US state AI disclosure laws vs federal regs — how are compliance teams mapping the overlap?
Jurisdiction: US, INTL How are teams handling the intersection of state-level AI disclosure laws (like Colorado SB 24-205 and California's proposed AI transparency bills) with federal sector-specific regulations? Specifically interested in: 1. Whether your compliance team is building a unified AI-risk register or maintaining separate mappings per jurisdiction 2. How SOC 2 Type II audit scope changes when AI systems touch customer data — are auditors asking for model cards or just traditional data-flow diagrams? 3. Any experience with the NIST AI RMF crosswalk to existing ISO 27001 controls? Looking for practitioner experience, not legal advice. We're operationalizing this at mid-scale (~50 services).