Recent updates to the AI Assured Framework

What changed in the framework and the regulatory landscape for 2026 — and what each change means for the work on your desk.

2026 framework changes

  • New Copilot governance article — reflects Microsoft 365 Copilot data-boundary and Restricted SharePoint Search updates.
  • Purview for AI article — added DLP-for-AI patterns now generally available across M365 Copilot, ChatGPT Enterprise and Gemini Enterprise.
  • Agentic AI playbook — first edition. Covers tool/permission scoping, kill-switches and OpenTelemetry GenAI semantic conventions.
  • Red-teaming & evals — aligned to OWASP LLM Top 10 2025 (Prompt Injection, Sensitive Information Disclosure, Supply Chain, Insecure Output Handling, etc.).
  • Bias testing techniques — deep-dive companion to the foundation bias article: Fairlearn, Aequitas, HELM, Giskard.

Regulatory context driving the changes

  • EU AI Act — prohibited-practice ban in force since Feb 2025; GPAI obligations since Aug 2025; high-risk obligations (Annex III) phase in through Aug 2026 and Aug 2027. See the dedicated article for dates.
  • UK ICO — updated generative-AI guidance through 2025 on lawful basis, purpose limitation and accuracy.
  • NIST AI RMF 1.0 + GenAI Profile (NIST AI 600-1) — now the de facto US baseline.
  • ISO/IEC 42001 — first AI management system standard; expect customer RFPs to ask for it from 2026.

Do this Monday

  1. Diff your AI risk register against the new articles — anything missing becomes a backlog ticket.
  2. Add EU AI Act key dates to your compliance calendar.