Most companies deployed AI faster than they documented it. Now regulators, enterprise buyers and insurers are all asking the same question: who checked this system, and can you prove it?
AI compliance and audit services exist to answer that question with evidence rather than assurances. This guide covers what these services actually include, which rules apply to US businesses in 2026, what an auditor examines, and how Miniml prepares client systems for review.
What Are AI Compliance and Audit Services?
AI compliance is the ongoing work of keeping your AI systems aligned with applicable law, standards and internal policy. An AI audit is a point-in-time review that tests those systems against a defined framework and produces documented findings.
People use the two terms interchangeably, which causes problems in scoping. Compliance is a continuous operational responsibility. An audit is a discrete engagement with a report at the end.
| AI Compliance | AI Audit | |
| Purpose | Stay aligned with rules day to day | Test and evidence current state |
| Frequency | Continuous | Point in time, usually annual |
| Output | Policies, controls, monitoring | Findings, gap analysis, remediation plan |
| Owner | Internal, often risk or legal | Independent reviewer |
Why AI Compliance Became a Business Requirement
The pressure is no longer coming only from regulators. Enterprise procurement teams now ask for AI documentation inside standard vendor security reviews, and a missing answer can stall a deal for months.
Three forces are driving this at once:
- Regulation catching up. Binding obligations now sit mostly in state and EU law rather than US federal statute.
- Procurement gatekeeping. Large buyers require model documentation, data handling detail and human oversight evidence before signing.
- Liability exposure. Insurers and general counsel are asking who is accountable when an automated decision goes wrong.
The Rules That Apply to US Companies in 2026
The US still has no comprehensive federal AI statute. Federal activity runs through executive orders and agency posture, and a December 2025 executive order created a Justice Department task force to challenge state AI laws it considers overly burdensome. That fight is live and unresolved, which means state law remains the binding layer until a statute or court decision says otherwise.

Two practical points follow from that. First, the map is fragmented rather than simplified. Second, deferrals and repeals do not remove obligations that are already in force.
US State Rules in Force
- Colorado. SB 26-189, signed May 2026, repealed and replaced the original Colorado AI Act with a disclosure-focused framework effective January 1, 2027, covering notice, adverse action review and three-year record retention.
- California. SB 53 frontier model duties are in effect, alongside Civil Rights Council rules on automated decision systems in employment and CPPA rules on automated decision-making technology.
- Illinois and Texas. Employment disclosure duties and the Texas TRAIGA regime took effect through 2026.
- New York City. Local Law 144 continues to require bias audits for automated employment decision tools.
- Sector rules. HIPAA, GLBA, FCRA and SR 11-7 model risk guidance already apply to AI systems in healthcare, lending and banking.
EU Rules That Reach US Businesses
The EU AI Act applies extraterritorially, so a US company placing an AI system on the EU market or serving EU users is in scope. The Digital Omnibus on AI, in force since July 2026, deferred the heaviest deadlines without changing the substance.
- Annex III standalone high-risk obligations now apply from December 2, 2027
- Annex I embedded high-risk obligations apply from August 2, 2028
- Article 50 transparency duties applied from August 2, 2026 and were not deferred
- Legacy system watermarking duties and new prohibited practices apply from December 2, 2026
Voluntary Frameworks Auditors Work From
- NIST AI Risk Management Framework for structuring governance, mapping and measurement
- ISO/IEC 42001 for a certifiable AI management system
- ISO/IEC 23894 for AI-specific risk guidance
- SOC 2 where AI sits inside an existing security programme
What an AI Audit Actually Examines
An audit is not a document review. A competent reviewer tests the system, reads the logs, and asks for evidence that controls operated rather than merely existed.
Miniml structures reviews around eight domains. Gaps in any one tend to surface problems in the others, and decision-level logging is where most engagements stall, because without it nothing else can be evidenced after the fact.
- Data. Provenance, consent basis, retention limits, licensing of training material, handling of sensitive attributes
- Model. Documented performance, known limitations, drift monitoring, version control and change history
- Bias and fairness. Disparate impact testing across protected classes, repeated on a schedule rather than once at launch
- Security. Prompt injection resistance, data leakage paths, endpoint access control, secrets handling
- Transparency. Model cards, system documentation, and disclosure to the people affected
- Human oversight. Defined review checkpoints, override authority, and a working escalation path
- Vendor risk. Third-party models, subprocessors, and what their terms actually permit
- Logging. Whether you can reconstruct why a specific decision was made six months later
The AI Audit Process, Step by Step
A well-run engagement follows a predictable sequence, and the early steps matter more than the technical testing that gets the attention.
- Inventory. Identify every AI system in use, including tools adopted by individual teams without central approval.
- Risk classification. Rank each system by consequence, regulatory exposure and data sensitivity.
- Evidence collection. Gather policies, model documentation, vendor terms, logs and prior test results.
- Technical testing. Run bias, robustness, security and accuracy tests against defined thresholds.
- Gap analysis. Compare findings against the chosen framework and applicable law.
- Remediation plan. Assign owners and deadlines to each gap, prioritised by risk rather than by ease.
- Re-test and monitor. Verify fixes and set the ongoing cadence for review.
Common Compliance Gaps Miniml Sees
The failures are consistent across sectors, and almost none of them are exotic. They come from AI being adopted departmentally and governed centrally only after the fact.
- No inventory. Nobody can say how many AI systems the organisation runs.
- Shadow AI. Staff use unsanctioned tools with company data, outside any policy.
- Missing documentation. Vendors never supplied model cards or evaluation results, and nobody asked.
- No decision logging. Outputs exist but the reasoning path was never captured.
- One-time bias testing. Tested at launch, never repeated as data and models drifted.
- Unowned policy. A written AI policy exists with no named owner and no enforcement.
Who Needs AI Compliance Services, and When
Timing is usually driven by an external event rather than an internal decision. Waiting for the event is the expensive route, because remediation under deadline pressure costs more than building controls in from the start.

Typical trigger points include an enterprise security review blocking a contract, deployment of AI in hiring, lending or clinical decisions, entry into EU markets, an acquisition that brings unknown AI systems with it, or an insurer asking questions at renewal.
Building Compliance Into AI Systems From the Start
Retrofitting governance onto a live system is slow and it interrupts teams already running the thing. Designing for it costs very little at the point of build, and it is the difference between an audit that takes six weeks and one that takes six months.
The controls worth putting in on day one are role-based access, decision-level logging, retrieval grounding with source citation, defined human review checkpoints, and a fixed evaluation set you can re-run after every model change.
Getting Your AI Systems Review Ready
Audit readiness is an engineering outcome, not a paperwork exercise. The organisations that pass cleanly are the ones that built logging, access control and documented evaluation into their systems before anyone asked to see them.
Miniml provides AI compliance assessments, audit preparation and remediation for organisations across the United States, covering custom AI solutions, generative AI systems and LLM integrations already in production. If you need to know where your AI systems stand before someone else checks, get in touch for an assessment and a prioritised roadmap.
FAQ
What is an AI audit? An AI audit is a structured review of an AI system against a defined framework such as NIST AI RMF or ISO/IEC 42001. It examines data handling, model performance, bias, security, transparency, human oversight and logging, and produces documented findings with a remediation plan.
Is AI compliance legally required in the United States? There is no comprehensive federal AI statute. Binding obligations currently come from state laws in California, Colorado, Illinois, Texas and New York City, plus existing sector rules such as HIPAA, FCRA and GLBA that already apply to automated decisions.
Does the EU AI Act apply to US companies? Yes. The Act applies extraterritorially to any company placing an AI system on the EU market or serving EU users. High-risk obligations for standalone Annex III systems now apply from December 2, 2027, while transparency duties have applied since August 2026.
How long does an AI audit take? A single-system review typically runs four to eight weeks. Organisation-wide programmes take longer, and the main variable is documentation quality rather than system complexity. Companies with existing logging and model documentation finish considerably faster.
What is the difference between an AI audit and a security audit? A security audit examines infrastructure, access and data protection. An AI audit covers those plus model behaviour, bias, training data provenance, human oversight and explainability. The two overlap but neither replaces the other.
How do I prepare my company for an AI audit? Start with an inventory of every AI system in use, including unsanctioned tools. Then collect vendor documentation, confirm decision-level logging exists, and assign a named owner to your AI policy. Those three steps resolve most findings before an auditor arrives.