How We Got Here
You do not need this chapter to do the work. You need it to understand why the work looks the way it does.
Read it once. It explains where these rules came from, why Europe is further along, and what lands in 2027.
Europe Started First
Data protection as a fundamental right
The European Union treats data protection as a fundamental right in its own name — listed separately from privacy in the EU Charter.
That framing has a practical consequence. Europe regulates data protection horizontally, across every sector at once, rather than industry by industry.
The General Data Protection Regulation
The General Data Protection Regulation — GDPR — took effect in May 2018. It replaced a directive that had been in place since 1995.
It established machinery that European practitioners have now run for years:
- Documented legal basis for every processing activity
- Purpose limitation and data minimization
- Impact assessments before high-risk processing
- Rules governing automated decisions about people
Two provisions matter most for what follows:
| Provision | Requirement |
|---|---|
| Article 22 | Governs automated decisions with significant effects |
| Article 35 | Requires an impact assessment before high-risk processing |
Neither mentions artificial intelligence. Both apply to it.
The United Kingdom diverged
After leaving the EU, the UK kept an adapted version of the same regulation. It is enforced by the Information Commissioner's Office — the ICO.
- Similar to the EU version, not identical
- The differences have widened since 2020
- 2025 legislation revised the automated-decision provisions specifically
If your footprint covers both, you track two bodies of law.
The United States Went Sector by Sector
There is no comprehensive federal privacy law in the United States. There are sectoral laws instead.
| Law | Covers |
|---|---|
| HIPAA — Health Insurance Portability and Accountability Act | Health information |
| GLBA — the Privacy Rule and Safeguards Rule | Financial institutions |
| FERPA — Family Educational Rights and Privacy Act | Education records |
| COPPA — Children's Online Privacy Protection Act | Children's data |
| FCRA — Fair Credit Reporting Act | Consumer reporting |
Read those names in full and the pattern is obvious. Protection. Privacy. Rights. Safeguards.
All of it is data privacy and data protection law.
The consequence for practitioners: if your background is US compliance, your privacy experience is probably deep in one or two of these and unfamiliar in the rest. That is how the law is structured, not a gap in your training.
Then the States Borrowed From Europe
Beginning with California, US states began passing comprehensive privacy laws. They borrowed heavily from the European model.
Concepts that arrived in recognizably European form:
- Data protection assessments
- Sensitive data categories
- Profiling restrictions
- Purpose limitation
- Consumer rights and opt-outs
A US practitioner encountering a "data protection assessment" requirement in Colorado or Virginia is meeting something European colleagues have completed many times.
This is the bridge. The state privacy laws brought European concepts into US practice. The AI laws now build on those same concepts.
AI-Specific Laws Arrive
The United States moved first, in pieces
| Law | In force |
|---|---|
| NYC Local Law 144 — bias audits for hiring tools | 2023 |
| Utah AI Policy Act | May 2024 |
| Illinois HB 3773 — AI employment discrimination | Jan 1, 2026 |
| California AB 2013 and SB 53 | Jan 1, 2026 |
| Connecticut — private sector obligations | Oct 1, 2026 |
State laws vary considerably in scope:
- Some reach any organization deploying AI
- Others cover only government use
- Several were narrowed substantially during drafting
Texas is worth knowing as an example. Its Responsible AI Governance Act was cut back significantly before passage, and private-sector obligations are far lighter than the original draft suggested.
You cannot assume a state law applies. You cannot assume it doesn't.
The European Union passed the first comprehensive AI law
The EU AI Act was adopted in 2024. It phases in over several years.
The critical structural point: it sits on top of the General Data Protection Regulation. It does not replace it.
A single high-risk deployment in Europe can require both:
- A Data Protection Impact Assessment — DPIA — under GDPR Article 35
- A Fundamental Rights Impact Assessment — FRIA — under AI Act Article 27
One examines risk to data. The other examines risk to people.
They ask different questions. Neither substitutes for the other.
The Assessment Obligations Are Older Than People Think
One category deserves separating out, because organizations consistently misjudge it.
Most assessment requirements are already live.
| Requirement | Mandatory since |
|---|---|
| Data Protection Impact Assessment — EU | May 2018 |
| Data Protection Impact Assessment — UK | May 2018 |
| Virginia data protection assessment | January 2023 |
| Colorado data protection assessment | July 2023 |
| Connecticut data protection assessment | July 2023 |
| Texas data protection assessment | July 2024 |
| California risk assessment requirements | January 2026 |
| Fundamental Rights Impact Assessment | December 2027 |
Only the last one is future work — and it is the one attracting most of the attention.
A note on the UK date. The obligation did not begin at Brexit. It applied from May 2018 while the UK was an EU member state, and carried into UK GDPR when the transition period ended.
An organization planning for December 2027 while carrying an unmet obligation from 2018 has its attention in the wrong place.
Chapter 6 covers what these documents are and what goes into them.
Enforcement Is Already Happening
Not warnings. Decisions, with orders attached.
| Matter | Subject and penalty | What the regulator ordered produced |
|---|---|---|
| Massachusetts — Earnest Operations | AI loan underwriting · 2025 · $2.5M | A written AI governance system. Documented fair-lending testing. Risk assessments. A named oversight team. |
| Hungary — Budapest Bank | Emotion analysis on calls · 2022 · HUF 250M | A completed impact assessment, a documented legal basis, and demonstrable safeguards — or stop the processing. |
| Italy — Foodinho | Algorithmic rider scoring · 2021 · €2.6M | Human intervention in algorithmic decisions, and periodic checks on the algorithm's accuracy. |
| Germany — Berlin bank | Automated credit decision · 2023 · €300K | The specific data, factors, and criteria behind a single automated decision, on request. |
Different countries. Different sectors. Different years.
In each case the regulator asked for the same categories of material:
- The assessment
- The documented legal basis
- A record of what the system did and why
None of it could be produced quickly. None of it should be created after the request arrived.
Remediation is different. A regulator expects gaps to be addressed immediately, and starting that work is the right response.
But a document dated after the request answers a different question than the one being asked. The record shows what you did at the time. Remediation shows what you are doing now. Both matter. They are not interchangeable.
- May 2018GDPR applies
Impact assessments and automated-decision rules take effect across the EU. Most unmet obligations still date from here.
- January 1, 2026California risk assessments
California risk assessment requirements take effect.
- October 1, 2026Connecticut, staged
Private-sector AI obligations begin phasing in.
- January 1, 2027The US state cluster
At least ten state requirements take effect on one date — automated decisions, two comprehensive privacy laws, health and insurance AI, companion chatbots, frontier models, and content provenance.
- December 2, 2027EU AI Act high-risk deployers
Article 26 deployer obligations attach for standalone Annex III systems; Article 27 adds a Fundamental Rights Impact Assessment for certain deployers.
Two of these are the subject of this chapter. The rest are already in force.
What Lands in 2027
Two dates.
January 1, 2027 — the US state cluster
At least ten state requirements take effect on this single date. They cover very different subject matter, which is the point worth noticing.
Automated decision-making
| Law | What it requires |
|---|---|
| Colorado SB 26-189 | Notice, explanation, correction, and human review rights where automated technology materially influences consequential decisions |
| California — CCPA automated decision-making regulations | Risk assessments, pre-use notices, and consumer opt-outs for significant decisions |
Colorado's applies to employment, housing, education, lending, insurance, healthcare, and essential government services. Deployers must provide consumer notices, keep compliance records for at least three years, support consumer rights, and offer meaningful human review after some adverse decisions.
The law was signed May 14, 2026, replacing the original after it was repealed. It removes the earlier duty-of-care standard and the annual impact assessment requirement. Developers get a 60-day cure period, which sunsets January 1, 2030.
Comprehensive privacy laws
| State | Note |
|---|---|
| Louisiana | Applies at $25M revenue, or 75,000 consumers, or 50% of revenue from selling personal information |
| Oklahoma | New omnibus privacy law |
Both follow the familiar consensus framework, with state-specific differences worth reading.
AI in healthcare and insurance
| Law | What it requires |
|---|---|
| Georgia SB 444 | Coverage decisions may not be based solely on AI; a clinical peer must participate before an adverse determination |
| Utah SB 319 | Insurers must disclose AI use in authorization review; adverse determinations require independent medical judgment |
Companion chatbots
| Law | What it requires |
|---|---|
| Washington HB 2225 | Disclosure that the bot is not human, crisis protocols for suicidal ideation and self-harm, public reporting of crisis referrals |
| Oregon SB 1546 | Protections for minors interacting with chatbot products |
Washington's duty runs to all users, not only minors, and violations are unfair or deceptive acts carrying a private right of action.
Frontier models and content provenance
| Law | What it requires |
|---|---|
| New York RAISE Act | Safety and transparency obligations on large frontier AI developers |
| California AI Transparency Act — platform provisions | Large platforms must detect and label machine-readable provenance on AI-generated content |
What that spread tells you
Ten laws. One date. And no single theme.
- Employment and lending decisions
- Health insurance authorization
- Consumer chatbots
- Frontier model safety
- Content labeling
- Two general privacy frameworks
You cannot scope this by watching one category of law. An organization tracking only "AI hiring rules" misses the insurance provisions. One tracking only privacy misses the chatbot duties.
The obligations attach based on what your tools actually do — not on which regulatory conversation you happen to be following.
December 2, 2027 — EU AI Act high-risk deployers
Obligations for deployers of standalone Annex III high-risk systems become applicable, following the deferral agreed in 2026.
Annex III categories include:
- Employment and workforce management
- Creditworthiness assessment
- Insurance risk assessment
- Education
- Access to essential services
Article 26 deployer obligations attach on that date. For certain deployer categories, Article 27 also requires a Fundamental Rights Impact Assessment before the system is put into use.
The Penalty Structure
| Instrument | Breach | Maximum |
|---|---|---|
| EU AI Act | Prohibited practices | €35M or 7% of turnover |
| EU AI Act | Deployer and provider duties | €15M or 3% of turnover |
| GDPR | Serious violations | €20M or 4% of turnover |
| GDPR | Lesser violations, incl. missing DPIA | €10M or 2% of turnover |
The two instruments are independent.
A single deployment can breach both. The exposure is cumulative, not alternative.
The Short Version
If you read nothing else in this chapter:
- Europe built the foundation, starting in 2018
- The United States regulated by sector, then by state
- State privacy laws imported the European concepts
- AI-specific laws build on those same concepts
- The EU AI Act sits on top of GDPR, not instead of it
- Enforcement has already begun in several jurisdictions
- At least ten state laws take effect January 1, 2027
- EU AI Act high-risk deployer duties follow on December 2, 2027
This is not a new discipline. It is data protection law, extended to a new technology, arriving faster than most organizations have built the practice to absorb it.
Chapter 2 covers where to start.
Sources
All statutory provisions should be read in their current form. Where a secondary source is cited below, it is named — verify against the primary text before relying on any specific requirement.
European law
- General Data Protection Regulation, Regulation (EU) 2016/679 — Articles 22 and 35
- EU Artificial Intelligence Act, Regulation (EU) 2024/1689 — Articles 26 and 27, with Annex III for the high-risk categories
- UK General Data Protection Regulation and the Data Protection Act 2018
- The December 2027 date for standalone Annex III high-risk deployer obligations reflects the deferral agreed in 2026. Confirm the current date before planning against it.
Penalty thresholds
Each figure in the penalty table comes from one of two provisions. Read both before quoting the numbers.
| Threshold | Provision |
|---|---|
| €35M or 7% — prohibited practices | EU AI Act, Article 99 |
| €15M or 3% — deployer and provider obligations | EU AI Act, Article 99 |
| €20M or 4% — serious violations | GDPR, Article 83 |
| €10M or 2% — lesser violations, including a missing assessment | GDPR, Article 83 |
Both provisions set maximums rather than fixed amounts, and both are expressed as the higher of a fixed sum or a percentage of worldwide annual turnover. The tiers within each Article are more granular than the table above; check which tier applies to a specific breach rather than assuming the headline figure.
United States — laws effective January 1, 2027
| Law | Verification status |
|---|---|
| Colorado SB 26-189 | Confirmed against the Colorado General Assembly record. Passed May 9, 2026; signed May 14, 2026. See litigation note below. |
| California — CCPA automated decision-making regulations | Confirmed. Related risk assessment requirements took effect January 1, 2026. |
| California AI Transparency Act — platform provisions | Confirmed. |
| New York RAISE Act | Confirmed. |
| Louisiana Data Privacy Act | Confirmed. |
| Oklahoma comprehensive privacy law | Confirmed. |
| Georgia SB 444 | Confirmed against the Georgia legislative record. |
| Utah SB 319 | Confirmed. |
| Washington HB 2225 | Confirmed against the Washington State Legislature record. |
| Oregon SB 1546 | Confirmed against the Oregon legislative record. Or. Laws 2026 ch. 85. |
United States — laws already in effect
- New York City Local Law 144 of 2021 — automated employment decision tools
- Utah Artificial Intelligence Policy Act
- Illinois HB 3773 — amending the Illinois Human Rights Act
- California AB 2013 and SB 53
- Connecticut — private sector AI obligations, staged from October 1, 2026
- Texas HB 149, Responsible Artificial Intelligence Governance Act
Assessment effective dates
- Data Protection Impact Assessment — GDPR Article 35, applicable from May 25, 2018 in both the EU and the UK
- Virginia Consumer Data Protection Act — effective January 1, 2023
- Colorado Privacy Act — effective July 1, 2023
- Connecticut Data Privacy Act — effective July 1, 2023
- Texas Data Privacy and Security Act — effective July 1, 2024
- California risk assessment requirements — effective January 1, 2026
- Fundamental Rights Impact Assessment — EU AI Act Article 27
Enforcement decisions referenced
| Matter | Citation |
|---|---|
| Massachusetts — AI loan underwriting, 2025, $2.5M | Massachusetts Office of the Attorney General, In re Earnest Operations LLC, Assurance of Discontinuance, July 10, 2025 |
| Hungary — emotion analysis on customer service calls, 2022, HUF 250M | Hungarian National Authority for Data Protection and Freedom of Information (NAIH), Decision NAIH-85-3/2022 (Budapest Bank) |
| Italy — algorithmic rider scoring, 2021, €2.6M | Garante per la protezione dei dati personali, order no. 234/2021 (Foodinho) |
| Germany — automated credit decision, Berlin, 2023, €300K | Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI), administrative fine, May 31, 2023 — GDPR Articles 5(1)(a), 15(1)(h), 22(3) |
These are publicly reported enforcement actions, described here for information only. Nothing in this chapter is a prediction of any outcome for any organization.
A note on Colorado
The Colorado framework has been unusually unstable, and a reader planning against the January 2027 date should know why.
- The original law, SB 24-205, was enacted in 2024 with an effective date later extended
- A federal court enjoined its enforcement in April 2026 in xAI v. Weiser
- The legislature then repealed and reenacted it as SB 26-189
- The replacement narrows the statute substantially — the duty-of-care standard, risk management programs, and annual impact assessments from the original are gone
- The replacement takes effect January 1, 2027, and applies to decisions made on or after that date
Litigation over the framework was ongoing at the time of writing. Confirm the current position before planning around this date specifically.
A standing note on verification
Effective dates move. Colorado's original AI law was repealed and replaced before it took effect. The EU AI Act's high-risk deployer date was deferred by more than a year. Nothing in this chapter should be treated as settled without checking the current position.
Use and reuse
Free to use, share, and adapt within your organization. Attribution appreciated, not required. No warranty of any kind — this is practitioner guidance, not legal advice, and sufficiency is determined by your counsel.
LegisGate · Regulatory Intelligence for AI Deployments · legisgate.com
Written by compliance and audit practitioners who spent decades on the other side of the table.
Version 1.0 · Current as of August 2026 · Verify time-sensitive claims against current sources before relying on them.