Deadline tracker · reviewed 2026-09-21

Every date that matters, with a source

19 obligations across the EU, Poland, South Korea and the United States. Status reflects the Digital Omnibus (Regulation (EU) 2026/1744) and the state-law changes of 2026. Machine-readable copy at /deadlines.json.

In force applies now   Upcoming a fixed future date   Deferred postponed by legislation, still coming

Each obligation also has its own page, for example Article 50 transparency. The data is free to reuse with attribution.

Upcoming and deferred

DateObligationStatusWhoWhat and evidence
28 October 2026
in 36 days
KRiBSI inspections and fines begin
Poland · Ustawa o systemach sztucznej inteligencji
Upcoming Companies and public bodies operating in Poland KRiBSI may inspect on 7 days' notice, remotely by default, covering documentation, procedures, internal logs, cloud systems and contractor agreements, and may impose the AI Act fine tiers. For SMEs the cap is the lower of the fixed amount and the percentage of turnover.
Evidence: Inspection protocol, named contact, document index, trade-secret marking.
2 December 2026
in 71 days
Machine-readable marking of generative AI output
EU · EU AI Act as amended by Reg. 2026/1744
Upcoming Providers of generative AI systems and, in practice, companies publishing generated content New obligation introduced by the Digital Omnibus: generated output must carry machine-readable marking. The same package bans generating non-consensual intimate imagery and child sexual abuse material, with penalties up to €35M or 7% of global turnover.
Evidence: Marking mechanism in place for every generative system in the inventory.
1 January 2027
in 101 days
Colorado ADMT duties begin
US, Colorado · SB 26-189 (Automated Decision-Making Technology)
Upcoming Developers and deployers of automated decision-making technology affecting Colorado consumers Replaces the 2024 Colorado AI Act. Requires pre-use consumer notices, an explanation within 30 days of an adverse outcome, meaningful human review rights and developer documentation. The earlier risk-management-programme and impact-assessment duties were removed.
Evidence: Pre-use notice texts, adverse-outcome explanation procedure, human review process.
1 January 2027
in 101 days
ADMT significant-decision obligations
US, California · CPPA automated decision-making regulations
Upcoming Businesses under the CCPA using automated decision-making for significant decisions about consumers Notices, opt-out and access rights around automated decisions with significant effects.
Evidence: ADMT notice, opt-out process, risk assessment where required.
1 January 2027
in 101 days
Provenance duties extend to large online platforms
US, California · AB 853
Upcoming Large online platforms (2027) and capture-device manufacturers (2028) Extends SB 942 obligations to platforms from 1 January 2027 and to capture devices from 1 January 2028.
Evidence: Platform provenance handling (platforms only).
22 January 2027
in 122 days
End of the one-year grace period for fines (expected)
South Korea · AI Basic Act
Upcoming All businesses in scope of the Act The grace period on administrative fines runs at least one year from 22 January 2026. Treat this date as the earliest point at which routine fines start.
Evidence: All generative-AI notices and high-impact assessments complete.
2 December 2027
in 436 days
High-risk obligations for stand-alone systems (Annex III)
EU · EU AI Act as amended by Reg. 2026/1744
Deferred Providers and deployers of high-risk AI in employment, education, credit, essential services, law enforcement, migration and justice Risk management, data governance, technical documentation, logging, human oversight, conformity assessment and registration. Deferred from 2 August 2026 by the Digital Omnibus.
Evidence: Risk classification record, impact assessment, vendor documentation, oversight design.
2 August 2028
in 680 days
High-risk obligations for AI in regulated products (Annex I)
EU · EU AI Act as amended by Reg. 2026/1744
Deferred AI embedded in products under EU product law (machinery, medical devices, vehicles and similar) Deferred from 2 August 2027 by the Digital Omnibus.
Evidence: Product conformity files updated for AI components.

Already in force

DateObligationStatusWhoWhat and evidence
1 May 2024
874 days ago
AI disclosure duties in Utah
US, Utah · Utah AI Policy Act (SB 149, narrowed 2025)
In force Businesses using generative AI with Utah consumers, with stricter duties in regulated professions Disclose the use of generative AI on request in consumer interactions and proactively in regulated professions.
Evidence: Disclosure texts, script for staff answering 'am I talking to AI?'.
2 February 2025
597 days ago
AI literacy duty, Article 4
EU · EU AI Act (Reg. 2024/1689)
In force Providers and deployers of AI systems Take measures, to your best extent, so that staff and others operating AI on your behalf have sufficient AI literacy. The Digital Omnibus (July 2026) clarified that no specific level must be guaranteed. The duty itself was kept.
Evidence: Training register, training programme, validation of learning outcomes, written AI usage rules.
2 August 2025
416 days ago
General-purpose AI model obligations
EU · EU AI Act (Reg. 2024/1689)
In force Providers of general-purpose AI models only Technical documentation, copyright policy and a training-data summary for model providers, with extra duties for models with systemic risk. Companies that only use AI tools are not in scope.
Evidence: Not applicable to deployers.
1 January 2026
264 days ago
TRAIGA in force
US, Texas · Texas Responsible AI Governance Act (HB 149)
In force Developers and deployers of AI in Texas; state agencies Bans intentional development or deployment of AI that incites self-harm or crime, AI-generated child sexual abuse material, non-consensual deepfake pornography and government social scoring. Rules for state-government AI.
Evidence: Acceptable-use policy prohibiting the banned uses.
1 January 2026
264 days ago
Generative AI training-data documentation
US, California · AB 2013 (training data transparency)
In force Developers of generative AI systems made available to Californians Developers must publish documentation about the datasets used to train their generative AI.
Evidence: Published training-data summary (developers only).
22 January 2026
243 days ago
AI Basic Act in force
South Korea · AI Basic Act
In force Domestic and foreign AI developers and businesses using AI in products; foreign firms above revenue or user thresholds must appoint a Korean representative Generative AI providers must notify users that AI is used and label AI-generated content, with clear notice where generated audio, image or video is hard to tell from real. One-year grace period before administrative fines, except serious cases.
Evidence: User notices and labels on generative outputs, domestic representative if thresholds met.
27 March 2026
179 days ago
Frontier-model developer duties
US, New York · RAISE Act (as amended 27 March 2026)
In force Developers of frontier AI models only Transparency and reporting on training, deployment, safety protocols and incidents for frontier developers. Not relevant to companies that only use AI.
Evidence: Not applicable to deployers.
21 July 2026
63 days ago
High-impact AI obligations activated
South Korea · AI Basic Act
In force Operators of high-impact AI (healthcare, energy, transport, hiring, biometric analysis and similar) Impact assessment on fundamental rights before deployment, meaningful explanation of outcomes, human oversight, a user protection plan and documentation. Fines up to KRW 30 million for notification failures, missing representative or refusing inspection.
Evidence: Impact assessment record, oversight design, user protection plan.
2 August 2026
51 days ago
Transparency obligations, Article 50
EU · EU AI Act (Reg. 2024/1689)
In force Providers of AI that talks to people or generates content; deployers of emotion recognition, biometric categorisation, deepfakes and AI-written public-interest text Chatbots must disclose they are AI unless obvious. Generated audio, image, video and text must be marked as artificial in a machine-readable way. Deepfakes and AI-generated public-interest text must be disclosed. Disclosure must be clear and given at the latest at first interaction. Not deferred by the Omnibus.
Evidence: Disclosure texts in place, marking mechanism documented, transparency checklist completed per system.
2 August 2026
51 days ago
Provenance and detection tools for large generative AI providers
US, California · SB 942 (AI Transparency Act)
In force Providers of generative image, video or audio tools with more than 1 million monthly users Offer AI detection tools, watermark options and disclosures for AI-generated content. Delayed from 1 January 2026 to 2 August 2026.
Evidence: Provenance features and disclosure options (large providers only).
11 August 2026
42 days ago
Polish AI Systems Act, main provisions in force
Poland · Ustawa o systemach sztucznej inteligencji
In force Companies and public bodies operating in Poland National law implementing the EU AI Act. Creates KRiBSI (Komisja Rozwoju i Bezpieczeństwa Sztucznej Inteligencji) as supervisor, a binding individual-opinion procedure (150 PLN fee, 30 to 60 days) and a regulatory sandbox that is free for SMEs.
Evidence: Register of AI systems, assigned roles, AI usage policy, vendor commitments.

How to use this

  1. Run the readiness scan to see which rows apply to you.
  2. Copy the applicable rows into your AI inventory as the jurisdictions and obligations columns.
  3. Assign an owner and a review date to each row. The Compliance Kit includes the jurisdiction-mapping spreadsheet with all rows pre-filled.