A free, continuously-updated calendar of AI-law deadlines, milestones, and enforcement dates — EU AI Act, GDPR, US state laws, ISO/NIST — the same catalog that powers the Workbench's Regulatory Horizon tool, published for anyone to check.
Deadline
2026-12-02 · Upcoming (100d)
EU AI Act (Digital Omnibus) · EU
The Digital Omnibus adds a prohibition on AI systems for non-consensual intimate imagery/CSAM and ends the synthetic-content marking grace period for pre-existing systems.
Action: Confirm generation guardrails block NCII/CSAM and that legacy systems mark synthetic content.
Requirements, status & controls →
Deadline
2027-01-01 · Upcoming (130d)
CPPA (California) · US
The CPPA ADMT and risk-assessment regulations took legal effect 1 Jan 2026, but businesses using automated decision-making technology for significant decisions must be compliant from 1 Jan 2027; risk assessments covering pre-existing processing are due 31 Dec 2027 (first submission to the CPPA 1 Apr 2028).
Action: Complete an ADMT risk assessment and ready significant-decision workflows for the 2027 compliance dates.
Requirements, status & controls →
Deadline
2027-01-01 · Upcoming (130d)
Colorado · US
Duties around consequential automated decisions — transparency, notice, and risk management. Replaced the original Colorado AI Act (SB 24-205), which was repealed in May 2026 before taking effect.
Action: Map consequential-decision systems and prepare consumer notices.
Requirements, status & controls →
Deadline
2027-04-01 · Upcoming (220d)
CPPA (California) · US
Consumers gain opt-out and pre-use notice rights for covered automated decisions.
Action: Build opt-out handling and pre-use notices into the product.
Requirements, status & controls →
Deadline
2027-05-01 · Upcoming (250d)
OSFI · CA
Federally regulated financial institutions must manage model risk across the lifecycle — inventory, risk-based materiality, independent validation, monitoring and human oversight — explicitly covering AI/ML models.
Action: Stand up or extend a model risk-management framework and validation function covering AI/ML before 1 May 2027.
Requirements, status & controls →
Deadline
2027-12-02 · Upcoming (465d)
EU AI Act · EU
Providers of high-risk systems must report serious incidents to authorities within 15 days (10 days on a death; 2 days for widespread infringement or critical-infrastructure disruption).
Action: Stand up an incident-detection, triage and reporting playbook with those clocks.
Requirements, status & controls →
Deadline
2027-12-02 · Upcoming (465d)
EU AI Act · EU
Full high-risk regime (risk management, data governance, logging, human oversight, accuracy, conformity assessment, registration). Moved from Aug 2026 to 2 Dec 2027 by the Digital Omnibus — Regulation (EU) 2026/1744, published in the Official Journal 24 July 2026 and in force since 27 July 2026, so this date is settled law.
Action: Start the Annex IV technical file, risk-management system, and conformity plan now.
Requirements, status & controls →
Deadline
2028-08-02 · Upcoming (709d)
EU AI Act · EU
High-risk AI embedded in regulated products (machinery, medical devices, vehicles) must comply. Moved from Aug 2027 to 2 Aug 2028 by the Digital Omnibus — Regulation (EU) 2026/1744, in force since 27 July 2026.
Action: If your AI is a safety component of a regulated product, fold it into the sectoral conformity procedure.
Requirements, status & controls →
Enforcement
2026-08-02 · Recently in force
EU AI Act · EU
Now live. Chatbots must disclose they are AI; deepfakes and emotion-recognition/biometric-categorisation uses must be disclosed. The Commission adopted final Art. 50 guidelines on 20 July 2026, and the AI Office's enforcement powers over GPAI providers (fines up to €15M or 3% of turnover) became applicable the same day. Providers' machine-readable marking of synthetic content under Art. 50(2) has a grace period to 2 Dec 2026.
Action: These duties are already binding — audit your live products for AI disclosure now, and close the Art. 50(2) marking gap before 2 Dec 2026.
Requirements, status & controls →
Deadline
2026-07-21 · Recently in force
CFPB · US
The CFPB removed the ECOA "effects test" — but disparate impact remains actionable under the Fair Housing Act, DOJ and state law, and the rule faces litigation.
Action: Keep fair-lending disparate-impact testing; treat ECOA disparate impact as contested / jurisdiction-dependent, not eliminated.
Requirements, status & controls →
Deadline
2026-06-24 · Recently in force
Treasury Board of Canada · CA
Federal automated administrative-decision systems must meet the fourth-review Directive: a published Algorithmic Impact Assessment, notice/explanation, recourse, and human intervention scaled to impact level.
Action: If you operate or sell federal ADM systems, complete and publish an AIA and wire in the scaled safeguards.
Requirements, status & controls →
Proposal
2026-06-15 · Recently in force
Parliament of Canada · CA
A proposed PIPEDA successor (first reading Jun 2026) would add automated-decision transparency duties and a Data Protection Commission with binding orders and penalties up to $10M or 3% of global revenue. Not yet law — AIDA was not revived.
Action: Monitor Bill C-36; keep PIPEDA + the OPC generative-AI principles as the current federal baseline.
Requirements, status & controls →
Guidance
2026-04-17 · Recently in force
Fed / OCC / FDIC · US
Modernised interagency MRM guidance for banks >$30B; supervised ML is in scope, generative & agentic AI are explicitly out of scope pending an interagency RFI.
Action: Update your model inventory, tiering and validation program to SR 26-2; track the forthcoming AI RFI for GenAI/agentic.
Requirements, status & controls →
Guidance
2026-02-19 · In force
US Treasury + Cyber Risk Institute · US
A ~230 control-objective finance operationalisation of the NIST AI RMF, crosswalked to SR 26-2 — the emerging US finance-sector AI control baseline.
Action: Adopt the FS AI RMF control objectives and crosswalk them to your NIST / ISO 42001 program.
Requirements, status & controls →
Deadline
2026-01-22 · In force
South Korea (MSIT) · KR
High-impact AI needs pre-deployment determination, explanations, human oversight and impact assessment; GenAI output must be labelled; large foreign providers need a domestic representative.
Action: Check Korean exposure: high-impact determination, labelling, and local-representative thresholds.
Requirements, status & controls →
Deadline
2026-01-01 · In force
Illinois · US
Employers may not use AI that discriminates in employment decisions (including via zip-code proxies) and must notify employees when AI is used.
Action: Test employment AI for disparate impact and add employee notices.
Requirements, status & controls →
Deadline
2026-01-01 · In force
California · US
Generative-AI developers must publish documentation about the datasets used to train the system.
Action: Prepare a public training-data summary for any GenAI you develop.
Requirements, status & controls →
Deadline
2026-01-01 · In force
California · US
Large frontier-model developers must publish a safety framework and transparency reports and report critical incidents to Cal OES within 15 days (24 hours if imminent risk).
Action: If you train frontier-scale models, stand up the safety framework and incident-report channel.
Requirements, status & controls →
Deadline
2026-01-01 · In force
Texas · US
Bans intentionally harmful AI uses and adds duties for consequential decisions and government deployments.
Action: Review consequential-decision use cases for Texas exposure.
Requirements, status & controls →
Deadline
2026-01-01 · In force
Ontario (ESA) · CA
Employers with 25+ employees must state in publicly advertised job postings whether AI is used to screen, assess or select applicants (ESA fines up to $100,000).
Action: Add an AI-use statement to Ontario job postings that involve automated screening.
Requirements, status & controls →
Deadline
2025-08-02 · In force
EU AI Act · EU
GPAI providers owe transparency, technical documentation, copyright policy, and systemic-risk duties for capable models.
Action: Inventory GPAI/foundation models you build or rely on and keep model documentation.
Requirements, status & controls →
Enforcement
2025-08-02 · In force
EU AI Act · EU
National competent authorities and fines (up to 7% of global turnover for prohibited use) become enforceable.
Action: Confirm your EU market roles (provider/deployer) and an accountable owner.
Requirements, status & controls →
Guidance
2025-07-10 · In force
EU AI Act · EU
The final GPAI Code of Practice (Transparency, Copyright, Safety & Security chapters) gives providers a voluntary route to demonstrate compliance ahead of harmonised standards.
Action: Track and consider adhering to the GPAI code of practice; use its Model Documentation Form.
Requirements, status & controls →
Deadline
2025-02-02 · In force
EU AI Act · EU
Eight unacceptable-risk practices (social scoring, manipulative AI, untargeted face-scraping, most real-time biometric ID) are banned.
Action: Confirm none of your use cases fall under a prohibited practice.
Requirements, status & controls →
Deadline
2025-01-17 · In force
EU (EBA/ESMA/EIOPA) · EU
Financial entities must run an ICT risk-management framework, keep a register of ICT/AI third-party arrangements, report major ICT incidents and perform resilience testing.
Action: Fold AI/cloud systems into your DORA ICT risk framework, third-party register and incident-reporting playbook.
Requirements, status & controls →
Guidance
2024-07-26 · In force
NIST · GLOBAL
Companion profile mapping GenAI-specific risks to the Govern/Map/Measure/Manage functions.
Action: Map your GenAI risks against the profile’s suggested actions.
Requirements, status & controls →
Deadline
2024-05-17 · In force
PRA / Bank of England · UK
Banks with internal-model approval must apply the five MRM principles — identification/tiering, governance, development, independent validation, mitigants — to AI/ML models.
Action: Map AI/ML models into your SS1/23 model inventory and validation cycle.
Requirements, status & controls →
Milestone
2023-12-18 · In force
ISO/IEC · GLOBAL
The first certifiable AI management-system standard — an auditable backbone for an AI governance program.
Action: Consider an AIMS (policy, impact assessment, controls, monitoring) toward certification.
Requirements, status & controls →
Enforcement
2023-09-22 · In force
Quebec (CAI) · CA
Decisions based exclusively on automated processing require notice, disclosure of the personal information and principal factors used, and a chance to have a human review the decision. Penalties reach $25M or 4% of worldwide turnover.
Action: Add automated-decision notices, a factors/parameters disclosure, and a human-review path for Quebec residents.
Requirements, status & controls →
Enforcement
2023-07-05 · In force
NYC · US
Automated employment decision tools require an annual independent bias audit and candidate notice.
Action: Commission an annual third-party bias audit and post the results.
Requirements, status & controls →
Enforcement
2018-05-25 · In force
EU GDPR · EU
Solely-automated decisions with legal/significant effect require safeguards incl. human review.
Action: Provide a meaningful human-review and contest path; run a DPIA.
Requirements, status & controls →