AI Regulation Tracker
Every US state AI law, federal action, and EU AI Act milestone we track — updated daily from LegiScan, the Federal Register, the FTC, and EUR-Lex. Members see per-regulation compliance notes and the full deadline calendar, free.
| Regulation | Jurisdiction | Status | Impact | Effective | Source |
|---|---|---|---|---|---|
Illinois AI Safety Act Signed July 6, 2026, this frontier-model law targets developers with over $500M revenue training models above defined compute thresholds. It requires public transparency frameworks, pre-deployment reports, 72-hour safety-incident reporting, quarterly catastrophic-risk assessments to the AG, and — a first in the US — annual independent third-party safety audits, with penalties up to $3M per violation. 🔒 “What to do” compliance notes — members only frontier-modelstransparency | IL (state) | Enacted | Watch | 2027-01-01 | View |
EU AI Act Digital Omnibus The EU's simplification package amending the AI Act: it defers high-risk obligations from August 2, 2026 to December 2, 2027 for stand-alone (Annex III) systems and August 2, 2028 for product-embedded (Annex I) systems, extends SME simplifications to small mid-caps, and adds a new prohibition on AI generating CSAM and non-consensual intimate imagery. Parliament approved June 16, 2026 and the Council gave final approval June 29, 2026; publication in the Official Journal is imminent. 🔒 “What to do” compliance notes — members only generaltransparency | European Union | Passed legislature | Watch | — | View |
EU AI Act The world's first comprehensive AI law, applying to any company placing AI systems on the EU market or whose AI outputs are used in the EU — including US startups with EU users. It bans certain practices (social scoring, manipulative AI), imposes heavy obligations on 'high-risk' systems (hiring, credit, biometrics), transparency duties on chatbots and synthetic content, and a dedicated regime for general-purpose AI models. Penalties reach 7% of global turnover. 🔒 “What to do” compliance notes — members only generalfrontier-modelstransparencychatbotsdeepfakesbiometricsemployment | European Union | In effect | Action required | 2024-08-01 | View |
Upcoming deadlines
Online platforms with 2M+ monthly users must detect and surface provenance metadata in content distributed on their services.
CCPA-covered businesses using automated decisionmaking technology for significant decisions must have pre-use notices, opt-out mechanisms, and access-request handling in place; CPPA enforcement expected after this date.
Colorado's revised AI law takes effect: deployers of covered automated decision-making technology must provide pre-use notices, 30-day adverse-decision notices, and honor data access/correction and human-review requests.
Large frontier AI developers must publish safety and security protocols and report safety incidents to New York within 72 hours, as finalized by the March 2026 chapter amendment.
Latest developments
California SB1159 requires AI transparency and governance standards; AI compliance owners should monitor this enrolled bill for final enactment, as it will likely impose new disclosure and oversight obligations on companies deploying AI systems in California.
FTC settled deceptive advertising cases against Cox Media Group and two other firms for $930,000 total, penalizing false claims about an AI-powered 'active listening' service that allegedly targeted ads based on smart device conversations without proper consumer consent. AI governance teams should note this reinforces FTC enforcement against deceptive AI capabilities and consent violations, signaling heightened scrutiny of AI marketing claims and smart device data collection practices.
The CFTC is seeking public input on how to oversee derivatives markets related to AI compute resources; AI compliance leaders should monitor this as it could affect how companies structure AI infrastructure investments and trading activities.
Don’t check this page — we’ll tell you.
Free weekly digest of what changed, every Monday morning.