Free tool

AI Regulation Deadline Tracker

Every dated AI obligation that lands on a product team, EU and US, with the primary source one click from each entry — verified against source and re-checked monthly, so you can plan on it.

Jurisdiction

Status

13 obligations

5 Jul 2023

In forceNew York City

Annual independent bias audit for automated employment tools

Local Law 144

Who it lands on
Employers and employment agencies using automated tools in hiring or promotion decisions in New York City.
What it requires
An annual bias audit by an independent auditor, published summary of results, and candidate notice.
Exposure
$500-1,500 per day, per violation.

The New York State Comptroller published a critical review of enforcement in December 2025. Expect tightening rather than relaxation.

NYC Department of Consumer and Worker Protection

1 Jan 2026

In forceTexas

Texas Responsible AI Governance Act in force

TRAIGA (HB 149)

Who it lands on
Government agencies, healthcare providers and their vendors, and anyone deploying AI toward Texas consumers.
What it requires
Disclosure that a consumer is interacting with AI, prohibited-use compliance, and a documented governance posture.
Exposure
Curable violations $10-12K each; uncurable $80-200K; continuing violations $2-40K per day.

Alignment with NIST AI RMF or another recognised framework is treated as a safe harbour. That makes an RMF-aligned risk assessment worth more here than the paperwork alone suggests.

Texas Legislature — HB 149

1 Jan 2026

In forceCalifornia

Training data disclosure

AB 2013

Who it lands on
Developers of generative AI systems made available to Californians.
What it requires
A published, documented summary of the datasets used to train the system.
California Legislative Information — AB 2013

1 Jan 2026

In forceCalifornia

Frontier model transparency and safety reporting

SB 53 (TFAIA)

Who it lands on
Frontier developers above the compute threshold, with the heavier obligations attaching above a large revenue threshold.
What it requires
Published safety framework, incident reporting, and transparency reporting.

Almost certainly not you. It is on this list so you can rule it out quickly rather than worry about it.

California Legislative Information — SB 53

14 May 2026

RepealedColorado

Prior Colorado AI Act repealed before it ever took effect

SB 24-205, repealed by SB 26-189

Who it lands on
Teams that built compliance programmes against SB 24-205's high-risk framework.
What it requires
Nothing, as of the repeal date. The duty-of-care standard, annual impact assessments, and risk-management programmes were all eliminated with the statute that required them. What survives is the narrower notice, explanation, and human-review regime in the row above.

Kept on this list deliberately: a repealed law is easy to keep preparing for by accident. Work already done against the old framework is not wasted — inventory and data-flow mapping carry straight over — but impact-assessment templates can be retired.

Colorado General Assembly — SB 24-205

2 Aug 2026

In forceEU

Transparency obligations applicable

EU AI Act, Article 50 — Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744

Who it lands on
Providers and deployers of systems that interact with people or generate synthetic content, selling into the EU.
What it requires
Disclosure at the interaction boundary, marking of synthetic content in a machine-readable form, and records that show both are actually happening.

The transparency duties themselves were left untouched by the AI Omnibus; the only change was the marking grace period below.

EUR-Lex — EU AI Act (Regulation 2024/1689)

2 Aug 2026

In forceCalifornia

California AI Transparency Act — provenance obligations

SB 942 (as amended by AB 853)

Who it lands on
Large generative AI providers serving California users.
What it requires
Provenance disclosure and content marking on generated output, plus a detection path.
California Legislative Information — SB 942

1 Sep 2026

UpcomingTexas

Attorney General complaint portal required

TRAIGA (HB 149)

Who it lands on
Everyone in scope of TRAIGA, indirectly.
What it requires
Nothing directly. It matters because a public complaint channel is what turns a statute on the books into enforcement activity, and it is the clearest forcing function on this list.
Texas Legislature — HB 149

Q4, annually

UpcomingMarket

Policy renewal questionnaires ask about AI and agent controls

Cyber insurance renewal cycle

Who it lands on
Anyone renewing a cyber policy who runs agents in production.
What it requires
Not a legal obligation — a commercial one. Renewal questionnaires increasingly ask whether an AI risk assessment has been completed in the last twelve months, and whether agent identity and least-privilege are enforced. The answer affects the premium and, occasionally, the coverage.

The evidence for this is drawn largely from enterprise and mid-market carriers. Whether it has reached Series B and C portfolios is not established — treat it as a trend to check with your broker, not a fact about your policy.

See the insurability scorecard

2 Dec 2026

UpcomingEU

Content-marking grace period ends for legacy systems

Regulation (EU) 2026/1744 — the AI Omnibus, amending Article 50(2)

Who it lands on
Systems already in service before the transparency obligations became applicable.
What it requires
The marking mechanics that new systems already needed, retrofitted onto the deployed estate. This is the one that is usually underestimated: retrofitting provenance into an existing generation path is engineering work, not a policy update.

Adopted June 2026 and in force since 27 July 2026. The grace covers only the Article 50(2) marking duty for pre-August systems — every other transparency obligation applied on schedule in August.

EUR-Lex — Regulation (EU) 2026/1744

1 Jan 2027

UpcomingColorado

Colorado AI Act replacement takes effect

SB 26-189

Who it lands on
Deployers of systems making consequential decisions about Colorado residents.
What it requires
Pre-use notice, notice within 30 days of an adverse decision, a human review path, and three years of records.
Exposure
Up to $20K per violation.

The Attorney General has said enforcement waits until implementing rules exist, and litigation against the predecessor statute is still technically live. Prepare for the shape, not the wording.

Colorado General Assembly — SB 26-189

2 Dec 2027

UpcomingEU

High-risk obligations apply to Annex III systems

EU AI Act, Annex III

Who it lands on
Systems in the listed high-risk categories: employment, credit, essential services, education, and the rest of the Annex III list.
What it requires
Risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness measures, and conformity assessment.

This date moved once already. It is the deadline most people plan around and the one least safe to treat as fixed — in either direction.

EUR-Lex — EU AI Act

2 Aug 2028

UpcomingEU

High-risk obligations apply to Annex I systems

EU AI Act, Annex I

Who it lands on
AI embedded in products already covered by EU product-safety legislation.
What it requires
The high-risk regime, routed through the existing sectoral conformity assessment rather than a standalone one.
EUR-Lex — EU AI Act

Runs entirely in your browser. Nothing you type here is transmitted, logged, or stored anywhere. There is no server-side copy because there is no transmission. Close the tab and it is gone.

How this works, and what it does not cover

This list covers obligations that reach a team building or deploying AI products. It does not cover sector-specific supervision, employment law generally, or anything that applies to you only because of what industry you are in.

Every row names the instrument and links to primary source — EUR-Lex, the state legislature, or the agency. Secondary commentary is not treated as a source. Where enforcement is paused, litigated, or merely expected, the row says so rather than implying certainty that does not exist.

European AI policy has already moved one of these dates once, and state legislatures move faster than that. If you are making a decision with money attached, open the source link.

This is a technical reading of what each obligation requires in engineering terms. It is not legal advice — for applicability questions, counsel has the final word, and the primary-source links are there to make those conversations faster.

Verified against source on August 24, 2026.

An email when a date on this list moves, and nothing else. European AI policy is volatile by design; the tracker gets corrected when it changes.

No cookies, no tracking pixels, never shared or sold. How the data is handled.

If you would rather not do this yourself

AI Compliance Package — EU Article 50 plus US module

Three weeks: the transparency and marking controls the regulation asks for, running in production, plus the optional US state module.

3 weeks · $15-25K
All free tools