Every AI rulebook starts with the same demand: show your records.

Regulators and frameworks disagree on much — but nearly all of them expect organizations to know what AI systems they run and keep records of how they're governed. Meridian's ledger provides that inventory from your connected billing and usage sources, with spend and usage evidence attached.

Also on the Meridian product page: #regulatory

NAIC AI Model Bulletin (insurance)

Adopted or reflected in AI-related insurance guidance by more than 20 U.S. jurisdictions, the NAIC Model Bulletin expects insurers to maintain a written AI Systems Program proportionate to risk — with governance, documentation, and oversight of third-party AI. Meridian builds the working record of AI systems detected in your billing and usage sources, with owner, department, and spend attached. How Meridian supports NAIC-aligned programs

Bank AI governance (post–SR 26-2)

On April 17, 2026, SR 26-2 replaced SR 11-7 — and explicitly placed generative and agentic AI outside model-risk scope, while directing that existing risk-management practices should still govern them. Banks must now construct agent governance without a prescribed rulebook — and the first artifact any such program needs is a current, evidence-backed inventory of the AI estate. How Meridian supports bank AI governance

HIPAA & AI oversight (healthcare)

When an AI system creates, receives, maintains, or transmits ePHI, it should be evaluated within the covered entity's or business associate's Security Rule risk-analysis and security-management process. Meridian gives compliance teams the documented AI-system inventory and vendor view that feed that process — with a metering workflow designed not to require PHI. How Meridian supports healthcare AI oversight

EU AI Act

Obligations are phasing in — certain provisions have applied since 2025, and the timetable for standalone high-risk obligations was formally revised in 2026 to December 2, 2027. Obligations differ by role: providers, deployers, importers, and distributors each carry their own. Meridian's retention-controlled records and attribution provenance support the governance-records posture the Act expects. How Meridian supports EU AI Act readiness

ISO/IEC 42001

The AI management-system standard requires organizations to establish, operate, and continually improve an AIMS — including documented resources, defined responsibilities, operational controls, and evidence for internal or third-party conformity audits. Meridian supplies the AI-estate records and operating evidence auditors sample. Certification bodies determine conformity; tools do not. How Meridian supports ISO 42001 programs

NIST AI RMF

Voluntary guidance organized around GOVERN, MAP, MEASURE, and MANAGE — with a playbook that specifically contemplates AI-system inventories and accountability structures. Meridian answers the inventory and accountability questions from billing-grade data your finance team already trusts. How Meridian supports the NIST AI RMF

FAQ

Why is there no Colorado AI Act page?
Colorado repealed and replaced its AI Act in May 2026 with a disclosure-based ADMT law effective January 1, 2027. That regime is still too unsettled to anchor a dedicated page; we will revisit in Q1 2027. Records retention and inventory posture remain relevant for any disclosure-based program.
Does Meridian decide our regulatory status?
No. Meridian produces records that support your program. Legal advice and determinations stay with your counsel and regulators.
Where should we start?
Start with the free Agent Spend Assessment — two weeks, read-only — or the Zero-Access Assessment if you prefer file-based metering with no credentials connected.