<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/ai-governance-11-laws-frameworks-and-assurance-schemes-and-3-jobs-they-serve--enkpdmse3" -->

---
title: AI governance: 11 laws, frameworks, and assurance...
description: The EU AI Act&#x27;s Digital Omnibus (Regulation 2026/1744, in force July 27, 2026) deferred high-risk system duties under Chapter III to December 2, 2027 for...
canonical: https://daily.dev/posts/ai-governance-11-laws-frameworks-and-assurance-schemes-and-3-jobs-they-serve--enkpdmse3
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: AI governance: 11 laws, frameworks, and assurance schemes—and 3 jobs they serve. | daily.dev
og:description: The EU AI Act&#x27;s Digital Omnibus (Regulation 2026/1744, in force July 27, 2026) deferred high-risk system duties under Chapter III to December 2, 2027 for...
og:url: https://daily.dev/posts/ai-governance-11-laws-frameworks-and-assurance-schemes-and-3-jobs-they-serve--enkpdmse3
og:image: https://api.daily.dev/og/posts/eNKpDmSE3.png
og:image:alt: AI governance: 11 laws, frameworks, and assurance schemes—and 3 jobs they serve.
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# AI governance: 11 laws, frameworks, and assurance schemes—and 3 jobs they serve.

**[WunderGraph](https://daily.dev/sources/wundergraph)** · 24 min read · 0 upvotes · 0 comments

## Summary

The EU AI Act's Digital Omnibus (Regulation 2026/1744, in force July 27, 2026) deferred high-risk system duties under Chapter III to December 2, 2027 for standalone systems and August 2, 2028 for embedded systems, but other obligations remain on schedule: AI literacy and Article 5 bans since February 2025, GPAI provider duties since August 2025, most Article 50 transparency duties from August 2, 2026, and a ninth banned-practice category from December 2, 2026. The piece maps eleven overlapping laws, frameworks, and assurance schemes (EU AI Act, ISO 42001, NIST AI RMF, NIST AI 600-1, NIST COSAiS, OWASP LLM/Agentic Top 10, MITRE ATLAS, CSA AICM, AIUC-1, SOC 2) into three jobs — prove compliance, defend against attacks, and build systems — and stresses that ISO 42001 certification alone does not equal EU AI Act compliance, citing CSA's gap analysis around incident reporting, change management, and fundamental-rights assessments. It closes with a recommended starting sequence and notes how WunderGraph's Cosmo/Hub API governance tooling can contribute supporting evidence (audit logs, schema change approvals) without itself being an AI-governance product.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://wundergraph.com/blog/enterprise-ai-governance-frameworks>

## Questions this post answers

### Did the EU AI Act's Digital Omnibus delay all of the Act's deadlines?

No, only the Chapter III high-risk-system obligations were deferred. Standalone Annex III systems now apply from December 2, 2027, and Annex I systems embedded in regulated products from August 2, 2028. AI literacy and Article 5 bans have applied since February 2, 2025, GPAI provider duties since August 2, 2025, and most Article 50 transparency duties (chatbot disclosure, synthetic content marking, emotion recognition notices) still apply from August 2, 2026.

_Track fast-moving EU AI Act compliance deadlines on daily.dev so nothing slips past your team._

### Is ISO 42001 certification enough to be compliant with the EU AI Act?

No, ISO 42001 certification only shows an organization operates an AI management system; it is not a finding that every AI system it provides or deploys meets EU AI Act requirements. Gaps include no per-system regulatory mapping, no change management for continuous-learning systems under Article 17(1)(a), no Article 73 incident-reporting timetable, generic rather than AI-specific supply-chain provisions, and no Article 27 fundamental-rights impact assessment.

_Compare governance frameworks like ISO 42001 against regulatory requirements on daily.dev before committing to a compliance strategy._

### What is the deadline for reporting a serious AI incident under EU AI Act Article 73?

Providers of high-risk systems must report immediately after establishing a causal link, or a reasonable likelihood of one, and in any event within 15 days of becoming aware. That window shortens to two days for a widespread infringement or a serious incident involving critical infrastructure, and when a death is involved, the report is due immediately upon suspecting causation and no later than 10 days after becoming aware.

_Developers building high-risk AI systems can follow incident-reporting rule changes like this on daily.dev._

## Similar posts on daily.dev

- [What Does EU AI Act Compliance Require?](https://daily.dev/posts/what-does-eu-ai-act-compliance-require--fxpo6vqo8) · Docker · 0 upvotes · 0 comments
- [EU AI Act Guide 2025: AI Security and Compliance Rules](https://daily.dev/posts/eu-ai-act-guide-2025-ai-security-and-compliance-rules-xlytomopx) · Netguru · 0 upvotes · 0 comments
- [The 2026 Data Mandate: Is Your Governance Architecture a Fortress or a Liability?](https://daily.dev/posts/the-2026-data-mandate-is-your-governance-architecture-a-fortress-or-a-liability--cmdzgiroe) · Towards Data Science · 2 upvotes · 0 comments

---

Tags: [#compliance](https://daily.dev/tags/compliance), [#ai-governance](https://daily.dev/tags/ai-governance)

[View this post on daily.dev](https://daily.dev/posts/ai-governance-11-laws-frameworks-and-assurance-schemes-and-3-jobs-they-serve--enkpdmse3)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"AI governance: 11 laws, frameworks, and assurance schemes—and 3 jobs they serve.","url":"https://daily.dev/posts/ai-governance-11-laws-frameworks-and-assurance-schemes-and-3-jobs-they-serve--enkpdmse3","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/ai-governance-11-laws-frameworks-and-assurance-schemes-and-3-jobs-they-serve--enkpdmse3"},"datePublished":"2026-09-23T16:13:29.502Z","dateModified":"2026-09-23T16:13:57.393Z","description":"The EU AI Act's Digital Omnibus (Regulation 2026/1744, in force July 27, 2026) deferred high-risk system duties under Chapter III to December 2, 2027 for...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/67e9591915aaf95cf45e30482b51f6b2?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/67e9591915aaf95cf45e30482b51f6b2?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"WunderGraph","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"WunderGraph","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1681654408/logos/WunderGraphs","url":"https://daily.dev/sources/wundergraph"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/ai-governance-11-laws-frameworks-and-assurance-schemes-and-3-jobs-they-serve--enkpdmse3","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"compliance,ai-governance","timeRequired":"PT24M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"WunderGraph","item":"https://daily.dev/sources/wundergraph"},{"@type":"ListItem","position":3,"name":"AI governance: 11 laws, frameworks, and assurance schemes—and 3 jobs they serve."}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/ai-governance-11-laws-frameworks-and-assurance-schemes-and-3-jobs-they-serve--enkpdmse3#faq","mainEntity":[{"@type":"Question","name":"Did the EU AI Act's Digital Omnibus delay all of the Act's deadlines?","acceptedAnswer":{"@type":"Answer","text":"No, only the Chapter III high-risk-system obligations were deferred. Standalone Annex III systems now apply from December 2, 2027, and Annex I systems embedded in regulated products from August 2, 2028. AI literacy and Article 5 bans have applied since February 2, 2025, GPAI provider duties since August 2, 2025, and most Article 50 transparency duties (chatbot disclosure, synthetic content marking, emotion recognition notices) still apply from August 2, 2026. Track fast-moving EU AI Act compliance deadlines on daily.dev so nothing slips past your team."}},{"@type":"Question","name":"Is ISO 42001 certification enough to be compliant with the EU AI Act?","acceptedAnswer":{"@type":"Answer","text":"No, ISO 42001 certification only shows an organization operates an AI management system; it is not a finding that every AI system it provides or deploys meets EU AI Act requirements. Gaps include no per-system regulatory mapping, no change management for continuous-learning systems under Article 17(1)(a), no Article 73 incident-reporting timetable, generic rather than AI-specific supply-chain provisions, and no Article 27 fundamental-rights impact assessment. Compare governance frameworks like ISO 42001 against regulatory requirements on daily.dev before committing to a compliance strategy."}},{"@type":"Question","name":"What is the deadline for reporting a serious AI incident under EU AI Act Article 73?","acceptedAnswer":{"@type":"Answer","text":"Providers of high-risk systems must report immediately after establishing a causal link, or a reasonable likelihood of one, and in any event within 15 days of becoming aware. That window shortens to two days for a widespread infringement or a serious incident involving critical infrastructure, and when a death is involved, the report is due immediately upon suspecting causation and no later than 10 days after becoming aware. Developers building high-risk AI systems can follow incident-reporting rule changes like this on daily.dev."}}]}
```

