Skip to content

AI laws and regulations

26 regulations worldwide that deal with ai, with every phased deadline and the official source for each.

Upcoming deadlines

September 20261 deadline

  1. ICO abolished; Information Commission takes over

    Sections 118-119 commence: office of Information Commissioner abolished and functions transferred to the Information Commission (Commencement No. 9 Regulations 2026).

    Takes effectin 6 daysSource

October 20261 deadline

  1. PA 26-64 (SB 4) amendments take effect

    Prohibits controllers and third parties from selling precise geolocation data and enacts data broker and other consumer protection provisions.

    Takes effectin 7 daysSource

December 20264 deadlines

  1. EU AI Act

    New bans on sexual deepfakes and CSAM generation; Art 50(2) grace period ends

    New Art 5(1)(ba)/(bb) prohibitions on AI systems that generate non-consensual intimate imagery of identifiable persons or child sexual abuse material apply. Generative AI systems placed on the market before 2 Aug 2026 must comply with the Art 50(2) marking duty by this date (new Art 111(4)).

    Compliance deadlinein 2 monthsSource
  2. Transposition deadline; old PLD repealed

    Member States must transpose by 9 Dec 2026 (Art 22). Directive 85/374/EEC is repealed from that date but still applies to products placed on the market before it (Art 21).

    Transitionin 3 monthsSource
  3. Children's Online Privacy Code must be registered

    OAIC must develop and register the Children's Online Privacy Code within 24 months of Royal Assent.

    Compliance deadlinein 3 monthsSource
  4. Automated decision-making transparency applies

    Privacy policies must disclose the kinds of personal information used in substantially automated decisions that significantly affect individuals (24 months after assent).

    Compliance deadlinein 3 monthsSource

January 20278 deadlines

  1. Large online platform and hosting platform duties

    Large online platforms and GenAI hosting platforms must meet the provenance duties added by AB 853.

    Compliance deadlinein 3 monthsSource
  2. First OES anonymized incident report and CDT definition review

    OES begins publishing annual anonymized incident summaries and the Department of Technology begins annual review of the act's definitions; the CalCompute framework report is due to the Legislature.

    Reportingin 3 monthsSource
  3. CCPA / CPRA

    ADMT requirements compliance date

    Businesses using ADMT for significant decisions must comply with Article 11 (pre-use notice, opt-out, access rights) by this date (11 CCR 7200(b)).

    Compliance deadlinein 3 monthsSource
  4. CCPA / CPRA

    Browsers must support opt-out preference signal (AB 566)

    Businesses that develop or maintain a browser must include consumer-configurable functionality to send an opt-out preference signal (Civ. Code 1798.136, operative Jan 1, 2027).

    Compliance deadlinein 3 monthsSource
  5. ADMT obligations apply

    Developer documentation, consumer notices, post-adverse-outcome disclosure, correction and human-review rights take effect.

    Takes effectin 3 monthsSource
  6. AG rules due

    Attorney General must adopt rules clarifying the post-adverse-outcome disclosure requirements.

    Compliance deadlinein 3 monthsSource
  7. Data broker registration required

    Data brokers may not sell or license brokered personal data in Connecticut unless registered with the Department of Consumer Protection ($2,500 initial fee).

    Compliance deadlinein 3 monthsSource
  8. NY RAISE Act

    RAISE Act takes effect

    Transparency reports, frontier AI frameworks, incident reporting and DFS disclosure filings apply.

    Takes effectin 3 monthsSource

March 20271 deadline

  1. Transition ends for existing AI systems (general)

    Existing AI systems in most sectors must comply (12-month transition).

    Transitionin 5 monthsSource

July 20272 deadlines

  1. First annual report to Office of Suicide Prevention

    Operators begin annual reporting on crisis referrals and detection protocols.

    Reportingin 9 monthsSource
  2. Scheduled repeal of Title 13, Ch. 72

    SB 332 extends the AI Policy Act repeal date from May 1, 2025 to July 1, 2027.

    Sunsetin 9 monthsSource

August 20271 deadline

  1. EU AI Act

    Legacy GPAI models must comply; national AI sandboxes operational

    Providers of GPAI models placed on the market before 2 Aug 2025 must comply (Art 111(3)). Each Member State must have at least one national AI regulatory sandbox operational (Art 57(1) as amended by the Omnibus).

    Compliance deadlinein 10 monthsSource

September 20271 deadline

  1. Transition ends for existing AI systems in health, education and finance

    Existing AI systems in healthcare, education and finance must comply (18-month transition).

    Transitionin 11 monthsSource

December 20272 deadlines

  1. EU AI Act

    High-risk obligations apply to Annex III systems

    Chapter III Sections 1-3 (high-risk requirements and provider/deployer obligations) apply to AI systems classified high-risk under Art 6(2) and Annex III (employment, credit scoring, education, biometrics, essential services and similar). Deferred from 2 Aug 2026 by Regulation (EU) 2026/1744.

    Compliance deadlinein 14 monthsSource
  2. CCPA / CPRA

    Risk assessments for pre-existing processing due

    Risk assessments must be completed and documented for high-risk processing that began before Jan 1, 2026 and continues after (11 CCR 7155(b)).

    Compliance deadlinein 15 monthsSource

January 20282 deadlines

  1. Capture device manufacturer duties

    Capture device manufacturer provenance requirements become operative.

    Compliance deadlinein 15 monthsSource
  2. Vermont Data Privacy and Online Surveillance Act takes effect

    All obligations under Act 145 apply (sec. 4).

    Takes effectin 15 monthsSource

April 20282 deadlines

  1. CCPA / CPRA

    First risk assessment submission to CPPA

    Businesses must submit required risk assessment information and attestation for assessments conducted in 2026 and 2027 (11 CCR 7157(a)(1)); annually by April 1 thereafter.

    Reportingin 18 monthsSource
  2. CCPA / CPRA

    Cybersecurity audit due: revenue over $100M

    First cybersecurity audit report (covering Jan 1, 2027 - Jan 1, 2028) and certification due for businesses with 2026 annual gross revenue over $100M (11 CCR 7121(a)(1)).

    Reportingin 18 monthsSource

August 20281 deadline

  1. EU AI Act

    High-risk obligations apply to Annex I product-embedded systems

    Chapter III Sections 1-3 apply to AI systems classified high-risk under Art 6(1) and Annex I (safety components of products covered by EU harmonisation legislation). Deferred from 2 Aug 2027 by Regulation (EU) 2026/1744.

    Compliance deadlinein 22 monthsSource

October 20281 deadline

  1. Data brokers must process state deletion mechanism requests

    Registered data brokers must access the DCP accessible deletion mechanism at least every 45 days and process deletion requests.

    Compliance deadlinein 2 yearsSource

April 20291 deadline

  1. CCPA / CPRA

    Cybersecurity audit due: revenue $50M-$100M

    First cybersecurity audit report (covering 2028) due for businesses with 2027 annual gross revenue between $50M and $100M (11 CCR 7121(a)(2)).

    Reportingin 2.5 yearsSource

June 20291 deadline

  1. Mandatory 60-day cure period expires

    The AG's duty to issue a cure notice before enforcement ends June 30, 2029 (Act 145 sec. 3).

    Enforcementin 2.8 yearsSource

January 20301 deadline

  1. Mandatory cure period ends

    The AG's obligation to offer a 60-day notice-and-cure period expires.

    Sunsetin 3.3 yearsSource

April 20301 deadline

  1. CCPA / CPRA

    Cybersecurity audit due: revenue under $50M

    First cybersecurity audit report (covering 2029) due for covered businesses with 2028 annual gross revenue under $50M (11 CCR 7121(a)(3)); annual by April 1 thereafter.

    Reportingin 3.5 yearsSource

August 20301 deadline

  1. EU AI Act

    Public-authority high-risk systems must comply

    Providers and deployers of high-risk AI systems intended for use by public authorities that were placed on the market before the Chapter III application date must comply (Art 111(2), as replaced by the Omnibus).

    Compliance deadlinein 3.9 yearsSource

December 20301 deadline

  1. EU AI Act

    Large-scale EU IT systems must comply

    AI systems that are components of the large-scale IT systems in Annex X (e.g. SIS, VIS, Eurodac, EES, ETIAS) placed on the market before 2 Aug 2027 must be brought into compliance (Art 111(1)).

    Compliance deadlinein 4.3 yearsSource

Past deadlines

August 20263 deadlines

  1. EU AI Act

    General application: transparency obligations, GPAI fines, most other rules

    The AI Act's general date of application. Article 50 transparency obligations (chatbot disclosure, deepfake labelling, machine-readable marking of synthetic content) and Commission fines on GPAI providers (Art 101) apply. Not deferred by the Omnibus.

    Takes effect53 days agoSource
  2. Covered provider duties apply

    Detection tool, manifest and latent disclosures, and license-revocation duties become operative.

    Takes effect53 days agoSource
  3. Profiling impact assessments apply

    Impact assessment requirements apply to profiling activities created or generated on or after Aug 1, 2026 (Conn. Gen. Stat. 42-522 as amended).

    Compliance deadline54 days agoSource

July 20263 deadlines

  1. EU AI Act

    Digital Omnibus on AI enters into force

    Regulation (EU) 2026/1744 (adopted 8 July 2026, OJ 24 July 2026) enters into force on the third day after publication. Amended Articles 102 to 110 apply from this date (new Art 113(d)).

    Transition59 days agoSource
  2. 2026 APPI amendment act promulgated

    Amendment enacted by the Diet on 10 July 2026 and promulgated; main provisions take effect by cabinet order within two years of promulgation.

    Transition2 months agoSource
  3. PA 25-113 (SB 1295) amendments take effect

    Thresholds drop to 35,000 consumers or any sensitive-data processing or data sale; expanded sensitive data, minors' protections, and LLM-training disclosure in privacy notices.

    Takes effect3 months agoSource

June 20263 deadlines

  1. Delayed effective date (superseded)

    SB 25B-004 date; superseded by SB 26-189 before it arrived, so no obligations applied.

    Transition3 months agoSource
  2. Mandatory data protection complaints procedure

    Controllers must have a process for data subject complaints (s.103 and Sch. 10), per Commencement No. 6 Regulations 2026, reg. 3.

    Compliance deadline3 months agoSource
  3. IDHR withdraws and postpones proposed rules

    IDHR withdraws the Subpart J proposal and postpones the June 10, 2026 hearing; no new date announced.

    Transition4 months agoSource

May 20263 deadlines

  1. TAKE IT DOWN Act

    Platform notice-and-removal process required

    Covered platforms must have a clear notice-and-removal process and remove valid reported content within 48 hours (Sec. 3, one year after enactment).

    Compliance deadline4 months agoSource
  2. IDHR proposed notice rules published

    IDHR publishes proposed Subpart J rules on AI notice in the Illinois Register.

    Transition4 months agoSource
  3. SB 26-189 signed (repeal and reenact)

    SB 26-189 replaces SB 24-205 with a narrower ADMT disclosure framework and moves the effective date to January 1, 2027.

    Transition4 months agoSource

March 20262 deadlines

  1. NY RAISE Act

    Chapter amendment S8828 signed

    Chapter amendment (ch. 96) finalizes the RAISE Act text.

    Transition6 months agoSource
  2. AI Law takes effect

    Risk classification, transparency and labeling obligations apply to new AI systems.

    Takes effect7 months agoSource

February 20262 deadlines

  1. Stage 3: main data protection changes commence

    Recognised legitimate interests, ADM reforms, DSAR changes, international transfer test, cookie exemptions and PECR fines at UK GDPR levels apply (Commencement No. 6 Regulations 2026, reg. 2).

    Takes effect8 months agoSource
  2. Original effective date (superseded)

    Original SB 24-205 date; postponed by SB 25B-004, so no obligations applied.

    Transition8 months agoSource

January 20269 deadlines

  1. AI Basic Act and Enforcement Decree take effect

    Transparency, labeling, high-impact AI, and domestic representative obligations apply (fines deferred during the grace period).

    Takes effect8 months agoSource
  2. TRAIGA

    TRAIGA takes effect

    Prohibited-practice rules, AG enforcement, sandbox program and government AI disclosure duties apply.

    Takes effect9 months agoSource
  3. AI anti-discrimination and notice duties apply

    Prohibition on discriminatory AI use and the employee notice requirement take effect.

    Takes effect9 months agoSource
  4. 2025 amendments take effect

    Higher fines, first-violation fines, AI governance provisions and PIPL-alignment duties apply under the 28 Oct 2025 NPCSC Decision.

    Takes effect9 months agoSource
  5. CCPA / CPRA

    New CCPA regulations take effect

    ADMT, risk assessment, cybersecurity audit and updated CCPA regulations become effective; risk assessments required for new high-risk processing.

    Takes effect9 months agoSource
  6. Frontier developer obligations apply

    Frontier AI frameworks, transparency reports, critical safety incident reporting (15 days, or 24 hours for imminent risk of death or serious injury) and whistleblower protections apply.

    Takes effect9 months agoSource
  7. Chatbot safeguards apply

    AI disclosure, suicide and self-harm protocols, and minor protections apply.

    Takes effect9 months agoSource
  8. Original operative date (superseded)

    Original SB 942 date; delayed to August 2, 2026 by AB 853.

    Transition9 months agoSource
  9. Training-data documentation due

    Documentation must be posted for GenAI systems released since January 1, 2022, and before each later release or substantial modification.

    Compliance deadline9 months agoSource

December 20251 deadline

  1. NY RAISE Act

    RAISE Act signed

    Governor Hochul signs the RAISE Act with an agreed chapter amendment.

    Transition9 months agoSource

October 20252 deadlines

  1. SB 243 signed

    SB 243 chaptered (ch. 677).

    Transition11 months agoSource
  2. AB 853 signed

    AB 853 (ch. 674) delays the operative date and adds platform and device duties.

    Transition11 months agoSource

September 20254 deadlines

  1. SB 53 signed

    Governor Newsom signs SB 53 (chapter 138).

    Transition12 months agoSource
  2. CCPA / CPRA

    ADMT, risk assessment and cybersecurity audit regulations approved

    OAL approves the CCPA Updates, Cybersecurity Audit, Risk Assessment, ADMT and Insurance regulations and files them with the Secretary of State.

    Transition12 months agoSource
  3. AI Promotion Act fully in force

    Provisions establishing the AI Strategy Headquarters and AI Basic Plan take effect.

    Takes effect13 months agoSource
  4. AI content labeling measures and GB 45438-2025 take effect

    Explicit and implicit labeling duties for AI-generated content and platform detection duties apply.

    Takes effect13 months agoSource

August 20253 deadlines

  1. SB 25B-004 delays the act

    Special-session bill pushes the SB 24-205 effective date from February 1, 2026 to June 30, 2026.

    Transition13 months agoSource
  2. Stage 1 commencement

    Technical data protection provisions, ICO statutory objects, Smart Data framework (Part 1) and AI/copyright reporting duties commence (Commencement No. 1 Regulations 2025).

    Takes effect13 months agoSource
  3. EU AI Act

    GPAI, governance, notified bodies and penalties apply

    Chapter III Section 4 (notifying authorities), Chapter V (general-purpose AI model obligations), Chapter VII (governance), Chapter XII (penalties, except Art 101) and Art 78 apply (Art 113(b)).

    Takes effect14 months agoSource

June 20254 deadlines

  1. TRAIGA

    HB 149 signed

    Governor Abbott signs TRAIGA.

    Transition15 months agoSource
  2. Royal Assent

    The Act receives Royal Assent; commencement staged by regulations.

    Takes effect15 months agoSource
  3. Statutory tort for serious invasions of privacy commences

    Individuals can sue for serious invasions of privacy (Schedule 2), 6 months after Royal Assent.

    Takes effect15 months agoSource
  4. AI Promotion Act promulgated and partly in force

    Most provisions, including basic principles and stakeholder duties, take effect on promulgation.

    Takes effect16 months agoSource

May 20251 deadline

  1. TAKE IT DOWN Act

    Criminal provisions effective on enactment

    Publishing or threatening to publish non-consensual intimate images, including digital forgeries, became a federal crime upon signature.

    Takes effect16 months agoSource

When the rules change: new data, privacy and AI laws and deadlines, the next morning.