Scrutineer · By framework
AI governance tools, platform and software for ISO 42001
Two of the AI deadlines most US companies planned their 2026 around no longer exist. The Colorado AI Act was repealed before it took effect, and the EU high risk obligations were deferred by more than a year.
Scrutineer holds your AI inventory, model documentation and human oversight evidence once, then maps it to ISO 42001, the NIST AI RMF and the rules that did land on schedule.
Control-mapped findings · linked evidence · you decide what to remediate
›
Illustrative sample · not an audit attestation
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with AI governance
Most AI governance content is describing a rulebook that changed
The two obligations that drove nearly every 2026 AI roadmap have both moved. Colorado repealed SB 24-205 outright and replaced it with SB 26-189, a narrower notice and rights framework for automated decision making that does not start until January 1, 2027, after a federal court had already stayed enforcement of the original in April 2026. In the EU, the Digital Omnibus entered into force on July 27, 2026 and pushed the standalone high risk obligations in Annex III from August 2, 2026 out to December 2, 2027, and the obligations for AI embedded in regulated products to August 2, 2028. Building an impact assessment program this quarter because Colorado required one is building for a law that no longer exists. Scrutineer tracks what each rule requires and when it actually binds, so scope follows the statute rather than last year commentary.
The date that did not move is the one nobody prepared for
Article 50 of the EU AI Act, the transparency duty, was deliberately left out of the deferral and applied on schedule on August 2, 2026. If your product runs a chatbot, generates synthetic text, images, audio or video, or uses emotion recognition, you owe disclosure to the people interacting with it, and the duty falls on deployers as well as providers. Systems that generate synthetic content and were already on the market before August 2, 2026 have until December 2, 2026 for the machine readable marking obligation, which is the only transitional runway in it. That is a live requirement for a US SaaS company with EU users right now, while the high risk paperwork everyone was worried about sits eighteen months out.
One AI control set, mapped to every framework that asks for it
ISO 42001 and the NIST AI RMF want the same underlying artifacts: an inventory of AI systems, documented purpose and limitations, data provenance, risk assessment, human oversight, monitoring and incident handling. So do the buyers sending you AI questions in a security questionnaire. Maintaining a separate binder for each is how AI governance turns into a documentation project with no operational value. Scrutineer maps a control once and shows every framework, statute and customer question it answers, so the marginal cost of the next standard is the delta rather than a fresh program. Scrutineer is readiness and decision support; an accredited certification body still issues an ISO 42001 certificate.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Keeps a live inventory of every AI system, model and third party AI feature in your product, which is the artifact every framework and questionnaire starts from
- Maps each AI control once to ISO 42001 Annex A, the NIST AI RMF functions and the EU AI Act articles it satisfies
- Tracks whether each rule is in force, deferred or repealed, so you scope against the current statute rather than superseded commentary
- Separates your provider obligations from your deployer obligations, which is what decides how much of the EU AI Act reaches you
- Flags Article 50 transparency exposure across chatbots, synthetic media and emotion recognition, including the deployer side duties
- Records training data provenance and documented limitations, which California AB 2013 requires and enterprise buyers now ask for directly
- Holds human oversight evidence, review logs and escalation paths rather than a policy that claims oversight exists
- Answers the AI sections that now appear in inbound security questionnaires from the same evidence base as your SOC 2 and ISO 27001 work
- Shows the delta when a new AI rule takes effect, instead of restarting the program each time a legislature moves
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
Status reference
Which AI rules are actually in force for a US company today, and which ones moved
Almost every published AI governance table compares frameworks against each other, which tells you nothing about what you owe this quarter. The axis that decides your roadmap is status: in force, deferred, or repealed. Three rows here contradict guidance that is still widely republished. The Colorado AI Act was repealed rather than delayed, the EU high risk deadline moved by more than a year, and the one EU deadline that did land on August 2, 2026 is the transparency duty almost nobody scoped.
| Rule or standard | Status in August 2026 | Who it reaches | What it actually asks for | Where teams get it wrong |
|---|---|---|---|---|
| EU AI Act Article 50, transparency | In force. Applied August 2, 2026 and was deliberately excluded from the Digital Omnibus deferral. | Providers and deployers of chatbots, synthetic content generators, emotion recognition and deepfake tools, including US companies whose systems reach EU users. | Tell people when they are interacting with AI, disclose emotion recognition and biometric categorisation, and mark or disclose AI generated and manipulated content. | Assuming the whole August 2026 deadline was cancelled. It was not. Only the high risk obligations moved, and the deployer side disclosure duty applied immediately. |
| EU AI Act Annex III, standalone high risk | Deferred to December 2, 2027 by the Digital Omnibus, in force July 27, 2026. | Providers and deployers of AI used in employment, credit, education, essential services and similar consequential decisions in the EU. | Risk management system, data governance, technical documentation, logging, human oversight, accuracy and conformity assessment. | Running a crash conformity assessment project this quarter. There is now more than a year of runway, and the standards it will be assessed against are still being finalised. |
| EU AI Act Annex I, product embedded high risk | Deferred to August 2, 2028. | AI built into products already covered by EU product safety law, such as medical devices and machinery. | The high risk obligation set, folded into the existing product conformity route. | Treating this as the same deadline as Annex III. It is two separate dates, twenty months apart. |
| Colorado AI Act, SB 24-205 | Repealed. Replaced by SB 26-189, signed May 14, 2026, effective January 1, 2027. | Nobody, in its original form. The replacement is a narrower notice and rights framework for automated decision making. | The original demanded risk management programs, annual impact assessments and algorithmic discrimination duties. The replacement drops all three. | Building an impact assessment program because a 2024 law required one. Enforcement was stayed in April 2026 and the statute was repealed in May 2026. |
| Texas TRAIGA, HB 149 | In force since January 1, 2026. | Anyone doing business in Texas, or developing, deploying or offering AI systems in Texas. Public entities carry heavier duties than private ones. | Avoid specific discriminatory, harmful and manipulative uses, and keep documentation on data, limitations and performance. No mandated risk program for private business. | Reading it as a Colorado style program mandate. It is intent based and narrower, and the Attorney General must give 60 days to cure before enforcing. |
| California AB 2013 and SB 942 | Both in force. AB 2013 from January 1, 2026, SB 942 duties from August 2, 2026. | AB 2013 reaches developers of generative AI made available in California. SB 942 reaches covered providers above one million monthly California users. | AB 2013 requires published documentation of training data provenance. SB 942 requires AI content disclosure and a detection tool. | Assuming California AI law means SB 53. SB 53 only reaches frontier developers above 10 to the 26th FLOPs and 500 million dollars of revenue, so it misses almost every SaaS company. |
| ISO 42001 and the NIST AI RMF | Voluntary. Neither is required by any US law. | Whoever your customers say. Both increasingly appear in enterprise vendor questionnaires and procurement checklists. | ISO 42001 is a certifiable management system audited by an accredited body. The NIST AI RMF is a voluntary framework with no certificate. | Waiting for a regulator. In this category the demand almost always arrives from a customer procurement team first. |
Status verified against multiple independent legal sources in August 2026. AI legislation in this area has changed several times in twelve months, so confirm the current position before relying on any date, including these.
Good questions
Questions about AI governance
Keep reading
Related reading
Best AI governance tools and platforms
What each category of AI governance tooling actually does, where model evaluation stops and program evidence begins, and how to tell which one you need.
Read the guideAI governance framework: ISO 42001 vs NIST AI RMF
The three frameworks compared on what they require, what they produce and who they satisfy, plus where US state AI law actually stands.
Read the guideBest security questionnaire automation software
AI questions now arrive inside inbound security questionnaires, which is where most teams first meet an AI governance requirement.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification