Free Consultation
Observatory

AI Regulatory Deadlines

A free, continuously-updated calendar of AI-law deadlines, milestones, and enforcement dates — EU AI Act, GDPR, US state laws, ISO/NIST — the same catalog that powers the Workbench's Regulatory Horizon tool, published for anyone to check.

All 31 dated obligations we track.

Put these in your calendar Subscribe → Download .ics

Subscribing keeps it current: new deadlines our agents publish appear in your calendar on their own, with a reminder 30 days ahead.

Deadline 2027-01-01 · Upcoming (130d)

California CPPA — ADMT compliance required

CPPA (California) · US

The CPPA ADMT and risk-assessment regulations took legal effect 1 Jan 2026, but businesses using automated decision-making technology for significant decisions must be compliant from 1 Jan 2027; risk assessments covering pre-existing processing are due 31 Dec 2027 (first submission to the CPPA 1 Apr 2028).

Action: Complete an ADMT risk assessment and ready significant-decision workflows for the 2027 compliance dates.

Requirements, status & controls →
Deadline 2027-01-01 · Upcoming (130d)

Colorado ADMT Act (SB 26-189) effective

Colorado · US

Duties around consequential automated decisions — transparency, notice, and risk management. Replaced the original Colorado AI Act (SB 24-205), which was repealed in May 2026 before taking effect.

Action: Map consequential-decision systems and prepare consumer notices.

Requirements, status & controls →
Deadline 2027-12-02 · Upcoming (465d)

EU AI Act — Annex III high-risk obligations apply

EU AI Act · EU

Full high-risk regime (risk management, data governance, logging, human oversight, accuracy, conformity assessment, registration). Moved from Aug 2026 to 2 Dec 2027 by the Digital Omnibus — Regulation (EU) 2026/1744, published in the Official Journal 24 July 2026 and in force since 27 July 2026, so this date is settled law.

Action: Start the Annex IV technical file, risk-management system, and conformity plan now.

Requirements, status & controls →
Deadline 2028-08-02 · Upcoming (709d)

EU AI Act — Annex I embedded high-risk obligations apply

EU AI Act · EU

High-risk AI embedded in regulated products (machinery, medical devices, vehicles) must comply. Moved from Aug 2027 to 2 Aug 2028 by the Digital Omnibus — Regulation (EU) 2026/1744, in force since 27 July 2026.

Action: If your AI is a safety component of a regulated product, fold it into the sectoral conformity procedure.

Requirements, status & controls →
Enforcement 2026-08-02 · Recently in force

EU AI Act — Art. 50 transparency obligations in force

EU AI Act · EU

Now live. Chatbots must disclose they are AI; deepfakes and emotion-recognition/biometric-categorisation uses must be disclosed. The Commission adopted final Art. 50 guidelines on 20 July 2026, and the AI Office's enforcement powers over GPAI providers (fines up to €15M or 3% of turnover) became applicable the same day. Providers' machine-readable marking of synthetic content under Art. 50(2) has a grace period to 2 Dec 2026.

Action: These duties are already binding — audit your live products for AI disclosure now, and close the Art. 50(2) marking gap before 2 Dec 2026.

Requirements, status & controls →
Proposal 2026-06-15 · Recently in force

Federal Bill C-36 — privacy reform (PPCDA) introduced

Parliament of Canada · CA

A proposed PIPEDA successor (first reading Jun 2026) would add automated-decision transparency duties and a Data Protection Commission with binding orders and penalties up to $10M or 3% of global revenue. Not yet law — AIDA was not revived.

Action: Monitor Bill C-36; keep PIPEDA + the OPC generative-AI principles as the current federal baseline.

Requirements, status & controls →
Deadline 2026-01-22 · In force

South Korea AI Basic Act in force

South Korea (MSIT) · KR

High-impact AI needs pre-deployment determination, explanations, human oversight and impact assessment; GenAI output must be labelled; large foreign providers need a domestic representative.

Action: Check Korean exposure: high-impact determination, labelling, and local-representative thresholds.

Requirements, status & controls →
Guidance 2025-07-10 · In force

EU AI Act — GPAI Code of Practice published

EU AI Act · EU

The final GPAI Code of Practice (Transparency, Copyright, Safety & Security chapters) gives providers a voluntary route to demonstrate compliance ahead of harmonised standards.

Action: Track and consider adhering to the GPAI code of practice; use its Model Documentation Form.

Requirements, status & controls →
Deadline 2025-01-17 · In force

DORA — Digital Operational Resilience Act applies

EU (EBA/ESMA/EIOPA) · EU

Financial entities must run an ICT risk-management framework, keep a register of ICT/AI third-party arrangements, report major ICT incidents and perform resilience testing.

Action: Fold AI/cloud systems into your DORA ICT risk framework, third-party register and incident-reporting playbook.

Requirements, status & controls →
Enforcement 2023-09-22 · In force

Quebec Law 25 — automated-decision transparency (s. 12.1) in force

Quebec (CAI) · CA

Decisions based exclusively on automated processing require notice, disclosure of the personal information and principal factors used, and a chance to have a human review the decision. Penalties reach $25M or 4% of worldwide turnover.

Action: Add automated-decision notices, a factors/parameters disclosure, and a human-review path for Quebec residents.

Requirements, status & controls →