If your AI compliance framework is built primarily around GDPR, the 2025 data shows you are now navigating an environment where GDPR is one of four major regulatory anchors, not the dominant one. The shape of the regulatory landscape changed in twelve months, and strategic compliance plans need to absorb the new structure.
Organisations influenced by AI regulations, 2024 vs 2025:
The data, from McKinsey's 2025 global AI survey:
GDPR remains the most-cited regulatory influence on responsible AI practices, but its share dropped from 65% in 2024 to 60% in 2025. That is a 5 percentage point slip: meaningful but not catastrophic.
The EU AI Act rose from 41 to 43% (+2pp). The trajectory is up but the pace is modest, consistent with the Act's phased implementation. The bulk of EU AI Act obligations land in 2026–2027.
Two new entries appeared in 2025 that did not exist as significant influences a year earlier. ISO/IEC 42001 (an AI management system standard published in late 2023) is now cited by 36% of organisations as a regulatory influence on RAI decision-making. The NIST AI Risk Management Framework (AI RMF) is cited by 33%. Both crossed the one-third threshold in their first full year as named options on the survey.
The OECD AI Principles slipped from 21 to 16%. The US Presidential Executive Order on AI moved from 19 to 21%, though that captures a complicated picture, since the Biden-era executive order was revoked in early 2025 and the subsequent US federal policy environment shifted significantly.
The share of organisations reporting no regulatory influence at all on their RAI practices dropped from 17 to 12%.
For strategic AI planning, the shape change in the data has three significant features.
The first: AI compliance is now a multi-framework problem, not a single-framework problem. In 2024, a compliance team that handled GDPR well was operating against most of the relevant regulatory pressure. In 2025, the same team is handling roughly half of it. EU AI Act adds requirements GDPR does not cover (high-risk AI assessments, conformity documentation, post-market monitoring). ISO/IEC 42001 adds management-system requirements (governance structure, documented procedures, internal audit) that overlap with but do not duplicate GDPR or the EU AI Act. NIST AI RMF adds risk-management methodology that overlaps with but does not duplicate the others.
The second: the new entries are technical standards rather than legislation. ISO/IEC 42001 is a voluntary management system standard. NIST AI RMF is a voluntary risk management framework. Neither is law in the same sense GDPR or the EU AI Act is law. Both are nonetheless reported by approximately one-third of surveyed organisations as influencing their RAI decision-making. The implication: organisations are increasingly using technical standards as the operating layer for AI governance, even when those standards have no direct regulatory enforcement. The technical-standards layer is being adopted faster than the legislative layer, partly because legislation moves slowly and partly because customers, insurers, and auditors are using standards as proxies for "is this organisation doing AI responsibly?"
The third: regulatory fragmentation is increasing, not decreasing. The 2024 survey showed five named regulatory frameworks. The 2025 survey shows seven, with the new entries being substantial. The number of frameworks a multinational organisation needs to navigate has grown, not consolidated. The "wait for one global AI regulation to emerge" planning strategy is operating against a trajectory where the number of frameworks is increasing.
Three implications for compliance and strategic planning.
Build compliance infrastructure that maps across multiple frameworks, not infrastructure tied to a single framework. A compliance team built around GDPR alone is now operating against perhaps 60% of the regulatory pressure. Compliance frameworks that treat GDPR, EU AI Act, ISO/IEC 42001, and NIST AI RMF as four streams that need to be navigated together, with controls that map to multiple frameworks simultaneously, will out-perform single-framework frameworks.
Adopt the technical standards proactively. ISO/IEC 42001 and NIST AI RMF are voluntary, but the survey data shows they are being adopted at a pace that makes them de facto baseline practice. Organisations that adopt these standards proactively will navigate customer, insurer, and audit pressures more smoothly than organisations that wait for them to become legally mandatory. The procurement and partnership conversations of 2026–2027 will increasingly reference these standards.
Plan for continued fragmentation rather than consolidation. The trajectory of the data does not point toward a single global AI regulation that supersedes the current patchwork. It points toward more frameworks, more national variations, and more sector-specific overlays. Compliance plans built around "we will streamline once the regulatory environment settles" are betting on a settlement that the data does not support.
The trajectory: the AI regulatory environment is consolidating around four-to-six anchor frameworks (GDPR, EU AI Act, ISO/IEC 42001, NIST AI RMF, US Executive Order on AI, OECD AI Principles, plus emerging national legislation in the UK, Australia, India, Singapore, and elsewhere), each covering overlapping but non-identical scope. The shape will continue to fragment by jurisdiction over the next 24–36 months, with technical standards spreading faster than legislation. Strategic compliance plans that build for this fragmentation (multi-framework infrastructure, proactive technical-standard adoption, jurisdictional navigation as a core competence rather than an exception case) will produce better outcomes than plans built around a single dominant framework.
For executives setting AI direction, the planning anchor needs to shift from "navigate GDPR for AI-specific use cases" to "navigate a fragmenting multi-framework environment in which technical standards are the operating layer and legislation is the enforcement layer." The shift sounds small. The implementation differences are large, and the teams that work it out first will have meaningful structural advantages.
Sources
- Primary: Stanford AI Index 2026, Chapter 3 (Responsible AI) 3.3 — hai.stanford.edu/ai-index/2026
- Organisational regulatory influence: McKinsey & Company "State of AI" Survey, 2025 — regulatory frameworks influencing RAI practices
- Frameworks referenced: GDPR (EU General Data Protection Regulation); EU AI Act; ISO/IEC 42001 (AI Management System Standard); NIST AI Risk Management Framework; OECD AI Principles
Discussion