All posts
AI
September 30, 2026

The World Is Regulating AI: A Deployer's Effective-Date Timeline

The World Is Regulating AI: A Deployer's Effective-Date Timeline

AI governance is no longer an EU story. Binding AI rules now apply across Europe, Asia and North America, and the calendars keep moving. In July 2026 the EU pushed its high-risk deadlines to December 2027, days before they were due. Meanwhile, Asia-Pacific governments brought framework AI laws into force, US states switched on their own rules, and privacy and anti-discrimination law kept reaching AI without waiting for new statutes.

This map is for organizations that deploy AI, not the companies that train frontier models. Dates show when obligations apply, sector rules are summarized, and the unit that matters is the use case, not the model: a hiring screen and a marketing draft carry very different duties, even on the same model.

The timeline: what is in force, and what is coming

Most of the rules below took effect in 2026, and the next wave runs through 2028.

Timeline chart of deployer-relevant AI rule effective dates by region, as of Sept. 28, 2026. In force: EU prohibitions and literacy (Feb 2, 2025), China AI content labels (Sep 1, 2025), Italy national AI law (Oct 10, 2025), Texas, Illinois, California and Ontario (Jan 1, 2026), Taiwan AI Basic Act (Jan 14, 2026), South Korea AI Basic Act (Jan 22, 2026), UK automated decisions (Feb 5, 2026), India synthetic media (Feb 20, 2026), Vietnam AI Law (Mar 1, 2026), China companion AI (Jul 15, 2026), EU transparency duties (Aug 2, 2026). Coming next: Australia ADM disclosure (Dec 10, 2026), Colorado and California ADMT (Jan 1, 2027), Vietnam transition ends (Mar 1, 2027), EU high-risk uses (Dec 2, 2027), Taiwan law alignment due (Jan 14, 2028), EU AI in regulated products (Aug 2, 2028).

Everything left of the dashed line already applies; the shaded side is what is coming. The tables below carry the detail for each date.

Already in force

Date Jurisdiction What applies to deployers
Feb. 2, 2025 European Union AI Act: prohibited practices and AI literacy
Sept. 1, 2025 China Labeling Measures: visible and invisible labels on AI content
Oct. 10, 2025 Italy Law 132/2025: worker notice, parental consent under 14
Jan. 1, 2026 Texas HB 149 (TRAIGA): prohibited AI uses, government AI disclosure
Jan. 1, 2026 Illinois Public Act 103-0804: no discriminatory AI in employment, worker notice
Jan. 1, 2026 California CPPA regulations take effect; SB 243 companion chatbot duties
Jan. 1, 2026 Ontario Employment Standards Act: AI disclosure in job postings, 25+ employees
Jan. 14, 2026 Taiwan AI Basic Act: principles now, sector rules to follow
Jan. 22, 2026 South Korea AI Basic Act: high-impact AI duties, generative AI labeling
Feb. 5, 2026 United Kingdom Data (Use and Access) Act, s. 80: new automated decision rules and safeguards
Feb. 20, 2026 India IT Rules amendment: labels and provenance for synthetic media
March 1, 2026 Vietnam Law on AI: risk classification, labeling, deployer duties
July 15, 2026 China Anthropomorphic AI Measures: companion and emotional-support services
Aug. 2, 2026 European Union AI Act, Article 50: AI interaction disclosure, deepfake labels

Coming next

Date Jurisdiction What applies to deployers
Dec. 10, 2026 Australia Privacy Act, APP 1.7 to 1.9: disclose automated decisions in privacy policies
Jan. 1, 2027 Colorado SB 26-189: pre-use notice, adverse-outcome explanation, human review
Jan. 1, 2027 California ADMT duties for significant decisions: pre-use notice, opt-out, access
Early 2027 South Korea Ministry’s grace period on fines expected to end
March 1, 2027 Vietnam Existing systems must comply; Sept. 1, 2027 for health, education and finance
May 1, 2027 Canada OSFI Guideline E-23: model risk management, including AI, for federal financial institutions
Dec. 2, 2027 European Union Digital Omnibus: high-risk rules for hiring, credit, education, essential services
Jan. 14, 2028 Taiwan Deadline to align national laws with the AI Basic Act
Aug. 2, 2028 European Union High-risk rules for AI in regulated products, such as medical devices

On the horizon, no date yet

What the map shows

Europe sets the frame, but it is not alone. The EU’s Digital Omnibus deferred the high-risk regime rather than dismantling it, and Article 50 transparency duties already apply. Italy layered a national AI law on top of the EU Act, and the UK rewrote its automated decision rules instead of passing an AI statute.

Asia-Pacific moved fastest in 2026. South Korea, Taiwan and Vietnam all brought framework AI laws into force in the first quarter. China keeps adding targeted measures, most recently for companion AI. India regulates synthetic media through platform rules, and Japan has chosen to influence rather than regulate, with an AI Promotion Act that carries no penalties.

The Americas regulate without a federal AI statute. Executive Order 14365 is pressure, not preemption: state laws remain enforceable until a court or Congress says otherwise. Colorado is the cautionary tale. Its first comprehensive AI law was delayed once and then replaced before it bound anyone, so a program built to one statute carries repeal risk as well as deadline risk. Canada and Brazil still regulate largely through existing law, and Brazil’s data protection law already gives people a right to review solely automated decisions.

Sector rules, in brief

Children and minors. Companion chatbots are the main target. New York and California already require operators to disclose that users are talking to AI and to run self-harm crisis protocols, and more states follow in 2027. China’s companion AI measures and Italy’s under-14 consent rule point the same way: if an AI system can reach minors, age awareness, disclosure and crisis escalation are becoming baseline.

Health. The emerging rule is that AI may assist but may not decide alone or impersonate a clinician. US states are requiring patient disclosure, human review of insurer coverage denials and limits on AI therapy. Abroad, health is treated as high-risk or high-impact almost everywhere, while HIPAA, GDPR and national health privacy laws still govern the data.

Employment. Hiring is the most consistently regulated AI use case in the world, covered by the EU, South Korea, Illinois, Colorado, California, New York City and Ontario. The common requirements are notice, testing for discriminatory outcomes and a path to human review.

One control set, many frameworks

Across every jurisdiction above, the same five expectations recur: know which AI you run, tell people when it affects them, assess the high-stakes uses, keep a human able to intervene, and prove the controls operated. The deadlines differ. The controls mostly do not.

That is why Airia treats framework support and mapping as the core of AI governance, not an add-on. The platform carries regulatory content as structured, versioned frameworks, including the EU AI Act, ISO/IEC 42001, the NIST AI Risk Management Framework, GDPR, HIPAA, California’s ADMT regulations, Texas TRAIGA, Colorado SB 26-189, Singapore’s Model AI Governance Framework and Australia’s Privacy Act. In practice, that means:

  • One control, many obligations. Each requirement maps to a common control layer, so a single pre-use notice, impact assessment or human-review path can satisfy overlapping duties across jurisdictions.
  • Applicability by use case. Obligations attach to each AI use case based on its purpose, the jurisdictions it touches and your role, so teams see what applies to a system without reading every statute.
  • Versioned frameworks. When a regulator moves a date, as the EU did in July, the change lands as a framework update, and the mapped controls and evidence carry forward.
  • Evidence as a byproduct. Controls produce records as work happens, ready for auditors, customers and regulators, instead of being assembled the week before a review.

The global map will keep changing. A governance program built on mapped frameworks absorbs those changes instead of starting over.

A note on dates

Dates are current as of September 28, 2026 and reflect when obligations apply, not when laws passed. Links go to official legal texts. Several regimes phase in or depend on implementing rules, so confirm against the current text before relying on a single date. This post is general information, not legal advice.

Put these ideas to work.

Schedule a 30-minute walkthrough with our team.

Talk through your use case