The Conventional Wisdom
Many compliance teams are waiting for federal AI regulation before taking action. It seems logical: Why invest in controls when the rules are unclear? Illinois recently mandated third-party AI audits for developers with significant revenue and computing power. Colorado passed an AI act, only to have it challenged in court. President Trump signed Executive Order 14365 in December 2025, directing agencies to challenge state AI laws that hinder competitiveness. With such chaos, waiting seems prudent.
Your legal team likely advised this, and your CFO probably agrees. If your organization doesn't develop AI models in-house, you might think you're exempt.
Why This Approach Is Incomplete
Confusing regulatory clarity with business necessity is a mistake. Legal preemption may strike down laws, but it doesn't affect customer expectations or contractual obligations. Even if state AI laws are blocked, your enterprise customers will still demand proof of fairness in your hiring platform. Requests for independent AI assurance won't vanish because a court halted a statute.
We've seen this before. Cloud computing adoption outpaced verification frameworks in 2010. There was no law requiring SOC 2 reports, yet buyers demanded independent assurance. Soon, you couldn't secure enterprise deals without third-party attestation. Procurement set the standard, not legislation.
AI is on a similar path, but with higher stakes. Cloud systems mainly affected data security, while AI impacts employment, credit, and healthcare decisions. The compliance risk is broader, and your customers are aware.
You're likely already using AI, even if you think you aren't. One organization believed it had no AI exposure because it didn't develop models. An audit revealed three systems in use: an HR recruiting platform, a customer service AI assistant, and a sales credit scoring tool. None were built internally, yet all triggered state disclosure requirements for automated systems.
That organization lacked documentation for systems it didn't build. They faced compliance risks for technology they couldn't evaluate or explain.
The Evidence
Illinois was the first state to require independent third-party audits of AI safety measures when Governor JB Pritzker signed Senate Bill 315 on July 6, 2026. The Act takes effect January 1, 2027, with audits starting January 1, 2028. It targets developers with over $500 million in revenue and significant computing capabilities. Violations carry hefty penalties.
Your organization might not meet these thresholds, but SB 315 is a signal. Legislators identified the most impactful AI systems and deemed self-attestation inadequate. This logic will influence deployment requirements for ordinary organizations, just as it has in other states.
The trend is clear: disclosure, then transparency, and eventually independent verification. Waiting for federal clarity means you'll scramble when your largest customer demands third-party AI assurance next quarter.
What to Do Instead
Start building your verification layer now. Begin with ISO/IEC 42001:2023, the first international standard for AI management systems. Certification includes documentation audits, control testing for transparency and bias, human oversight verification, and data management practices. It addresses risk across the entire lifecycle, unlike one-time model assessments.
If you already conduct SOC 2 engagements, integrate AI controls into your existing audit. Model validation, training data handling, version control, and monitoring fit within established criteria, reducing costs.
Inventory all deployed AI functions, including those in licensed software. Document inputs, purpose, and human oversight for each decision point. Design a control framework that maps overlapping requirements to a single set of processes meeting the most stringent standard.
Upstream enforcement is crucial. Procurement should require ISO 42001 certification or SOC 2 reports from vendors. Suppliers without independent attestation are asking for blind trust. Cloud vendors moved away from this practice years ago, and you shouldn't accept it now.
When the Conventional Wisdom Is Right
If you're a small organization with no customer-facing AI, no employment decision tools, and no vendors using AI in material processes, waiting makes sense. You don't need ISO 42001 certification if you're not deploying systems affecting jobs, credit, housing, or healthcare.
The regulatory landscape is indeed messy. Federal preemption challenges create uncertainty about which state laws will survive. You shouldn't build your program around compliance with a potentially enjoined statute.
Focus on independent verification instead of regulatory box-checking. An ISO 42001 certification or AI-scoped SOC 2 report isn't tied to any single law. It shows operational maturity regardless of which requirements prevail. When federal standards emerge, you'll have the evidence infrastructure ready.
Technology has outpaced regulation. Your customers are moving faster than both. You can wait for Washington to sort it out, or you can build the assurance framework procurement teams will soon demand. One path leaves you ready, the other leaves you explaining why you can't answer basic questions about systems you're already using.



