COMPLIANCE FRAMEWORKS / CROSS-MAPPING

Every framework being used to govern AI access.

Each framework below is broken down section by section with AI impact annotations showing where compliance requirements are being shaped to narrow AI access, favor centralized infrastructure, or create compliance traps. This is the reference. This is the evidence.

US GOVERNMENT / NIST
NIST SP 800-53 Rev 5
Security and privacy controls for federal information systems. The backbone of FedRAMP and federal AI deployment requirements.
NIST.SP.800-53r5 · 1,026 controls · 18 families
US GOVERNMENT / NIST
NIST SP 800-171 Rev 2
Protecting CUI in nonfederal systems. The foundation of CMMC. Every DoD contractor handling AI-processed CUI must comply.
NIST.SP.800-171r2 · 110 controls · 14 families
US GOVERNMENT / DoD
CMMC 2.0
Cybersecurity Maturity Model Certification. DoD's enforcement layer on 800-171. Phase II suspended July 2026. Phase I self-assessment active.
32 CFR Part 170 · 3 levels · Phase II suspended
US GOVERNMENT / GSA
FedRAMP
Federal Risk and Authorization Management Program. The gatekeeper for cloud AI services serving federal agencies. LOW/MOD/HIGH baselines.
FedRAMP.gov · 3 baselines · Based on NIST 800-53
US GOVERNMENT / HHS
HIPAA Security Rule
45 CFR Part 164, Subpart C. Administrative, physical, and technical safeguards for protected health information. AI in healthcare hits every requirement.
45 CFR 164.302-318 · 18 standards · 36 implementation specs
US GOVERNMENT / NIST
NIST AI RMF 1.0
AI Risk Management Framework. Voluntary framework already being adopted as procurement requirement. The "voluntary" entry ramp in action.
NIST.AI.100-1 · 4 functions · GOVERN-MAP-MEASURE-MANAGE
US GOVERNMENT / EXECUTIVE
Executive Order 14409
Promoting Advanced AI Innovation and Security. Signed June 2, 2026. Directs agencies to harden infrastructure against AI risks. The latest EO in the AI governance chain.
EO 14409 · Signed June 2, 2026 · Federal Register June 5, 2026
INTERNATIONAL / EU
EU AI Act
Regulation (EU) 2024/1689. The world's first comprehensive AI law. Risk-tiered approach from minimal to unacceptable risk. Extraterritorial reach.
Reg 2024/1689 · 113 articles · Risk-tiered · Effective 2026
INTERNATIONAL / ISO
ISO/IEC 42001
AI Management System standard. The international certifiable standard for AI governance. Companies will adopt it for procurement compliance.
ISO/IEC 42001:2023 · Certifiable · Paywalled full text
INTERNATIONAL / ISO
ISO/IEC 27001
Information Security Management Systems. The global standard for infosec. AI systems processing data must comply with ISMS requirements.
ISO/IEC 27001:2022 · Annex A controls · Certifiable
INTERNATIONAL / EU
GDPR
General Data Protection Regulation (EU) 2016/679. AI training data, automated decisions, profiling rights. The regulation that shaped global AI data law.
Reg 2016/679 · 99 articles · 173 recitals
INDUSTRY / AICPA
SOC 2
System and Organization Controls 2. Trust Services Criteria for service organizations. Cloud AI providers need SOC 2 for enterprise sales.
AICPA TSC 2017 · 5 categories · 64 criteria
INDUSTRY / PCI SSC
PCI-DSS v4.0
Payment Card Industry Data Security Standard. AI systems handling cardholder data must meet all 12 requirements. v4.0 added AI-adjacent controls.
PCI DSS v4.0 · 12 requirements · 64 sub-requirements
INDUSTRY / OSAA
SAFE RFC
Secure AI Framework for Enterprises. The OSAA/Linux Foundation standard that started as "voluntary" and is becoming a procurement requirement. Track 02 case study.
OpenSecureAIAlliance/RFCs · GitHub · Proposal stage
COST ANALYSIS / THE FILTER
Compliance Cost Analysis
What businesses actually pay for compliance — by size, by framework, by combination. Sourced dollar amounts showing how compliance cost concentrates the AI market. 25 sources cited.
25 sources · 5 frameworks · 4 combinations · 10 required services
DECENTRALIZED AI / THE SOLUTION
Decentralized AI — Compliance by Design
How local-first, sovereign AI architecture inherently meets HIPAA, NIST 800-171, SOC 2, and GDPR requirements through design — not through expensive compliance programs. Ownership, privacy, and sovereignty as the compliance solution.
5 frameworks · BAA elimination · FIPS control · $13K/yr vs $140K/yr