A planned update to cybersecurity controls and a new cloud framework suggest regulators are treating AI-enabled threats as an operational compliance problem, not a theoretical one.