AI News Today.

Artificial intelligence, professionally covered

Reference

AI Compliance Calendar

Every AI obligation we can tie to a date, across 23 jurisdictions — what falls due, when, and who it binds. Each row quotes the instrument that sets the date and shows when we last checked it. Where a country has no dated obligation, we say so instead of padding the list.

7
Due within 30 days
10
Due within 90 days
36
Deadlines ahead
23
Jurisdictions
Add to your calendar

Subscribe once and every deadline below — plus each new one we verify — appears in Google Calendar, Outlook or Apple Calendar, with a week's notice.

36 deadlines
Aug 31, 2026
Today

United States — federal · Comments close

CMS CY2027 hospital outpatient (OPPS/ASC) payment rule

Health and Human Services Department — Proposed Rule

Detail and source

CMS CY2027 hospital outpatient (OPPS/ASC) payment rule; section X.B proposes an interim Medicare payment framework for AI/algorithm-driven clinical software (renaming SaaS to 'Software as a Medical Service', new status indicator O1, 36 HCPCS codes moved to new-technology APCs) and asks for comment on it.

comments_close_on: 2026-08-31 (Federal Register API)

Docket CMS-1850-P

Medicare Program: Hospital Outpatient Prospective Payment and Ambulatory Surgical Center Payment Systems; and Quality Reporting Programs; Including the Hospital Outpatient Quality Reporting Program and Ambulatory Surgical Center Quality Program; Request for Information on Strengthening the Standardization and Comparability of Hospital Price Transparency (HPT) Data; Prior Authorization; Accrediting Organization (AO) Deeming for Emergency Medical Treatment and Labor Act (EMTALA); and Notices of Closure of Teaching Hospitals and Opportunities To Apply for Available Slots · verified Aug 30, 2026

Aug 31, 2026
Today

United States — federal · Comments close

NHTSA seeks comment on interim guidance for 49 CFR part 555 'General Exemption' applications that let…

Transportation Department — Notice

Detail and source

NHTSA seeks comment on interim guidance for 49 CFR part 555 'General Exemption' applications that let automated-driving-system vehicles be commercially deployed without meeting all FMVSS, and on how the exemption process for ADS vehicles could be improved.

comments_close_on: 2026-08-31 (Federal Register API)

Docket Docket No. NHTSA-2026-1552

AV Framework Updates and Request for Comments on Interim Guidance · verified Aug 30, 2026

Sep 8, 2026
in 8 days

United States — federal · Comments close

BLS seeks comment on adding a new AI module to the American Time Use Survey

Labor Department — Notice

Detail and source

BLS seeks comment on adding a new AI module to the American Time Use Survey - questions on whether people use AI tools, for which tasks, and how AI use varies by demographic/occupational group - to be fielded from January 2027 for two years.

comments_close_on: 2026-09-08 (Federal Register API)

Proposed Information Collection; ATUS Artificial Intelligence (AI) Questions · verified Aug 30, 2026

Sep 11, 2026
in 11 days

European Union · Reporting

Manufacturers must report actively exploited vulnerabilities and severe incidents to ENISA and the national CSIRT

Cyber Resilience Act (Regulation (EU) 2024/2847)

ManufacturerSoftwareHardwareIoT
Detail and source

Early-warning notification within 24 hours to the CSIRT designated as coordinator and to ENISA, via the Article 16 single reporting platform. Covers products with digital elements; Article 12 explicitly extends to products classified as high-risk AI systems under Article 6 of the AI Act.

Reach: Products with digital elements placed on the EU market, wherever the manufacturer is established

Penalty: Up to EUR 15 000 000 or 2.5% of total worldwide annual turnover, whichever is higher (Art. 64(2))

This Regulation shall apply from 11 December 2027. However, Article 14 shall apply from 11 September 2026 and Chapter IV (Articles 35 to 51) shall apply from 11 June 2026. (Article 71(2), Entry into force and application)

Article 64 is outside the early-application carve-out in Article 71(2): on 11 September 2026 the reporting duty binds, but the administrative fine backing it only applies from 11 December 2027.

Cyber Resilience Act — summary of the legislative text, European Commission · verified Aug 30, 2026

Sep 14, 2026
in 14 days

United States — federal · Comments close

CMS/CDC request for information on modernizing the 1988 CLIA clinical-laboratory regulations, with one of its…

Health and Human Services Department — Proposed Rule

Detail and source

CMS/CDC request for information on modernizing the 1988 CLIA clinical-laboratory regulations, with one of its numbered topics asking specifically how labs use AI and software algorithms to interpret test results and whether AI should be written into the CLIA rules.

comments_close_on: 2026-09-14 (Federal Register API)

Docket CMS-3485-NC

Request for Information; Clinical Laboratory Improvement Amendments of 1988 (CLIA) Regulations · verified Aug 30, 2026

Sep 14, 2026
in 14 days

United States — federal · Comments close

CMS CY2027 Physician Fee Schedule rule which, alongside routine payment policy, runs a large RFI on paying…

Health and Human Services Department — Proposed Rule

Detail and source

CMS CY2027 Physician Fee Schedule rule which, alongside routine payment policy, runs a large RFI on paying for clinical AI in primary care (AI scribes, decision support, AI-enabled Annual Wellness Visits, whether AI companies may deliver AWV services) and proposes two AI-focused MIPS improvement activities plus AI/algorithm-driven 'Software as a Medical Service' lab-analysis payment.

comments_close_on: 2026-09-14 (Federal Register API)

Docket CMS-1848-P

Medicare and Medicaid Programs; CY 2027 Payment Policies Under the Physician Fee Schedule and Other Changes to Part B Payment and Coverage Policies; Medicare Shared Savings Program Requirements; and Medicare Prescription Drug Inflation Rebate Program · verified Aug 30, 2026

Sep 30, 2026
in 30 days

United States — federal · Comments close

FCC seeks comment on overhauling how the Universal Service Fund is administered by USAC

Federal Communications Commission — Proposed Rule

Detail and source

FCC seeks comment on overhauling how the Universal Service Fund is administered by USAC (processes, shot clocks, audits and recoveries, operating costs, USAC's board), and asks repeatedly whether AI should be used to review USF applications, audits and appeals - and what safeguards, governance and privacy protections that would require.

comments due 2026-09-30; reply comments 2026-10-30 (Federal Register API)

Docket WC Docket No. 26-173 · Reply comments due 2026-10-30

Maximizing Efficiencies in Universal Service Administration · verified Aug 30, 2026 · likely, see note

Oct 1, 2026
in 31 days

United States — Connecticut · Compliance · Enacted, not yet applicable

WARN Act layoff notices must state whether the layoffs relate to the employer's use of AI or another technological change

Connecticut AI Responsibility and Transparency Act (Public Act 26-15, SB 5)

EmployerEmployment
Detail and source

First operative date of the CART Act, signed 2 June 2026. The Act phases in between October 2026 and January 2028 and covers employment decision tools, consumer chatbots, frontier developers, generative-AI provenance and platforms used by minors.

Who: employers subject to the federal WARN Act

Closest verified wording (from concurring analyses of the session law): employers must give written notice to the Connecticut Department of Labor disclosing "whether the layoffs are related to the employer's use of artificial intelligence or another technological change", triggered where the layoffs "qualify as a mass layoff or plant closing under the federal Worker Adjustment and Retraining Notification (WARN) Act", effective October 1, 2026. The row's source_quote ("Beginning October 1, 2026, any employer that serves written notice...") is a commentator's construction, not statutory drafting -- Connecticut public acts carry effective dates in a separate effective-date table, never as an inline 'Beginning [date]' clause.

cga.ct.gov currently serves an incomplete TLS certificate chain, so the session-law URL fails strict clients and link-checkers even though the document is real. Open it in a browser and confirm before publication.

Connecticut Public Act 26-15 (CART Act) · verified Aug 30, 2026

Oct 13, 2026
in 43 days

United States — federal · Comments close

NIST asks how the National Vulnerability Database should be rebuilt for an AI-driven security landscape

Commerce Department — Notice

Detail and source

NIST asks how the National Vulnerability Database should be rebuilt for an AI-driven security landscape - which parts of the vulnerability lifecycle to hand to AI automation, where human review must stay, how to make AI-driven risk prioritisation auditable, and what safeguards are needed against bad AI-generated fixes.

comments_close_on: 2026-10-13 (Federal Register API)

Docket Docket Number: 260805-0401

Request for Information (RFI) on Modernizing the National Vulnerability Database in the Age of Artificial Intelligence · verified Aug 30, 2026

Oct 20, 2026
in 2 months

United States — federal · Comments close

CFTC asks how exchanges should design and list futures/swaps whose underlying commodity is AI compute capacity

Commodity Futures Trading Commission — Proposed Rule

Detail and source

CFTC asks how exchanges should design and list futures/swaps whose underlying commodity is AI compute capacity - how to measure the size, liquidity and price transparency of the compute cash market, whether a contract may settle to an index the CFTC cannot verify, and what standards fungible 'compute' delivery would require.

comments_close_on: 2026-10-20 (Federal Register API)

Request for Comment on the Listing of Compute Derivatives Contracts · verified Aug 30, 2026

Dec 1, 2026
in 3 months

Chile · Law applies · Enacted, not yet applicable

Automated individual decisions and profiling: data subjects gain the right to object and not to be subject to decisions based on automated processing that produce legal effects or significantly affect them; controllers must in all cases guarantee information and transparency, an explanation, human intervention, the right to express a point of view and to request review of the decision, and must disclose the existence of automated decisions together with meaningful information on the logic applied

Ley N. 21.719 — Regula la protección y el tratamiento de los datos personales y crea la Agencia de Protección de Datos Personales (promulgada 25-NOV-2024, publicada en el Diario Oficial 13-DIC-2024), en particular el nuevo Artículo 8° bis y el Artículo 14 letra l) que incorpora a la Ley N. 19.628

ControllerDeployerProcessorAll sectors — public and private
Detail and source

Art. 8° bis is Chile's GDPR-Art.22 analogue and is the operative AI/ADM hook. The exceptions are narrow (necessary for the conclusion or performance of a contract; prior express consent under art. 12; where the law so provides with safeguards) and even inside those exceptions the safeguard duties still apply. Art. 14(l) adds a standing transparency duty to disclose 'la existencia de decisiones automatizadas, incluida la elaboración de perfiles' with 'información significativa sobre la lógica aplicada, así como las consecuencias previstas de dicho tratamiento para el titular'. Profiling is defined in the new letter w): 'toda forma de tratamiento automatizado de datos personales que consista en utilizar esos datos para evaluar, analizar o predecir aspectos relativos al rendimiento profesional, situación económica, de salud, preferencias personales, intereses, fiabilidad, comportamiento, ubicación o movimientos de una persona natural'. The law also creates the Agencia de Protección de Datos Personales as enforcement authority.

Who: no size threshold

Reach: Chile — with extraterritorial reach under the new Article 1 bis on territorial scope of application

Penalty: Enforced by the newly created Agencia de Protección de Datos Personales through an administrative sanctioning regime graded by seriousness of infringement, with fines in UTM and a Registro Nacional de Sanciones y Cumplimiento; the Agency also holds inspection and instruction powers.

Entra en vigencia el 01-DIC-2026 — LEY 21719 REGULA LA PROTECCIÓN Y EL TRATAMIENTO DE LOS DATOS PERSONALES Y CREA LA AGENCIA DE PROTECCIÓN DE DATOS PERSONALES. Promulgación: 25-NOV-2024. Publicación: 13-DIC-2024. Versión: Con Vigencia Diferida por Fecha - 01-DIC-2026.

FUTURE DATE — the single most calendar-relevant item found for Latin America (today 2026-08-30, so roughly three months out). The date is taken from the BCN's own status banner, which writes it as a calendar date ('Entra en vigencia el 01-DIC-2026'), NOT computed by me. The law's own transitional clause is relative — 'Artículo primero.- Las modificaciones a las leyes N° 19.628 ... entrarán en vigencia el día primero del mes vigésimo cuarto posterior a la publicación de esta ley en el Diario Oficial' — which is why the BCN record is cited as the date source. NOTE the phrase 'artificial intelligence' does NOT appear anywhere in Ley 21.719 (checked: zero occurrences of 'inteligencia artificial' and of 'algoritmo'); the AI relevance rests entirely on the automated-decision and profiling wording quoted above, hence ai_explicit_hook rather than ai_specific. BCN records 'Última modificación: 05-FEB-2026 - Ley 21806' — that later amending law did not displace the 01-DIC-2026 commencement, which the BCN banner still shows. Artículo segundo transitorio requires the implementing reglamentos to be issued within six months of publication (relative period, no calendar date, so no separate row). BCN's leychile site is a JavaScript application — the text was read by rendering it in a browser; curl returns a 9.6 KB shell and the PDF export service returned an empty file.

Ley Chile — LEY 21719, Biblioteca del Congreso Nacional (official consolidated text and status record) · verified Aug 30, 2026

Dec 2, 2026
in 3 months

European Union · Compliance

Four-month transitional period ends for marking generative AI systems already on the market before 2 August 2026

EU AI Act (Regulation (EU) 2024/1689)

ProviderAll
Detail and source

Regulation (EU) 2026/1744 gave providers whose generative systems were already placed on the market a four-month grace period on the Article 50 marking duty. After it, no carve-out remains.

Penalty: Up to EUR 15 000 000 or 3% of worldwide annual turnover

Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, that have been placed on the market before 2 August 2026 shall take the necessary steps in order to comply with Article 50(2) by 2 December 2026.

Date computed as four months from 2 August 2026 — the recital states the length, not the end date. Flagged as 'likely' until the Commission publishes the operative date.

Regulation (EU) 2026/1744, Recital 38 · verified Aug 30, 2026

Dec 9, 2026
in 3 months

European Union · Law applies

New product liability regime applies to software and AI systems placed on the market

Product Liability Directive (Directive (EU) 2024/2853)

ProviderManufacturerImporterSoftwareAI development
Detail and source

Software — explicitly including AI systems, whether embedded, networked or delivered as SaaS — becomes a 'product' for strict liability. AI system providers are treated as manufacturers. Applies to products placed on the market or put into service after 9 December 2026.

Reach: Products placed on the EU market

Penalty: Strict civil liability for damage caused by defective products; no financial ceiling

Article 2(1): 'This Directive shall apply to products placed on the market or put into service after 9 December 2026.' Article 4(1): ‘product’ means all movables, even if integrated into, or inter-connected with, another movable or an immovable; it includes electricity, digital manufacturing files, raw materials and software'. Article 22(1): 'Member States shall bring into force the laws, regulations and administrative provisions necessary to comply with this Directive by 9 December 2026.'

Directive (EU) 2024/2853, Article 2(1) and Article 4(1) · verified Aug 30, 2026

Dec 10, 2026
in 3 months

Australia · Compliance

Privacy policies must disclose automated decision-making that significantly affects people

Privacy Act 1988 (Cth), as amended by the Privacy and Other Legislation Amendment Act 2024

DeployerBusinessAll
Detail and source

A disclosure duty, not a ban: APP entities must state in their privacy policy which personal information is used by computer programs to make decisions that significantly affect individuals, and what kinds of decisions those are. Reaches ordinary businesses, not only AI companies; human oversight does not exempt.

Who: APP entities under the Privacy Act

Reach: Organisations covered by the Privacy Act 1988, including foreign entities carrying on business in Australia

Penalty: Low-tier civil penalty regime under s 13K(1)(b)(iia) — infringement and compliance notices, up to roughly AUD 330,000 for a body corporate

The ADM obligation commences on 10 December 2026. ... The ADM obligation will enhance the right to privacy by introducing requirements that entities must include information in privacy policies about the kinds of personal information used in, and types of decisions made by, computer programs that use personal information to make decisions that could reasonably be expected to significantly affect the rights or interests of an individual. (OAIC, Automated Decision-Making Transparency Obligation (APP 1) Issues Paper, 18 May 2026, Executive summary). OAIC consultation page wording: "From 10 December 2026, APP entities that use personal information in ADM with the potential to affect rights or interests will be required to provide information in their privacy policies about the kinds of personal information used and the kinds of decisions made using ADM." Statutory text (Attachment A, new APP 1.7): "Without limiting subclause 1.3, the APP privacy policy of an APP entity must contain the information covered by subclause 1.8 if: (a) the entity has arranged for a computer program to make, or do a thing that is substantially and directly related to making, a decision; and (b) the decision could reasonably be expected to significantly affect the rights or interests of an individual; and (c) personal information about the individual is used in the operation of the computer program to make the decision or do the thing that is substantially and directly related to making the decision."

Commencement is 24 months from Royal Assent (10 Dec 2024) of Schedule 1 Part 15 — not Part 2. The Privacy Act text says 'computer program', not 'artificial intelligence'; the AI framing comes from the OAIC's own material, so this is an AI-adjacent row with an explicit regulator hook.

Privacy Act 1988 — automated decision-making transparency (Sch. 1, Pt. 2) · verified Aug 30, 2026

Dec 31, 2026
in 4 months

United Kingdom · Reporting

Secretary of State must lay before Parliament a progress report on making regulations to bring illegal AI-generated content and AI services into the Online Safety Act 2023

Crime and Policing Act 2026, s.249 (duty to make progress report), in force at Royal Assent per s.255(2)(k)

Secretary of State (duty holder)Providers of AI services and chatbots (prospective duty holders under the resulting regulations)Generative AIChatbotsSocial mediaSearch
Detail and source

Section 248 of the Crime and Policing Act 2026 ('Power to amend Online Safety Act 2023: AI') inserts a new s.216A into the Online Safety Act 2023, letting the Secretary of State amend that Act by regulations to address risks from illegal AI-generated content and the use of AI services to commit or facilitate priority offences. An 'AI service' is defined as an internet service capable of generating AI-generated content, no matter what proportion of content on the service is AI-generated - the route by which standalone AI chatbots, which Ofcom has said fall outside Part 3 when output is not user-generated or search content, can be brought into the illegal content duties. Section 249 backs that power with a hard reporting deadline: the Secretary of State must lay a progress report by 31 December 2026 unless draft regulations have been laid before Parliament by then.

Who: n/a

Reach: United Kingdom

Penalty: Parliamentary duty on the Secretary of State; no financial penalty. The regulations it anticipates would carry full Online Safety Act enforcement against AI services.

(1) The Secretary of State must, no later than 31 December 2026, lay before Parliament a report about the progress that has been made towards making regulations under section 216A of the Online Safety Act 2023 (power to amend Act in relation to illegal AI-generated content). (2) Subsection (1) does not apply if a draft of a statutory instrument containing regulations under that section is laid before Parliament before 31 December 2026.

FUTURE DATE - the only forward-looking dated UK AI obligation found. Both ss.248 and 249 are in force at Royal Assent (commencement notes: 'in force at Royal Assent, see s. 255(2)(k)'). The duty falls away if draft regulations under the new OSA s.216A are laid before 31 December 2026, so the calendar entry should be checked against whether a draft SI has been laid. Background: the power was added to the Crime and Policing Bill by government amendment after concerns about AI chatbot content.

Crime and Policing Act 2026, section 249 (duty to make progress report) · verified Aug 30, 2026

Jan 1, 2027
in 4 months

United States — California · Compliance

Businesses using ADMT for significant decisions must comply in full: pre-use notice, opt-out and access rights

CCPA regulations on automated decisionmaking technology (CPPA, eff. 1 Jan 2026)

BusinessDeployerEmploymentCreditHousingEducation
Detail and source

Significant decisions include financial or lending services, housing, education, employment or independent contracting opportunities and healthcare.

Reach: Businesses processing personal information of California residents above CCPA thresholds

Penalty: CCPA administrative fines up to $2,663 per violation, $7,988 per intentional violation (CPPA enforcement)

CCPA Regulations (11 CCR) § 7200(b): “A business that uses ADMT for a significant decision prior to January 1, 2027, must be in compliance with the requirements of this Article no later than January 1, 2027. A business that uses ADMT on or after January 1, 2027, must be in compliance with the requirements of this Article any time it is using ADMT for a significant decision.”

Scope fix: WRONG SECTION CITATION: the quoted sentence is § 7200(b) (‘When a Business’s Use of Automated Decisionmaking Technology is Subject to the Requirements of This Article’), NOT § 7221(b). § 7221(b) is an unrelated provision listing the circumstances in which a business need NOT offer an ADMT opt-out (human-appeal exception etc.). Fix source_title to '11 CCR § 7200(b)'. applies_to: drop 'deployer' — the regulations impose duties only on a 'business' as defined in Civ. Code § 1798.140(d); 'deployer' is not a term in the CCPA or these regulations. Also add the CCPA business threshold: only entities meeting Civ. Code § 1798.140(d)(1) (revenue/consumer-volume/sale-of-data thresholds) are covered, so the current applies_to (no size field) reads broader than the rule. Sectors list is ACCURATE and matches § 7001(ddd): 'a decision that results in the provision or denial of financial or lending services, housing, education enrollment or opportunities, employment or independent contracting opportunities or compensation, or healthcare services.' Obligation text (pre-use notice § 7220, opt-out § 7221, access § 7222) is accurate. Penalty figures $2,663 / $7,988 VERIFIED as the amounts currently in force (CPPA CPI adjustment effective 2025-01-01, per Civ. Code § 1798.199.95(d); next biennial adjustment due to be posted by 2027-01-15) — but $7,988 covers 'each intentional violation AND each violation involving the personal information of consumers the business has actual knowledge are under 16 years of age' under Civ. Code § 1798.155(a), so 'per intentional violation' alone is incomplete.

CCPA Regulations § 7221(b) · verified Aug 30, 2026

Jan 1, 2027
in 4 months

United States — California · Compliance

Large online platforms must detect and surface content provenance data

California AI Transparency Act (SB 942 as amended by AB 853)

PlatformOnline platforms
Detail and source

Platforms above 2 million monthly users must detect provenance data in distributed content, expose it in the user interface, and let users inspect whether content was AI-generated or captured by a device.

Who: over 2 million monthly users

Bus. & Prof. Code § 22757.3.1 (added by AB 853, Ch. 674, Stats. 2025), operative-date sentence: “This section shall become operative on January 1, 2027.” The duty it dates, in the section's own words, is to “detect whether any provenance data that is compliant with widely adopted specifications adopted by an established standards-setting body is embedded into or attached to content.”

Scope fix: The row's source_quote is a compressed restatement, not statutory language — replace with the § 22757.3.1 operative-date sentence plus the 'detect whether any provenance data...' clause. applies_to.roles 'platform' is broader than the text: § 22757.1 limits the duty to a 'large online platform', defined as a public-facing social media platform, file-sharing platform, mass messaging platform, or stand-alone search engine that distributes content to users who did not create or collaborate in creating it — and it expressly excludes broadband internet access service and telecommunications service. applies_to.size should read 'exceeded 2,000,000 unique monthly users during the preceding 12 months' (the statute measures unique monthly users over a trailing 12-month window, not a flat headcount). PENALTY IS MISSING: § 22757.4 provides a civil penalty of $5,000 per violation, enforceable by the Attorney General, a city attorney, or a county counsel, with each day a large online platform is in violation deemed a discrete violation (prevailing plaintiff also recovers attorney's fees and costs). The obligation line understates the duty: besides detecting provenance data, § 22757.3.1 requires a user interface disclosing the availability of system provenance data (whether content was generated or substantially altered by a GenAI system, or captured by a capture device), letting users inspect that data in an easily accessible manner, and bars knowingly stripping compliant system provenance data or digital signatures where technically feasible.

AB 853, California AI Transparency Act · verified Aug 30, 2026

Jan 1, 2027
in 4 months

United States — Colorado · Compliance · Enacted, not yet applicable

Developers and deployers of ADMT used in consequential decisions must give notice, documentation and post-decision disclosures

Colorado SB 26-189, Automated Decision-Making Technology

DeveloperDeployerEmploymentCreditHousingEducation
Detail and source

Replaces the repealed Colorado AI Act (SB 24-205). Developers must hand deployers technical documentation on intended uses, training-data categories, known limitations and human-review instructions; both sides keep compliance records for three years.

Penalty: Enforcement centralised with the Colorado Attorney General; fault-based apportionment of discrimination liability

From the enrolled Final Act: "SECTION 5. Effective date - applicability. (1) Except as otherwise provided in subsection (2) of this section, this act takes effect January 1, 2027. ... (3) This act applies to consequential decisions made on or after January 1, 2027." Operative duty: "6-1-1702. Developer responsibilities - documentation. (1) ON AND AFTER JANUARY 1, 2027, A DEVELOPER SHALL MAKE AVAILABLE TO EACH DEPLOYER OF A COVERED ADMT DEVELOPED BY THE DEVELOPER, IN A FORM AND MANNER THAT IS REASONABLY UNDERSTANDABLE TO A DEPLOYER AND THAT PROTECTS TRADE SECRETS...". Deployer notice: "[A DEPLOYER] SHALL PROVIDE A CLEAR AND CONSPICUOUS NOTICE TO A CONSUMER THAT THE DEPLOYER USED OR WILL USE A COVERED ADMT IN A CONSEQUENTIAL DECISION AFFECTING THE CONSUMER AND INSTRUCTIONS REGARDING HOW THE CONSUMER MAY OBTAIN THE ADDITIONAL INFORMATION DESCRIBED IN THIS SECTION." AG rulemaking (BOTH provisions): "(b) ON OR BEFORE JANUARY 1, 2027, THE ATTORNEY GENERAL SHALL ADOPT RULES TO CLARIFY AND IMPLEMENT THE POST-ADVERSE OUTCOME DISCLOSURE REQUIREMENTS SET FORTH IN SUBSECTION (3) OF THIS SECTION" and "(3) ON OR BEFORE JANUARY 1, 2027, THE ATTORNEY GENERAL SHALL ADOPT RULES TO CLARIFY AND IMPLEMENT THE REQUIREMENTS OF THIS SECTION." Fault apportionment: "FAULT SHALL BE ALLOCATED AMONG DEPLOYERS AND DEVELOPERS BASED ON THEIR RELATIVE FAULT FOR THE VIOLATION."

Third date this obligation has had: 1 Feb 2026 → 30 Jun 2026 (SB 25B-004) → repealed and replaced. The Attorney General must adopt mandatory rules under 6-1-1704(4)(b) and 6-1-1705(3) on or before the same 1 January 2027 date on which compliance starts — a real planning risk.

SB26-189 Automated Decision-Making Technology, Colorado General Assembly · verified Aug 30, 2026

Jan 1, 2027
in 4 months

United States — Colorado · Regulator milestone · Enacted, not yet applicable

Attorney General must adopt implementing rules — on the same day compliance begins

Colorado SB 26-189, Automated Decision-Making Technology

Colorado Attorney GeneralAll
Detail and source

Two mandatory rulemaking duties, 6-1-1704(4)(b) and 6-1-1705(3), both worded 'on or before January 1, 2027, the Attorney General shall adopt rules'. Deployers therefore may not see final rules before their own obligations start.

ON OR BEFORE JANUARY 1, 2027, THE ATTORNEY GENERAL SHALL ADOPT RULES

ADDED BY FACT-CHECK — quoted from the enrolled Final Act during verification of the main Colorado row.

Colorado SB 26-189, sections 6-1-1704(4)(b) and 6-1-1705(3) · verified Aug 30, 2026

Jan 1, 2027
in 4 months

United States — New York · Compliance · Enacted, not yet applicable

Frontier model developers must publish a safety framework, file disclosures and report safety incidents within 72 hours

Responsible AI Safety and Education Act (RAISE Act)

DeveloperFrontierAI development
Detail and source

Base law is Chapter 699 of 2025 (S6953-B, signed 19 December 2025), overhauled by chapter amendment S8828/A9449 signed 27 March 2026, which struck the original commencement and wrote in 1 January 2027. The amendment also moved oversight to a new office inside NYDFS.

Who: over $500M annual revenue

Penalty: Civil penalties up to $1,000,000 (first violation) and $3,000,000 (subsequent), enforced through NYDFS — reduced from $10M/$30M by the March 2026 amendment

Effective-date clause as amended (S8828 sec. 3, showing the bracketed repeal and new date): "This act shall take effect [on the ninetieth day after it shall have become a law] JANUARY 1, 2027." Operative duties in the consolidated text: "A LARGE FRONTIER DEVELOPER SHALL WRITE, IMPLEMENT, COMPLY WITH, AND CLEARLY AND CONSPICUOUSLY PUBLISH ON ITS INTERNET WEBSITE A FRONTIER AI FRAMEWORK"; "A LARGE FRONTIER DEVELOPER SHALL TRANSMIT TO THE OFFICE A SUMMARY OF ANY ASSESSMENT OF CATASTROPHIC RISK RESULTING FROM INTERNAL USE OF ITS FRONTIER MODELS EVERY THREE MONTHS"; "A FRONTIER DEVELOPER SHALL REPORT ANY CRITICAL SAFETY INCIDENT PERTAINING TO ONE OR MORE OF ITS FRONTIER MODELS TO THE OFFICE WITHIN SEVENTY-TWO HOURS". Threshold definition: "A FRONTIER DEVELOPER THAT TOGETHER WITH ITS AFFILIATES COLLECTIVELY HAD ANNUAL GROSS REVENUES IN EXCESS OF FIVE HUNDRED MILLION DOLLARS IN THE PRECEDING CALENDAR YEAR."

Scope split: only the Frontier AI Framework, quarterly catastrophic-risk summaries and biennial disclosure statements sit behind the $500M revenue gate. The 72-hour critical-incident report binds ANY frontier developer, with no revenue floor.

New York RAISE Act · verified Aug 30, 2026

Jan 20, 2027
in 5 months

European Union · Law applies

New machinery regime applies, covering digital and AI-driven risks for the first time

Machinery Regulation (Regulation (EU) 2023/1230)

ManufacturerImporterMachineryRoboticsManufacturing
Detail and source

Replaces the Machinery Directive. Safety assessment must account for AI-based control functions and human-robot collaboration; machinery with AI safety components sits in the higher conformity-assessment category.

Reach: Machinery placed on the EU market

Penalty: National penalties under Article 50 — effective, proportionate and dissuasive, and may include criminal penalties for serious infringements

Article 54 'Entry into force and application', second paragraph, AS CORRECTED: 'It shall apply from 20 January 2027.' The as-published OJ L 165 text reads '14 January 2027'; the Corrigendum in OJ L 169, 4.7.2023, p. 35 states: '10. On page 39, Article 54, second paragraph: for: ‘14 January 2027’, read: ‘20 January 2027’.' Article 54, first paragraph (unchanged): 'This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.'

The as-published OJ text says 14 January 2027; a corrigendum (OJ L 169, 4.7.2023, p. 35) moved fourteen dates by six days, including Article 54 → 20 January 2027. Cite the corrigendum or a future re-check will 'correct' this correct row into a wrong one. AI hook is operative, not incidental: Annex I Part A item 5 covers safety components with self-evolving behaviour using machine learning.

Regulation (EU) 2023/1230 on machinery · verified Aug 30, 2026

Mar 1, 2027
in 6 months

Vietnam · Compliance

Legacy high-risk AI systems outside health/education/finance that were already in operation before 15 August 2026 must have completed their compliance obligations under the AI Law

Prime Minister's Decision No. 33/2026/QD-TTg (List of high-risk AI systems) — compliance roadmap, read with Law on AI No. 134/2025/QH15 Art. 35

ProviderDeployerEthnic-and-religious-affairsJusticeTransport
Detail and source

Providers (nhà cung cấp) and deployers (bên triển khai) of AI systems on the high-risk list that were already deployed before the Decision took effect get a transition window. Systems may keep operating during the window, except where the competent state authority determines a system risks serious harm and orders suspension or termination.

Who: all

Reach: Vietnam

Penalty: Competent state authority may require suspension or termination of the system during the transition window if it poses a risk of serious harm

Trước ngày 01/3/2027 đối với các hệ thống trí tuệ nhân tạo thuộc các lĩnh vực còn lại trong Danh mục. // 'Before 1 March 2027 for the artificial intelligence systems in the remaining fields on the List.'

Date is STATED by the regulator (MST) and by the Government newspaper as an explicit calendar date, not derived by me from a period. It corresponds to the 12-month transition in Art. 35 of Law 134/2025/QH15, but I am recording the date the regulator wrote. Verified 2026-08-30.

Bộ Khoa học và Công nghệ — 46 hệ thống AI được xếp vào nhóm rủi ro cao, phải quản lý nghiêm ngặt · verified Aug 30, 2026

May 1, 2027
in 8 months

Canada — federal · Compliance

Federally regulated financial institutions must have enterprise-wide, risk-based model risk management covering ALL models including artificial intelligence and machine learning models — model inventory, risk tiering, governance and accountability across the full model lifecycle from development through deployment, monitoring and decommissioning

OSFI Guideline E-23 — Model Risk Management (2027), Office of the Superintendent of Financial Institutions (final version published 11 September 2025)

DeployerOperatorRisk ownerFinancial services — banks, insurance companies, property and casualty companies, trust and loan companies
Detail and source

E-23 is principles-based and organised around three pillars — model risk understood and managed enterprise-wide; a risk-based approach built on model inventory, risk tiering and assurance; and governance across the full model lifecycle. The 2027 version materially widens the 2017 original: scope expands from deposit-taking institutions to ALL federally regulated financial institutions including insurers and foreign branches, and the definition of 'model' is broadened so AI/ML systems fall squarely inside, with added context for AI/ML model risk. Policies, procedures and controls must be proportionate to the institution's size, risk profile, complexity of operations and interconnectedness in the financial system.

Who: all federally regulated financial institutions, including foreign bank branches and foreign insurance company branches; expectations are proportionate to size, risk profile, complexity and interconnectedness

Reach: Canada — federally regulated financial institutions, including the Canadian business of foreign bank and foreign insurance company branches

Penalty: OSFI guidelines are supervisory expectations rather than statutory offences: non-compliance is addressed through the supervisory process — findings and recommendations, elevated risk ratings and intervention staging, and where warranted directions of compliance and other supervisory powers under the Bank Act, Insurance Companies Act and Trust and Loan Companies Act. No administrative monetary penalty attaches to the guideline itself.

Effective date: May 1, 2027

FUTURE DATE — the most calendar-relevant Canadian federal item found, and the one that actually binds the private sector (the Treasury Board Directive binds only federal institutions). Status is set to in_force because the guideline is issued and final; the duties bite on the stated effective date of 2027-05-01. The guideline applies to 'all federally regulated financial institutions, including foreign bank branches and foreign insurance company branches, to the extent it is consistent with applicable requirements and legal obligations related to their business in Canada'. Classified ai_explicit_hook rather than ai_specific because the instrument governs models generally, with AI/ML named explicitly in the operative text and given dedicated treatment.

Guideline E-23 – Model Risk Management (2027) — Office of the Superintendent of Financial Institutions (regulator's own guidance library page) · verified Aug 30, 2026

Aug 1, 2027
in 11 months

European Union · Regulator milestone

Commission guidance due on practical implementation of Articles 8(2), 9(10) and 17(3)

EU AI Act (Regulation (EU) 2024/1689)

European Commission
Detail and source

Guidance on avoiding duplication between the AI Act and Annex I Section A product legislation — it serves the Annex I cohort whose obligations land on 2 August 2028.

the practical implementation of Article 8(2), Article 9(10) and Article 17(3) in accordance with the principle of complementarity and proportionality, with a view to ensuring consistency, avoiding duplication and minimising additional burdens when complying with the requirements of this Regulation and the requirements of the Union harmonisation legislation listed in Section A of Annex I; such guidelines shall be published by 1 August 2027.

Obligation on the Commission, not on business. Earlier framing of this row as gating the December 2027 high-risk date was wrong — it serves the 2028 product cohort.

Regulation (EU) 2026/1744, Recital 37 · verified Aug 30, 2026

Aug 2, 2027
in 11 months

European Union · Compliance

Legacy general-purpose AI models placed on the market before 2 August 2025 must be brought into compliance

EU AI Act (Regulation (EU) 2024/1689)

ProviderGPAIAll
Detail and source

Two-year grandfathering under Article 111(3) expires. Applies to GPAI models already on the market when the GPAI chapter started applying.

Penalty: Up to EUR 15 000 000 or 3% of worldwide annual turnover (Art. 101)

Providers of general-purpose AI models that have been placed on the market before 2 August 2025 shall take the necessary steps in order to comply with the obligations laid down in this Regulation by 2 August 2027.

Regulation (EU) 2024/1689 — Article 111(3) · verified Aug 30, 2026

Sep 1, 2027
in 12 months

Vietnam · Compliance

Legacy high-risk AI systems in health, education and finance that were already in operation before 15 August 2026 must have completed their compliance obligations under the AI Law

Prime Minister's Decision No. 33/2026/QD-TTg (List of high-risk AI systems) — compliance roadmap, read with Law on AI No. 134/2025/QH15 Art. 35

ProviderDeployerHealthEducationFinanceBanking
Detail and source

Longer transition window (than other sectors) for AI systems already deployed in health care, education and finance. Systems may keep operating during the window, except where the competent state authority determines a system risks serious harm and orders suspension or termination.

Who: all

Reach: Vietnam

Penalty: Competent state authority may require suspension or termination of the system during the transition window if it poses a risk of serious harm

Trước ngày 01/9/2027 đối với các hệ thống trí tuệ nhân tạo trong lĩnh vực y tế, giáo dục và tài chính. // 'Before 1 September 2027 for artificial intelligence systems in the health, education and finance sectors.'

Date STATED as a calendar date by the regulator (MST) and by baochinhphu.vn; corresponds to the 18-month transition in Art. 35 of Law 134/2025/QH15 for health, education and finance. Verified 2026-08-30.

Bộ Khoa học và Công nghệ — 46 hệ thống AI được xếp vào nhóm rủi ro cao, phải quản lý nghiêm ngặt · verified Aug 30, 2026

Sep 2, 2027
in 12 months

European Union · Regulator milestone

Commission post-market monitoring guidance due

EU AI Act (Regulation (EU) 2024/1689)

European Commission
Detail and source
The Commission, taking utmost account of the opinion of the Board, shall adopt guidance, including a template, on the post-market monitoring plan by 2 September 2027.

Regulation (EU) 2026/1744, Recital 41 · verified Aug 30, 2026

Oct 1, 2027
in 13 months

United States — Connecticut · Compliance · Enacted, not yet applicable

Employers using automated employment decision technology must give detailed notices to applicants and employees

Connecticut AI Responsibility and Transparency Act (Public Act 26-15, SB 5)

EmployerDeployerEmployment
Detail and source
Closest verified wording: from 1 October 2027, deployers of automated employment-related decision technology must disclose to applicants and employees that they are interacting with AEDT unless it is obvious, and where AEDT is used to make, or its output is a substantial factor in making, an employment-related decision, must give written notice before the decision covering the fact of its use, the purposes and the employment decisions affected, the trade name of the technology, the categories of personal data analysed and how they are assessed, and employer contact details; for an adverse decision the notice must give "a high-level statement disclosing the principal reasons for the decision, including how much and how the automated process output contributed to the decision, and the type and source of data." AEDT is defined as "any technology that processes personal data and uses computation to generate any output, including predictions, recommendations, classifications, rankings, scores or other information, that is a substantial factor used to make or materially influence an employment-related decision." The row's source_quote is a commentator's paraphrase, not statutory text.

Same TLS caveat as the October 2026 Connecticut row — confirm the session-law URL manually before publication.

Connecticut Public Act 26-15 (CART Act) · verified Aug 30, 2026

Dec 2, 2027
in 15 months

European Union · Compliance

High-risk obligations apply to stand-alone Annex III systems — deferred from 2 August 2026

EU AI Act (Regulation (EU) 2024/1689), as amended by Regulation (EU) 2026/1744

ProviderDeployerImporterDistributorHighEmploymentCreditEducationEssential services
Detail and source

Risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness, conformity assessment and EU database registration for stand-alone high-risk systems: employment, credit, education, essential services, law enforcement, migration, justice, biometrics.

Reach: Extraterritorial: applies wherever the provider is established if the system is placed on the EU market or its output is used in the EU

Penalty: Up to EUR 15 000 000 or 3% of worldwide annual turnover (Art. 99(4))

Chapter III, Sections 1, 2, and 3, with the exception of Article 6(5), shall apply from: (i) 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III; and (ii) 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I;

Only Chapter III Sections 1–3 are deferred. Section 5 (Arts 40–49: conformity assessment, certificates, registration) has applied since 2 August 2026 and Section 4 since 2 August 2025, and Article 6(5) is expressly excepted — 'high-risk rules do not start until December 2027' overstates the relief.

Regulation (EU) 2026/1744 — deferral of Chapter III obligations · verified Aug 30, 2026

Dec 11, 2027
in 15 months

European Union · Compliance

Full CRA regime applies: security by design, vulnerability handling, CE marking for products with digital elements

Cyber Resilience Act (Regulation (EU) 2024/2847)

ManufacturerImporterDistributorSoftwareHardwareIoT
Detail and source

Reach: Products with digital elements placed on the EU market

Penalty: Up to EUR 15 000 000 or 2.5% of total worldwide annual turnover, whichever is higher (Art. 64(2))

This Regulation shall apply from 11 December 2027. (Article 71(2), first subparagraph)

Cyber Resilience Act — summary of the legislative text, European Commission · verified Aug 30, 2026

Dec 31, 2027
in 16 months

United States — California · Compliance

Risk assessments must be completed for processing activities started before the regulations took effect and still running

CCPA regulations on risk assessments (CPPA, eff. 1 Jan 2026)

BusinessAll
Detail and source
CCPA Regulations (11 CCR) § 7155(b): “For any processing activity identified in section 7150, subsection (b), that the business initiated prior to [OAL to fill in the effective date of these regulations] and that continues after [OAL to fill in the effective date of these regulations], the business must conduct, and document as set forth in section 7152, a risk assessment in accordance with the requirements of this Article no later than December 31, 2027. The business must comply with the submission requirements set forth in section 7157, subsection (a)(1).”

Scope fix: WRONG SECTION CITATION: the sentence is § 7155(b) (‘Timing and Retention Requirements for Risk Assessments’), NOT § 7156(b). § 7156 is ‘Conducting Risk Assessments for a Comparable Set of Processing Activities or in Compliance with Other Laws or Regulations’, and its subsection (b) is about reusing an assessment prepared for another purpose — it contains no date. Fix source_title to '11 CCR § 7155(b)'. applies_to reads too broadly: the retroactive-assessment duty is not owed by every business for every activity. It bites only where the business (i) meets the CCPA 'business' thresholds in Civ. Code § 1798.140(d)(1), and (ii) carries on one of the six processing activities enumerated in § 7150(b): selling or sharing personal information; processing sensitive personal information; using ADMT for a significant decision; using automated processing to infer or extrapolate traits of job/education applicants, students, employees or independent contractors; the same inference based on presence in a sensitive location; or processing personal information intended to train an ADMT for a significant decision or to train facial-recognition, emotion-recognition or other identification/profiling technology. Recommend replacing sectors 'all' with the § 7150(b) activity triggers. Penalty is null but CCPA administrative fines (currently $2,663 / $7,988 per Civ. Code § 1798.155(a) as CPI-adjusted effective 2025-01-01) do attach to violations of these regulations.

CCPA Regulations § 7156(b) · verified Aug 30, 2026

Jan 1, 2028
in 16 months

United States — California · Compliance

Capture device manufacturers must embed latent provenance disclosures by default

California AI Transparency Act (SB 942 as amended by AB 853)

ManufacturerHardwareConsumer electronics
Detail and source

Manufacturer name, device name and version, and content creation date/time embedded in captured content, with a user option to include them.

Bus. & Prof. Code § 22757.3.3 (added by AB 853, Ch. 674, Stats. 2025), operative-date sentence: “This section shall become operative on January 1, 2028.” The duty it dates reads “Embed latent disclosures in content captured by the device by default.” The Legislative Counsel's Digest states the scope: “This bill would require, beginning January 1, 2028, a capture device manufacturer, with respect to any capture device the capture device manufacturer first produced for sale in the state on or after January 1, 2028, to, among other things, provide a user with the option to include a latent disclosure in content captured by the capture device that conveys certain information, including the name of the capture device manufacturer.”

Scope fix: The source_quote string ‘certain capture device manufacturers from January 1, 2028’ does NOT appear anywhere in AB 853 — verified against the bill text. It is not a sentence and is unusable as a citation; replace it with the § 22757.3.3 operative-date sentence and the ‘Embed latent disclosures in content captured by the device by default’ requirement. SCOPE OVER-REACH: the obligation is not owed for a manufacturer's whole product line. It attaches only ‘with respect to any capture device the capture device manufacturer first produced for sale in the state on or after January 1, 2028’ — i.e. it is limited to new California-market devices of 2028+ vintage, and does not reach installed base or devices already on sale. applies_to should carry that device-vintage/California-sale qualifier. The obligation line also omits half the duty: besides embedding by default, the manufacturer must provide the user with the OPTION to include a latent disclosure conveying specified information (manufacturer name, device name and version, and the time and date the content was created). ‘Capture device’ is defined in § 22757.1 as ‘a device that can record photographs, audio, or video content, including, but not limited to, video and still photography cameras, mobile phones with built-in cameras or microphones, and voice recorders’ — so the sectors tag should note mobile phones and voice recorders, not just ‘hardware/consumer electronics’. PENALTY IS MISSING: § 22757.4 sets a civil penalty of $5,000 per violation, enforceable by the Attorney General, a city attorney, or a county counsel, with each day a capture device manufacturer is in violation deemed a discrete violation.

AB 853, California AI Transparency Act · verified Aug 30, 2026

Jan 28, 2028
in 17 months

European Union · Compliance

Deadline for notified bodies to apply for designation under the 18-month transition

EU AI Act (Regulation (EU) 2024/1689), as amended by Regulation (EU) 2026/1744

Notified bodyHigh
Detail and source
Without prejudice to Article 28, such notified bodies which have been notified under the Union harmonisation legislation in Section A of Annex I, shall apply for designation in accordance with Section 4 of this Chapter by 28 January 2028.

Not a bar: Recital 18 confirms bodies may still apply during and after these 18 months.

Regulation (EU) 2026/1744 — Article 43(3) as amended, Recital 18 · verified Aug 30, 2026

Apr 1, 2028
in 19 months

United States — California · Reporting

First risk-assessment submission to the CPPA — covering assessments conducted in 2026 and 2027

CCPA regulations on risk assessments (CPPA, eff. 1 Jan 2026)

BusinessAll
Detail and source
CCPA Regulations (11 CCR) § 7157(a)(1): “For risk assessments conducted in 2026 and 2027, the business must submit to the Agency the information required by subsection (b) no later than April 1, 2028.”

Scope fix: WRONG SUBSECTION CITATION: the sentence is § 7157(a)(1) (‘Timing of Risk Assessment Submissions’), NOT § 7157(c)(1). § 7157(c) governs WHO may sign — it requires a member of the business's executive management team who ‘(1) Is directly responsible for the business's risk-assessment compliance’ — and carries no date. Fix source_title to '11 CCR § 7157(a)(1)'. applies_to is too broad in the same way as the 2027-12-31 risk-assessment row: the duty falls only on entities that meet the CCPA 'business' thresholds in Civ. Code § 1798.140(d)(1) AND conduct one of the six § 7150(b) processing activities; sectors 'all' should be replaced by those activity triggers. Worth flagging in the obligation text: what is due on 2028-04-01 is NOT the risk assessment reports themselves but an abridged submission under § 7157(b) — business name and contact, time period, the number of assessments conducted or updated in total and per § 7150(b) activity, which categories of personal and sensitive personal information were involved, and an attestation signed under penalty of perjury by a qualifying executive. Full risk assessment reports are produced only on demand: § 7157(e) lets the Agency or the Attorney General require them at any time, due within 30 calendar days. Submission is made via the Agency's website (§ 7157(d)). Penalty is null; CCPA administrative fines (currently $2,663 / $7,988 per Civ. Code § 1798.155(a)) do attach.

CCPA Regulations § 7157(c)(1) · verified Aug 30, 2026

Aug 2, 2028
in 23 months

European Union · Compliance

High-risk obligations apply to AI embedded in regulated products (Annex I) — deferred from 2 August 2027

EU AI Act (Regulation (EU) 2024/1689), as amended by Regulation (EU) 2026/1744

ProviderManufacturerHighMedical devicesToysRadio equipmentLifts
Detail and source

Machinery, medical devices, vehicles, lifts, toys, radio equipment and the other Annex I product regimes. Corresponding machinery AI requirements land on the same date.

Penalty: Up to EUR 15 000 000 or 3% of worldwide annual turnover

Chapter III, Sections 1, 2, and 3, with the exception of Article 6(5), shall apply from: ... (ii) 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I;

Machinery was moved OUT of Annex I Section A by Regulation (EU) 2026/1744 Art. 1(41) and into Section B, where only Article 6(1), Articles 102–109 and Article 112 apply — no Chapter III duties. Machinery is handled by delegated acts instead.

Regulation (EU) 2026/1744, Recital 40 and Recital 42 · verified Aug 30, 2026

Dec 31, 2030
in 4.3 years

European Union · Compliance

Large-scale EU IT systems listed in Annex X must comply

EU AI Act (Regulation (EU) 2024/1689)

ProviderDeployerPublic sectorBorder management
Detail and source

Systems such as SIS, VIS, EES and ETIAS placed on the market before 2 August 2027 get until end-2030.

AI systems which are components of the large-scale IT systems established by the legal acts listed in Annex X that have been placed on the market or put into service before 2 August 2027 shall be brought into compliance with this Regulation by 31 December 2030.

Regulation (EU) 2024/1689 — Article 111(1) · verified Aug 30, 2026

Aug 15, 2026
16 days ago

Vietnam · Law applies

High-risk AI list takes effect: 46 named AI systems across 6 sectors become 'high-risk' under the Law on AI 134/2025/QH15, triggering the strict-management duties (operating principles and compliance roadmap set by the Decision)

Prime Minister's Decision No. 33/2026/QD-TTg of 30 June 2026 issuing the List of high-risk artificial intelligence systems (Quyết định 33/2026/QĐ-TTg — Danh mục hệ thống trí tuệ nhân tạo có rủi ro cao)

ProviderDeployerEducationEthnic-and-religious-affairsHealthBanking
Detail and source

Signed 30 June 2026 by Deputy PM Hồ Quốc Dũng. Sectors: education; ethnic and religious affairs; health; banking; legal proceedings (tố tụng); transport (transport alone accounts for 31 of the 46 systems). The Decision sets both the operating principles and the compliance roadmap for systems on the list.

Who: all

Reach: Vietnam

Penalty: State AI authority may require suspension or termination of a system it finds poses a risk of serious harm

Ngày có hiệu lực: 15-08-2026 // 'Effective date: 15 August 2026'. Người ký: Hồ Quốc Dũng; Ngày ban hành: 30-06-2026.

Verified 2026-08-30. Effective date taken from the Government's own document portal (vanban.chinhphu.vn) record; sector list and the '46 systems' figure from the Ministry of Science and Technology, the regulator. Signed by Deputy PM (Phó Thủ tướng) Hồ Quốc Dũng.

Cổng thông tin văn bản Chính phủ — Quyết định số 33/2026/QĐ-TTg của Thủ tướng Chính phủ: Ban hành Danh mục hệ thống trí tuệ nhân tạo có rủi ro cao · verified Aug 30, 2026

Aug 3, 2026
28 days ago

New Zealand · Compliance

Organisations that were ALREADY carrying out automated biometric processing before 3 November 2025 must, from this date, comply in full with the Code's 13 rules — including the Rule 1 proportionality assessment, notification duties and the limits on biometric categorisation

Biometric Processing Privacy Code 2025 — end of the transition period for existing biometric processing

DeployerCross-sectorRetailSecurityFinancial-services
Detail and source

The Privacy Commissioner gave a nine-month grace period from commencement for legacy biometric deployments (facial recognition in retail and security, voice authentication, age-estimation systems). That grace period has now expired, so pre-existing systems are fully in scope.

Who: agencies already carrying out biometric processing before 3 November 2025

Reach: New Zealand

Penalty: Interference with privacy under the Privacy Act 2020: complaints, compliance notices, and Human Rights Review Tribunal proceedings including damages

The BPPC came into force on 3 November 2025, but agencies already using biometrics had a nine-month grace period to move to the new set of rules. That transition period ended on 3 August 2026.

The end date is STATED by the regulator in those words ('That transition period ended on 3 August 2026') — not computed by me from the nine-month period. Verified 2026-08-30; date has just passed relative to today.

Office of the Privacy Commissioner — Biometric Processing Privacy Code 2025 · verified Aug 30, 2026

Aug 2, 2026
29 days ago

European Union · Compliance

Transparency obligations for AI interacting with people, synthetic content marking and deepfake disclosure apply (Art. 50)

EU AI Act (Regulation (EU) 2024/1689)

ProviderDeployerLimitedAll
Detail and source

Chatbots must disclose they are machines; synthetic audio, image, video and text must be machine-readably marked; deepfakes and AI-generated public-interest text must be labelled. Also the date the Act's penalties regime and Member State sandboxes become operational.

Reach: Providers and deployers placing AI on the EU market or whose output is used in the EU, wherever established

Penalty: Up to EUR 15 000 000 or 3% of worldwide annual turnover (Art. 99(4))

It shall apply from 2 August 2026.

Already in force — kept as the anchor the later deadlines are measured from.

Regulation (EU) 2024/1689 — Article 113, Article 50 · verified Aug 30, 2026

Jul 15, 2026
47 days ago

China (People's Republic of China) · Law applies

Anthropomorphic (companion/emotional) AI interaction service providers must comply in full: AI-disclosure and content labelling, 2-hour continuous-use reminders, minors protections, security assessment filed with the provincial cyberspace administration, and algorithm filing

人工智能拟人化互动服务管理暂行办法 — Interim Measures for the Administration of Anthropomorphic AI Interaction Services (CAC/NDRC/MIIT/MPS/SAMR Order No. 21, promulgated 10 April 2026)

Provider (拟人化互动服务提供者) — service provider offering anthropomorphic AI interaction services to the public within the PRCAI companionship / emotional-support chatbotsVirtual partner and virtual companion appsConsumer-facing generative AI with persistent persona-based emotional interaction
Detail and source

China's first national-level rules aimed specifically at AI companionship/emotional-interaction services. From this date providers must: (Art. 18) discharge the AI-generated-synthetic-content labelling duty and take effective measures to alert users that they are interacting with an AI service and not a natural person, and remind users of elapsed time by dialogue or pop-up every time continuous use exceeds 2 hours; (Art. 14) NOT provide virtual-kin, virtual-partner or other virtual intimate-relationship services to minors at all, and obtain parent/guardian consent before providing other anthropomorphic interaction services to under-14s; (Art. 22) carry out a security assessment and submit the assessment report to the provincial cyberspace administration before launching such a service or adding anthropomorphic-interaction functionality; (Art. 26) complete algorithm filing, and filing changes/cancellations, under the Internet Information Service Algorithmic Recommendation Management Provisions.

Reach: Mainland China — services provided to the public within the territory of the People's Republic of China (境内公众). Extraterritorial by effect: an offshore provider serving PRC users is in scope.

Penalty: Art. 30: handling/punishment by the cyberspace, development-and-reform, industry-and-information-technology and public-security departments under applicable laws and administrative regulations; where no law or regulation provides, those departments may issue a warning, circulate criticism, order correction within a time limit, and may require measures such as suspending new user account registration or other related services. For refusal to correct or serious circumstances: order to stop providing the relevant service, plus a fine of RMB 10,000–100,000; where citizens' life and health safety are endangered with harmful consequences, a fine of RMB 100,000–200,000.

第三十二条 本办法自2026年7月15日起施行。

BOTH DATES VERIFIED AGAINST PRIMARY CAC SOURCES on 2026-08-30. Promulgated 2026-04-10 as Order No. 21 (第21号) JOINTLY by FIVE departments: 国家互联网信息办公室 (Cyberspace Administration of China), 国家发展和改革委员会 (NDRC), 工业和信息化部 (MIIT), 公安部 (Ministry of Public Security), 国家市场监督管理总局 (SAMR). Effective 2026-07-15 per Art. 32. THE DATE HAS ALREADY PASSED as of 2026-08-30 — this is a live in-force obligation, not an upcoming one. Scope carve-out worth flagging to readers: Art. 2 EXPRESSLY EXCLUDES 智能客服 (intelligent customer service), 知识问答 (knowledge Q&A), 工作助手 (work assistants), 学习教育 (learning/education) and 科学研究 (scientific research) — this is not a general chatbot rule, it bites only on persistent emotional/companionship interaction. Draft consultation version was published 2025-12-07 (cac.gov.cn/2025-12/27/c_1768571207311996.htm is the consultation notice); the final text is the operative one. Title note: the instrument is 拟人化互动 (anthropomorphic interaction); some English commentary renders it 'humanlike/anthropomorphic AI interaction services'.

人工智能拟人化互动服务管理暂行办法 — full official text, Cyberspace Administration of China (cac.gov.cn), Order No. 21 · verified Aug 30, 2026

Jun 29, 2026
63 days ago

Singapore · Enforcement

Online Safety Commission starts operating and the statutory torts / directions regime commences for the first five harms — intimate image abuse, image-based child abuse, doxxing, online harassment (including online sexual harassment) and online stalking. AI-generated material is expressly inside the first two: an 'intimate image or recording' and a 'child abuse image or recording' include images or recordings 'altered or generated by any means'. Communicators of harmful content, online administrators, online platforms, internet access service providers and app distribution services must comply with Commission directions (takedown, account restriction, right of reply, access disabling).

Online Safety (Relief and Accountability) Act 2025 (Bill 18/2025, passed 5 November 2025) — partial commencement; Online Safety Commission begins operations

PlatformOnline-administratorInternet-access-service-providerApp-distribution-serviceIndividualOnline-platformsSocial-mediaMessagingApp-stores
Detail and source

The Act creates 13 categories of online harm; only these five commence on this date, and the remaining eight — including 'inauthentic material abuse' (deepfakes) — are to be implemented progressively with NO date announced. Mr Francis Ng was appointed Commissioner-Designate of Online Safety from 1 June 2026 to 28 June 2026 and became Commissioner on 29 June 2026.

Who: all

Reach: Singapore

Penalty: Statutory torts giving victims civil claims; offences for non-compliance with Online Safety Commission directions

From 29 June 2026, Singaporeans will have stronger protection and faster avenues for relief against online harms. … Intimate image abuse; Image-based child abuse; Doxxing; Online harassment (including online sexual harassment); and Online stalking. … The remaining categories will be progressively implemented.

Verified 2026-08-30. The commencement date comes from the joint MinLaw/MDDI announcement (both ministries' own pages carry it); the AI wording comes from the Bill as published in the Government Gazette Bills Supplement (18.pdf), downloaded and text-extracted. The deepfake-specific harm — 'inauthentic material abuse' (Clause 16), defined as material 'altered or generated using digital means' with Explanation 2 stating 'The technology known as generative artificial intelligence is an example of digital means by which content could be altered or generated', and expressly covering 'deepfakes' — is NOT in this tranche and has no announced date; see the Singapore watchlist row.

Ministry of Law / Ministry of Digital Development and Information — Online Safety Commission and Online Safety (Relief and Accountability) Act 2025 to Start on 29 June 2026 · verified Aug 30, 2026

Jun 29, 2026
63 days ago

United Kingdom · Compliance

Sexual deepfake offences become 'priority offences' under the Online Safety Act, extending Part 3 illegal-content duties of user-to-user and search services to AI-generated intimate images

Crime and Policing Act 2026, Schedule 13 paragraph 24 (amendment of Schedule 7 to the Online Safety Act 2023), commenced by SI 2026/689 reg. 2(1)(z9)

Providers of user-to-user servicesProviders of search servicesSocial mediaSearchContent hostingAI image apps with sharing features
Detail and source

Paragraph 24 of Schedule 13 adds to paragraph 28A of Schedule 7 to the Online Safety Act 2023 the offences in s.66E (creating purported intimate image of adult) and s.66F (requesting the creation of purported intimate image of adult) of the Sexual Offences Act 2003. Listing an offence in Schedule 7 makes the related content 'priority illegal content', so Part 3 providers must take proportionate proactive measures to prevent users encountering it and to minimise the time it is present, and must reflect it in their illegal content risk assessments.

Who: all Part 3 services in scope of the Online Safety Act 2023

Reach: United Kingdom (Online Safety Act 2023 extraterritorial scope: services with links to the UK)

Penalty: Ofcom enforcement under the Online Safety Act 2023: fines up to the greater of GBP 18 million or 10% of qualifying worldwide revenue, business disruption measures, and senior manager liability for named offences

In Schedule 7 to the Online Safety Act 2023 (priority offences), in paragraph 28A (Sexual Offences Act 2003), at the end insert— "(c) section 66E (creating purported intimate image of adult); (d) section 66F (requesting the creation of purported intimate image of adult)."

Commencement date is stated in SI 2026/689 reg 2(1): 'the following provisions of the 2026 Act come into force on 29th June 2026' with (z9) 'Schedule 13, paragraph 24 (priority offences under the Online Safety Act 2023)'. Recent milestone. Ofcom has separately confirmed that one-to-one chatbot output outside user-to-user sharing sits outside Part 3, so the practical reach is content shared on in-scope services.

Crime and Policing Act 2026, Schedule 13, paragraph 24 (with commencement note citing S.I. 2026/689, reg. 2(1)(z9)) · verified Aug 30, 2026

Jun 29, 2026
63 days ago

United Kingdom · Enforcement

Offences of making, adapting, possessing, supplying or offering to supply a tool for creating purported (deepfake) intimate images take effect

Crime and Policing Act 2026, s.99 (purported intimate image generators), commenced by SI 2026/689 (Commencement No.1 and Saving Provision) Regulations 2026

Developers of image-generation modelsOperators of nudification servicesApp stores and hostsIndividualsConsumer AI appsModel hostingAdult content
Detail and source

Section 99 inserts new sections 66I-66L into the Sexual Offences Act 2003, criminalising making or adapting 'a thing for creating, or facilitating the creation of, purported intimate images of a person' and possessing, supplying or offering to supply such a generator. 'Thing' is defined to include 'a program, information in electronic form and a service', which captures nudification apps, image-generation models and hosted services. This targets the supply side of sexual deepfakes, complementing the s.138 DUAA creation offence.

Who: all

Reach: England and Wales

Penalty: Criminal offence under the Sexual Offences Act 2003 as amended; see the new ss.66I-66L for the applicable penalties

Subject to paragraph (2), the following provisions of the 2026 Act come into force on 29th June 2026— ... (i) section 99 (purported intimate image generators);

Recent milestone (29 June 2026). The legislation.gov.uk commencement note on s.99 reads 'S. 99 in force at 29.6.2026 by S.I. 2026/689, reg. 2(1)(i)'. Sibling provision s.72 (child sexual abuse image-generators, new SOA 2003 s.46A - 'thing' includes 'a program, information in electronic form and a service') is NOT yet in force: the legislation.gov.uk note still reads 'S. 72 not in force at Royal Assent, see s. 255(1)' and it was not in the Commencement No.1 list - so it has no date and is not a calendar row yet.

The Crime and Policing Act 2026 (Commencement No.1 and Saving Provision) Regulations 2026, SI 2026/689 (C. 58), regulation 2(1) · verified Aug 30, 2026

Jun 24, 2026
68 days ago

Canada — federal · Compliance

Legacy automated decision systems must be brought into compliance with the new/updated Directive requirements

Treasury Board Directive on Automated Decision-Making (issued under the Policy on Service and Digital; amendments dated 2025-06-24)

DeployerOperatorPublic sector — federal government of Canada
Detail and source

Federal departments operating automated decision systems that were developed or procured BEFORE 2025-06-24 had a transition window to meet the requirements added in the 2025 amendment round — Algorithmic Impact Assessment completion and publication on the Open Government Portal, the Appendix C measures for the assigned impact level (notice, explanation, human-in-the-loop, peer review, monitoring, employee training, IT/business continuity), and access-to-components rights for audit. Systems developed or procured after 2020-04-01 were already bound; s.1.2.1 is the catch-up date for the pre-existing estate.

Who: all federal departments listed in Schedules I, I.1 and II of the Financial Administration Act, per the Policy on Service and Digital scope

Reach: Government of Canada federal institutions (does not bind the private sector or the provinces)

Penalty: No monetary penalty. Non-compliance is handled administratively under the Treasury Board Framework for the Management of Compliance — deputy heads must respond to non-compliance; consequences can include removal of delegated authority and requiring the system be taken out of production. Section 8.3.5 requires approval to operate for level 4 (highest impact) systems.

1.2.1 Existing automated decision systems developed or procured prior to June 24, 2025, will have until June 24, 2026 to comply with the new or updated requirements.

Date has already passed as of 2026-08-30 — this is a live in-force obligation, not an upcoming one. Retrieved by curl; the TBS site returns HTTP 403 to some automated fetchers. Original baseline dates in s.1.1 are 2019-04-01 (takes effect) and 2020-04-01 (first compliance) — too old for the calendar. s.1.3 says the directive 'will be reviewed every two years, and as determined by the Chief Information Officer of Canada' — NO specific next-review date is stated, so no review row is created; do not compute one from the 2025 amendment date.

Directive on Automated Decision-Making — Treasury Board of Canada Secretariat (official policy instrument page, Date modified 2025-06-24) · verified Aug 30, 2026

Jun 24, 2026
68 days ago

Canada — federal · Compliance

Agents of Parliament must comply with the Directive's requirements

Treasury Board Directive on Automated Decision-Making, s.1.2.2

DeployerOperatorPublic sector — Agents of Parliament
Detail and source

Separate transition date extending the Directive to Agents of Parliament (e.g. Office of the Auditor General, Office of the Privacy Commissioner, Office of the Commissioner of Official Languages, Chief Electoral Officer). Their heads are solely responsible for monitoring and enforcing compliance internally (s.8.3.2) and for approving level 4 systems to operate (s.8.3.5).

Who: all Agents of Parliament

Reach: Canada — federal Agents of Parliament

Penalty: No monetary penalty. Heads of Agents of Parliament are 'solely responsible for monitoring and ensuring compliance with this directive within their organizations, as well as for responding to cases of non-compliance' (s.8.3.2).

1.2.2 Agents of Parliament will have until June 24, 2026, to comply with the requirements.

Date already passed as of 2026-08-30. Same date as s.1.2.1 but a distinct duty on a distinct population, hence a separate row.

Directive on Automated Decision-Making — Treasury Board of Canada Secretariat · verified Aug 30, 2026

Jun 1, 2026
91 days ago

Malaysia · Compliance

Licensed service providers must label synthetic media: generated or manipulated images, audio or video that closely resemble real persons, objects, places, entities or events and are likely to falsely appear authentic must be clearly distinguishable through prominent labels or markings on the service's online interface (para. 4.2.4(d), 'Safe Design of the Service'). The same Code also requires providers to test and adapt algorithmic and recommender systems against exposure to harmful content (para. 4.2.4(c)) and to run a documented harmful-content risk assessment reviewed at least annually.

Risk Mitigation Code issued by the Malaysian Communications and Multimedia Commission (MCMC) under s.80 of the Online Safety Act 2025 [Act 866]

PlatformApplications-service-providerContent-applications-service-providerOnline-platformsSocial-mediaMessaging
Detail and source

The Code specifies the measures licensed service providers must implement to discharge their duty under s.13 of the ONSA 2025. It binds providers of applications services enabling communication between users, and of content applications services, that use internet access service. Where synthetic content is to be identified through user or advertiser disclosures/reports, the provider must supply accessible functionality and guidance for those disclosures. Providers may substitute alternative measures only if they satisfy the Commission that these better mitigate risk (s.13(2) ONSA).

Who: licensed service providers (MCMC has applied the ONSA regime to platforms with more than 8 million Malaysian users)

Reach: Malaysia

Penalty: Enforcement under the Online Safety Act 2025 including financial penalties reported up to RM10 million for non-compliance with duties under the Act

Date of Publication: 22 May 2026 / Date of Enforcement: 1 June 2026 (cover page of the Code, MCMC).

Verified 2026-08-30 by downloading the Code PDF from MCMC's own ONSA portal and extracting its text: the cover page carries the enforcement date verbatim. HONEST CAVEAT: the Code's operative wording says 'generated or manipulated', not 'artificial intelligence' — it is a synthetic-media labelling duty, which is why it is classed ai_specific on the synthetic-content limb rather than by an explicit 'AI' word. MCMC issued a companion Child Protection Code on the same dates (22 May 2026 publication, 1 June 2026 enforcement) which I did not find to carry a synthetic-media clause. Malaysia's separate cross-sector AI Governance Bill is still in consultation — see the Malaysia watchlist row.

MCMC — Online Safety Act 2025: Risk Mitigation Code · verified Aug 30, 2026

May 15, 2026
108 days ago

United Kingdom · Registration

The permit regime for automated passenger services goes live: self-driving taxi, private-hire and bus-like services must operate under a permit granted by the appropriate national authority

Automated Vehicles Act 2024, Part 5 (permits for automated passenger services), commenced by SI 2026/437 (Commencement No. 2) Regulations 2026, together with the Automated Vehicles (Permits for Automated Passenger Services) Regulations 2026 (SI 2026/439)

Automated passenger service operatorsSelf-driving taxi and PHV operatorsBus-like autonomous shuttle operatorsNo-user-in-charge operatorsRoad transportMobility
Detail and source

SI 2026/437 commenced the whole of Part 5 of the Automated Vehicles Act 2024 on 15 May 2026, except s.84 (civil sanctions for infringements of the permit scheme) and s.89(8)(b) and (10). Section 82 empowers the appropriate national authority to grant permits for 'automated passenger services' - the carrying of passengers in a road vehicle 'designed or adapted to travel autonomously' or used in a trial to develop such vehicles - and the permit must specify areas, vehicles, validity period and conditions. The procedural regime (applications, notices, review) is in SI 2026/439, which came into force the same day. Section 83 disapplies taxi, private hire vehicle and bus legislation for services covered by a permit.

Who: all

Reach: England, Wales and Scotland for bus-like public service vehicle services; England only for other automated passenger services (per SI 2026/439 reg. 1(3))

Penalty: Permit conditions are binding on the permit holder; note that s.84 (civil sanctions for infringements of the permit scheme) is expressly NOT yet commenced

The following provisions of the Automated Vehicles Act 2024, so far as not already in force, come into force on 15th May 2026— (a) Part 5 (permits for automated passenger services), except— (i) section 84 (civil sanctions for infringements of the permit scheme), and (ii) section 89(8)(b) and (10) (procedural and administrative matters); (b) section 93 (provision of information about traffic regulation measures).

Recent milestone (15 May 2026). SI 2026/439 reg. 1(1) verbatim: 'These Regulations may be cited as the Automated Vehicles (Permits for Automated Passenger Services) Regulations 2026 and come into force on 15th May 2026.' Two carve-outs remain uncommenced with NO appointed date: s.84 civil sanctions and s.89(8)(b)/(10). The core Part 1 self-driving vehicle AUTHORISATION regime (ss.1-54) is still not commenced and no commencement date has been appointed for it - DfT has publicly referred only to the 'second half of 2027', which is not a stated date and is therefore not a calendar row.

The Automated Vehicles Act 2024 (Commencement No. 2) Regulations 2026, SI 2026/437, regulation 2 · verified Aug 30, 2026

May 12, 2026
111 days ago

United Kingdom · Compliance

Statutory duty on the Information Commissioner to prepare a code of practice on processing personal data for developing and using AI and for automated decision-making takes effect

The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026, SI 2026/425

Information Commissioner (duty holder)Data controllers developing or using AIDeployers of automated decision-makingAll
Detail and source

Regulation 2 provides: 'The Commissioner must prepare an appropriate code of practice giving guidance as to good practice in the processing of personal data under the relevant data protection legislation in relation to (a) developing and using artificial intelligence, and (b) automated decision-making.' This is the secondary legislation the Government committed to during passage of the Data (Use and Access) Act 2025. Once issued under the Data Protection Act 2018 procedure, the code is a statutory code: the Commissioner must take it into account when exercising regulatory functions and it is admissible in evidence in legal proceedings, so it will in practice bind controllers developing or deploying AI.

Who: all

Reach: England and Wales, Scotland and Northern Ireland

Penalty: None directly; the resulting statutory code will be taken into account by the ICO in enforcement and is admissible in evidence in court and tribunal proceedings

Made 16th April 2026 / Laid before Parliament 21st April 2026 / Coming into force 12th May 2026

Recent milestone (12 May 2026). IMPORTANT: the Regulations set NO deadline by which the Commissioner must prepare, consult on or issue the code - so the publication date of the AI/ADM code itself is a watchlist item, not a calendar date. The ICO has said it is starting work on the code and will publish timings through its codes of practice pipeline, and that draft ADM and profiling guidance will be consulted on first.

The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026, SI 2026/425 · verified Aug 30, 2026

May 1, 2026
122 days ago

Vietnam · Compliance

Operative implementing rules for the AI Law take effect: risk classification of AI systems into high/medium/low, conformity assessment for high-risk AI systems, accountability/transparency and incident-handling duties, registration on the one-stop AI portal and the national AI systems database, and the regulatory sandbox

Decree No. 142/2026/ND-CP of 30 April 2026 detailing articles and implementation measures of the Law on Artificial Intelligence (Nghị định 142/2026/NĐ-CP)

DeveloperProviderDeployerUserCross-sector
Detail and source

8 chapters, 46 articles plus forms. Applies to AI system providers, developers, deployers and users, and to Vietnamese and foreign bodies, organisations and individuals engaged in AI activity in Vietnam. Providers of medium- and high-risk AI systems must notify their risk classification before putting the system into use. Serious-incident reporting: preliminary report within 72 hours (emergency) or 5 working days (other serious incidents), final report within 15 days of the preliminary report.

Who: all

Reach: Vietnam; Vietnamese and foreign organisations and individuals participating in AI activities in Vietnam

Penalty: Administrative measures under the AI Law; suspension/termination powers for systems posing serious risk

Ngày ban hành: 30-04-2026; Ngày có hiệu lực: 01-05-2026; Người ký: Hồ Quốc Dũng. // 'Date issued: 30 April 2026; Effective date: 1 May 2026; Signed by: Hồ Quốc Dũng.' Signed text: https://datafiles.chinhphu.vn/cpp/files/vbpq/2026/4/142-2026-ndcp.signed.pdf

Effective date and signer taken from the Government's own document portal; the Ministry of Justice legal-dissemination portal independently states 'Nghị định có hiệu lực từ ngày 01/5/2026'. Verified 2026-08-30.

Cổng thông tin văn bản Chính phủ — Nghị định số 142/2026/NĐ-CP của Chính phủ: Quy định chi tiết một số điều và biện pháp thi hành Luật Trí tuệ nhân tạo · verified Aug 30, 2026

May 1, 2026
122 days ago

Vietnam · Compliance

Synthetic-content marking and labelling duty: PROVIDERS must apply technical solutions so that audio, image and video outputs are marked in a machine-readable format; DEPLOYERS must give clear notice and an easily recognisable label when releasing to the public content generated or edited by AI that could mislead as to the authenticity of an event, a person or the origin of the content

Decree No. 142/2026/ND-CP, Article 18 — notification of AI interaction and labelling of AI-generated content (read with the Law on Artificial Intelligence No. 134/2025/QH15)

ProviderDeployerCross-sectorMediaOnline-platformsAdvertising
Detail and source

Split duty between nhà cung cấp (provider) and bên triển khai (deployer). Machine-readable marking at the provider layer plus human-visible labelling at the distribution layer — the same two-layer design as the EU AI Act Art. 50. The Ministry of Science and Technology publishes and updates reference technical guidance on the form of the notification and of the displayed label.

Who: all

Reach: Vietnam; Vietnamese and foreign organisations and individuals engaged in AI activity in Vietnam

Penalty: Administrative liability under the Law on AI and its implementing decree; suspension/termination powers for systems posing serious risk

Nghị định có hiệu lực từ ngày 01/5/2026. … nhà cung cấp phải áp dụng giải pháp kỹ thuật để nội dung đầu ra là âm thanh, hình ảnh, video được đánh dấu ở định dạng máy đọc; bên triển khai phải thông báo rõ ràng, gắn nhãn dễ nhận biết khi cung cấp ra công chúng nội dung do AI tạo ra hoặc chỉnh sửa … có khả năng gây nhầm lẫn về tính xác thực của sự kiện, nhân vật hoặc nguồn gốc nội dung. // 'The Decree takes effect from 1 May 2026. … the provider must apply technical solutions so that output audio, image and video content is marked in a machine-readable format; the deployer must give clear notice and an easily recognisable label when providing to the public content generated or edited by AI … that is liable to cause confusion as to the authenticity of an event, a person or the origin of the content.'

Recorded separately from the general Decree 142/2026 commencement row because this is the operative synthetic-media labelling duty a compliance calendar needs named. Same date (1 May 2026) as the Decree's commencement. Verified 2026-08-30 against the Ministry of Justice legal-dissemination portal; effective date cross-checked on the Government document portal (vanban.chinhphu.vn: 'Ngày có hiệu lực: 01-05-2026'). The signed text is at https://datafiles.chinhphu.vn/cpp/files/vbpq/2026/4/142-2026-ndcp.signed.pdf but is a scanned image PDF with no text layer, so article wording is quoted from the Ministry of Justice summary.

Bộ Tư pháp (Ministry of Justice) — Giới thiệu Nghị định số 142/2026/NĐ-CP quy định chi tiết một số điều và biện pháp thi hành Luật Trí tuệ nhân tạo · verified Aug 30, 2026

Mar 11, 2026
173 days ago

United States — federal · Regulator milestone

Commerce identifies state AI laws for challenge by the DOJ AI Litigation Task Force; BEAD funding eligibility tied to state AI rules

Executive Order, Ensuring a National Policy Framework for Artificial Intelligence (11 Dec 2025)

State governmentAll
Detail and source

Not a business compliance duty but the reason several state deadlines below moved. The Task Force challenges state AI laws deemed inconsistent with federal policy; states with targeted rules risk losing BEAD broadband funds.

Sec. 4. Evaluation of State AI Laws. Within 90 days of the date of this order, the Secretary of Commerce, consistent with the Secretary's authorities under 47 U.S.C. 902(b), shall, in consultation with the Special Advisor for AI and Crypto, the Assistant to the President for Economic Policy, the Assistant to the President for Science and Technology, and the Assistant to the President and Counsel to the President, publish an evaluation of existing State AI laws that identifies onerous laws that conflict with the policy set forth in section 2 of this order, as well as laws that should be referred to the Task Force established pursuant to section 3 of this order.

Imposes no dated duty on any business: every operative section runs to government actors (AG, Commerce, agencies, FCC, FTC). The order itself says only 'within 90 days of the date of this order' — 11 March 2026 is arithmetic, not a quoted date. Kept as context for the preemption risk hanging over the US state rows.

Executive Order on eliminating state-law obstruction of national AI policy · verified Aug 30, 2026

Mar 1, 2026
183 days ago

Vietnam · Compliance

Vietnam's dedicated AI Law enters into force: risk-tiered duties on developers, providers and deployers of AI systems (risk classification, data/testing/monitoring and human-oversight requirements for high-risk uses in finance, health, justice, labour and education; transparency and marking of AI-generated content)

Law on Artificial Intelligence No. 134/2025/QH15 (Luật Trí tuệ nhân tạo)

DeveloperProviderDeployerUserFinanceHealthJusticeLabour
Detail and source

Passed by the 15th National Assembly at its 10th session on 10 December 2025 by 429/434 deputies (90.70%). 8 chapters, 35 articles. First comprehensive Vietnamese statute governing research, development, provision, deployment and use of AI systems. Technical detail is delegated to implementing decrees (see Decree 142/2026/ND-CP).

Who: all

Reach: Vietnam; activities of research, development, provision, deployment and use of AI systems in Vietnam

Penalty: Administrative and criminal liability under general Vietnamese law; detail delegated to implementing decrees

Luật Trí tuệ nhân tạo chính thức có hiệu lực từ hôm nay, ngày 01/3/2026. // 'The Law on Artificial Intelligence officially takes effect from today, 1 March 2026.' Also: 'Ngày 10/12/2025, Quốc hội biểu quyết thông qua Luật Trí tuệ nhân tạo' ('On 10 December 2025 the National Assembly voted to pass the Law on Artificial Intelligence').

Verified 2026-08-30 against the Ministry of Science and Technology (MST) portal, the responsible ministry. Law number 134/2025/QH15 confirmed by the Government Gazette (Công báo) record. Date is in the past relative to 2026-08-30 — row is 'in force', useful as the anchor entry for Vietnam. Still to check: transitional provisions (Điều khoản chuyển tiếp) that may set a later compliance date for AI systems already in operation.

Bộ Khoa học và Công nghệ — Luật Trí tuệ nhân tạo chính thức có hiệu lực từ 1/3 · verified Aug 30, 2026

Feb 20, 2026
192 days ago

India · Compliance

Intermediaries must label and trace synthetically generated content

Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026

IntermediaryPlatformOnline platforms
Detail and source

Gazette notification G.S.R. 120(E) dated 10 February 2026, in force 20 February 2026. The synthetically generated information definition covers audio and visual content — text is excluded — and the draft's 10% surface-area watermark rule did not survive into the notified version.

Gazette of India, Extraordinary, Part II Section 3(i), notification G.S.R. 120(E) dated 10 February 2026 (gazette doc id CG-DL-E-10022026-269993); the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 come into force on 20 February 2026. Rule 2(1)(wa) definition, verbatim: 'audio, visual or audio-visual information which is artificially or algorithmically created, generated, modified or altered using a computer resource, in a manner that such information appears to be real, authentic or true and depicts or portrays any individual or event in a manner that is, or is likely to be perceived as indistinguishable from a natural person or real-world event.' Labelling standard as notified: the label must be 'clearly and prominently' displayed - a visible label on visual content and an audio disclosure on audio content, 'prominent and clearly noticeable'. Provenance duty: intermediaries must 'embed permanent metadata or unique identifiers to trace the computer resource used to generate or alter the content'. SSMI duty: obtain a user declaration whether content is SGI and 'deploy appropriate technical measures, including automated tools, to verify whether the declaration is accurate'.

meity.gov.in sits behind a WAF that returns 403 to automated fetches, so the wording was reconstructed from several independent readings — worth one human eyeball before publication.

IT Amendment Rules 2026, Ministry of Electronics and Information Technology · verified Aug 30, 2026

Feb 6, 2026
206 days ago

United Kingdom · Enforcement

New criminal offences of creating, or requesting the creation of, a purported (deepfake) intimate image of an adult without consent come into force

Data (Use and Access) Act 2025, s.138 (creating, or requesting the creation of, purported intimate image of adult), commenced by SI 2026/31 (Commencement No. 5) Regulations 2026

IndividualsOperators of nudification and image-generation toolsPlatforms hosting such toolsConsumer AI appsSocial mediaAdult content
Detail and source

Section 138 DUAA inserts new sections 66E-66H into the Sexual Offences Act 2003. A 'purported intimate image' is an image made or altered so that it appears to be a photograph or film of another person in an intimate state - i.e. AI-generated or digitally altered 'nudification' and sexual deepfakes. It is an offence to create such an image of an adult without consent and without reasonable belief in consent, and separately to request its creation. Defences of reasonable excuse apply; courts get deprivation-order powers over the images and equipment.

Who: all

Reach: England and Wales (with corresponding service offence provision under the Armed Forces Act 2006)

Penalty: Criminal offence: on summary conviction, imprisonment up to the maximum term for summary offences and/or a fine; deprivation orders in respect of the image and equipment used

Section 138 of the Data (Use and Access) Act 2025 (creating, or requesting the creation of, purported intimate image of adult) comes into force on 6th February 2026.

Date already passed (in force 6 Feb 2026) - recent milestone. SI 2026/31 was made 15 January 2026 and commences only this section. Directly relevant to nudification and image-generation tools.

The Data (Use and Access) Act 2025 (Commencement No. 5) Regulations 2026, SI 2026/31 · verified Aug 30, 2026

Feb 5, 2026
207 days ago

United Kingdom · Compliance

New UK GDPR Articles 22A-22D automated decision-making regime takes effect: controllers taking significant solely-automated decisions must have safeguards in place

Data (Use and Access) Act 2025, s.80 and Schedule 6 (automated decision-making), commenced by SI 2026/82 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026

Data controllersData processorsDeployers of automated decision systemsAll
Detail and source

Section 80 DUAA replaces UK GDPR Article 22 with Articles 22A-22D. A decision is 'based solely on automated processing' if there is no meaningful human involvement; where a significant decision is taken about a data subject based solely on automated processing, the controller must ensure safeguards consisting of or including measures to provide information about the decision, enable representations, enable human intervention and enable the decision to be contested. Commencement Regulation 5 of SI 2026/82 saves the old Article 22(3) regime for decisions taken before 5 February 2026, so the new duties bite on decisions taken from that date.

Who: all

Reach: United Kingdom (UK GDPR / Data Protection Act 2018 territorial scope, including controllers outside the UK targeting UK data subjects)

Penalty: UK GDPR / DPA 2018 enforcement: penalty notices up to the higher maximum (GBP 17.5m or 4% of total annual worldwide turnover), plus enforcement notices and data subject compensation claims

The following provisions of the 2025 Act, so far as not already in force, come into force on 5th February 2026— ... (j) section 80 (automated decision-making); ... (z8) Schedule 6 (automated decision-making: minor and consequential amendments).

Date already passed (in force since 5 Feb 2026) - include as a recent milestone. Regulation 5 of the same SI is the transitional saving that fixes 5 February 2026 as the cut-off. Regulation 3 of SI 2026/82 commences s.103 and Sch.10 on 19 June 2026, but those are not AI-related.

The Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026, SI 2026/82, regulation 2 · verified Aug 30, 2026

Jan 14, 2026
229 days ago

Taiwan · Compliance

Taiwan's AI Basic Act enters into force on promulgation: 20 articles establishing the 7 governing principles, a duty that high-risk AI applications be labelled (Art. 5), MODA-led AI risk-classification framework and sectoral management rules with power to restrict or prohibit unlawful applications (Art. 16), and allocation of liability plus a redress/compensation mechanism for high-risk AI applications (Art. 17)

Artificial Intelligence Basic Act (人工智慧基本法), promulgated by Presidential Order 華總一義字第11500001671號 of 14 January 2026

DeveloperProviderDeployerGovernmentCross-sector
Detail and source

Passed by the Legislative Yuan at third reading on 23 December 2025 (民國114年12月23日); promulgated and brought into force 14 January 2026. Central competent authority: National Science and Technology Council (國科會); local: municipal and county governments. Art. 18 requires government to complete adaptation of laws and administrative measures within two years of commencement (a PERIOD, not a stated date — not recorded as a separate row). Art. 6 requires the Executive Yuan to establish a National AI Strategy Special Committee and adopt a National AI Development Programme.

Who: all

Reach: Taiwan

Penalty: No penal provisions in the Act itself. Enforcement runs through sectoral competent authorities: under Art. 16, where an application breaches Art. 5 it 'shall be restricted or prohibited in accordance with laws and regulations' (有第5條違法情事者,應依法令限制或禁止).

公布日期:民國 115 年 01 月 14 日 … 第二十條「本法自公布之日起施行。」 // 'Promulgation date: 14 January 2026 (ROC year 115) … Article 20: This Act shall come into force from the date of promulgation.'

Verified 2026-08-30 against the national laws database (law.moj.gov.tw, pcode H0160093), the MODA press release on the third reading, and the NSTC's own implementation plan filed with the Executive Yuan (ey.gov.tw File 76681FD3D1A41585). Promulgation text also in Presidential Office Gazette No. 7837 of 14 January 2026 (president.gov.tw/File/Doc/80165b6d-cb49-4b49-952f-56e1e6abe51b). The Act carries NO penalties of its own — the calendar row is the commencement of a framework statute with an operative labelling duty, not a sanction-backed deadline. Legislative supplementary resolutions set 3-month / 6-month / 1-year tasks for GOVERNMENT bodies (gender, human-rights and child-impact assessments; agency AI risk assessments and internal control rules; MOE AI-use guidance) — all expressed as periods, all internal to government, so no derived dates recorded.

全國法規資料庫 — 人工智慧基本法 · verified Aug 30, 2026

Jan 6, 2026
237 days ago

Qatar — Qatar Financial Centre (QICDRC courts) · Compliance

Litigants and legal representatives before the QFC Court and the Regulatory Tribunal must verify the accuracy of AI-assisted submissions, identify AI-assisted portions when required, and must not input confidential, privileged or legally protected information into publicly available AI tools

QICDRC Practice Direction No. 1 of 2026, with accompanying Practice Guidance on the use of artificial intelligence in court proceedings

LitigantsLegal representativesCounselLitigation and dispute resolution before the QFC Court and Regulatory Tribunal
Detail and source

Issued by the Qatar International Court and Dispute Resolution Centre following the judgment in Jonathan David Sheppard v Jillion LLC [2025] QIC (E) 3. Sets a framework for the responsible, transparent and disciplined use of AI tools in proceedings. Legal representatives remain responsible for the accuracy of all material submitted regardless of whether AI was used; where the Court requires it, they must identify AI-assisted portions and explain the steps taken to verify accuracy and ensure compliance with professional and ethical standards. Advance disclosure of AI use is not automatically mandatory unless the Court requires it.

Who: all

Reach: Proceedings before the Qatar International Court (QFC Court) and the Regulatory Tribunal within the Qatar Financial Centre

Penalty: Court sanctions in proceedings — exclusion of AI-generated evidence, adverse costs and professional/ethical consequences for legal representatives; no separate monetary penalty schedule

The Qatar International Court and Dispute Resolution Centre (QICDRC) has issued Practice Direction No. 1 of 2026, together with accompanying Practice Guidance on the use of artificial intelligence in court proceedings, setting out a comprehensive framework governing the responsible, transparent, and disciplined use of AI tools before the QFC Court and the Regulatory Tribunal.

Date 06 January 2026 is the date line and issuance date shown on the QICDRC's own media-centre page. The Practice Direction does not state a separate deferred effective date — it applies from issuance. NARROW SCOPE: this binds parties and lawyers in QICDRC proceedings, not businesses generally; include only if the calendar carries litigation-practice duties. Library of Congress Global Legal Monitor also covers it (loc.gov returned HTTP 403 to automated fetching, listed as second source from search result metadata).

QICDRC Issues Practice Direction No. 1 of 2026 and Practice Guidance on the Use of Artificial Intelligence in Court Proceedings · verified Aug 30, 2026

Jan 1, 2026
242 days ago

Vietnam · Compliance · Enacted, not yet applicable

First binding Vietnamese AI transparency duties took effect: an AI system interacting directly with a person must tell the user they are interacting with an AI system, and digital products on the Minister's list of AI-generated digital products must carry an identifying mark readable by a person or a machine

Law on Digital Technology Industry No. 71/2025/QH15 (Luật Công nghiệp công nghệ số), Chapter IV — Artificial Intelligence, Art. 44

ProviderDeployerCross-sector
Detail and source

Law passed 14 June 2025, published in Công báo issues 965+966 of 24 July 2025, signed by National Assembly Chairman Trần Thanh Mẫn. 6 chapters, 51 articles; Chapter IV (Arts. 41-45) covered AI. The Minister of Science and Technology was to issue the List of AI-generated digital products and to inspect compliance. SUPERSEDED: Art. 34 of the Law on Artificial Intelligence No. 134/2025/QH15 repeals Chapter IV of Law 71/2025/QH15 (together with Art. 3(9), Art. 4(7), Art. 12(6) and Art. 34(2)(dd)) with effect from 1 March 2026; equivalent transparency and AI-content labelling duties continue under the AI Law.

Who: all

Reach: Vietnam

Penalty: Administrative inspection by the Ministry of Science and Technology; general administrative liability

Ngày ban hành: 14/06/2025; Ngày hiệu lực: 01/01/2026 (Công báo số 965 + 966, ngày 24/7/2025; người ký: Trần Thanh Mẫn). // 'Issued 14 June 2025; effective 1 January 2026.'

IMPORTANT CAVEAT — this row is historical: the duty applied from 1 Jan 2026 but Chapter IV was repealed on 1 Mar 2026 by Art. 34 of Law 134/2025/QH15. Kept because it is the dated moment Vietnam's first binding AI duty began. Gazette page confirms the dates; the official PDF on congbao is a scanned image with no text layer, so Art. 44 wording is quoted from Vietnamese legal-database reproductions cross-checked against MST's own summary ('hệ thống trí tuệ nhân tạo tương tác trực tiếp với con người phải có thông báo để người sử dụng biết'). Verified 2026-08-30.

Công báo Chính phủ — Luật số 71/2025/QH15 luật Công nghiệp công nghệ số · verified Aug 30, 2026

Jan 1, 2026
242 days ago

Canada — Ontario · Compliance

Employers must disclose in a publicly advertised job posting that artificial intelligence is used to screen, assess or select applicants

Employment Standards Act, 2000 (S.O. 2000, c. 41), Part III.1 'Job Postings', s. 8.4 — added by the Working for Workers Four Act, 2024 (S.O. 2024, c. 3), Schedule 2, s. 2(1); supported by O. Reg. 476/24 (Rules and Exemptions re Job Postings)

EmployerDeployerAll sectors — employment / recruitment
Detail and source

s. 8.4(1) is a positive disclosure duty: if AI is used anywhere in screening, assessment or selection for the advertised position, a statement disclosing that use must appear in the posting itself. O. Reg. 476/24 defines 'artificial intelligence' in OECD terms and exempts employers with fewer than 25 employees on the day the posting is posted, general recruitment campaigns and help-wanted signs that do not advertise a specific position, internal-only postings, and postings for work performed outside Ontario. This is the first in-force statutory AI-hiring disclosure duty in Canada.

Who: employers with 25 or more employees on the day the posting is posted (O. Reg. 476/24 s. 1 exempts employers with fewer than 25 employees)

Reach: Ontario — publicly advertised job postings for work performed in Ontario; excludes postings for work performed wholly outside Ontario

Penalty: Enforced under the Employment Standards Act, 2000: employment standards officers may issue compliance orders and notices of contravention carrying prescribed administrative penalties, and contravention of the Act is an offence prosecutable under Part XXV of the ESA.

Use of artificial intelligence — 8.4 (1) Every employer who advertises a publicly advertised job posting and who uses artificial intelligence to screen, assess or select applicants for the position shall include in the posting a statement disclosing the use of the artificial intelligence. 2024, c. 3, Sched. 2, s. 2 (1). [Section Amendments with date in force (d/m/y): 2024, c. 3, Sched. 2, s. 2 (1) - 01/01/2026]

VERIFIED IN FORCE — date has passed (today 2026-08-30). The parent Act did NOT state the date: Working for Workers Four Act, 2024, Schedule 2, s. 10(3) says 'Section 2 and subsection 7 (1) come into force on a day to be named by proclamation of the Lieutenant Governor.' The actual date comes from the proclamation as recorded in the e-Laws consolidation history for s. 8.4: '2024, c. 3, Sched. 2, s. 2 (1) - 01/01/2026'. O. Reg. 476/24 shows 'Consolidation period: January 1, 2026 - e-Laws currency date (August 26, 2026)' with no amendments, confirming the operative version. e-Laws is a JavaScript application — the amendment note is in a collapsed <p class='footnoteLeft amendments'> and was read by rendering the page in a browser; plain curl returns only a 'needs JavaScript' stub.

Employment Standards Act, 2000, S.O. 2000, c. 41 — official Ontario e-Laws consolidation, s. 8.4 with 'Section Amendments with date in force (d/m/y)' · verified Aug 30, 2026

Dec 5, 2025
269 days ago

Canada — Quebec · Law applies

Binding generative-AI measures apply to Quebec public bodies: organizational AI governance structure, risk and compliance review before deployment, data-protection and confidentiality rules, mandatory preference for secure private GenAI systems over public ones, and lifecycle quality/security controls

Indication d'application IA-RI-2025-003-OP — « Mesures applicables lors de l'utilisation de l'intelligence artificielle générative » (formulated by the Dirigeant principal de l'information under LGGRI, chapitre G-1.03, art. 7); complements arrêté ministériel 2025-02 of 3 December 2025 (Énoncé de principes pour une utilisation responsable de l'IA par les organismes publics)

DeployerUserPublic sector — Quebec public bodies (ministries, agencies, health and social services, education, Crown corporations)
Detail and source

An 'indication d'application' is a written instruction with which public bodies MUST comply under the Act respecting the governance and management of the information resources of public bodies and government enterprises (chapter G-1.03). Status field on the instrument reads 'En vigueur'. It applies to the public bodies listed in s.2 of the LGGRI — ministries, government agencies, health and social services bodies, school service centres and Crown corporations. It also repeals the earlier IA-RI-2025-001-OP suspension of generative-AI virtual assistants, and sits alongside standing prohibitions (DeepSeek assistants, Microsoft Teams voice/face enrolment).

Who: all bodies covered by art. 2 LGGRI

Reach: Province of Quebec — public sector only (does not bind private-sector businesses)

Penalty: No monetary penalty in the instrument. Compliance is mandatory under the LGGRI (c. G-1.03); the Dirigeant principal de l'information may under art. 24 exempt a body in whole or in part and set conditions. Enforcement is administrative through the Ministère de la Cybersécurité et du Numérique.

Statut : En vigueur — No de référence : IA-RI-2025-003-OP — Organismes visés : Organismes publics — Référence légale : LGGRI (chapitre G-1.03), art. 7 — Date de formulation : 2025-12-05 — Date d'entrée en vigueur : 2025-12-05

IMPORTANT — the widely repeated '5 juin 2026 compliance deadline' is NOT stated anywhere in the instrument and is NOT recorded here. Art. 23 says only: « Un organisme public peut, à compter de la date d'entrée en vigueur de la présente indication d'application échelonner la mise en œuvre des mesures qui y sont prévues sur une période maximale de six mois suivant cette date. » — i.e. a maximum six-month phase-in from 2025-12-05, with no end date written out. The 2026-06-05 figure circulating in secondary commentary is a computation from that clause; the 28-page official Guide d'application (GU_lignes_dir_IAG_2025.pdf) was checked and contains no 2026 date, no 'six mois' and no 'au plus tard'. Per the no-inferred-dates rule, only the stated 2025-12-05 entry into force is recorded. Related instruments: arrêté 2025-02 (3 December 2025) amending arrêté 2024-02 (27 June 2024); arrêté ministériel 2024-01 on IT-resource requirements for AI. Gazette officielle PDFs at publicationsduquebec.gouv.qc.ca were unreachable from this environment (DNS blocked) — the arrêté dates are quoted from the operative text of IA-RI-2025-003-OP art. 1 and from the Énoncé de principes PDF ('constitue l'annexe prévue à l'Arrêté 2025-02 du 3 décembre 2025').

IA-RI-2025-003-OP — Mesures applicables lors de l'utilisation de l'intelligence artificielle générative (Ministère de la Cybersécurité et du Numérique, Gouvernement du Québec) · verified Aug 30, 2026

Nov 3, 2025
301 days ago

New Zealand · Compliance

Binding code of practice for automated biometric processing comes into force for NEW biometric processing: 13 modified privacy rules including a proportionality assessment before collection (Rule 1 — lawful purpose, necessity, effectiveness and no less privacy-intrusive alternative reasonably available), transparency/notification duties, restrictions on biometric categorisation, retention limits and cross-border safeguards

Biometric Processing Privacy Code 2025, issued by the Privacy Commissioner under the Privacy Act 2020

DeployerProviderCross-sectorRetailSecurityFinancial-services
Detail and source

Applies to organisations that collect biometric information in an AUTOMATED process to verify, identify or categorise people. 'Biometric categorisation' expressly covers inference systems — e.g. using a biometric system to infer someone's emotions from their voice or to estimate their age from their face. Health agencies carrying out biometric processing to deliver health services are outside the Code.

Who: all agencies as defined in the Privacy Act 2020

Reach: New Zealand

Penalty: Breach of a code rule is treated as an interference with privacy under the Privacy Act 2020 — complaints to the Privacy Commissioner, compliance notices, and Human Rights Review Tribunal proceedings with damages. OPC applies its Compliance and Regulatory Action Framework.

The Biometric Processing Privacy Code 2025 (BPPC) was issued on 21 July 2025. … The BPPC came into force on 3 November 2025, but agencies already using biometrics had a nine-month grace period to move to the new set of rules.

Verified 2026-08-30 against the Privacy Commissioner's own Code page and Factsheet 1 (document ref A1104348, downloaded and text-extracted). New Zealand has no AI statute; this Code is its only binding, dated instrument whose operative scope is defined by AUTOMATED processing and inference. Note the OPC page gives the issue date as 21 July 2025 (some law-firm notes say 6 August 2025 — I used the regulator's own date).

Office of the Privacy Commissioner — Biometric Processing Privacy Code 2025 · verified Aug 30, 2026

Sep 19, 2025
346 days ago

Nigeria · Compliance

Data controllers and data processors deploying Artificial Intelligence (and other emerging technologies) to process personal data must set and document technical and organisational parameters, carry out a DPIA, test in low-risk environments, assess disparate outcomes, re-test, and put continuous monitoring in place — with the parameters and DPIA filed with the Commission as part of NDP Act Compliance Audit Returns

Nigeria Data Protection Act (NDP Act) 2023 — General Application and Implementation Directive (GAID) 2025, ref. NDPC/NDP ACT-GAID/01/2025, Article 43 (Emerging Technologies)

Data controllerData processorData controllers and processors of major importanceData Protection OfficerAll sectors processing personal data of data subjects in Nigeria
Detail and source

Article 43(1) applies to any controller/processor who 'deploys or intends to deploy Emerging Technologies (ETs) such as Artificial Intelligence, Internet of Things and Blockchain for the purposes of processing personal data'. Art 43(2) requires parameters that take account of the right not to be subject to a decision solely based on automated processes or algorithms, the right to be forgotten, sensitive-data and child safeguards, cross-border flows, and privacy by design and default. Art 43(3) makes the parameters filable with the Commission as part of the Compliance Audit Return. Art 43(4) requires a DPIA (accounting for disparate outcomes and Data Subjects' Vulnerability Indexes), data anonymisation suitability, low-risk-environment testing, retooling and re-testing until satisfactory or discarding the tool for unmitigable privacy risk, and continuous monitoring once deemed safe. Art 44(3) requires controllers to 'refrain from or cease the use of ET systems that are impossible to operate in compliance with international human rights law'. GAID repealed the NDPR 2019 and the NDPR Implementation Framework 2020.

Who: all; heavier registration and audit duties for Data Controllers/Processors of Major Importance

Reach: Nigeria — applies where the data subject is in Nigeria regardless of the controller's or processor's domiciliation

Penalty: Enforcement under the NDP Act 2023: sanctions up to NGN 10,000,000 or 2% of annual gross revenue in the preceding year for data controllers of major importance (NGN 2,000,000 or 2% for others), plus remediation orders and compensation

Issued under my hand this 20th Day of March, 2025

CONFIDENCE 'likely' AND WHY: the operative AI duty and the AI wording are verified verbatim against the NDPC's own published PDF, and the issue date (20 March 2025) is stated inside the instrument in the signature block of the National Commissioner/CEO Dr Vincent O. Olatunji. HOWEVER the GAID contains NO commencement article and NO clause stating '19 September 2025'. That date is the end of the six-month transition the Commission announced when issuing the GAID, and the instrument does say obligations fall due 'within six (6) months of the issuance of this GAID' (Art. 39 software provision). It is reported consistently as the effective date by DLA Piper, Aluko & Oyebode, Afriwise and Nigerian trade press, but I could not open an NDPC page stating it verbatim. If the calendar requires a date stated in the instrument itself, use 2025-03-20 (issuance) instead. NOTE ALSO: secondary sources widely cite 'Article 43' for emerging technologies in the 2024 draft numbering — in the final GAID 2025 the Emerging Technologies article is Article 43, but in the earlier 2024 draft it was Article 44; verified against both texts. Separately, GAID fee provisions were reported to take effect January 2026 but are not AI-specific.

Nigeria Data Protection Act (NDP Act) 2023 — General Application and Implementation Directive (GAID) 2025, official text published by the Nigeria Data Protection Commission · verified Aug 30, 2026 · likely, see note

Sep 1, 2025
364 days ago

China · Compliance

Explicit and implicit labelling of AI-generated text, images, audio, video and virtual scenes

Measures for Labelling AI-Generated Synthetic Content + mandatory standard GB 45438-2025

ProviderPlatformAll
Detail and source

Providers of generation and synthesis services must attach both visible labels and embedded metadata; distribution platforms must verify and surface them. In force since 1 September 2025 — listed as the standing baseline every later Chinese AI rule builds on.

Reach: Services offered to users in mainland China

Measures, Article 14 (verbatim): '本办法自2025年9月1日起施行' = 'These Measures shall come into force on 1 September 2025.' Article 3 defines the two labelling modes and the covered content: 显式标识 = a label 'presented by way of text, sound, graphics etc. and able to be clearly perceived by users'; 隐式标识 = a label 'added by technical means into the data of the generated or synthetic content file, not readily perceptible to users'; covered content is '文本、图片、音频、视频、虚拟场景等信息' = 'text, images, audio, video, virtual scenes and other information'. Article 13 (enforcement): '由网信、电信、公安和广播电视等有关主管部门依据职责,按照有关法律、行政法规、部门规章的规定予以处理' = 'the competent cyberspace, telecommunications, public security and radio-and-television authorities shall handle it according to their duties and in accordance with relevant laws, administrative regulations and departmental rules.' GB 45438-2025, per the official SAMR national standards database: 标准号 GB 45438-2025, 中文标准名称 '网络安全技术 人工智能生成合成内容标识方法' (Cybersecurity technology - Labelling method for AI-generated synthetic content), 标准性质 强制性 (MANDATORY), 发布日期 2025-02-28, 实施日期 2025-09-01.

Article 14 of the Measures sets the date. GB 45438-2025 is mandatory (SAMR records it as 强制性), same implementation date. In force in practice, not just on paper: CAC ran a publicised enforcement sweep on 25 November 2025.

Measures for Labeling of AI-Generated Synthetic Content (CAC, 14 March 2025) · verified Aug 30, 2026

Jun 11, 2025
446 days ago

Canada — Alberta · Compliance

Public bodies must state in their collection notice when personal information being collected will be used in an automated system to generate content or to make decisions, recommendations or predictions

Protection of Privacy Act (POPA), SA 2024, c. P-27.5, s. 5(2)(d), and the Protection of Privacy Regulation / Protection of Privacy (Ministerial) Regulation

DeployerControllerPublic sector — Alberta provincial and local public bodies, including educational, health care and local government bodies, and the offices of the Auditor General, Ombudsman, Chief Electoral Officer, Ethics Commissioner, Information and Privacy Commissioner, Child and Youth Advocate and Public Interest Commissioner
Detail and source

POPA replaced Alberta's Freedom of Information and Protection of Privacy Act for the public sector. s. 5(2)(d) makes AI/automated-system use a mandatory element of the collection notice given to individuals. Alberta's own guidance adds that where an automated system is actually used to make decisions, the public body must make every reasonable effort to ensure the accuracy and completeness of the personal information and retain it for at least one year after use. The Act applies from proclamation forward: personal information collected before that date may still be used in AI/automated systems, but collection notices must be updated as new information is collected or programs are revised.

Who: all public bodies designated under the Access to Information Act s. 1(t) and the Designation of Public Bodies Regulation

Reach: Province of Alberta — public sector only. Alberta's private sector remains under PIPA, which has no equivalent AI clause.

Penalty: POPA carries what the Government of Alberta describes as the strongest penalties for privacy violations in Canada; offences under the Act are punishable by fines, and the Information and Privacy Commissioner of Alberta has investigation and order powers.

The Protection of Privacy Act (POPA) and regulation came into force June 11, 2025. Upon proclamation, the Freedom of Information and Protection of Privacy Act was repealed.

Date already passed (today 2026-08-30). The AI duty is a hook inside a privacy statute, not a standalone AI law — the operative words are 'automated system', with 'artificial intelligence' supplied by the Government of Alberta's own fact sheet interpreting that section. The separate POPA milestone of 11 June 2026 (expiry of the one-year grace period for public bodies to implement a privacy management program) is NOT recorded as a row because the privacy management program duty is not AI-specific and its operative text does not name AI or automated systems. Alberta's official POPA Guide PDF was checked and states no separate date for s. 5(2)(d).

About the Protection of Privacy Act — Government of Alberta (official), section 'Proclamation of law' · verified Aug 30, 2026

Jan 22, 2025
586 days ago

Singapore · Enforcement

Criminal ban, during an election period, on publishing, boosting, sharing or reposting online election advertising that contains a realistic but false digitally generated or manipulated depiction of a candidate saying or doing something they did not say or do; Returning Officer may issue corrective directions to individuals, social media services and internet access service providers to take down or block such content

Elections (Integrity of Online Advertising) (Amendment) Act 2024 (Act 34 of 2024), inserting s.61MA into the Parliamentary Elections Act 1954 and an equivalent provision into the Presidential Elections Act 1991; commenced by Commencement Notification 2025 (S 47/2025)

IndividualPlatformSocial-media-serviceInternet-access-service-providerElectionsOnline-platforms
Detail and source

The prohibition bites from the issue of the Writ of Election until the close of polling. Elements of the offence include that 'the representation was created wholly or partly with content that was generated or manipulated using digital means' and that it is 'realistic enough such that it is likely that some members of the general public would ... reasonably believe that the candidate said or did that thing'.

Who: all

Reach: Singapore; content published in Singapore during an election period

Penalty: Criminal offence; Returning Officer corrective directions with offences for non-compliance (Parliamentary Elections Act 1954 as amended)

2. The Elections (Integrity of Online Advertising) (Amendment) Act 2024 comes into operation on 22 January 2025. — Made on 16 January 2025. LEO YIP, Permanent Secretary, Prime Minister's Office, Singapore. [First published in the Government Gazette, Electronic Edition, on 20 January 2025 at 5 pm.]

Verified 2026-08-30 from the Elections Department's own gazette PDF (S 47/2025) and the Parliament bill text (Bill 29/2024), both downloaded and text-extracted. This is the only Singapore instrument I could confirm as binding, dated AND AI-hooked. Date is in the past; the duty is permanent but only operative during an election period, so the row is best read as 'in force' rather than a future deadline.

Government Gazette S 47/2025 — Elections (Integrity of Online Advertising) (Amendment) Act 2024 (Commencement) Notification 2025 · verified Aug 30, 2026

Sep 22, 2023
1074 days ago

Canada — Quebec · Compliance

Automated decision-making transparency: notify the individual when a decision is based exclusively on automated processing of personal information, and on request disclose the personal information used, the reasons and the principal factors and parameters that led to the decision, plus the right to have that information corrected and to submit observations to a member of staff able to review the decision

Loi 25 — Act to modernize legislative provisions as regards the protection of personal information (assented 22 September 2021, LQ 2021, c. 25), inserting s. 12.1 into the Act respecting the protection of personal information in the private sector (RLRQ c. P-39.1) and s. 65.2 into the Act respecting access to documents held by public bodies (RLRQ c. A-2.1)

DeployerControllerAll sectors — private enterprises and public bodies
Detail and source

Broader than GDPR Art. 22: Quebec's duty attaches to ANY decision based exclusively on automated processing of personal information, with no legal-effects or significant-effects threshold and no exemption list. It binds every person carrying on an enterprise in Quebec (s. 12.1 P-39.1) and, in parallel, every public body (s. 65.2 Act respecting access). The Government of Quebec's own guidance states a decision is 'exclusively automated' where no natural person exercised meaningful control, and that minor human intervention with no real effect on the outcome does not take the decision outside the rule.

Who: no size threshold; applies to any person carrying on an enterprise

Reach: Province of Quebec — applies to any organisation processing personal information of persons in Quebec

Penalty: Administrative monetary penalties up to CAD 10,000,000 or 2% of worldwide turnover (whichever is greater) and penal fines up to CAD 25,000,000 or 4% of worldwide turnover, under the Law 25 enforcement provisions in force since 22 September 2023; plus a private right of action for punitive damages for intentional or grossly negligent breaches.

Date de la sanction : 22 septembre 2021 — Chapitre dans le Recueil annuel des lois du Québec : 2021, chapitre 25 — Mode d'entrée en vigueur : le 22 septembre 2023, sauf exceptions

CONFIDENCE = likely, and here is exactly why. The National Assembly's own record (primary) states the Act's mode of entry into force is 22 September 2023 'sauf exceptions'. The exceptions are the first tranche in force 22 September 2022 (privacy officer, incident register, breach notification, governance policies) and the last tranche 22 September 2024 (data portability). s. 12.1 / s. 65.2 fall in the general 2023 tranche, but I could NOT open the statute's own coming-into-force section (s. 168 of chapter 25) to verify the article-by-article list: legisquebec.gouv.qc.ca and publicationsduquebec.gouv.qc.ca do not resolve from this environment (DNS blocked), cai.gouv.qc.ca does not resolve, and canlii.org returns HTTP 403. The Government of Quebec news release of 22 September 2023 confirms 'La majorité des dispositions législatives de la Loi 25 ... entrent en vigueur aujourd'hui' but does not name s. 12.1. The official quebec.ca page on 'Décision fondée exclusivement sur un traitement automatisé' explains s. 65.2 in detail but states no date. Anyone re-verifying should open LQ 2021 c. 25 s. 168 directly. Date is ~3 years past — this is settled in-force law, not an upcoming deadline. No newer Quebec AI-specific duty on the PRIVATE sector was found; the December 2025 generative-AI instruments bind the public sector only (separate row).

Assemblée nationale du Québec — Projet de loi n° 64, Loi modernisant des dispositions législatives en matière de protection des renseignements personnels (official legislature record) · verified Aug 30, 2026 · likely, see note

Sep 1, 2023
1095 days ago

United Arab Emirates — DIFC · Compliance

Deployers and Operators of autonomous/semi-autonomous systems (incl. AI and machine-learning systems) that process personal data must meet Regulation 10 design, transparency, accountability and high-risk requirements

DIFC Data Protection Regulations, Consolidated Version No. 2 — Regulation 10 (Personal Data Processed Through Autonomous and Semi-Autonomous Systems), made under DIFC Data Protection Law No. 5 of 2020

DeployerOperatorProviderControllerProcessorAll sectors operating in or from the DIFC
Detail and source

Regulation 10 is the first binding AI-specific data protection instrument in the MEASA region. Reg 10.3.2 prohibits commercial use of a System to process personal data unless it processes only for human-defined or human-approved purposes and is designed in compliance with Reg 10.3.1 (ethical, fair, transparent, secure, accountable). Reg 10.3.3 adds conditions for High Risk Processing Activities, including appointment of an Autonomous Systems Officer (ASO). Reg 10.2.2 requires notice to individuals about the underlying technology. General certification requirements are left to future Commissioner guidance and were still outstanding as of January 2026.

Who: all

Reach: Dubai International Financial Centre (DIFC) free zone — applies to processing carried out in the context of activities of a DIFC establishment

Penalty: Fines under the DIFC Data Protection Law No. 5 of 2020 fines schedule, as revised by DIFC Laws Amendment Law No. 1 of 2025: USD 50,000 for failing to comply with the general Article 9 processing requirements (which Regulation 10.2.1 expressly applies to System processing) and USD 50,000 for failing to carry out a DPIA prior to High Risk Processing Activities (raised from USD 20,000). The Commissioner may also issue directions and enforcement notices, and since 15 July 2025 data subjects have a direct right of action in the DIFC Courts for compensation including non-financial damage such as distress.

In force on 1 September 2023

VERIFIED AGAINST TWO DIFC PRIMARY DOCUMENTS. (1) The official consolidated Data Protection Regulations: the ONLY date anywhere in the instrument is the cover-page line 'In force on 1 September 2023'. There is NO transitional provision and NO deferred compliance date. (2) The DIFC Commissioner's own guidance 'FAQs: Regulation 10 on Personal Data Processed Through Autonomous and Semi-Autonomous Systems' (ref. DIFC-DP-GL-24, dated 27 August 2024) likewise states NO transition period, NO grace period and NO deferred enforcement date; it describes Regulation 10 simply as 'enacted in September 2023'. CORRECTION TO A WIDELY REPEATED CLAIM: numerous low-quality secondary sites (theleveragedyears.com, magureinc.com, orbit.reconn.io, whitelabelconsultancy.com, uaeahead.com, ailawguide.org) assert that DIFC 'moved to full enforcement' of Regulation 10 on 1 January 2026 after a grace period. That date appears in NO DIFC instrument and NO Commissioner statement, and Mayer Brown's January 2026 analysis devoted to Regulation 10 states no enforcement deadline at all. DO NOT PUBLISH 1 JANUARY 2026. CERTIFICATION STATUS: contrary to Mayer Brown's suggestion that certification requirements were still awaited, the Commissioner's FAQ Q11 confirms the framework already exists: 'Is there such an audit and certification framework? Yes, the Regulation 10 Accreditation and Certification Framework (the "Framework") is published on the DIFC Regulation 10 page'. Certification is awarded and monitored by an Accredited Certification Body. ALSO CHECKED AND REJECTED: DIFC Laws Amendment Law No. 1 of 2025 (enacted 8 July 2025, in force 15 July 2025 per its Enactment Notice) amends the Data Protection Law 2020 — Articles 6, 28, 46, 59, 61, 64, new Article 64A private right of action, and the fines schedule — but its text does NOT mention autonomous systems, Regulation 10, artificial intelligence or machine learning, so it fails the AI-relevance test and is not a separate row. Note its own commencement clause states only 'This Law comes into force on the date specified in the Enactment Notice', i.e. the law itself names no date. FETCHING NOTE: difc.com and difc.ae return HTTP 403 to automated fetching; the Regulations text was obtained via the DataGuidance mirror of the official PDF and the FAQ direct from assets.difc.com.

DIFC Data Protection Regulations, Consolidated Version No. 2 (official text) · verified Aug 30, 2026

These jurisdictions were checked against their own primary sources and have no AI obligation with a date attached — the law is pending, purely promotional, advisory, or sets a period rather than a day. An empty row is a finding, not a gap.

Kenyapending

Checked the Artificial Intelligence Bill, the Data Protection Act 2019 and the ODPC. NO enacted AI law and no binding AI instrument with a stated date. The Artificial Intelligence Bill, 2026 (Senate Bills No. 4 of 2026, sponsored by Senator Karen Nyamu) would create an Office of the Artificial Intelligence Commissioner and a risk-based regime with stringent governance, transparency, data protection and record-keeping duties for high-risk AI, plus disclosure duties on ALL providers and deployers covering 'the nature, purpose and limitations of the system, the extent of automated decision-making, and the measures taken to mitigate biases'. It is NOT LAW: it was read a First Time in the Senate on 2 April 2026 and, because it affects county governments, must also pass the National Assembly before presidential assent. As of reporting through mid-2026 it had not completed passage, and any commencement date would come from a provision that does not yet exist. Kenya's National AI Strategy 2025-2030 is a strategy document, not a duty. The Data Protection Act 2019 contains a general automated-decision-making provision, but it is a general privacy statute whose operative text does not name AI, and its commencement is a 2019/2020 privacy date, not an AI milestone. The Data Protection (Amendment) Bill 2025 proposing AI-related obligations is likewise still a bill.

Watching: Passage of the Artificial Intelligence Bill 2026 by both Houses and presidential assent, followed by a commencement notice in the Kenya Gazette — that would give a real date. Also: an ODPC guidance note or enforcement directive on AI carrying a compliance deadline.

South Africain force, no dated deadline

Checked the Information Regulator, POPIA and the national AI policy. NO binding AI instrument with a stated date. (1) South Africa has no standalone AI Act and none is imminent: the Draft National Artificial Intelligence Policy was published by the Department of Communications and Digital Technologies on 10 April 2026 as Notice 3880 of 2026 in Government Gazette No. 54477 — it is a DRAFT POLICY out for comment, not law. Government confirmed the national AI policy will not be finalised until the 2026-2027 financial year and that, when it lands, it will not be standalone legislation but a sector-specific, risk-based approach layered onto existing laws. (2) POPIA section 71 DOES bind and DOES govern automated decision-making — it restricts decisions based solely on automated processing of personal information that result in legal consequences or substantially affect the data subject, and it bites wherever AI affects people in credit, employment or insurance. But its date is a general privacy commencement, not an AI milestone: the substantive sections of POPIA commenced on 1 July 2020 under Proclamation No. R. 21 of 2020 (Government Gazette No. 43461, 22 June 2020) with a one-year grace period, so compliance has been required since 1 July 2021. Section 71's text does not name AI or machine learning. (3) The Information Regulator has issued NO binding AI guidance note with a compliance date; amended POPIA/PAIA regulations took effect 17 April 2025 but concern enforcement machinery, not AI. If the calendar wants a general automated-decision row for South Africa, POPIA s.71 with 2021-07-01 is defensible — but it is not an AI-specific dated obligation and I have not recorded it as one.

Watching: Finalisation of the National AI Policy in FY2026-27 and any implementing instrument with a commencement date; or an Information Regulator guidance note or enforcement notice on AI / automated decision-making carrying a stated compliance date.

China (People's Republic of China)pending

《数字虚拟人信息服务管理办法(征求意见稿)》 (draft Administrative Measures for Digital Virtual Human Information Services) remains AT DRAFT/CONSULTATION STAGE ONLY as of 2026-08-30. The CAC consultation notice was published 2026-04-03 and states verbatim '意见反馈截止时间为2026年5月6日' (comment deadline 6 May 2026) — so the consultation did close on 6 May 2026 as reported. But NO promulgated version has been issued since. Checked on 2026-08-30: (1) the draft's own effective-date article is LITERALLY BLANK — Art. 27 reads '本办法自2026年 月 日起施行。' with the month and day left as unfilled placeholders, so there is no date to record even in the draft; (2) a site-restricted search of cac.gov.cn for 数字虚拟人 returns only the 2026-04-03 consultation-stage documents (the notice plus two 专家解读 expert-commentary pieces) and nothing later; (3) no CAC order (令) promulgating these measures was found for June, July or August 2026. Contrast with the sibling instrument 《人工智能拟人化互动服务管理暂行办法》, which DID complete the cycle — consultation 2025-12-07, promulgated as Order No. 21 on 2026-04-10, effective 2026-07-15 — showing what promulgation of one of these looks like when it happens.

Watching: Publication on cac.gov.cn of the final 《数字虚拟人信息服务管理办法》 as a numbered CAC order (令), which will carry a filled-in Art. 27 in the form 本办法自YYYY年M月D日起施行. Take the date from that article verbatim — do NOT infer it from the consultation close, and do NOT assume the ~3-month promulgation-to-effect gap seen in the anthropomorphic-interaction measures. Watch also for whether it is issued by CAC alone or jointly with other ministries, since that changes who enforces it.

Indonesiano dated obligation

As at 2026-08-30 Indonesia has NO promulgated AI-specific instrument and therefore no dated AI duty. What I checked: (1) The two AI Presidential Regulations — RPerpres on AI Ethics (Etika Kecerdasan Artifisial) and RPerpres on the National AI Roadmap — were listed in Presidential Decision (Keppres) No. 38 of 2025 of 22 December 2025 setting the 2026 Perpres drafting programme, but as of mid-August 2026 both are still UNSIGNED and awaiting the President; Komdigi's own JDIH item of 12 February 2026 says only 'Pemerintah menargetkan Rancangan Perpres Peta Jalan Kecerdasan Artifisial Nasional dapat ditetapkan pada kuartal pertama tahun 2026' ('The Government targets that the draft Presidential Regulation on the National AI Roadmap can be enacted in Q1 2026') — a target that slipped, and a target is not a promulgated date. (2) PP No. 33 of 2026, the long-awaited implementing regulation of the Personal Data Protection Law (UU 27/2022), was enacted and promulgated on 16 July 2026 (Lembaran Negara 2026 No. 88, Tambahan LN No. 7190; 12 chapters, 225 articles) — but it comes into force '6 months after promulgation', a PERIOD with no calendar date stated in the instrument or by Komdigi, so I did not derive 16 January 2027; and I could not confirm that its operative text names AI or solely-automated decision-making (the AI hook sits in Art. 10 of the parent UU PDP, on objecting to decisions based solely on automated processing including profiling). (3) PP No. 17 of 2025 (PP TUNAS, governance of electronic systems in child protection) was enacted and promulgated 27 March 2025 with a transition expressed as a period, and is not AI-specific. (4) Komdigi Circular Letter (Surat Edaran) No. 9 of 2023 on AI ethics is guidance and creates no enforceable duty.

Watching: Presidential signature on either AI Perpres (Etika KA; Peta Jalan KA Nasional) and its promulgation date in the Lembaran Negara; a Komdigi Ministerial Regulation implementing them; the announced move from Perpres to a full UU AI; and any Komdigi or OJK statement fixing the calendar date on which PP 33/2026 becomes effective.

Japanin force, no dated deadline

Japan's AI Promotion Act (人工知能関連技術の研究開発及び活用の推進に関する法律, Act No. 53 of 4 June 2025) is fully in force but is PROMOTIONAL, not regulatory — it creates no dated compliance duty and carries no sanction, so it does not qualify as a calendar row. Verified against the official e-Gov statute text (API, law id 507AC0000000053): 附則第一条 reads 'この法律は、公布の日から施行する。ただし、第三章及び第四章並びに附則第三条及び第四条の規定は、公布の日から起算して三月を超えない範囲内において政令で定める日から施行する。' ('This Act comes into effect on the date of promulgation; provided that Chapters 3 and 4 and Arts. 3 and 4 of the Supplementary Provisions come into effect on a date specified by Cabinet Order within a period not exceeding three months from the date of promulgation.'). The Cabinet Office states: '令和7年6月4日にAI法が公布・一部施行され、9月1日にはAI戦略本部の設置に係る規定等も含め、全面施行されました' ('The AI Act was promulgated and partly brought into force on 4 June 2025, and on 1 September it was fully brought into force, including the provisions establishing the AI Strategy Headquarters'). The e-Gov text contains NO article headed 罰則 (penal provisions). The only business-facing article, Art. 7 活用事業者の責務 (duties of AI-utilising business operators), is a best-efforts duty to pursue AI use and to cooperate with state and local government measures — unenforceable by sanction. The AI Basic Plan (人工知能基本計画 ~「信頼できる AI」による「日本再起」~) was adopted by Cabinet decision on 23 December 2025 (cited in the PPC's own 2026 APPI overview) and is likewise a plan, not an obligation. As at 2026-08-30 Japan still has no statutory duty to label AI-generated content, and no dedicated deepfake statute — the government said it would assess sexual-deepfake measures during FY2026 under the AI Promotion Act.

Watching: Any amendment adding sanctions to the AI Promotion Act; a dedicated deepfake/synthetic-media bill in the Diet; a Cabinet Order fixing the enforcement date of the 2026 APPI amendment (separate watchlist row); FSA or PPC binding notices naming AI.

Malaysiapending

Malaysia's cross-sector AI Governance Bill (Rang Undang-Undang Tadbir Urus Kecerdasan Buatan) is NOT enacted and carries no date. The Ministry of Digital (Kementerian Digital) opened public engagement on the proposal via the Unified Public Consultation portal on 10 July 2026, following the Digital Minister's remarks in Parliament on 24 June 2026; the press release states no date for tabling in the Dewan Rakyat and no commencement date. It would be Malaysia's first horizontal, risk-based AI legal framework with safeguards and incident reporting. Separately, the National Guidelines on AI Governance & Ethics and the National AI Office (NAIO) framework are non-binding. The one binding, dated AI-relevant Malaysian duty found is the MCMC Risk Mitigation Code under the Online Safety Act 2025, recorded as a deadline row (enforcement 1 June 2026, synthetic-media labelling at para. 4.2.4(d)). The Online Safety Act 2025 (Act 866) itself came into operation on 1 January 2026 but its operative text does not name AI — its AI reach comes through the Code.

Watching: Tabling and passage of the AI Governance Bill in the Dewan Rakyat and its commencement clause; any further MCMC code or determination under the Online Safety Act 2025 expressly requiring AI-content labelling (MCMC has said it is considering making AI-content labels mandatory); and subsidiary legislation under Act 866 such as the Online Safety (Online Safety Plan) Regulations 2026.

New Zealandvoluntary only

Beyond the Biometric Processing Privacy Code 2025 (recorded separately as dated rows), New Zealand has NO binding AI instrument and no dated AI duty. The Algorithm Charter for Aotearoa New Zealand (Stats NZ) is an explicitly voluntary commitment signed by government agencies about their own algorithm use — not law, and it binds no private party. The 2025 National AI Strategy and the public-sector generative-AI and business 'responsible AI' guidance are non-binding. New Zealand's stated policy is that existing technology-neutral law (principally the Privacy Act 2020) is sufficient, and no omnibus AI bill has been introduced.

Watching: Any AI bill introduced to Parliament; a further Privacy Commissioner code of practice or compliance notice aimed at automated decision-making; Financial Markets Authority or Reserve Bank instruments naming AI with a compliance date.

Philippinesno dated obligation

As at 2026-08-30 there is NO signed Philippine AI statute. The House is consolidating 26 bills, 3 resolutions and a privilege speech into a draft Artificial Intelligence Development and Regulation Act (building on HB 7396 Artificial Intelligence Development Act and HB 7913 AI Bill of Rights, which would create an AI Development Authority); all remain under legislative review. The National AI Strategy for the Philippines (NAIS-PH), approved by the President in May 2025, is a strategy, not an obligation. The one genuinely binding, dated, AI-specific Philippine instrument I found is COMELEC Resolution No. 11064 (guidelines on the use of social media, artificial intelligence and internet technology for the 2025 National, Local and BARMM Parliamentary Elections), promulgated 17 September 2024, effective 26 September 2024, amended by Resolution No. 11064-A of 13 November 2024. It banned 'false amplifiers' (fake accounts, bots, deepfakes, cheapfakes, softfakes), required disclosure of AI use in campaign material and required registration of digital campaign platforms with the COMELEC Education and Information Department within 30 calendar days of filing certificates of candidacy, i.e. by 13 December 2024. I have NOT recorded it as a live calendar row because it is expressly tied to the May 2025 election cycle, which has passed, and no successor resolution has yet been issued for the 2028 cycle. Sanctions were criminal charges under the Omnibus Election Code, including disqualification.

Watching: Passage and signing of the consolidated Artificial Intelligence Development and Regulation Act (a Republic Act would state its own effectivity clause); a fresh COMELEC resolution on AI for the 2028 elections; and any National Privacy Commission circular (as opposed to advisory) imposing dated AI or automated-decision duties under the Data Privacy Act.

Singaporevoluntary only

Apart from the two dated rows recorded (Elections (Integrity of Online Advertising) (Amendment) Act 2024 in force 22 January 2025, and the partial commencement of the Online Safety (Relief and Accountability) Act 2025 on 29 June 2026), Singapore has NO binding, dated AI instrument. Specifically: (1) The Model AI Governance Framework — including the Generative AI edition — is VOLUNTARY, an IMDA/AI Verify Foundation advisory framework with no legal force and no compliance date; it is not a calendar row. (2) MAS's Guidelines on AI Risk Management are supervisory expectations, not law: MAS consulted on them from 13 November 2025 with comments due 31 January 2026, proposed a 12-month transition after issue, and as at August 2026 the final Guidelines had not been issued — so there is no date, and even when issued they are Guidelines, not a Notice (MAS Notices are the legally binding form). (3) The Government has expressly declined to impose AI labelling: MTI's written reply to a Parliamentary Question of 6 November 2025 states 'There are currently no plans to introduce specific disclosure requirements or labelling standards for AI-generated content of products and services', relying instead on Technical Reference 76, the AI Markets Toolkit and advertising standards — all voluntary. (4) Health-sector AI guidance from HSA (software/AI medical devices) is regulatory guidance under the existing Health Products Act device-registration regime, with no AI-specific dated duty. (5) Under OSRAA, the deepfake-specific harm 'inauthentic material abuse' (Clause 16) is defined by reference to material 'altered or generated using digital means' and expressly names generative AI, but it is in the deferred tranche with NO commencement date announced.

Watching: The commencement notification bringing OSRAA's 'inauthentic material abuse' and the other seven deferred harms into force; MAS issuing the final AI Risk Management Guidelines (which would start their 12-month transition) or converting any AI requirement into a binding Notice; any IMDA Code of Practice amendment under Part 10A of the Broadcasting Act adding AI-content duties; any reversal of MTI's 'no plans' position on AI labelling.

Taiwanin force, no dated deadline

Beyond the AI Basic Act itself (recorded as a dated row: promulgated and in force 14 January 2026), Taiwan has NO further binding AI instrument carrying a date. What I checked: (1) The Act contains no penal provisions; its Art. 18 obliges GOVERNMENT to complete the adaptation of laws and administrative measures 'within two years of this Act coming into force' — a period, not a stated date, and a duty on the state, not on business, so I did not derive 14 January 2028. (2) The MODA (數位發展部) AI risk-classification framework required by Art. 16 — the instrument that would actually put concrete duties on providers of high-risk AI — has been announced but not yet published, and no publication or compliance date has been stated. (3) The FSC's '金融業運用人工智慧(AI)指引' (Guidelines for Financial Institutions' Application of AI) are guidelines, not a binding order (法規命令); the FSC Chairman said in May 2026 that programmable AI, AI agents and AI risk classification would be folded into those Guidelines, again with no stated compliance date. (4) The legislative supplementary resolutions attached to the AI Basic Act set 3-month, 6-month and 1-year tasks (gender/human-rights/child impact assessments by MODA with NSTC, MOHW, MOE and the Executive Yuan human-rights and gender-equality offices; agency AI risk assessments and internal control rules; MOE AI-use and learning guidance) — all periods, all directed at government bodies.

Watching: MODA's publication of the AI risk-classification framework and any sectoral management rules (管理規範) made under Art. 16 — those would carry the first dated duties on private AI providers; conversion of the FSC AI Guidelines into a binding order; and the government's law-adaptation package under Art. 18.

Thailandno dated obligation

As at 2026-08-30 Thailand has NO enacted AI instrument and therefore no dated AI duty. The Ministry of Digital Economy and Society (DE) and ETDA published '(ร่าง) หลักการของกฎหมายว่าด้วยปัญญาประดิษฐ์' — DRAFT principles for Thailand's first AI law, focused on controlling high-risk AI — and ran a public hearing that closed 24 June 2568 (2025). ETDA's own page confirms it is still a draft (ร่าง): it has NOT been published in the Royal Gazette (ราชกิจจานุเบกษา) and states no enactment or entry-into-force date. A companion draft Royal Decree on AI-system business services completed consultation but likewise has not been gazetted. Reporting indicates the government aims to move the draft through Cabinet and Parliament during 2569 (2026), but a target is not a promulgated date. The National Press Council's 2567 (2024) guidance on AI and journalistic ethics is a professional-ethics guideline, not law.

Watching: Publication of the AI law or the Royal Decree on AI business services in the Royal Gazette (ราชกิจจานุเบกษา) — Thai instruments state their entry into force relative to that gazette date; also watch PDPC subordinate notifications and BOT/SEC notifications naming AI.

Icelandno dated obligation

The EU AI Act has not been taken into the EEA Agreement, so Iceland has no implementing act and no date. Verified on the Icelandic Government's own site (Stjornarradid, joint release of the Ministry of Culture, Innovation and Higher Education, the Ministry of Justice and the Ministry of Industries, dated 28 May 2026), which says of the AI Act: 'Gert er rad fyrir ad leggja fram frumvarp a Althingi til innleidingar a reglugerdinni thegar hun hefur verid tekin upp i EES-samninginn' - a bill will be laid before Althingi to implement the regulation ONCE it has been taken into the EEA Agreement. The same release confirms the DSA likewise 'hefur ekki verid tekin upp i EES-samninginn'. No Icelandic AI bill has been introduced and no commencement date exists.

Watching: An EEA Joint Committee Decision incorporating Regulation (EU) 2024/1689 into the EEA Agreement, followed by an Icelandic implementing bill (frumvarp) with a stated gildistaka (entry into force). Also watch the three-ministry deepfake working group set up on 28 May 2026, whose conclusions are due 'eigi sidar en 1. oktober' (no year stated in the source, so not recorded as a dated row) - its recommendations could produce dated Icelandic deepfake legislation.

Liechtensteinno dated obligation

The EU AI Act has not been incorporated into the EEA Agreement, so it is not applicable in Liechtenstein and there is no national implementing act or date. Primary evidence opened live: the Government's Interpellationsbeantwortung to the Landtag on artificial intelligence, cloud computing and technological infrastructure, BuA No. 59/2026 (Vaduz, 12 May 2026, LNR 2026-660, on the Government's own Berichte und Antraege database), where the interpellating MPs ask the Government: 'Welchen Zeitplan sieht die Regierung fuer die EWR-Uebernahme relevanter EU-Rechtsakte (z. B. EU-KI-Verordnung/AI Act, NIS2), und welche Auswirkungen erwartet sie fuer Unternehmen und Verwaltung?' - i.e. as of May 2026 no timetable for EEA incorporation had been published, which is why Parliament had to ask. Corroborated by Norway's Nkom (page updated 24.03.2026: the regulation must be taken into the EEA Agreement before it has effect) and by the Icelandic Government (28 May 2026: a bill will be laid 'once it has been taken up into the EEA Agreement'). Separately, in April 2026 the Government adopted only an internal AI strategy for the national administration (Medienmitteilung 21.04.2026), which is a policy document with no fixed validity period and no obligations on private parties; the only date it contains is a review 'spaetestens im Jahr 2030'.

Watching: An EEA Joint Committee Decision incorporating Regulation (EU) 2024/1689 into the EEA Agreement, and the Government's subsequent Vernehmlassung and Bericht und Antrag for a Liechtenstein implementing act (Durchfuehrungsgesetz) - the BuA will state the intended Inkrafttreten. The Stabsstelle fuer Digitale Innovation (SDI) leads the EEA incorporation and national implementation.

Norwayno dated obligation

The EU AI Act (Regulation (EU) 2024/1689) has NOT been incorporated into the EEA Agreement, so it does not apply in Norway and there is no EEA-derived date. Verified on the page of Nkom, the Norwegian Communications Authority designated as Norway's AI coordination authority (page last updated 24.03.2026), which states: 'For at dette regelverket skal fa virkning i Norge, ma det tas inn i EOS-avtalen gjennom den nye norske loven om kunstig intelligens (KI-loven).' Nkom's own timeline page lists only EU application dates (1 Aug 2024 entry into force, 2 Feb 2025 prohibitions, 2 Aug 2025 GPAI, 2 Aug 2026 remaining provisions) and makes no statement that any of them apply in Norway. Nkom also records that, following the AI omnibus, the date for the high-risk requirements is 'not determined'. Nationally: the draft Norwegian AI law (KI-loven) went to consultation with a 30 September 2025 deadline; after the EU simplification package the government said it would run a second consultation and its stated ambition is to lay the bill before the Storting in spring 2027 - an ambition, not an appointed date. I could not open efta.int directly (Cloudflare human-verification challenge, which I did not bypass); its EEA-Lex factsheet for 32024R1689 is reported as 'under scrutiny for incorporation into the EEA Agreement by Iceland, Liechtenstein and Norway', consistent with the regulator's statement.

Watching: Adoption of an EEA Joint Committee Decision incorporating Regulation (EU) 2024/1689 (and Regulation (EU) 2026/1744, the AI omnibus) into Annex XI of the EEA Agreement - the JCD itself states its entry-into-force date and any adapted transitional dates, which is what would create the first real Norwegian calendar rows. Also watch: Royal assent and a commencement date for the Norwegian KI-lov, and the opening of the announced second consultation (which will carry a stated closing date).

Switzerlandno dated obligation

Checked the Federal Council's own media release of 12 February 2025 (admin.ch, opened directly) - it sets only an internal planning milestone: 'Das EJPD wird mit dem UVEK und dem EDA bis Ende 2026 eine Vernehmlassungsvorlage erstellen' and 'Das UVEK wird zudem mit dem EJPD, dem EDA und dem WBF bis Ende 2026 einen Plan fuer die weiteren Massnahmen von rechtlich nicht verbindlicher Natur erarbeiten'. 'By end of 2026' is a departmental deliverable, not a stated date and not a duty on any regulated entity; the approach is expressly sectoral with no horizontal Swiss AI act. On the treaty side: the Council of Europe Treaty Office chart for CETS No. 225 (Framework Convention on AI), 'Status as of 30/08/2026', shows Switzerland signed 27/03/2025 but has NOT ratified; 'Total number of ratifications/accessions 1' (European Union, 15/05/2026) against an entry-into-force rule of '5 Ratifications including at least 3 member States of the Council of Europe' - so the Convention is not in force and creates no dated Swiss obligation. Also checked admin.ch/news for any 2026 Federal Council AI decision superseding the 12 Feb 2025 one - none found. Swiss sectoral automated-driving ordinance (VAF) has been in force since 1 March 2025, i.e. not a recent or forthcoming milestone.

Watching: Publication of the EJPD/UVEK/EDA consultation draft (Vernehmlassungsvorlage) implementing the CoE AI Convention - the opening of a Vernehmlassung carries a stated closing date, which would be the first real Swiss AI calendar date; a Federal Council dispatch (Botschaft) to Parliament on ratifying CETS No. 225; deposit of the 5th ratification of CETS No. 225 (3 of them CoE members), which would fix the Convention's entry-into-force date.

United Kingdompending

Companion entry to the six dated UK rows in this file - these AI items were checked and have NO stated date, so they are deliberately NOT calendar rows. (1) Regulating for Growth Bill: announced in the King's Speech of 13/14 May 2026, creating cross-economy regulatory sandbox powers including for AI; not yet introduced with a published text and no commencement dates - the 2026 legislative programme was set out in the written statement of 14 May 2026 (HCWS7). (2) ICO statutory AI/ADM code of practice: SI 2026/425 imposes the duty to prepare it from 12 May 2026 but sets NO deadline; the ICO says timings will come via its codes of practice pipeline and draft ADM/profiling guidance will be consulted on first. (3) Crime and Policing Act 2026 s.72 (child sexual abuse image-generators, new SOA 2003 s.46A - 'thing' includes 'a program, information in electronic form and a service'): commencement note still reads 'not in force at Royal Assent, see s. 255(1)' and it was absent from the Commencement No.1 list; no appointed day. (4) Automated Vehicles Act 2024 Part 1 (the core self-driving vehicle authorisation regime) plus s.84 civil sanctions and s.89(8)(b)/(10): uncommenced, no appointed day; DfT has publicly referred only to 'the second half of 2027', which is not a stated date. (5) DUAA 2025 ss.135-136 (economic impact assessment on copyright and AI, and report on the use of copyright works in the development of AI systems): the duties are expressed as 'before the end of the period of 9 months beginning with the day on which this Act is passed' - a period, not a stated date, so no row is created. (6) FCA: confirmed on its own 'AI and the FCA: our approach' pages that it is not introducing AI-specific rules, relying on the Consumer Duty and SM&CR; its 2026 AI activity was input-gathering (long-term review contributions closed 24 February 2026; AI Input Zone open 14 May to 19 June 2026), not compliance duties. (7) MHRA: software and AI as a medical device reform remains at consultation/evidence stage with no AI-specific SI in force or with an appointed date. (8) Ofcom: has published guidance that AI chatbot output falls inside Part 3 duties only where it is user-generated or search content - interpretation of existing 2025 deadlines, not a new dated AI duty. (9) Council of Europe Framework Convention on AI (CETS No. 225): the UK signed on 05/09/2024 but has not ratified; per the CoE Treaty Office chart, status as of 30/08/2026, there is 1 ratification in total and the treaty is not in force.

Watching: Introduction and commencement provisions of the Regulating for Growth Bill; an ICO announcement of the AI/ADM code timetable (draft for consultation carries a stated closing date); a Crime and Policing Act 2026 commencement SI appointing a day for s.72; an Automated Vehicles Act 2024 commencement SI for Part 1; and above all a draft statutory instrument under the new s.216A of the Online Safety Act 2023 bringing AI services and illegal AI-generated content into scope - laying that draft before 31 December 2026 would displace the s.249 progress-report duty already recorded as a dated row.

Council of Europe — Framework Convention on AI (CETS No. 225)not in force

Checked the Council of Europe Treaty Office chart of signatures and ratifications for CETS No. 225 directly on 2026-08-30; the page itself is stamped 'Status as of 30/08/2026'. It reports 'Total number of ratifications/accessions 1' and 'Total number of signatures not followed by ratifications 20'. The ONLY ratification is by the European Union (signature 05/09/2024, ratification 15/05/2026) — an international organisation, not a State. ZERO Council of Europe member States have ratified. The Entry into Force condition printed in the chart header is '- 5 Ratifications including at least 3 member States of the Council of Europe', and Article 30(3) of the Convention (as published in OJ L 2026/1081, 13.5.2026) requires five signatories including at least three CoE member States. The 'Entry into Force' column is BLANK for every row, including the EU's. Therefore the Convention has NOT entered into force, it binds nobody yet, and no entry-into-force date exists to record — not for the treaty and not for the EU. NOTE FOR THE EDITOR: widely repeated secondary commentary claiming CETS 225 'entered into force on 1 November 2025 after ratification by the United Kingdom, France and Norway' is FALSE against the depositary chart — the UK and Norway show signature only (both 05/09/2024) and France appears in the chart with no signature and no ratification at all.

Watching: Four more ratifications, at least three of which must be by Council of Europe member States. When the fifth consent-to-be-bound is deposited, Article 30(3) fixes general entry into force on 'the first day of the month following the expiration of a period of three months' after that deposit; each later ratifying State then gets its own staggered date under Article 30(4). Re-check the same Treaty Office chart — it publishes an 'Entry into Force' column per State and the Secretary General notifies EIF dates under Article 36(c). Do NOT compute any of these dates: take them from the chart once printed.

European Union — ratification of CETS No. 225pending

NO ratification anywhere creates a dated domestic implementation duty at present, and the reason is twofold. FIRST: no STATE has ratified CETS No. 225 at all — the Council of Europe Treaty Office chart, status as of 30/08/2026, reports 'Total number of ratifications/accessions 1', and that single ratification is the European Union (signed 05/09/2024, ratified 15/05/2026). So there is no national ratification anywhere from which a domestic implementation duty could flow. SECOND: the EU's own ratification instrument expressly declines to create one. Council Decision (EU) 2026/1080 of 21 April 2026 on the conclusion, on behalf of the European Union, of the Convention states at Article 3: 'The Convention shall be implemented in the Union exclusively through Regulation (EU) 2024/1689 and other relevant Union acquis, where applicable.' That is a deferral, not a new duty — the word 'exclusively' rules out any separate implementation obligation or timetable, and Article 4 provides only that 'This Decision shall enter into force on the date of its adoption.' Nothing in the Decision imposes a dated obligation on member states or on companies; every operative date for EU-regulated entities remains an AI Act date and is already tracked under that instrument. Compounding all of this, the Convention is not in force (it needs five ratifications including at least three Council of Europe member States), so even the EU is not yet bound by it and its 'Entry into Force' cell in the depositary chart is blank. Conclusion: NO calendar row is justified for any ratification at this time.

Watching: Two distinct triggers, and they are not the same event. (1) The Convention's general entry into force, once the fifth consent-to-be-bound is deposited with at least three of them from CoE member States — read the date off the Treaty Office chart's 'Entry into Force' column, never compute it. (2) A ratifying STATE that, unlike the EU, enacts implementing legislation with its own commencement date — that domestic statute, not the ratification, would be the calendar row. Watch in particular any ratifying state without an existing horizontal AI statute, since those are the ones likely to legislate afresh. For the EU specifically, treat the AI Act timetable as the only live source of dates; do not create CETS 225 rows for EU operators.

UNESCO — Recommendation on the Ethics of Artificial Intelligenceaspirational only

NOT BINDING — verified against UNESCO's own Legal Affairs page for the instrument. The UNESCO Recommendation on the Ethics of Artificial Intelligence was adopted on 23 November 2021 at the 41st session of the General Conference in Paris. A 'Recommendation' is UNESCO's non-binding class of standard-setting instrument, as distinct from a Convention, and the text itself makes the voluntary character explicit: Member States are to 'apply on a voluntary basis the provisions of this Recommendation by taking appropriate steps, including whatever legislative or other measures may be required, in conformity with the constitutional practice and governing structures of each State'. There is NO dated compliance deadline for States and none at all for companies — the Recommendation does not bind private actors in any way. Implementation tooling (the Readiness Assessment Methodology, the Ethical Impact Assessment) is advisory and carries no deadline. UNESCO's role is described as partnership and support: 'UNESCO can be a partner and support Member States in the development as well as monitoring and evaluation of policy mechanisms.' Nothing here is a calendar row.

Watching: Only a binding successor instrument would qualify — i.e. UNESCO's General Conference adopting a CONVENTION on AI (which would then need signature, ratification and an entry-into-force clause), rather than revising or supplementing the Recommendation. Note that even the periodic implementation reporting UNESCO Member States do under the Constitution is a reporting cycle to UNESCO, not a compliance duty on regulated entities, so it should not be converted into calendar rows.

United Nations — General Assembly (AI instruments)aspirational only

NOT BINDING — read the primary text of UN General Assembly resolution A/RES/79/325, 'Terms of reference and modalities for the establishment and functioning of the Independent International Scientific Panel on Artificial Intelligence and the Global Dialogue on Artificial Intelligence Governance', headed 'Resolution adopted by the General Assembly on 26 August 2025' (89th plenary meeting, 26 August 2025). A UNGA resolution of this kind is a recommendation, and the text confirms it on its face: the operative verbs create UN INSTITUTIONS, not duties on anyone — para 1 'Establishes, within the United Nations, the multidisciplinary Independent International Scientific Panel on Artificial Intelligence', para 4 'Establishes, within the United Nations, the Global Dialogue on Artificial Intelligence Governance'. The Panel's output is expressly described as 'one annual policy-relevant but non-prescriptive summary report'. The ONLY operative paragraph aimed at States is para 11, which merely 'Encourages States, as well as the private sector, financial institutions, foundations and other donors in a position to do so, to support the effective functioning of the Panel and Dialogue'. 'Requires' (para 2) binds candidates for Panel nomination to disclose conflicts of interest, not Member States; 'Requests' (paras 3, 10) is addressed to the Secretary-General. There is NO obligation on any State or company and NO dated compliance deadline anywhere in the resolution. Its predecessor instruments are the same in character: resolution 79/1 'The Pact for the Future' and its annex the 'Global Digital Compact', plus resolutions 78/265 and 78/311, all recommendatory. The dates the resolution does contain are EVENT dates for UN meetings, not compliance dates: para 6 provides the Global Dialogue 'will initially be held back-to-back in the margins of the International Telecommunication Union Artificial Intelligence for Good Global Summit in Geneva, in 2026, and of the multi-stakeholder forum on science, technology and innovation for the Sustainable Development Goals in New York, in 2027'. Related 2026 activity is also institutional, not regulatory: the GA appointed the Panel's 40 members on 12 February 2026 and the first Global Dialogue was held in Geneva on 6-7 July 2026. None of this belongs in a compliance calendar.

Watching: The UN has no treaty-making step under way for AI. A calendar row would require a genuinely binding instrument — a convention opened for signature and ratification under a UN depositary, with an entry-into-force clause — not another resolution, dialogue or panel report. Para 12 notes only that continuation of the Panel's and Dialogue's terms of reference 'may be considered and decided upon by the General Assembly during the high-level review of the Global Digital Compact at its eighty-second session'; that is a mandate-renewal question, still not an obligation on anyone.

Argentinano dated obligation

Argentina has NO AI statute. Checked 2026-08-30. The closest binding-adjacent instrument is Resolucion SIGEN 197/2026 (Sindicatura General de la Nacion, Argentina's internal-audit body), dated 16 June 2026 and published in the Boletin Oficial No. 35934 on 22 June 2026, page 29, whose sole operative clause is 'APRUEBASE LA GUIA DE CONTROLES INTELIGENCIA ARTIFICIAL - SIGEN'. It is a risk-based internal-control GUIDE for AI adoption across the National Public Sector, not a regulation imposing duties on regulated entities, and — checked on the official Argentina.gob.ar normativa record — it contains NO vigencia article and NO compliance deadline. Several AI bills are in parliamentary discussion, informed by an anteproyecto prepared by the Agencia de Acceso a la Informacion Publica (AAIP), but none has been sanctioned. In the meantime AI that processes personal data falls under the pre-existing Ley 25.326 de Proteccion de los Datos Personales, which dates from 2000 and gained no new date from any of this.

Watching: Sanction and Boletin Oficial publication of an AI law, or an AAIP resolution (rather than an anteproyecto) imposing dated duties on automated decision-making. A SIGEN follow-up converting the guide into mandatory audit criteria with a compliance date would also create a row.

Brazilno dated obligation

ANPD (Autoridade Nacional de Protecao de Dados) has issued NO binding normative act on AI carrying a compliance date. Checked 2026-08-30. What exists is agenda and preparatory work only: item 7 of the ANPD Regulatory Agenda for the 2025-2026 biennium is dedicated to AI and specifically to the right to review automated decisions under LGPD art. 20; the ANPD ran a Tomada de Subsidios on that topic and consolidated the responses in Nota Tecnica n. 12/2025; and in December 2025 the ANPD published its Priority Themes Map for 2026-2027 naming artificial intelligence and emerging technologies as one of four supervisory axes. None of these is a regulation and none carries an obligation date. The underlying LGPD duty — art. 20, the data subject's right to request review of decisions taken solely on automated processing of personal data affecting their interests, and the controller's duty to give clear information about the criteria and procedures used — has been in force since the LGPD took effect in 2020 and was NOT given a new date by any of this work.

Watching: Publication in the Diario Oficial da Uniao of an ANPD resolution regulating LGPD art. 20 / automated decisions, which would carry its own vigencia clause and any transition period. Also watch whether PL 2338/2023 designates ANPD as the coordinating authority of the SIA, which would trigger implementing regulations with dates.

Chilepending

Chile's dedicated AI bill — 'Regula los sistemas de inteligencia artificial', Boletin 16821-19 (refundido with 15869-19), a risk-based framework imposing obligations on developers, providers, implementers and distributors of AI systems including foreign ones operating in Chile — is NOT law. Verified 2026-08-30: the Camara de Diputados approved it en particular on 13 October 2025 and remitted it to the Senate; it is in SECOND constitutional trámite before the Senate's Comision de Desafios del Futuro, Ciencia, Tecnologia e Innovacion, and must also pass the Comision de Hacienda. Recorded movements include an urgencia suma presented 6 January 2026 and withdrawn-and-re-presented 20 January 2026. No third trámite, no approval, no promulgation, no Diario Oficial publication — therefore no commencement date exists. Note this is SEPARATE from Ley 21.719 (data protection), which IS enacted and does have a dated commencement — recorded as a deadline row.

Watching: Senate approval in second trámite, any third trámite or comision mixta, then promulgation and Diario Oficial publication with the transitional article setting vigencia. The BCN record at bcn.cl will show 'Entra en vigencia el ...' once published, which is the citable date source.

Colombiapending

Colombia has NO enacted AI law and no binding regulator instrument on AI with a date. Checked 2026-08-30. The government-backed bill PL 043/2025 Senado - 324/2025 Camara ('Por medio del cual se regula la inteligencia artificial en Colombia...'), filed 28 July 2025 by MinCiencias and given an urgency message on 8 September 2025, was ARCHIVED at the end of the legislature without becoming law. A replacement bill was radicado on 21 July 2026 in the Camara de Representantes — 'Proyecto de Ley Por medio de la cual se regula la inteligencia artificial en Colombia para garantizar su desarrollo etico y responsable y se dictan otras disposiciones' (proyecto 36127, P.L. 025-2026SC), an 86-page text. Its own Article 37 reads 'Entrada en vigencia. La presente ley regira a partir de su promulgacion y deroga...' — commencement on promulgation, so even the bill states no date, and it has not been debated, approved or promulgated. Colombia's AI policy instrument, CONPES 4144, is a policy document setting government action lines, not a source of enforceable dated duties on regulated entities.

Watching: Passage of P.L. 025-2026SC through both chambers, presidential sanction and publication in the Diario Oficial — at which point Article 37's 'a partir de su promulgacion' plus the promulgation date would give a citable date. Also watch the Superintendencia de Industria y Comercio (data protection authority) for any circular externa on automated decision-making, which would carry its own effective date.

Mexicopending

There is NO Ley General de Inteligencia Artificial in Mexico. Checked 2026-08-30: the comprehensive AI bill never reached the floor of Congress, so it has not been voted and has not been published in the Diario Oficial de la Federacion. Separately, a constitutional reform initiative was presented to the Comision Permanente by Morena deputy Gabriela Jimenez to amend fraccion XVII of Article 73 of the Constitution so as to expressly empower the Congreso de la Union to legislate on the use and implementation of artificial intelligence systems — that is an enabling-power amendment, still an initiative, not approved and not published. Neither carries any date. Mexico's AI regulation is therefore sectoral only (see the separate entry on the LFT/LFDA reform of 14 May 2026).

Watching: Approval and DOF publication of the Article 73 constitutional reform (which would then require secondary legislation), or a Ley General de IA reaching a floor vote. Either would come with transitorios setting commencement. Track the Camara de Diputados boletines and the Senado's agenda.

Peruin force, no dated deadline

Peru HAS a binding, AI-specific regulation with a full staggered compliance schedule — Decreto Supremo N. 115-2025-PCM approving the Reglamento of Ley N. 31814 (Ley que promueve el uso de la inteligencia artificial en favor del desarrollo economico y social del pais). El Peruano states 'Fecha de publicacion: 09/09/2025'. It creates real duties: risk classification with prohibited uses, Art. 25 'Transparencia Algoritmica' (developers and implementers of HIGH-RISK AI systems must give users prior, clear and simple information about the system's purpose, main functionalities and the type of decisions it can make), and Arts. 28.11 / 31.4 requiring human oversight mechanisms able to stop, correct or invalidate AI decisions in health, education, justice, finance and access to basic services. BUT NOT ONE COMPLIANCE DATE IS WRITTEN AS A CALENDAR DATE — every deadline is a relative period. Vigencia clause: 'El presente Decreto Supremo entra en vigencia a partir de los noventa (90) dias habiles siguientes de su publicacion en el diario oficial El Peruano, con excepcion de la Primera, Segunda, Cuarta y Quinta Disposiciones Complementarias Finales ... las cuales entran en vigencia al dia siguiente de la publicacion'. PRIMERA Disposicion Complementaria Final (Cronograma de implementacion) then sets, all 'contado a partir del dia siguiente de la publicacion del Decreto Supremo': PUBLIC SECTOR — Executive/Legislative/Judiciary 1 year; Organismos Constitucionales Autonomos 1 year; EsSalud, regional governments and public universities 2 years; local governments Type A/B/C 3 years; public enterprises of regional/local governments and FONAFE 2 years; other entities under Ley 27444 2 years; local governments Type D-G optional. PRIVATE SECTOR — health, education, justice, security, economy and finance 1 year; transport, commerce and labour 2 years; production, agriculture, energy and mining 3 years; all other uses 4 years. MYPES/innovative startups — small enterprises (sales above 150 UIT up to 1700 UIT) 2 years; microenterprises (up to 150 UIT) 3 years. Commonly cited derived dates (general vigencia 22 January 2026; first private-sector tranche 10 September 2026) are law-firm computations, not text. Per the no-computed-dates rule none of these becomes a calendar row.

Watching: A Resolucion Secretarial from the SGTD (Secretaria de Gobierno y Transformacion Digital) under the SEGUNDA Disposicion Complementaria Final — it is empowered to issue the complementary norms, technical specifications, standards and the Transparencia Algoritmica lineamientos (Art. 25.4), and such a resolution would carry its own publication and effective dates. Also watch for any SGTD implementation calendar that writes the tranche dates out explicitly; that would immediately yield several high-value rows (deadline_type compliance, ai_specific).

Egyptpending

CLOSE TO A ROW BUT THE DATE IS COMPUTED, NOT STATED — deliberately withheld. Egypt's Personal Data Protection Law No. 151 of 2020 was finally operationalised by its Executive Regulations (Ministerial Decision No. 81 of 2025). The Regulations DO carry an AI hook: per Baker McKenzie's review of the text, 'The Regulations refer briefly to AI training, with a requirement for processors to handle personal data in accordance with "locally, regionally and internationally recognized principles" when using personal data for AI training and emerging or innovative technologies. Processors must ensure that these technologies are used in a manner that does not cause harm to the data subject.' The compliance clock is real but its end date is nowhere STATED. The PDPL sets a formula, not a date: 'a grace period for compliance extending until one year after the date of the issuance of executive regulations supplementing the law.' The anchor is contested — the Regulations were 'publicly released on 25 December 2025' while 'The formal date of publication is 1 November 2025 (being the date of the official gazette in which the Regulations were circulated).' Baker McKenzie then only ANTICIPATES the result: 'Accordingly, we anticipate that the compliance grace period contemplated in the PDPL will extend until 1 November 2026.' LexAfrica computes 31 October 2026 from the same facts. Two credible firms differ by a day and one expressly hedges — that is proof the date is derived, not declared. No Egyptian regulator (the Personal Data Protection Centre) has published the deadline. Egypt's draft Artificial Intelligence Law remains in the parliamentary process and is not enacted; the National AI Strategy and AI ethics charter are non-binding.

Watching: A statement from Egypt's Personal Data Protection Centre or a ministerial decision fixing the exact end of the PDPL grace period (expected around 1 November 2026) — that would convert this into a dated row with the AI-training provision as its AI hook. Also: enactment of Egypt's draft AI Law.

Israeladvisory only

Checked for binding AI law and for Privacy Protection Authority AI instruments. Israel has NO AI statute and no binding AI instrument with a stated date. (1) 'Currently, there are no specific codified laws, statutory rules or regulations in Israel that directly regulate AI'; as of 2026 there is no Israeli AI Act and companies rely on a patchwork of existing law. (2) The joint Ministry of Innovation, Science and Technology / Ministry of Justice policy on 'Artificial Intelligence Regulation and Ethics' (2023, following a 2022 White Paper) is POLICY GUIDANCE, not binding law, and it deliberately favours soft regulation — sandboxes, pilots, standards and non-binding principles — plus a proposed AI Policy Coordination Centre to advise sectoral regulators. (3) The Privacy Protection Authority has published DRAFT guidelines on how the Privacy Protection Law applies to AI systems following Amendment 13; these were still draft, with finalisation and active enforcement only expected during 2026 — no adopted date. (4) Amendment 13 to the Privacy Protection Law did come into force in August 2025 and materially expanded PPA enforcement powers, but it is a general privacy amendment, not an AI instrument, and its operative text does not name AI.

Watching: The Privacy Protection Authority finalising its AI guidelines with a stated effective or enforcement date; or an Israeli AI bill reaching the Knesset with a commencement provision.

Qatarin force, no dated deadline

Checked the Qatar Central Bank 'Artificial Intelligence Guideline on Regulating the use of Artificial Intelligence by QCB Licensed Entities'. Qatar News Agency (official state agency) confirms it was issued on 4 September 2024 ('Doha, September 04 (QNA)'). Its obligations are written in mandatory terms for QCB-licensed entities (AI strategy, risk assessment, human oversight, AI register, approval for high-risk systems, customer transparency, disclosure of AI activity to QCB), so it is binding in substance. BUT no primary source — neither QNA nor the QCB itself — states a separate effective date, compliance deadline or transition period; the duty simply attached on issuance. QCB's own site (qcb.gov.qa) could not be fetched (TLS certificate error). Qatar has NO general AI statute: the National AI Strategy (2019) and the Cabinet Decision No. 10 (2021) AI Committee are strategy/institutional documents, not binding duties. Separately, the QICDRC Practice Direction No. 1 of 2026 IS dated and is recorded as a deadline row.

Watching: A QCB circular setting a dated compliance or attestation deadline for the AI Guideline; or a Qatari federal AI statute or Cabinet decision published in the Official Gazette with a stated in-force date.

Saudi Arabiaadvisory only

Checked every SDAIA instrument plus the Global AI Hub Law, SAMA and the PDPL. NO binding AI instrument with a stated date exists. (1) SDAIA AI Ethics Principles and the SDAIA AI Adoption Framework (v1 Sept 2024, v2 May 2025) are policy guidance — CMS's AI regulation scanner states plainly: 'These instruments are non-binding unless linked to other enforceable laws (e.g., PDPL)', and 'Saudi Arabia does not currently have an AI-specific law and has not announced any formal legislative process to enact one.' Secondary sites describing the Adoption Framework as a 'mandatory baseline' are not supported by any primary text; SDAIA's own PDF (sdaia.gov.sa) is behind a web filter and returns an access-denied page to automated fetching. (2) Global AI Hub Law: still a DRAFT. CST published it for public consultation on 14 April 2025, closing 14 May 2025; CMS confirms 'This draft law has not been enacted to date' and 'It remains a draft and is not yet in force.' It has NOT been published in Umm Al-Qura. Note also that despite its name it regulates data embassies and sovereign hosting, not AI systems. Its draft entry-into-force clause ('shall apply after sixty days from the date of its publication in the Official Gazette') is conditional on a publication date that does not yet exist — computing a date from it would be invention. (3) SDAIA draft Responsible AI Policy: consultation ran 3 April 2026 to 3 May 2026 and had not been adopted as binding as of reporting through July 2026. (4) SAMA has no dedicated AI rulebook chapter with a compliance date; AI expectations sit inside existing cybersecurity and data governance frameworks. (5) PDPL (Royal Decree M/19) does contain automated-decision provisions — a data subject right not to be subject to decisions based solely on automated processing, and mandatory DPIAs for automated decision-making under Article 25 of the Implementing Regulations — but the PDPL is a general data protection statute whose operative text does not name AI or ML, and its compliance date (end of the grace period, 14 September 2024) is a general privacy date, not an AI milestone. 2026 was declared the 'Year of Artificial Intelligence' by Cabinet on 10 March 2026 — a designation, not a duty.

Watching: Publication of the Global AI Hub Law in Umm Al-Qura (would start its stated 60-day clock and produce a real date); formal adoption of SDAIA's Responsible AI Policy as a binding instrument rather than a policy; or a SDAIA/SAMA circular imposing a dated AI compliance or registration obligation.

Türkiyepending

Checked the AI bills before the Grand National Assembly (TBMM), the KVKK's AI outputs, and the Resmî Gazete. NO binding AI instrument with a compliance date. (1) Legislation: at least three AI legislative proposals have been submitted to the TBMM and NONE has been enacted; the most recent was submitted on 23 July 2025 and remains under committee review. There is no adopted Turkish AI law. (2) The Türkiye Artificial Intelligence Action Plan (2026-2030) WAS published in the official gazette — Presidential Circular No. 2026/9, Resmî Gazete No. 33344 of 18 August 2026 — but it is a national action plan assigning coordination tasks to public institutions under the Ministry of Industry and Technology, not a compliance duty on regulated entities, so it is not a calendar row despite having a real gazette date. (3) KVKK (the Personal Data Protection Authority) has issued AI material in 2026 — a guidance document on 'Agentic Artificial Intelligence (Agentic AI)' published 15 April 2026, plus earlier 'AI Chatbots: Privacy and Security Guidelines' and recommendations on protecting personal data in AI. These are EXPLICITLY NOT BINDING: the agentic AI document 'is not a binding regulation under Law No. 6698 on the Protection of Personal Data, but represents the DPA's formal position on how existing data protection obligations apply'. No KVKK Board decision imposing a dated AI obligation was found.

Watching: Adoption of one of the TBMM AI bills and its publication in the Resmî Gazete with an in-force date; or a binding KVKK Board decision (ilke kararı) on AI carrying a compliance date.

United Arab Emirates — federal (incl. TDRA, ADGM)no dated obligation

Checked for federal AI legislation, TDRA rules and ADGM. NO binding federal AI instrument with a stated date exists. (1) There is no horizontal UAE AI statute: legal risk for AI is handled through Federal Decree-Law No. 45 of 2021 (PDPL) and sectoral rules. (2) On 14 June 2026 the UAE announced the creation of the Federal Authority for Artificial Intelligence and Data, consolidating AI oversight, digital government and data regulation under one body reporting to Cabinet — this CREATES A REGULATOR, it does not impose a dated duty on anyone, so it is not a calendar row. (3) The UAE AI Charter and the 'Deepfake Guide' published by the UAE National Programme for Artificial Intelligence (July 2021) are expressly ADVISORY — the Deepfake Guide is a non-binding awareness framework complementing existing cybercrime and data protection law. TDRA has issued no binding AI rule with a compliance date. (4) ADGM: the Data Protection Regulations 2021 were enacted 14 February 2021 and applied from 14 August 2021 (new entities) and 14 February 2022 (existing entities), and they do contain a right not to be subject to solely automated decision-making/profiling — but this is a GDPR-style general data protection regulation, not an AI instrument, its operative text does not name AI or machine learning, and its dates are general privacy commencement dates already long past. ADGM's official PDFs (assets.adgm.com and the Thomson Reuters mirror) return HTTP 403 to automated fetching, so the absence of AI wording is asserted from the regulation's structure and secondary summaries, not verified line by line. THE ONE REAL UAE ROW IS DIFC REGULATION 10, recorded separately. IMPORTANT: several sites (uaeahead.com, ailawguide.org, theleveragedyears.com, magureinc.com) assert DIFC Regulation 10 'reached full enforcement on 1 January 2026' — this is unsourced and contradicted by the primary text; do not carry it.

Watching: The new Federal Authority for Artificial Intelligence and Data issuing its first binding regulation or Cabinet Decision with an in-force date; a TDRA rule on synthetic media or deepfakes with a compliance date; or an ADGM AI-specific regulation comparable to DIFC Regulation 10.

Canada — British Columbiain force, no dated deadline

Checked 2026-08-30. British Columbia has NO AI statute and no AI regulation. The only province-wide AI instrument is the 'Policy on the use of generative AI' published by the Province on digital.gov.bc.ca, which is an internal conduct policy for BC Public Service employees, not legislation: 'This policy applies to all BC Public Service employees.' It uses mandatory language ('employees must log in using their IDIR', 'must not put any confidential information ... into publicly available gen AI tools like ChatGPT', 'must review the outputs to ensure they are factually accurate'), but it states only 'Last updated on May 9, 2025' — no commencement date, no compliance date, no transition period, and no penalty. It binds employees through the Standards of Conduct and Appropriate Use Policy, not through any dated legal obligation on organisations. BC's FOIPPA contains no automated-decision-making clause equivalent to Quebec s. 12.1 or Alberta POPA s. 5(2)(d).

Watching: A BC statute or FOIPPA amendment creating AI/automated decision duties, or a Treasury Board / Chief Information Officer directive with a stated compliance date. BC's independent oversight offices have publicly called for AI legislation, so a bill is the thing to watch.

Canada — Ontariono dated obligation

Enhancing Digital Security and Trust Act, 2024 (Schedule 1 to Bill 194, Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024, S.O. 2024, c. 24) contains real AI duties for public sector entities — s. 5 (inform the public about AI use, develop and implement an accountability framework, manage risks, comply with prescribed requirements, obey prohibited-use rules) and s. 6 (disclose AI use and ensure a human exercises oversight). But EVERY one of those duties is expressed as 'in accordance with the regulations' / 'as may be prescribed', and s. 5(1) only applies to 'such public sector entities as may be prescribed'. Checked 2026-08-30: the only regulations actually made under EDSTA are O. Reg. 51/26 (cyber security — contact point, biennial cyber maturity assessments, 72-hour incident reporting for hospitals, colleges and universities, school boards and children's aid societies) and O. Reg. 52/26 (digital technology affecting individuals under 18 — plain-language notice by school boards when student digital information is shared with third-party software). The Government of Ontario's own EDSTA page states these take effect 1 July 2026 and neither imposes any AI obligation; AI appears on that page only in the rationale ('address emerging risks from powerful technologies like artificial intelligence') and in a non-statutory internal 'Responsible Use of AI Directive' for ministries and provincial agencies. Bill text s. 17: 'The Act set out in this Schedule comes into force on a day to be named by proclamation of the Lieutenant Governor.' With no AI regulation prescribing entities or circumstances, no AI duty is triggered and no date attaches.

Watching: An Ontario regulation made under EDSTA s. 7 prescribing the public sector entities and circumstances for ss. 5-6, with its own effective date — that is what would create a dated AI obligation. Also watch for the Responsible Use of AI Directive being given statutory force.

Canada — federalpending

Bill C-34 (Safe Social Media Act — enacts the Digital Safety Act and the Digital Safety Commission of Canada Act) would impose a Duty to Protect Children on 'regulated services' expressly including AI chatbot services. LEGISinfo checked 2026-08-30: FIRST READING 2026-06-10, currently 'At second reading in the House of Commons', no further stages completed, NO royal assent. No commencement date stated anywhere in the bill's parliamentary record.

Watching: Royal assent, then the order in council / CIF provision setting the date the Digital Safety Act applies to AI chatbot services, plus the regulations the Digital Safety Commission must make before duties bite.

Dates come from instruments, never from arithmetic.A row exists only where an official text or the regulator states a calendar date. Where a law says “180 days after publication” and commentators do the sum, we keep it out and record it in the list above instead — third-party arithmetic is how wrong dates spread.

Every row is checked against the primary source. Each carries the instrument, a verbatim quote of the sentence that sets the date, a link to the text we opened, and the date we last verified it. Secondary sources are used to find the primary one, never to stand in for it.

Two layers. Statutory obligations are curated and re-checked. Open regulator consultations are refreshed daily from the U.S. Federal Register API, so comment windows never go stale here.

Limits. This is a calendar, not legal advice, and it does not tell you whether a given obligation applies to your business. Scope lines are compressed from the text and lose detail; follow the source link before acting. Spotted an error or a missing deadline? Tell us — a wrong date costs a reader more than a missing one.

Last verification pass: Aug 30, 2026.