Share with your CISO
With the EU AI Act already binding, Colorado’s algorithmic-decision law live, and four other U.S. states adding requirements, CIOs are building jurisdiction-spanning AI governance frameworks rather than waiting for federal clarity. Trump’s December 2025 executive order signals Washington wants to suppress state-level rules, but it doesn’t preempt them yet. The practical playbook that emerges from CIOs at Rimini Street, Sedgwick, and Axis Communications centers on cross-functional governance committees, mandatory AI system inventories, risk-tiered review workflows, and vendor due diligence strict enough to reject tools that exfiltrate training data.
What this means for your business
The organizations most exposed here aren’t the ones deploying the most AI. They’re the ones deploying AI without knowing where it lives. Shadow AI, meaning AI capabilities quietly embedded in existing SaaS tools that employees trigger without recognizing them as AI, is the gap most governance programs miss. If your CISO or CIO hasn’t completed a full inventory that includes third-party software with bundled AI features, your compliance posture is worse than your policy documents suggest, regardless of how polished those documents look.
The regulatory picture is more stable than the uncertainty framing implies, and that’s actually the more important read. Trump’s executive orders create political pressure against new state mandates, but existing laws in Colorado, California, Connecticut, Utah, and Illinois aren’t going anywhere. The practical consequence is that the floor of compliance requirements is already set for enterprises operating across those states. What’s genuinely uncertain is the ceiling, whether a federal standard eventually arrives and where it lands. Building governance to the current floor, with architecture flexible enough to extend upward, is the correct bet. Organizations that treat current state laws as temporary and defer governance investment are misreading the signal.
The vendor governance point deserves more weight than it typically gets. Locandro’s disclosure that Rimini Street rejected tools because training-data exfiltration couldn’t be traced names a risk that procurement checklists routinely miss. A vendor’s AI feature may be genuinely useful and still create unacceptable data lineage exposure. The governance discipline that matters most right now isn’t the committee structure or the risk matrix, it’s whether the organization has a credible answer to the question of where its data goes once it enters a vendor’s model. That’s the renewal conversation worth stress-testing before the next contract cycle.
Concept deep-dive: Risk-tiered review
Risk-tiered review routes AI use-case approvals based on potential harm, the way a hospital triage system sorts patients by severity rather than arrival order. Low-risk requests using approved vendors and non-sensitive data move through automated workflows. High-risk requests, those touching sensitive customer data, employment decisions, or unvetted models, escalate to human committee review. The business case is scale: as AI adoption grows, flat manual review becomes a bottleneck, and tiering lets governance keep pace without adding headcount proportionally.
Based on reporting from How CIOs can navigate federal, state AI regulation uncertainty, originally published 2026-07-23 11:39:00.

