Why CIOs Can't Wait for Perfect AI Rules: A Practical Governance Playbook
Chief information officers face a fragmented regulatory landscape where waiting for perfect clarity is no longer an option. With the European Union's AI Act, five US states passing their own AI laws, and the Trump administration signaling a preference for minimal federal oversight, organizations must adopt adaptable governance frameworks that can evolve as rules change. The patchwork of requirements creates compliance challenges for companies operating across multiple jurisdictions, but experts argue that building robust internal controls now positions organizations to meet future requirements without sacrificing innovation.
What's Driving the Regulatory Fragmentation?
The AI regulatory landscape has splintered into competing approaches. The European Union's AI Act represents the most comprehensive framework, using a risk-based approach that imposes stricter requirements for AI systems affecting employment, healthcare, and finance. Meanwhile, in the United States, the federal government has struggled to establish a unified policy. In December 2025, President Trump signed an executive order directing federal agencies to evaluate state AI laws and develop recommendations for a national framework that would limit what the administration views as overly burdensome state-level regulation. However, this order does not eliminate existing state laws, meaning companies must continue complying with requirements already in place.
Several US states have moved ahead independently. Colorado passed one of the country's first and broadest regulatory frameworks for AI-driven consequential decisions, though lawmakers amended parts of the law after companies raised concerns about compliance burdens. California has enacted multiple AI-related measures focused on transparency and consumer protection, while Connecticut, Utah, and Illinois have each established their own requirements for high-risk AI systems, consumer disclosures, and employment-related AI use.
"There's just a huge pushback on anything AI regulation right now," said Tyler Thompson, partner and attorney at Reed Smith's Emerging Technologies practice group, noting that outside money and lawsuits have complicated the regulatory environment.
Tyler Thompson, Partner and Attorney, Reed Smith
How Can Organizations Build Governance That Adapts to Changing Rules?
Rather than waiting for regulatory certainty, CIOs should establish governance frameworks that can flex as new laws emerge. Experts recommend several key steps:
- Create a Cross-Functional Committee: Establish a governance group with representatives from IT, legal, security, compliance, HR, and relevant business units to review AI use cases, evaluate risks, and oversee both internally developed systems and third-party tools.
- Achieve AI Visibility: Identify where employees use AI across the organization, including approved tools, shadow AI systems that operate without formal oversight, and embedded AI capabilities built into existing software.
- Apply Risk-Based Oversight: Evaluate AI systems based on factors such as bias, privacy, security, and compliance requirements rather than treating all AI deployments equally.
- Establish Cross-Jurisdiction Standards: Develop governance principles that work across regions rather than creating separate processes for every new regulation, reducing complexity and operational overhead.
- Build Continuous Adaptation: Design a flexible governance framework that allows quick adjustments as regulations evolve, rather than rigid policies that become outdated.
Jason Landrum, global CIO of Sedgwick, described how his organization implements this approach through bimonthly governance meetings where teams review all incoming AI requests. As AI adoption grows, manual reviews may not scale, so Landrum's team is automating parts of the approval process by routing lower-risk requests through predefined workflows while reserving in-depth human review for higher-risk use cases involving sensitive customer information or new models.
"Don't wait for the perfect regulatory clarity. Just build an adaptable governance framework now. Make the ownership clear, inventory all your cases and match the oversight to risk," said Joe Locandro, global CIO of Rimini Street.
Joe Locandro, Global CIO, Rimini Street
Why Does the EU AI Act Matter for US Companies?
For multinational organizations, the EU AI Act has become a critical consideration in building AI governance programs and deciding how to deploy AI across different markets. The regulation's risk-based approach and clear, consistent expectations have set a standard that many organizations are adopting globally, even those primarily operating in the United States. Jonas Hansson, CIO of Axis Communications, noted that the EU's approach represents "a serious attempt at comprehensive, principled regulation" and that the ambition to evaluate use cases on their risk and set clear expectations is the right direction.
Jonas Hansson, CIO of Axis Communications
The EU's enforcement actions underscore the stakes. The European Commission has repeatedly fined Google for antitrust violations related to its digital services, including a $1 billion fine in July 2026 for breaching the Digital Markets Act by favoring its own services in search results and restricting app developers from directing users elsewhere. These penalties demonstrate that regulators are actively enforcing AI and digital governance rules, making compliance a business imperative rather than an optional consideration.
What Does the Trump Administration's Approach Signal?
In June 2026, President Trump signed a second executive order focused on the security risks of advanced AI systems, often called frontier models. Unlike the December 2025 order targeting state AI laws, this action created a voluntary process for developers of the most advanced AI models to share information with the federal government before public release. The order focuses on national security and cybersecurity concerns, including how frontier models could expose vulnerabilities or affect critical infrastructure.
For most CIOs managing enterprise AI deployments, the executive order does not create new compliance requirements. It primarily affects developers of advanced frontier models, not organizations using AI tools for business operations. However, the administration's overall stance suggests that federal-level AI regulation will remain minimal in the near term, leaving state and international rules as the primary compliance drivers for most organizations.
The regulatory uncertainty reflects broader tensions between innovation and oversight. While some argue that strict regulation could slow AI development, others contend that clear rules provide the certainty needed for responsible deployment. Organizations that build governance frameworks now, rather than waiting for perfect clarity, position themselves to navigate this evolving landscape without sacrificing the competitive advantages that AI can deliver.