AI Policy Wiki
Dashboard

AI Compliance Industry / Regulatory Fragmentation

medium confidence · updated 2026-06-06

The emerging AI compliance industry (Holistic AI, Credo AI, Trail) and the multi-jurisdiction compliance burden driving it — the audit market, the 'race to the top vs bottom' dynamic, and the techno-federalist structure of AI regulation.

AI compliance fragmentation refers to the multiplicity of overlapping, non-identical regulatory obligations applying to AI systems across jurisdictions. The AI compliance industry is the commercial ecosystem that has emerged to help firms manage that multiplicity, including dedicated AI governance software vendors, audit firms, legal advisory services, and in-house compliance functions. A firm operating multi-jurisdictionally faces dozens of distinct AI-specific compliance obligations, each with its own scope definition, disclosure format, timing, audit requirement, and enforcement regime. The associated third-party software, services, and audit market has grown from roughly zero in 2020 to hundreds of millions of dollars by 2026, and the structure raises a policy question of whether fragmentation produces a race to the top (best-practice convergence) or a race to the bottom (regulatory arbitrage to permissive jurisdictions).

The set of overlapping requirements includes the EU AI Act, the Colorado AI Act, California SB 53, the NY RAISE Act, Texas TRAIGA, Illinois SB 3444, NIST AI 600-1, the GPAI Code of Practice, NYC LL 144, California AB 3030, Chinese algorithmic-recommendation rules, the Singapore Model AI Governance Framework (MGF), and others.

Dimensions of fragmentation

Fragmentation occurs across multiple axes:

  1. Jurisdictional. Federal (US) vs. state vs. municipal; US vs. EU vs. China vs. UK vs. Singapore, and others.
  2. Sectoral. Employment (NYC LL 144, EEOC guidance), finance (CFPB, OCC), healthcare (FDA SaMD), education (state AI literacy frameworks).
  3. Model tier. Frontier (SB 53, RAISE, GPAI Code of Practice) vs. high-risk deployer (Colorado, EU) vs. general-purpose user obligations.
  4. Governance style. Transparency-first (SB 53), duty of care (Colorado), intent-based prohibitions (Texas TRAIGA), conformity assessment (EU AI Act), safe-harbor (IL SB 3444).
  5. Timing. Annual, continuous, on-deployment, on-modification — no harmonized cadence.
  6. Disclosure format. Different regimes demand different documentation (risk management plan, impact assessment, conformity declaration, transparency report, safety framework, system card, model card) with overlapping but non-identical contents.

A frontier AI developer operating in both the US and EU is simultaneously subject to the EU AI Act (GPAI duties, prohibited-practices compliance, high-risk conformity assessment, Article 4 literacy, AI Office oversight); the GPAI Code of Practice (detailed implementation of those duties); California SB 53 (frontier transparency, kill-switch, whistleblower protections); the NY RAISE Act (similar frontier transparency); the Colorado AI Act (high-risk deployer duties, if selling decision tools into Colorado); Texas TRAIGA (prohibited-practice compliance, if operating in Texas); Illinois SB 3444 (opt-in safe harbor, if applicable); NYC LL 144 (if using automated employment decision tools in hiring); California AB 3030 (if generating clinical communications); the NIST AI RMF (de facto baseline for US federal engagement); Chinese algorithmic-recommendation rules (if operating in China); the Singapore MGF for generative AI (if deploying in Singapore); and sectoral regulators including the FTC, CFPB, EEOC, HHS/OCR, and FDA as applicable. Each regime has its own documentation requirements; many overlap substantively (describe the safety framework, describe testing procedures) but none map cleanly, so duplication is structural.

Compliance burden

The compliance burden is typically decomposed into an initial build (creating documentation, risk-management processes, and disclosure templates), ongoing monitoring (tracking AI inventory, reporting incidents, updating assessments), audit and verification (third-party review under specific regimes), and multi-jurisdiction reconciliation (mapping obligations across regimes). Industry estimates suggest the combined cost can reach 1–3% of revenue for AI-heavy firms in regulated sectors. Smaller firms face disproportionate per-dollar compliance costs, raising concentration concerns.

Compliance-industry structure

By 2026 the AI compliance market had structured into roughly the following segments:

  • AI governance software (GRC) — platforms for cataloging AI systems, running impact assessments, and managing audits. Vendors include Credo AI, Holistic AI, Trail (formerly Luminos), Arize AI, Fiddler, and Relyance AI.
  • Bias audit firms — specialized consultancies performing third-party bias audits (NYC LL 144, Colorado AI Act). The market is small and growing.
  • Conformity-assessment notified bodies — EU-accredited bodies assessing high-risk AI under the AI Act, a subset of the broader CE marking notified-body ecosystem adapting to AI.
  • Big Four and legal advisory — the major audit firms (Deloitte, PwC, EY, KPMG) and major law firms have all built dedicated AI-governance practices.
  • Standards and certification — ISO/IEC 42001 certification bodies and NIST RMF advisors.
  • Red teaming and evaluation — companies including Gretel, Haize Labs, and Apollo Research (see Apollo Research) at the safety-evaluation end.

The IAPP AI Governance Vendor Report 2026 (IAPP AI Governance Vendor Report 2026) catalogs more than 80 AI governance vendors across four product categories:

  • Independent audit and evaluation: Holistic AI, ForHumanity, TÜViT, BABL AI, Responsible AI Institute.
  • Advisory services: Accenture Responsible AI, BCG, Deloitte Digital, KPMG, EY, PwC, IBM — all major consulting firms with dedicated AI governance practices.
  • Governance tools and processes: Credo AI, OneTrust, Securiti.ai, Collibra, DataRobot — GRC platforms specializing in AI inventory management and impact assessment.
  • Technical testing and monitoring: Fiddler AI, Arthur AI, Protect AI, Armilla.ai, LatticeFlow, Cranium AI.

The presence of all the Big Four consulting firms reflects enterprise-level compliance demand. The vendor count of more than 80 has grown from near zero in 2020, consistent with the scaling compliance burden the regulatory-fragmentation analysis describes.

Among individual vendors, Credo AI (founded 2020, venture-backed) operates an AI governance platform and has partnerships with the World Economic Forum; Holistic AI (founded 2020, London) operates an AI auditing platform and was an early mover in NYC LL 144 audits; and Armilla.ai sits at the AI risk-insurance nexus, connecting the compliance market to financial coverage for AI liability. The segment has attracted venture investment in the aggregate hundreds of millions of dollars, which observers read as investor conviction that the compliance burden will grow.

The bias-audit market (NYC LL 144, Colorado AI Act) is small, concentrated, and contested. Firms offer audits at wide price ranges, methodologies are not standardized, and enforcement is thin. The "audit washing" critique that informs skepticism about the compliance market is discussed at Algorithmic Accountability and Bias Audits.

Debates and positions

Race to the top vs. race to the bottom

A central policy-analytic question is whether fragmentation drives regulation upward — firms adopting the strictest rule as a global baseline to avoid per-market compliance variation, the so-called "Brussels effect" — or downward, with firms relocating to the most permissive jurisdiction. Race-to-the-top arguments point to the Brussels effect for GDPR, where global firms largely adopted GDPR-style processes to avoid per-market product forks, and to similar dynamics in EU AI Act compliance among US frontier labs. Race-to-the-bottom arguments note that Texas's TRAIGA and Illinois's SB 3444 are already cited as industry-preferred templates relative to California, and that the EU's CE marking burden has plausibly pushed some consumer-AI products out of the EU market. The empirical evidence is mixed and considered too early to adjudicate: GDPR experience suggests Brussels-effect dominance, while AI-specific evidence remains underdetermined.

Relation to techno-federalism

AI compliance fragmentation is described as the operational manifestation of Techno-Federalism: How Regulatory Fragmentation Shapes the U.S.-China AI Race. Central governments have not established comprehensive AI regulation, and states, municipalities, and industry self-regulation fill the gap in ways that produce a patchwork; the compliance industry exists because of that patchwork. An illustrative structural case arises in Illinois, where Sen. Durbin (D-IL) sponsors the federal AI LEAD Act with strict liability and floor preemption, while Sen. Cunningham (D-IL) sponsors Illinois SB 3444 with safe-harbor immunity. A firm operating in Illinois could simultaneously face federal strict liability and state safe-harbor shelter, leaving the compliance obligation irreducibly complex — and compliance vendors' value proposition is to manage that complexity.

Policy responses

Harmonization attempts

Several efforts aim to reduce divergence. The NIST AI RMF serves as a de facto US federal baseline that states cite; ISO/IEC 42001 is an international management-system standard aiming for cross-border recognition; the GPAI Code of Practice is a detailed EU-coordinated implementation of GPAI duties; the OECD AI Principles provide high-level international framing; and the Hiroshima Process (G7 Hiroshima Code of Conduct for Advanced AI (2023)) sets G7-level voluntary principles.

Mutual recognition

No binding AI mutual-recognition agreement exists. The EU-US Trade and Technology Council discussed harmonization but produced only non-binding principles. Singapore's AI Verify explicitly aims for interoperability.

Industry self-coordination

The Frontier Model Forum, the Partnership on AI, and other industry-convened efforts attempt to harmonize voluntary commitments across member firms. These have not substantively reduced the multi-jurisdictional compliance burden.

Relationships