AI Regulatory Tracker
Critical deadlines, active regulations, and what enterprise leaders need to act on now. Updated as new regulations emerge.
EU AI Act high-risk enforcement begins August 2, 2026: 4 months away
Non-compliance penalties reach 15M euros or 3% of global revenue. Organizations subject to the Act need to begin documentation and classification programs now: compliance evidence cannot be built retroactively. US-only companies: The Act follows AI outputs, not company location. If your AI affects EU residents, you are likely in scope.
Does the EU AI Act apply to US-only companies?
Scope is determined by where AI outputs are used: not where the company is headquartered. A US firm with no EU office is still in scope if its AI affects EU residents (hiring, lending, recommendations, SaaS users). This mirrors GDPR's extraterritorial logic. KPMG: "The EU AI Act is applicable to many U.S. companies, potentially even including those with no physical EU presence."
In scope:
SaaS with EU users, AI screening EU job applicants, credit models for EU residentsLikely out:
Purely domestic US operations with zero EU-facing AI outputs or EU customersUS State Regulation: Federal Preemption Attempt
On December 11, 2025, President Trump signed an Executive Order directing the DOJ to establish an AI Litigation Task Force to challenge state AI laws deemed "onerous." The 10-year state AI moratorium was rejected 99 to 1 by the US Senate in July 2025. Executive Orders cannot directly preempt state law without Congressional action.
Warning:
Do not assume state laws are being eliminated. Most are still in force. California, New York, Illinois, Colorado enforcement continues regardless of federal EO status.Sources: Seyfarth Shaw, Buchanan Ingersoll, Paul Hastings, White House EO Dec 11 2025
Regulatory and Compliance Tracker
Critical deadlines, active regulations, and enterprise obligations.
| Regulation / Framework | Jurisdiction | Key Deadline | Status | Primary Obligation |
|---|---|---|---|---|
EU AI Act - Prohibited Practices Article 5 enforcement | EU / Global | Feb 2025 | ● Passed - enforce now | Discontinue social scoring, subliminal manipulation, real-time biometric surveillance in public spaces |
EU AI Act - GPAI Model Obligations Foundation model providers | EU / Global | Aug 2025 | ● Passed - enforce now | Technical documentation, copyright compliance, training data summaries for GPAI model providers |
EU AI Act - High-Risk AI Systems Broadest enterprise impact | EU / Global | Aug 2, 2026 | ● 4 months - act now | Risk management systems, EU database registration, full documentation for biometrics, employment, credit, education, law enforcement AI |
EU AI Act - Transparency Requirements All AI-using companies | EU / Global | Jun 2026 | ● Upcoming | Full implementation of AI content disclosure, data protection compliance, user notification obligations |
FINRA 2026 AI Oversight Priorities Financial services | US - Financial | Active 2026 | ● Active examination | Formal AI governance structure, GenAI supervision frameworks, human-in-the-loop for AI-assisted client advice, prompt/output retention |
SEC AI Governance Examination Registered advisers and funds | US - Financial | Active 2026 | ● Active examination | Explainability and controls around AI-based investment tools; documentation of AI use in client-facing decisions |
NIST AI Risk Management Framework US voluntary standard | US - All sectors | Active | ● Voluntary - widely adopted | Govern, Map, Measure, Manage: baseline framework for enterprise AI risk management. Increasingly referenced in contracts and RFPs. |
US State AI Laws (30+ states) CA, TX, CO, IL leading | US - Varies | 2025-2026 | ● Patchwork - monitor | AI in hiring decisions, algorithmic bias audits, automated decision notices. California leads; Texas and Colorado active legislation. |
Trump EO - Federal Preemption of State AI Laws Dec 11, 2025 - Active litigation | US Federal | Active 2026 | ● Contested - uncertainty | DOJ AI Litigation Task Force targets state laws deemed "onerous." BEAD funding withheld from states with conflicting AI laws. 36 state AGs oppose. No comprehensive federal AI law exists. |
UK AI Regulatory Framework Cross-sector, principles-based | UK | Active | ● Active - less prescriptive | Safety, transparency, fairness, accountability: sector regulators (FCA, ICO, CMA) apply principles within their domains. |
What You Should Do: Regulation-by-Regulation
EU AI Act - Prohibited Practices
Deadline: Feb 2025
Review all AI use cases against the prohibited practices list. Document and cease any in-scope activities immediately.
EU AI Act - GPAI Model Obligations
Deadline: Aug 2025
If your organization provides foundation models or deploys models for others, complete technical documentation and data summaries now.
EU AI Act - High-Risk AI Systems
Deadline: Aug 2, 2026
Begin AI system classification immediately. High-risk systems require risk management documentation that cannot be built retroactively. Non-compliance penalties reach 15M euros or 3% of global revenue.
EU AI Act - Transparency Requirements
Deadline: Jun 2026
Audit all customer-facing AI interactions. Implement disclosure mechanisms for AI-generated content. Review data protection practices for AI systems.
FINRA 2026 AI Oversight Priorities
Deadline: Active 2026
Establish formal AI governance documentation. Implement supervision frameworks for GenAI. Retain prompt and output logs for AI-assisted client advice.
SEC AI Governance Examination
Deadline: Active 2026
Document all AI use in investment decision-making. Implement explainability controls. Prepare for examination questions about AI governance.
$3.4B
global AI governance and compliance market in 2026, growing to $68.2B by 2035 at 39% CAGR: the fastest-growing enterprise software category.
Source: Market.us 2026
15M EUR
or 3% of global revenue: the EU AI Act penalty for high-risk AI violations. Full enforcement begins August 2026. Prohibited practices (Article 5) already active.
Source: EU AI Act Official Regulation
30+
US states with active AI legislation in 2025-2026. Compliance with the EU AI Act alone will not be sufficient. US organizations face a patchwork of state requirements.
Source: Cimplifi AI Regulation Landscape 2026
Stay ahead of the enterprise AI curve
Get the weekly C-Suite Brief: the data and decisions that matter for AI transformation leaders. No fluff.
No spam. Unsubscribe anytime. Used by AI transformation leaders at 200+ enterprise organizations.