AI compliance is the operational practice of meeting the external and internal obligations governing an organization's use of AI systems. It covers inventory and accountability, risk assessment, transparency and documentation, model evaluation, incident reporting, and ongoing monitoring against named frameworks and statutes.
- Meeting the external and internal obligations that govern AI use
- Spans inventory, risk assessment, documentation, and incident reporting
- Measured against the EU AI Act, NIST AI RMF, ISO 42001, and state statutes
- Document templates alone fail an audit that asks for request-level evidence
Why is AI compliance important?
AI compliance matters because it is the conversation a CISO has with the audit committee, and increasingly with a regulator. It is also the one AI discipline where an external party defines the standard and tests your answer against it.
The regulatory picture is phased rather than binary. Enforcement of the EU AI Act began in February 2025 with the Article 5 prohibitions on unacceptable-risk systems, with broader obligations taking effect on the timeline set out in Article 113. United States state-level rules are following, including the Colorado AI Act, which scopes consumer-protection obligations for developers and deployers of high-risk AI systems.
The practical failure is predictable. A compliance program built on document templates satisfies an internal review and then does not survive the first audit that asks for evidence at the agent and request level: which system took this action, what authorization applied, and what control evaluated it. Producing that requires instrumentation, not a policy library.
What is AI compliance?
AI compliance is the operational work of demonstrating that AI use inside an organization meets the obligations that apply to it. Those obligations arrive from four directions, and the practice has to satisfy all of them from one body of evidence.
Six activities make up the discipline. Inventory and accountability establish which AI systems exist and who owns each. Risk assessment classifies systems by the harm they could cause, which determines what else applies. Transparency and documentation produce the artifacts a reviewer asks for. Model evaluation tests systems against defined criteria before and during deployment. Incident reporting handles disclosure obligations when something goes wrong. Ongoing monitoring keeps all of it current.
Compliance is distinct from governance, though the two are often conflated. Governance is the internal program deciding what your AI systems may do. Compliance is conformance to an external standard. Governance done well produces most of the evidence compliance requires, which is why the sequence matters.
Types of AI compliance
Obligations divide by where they originate, and the distinction determines who enforces them and what evidence satisfies them.
Regulatory obligations come from law: the EU AI Act, state statutes such as the Colorado AI Act, and sector rules in regulated industries including finance and healthcare. These carry penalties and are enforced by an authority. Standards-based obligations come from frameworks an organization adopts voluntarily or contractually – ISO/IEC 42001 for AI management systems, the NIST AI Risk Management Framework for risk practice. These are certifiable or attestable rather than enforced.
Contractual obligations arrive through customer agreements and vendor terms, and they increasingly specify AI-related controls directly. Internal policy obligations are self-imposed and are usually the strictest, because they cover the risks a regulator has not reached yet.
Most enterprises are subject to all four at once, which is why mapped reporting matters more than any single certification.
AI compliance & Onyx
Onyx produces mapped reporting across major frameworks including the EU AI Act, NIST AI RMF, the OWASP Top 10 for LLM Applications, MITRE ATLAS, and ISO/IEC 42001, so one body of evidence answers several regimes rather than each being assembled separately.
The underlying approach is continuous posture management with periodic re-baselining rather than one-off scans, which matters because compliance is a statement about an ongoing condition rather than a moment. Because AI Governance records every policy decision against the agent identity that triggered it, the request-level evidence an auditor asks for is a query rather than a reconstruction.

