AI Regulation Enforcement Deadlines: Global Tracker

    Every major AI regulation, enforcement date, and compliance obligation, filterable by region and industry. Updated monthly.

    Showing 21 of 21 regulations

    EUEffective Soon

    EU AI Act, High-Risk Provisions

    In Force August 2, 2026

    InsuranceHealthcareFinancial ServicesGovernment

    Requires conformity assessments, human oversight, audit trails, and technical documentation for AI systems in high-risk categories. Covered uses include credit decisions, insurance underwriting, employment, and healthcare.

    Learn more
    EUEffective Soon

    EU AI Act, General Purpose AI (GPAI) Rules

    In Force August 2, 2026

    All Industries

    Requires transparency disclosures and copyright compliance documentation from providers of general purpose AI models. Models above defined compute thresholds must also complete systemic risk assessments.

    Learn more
    USEnacted

    NAIC Model Bulletin on AI

    Adopted in 25+ states as of August 2026

    Insurance

    Requires insurers to maintain governance programs for AI and algorithmic tools used in underwriting, rating, and claims. Carriers must be able to demonstrate those programs to market conduct examiners.

    Learn more
    USIn Force

    Colorado SB 21-169 (AI in Insurance)

    In Force Since January 1, 2023

    Insurance

    Prohibits unfair discrimination in insurance through external consumer data sources and AI models. Requires annual certifications and documented governance of covered systems.

    Learn more
    USIn Force

    Texas AI Law (HB 1709)

    In Force Since January 1, 2026

    All Industries

    Requires developers and deployers of high-risk AI to conduct impact assessments before and during deployment. Consumers must receive transparency notices when AI materially influences a decision about them.

    Learn more
    EUIn Force

    EU AI Act, Prohibited AI Practices

    In Force Since February 2, 2025

    All Industries

    Bans a defined set of AI practices outright, including social scoring and manipulation of vulnerable groups. Real-time biometric surveillance in public spaces is prohibited outside narrow exemptions.

    Learn more
    USIn Force

    HIPAA and AI Guidance (HHS OCR)

    Ongoing enforcement, 2026 AI guidance issued

    Healthcare

    Extends HIPAA breach investigation scrutiny to AI systems that access, process, or generate protected health information. Covered entities must show how AI tooling is governed, logged, and access controlled.

    Learn more
    USEnacted

    NIST AI Risk Management Framework (AI RMF 1.0)

    Voluntary, referenced in federal procurement

    All Regulated Industries

    A lifecycle framework for identifying, measuring, and managing AI risk. It is increasingly written into federal contracts and state AI bills as the expected baseline.

    Learn more
    GlobalIn Force

    ISO 42001 (AI Management Systems Standard)

    Published December 2023, adoption accelerating 2025 to 2026

    All Industries

    A certifiable standard for AI management systems, the ISO 27001 equivalent for AI governance. Certification is becoming a procurement expectation for enterprise AI vendors.

    Learn more
    USIn Force

    SR 11-7 (Federal Reserve Model Risk Management)

    Ongoing

    Financial Services

    Requires banks to apply model risk management governance to all models used in decision-making, including AI and machine learning. Validation, documentation, and ongoing monitoring are examiner expectations.

    Learn more
    USProposed

    FDA AI Action Plan

    Post-market surveillance requirements expected 2026 to 2027

    Healthcare

    Signals mandatory continuous monitoring for AI-enabled medical devices after clearance. Manufacturers should expect formal post-market surveillance and change-control obligations.

    Learn more
    EUProposed

    EU AI Liability Directive

    Proposed, timeline TBD

    All Industries

    Would make it easier for individuals harmed by AI systems to seek compensation. It creates significant liability exposure for enterprises deploying AI in consumer-facing contexts.

    Learn more
    EUIn Force

    GDPR and AI

    Ongoing enforcement

    All Industries with EU data subjects

    GDPR's automated decision-making provisions under Article 22 apply directly to AI systems making decisions about individuals. Enforcement is active today and regulatory attention is increasing.

    Learn more
    USIn Force

    CCPA / CPRA (California)

    Ongoing

    All Industries with California consumers

    Automated decision-making technology rules under CPRA give consumers a right to opt out of profiling. Additional regulations are expected from the California Privacy Protection Agency.

    Learn more
    SingaporeProposed

    MAS Guidelines on AI Risk Management

    Consultation closed January 31, 2026, implementation expected 12 months after finalization

    Financial ServicesInsurance

    Issued by the Monetary Authority of Singapore for all MAS-regulated financial institutions. Requires formal AI governance frameworks, board accountability, lifecycle controls, third-party AI oversight, and documented AI risk management covering traditional AI, GenAI, and AI agents. Enforced through proportionate MAS supervisory action.

    Learn more
    SingaporeIn Force

    Singapore Model AI Governance Framework

    Agentic AI framework published January 2026, world's first agentic AI governance framework

    All Industries

    Voluntary IMDA and AI Verify Foundation framework in three generations: Traditional AI (2020), Generative AI (2024), and Agentic AI (2026). Covers content provenance, safety alignment, autonomous agents, cascading actions, and multi-agent coordination. Increasingly expected in enterprise contracts and audits; PDPA enforcement applies where personal data is involved.

    Learn more
    AustraliaIn Force

    APRA AI Risk Management Letter and CPS 230 Amendments

    CPS 230 amended provisions in force since July 1, 2026

    Financial ServicesInsurance

    APRA's April 30, 2026 letter calls for a step-change in AI governance across banks, insurers, and superannuation trustees. Expects formal AI governance frameworks, a full AI inventory, board accountability, human oversight of high-risk decisions, and third-party AI vendor management under CPS 230. The Financial Accountability Regime creates named individual liability for AI failures.

    Learn more
    South KoreaIn Force

    South Korea AI Basic Act

    In Force Since January 22, 2026

    HealthcareFinancial ServicesGovernment

    The world's second comprehensive AI law and the first in Asia-Pacific, overseen by the Ministry of Science and ICT. Sets risk-based obligations for High-Impact AI and Generative AI, including transparency, human oversight, impact assessments, and user protection. Applies extraterritorially to organizations serving Korean users, with penalties set by enforcement decrees.

    Learn more
    JapanIn Force

    Japan AI Promotion Act

    In Force Since September 1, 2025, METI/MIC AI Guidelines v1.2 published March 2026

    All Industries

    Japan's first dedicated AI law establishes the AI Strategic Headquarters under the Cabinet and a Basic Plan for AI. It carries no monetary penalties or mandatory conformity assessments; enforcement is through administrative guidance and public disclosure. The METI and MIC AI Guidelines for Business are the operative compliance benchmark in procurement.

    Learn more
    Hong Kong SARIn Force

    HKMA Generative AI Governance Guidance

    In force since 2024, GenAI Sandbox++ launched March 2026

    Financial ServicesInsurance

    Requires HKMA-regulated banks using customer-facing GenAI to keep a human in the loop, offer opt-outs, disclose purposes and limitations, and document the demographic impact of credit scoring algorithms. The March 2026 GenAI Sandbox++ extends supervised experimentation across HKMA, SFC, IA, and MPFA.

    Learn more
    IndiaEnacted

    India Digital Personal Data Protection Act (DPDP Act)

    Enacted August 2023, DPDP Rules finalization expected 2026

    All Industries with Indian users

    Governs personal data processing by AI systems handling data of Indian citizens, with consent requirements, data principal rights, and data fiduciary obligations. Rules expected in 2026 will add obligations around automated decision-making and children's data. Penalties reach INR 250 crore (about $30M USD) per violation.

    Learn more

    Get regulation updates in your inbox

    We update this tracker monthly. Subscribe to the Trussed AI newsletter for the latest AI regulation enforcement dates, industry analysis, and governance insights.