AI Compliance Academy
Know which AI rules apply to you — and level up
Plain-words lessons on the EU AI Act, US and Canadian rules and the standards, real enforcement cases, and a maturity check that tells you exactly what to fix first.
Educational content, not legal advice. Use it to ask better questions — a qualified lawyer answers the ones that matter for your case.
Your level
Your level
Take the 10-minute check
No account needed. Sign in afterwards to keep your history and track progress.
What changed recently
Key dates
Every deadline we track, by region. Passed dates are ticked; what is still ahead is in purple.
EU
Apr 27, 2016✓
Adopted by the European Parliament and Council
May 25, 2018✓
Applies across the EU and EEA
Aug 1, 2024✓
Entered into force
Feb 2, 2025✓
Prohibited practices (Art. 5) and AI-literacy duty (Art. 4) apply
Aug 2, 2025✓
General-purpose AI model obligations, governance and penalty rules apply
Jul 24, 2026✓
Published in the Official Journal
Jul 27, 2026✓
Digital Omnibus on AI (Reg. (EU) 2026/1744) in force: deadlines moved, new prohibitions added
Jul 27, 2026✓
Entered into force
Aug 2, 2026✓
Art. 50 transparency duties apply (chatbot disclosure, deepfake labelling); Commission may enforce against GPAI providers
- Today · Sep 25, 2026
Dec 2, 2026
End of marking grace period for generative systems already on the market; new bans on AI generating CSAM or non-consensual intimate imagery apply
Dec 2, 2026
New prohibitions (AI generating CSAM / non-consensual intimate imagery) apply; marking grace period for existing generative systems ends
Aug 2, 2027
National AI regulatory sandboxes must be operational (deferred from 2 Aug 2026)
Dec 2, 2027
Annex III high-risk obligations apply (hiring, credit, education, public services, etc.)
Dec 2, 2027
Annex III high-risk obligations apply (deferred from 2 Aug 2026)
Aug 2, 2028
Annex I high-risk obligations apply (AI embedded in regulated products)
Aug 2, 2028
Annex I high-risk obligations apply (deferred from 2 Aug 2027)
US
Jul 5, 2023✓
Enforcement began
Mar 13, 2024✓
SB 149 signed
May 1, 2024✓
In effect — first US state generative-AI disclosure law
May 17, 2024✓
Original Colorado AI Act (SB 24-205) signed
Sep 28, 2024✓
Signed by Governor Newsom
May 7, 2025✓
SB 226 / SB 332 amendments in effect: disclosure narrowed to on-request and 'high-risk' interactions; sunset extended
Jun 22, 2025✓
Signed by Governor Abbott
Aug 28, 2025✓
SB 24-205 start date delayed to 30 June 2026 (SB25B-004)
Oct 13, 2025✓
AB 853 signed: operative date moved from 1 Jan 2026 to 2 Aug 2026 and scope expanded
Dec 2, 2025✓
NY State Comptroller audit reported weak enforcement by DCWP
Dec 11, 2025✓
EO 14365 (federal preemption push)
Signed by the President
Dec 16, 2025✓
EO 14365 (federal preemption push)
Published in the Federal Register
Dec 19, 2025✓
Signed by Governor Hochul (with agreed chapter amendments)
Jan 1, 2026✓
In effect
Jan 1, 2026✓
In effect
Jan 1, 2026✓
In effect for generative AI systems released since 1 January 2022
Jan 9, 2026✓
EO 14365 (federal preemption push)
DOJ AI Litigation Task Force created to challenge state AI laws
Mar 11, 2026✓
EO 14365 (federal preemption push)
Deadline for Commerce to publish its evaluation of 'onerous' state AI laws (reported as missed at the time)
Mar 27, 2026✓
Chapter amendment signed — final text
May 14, 2026✓
SB 26-189 signed: repeals and replaces SB 24-205
May 15, 2026✓
IDHR published proposed notice rules (later temporarily withdrawn; statute still applies)
Jul 7, 2026✓
EO 14365 (federal preemption push)
FTC policy statement on 'suppression of accuracy' in AI systems published in the Federal Register (reported)
Aug 2, 2026✓
Operative: covered providers must offer detection tool and latent/manifest disclosures
- Today · Sep 25, 2026
Jan 1, 2027
Large online platforms must detect and display provenance data; hosting platforms may not knowingly offer non-compliant systems
Jan 1, 2027
SB 26-189 takes effect; AG rules due
Jan 1, 2027
Takes effect
Jul 1, 2027
Act sunsets unless renewed
Jan 1, 2028
Capture-device makers must enable provenance disclosures by default
Jan 1, 2030
60-day cure period sunsets
Canada
Nov 1, 2018✓
Mandatory breach reporting in force
Apr 1, 2019✓
Directive took effect for federal institutions
Jun 16, 2022✓
Bill C-27 introduced in the House of Commons
Sep 22, 2022✓
First phase in force (privacy officer, breach reporting)
Apr 25, 2023✓
Third-review amendments in force (scope extended to internal services such as hiring; AIA published before launch)
Sep 22, 2023✓
Automated-decision (s. 12.1), profiling notice (s. 8.1) and privacy impact assessment duties in force
Sep 27, 2023✓
Launched by Innovation, Science and Economic Development Canada
Mar 21, 2024✓
Ontario AI job-posting disclosure
Working for Workers Four Act, 2024 received Royal Assent
Apr 25, 2024✓
Existing systems had to comply with the amended Directive
May 27, 2024✓
Eight more organisations sign (30 signatories at the time)
Sep 22, 2024✓
Data-portability right in force
Jan 6, 2025✓
Parliament prorogued; Bill C-27 died on the Order Paper
Jan 1, 2026✓
Ontario AI job-posting disclosure
Job-posting rules in force (AI disclosure, pay ranges, vacancy status, record-keeping)
May 6, 2026✓
OPC and provincial regulators publish joint findings on OpenAI/ChatGPT (PIPEDA Findings #2026-002)
- Today · Sep 25, 2026
Standards
Jan 26, 2023✓
AI RMF 1.0 released
Dec 18, 2023✓
First edition published (December 2023)
Jul 26, 2024✓
Generative AI Profile (NIST AI 600-1) released
Apr 7, 2026✓
Concept note for a Critical Infrastructure profile released; AI RMF revision under way
- Today · Sep 25, 2026
Laws and standards
Every rule we track, in one line each. Open one for who it applies to, the dates, what you have to do and the penalties.
- EU AI ActIn force
European Union
The EU AI Act is the first comprehensive AI law. It bans a short list of practices (social scoring, manipulative systems, most real-time public biometric ID), imposes strict duties on 'high-risk' uses such as hiring and credit scoring, sets transparency rules for chatbots and synthetic media, and regulates general-purpose AI models. It applies in stages from 2025 to 2028. The 2026 Digital Omnibus pushed the high-risk deadlines back and softened the AI-literacy duty.
- EU AI Omnibus 2026In force
European Union
The Digital Omnibus on AI is the first amendment to the EU AI Act. Proposed in November 2025 and in force since 27 July 2026, it delays the high-risk obligations (Annex III to 2 December 2027, Annex I to 2 August 2028), gives generative systems already on the market until 2 December 2026 to add machine-readable marking, adds two prohibitions on AI that generates child sexual abuse material or non-consensual intimate imagery, replaces the AI-literacy article with a softer 'support' duty, and extends SME relief to small mid-caps.
- GDPRIn force
European Union
The GDPR is the EU's general privacy law and the one most often enforced against AI so far. Personal data needs a legal basis, transparency and purpose limits, whether it feeds model training, prompts or outputs. Article 22 gives people the right not to be subject to solely automated decisions with legal or similarly significant effects, and Article 35 requires a data protection impact assessment (DPIA) before high-risk processing such as profiling or large-scale monitoring.
- EO 14365 (federal preemption push)In force
United States (federal)
EO 14365 (11 December 2025) declares a federal policy of one 'minimally burdensome' national AI framework and targets the state-by-state patchwork. It creates a DOJ task force to sue states over conflicting AI laws, tells Commerce to list 'onerous' state laws, asks the FTC to say when state rules forcing AI to 'alter truthful outputs' are preempted, ties some broadband (BEAD) funding to state AI policy, and calls for preemption legislation. Child safety, data centres and state procurement are carved out. It creates no direct duties for businesses.
- Texas TRAIGAIn force
United States · Texas
TRAIGA took effect on 1 January 2026. Instead of a broad high-risk regime, it bans AI built or used with intent to manipulate people into self-harm or crime, to discriminate unlawfully, to run government social scoring or biometric identification, or to make sexual deepfakes and CSAM. Government agencies must tell people when they interact with AI; healthcare providers must disclose AI used in treatment. The Attorney General enforces it after a 60-day cure period, there is no private right of action, and following NIST's AI RMF is a defence.
- Illinois HB 3773In force
United States · Illinois
From 1 January 2026, Illinois employers may not use AI that has the effect of discriminating on the basis of a protected class in recruitment, hiring, promotion, training selection, discipline, discharge or terms of employment. Intent does not matter. Employers must notify applicants and employees when AI is used for those decisions and may not use zip codes as a proxy for protected classes. The Illinois Department of Human Rights proposed notice rules in May 2026 and then paused them, but the statutory duties apply regardless.
- California AB 2013In force
United States · California
From 1 January 2026, anyone who develops a generative AI system available to people in California must post a high-level summary of its training data on their website. The summary covers about a dozen points: dataset sources or owners, purpose, number and types of data points, whether copyrighted, licensed or personal information is included, cleaning steps, collection periods and synthetic data. It reaches back to systems released since January 2022, with narrow carve-outs for security, aviation and national-security systems. xAI has challenged the law in court.
- California SB 942In force
United States · California
Operative since 2 August 2026, the AI Transparency Act requires large generative AI providers (over one million monthly users, accessible in California) to give users a free public tool to check whether image, video or audio content was AI-generated, to embed a 'latent' machine-readable disclosure in all such outputs, and to offer an optional visible 'manifest' disclosure. Licensees of the system must keep those features or lose their licence. AB 853 delayed the original January 2026 start and added duties for large online platforms (2027) and capture devices (2028).
- Colorado ADMT ActUpcoming
United States · Colorado
Colorado repealed its landmark 2024 AI Act before it ever applied and replaced it with SB 26-189, effective 1 January 2027. The new law drops the duty-of-care and annual impact-assessment model and instead focuses on transparency: deployers must give notice before a covered ADMT influences a consequential decision, explain adverse decisions within 30 days, and let people correct data and request human review. Developers must give deployers documentation on intended use, training-data categories, limits and human-review instructions. The Attorney General enforces it exclusively.
- NYC Local Law 144In force
United States · New York (state)
Since 5 July 2023, NYC employers and employment agencies may not use an automated employment decision tool (AEDT) to screen candidates for hire or promotion unless the tool has had an independent bias audit within the past year, a summary of the audit is published on their website, and candidates are told at least 10 business days in advance that the tool will be used, what it assesses, and how to request an alternative process. The audit reports selection or scoring rates by sex and race/ethnicity.
- Utah AI Policy ActIn force
United States · Utah
Utah's AI Policy Act, in force since 1 May 2024, was the first US state generative-AI disclosure law. As amended in 2025, a business must clearly disclose that a person is interacting with generative AI when asked, and proactively in 'high-risk' interactions — those collecting sensitive data or giving financial, legal, medical or mental-health advice. Regulated professionals must disclose up front. Using AI is no defence to a consumer-protection breach. The Act created an Office of AI Policy and a sandbox and sunsets on 1 July 2027 unless renewed.
- NY RAISE ActUpcoming
United States · New York (state)
The RAISE Act, signed in December 2025 and finalised by chapter amendment in March 2026, applies from 1 January 2027 to 'large frontier developers' — companies with over $500 million in annual revenue that train models above 10^26 operations. They must publish a frontier AI safety framework, report critical safety incidents to a new office in the Department of Financial Services within 72 hours of determining one occurred, and submit periodic risk assessments. It follows California's SB 53 model and is enforced by the Attorney General.
- PIPEDA (Canada)In force
Canada (federal)
PIPEDA is Canada's federal private-sector privacy law. It has no AI-specific chapter, but its ten fair-information principles — accountability, identified purposes, consent, limited collection, limited use and retention, accuracy, safeguards, openness, access and challenge — apply to any AI that collects or uses personal data, from training on scraped data to automated decisions. The May 2026 joint findings on OpenAI confirmed that scraping personal data from the internet is not 'publicly available' information and needs a valid legal basis.
- AIDA / Bill C-27 (died)Repealed
Canada (federal)
AIDA was Canada's proposed federal AI law, tabled in June 2022 as part of Bill C-27 alongside a new privacy act. It would have imposed risk-assessment, mitigation, monitoring and record-keeping duties on 'high-impact' AI systems, with a new AI and Data Commissioner. The bill stalled in committee and died when Parliament was prorogued on 6 January 2025. Canada currently has no federal AI-specific statute; PIPEDA, provincial privacy laws, human-rights law and the voluntary generative-AI code fill the gap.
- Quebec Law 25In force
Canada · Quebec
Quebec's Law 25 modernised the province's private-sector privacy law with GDPR-style duties. Three rules matter most for AI. When a decision about a person is made exclusively by automated processing, you must tell them by the time of the decision and, on request, explain the information and main factors used, let them correct data and make representations to a human. When technology profiles, locates or identifies people, you must say so and offer to deactivate it. A privacy impact assessment is required for new systems handling personal information.
- Ontario AI job-posting disclosureIn force
Canada · Ontario
From 1 January 2026, Ontario employers with 25 or more employees must state in every publicly advertised job posting whether artificial intelligence is used to screen, assess or select applicants. The same law requires pay ranges, a statement on whether the posting is for an existing vacancy, no 'Canadian experience' requirements, follow-up with interviewed candidates within 45 days, and retention of postings and application forms for three years. 'AI' is defined broadly as a machine-based system that infers from inputs to produce predictions, recommendations or decisions.
- Canada TBS ADM DirectiveIn force
Canada (federal)
The Directive governs how federal departments use automated systems to make or support administrative decisions about people. Before launching a system, a department must complete and publish an Algorithmic Impact Assessment that scores the system into one of four impact levels; higher levels trigger peer review, human-in-the-loop decision-making, more testing and monitoring. Plain-language notices, explanations of decisions, bias testing and data-governance duties apply. The 2023 amendments extended it to internal services such as hiring and required the AIA to be published before launch.
- Canada GenAI Code of ConductVoluntary
Canada (federal)
Launched in September 2023 while AIDA was still before Parliament, the Code sets out six outcomes that signatories commit to for advanced generative AI: accountability, safety, fairness and equity, transparency, human oversight and monitoring, and validity and robustness. Developers commit to risk assessments, red-teaming, content provenance measures and publishing capabilities and limits; managers commit to monitoring after deployment. With AIDA dead, the Code is currently Canada's main federal statement of expected practice for generative AI, and ISED lists around 50 signatories.
- NIST AI RMFVoluntary
International standard
The NIST AI RMF is a free, voluntary US framework for managing AI risk across the lifecycle, built on four functions: Govern (policies and accountability), Map (context and risks), Measure (testing and metrics) and Manage (prioritising and responding). The 2024 Generative AI Profile adds about 200 suggested actions for twelve generative-AI risks such as confabulation, data privacy, provenance, bias and harmful content. It is the most common reference point in US state laws and contracts, and a practical starting point for SMBs that need a defensible programme.
- ISO/IEC 42001Voluntary
International standard
ISO/IEC 42001 is the first certifiable international standard for an AI management system (AIMS). Like ISO 27001 for security, it asks an organisation to set AI policy and objectives, assess AI risks and impacts, assign roles, control the AI lifecycle and suppliers, and improve continually, with an Annex A of controls. Certification involves a two-stage audit and annual surveillance. It does not make you legally compliant by itself, but it maps well onto EU AI Act quality-management and documentation duties and is increasingly requested in procurement.