Opens in a new tab
vmblog logo 2024 wht (updated)

Key Saas Compliance Predictions for 2026

Share: 

David Marshall | Published: December 18, 2025

vmblog-2026-prediction-series   

Industry executives and experts share their predictions for 2026.  Read them in this 18th annual VMblog.com series exclusive. 

By Marcia Foley, VP Global Compliance and IT at Sauce Labs

The rapid adoption of Artificial Intelligence (AI) will continue in 2026, forcing organizations to invest in Governance, Risk, and Compliance (GRC) to manage these risks.

Five AI Compliance Challenges for 2026

1. EU AI Act Will Require Full Compliance by August 2026 for High-risk AI Systems

The EU AI Act is the world’s first comprehensive AI law. Companies must comply by August 2026, creating a shift in AI governance from theory to practice. The EU AI Act compliance is a requirement for any organization that places AI systems on the EU market or puts them into service in the EU. If the output of your AI system is used in the EU, the Act also applies. Outside of the EU AI Act, more companies are expected to pursue ISO 42001 and the NIST AI framework to demonstrate AI maturity within the compliance function.

2. Regulatory Changes Will Increase Exponentially

Global companies will be forced to comply with increased regulatory changes. According to the Stanford AI Index, Global legislative proceedings regarding AI have increased more than ninefold since 2016. Inconsistent laws and local and regional interpretation of AI regulations will require SaaS companies to focus on governance.

3. Companies Will Be at Even More Risk from Shadow IT

The unauthorized use of AI tools by employees within SaaS companies will represent risk and possible data exposure. Companies will need to empower organizational representatives to review and approve the use of AI tools before individual employees decide to deploy them. If companies cannot provide a “fast lane” to process requests for the internal adoption of AI tools, employees will deploy these tools without waiting, increasing corporate risk.

4. Data Governance Must Be Treated in a Unique Way

Data governance for AI will require its own AI data taxonomy and classification system. AI technologies will be categorized based on capabilities, functions, and application areas. This new framework will assist organizations in evaluating and prioritizing AI solutions.

5. Compliance Evolves from a Point Review to an Ongoing Inspection

Annual audits will not be sufficient for AI products. Adding AI agents into operational and business productivity tools means compliance is always on. AI agents will continuously scan control environments and generate alerts for investigation. Companies must shift from reactive manual checks to real-time, Continuous Control Monitoring.

##

ABOUT THE AUTHOR 

Marcia Foley, PMP, is the Vice President of Global Compliance & IT at Sauce Labs. With a background spanning operations, program management, and global compliance, including previous leadership roles in SaaS companies. Marcia specializes in architecting governance frameworks that enable, rather than block, engineering velocity. Marcia’s focus is on ensuring that innovation and compliance grow in tandem.