Stacked Zero Trust Meets the Regulators
Stacked Zero Trust: Post 9 of 13
By this point in the series, a pattern should be difficult to ignore. Identity becomes harder once the subject is agentic. Trust scoring becomes harder. Governance becomes harder. Questions that looked reasonably settled under the traditional model start becoming noticeably less settled once the subject begins acting with a degree of autonomy, and the consequences rarely stay confined to a single area.
That raises a different question. What happens when regulators begin forming expectations around systems whose architecture is still evolving?
The answer, at least in 2026, is that regulators and architects are often examining the same problem from opposite directions. Regulators describe outcomes: governance, accountability, monitoring, evidence and control. Architects describe mechanisms: identity, trust algorithms, mediators and subjects. Most of the time those perspectives meet somewhere in the middle. Sometimes they do not, and that is what makes the current regulatory landscape interesting.
Across the EU, the UK, the US and the Five Eyes community, regulators have become considerably more sophisticated in what they expect organisations to do with AI systems. In some areas they are arguably ahead of the architecture. In others they are still reasoning about AI as though it were an artefact to be governed rather than a subject capable of acting. The distinction matters because compliance and architecture are ultimately solving different parts of the same problem. Compliance tells an organisation what it must achieve and what evidence it must be able to produce. Architecture determines whether those outcomes can be achieved consistently in the first place.
Viewed through the lens of Stacked Zero Trust, the most useful question is not whether a regulation applies. It is what that regulation is assuming about the thing being regulated, and whether those assumptions continue to hold once the subject becomes agentic.
Four perspectives, then the architectural read.
The EU: ahead on governance
The EU AI Act remains the most consequential piece of AI legislation in the world, partly because of its substance and partly because of its reach. Organisations do not need to be headquartered inside the European Union to find themselves within scope; serving EU users is often enough, which means its influence now extends well beyond the Union itself.
The implementation timetable has been the source of considerable manoeuvring throughout 2025 and 2026, although what has moved is mostly the timing rather than the substance. Certain deadlines have shifted, particularly around parts of the high-risk-system regime, but the underlying obligations remain largely intact. For many organisations the practical challenge is no longer deciding whether the Act matters but determining how quickly they can prepare for requirements whose supporting standards and guidance may arrive much later than they would like.
What is striking, viewed through the lens of Stacked Zero Trust, is how much of the Act is really layer-one and layer-two thinking expressed in regulatory language. Risk management systems, continuous monitoring, governance processes, technical documentation, conformity assessments and incident reporting all point towards the same underlying concern: establish confidence in a system that may behave badly, maintain evidence that confidence is justified, and continue validating that assumption throughout the system’s operational life.
Read through the architecture, most of that maps reasonably cleanly onto the substrate and the mediator. Identity, governance, documentation and control belong comfortably within layer one, while continuous observation, monitoring and response are recognisably layer-two functions. The architecture already has somewhere to place most of what the Act is asking for, which is one reason the alignment feels stronger than people sometimes assume.
The alignment becomes less comfortable once we reach layer three, because the Act still tends to reason about high-risk AI systems as things that can be characterised, documented and governed as identifiable artefacts. That assumption becomes progressively harder to sustain once the subject is an autonomous agent operating through chains of action, delegated authority and continuously changing context. This is one of the places where the architecture is arguably further ahead than the law, not because the law is wrong but because the nature of the subject has changed more quickly than the regulatory model built around it.
The UK: governance through regulators
The UK has chosen a deliberately different path, one that relies on existing regulators extending established frameworks into AI rather than creating a dedicated AI statute. There is no UK AI Act, and there is little indication that one is imminent. Responsibility instead sits with bodies such as the ICO, FCA and Ofcom, each applying AI expectations within its own domain through powers and obligations that already exist.
That distinction matters because the UK’s approach is often described as lighter-touch, when in practice it can feel considerably denser. Instead of dealing with a single AI regulator, organisations frequently find themselves satisfying several regulators at once, each examining the same system through a different lens. A financial-services deployment, for example, may trigger UK GDPR obligations, Consumer Duty requirements, SMCR accountability expectations and, where EU operations are involved, parts of the EU AI Act as well. The result is less a unified AI regime than a collection of overlapping perspectives on the same problem.
The ICO has moved furthest. Its strategy, Preventing Harm, Promoting Trust, increasingly frames AI as a cybersecurity issue as much as a privacy issue. By 2026 its guidance explicitly addresses AI-enhanced phishing, deepfake social engineering, automated vulnerability discovery, AI-assisted malware, credential attacks, data poisoning and indirect prompt injection.
What is interesting is how familiar the recommendations sound once they are read through an architectural lens. The ICO points organisations towards the NCSC Cyber Assessment Framework, Cyber Essentials, the Cyber Governance Code of Practice and the government’s AI Cyber Security Code of Practice. These are recognisably substrate controls reinforced by mediator-style monitoring and governance capabilities. The regulators have, in effect, codified the layer-one position.
For UK organisations the architectural interpretation is therefore relatively straightforward. Most current guidance maps cleanly onto layers one and two. Questions of governance, accountability, monitoring and control are increasingly well served. Layer three remains the gap, because the guidance increasingly acknowledges AI systems as sources of risk while still tending to treat them as things an organisation deploys rather than subjects capable of acting on its behalf. The architecture has already crossed that line. The regulatory guidance is still making its way towards it.
The US: governance through frameworks
The US is harder to describe because there is no single regime to describe. What exists instead is an ongoing contest between state-level regulation and federal attempts to establish a uniform position, with organisations caught somewhere in the middle. While federal policy has moved towards deregulation and pre-emption, states have continued building their own approaches, producing a landscape that remains fragmented and actively contested.
Colorado’s AI Act is the clearest example, creating obligations for developers and deployers while recognising frameworks such as NIST AI RMF and ISO/IEC 42001 as evidence of reasonable care. California and Texas have pursued their own paths, while the broader federal-state pre-emption debate remains unresolved.
Whatever happens politically, the practical response has been surprisingly consistent. Organisations looking for a defensible position have tended to align themselves with NIST AI RMF and ISO/IEC 42001, not because either framework answers every question, but because they provide a common language that regulators, auditors and legal teams increasingly recognise.
Viewed through Stacked Zero Trust, that places most of the US conversation firmly in layer one, with some extension into layer two. The emphasis remains governance, controls, accountability, documentation and risk management. Continuous monitoring appears largely in support of those governance objectives rather than as a separate architectural capability in its own right.
The same layer-three gap appears here as well, because the frameworks largely continue to reason about AI as something to be governed rather than something acting as a subject in its own right. Even where ideas such as identity resolution start to emerge, the harder questions around delegated authority, behavioural trust and autonomous action remain only partially addressed, leaving the architecture asking questions that the framework literature has only recently begun to explore.
The Five Eyes: closest to the architecture
The single most consequential piece of agentic-AI guidance issued in 2026 does not belong to any one jurisdiction.
*Careful Adoption of Agentic AI Services*, published on 1 May 2026 by ASD ACSC, CISA, NSA, the Canadian Centre for Cyber Security, NCSC New Zealand and NCSC UK, is the first coordinated Five Eyes guidance focused specifically on autonomous AI agents. More importantly, it is the first major document that begins approaching the problem in a way that looks recognisably architectural.
The guidance groups risk into five categories: privilege risk, design and configuration risk, behavioural risk, structural risk and accountability risk. It goes on to recommend concrete controls including cryptographically anchored identities, short-lived credentials, mutual-authentication mechanisms, behavioural monitoring, incremental rollout practices and human approval workflows for higher-risk actions.
What makes the document particularly interesting is not simply the controls themselves but the assumptions underneath them. The guidance implicitly accepts that agents need distinct identities. It assumes behaviour must be monitored as behaviour rather than inferred from static state. It recognises that chains of activity can create risks not visible within individual actions. In other words, it starts from assumptions that look remarkably similar to those explored throughout this series.
A note on parallel work is owed here, and I would rather make it openly than leave it implicit.
*Careful Adoption of Agentic AI Services* was published while posts 6, 7 and 8 of this series were being drafted, and a careful reader will notice a degree of convergence between the two. The document’s treatment of agent identity aligns naturally with the argument that agents should be understood as first-class subjects. Its discussion of behavioural risk aligns closely with the trust-scoring discussion from Post 8. Its treatment of structural risk maps directly onto the chains-and-cascades argument running through the series.
That convergence should not be surprising. When multiple practitioners examine the same emerging technology seriously and reason from first principles, they often arrive in similar places. Both bodies of work are describing the same underlying problem from different directions.
The Five Eyes guidance and Stacked Zero Trust are solving related but different problems. The guidance provides a detailed control catalogue covering identity, behaviour, privilege, structure and accountability. What it does not attempt to provide is an architectural model showing how those controls interact or depend on one another. That is where the layering becomes useful, because it provides a coordinate system within which the controls can be located and understood rather than simply listed.
For any organisation taking agentic AI seriously, the Five Eyes guidance is now required reading.
Where the architecture is still ahead
Step back from the jurisdictional detail and something more interesting begins to appear.
The regulators have become considerably more sophisticated in what they expect. The Five Eyes guidance demonstrates that particularly clearly. Identity, governance, monitoring, accountability and control of privileged actions are no longer theoretical concerns. They are increasingly explicit expectations.
What remains largely absent is a connective layer.
The Five Eyes guidance tells organisations what to do about agent identity, behaviour, structure and accountability in considerable detail. The EU AI Act describes governance and risk-management obligations. NIST AI RMF provides categories, principles and controls. All of them are useful, and none of them are wrong.
What none of them are trying to answer is a slightly different question: how do these controls fit together inside a functioning trust model?
This is not a criticism of those documents. They are doing precisely the jobs they were written to do. It is, however, the gap an architectural framework is supposed to fill.
The architecture tells us which controls depend on which others. It reveals where governance without visibility becomes ineffective, where monitoring without identity loses context, and where behavioural controls become difficult to operate in the absence of a coherent trust model. It does not replace the controls. It explains how they cohere.
That distinction becomes more important as organisations move from experimentation into operational deployment. The requirements themselves are demanding enough. The deadlines are real. The audit conversations are already happening. Yet meeting the compliance requirement and answering the architectural question are not quite the same thing, because the former is increasingly expected while the latter remains unevenly understood.
A note on the moving target
A final point is worth being explicit about.
The regulatory positions described above are accurate as of mid-2026. They will not remain unchanged. EU deadlines may move again. The US pre-emption debate may resolve in several different ways. UK regulators will continue publishing guidance that subtly shifts expectations over time.
Anyone treating this post as a definitive compliance reference is using it incorrectly. Treat it as a snapshot of the landscape at the moment the series is being written, and treat the architectural interpretation as the durable part.
The reference document at the end of the series will provide a more complete regulatory treatment with primary sources cited directly. The architecture itself, by contrast, is less dependent on political outcomes. Whatever happens to specific deadlines, enforcement dates or jurisdictional disputes, the underlying architectural questions remain largely the same.
One thing to take from this
The most interesting thing about the regulatory landscape in 2026 is not that the EU, UK, US and Five Eyes communities have adopted identical approaches. They clearly have not. What is striking, however, is how often they arrive at remarkably similar concerns despite taking different routes.
Identity. Governance. Monitoring. Accountability. Control of privileged actions. Confidence that systems behave within acceptable bounds and that organisations can demonstrate that confidence when challenged.
Those concerns map surprisingly well onto the three layers of Stacked Zero Trust.
What remains largely unresolved is how the controls fit together architecturally. Regulations and guidance documents are increasingly good at describing what organisations should do. They are generally less concerned with describing how those controls cohere inside a working trust model, and that is the gap architecture exists to fill.
Compliance remains necessary. The deadlines are real. The Five Eyes guidance in particular is likely to influence procurement, governance and audit conversations for years to come. Compliance alone, however, is not the same thing as architectural adequacy. The organisations that do best in the next phase will be the ones that treat regulatory compliance as an input into the architecture rather than a substitute for it.
The next post turns to a different but related problem: how organisations are expected to govern AI systems they often do not even know they have, as shadow AI begins to follow the same path shadow IT took before it.
Post 9 of 13 in Stacked Zero Trust.
Previously: Post 8 - Trust Scoring a Probabilistic Subject.
Next: Post 10 - Shadow AI Is the New Shadow IT, Only Faster.
The reference document at the end of the series includes a fuller treatment of the regulatory landscape with primary sources, and the OT/IEC 62443 dimension that this series otherwise treats as out of scope.
References drawn on in this post: **Careful Adoption of Agentic AI Services**, joint guidance co-authored by ASD ACSC, CISA, NSA, the Canadian Centre for Cyber Security, NCSC New Zealand, and NCSC-UK, published 1 May 2026 (Five Eyes); EU AI Act (Regulation (EU) 2024/1689) and the European Commission’s November 2025 Digital Omnibus proposals; UK ICO AI and biometrics strategy and May 2026 cyber-threat guidance; UK NCSC Cyber Assessment Framework and Cyber Essentials; UK government AI Cyber Security Code of Practice; FCA AI update and the joint Bank of England / PRA approach to AI in financial services; UK Data (Use and Access) Act 2025; the US Executive Order of December 11, 2025 (”Ensuring a National Policy Framework for Artificial Intelligence”); NIST AI Risk Management Framework and NIST Cybersecurity Framework Profile for AI; ISO/IEC 42001; Colorado AI Act (SB 24-205); California TFAIA; Texas RAIGA; US Treasury Department AI framework (February 2026). The Five Eyes guidance was published as this series was being drafted; convergent observations between the two bodies of work were arrived at independently.


