Regulatory Calendar
Grouped by regime, because a use case runs on several clocks at once. The AI Act is the only domain whose staged dates are fixed in the graph today; for the others the instruments are in force and their duties bite on entry into application, which is stated per instrument rather than invented as a date.
Standards and assessment infrastructure run on their own clock — see the standards & guidance lifecycle tracker →
Target market(s)European UnionUnited States (federal)change
Entries for markets outside your selection stay visible below, de-emphasised — history is never hidden.
Jurisdiction swimlanes — major new regimes
One lane per regime, built only from dated facts already on the graph. A regime with no dated milestone says so and links to the verification queue instead of inventing a date.
- Interim Measures for Generative AI Services (CN) in force — in force since 15 Aug 2023
- AI-Generated Synthetic Content Labeling Measures (CN) in force — in force since 1 Sep 2025
- Deep Synthesis Provisions (CN) in force — in force since 10 Jan 2023
- Algorithmic Recommendation Provisions (CN) in force — in force since 1 Mar 2022
- PIPL (CN) in force — in force since 1 Nov 2021
- Data Security Law (CN) in force — in force since 1 Sep 2021
- Amended Cybersecurity Law — AI provisions (CN) in force — in force since 1 Jan 2026
- AI Framework Act (KR) in force — in force since 22 Jan 2026 (promulgated 21 Jan 2025)
- PIPA (KR) in force — in force; 2023 amendment ADM rights effective Mar 2024
- AI Promotion Act (JP) in force — passed 28 May 2025, fully in force Sep 2025; Basic AI Plan adopted 23 Dec 2025
- APPI (JP) in force — in force; major amendments effective Apr 2022
- METI/MIC AI Guidelines for Business v1.0 (JP) voluntary — published Apr 2024
- Standalone AI Law (VN) in force — enacted 10 Dec 2025, in force since 1 Mar 2026
- Law on Digital Technology Industry (VN) in force — in force 1 Jan 2026
- Pro-innovation AI framework (GB) voluntary — 2023 white paper; regulator-applied
- UK GDPR / DPA 2018 as amended by DUAA 2025 in force — in force phased; DUAA royal assent 19 Jun 2025
- Online Safety Act 2023 (GB) in force — in force; Ofcom codes phased 2025–26
- Crime and Policing Act 2026 (GB) unverified — help verify — enacted Apr 2026
- LGPD 13.709/2018 (BR) in force — in force
- Bill C-36 — Protecting Privacy and Consumer Data Act (CA) pending — not yet law — tabled 15 Jun 2026
- PIPEDA (CA) in force — in force
- Quebec Law 25 (CA) in force — in force
AI law — staged dates
AI Act enters into force
Regulation (EU) 2024/1689 in force; countdown for all staged obligations starts.
Prohibitions + AI literacy
Art. 5 prohibited practices ban applies (manipulation, social scoring, untargeted face scraping, workplace emotion recognition); Art. 4 AI literacy duty.
GPAI + governance + penalties
Chapter V GPAI model obligations, notification authorities, governance structures and fining provisions apply. The GPAI Code of Practice was published 10 July 2025 with 21 signatories.
Digital Omnibus in force
Regulation (EU) 2026/1744 in force since 27 July 2026 (Council adoption 29 June, OJ L, 24 July 2026; CELEX 32026R1744): fixes the high-risk application dates at 2 Dec 2027 (Annex III standalone) and 2 Aug 2028 (Annex I embedded), and the softened Art. 4 AI-literacy duty takes effect on this date. Source: https://eur-lex.europa.eu/eli/reg/2026/1744/oj
General applicability + Art. 50 transparency applies
Art. 50 transparency duties APPLY from 2 August 2026 — chatbot disclosure, deepfake labelling, synthetic-content and emotion-recognition disclosure are binding now, not next December. EU-level enforcement begins. Confirmed against Regulation (EU) 2026/1744 (OJ L, 24.7.2026; CELEX 32026R1744). Source: https://eur-lex.europa.eu/eli/reg/2026/1744/oj
CRA incident & vulnerability reporting applies
Cyber Resilience Act Art. 14 reporting duties for actively exploited vulnerabilities and severe incidents apply from 11 Sep 2026 (coordinator CSIRT + ENISA).
Art. 50(2) marking — grace period ends for legacy generative systems
End of the transitional grace period for the Art. 50(2) machine-readable marking duty, and ONLY for generative systems placed on the market BEFORE 2 August 2026. Systems placed on the market on or after 2 August 2026 owe the marking duty immediately. This date does not delay the rest of Art. 50, which applies from 2 August 2026. Source: https://eur-lex.europa.eu/eli/reg/2026/1744/oj
New Art. 5 prohibitions apply (NCII, CSAM generation)
The two prohibited practices inserted into Art. 5 by Regulation (EU) 2026/1744 — generation of non-consensual intimate imagery and of child sexual abuse material — apply from 2 December 2026. The Art. 5 prohibitions that existed before the omnibus have applied since 2 February 2025. Source: https://eur-lex.europa.eu/eli/reg/2026/1744/oj
Regulatory sandboxes
AI regulatory sandboxes operational from 2 Aug 2027 per Regulation (EU) 2026/1744.
Annex III high-risk obligations (Art. 6(2))
Standalone Annex III high-risk systems must comply from 2 Dec 2027 — fixed date under Regulation (EU) 2026/1744, no longer coupled to standards availability.
Annex I embedded high-risk (Art. 6(1))
High-risk AI as safety components in already-regulated products (Annex I: MDR, machinery, automotive …) must comply from 2 Aug 2028 — fixed date under Regulation (EU) 2026/1744.
Public-sector legacy systems
High-risk systems placed on the market or put into service by public authorities before the relevant application date must comply by 2 August 2030 (Art. 111(2)). Source: https://eur-lex.europa.eu/eli/reg/2024/1689/oj
Other regimes in scope
28 instruments · no staged dates recorded in the graph
- GDPR — in-force
- Data Act
- Data Governance Act — in-force
- ePrivacy Directive — amended
- EHDS — in-force
- HIPAA (US Health Privacy) — in-force
- PIPL (CN) — in-force
- PIPA (KR) — in-force
- APPI (JP) — in-force
- PDPA (SG) — in-force
- DPDP Act 2023 (IN) — in-force
- Privacy Act 1988 + 2024 Amendment (AU) — in-force
- PDP Law 27/2022 (ID) — in-force
- DIFC Data Protection Law No. 5/2020 (AE) — in-force
- ADGM Data Protection Regulations 2021 (AE) — in-force
- Federal PDPL — enacted-not-yet-applicable
- PDPL (SA) — in-force
- Nigeria Data Protection Act 2023 — in-force
- POPIA (ZA) — in-force
- Data Protection Act 2019 (KE) — in-force
- PDPL 151/2020 (EG) — enacted-not-yet-applicable
- Data Protection Law 058/2021 (RW) — in-force
- UK GDPR / DPA 2018 as amended by DUAA 2025 — in-force
- Bill C-36 — pending
- PIPEDA (CA) — in-force
- Quebec Law 25 (CA) — in-force
- LGPD 13.709/2018 (BR) — in-force
- Revised FADP (CH) — in-force
8 instruments · no staged dates recorded in the graph
- Cyber Resilience Act — in-force
- NIS2 Directive — in-force
- DORA — in-force
- eIDAS 2 (EUDI / Trust Services) — in-force
- CFAA & Anti-Scraping Regimes
- US CLOUD Act (18 U.S.C. §2523 / §2713) — in-force
- Data Security Law (CN) — in-force
- Amended Cybersecurity Law — in-force
4 instruments · no staged dates recorded in the graph
- Digital Services Act — in-force
- IT Act 2000 + Intermediary Guidelines 2021 (IN) — in-force
- Online Safety Act 2023 (GB) — in-force
- Crime and Policing Act 2026 (GB) — in-force
5 instruments · no staged dates recorded in the graph
- Revised Product Liability Directive — in-force — transposition pending
- General Product Safety Regulation
- MDR / IVDR — amended
- Machinery Regulation — amended
- Sector Safety Regimes (EASA / ERA / NERC CIP)
12 instruments · no staged dates recorded in the graph
- AML Package (AMLR/AMLA) — in-force
- ECOA / CFPB Adverse-Action Regime — in-force
- SEC Rule 17a-4 (US Records Retention)
- FINRA Rule 4511 (General Books & Records)
- Bank Secrecy Act / FinCEN Program Rules
- SEC Advisers Act Rule 204-2 (Books & Records) — in-force
- SEC Regulation Best Interest — in-force
- Sarbanes-Oxley Act (SOX §302 / §404) — in-force
- USA PATRIOT Act §326 (CIP) — in-force
- National Tax Codes & OECD BEPS / Pillar Two — in-force
- SEC Cybersecurity Disclosure Rules (Item 1.05 Form 8-K) — in-force
- SEC Regulation S-X Rule 2-01 — in-force
95 instruments · no staged dates recorded in the graph
- Unfair Commercial Practices Directive — amended
- CSDDD (Corporate Sustainability Due Diligence) — in-force
- TCPA / FCC AI-Voice Rules (US)
- EEOC / Title VII Algorithmic Fairness (US)
- FTC Act §5 & Endorsement / AI-Claims Guidance — in-force
- Colorado ADMT Act (SB 26-189) — enacted-not-yet-applicable
- Illinois AI Video Interview Act — in-force
- Illinois Biometric Information Privacy Act (BIPA) — in-force
- FDA oversight of Software as a Medical Device (US) — unverified
- Colorado Chatbot Safety Act (HB 26-1263) — enacted-not-yet-applicable — session law effective 12 August 2026; operator requirements and prohibitions apply from 1 January 2027
- BaFin MaRisk (Mindestanforderungen an das Risikomanagement) — in-force
- § 87(1) No. 6 BetrVG — in-force
- EU Employment Equality Directives (2000/78 et al.) — in-force
- EU Equal Treatment Directives (Goods, Services, Social Protection) — in-force
- ADA Title I & ADEA (US employment anti-discrimination) — in-force
- FCRA — in-force
- Consumer Credit Directive II (CCD2) — in-force
- § 26 BDSG — in-force
- AGG (German General Equal Treatment Act) — in-force
- CER Directive (Critical Entities Resilience) — in-force
- EU DSM Copyright Directive (TDM, Arts 3–4) — in-force
- TAKE IT DOWN Act / 18 U.S.C. § 2258A (platform duties) — in-force
- Law Enforcement Directive (EU) 2016/680 — in-force
- EU Visa Code (Regulation (EC) No 810/2009) — in-force
- Illinois Human Rights Act — in-force
- PSD2 RTS on Strong Customer Authentication (SCA-RTS) — in-force
- KSchG § 1 & BetrVG §§ 95, 102 — in-force
- EU Digital Accessibility Directives (EAA & WAD) — in-force
- EU Electricity Cybersecurity Network Code (NCCS) — in-force
- OSH Framework Directive 89/391/EEC — in-force
- RED Cybersecurity Delegated Regulation (EU) 2022/30 — in-force
- Platform Work Directive (EU) 2024/2831 — enacted-not-yet-applicable
- Fair Housing Act (US) — in-force
- General Safety Regulation (EU) 2019/2144 (vehicle type-approval) — in-force
- Drinking Water Directive (EU) 2020/2184 — in-force
- EU Toy Safety (Directive 2009/48/EC → Regulation (EU) 2025/2509) — in-force
- COPPA Rule (16 CFR Part 312) — in-force
- European Electronic Communications Code — in-force
- Colorado Privacy Act — in-force
- Working Time Directive 2003/88/EC — in-force
- Electricity Directive (EU) 2019/944 — amended
- Consumer Rights Directive (EU) — amended
- § 41a EnWG — amended
- New York AI Companion Models Law (GBL Art. 47) — in-force
- Machinery Directive 2006/42/EC (transitional, pre-2027) — amended
- OSH Act General Duty Clause (US) — in-force
- Driving Times, Breaks and Rest Periods — in-force
- Platform-to-Business Regulation (EU) 2019/1150 — in-force
- Digital Platform Workers' Rights Act, 2022 (Ontario, CA) — in-force
- Online Safety Amendment (Social Media Minimum Age) Act 2024 (AU) — in-force
- ADA Title II Web and Mobile App Accessibility Rule (US) — enacted-not-yet-applicable
- HHS Section 504 Web and Mobile Accessibility Rule (US) — enacted-not-yet-applicable
- Public Sector Bodies (Websites and Mobile Applications) Accessibility Regulations 2018 (GB) — in-force
- RESPA / Regulation X (Settlement Services) — in-force
- State Unauthorized Practice of Law Restrictions on Real-Estate Closings (US) — in-force
- EU Statutory Audit Directive (2006/43/EC, as amended) — amended
- EU Audit Regulation (537/2014) — in-force
- PCAOB Technology-Assisted Analysis Standards (AS 1105 / AS 2301) — in-force
- EU Clinical Trials Regulation (536/2014) — in-force
- ICH E6 Good Clinical Practice Guideline (R2/R3) — in-force
- FDA 21 CFR Part 11 (Electronic Records; Electronic Signatures) — in-force
- FDA 21 CFR Part 312 (IND Safety Reporting) — in-force
- SEC Investment Company Act Rules 31a-1 to 31a-3 (Fund Books & Records) — in-force
- AIFMD (EU Alternative Investment Fund Managers Directive) — amended
- False Claims Act — in-force
- SGB V § 106d - Billing Review in Contract-Physician Care — in-force
- EU Insurance Distribution Directive (IDD) — amended
- NAIC Model Bulletin on Use of AI Systems by Insurers — in-force
- Fair Labor Standards Act (Wage & Hour) — in-force
- IRC § 6672 — in-force
- Mortgage Credit Directive (MCD) — in-force
- TILA-RESPA Integrated Disclosure Rule (TRID) — in-force
- DEA Controlled Substances Act Dispensing & E-Prescribing Rules — in-force
- Illinois Prescription Drug Affordability Act (PBM Reform) — in-force — reporting requirements preliminarily enjoined as applied to ERISA plans (C.D. Ill., 31 Aug 2026)
- FMCSA Property Broker Licensing & Financial Responsibility — in-force
- Union Customs Code - Regulation (EU) No 952/2013 — in-force
- EU Dual-Use Export Control Regulation (EU) 2021/821 — in-force
- EU Directive on Criminal Penalties for Violating Union Restrictive Measures (2024/1226) — in-force
- US Customs Entry and Penalty Regime (19 U.S.C. §§ 1484, 1592) — in-force
- US Export Administration Regulations (EAR) — in-force
- US OFAC Sanctions - IEEPA, Enforcement Guidelines and Compliance Framework — in-force
- EU Political Advertising Regulation (EU) 2024/900 — in-force
- Circular 230 — in-force — reach over non-practitioner return preparers and contingent fees contested; Treasury NPRM of 26 Dec 2024 pending
- IRC §§ 7216 & 6713 — in-force
- FTC Safeguards Rule (16 CFR Part 314) — in-force
- Steuerberatungsgesetz (StBerG) — in-force
- § 203 StGB — in-force
- Federal Wiretap Act / ECPA (18 U.S.C. §§ 2510-2523) — in-force
- California Invasion of Privacy Act - CIPA (Cal. Penal Code §§ 630-638.55) — in-force
- Florida Security of Communications - Fla. Stat. ch. 934 (§§ 934.03, 934.10) — in-force
- § 201 StGB - Verletzung der Vertraulichkeit des Wortes (DE) — in-force
- EU Directive on Attacks Against Information Systems (2013/40/EU) — in-force
- USPTO Practice Rules & Inventorship Guidance for AI-Assisted Filings (US) — in-force
- US Foreign-Filing Licence & Export Control of Patent Technical Data — in-force
- EPC Inventor Designation & EPO Guidelines on AI-Assisted Submissions — in-force
Implementation Roadmap
The delivery-side counterpart to the regulatory dates: what has to exist internally before an outcome-priced AI service can carry regulated work. See the architecture →
Foundational governance & architectural hardening
Establish core compliance policies and secure infrastructure enclaves.
Technical: Deploy zero-trust ingestion with PII/PHI tokenisation; stand up the model-abstraction layer.
Governance: Finalise ISO 42001 AIMS policies; execute zero-data-retention vendor contracts.
Workflow taxonomy & regulatory tiering
Map every vertical workflow to its risk tier.
Technical: Build HITL operator dashboards with confidence-threshold routing (C_s < θ).
Governance: Complete AI Act classifications (high vs. limited vs. minimal) per workflow.
Artifact automation & immutable auditability
Automate production of required compliance documentation.
Technical: Connect transaction pipelines to append-only WORM storage with external trust anchoring.
Governance: Auto-generate AI impact assessments and model cards per deployment.
Scaled outcome-based commercial deployment
Move client contracts to outcome-priced structures.
Technical: Continuous drift monitoring and dynamic multi-model fallback in production.
Governance: Annual ISO 42001 audits; continuous AI Act conformity validation.
Release history
87 releases so far, the latest being v2.56.0 (2026-09-22). Every change is recorded with the community challenge and the contributor that caused it. Read the full changelog →
Download the v1.5 teaser (PDF)
Control Layer & Currency
Control chain: obligation (article) → operationalized_by → control objective → satisfied_by → component/pattern; control objective → evidenced_by → evidence artifact
Mapping an obligation directly to a component answers 'what do I build?' but not 'what must be true?'. The control objective is the testable statement in between — it is what an auditor actually assesses and what a runtime check actually verifies. Separating it makes one obligation explode into several objectives, and lets one objective be satisfied by alternative components.
Coverage: 314 of 359 legal and standard claims carry a verification date (87%); 312 carry a lifecycle status. The remaining claims are published as unverified rather than backdated with an invented date — see the coverage worklist →
Currency: Every legal act and standard in this graph is a moving target. A node without a lastVerified date is a claim, not a fact.
- Official Journal of the EU (OJEU) — harmonised-standard citations & amending acts
- European Parliament Legislative Observatory — Omnibus & EHDS procedure files (the AILD file is closed: the proposal was withdrawn in the Commission's 2025 work programme; watched only for a successor)
- CEN-CENELEC JTC 21 work programme & standards trackers
- EU AI Office guidance, delegated & implementing acts
- National layer: BSI publications, DAkkS accreditations, TÜV AI.Lab assessments
- Council of Europe CETS 225 ratification count
- Taiwan AI Basic Act promulgation and effective date
- Brazil Chamber of Deputies vote on PL 2338/2023
- Canada Bill C-36 legislative progress
- Indonesia draft Presidential Regulation on AI
- Switzerland end-2026 sectoral AI consultation draft
- India DPDP Act phase-in deadlines
Method
The graph encodes four source layers: (1) the EU AI Act and the surrounding digital acquis (GDPR, CRA, NIS2, DORA, PLD, Data Act, DGA, DSA, ePrivacy, GPSR plus sectoral instruments), (2) the standards landscape (CEN/CENELEC JTC 21, ISO/IEC SC 42, DIN, BSI, NIST, OWASP, ENISA, IEEE), (3) compliance-by-design architecture patterns, and (4) the Regulatory Design & Architecture (RDA) framework for agentic systems with the four-mode oversight taxonomy. Derivation logic: use case → risk class → imposed articles → implementing components & supporting standards, joined with regulation-specific requirements and threat mitigations.
About the platform
RAIN is free to join and contribute-to-participate: sign up yourself, or be invited by an existing member — either way every account is confirmed by a curator against a real professional profile, and carries a small balance of contribution credits. Credits are earned by hardening the graph — accepted verifications, accepted use cases, peer reviews, inviting a member who gets verified — and spent on member services such as saving an analysis or requesting an expert review, so the people who use the graph are the people who maintain it. Verification is revalidated every twelve months; what the graph currently contains and how well it is sourced is public on graph statistics.