AI laws and regulations
26 regulations worldwide that deal with ai, with every phased deadline and the official source for each.
26 regulations
Add to calendar
- Data (Use and Access) Act
United Kingdom
In forcePrivacyData access and sharingNext: Sep 30, 2026 ICO abolished; Information Commission takes over
- Connecticut Data Privacy Act (CTDPA)
Connecticut
AmendedPrivacyChildrenNext: Oct 1, 2026 PA 26-64 (SB 4) amendments take effect
- EU AI Act
European Union
AmendedAIBiometricsNext: Dec 2, 2026 New bans on sexual deepfakes and CSAM generation; Art 50(2) grace period ends
- Product Liability Directive
European Union
EnactedAICybersecurityNext: Dec 9, 2026 Transposition deadline; old PLD repealed
- Australia Privacy Act
Australia
AmendedPrivacyChildrenNext: Dec 10, 2026 Children's Online Privacy Code must be registered
- California AI Transparency Act (SB 942)
California
AmendedAINext: Jan 1, 2027 Large online platform and hosting platform duties
- California SB 53 (TFAIA)
California
In forceAINext: Jan 1, 2027 First OES anonymized incident report and CDT definition review
- CCPA / CPRA
California
AmendedPrivacyAINext: Jan 1, 2027 ADMT requirements compliance date
- Colorado AI Act
Colorado
EnactedAIPrivacyNext: Jan 1, 2027 ADMT obligations apply
- NY RAISE Act
New York
EnactedAINext: Jan 1, 2027 RAISE Act takes effect
- Vietnam AI Law
Vietnam
In forceAINext: Mar 1, 2027 Transition ends for existing AI systems (general)
- California SB 243 (companion chatbots)
California
In forceAIChildrenNext: Jul 1, 2027 First annual report to Office of Suicide Prevention
- AmendedAI
Next: Jul 1, 2027 Scheduled repeal of Title 13, Ch. 72
- Vermont VDPOSA
Vermont
EnactedPrivacyHealth dataNext: Jan 1, 2028 Vermont Data Privacy and Online Surveillance Act takes effect
- ProposedAI
- In forceAIPrivacy
Effective Jan 1, 2026
- In forceAIOnline safety
Effective Sep 1, 2025
- AmendedCybersecurityData residency
Effective Jun 1, 2017
- Digital Omnibus (data/GDPR)
European Union
ProposedPrivacyData access and sharing - In forceAI
Effective Jan 1, 2026
- In forceAI
Effective Jun 4, 2025
- Japan APPI
Japan
AmendedPrivacyChildrenEffective Apr 1, 2005
- NYC Local Law 144 (AEDT)
New York City, New York
In forceAIEffective Jul 5, 2023
- South Korea AI Basic Act
South Korea
In forceAIEffective Jan 22, 2026
- TAKE IT DOWN Act
United States (Federal)
In forceOnline safetyAIEffective May 19, 2025
- TRAIGA
Texas
In forceAIBiometricsEffective Jan 1, 2026
Upcoming deadlines
September 20261 deadline
ICO abolished; Information Commission takes over
Sections 118-119 commence: office of Information Commissioner abolished and functions transferred to the Information Commission (Commencement No. 9 Regulations 2026).
October 20261 deadline
PA 26-64 (SB 4) amendments take effect
Prohibits controllers and third parties from selling precise geolocation data and enacts data broker and other consumer protection provisions.
December 20264 deadlines
- EU AI ActEuropean Union
New bans on sexual deepfakes and CSAM generation; Art 50(2) grace period ends
New Art 5(1)(ba)/(bb) prohibitions on AI systems that generate non-consensual intimate imagery of identifiable persons or child sexual abuse material apply. Generative AI systems placed on the market before 2 Aug 2026 must comply with the Art 50(2) marking duty by this date (new Art 111(4)).
- Product Liability DirectiveEuropean Union
Transposition deadline; old PLD repealed
Member States must transpose by 9 Dec 2026 (Art 22). Directive 85/374/EEC is repealed from that date but still applies to products placed on the market before it (Art 21).
Children's Online Privacy Code must be registered
OAIC must develop and register the Children's Online Privacy Code within 24 months of Royal Assent.
Automated decision-making transparency applies
Privacy policies must disclose the kinds of personal information used in substantially automated decisions that significantly affect individuals (24 months after assent).
January 20278 deadlines
Large online platform and hosting platform duties
Large online platforms and GenAI hosting platforms must meet the provenance duties added by AB 853.
First OES anonymized incident report and CDT definition review
OES begins publishing annual anonymized incident summaries and the Department of Technology begins annual review of the act's definitions; the CalCompute framework report is due to the Legislature.
ADMT requirements compliance date
Businesses using ADMT for significant decisions must comply with Article 11 (pre-use notice, opt-out, access rights) by this date (11 CCR 7200(b)).
Browsers must support opt-out preference signal (AB 566)
Businesses that develop or maintain a browser must include consumer-configurable functionality to send an opt-out preference signal (Civ. Code 1798.136, operative Jan 1, 2027).
ADMT obligations apply
Developer documentation, consumer notices, post-adverse-outcome disclosure, correction and human-review rights take effect.
AG rules due
Attorney General must adopt rules clarifying the post-adverse-outcome disclosure requirements.
Data broker registration required
Data brokers may not sell or license brokered personal data in Connecticut unless registered with the Department of Consumer Protection ($2,500 initial fee).
RAISE Act takes effect
Transparency reports, frontier AI frameworks, incident reporting and DFS disclosure filings apply.
March 20271 deadline
Transition ends for existing AI systems (general)
Existing AI systems in most sectors must comply (12-month transition).
July 20272 deadlines
First annual report to Office of Suicide Prevention
Operators begin annual reporting on crisis referrals and detection protocols.
Scheduled repeal of Title 13, Ch. 72
SB 332 extends the AI Policy Act repeal date from May 1, 2025 to July 1, 2027.
August 20271 deadline
- EU AI ActEuropean Union
Legacy GPAI models must comply; national AI sandboxes operational
Providers of GPAI models placed on the market before 2 Aug 2025 must comply (Art 111(3)). Each Member State must have at least one national AI regulatory sandbox operational (Art 57(1) as amended by the Omnibus).
September 20271 deadline
Transition ends for existing AI systems in health, education and finance
Existing AI systems in healthcare, education and finance must comply (18-month transition).
December 20272 deadlines
- EU AI ActEuropean Union
High-risk obligations apply to Annex III systems
Chapter III Sections 1-3 (high-risk requirements and provider/deployer obligations) apply to AI systems classified high-risk under Art 6(2) and Annex III (employment, credit scoring, education, biometrics, essential services and similar). Deferred from 2 Aug 2026 by Regulation (EU) 2026/1744.
Risk assessments for pre-existing processing due
Risk assessments must be completed and documented for high-risk processing that began before Jan 1, 2026 and continues after (11 CCR 7155(b)).
January 20282 deadlines
Capture device manufacturer duties
Capture device manufacturer provenance requirements become operative.
Vermont Data Privacy and Online Surveillance Act takes effect
All obligations under Act 145 apply (sec. 4).
April 20282 deadlines
First risk assessment submission to CPPA
Businesses must submit required risk assessment information and attestation for assessments conducted in 2026 and 2027 (11 CCR 7157(a)(1)); annually by April 1 thereafter.
Cybersecurity audit due: revenue over $100M
First cybersecurity audit report (covering Jan 1, 2027 - Jan 1, 2028) and certification due for businesses with 2026 annual gross revenue over $100M (11 CCR 7121(a)(1)).
August 20281 deadline
- EU AI ActEuropean Union
High-risk obligations apply to Annex I product-embedded systems
Chapter III Sections 1-3 apply to AI systems classified high-risk under Art 6(1) and Annex I (safety components of products covered by EU harmonisation legislation). Deferred from 2 Aug 2027 by Regulation (EU) 2026/1744.
October 20281 deadline
Data brokers must process state deletion mechanism requests
Registered data brokers must access the DCP accessible deletion mechanism at least every 45 days and process deletion requests.
April 20291 deadline
Cybersecurity audit due: revenue $50M-$100M
First cybersecurity audit report (covering 2028) due for businesses with 2027 annual gross revenue between $50M and $100M (11 CCR 7121(a)(2)).
June 20291 deadline
Mandatory 60-day cure period expires
The AG's duty to issue a cure notice before enforcement ends June 30, 2029 (Act 145 sec. 3).
January 20301 deadline
Mandatory cure period ends
The AG's obligation to offer a 60-day notice-and-cure period expires.
April 20301 deadline
Cybersecurity audit due: revenue under $50M
First cybersecurity audit report (covering 2029) due for covered businesses with 2028 annual gross revenue under $50M (11 CCR 7121(a)(3)); annual by April 1 thereafter.
August 20301 deadline
- EU AI ActEuropean Union
Public-authority high-risk systems must comply
Providers and deployers of high-risk AI systems intended for use by public authorities that were placed on the market before the Chapter III application date must comply (Art 111(2), as replaced by the Omnibus).
December 20301 deadline
Past deadlines
August 20263 deadlines
- EU AI ActEuropean Union
General application: transparency obligations, GPAI fines, most other rules
The AI Act's general date of application. Article 50 transparency obligations (chatbot disclosure, deepfake labelling, machine-readable marking of synthetic content) and Commission fines on GPAI providers (Art 101) apply. Not deferred by the Omnibus.
Covered provider duties apply
Detection tool, manifest and latent disclosures, and license-revocation duties become operative.
Profiling impact assessments apply
Impact assessment requirements apply to profiling activities created or generated on or after Aug 1, 2026 (Conn. Gen. Stat. 42-522 as amended).
July 20263 deadlines
2026 APPI amendment act promulgated
Amendment enacted by the Diet on 10 July 2026 and promulgated; main provisions take effect by cabinet order within two years of promulgation.
PA 25-113 (SB 1295) amendments take effect
Thresholds drop to 35,000 consumers or any sensitive-data processing or data sale; expanded sensitive data, minors' protections, and LLM-training disclosure in privacy notices.
June 20263 deadlines
Delayed effective date (superseded)
SB 25B-004 date; superseded by SB 26-189 before it arrived, so no obligations applied.
Mandatory data protection complaints procedure
Controllers must have a process for data subject complaints (s.103 and Sch. 10), per Commencement No. 6 Regulations 2026, reg. 3.
IDHR withdraws and postpones proposed rules
IDHR withdraws the Subpart J proposal and postpones the June 10, 2026 hearing; no new date announced.
May 20263 deadlines
Platform notice-and-removal process required
Covered platforms must have a clear notice-and-removal process and remove valid reported content within 48 hours (Sec. 3, one year after enactment).
IDHR proposed notice rules published
IDHR publishes proposed Subpart J rules on AI notice in the Illinois Register.
SB 26-189 signed (repeal and reenact)
SB 26-189 replaces SB 24-205 with a narrower ADMT disclosure framework and moves the effective date to January 1, 2027.
March 20262 deadlines
Chapter amendment S8828 signed
Chapter amendment (ch. 96) finalizes the RAISE Act text.
AI Law takes effect
Risk classification, transparency and labeling obligations apply to new AI systems.
February 20262 deadlines
Stage 3: main data protection changes commence
Recognised legitimate interests, ADM reforms, DSAR changes, international transfer test, cookie exemptions and PECR fines at UK GDPR levels apply (Commencement No. 6 Regulations 2026, reg. 2).
Original effective date (superseded)
Original SB 24-205 date; postponed by SB 25B-004, so no obligations applied.
January 20269 deadlines
AI Basic Act and Enforcement Decree take effect
Transparency, labeling, high-impact AI, and domestic representative obligations apply (fines deferred during the grace period).
AI anti-discrimination and notice duties apply
Prohibition on discriminatory AI use and the employee notice requirement take effect.
2025 amendments take effect
Higher fines, first-violation fines, AI governance provisions and PIPL-alignment duties apply under the 28 Oct 2025 NPCSC Decision.
New CCPA regulations take effect
ADMT, risk assessment, cybersecurity audit and updated CCPA regulations become effective; risk assessments required for new high-risk processing.
Frontier developer obligations apply
Frontier AI frameworks, transparency reports, critical safety incident reporting (15 days, or 24 hours for imminent risk of death or serious injury) and whistleblower protections apply.
Chatbot safeguards apply
AI disclosure, suicide and self-harm protocols, and minor protections apply.
Original operative date (superseded)
Original SB 942 date; delayed to August 2, 2026 by AB 853.
Training-data documentation due
Documentation must be posted for GenAI systems released since January 1, 2022, and before each later release or substantial modification.
December 20251 deadline
RAISE Act signed
Governor Hochul signs the RAISE Act with an agreed chapter amendment.
October 20252 deadlines
SB 243 signed
SB 243 chaptered (ch. 677).
AB 853 signed
AB 853 (ch. 674) delays the operative date and adds platform and device duties.
September 20254 deadlines
SB 53 signed
Governor Newsom signs SB 53 (chapter 138).
ADMT, risk assessment and cybersecurity audit regulations approved
OAL approves the CCPA Updates, Cybersecurity Audit, Risk Assessment, ADMT and Insurance regulations and files them with the Secretary of State.
AI Promotion Act fully in force
Provisions establishing the AI Strategy Headquarters and AI Basic Plan take effect.
AI content labeling measures and GB 45438-2025 take effect
Explicit and implicit labeling duties for AI-generated content and platform detection duties apply.
August 20253 deadlines
SB 25B-004 delays the act
Special-session bill pushes the SB 24-205 effective date from February 1, 2026 to June 30, 2026.
Stage 1 commencement
Technical data protection provisions, ICO statutory objects, Smart Data framework (Part 1) and AI/copyright reporting duties commence (Commencement No. 1 Regulations 2025).
- EU AI ActEuropean Union
GPAI, governance, notified bodies and penalties apply
Chapter III Section 4 (notifying authorities), Chapter V (general-purpose AI model obligations), Chapter VII (governance), Chapter XII (penalties, except Art 101) and Art 78 apply (Art 113(b)).
June 20254 deadlines
Royal Assent
The Act receives Royal Assent; commencement staged by regulations.
Statutory tort for serious invasions of privacy commences
Individuals can sue for serious invasions of privacy (Schedule 2), 6 months after Royal Assent.
AI Promotion Act promulgated and partly in force
Most provisions, including basic principles and stakeholder duties, take effect on promulgation.
May 20251 deadline
Criminal provisions effective on enactment
Publishing or threatening to publish non-consensual intimate images, including digital forgeries, became a federal crime upon signature.