AI regulation is coming for organisations, not just the labs

Most of the noise about AI regulation is about the frontier labs. Who tests the big models, who can pause them, who carries the liability. That matters, but it misses the part that reaches the rest of us sooner. The same week in July gave us two proposals that show where this is actually heading, and it is heading toward the organisations that use AI, not just the ones that build it.
On 14 July 2026, HM Treasury (UK) published its Financial Services AI Adoption Plan, written by the government’s AI Champions for the sector, Harriet Rees of Starling and Dr Rohit Dhawan of Lloyds. Ten recommendations. The one worth reading twice is a voluntary, industry-led assurance scheme where an independent assessor certifies an AI system against agreed standards, so a firm can trust a certificate rather than run its own checks from scratch every time. In practice, that looks a lot like ISO 42001. The plan is explicit that the scheme could start voluntarily and later be adopted by a central body, with regulators choosing to fold it into supervision.
Two proposals, one playbook
The same day, Demis Hassabis (Google’s DeepMind) published his own framework for frontier AI. His model is a standards body built on FINRA, the private watchdog that polices Wall Street under government oversight. Labs would share models for testing up to 30 days before release. Voluntary at first, and once the process proves itself, mandatory for deployment in the US market.
Two proposals, same week, same idea. Take the playbook that already governs financial services and point it at AI. The tell in both is the word voluntary. Nobody drafting these schemes means voluntary forever. They mean voluntary until it proves itself, and then it becomes the baseline everyone is measured against.
What this actually means in practice
Here’s where it stops being abstract, most organisations are already running AI, they just have not written it down. Someone in finance is pasting figures into ChatGPT to summarise them. A sales rep is running customer notes through a model to draft follow-ups. An engineer is putting source code into an assistant to debug it. None of it is logged, none of it is governed, and much of it is going into personal accounts the organisation cannot see.
That’s the real exposure. Not the frontier lab a continent away, but the employee uploading a client contract into a free tool that trains on the input. When a regulator, an auditor or your biggest customer asks who is using AI here, on what, and with what data, most organisations cannot answer. That gap is what every one of these frameworks is built to close.
A guardrail does not have to be heavy. It is knowing which tools are approved, what data can go into them, where the outputs land, and who is accountable when something goes wrong. Whether your people use Claude, GPT, Gemini or an open source model running in-house, the requirement is the same. Show that AI is used deliberately, not by accident.
This pattern is now global
The UK and US are not alone. In January 2026, Singapore launched its Model AI Governance Framework for Agentic AI, the first framework of its kind aimed at autonomous systems, building on the governance foundations it laid for generative AI. Japan brought its AI Promotion Act into full force in September 2025, a lighter-touch model built on transparency and safety baselines rather than hard prohibitions and penalties. South Korea’s AI Basic Act came into force on 22 January 2026, joining the EU as one of the first comprehensive AI laws in the world, with mandatory transparency and safety duties on high-impact systems and extraterritorial reach.
The Gulf is moving too. In the UAE, the DIFC’s Regulation 10 reached full enforcement in January 2026, imposing specific duties on organisations that deploy autonomous or semi-autonomous systems processing personal data, including certification and an appointed Autonomous Systems Officer for high-risk processing. Saudi Arabia declared 2026 its Year of Artificial Intelligence, and its Data and AI Authority released an AI Adoption Framework that sets a mandatory governance baseline for public sector entities, with data governance, model accountability and human oversight at its core.
And ISO 42001, the international standard for AI management systems, has become the common denominator across all of it. It is being adopted or mapped in jurisdiction after jurisdiction, and in procurement it is shifting from a nice to have into a requirement.
Australia shows the direction
Australia is the instructive case, because it went the other way. The federal government pulled back from mandatory guardrails in the National AI Plan released in December 2025, choosing to rely on existing laws and voluntary guidance for now, supported by a new AI Safety Institute with an advisory role rather than enforcement powers.
But that is not the whole picture. In its April 2026 response to the Senate Select Committee, the government accepted the principle of mandatory guardrails for high-risk AI, committing to further consultation on how to implement them. And it has already made AI requirements mandatory for its own Commonwealth agencies. For anyone reading the direction of travel, not yet is not the same as not coming.
What we’re seeing organisations do
The organisations getting ahead of this are not waiting for the mandate. They are doing the unglamorous work now. Writing down which AI tools are sanctioned. Setting a policy on what data can and cannot go into a model. Giving employees an approved way to use AI so they stop reaching for the unapproved one. Getting certified against ISO 42001 while it is still a choice rather than a scramble.
The ones who wait tend to find out the hard way, when a customer’s procurement team sends a questionnaire asking how AI is governed, or a regulator asks for evidence, and there is nothing to show. By then the head start is gone.
Why adopt the standard now
Here is what all of it adds up to. Regulators across four continents are converging on the same model: voluntary assurance schemes, graduated by risk, hardening into mandatory ones. The certification most of these schemes will lean on already exists, and it is ISO 42001. The organisations adopting it now are not being early for the sake of it. They are getting certified while it is still a choice, before an auditor, a regulator or a customer in any of these jurisdictions asks them to prove it.
This is the part we care about at Vissibl. Knowing the regulation is coming is not the same as being ready for it. We track these shifts as they happen, across every jurisdiction our customers operate in, and we turn the standard into something an organisation can actually run rather than a document that sits in a drawer. Seeing round the corner is only useful if someone helps you act on it before it arrives.
Compliance frameworks rarely arrive as a surprise. They arrive as a voluntary scheme first, and by the time they are mandatory the head start is gone. If you are running AI in a regulated setting, the real question is not whether this reaches you or when. It is whether you would rather adopt the standard on your own timeline or on someone else’s.
Sources and further reading
UK Financial Services AI Adoption Plan: https://www.gov.uk/government/publications/ai-adoption-plan-financial-services
Singapore Model AI Governance Framework for Agentic AI: https://www.imda.gov.sg/resources/press-releases-factsheets-and-speeches/press-releases/2026/new-model-ai-governance-framework-for-agentic-ai
Japan AI Promotion Act: https://oecd.ai/en/dashboards/policy-initiatives/act-on-promotion-of-research,-development,-and-utilization-of-artificial-intelligence-related-technologies
South Korea AI Basic Act: https://www.loc.gov/item/global-legal-monitor/2026-02-20/south-korea-comprehensive-ai-legal-framework-takes-effect
UAE DIFC Regulation 10: https://www.difc.com/business/registrars-and-commissioners/commissioner-of-data-protection/regulation-10
Saudi Arabia SDAIA AI Adoption Framework: https://sdaia.gov.sa/en/SDAIA/about/Files/AIAdoptionFramework.pdf
EU AI Act: https://artificialintelligenceact.eu
ISO 42001: https://www.iso.org/standard/42001
Australian National AI Plan: https://www.industry.gov.au