The convergence moment
For the first time, at least five regulatory regimes are moving simultaneously on AI in critical infrastructure. On April 7, 2026, NIST released the Concept Note for the AI RMF Profile on Trustworthy AI in Critical Infrastructure. Twenty-four days later, CISA and the Five Eyes published their first coordinated guidance on autonomous AI agents in critical infrastructure.
Between those publications, the FCC expanded the Covered List, CISA continued CIRCIA rulemaking on mandatory incident reporting, and the EU AI Act's high-risk system deadline approaches - with fines reaching €15 million or 3% of global annual turnover.
None of these regimes will accept "we implemented the NIST framework" as evidence of compliance. Each demands a different artifact. Each has teeth.
The four collisions
The structural gap between governance and compliance produces specific, demonstrable collisions when the AI RMF meets mandatory regimes:
An operator can be fully NIST-compliant - third-party AI risk documented under GOVERN 6 - while simultaneously violating FCC equipment authorisation rules because an AI component was never cross-referenced against the Covered List. The FCC asks a binary question: does this equipment contain a prohibited component? A policy is not an attestation.
CIRCIA requires 72-hour incident reporting for critical infrastructure. But the rule does not yet define whether AI-specific incidents - model poisoning, AI hallucinations cascading into outages - constitute a "covered cyber incident." An operator with an incident process does not yet have the specific data fields, format, or pipeline CIRCIA will demand. A process is not a report.
The NIST framework's disengagement mechanism was designed for AI systems that operate individually. The Five Eyes guidance addresses a world where AI agents operate collectively, inherit permissions, and make autonomous decisions at machine speed. It requires cryptographically anchored agent identities - infrastructure no current NIST framework addresses. A procedure is not an infrastructure.
Article 14 requires that human overseers can understand, interpret, override, and interrupt high-risk AI. As Issues Paper No. 2 documented: can the overseer actually understand what an autonomous agent decided between prompts? A policy document cannot answer this - only production-grade evidentiary governance can. A role description is not a conformity assessment.
Salt Typhoon: what governance gaps cost
Salt Typhoon - a Chinese state-sponsored APT - compromised at least 200 American companies across 80 countries, including major telecom providers AT&T and Verizon, gaining the ability to geolocate subscribers and intercept communications. The operators had cybersecurity frameworks. They had governance. What they did not have was the specific operational mapping from framework to control to evidence that would have prevented exploitation.
The compliance collision this paper describes is the same structural pattern applied to AI.
The proposal: a Compliance Translation Layer
A Compliance Translation Layer takes the governance outputs the AI RMF produces and converts them into the specific evidence each mandatory regime requires. Not four separate compliance programmes. One governance foundation. One translation layer. Multiple compliance endpoints.
Think of it the way a telecom engineer would: a network management system produces telemetry in an internal format. Multiple external interfaces - a regulator portal, an emergency services gateway - each expect data in a different format. The operator builds a mediation layer that translates for each endpoint.
- FCC endpoint - Binary attestation for each AI component against the Covered List, derived from an AI Bill of Materials
- CIRCIA endpoint - Pre-formatted incident report populated from continuous AI system logging, filed within 72 hours
- EU AI Act endpoint - Conformity assessment evidence from the Continuous Shadow Deployment log proposed in Issues Paper No. 2
- CISA agentic AI endpoint - Cryptographic identity architecture with continuous privilege auditing
Three Compliance Architecture Questions
Building on the diagnostics from Paper No. 1 and Paper No. 2:
- Can you enumerate every mandatory obligation that applies to each AI system on your network? - A question of obligation mapping. Not by framework, but by enforcement authority.
- For each obligation, can you trace a direct line from your governance architecture to the specific evidence that obligation requires? - A question of evidence traceability.
- Where gaps exist between governance and compliance evidence, who owns the gap - and what is the remediation timeline? - A question of gap ownership.
The nine-question diagnostic across three papers
The three ITS Issues Papers together form a nine-question diagnostic covering the full scope of operational control over AI in telecom critical infrastructure:
An operator that can answer all nine has operational sovereignty. An operator that cannot has a framework, not a capability. When the regulator arrives, it is the capability that matters.
Citation: Institute for Technology Stewardship (2026). The Compliance Collision: Why AI Governance Will Not Protect Telecom Operators When Regulators Arrive. Issues Paper No. 3, July 2026.
© 2026 Institute for Technology Stewardship. Licensed under CC BY-NC 4.0.