Explore
Coming into force
Enacted AI law that starts applying after the data date, by month: plan the guard before the date, not after launch.
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.
43 dated obligation starts from 38 rules in 9 jurisdictions, 1 Oct 2026 to 1 Jan 2029, as of the data date 2026-10-01. Stayed laws are listed with the date they would apply from. Dates change (amendments, stays, court orders): check the official source.
Download the calendar (.ics) One all-day event per obligation start; import it into any calendar app.
October 2026
· Connecticut (US-CT) · a further phase of law in force
Large GenAI providers must embed tamper-resistant provenance data (Connecticut) Conn. PA 26-15 Sec. 15(b)
Sec. 15 takes effect October 1, 2026: covered providers (more than one million users per month, publicly accessible to consumers for personal use) include tamper-resistant provenance data in AI-created or materially altered audio, image and video.
Guard: Mark every generated image, audio, video, or text output with machine-readable provenance, such as a signed C2PA manifest or watermark, before it is saved, served, or published. Control
December 2026
· European Union (EU) · first application
AI generating non-consensual intimate imagery or CSAM is prohibited (EU AI Act Art. 5(1)(ba),(bb)) Article 5(1)(ba),(bb) [as inserted by Reg. (EU) 2026/1744]
Article 5(1)(ba), (bb), (1a) and (1b) apply from 2 December 2026 (Art. 113, third paragraph, point (a)).
Guard: Classify prompts, uploads, and outputs for sexual content and minors on every image, video, or audio generation path, refuse sexual edits of real people, and keep a misuse-report route. Control
· European Union (EU) · a further phase of law in force
Synthetic AI output must be machine-readably marked as artificial Article 50(2)
Systems placed on the market before 2 August 2026 must comply with Art. 50(2) by 2 December 2026 (Art. 111(4)).
Guard: Mark every generated image, audio, video, or text output with machine-readable provenance, such as a signed C2PA manifest or watermark, before it is saved, served, or published. Control
January 2027
· California (US-CA) · first application
GenAI hosting platforms must not distribute systems that omit disclosures (California) Cal. Bus. & Prof. Code 22757.3.2(a)
Guard: Embed a signed C2PA manifest or equivalent latent disclosure in generated or captured media when it is created, and do not distribute systems or files that lack it. Control
· California (US-CA) · first application
Large online platforms must detect and display content provenance (California) Cal. Bus. & Prof. Code 22757.3.1(a)
Guard: Read embedded C2PA provenance on upload, preserve it through media processing, and show users a Content Credentials indicator with a way to inspect the data. Control
· California (US-CA) · first application
Consumers requesting access to ADMT must receive a plain-language explanation 11 CCR 7200(a)-(b)
CCPA-covered businesses using ADMT for significant decisions concerning California consumers must provide the Article 11 access explanation on request.
Guard: Store each ADMT decision's purpose, logic, output, and use at decision time, and return them in plain language from a consumer access-request path. Control
· California (US-CA) · first application
Consumers must be able to opt out of automated decision technology 11 CCR 7010(c)-(d)
CCPA-covered businesses using ADMT for significant decisions concerning California consumers must provide an opt-out or qualifying human-appeal alternative.
Guard: Offer an ADMT opt-out (or a qualifying human appeal), store the consumer's choice, and check it before the model runs on any significant-decision path. Control
· California (US-CA) · first application
Automated decision technology requires pre-use notice 11 CCR 7010(c)-(d)
CCPA-covered businesses using ADMT for significant decisions concerning California consumers must provide the Article 11 pre-use notice.
Guard: Send the person an AI-use notice on the decision path, before or when an AI system makes or substantially factors a consequential decision about them, and record its delivery. Control
· Colorado (US-CO) · stayed: would apply from this date
Adverse ADMT outcomes require a 30-day plain-language explanation C.R.S. 6-1-1704(3)
Guard: Send each adverse AI-assisted decision with its main reasons and the AI's role, plus a way to correct data and appeal to a human who can change the outcome. Control
· Colorado (US-CO) · stayed: would apply from this date
Deployers must give point-of-interaction notice when covered ADMT influences a consequential decision C.R.S. 6-1-1704(1)
Guard: Send the person an AI-use notice on the decision path, before or when an AI system makes or substantially factors a consequential decision about them, and record its delivery. Control
· Colorado (US-CO) · stayed: would apply from this date
Developers of covered ADMT must document intended uses, training data, and limitations for deployers C.R.S. 6-1-1702(1)
Guard: Ship a deployer-facing model card or deployer guide with each ADMT release covering intended uses, training-data categories, limitations, and human-review instructions. Control
· Colorado (US-CO) · stayed: would apply from this date
Consumers can request human review and data correction after an adverse ADMT decision C.R.S. 6-1-1705(1)
Guard: Give people who receive an adverse AI-influenced decision a way to see and correct the data used and to request human review that can change the outcome. Control
· Connecticut (US-CT) · first application
AI companions must maintain a suicide/self-harm crisis protocol (Connecticut) Conn. PA 26-15 Sec. 5(a)
Guard: Screen every user message for suicidal ideation and self-harm, return a crisis referral instead of the normal reply on detection, and block encouragement or method content. Control
· Connecticut (US-CT) · first application
AI companions must disclose they are not human (Connecticut) Conn. PA 26-15 Sec. 5(b)
Guard: Show an AI-identity notice at or before the first assistant turn, in the UI or as the opening message, and answer truthfully when asked if it is a bot. Control
· Illinois (US-IL) · first application
Frontier developers must report critical safety incidents to Illinois within 72 hours, or 24 hours if lives are at imminent risk (Illinois SB 315) IL PA 104-0538, Sec. 15(c)
The Act takes effect on January 1, 2027 (Sec. 99); this duty carries no later start date.
Guard: Keep a critical safety incident runbook that classifies the defined incident classes and runs the 72-hour report and 24-hour imminent-risk escalation clocks. Control
· Illinois (US-IL) · first application
Large frontier developers must publish and follow a frontier AI framework from 2028 (Illinois SB 315) IL PA 104-0538, Sec. 10(a)
Act in effect (Sec. 99): large frontier developers must send IEMA-OHS summaries of internal-use catastrophic-risk assessments every three months or on an agreed schedule (Sec. 10(e), which states no later start date).
Guard: Publish a frontier AI framework covering capability thresholds, mitigations, incident response, and internal-use risk, and gate model releases on it. Control
· Illinois (US-IL) · first application
Frontier developers must publish a transparency report at deployment, with machine-readable risk summaries (Illinois SB 315) IL PA 104-0538, Sec. 10(c)(1)
The Act takes effect on January 1, 2027 (Sec. 99); this duty carries no later start date.
Guard: Publish a transparency report or system card on the developer's website before or at each new or substantially modified frontier-model deployment, and gate release on it. Control
· Illinois (US-IL) · first application
Frontier developers must not gag or retaliate against AI safety whistleblowers (Illinois SB 315) IL PA 104-0538, Sec. 20(a)
The Act takes effect on January 1, 2027 (Sec. 99); this duty carries no later start date.
Guard: Carve AI-safety and legal-violation disclosures out of every NDA and policy, adopt non-retaliation, and run an internal safety-concern channel for covered employees. Control
· New York (US-NY) · first application
Frontier developers must report critical safety incidents within 72 hours, or 24 hours if lives are at imminent risk (New York RAISE Act) N.Y. Gen. Bus. Law 1422(3)(a)-(b)
Article 44-B as re-enacted by L. 2026, ch. 96 applies from January 1, 2027, the date ch. 96 sets for the 2025 RAISE Act chapter (S.6953-B / A.6453-B) in place of its original 90-day effective date.
Guard: Keep a critical safety incident runbook that classifies the defined incident classes and runs the 72-hour report and 24-hour imminent-risk escalation clocks. Control
· New York (US-NY) · first application
Large frontier developers must publish and follow a frontier AI framework (New York RAISE Act) N.Y. Gen. Bus. Law 1421(1)
Article 44-B as re-enacted by L. 2026, ch. 96 applies from January 1, 2027, the date ch. 96 sets for the 2025 RAISE Act chapter (S.6953-B / A.6453-B) in place of its original 90-day effective date.
Guard: Publish a frontier AI framework covering capability thresholds, mitigations, incident response, and internal-use risk, and gate model releases on it. Control
· New York (US-NY) · first application
Frontier developers must publish a transparency report when deploying a new or substantially modified frontier model (New York RAISE Act) N.Y. Gen. Bus. Law 1421(3)(a)
Article 44-B as re-enacted by L. 2026, ch. 96 applies from January 1, 2027, the date ch. 96 sets for the 2025 RAISE Act chapter (S.6953-B / A.6453-B) in place of its original 90-day effective date.
Guard: Publish a transparency report or system card on the developer's website before or at each new or substantially modified frontier-model deployment, and gate release on it. Control
· Oregon (US-OR) · first application
AI companions must maintain a self-harm crisis protocol with 988 referral (Oregon) Oregon SB 1546 (2026), Section 1(3)
Guard: Screen every user message for suicidal ideation and self-harm, return a crisis referral instead of the normal reply on detection, and block encouragement or method content. Control
· Oregon (US-OR) · first application
AI companions must disclose non-human interaction (Oregon) Oregon SB 1546 (2026), Section 1(2)
Guard: Show an AI-identity notice at or before the first assistant turn, in the UI or as the opening message, and answer truthfully when asked if it is a bot. Control
· Washington (US-WA) · first application
AI companion chatbots must maintain a self-harm crisis protocol (Washington) Washington HB 2225 (2026), Section 5
Guard: Screen every user message for suicidal ideation and self-harm, return a crisis referral instead of the normal reply on detection, and block encouragement or method content. Control
· Washington (US-WA) · first application
AI companion chatbots must disclose they are not human (Washington) Washington HB 2225 (2026), Section 3
Guard: Show an AI-identity notice at or before the first assistant turn, in the UI or as the opening message, and answer truthfully when asked if it is a bot. Control
July 2027
· Nebraska (US-NE) · first application
Conversational AI must adopt a self-harm crisis-referral protocol (Nebraska) Nebraska LB 525, Sec. 16
Guard: Screen every user message for suicidal ideation and self-harm, return a crisis referral instead of the normal reply on detection, and block encouragement or method content. Control
· Nebraska (US-NE) · first application
Conversational AI must disclose it is not human when a user could be misled (Nebraska) Nebraska LB 525, Sec. 15 (Conversational AI Safety Act)
Guard: Show an AI-identity notice at or before the first assistant turn, in the UI or as the opening message, and answer truthfully when asked if it is a bot. Control
· Nebraska (US-NE) · first application
Conversational AI must not claim to provide professional mental health care (Nebraska) Nebraska LB 525, Sec. 17
Guard: Strip claims that the AI is a licensed therapist or provides professional mental health care from its prompts, replies, product name, UI, and listings. Control
October 2027
· Connecticut (US-CT) · first application
AEDT deployers must give employees a pre-decision notice (Connecticut) Conn. PA 26-15 Sec. 10
Guard: Send the person an AI-use notice on the decision path, before or when an AI system makes or substantially factors a consequential decision about them, and record its delivery. Control
December 2027
· European Union (EU) · first application
High-risk AI training data must be governed and examined for bias (EU AI Act Art. 10) Article 10(2)
Applies to high-risk AI systems classified under Article 6(2) and Annex III (Art. 113, third paragraph, point (c)(i)).
Guard: Compute per-group accuracy and bias metrics in the training pipeline of every consequential-decision model, keep the results per version, and rerun them on a schedule. Control
· European Union (EU) · first application
High-risk AI systems must automatically log events for traceability (EU AI Act Art. 12) Article 12
Applies to high-risk AI systems classified under Article 6(2) and Annex III (Art. 113, third paragraph, point (c)(i)).
Guard: Write a structured event record for every inference and decision of the high-risk system (when, model version, input reference, output, operator) to a log store with explicit retention. Control
· European Union (EU) · first application
Applies to high-risk AI systems classified under Article 6(2) and Annex III (Art. 113, third paragraph, point (c)(i)).
Guard: Give a human a working way to review and overturn each consequential AI decision: a pending-review step before it takes effect and an override that restores the prior state. Control
· European Union (EU) · first application
Applies to high-risk AI systems classified under Article 6(2) and Annex III (Art. 113, third paragraph, point (c)(i)).
Guard: Declare accuracy metrics per model version, add a fail-safe fallback, gate retraining on verified labels, and defend against poisoning, adversarial input and tampering. Control
· European Union (EU) · first application
Deployers must inform people they are subject to a high-risk AI decision (EU AI Act Art. 26(11)) Article 26(11)
Applies to high-risk AI systems classified under Article 6(2) and Annex III (Art. 113, third paragraph, point (c)(i)).
Guard: Send the person an AI-use notice on the decision path, before or when an AI system makes or substantially factors a consequential decision about them, and record its delivery. Control
· European Union (EU) · first application
Public-sector and essential-service deployers must run a fundamental rights impact assessment (EU AI Act Art. 27) Article 27(1)
Applies to high-risk AI systems classified under Article 6(2) and Annex III (Art. 113, third paragraph, point (c)(i)).
Guard: Complete an impact assessment of a high-impact AI deployment's benefits, risks to affected people, mitigations, and oversight before first use, and keep it current. Control
January 2028
· California (US-CA) · first application
Capture device manufacturers must offer latent provenance disclosure (California) Cal. Bus. & Prof. Code 22757.3.3(a)
Guard: Embed a signed C2PA manifest or equivalent latent disclosure in generated or captured media when it is created, and do not distribute systems or files that lack it. Control
· Illinois (US-IL) · later phase
Large frontier developers must publish and follow a frontier AI framework from 2028 (Illinois SB 315) IL PA 104-0538, Sec. 10(a)
Additionally, large frontier developers must write, implement, follow, and publish the frontier AI framework (Sec. 10(a)) and review it at least annually, republishing material changes with a justification within 30 days (Sec. 10(b)).
Guard: Publish a frontier AI framework covering capability thresholds, mitigations, incident response, and internal-use risk, and gate model releases on it. Control
· Illinois (US-IL) · first application
Large frontier developers must obtain and publish an annual independent compliance audit from 2028 (Illinois SB 315) IL PA 104-0538, Sec. 10(d)
First annual independent compliance audit year begins for large frontier developers (or 90 days after a developer first qualifies, if later); the Act itself is in effect from 2027-01-01 (Sec. 99).
Guard: Engage an independent auditor on non-contingent fees each year to audit frontier-safety obligations, then publish, transmit, and retain the signed report. Control
August 2028
· European Union (EU) · later phase
High-risk AI training data must be governed and examined for bias (EU AI Act Art. 10) Article 10(2)
Applies to high-risk AI systems classified under Article 6(1) and Annex I (product-embedded) (Art. 113, third paragraph, point (c)(ii)).
Guard: Compute per-group accuracy and bias metrics in the training pipeline of every consequential-decision model, keep the results per version, and rerun them on a schedule. Control
· European Union (EU) · later phase
High-risk AI systems must automatically log events for traceability (EU AI Act Art. 12) Article 12
Applies to high-risk AI systems classified under Article 6(1) and Annex I (product-embedded) (Art. 113, third paragraph, point (c)(ii)).
Guard: Write a structured event record for every inference and decision of the high-risk system (when, model version, input reference, output, operator) to a log store with explicit retention. Control
· European Union (EU) · later phase
Applies to high-risk AI systems classified under Article 6(1) and Annex I (product-embedded) (Art. 113, third paragraph, point (c)(ii)).
Guard: Give a human a working way to review and overturn each consequential AI decision: a pending-review step before it takes effect and an override that restores the prior state. Control
· European Union (EU) · later phase
Applies to high-risk AI systems classified under Article 6(1) and Annex I (product-embedded) (Art. 113, third paragraph, point (c)(ii)).
Guard: Declare accuracy metrics per model version, add a fail-safe fallback, gate retraining on verified labels, and defend against poisoning, adversarial input and tampering. Control
January 2029
· California (US-CA) · a further phase of law in force
GenAI providers must embed latent provenance disclosure in synthetic media (California) Cal. Bus. & Prof. Code 22757.3(a)
The assistive-technology exclusion ends (22757.5(b)) and the latent disclosure must also state whether the GenAI system is designed to primarily function as assistive technology (22757.3(a)(1)(F)).
Guard: Embed a signed C2PA manifest or equivalent latent disclosure in generated or captured media when it is created, and do not distribute systems or files that lack it. Control
Coding agents get the same list from the MCP tool coming_into_force, filtered by their repository's AI features and markets.