Curated for practitioners in regulated industries. No hype, no noise — just what's moving the field forward and what it means for production AI governance.
This week in AI governance
Week of September 28, 2026California Governor Gavin Newsom vetoed SB 1047 on September 29, rejecting one of the most ambitious state-level AI regulatory frameworks attempted in the U.S. — but immediately issued a directive requiring every state agency to produce its own AI safety plan. The veto removes the statewide compliance mandate for AI developers, while the directive signals that governance expectations for public-sector AI are only tightening. For enterprises with California government contracts, the practical effect is the same: document your AI risk posture or lose access.
CalMatters ↗Governor Pritzker signed Illinois SB 315, the Artificial Intelligence Safety Measures Act, into law on July 6 — the first U.S. state law to mandate annual third-party audits of large AI developers. Companies with more than $500M in annual revenue that train models using more than 10^26 compute operations must disclose safety policies for catastrophic risks and submit to independent verification. The law takes effect January 1, 2027, with compliance obligations beginning January 1, 2028. It is likely to affect OpenAI, Anthropic, Google, Meta, and xAI directly.
Capitol News Illinois ↗The FDA accepted four generative AI-enabled medical devices — including products from Cadence and Limbic — into its TEMPO pilot, a program allowing digital health companies to deploy devices in real-world clinical settings before receiving marketing authorization. The pilot gives FDA direct observational data on how foundation models perform in clinical practice, while giving manufacturers a regulated pathway to validate performance with actual patients. For health tech teams, TEMPO is the clearest signal yet that FDA expects AI governance to be built into the development process, not applied at submission.
STAT News ↗NIST released Special Publication 1353 (initial public draft) on August 19 — a Quick-Start Guide showing organizations how to use AI systems to perform CSF 2.0 gap analysis and generate compliance reporting. The draft is open for public comment through October 15, 2026, under docket NIST-2026-SP1353. For regulated institutions already using AI internally, this publication signals that NIST expects AI-assisted governance tooling to meet the same rigor as the underlying framework — meaning the AI doing compliance work also needs to be governed.
NIST CSRC ↗aiApas insights
September 28, 2026Newsom vetoed SB 1047 this week, and commentators called it a win for innovation. The Illinois frontier AI law is live, and commentators called it a landmark. Both things can be true and still miss the point: enterprises operating across state lines are now managing a patchwork of obligations with no federal floor to stand on. California has 30 AI bills in flight with a Sept 30 governor deadline. Illinois kicks in January 2027. More states are filing every session.
The governance risk here is not regulatory overreach. It is fragmentation without harmonization. An organization that builds its AI governance program around one state's requirements will be out of compliance in another. What is needed — and what most organizations do not yet have — is a jurisdiction-agnostic governance layer: documented risk assessments, audit-ready model inventories, and human oversight records that satisfy any framework. Build that once. Map it to each state's requirements as they arrive. The alternative is rebuilding it every time a governor signs something new.
Full piece on The Deployment Layer ↗The 2026 International AI Safety Report's most cited finding is not about catastrophic AI scenarios — it's a quieter claim: the biggest enterprise AI risks come from complex systems built around models, not from the models themselves. What happens after the model answers? If the answer triggers a business process, updates a record, sends a notification, or informs a decision — that downstream chain is where governance actually needs to live.
Most AI governance frameworks still center on model evaluation: accuracy, bias, explainability. Those are necessary. But they're insufficient for production systems where the model is one node in a larger workflow. Our practice treats the model-plus-system boundary as the primary governance surface — what can the model trigger, who approves irreversible actions, and what does the audit trail cover across the full chain, not just the inference.
Full piece on The Deployment Layer ↗Client impact
Updated monthly — August 2026Reduction in fraud losses after deploying a governed AML model with continuous monitoring, documented decision logic, and automated suspicious-activity reporting workflows.
Improvement in delivery timeline for a production LLM deployment — driven by governance-first architecture that reduced late-stage compliance rework and eliminated one full review cycle.
Gain in data workflow efficiency after restructuring AML and LLM Ops pipelines — documentation, validation, and monitoring unified into a single governed architecture.
The Deployment Layer — weekly enterprise AI architecture for practitioners in regulated industries. Free, always.