AI Regulation Tracker
The 100 most recent verified regulatory updates, grouped by framework. Browse all activity for a framework on its hub page.
EU AI Act
Commission publishes transparency guidance under the AI Act
The Commission published guidance on Article 50 transparency obligations ahead of the 2 August 2026 applicability date, so providers and deployers now need to operationalize labeling and disclosure workflows rather than wait for enforcement to start.
Digital Omnibus on AI amends the EU AI Act
Regulation (EU) 2026/1744 amends the AI Act and makes the new prohibitions on realistic intimate/deepfake-style synthetic content and the updated Article 50 transparency obligations operative from 2 December 2026, creating immediate implementation work for AI providers and deployers.
CJEU preliminary reference on whether AI-assisted expert reporting is high-risk under the AI Act
A 2026 CJEU reference asks whether software generating automated outcomes or using AI elements in an expert report should be treated as a high-risk AI system under the AI Act, creating interpretive uncertainty for litigation-support tools.
European Commission AI Office implementation guidance and GPAI compliance support
The Commission’s AI Office continues publishing guidance and code-of-practice materials to operationalize AI Act obligations for GPAI providers, creating near-term compliance expectations even before further implementing acts land.
EESC opinion on the AI Omnibus and Digital Omnibus simplification proposals
The EESC backed simplification of the AI Act and digital rulebook while warning that high-risk AI obligations are still expected to become binding as early as August 2026, so firms should not delay compliance planning pending omnibus negotiations.
AI Act consultations on sandboxes, rights reservations, and scientific panel
The Commission has opened consultation processes on AI regulatory sandboxes, rights-reservation protocols for text and data mining, and the scientific panel, signaling that implementation architecture is still being built and that stakeholders should feed in compliance concerns now.
Commission releases GPAI Code of Practice and implementation guidance
The Commission has made the general-purpose AI Code of Practice available and issued companion guidance, giving GPAI providers a concrete compliance path they can use now to demonstrate AI Act conformity rather than waiting for further enforcement detail.
EU consults on scientific panel for AI Act oversight
The Commission is consulting on the AI Act scientific panel, indicating that expert oversight infrastructure is still being finalized and could influence how technical disputes and risk questions are handled.
EU seeks feedback on AI regulatory sandboxes under the AI Act
The Commission’s sandbox consultation shows that AI Act supervisory pathways are still being shaped, so organizations interested in testing or pilot programs should monitor the implementing act closely.
EU opens consultation on transparency guidelines for AI-generated content
The Commission is consulting on transparency guidelines for AI-generated and manipulated content, so providers should prepare labeling and disclosure controls for Article 50 now rather than waiting for final guidance.
EU finalizes general-purpose AI Code of Practice
The Commission’s finalized General-Purpose AI Code of Practice gives providers a practical route to demonstrate AI Act compliance, so GPAI teams should map their controls to the code now.
European AI Office prepares AI Act implementation guidelines and codes of practice
The European AI Office is actively preparing AI Act guidance, codes of practice, and implementation materials, so providers should expect practical compliance instructions to tighten before and after rollout.
EU consults on future cloud and AI policies tied to AI Act implementation
The Commission’s cloud-and-AI policy consultation explicitly seeks input on AI Act implementation, so organisations should treat it as an active policy-development channel that may shape future operational obligations.
EU AI Office advances GPAI code of practice and AI-generated content transparency work
The EU AI Office is actively operationalizing the AI Act through codes of practice and related guidance for general-purpose AI and AI-generated content, meaning providers should align now to avoid being behind the forthcoming compliance baseline.
EU consultation on transparency obligations under the AI Act
The Commission has launched a consultation on AI Act transparency rules, signaling that providers should prepare for clearer obligations on informing users and marking synthetic content.
EU AI Office finalizes General-Purpose AI Code of Practice
The Commission’s 2025 AI Act update makes the General-Purpose AI Code of Practice available as a voluntary compliance tool, meaning GPAI providers now have a concrete benchmark for transparency, copyright, and safety/security obligations.
EU AI Office implementation guidance and content-labeling work advances
The EU AI Office says it is preparing implementation guidelines and a code of practice for AI-generated content labeling, so providers should expect near-term interpretive detail on transparency obligations.
EU AI Act sandbox implementing act consultation closes
The Commission’s consultation on the AI Act implementing act for regulatory sandboxes closed on 2026-01-13, so organizations seeking sandbox access should now watch for the final rules and application conditions.
EU AI Office final GPAI Code of Practice available
The European Commission announced the final General-Purpose AI Code of Practice, giving GPAI providers a practical route to demonstrate AI Act compliance before the AI Office begins enforcing the relevant obligations.
DORA
ESRB Warning on systemic cyber risks from frontier AI models
The ESRB warned that frontier AI models can collapse defensive time buffers and materially increase systemic cyber risk for EU financial institutions, and it specifically points to ECB-requested action plans due by 31 October 2026 as the near-term trigger for supervisory attention.
ESAs publish first annual report on DORA major ICT-related incidents
On 2026-06-03, the EBA, EIOPA and ESMA published their first annual overview of major ICT-related incidents under DORA, underscoring that borderless ICT and AI-driven risks now require financial entities to tighten cybersecurity and incident-reporting readiness.
ISO 27001
ISO/IEC 42001
ISO/IEC 42001 certification ecosystem expands with new accreditation and audit guidance
ISO/IEC 42001 is increasingly operationalized through new accreditation and certification guidance, so organizations adopting the standard now need to validate which certifiers and audit bodies are recognized.
ISO 42001 explained
ISO’s explainer confirms certification to ISO/IEC 42001 is voluntary, so organizations should treat it as a governance framework rather than a mandatory legal requirement.
ISO/IEC 42001:2023 AI management systems
ISO/IEC 42001:2023 is the current published edition and establishes the baseline requirements for implementing an AI management system, so teams pursuing certification or AI governance alignment should treat it as the operative reference now.
ISO AI governance toolkit expands around ISO/IEC 42001 and ISO/IEC 42005
ISO’s package page shows 42001 as part of a broader AI governance toolkit alongside ISO/IEC 42005:2025, so organizations should track adjacent standards that may shape documentation and impact assessment expectations.
ISO/IEC 42001:2023 remains the reference AI management system standard
ISO confirms that ISO/IEC 42001:2023 remains the baseline standard for establishing and continually improving an AI management system, so teams should keep certification and control mappings anchored to this version.
UKAS grants first accreditation for ISO/IEC 42001 certification
UKAS accredited BSI for ISO/IEC 42001 certification, creating a live accredited certification market that materially changes how organizations can seek independent assurance for AI management systems.
ISO/IEC 42005:2025 published for AI system impact assessments
ISO published ISO/IEC 42005:2025 in May 2025, adding a formal AI system impact-assessment standard that organizations can now use to evidence structured AI governance alongside ISO/IEC 42001.
BS ISO/IEC 42006:2025 requirements for AI management system certification bodies
BSI says BS ISO/IEC 42006:2025 now sets requirements for bodies that audit and certify AI management systems, which raises the bar for ISO/IEC 42001 certification quality.
ISO/IEC AWI 42003 guidance on implementing ISO/IEC 42001
ISO has approved ISO/IEC AWI 42003 as a work item for implementation guidance, signaling that practitioners should expect new detailed advice for applying ISO/IEC 42001.
ISO/IEC 42001:2023 AI management systems
ISO/IEC 42001:2023 is the published AI management system standard, and organizations can use it now to formalize AI governance, controls, and certification-ready documentation.
BSI publishes global guidance on transparent AI decision-making
BSI announced ISO/IEC TS 6254 guidance on transparent AI decision-making, adding a practical companion resource for organizations implementing AI governance and explainability controls.
ISO/IEC 42001:2023 AI management systems standard
ISO confirms that ISO/IEC 42001:2023 remains the core certifiable AI management system standard, so organizations seeking formal AI governance assurance can now anchor their programs to a stable international standard.
NIST AI RMF
NIST AI Resource Center operationalization support
NIST’s AI Resource Center is an implementation hub for operationalizing the AI RMF, so compliance teams should use it as a support source rather than a source of new obligations.
NIST AI RMF 1.0 overview and playbook update signal
NIST’s AI RMF overview confirms the framework remains AI RMF 1.0 and says the Playbook will be enhanced, so the current change is to supporting materials rather than the base framework.
NIST AI RMF critical infrastructure profile concept note
On 2026-04-07 NIST released a concept note for a trustworthy AI in critical infrastructure profile, indicating active profile development that regulated operators should monitor now.
White House AI Action Plan reference in NIST AI materials
NIST’s AI hub notes it was named in the White House’s July 23, 2025 AI Action Plan, signaling policy direction rather than a direct legal change to the AI RMF itself.
NIST draft misuse-risk guidance targets dual-use foundation models
NIST’s draft guidance on dual-use foundation models may affect model governance and testing workflows, so teams should treat it as an emerging reference for misuse-risk management even though it is not itself an AI RMF update.
NIST generative AI profile remains a key AI RMF companion resource
NIST’s July 26, 2024 Generative AI Profile remains a key companion to AI RMF 1.0, so organizations using GenAI should continue to map controls to the profile’s risk scenarios and governance themes.
NIST AI RMF development hub remains the authoritative framework source
NIST’s development page serves as the official baseline for AI RMF 1.0 and related resources, so teams should use it as the authoritative source for the framework’s scope and companion materials.
NIST ITL AI Program confirms concept note and agentic AI evaluation work
NIST’s ITL AI Program page reiterates the April 7, 2026 concept note and a related webinar on agentic AI evaluation probes, indicating the next wave of AI RMF work is focused on testing and evaluation infrastructure.
NIST releases concept note for AI RMF Profile on Trustworthy AI in Critical Infrastructure
On April 7, 2026, NIST released a concept note for an AI RMF Profile on Trustworthy AI in Critical Infrastructure, which means critical-infrastructure AI programs should start aligning risk assessments and evaluation workflows to the emerging profile now.
NIST updated guidelines for managing misuse risk for dual-use foundation models
NIST’s second public draft on dual-use foundation-model misuse risk closed for comments on March 15, 2025, making it an important adjacent reference for foundation-model governance even though it is not the AI RMF itself.
NIST AI RMF Generative AI Profile
NIST’s generative AI profile was updated on April 8, 2026, making it the current companion reference for organizations governing GenAI risk under the AI RMF.
NIST AI Risk Management Framework hub and critical infrastructure profile concept note
NIST’s AI RMF hub now highlights a new April 7, 2026 concept note for a trustworthy AI profile in critical infrastructure, indicating the framework’s next expansion area for high-consequence sectors.
FTC AI enforcement hub
The FTC’s AI hub consolidates current enforcement materials and investigations, signaling that deceptive AI claims, model substantiation, and AI-related process inquiries remain active priority areas.
Colorado SB 189 – Automated Decision-Making Technology
Colorado SB 189 was signed by the Governor on 2026-05-14, indicating the state has enacted a new automated decision-making framework that compliance teams need to map against existing AI controls.
FTC settles deceptive “active listening” AI marketing claims with Cox Media Group and two firms
On 2026-05-21, the FTC required Cox Media Group and two other firms to pay $930,000 to resolve allegations that they falsely claimed an AI-powered “active listening” service could target ads using consumers’ smart-device conversations and that consumers had opted in.
FINMA
FINMA guidance on governance and risk management when using artificial intelligence
FINMA’s 18 December 2024 guidance says supervised institutions must adapt governance and controls to the materiality and probability of AI risks, including operational, model, data, IT/cyber, third-party, legal, and reputational risks.
FDPIC AI and data protection guidance
The FDPIC states that Switzerland’s FADP applies directly to AI-supported processing and expects manufacturers, providers, and users to be transparent about purpose, functionality, and data sources.
FDPIC guidance on AI and data protection
The FDPIC’s AI guidance states that the Swiss FADP applies directly to AI-supported processing and requires transparency about purpose, functionality, and data sources, which elevates compliance expectations for AI deployments in Switzerland.
HIPAA
FDA AI-enabled medical device guidance and lifecycle expectations
FDA’s AI/ML medical device guidance set and device list continue to expand, so AI health-tech teams need to align premarket, transparency, and change-control evidence before new or modified systems are submitted or marketed.
FDA draft guidance on artificial intelligence-enabled medical devices
The FDA’s January 2025 draft guidance on AI-enabled medical devices remains the key current benchmark for lifecycle, transparency, bias, and documentation expectations for AI device submissions and post-market controls.
CCPA/CPRA
California AI and privacy legislative activity remains active
California’s AI/privacy legislative tracker and related materials show continuing state-level momentum on transparency, governance, and AI-specific consumer rights, so deployers should expect additional California requirements to layer on top of federal obligations.
Multiple AI-related U.S. court and state actions signal rising litigation risk
The source set includes multiple recent court decisions and state legislative actions around AI, biometric data, and automated decision tools, indicating that U.S. litigation and state-law exposure for AI systems is expanding even without a single federal AI statute.
California SB 947 – Employment: automated decision systems
California SB 947 remained in motion on 2026-05-20, so employers and HR vendors should track it closely for prospective rules governing automated decision systems in hiring and employment.
California AB 2575 – Health care services: artificial intelligence
California AB 2575 was last acted on 2026-05-18 and is still moving as an introduced bill, so healthcare AI teams should track it for emerging state-level obligations rather than treat it as operative law.
GDPR
EDPB adopts final guidance on anonymisation and web scraping for generative AI
The EDPB adopted final guidelines on anonymisation and web scraping for generative AI on 2026-07-08, creating an immediate supervisory reference point for model-training and de-identification practices under the GDPR.
ICO AI and data protection guidance remains the regulator’s operational baseline
The ICO says its AI guidance is both compliance best practice and the basis for audit/enforcement activity, so organizations processing personal data in AI systems must treat it as current supervisory expectation, not optional advice.
ICO investigation into Grok
The ICO has opened an investigation into Grok, signaling active enforcement scrutiny of AI processing under UK data protection law rather than a purely policy-level review.
ICO guidance on AI and data protection
The ICO’s AI guidance remains the key UK data-protection reference for AI systems, and the page is under review because of the Data (Use and Access) Act coming into force on 19 June 2025.
AI v The Information Commissioner – FOIA vexatious request appeal allowed
On 2026-05-22 the UK First-tier Tribunal allowed the appeal and ordered the Leeds Teaching Hospitals NHS Trust to issue a fresh FOIA response by 4:00 p.m. on 2026-06-19, rejecting the vexatious-request characterization under section 14(1).
Other updates
Singapore updates its Model AI Governance Framework for Agentic AI
IMDA updated its agentic AI governance framework in May 2026, so organizations using autonomous or multi-agent systems should refresh their control assumptions, human accountability model, and end-user transparency now.
ICO AI and data protection guidance remains active and under review
The ICO says its AI guidance is not statutory but is used for audit and enforcement, and it is under review due to the UK’s newer data legislation, so organizations should treat it as live supervisory guidance.
FDPIC confirms Swiss data-protection law applies directly to AI
The FDPIC reiterates that the Swiss Federal Data Protection Act applies directly to AI-supported processing, so organizations cannot wait for a separate AI statute before fixing transparency, automated-decision, and human-review controls.
FTC enforcement against deceptive AI claims continues
The FTC’s AI enforcement actions and related press releases show that deceptive AI performance claims remain an active Section 5 risk, so marketing and product teams need substantiation before regulators ask for it.
FTC seeks public comment on AI accuracy policy statement
On 2026-07-07, the FTC proposed a policy statement on AI accuracy, signaling that claims and system behavior that manipulate expected accuracy may be treated as deceptive under Section 5.
ESAs support ESRB warning on systemic cyber risks from frontier AI models
On 2026-07-07, the European Supervisory Authorities backed the ESRB’s warning that frontier AI models can create systemic cyber risks for financial markets, elevating AI cyber resilience as a supervisory priority.
Congressional AI-related bills remain active but are not a single federal AI regime
Several AI-adjacent bills are active in Congress, but they do not create a unified federal AI law, so federal compliance planning remains agency-driven rather than statute-driven.
FTC seeks public comment on proposed AI accuracy policy statement
The FTC opened public comment on a proposed policy statement targeting AI accuracy claims, signaling that businesses making AI-performance representations should expect scrutiny over substantiation and deception risk now.
SEC AI-washing enforcement against investment advisers and issuers
The SEC’s AI-washing cases against advisers and related enforcement commentary confirm that false or exaggerated statements about AI use in securities business lines are a live anti-fraud issue, not a theoretical disclosure concern.
FTC crackdown on deceptive AI claims and AI-washing
The FTC’s Operation AI Comply and related case activity show it is actively targeting deceptive or unsupported AI marketing claims, so any AI performance, automation, or targeting assertion now carries immediate enforcement risk.
California SB1159 advances on AI transparency and governance
California SB1159 is moving forward on AI transparency and governance, so organizations should prepare for potential state-level governance, disclosure, or accountability requirements.
New York FAIR news act proposals would require generative AI transparency in news content
New York’s FAIR news act bills would require transparency for news content created with generative AI, so publishers and content platforms should track whether labeling and disclosure rules emerge.
California SB947 moves forward on automated decision systems in employment
California SB947 advanced out of committee on automated decision systems in employment, so employers using AI for hiring or workforce decisions should prepare for possible new disclosure and governance duties.
California AB2575 advances healthcare AI legislation
California AB2575 is moving through the legislature on AI in health care services, so covered organizations should track whether it introduces new governance, disclosure, or oversight duties for clinical AI use.
FTC Air.ai case shows enforcement against AI-enabled deceptive business opportunities
The FTC’s Air.ai matter shows that AI branding used in deceptive business-opportunity schemes can still trigger enforcement, so teams should not assume “AI” language lowers the fraud risk.
FTC launches Operation AI Comply crackdown on deceptive AI schemes
FTC’s Operation AI Comply signals active enforcement against deceptive or unfair AI schemes, so organizations should expect closer scrutiny of AI marketing, product claims, and consumer-facing automation.
FTC orders accessiBe to stop deceptive AI accessibility claims and pay $1 million
The FTC settlement with accessiBe bars unsupported claims that its AI tool could make websites WCAG-compliant and imposes $1 million in relief, so AI accessibility marketing now needs hard substantiation.
FTC finalizes DoNotPay order over deceptive AI lawyer claims
The FTC finalized its DoNotPay order, imposing monetary relief and barring deceptive AI-lawyer claims, which means legal and compliance teams must police any claims that AI can replace professional services.
FTC seeks substantiation for Workado's AI detection accuracy claims
The FTC proposed an order against Workado over unsupported claims that its AI content detector was 98% accurate, so AI vendors must substantiate performance claims and preserve the evidence now.
FTC continues AI deception and AI-companion scrutiny
The FTC’s recent AI enforcement and 6(b) activity shows that deceptive AI claims, misleading chatbot marketing, and data-handling practices remain active enforcement targets and can trigger orders, notices, or information demands without new AI-specific legislation.
California AB2575 health care services artificial intelligence
California AB2575 was introduced to regulate AI in health care services, adding to the state’s growing AI governance patchwork and requiring ongoing monitoring by health-sector operators.
SEC actions on false and misleading AI statements
SEC enforcement releases in 2024–2026 show the Commission continuing to treat false or misleading AI claims as a disclosure and fraud problem for public companies and advisers.
FTC inquiry into generative AI investments and partnerships
The FTC’s 6(b)-style inquiry into major AI investments and partnerships signals antitrust and market-structure scrutiny for AI deals and ecosystem concentration.
FTC authorization for compulsory process for AI-related products and services
The FTC approved compulsory-process authority for AI-related products and services, suggesting faster investigative requests and higher scrutiny of AI claims and practices.
FTC action against IntelliVision for deceptive facial recognition claims
FTC alleged that IntelliVision made unsupported claims that its facial recognition software was bias-free, highly accurate, and spoof-resistant, and the proposed order would bar future claims unless backed by competent and reliable testing.
FTC crackdown on deceptive AI claims and schemes
The FTC’s Operation AI Comply shows the agency is actively pursuing deceptive or unfair AI claims, making substantiation and marketing accuracy urgent compliance issues now.
FCA, Bank of England and Treasury joint statement on frontier AI models and cyber resilience
The FCA, Bank of England, and HM Treasury said firms must be able to identify, monitor, and manage external AI-related applications, libraries, and services integrated into their networks, raising the bar for cyber and third-party resilience.
FCA Mills Review on how AI will reshape retail financial services
The FCA launched a review of advanced AI’s impact on retail financial services, with feedback due 24 February 2026 and recommendations expected for the FCA Board in summer 2026.
COVID-19 Origin Act of 2023
The COVID-19 Origin Act of 2023 was enacted as Public Law No. 118-2 on 2023-03-20, making it a completed federal legislative item with no new AI compliance obligation identified in the source.
Singapore PDPC advisory guidelines on personal data in AI recommendation and decision systems
PDPC finalized advisory guidelines on the use of personal data in AI recommendation and decision systems, clarifying PDPA expectations for training and deployment workflows that use personal data.
Singapore publishes Model AI Governance Framework for Agentic AI
IMDA published Version 1.0 of the Model AI Governance Framework for Agentic AI on 2026-01-22, creating immediate governance expectations for autonomous AI systems that reason and act on their own.
California AB2545 labor force impact report on AI advances
California AB2545 cleared committee on 2026-05-14, indicating growing legislative interest in AI labor impacts and signaling a possible future reporting obligation for employers and developers.
California AB1979 advances on health care AI
California AB1979 passed committee on 2026-05-14, keeping health-care AI regulation active in California and requiring providers and vendors to continue preparing for disclosure and oversight duties.
New York bill on technological displacement notice and workforce transition
New York S08589 was printed on 2026-05-14 and would require notice, reporting, and a workforce transition period before technological displacement, so employers should assess restructuring plans now.
Colorado SB189 sent to governor on automated decision-making technology
Colorado SB189 was sent to the governor on 2026-05-12, meaning a statewide automated decision-making law may be imminent and organizations should finalize gap remediation before enactment.
California SB947 advances on employment automated decision systems
California SB947 was read a second time and amended on 2026-05-14, so employers should expect a rapidly evolving employment-AI compliance bill and begin impact assessment planning now.
New York automated lending decision tools bill advances
New York A00773 advanced to third reading on 2026-04-30, signaling imminent scrutiny of automated lending tools and the need to prepare consent/opt-out and governance controls now.
Weekly digest
Leave your email to get each issue in your inbox. Free, no account required.
We use your email only for the digest. Privacy policy