Every dated AI compliance obligation we track across the EU, UK, and US, on one page. 17 obligations: 6 already in force, 11 still ahead. Every row links its primary source.

This page is maintained. Dates move — the EU’s Digital Omnibus already shifted several high-risk deadlines into 2027 and 2028 — and it is updated as they do. Last updated 2026-08-12.

In force now

These are live. Non-compliance is exposure today, not a future project.

Date

Where

What you must do

2026-01-01
in force

US-TX

TRAIGA (HB 149)
In force. Developers and deployers doing business in Texas must meet the Act's intent-based prohibitions and disclosure duties.
Who: Any company developing or deploying AI systems in Texas or serving Texas residents.

2026-01-01
in force

US-IL

Illinois Human Rights Act amendment (HB 3773)
In force. Employers may not use AI that discriminates on a protected basis, and must notify applicants and employees when AI is used in employment decisions.
Who: Employers using AI in recruiting, hiring, promotion, discipline, discharge, or training selection in Illinois.

2026-01-01
in force

US-CA

Transparency in Frontier AI Act (SB 53)
In force. Frontier model developers must publish safety protocols, report critical safety incidents, and maintain whistleblower protections.
Who: Developers of frontier AI models above the statutory compute/revenue thresholds.

2026-01-01
in force

US-CA

CCPA regulations — risk assessments
In force. Conduct a risk assessment BEFORE initiating any covered processing, including using automated decision-making technology for a significant decision or training ADMT on personal information.
Who: CCPA-covered businesses processing California residents' personal information with ADMT.

2026-08-02
in force

EU

AI Act — Article 50, penalties, GPAI enforcement
In force. Transparency duties apply (label AI interaction, mark synthetic content, disclose deepfakes), the penalty regime applies, and the AI Office can demand information, evaluate models, order mitigations, and fine GPAI providers.
Who: Providers and deployers of AI that interacts with people or generates synthetic content, and all GPAI model providers.

2026-08-02
in force

US-CA

California AI Transparency Act (SB 942)
Operative now. Covered generative AI providers must offer a free AI-detection tool and apply latent and manifest disclosures to AI-generated content.
Who: Generative AI system providers with over 1,000,000 monthly users accessible in California.

Next 120 days

If any of these are news to you, start here.

Date

Where

What you must do

2026-12-02
112 days

EU

AI Act — Article 50 marking, systems already on the market
AI systems placed on the market before 2 August 2026 must comply with the machine-readable marking obligations from this date. This is the grace period for existing products, and it is the next hard EU deadline.
Who: Providers of generative or content-altering AI systems that were already on the EU market before August 2026.

Further out

Date

Where

What you must do

2027-01-01
142 days

US-CA

California AI Transparency Act (SB 942) — platform duties
Large online platforms must detect provenance data on uploaded content and label it as AI-generated where the data is present.
Who: Large online platforms distributing user-uploaded content to California users.

2027-01-01
142 days

US-CO

Colorado Automated Decision-Making Technology Act (SB 26-189)
Replacement for the repealed Colorado AI Act. Give consumers notice of ADMT use in consequential decisions, explain adverse outcomes, provide meaningful human review, and keep developer documentation. Enforcement is reportedly on hold pending a federal lawsuit — verify status before relying on the pause.
Who: Developers and deployers of ADMT that materially influences consequential decisions about Colorado residents.
Status: uncertain — verify before relying on this date.

2027-01-01
142 days

US-CA

CCPA regulations — ADMT compliance
Businesses already using ADMT for significant decisions must be fully compliant by this date; anyone starting after it must comply from day one.
Who: CCPA-covered businesses using automated decision-making for significant decisions about California residents.

2027-04-01
232 days

US-CA

CCPA regulations — ADMT consumer rights
Serve pre-use notices, honor opt-outs, answer access requests about ADMT logic and outcomes, and allow appeals of automated significant decisions.
Who: CCPA-covered businesses using ADMT for significant decisions.

2027-07-01
323 days

US-UT

Utah AI Policy Act (extended by SB 332)
Watch item, not an obligation: the Act's sunset was pushed out two years, so its generative-AI disclosure duties run until roughly this point unless extended again.
Who: Suppliers using generative AI in regulated occupations and high-risk consumer interactions in Utah.
Status: uncertain — verify before relying on this date.

2027-08-02
355 days

EU

AI Act — Article 111(3), legacy GPAI models
GPAI models placed on the market before 2 August 2025 must be brought into full compliance with the GPAI obligations by this date.
Who: Providers of general-purpose AI models released before August 2025.

2027-12-02
477 days

EU

AI Act — Annex III high-risk systems (as amended by the Digital Omnibus)
Deferred from 2 August 2026. Stand-alone high-risk systems — hiring, credit scoring, biometrics, education, essential services — must meet the full high-risk regime: risk management, data governance, technical documentation, logging, human oversight, conformity assessment, registration.
Who: Providers and deployers of Annex III high-risk AI systems in the EU.

2028-04-01
598 days

US-CA

CCPA regulations — risk assessment filing
Submit risk-assessment documentation covering the prior period to the California Privacy Protection Agency.
Who: CCPA-covered businesses that conducted mandatory risk assessments.

2028-08-02
721 days

EU

AI Act — Annex I high-risk AI in regulated products (as amended)
Deferred from 2 August 2027. AI embedded in products already covered by EU product-safety law — medical devices, machinery, toys, vehicles — must meet the high-risk regime through the existing sectoral conformity assessment.
Who: Manufacturers of regulated products that embed AI as a safety component.

2030-12-31
1602 days

EU

AI Act — Article 111(1), large-scale IT systems
AI systems that are components of the large-scale EU IT systems listed in Annex X and were placed on the market before 2 August 2027 must be brought into compliance.
Who: Operators of Annex X large-scale EU information systems.

How this list is maintained

Each entry is checked against a primary source — the regulation, the regulator, or an official guidance document — before it appears here, and anything that could not be fully verified is marked rather than quietly presented as settled. The same dataset drives the Deadline Radar in every issue of the brief, so the two can never disagree.

Not legal advice. This is a reading of public sources compiled so you can act on them; verify against the primary text linked on each row before you rely on it. Compiled and maintained with an AI pipeline, human-reviewed.