Recent updates to the AI Assured Framework
What changed in the framework and the regulatory landscape for 2026 — and what each change means for the work on your desk.
2026 framework changes
- New Copilot governance article — reflects Microsoft 365 Copilot data-boundary and Restricted SharePoint Search updates.
- Purview for AI article — added DLP-for-AI patterns now generally available across M365 Copilot, ChatGPT Enterprise and Gemini Enterprise.
- Agentic AI playbook — first edition. Covers tool/permission scoping, kill-switches and OpenTelemetry GenAI semantic conventions.
- Red-teaming & evals — aligned to OWASP LLM Top 10 2025 (Prompt Injection, Sensitive Information Disclosure, Supply Chain, Insecure Output Handling, etc.).
- Bias testing techniques — deep-dive companion to the foundation bias article: Fairlearn, Aequitas, HELM, Giskard.
Regulatory context driving the changes
- EU AI Act — prohibited-practice ban in force since Feb 2025; GPAI obligations since Aug 2025; high-risk obligations (Annex III) phase in through Aug 2026 and Aug 2027. See the dedicated article for dates.
- UK ICO — updated generative-AI guidance through 2025 on lawful basis, purpose limitation and accuracy.
- NIST AI RMF 1.0 + GenAI Profile (NIST AI 600-1) — now the de facto US baseline.
- ISO/IEC 42001 — first AI management system standard; expect customer RFPs to ask for it from 2026.
Do this Monday
- Diff your AI risk register against the new articles — anything missing becomes a backlog ticket.
- Add EU AI Act key dates to your compliance calendar.