EAAPLEnterprise AI Architecture Pattern Library
Live Intelligence Feed

Regulatory Change Engine

Tracks AI regulatory developments across jurisdictions and maps each change to the architectural gaps it creates — so you know exactly what to build next.

16
Changes Tracked
9
Frameworks
6
Jurisdictions
Approaching Deadlines
50dEU AI ActEU AI Act: High-Risk AI System Obligations Apply
Assess your gap →
Framework
Impact
Type

16 changes matching current filters

DEADLINE APPROACHING — 50 days remaining(2 Aug 2026)
2 Aug 2026EU AI Acthigh impactDeadlineEuropean Union

EU AI Act: High-Risk AI System Obligations Apply

From 2 August 2026, all high-risk AI systems listed in Annex III must comply with the full suite of obligations under Chapter III, Section 2, including conformity assessments, technical documentation, human oversight, and registration in the EU AI database.

What changed

High-risk AI systems in employment, credit, insurance underwriting, biometric identification, education, law enforcement, and critical infrastructure must have full compliance.

Architectural implication

Any AI system making or assisting decisions in Annex III categories must be architected with human override capability, immutable audit logging, and model performance monitoring from day one.

Affected domains
governanceobservabilityarchitecturesecurity

EU AI Act Article 6, Annex III. Applicability timeline per Article 113(c).

1 Apr 2026APRA CPS230/234high impactEnforcementAustralia

APRA Issues Supervisory Letters to 4 Entities for AI Governance Failures

APRA identified material AI governance failures at four regulated financial institutions during supervisory reviews and issued formal supervisory letters. This is the first material APRA AI-specific enforcement action.

What changed

Formal supervisory letters issued requiring remediation within defined timeframes. APRA made clear that CPS230 and CPS234 obligations extend to LLM-based and AI-assisted decision systems.

Architectural implication

Organisations subject to APRA oversight must have a centralised AI model register, a documented AI risk classification process, an approval workflow before AI deployment, and AI-specific incident response runbooks.

Affected domains
governance

APRA supervisory activity Q2 2026.

2 Aug 2025EU AI Acthigh impactDeadlineEuropean Union

EU AI Act: GPAI Model Obligations Apply

From 2 August 2025, all providers of General-Purpose AI (GPAI) models must comply with transparency, technical documentation, and copyright policy requirements under Articles 53-55.

What changed

GPAI providers must publish model training data summaries, maintain technical documentation, implement copyright compliance policies, and publish model capability evaluations.

Architectural implication

Enterprises building on top of GPAI models must assess whether their downstream use creates systemic risk. Data lineage documentation becomes a compliance requirement.

Affected domains
governancedata-compliance

EU AI Act Article 53-55. Applicability timeline per Article 113(b).

5 Sept 2024Privacy Actmedium impactGuidanceAustralia

Australia Voluntary AI Safety Standard Published

The Australian Government published a voluntary AI Safety Standard with ten guardrails for organisations deploying AI in high-risk settings. The standard signals the direction of future mandatory regulation.

What changed

Ten guardrails established: accountability structures, risk management, data governance, testing and evaluation, human oversight, transparency, security, monitoring, incident response, and safe use practices.

Architectural implication

Organisations in government, financial services, and healthcare that deploy AI in high-risk settings should treat the ten guardrails as pre-regulatory baseline requirements.

Affected domains
governanceobservabilitysecurity

Australian Government, Voluntary AI Safety Standard, Department of Industry, Science and Resources, September 2024.

1 Aug 2024EU AI Acthigh impactRegulationEuropean Union

EU AI Act Enters into Force

The EU Artificial Intelligence Act was published in the Official Journal and entered into force on 1 August 2024. It is the world's first comprehensive legal framework for AI, establishing risk-based obligations across four tiers.

What changed

Legal framework created. Full compliance timeline activated. 12-month clock for GPAI model obligations began. 24-month clock for high-risk AI system obligations began.

Architectural implication

All AI systems serving EU users must now be classified by risk tier. High-risk systems require conformity assessments, human oversight mechanisms, technical documentation, and logging.

Affected domains
governancesecuritydata-complianceobservabilityarchitecture

Official Journal of the European Union, Regulation (EU) 2024/1689, 12 July 2024.

26 July 2024NIST AI RMFmedium impactGuidanceUnited States

NIST Generative AI Risk Profile Published

NIST published the Generative AI Profile (NIST AI 600-1) as a companion to the AI RMF, addressing risks unique to GenAI systems including hallucination, confabulation, data privacy, and CBRN information risks.

What changed

Introduced 12 GenAI-specific risks including confabulation, data privacy violations, obscene content generation, information hazards, intellectual property issues, and data poisoning.

Architectural implication

Organisations deploying LLMs in regulated contexts must now address hallucination detection, output filtering, prompt injection defence, and PII leakage prevention as explicit risk categories.

Affected domains
securityobservabilityarchitecture

NIST AI 600-1, July 2024.

18 Dec 2023ISO/IEC 42001high impactStandardInternational

ISO/IEC 42001:2023 AI Management System Standard Published

ISO/IEC 42001:2023 establishes requirements for an AI management system (AIMS) — the first internationally recognised management system standard specifically for AI.

What changed

New international standard creates certification pathway for AI governance. Annex A contains 38 controls spanning AI policy, resources, impact assessments, system design, data use, and third-party AI.

Architectural implication

Organisations pursuing ISO 42001 certification must document AI objectives, maintain an AI register, conduct impact assessments for high-risk applications, implement controls for responsible AI.

Affected domains
governancedata-complianceobservability

ISO/IEC 42001:2023, published by ISO December 2023.

30 Oct 2023ISO/IEC 42001medium impactGuidanceInternational

G7 Hiroshima AI Code of Conduct for Advanced AI

The G7 Hiroshima AI Process produced an International Code of Conduct for Advanced AI Systems signed by G7 nations. The 11-point code covers risk identification, incident reporting, information sharing, and transparency obligations.

What changed

Eleven international obligations for advanced AI: risk identification and mitigation, incident tracking and reporting, information sharing with governments, responsible capability disclosure, data input transparency.

Architectural implication

Organisations deploying foundation models in G7 markets should align their governance architecture with the 11 points as a geopolitical baseline.

Affected domains
governanceobservability

G7 International Code of Conduct for Advanced AI Systems, Hiroshima AI Process, October 2023.

30 Oct 2023NIST AI RMFhigh impactRegulationUnited States

US Executive Order on Safe, Secure, and Trustworthy AI

President Biden's Executive Order on AI directed federal agencies to establish AI safety standards, required frontier model providers to report safety test results to the government, and tasked NIST with developing red-teaming guidance.

What changed

Dual-use foundation model providers must notify the US government of training runs above compute thresholds and share red-team results. Federal agencies must appoint Chief AI Officers and complete AI use-case inventories.

Architectural implication

Organisations operating frontier models in US market must have red-teaming pipelines, safety evaluation infrastructure, and reporting capability. Federal contractors must document AI use cases.

Affected domains
governancesecurity

Executive Order 14110, Federal Register, October 2023.

1 July 2023APRA CPS230high impactRegulationAustralia

APRA CPS 230 Operational Risk — AI Systems as Critical Operations

The new APRA CPS 230 standard (effective July 2024) explicitly includes AI-driven processes within the definition of critical operations. AI systems that materially affect financial outcomes, customer decisions, or regulatory reporting require operational resilience controls.

What changed

AI systems performing credit decisioning, fraud detection, or customer communication now require documented tolerance levels, tested failover procedures, supplier concentration risk assessment, and 72-hour notification to APRA for material AI incidents.

Architectural implication

AI systems must be designed with recovery time objectives, rollback capability, and human fallback procedures. An AI model that goes into degraded accuracy is a CPS 230 event.

Affected domains
governanceobservabilityarchitecture

APRA Prudential Standard CPS 230 Operational Risk Management, effective 1 July 2024.

20 Mar 2023GDPRhigh impactEnforcementEuropean Union

CJEU Ruling: GDPR Article 22 Applies to AI-Assisted Decisions

The Court of Justice of the EU clarified that GDPR Article 22 applies when an AI system contributes materially to a human decision. Human 'rubber-stamping' of AI recommendations does not exempt an organisation from Article 22 obligations.

What changed

The threshold for Article 22 compliance is lower than previously interpreted. Any AI system where human review is perfunctory is now in scope. Meaningful human oversight must be documented and evidenced.

Architectural implication

Human-in-the-loop implementations must demonstrate genuine decision authority. Audit logs must capture evidence that human reviewers had access to model reasoning and exercised independent judgement.

Affected domains
governancearchitecture

CJEU Case C-634/21, SCHUFA Holding, judgment 7 December 2023.

15 Mar 2023GDPRmedium impactGuidanceUnited Kingdom

UK ICO Guidance on AI and Data Protection

The UK ICO published updated guidance on AI and data protection, clarifying obligations when using personal data to train, test, and deploy AI systems. The guidance addresses lawful basis for AI training, data minimisation, automated decision-making transparency, and fairness requirements.

What changed

Explicit ICO position: organisations must complete a DPIA before training AI on personal data. Models trained on personal data retain it and may need to be 'forgotten'. Automated decisions require explanation capability.

Architectural implication

AI systems processing personal data must have documented lawful basis, purpose limitation, and data minimisation built into the architecture. The 'right to erasure' may require model retraining capability.

Affected domains
data-compliancegovernance

ICO Guidance on AI and Data Protection, ico.org.uk, March 2023.

26 Jan 2023NIST AI RMFhigh impactStandardUnited States

NIST AI Risk Management Framework 1.0 Released

NIST released the AI Risk Management Framework (AI RMF 1.0) as a voluntary framework for managing AI risks across the full lifecycle. It organises AI risk management around four core functions: GOVERN, MAP, MEASURE, and MANAGE.

What changed

Established the GOVERN-MAP-MEASURE-MANAGE framework as the dominant US framework for AI risk. AI RMF Playbook provides 100+ suggested actions.

Architectural implication

The MEASURE function requires quantitative metrics for AI system trustworthiness. The MANAGE function requires incident response processes.

Affected domains
governanceobservability

NIST AI RMF 1.0, NIST AI 100-1, January 2023.

1 July 2022APRA CPS234high impactGuidanceAustralia

APRA CPS 234 Third-Party Guidance Letter — AI Vendors Included

APRA issued guidance clarifying that AI model providers and LLM vendors are in-scope third-party service providers under CPS 234. Financial institutions using OpenAI, AWS Bedrock, Azure OpenAI, or similar services must apply the full third-party risk management framework.

What changed

AI/ML vendors explicitly in scope for CPS 234 third-party risk. APRA expects vendor security assessments before onboarding, contractual data protection clauses, data residency documentation, breach notification terms, and ongoing monitoring.

Architectural implication

Any AI API call leaving the organisation's perimeter is now a CPS 234 event. Organisations must log what data leaves, to which vendor, under what contractual protection.

Affected domains
securitydata-compliancegovernance

APRA Prudential Practice Guide CPG 234. APRA's third-party guidance letters 2022.

3 Nov 2021Privacy Acthigh impactEnforcementAustralia

OAIC Orders Clearview AI to Destroy Australian Data

The OAIC found Clearview AI breached the Australian Privacy Act by collecting facial images from the web without consent and creating a biometric database used by law enforcement. The OAIC ordered Clearview to stop collecting facial images of Australians and destroy all data.

What changed

Established that web scraping to train AI models constitutes collection of personal information under the Privacy Act. Processing biometric data without a lawful basis breaches APP 3.

Architectural implication

AI training pipelines scraping public web data may breach Privacy Act obligations if the data contains identifiable information. Privacy impact assessments must precede training data collection.

Affected domains
data-compliancegovernance

OAIC determination, Commissioner initiated investigation into Clearview AI Inc, November 2021.

6 Nov 2018MAS FEATmedium impactGuidanceSingapore

MAS FEAT Principles for Responsible AI in Financial Services

The Monetary Authority of Singapore published the FEAT Principles — Fairness, Ethics, Accountability, Transparency — as the cornerstone guidance for responsible use of AI in financial services.

What changed

Established four principles: Fairness (no prohibited discrimination), Ethics (aligned with customer interests), Accountability (human accountability for AI decisions), Transparency (explainable to customers).

Architectural implication

Explainability is a first-class architectural requirement, not a post-hoc addition. Models used in customer-facing decisions must generate human-readable explanations.

Affected domains
governanceobservability

MAS FEAT Principles for Responsible Use of AI and Data Analytics, November 2018.

Delta Computation

Compute your regulatory delta

Connect this engine to your assessment results to see which regulatory changes create new architectural gaps for your organisation — and which patterns close them.

Run your assessment →Australian market signals → AEAI ↗