For years, compliance teams built their programs around a manageable, well-known set of frameworks: PCI-DSS for payment data, HIPAA for healthcare, SOC 2 for service organizations, ISO 27001 for information security management. These frameworks were stable. Auditors knew them. Tooling was built around them. And most importantly, the list didn't change very often.
That era is over.
In the last two years alone, organizations operating across borders have had to absorb a wave of new privacy and AI-specific regulation: the EU AI Act, which introduces risk-based obligations for organizations that develop or deploy AI systems; India's Digital Personal Data Protection Act (DPDPA), which reshapes how personal data of Indian residents must be collected, processed, and protected; and amendments to Australia's Privacy Act, which raise the bar on breach notification, penalties, and data handling obligations for entities operating in or serving the Australian market. None of these existed in their current form a few years ago. All of them now apply, in full force, to global organizations that may not have designed their compliance programs with them in mind.
This isn't a temporary spike in regulatory activity. It's the new baseline. Generative AI adoption is accelerating faster than most legal and compliance functions can track, and regulators around the world are responding with new rules aimed specifically at how organizations collect, use, and protect data in AI-driven systems. At the same time, data privacy law continues to mature and diverge across jurisdictions, meaning global organizations increasingly must satisfy multiple, sometimes overlapping, sometimes conflicting, sets of obligations simultaneously.
The real cost isn't the regulation, it's the reaction time
Ask any compliance leader what keeps them up at night, and it's rarely the substance of a new regulation itself. It's the operational scramble that follows – mapping the new requirements to existing controls, figuring out which systems and data stores are even in scope, pulling together evidence for auditors, and doing all of it under a deadline that was set by a legislature, not by the compliance team's own roadmap.
This reactive posture is expensive in ways that don't always show up on a budget line. It consumes disproportionate hours from already-stretched teams. It forces organizations to treat every new regulation as a special project, rather than as a routine extension of an existing capability. And it creates real business risk in the gap between "the law is now in effect" and "our program is actually compliant with it."
The organizations that handle this well share a common trait: they've stopped treating compliance frameworks as separate, siloed initiatives, each requiring its own tooling, its own reporting, and its own manual evidence-gathering process. Instead, they've invested in a compliance capability that treats the underlying data as the constant, and the framework being applied to it as a variable that can be added without re-architecting anything.
What "framework-agnostic" compliance looks like
In practice, this means a few things need to be true of a modern data security and compliance program:
Visibility must come before benchmarking. You cannot assess your compliance posture against any framework, new or old, if you don't already have a current, accurate map of where sensitive data lives, how it's classified, and who can access it. Data Security Posture Management (DSPM) exists precisely to solve this foundational problem, continuously discovering and classifying data across cloud and SaaS environments so that compliance assessment has something real to stand on.
Adding a new framework should be a configuration step, not an engineering project. When a new regulation applies to your organization, the question shouldn't be "how long will it take to build support for this," it should be "how quickly can we evaluate our posture against it." That's only possible when the underlying data visibility and control mapping already exist, and a new framework can be layered on top as a new lens rather than a new system.
A single score should tell you where you stand across everything that you're accountable for. Compliance leaders don't need four disconnected reports to answer, "where do we stand?" They need one view that shows compliance posture across every applicable framework side by side, so leadership can see the full regulatory footprint immediately before drilling into any one area.
Detail must be available the moment leadership asks for it. A single compliance score is a useful headline, but it's not actionable on its own. The real value comes from being able to move, in the same session and without switching tools, from "here's our overall posture" to "here's exactly which control is failing, in which section, and how many resources are affected." That's the difference between a dashboard and a remediation plan.
Proofpoint's new compliance experience in DSPM
This is the exact problem Proofpoint set out to solve with the new Compliance experience in Proofpoint DSPM.
DSPM gives organizations a single, unified view of compliance posture across every framework they're tracking — PCI-DSS, HIPAA, SOC 2, ISO 27001, and now the EU AI Act, India's DPDPA, and the Australian Privacy Act — instead of four disconnected reports. From that unified view, teams can move seamlessly into the detail behind any one framework to understand exactly what's driving a gap and what to fix first.
The part that matters most for everything discussed above: newly emerging regulations plug into the same experience customers already use for established frameworks. No new tooling, no new configuration project, no separate learning curve. A framework which organizations weren't even tracking a year ago becomes just another lens on data they've already made visible — one place to see where you stand today, and wherever the next regulation takes you.


Figure 1: Cross-benchmark and single-benchmark views of compliance posture
Why this matters beyond the compliance team
It's tempting to think of regulatory compliance as a back-office function — something legal and compliance teams manage quietly while the rest of the business focuses on growth. But the frameworks arriving now, particularly around AI governance, are increasingly board-level and customer-facing concerns. Enterprise customers are asking vendors directly about AI risk management. Regulators are imposing meaningful penalties for non-compliance. And the pace of change means that an organization's ability to adapt quickly is becoming a competitive differentiator, not just a defensive capability.
Organizations that can demonstrate compliance with an emerging framework within days of it taking effect send a clear signal: their data governance program isn't held together by manual processes and institutional knowledge; it's built on a platform that scales with the regulatory environment rather than lagging it.
The path forward
The list of frameworks with which organizations need to comply is not going to get shorter, and it's not going to stop changing. AI-specific regulation is still in its early stages globally, and more jurisdictions are expected to introduce their own versions of rules already in effect in the EU, India, and elsewhere. Data privacy law will continue to evolve as well, particularly as enforcement actions clarify how existing laws apply to new categories of data and new use cases.
The organizations best positioned for what's coming aren't the ones trying to predict exactly which regulation will land next. They're the ones that have built a compliance capability flexible enough that it doesn't matter which one does. When the underlying data visibility is solid and framework support is additive rather than architectural, “we now have to comply with a new regulation” stops being an emergency and starts being Tuesday.
That's the standard compliance programs should be held to going forward: not just compliant with today's rules, but ready for whatever rules come next.
Learn more:
Watch Proofpoint Innovations: Defend Data August webinar to learn more about Proofpoint DSPM’s compliance capabilities.