Which AI rules should your GRC team read in 2027? Get the 23 that matter, each with why it matters, what it covers, and a link to the source document so you don't need to hunt for it.
August 11, 2026

There are more than 100 AI-related regulations, standards, directives and guides in circulation right now.
Which ones should you read?
You can't give all of them equal attention.
So which ones actually deserve your team's attention in 2027?
You probably already know the three big ones NIST AI RMF the EU AI Act and ISO/IEC 42001.
But AI governance reaches a lot further than them.
Law. Governance. Management systems. Impact assessment. Technical security. Board accountability.
The list keeps growing, and most of it lands on GRC, and a surprising amount is new.
One large tech company we work with already had more than 100 frameworks mapped. They knew there had to be gaps, but where are how many.
Then they compared their existing controls against this set of AI documents and found more than 500 requirements they had never identified before.
Even a mature program has gaps. The trick is knowing which documents are likely to expose the requirements you haven't dealt with yet.
So we did the sorting for you.
The 2027 AI Governance Shortlist pulls together the 23 documents CISOs and GRC teams should have on their radar, across the US, the EU and Asia Pacific.
For each one, you get who issued it, why it matters, what it covers, how many clauses and requirements sit inside it, and a direct link to the original source.
That's 23 documents, 5,994 clauses and 5,426 requirements, sorted and explained in plain English. No hunting around regulator websites. No guessing which one to open first.
Use it as a quick check on your own priorities. Which ones have you already covered? Which are in the queue? And which never made your list at all?
If your team wants to map them yourselves, be our guest. The links take you straight to the source.