BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//autogovern.io//Regulatory Horizon//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:AI Regulatory Deadlines
X-WR-CALDESC:Dated AI-regulation obligations tracked by autogovern.io. Upda
 tes automatically as new deadlines are published.
REFRESH-INTERVAL;VALUE=DURATION:PT12H
X-PUBLISHED-TTL:PT12H
BEGIN:VEVENT
UID:eu-ncii-watermark@autogovern.io
DTSTAMP:20260824T050519Z
DTSTART;VALUE=DATE:20261202
DTEND;VALUE=DATE:20261203
SUMMARY:EU AI Act — NCII/CSAM ban + end of marking grace period
DESCRIPTION:The Digital Omnibus adds a prohibition on AI systems for non-co
 nsensual intimate imagery/CSAM and ends the synthetic-content marking grac
 e period for pre-existing systems.\n\nAction: Confirm generation guardrail
 s block NCII/CSAM and that legacy systems mark synthetic content.\n\nAutho
 rity: EU AI Act (Digital Omnibus)\n\nhttps://autogovern.io/deadline/eu-nci
 i-watermark
URL:https://autogovern.io/deadline/eu-ncii-watermark
TRANSP:TRANSPARENT
CATEGORIES:Deadline
BEGIN:VALARM
ACTION:DISPLAY
TRIGGER:-P30D
DESCRIPTION:EU AI Act — NCII/CSAM ban + end of marking grace period — i
 n 30 days
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:ca-admt@autogovern.io
DTSTAMP:20260824T050519Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:California CPPA — ADMT compliance required
DESCRIPTION:The CPPA ADMT and risk-assessment regulations took legal effect
  1 Jan 2026\, but businesses using automated decision-making technology fo
 r significant decisions must be compliant from 1 Jan 2027\; risk assessmen
 ts covering pre-existing processing are due 31 Dec 2027 (first submission 
 to the CPPA 1 Apr 2028).\n\nAction: Complete an ADMT risk assessment and r
 eady significant-decision workflows for the 2027 compliance dates.\n\nAuth
 ority: CPPA (California)\n\nhttps://autogovern.io/deadline/ca-admt
URL:https://autogovern.io/deadline/ca-admt
TRANSP:TRANSPARENT
CATEGORIES:Deadline
BEGIN:VALARM
ACTION:DISPLAY
TRIGGER:-P30D
DESCRIPTION:California CPPA — ADMT compliance required — in 30 days
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:co-ai-act@autogovern.io
DTSTAMP:20260824T050519Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:Colorado ADMT Act (SB 26-189) effective
DESCRIPTION:Duties around consequential automated decisions — transparenc
 y\, notice\, and risk management. Replaced the original Colorado AI Act (S
 B 24-205)\, which was repealed in May 2026 before taking effect.\n\nAction
 : Map consequential-decision systems and prepare consumer notices.\n\nAuth
 ority: Colorado\n\nhttps://autogovern.io/deadline/co-ai-act
URL:https://autogovern.io/deadline/co-ai-act
TRANSP:TRANSPARENT
CATEGORIES:Deadline
BEGIN:VALARM
ACTION:DISPLAY
TRIGGER:-P30D
DESCRIPTION:Colorado ADMT Act (SB 26-189) effective — in 30 days
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:ca-admt-optout@autogovern.io
DTSTAMP:20260824T050519Z
DTSTART;VALUE=DATE:20270401
DTEND;VALUE=DATE:20270402
SUMMARY:California ADMT — opt-out & pre-use notice phase
DESCRIPTION:Consumers gain opt-out and pre-use notice rights for covered au
 tomated decisions.\n\nAction: Build opt-out handling and pre-use notices i
 nto the product.\n\nAuthority: CPPA (California)\n\nhttps://autogovern.io/
 deadline/ca-admt-optout
URL:https://autogovern.io/deadline/ca-admt-optout
TRANSP:TRANSPARENT
CATEGORIES:Deadline
BEGIN:VALARM
ACTION:DISPLAY
TRIGGER:-P30D
DESCRIPTION:California ADMT — opt-out & pre-use notice phase — in 30 da
 ys
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:ca-osfi-e23@autogovern.io
DTSTAMP:20260824T050519Z
DTSTART;VALUE=DATE:20270501
DTEND;VALUE=DATE:20270502
SUMMARY:OSFI Guideline E-23 — Model Risk Management (incl. AI/ML) effecti
 ve
DESCRIPTION:Federally regulated financial institutions must manage model ri
 sk across the lifecycle — inventory\, risk-based materiality\, independe
 nt validation\, monitoring and human oversight — explicitly covering AI/
 ML models.\n\nAction: Stand up or extend a model risk-management framework
  and validation function covering AI/ML before 1 May 2027.\n\nAuthority: O
 SFI\n\nhttps://autogovern.io/deadline/ca-osfi-e23
URL:https://autogovern.io/deadline/ca-osfi-e23
TRANSP:TRANSPARENT
CATEGORIES:Deadline
BEGIN:VALARM
ACTION:DISPLAY
TRIGGER:-P30D
DESCRIPTION:OSFI Guideline E-23 — Model Risk Management (incl. AI/ML) eff
 ective — in 30 days
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:eu-highrisk@autogovern.io
DTSTAMP:20260824T050519Z
DTSTART;VALUE=DATE:20271202
DTEND;VALUE=DATE:20271203
SUMMARY:EU AI Act — Annex III high-risk obligations apply
DESCRIPTION:Full high-risk regime (risk management\, data governance\, logg
 ing\, human oversight\, accuracy\, conformity assessment\, registration). 
 Moved from Aug 2026 to 2 Dec 2027 by the Digital Omnibus — Regulation (E
 U) 2026/1744\, published in the Official Journal 24 July 2026 and in force
  since 27 July 2026\, so this date is settled law.\n\nAction: Start the An
 nex IV technical file\, risk-management system\, and conformity plan now.\
 n\nAuthority: EU AI Act\n\nhttps://autogovern.io/deadline/eu-highrisk
URL:https://autogovern.io/deadline/eu-highrisk
TRANSP:TRANSPARENT
CATEGORIES:Deadline
BEGIN:VALARM
ACTION:DISPLAY
TRIGGER:-P30D
DESCRIPTION:EU AI Act — Annex III high-risk obligations apply — in 30 d
 ays
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:eu-incident@autogovern.io
DTSTAMP:20260824T050519Z
DTSTART;VALUE=DATE:20271202
DTEND;VALUE=DATE:20271203
SUMMARY:EU AI Act — serious-incident reporting (Art. 73)
DESCRIPTION:Providers of high-risk systems must report serious incidents to
  authorities within 15 days (10 days on a death\; 2 days for widespread in
 fringement or critical-infrastructure disruption).\n\nAction: Stand up an 
 incident-detection\, triage and reporting playbook with those clocks.\n\nA
 uthority: EU AI Act\n\nhttps://autogovern.io/deadline/eu-incident
URL:https://autogovern.io/deadline/eu-incident
TRANSP:TRANSPARENT
CATEGORIES:Deadline
BEGIN:VALARM
ACTION:DISPLAY
TRIGGER:-P30D
DESCRIPTION:EU AI Act — serious-incident reporting (Art. 73) — in 30 da
 ys
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:eu-annex1@autogovern.io
DTSTAMP:20260824T050519Z
DTSTART;VALUE=DATE:20280802
DTEND;VALUE=DATE:20280803
SUMMARY:EU AI Act — Annex I embedded high-risk obligations apply
DESCRIPTION:High-risk AI embedded in regulated products (machinery\, medica
 l devices\, vehicles) must comply. Moved from Aug 2027 to 2 Aug 2028 by th
 e Digital Omnibus — Regulation (EU) 2026/1744\, in force since 27 July 2
 026.\n\nAction: If your AI is a safety component of a regulated product\, 
 fold it into the sectoral conformity procedure.\n\nAuthority: EU AI Act\n\
 nhttps://autogovern.io/deadline/eu-annex1
URL:https://autogovern.io/deadline/eu-annex1
TRANSP:TRANSPARENT
CATEGORIES:Deadline
BEGIN:VALARM
ACTION:DISPLAY
TRIGGER:-P30D
DESCRIPTION:EU AI Act — Annex I embedded high-risk obligations apply — 
 in 30 days
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:eu-art50@autogovern.io
DTSTAMP:20260824T050519Z
DTSTART;VALUE=DATE:20260802
DTEND;VALUE=DATE:20260803
SUMMARY:EU AI Act — Art. 50 transparency obligations in force
DESCRIPTION:Now live. Chatbots must disclose they are AI\; deepfakes and em
 otion-recognition/biometric-categorisation uses must be disclosed. The Com
 mission adopted final Art. 50 guidelines on 20 July 2026\, and the AI Offi
 ce's enforcement powers over GPAI providers (fines up to €15M or 3% of t
 urnover) became applicable the same day. Providers' machine-readable marki
 ng of synthetic content under Art. 50(2) has a grace period to 2 Dec 2026.
 \n\nAction: These duties are already binding — audit your live products 
 for AI disclosure now\, and close the Art. 50(2) marking gap before 2 Dec 
 2026.\n\nAuthority: EU AI Act\n\nhttps://autogovern.io/deadline/eu-art50
URL:https://autogovern.io/deadline/eu-art50
TRANSP:TRANSPARENT
CATEGORIES:Enforcement
BEGIN:VALARM
ACTION:DISPLAY
TRIGGER:-P30D
DESCRIPTION:EU AI Act — Art. 50 transparency obligations in force — in 
 30 days
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:us-regb-di@autogovern.io
DTSTAMP:20260824T050519Z
DTSTART;VALUE=DATE:20260721
DTEND;VALUE=DATE:20260722
SUMMARY:Reg B rule removing the ECOA disparate-impact effects test effectiv
 e
DESCRIPTION:The CFPB removed the ECOA "effects test" — but disparate impa
 ct remains actionable under the Fair Housing Act\, DOJ and state law\, and
  the rule faces litigation.\n\nAction: Keep fair-lending disparate-impact 
 testing\; treat ECOA disparate impact as contested / jurisdiction-dependen
 t\, not eliminated.\n\nAuthority: CFPB\n\nhttps://autogovern.io/deadline/u
 s-regb-di
URL:https://autogovern.io/deadline/us-regb-di
TRANSP:TRANSPARENT
CATEGORIES:Deadline
BEGIN:VALARM
ACTION:DISPLAY
TRIGGER:-P30D
DESCRIPTION:Reg B rule removing the ECOA disparate-impact effects test effe
 ctive — in 30 days
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:ca-tbs-adm@autogovern.io
DTSTAMP:20260824T050519Z
DTSTART;VALUE=DATE:20260624
DTEND;VALUE=DATE:20260625
SUMMARY:Federal ADM Directive — compliance deadline for existing systems
DESCRIPTION:Federal automated administrative-decision systems must meet the
  fourth-review Directive: a published Algorithmic Impact Assessment\, noti
 ce/explanation\, recourse\, and human intervention scaled to impact level.
 \n\nAction: If you operate or sell federal ADM systems\, complete and publ
 ish an AIA and wire in the scaled safeguards.\n\nAuthority: Treasury Board
  of Canada\n\nhttps://autogovern.io/deadline/ca-tbs-adm
URL:https://autogovern.io/deadline/ca-tbs-adm
TRANSP:TRANSPARENT
CATEGORIES:Deadline
BEGIN:VALARM
ACTION:DISPLAY
TRIGGER:-P30D
DESCRIPTION:Federal ADM Directive — compliance deadline for existing syst
 ems — in 30 days
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:ca-c36@autogovern.io
DTSTAMP:20260824T050519Z
DTSTART;VALUE=DATE:20260615
DTEND;VALUE=DATE:20260616
SUMMARY:Federal Bill C-36 — privacy reform (PPCDA) introduced
DESCRIPTION:A proposed PIPEDA successor (first reading Jun 2026) would add 
 automated-decision transparency duties and a Data Protection Commission wi
 th binding orders and penalties up to $10M or 3% of global revenue. Not ye
 t law — AIDA was not revived.\n\nAction: Monitor Bill C-36\; keep PIPEDA
  + the OPC generative-AI principles as the current federal baseline.\n\nAu
 thority: Parliament of Canada\n\nhttps://autogovern.io/deadline/ca-c36
URL:https://autogovern.io/deadline/ca-c36
TRANSP:TRANSPARENT
CATEGORIES:Proposal
BEGIN:VALARM
ACTION:DISPLAY
TRIGGER:-P30D
DESCRIPTION:Federal Bill C-36 — privacy reform (PPCDA) introduced — in 
 30 days
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:us-sr26-2@autogovern.io
DTSTAMP:20260824T050519Z
DTSTART;VALUE=DATE:20260417
DTEND;VALUE=DATE:20260418
SUMMARY:SR 26-2 — revised Model Risk Management guidance (supersedes SR 1
 1-7)
DESCRIPTION:Modernised interagency MRM guidance for banks >$30B\; supervise
 d ML is in scope\, generative & agentic AI are explicitly out of scope pen
 ding an interagency RFI.\n\nAction: Update your model inventory\, tiering 
 and validation program to SR 26-2\; track the forthcoming AI RFI for GenAI
 /agentic.\n\nAuthority: Fed / OCC / FDIC\n\nhttps://autogovern.io/deadline
 /us-sr26-2
URL:https://autogovern.io/deadline/us-sr26-2
TRANSP:TRANSPARENT
CATEGORIES:Guidance
BEGIN:VALARM
ACTION:DISPLAY
TRIGGER:-P30D
DESCRIPTION:SR 26-2 — revised Model Risk Management guidance (supersedes 
 SR 11-7) — in 30 days
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:us-fs-ai-rmf@autogovern.io
DTSTAMP:20260824T050519Z
DTSTART;VALUE=DATE:20260219
DTEND;VALUE=DATE:20260220
SUMMARY:Treasury/CRI Financial Services AI RMF released
DESCRIPTION:A ~230 control-objective finance operationalisation of the NIST
  AI RMF\, crosswalked to SR 26-2 — the emerging US finance-sector AI con
 trol baseline.\n\nAction: Adopt the FS AI RMF control objectives and cross
 walk them to your NIST / ISO 42001 program.\n\nAuthority: US Treasury + Cy
 ber Risk Institute\n\nhttps://autogovern.io/deadline/us-fs-ai-rmf
URL:https://autogovern.io/deadline/us-fs-ai-rmf
TRANSP:TRANSPARENT
CATEGORIES:Guidance
BEGIN:VALARM
ACTION:DISPLAY
TRIGGER:-P30D
DESCRIPTION:Treasury/CRI Financial Services AI RMF released — in 30 days
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:kr-ai-basic@autogovern.io
DTSTAMP:20260824T050519Z
DTSTART;VALUE=DATE:20260122
DTEND;VALUE=DATE:20260123
SUMMARY:South Korea AI Basic Act in force
DESCRIPTION:High-impact AI needs pre-deployment determination\, explanation
 s\, human oversight and impact assessment\; GenAI output must be labelled\
 ; large foreign providers need a domestic representative.\n\nAction: Check
  Korean exposure: high-impact determination\, labelling\, and local-repres
 entative thresholds.\n\nAuthority: South Korea (MSIT)\n\nhttps://autogover
 n.io/deadline/kr-ai-basic
URL:https://autogovern.io/deadline/kr-ai-basic
TRANSP:TRANSPARENT
CATEGORIES:Deadline
BEGIN:VALARM
ACTION:DISPLAY
TRIGGER:-P30D
DESCRIPTION:South Korea AI Basic Act in force — in 30 days
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:ca-ab2013@autogovern.io
DTSTAMP:20260824T050519Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:California AB 2013 — training-data transparency
DESCRIPTION:Generative-AI developers must publish documentation about the d
 atasets used to train the system.\n\nAction: Prepare a public training-dat
 a summary for any GenAI you develop.\n\nAuthority: California\n\nhttps://a
 utogovern.io/deadline/ca-ab2013
URL:https://autogovern.io/deadline/ca-ab2013
TRANSP:TRANSPARENT
CATEGORIES:Deadline
BEGIN:VALARM
ACTION:DISPLAY
TRIGGER:-P30D
DESCRIPTION:California AB 2013 — training-data transparency — in 30 day
 s
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:tx-traiga@autogovern.io
DTSTAMP:20260824T050519Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Texas TRAIGA — Responsible AI Governance Act effective
DESCRIPTION:Bans intentionally harmful AI uses and adds duties for conseque
 ntial decisions and government deployments.\n\nAction: Review consequentia
 l-decision use cases for Texas exposure.\n\nAuthority: Texas\n\nhttps://au
 togovern.io/deadline/tx-traiga
URL:https://autogovern.io/deadline/tx-traiga
TRANSP:TRANSPARENT
CATEGORIES:Deadline
BEGIN:VALARM
ACTION:DISPLAY
TRIGGER:-P30D
DESCRIPTION:Texas TRAIGA — Responsible AI Governance Act effective — in
  30 days
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:il-hb3773@autogovern.io
DTSTAMP:20260824T050519Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Illinois HB 3773 — AI in employment decisions
DESCRIPTION:Employers may not use AI that discriminates in employment decis
 ions (including via zip-code proxies) and must notify employees when AI is
  used.\n\nAction: Test employment AI for disparate impact and add employee
  notices.\n\nAuthority: Illinois\n\nhttps://autogovern.io/deadline/il-hb37
 73
URL:https://autogovern.io/deadline/il-hb3773
TRANSP:TRANSPARENT
CATEGORIES:Deadline
BEGIN:VALARM
ACTION:DISPLAY
TRIGGER:-P30D
DESCRIPTION:Illinois HB 3773 — AI in employment decisions — in 30 days
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:ca-sb53@autogovern.io
DTSTAMP:20260824T050519Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:California SB 53 — frontier AI transparency & incidents
DESCRIPTION:Large frontier-model developers must publish a safety framework
  and transparency reports and report critical incidents to Cal OES within 
 15 days (24 hours if imminent risk).\n\nAction: If you train frontier-scal
 e models\, stand up the safety framework and incident-report channel.\n\nA
 uthority: California\n\nhttps://autogovern.io/deadline/ca-sb53
URL:https://autogovern.io/deadline/ca-sb53
TRANSP:TRANSPARENT
CATEGORIES:Deadline
BEGIN:VALARM
ACTION:DISPLAY
TRIGGER:-P30D
DESCRIPTION:California SB 53 — frontier AI transparency & incidents — i
 n 30 days
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:ca-on-hiring@autogovern.io
DTSTAMP:20260824T050519Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Ontario — AI-in-hiring disclosure required in job postings
DESCRIPTION:Employers with 25+ employees must state in publicly advertised 
 job postings whether AI is used to screen\, assess or select applicants (E
 SA fines up to $100\,000).\n\nAction: Add an AI-use statement to Ontario j
 ob postings that involve automated screening.\n\nAuthority: Ontario (ESA)\
 n\nhttps://autogovern.io/deadline/ca-on-hiring
URL:https://autogovern.io/deadline/ca-on-hiring
TRANSP:TRANSPARENT
CATEGORIES:Deadline
BEGIN:VALARM
ACTION:DISPLAY
TRIGGER:-P30D
DESCRIPTION:Ontario — AI-in-hiring disclosure required in job postings 
 — in 30 days
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:eu-gpai@autogovern.io
DTSTAMP:20260824T050519Z
DTSTART;VALUE=DATE:20250802
DTEND;VALUE=DATE:20250803
SUMMARY:EU AI Act — general-purpose AI (GPAI) obligations apply
DESCRIPTION:GPAI providers owe transparency\, technical documentation\, cop
 yright policy\, and systemic-risk duties for capable models.\n\nAction: In
 ventory GPAI/foundation models you build or rely on and keep model documen
 tation.\n\nAuthority: EU AI Act\n\nhttps://autogovern.io/deadline/eu-gpai
URL:https://autogovern.io/deadline/eu-gpai
TRANSP:TRANSPARENT
CATEGORIES:Deadline
BEGIN:VALARM
ACTION:DISPLAY
TRIGGER:-P30D
DESCRIPTION:EU AI Act — general-purpose AI (GPAI) obligations apply — i
 n 30 days
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:eu-gov-penalties@autogovern.io
DTSTAMP:20260824T050519Z
DTSTART;VALUE=DATE:20250802
DTEND;VALUE=DATE:20250803
SUMMARY:EU AI Act — governance bodies & penalties live
DESCRIPTION:National competent authorities and fines (up to 7% of global tu
 rnover for prohibited use) become enforceable.\n\nAction: Confirm your EU 
 market roles (provider/deployer) and an accountable owner.\n\nAuthority: E
 U AI Act\n\nhttps://autogovern.io/deadline/eu-gov-penalties
URL:https://autogovern.io/deadline/eu-gov-penalties
TRANSP:TRANSPARENT
CATEGORIES:Enforcement
BEGIN:VALARM
ACTION:DISPLAY
TRIGGER:-P30D
DESCRIPTION:EU AI Act — governance bodies & penalties live — in 30 days
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:eu-codes-gpai@autogovern.io
DTSTAMP:20260824T050519Z
DTSTART;VALUE=DATE:20250710
DTEND;VALUE=DATE:20250711
SUMMARY:EU AI Act — GPAI Code of Practice published
DESCRIPTION:The final GPAI Code of Practice (Transparency\, Copyright\, Saf
 ety & Security chapters) gives providers a voluntary route to demonstrate 
 compliance ahead of harmonised standards.\n\nAction: Track and consider ad
 hering to the GPAI code of practice\; use its Model Documentation Form.\n\
 nAuthority: EU AI Act\n\nhttps://autogovern.io/deadline/eu-codes-gpai
URL:https://autogovern.io/deadline/eu-codes-gpai
TRANSP:TRANSPARENT
CATEGORIES:Guidance
BEGIN:VALARM
ACTION:DISPLAY
TRIGGER:-P30D
DESCRIPTION:EU AI Act — GPAI Code of Practice published — in 30 days
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:eu-prohibited@autogovern.io
DTSTAMP:20260824T050519Z
DTSTART;VALUE=DATE:20250202
DTEND;VALUE=DATE:20250203
SUMMARY:EU AI Act — prohibited practices in force
DESCRIPTION:Eight unacceptable-risk practices (social scoring\, manipulativ
 e AI\, untargeted face-scraping\, most real-time biometric ID) are banned.
 \n\nAction: Confirm none of your use cases fall under a prohibited practic
 e.\n\nAuthority: EU AI Act\n\nhttps://autogovern.io/deadline/eu-prohibited
URL:https://autogovern.io/deadline/eu-prohibited
TRANSP:TRANSPARENT
CATEGORIES:Deadline
BEGIN:VALARM
ACTION:DISPLAY
TRIGGER:-P30D
DESCRIPTION:EU AI Act — prohibited practices in force — in 30 days
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:eu-dora@autogovern.io
DTSTAMP:20260824T050519Z
DTSTART;VALUE=DATE:20250117
DTEND;VALUE=DATE:20250118
SUMMARY:DORA — Digital Operational Resilience Act applies
DESCRIPTION:Financial entities must run an ICT risk-management framework\, 
 keep a register of ICT/AI third-party arrangements\, report major ICT inci
 dents and perform resilience testing.\n\nAction: Fold AI/cloud systems int
 o your DORA ICT risk framework\, third-party register and incident-reporti
 ng playbook.\n\nAuthority: EU (EBA/ESMA/EIOPA)\n\nhttps://autogovern.io/de
 adline/eu-dora
URL:https://autogovern.io/deadline/eu-dora
TRANSP:TRANSPARENT
CATEGORIES:Deadline
BEGIN:VALARM
ACTION:DISPLAY
TRIGGER:-P30D
DESCRIPTION:DORA — Digital Operational Resilience Act applies — in 30 d
 ays
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:nist-genai@autogovern.io
DTSTAMP:20260824T050519Z
DTSTART;VALUE=DATE:20240726
DTEND;VALUE=DATE:20240727
SUMMARY:NIST AI RMF — Generative AI Profile published
DESCRIPTION:Companion profile mapping GenAI-specific risks to the Govern/Ma
 p/Measure/Manage functions.\n\nAction: Map your GenAI risks against the pr
 ofile’s suggested actions.\n\nAuthority: NIST\n\nhttps://autogovern.io/d
 eadline/nist-genai
URL:https://autogovern.io/deadline/nist-genai
TRANSP:TRANSPARENT
CATEGORIES:Guidance
BEGIN:VALARM
ACTION:DISPLAY
TRIGGER:-P30D
DESCRIPTION:NIST AI RMF — Generative AI Profile published — in 30 days
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:uk-pra-ss123@autogovern.io
DTSTAMP:20260824T050519Z
DTSTART;VALUE=DATE:20240517
DTEND;VALUE=DATE:20240518
SUMMARY:PRA SS1/23 — Model Risk Management principles effective
DESCRIPTION:Banks with internal-model approval must apply the five MRM prin
 ciples — identification/tiering\, governance\, development\, independent
  validation\, mitigants — to AI/ML models.\n\nAction: Map AI/ML models i
 nto your SS1/23 model inventory and validation cycle.\n\nAuthority: PRA / 
 Bank of England\n\nhttps://autogovern.io/deadline/uk-pra-ss123
URL:https://autogovern.io/deadline/uk-pra-ss123
TRANSP:TRANSPARENT
CATEGORIES:Deadline
BEGIN:VALARM
ACTION:DISPLAY
TRIGGER:-P30D
DESCRIPTION:PRA SS1/23 — Model Risk Management principles effective — i
 n 30 days
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:iso-42001@autogovern.io
DTSTAMP:20260824T050519Z
DTSTART;VALUE=DATE:20231218
DTEND;VALUE=DATE:20231219
SUMMARY:ISO/IEC 42001 — AI Management System certifiable
DESCRIPTION:The first certifiable AI management-system standard — an audi
 table backbone for an AI governance program.\n\nAction: Consider an AIMS (
 policy\, impact assessment\, controls\, monitoring) toward certification.\
 n\nAuthority: ISO/IEC\n\nhttps://autogovern.io/deadline/iso-42001
URL:https://autogovern.io/deadline/iso-42001
TRANSP:TRANSPARENT
CATEGORIES:Milestone
BEGIN:VALARM
ACTION:DISPLAY
TRIGGER:-P30D
DESCRIPTION:ISO/IEC 42001 — AI Management System certifiable — in 30 da
 ys
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:ca-qc-law25-adm@autogovern.io
DTSTAMP:20260824T050519Z
DTSTART;VALUE=DATE:20230922
DTEND;VALUE=DATE:20230923
SUMMARY:Quebec Law 25 — automated-decision transparency (s. 12.1) in forc
 e
DESCRIPTION:Decisions based exclusively on automated processing require not
 ice\, disclosure of the personal information and principal factors used\, 
 and a chance to have a human review the decision. Penalties reach $25M or 
 4% of worldwide turnover.\n\nAction: Add automated-decision notices\, a fa
 ctors/parameters disclosure\, and a human-review path for Quebec residents
 .\n\nAuthority: Quebec (CAI)\n\nhttps://autogovern.io/deadline/ca-qc-law25
 -adm
URL:https://autogovern.io/deadline/ca-qc-law25-adm
TRANSP:TRANSPARENT
CATEGORIES:Enforcement
BEGIN:VALARM
ACTION:DISPLAY
TRIGGER:-P30D
DESCRIPTION:Quebec Law 25 — automated-decision transparency (s. 12.1) in 
 force — in 30 days
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:nyc-ll144@autogovern.io
DTSTAMP:20260824T050519Z
DTSTART;VALUE=DATE:20230705
DTEND;VALUE=DATE:20230706
SUMMARY:NYC Local Law 144 — bias audits enforced (AEDT)
DESCRIPTION:Automated employment decision tools require an annual independe
 nt bias audit and candidate notice.\n\nAction: Commission an annual third-
 party bias audit and post the results.\n\nAuthority: NYC\n\nhttps://autogo
 vern.io/deadline/nyc-ll144
URL:https://autogovern.io/deadline/nyc-ll144
TRANSP:TRANSPARENT
CATEGORIES:Enforcement
BEGIN:VALARM
ACTION:DISPLAY
TRIGGER:-P30D
DESCRIPTION:NYC Local Law 144 — bias audits enforced (AEDT) — in 30 day
 s
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:gdpr-art22@autogovern.io
DTSTAMP:20260824T050519Z
DTSTART;VALUE=DATE:20180525
DTEND;VALUE=DATE:20180526
SUMMARY:GDPR Art. 22 — safeguards for automated decisions
DESCRIPTION:Solely-automated decisions with legal/significant effect requir
 e safeguards incl. human review.\n\nAction: Provide a meaningful human-rev
 iew and contest path\; run a DPIA.\n\nAuthority: EU GDPR\n\nhttps://autogo
 vern.io/deadline/gdpr-art22
URL:https://autogovern.io/deadline/gdpr-art22
TRANSP:TRANSPARENT
CATEGORIES:Enforcement
BEGIN:VALARM
ACTION:DISPLAY
TRIGGER:-P30D
DESCRIPTION:GDPR Art. 22 — safeguards for automated decisions — in 30 d
 ays
END:VALARM
END:VEVENT
END:VCALENDAR
