AI Compliance Deadlines: What Applies, When, and to Whom

A company running a customer chatbot in Germany crossed a real line on 2 August 2026. A company training frontier models in California crossed one on 1 January 2026. A company doing neither may have no AI-specific deadline at all this year, and the honest answer for them is: none of this binds you yet.

This page keeps the dates in one place.

Last reviewed: 17 September 2026.

This page is maintained as a living reference. It is reviewed monthly and updated when a significant regulatory event occurs — an amendment, a court decision, a delayed applicability date, or new implementing guidance. Every row in the master table carries its own Last verified date.

Regulatory dates change, and several in this table already have. Verify the linked primary source before making a compliance decision.

This tracker is provided for informational purposes and is not legal advice. Regulatory requirements can depend on an organization’s jurisdiction, role, system, sector, and specific facts. Always verify the current primary-source text and applicable guidance before making compliance decisions.

Key Takeaways
  • The EU AI Act’s biggest deadline moved, and most people have the wrong date. Regulation (EU) 2026/1744 — the Digital Omnibus on AI — entered into force on 27 July 2026 and pushed standalone high-risk obligations from 2 August 2026 to 2 December 2027, and embedded high-risk systems to 2 August 2028.
  • 2 August 2026 still landed. Article 50 transparency duties, general application of the Act, and the AI Office’s enforcement powers over GPAI model providers all took effect as originally scheduled. Only Chapter III moved.
  • Two new EU prohibitions arrive on 2 December 2026, covering AI systems that generate non-consensual intimate material or child sexual abuse material. They sit in the Article 5 tier, with fines up to €35 million or 7% of worldwide turnover.
  • Colorado’s AI Act never took effect. SB 24-205 was repealed by SB 26-189, signed 14 May 2026. A narrower automated decision-making regime applies from 1 January 2027.
  • The United States has no federal AI statute. Executive Order 14365 directs agencies to challenge state AI laws, but no federal law or court has preempted any of them. State requirements remain enforceable.
  • 1 January 2027 is the densest date on the calendar: Colorado’s ADMT Act, New York’s RAISE Act, Illinois SB 315 and California’s CPPA ADMT compliance date all land together.
  • Most obligations bind providers and developers, not deployers — but Article 50, Connecticut’s employment provisions and Colorado’s notice duties all reach the organisation using the system.

Quick Navigation


The AI Compliance Deadline Calendar

This is the reference table. It covers enacted, operative instruments with firm dates. Rows are chronological. “Status” describes the legal position as of the last review date, not a judgement about severity.

DateJurisdictionRegulation / RuleWhat changesWho it applies toWhat is actually requiredStatusLast verified
1 Aug 2024EUAI Act, Reg. (EU) 2024/1689Entry into force — no obligations attachNothing yet; starts the Art. 113 clockIn force17 Sep 2026
2 Feb 2025EUAI Act Arts. 4, 5Prohibited practices; AI literacyProviders, deployersCease prohibited uses; take measures supporting AI literacyApplicable17 Sep 2026
2 Aug 2025EUAI Act Ch. V, VII, XIIGPAI obligations; governance; penaltiesGPAI model providersTechnical documentation, downstream information, copyright policy, training-content summary; systemic-risk models add evaluation, adversarial testing, incident reporting, cybersecurityApplicable17 Sep 2026
1 Sep 2025ChinaAI content labelling measuresLabelling of AI-generated contentService providers in ChinaExplicit and implicit labelling of synthetic contentIn force17 Sep 2026
1 Jan 2026US — CaliforniaSB 53 (TFAIA)Frontier model transparencyFrontier / large frontier developersPublish frontier AI framework and transparency reports; report critical safety incidents; whistleblower protectionsIn force17 Sep 2026
1 Jan 2026US — CaliforniaAB 2013Training-data transparencyDevelopers of generative AI systems offered to CaliforniansPublish high-level training-data documentationIn force17 Sep 2026
1 Jan 2026US — CaliforniaCPPA regulationsADMT, risk assessment and cybersecurity audit rules effectiveCCPA-covered businessesProspective risk-assessment duties begin; ADMT duties phased (see 2027)In force17 Sep 2026
1 Jan 2026US — TexasTRAIGA (HB 149)Comprehensive AI governance regimeDevelopers and deployers in TexasProhibited-use restrictions; disclosure duties; AG enforcement with civil penaltiesIn force17 Sep 2026
1 Jan 2026US — IllinoisHB 3773AI in employment decisionsEmployersNon-discrimination and notice duties under the Human Rights ActIn force17 Sep 2026
22 Jan 2026South KoreaAI Basic / Framework Act + Enforcement DecreeComprehensive national AI frameworkOperators serving Korean users, incl. foreignAdvance user notice for generative and high-impact AI; labelling; risk management for high-impact AI; domestic representative where triggeredIn force (transitional enforcement grace)17 Sep 2026
19 May 2026US — FederalTAKE IT DOWN Act, §3Notice-and-removal duties enforceableCovered platforms hosting user-generated contentClear removal process; remove valid NCII reports and known identical copies within 48 hoursIn force; FTC enforcing17 Sep 2026
27 Jul 2026EUDigital Omnibus on AI, Reg. (EU) 2026/1744Amends the AI Act; defers high-risk datesAmendments become part of the AI ActIn force17 Sep 2026
2 Aug 2026EUAI Act Art. 50; general applicationTransparency duties; AI Office enforcement powers liveProviders and deployers of interactive / synthetic-content systems; GPAI model providersDisclose AI interaction; mark synthetic output machine-readably; label deepfakes; GPAI enforcement now activeApplicable17 Sep 2026
2 Aug 2026US — CaliforniaSB 942 as amended by AB 853Covered provider obligations operativeGenerative AI providers >1M monthly usersFree AI detection tool; optional manifest disclosure; latent disclosure in image, video, audio; flow-down to licenseesIn force17 Sep 2026
1 Oct 2026US — ConnecticutSB 5 (CART Act), P.A. 26-15First tranche of AI dutiesEmployers; AEDT developers; large synthetic-media providers; frontier developersAEDT anti-discrimination and developer-to-deployer documentation; provenance for 1M+ user providers; subscription disclosures; WARN notice AI disclosure; whistleblower protectionsUpcoming17 Sep 2026
2 Dec 2026EUAI Act Art. 5(1)(ba),(bb) via Reg. 2026/1744Two new prohibitionsProviders and deployersNo placing on market, putting into service, or use of AI generating or manipulating non-consensual intimate material or CSAMUpcoming17 Sep 2026
2 Dec 2026EUAI Act Art. 50(2) / Art. 111(4)Legacy marking grace period endsProviders of generative systems on the market before 2 Aug 2026Machine-readable marking of synthetic outputUpcoming17 Sep 2026
1 Jan 2027US — ColoradoSB 26-189 (ADMT Act)Replaces repealed SB 24-205Developers and deployers of covered ADMTDeveloper technical documentation and update notices; deployer point-of-interaction notice; 30-day adverse-outcome explanation; access, correction and human-review rights; 3-year recordsUpcoming17 Sep 2026
1 Jan 2027US — New YorkRAISE Act (as amended 27 Mar 2026)Frontier model safety regimeLarge frontier developersSafety protocol publication; incident reporting; AG enforcementUpcoming17 Sep 2026
1 Jan 2027US — IllinoisSB 315 (AI Safety Measures Act)Frontier AI safety regime takes effectFrontier developers (revenue-tiered)Disclosure and whistleblower duties from this date; framework and audit duties from 1 Jan 2028Upcoming17 Sep 2026
1 Jan 2027US — CaliforniaCPPA ADMT provisionsADMT compliance dateCCPA-covered businesses using ADMT for significant decisionsPre-use notice, opt-out, access to decision logic; pre-2027 systems must be brought into complianceUpcoming17 Sep 2026
1 Jan 2027US — CaliforniaSB 942 / AB 853 tranche 2Platform duties beginGenerative AI hosting platforms; large online platformsEnsure downloadable systems carry disclosures; detect and surface provenance dataUpcoming17 Sep 2026
2 Aug 2027EUAI Act Art. 111Legacy GPAI compliance dateProviders of GPAI models on the market before 2 Aug 2025Bring pre-existing models into Chapter V complianceUpcoming17 Sep 2026
2 Aug 2027EUAI Act Art. 57 via Reg. 2026/1744Sandbox obligation deferred to this dateMember StatesAt least one national AI regulatory sandbox operationalUpcoming17 Sep 2026
1 Oct 2027US — ConnecticutSB 5 (CART Act)AEDT deployer duties operativeEmployers using AEDTPre-decision notice and disclosure to applicants and employeesUpcoming17 Sep 2026
2 Dec 2027EUAI Act Ch. III, Annex IIIStandalone high-risk obligations applyProviders, deployers, importers, distributors of Annex III systemsConformity assessment, QMS, technical documentation, logging, human oversight, CE marking, EU database registration, FRIA where applicableUpcoming (deferred from 2 Aug 2026)17 Sep 2026
1 Jan 2028US — IllinoisSB 315Framework and audit duties beginLarge frontier developersPublished catastrophic-risk framework; annual independent third-party auditUpcoming17 Sep 2026
2 Aug 2028EUAI Act Art. 6(1), Annex IEmbedded high-risk obligations applyProduct manufacturers and providers under Annex I legislationHigh-risk requirements for AI in regulated productsUpcoming (deferred from 2 Aug 2027)17 Sep 2026

The rest of this page explains the rows that need explaining.


EU AI Act Compliance Deadlines

The single most common error in EU AI Act compliance planning is treating entry into force as a deadline. It is not.

Regulation (EU) 2024/1689 entered into force on 1 August 2024. That date started the clock. It imposed nothing. Individual obligations become applicable on the separate dates set out in Article 113, and those dates have since been amended.

2 February 2025 — Prohibitions and AI literacy

Chapters I and II applied. The Article 5 prohibited practices became enforceable, and the Article 4 AI literacy duty attached to providers and deployers. The Digital Omnibus later rewrote Article 4 from a duty to ensure AI literacy into a duty to take measures to support its development — an obligation of effort rather than of result.

2 August 2025 — GPAI obligations and governance

Chapter V applied to providers of general-purpose AI models, alongside the governance and penalty framework. Crucially, the Commission’s power to actually enforce those GPAI rules did not arrive with them.

2 August 2026 — General application, Article 50, and live GPAI enforcement

This is the date that mattered most in 2026, and the one most widely assumed to have been cancelled.

It was not. The Act reached its general date of application. Article 50 transparency obligations became directly applicable to providers and deployers: users must be told when they are interacting with an AI system, and synthetic audio, image, video and text must be marked in a machine-readable format. Deepfake and public-interest-text disclosure duties fall on deployers.

On the same date, the AI Office and national market surveillance authorities gained their supervision and enforcement powers, including over GPAI model providers. Article 50 breaches sit in the Article 99(4) band — up to €15 million or 3% of worldwide turnover, whichever is higher.

If you run a chatbot for EU users or publish synthetic media into the EU market, your deadline has passed.

2 December 2026 — New prohibitions and the marking grace period

Two things land together.

First, the new Article 5 prohibitions added by the Digital Omnibus apply: AI systems intended to generate or manipulate non-consensual intimate material or child sexual abuse material. The Council’s own framing named the “nudify app” category directly. These sit in the prohibited-practices tier, at up to €35 million or 7% of turnover.

Second, the transitional window closes for Article 50(2). Providers of generative systems placed on the market before 2 August 2026 were given a grace period to implement machine-readable marking. The Omnibus cut that window from six months to three, fixing the date at 2 December 2026. Systems launched after 2 August 2026 never had a grace period.

2 December 2027 and 2 August 2028 — High-risk obligations

Chapter III Sections 1–3 now apply from 2 December 2027 for standalone Annex III systems — recruitment, credit scoring, education, essential services, law enforcement, migration, administration of justice — and from 2 August 2028 for AI embedded in products already covered by Annex I harmonization legislation.

The obligations themselves did not change. Conformity assessment, quality management systems, technical documentation, logging, human oversight, CE marking, EU database registration and fundamental rights impact assessments all survive intact. Only the clock moved, and it moved because the harmonised standards and national authority designations were not ready.

Two smaller Omnibus dates are worth calendaring: at least one national AI regulatory sandbox must be operational by 2 August 2027, and the Commission must publish coordination guidance for Annex I sectors by 1 August 2027.


GPAI Compliance Deadlines

General-purpose AI obligations deserve separate treatment because they bind a narrow population and are routinely misapplied to a wide one.

The obligations fall on providers of GPAI models. Not on companies that build applications using those models. If you call an API, you are a downstream deployer or a provider of an AI system — you are not a GPAI model provider, and Articles 51–55 do not attach to you.

Two dates govern:

  • 2 August 2025 — Chapter V applied to GPAI models placed on the EU market from that date. Providers must maintain technical documentation, supply information to downstream providers, put a copyright policy in place, and publish a sufficiently detailed summary of training content. Providers of models with systemic risk carry additional model evaluation, adversarial testing, incident reporting and cybersecurity duties.
  • 2 August 2027 — the Article 111 transitional rule. Providers of GPAI models already on the market before 2 August 2025 have until this date to bring those models into compliance.

Between August 2025 and August 2026, Chapter V was effectively compliance on paper: the obligations existed, the Commission’s enforcement machinery did not. That gap closed on 2 August 2026. GPAI model providers now answer to the AI Office directly, on a deliberately centralised basis, with exposure up to €15 million or 3% of worldwide turnover.


U.S. AI Compliance Deadlines

The United States has no comprehensive federal AI Act. Anyone telling you otherwise is describing an executive order or a bill.

Compliance runs across three layers, and they do not align.

Federal executive action. Executive Order 14365, Ensuring a National Policy Framework for Artificial Intelligence, was signed on 11 December 2025 and published in the Federal Register on 16 December 2025. It directs the Attorney General to establish an AI Litigation Task Force to challenge state AI laws, conditions certain discretionary and broadband funding on state regulatory restraint, and asks for a legislative recommendation for a preemptive federal framework.

An executive order cannot preempt state law. Only Congress or a court can. As of this review, no federal statute and no court decision has preempted or stayed any state AI law, and a bipartisan coalition of state attorneys general has publicly opposed broad preemption. State AI requirements remain enforceable and should be treated as live.

Federal statute. One genuinely federal deadline has already passed. The TAKE IT DOWN Act’s notice-and-removal requirements became enforceable on 19 May 2026. Covered platforms hosting user-generated content must provide a clear removal process for non-consensual intimate imagery — including AI-generated forgeries — and remove valid reports, plus known identical copies, within 48 hours. The FTC began enforcement on that date, with civil penalties assessed per violation.

Sector regulators. Existing law already applies to AI without naming it. The FTC issued a Section 5 policy statement on AI in March 2026; financial, health and employment regulators continue to apply existing authorities. There is no new deadline here, which is precisely why it gets missed.


Colorado’s AI Compliance Deadline

Colorado is the clearest illustration of why a tracker needs date-stamped rows.

SB 24-205, the Colorado Artificial Intelligence Act, was signed in May 2024 with an effective date of 1 February 2026. A special-session bill, SB 25B-004, pushed that to 30 June 2026. In April 2026 a federal magistrate stayed enforcement. The law never took effect at any point.

On 14 May 2026, Governor Polis signed SB 26-189, the Automated Decision-Making Technology Act (Chapter 131 of the 2026 Session Laws). It repeals and reenacts the SB 24-205 framework as something materially narrower. The reasonable-care duty, the algorithmic-discrimination impact assessments and the risk-management-programme mandate are gone — and with them the affirmative defence for aligning to the NIST AI RMF.

Effective 1 January 2027, for decisions made on or after that date.

Who it binds. Developers and deployers of automated decision-making technology used to materially influence a consequential decision — one relating to access to, eligibility for, or compensation related to education, employment, housing, financial or lending services, insurance, health-care services, or essential government services and public benefits.

What developers must do. Provide deployers with technical documentation covering intended uses, categories of training data, known limitations, and instructions for appropriate use and human review. Notify deployers of material updates. Retain compliance records for at least three years.

What deployers must do. Give consumers clear and conspicuous notice at the point of interaction. Where a covered ADMT produces an adverse outcome, provide a plain-language description of its role within 30 days. Honour consumer rights to access and correct personal data, and to request meaningful human review and reconsideration.

Enforcement. The Attorney General, through the Colorado Consumer Protection Act; a violation is a deceptive trade practice. Before 1 January 2030, the AG must give 60 days’ notice and an opportunity to cure where a cure is possible. There is no private right of action, though the Act allocates fault between developers and deployers in existing discrimination claims.

One item to watch: the AG must adopt rules clarifying the post-adverse-outcome disclosure requirements by 1 January 2027. Those rules will determine much of the operational detail.


State AI Compliance Deadlines

Enacted regimes with operative dates only.

StateInstrumentEffectiveBindsCore duty
CaliforniaSB 53 (TFAIA)1 Jan 2026Frontier developersSafety framework, transparency reports, incident reporting
CaliforniaAB 20131 Jan 2026Generative AI developersTraining-data documentation
CaliforniaSB 942 / AB 8532 Aug 2026 → 2028Providers, platforms, device makersDetection tool, manifest and latent disclosures, provenance
CaliforniaCPPA regulations1 Jan 2026 → 1 Jan 2027CCPA-covered businessesRisk assessments; ADMT notice, opt-out, logic access
TexasTRAIGA (HB 149)1 Jan 2026Developers and deployersProhibited uses, disclosure, AG enforcement
IllinoisHB 37731 Jan 2026EmployersEmployment AI non-discrimination and notice
IllinoisSB 3151 Jan 2027 / 1 Jan 2028Frontier developersDisclosure, whistleblower; then framework and audit
ConnecticutSB 5 (CART Act)1 Oct 2026 → 1 Jan 2028Employers, providers, platformsAEDT duties, provenance, companion-chatbot rules
New YorkRAISE Act1 Jan 2027Large frontier developersSafety protocols, incident reporting
ColoradoSB 26-189 (ADMT Act)1 Jan 2027Developers and deployersDocumentation, notice, explanation, human review

Three patterns are worth naming.

  1. A frontier-model template has emerged. California SB 53, New York’s RAISE Act and Illinois SB 315 share definitions, compute thresholds and structure. All three reach developers training models above roughly 10²⁶ operations; the heavier duties attach to those also clearing $500 million in revenue. If you are not training frontier models, none of them bind you. Illinois went furthest, adding the first mandatory annual third-party audit requirement in U.S. law — from 1 January 2028, not 2027.
  2. Transparency laws bind providers; employment laws bind employers. California’s AI Transparency Act (SB 942, as amended by AB 853) phases in by role: covered providers from 2 August 2026, generative AI hosting platforms and large online platforms from 1 January 2027, capture device manufacturers from 1 January 2028. Connecticut’s SB 5 reaches employers directly.
  3. Privacy regulation is doing AI regulation’s work. California’s CPPA regulations took effect on 1 January 2026, but the ADMT-specific duties — pre-use notice, opt-out, access to decision logic — bind from 1 January 2027, with risk assessments for pre-2026 processing due by 31 December 2027 and first summary reporting on 1 April 2028. For most businesses this is a larger operational lift than any AI-specific statute.

International AI Compliance Deadlines

Only jurisdictions with a firm, operative milestone appear here.

South Korea is the substantive one. The Framework Act on the Development of Artificial Intelligence (the AI Basic Act) and its Enforcement Decree took effect on 22 January 2026. It applies extraterritorially to foreign businesses whose AI activities affect Korean users, sets a high-impact threshold at 10²⁶ FLOPs, requires advance notice to users of generative and high-impact AI, mandates labelling of outputs hard to distinguish from human-made content, and can require foreign operators to designate a domestic representative. Fines are modest by EU standards, and a transitional grace period on enforcement applies for roughly the first year.

China enforces a stack of binding measures rather than a single act. The AI content labelling measures have applied since 1 September 2025, alongside existing generative AI and algorithm filing requirements.

The United Kingdom, Canada, Australia, Japan, Singapore and Brazil do not currently have a horizontal AI statute with a firm compliance deadline. The UK remains regulator-led with no general AI Act. Canada’s AIDA died on the order paper and has not been revived. Singapore’s agentic AI governance framework is voluntary. Brazil’s PL 2338 has not completed passage. Saying so plainly is more useful than inventing a date.


How to Read an AI Compliance Deadline

A date alone tells you almost nothing. Six things in sequence tell you everything.

Date → Jurisdiction → Role → System → Obligation → Evidence.

AI compliance deadlines
  1. Date. Distinguish entry into force from applicability. The EU AI Act has been in force since August 2024 and still has obligations arriving in 2028.
  2. Jurisdiction. Territorial scope is rarely where your office is. The EU AI Act reaches providers placing systems on the EU market; Korea’s Act reaches foreign operators affecting Korean users.
  3. Role. Provider, deployer, importer, distributor, product manufacturer, developer, employer, covered business. This is where most misreadings happen. GPAI obligations bind model providers. Article 50 deepfake duties bind deployers. Colorado splits duties between developers and deployers with different content.
  4. System. Is it in scope at all? Annex III classification, “covered ADMT”, “frontier model”, “automated employment-related decision technology” — each is a defined term with a threshold, and most systems fall outside most of them.
  5. Obligation. What is the actual act required: documentation, notice, marking, assessment, reporting, human review, registration?
  6. Evidence. What would you show a regulator? An obligation you cannot evidence is one you have not met.

Run any row of the table through those six and you will know whether it is yours.


What to Do Before an AI Compliance Deadline

  1. Re-check the primary source in the month before the date. Two of the dates on this page moved in the last year.
  2. List the jurisdictions where your systems are placed on the market, put into service, or reach users. Not where you are incorporated.
  3. Inventory your AI systems. Include vendor tools and embedded features. The systems that cause problems are the ones nobody registered as AI.
  4. Assign a role per system per jurisdiction. The same organisation is often a provider in one relationship and a deployer in another.
  5. Classify. Does the system meet the definitional threshold — Annex III, covered ADMT, frontier model, AEDT?
  6. Map obligations to the classification, not to the headline. Most deadlines carry a handful of duties, not all of them.
  7. Name an accountable owner per obligation. A calendar entry with no owner is a missed deadline with a paper trail.
  8. Build the documentation now. Technical documentation, training-data summaries and instructions for use take longer than the notice text does.
  9. Instrument logging and incident detection. Incident reporting duties assume you can detect the incident.
  10. Review your model and vendor dependencies. Your obligations often depend on what your upstream provider gives you.

Why AI Compliance Deadlines Keep Moving

Not political weather. Structural mechanics, and each produces a different kind of change.

  • Amendments. The Digital Omnibus is the clearest case: a regulation amending a regulation, moving dates without reopening substance.
  • Missing implementation infrastructure. The EU high-risk deferral happened largely because harmonised standards from CEN-CENELEC and national competent authority designations were not ready. An obligation whose compliance tools do not exist is not enforceable in practice.
  • Legislative replacement. Colorado did not delay its law a third time. It repealed and rewrote it, which changes the obligations, not just the date.
  • Litigation. A federal magistrate stayed SB 24-205 before it took effect. Court decisions can pause a date without touching the text.
  • Agency rulemaking. Colorado’s AG rules and the CPPA’s phased schedule determine what a statutory date actually requires.
  • Federal-state conflict. EO 14365’s machinery is running. It has changed no obligation yet, but it is the most likely source of movement in the U.S. rows.

How We Maintain This Tracker

Stated plainly, because a maintenance claim is only useful if it is accurate.

  • Primary sources first. Dates come from the Official Journal, EUR-Lex, the Federal Register, state legislature records and regulator publications. Law firm and consultancy analysis is used to interpret provisions, never to establish a date.
  • Per-row date stamps. Every row carries its own Last verified date, because rows are not all checked with equal frequency.
  • Monthly review of the full table, plus an event-driven update when a significant development occurs.
  • Discrepancies are disclosed, not resolved silently. Where reputable sources disagree, the page says so and identifies which source is closer to the primary text.
  • Change notes are recorded in the Update History at the foot of the page.
  • No predictive dates. Where a date is not fixed, the table says “Not yet fixed” rather than estimating.

The calendar moves. The page moves with it, or it is worth nothing.


Sources

Tier 1 — primary legal and regulatory sources

Tier 2 — standards and official guidance


Frequently Asked Questions

When does the EU AI Act apply?

In phases, not all at once. Regulation (EU) 2024/1689 entered into force on 1 August 2024. Prohibited practices and AI literacy duties applied from 2 February 2025, GPAI obligations from 2 August 2025, and the Act reached general application — including Article 50 transparency duties — on 2 August 2026. High-risk obligations now apply from 2 December 2027 for standalone Annex III systems and 2 August 2028 for AI embedded in regulated products.

Were the EU AI Act’s high-risk deadlines cancelled?

No. They were deferred. Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and moved the dates. The substantive obligations — conformity assessment, quality management systems, technical documentation, logging, human oversight, CE marking, database registration — are unchanged. Only the clock moved.

When do GPAI obligations apply, and who do they bind?

They bind providers of general-purpose AI models, not companies that build applications on top of those models. Obligations applied from 2 August 2025 for models placed on the EU market from that date. Providers of models already on the market before 2 August 2025 have until 2 August 2027. The Commission’s AI Office gained active enforcement powers on 2 August 2026.

Do AI laws apply to developers or to deployers?

Both, but rarely the same obligations. EU GPAI duties bind model providers. EU Article 50 duties bind providers and deployers differently — providers mark output, deployers disclose deepfakes and chatbot interaction. Colorado splits developer documentation duties from deployer notice duties. Determining your role per system per jurisdiction is the first real step in any assessment.

Where should organisations verify an AI regulation?

At the primary source: EUR-Lex and the Official Journal for EU instruments, the Federal Register and agency sites for U.S. federal action, state legislature records for state law, and the relevant regulator for implementing rules. Secondary analysis is useful for interpreting complex provisions but should never be the basis for a date.


Keep reading

AI compliance deadlines

AI Compliance Deadlines: What Applies, When, and to Whom

There is no single AI compliance deadline. There is a calendar of them, each attached to a particular jurisdiction, a particular kind of organisation, and …

Read more

AI agent framework security

AI Agent Framework Security: 10 Frameworks Audited

A developer runs pip install, decorates three functions with @tool, and points an agent at them. The agent now has a shell in your process. …

Read more

Cluster Topology

Cluster Topology Decides What You Can Actually Run

Two teams buy 512 H100s. One trains a 400-billion-parameter mixture-of-experts model. The other cannot fit that job at all, and burns six weeks finding out …

Read more

Multi-Agent Delegation

Multi-Agent Delegation: 4 Costs Nobody Models First

A planner agent receives a refund request. It hands the task to a billing agent. The billing agent queries an account agent, which calls a …

Read more

Advertisement

Leave a Comment