence for substantial compliance with the NIST AI Risk Management Framework, combined with discovery through internal testing or a good-faith third-party audit. That is the only place in US AI law where a voluntary framework buys a codified defence.
California stacked four regimes. SB 53, in effect since 1 January 2026, requires large frontier developers to publish an annual framework covering catastrophic risk, governance and cybersecurity practices, plus critical safety incident reporting to Cal OES within 15 days, or 24 hours where there is imminent danger of death or serious injury. AB 2013 took effect the same day and requires a public training-data summary across twelve categories, retroactive to systems made public since January 2022, reaching fine-tuners and integrators rather than only foundation model labs. The CPPA's ADMT regulations became effective 1 January 2026, with compliance due 1 January 2027 for existing significant-decision uses. And the California AI Transparency Act became operative 2 August 2026, requiring providers above one million monthly users to embed latent provenance disclosure in generated content.
Illinois HB 3773 took effect 1 January 2026, prohibiting AI use in employment decisions that has a discriminatory effect. The Department of Human Rights proposed implementing rules in May 2026 and withdrew them on 2 June 2026, so the statutory obligations remain in force without rules. New York's RAISE Act follows on 1 January 2027, with 72 hour critical safety incident reporting to the Department of Financial Services, a materially tighter clock than California's fifteen days.
NIST's output is uneven. SP 800-218A, the SSDF community profile for generative AI and dual-use foundation models, has been final since July 2024 and remains the only US government secure-development profile for AI models, and NIST AI 100-2 E2025 on adversarial machine learning was finalised in March 2025. The AI RMF revision, the SP 800-53 control overlays for securing AI systems, and the Cybersecurity Framework Profile for AI were all still unfinished as of March 2026.
Asia Pacific is regulating AI operators and AI output
South Korea's AI Framework Act took effect 22 January 2026, the second comprehensive national AI statute after the EU's. It is extraterritorial, with a domestic representative required above any of three thresholds including one million average daily Korean users. High-impact AI operators owe a meaningful explanation of outcomes and training data, human oversight and a fundamental-rights impact assessment, and models above 10^26 FLOPs of cumulative training compute trigger a lifecycle risk management plan reported to MSIT. Fines are modest, and MSIT granted a one-year enforcement grace period running to roughly January 2027.
Japan's AI Promotion Act carries no direct penalties, with enforcement running through existing privacy, competition, IP and product safety law. China regulates output and training data rather than development process: labelling of AI-generated synthetic content has been mandatory since 1 September 2025, requiring both explicit user-perceivable labels and implicit labels embedded in file metadata, and three national standards covering data annotation and training datasets took effect 1 November 2025.
Singapore published the most directly useful engineering guidance in the region. The Model AI Governance Framework for Agentic AI, launched 22 January 2026, is voluntary, and its technical control set reads like an AppSec checklist: limit agent autonomy, tool access and data exposure, require human approval checkpoints for significant decisions, apply baseline testing and restrict access to authorised services across the agent lifecycle, and counter automation bias so agents do not take unauthorised environment-changing actions such as database writes or payments.
India notified IT Amendment Rules on synthetically generated information on 20 February 2026, requiring prominent labelling or embedded metadata on realistic AI-generated content, with safe harbour conditioned on compliance.
The security baselines converged, and they all ask what the agent can reach
While the statutes argued about scope, the technical guidance quietly agreed with itself. The consolidated view of where the risk sits across the stack is in our AI application security guide; what follows is the regulatory-facing subset.
The OWASP Top 10 for Agentic Applications was published 9 December 2025. Read the list as a requirements document rather than a taxonomy: agent goal hijack (ASI01), tool misuse and exploitation (ASI02), identity and privilege abuse (ASI03), agentic supply chain vulnerabilities including MCP servers (ASI04), unexpected code execution (ASI05), memory and context poisoning (ASI06), insecure inter-agent communication (ASI07), cascading failures (ASI08), human-agent trust exploitation (ASI09) and rogue agents (ASI10). A new OWASP GenAI LLM Top 10 2026 was released 3 August 2026 with mappings to NIST, MITRE ATLAS and CWE. The entry list differs from the 2025 version, so do not assume the LLM01 through LLM10 identifiers carry over. The OWASP Top 10 for LLM Applications remains the shared taxonomy reference.
Six national agencies published "Careful adoption of agentic AI services" on 30 April 2026: ASD's ACSC leading, with CISA, NSA, the Canadian Centre for Cyber Security, NCSC-NZ and NCSC-UK. It names five risk categories (privilege compromise, design flaws, behavioural misalignment, cascading failures, supply chain) and prescribes controls by lifecycle phase. The convergent recommendations across it, the NSA's May 2026 guidance on Model Context Protocol security, and Singapore's agentic framework are strikingly consistent:
- Per-agent cryptographic identity. Each agent as a distinct principal, not a shared service account.
- Short-lived scoped credentials rather than shared API keys, with least privilege scoped to specific resources.
- Tool allow-lists, with an explicit warning that two-way tool integrations let tools send arbitrary instructions back to the model.
- Signed manifest provenance for dynamically discovered tools and servers.
- Sandboxed execution and network segmentation isolating agent runtimes.
- Human approval gates on high-impact and irreversible actions.
- Logging that captures reasoning traces and tool-call sequences, not just requests.
Prompt injection is characterised in that guidance as the most pervasive and difficult-to-mitigate threat. The UK NCSC used its March 2026 RSA Conference appearance to argue that AI coding tools must be designed so they do not introduce or propagate vulnerabilities, alongside six principles for AI-assisted development that include applying automated audits to all code, human-written and machine-generated alike.
Every one of those controls has the same prerequisite. You cannot scope an allow-list, assign a per-agent identity, or apply an approval gate to an agent you do not know exists.
The dates that already passed matter more than the one that moved
Read the section above as a calendar and the shape is clear. Everything that binds AI systems today arrived on schedule: Texas, California and Illinois on 1 January 2026, Korea on 22 January, the Singapore agentic framework the same week, the Five Eyes agentic guidance on 30 April, EU general applicability and the California AI Transparency Act on 2 August. The only thing that slipped is the one obligation that required real engineering, and it slipped into a window where no harmonised standard exists to build against. A dated calendar of every item, from October 2024 through August 2028, ships with the downloadable matrix.
Regulators are asking for an inventory nobody can produce from code
Strip the jurisdictional detail away and the 2026 rules ask four questions.
What AI is running in your applications? Every regime assumes an inventory. The EU AI Act's classification and registration duties, Korea's high-impact assessment, Colorado's developer documentation, and every customer security questionnaire all start there.
What can it reach, and what can reach it? Article 15(5) names data poisoning and confidentiality attacks. OWASP names goal hijack, tool misuse and excessive agency. The Five Eyes guidance names privilege compromise. These are all data-surface questions: what reaches the model, and where output can go.
Is it configured the way you said? Guardrails as loaded in the running process, not as claimed in a console. Model bindings checked against an approved list.
Can you prove any of it? Reporting clocks of 24 hours, 72 hours and 15 days do not accommodate a discovery phase.
The structural problem is that the three obvious places to look each miss the layer where the risk lives. Manifests and SCA see that langchain is a dependency. They cannot say whether an agent exists, what tools it can call, or which model it binds. Network and gateway inspection sees traffic to a model provider. It cannot see locally served models, in-memory delegation between agents, or a tool registry imported at runtime through MCP. Much of the agentic attack surface never appears as a packet. Code review and questionnaires capture intent, not reality: agents are wired dynamically, tool surfaces expand at runtime, and dormant capability is invisible to a point-in-time review.
A sub-agent wired into production that has never fired is invisible to anything watching activity, and it is exactly what an auditor is asking about. So the useful question is not what your code declares. It is what is loaded in the running process. That is where runtime intelligence applies to the AI layer, and it is the basis of agentic AI security that survives contact with an actual audit.
Mapping Kodem capabilities to the 2026 AI requirements
Two things to be precise about before the table. First, Kodem's AI Security pillar is pre-GA: AI Discovery, AI-BOM and the AI Risk issue type are emerging capabilities advancing through active development with design partners and are not yet generally available. Everything marked GA is generally available today. Second, agent-aware governance and enforcement, meaning per-agent policy and allow or deny decisions at a gateway, is product direction rather than current capability, and is deliberately not in the table below.
The complete matrix runs to sixteen columns including prerequisites, source verification and per-row notes, and is published as a downloadable workbook alongside this post.
| Regulation and clause | What it requires | Kodem capability and status | Evidence produced |
|---|---|---|---|
EU · AI Act (EU) 2024/1689 as amended by (EU) 2026/1744Art. 15(5) | Prevent, detect, respond to, resolve and control for data poisoning and model poisoning in high-risk AI systems 2 Dec 2027 / 2 Aug 2028 | AI Discovery (AI runtime discovery) (Pre-GA) Exploit-pattern detection (GA) | Which sources can reach the model, drawn from how the agent is actually wired in the running process |
EU · CRA (EU) 2024/2847 Art. 12 bridge to AI Act Art. 15Annex I Part I | Meet the essential cybersecurity requirements for products with digital elements 11 Dec 2027 | Kodem Code (SAST, SCA, IaC, Secrets) (GA) | Component and code-level findings on the shipped artifact, which is the substance behind the declaration of conformity |
EU · CRA (EU) 2024/2847 Art. 12 bridge to AI Act Art. 15Annex I Part II | Manufacturer processes meeting the essential requirements on vulnerability handling 11 Dec 2027 | Governance policies (SCM and CI) (GA) | Enforced gates and fix verification, evidenced end to end for the conformity file |
EU · AI Act (EU) 2024/1689Art. 55(1)(d) | Adequate cybersecurity protection for the model and its physical infrastructure, including model and weight theft 2 Aug 2025, enforced from 2 Aug 2026 | AI Discovery (AI runtime discovery) (Pre-GA) Secret scanning (GA) Container image malware detection (GA) | Local model files confirmed loaded in memory with format, parameters, quantization, license and digest, which network and gateway tools cannot see |
EU · AI Act (EU) 2024/1689Art. 53 and Annex XI / XII | Technical documentation and downstream provider information for general-purpose AI models 2 Aug 2025 | AI-BOM / AI-RBOM (Pre-GA) | Package-level AI bill of materials covering frameworks, SDKs and model files, narrowed to what is confirmed loaded or executing |
US Colorado · SB 26-189 Automated Decision-Making TechnologyDeveloper duties | Give deployers technical documentation covering intended uses, categories of training data and known limitations (citation needs re-check) 12 Aug 2026 or 1 Jan 2027 | AI-BOM / AI-RBOM (Pre-GA) | AI components correlated back to the repo and image they ship from, which answers the ownership and scope half of the documentation duty |
South Korea · AI Framework ActHigh-impact AI duties | Assess whether a system is high-impact and maintain a lifecycle risk management plan 22 Jan 2026 | AI Discovery (AI runtime discovery) (Pre-GA) AI Risk (Triage issue type) (Pre-GA) | Inventory of agents, workflows, tools, MCP servers, models and guardrails per application, reconstructed from runtime evidence |
Global · OWASP Top 10 for Agentic Applications 2026ASI01 Agent Goal Hijack | Know which untrusted content can reach the model and redirect the agent's objective 9 Dec 2025 | AI Discovery (AI runtime discovery) (Pre-GA) | Reachable paths from untrusted sources to the model, surfaced as an AI Risk issue mapped to LLM01 prompt injection |
Global · OWASP Top 10 for Agentic Applications 2026ASI06 Memory and Context Poisoning | Identify data that the agent later treats as its own knowledge 9 Dec 2025 | AI Discovery (AI runtime discovery) (Pre-GA) | The set of sources feeding model context, including file reads and tool outputs that never appear as network traffic |
Global · OWASP Top 10 for Agentic Applications 2026ASI02 Tool Misuse and Exploitation | Maintain an accurate picture of what each agent can invoke 9 Dec 2025 | AI Discovery (AI runtime discovery) (Pre-GA) | The function or endpoint behind each tool and its trust origin: framework, application code, or arrived over a runtime MCP connection |
Global · OWASP Top 10 for Agentic Applications 2026ASI03 Identity and Privilege Abuse | Understand which credentials and capabilities an agent inherits 9 Dec 2025 | AI Discovery (AI runtime discovery) (Pre-GA) | Which agent binds which model and which tools, including sub-agents and delegation, reconstructed from process memory |
Global · OWASP Top 10 for Agentic Applications 2026ASI04 Agentic Supply Chain | Continuous risk assessment of agent frameworks, connectors and runtime-integrated components 9 Dec 2025 | Malicious-package detection (GA) | Typosquat, dependency confusion and compromised package detection across the agent framework supply chain |
Twelve clauses are shown here. The full matrix covers 31 mapped obligations with sixteen columns, including prerequisites, capability detail, source verification and per-row notes.
The pattern is the same as it is in the rest of AppSec. The regulations ask what is real. Declarations answer what was intended. Reading the running process is what closes that gap, and it is why runtime AI security is a different question from scanning an AI framework's manifest. For the incident-reporting rows, the detection signal comes from the same place: application detection and response inside the workload, not a perimeter alert.
What actually changes engineering work this quarter
Provenance metadata is a shipping requirement on overlapping clocks. EU Article 50(2) applies from 2 August 2026, with 2 December 2026 for systems already on the market. California's latent disclosure applies now above one million users. China has required implicit metadata labels since September 2025, India since February 2026. One C2PA-class implementation satisfies most of it. Doing it five times will not.
Training data provenance became a disclosure artifact. AB 2013's twelve categories are retroactive to January 2022 and reach fine-tuners and integrators, the EU requires a training-content summary on the AI Office template, and Colorado requires developers to hand deployers the categories of training data. If nobody owns this, it lands on the team that shipped the model.
Do not de-prioritise Article 15 work because the date moved. No harmonised standard carries an OJ citation, so no presumption of conformity is available, and the CRA bridge has an earlier deadline than the AI Act obligation it satisfies.
Start the agent inventory now. Every control in the Five Eyes guidance, the Singapore framework and the OWASP agentic list presupposes it, and it is the item that takes longest, because the answer is not in a repository.
The first wave of AI regulation asked organisations to describe their AI governance. The 2026 wave asks them to enumerate their AI systems and prove what those systems can reach. That is a hard question to answer from a questionnaire and a much easier one to answer from the running process. The teams that handle 2027 comfortably will be the ones that stop asking what their AI is supposed to do and start reading what it actually loaded.
Related blogs

The Hidden Security Cost of Self-Hosting Kimi, DeepSeek, and Qwen
Open-weight models cut inference costs by 60 to 90 percent. They also turn AI into infrastructure the security team has to discover, secure, and continuously verify.
12
Stop the waste.
Protect your environment with Kodem.
The State of the Application Security Workflow
This report aims to equip readers with actionable insights that can help future-proof their security programs. Kodem, the publisher of this report, purpose built a platform that bridges these gaps by unifying shift-left strategies with runtime monitoring and protection.
.avif)
Get real-time insights across the full stack…code, containers, OS, and memory
Watch how Kodem’s runtime security platform detects and blocks attacks before they cause damage. No guesswork. Just precise, automated protection.



