AI Regulation Tracker
The 100 most recent verified regulatory updates, grouped by framework. Browse all activity for a framework on its hub page.
EU AI Act
AI Act consultations and implementation guidance for GPAI, sandboxes, and transparency
The Commission has opened or advanced multiple AI Act implementation workstreams for GPAI, high-risk classification, transparency, and regulatory sandboxes, meaning providers and deployers must now align their implementation plans to the emerging guidance rather than wait for finalised national practice.
EU AI Act implementation consultations advance on GPAI, transparency, high-risk classification and sandboxes
The Commission’s AI Act consultations on GPAI, transparency obligations, high-risk classification, sandboxes, and the scientific panel show that the operational rulebook is still being finalized, so affected providers should engage now to shape interpretation.
EU AI Office and supervisors call for enhanced governance for frontier AI in financial services
EU financial supervisors and the AI Office are signaling stronger governance and consistent supervision expectations for frontier AI models in the financial sector, so firms should treat this as an immediate AI Act implementation and risk-governance update rather than a future issue.
EU AI Office and Commission implementation guidance for AI Act and GPAI code
The Commission and AI Office have moved from policy design into active AI Act implementation by issuing operational guidance on transparency, GPAI obligations, and governance, making immediate compliance mapping necessary for providers facing Article 50 and GPAI code expectations.
CJEU preliminary reference on whether AI software can be a high-risk AI system
A 2026 CJEU preliminary reference asks whether software using AI elements qualifies as a high-risk AI system, which could materially affect classification, oversight, and traceability expectations under the AI Act.
EU AI Office promotes Code of Practice on transparency of AI-generated content
The AI Office’s transparency code for AI-generated content is designed to support Article 50 compliance and applies from 2026-08-02, so content provenance and labeling controls now need to be operationalized.
EU AI Office publishes GPAI compliance guidance and transparency obligations
The European Commission’s AI Office issued GPAI and transparency guidance in 2026 and confirmed that full enforcement of GPAI and transparency obligations begins on 2026-08-02, creating an immediate deadline for providers and deployers.
Commission publishes transparency guidance under the AI Act
The Commission published guidance on Article 50 transparency obligations ahead of the 2 August 2026 applicability date, so providers and deployers now need to operationalize labeling and disclosure workflows rather than wait for enforcement to start.
Digital Omnibus on AI amends the EU AI Act
Regulation (EU) 2026/1744 amends the AI Act and makes the new prohibitions on realistic intimate/deepfake-style synthetic content and the updated Article 50 transparency obligations operative from 2 December 2026, creating immediate implementation work for AI providers and deployers.
CJEU preliminary reference on whether AI-assisted expert reporting is high-risk under the AI Act
A 2026 CJEU reference asks whether software generating automated outcomes or using AI elements in an expert report should be treated as a high-risk AI system under the AI Act, creating interpretive uncertainty for litigation-support tools.
European Commission AI Office implementation guidance and GPAI compliance support
The Commission’s AI Office continues publishing guidance and code-of-practice materials to operationalize AI Act obligations for GPAI providers, creating near-term compliance expectations even before further implementing acts land.
EESC opinion on the AI Omnibus and Digital Omnibus simplification proposals
The EESC backed simplification of the AI Act and digital rulebook while warning that high-risk AI obligations are still expected to become binding as early as August 2026, so firms should not delay compliance planning pending omnibus negotiations.
AI Act consultations on sandboxes, rights reservations, and scientific panel
The Commission has opened consultation processes on AI regulatory sandboxes, rights-reservation protocols for text and data mining, and the scientific panel, signaling that implementation architecture is still being built and that stakeholders should feed in compliance concerns now.
Commission releases GPAI Code of Practice and implementation guidance
The Commission has made the general-purpose AI Code of Practice available and issued companion guidance, giving GPAI providers a concrete compliance path they can use now to demonstrate AI Act conformity rather than waiting for further enforcement detail.
EU consults on scientific panel for AI Act oversight
The Commission is consulting on the AI Act scientific panel, indicating that expert oversight infrastructure is still being finalized and could influence how technical disputes and risk questions are handled.
EU seeks feedback on AI regulatory sandboxes under the AI Act
The Commission’s sandbox consultation shows that AI Act supervisory pathways are still being shaped, so organizations interested in testing or pilot programs should monitor the implementing act closely.
EU opens consultation on transparency guidelines for AI-generated content
The Commission is consulting on transparency guidelines for AI-generated and manipulated content, so providers should prepare labeling and disclosure controls for Article 50 now rather than waiting for final guidance.
EU finalizes general-purpose AI Code of Practice
The Commission’s finalized General-Purpose AI Code of Practice gives providers a practical route to demonstrate AI Act compliance, so GPAI teams should map their controls to the code now.
European AI Office prepares AI Act implementation guidelines and codes of practice
The European AI Office is actively preparing AI Act guidance, codes of practice, and implementation materials, so providers should expect practical compliance instructions to tighten before and after rollout.
DORA
EBA, EIOPA and ESMA call for enhanced governance over frontier AI ICT risks in EU financial services
On 2026-07-31, the EU supervisory authorities called for stronger governance and consistent supervision to mitigate ICT risks from frontier AI models in the financial sector, signaling that firms should tighten controls now rather than wait for formal rule changes.
ESA call for enhanced governance and consistent supervision of frontier AI ICT risks
On 2026-07-31, EBA, EIOPA and ESMA called on EU financial-sector firms and supervisors to tighten governance and supervision of frontier AI-related ICT risks, signaling immediate expectations for stronger control frameworks under existing resilience obligations.
ESAs call for stronger governance over frontier AI ICT risks in EU finance
On 2026-07-31, the EBA, EIOPA and ESMA issued a joint statement urging a cross-sector, risk-based and consistent supervisory approach for frontier AI models because their ICT risks are now a live supervisory concern in the EU financial sector.
ESRB Warning on systemic cyber risks from frontier AI models
The ESRB warned that frontier AI models can collapse defensive time buffers and materially increase systemic cyber risk for EU financial institutions, and it specifically points to ECB-requested action plans due by 31 October 2026 as the near-term trigger for supervisory attention.
ISO/IEC 42001
Singapore updates agentic AI governance framework and PDPC personal-data guidance
Singapore has updated its model AI governance framework for agentic AI and already has advisory guidelines for personal-data use in AI recommendation and decision systems, so organizations should refresh governance, human oversight, and data-use controls now.
ICO AI and data protection guidance remains active but under review
The ICO says its AI guidance supports audit and enforcement activity and is under review following the Data (Use and Access) Act 2025, so UK organizations should keep using it as the current baseline while planning for revisions.
ISO/IEC 42006:2025 defines requirements for AI management system certification bodies
ISO/IEC 42006:2025 supplements the requirements for bodies auditing and certifying AI management systems against ISO/IEC 42001; the ISO catalog records its publication in July 2025.
ISO AI management-system and adjacent AI standards pipeline expands
ISO’s AI standards pages and draft items show an active pipeline around AI management systems, audit/certification, societal concerns, and privacy protection, so organizations pursuing ISO-based assurance should update their standards watchlist now.
ISO/IEC 42001 certification ecosystem expands with new accreditation and audit guidance
ISO/IEC 42001 is increasingly operationalized through new accreditation and certification guidance, so organizations adopting the standard now need to validate which certifiers and audit bodies are recognized.
ISO 42001 explained
ISO’s explainer confirms certification to ISO/IEC 42001 is voluntary, so organizations should treat it as a governance framework rather than a mandatory legal requirement.
ISO/IEC 42001:2023 AI management systems
ISO/IEC 42001:2023 is the current published edition and establishes the baseline requirements for implementing an AI management system, so teams pursuing certification or AI governance alignment should treat it as the operative reference now.
NIST AI RMF
FCA confirms no new AI-specific rules for financial services
The FCA says it is not planning AI-specific regulation and will rely on existing frameworks such as Consumer Duty and SM&CR, so firms should focus on fitting AI governance into current control regimes rather than waiting for a new rulebook.
California AI bills advancing on healthcare and employment automation
California’s 2026 AI bills on healthcare services and automated decision systems advanced late in session, so employers and health providers should continue tracking whether they become enacted obligations.
SEC announces internal AI task force
The SEC announced an internal AI task force on 1 August 2025 to coordinate responsible AI adoption across the agency; the announcement does not introduce a new external compliance obligation.
FTC AI enforcement actions on deceptive claims and substantiation
These records cover separate FTC proceedings concerning AI claims, an AI companion chatbot inquiry, and the later setting aside of the Rytr order; they do not establish a common new compliance deadline.
NIST AI RMF revision and critical-infrastructure profile development
NIST says the AI RMF is being revised and that a new trustworthy-use profile for critical infrastructure is under development, while the baseline AI RMF 1.0 remains voluntary and headed for review no later than 2028.
NIST signals revision of AI RMF and new critical-infrastructure profile work
NIST’s AI RMF materials state that the framework is being revised and that a new critical-infrastructure trustworthy-AI profile was launched on 2026-04-07, so organizations relying on the RMF should track the revision now for shifting implementation guidance.
MindSift LLC matter
The FTC matter against MindSift alleges deceptive AI-powered active-listening and opt-in claims, underscoring immediate enforcement risk where AI functionality or data-collection claims are overstated.
NIST SP 1353 AI-enabled CSF analysis and reporting draft
NIST issued the initial public draft of SP 1353 on 2026-08-19 and set comments due by 2026-10-15, so teams using AI for CSF analysis should assess the draft and submit feedback before the close date.
NIST AI RMF update process tied to White House AI Action Plan
NIST says the AI RMF 1.0 is being revised under the July 23, 2025 White House AI Action Plan, which means organizations relying on the framework should expect updated implementation guidance and profile changes rather than a static reference.
US voluntary AI commitments and frontier AI policy direction
White House voluntary AI commitments remain a benchmark for frontier AI governance, so firms should continue aligning safety testing, provenance, cybersecurity, and information-sharing controls even though the commitments are nonbinding.
FTC deceptive AI claims enforcement and AI accuracy policy proposal
The FTC is actively enforcing against deceptive AI claims and has proposed an AI accuracy policy statement, so companies must immediately substantiate AI performance, output accuracy, and marketing representations or face Section 5 exposure.
NIST AI Resource Center operationalization support
NIST’s AI Resource Center is an implementation hub for operationalizing the AI RMF, so compliance teams should use it as a support source rather than a source of new obligations.
NIST AI RMF 1.0 overview and playbook update signal
NIST’s AI RMF overview confirms the framework remains AI RMF 1.0 and says the Playbook will be enhanced, so the current change is to supporting materials rather than the base framework.
NIST AI RMF critical infrastructure profile concept note
On 2026-04-07 NIST released a concept note for a trustworthy AI in critical infrastructure profile, indicating active profile development that regulated operators should monitor now.
White House AI Action Plan reference in NIST AI materials
NIST’s AI hub notes it was named in the White House’s July 23, 2025 AI Action Plan, signaling policy direction rather than a direct legal change to the AI RMF itself.
NIST draft misuse-risk guidance targets dual-use foundation models
NIST’s draft guidance on dual-use foundation models may affect model governance and testing workflows, so teams should treat it as an emerging reference for misuse-risk management even though it is not itself an AI RMF update.
SOC 2 + AI
AICPA SOC 2 resources reaffirm current Trust Services Criteria for AI-enabled services
AICPA’s SOC resources confirm the current Trust Services Criteria baseline and do not create AI-specific rules, but they reinforce that AI-enabled services must still satisfy existing security, privacy, and processing integrity controls in audits.
DoNotPay final order on deceptive AI lawyer claims
The FTC finalized its DoNotPay order in February 2025, prohibiting deceptive AI lawyer claims and requiring monetary relief and notice, which raises the bar for substantiation of legal-assistance AI products.
FTC AI enforcement and policy hub
The FTC’s AI hub consolidates recent AI enforcement and policy actions, reinforcing that deceptive or unsubstantiated AI capability claims remain an active Section 5 enforcement risk for vendors and deployers.
FTC inquiry into AI chatbots acting as companions
The FTC has launched a formal inquiry into AI companion chatbots, signaling intensified scrutiny of data practices, age protections, and safety controls even before any new rulemaking or enforcement order is issued.
FTC final order against Workado for misleading AI accuracy claims
The FTC has entered a final order against Workado over false claims about AI content-detection accuracy, requiring substantiation and multi-year compliance reporting, so AI marketing claims must now be treated as an active enforcement risk.
FINMA
Swiss FDPIC guidance on AI and data protection, plus legislative roadmap
The FDPIC has made clear that Switzerland’s data protection law already applies to AI-supported processing and that the federal government is targeting an AI bill by the end of 2026, so organizations should harden transparency and automated-decision controls now.
FINMA sets governance and risk-management expectations for AI use in Swiss financial institutions
FINMA’s 2024 guidance states that Swiss financial institutions using AI must identify, limit, control, and monitor AI-related risks within their existing supervisory framework, so firms should immediately test whether their governance and model-risk controls are adequate.
FDPIC says Swiss data-protection law applies directly to AI-supported processing
On 2025-05-08, the FDPIC reiterated that Switzerland’s data-protection law already applies directly to AI-supported processing, meaning transparency, purpose limitation, and data-subject rights must be built into current AI operations now.
AIUC-1
HIPAA
FDA AI-enabled medical device and PCCP guidance baseline
FDA’s August 2025 PCCP guidance provides recommendations for planned modifications to AI-enabled devices reviewed through the 510(k), De Novo and PMA pathways.
FDA continues AI-enabled medical device guidance and submissions workflow updates
FDA’s AI-enabled medical device materials show an active draft-guidance and feedback cycle, with public feedback on generative AI-enabled medical devices due by 2026-10-19, so device teams need to prepare submission and validation materials now.
FDA draft guidance for developers of AI-enabled medical devices
FDA’s January 2025 draft guidance for AI-enabled medical devices puts lifecycle documentation, transparency, maintenance, and bias controls front and center, so device teams should align submissions and post-market processes now.
FDA final guidance on clinical decision support software
FDA’s January 2026 final guidance clarifies when clinical decision support software is outside device regulation and when FDA oversight still applies, so AI health tools must be re-triaged immediately against the final criteria.
FDA draft guidance and AI-enabled medical device lifecycle expectations
FDA has issued comprehensive draft guidance for AI-enabled medical devices and continues to emphasize lifecycle documentation, PCCPs, and real-world performance monitoring, so device teams need to update submissions and postmarket controls now.
FDA seeks public comment on real-world evaluation of AI-enabled medical devices
FDA opened a public comment process in 2025 on how to measure and evaluate AI-enabled medical device performance in the real world, with comments due 2025-09-25 and implications for post-market monitoring and drift management.
FDA AI-enabled medical device guidance and lifecycle expectations
FDA’s AI/ML medical device guidance set and device list continue to expand, so AI health-tech teams need to align premarket, transparency, and change-control evidence before new or modified systems are submitted or marketed.
CCPA/CPRA
California AI health-care bills and transparency bill advance in the 2026 session
Several California AI bills were active in late August 2026, including health-care AI and transparency measures moving through amendments and enrollment, meaning California-facing AI teams should monitor final text closely for new obligations.
FTC AI enforcement posture remains active across deceptive claims and AI investments
The FTC’s AI hub and related matters, including Rytr, Workado, and DoNotPay, show that the agency continues to police deceptive AI claims and conduct, so AI product and marketing teams should assume ongoing enforcement scrutiny now.
FTC finalizes orders against Cox Media Group and two other firms over deceptive AI-powered marketing claims
On 2026-08-27, the FTC finalized orders and $930,000 in settlements after alleging the firms falsely claimed an AI-powered “active listening” ad service and deceptive customer consent, creating immediate enforcement risk for any AI marketing claims that are not fully substantiated.
California AI bills on healthcare, employment, and transparency
California state AI bills AB2575, SB947, SB503, AB1979, and SB1159 advanced in late August 2026, signaling continued movement on healthcare AI, automated decision systems, and AI transparency/governance.
Historical Congressional source: no current AI obligation identified
The linked source is a 1996 Congressional bill record and does not establish a current AI compliance update. It is retained here to explain the correction to the earlier entry.
California SB947 on employment automated decision systems
California SB947 would regulate employment automated decision systems, so employers and HR vendors should begin mapping any hiring, promotion, or screening tools against likely disclosure and oversight obligations while the bill is still moving.
California AI bills advance on employment, health care, and governance
Multiple California AI bills moved forward on August 12-13, 2026, including measures on automated decision systems, agentic AI, transparency, and health-care AI, so companies operating in California should treat state legislative tracking as an active near-term compliance task.
California 2026 AI bills on employment, health care, and agentic AI
California has introduced multiple AI bills affecting employment, health care, labor impacts, and agentic AI, and several were already set for hearing or suspense-file consideration as of early August 2026, so employers and AI vendors should review them immediately.
California AI and privacy legislative activity remains active
California’s AI/privacy legislative tracker and related materials show continuing state-level momentum on transparency, governance, and AI-specific consumer rights, so deployers should expect additional California requirements to layer on top of federal obligations.
GDPR
FDPIC guidance and enforcement focus on AI and data protection
The FDPIC states that the Swiss FADP applies directly to AI-supported processing and is actively pursuing investigations, so organizations using AI with personal data must now evidence transparency, proportionality, purpose limitation, and human review readiness.
EDPB adopts final guidance on anonymisation and web scraping for generative AI
The EDPB adopted final guidelines on anonymisation and web scraping for generative AI on 2026-07-08, creating an immediate supervisory reference point for model-training and de-identification practices under the GDPR.
ICO AI and data protection guidance remains the regulator’s operational baseline
The ICO says its AI guidance is both compliance best practice and the basis for audit/enforcement activity, so organizations processing personal data in AI systems must treat it as current supervisory expectation, not optional advice.
Other updates
Recent state-level court decisions with AI-adjacent implications
The source set includes multiple recent state and federal court decisions that may affect AI-related liability and employment disputes, so legal teams should monitor them as developing precedent rather than settled regulatory rules.
Congressional AI bills and resolutions introduced in 119th Congress
Multiple 119th Congress measures listed on Congress.gov, including AI-adjacent resolutions and bills, were introduced or advanced in 2025 but do not yet create binding federal AI obligations.
SEC charges advisers with false AI claims
The SEC charged two investment advisers for making false and misleading statements about their use of artificial intelligence, confirming that AI-wash in financial marketing and disclosures is an enforcement priority.
SEC creates AI Task Force to coordinate agency AI oversight
On 2025-08-01, the SEC created an AI Task Force to coordinate innovation and efficiency across the agency, signaling more structured internal oversight of AI-related supervisory and enforcement activity.
FTC launches inquiry into AI companion chatbots
On 2025-09-01, the FTC launched 6(b) orders into AI companion chatbots, signaling that advertising, safety, and data-handling practices for consumer chatbots are under active federal review.
FTC orders $1 million penalty over deceptive accessibility-compliance AI claims
The FTC took action against deceptive claims that an AI product could make websites WCAG-compliant, reinforcing that capability claims tied to compliance outcomes must be fully substantiated before they are marketed.
FTC finalizes order against DoNotPay over deceptive AI lawyer claims
The FTC finalized an order on 2025-02-xx/2025-02 against DoNotPay that prohibits deceptive 'AI lawyer' claims and imposes monetary relief and consumer-notice obligations, making unsupported AI marketing an immediate enforcement risk.
Singapore updates its Model AI Governance Framework for Agentic AI
IMDA updated its agentic AI governance framework in May 2026, so organizations using autonomous or multi-agent systems should refresh their control assumptions, human accountability model, and end-user transparency now.
ICO AI and data protection guidance remains active and under review
The ICO says its AI guidance is not statutory but is used for audit and enforcement, and it is under review due to the UK’s newer data legislation, so organizations should treat it as live supervisory guidance.
FDPIC confirms Swiss data-protection law applies directly to AI
The FDPIC reiterates that the Swiss Federal Data Protection Act applies directly to AI-supported processing, so organizations cannot wait for a separate AI statute before fixing transparency, automated-decision, and human-review controls.
FTC enforcement against deceptive AI claims continues
The FTC’s AI enforcement actions and related press releases show that deceptive AI performance claims remain an active Section 5 risk, so marketing and product teams need substantiation before regulators ask for it.
FTC seeks public comment on AI accuracy policy statement
On 2026-07-07, the FTC proposed a policy statement on AI accuracy, signaling that claims and system behavior that manipulate expected accuracy may be treated as deceptive under Section 5.
ESAs support ESRB warning on systemic cyber risks from frontier AI models
On 2026-07-07, the European Supervisory Authorities backed the ESRB’s warning that frontier AI models can create systemic cyber risks for financial markets, elevating AI cyber resilience as a supervisory priority.
Congressional AI-related bills remain active but are not a single federal AI regime
Several AI-adjacent bills are active in Congress, but they do not create a unified federal AI law, so federal compliance planning remains agency-driven rather than statute-driven.
FTC seeks public comment on proposed AI accuracy policy statement
The FTC opened public comment on a proposed policy statement targeting AI accuracy claims, signaling that businesses making AI-performance representations should expect scrutiny over substantiation and deception risk now.
SEC AI-washing enforcement against investment advisers and issuers
The SEC’s AI-washing cases against advisers and related enforcement commentary confirm that false or exaggerated statements about AI use in securities business lines are a live anti-fraud issue, not a theoretical disclosure concern.
FTC crackdown on deceptive AI claims and AI-washing
The FTC’s Operation AI Comply and related case activity show it is actively targeting deceptive or unsupported AI marketing claims, so any AI performance, automation, or targeting assertion now carries immediate enforcement risk.
California SB1159 advances on AI transparency and governance
California SB1159 is moving forward on AI transparency and governance, so organizations should prepare for potential state-level governance, disclosure, or accountability requirements.
New York FAIR news act proposals would require generative AI transparency in news content
New York’s FAIR news act bills would require transparency for news content created with generative AI, so publishers and content platforms should track whether labeling and disclosure rules emerge.
California SB947 moves forward on automated decision systems in employment
California SB947 advanced out of committee on automated decision systems in employment, so employers using AI for hiring or workforce decisions should prepare for possible new disclosure and governance duties.
California AB2575 advances healthcare AI legislation
California AB2575 is moving through the legislature on AI in health care services, so covered organizations should track whether it introduces new governance, disclosure, or oversight duties for clinical AI use.
FTC Air.ai case shows enforcement against AI-enabled deceptive business opportunities
The FTC’s Air.ai matter shows that AI branding used in deceptive business-opportunity schemes can still trigger enforcement, so teams should not assume “AI” language lowers the fraud risk.
FTC launches Operation AI Comply crackdown on deceptive AI schemes
FTC’s Operation AI Comply signals active enforcement against deceptive or unfair AI schemes, so organizations should expect closer scrutiny of AI marketing, product claims, and consumer-facing automation.
FTC orders accessiBe to stop deceptive AI accessibility claims and pay $1 million
The FTC settlement with accessiBe bars unsupported claims that its AI tool could make websites WCAG-compliant and imposes $1 million in relief, so AI accessibility marketing now needs hard substantiation.
FTC finalizes DoNotPay order over deceptive AI lawyer claims
The FTC finalized its DoNotPay order, imposing monetary relief and barring deceptive AI-lawyer claims, which means legal and compliance teams must police any claims that AI can replace professional services.
FTC seeks substantiation for Workado's AI detection accuracy claims
The FTC proposed an order against Workado over unsupported claims that its AI content detector was 98% accurate, so AI vendors must substantiate performance claims and preserve the evidence now.
Weekly digest
Leave your email to get each issue in your inbox. Free, no account required.
We use your email only for the digest. Privacy policy