Oct 01
Connecticut CART Act - First Employment and Transparency Provisions Effective
Connecticut Public Act 26-15 (AI Responsibility and Transparency Act / CART Act) begins its phased rollout on October 1, 2026. Initial obligations include employer notice when AI tools are used in employment-related decisions, transparency about AI-related reductions in force, and the clarification that using AI is not a defense to antidiscrimination claims. Additional provisions take effect October 1, 2027.
US
Oct 31
ECB AI Cybersecurity Action Plans Due from Eurozone Banks
Following the ESRB July 7 warning on systemic cyber risks from frontier AI models, the ECB set an October 31, 2026 deadline for significant eurozone banks to submit AI cybersecurity action plans addressing AI-enhanced cyber threats to financial stability.
EU
Jan 01
NY RAISE Act Takes Effect
New York S6953-B (RAISE Act) takes effect for frontier AI model developers with over $500M annual revenue. Requires safety protocols, AI impact assessments, 72-hour incident reporting to new NY AI oversight office. Penalties up to $1M first violation, $3M subsequent.
US
Jan 01
Illinois AI Safety Measures Act (SB 315) Takes Effect
Illinois SB 315 (Artificial Intelligence Safety Measures Act), signed by Governor Pritzker on July 6, 2026, takes effect January 1, 2027. Requires AI model developers with over $500 million in annual revenue to: publish a catastrophic risk framework; undergo annual independent third-party audits (first-in-nation requirement); report incidents within 72 hours (24 hours if imminent death/injury risk); and extend whistleblower protections. Effective the same day as Colorado SB 26-189, NY RAISE Act, creating a multi-state frontier AI compliance event.
US
Jan 01
Colorado SB 26-189 - ADMT Notice Framework Effective
Colorado SB 26-189 (automated decision-making technology notice-and-explanation framework) takes effect. Replaces SB 24-205's higher-risk AI compliance regime with a narrower ADMT disclosure requirement, exclusive AG enforcement.
US
Dec 02
EU AI Act - High-Risk AI System Obligations (Delayed, Annex III)
Stand-alone Annex III high-risk AI obligations, originally due August 2, 2026, were delayed to December 2, 2027 under the Digital Omnibus (Regulation EU 2026/1744, published July 24, 2026, in force July 27, 2026). Annex I embedded-product high-risk systems move to August 2, 2028. GPAI transparency in force since August 2, 2025. Penalties up to 7% global annual turnover.
EU
Aug 02
EU AI Act - Annex I Embedded-Product High-Risk Obligations (Delayed)
High-risk obligations for AI embedded in regulated products under Annex I, deferred to August 2, 2028 under the Digital Omnibus (from the original August 2, 2027 timeline). Represents full implementation of high-risk EU AI Act requirements for product-embedded systems.
EU