The pace of AI adoption has outrun the controls that govern it. Regulators have caught up, and they are now coordinating. The EU AI Act (as amended by the May 2026 Digital Omnibus), ISO 42001, NIST AI RMF, NYC Local Law 144, Colorado AI Act, Texas TRAIGA, California SB 53, DORA, NIS2, GDPR, the UK pro-innovation framework, Singapore's Model AI Governance, and sectoral model-risk regimes (SR 11-7, PRA SS1/23) now place unprecedented obligations on boards, model owners and data custodians. Incube helps organisations move from ad-hoc AI experimentation to governed, auditable, enterprise-grade deployment without slowing innovation.
A consolidated view of all 22 key dates across the EU AI Act (as amended by the May 2026 Digital Omnibus), DORA, GDPR, NIS2, the Cyber Resilience Act, ISO 42001, NIST AI RMF and US state-level laws (TRAIGA, California SB 53, Colorado). Sorted chronologically, sourced and ready for the risk register.
Nine high-risk categories. If your product touches any of these, as provider or deployer, the full obligations apply.
CV screening, candidate ranking, interview scoring, sourcing.
Performance evaluation, monitoring, promotion, termination.
Admissions, exam grading, learner placement and progression.
Scoring, access to essential financial services, eligibility.
Life and health risk assessment, premium pricing decisions.
Eligibility decisions for state benefits and essential services.
Identification, categorisation, emotion and affect recognition.
Safety components in transport, utilities, communications.
Migration, asylum, border control, justice administration.
A phased path, deliverable in 12-20 weeks depending on portfolio complexity. Expert network embedded throughout.
AI inventory across business. Map every system, every supplier.
Risk-classify each system against Annex III. Provider or deployer.
Article 11 technical files, datasheets, intended-purpose records.
Risk management, human oversight, transparency, post-market plan.
Conformity assessment, EU database, ongoing drift & incident control.
Four governance pillars, each with named deliverables. How each is built is our craft, shared at proposal rather than published as a manual. Network specialists embedded for the duration.
Cross-regime alignment: EU AI Act, ISO 42001, NIST AI RMF, US state-level laws (TRAIGA, California SB 53, Colorado), UK pro-innovation framework, Singapore Model AI Governance and sectoral model-risk regimes, all mapped to your risk profile and the revised timeline.
Bias auditing, explainability, human oversight, and fairness testing baked into the model lifecycle, covering both EU and US obligations.
Model inventory, validation, monitoring, drift detection and control frameworks aligned to SR 11-7 and PRA SS1/23.
Lineage, quality, privacy, consent, stewardship and lifecycle controls, from data foundation up to AI use case. Aligned across the EU digital stack: GDPR, NIS2, Data Act, Cyber Resilience Act.
A framework-by-framework reference. EU AI Act, GDPR, DORA, NIS2, EU Data Act, ISO 42001, NIST AI RMF, NYC Local Law 144, Colorado AI Act, Texas TRAIGA, California SB 53, UK pro-innovation framework, Singapore MGF, SR 11-7 and PRA SS1/23, each with jurisdiction, status, next milestone and what it means in practice. Mapped to a single control set, so one body of evidence carries across regulators.
The May 2026 Digital Omnibus moved the high-risk deadlines, but the standards work, conformity evidence and operating-model build still need 12-18 months of runway. Tell us your sector, scope and current state. We come back within 48 hours with a tailored brief, a shortlisted bench, and a phased path to compliance.
Five questions. No data collected. Indicative only, not legal advice. For a definitive scoping, request a brief.
Being compliant and being able to prove you were compliant, two years later and under a disclosure order, to a court, a regulator, an underwriter or an acquirer, are different capabilities. The first is a programme. The second is an evidence discipline. Four forces have converged in 2026 to make that discipline urgent, and most AI estates cannot yet survive the scrutiny.
A nationwide US collective action over AI hiring tools is in discovery, with vendor and deployer liability both in play. Chatbot output, screening decisions and training data are already producing claims, and courts are ordering parties to explain their AI workflows.
The revised EU Product Liability Directive treats software and AI as products from December 2026, with court-ordered disclosure, rebuttable presumptions of defect, and damages extended to data loss and psychological harm. The defence is the evidence file.
Generative-AI exclusions entered standard liability wordings in January 2026. The emerging affirmative AI cover, written at Lloyd's and by reinsurer-backed programmes, is granted and priced on one thing: documented governance evidence.
EU AI Act high-risk obligations land December 2027 and August 2028; US state regimes are already in force. When the request-for-information arrives, the answer is not a policy; it is a producible record.
A gate pack is the set of documents a project brings to the meeting where it is allowed to spend the next tranche of budget. This is the one for AI initiatives.
Stage gates accept deliverables that meet a specification. AI produces a probability distribution. Six gates, thirteen evidence artefacts and three proportionate lanes, attached to the PRINCE2, MSP or PMI lifecycle you already have, producing your Annex IV and ISO 42001 evidence as a by-product of running delivery.
The practice advises; the products let you run the same operating system yourself. Start free, buy the depth you need.
Fifteen questions about one AI initiative, returning how much governance it actually earns. Free, on this site, no registration.
Run the triage →The forty-question defensibility assessment with a worked insurance case, licensed for team use.
The kit →Forty questions, scored on screen with a live gap list mapped to the documents that close each gap. Free, on this site, no registration.
Score yourself →Six gates, thirteen documents, three proportionate lanes for governing AI delivery. Licence from £1,950.
The product →The complete document set for an AI management system: twenty-seven templates, filled specimens, and the interactive Readiness Toolkit in the Professional tier. From £495.
The pack →The three-in-one toolkit, standards atlas and diagram pack from the book series. Free on registration.
Register →