Recent updates to the AI Assured Framework
What changed in the framework and the regulatory landscape for 2026 - and what each change means for the work on your desk.
2026 framework changes
- New Copilot governance article - reflects Microsoft 365 Copilot data-boundary and Restricted SharePoint Search updates.
- Purview for AI article - added DLP-for-AI patterns now generally available across M365 Copilot, ChatGPT Enterprise and Gemini Enterprise.
- Agentic AI playbook - first edition. Covers tool/permission scoping, kill-switches and OpenTelemetry GenAI semantic conventions.
- Red-teaming & evals - aligned to OWASP LLM Top 10 2025 (Prompt Injection, Sensitive Information Disclosure, Supply Chain, Insecure Output Handling, etc.).
- Bias testing techniques - deep-dive companion to the foundation bias article: Fairlearn, Aequitas, HELM, Giskard.
Regulatory context driving the changes
- EU AI Act - prohibited-practice ban in force since Feb 2025; GPAI obligations since Aug 2025; high-risk obligations (Annex III) phase in through Aug 2026 and Aug 2027. See the dedicated article for dates.
- UK ICO - updated generative-AI guidance through 2025 on lawful basis, purpose limitation and accuracy.
- NIST AI RMF 1.0 + GenAI Profile (NIST AI 600-1) - now the de facto US baseline.
- ISO/IEC 42001 - first AI management system standard; expect customer RFPs to ask for it from 2026.
Do this Monday
- Diff your AI risk register against the new articles - anything missing becomes a backlog ticket.
- Add EU AI Act key dates to your compliance calendar.