BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//AI News Today//AI Compliance Calendar//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:AI Compliance Deadlines — AI News Today
X-WR-CALDESC:Dated AI compliance obligations, each verified against its pr
 imary source.
X-PUBLISHED-TTL:PT12H
REFRESH-INTERVAL;VALUE=DURATION:PT12H
BEGIN:VEVENT
UID:vn|prime-minister-s-decision-no-33-2026-qd-ttg-of-30-june-2026-issuing
 -th|high-risk-ai-list-takes-effect-46-named-ai-systems-across-6|2026-08-1
 5@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20260815
DTEND;VALUE=DATE:20260816
SUMMARY:Vietnam: High-risk AI list takes effect: 46 named AI systems acros
 s 6 sectors become 'high-risk' under the Law on AI 134/2025/QH15\, trigge
 ring the strict-management duties (operating principles and compliance ro
 admap set by the Decision)
DESCRIPTION:High-risk AI list takes effect: 46 named AI systems across 6 s
 ectors become 'high-risk' under the Law on AI 134/2025/QH15\, triggering 
 the strict-management duties (operating principles and compliance roadmap
  set by the Decision)\nPrime Minister's Decision No. 33/2026/QD-TTg of 30
  June 2026 issuing the List of high-risk artificial intelligence systems 
 (Quyết định 33/2026/QĐ-TTg — Danh mục hệ thống trí tuệ n
 hân tạo có rủi ro cao)\nSigned 30 June 2026 by Deputy PM Hồ Quố
 c Dũng. Sectors: education\; ethnic and religious affairs\; health\; ban
 king\; legal proceedings (tố tụng)\; transport (transport alone accou
 nts for 31 of the 46 systems). The Decision sets both the operating princ
 iples and the compliance roadmap for systems on the list.\nApplies to: pr
 ovider\, deployer\nWho: all\nPenalty: State AI authority may require susp
 ension or termination of a system it finds poses a risk of serious harm\n
 Source says: "Ngày có hiệu lực: 15-08-2026 // 'Effective date: 15 A
 ugust 2026'. Người ký: Hồ Quốc Dũng\; Ngày ban hành: 30-06-202
 6."\nSource: https://vanban.chinhphu.vn/?pageid=27160&docid=218658&classi
 d=1&typegroupid=5\nVerified: Aug 30\, 2026\nhttps://agenccy.ai/ai-complia
 nce-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Law applies
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:Vietnam: High-risk AI list takes effect: 46 named AI systems a
 cross 6 sectors become 'high-risk' under the Law on AI 134/2025/QH15\, tr
 iggering the strict-management duties (operating principles and complianc
 e roadmap set by the Decision)
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:nz|biometric-processing-privacy-code-2025-end-of-the-transition-period
 -fo|organisations-that-were-already-carrying-out-automated-biome|2026-08-
 03@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20260803
DTEND;VALUE=DATE:20260804
SUMMARY:New Zealand: Organisations that were ALREADY carrying out automate
 d biometric processing before 3 November 2025 must\, from this date\, com
 ply in full with the Code's 13 rules — including the Rule 1 proportiona
 lity assessment\, notification duties and the limits on biometric categor
 isation
DESCRIPTION:Organisations that were ALREADY carrying out automated biometr
 ic processing before 3 November 2025 must\, from this date\, comply in fu
 ll with the Code's 13 rules — including the Rule 1 proportionality asse
 ssment\, notification duties and the limits on biometric categorisation\n
 Biometric Processing Privacy Code 2025 — end of the transition period f
 or existing biometric processing\nThe Privacy Commissioner gave a nine-mo
 nth grace period from commencement for legacy biometric deployments (faci
 al recognition in retail and security\, voice authentication\, age-estima
 tion systems). That grace period has now expired\, so pre-existing system
 s are fully in scope.\nApplies to: deployer\nWho: agencies already carryi
 ng out biometric processing before 3 November 2025\nPenalty: Interference
  with privacy under the Privacy Act 2020: complaints\, compliance notices
 \, and Human Rights Review Tribunal proceedings including damages\nSource
  says: "The BPPC came into force on 3 November 2025\, but agencies alread
 y using biometrics had a nine-month grace period to move to the new set o
 f rules. That transition period ended on 3 August 2026."\nSource: https:/
 /www.privacy.org.nz/privacy-principles/codes-of-practice/biometric-proces
 sing-privacy-code/\nVerified: Aug 30\, 2026\nhttps://agenccy.ai/ai-compli
 ance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:New Zealand: Organisations that were ALREADY carrying out auto
 mated biometric processing before 3 November 2025 must\, from this date\,
  comply in full with the Code's 13 rules — including the Rule 1 proport
 ionality assessment\, notification duties and the limits on biometric cat
 egorisation
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:eu|eu-ai-act-regulation-eu-2024-1689|transparency-obligations-for-ai-i
 nteracting-with-people-synt|2026-08-02@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20260802
DTEND;VALUE=DATE:20260803
SUMMARY:European Union: Transparency obligations for AI interacting with p
 eople\, synthetic content marking and deepfake disclosure apply (Art. 50)
DESCRIPTION:Transparency obligations for AI interacting with people\, synt
 hetic content marking and deepfake disclosure apply (Art. 50)\nEU AI Act 
 (Regulation (EU) 2024/1689)\nChatbots must disclose they are machines\; s
 ynthetic audio\, image\, video and text must be machine-readably marked\;
  deepfakes and AI-generated public-interest text must be labelled. Also t
 he date the Act's penalties regime and Member State sandboxes become oper
 ational.\nApplies to: provider\, deployer\nPenalty: Up to EUR 15 000 000 
 or 3% of worldwide annual turnover (Art. 99(4))\nSource says: "It shall a
 pply from 2 August 2026."\nSource: https://ai-act-service-desk.ec.europa.
 eu/en/ai-act/article-113\nVerified: Aug 30\, 2026\nhttps://agenccy.ai/ai-
 compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:European Union: Transparency obligations for AI interacting wi
 th people\, synthetic content marking and deepfake disclosure apply (Art.
  50)
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:cn|interim-measures-for-the-administration-of-anthropomorphic-ai-inter
 act|anthropomorphic-companion-emotional-ai-interaction-service-p|2026-07-
 15@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20260715
DTEND;VALUE=DATE:20260716
SUMMARY:China (People's Republic of China): Anthropomorphic (companion/emo
 tional) AI interaction service providers must comply in full: AI-disclosu
 re and content labelling\, 2-hour continuous-use reminders\, minors prote
 ctions\, security assessment filed with the provincial cyberspace adminis
 tration\, and algorithm filing
DESCRIPTION:Anthropomorphic (companion/emotional) AI interaction service p
 roviders must comply in full: AI-disclosure and content labelling\, 2-hou
 r continuous-use reminders\, minors protections\, security assessment fil
 ed with the provincial cyberspace administration\, and algorithm filing\n
 人工智能拟人化互动服务管理暂行办法 — Interim Measures 
 for the Administration of Anthropomorphic AI Interaction Services (CAC/ND
 RC/MIIT/MPS/SAMR Order No. 21\, promulgated 10 April 2026)\nChina's first
  national-level rules aimed specifically at AI companionship/emotional-in
 teraction services. From this date providers must: (Art. 18) discharge th
 e AI-generated-synthetic-content labelling duty and take effective measur
 es to alert users that they are interacting with an AI service and not a 
 natural person\, and remind users of elapsed time by dialogue or pop-up e
 very time continuous use exceeds 2 hours\; (Art. 14) NOT provide virtual-
 kin\, virtual-partner or other virtual intimate-relationship services to 
 minors at all\, and obtain parent/guardian consent before providing other
  anthropomorphic interaction services to under-14s\; (Art. 22) carry out 
 a security assessment and submit the assessment report to the provincial 
 cyberspace administration before launching such a service or adding anthr
 opomorphic-interaction functionality\; (Art. 26) complete algorithm filin
 g\, and filing changes/cancellations\, under the Internet Information Ser
 vice Algorithmic Recommendation Management Provisions.\nApplies to: provi
 der (拟人化互动服务提供者) — service provider offering anthro
 pomorphic AI interaction services to the public within the PRC\nPenalty: 
 Art. 30: handling/punishment by the cyberspace\, development-and-reform\,
  industry-and-information-technology and public-security departments unde
 r applicable laws and administrative regulations\; where no law or regula
 tion provides\, those departments may issue a warning\, circulate critici
 sm\, order correction within a time limit\, and may require measures such
  as suspending new user account registration or other related services. F
 or refusal to correct or serious circumstances: order to stop providing t
 he relevant service\, plus a fine of RMB 10\,000–100\,000\; where citiz
 ens' life and health safety are endangered with harmful consequences\, a 
 fine of RMB 100\,000–200\,000.\nSource says: "第三十二条 本办法
 自2026年7月15日起施行。"\nSource: https://www.cac.gov.cn/2026-04/
 10/c_1777558395078289.htm\nVerified: Aug 30\, 2026\nhttps://agenccy.ai/ai
 -compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Law applies
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:China (People's Republic of China): Anthropomorphic (companion
 /emotional) AI interaction service providers must comply in full: AI-disc
 losure and content labelling\, 2-hour continuous-use reminders\, minors p
 rotections\, security assessment filed with the provincial cyberspace adm
 inistration\, and algorithm filing
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:sg|online-safety-relief-and-accountability-act-2025-bill-18-2025-passe
 d-5|online-safety-commission-starts-operating-and-the-statutory|2026-06-2
 9@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20260629
DTEND;VALUE=DATE:20260630
SUMMARY:Singapore: Online Safety Commission starts operating and the statu
 tory torts / directions regime commences for the first five harms — int
 imate image abuse\, image-based child abuse\, doxxing\, online harassment
  (including online sexual harassment) and online stalking. AI-generated m
 aterial is expressly inside the first two: an 'intimate image or recordin
 g' and a 'child abuse image or recording' include images or recordings 'a
 ltered or generated by any means'. Communicators of harmful content\, onl
 ine administrators\, online platforms\, internet access service providers
  and app distribution services must comply with Commission directions (ta
 kedown\, account restriction\, right of reply\, access disabling).
DESCRIPTION:Online Safety Commission starts operating and the statutory to
 rts / directions regime commences for the first five harms — intimate i
 mage abuse\, image-based child abuse\, doxxing\, online harassment (inclu
 ding online sexual harassment) and online stalking. AI-generated material
  is expressly inside the first two: an 'intimate image or recording' and 
 a 'child abuse image or recording' include images or recordings 'altered 
 or generated by any means'. Communicators of harmful content\, online adm
 inistrators\, online platforms\, internet access service providers and ap
 p distribution services must comply with Commission directions (takedown\
 , account restriction\, right of reply\, access disabling).\nOnline Safet
 y (Relief and Accountability) Act 2025 (Bill 18/2025\, passed 5 November 
 2025) — partial commencement\; Online Safety Commission begins operatio
 ns\nThe Act creates 13 categories of online harm\; only these five commen
 ce on this date\, and the remaining eight — including 'inauthentic mate
 rial abuse' (deepfakes) — are to be implemented progressively with NO d
 ate announced. Mr Francis Ng was appointed Commissioner-Designate of Onli
 ne Safety from 1 June 2026 to 28 June 2026 and became Commissioner on 29 
 June 2026.\nApplies to: platform\, online-administrator\, internet-access
 -service-provider\, app-distribution-service\, individual\nWho: all\nPena
 lty: Statutory torts giving victims civil claims\; offences for non-compl
 iance with Online Safety Commission directions\nSource says: "From 29 Jun
 e 2026\, Singaporeans will have stronger protection and faster avenues fo
 r relief against online harms. … Intimate image abuse\; Image-based chi
 ld abuse\; Doxxing\; Online harassment (including online sexual harassmen
 t)\; and Online stalking. … The remaining categories will be progressiv
 ely implemented."\nSource: https://www.mlaw.gov.sg/online-safety-commissi
 on-and-online-safety-relief-and-accountability-act-2025-to-start-on-29-ju
 ne-2026/\nVerified: Aug 30\, 2026\nhttps://agenccy.ai/ai-compliance-calen
 dar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Enforcement
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:Singapore: Online Safety Commission starts operating and the s
 tatutory torts / directions regime commences for the first five harms —
  intimate image abuse\, image-based child abuse\, doxxing\, online harass
 ment (including online sexual harassment) and online stalking. AI-generat
 ed material is expressly inside the first two: an 'intimate image or reco
 rding' and a 'child abuse image or recording' include images or recording
 s 'altered or generated by any means'. Communicators of harmful content\,
  online administrators\, online platforms\, internet access service provi
 ders and app distribution services must comply with Commission directions
  (takedown\, account restriction\, right of reply\, access disabling).
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:uk|crime-and-policing-act-2026-schedule-13-paragraph-24-amendment-of-s
 che|sexual-deepfake-offences-become-priority-offences-under-the|2026-06-2
 9@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20260629
DTEND;VALUE=DATE:20260630
SUMMARY:United Kingdom: Sexual deepfake offences become 'priority offences
 ' under the Online Safety Act\, extending Part 3 illegal-content duties o
 f user-to-user and search services to AI-generated intimate images
DESCRIPTION:Sexual deepfake offences become 'priority offences' under the 
 Online Safety Act\, extending Part 3 illegal-content duties of user-to-us
 er and search services to AI-generated intimate images\nCrime and Policin
 g Act 2026\, Schedule 13 paragraph 24 (amendment of Schedule 7 to the Onl
 ine Safety Act 2023)\, commenced by SI 2026/689 reg. 2(1)(z9)\nParagraph 
 24 of Schedule 13 adds to paragraph 28A of Schedule 7 to the Online Safet
 y Act 2023 the offences in s.66E (creating purported intimate image of ad
 ult) and s.66F (requesting the creation of purported intimate image of ad
 ult) of the Sexual Offences Act 2003. Listing an offence in Schedule 7 ma
 kes the related content 'priority illegal content'\, so Part 3 providers 
 must take proportionate proactive measures to prevent users encountering 
 it and to minimise the time it is present\, and must reflect it in their 
 illegal content risk assessments.\nApplies to: providers of user-to-user 
 services\, providers of search services\nWho: all Part 3 services in scop
 e of the Online Safety Act 2023\nPenalty: Ofcom enforcement under the Onl
 ine Safety Act 2023: fines up to the greater of GBP 18 million or 10% of 
 qualifying worldwide revenue\, business disruption measures\, and senior 
 manager liability for named offences\nSource says: "In Schedule 7 to the 
 Online Safety Act 2023 (priority offences)\, in paragraph 28A (Sexual Off
 ences Act 2003)\, at the end insert— "(c) section 66E (creating purport
 ed intimate image of adult)\; (d) section 66F (requesting the creation of
  purported intimate image of adult).""\nSource: https://www.legislation.g
 ov.uk/ukpga/2026/20/schedule/13/paragraph/24\nVerified: Aug 30\, 2026\nht
 tps://agenccy.ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:United Kingdom: Sexual deepfake offences become 'priority offe
 nces' under the Online Safety Act\, extending Part 3 illegal-content duti
 es of user-to-user and search services to AI-generated intimate images
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:uk|crime-and-policing-act-2026-s-99-purported-intimate-image-generator
 s-c|offences-of-making-adapting-possessing-supplying-or-offering|2026-06-
 29@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20260629
DTEND;VALUE=DATE:20260630
SUMMARY:United Kingdom: Offences of making\, adapting\, possessing\, suppl
 ying or offering to supply a tool for creating purported (deepfake) intim
 ate images take effect
DESCRIPTION:Offences of making\, adapting\, possessing\, supplying or offe
 ring to supply a tool for creating purported (deepfake) intimate images t
 ake effect\nCrime and Policing Act 2026\, s.99 (purported intimate image 
 generators)\, commenced by SI 2026/689 (Commencement No.1 and Saving Prov
 ision) Regulations 2026\nSection 99 inserts new sections 66I-66L into the
  Sexual Offences Act 2003\, criminalising making or adapting 'a thing for
  creating\, or facilitating the creation of\, purported intimate images o
 f a person' and possessing\, supplying or offering to supply such a gener
 ator. 'Thing' is defined to include 'a program\, information in electroni
 c form and a service'\, which captures nudification apps\, image-generati
 on models and hosted services. This targets the supply side of sexual dee
 pfakes\, complementing the s.138 DUAA creation offence.\nApplies to: deve
 lopers of image-generation models\, operators of nudification services\, 
 app stores and hosts\, individuals\nWho: all\nPenalty: Criminal offence u
 nder the Sexual Offences Act 2003 as amended\; see the new ss.66I-66L for
  the applicable penalties\nSource says: "Subject to paragraph (2)\, the f
 ollowing provisions of the 2026 Act come into force on 29th June 2026— 
 ... (i) section 99 (purported intimate image generators)\;"\nSource: http
 s://www.legislation.gov.uk/uksi/2026/689/regulation/2/made\nVerified: Aug
  30\, 2026\nhttps://agenccy.ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Enforcement
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:United Kingdom: Offences of making\, adapting\, possessing\, s
 upplying or offering to supply a tool for creating purported (deepfake) i
 ntimate images take effect
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:ca|treasury-board-directive-on-automated-decision-making-issued-under-
 the|legacy-automated-decision-systems-must-be-brought-into-compl|2026-06-
 24@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20260624
DTEND;VALUE=DATE:20260625
SUMMARY:Canada — federal: Legacy automated decision systems must be brou
 ght into compliance with the new/updated Directive requirements
DESCRIPTION:Legacy automated decision systems must be brought into complia
 nce with the new/updated Directive requirements\nTreasury Board Directive
  on Automated Decision-Making (issued under the Policy on Service and Dig
 ital\; amendments dated 2025-06-24)\nFederal departments operating automa
 ted decision systems that were developed or procured BEFORE 2025-06-24 ha
 d a transition window to meet the requirements added in the 2025 amendmen
 t round — Algorithmic Impact Assessment completion and publication on t
 he Open Government Portal\, the Appendix C measures for the assigned impa
 ct level (notice\, explanation\, human-in-the-loop\, peer review\, monito
 ring\, employee training\, IT/business continuity)\, and access-to-compon
 ents rights for audit. Systems developed or procured after 2020-04-01 wer
 e already bound\; s.1.2.1 is the catch-up date for the pre-existing estat
 e.\nApplies to: deployer\, operator\nWho: all federal departments listed 
 in Schedules I\, I.1 and II of the Financial Administration Act\, per the
  Policy on Service and Digital scope\nPenalty: No monetary penalty. Non-c
 ompliance is handled administratively under the Treasury Board Framework 
 for the Management of Compliance — deputy heads must respond to non-com
 pliance\; consequences can include removal of delegated authority and req
 uiring the system be taken out of production. Section 8.3.5 requires appr
 oval to operate for level 4 (highest impact) systems.\nSource says: "1.2.
 1 Existing automated decision systems developed or procured prior to June
  24\, 2025\, will have until June 24\, 2026 to comply with the new or upd
 ated requirements."\nSource: https://www.tbs-sct.canada.ca/pol/doc-eng.as
 px?id=32592\nVerified: Aug 30\, 2026\nhttps://agenccy.ai/ai-compliance-ca
 lendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:Canada — federal: Legacy automated decision systems must be 
 brought into compliance with the new/updated Directive requirements
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:ca|treasury-board-directive-on-automated-decision-making-s-1-2-2|agent
 s-of-parliament-must-comply-with-the-directive-s-requir|2026-06-24@agencc
 y.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20260624
DTEND;VALUE=DATE:20260625
SUMMARY:Canada — federal: Agents of Parliament must comply with the Dire
 ctive's requirements
DESCRIPTION:Agents of Parliament must comply with the Directive's requirem
 ents\nTreasury Board Directive on Automated Decision-Making\, s.1.2.2\nSe
 parate transition date extending the Directive to Agents of Parliament (e
 .g. Office of the Auditor General\, Office of the Privacy Commissioner\, 
 Office of the Commissioner of Official Languages\, Chief Electoral Office
 r). Their heads are solely responsible for monitoring and enforcing compl
 iance internally (s.8.3.2) and for approving level 4 systems to operate (
 s.8.3.5).\nApplies to: deployer\, operator\nWho: all Agents of Parliament
 \nPenalty: No monetary penalty. Heads of Agents of Parliament are 'solely
  responsible for monitoring and ensuring compliance with this directive w
 ithin their organizations\, as well as for responding to cases of non-com
 pliance' (s.8.3.2).\nSource says: "1.2.2 Agents of Parliament will have u
 ntil June 24\, 2026\, to comply with the requirements."\nSource: https://
 www.tbs-sct.canada.ca/pol/doc-eng.aspx?id=32592\nVerified: Aug 30\, 2026\
 nhttps://agenccy.ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:Canada — federal: Agents of Parliament must comply with the 
 Directive's requirements
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:my|risk-mitigation-code-issued-by-the-malaysian-communications-and-mul
 tim|licensed-service-providers-must-label-synthetic-media-genera|2026-06-
 01@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20260601
DTEND;VALUE=DATE:20260602
SUMMARY:Malaysia: Licensed service providers must label synthetic media: g
 enerated or manipulated images\, audio or video that closely resemble rea
 l persons\, objects\, places\, entities or events and are likely to false
 ly appear authentic must be clearly distinguishable through prominent lab
 els or markings on the service's online interface (para. 4.2.4(d)\, 'Safe
  Design of the Service'). The same Code also requires providers to test a
 nd adapt algorithmic and recommender systems against exposure to harmful 
 content (para. 4.2.4(c)) and to run a documented harmful-content risk ass
 essment reviewed at least annually.
DESCRIPTION:Licensed service providers must label synthetic media: generat
 ed or manipulated images\, audio or video that closely resemble real pers
 ons\, objects\, places\, entities or events and are likely to falsely app
 ear authentic must be clearly distinguishable through prominent labels or
  markings on the service's online interface (para. 4.2.4(d)\, 'Safe Desig
 n of the Service'). The same Code also requires providers to test and ada
 pt algorithmic and recommender systems against exposure to harmful conten
 t (para. 4.2.4(c)) and to run a documented harmful-content risk assessmen
 t reviewed at least annually.\nRisk Mitigation Code issued by the Malaysi
 an Communications and Multimedia Commission (MCMC) under s.80 of the Onli
 ne Safety Act 2025 [Act 866]\nThe Code specifies the measures licensed se
 rvice providers must implement to discharge their duty under s.13 of the 
 ONSA 2025. It binds providers of applications services enabling communica
 tion between users\, and of content applications services\, that use inte
 rnet access service. Where synthetic content is to be identified through 
 user or advertiser disclosures/reports\, the provider must supply accessi
 ble functionality and guidance for those disclosures. Providers may subst
 itute alternative measures only if they satisfy the Commission that these
  better mitigate risk (s.13(2) ONSA).\nApplies to: platform\, application
 s-service-provider\, content-applications-service-provider\nWho: licensed
  service providers (MCMC has applied the ONSA regime to platforms with mo
 re than 8 million Malaysian users)\nPenalty: Enforcement under the Online
  Safety Act 2025 including financial penalties reported up to RM10 millio
 n for non-compliance with duties under the Act\nSource says: "Date of Pub
 lication: 22 May 2026 / Date of Enforcement: 1 June 2026 (cover page of t
 he Code\, MCMC)."\nSource: https://www.mcmc.gov.my/skmmgovmy/media/Genera
 l/pdf2/ONSA-Risk-Mitigation-Code_1.pdf\nVerified: Aug 30\, 2026\nhttps://
 agenccy.ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:Malaysia: Licensed service providers must label synthetic medi
 a: generated or manipulated images\, audio or video that closely resemble
  real persons\, objects\, places\, entities or events and are likely to f
 alsely appear authentic must be clearly distinguishable through prominent
  labels or markings on the service's online interface (para. 4.2.4(d)\, '
 Safe Design of the Service'). The same Code also requires providers to te
 st and adapt algorithmic and recommender systems against exposure to harm
 ful content (para. 4.2.4(c)) and to run a documented harmful-content risk
  assessment reviewed at least annually.
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:uk|automated-vehicles-act-2024-part-5-permits-for-automated-passenger-
 ser|the-permit-regime-for-automated-passenger-services-goes-live|2026-05-
 15@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20260515
DTEND;VALUE=DATE:20260516
SUMMARY:United Kingdom: The permit regime for automated passenger services
  goes live: self-driving taxi\, private-hire and bus-like services must o
 perate under a permit granted by the appropriate national authority
DESCRIPTION:The permit regime for automated passenger services goes live: 
 self-driving taxi\, private-hire and bus-like services must operate under
  a permit granted by the appropriate national authority\nAutomated Vehicl
 es Act 2024\, Part 5 (permits for automated passenger services)\, commenc
 ed by SI 2026/437 (Commencement No. 2) Regulations 2026\, together with t
 he Automated Vehicles (Permits for Automated Passenger Services) Regulati
 ons 2026 (SI 2026/439)\nSI 2026/437 commenced the whole of Part 5 of the 
 Automated Vehicles Act 2024 on 15 May 2026\, except s.84 (civil sanctions
  for infringements of the permit scheme) and s.89(8)(b) and (10). Section
  82 empowers the appropriate national authority to grant permits for 'aut
 omated passenger services' - the carrying of passengers in a road vehicle
  'designed or adapted to travel autonomously' or used in a trial to devel
 op such vehicles - and the permit must specify areas\, vehicles\, validit
 y period and conditions. The procedural regime (applications\, notices\, 
 review) is in SI 2026/439\, which came into force the same day. Section 8
 3 disapplies taxi\, private hire vehicle and bus legislation for services
  covered by a permit.\nApplies to: automated passenger service operators\
 , self-driving taxi and PHV operators\, bus-like autonomous shuttle opera
 tors\, no-user-in-charge operators\nWho: all\nPenalty: Permit conditions 
 are binding on the permit holder\; note that s.84 (civil sanctions for in
 fringements of the permit scheme) is expressly NOT yet commenced\nSource 
 says: "The following provisions of the Automated Vehicles Act 2024\, so f
 ar as not already in force\, come into force on 15th May 2026— (a) Part
  5 (permits for automated passenger services)\, except— (i) section 84 
 (civil sanctions for infringements of the permit scheme)\, and (ii) secti
 on 89(8)(b) and (10) (procedural and administrative matters)\; (b) sectio
 n 93 (provision of information about traffic regulation measures)."\nSour
 ce: https://www.legislation.gov.uk/uksi/2026/437/regulation/2/made\nVerif
 ied: Aug 30\, 2026\nhttps://agenccy.ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Registration
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:United Kingdom: The permit regime for automated passenger serv
 ices goes live: self-driving taxi\, private-hire and bus-like services mu
 st operate under a permit granted by the appropriate national authority
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:uk|the-data-protection-act-2018-code-of-practice-on-artificial-intelli
 gen|statutory-duty-on-the-information-commissioner-to-prepare-a|2026-05-1
 2@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20260512
DTEND;VALUE=DATE:20260513
SUMMARY:United Kingdom: Statutory duty on the Information Commissioner to 
 prepare a code of practice on processing personal data for developing and
  using AI and for automated decision-making takes effect
DESCRIPTION:Statutory duty on the Information Commissioner to prepare a co
 de of practice on processing personal data for developing and using AI an
 d for automated decision-making takes effect\nThe Data Protection Act 201
 8 (Code of Practice on Artificial Intelligence and Automated Decision-Mak
 ing) Regulations 2026\, SI 2026/425\nRegulation 2 provides: 'The Commissi
 oner must prepare an appropriate code of practice giving guidance as to g
 ood practice in the processing of personal data under the relevant data p
 rotection legislation in relation to (a) developing and using artificial 
 intelligence\, and (b) automated decision-making.' This is the secondary 
 legislation the Government committed to during passage of the Data (Use a
 nd Access) Act 2025. Once issued under the Data Protection Act 2018 proce
 dure\, the code is a statutory code: the Commissioner must take it into a
 ccount when exercising regulatory functions and it is admissible in evide
 nce in legal proceedings\, so it will in practice bind controllers develo
 ping or deploying AI.\nApplies to: Information Commissioner (duty holder)
 \, data controllers developing or using AI\, deployers of automated decis
 ion-making\nWho: all\nPenalty: None directly\; the resulting statutory co
 de will be taken into account by the ICO in enforcement and is admissible
  in evidence in court and tribunal proceedings\nSource says: "Made 16th A
 pril 2026 / Laid before Parliament 21st April 2026 / Coming into force 12
 th May 2026"\nSource: https://www.legislation.gov.uk/uksi/2026/425/made\n
 Verified: Aug 30\, 2026\nhttps://agenccy.ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:United Kingdom: Statutory duty on the Information Commissioner
  to prepare a code of practice on processing personal data for developing
  and using AI and for automated decision-making takes effect
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:vn|decree-no-142-2026-nd-cp-of-30-april-2026-detailing-articles-and-im
 ple|operative-implementing-rules-for-the-ai-law-take-effect-risk|2026-05-
 01@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20260501
DTEND;VALUE=DATE:20260502
SUMMARY:Vietnam: Operative implementing rules for the AI Law take effect: 
 risk classification of AI systems into high/medium/low\, conformity asses
 sment for high-risk AI systems\, accountability/transparency and incident
 -handling duties\, registration on the one-stop AI portal and the nationa
 l AI systems database\, and the regulatory sandbox
DESCRIPTION:Operative implementing rules for the AI Law take effect: risk 
 classification of AI systems into high/medium/low\, conformity assessment
  for high-risk AI systems\, accountability/transparency and incident-hand
 ling duties\, registration on the one-stop AI portal and the national AI 
 systems database\, and the regulatory sandbox\nDecree No. 142/2026/ND-CP 
 of 30 April 2026 detailing articles and implementation measures of the La
 w on Artificial Intelligence (Nghị định 142/2026/NĐ-CP)\n8 chapters
 \, 46 articles plus forms. Applies to AI system providers\, developers\, 
 deployers and users\, and to Vietnamese and foreign bodies\, organisation
 s and individuals engaged in AI activity in Vietnam. Providers of medium-
  and high-risk AI systems must notify their risk classification before pu
 tting the system into use. Serious-incident reporting: preliminary report
  within 72 hours (emergency) or 5 working days (other serious incidents)\
 , final report within 15 days of the preliminary report.\nApplies to: dev
 eloper\, provider\, deployer\, user\nWho: all\nPenalty: Administrative me
 asures under the AI Law\; suspension/termination powers for systems posin
 g serious risk\nSource says: "Ngày ban hành: 30-04-2026\; Ngày có hi
 ệu lực: 01-05-2026\; Người ký: Hồ Quốc Dũng. // 'Date issued
 : 30 April 2026\; Effective date: 1 May 2026\; Signed by: Hồ Quốc Dũ
 ng.' Signed text: https://datafiles.chinhphu.vn/cpp/files/vbpq/2026/4/142
 -2026-ndcp.signed.pdf"\nSource: https://vanban.chinhphu.vn/?pageid=27160&
 docid=218029\nVerified: Aug 30\, 2026\nhttps://agenccy.ai/ai-compliance-c
 alendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:Vietnam: Operative implementing rules for the AI Law take effe
 ct: risk classification of AI systems into high/medium/low\, conformity a
 ssessment for high-risk AI systems\, accountability/transparency and inci
 dent-handling duties\, registration on the one-stop AI portal and the nat
 ional AI systems database\, and the regulatory sandbox
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:vn|decree-no-142-2026-nd-cp-article-18-notification-of-ai-interaction-
 and|synthetic-content-marking-and-labelling-duty-providers-must|2026-05-0
 1@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20260501
DTEND;VALUE=DATE:20260502
SUMMARY:Vietnam: Synthetic-content marking and labelling duty: PROVIDERS m
 ust apply technical solutions so that audio\, image and video outputs are
  marked in a machine-readable format\; DEPLOYERS must give clear notice a
 nd an easily recognisable label when releasing to the public content gene
 rated or edited by AI that could mislead as to the authenticity of an eve
 nt\, a person or the origin of the content
DESCRIPTION:Synthetic-content marking and labelling duty: PROVIDERS must a
 pply technical solutions so that audio\, image and video outputs are mark
 ed in a machine-readable format\; DEPLOYERS must give clear notice and an
  easily recognisable label when releasing to the public content generated
  or edited by AI that could mislead as to the authenticity of an event\, 
 a person or the origin of the content\nDecree No. 142/2026/ND-CP\, Articl
 e 18 — notification of AI interaction and labelling of AI-generated con
 tent (read with the Law on Artificial Intelligence No. 134/2025/QH15)\nSp
 lit duty between nhà cung cấp (provider) and bên triển khai (deploy
 er). Machine-readable marking at the provider layer plus human-visible la
 belling at the distribution layer — the same two-layer design as the EU
  AI Act Art. 50. The Ministry of Science and Technology publishes and upd
 ates reference technical guidance on the form of the notification and of 
 the displayed label.\nApplies to: provider\, deployer\nWho: all\nPenalty:
  Administrative liability under the Law on AI and its implementing decree
 \; suspension/termination powers for systems posing serious risk\nSource 
 says: "Nghị định có hiệu lực từ ngày 01/5/2026. … nhà cun
 g cấp phải áp dụng giải pháp kỹ thuật để nội dung đ
 ầu ra là âm thanh\, hình ảnh\, video được đánh dấu ở đ
 ịnh dạng máy đọc\; bên triển khai phải thông báo rõ ràng
 \, gắn nhãn dễ nhận biết khi cung cấp ra công chúng nội du
 ng do AI tạo ra hoặc chỉnh sửa … có khả năng gây nhầm l
 ẫn về tính xác thực của sự kiện\, nhân vật hoặc nguồ
 n gốc nội dung. // 'The Decree takes effect from 1 May 2026. … the 
 provider must apply technical solutions so that output audio\, image and 
 video content is marked in a machine-readable format\; the deployer must 
 give clear notice and an easily recognisable label when providing to the 
 public content generated or edited by AI … that is liable to cause conf
 usion as to the authenticity of an event\, a person or the origin of the 
 content.'"\nSource: https://khpl.moj.gov.vn/portal/tin-tuc/chi-tiet/gioi-
 thieu-nghi-inh-so-1422026n-cp-quy-inh-chi-tiet-mot-so-ieu-va-bien-phap-th
 i-hanh-luat-tri-tue-nhan-tao-th2pbneb5f.html\nVerified: Aug 30\, 2026\nht
 tps://agenccy.ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:Vietnam: Synthetic-content marking and labelling duty: PROVIDE
 RS must apply technical solutions so that audio\, image and video outputs
  are marked in a machine-readable format\; DEPLOYERS must give clear noti
 ce and an easily recognisable label when releasing to the public content 
 generated or edited by AI that could mislead as to the authenticity of an
  event\, a person or the origin of the content
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:us|executive-order-ensuring-a-national-policy-framework-for-artificial
 -in|commerce-identifies-state-ai-laws-for-challenge-by-the-doj-a|2026-03-
 11@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20260311
DTEND;VALUE=DATE:20260312
SUMMARY:United States — federal: Commerce identifies state AI laws for c
 hallenge by the DOJ AI Litigation Task Force\; BEAD funding eligibility t
 ied to state AI rules
DESCRIPTION:Commerce identifies state AI laws for challenge by the DOJ AI 
 Litigation Task Force\; BEAD funding eligibility tied to state AI rules\n
 Executive Order\, Ensuring a National Policy Framework for Artificial Int
 elligence (11 Dec 2025)\nNot a business compliance duty but the reason se
 veral state deadlines below moved. The Task Force challenges state AI law
 s deemed inconsistent with federal policy\; states with targeted rules ri
 sk losing BEAD broadband funds.\nApplies to: state government\nSource say
 s: "Sec. 4. Evaluation of State AI Laws. Within 90 days of the date of th
 is order\, the Secretary of Commerce\, consistent with the Secretary's au
 thorities under 47 U.S.C. 902(b)\, shall\, in consultation with the Speci
 al Advisor for AI and Crypto\, the Assistant to the President for Economi
 c Policy\, the Assistant to the President for Science and Technology\, an
 d the Assistant to the President and Counsel to the President\, publish a
 n evaluation of existing State AI laws that identifies onerous laws that 
 conflict with the policy set forth in section 2 of this order\, as well a
 s laws that should be referred to the Task Force established pursuant to 
 section 3 of this order."\nSource: https://www.whitehouse.gov/presidentia
 l-actions/2025/12/eliminating-state-law-obstruction-of-national-artificia
 l-intelligence-policy/\nVerified: Aug 30\, 2026\nhttps://agenccy.ai/ai-co
 mpliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Regulator milestone
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:United States — federal: Commerce identifies state AI laws f
 or challenge by the DOJ AI Litigation Task Force\; BEAD funding eligibili
 ty tied to state AI rules
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:vn|law-on-artificial-intelligence-no-134-2025-qh15-lu-t-tr-tu-nh-n-t-o
 |vietnam-s-dedicated-ai-law-enters-into-force-risk-tiered-dut|2026-03-01@
 agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20260301
DTEND;VALUE=DATE:20260302
SUMMARY:Vietnam: Vietnam's dedicated AI Law enters into force: risk-tiered
  duties on developers\, providers and deployers of AI systems (risk class
 ification\, data/testing/monitoring and human-oversight requirements for 
 high-risk uses in finance\, health\, justice\, labour and education\; tra
 nsparency and marking of AI-generated content)
DESCRIPTION:Vietnam's dedicated AI Law enters into force: risk-tiered duti
 es on developers\, providers and deployers of AI systems (risk classifica
 tion\, data/testing/monitoring and human-oversight requirements for high-
 risk uses in finance\, health\, justice\, labour and education\; transpar
 ency and marking of AI-generated content)\nLaw on Artificial Intelligence
  No. 134/2025/QH15 (Luật Trí tuệ nhân tạo)\nPassed by the 15th Na
 tional Assembly at its 10th session on 10 December 2025 by 429/434 deputi
 es (90.70%). 8 chapters\, 35 articles. First comprehensive Vietnamese sta
 tute governing research\, development\, provision\, deployment and use of
  AI systems. Technical detail is delegated to implementing decrees (see D
 ecree 142/2026/ND-CP).\nApplies to: developer\, provider\, deployer\, use
 r\nWho: all\nPenalty: Administrative and criminal liability under general
  Vietnamese law\; detail delegated to implementing decrees\nSource says: 
 "Luật Trí tuệ nhân tạo chính thức có hiệu lực từ hôm n
 ay\, ngày 01/3/2026. // 'The Law on Artificial Intelligence officially t
 akes effect from today\, 1 March 2026.' Also: 'Ngày 10/12/2025\, Quốc 
 hội biểu quyết thông qua Luật Trí tuệ nhân tạo' ('On 10 De
 cember 2025 the National Assembly voted to pass the Law on Artificial Int
 elligence')."\nSource: https://mst.gov.vn/ai-la-cong-cu-ho-tro-quyet-dinh
 -cuoi-cung-van-la-con-nguoi-19726030111172663.htm\nVerified: Aug 30\, 202
 6\nhttps://agenccy.ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:Vietnam: Vietnam's dedicated AI Law enters into force: risk-ti
 ered duties on developers\, providers and deployers of AI systems (risk c
 lassification\, data/testing/monitoring and human-oversight requirements 
 for high-risk uses in finance\, health\, justice\, labour and education\;
  transparency and marking of AI-generated content)
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:in|information-technology-intermediary-guidelines-and-digital-media-et
 hic|intermediaries-must-label-and-trace-synthetically-generated|2026-02-2
 0@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20260220
DTEND;VALUE=DATE:20260221
SUMMARY:India: Intermediaries must label and trace synthetically generated
  content
DESCRIPTION:Intermediaries must label and trace synthetically generated co
 ntent\nInformation Technology (Intermediary Guidelines and Digital Media 
 Ethics Code) Amendment Rules\, 2026\nGazette notification G.S.R. 120(E) d
 ated 10 February 2026\, in force 20 February 2026. The synthetically gene
 rated information definition covers audio and visual content — text is 
 excluded — and the draft's 10% surface-area watermark rule did not surv
 ive into the notified version.\nApplies to: intermediary\, platform\nSour
 ce says: "Gazette of India\, Extraordinary\, Part II Section 3(i)\, notif
 ication G.S.R. 120(E) dated 10 February 2026 (gazette doc id CG-DL-E-1002
 2026-269993)\; the Information Technology (Intermediary Guidelines and Di
 gital Media Ethics Code) Amendment Rules\, 2026 come into force on 20 Feb
 ruary 2026. Rule 2(1)(wa) definition\, verbatim: 'audio\, visual or audio
 -visual information which is artificially or algorithmically created\, ge
 nerated\, modified or altered using a computer resource\, in a manner tha
 t such information appears to be real\, authentic or true and depicts or 
 portrays any individual or event in a manner that is\, or is likely to be
  perceived as indistinguishable from a natural person or real-world event
 .' Labelling standard as notified: the label must be 'clearly and promine
 ntly' displayed - a visible label on visual content and an audio disclosu
 re on audio content\, 'prominent and clearly noticeable'. Provenance duty
 : intermediaries must 'embed permanent metadata or unique identifiers to 
 trace the computer resource used to generate or alter the content'. SSMI 
 duty: obtain a user declaration whether content is SGI and 'deploy approp
 riate technical measures\, including automated tools\, to verify whether 
 the declaration is accurate'."\nSource: https://www.meity.gov.in/static/u
 ploads/2026/02/550681ab908f8afb135b0ad42816a1c9.pdf\nVerified: Aug 30\, 2
 026\nhttps://agenccy.ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:India: Intermediaries must label and trace synthetically gener
 ated content
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:uk|data-use-and-access-act-2025-s-138-creating-or-requesting-the-creat
 ion|new-criminal-offences-of-creating-or-requesting-the-creation|2026-02-
 06@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20260206
DTEND;VALUE=DATE:20260207
SUMMARY:United Kingdom: New criminal offences of creating\, or requesting 
 the creation of\, a purported (deepfake) intimate image of an adult witho
 ut consent come into force
DESCRIPTION:New criminal offences of creating\, or requesting the creation
  of\, a purported (deepfake) intimate image of an adult without consent c
 ome into force\nData (Use and Access) Act 2025\, s.138 (creating\, or req
 uesting the creation of\, purported intimate image of adult)\, commenced 
 by SI 2026/31 (Commencement No. 5) Regulations 2026\nSection 138 DUAA ins
 erts new sections 66E-66H into the Sexual Offences Act 2003. A 'purported
  intimate image' is an image made or altered so that it appears to be a p
 hotograph or film of another person in an intimate state - i.e. AI-genera
 ted or digitally altered 'nudification' and sexual deepfakes. It is an of
 fence to create such an image of an adult without consent and without rea
 sonable belief in consent\, and separately to request its creation. Defen
 ces of reasonable excuse apply\; courts get deprivation-order powers over
  the images and equipment.\nApplies to: individuals\, operators of nudifi
 cation and image-generation tools\, platforms hosting such tools\nWho: al
 l\nPenalty: Criminal offence: on summary conviction\, imprisonment up to 
 the maximum term for summary offences and/or a fine\; deprivation orders 
 in respect of the image and equipment used\nSource says: "Section 138 of 
 the Data (Use and Access) Act 2025 (creating\, or requesting the creation
  of\, purported intimate image of adult) comes into force on 6th February
  2026."\nSource: https://www.legislation.gov.uk/uksi/2026/31/made\nVerifi
 ed: Aug 30\, 2026\nhttps://agenccy.ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Enforcement
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:United Kingdom: New criminal offences of creating\, or request
 ing the creation of\, a purported (deepfake) intimate image of an adult w
 ithout consent come into force
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:uk|data-use-and-access-act-2025-s-80-and-schedule-6-automated-decision
 -ma|new-uk-gdpr-articles-22a-22d-automated-decision-making-regim|2026-02-
 05@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20260205
DTEND;VALUE=DATE:20260206
SUMMARY:United Kingdom: New UK GDPR Articles 22A-22D automated decision-ma
 king regime takes effect: controllers taking significant solely-automated
  decisions must have safeguards in place
DESCRIPTION:New UK GDPR Articles 22A-22D automated decision-making regime 
 takes effect: controllers taking significant solely-automated decisions m
 ust have safeguards in place\nData (Use and Access) Act 2025\, s.80 and S
 chedule 6 (automated decision-making)\, commenced by SI 2026/82 (Commence
 ment No. 6 and Transitional and Saving Provisions) Regulations 2026\nSect
 ion 80 DUAA replaces UK GDPR Article 22 with Articles 22A-22D. A decision
  is 'based solely on automated processing' if there is no meaningful huma
 n involvement\; where a significant decision is taken about a data subjec
 t based solely on automated processing\, the controller must ensure safeg
 uards consisting of or including measures to provide information about th
 e decision\, enable representations\, enable human intervention and enabl
 e the decision to be contested. Commencement Regulation 5 of SI 2026/82 s
 aves the old Article 22(3) regime for decisions taken before 5 February 2
 026\, so the new duties bite on decisions taken from that date.\nApplies 
 to: data controllers\, data processors\, deployers of automated decision 
 systems\nWho: all\nPenalty: UK GDPR / DPA 2018 enforcement: penalty notic
 es up to the higher maximum (GBP 17.5m or 4% of total annual worldwide tu
 rnover)\, plus enforcement notices and data subject compensation claims\n
 Source says: "The following provisions of the 2025 Act\, so far as not al
 ready in force\, come into force on 5th February 2026— ... (j) section 
 80 (automated decision-making)\; ... (z8) Schedule 6 (automated decision-
 making: minor and consequential amendments)."\nSource: https://www.legisl
 ation.gov.uk/uksi/2026/82/regulation/2/made\nVerified: Aug 30\, 2026\nhtt
 ps://agenccy.ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:United Kingdom: New UK GDPR Articles 22A-22D automated decisio
 n-making regime takes effect: controllers taking significant solely-autom
 ated decisions must have safeguards in place
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:tw|artificial-intelligence-basic-act-promulgated-by-presidential-order
 -11|taiwan-s-ai-basic-act-enters-into-force-on-promulgation-20-a|2026-01-
 14@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20260114
DTEND;VALUE=DATE:20260115
SUMMARY:Taiwan: Taiwan's AI Basic Act enters into force on promulgation: 2
 0 articles establishing the 7 governing principles\, a duty that high-ris
 k AI applications be labelled (Art. 5)\, MODA-led AI risk-classification 
 framework and sectoral management rules with power to restrict or prohibi
 t unlawful applications (Art. 16)\, and allocation of liability plus a re
 dress/compensation mechanism for high-risk AI applications (Art. 17)
DESCRIPTION:Taiwan's AI Basic Act enters into force on promulgation: 20 ar
 ticles establishing the 7 governing principles\, a duty that high-risk AI
  applications be labelled (Art. 5)\, MODA-led AI risk-classification fram
 ework and sectoral management rules with power to restrict or prohibit un
 lawful applications (Art. 16)\, and allocation of liability plus a redres
 s/compensation mechanism for high-risk AI applications (Art. 17)\nArtific
 ial Intelligence Basic Act (人工智慧基本法)\, promulgated by Presi
 dential Order 華總一義字第11500001671號 of 14 January 2026\nPassed
  by the Legislative Yuan at third reading on 23 December 2025 (民國114
 年12月23日)\; promulgated and brought into force 14 January 2026. Cent
 ral competent authority: National Science and Technology Council (國科
 會)\; local: municipal and county governments. Art. 18 requires governme
 nt to complete adaptation of laws and administrative measures within two 
 years of commencement (a PERIOD\, not a stated date — not recorded as a
  separate row). Art. 6 requires the Executive Yuan to establish a Nationa
 l AI Strategy Special Committee and adopt a National AI Development Progr
 amme.\nApplies to: developer\, provider\, deployer\, government\nWho: all
 \nPenalty: No penal provisions in the Act itself. Enforcement runs throug
 h sectoral competent authorities: under Art. 16\, where an application br
 eaches Art. 5 it 'shall be restricted or prohibited in accordance with la
 ws and regulations' (有第5條違法情事者，應依法令限制或禁
 止).\nSource says: "公布日期：民國 115 年 01 月 14 日 … 第
 二十條「本法自公布之日起施行。」 // 'Promulgation date: 1
 4 January 2026 (ROC year 115) … Article 20: This Act shall come into fo
 rce from the date of promulgation.'"\nSource: https://law.moj.gov.tw/LawC
 lass/LawAll.aspx?pcode=H0160093\nVerified: Aug 30\, 2026\nhttps://agenccy
 .ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:Taiwan: Taiwan's AI Basic Act enters into force on promulgatio
 n: 20 articles establishing the 7 governing principles\, a duty that high
 -risk AI applications be labelled (Art. 5)\, MODA-led AI risk-classificat
 ion framework and sectoral management rules with power to restrict or pro
 hibit unlawful applications (Art. 16)\, and allocation of liability plus 
 a redress/compensation mechanism for high-risk AI applications (Art. 17)
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:qa-qfc|qicdrc-practice-direction-no-1-of-2026-with-accompanying-practi
 ce-guid|litigants-and-legal-representatives-before-the-qfc-court-and|2026
 -01-06@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20260106
DTEND;VALUE=DATE:20260107
SUMMARY:Qatar — Qatar Financial Centre (QICDRC courts): Litigants and le
 gal representatives before the QFC Court and the Regulatory Tribunal must
  verify the accuracy of AI-assisted submissions\, identify AI-assisted po
 rtions when required\, and must not input confidential\, privileged or le
 gally protected information into publicly available AI tools
DESCRIPTION:Litigants and legal representatives before the QFC Court and t
 he Regulatory Tribunal must verify the accuracy of AI-assisted submission
 s\, identify AI-assisted portions when required\, and must not input conf
 idential\, privileged or legally protected information into publicly avai
 lable AI tools\nQICDRC Practice Direction No. 1 of 2026\, with accompanyi
 ng Practice Guidance on the use of artificial intelligence in court proce
 edings\nIssued by the Qatar International Court and Dispute Resolution Ce
 ntre following the judgment in Jonathan David Sheppard v Jillion LLC [202
 5] QIC (E) 3. Sets a framework for the responsible\, transparent and disc
 iplined use of AI tools in proceedings. Legal representatives remain resp
 onsible for the accuracy of all material submitted regardless of whether 
 AI was used\; where the Court requires it\, they must identify AI-assiste
 d portions and explain the steps taken to verify accuracy and ensure comp
 liance with professional and ethical standards. Advance disclosure of AI 
 use is not automatically mandatory unless the Court requires it.\nApplies
  to: litigants\, legal representatives\, counsel\nWho: all\nPenalty: Cour
 t sanctions in proceedings — exclusion of AI-generated evidence\, adver
 se costs and professional/ethical consequences for legal representatives\
 ; no separate monetary penalty schedule\nSource says: "The Qatar Internat
 ional Court and Dispute Resolution Centre (QICDRC) has issued Practice Di
 rection No. 1 of 2026\, together with accompanying Practice Guidance on t
 he use of artificial intelligence in court proceedings\, setting out a co
 mprehensive framework governing the responsible\, transparent\, and disci
 plined use of AI tools before the QFC Court and the Regulatory Tribunal."
 \nSource: https://www.qicdrc.gov.qa/media-center/news/qicdrc-issues-pract
 ice-direction-no-1-2026-and-practice-guidance-use-artificial\nVerified: A
 ug 30\, 2026\nhttps://agenccy.ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:Qatar — Qatar Financial Centre (QICDRC courts): Litigants an
 d legal representatives before the QFC Court and the Regulatory Tribunal 
 must verify the accuracy of AI-assisted submissions\, identify AI-assiste
 d portions when required\, and must not input confidential\, privileged o
 r legally protected information into publicly available AI tools
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:vn|law-on-digital-technology-industry-no-71-2025-qh15-lu-t-c-ng-nghi-p
 -c|first-binding-vietnamese-ai-transparency-duties-took-effect|2026-01-01
 @agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Vietnam: First binding Vietnamese AI transparency duties took effe
 ct: an AI system interacting directly with a person must tell the user th
 ey are interacting with an AI system\, and digital products on the Minist
 er's list of AI-generated digital products must carry an identifying mark
  readable by a person or a machine
DESCRIPTION:First binding Vietnamese AI transparency duties took effect: a
 n AI system interacting directly with a person must tell the user they ar
 e interacting with an AI system\, and digital products on the Minister's 
 list of AI-generated digital products must carry an identifying mark read
 able by a person or a machine\nLaw on Digital Technology Industry No. 71/
 2025/QH15 (Luật Công nghiệp công nghệ số)\, Chapter IV — Arti
 ficial Intelligence\, Art. 44\nLaw passed 14 June 2025\, published in Cô
 ng báo issues 965+966 of 24 July 2025\, signed by National Assembly Chai
 rman Trần Thanh Mẫn. 6 chapters\, 51 articles\; Chapter IV (Arts. 41-
 45) covered AI. The Minister of Science and Technology was to issue the L
 ist of AI-generated digital products and to inspect compliance. SUPERSEDE
 D: Art. 34 of the Law on Artificial Intelligence No. 134/2025/QH15 repeal
 s Chapter IV of Law 71/2025/QH15 (together with Art. 3(9)\, Art. 4(7)\, A
 rt. 12(6) and Art. 34(2)(dd)) with effect from 1 March 2026\; equivalent 
 transparency and AI-content labelling duties continue under the AI Law.\n
 Applies to: provider\, deployer\nWho: all\nPenalty: Administrative inspec
 tion by the Ministry of Science and Technology\; general administrative l
 iability\nSource says: "Ngày ban hành: 14/06/2025\; Ngày hiệu lực:
  01/01/2026 (Công báo số 965 + 966\, ngày 24/7/2025\; người ký: 
 Trần Thanh Mẫn). // 'Issued 14 June 2025\; effective 1 January 2026.'
 "\nSource: https://congbao.chinhphu.vn/van-ban/luat-so-71-2025-qh15-45555
 .htm\nVerified: Aug 30\, 2026\nhttps://agenccy.ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:Vietnam: First binding Vietnamese AI transparency duties took 
 effect: an AI system interacting directly with a person must tell the use
 r they are interacting with an AI system\, and digital products on the Mi
 nister's list of AI-generated digital products must carry an identifying 
 mark readable by a person or a machine
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:ca-on|employment-standards-act-2000-s-o-2000-c-41-part-iii-1-job-posti
 ngs-s|employers-must-disclose-in-a-publicly-advertised-job-posting|2026-0
 1-01@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Canada — Ontario: Employers must disclose in a publicly advertis
 ed job posting that artificial intelligence is used to screen\, assess or
  select applicants
DESCRIPTION:Employers must disclose in a publicly advertised job posting t
 hat artificial intelligence is used to screen\, assess or select applican
 ts\nEmployment Standards Act\, 2000 (S.O. 2000\, c. 41)\, Part III.1 'Job
  Postings'\, s. 8.4 — added by the Working for Workers Four Act\, 2024 
 (S.O. 2024\, c. 3)\, Schedule 2\, s. 2(1)\; supported by O. Reg. 476/24 (
 Rules and Exemptions re Job Postings)\ns. 8.4(1) is a positive disclosure
  duty: if AI is used anywhere in screening\, assessment or selection for 
 the advertised position\, a statement disclosing that use must appear in 
 the posting itself. O. Reg. 476/24 defines 'artificial intelligence' in O
 ECD terms and exempts employers with fewer than 25 employees on the day t
 he posting is posted\, general recruitment campaigns and help-wanted sign
 s that do not advertise a specific position\, internal-only postings\, an
 d postings for work performed outside Ontario. This is the first in-force
  statutory AI-hiring disclosure duty in Canada.\nApplies to: employer\, d
 eployer\nWho: employers with 25 or more employees on the day the posting 
 is posted (O. Reg. 476/24 s. 1 exempts employers with fewer than 25 emplo
 yees)\nPenalty: Enforced under the Employment Standards Act\, 2000: emplo
 yment standards officers may issue compliance orders and notices of contr
 avention carrying prescribed administrative penalties\, and contravention
  of the Act is an offence prosecutable under Part XXV of the ESA.\nSource
  says: "Use of artificial intelligence — 8.4 (1) Every employer who adv
 ertises a publicly advertised job posting and who uses artificial intelli
 gence to screen\, assess or select applicants for the position shall incl
 ude in the posting a statement disclosing the use of the artificial intel
 ligence. 2024\, c. 3\, Sched. 2\, s. 2 (1). [Section Amendments with date
  in force (d/m/y): 2024\, c. 3\, Sched. 2\, s. 2 (1) - 01/01/2026]"\nSour
 ce: https://www.ontario.ca/laws/statute/00e41\nVerified: Aug 30\, 2026\nh
 ttps://agenccy.ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:Canada — Ontario: Employers must disclose in a publicly adve
 rtised job posting that artificial intelligence is used to screen\, asses
 s or select applicants
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:ca-qc|indication-d-application-ia-ri-2025-003-op-mesures-applicables-l
 ors-de|binding-generative-ai-measures-apply-to-quebec-public-bodies|2025-
 12-05@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20251205
DTEND;VALUE=DATE:20251206
SUMMARY:Canada — Quebec: Binding generative-AI measures apply to Quebec 
 public bodies: organizational AI governance structure\, risk and complian
 ce review before deployment\, data-protection and confidentiality rules\,
  mandatory preference for secure private GenAI systems over public ones\,
  and lifecycle quality/security controls
DESCRIPTION:Binding generative-AI measures apply to Quebec public bodies: 
 organizational AI governance structure\, risk and compliance review befor
 e deployment\, data-protection and confidentiality rules\, mandatory pref
 erence for secure private GenAI systems over public ones\, and lifecycle 
 quality/security controls\nIndication d'application IA-RI-2025-003-OP —
  « Mesures applicables lors de l'utilisation de l'intelligence artificie
 lle générative » (formulated by the Dirigeant principal de l'informati
 on under LGGRI\, chapitre G-1.03\, art. 7)\; complements arrêté minist
 ériel 2025-02 of 3 December 2025 (Énoncé de principes pour une utilisa
 tion responsable de l'IA par les organismes publics)\nAn 'indication d'ap
 plication' is a written instruction with which public bodies MUST comply 
 under the Act respecting the governance and management of the information
  resources of public bodies and government enterprises (chapter G-1.03). 
 Status field on the instrument reads 'En vigueur'. It applies to the publ
 ic bodies listed in s.2 of the LGGRI — ministries\, government agencies
 \, health and social services bodies\, school service centres and Crown c
 orporations. It also repeals the earlier IA-RI-2025-001-OP suspension of 
 generative-AI virtual assistants\, and sits alongside standing prohibitio
 ns (DeepSeek assistants\, Microsoft Teams voice/face enrolment).\nApplies
  to: deployer\, user\nWho: all bodies covered by art. 2 LGGRI\nPenalty: N
 o monetary penalty in the instrument. Compliance is mandatory under the L
 GGRI (c. G-1.03)\; the Dirigeant principal de l'information may under art
 . 24 exempt a body in whole or in part and set conditions. Enforcement is
  administrative through the Ministère de la Cybersécurité et du Numér
 ique.\nSource says: "Statut : En vigueur — No de référence : IA-RI-20
 25-003-OP — Organismes visés : Organismes publics — Référence lég
 ale : LGGRI (chapitre G-1.03)\, art. 7 — Date de formulation : 2025-12-
 05 — Date d'entrée en vigueur : 2025-12-05"\nSource: https://cdn-conte
 nu.quebec.ca/cdn-contenu/adm/min/cybersecurite_numerique/Publications/Str
 ategie_IA/Indication_app_IAG.pdf\nVerified: Aug 30\, 2026\nhttps://agencc
 y.ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Law applies
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:Canada — Quebec: Binding generative-AI measures apply to Que
 bec public bodies: organizational AI governance structure\, risk and comp
 liance review before deployment\, data-protection and confidentiality rul
 es\, mandatory preference for secure private GenAI systems over public on
 es\, and lifecycle quality/security controls
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:nz|biometric-processing-privacy-code-2025-issued-by-the-privacy-commis
 sio|binding-code-of-practice-for-automated-biometric-processing|2025-11-0
 3@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20251103
DTEND;VALUE=DATE:20251104
SUMMARY:New Zealand: Binding code of practice for automated biometric proc
 essing comes into force for NEW biometric processing: 13 modified privacy
  rules including a proportionality assessment before collection (Rule 1 
 — lawful purpose\, necessity\, effectiveness and no less privacy-intrus
 ive alternative reasonably available)\, transparency/notification duties\
 , restrictions on biometric categorisation\, retention limits and cross-b
 order safeguards
DESCRIPTION:Binding code of practice for automated biometric processing co
 mes into force for NEW biometric processing: 13 modified privacy rules in
 cluding a proportionality assessment before collection (Rule 1 — lawful
  purpose\, necessity\, effectiveness and no less privacy-intrusive altern
 ative reasonably available)\, transparency/notification duties\, restrict
 ions on biometric categorisation\, retention limits and cross-border safe
 guards\nBiometric Processing Privacy Code 2025\, issued by the Privacy Co
 mmissioner under the Privacy Act 2020\nApplies to organisations that coll
 ect biometric information in an AUTOMATED process to verify\, identify or
  categorise people. 'Biometric categorisation' expressly covers inference
  systems — e.g. using a biometric system to infer someone's emotions fr
 om their voice or to estimate their age from their face. Health agencies 
 carrying out biometric processing to deliver health services are outside 
 the Code.\nApplies to: deployer\, provider\nWho: all agencies as defined 
 in the Privacy Act 2020\nPenalty: Breach of a code rule is treated as an 
 interference with privacy under the Privacy Act 2020 — complaints to th
 e Privacy Commissioner\, compliance notices\, and Human Rights Review Tri
 bunal proceedings with damages. OPC applies its Compliance and Regulatory
  Action Framework.\nSource says: "The Biometric Processing Privacy Code 2
 025 (BPPC) was issued on 21 July 2025. … The BPPC came into force on 3 
 November 2025\, but agencies already using biometrics had a nine-month gr
 ace period to move to the new set of rules."\nSource: https://www.privacy
 .org.nz/privacy-principles/codes-of-practice/biometric-processing-privacy
 -code/\nVerified: Aug 30\, 2026\nhttps://agenccy.ai/ai-compliance-calenda
 r/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:New Zealand: Binding code of practice for automated biometric 
 processing comes into force for NEW biometric processing: 13 modified pri
 vacy rules including a proportionality assessment before collection (Rule
  1 — lawful purpose\, necessity\, effectiveness and no less privacy-int
 rusive alternative reasonably available)\, transparency/notification duti
 es\, restrictions on biometric categorisation\, retention limits and cros
 s-border safeguards
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:ng|nigeria-data-protection-act-ndp-act-2023-general-application-and-im
 ple|data-controllers-and-data-processors-deploying-artificial-in|2025-09-
 19@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20250919
DTEND;VALUE=DATE:20250920
SUMMARY:Nigeria: Data controllers and data processors deploying Artificial
  Intelligence (and other emerging technologies) to process personal data 
 must set and document technical and organisational parameters\, carry out
  a DPIA\, test in low-risk environments\, assess disparate outcomes\, re-
 test\, and put continuous monitoring in place — with the parameters and
  DPIA filed with the Commission as part of NDP Act Compliance Audit Retur
 ns
DESCRIPTION:Data controllers and data processors deploying Artificial Inte
 lligence (and other emerging technologies) to process personal data must 
 set and document technical and organisational parameters\, carry out a DP
 IA\, test in low-risk environments\, assess disparate outcomes\, re-test\
 , and put continuous monitoring in place — with the parameters and DPIA
  filed with the Commission as part of NDP Act Compliance Audit Returns\nN
 igeria Data Protection Act (NDP Act) 2023 — General Application and Imp
 lementation Directive (GAID) 2025\, ref. NDPC/NDP ACT-GAID/01/2025\, Arti
 cle 43 (Emerging Technologies)\nArticle 43(1) applies to any controller/p
 rocessor who 'deploys or intends to deploy Emerging Technologies (ETs) su
 ch as Artificial Intelligence\, Internet of Things and Blockchain for the
  purposes of processing personal data'. Art 43(2) requires parameters tha
 t take account of the right not to be subject to a decision solely based 
 on automated processes or algorithms\, the right to be forgotten\, sensit
 ive-data and child safeguards\, cross-border flows\, and privacy by desig
 n and default. Art 43(3) makes the parameters filable with the Commission
  as part of the Compliance Audit Return. Art 43(4) requires a DPIA (accou
 nting for disparate outcomes and Data Subjects' Vulnerability Indexes)\, 
 data anonymisation suitability\, low-risk-environment testing\, retooling
  and re-testing until satisfactory or discarding the tool for unmitigable
  privacy risk\, and continuous monitoring once deemed safe. Art 44(3) req
 uires controllers to 'refrain from or cease the use of ET systems that ar
 e impossible to operate in compliance with international human rights law
 '. GAID repealed the NDPR 2019 and the NDPR Implementation Framework 2020
 .\nApplies to: data controller\, data processor\, data controllers and pr
 ocessors of major importance\, Data Protection Officer\nWho: all\; heavie
 r registration and audit duties for Data Controllers/Processors of Major 
 Importance\nPenalty: Enforcement under the NDP Act 2023: sanctions up to 
 NGN 10\,000\,000 or 2% of annual gross revenue in the preceding year for 
 data controllers of major importance (NGN 2\,000\,000 or 2% for others)\,
  plus remediation orders and compensation\nSource says: "Issued under my 
 hand this 20th Day of March\, 2025"\nSource: https://ndpc.gov.ng/wp-conte
 nt/uploads/2025/07/NDP-ACT-GAID-2025-MARCH-20TH.pdf\nVerified: Aug 30\, 2
 026\nhttps://agenccy.ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:Nigeria: Data controllers and data processors deploying Artifi
 cial Intelligence (and other emerging technologies) to process personal d
 ata must set and document technical and organisational parameters\, carry
  out a DPIA\, test in low-risk environments\, assess disparate outcomes\,
  re-test\, and put continuous monitoring in place — with the parameters
  and DPIA filed with the Commission as part of NDP Act Compliance Audit R
 eturns
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:cn|measures-for-labelling-ai-generated-synthetic-content-mandatory-sta
 nda|explicit-and-implicit-labelling-of-ai-generated-text-images|2025-09-0
 1@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20250901
DTEND;VALUE=DATE:20250902
SUMMARY:China: Explicit and implicit labelling of AI-generated text\, imag
 es\, audio\, video and virtual scenes
DESCRIPTION:Explicit and implicit labelling of AI-generated text\, images\
 , audio\, video and virtual scenes\nMeasures for Labelling AI-Generated S
 ynthetic Content + mandatory standard GB 45438-2025\nProviders of generat
 ion and synthesis services must attach both visible labels and embedded m
 etadata\; distribution platforms must verify and surface them. In force s
 ince 1 September 2025 — listed as the standing baseline every later Chi
 nese AI rule builds on.\nApplies to: provider\, platform\nSource says: "M
 easures\, Article 14 (verbatim): '本办法自2025年9月1日起施行' =
  'These Measures shall come into force on 1 September 2025.' Article 3 de
 fines the two labelling modes and the covered content: 显式标识 = a l
 abel 'presented by way of text\, sound\, graphics etc. and able to be cle
 arly perceived by users'\; 隐式标识 = a label 'added by technical mea
 ns into the data of the generated or synthetic content file\, not readily
  perceptible to users'\; covered content is '文本、图片、音频、
 视频、虚拟场景等信息' = 'text\, images\, audio\, video\, virtua
 l scenes and other information'. Article 13 (enforcement): '由网信、
 电信、公安和广播电视等有关主管部门依据职责，按照
 有关法律、行政法规、部门规章的规定予以处理' = 'the c
 ompetent cyberspace\, telecommunications\, public security and radio-and-
 television authorities shall handle it according to their duties and in a
 ccordance with relevant laws\, administrative regulations and departmenta
 l rules.' GB 45438-2025\, per the official SAMR national standards databa
 se: 标准号 GB 45438-2025\, 中文标准名称 '网络安全技术 人
 工智能生成合成内容标识方法' (Cybersecurity technology - Labe
 lling method for AI-generated synthetic content)\, 标准性质 强制性
  (MANDATORY)\, 发布日期 2025-02-28\, 实施日期 2025-09-01."\nSourc
 e: https://www.cac.gov.cn/2025-03/14/c_1743654684782215.htm\nVerified: Au
 g 30\, 2026\nhttps://agenccy.ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:China: Explicit and implicit labelling of AI-generated text\, 
 images\, audio\, video and virtual scenes
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:ca-ab|protection-of-privacy-act-popa-sa-2024-c-p-27-5-s-5-2-d-and-the-
 protec|public-bodies-must-state-in-their-collection-notice-when-per|2025-
 06-11@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20250611
DTEND;VALUE=DATE:20250612
SUMMARY:Canada — Alberta: Public bodies must state in their collection n
 otice when personal information being collected will be used in an automa
 ted system to generate content or to make decisions\, recommendations or 
 predictions
DESCRIPTION:Public bodies must state in their collection notice when perso
 nal information being collected will be used in an automated system to ge
 nerate content or to make decisions\, recommendations or predictions\nPro
 tection of Privacy Act (POPA)\, SA 2024\, c. P-27.5\, s. 5(2)(d)\, and th
 e Protection of Privacy Regulation / Protection of Privacy (Ministerial) 
 Regulation\nPOPA replaced Alberta's Freedom of Information and Protection
  of Privacy Act for the public sector. s. 5(2)(d) makes AI/automated-syst
 em use a mandatory element of the collection notice given to individuals.
  Alberta's own guidance adds that where an automated system is actually u
 sed to make decisions\, the public body must make every reasonable effort
  to ensure the accuracy and completeness of the personal information and 
 retain it for at least one year after use. The Act applies from proclamat
 ion forward: personal information collected before that date may still be
  used in AI/automated systems\, but collection notices must be updated as
  new information is collected or programs are revised.\nApplies to: deplo
 yer\, controller\nWho: all public bodies designated under the Access to I
 nformation Act s. 1(t) and the Designation of Public Bodies Regulation\nP
 enalty: POPA carries what the Government of Alberta describes as the stro
 ngest penalties for privacy violations in Canada\; offences under the Act
  are punishable by fines\, and the Information and Privacy Commissioner o
 f Alberta has investigation and order powers.\nSource says: "The Protecti
 on of Privacy Act (POPA) and regulation came into force June 11\, 2025. U
 pon proclamation\, the Freedom of Information and Protection of Privacy A
 ct was repealed."\nSource: https://www.alberta.ca/about-the-protection-of
 -privacy-act\nVerified: Aug 30\, 2026\nhttps://agenccy.ai/ai-compliance-c
 alendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:Canada — Alberta: Public bodies must state in their collecti
 on notice when personal information being collected will be used in an au
 tomated system to generate content or to make decisions\, recommendations
  or predictions
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:sg|elections-integrity-of-online-advertising-amendment-act-2024-act-34
 -of|criminal-ban-during-an-election-period-on-publishing-boostin|2025-01-
 22@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20250122
DTEND;VALUE=DATE:20250123
SUMMARY:Singapore: Criminal ban\, during an election period\, on publishin
 g\, boosting\, sharing or reposting online election advertising that cont
 ains a realistic but false digitally generated or manipulated depiction o
 f a candidate saying or doing something they did not say or do\; Returnin
 g Officer may issue corrective directions to individuals\, social media s
 ervices and internet access service providers to take down or block such 
 content
DESCRIPTION:Criminal ban\, during an election period\, on publishing\, boo
 sting\, sharing or reposting online election advertising that contains a 
 realistic but false digitally generated or manipulated depiction of a can
 didate saying or doing something they did not say or do\; Returning Offic
 er may issue corrective directions to individuals\, social media services
  and internet access service providers to take down or block such content
 \nElections (Integrity of Online Advertising) (Amendment) Act 2024 (Act 3
 4 of 2024)\, inserting s.61MA into the Parliamentary Elections Act 1954 a
 nd an equivalent provision into the Presidential Elections Act 1991\; com
 menced by Commencement Notification 2025 (S 47/2025)\nThe prohibition bit
 es from the issue of the Writ of Election until the close of polling. Ele
 ments of the offence include that 'the representation was created wholly 
 or partly with content that was generated or manipulated using digital me
 ans' and that it is 'realistic enough such that it is likely that some me
 mbers of the general public would ... reasonably believe that the candida
 te said or did that thing'.\nApplies to: individual\, platform\, social-m
 edia-service\, internet-access-service-provider\nWho: all\nPenalty: Crimi
 nal offence\; Returning Officer corrective directions with offences for n
 on-compliance (Parliamentary Elections Act 1954 as amended)\nSource says:
  "2. The Elections (Integrity of Online Advertising) (Amendment) Act 2024
  comes into operation on 22 January 2025. — Made on 16 January 2025. LE
 O YIP\, Permanent Secretary\, Prime Minister's Office\, Singapore. [First
  published in the Government Gazette\, Electronic Edition\, on 20 January
  2025 at 5 pm.]"\nSource: https://www.eld.gov.sg/gazettes/2025/Elections%
 20(Integrity%20of%20Online%20Advertising)%20(Amendment)%20Act%202024%20(C
 ommencement)%20Notification%202025.pdf\nVerified: Aug 30\, 2026\nhttps://
 agenccy.ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Enforcement
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:Singapore: Criminal ban\, during an election period\, on publi
 shing\, boosting\, sharing or reposting online election advertising that 
 contains a realistic but false digitally generated or manipulated depicti
 on of a candidate saying or doing something they did not say or do\; Retu
 rning Officer may issue corrective directions to individuals\, social med
 ia services and internet access service providers to take down or block s
 uch content
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:ca-qc|loi-25-act-to-modernize-legislative-provisions-as-regards-the-pr
 otecti|automated-decision-making-transparency-notify-the-individual|2023-
 09-22@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20230922
DTEND;VALUE=DATE:20230923
SUMMARY:Canada — Quebec: Automated decision-making transparency: notify 
 the individual when a decision is based exclusively on automated processi
 ng of personal information\, and on request disclose the personal informa
 tion used\, the reasons and the principal factors and parameters that led
  to the decision\, plus the right to have that information corrected and 
 to submit observations to a member of staff able to review the decision
DESCRIPTION:Automated decision-making transparency: notify the individual 
 when a decision is based exclusively on automated processing of personal 
 information\, and on request disclose the personal information used\, the
  reasons and the principal factors and parameters that led to the decisio
 n\, plus the right to have that information corrected and to submit obser
 vations to a member of staff able to review the decision\nLoi 25 — Act 
 to modernize legislative provisions as regards the protection of personal
  information (assented 22 September 2021\, LQ 2021\, c. 25)\, inserting s
 . 12.1 into the Act respecting the protection of personal information in 
 the private sector (RLRQ c. P-39.1) and s. 65.2 into the Act respecting a
 ccess to documents held by public bodies (RLRQ c. A-2.1)\nBroader than GD
 PR Art. 22: Quebec's duty attaches to ANY decision based exclusively on a
 utomated processing of personal information\, with no legal-effects or si
 gnificant-effects threshold and no exemption list. It binds every person 
 carrying on an enterprise in Quebec (s. 12.1 P-39.1) and\, in parallel\, 
 every public body (s. 65.2 Act respecting access). The Government of Queb
 ec's own guidance states a decision is 'exclusively automated' where no n
 atural person exercised meaningful control\, and that minor human interve
 ntion with no real effect on the outcome does not take the decision outsi
 de the rule.\nApplies to: deployer\, controller\nWho: no size threshold\;
  applies to any person carrying on an enterprise\nPenalty: Administrative
  monetary penalties up to CAD 10\,000\,000 or 2% of worldwide turnover (w
 hichever is greater) and penal fines up to CAD 25\,000\,000 or 4% of worl
 dwide turnover\, under the Law 25 enforcement provisions in force since 2
 2 September 2023\; plus a private right of action for punitive damages fo
 r intentional or grossly negligent breaches.\nSource says: "Date de la sa
 nction : 22 septembre 2021 — Chapitre dans le Recueil annuel des lois d
 u Québec : 2021\, chapitre 25 — Mode d'entrée en vigueur : le 22 sept
 embre 2023\, sauf exceptions"\nSource: https://www.assnat.qc.ca/fr/travau
 x-parlementaires/projets-loi/projet-loi-64-42-1.html\nVerified: Aug 30\, 
 2026\nhttps://agenccy.ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:Canada — Quebec: Automated decision-making transparency: not
 ify the individual when a decision is based exclusively on automated proc
 essing of personal information\, and on request disclose the personal inf
 ormation used\, the reasons and the principal factors and parameters that
  led to the decision\, plus the right to have that information corrected 
 and to submit observations to a member of staff able to review the decisi
 on
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:ae-difc|difc-data-protection-regulations-consolidated-version-no-2-reg
 ulation|deployers-and-operators-of-autonomous-semi-autonomous-system|2023
 -09-01@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20230901
DTEND;VALUE=DATE:20230902
SUMMARY:United Arab Emirates — DIFC: Deployers and Operators of autonomo
 us/semi-autonomous systems (incl. AI and machine-learning systems) that p
 rocess personal data must meet Regulation 10 design\, transparency\, acco
 untability and high-risk requirements
DESCRIPTION:Deployers and Operators of autonomous/semi-autonomous systems 
 (incl. AI and machine-learning systems) that process personal data must m
 eet Regulation 10 design\, transparency\, accountability and high-risk re
 quirements\nDIFC Data Protection Regulations\, Consolidated Version No. 2
  — Regulation 10 (Personal Data Processed Through Autonomous and Semi-A
 utonomous Systems)\, made under DIFC Data Protection Law No. 5 of 2020\nR
 egulation 10 is the first binding AI-specific data protection instrument 
 in the MEASA region. Reg 10.3.2 prohibits commercial use of a System to p
 rocess personal data unless it processes only for human-defined or human-
 approved purposes and is designed in compliance with Reg 10.3.1 (ethical\
 , fair\, transparent\, secure\, accountable). Reg 10.3.3 adds conditions 
 for High Risk Processing Activities\, including appointment of an Autonom
 ous Systems Officer (ASO). Reg 10.2.2 requires notice to individuals abou
 t the underlying technology. General certification requirements are left 
 to future Commissioner guidance and were still outstanding as of January 
 2026.\nApplies to: Deployer\, Operator\, Provider\, Controller\, Processo
 r\nWho: all\nPenalty: Fines under the DIFC Data Protection Law No. 5 of 2
 020 fines schedule\, as revised by DIFC Laws Amendment Law No. 1 of 2025:
  USD 50\,000 for failing to comply with the general Article 9 processing 
 requirements (which Regulation 10.2.1 expressly applies to System process
 ing) and USD 50\,000 for failing to carry out a DPIA prior to High Risk P
 rocessing Activities (raised from USD 20\,000). The Commissioner may also
  issue directions and enforcement notices\, and since 15 July 2025 data s
 ubjects have a direct right of action in the DIFC Courts for compensation
  including non-financial damage such as distress.\nSource says: "In force
  on 1 September 2023"\nSource: https://www.dataguidance.com/sites/default
 /files/data_protection_regualtions_final.pdf\nVerified: Aug 30\, 2026\nht
 tps://agenccy.ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:United Arab Emirates — DIFC: Deployers and Operators of auto
 nomous/semi-autonomous systems (incl. AI and machine-learning systems) th
 at process personal data must meet Regulation 10 design\, transparency\, 
 accountability and high-risk requirements
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:us|fedreg|2026-13656|2026-08-31@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20260831
DTEND;VALUE=DATE:20260901
SUMMARY:United States — federal: CMS CY2027 hospital outpatient (OPPS/AS
 C) payment rule
DESCRIPTION:CMS CY2027 hospital outpatient (OPPS/ASC) payment rule\nHealth
  and Human Services Department — Proposed Rule\nCMS CY2027 hospital out
 patient (OPPS/ASC) payment rule\; section X.B proposes an interim Medicar
 e payment framework for AI/algorithm-driven clinical software (renaming S
 aaS to 'Software as a Medical Service'\, new status indicator O1\, 36 HCP
 CS codes moved to new-technology APCs) and asks for comment on it.\nAppli
 es to: any interested party\nSource says: "comments_close_on: 2026-08-31 
 (Federal Register API)"\nSource: https://www.federalregister.gov/document
 s/2026/07/07/2026-13656/medicare-program-hospital-outpatient-prospective-
 payment-and-ambulatory-surgical-center-payment\nVerified: Aug 30\, 2026\n
 https://agenccy.ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Comments close
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:United States — federal: CMS CY2027 hospital outpatient (OPP
 S/ASC) payment rule
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:us|fedreg|2026-15483|2026-08-31@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20260831
DTEND;VALUE=DATE:20260901
SUMMARY:United States — federal: NHTSA seeks comment on interim guidance
  for 49 CFR part 555 'General Exemption' applications that let…
DESCRIPTION:NHTSA seeks comment on interim guidance for 49 CFR part 555 'G
 eneral Exemption' applications that let…\nTransportation Department —
  Notice\nNHTSA seeks comment on interim guidance for 49 CFR part 555 'Gen
 eral Exemption' applications that let automated-driving-system vehicles b
 e commercially deployed without meeting all FMVSS\, and on how the exempt
 ion process for ADS vehicles could be improved.\nApplies to: any interest
 ed party\nSource says: "comments_close_on: 2026-08-31 (Federal Register A
 PI)"\nSource: https://www.federalregister.gov/documents/2026/07/31/2026-1
 5483/av-framework-updates-and-request-for-comments-on-interim-guidance\nV
 erified: Aug 30\, 2026\nhttps://agenccy.ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Comments close
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:United States — federal: NHTSA seeks comment on interim guid
 ance for 49 CFR part 555 'General Exemption' applications that let…
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:us|fedreg|2026-13928|2026-09-08@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20260908
DTEND;VALUE=DATE:20260909
SUMMARY:United States — federal: BLS seeks comment on adding a new AI mo
 dule to the American Time Use Survey
DESCRIPTION:BLS seeks comment on adding a new AI module to the American Ti
 me Use Survey\nLabor Department — Notice\nBLS seeks comment on adding a
  new AI module to the American Time Use Survey - questions on whether peo
 ple use AI tools\, for which tasks\, and how AI use varies by demographic
 /occupational group - to be fielded from January 2027 for two years.\nApp
 lies to: any interested party\nSource says: "comments_close_on: 2026-09-0
 8 (Federal Register API)"\nSource: https://www.federalregister.gov/docume
 nts/2026/07/10/2026-13928/proposed-information-collection-atus-artificial
 -intelligence-ai-questions\nVerified: Aug 30\, 2026\nhttps://agenccy.ai/a
 i-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Comments close
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:United States — federal: BLS seeks comment on adding a new A
 I module to the American Time Use Survey
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:eu|cyber-resilience-act-regulation-eu-2024-2847|manufacturers-must-rep
 ort-actively-exploited-vulnerabilities|2026-09-11@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20260911
DTEND;VALUE=DATE:20260912
SUMMARY:European Union: Manufacturers must report actively exploited vulne
 rabilities and severe incidents to ENISA and the national CSIRT
DESCRIPTION:Manufacturers must report actively exploited vulnerabilities a
 nd severe incidents to ENISA and the national CSIRT\nCyber Resilience Act
  (Regulation (EU) 2024/2847)\nEarly-warning notification within 24 hours 
 to the CSIRT designated as coordinator and to ENISA\, via the Article 16 
 single reporting platform. Covers products with digital elements\; Articl
 e 12 explicitly extends to products classified as high-risk AI systems un
 der Article 6 of the AI Act.\nApplies to: manufacturer\nPenalty: Up to EU
 R 15 000 000 or 2.5% of total worldwide annual turnover\, whichever is hi
 gher (Art. 64(2))\nSource says: "This Regulation shall apply from 11 Dece
 mber 2027. However\, Article 14 shall apply from 11 September 2026 and Ch
 apter IV (Articles 35 to 51) shall apply from 11 June 2026. (Article 71(2
 )\, Entry into force and application)"\nSource: https://eur-lex.europa.eu
 /eli/reg/2024/2847/oj/eng\nVerified: Aug 30\, 2026\nhttps://agenccy.ai/ai
 -compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Reporting
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:European Union: Manufacturers must report actively exploited v
 ulnerabilities and severe incidents to ENISA and the national CSIRT
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:us|fedreg|2026-14358|2026-09-14@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20260914
DTEND;VALUE=DATE:20260915
SUMMARY:United States — federal: CMS/CDC request for information on mode
 rnizing the 1988 CLIA clinical-laboratory regulations\, with one of its
 …
DESCRIPTION:CMS/CDC request for information on modernizing the 1988 CLIA c
 linical-laboratory regulations\, with one of its…\nHealth and Human Ser
 vices Department — Proposed Rule\nCMS/CDC request for information on mo
 dernizing the 1988 CLIA clinical-laboratory regulations\, with one of its
  numbered topics asking specifically how labs use AI and software algorit
 hms to interpret test results and whether AI should be written into the C
 LIA rules.\nApplies to: any interested party\nSource says: "comments_clos
 e_on: 2026-09-14 (Federal Register API)"\nSource: https://www.federalregi
 ster.gov/documents/2026/07/16/2026-14358/request-for-information-clinical
 -laboratory-improvement-amendments-of-1988-clia-regulations\nVerified: Au
 g 30\, 2026\nhttps://agenccy.ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Comments close
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:United States — federal: CMS/CDC request for information on 
 modernizing the 1988 CLIA clinical-laboratory regulations\, with one of i
 ts…
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:us|fedreg|2026-14327|2026-09-14@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20260914
DTEND;VALUE=DATE:20260915
SUMMARY:United States — federal: CMS CY2027 Physician Fee Schedule rule 
 which\, alongside routine payment policy\, runs a large RFI on paying…
DESCRIPTION:CMS CY2027 Physician Fee Schedule rule which\, alongside routi
 ne payment policy\, runs a large RFI on paying…\nHealth and Human Servi
 ces Department — Proposed Rule\nCMS CY2027 Physician Fee Schedule rule 
 which\, alongside routine payment policy\, runs a large RFI on paying for
  clinical AI in primary care (AI scribes\, decision support\, AI-enabled 
 Annual Wellness Visits\, whether AI companies may deliver AWV services) a
 nd proposes two AI-focused MIPS improvement activities plus AI/algorithm-
 driven 'Software as a Medical Service' lab-analysis payment.\nApplies to:
  any interested party\nSource says: "comments_close_on: 2026-09-14 (Feder
 al Register API)"\nSource: https://www.federalregister.gov/documents/2026
 /07/16/2026-14327/medicare-and-medicaid-programs-cy-2027-payment-policies
 -under-the-physician-fee-schedule-and-other\nVerified: Aug 30\, 2026\nhtt
 ps://agenccy.ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Comments close
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:United States — federal: CMS CY2027 Physician Fee Schedule r
 ule which\, alongside routine payment policy\, runs a large RFI on paying
 …
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:us|fedreg|2026-17761|2026-09-30@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20260930
DTEND;VALUE=DATE:20261001
SUMMARY:United States — federal: FCC seeks comment on overhauling how th
 e Universal Service Fund is administered by USAC
DESCRIPTION:FCC seeks comment on overhauling how the Universal Service Fun
 d is administered by USAC\nFederal Communications Commission — Proposed
  Rule\nFCC seeks comment on overhauling how the Universal Service Fund is
  administered by USAC (processes\, shot clocks\, audits and recoveries\, 
 operating costs\, USAC's board)\, and asks repeatedly whether AI should b
 e used to review USF applications\, audits and appeals - and what safegua
 rds\, governance and privacy protections that would require.\nApplies to:
  any interested party\nSource says: "comments due 2026-09-30\; reply comm
 ents 2026-10-30 (Federal Register API)"\nSource: https://www.federalregis
 ter.gov/documents/2026/08/31/2026-17761/maximizing-efficiencies-in-univer
 sal-service-administration\nVerified: Aug 30\, 2026\nhttps://agenccy.ai/a
 i-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Comments close
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:United States — federal: FCC seeks comment on overhauling ho
 w the Universal Service Fund is administered by USAC
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:us-ct|connecticut-ai-responsibility-and-transparency-act-public-act-26
 -15-sb|warn-act-layoff-notices-must-state-whether-the-layoffs-are-r|2026-
 10-01@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20261001
DTEND;VALUE=DATE:20261002
SUMMARY:United States — Connecticut: WARN Act layoff notices must state 
 whether the layoffs relate to the employer's use of AI or another technol
 ogical change
DESCRIPTION:WARN Act layoff notices must state whether the layoffs relate 
 to the employer's use of AI or another technological change\nConnecticut 
 AI Responsibility and Transparency Act (Public Act 26-15\, SB 5)\nFirst o
 perative date of the CART Act\, signed 2 June 2026. The Act phases in bet
 ween October 2026 and January 2028 and covers employment decision tools\,
  consumer chatbots\, frontier developers\, generative-AI provenance and p
 latforms used by minors.\nApplies to: employer\nWho: employers subject to
  the federal WARN Act\nSource says: "Closest verified wording (from concu
 rring analyses of the session law): employers must give written notice to
  the Connecticut Department of Labor disclosing "whether the layoffs are 
 related to the employer's use of artificial intelligence or another techn
 ological change"\, triggered where the layoffs "qualify as a mass layoff 
 or plant closing under the federal Worker Adjustment and Retraining Notif
 ication (WARN) Act"\, effective October 1\, 2026. The row's source_quote 
 ("Beginning October 1\, 2026\, any employer that serves written notice...
 ") is a commentator's construction\, not statutory drafting -- Connecticu
 t public acts carry effective dates in a separate effective-date table\, 
 never as an inline 'Beginning [date]' clause."\nSource: https://www.cga.c
 t.gov/2026/act/pa/pdf/2026PA-00015-R00SB-00005-PA.pdf\nVerified: Aug 30\,
  2026\nhttps://agenccy.ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:United States — Connecticut: WARN Act layoff notices must st
 ate whether the layoffs relate to the employer's use of AI or another tec
 hnological change
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:us|fedreg|2026-16371|2026-10-13@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20261013
DTEND;VALUE=DATE:20261014
SUMMARY:United States — federal: NIST asks how the National Vulnerabilit
 y Database should be rebuilt for an AI-driven security landscape
DESCRIPTION:NIST asks how the National Vulnerability Database should be re
 built for an AI-driven security landscape\nCommerce Department — Notice
 \nNIST asks how the National Vulnerability Database should be rebuilt for
  an AI-driven security landscape - which parts of the vulnerability lifec
 ycle to hand to AI automation\, where human review must stay\, how to mak
 e AI-driven risk prioritisation auditable\, and what safeguards are neede
 d against bad AI-generated fixes.\nApplies to: any interested party\nSour
 ce says: "comments_close_on: 2026-10-13 (Federal Register API)"\nSource: 
 https://www.federalregister.gov/documents/2026/08/12/2026-16371/request-f
 or-information-rfi-on-modernizing-the-national-vulnerability-database-in-
 the-age-of\nVerified: Aug 30\, 2026\nhttps://agenccy.ai/ai-compliance-cal
 endar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Comments close
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:United States — federal: NIST asks how the National Vulnerab
 ility Database should be rebuilt for an AI-driven security landscape
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:us|fedreg|2026-17163|2026-10-20@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20261020
DTEND;VALUE=DATE:20261021
SUMMARY:United States — federal: CFTC asks how exchanges should design a
 nd list futures/swaps whose underlying commodity is AI compute capacity
DESCRIPTION:CFTC asks how exchanges should design and list futures/swaps w
 hose underlying commodity is AI compute capacity\nCommodity Futures Tradi
 ng Commission — Proposed Rule\nCFTC asks how exchanges should design an
 d list futures/swaps whose underlying commodity is AI compute capacity - 
 how to measure the size\, liquidity and price transparency of the compute
  cash market\, whether a contract may settle to an index the CFTC cannot 
 verify\, and what standards fungible 'compute' delivery would require.\nA
 pplies to: any interested party\nSource says: "comments_close_on: 2026-10
 -20 (Federal Register API)"\nSource: https://www.federalregister.gov/docu
 ments/2026/08/21/2026-17163/request-for-comment-on-the-listing-of-compute
 -derivatives-contracts\nVerified: Aug 30\, 2026\nhttps://agenccy.ai/ai-co
 mpliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Comments close
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:United States — federal: CFTC asks how exchanges should desi
 gn and list futures/swaps whose underlying commodity is AI compute capaci
 ty
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:cl|ley-n-21-719-regula-la-protecci-n-y-el-tratamiento-de-los-datos-per
 son|automated-individual-decisions-and-profiling-data-subjects-g|2026-12-
 01@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20261201
DTEND;VALUE=DATE:20261202
SUMMARY:Chile: Automated individual decisions and profiling: data subjects
  gain the right to object and not to be subject to decisions based on aut
 omated processing that produce legal effects or significantly affect them
 \; controllers must in all cases guarantee information and transparency\,
  an explanation\, human intervention\, the right to express a point of vi
 ew and to request review of the decision\, and must disclose the existenc
 e of automated decisions together with meaningful information on the logi
 c applied
DESCRIPTION:Automated individual decisions and profiling: data subjects ga
 in the right to object and not to be subject to decisions based on automa
 ted processing that produce legal effects or significantly affect them\; 
 controllers must in all cases guarantee information and transparency\, an
  explanation\, human intervention\, the right to express a point of view 
 and to request review of the decision\, and must disclose the existence o
 f automated decisions together with meaningful information on the logic a
 pplied\nLey N. 21.719 — Regula la protección y el tratamiento de los d
 atos personales y crea la Agencia de Protección de Datos Personales (pro
 mulgada 25-NOV-2024\, publicada en el Diario Oficial 13-DIC-2024)\, en pa
 rticular el nuevo Artículo 8° bis y el Artículo 14 letra l) que incorp
 ora a la Ley N. 19.628\nArt. 8° bis is Chile's GDPR-Art.22 analogue and 
 is the operative AI/ADM hook. The exceptions are narrow (necessary for th
 e conclusion or performance of a contract\; prior express consent under a
 rt. 12\; where the law so provides with safeguards) and even inside those
  exceptions the safeguard duties still apply. Art. 14(l) adds a standing 
 transparency duty to disclose 'la existencia de decisiones automatizadas\
 , incluida la elaboración de perfiles' with 'información significativa 
 sobre la lógica aplicada\, así como las consecuencias previstas de dich
 o tratamiento para el titular'. Profiling is defined in the new letter w)
 : 'toda forma de tratamiento automatizado de datos personales que consist
 a en utilizar esos datos para evaluar\, analizar o predecir aspectos rela
 tivos al rendimiento profesional\, situación económica\, de salud\, pre
 ferencias personales\, intereses\, fiabilidad\, comportamiento\, ubicaci
 ón o movimientos de una persona natural'. The law also creates the Agenc
 ia de Protección de Datos Personales as enforcement authority.\nApplies 
 to: controller\, deployer\, processor\nWho: no size threshold\nPenalty: E
 nforced by the newly created Agencia de Protección de Datos Personales t
 hrough an administrative sanctioning regime graded by seriousness of infr
 ingement\, with fines in UTM and a Registro Nacional de Sanciones y Cumpl
 imiento\; the Agency also holds inspection and instruction powers.\nSourc
 e says: "Entra en vigencia el 01-DIC-2026 — LEY 21719 REGULA LA PROTECC
 IÓN Y EL TRATAMIENTO DE LOS DATOS PERSONALES Y CREA LA AGENCIA DE PROTEC
 CIÓN DE DATOS PERSONALES. Promulgación: 25-NOV-2024. Publicación: 13-D
 IC-2024. Versión: Con Vigencia Diferida por Fecha - 01-DIC-2026."\nSourc
 e: https://www.bcn.cl/leychile/navegar?idNorma=1209272\nVerified: Aug 30\
 , 2026\nhttps://agenccy.ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Law applies
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:Chile: Automated individual decisions and profiling: data subj
 ects gain the right to object and not to be subject to decisions based on
  automated processing that produce legal effects or significantly affect 
 them\; controllers must in all cases guarantee information and transparen
 cy\, an explanation\, human intervention\, the right to express a point o
 f view and to request review of the decision\, and must disclose the exis
 tence of automated decisions together with meaningful information on the 
 logic applied
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:eu|eu-ai-act-regulation-eu-2024-1689|four-month-transitional-period-en
 ds-for-marking-generative-a|2026-12-02@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20261202
DTEND;VALUE=DATE:20261203
SUMMARY:European Union: Four-month transitional period ends for marking ge
 nerative AI systems already on the market before 2 August 2026
DESCRIPTION:Four-month transitional period ends for marking generative AI 
 systems already on the market before 2 August 2026\nEU AI Act (Regulation
  (EU) 2024/1689)\nRegulation (EU) 2026/1744 gave providers whose generati
 ve systems were already placed on the market a four-month grace period on
  the Article 50 marking duty. After it\, no carve-out remains.\nApplies t
 o: provider\nPenalty: Up to EUR 15 000 000 or 3% of worldwide annual turn
 over\nSource says: "Providers of AI systems\, including general-purpose A
 I systems\, generating synthetic audio\, image\, video or text content\, 
 that have been placed on the market before 2 August 2026 shall take the n
 ecessary steps in order to comply with Article 50(2) by 2 December 2026."
 \nSource: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_2
 02601744\nVerified: Aug 30\, 2026\nhttps://agenccy.ai/ai-compliance-calen
 dar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:European Union: Four-month transitional period ends for markin
 g generative AI systems already on the market before 2 August 2026
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:eu|product-liability-directive-directive-eu-2024-2853|new-product-liab
 ility-regime-applies-to-software-and-ai-syst|2026-12-09@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20261209
DTEND;VALUE=DATE:20261210
SUMMARY:European Union: New product liability regime applies to software a
 nd AI systems placed on the market
DESCRIPTION:New product liability regime applies to software and AI system
 s placed on the market\nProduct Liability Directive (Directive (EU) 2024/
 2853)\nSoftware — explicitly including AI systems\, whether embedded\, 
 networked or delivered as SaaS — becomes a 'product' for strict liabili
 ty. AI system providers are treated as manufacturers. Applies to products
  placed on the market or put into service after 9 December 2026.\nApplies
  to: provider\, manufacturer\, importer\nPenalty: Strict civil liability 
 for damage caused by defective products\; no financial ceiling\nSource sa
 ys: "Article 2(1): 'This Directive shall apply to products placed on the 
 market or put into service after 9 December 2026.' Article 4(1): ‘produ
 ct’ means all movables\, even if integrated into\, or inter-connected w
 ith\, another movable or an immovable\; it includes electricity\, digital
  manufacturing files\, raw materials and software'. Article 22(1): 'Membe
 r States shall bring into force the laws\, regulations and administrative
  provisions necessary to comply with this Directive by 9 December 2026.'"
 \nSource: https://eur-lex.europa.eu/eli/dir/2024/2853/oj/eng\nVerified: A
 ug 30\, 2026\nhttps://agenccy.ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Law applies
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:European Union: New product liability regime applies to softwa
 re and AI systems placed on the market
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:au|privacy-act-1988-cth-as-amended-by-the-privacy-and-other-legislatio
 n-a|privacy-policies-must-disclose-automated-decision-making-tha|2026-12-
 10@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20261210
DTEND;VALUE=DATE:20261211
SUMMARY:Australia: Privacy policies must disclose automated decision-makin
 g that significantly affects people
DESCRIPTION:Privacy policies must disclose automated decision-making that 
 significantly affects people\nPrivacy Act 1988 (Cth)\, as amended by the 
 Privacy and Other Legislation Amendment Act 2024\nA disclosure duty\, not
  a ban: APP entities must state in their privacy policy which personal in
 formation is used by computer programs to make decisions that significant
 ly affect individuals\, and what kinds of decisions those are. Reaches or
 dinary businesses\, not only AI companies\; human oversight does not exem
 pt.\nApplies to: deployer\, business\nWho: APP entities under the Privacy
  Act\nPenalty: Low-tier civil penalty regime under s 13K(1)(b)(iia) — i
 nfringement and compliance notices\, up to roughly AUD 330\,000 for a bod
 y corporate\nSource says: "The ADM obligation commences on 10 December 20
 26. ... The ADM obligation will enhance the right to privacy by introduci
 ng requirements that entities must include information in privacy policie
 s about the kinds of personal information used in\, and types of decision
 s made by\, computer programs that use personal information to make decis
 ions that could reasonably be expected to significantly affect the rights
  or interests of an individual. (OAIC\, Automated Decision-Making Transpa
 rency Obligation (APP 1) Issues Paper\, 18 May 2026\, Executive summary).
  OAIC consultation page wording: "From 10 December 2026\, APP entities th
 at use personal information in ADM with the potential to affect rights or
  interests will be required to provide information in their privacy polic
 ies about the kinds of personal information used and the kinds of decisio
 ns made using ADM." Statutory text (Attachment A\, new APP 1.7): "Without
  limiting subclause 1.3\, the APP privacy policy of an APP entity must co
 ntain the information covered by subclause 1.8 if: (a) the entity has arr
 anged for a computer program to make\, or do a thing that is substantiall
 y and directly related to making\, a decision\; and (b) the decision coul
 d reasonably be expected to significantly affect the rights or interests 
 of an individual\; and (c) personal information about the individual is u
 sed in the operation of the computer program to make the decision or do t
 he thing that is substantially and directly related to making the decisio
 n.""\nSource: https://www.oaic.gov.au/engage-with-us/consultations/consul
 tation-on-guidance-for-transparency-in-automated-decision-making\nVerifie
 d: Aug 30\, 2026\nhttps://agenccy.ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:Australia: Privacy policies must disclose automated decision-m
 aking that significantly affects people
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:uk|crime-and-policing-act-2026-s-249-duty-to-make-progress-report-in-f
 orc|secretary-of-state-must-lay-before-parliament-a-progress-rep|2026-12-
 31@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20261231
DTEND;VALUE=DATE:20270101
SUMMARY:United Kingdom: Secretary of State must lay before Parliament a pr
 ogress report on making regulations to bring illegal AI-generated content
  and AI services into the Online Safety Act 2023
DESCRIPTION:Secretary of State must lay before Parliament a progress repor
 t on making regulations to bring illegal AI-generated content and AI serv
 ices into the Online Safety Act 2023\nCrime and Policing Act 2026\, s.249
  (duty to make progress report)\, in force at Royal Assent per s.255(2)(k
 )\nSection 248 of the Crime and Policing Act 2026 ('Power to amend Online
  Safety Act 2023: AI') inserts a new s.216A into the Online Safety Act 20
 23\, letting the Secretary of State amend that Act by regulations to addr
 ess risks from illegal AI-generated content and the use of AI services to
  commit or facilitate priority offences. An 'AI service' is defined as an
  internet service capable of generating AI-generated content\, no matter 
 what proportion of content on the service is AI-generated - the route by 
 which standalone AI chatbots\, which Ofcom has said fall outside Part 3 w
 hen output is not user-generated or search content\, can be brought into 
 the illegal content duties. Section 249 backs that power with a hard repo
 rting deadline: the Secretary of State must lay a progress report by 31 D
 ecember 2026 unless draft regulations have been laid before Parliament by
  then.\nApplies to: Secretary of State (duty holder)\, providers of AI se
 rvices and chatbots (prospective duty holders under the resulting regulat
 ions)\nWho: n/a\nPenalty: Parliamentary duty on the Secretary of State\; 
 no financial penalty. The regulations it anticipates would carry full Onl
 ine Safety Act enforcement against AI services.\nSource says: "(1) The Se
 cretary of State must\, no later than 31 December 2026\, lay before Parli
 ament a report about the progress that has been made towards making regul
 ations under section 216A of the Online Safety Act 2023 (power to amend A
 ct in relation to illegal AI-generated content). (2) Subsection (1) does 
 not apply if a draft of a statutory instrument containing regulations und
 er that section is laid before Parliament before 31 December 2026."\nSour
 ce: https://www.legislation.gov.uk/ukpga/2026/20/section/249\nVerified: A
 ug 30\, 2026\nhttps://agenccy.ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Reporting
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:United Kingdom: Secretary of State must lay before Parliament 
 a progress report on making regulations to bring illegal AI-generated con
 tent and AI services into the Online Safety Act 2023
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:us-ca|ccpa-regulations-on-automated-decisionmaking-technology-cppa-eff
 -1-jan|businesses-using-admt-for-significant-decisions-must-comply|2027-0
 1-01@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:United States — California: Businesses using ADMT for significan
 t decisions must comply in full: pre-use notice\, opt-out and access righ
 ts
DESCRIPTION:Businesses using ADMT for significant decisions must comply in
  full: pre-use notice\, opt-out and access rights\nCCPA regulations on au
 tomated decisionmaking technology (CPPA\, eff. 1 Jan 2026)\nSignificant d
 ecisions include financial or lending services\, housing\, education\, em
 ployment or independent contracting opportunities and healthcare.\nApplie
 s to: business\, deployer\nPenalty: CCPA administrative fines up to $2\,6
 63 per violation\, $7\,988 per intentional violation (CPPA enforcement)\n
 Source says: "CCPA Regulations (11 CCR) § 7200(b): “A business that us
 es ADMT for a significant decision prior to January 1\, 2027\, must be in
  compliance with the requirements of this Article no later than January 1
 \, 2027. A business that uses ADMT on or after January 1\, 2027\, must be
  in compliance with the requirements of this Article any time it is using
  ADMT for a significant decision.”"\nSource: https://cppa.ca.gov/regula
 tions/pdf/ccpa_updates_cyber_risk_admt_appr_text.pdf\nVerified: Aug 30\, 
 2026\nhttps://agenccy.ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:United States — California: Businesses using ADMT for signif
 icant decisions must comply in full: pre-use notice\, opt-out and access 
 rights
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:us-ca|california-ai-transparency-act-sb-942-as-amended-by-ab-853|large
 -online-platforms-must-detect-and-surface-content-prove|2027-01-01@agencc
 y.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:United States — California: Large online platforms must detect a
 nd surface content provenance data
DESCRIPTION:Large online platforms must detect and surface content provena
 nce data\nCalifornia AI Transparency Act (SB 942 as amended by AB 853)\nP
 latforms above 2 million monthly users must detect provenance data in dis
 tributed content\, expose it in the user interface\, and let users inspec
 t whether content was AI-generated or captured by a device.\nApplies to: 
 platform\nWho: over 2 million monthly users\nSource says: "Bus. & Prof. C
 ode § 22757.3.1 (added by AB 853\, Ch. 674\, Stats. 2025)\, operative-da
 te sentence: “This section shall become operative on January 1\, 2027.
 ” The duty it dates\, in the section's own words\, is to “detect whet
 her any provenance data that is compliant with widely adopted specificati
 ons adopted by an established standards-setting body is embedded into or 
 attached to content.”"\nSource: https://leginfo.legislature.ca.gov/face
 s/billTextClient.xhtml?bill_id=202520260AB853\nVerified: Aug 30\, 2026\nh
 ttps://agenccy.ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:United States — California: Large online platforms must dete
 ct and surface content provenance data
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:us-co|colorado-sb-26-189-automated-decision-making-technology|develope
 rs-and-deployers-of-admt-used-in-consequential-decis|2027-01-01@agenccy.a
 i
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:United States — Colorado: Developers and deployers of ADMT used 
 in consequential decisions must give notice\, documentation and post-deci
 sion disclosures
DESCRIPTION:Developers and deployers of ADMT used in consequential decisio
 ns must give notice\, documentation and post-decision disclosures\nColora
 do SB 26-189\, Automated Decision-Making Technology\nReplaces the repeale
 d Colorado AI Act (SB 24-205). Developers must hand deployers technical d
 ocumentation on intended uses\, training-data categories\, known limitati
 ons and human-review instructions\; both sides keep compliance records fo
 r three years.\nApplies to: developer\, deployer\nPenalty: Enforcement ce
 ntralised with the Colorado Attorney General\; fault-based apportionment 
 of discrimination liability\nSource says: "From the enrolled Final Act: "
 SECTION 5. Effective date - applicability. (1) Except as otherwise provid
 ed in subsection (2) of this section\, this act takes effect January 1\, 
 2027. ... (3) This act applies to consequential decisions made on or afte
 r January 1\, 2027." Operative duty: "6-1-1702. Developer responsibilitie
 s - documentation. (1) ON AND AFTER JANUARY 1\, 2027\, A DEVELOPER SHALL 
 MAKE AVAILABLE TO EACH DEPLOYER OF A COVERED ADMT DEVELOPED BY THE DEVELO
 PER\, IN A FORM AND MANNER THAT IS REASONABLY UNDERSTANDABLE TO A DEPLOYE
 R AND THAT PROTECTS TRADE SECRETS...". Deployer notice: "[A DEPLOYER] SHA
 LL PROVIDE A CLEAR AND CONSPICUOUS NOTICE TO A CONSUMER THAT THE DEPLOYER
  USED OR WILL USE A COVERED ADMT IN A CONSEQUENTIAL DECISION AFFECTING TH
 E CONSUMER AND INSTRUCTIONS REGARDING HOW THE CONSUMER MAY OBTAIN THE ADD
 ITIONAL INFORMATION DESCRIBED IN THIS SECTION." AG rulemaking (BOTH provi
 sions): "(b) ON OR BEFORE JANUARY 1\, 2027\, THE ATTORNEY GENERAL SHALL A
 DOPT RULES TO CLARIFY AND IMPLEMENT THE POST-ADVERSE OUTCOME DISCLOSURE R
 EQUIREMENTS SET FORTH IN SUBSECTION (3) OF THIS SECTION" and "(3) ON OR B
 EFORE JANUARY 1\, 2027\, THE ATTORNEY GENERAL SHALL ADOPT RULES TO CLARIF
 Y AND IMPLEMENT THE REQUIREMENTS OF THIS SECTION." Fault apportionment: "
 FAULT SHALL BE ALLOCATED AMONG DEPLOYERS AND DEVELOPERS BASED ON THEIR RE
 LATIVE FAULT FOR THE VIOLATION.""\nSource: https://leg.colorado.gov/bills
 /sb26-189\nVerified: Aug 30\, 2026\nhttps://agenccy.ai/ai-compliance-cale
 ndar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:United States — Colorado: Developers and deployers of ADMT u
 sed in consequential decisions must give notice\, documentation and post-
 decision disclosures
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:us-co|colorado-sb-26-189-automated-decision-making-technology|ag-must-
 adopt-rules|2027-01-01@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:United States — Colorado: Attorney General must adopt implementi
 ng rules — on the same day compliance begins
DESCRIPTION:Attorney General must adopt implementing rules — on the same
  day compliance begins\nColorado SB 26-189\, Automated Decision-Making Te
 chnology\nTwo mandatory rulemaking duties\, 6-1-1704(4)(b) and 6-1-1705(3
 )\, both worded 'on or before January 1\, 2027\, the Attorney General sha
 ll adopt rules'. Deployers therefore may not see final rules before their
  own obligations start.\nApplies to: Colorado Attorney General\nSource sa
 ys: "ON OR BEFORE JANUARY 1\, 2027\, THE ATTORNEY GENERAL SHALL ADOPT RUL
 ES"\nSource: https://leg.colorado.gov/bills/sb26-189\nVerified: Aug 30\, 
 2026\nhttps://agenccy.ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Regulator milestone
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:United States — Colorado: Attorney General must adopt implem
 enting rules — on the same day compliance begins
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:us-ny|responsible-ai-safety-and-education-act-raise-act|frontier-model
 -developers-must-publish-a-safety-framework-fi|2027-01-01@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:United States — New York: Frontier model developers must publish
  a safety framework\, file disclosures and report safety incidents within
  72 hours
DESCRIPTION:Frontier model developers must publish a safety framework\, fi
 le disclosures and report safety incidents within 72 hours\nResponsible A
 I Safety and Education Act (RAISE Act)\nBase law is Chapter 699 of 2025 (
 S6953-B\, signed 19 December 2025)\, overhauled by chapter amendment S882
 8/A9449 signed 27 March 2026\, which struck the original commencement and
  wrote in 1 January 2027. The amendment also moved oversight to a new off
 ice inside NYDFS.\nApplies to: developer\nWho: over $500M annual revenue\
 nPenalty: Civil penalties up to $1\,000\,000 (first violation) and $3\,00
 0\,000 (subsequent)\, enforced through NYDFS — reduced from $10M/$30M b
 y the March 2026 amendment\nSource says: "Effective-date clause as amende
 d (S8828 sec. 3\, showing the bracketed repeal and new date): "This act s
 hall take effect [on the ninetieth day after it shall have become a law] 
 JANUARY 1\, 2027." Operative duties in the consolidated text: "A LARGE FR
 ONTIER DEVELOPER SHALL WRITE\, IMPLEMENT\, COMPLY WITH\, AND CLEARLY AND 
 CONSPICUOUSLY PUBLISH ON ITS INTERNET WEBSITE A FRONTIER AI FRAMEWORK"\; 
 "A LARGE FRONTIER DEVELOPER SHALL TRANSMIT TO THE OFFICE A SUMMARY OF ANY
  ASSESSMENT OF CATASTROPHIC RISK RESULTING FROM INTERNAL USE OF ITS FRONT
 IER MODELS EVERY THREE MONTHS"\; "A FRONTIER DEVELOPER SHALL REPORT ANY C
 RITICAL SAFETY INCIDENT PERTAINING TO ONE OR MORE OF ITS FRONTIER MODELS 
 TO THE OFFICE WITHIN SEVENTY-TWO HOURS". Threshold definition: "A FRONTIE
 R DEVELOPER THAT TOGETHER WITH ITS AFFILIATES COLLECTIVELY HAD ANNUAL GRO
 SS REVENUES IN EXCESS OF FIVE HUNDRED MILLION DOLLARS IN THE PRECEDING CA
 LENDAR YEAR.""\nSource: https://www.nysenate.gov/legislation/bills/2025/S
 8828\nVerified: Aug 30\, 2026\nhttps://agenccy.ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:United States — New York: Frontier model developers must pub
 lish a safety framework\, file disclosures and report safety incidents wi
 thin 72 hours
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:eu|machinery-regulation-regulation-eu-2023-1230|new-machinery-regime-a
 pplies-covering-digital-and-ai-driven|2027-01-20@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20270120
DTEND;VALUE=DATE:20270121
SUMMARY:European Union: New machinery regime applies\, covering digital an
 d AI-driven risks for the first time
DESCRIPTION:New machinery regime applies\, covering digital and AI-driven 
 risks for the first time\nMachinery Regulation (Regulation (EU) 2023/1230
 )\nReplaces the Machinery Directive. Safety assessment must account for A
 I-based control functions and human-robot collaboration\; machinery with 
 AI safety components sits in the higher conformity-assessment category.\n
 Applies to: manufacturer\, importer\nPenalty: National penalties under Ar
 ticle 50 — effective\, proportionate and dissuasive\, and may include c
 riminal penalties for serious infringements\nSource says: "Article 54 'En
 try into force and application'\, second paragraph\, AS CORRECTED: 'It sh
 all apply from 20 January 2027.' The as-published OJ L 165 text reads '14
  January 2027'\; the Corrigendum in OJ L 169\, 4.7.2023\, p. 35 states: '
 10. On page 39\, Article 54\, second paragraph: for: ‘14 January 2027
 ’\, read: ‘20 January 2027’.' Article 54\, first paragraph (unchang
 ed): 'This Regulation shall enter into force on the twentieth day followi
 ng that of its publication in the Official Journal of the European Union.
 '"\nSource: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELE
 X%3A32023R1230R%2801%29\nVerified: Aug 30\, 2026\nhttps://agenccy.ai/ai-c
 ompliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Law applies
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:European Union: New machinery regime applies\, covering digita
 l and AI-driven risks for the first time
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:vn|prime-minister-s-decision-no-33-2026-qd-ttg-list-of-high-risk-ai-sy
 ste|legacy-high-risk-ai-systems-outside-health-education-finance|2027-03-
 01@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20270301
DTEND;VALUE=DATE:20270302
SUMMARY:Vietnam: Legacy high-risk AI systems outside health/education/fina
 nce that were already in operation before 15 August 2026 must have comple
 ted their compliance obligations under the AI Law
DESCRIPTION:Legacy high-risk AI systems outside health/education/finance t
 hat were already in operation before 15 August 2026 must have completed t
 heir compliance obligations under the AI Law\nPrime Minister's Decision N
 o. 33/2026/QD-TTg (List of high-risk AI systems) — compliance roadmap\,
  read with Law on AI No. 134/2025/QH15 Art. 35\nProviders (nhà cung cấ
 p) and deployers (bên triển khai) of AI systems on the high-risk list 
 that were already deployed before the Decision took effect get a transiti
 on window. Systems may keep operating during the window\, except where th
 e competent state authority determines a system risks serious harm and or
 ders suspension or termination.\nApplies to: provider\, deployer\nWho: al
 l\nPenalty: Competent state authority may require suspension or terminati
 on of the system during the transition window if it poses a risk of serio
 us harm\nSource says: "Trước ngày 01/3/2027 đối với các hệ th
 ống trí tuệ nhân tạo thuộc các lĩnh vực còn lại trong Da
 nh mục. // 'Before 1 March 2027 for the artificial intelligence systems
  in the remaining fields on the List.'"\nSource: https://mst.gov.vn/46-he
 -thong-ai-duoc-xep-vao-nhom-rui-ro-cao-phai-quan-ly-nghiem-ngat-197260703
 152945179.htm\nVerified: Aug 30\, 2026\nhttps://agenccy.ai/ai-compliance-
 calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:Vietnam: Legacy high-risk AI systems outside health/education/
 finance that were already in operation before 15 August 2026 must have co
 mpleted their compliance obligations under the AI Law
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:ca|osfi-guideline-e-23-model-risk-management-2027-office-of-the-superi
 nte|federally-regulated-financial-institutions-must-have-enterpr|2027-05-
 01@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20270501
DTEND;VALUE=DATE:20270502
SUMMARY:Canada — federal: Federally regulated financial institutions mus
 t have enterprise-wide\, risk-based model risk management covering ALL mo
 dels including artificial intelligence and machine learning models — mo
 del inventory\, risk tiering\, governance and accountability across the f
 ull model lifecycle from development through deployment\, monitoring and 
 decommissioning
DESCRIPTION:Federally regulated financial institutions must have enterpris
 e-wide\, risk-based model risk management covering ALL models including a
 rtificial intelligence and machine learning models — model inventory\, 
 risk tiering\, governance and accountability across the full model lifecy
 cle from development through deployment\, monitoring and decommissioning\
 nOSFI Guideline E-23 — Model Risk Management (2027)\, Office of the Sup
 erintendent of Financial Institutions (final version published 11 Septemb
 er 2025)\nE-23 is principles-based and organised around three pillars —
  model risk understood and managed enterprise-wide\; a risk-based approac
 h built on model inventory\, risk tiering and assurance\; and governance 
 across the full model lifecycle. The 2027 version materially widens the 2
 017 original: scope expands from deposit-taking institutions to ALL feder
 ally regulated financial institutions including insurers and foreign bran
 ches\, and the definition of 'model' is broadened so AI/ML systems fall s
 quarely inside\, with added context for AI/ML model risk. Policies\, proc
 edures and controls must be proportionate to the institution's size\, ris
 k profile\, complexity of operations and interconnectedness in the financ
 ial system.\nApplies to: deployer\, operator\, risk owner\nWho: all feder
 ally regulated financial institutions\, including foreign bank branches a
 nd foreign insurance company branches\; expectations are proportionate to
  size\, risk profile\, complexity and interconnectedness\nPenalty: OSFI g
 uidelines are supervisory expectations rather than statutory offences: no
 n-compliance is addressed through the supervisory process — findings an
 d recommendations\, elevated risk ratings and intervention staging\, and 
 where warranted directions of compliance and other supervisory powers und
 er the Bank Act\, Insurance Companies Act and Trust and Loan Companies Ac
 t. No administrative monetary penalty attaches to the guideline itself.\n
 Source says: "Effective date: May 1\, 2027"\nSource: https://www.osfi-bsi
 f.gc.ca/en/guidance/guidance-library/guideline-e-23-model-risk-management
 -2027\nVerified: Aug 30\, 2026\nhttps://agenccy.ai/ai-compliance-calendar
 /
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:Canada — federal: Federally regulated financial institutions
  must have enterprise-wide\, risk-based model risk management covering AL
 L models including artificial intelligence and machine learning models 
 — model inventory\, risk tiering\, governance and accountability across
  the full model lifecycle from development through deployment\, monitorin
 g and decommissioning
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:eu|eu-ai-act-regulation-eu-2024-1689|commission-compliance-guidelines-
 for-high-risk-classificatio|2027-08-01@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20270801
DTEND;VALUE=DATE:20270802
SUMMARY:European Union: Commission guidance due on practical implementatio
 n of Articles 8(2)\, 9(10) and 17(3)
DESCRIPTION:Commission guidance due on practical implementation of Article
 s 8(2)\, 9(10) and 17(3)\nEU AI Act (Regulation (EU) 2024/1689)\nGuidance
  on avoiding duplication between the AI Act and Annex I Section A product
  legislation — it serves the Annex I cohort whose obligations land on 2
  August 2028.\nApplies to: European Commission\nSource says: "the practic
 al implementation of Article 8(2)\, Article 9(10) and Article 17(3) in ac
 cordance with the principle of complementarity and proportionality\, with
  a view to ensuring consistency\, avoiding duplication and minimising add
 itional burdens when complying with the requirements of this Regulation a
 nd the requirements of the Union harmonisation legislation listed in Sect
 ion A of Annex I\; such guidelines shall be published by 1 August 2027."\
 nSource: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_20
 2601744\nVerified: Aug 30\, 2026\nhttps://agenccy.ai/ai-compliance-calend
 ar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Regulator milestone
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:European Union: Commission guidance due on practical implement
 ation of Articles 8(2)\, 9(10) and 17(3)
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:eu|eu-ai-act-regulation-eu-2024-1689|legacy-general-purpose-ai-models-
 placed-on-the-market-before|2027-08-02@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20270802
DTEND;VALUE=DATE:20270803
SUMMARY:European Union: Legacy general-purpose AI models placed on the mar
 ket before 2 August 2025 must be brought into compliance
DESCRIPTION:Legacy general-purpose AI models placed on the market before 2
  August 2025 must be brought into compliance\nEU AI Act (Regulation (EU) 
 2024/1689)\nTwo-year grandfathering under Article 111(3) expires. Applies
  to GPAI models already on the market when the GPAI chapter started apply
 ing.\nApplies to: provider\nPenalty: Up to EUR 15 000 000 or 3% of worldw
 ide annual turnover (Art. 101)\nSource says: "Providers of general-purpos
 e AI models that have been placed on the market before 2 August 2025 shal
 l take the necessary steps in order to comply with the obligations laid d
 own in this Regulation by 2 August 2027."\nSource: https://ai-act-service
 -desk.ec.europa.eu/en/ai-act/article-111\nVerified: Aug 30\, 2026\nhttps:
 //agenccy.ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:European Union: Legacy general-purpose AI models placed on the
  market before 2 August 2025 must be brought into compliance
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:vn|prime-minister-s-decision-no-33-2026-qd-ttg-list-of-high-risk-ai-sy
 ste|legacy-high-risk-ai-systems-in-health-education-and-finance|2027-09-0
 1@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20270901
DTEND;VALUE=DATE:20270902
SUMMARY:Vietnam: Legacy high-risk AI systems in health\, education and fin
 ance that were already in operation before 15 August 2026 must have compl
 eted their compliance obligations under the AI Law
DESCRIPTION:Legacy high-risk AI systems in health\, education and finance 
 that were already in operation before 15 August 2026 must have completed 
 their compliance obligations under the AI Law\nPrime Minister's Decision 
 No. 33/2026/QD-TTg (List of high-risk AI systems) — compliance roadmap\
 , read with Law on AI No. 134/2025/QH15 Art. 35\nLonger transition window
  (than other sectors) for AI systems already deployed in health care\, ed
 ucation and finance. Systems may keep operating during the window\, excep
 t where the competent state authority determines a system risks serious h
 arm and orders suspension or termination.\nApplies to: provider\, deploye
 r\nWho: all\nPenalty: Competent state authority may require suspension or
  termination of the system during the transition window if it poses a ris
 k of serious harm\nSource says: "Trước ngày 01/9/2027 đối với c
 ác hệ thống trí tuệ nhân tạo trong lĩnh vực y tế\, giáo 
 dục và tài chính. // 'Before 1 September 2027 for artificial intelli
 gence systems in the health\, education and finance sectors.'"\nSource: h
 ttps://mst.gov.vn/46-he-thong-ai-duoc-xep-vao-nhom-rui-ro-cao-phai-quan-l
 y-nghiem-ngat-197260703152945179.htm\nVerified: Aug 30\, 2026\nhttps://ag
 enccy.ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:Vietnam: Legacy high-risk AI systems in health\, education and
  finance that were already in operation before 15 August 2026 must have c
 ompleted their compliance obligations under the AI Law
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:eu|eu-ai-act-regulation-eu-2024-1689|commission-post-market-monitoring
 -guidance-due|2027-09-02@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20270902
DTEND;VALUE=DATE:20270903
SUMMARY:European Union: Commission post-market monitoring guidance due
DESCRIPTION:Commission post-market monitoring guidance due\nEU AI Act (Reg
 ulation (EU) 2024/1689)\nApplies to: European Commission\nSource says: "T
 he Commission\, taking utmost account of the opinion of the Board\, shall
  adopt guidance\, including a template\, on the post-market monitoring pl
 an by 2 September 2027."\nSource: https://eur-lex.europa.eu/legal-content
 /EN/TXT/HTML/?uri=OJ:L_202601744\nVerified: Aug 30\, 2026\nhttps://agencc
 y.ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Regulator milestone
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:European Union: Commission post-market monitoring guidance due
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:us-ct|connecticut-ai-responsibility-and-transparency-act-public-act-26
 -15-sb|employers-using-automated-employment-decision-technology-mus|2027-
 10-01@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20271001
DTEND;VALUE=DATE:20271002
SUMMARY:United States — Connecticut: Employers using automated employmen
 t decision technology must give detailed notices to applicants and employ
 ees
DESCRIPTION:Employers using automated employment decision technology must 
 give detailed notices to applicants and employees\nConnecticut AI Respons
 ibility and Transparency Act (Public Act 26-15\, SB 5)\nApplies to: emplo
 yer\, deployer\nSource says: "Closest verified wording: from 1 October 20
 27\, deployers of automated employment-related decision technology must d
 isclose to applicants and employees that they are interacting with AEDT u
 nless it is obvious\, and where AEDT is used to make\, or its output is a
  substantial factor in making\, an employment-related decision\, must giv
 e written notice before the decision covering the fact of its use\, the p
 urposes and the employment decisions affected\, the trade name of the tec
 hnology\, the categories of personal data analysed and how they are asses
 sed\, and employer contact details\; for an adverse decision the notice m
 ust give "a high-level statement disclosing the principal reasons for the
  decision\, including how much and how the automated process output contr
 ibuted to the decision\, and the type and source of data." AEDT is define
 d as "any technology that processes personal data and uses computation to
  generate any output\, including predictions\, recommendations\, classifi
 cations\, rankings\, scores or other information\, that is a substantial 
 factor used to make or materially influence an employment-related decisio
 n." The row's source_quote is a commentator's paraphrase\, not statutory 
 text."\nSource: https://www.cga.ct.gov/2026/act/pa/pdf/2026PA-00015-R00SB
 -00005-PA.pdf\nVerified: Aug 30\, 2026\nhttps://agenccy.ai/ai-compliance-
 calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:United States — Connecticut: Employers using automated emplo
 yment decision technology must give detailed notices to applicants and em
 ployees
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:eu|eu-ai-act-regulation-eu-2024-1689-as-amended-by-regulation-eu-2026-
 174|high-risk-obligations-apply-to-stand-alone-annex-iii-systems|2027-12-
 02@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20271202
DTEND;VALUE=DATE:20271203
SUMMARY:European Union: High-risk obligations apply to stand-alone Annex I
 II systems — deferred from 2 August 2026
DESCRIPTION:High-risk obligations apply to stand-alone Annex III systems 
 — deferred from 2 August 2026\nEU AI Act (Regulation (EU) 2024/1689)\, 
 as amended by Regulation (EU) 2026/1744\nRisk management\, data governanc
 e\, technical documentation\, logging\, human oversight\, accuracy and ro
 bustness\, conformity assessment and EU database registration for stand-a
 lone high-risk systems: employment\, credit\, education\, essential servi
 ces\, law enforcement\, migration\, justice\, biometrics.\nApplies to: pr
 ovider\, deployer\, importer\, distributor\nPenalty: Up to EUR 15 000 000
  or 3% of worldwide annual turnover (Art. 99(4))\nSource says: "Chapter I
 II\, Sections 1\, 2\, and 3\, with the exception of Article 6(5)\, shall 
 apply from: (i) 2 December 2027 as regards AI systems classified as high-
 risk pursuant to Article 6(2) and Annex III\; and (ii) 2 August 2028 as r
 egards AI systems classified as high-risk pursuant to Article 6(1) and An
 nex I\;"\nSource: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?ur
 i=OJ:L_202601744\nVerified: Aug 30\, 2026\nhttps://agenccy.ai/ai-complian
 ce-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:European Union: High-risk obligations apply to stand-alone Ann
 ex III systems — deferred from 2 August 2026
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:eu|cyber-resilience-act-regulation-eu-2024-2847|full-cra-regime-applie
 s-security-by-design-vulnerability-han|2027-12-11@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20271211
DTEND;VALUE=DATE:20271212
SUMMARY:European Union: Full CRA regime applies: security by design\, vuln
 erability handling\, CE marking for products with digital elements
DESCRIPTION:Full CRA regime applies: security by design\, vulnerability ha
 ndling\, CE marking for products with digital elements\nCyber Resilience 
 Act (Regulation (EU) 2024/2847)\nApplies to: manufacturer\, importer\, di
 stributor\nPenalty: Up to EUR 15 000 000 or 2.5% of total worldwide annua
 l turnover\, whichever is higher (Art. 64(2))\nSource says: "This Regulat
 ion shall apply from 11 December 2027. (Article 71(2)\, first subparagrap
 h)"\nSource: https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng\nVerified
 : Aug 30\, 2026\nhttps://agenccy.ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:European Union: Full CRA regime applies: security by design\, 
 vulnerability handling\, CE marking for products with digital elements
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:us-ca|ccpa-regulations-on-risk-assessments-cppa-eff-1-jan-2026|risk-as
 sessments-must-be-completed-for-processing-activities|2027-12-31@agenccy.
 ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20271231
DTEND;VALUE=DATE:20280101
SUMMARY:United States — California: Risk assessments must be completed f
 or processing activities started before the regulations took effect and s
 till running
DESCRIPTION:Risk assessments must be completed for processing activities s
 tarted before the regulations took effect and still running\nCCPA regulat
 ions on risk assessments (CPPA\, eff. 1 Jan 2026)\nApplies to: business\n
 Source says: "CCPA Regulations (11 CCR) § 7155(b): “For any processing
  activity identified in section 7150\, subsection (b)\, that the business
  initiated prior to [OAL to fill in the effective date of these regulatio
 ns] and that continues after [OAL to fill in the effective date of these 
 regulations]\, the business must conduct\, and document as set forth in s
 ection 7152\, a risk assessment in accordance with the requirements of th
 is Article no later than December 31\, 2027. The business must comply wit
 h the submission requirements set forth in section 7157\, subsection (a)(
 1).”"\nSource: https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_r
 isk_admt_appr_text.pdf\nVerified: Aug 30\, 2026\nhttps://agenccy.ai/ai-co
 mpliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:United States — California: Risk assessments must be complet
 ed for processing activities started before the regulations took effect a
 nd still running
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:us-ca|california-ai-transparency-act-sb-942-as-amended-by-ab-853|captu
 re-device-manufacturers-must-embed-latent-provenance-di|2028-01-01@agencc
 y.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20280101
DTEND;VALUE=DATE:20280102
SUMMARY:United States — California: Capture device manufacturers must em
 bed latent provenance disclosures by default
DESCRIPTION:Capture device manufacturers must embed latent provenance disc
 losures by default\nCalifornia AI Transparency Act (SB 942 as amended by 
 AB 853)\nManufacturer name\, device name and version\, and content creati
 on date/time embedded in captured content\, with a user option to include
  them.\nApplies to: manufacturer\nSource says: "Bus. & Prof. Code § 2275
 7.3.3 (added by AB 853\, Ch. 674\, Stats. 2025)\, operative-date sentence
 : “This section shall become operative on January 1\, 2028.” The duty
  it dates reads “Embed latent disclosures in content captured by the de
 vice by default.” The Legislative Counsel's Digest states the scope: 
 “This bill would require\, beginning January 1\, 2028\, a capture devic
 e manufacturer\, with respect to any capture device the capture device ma
 nufacturer first produced for sale in the state on or after January 1\, 2
 028\, to\, among other things\, provide a user with the option to include
  a latent disclosure in content captured by the capture device that conve
 ys certain information\, including the name of the capture device manufac
 turer.”"\nSource: https://leginfo.legislature.ca.gov/faces/billTextClie
 nt.xhtml?bill_id=202520260AB853\nVerified: Aug 30\, 2026\nhttps://agenccy
 .ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:United States — California: Capture device manufacturers mus
 t embed latent provenance disclosures by default
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:eu|eu-ai-act-regulation-eu-2024-1689-as-amended-by-regulation-eu-2026-
 174|notified-bodies-18-month-conformity-assessment-transition-en|2028-01-
 28@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20280128
DTEND;VALUE=DATE:20280129
SUMMARY:European Union: Deadline for notified bodies to apply for designat
 ion under the 18-month transition
DESCRIPTION:Deadline for notified bodies to apply for designation under th
 e 18-month transition\nEU AI Act (Regulation (EU) 2024/1689)\, as amended
  by Regulation (EU) 2026/1744\nApplies to: notified body\nSource says: "W
 ithout prejudice to Article 28\, such notified bodies which have been not
 ified under the Union harmonisation legislation in Section A of Annex I\,
  shall apply for designation in accordance with Section 4 of this Chapter
  by 28 January 2028."\nSource: https://eur-lex.europa.eu/legal-content/EN
 /TXT/HTML/?uri=OJ:L_202601744\nVerified: Aug 30\, 2026\nhttps://agenccy.a
 i/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:European Union: Deadline for notified bodies to apply for desi
 gnation under the 18-month transition
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:us-ca|ccpa-regulations-on-risk-assessments-cppa-eff-1-jan-2026|first-r
 isk-assessment-submission-to-the-cppa-covering-assess|2028-04-01@agenccy.
 ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20280401
DTEND;VALUE=DATE:20280402
SUMMARY:United States — California: First risk-assessment submission to 
 the CPPA — covering assessments conducted in 2026 and 2027
DESCRIPTION:First risk-assessment submission to the CPPA — covering asse
 ssments conducted in 2026 and 2027\nCCPA regulations on risk assessments 
 (CPPA\, eff. 1 Jan 2026)\nApplies to: business\nSource says: "CCPA Regula
 tions (11 CCR) § 7157(a)(1): “For risk assessments conducted in 2026 a
 nd 2027\, the business must submit to the Agency the information required
  by subsection (b) no later than April 1\, 2028.”"\nSource: https://cpp
 a.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_appr_text.pdf\nVeri
 fied: Aug 30\, 2026\nhttps://agenccy.ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Reporting
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:United States — California: First risk-assessment submission
  to the CPPA — covering assessments conducted in 2026 and 2027
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:eu|eu-ai-act-regulation-eu-2024-1689-as-amended-by-regulation-eu-2026-
 174|high-risk-obligations-apply-to-ai-embedded-in-regulated-prod|2028-08-
 02@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20280802
DTEND;VALUE=DATE:20280803
SUMMARY:European Union: High-risk obligations apply to AI embedded in regu
 lated products (Annex I) — deferred from 2 August 2027
DESCRIPTION:High-risk obligations apply to AI embedded in regulated produc
 ts (Annex I) — deferred from 2 August 2027\nEU AI Act (Regulation (EU) 
 2024/1689)\, as amended by Regulation (EU) 2026/1744\nMachinery\, medical
  devices\, vehicles\, lifts\, toys\, radio equipment and the other Annex 
 I product regimes. Corresponding machinery AI requirements land on the sa
 me date.\nApplies to: provider\, manufacturer\nPenalty: Up to EUR 15 000 
 000 or 3% of worldwide annual turnover\nSource says: "Chapter III\, Secti
 ons 1\, 2\, and 3\, with the exception of Article 6(5)\, shall apply from
 : ... (ii) 2 August 2028 as regards AI systems classified as high-risk pu
 rsuant to Article 6(1) and Annex I\;"\nSource: https://eur-lex.europa.eu/
 legal-content/EN/TXT/HTML/?uri=OJ:L_202601744\nVerified: Aug 30\, 2026\nh
 ttps://agenccy.ai/ai-compliance-calendar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:European Union: High-risk obligations apply to AI embedded in 
 regulated products (Annex I) — deferred from 2 August 2027
END:VALARM
END:VEVENT
BEGIN:VEVENT
UID:eu|eu-ai-act-regulation-eu-2024-1689|large-scale-eu-it-systems-listed-
 in-annex-x-must-comply|2030-12-31@agenccy.ai
DTSTAMP:20260831T023727Z
DTSTART;VALUE=DATE:20301231
DTEND;VALUE=DATE:20310101
SUMMARY:European Union: Large-scale EU IT systems listed in Annex X must c
 omply
DESCRIPTION:Large-scale EU IT systems listed in Annex X must comply\nEU AI
  Act (Regulation (EU) 2024/1689)\nSystems such as SIS\, VIS\, EES and ETI
 AS placed on the market before 2 August 2027 get until end-2030.\nApplies
  to: provider\, deployer\nSource says: "AI systems which are components o
 f the large-scale IT systems established by the legal acts listed in Anne
 x X that have been placed on the market or put into service before 2 Augu
 st 2027 shall be brought into compliance with this Regulation by 31 Decem
 ber 2030."\nSource: https://ai-act-service-desk.ec.europa.eu/en/ai-act/ar
 ticle-111\nVerified: Aug 30\, 2026\nhttps://agenccy.ai/ai-compliance-cale
 ndar/
URL:https://agenccy.ai/ai-compliance-calendar/
CATEGORIES:Compliance
TRANSP:TRANSPARENT
BEGIN:VALARM
TRIGGER:-P7D
ACTION:DISPLAY
DESCRIPTION:European Union: Large-scale EU IT systems listed in Annex X mu
 st comply
END:VALARM
END:VEVENT
END:VCALENDAR
