Chapter 1 · How We Got HereThe Handbook
01Chapter 1 of 7

How We Got Here

You do not need this chapter to do the work. You need it to understand why the work looks the way it does.

Read it once. It explains where these rules came from, why Europe is further along, and what lands in 2027.


Europe Started First

Data protection as a fundamental right

The European Union treats data protection as a fundamental right in its own name — listed separately from privacy in the EU Charter.

That framing has a practical consequence. Europe regulates data protection horizontally, across every sector at once, rather than industry by industry.

The General Data Protection Regulation

The General Data Protection Regulation — GDPR — took effect in May 2018. It replaced a directive that had been in place since 1995.

It established machinery that European practitioners have now run for years:

  • Documented legal basis for every processing activity
  • Purpose limitation and data minimization
  • Impact assessments before high-risk processing
  • Rules governing automated decisions about people

Two provisions matter most for what follows:

ProvisionRequirement
Article 22Governs automated decisions with significant effects
Article 35Requires an impact assessment before high-risk processing

Neither mentions artificial intelligence. Both apply to it.

The United Kingdom diverged

After leaving the EU, the UK kept an adapted version of the same regulation. It is enforced by the Information Commissioner's Office — the ICO.

  • Similar to the EU version, not identical
  • The differences have widened since 2020
  • 2025 legislation revised the automated-decision provisions specifically

If your footprint covers both, you track two bodies of law.


The United States Went Sector by Sector

There is no comprehensive federal privacy law in the United States. There are sectoral laws instead.

LawCovers
HIPAA — Health Insurance Portability and Accountability ActHealth information
GLBA — the Privacy Rule and Safeguards RuleFinancial institutions
FERPA — Family Educational Rights and Privacy ActEducation records
COPPA — Children's Online Privacy Protection ActChildren's data
FCRA — Fair Credit Reporting ActConsumer reporting

Read those names in full and the pattern is obvious. Protection. Privacy. Rights. Safeguards.

All of it is data privacy and data protection law.

The consequence for practitioners: if your background is US compliance, your privacy experience is probably deep in one or two of these and unfamiliar in the rest. That is how the law is structured, not a gap in your training.


Then the States Borrowed From Europe

Beginning with California, US states began passing comprehensive privacy laws. They borrowed heavily from the European model.

Concepts that arrived in recognizably European form:

  • Data protection assessments
  • Sensitive data categories
  • Profiling restrictions
  • Purpose limitation
  • Consumer rights and opt-outs

A US practitioner encountering a "data protection assessment" requirement in Colorado or Virginia is meeting something European colleagues have completed many times.

This is the bridge. The state privacy laws brought European concepts into US practice. The AI laws now build on those same concepts.


AI-Specific Laws Arrive

The United States moved first, in pieces

LawIn force
NYC Local Law 144 — bias audits for hiring tools2023
Utah AI Policy ActMay 2024
Illinois HB 3773 — AI employment discriminationJan 1, 2026
California AB 2013 and SB 53Jan 1, 2026
Connecticut — private sector obligationsOct 1, 2026

State laws vary considerably in scope:

  • Some reach any organization deploying AI
  • Others cover only government use
  • Several were narrowed substantially during drafting

Texas is worth knowing as an example. Its Responsible AI Governance Act was cut back significantly before passage, and private-sector obligations are far lighter than the original draft suggested.

You cannot assume a state law applies. You cannot assume it doesn't.

The European Union passed the first comprehensive AI law

The EU AI Act was adopted in 2024. It phases in over several years.

The critical structural point: it sits on top of the General Data Protection Regulation. It does not replace it.

A single high-risk deployment in Europe can require both:

  • A Data Protection Impact Assessment — DPIA — under GDPR Article 35
  • A Fundamental Rights Impact Assessment — FRIA — under AI Act Article 27

One examines risk to data. The other examines risk to people.

They ask different questions. Neither substitutes for the other.


The Assessment Obligations Are Older Than People Think

One category deserves separating out, because organizations consistently misjudge it.

Most assessment requirements are already live.

RequirementMandatory since
Data Protection Impact Assessment — EUMay 2018
Data Protection Impact Assessment — UKMay 2018
Virginia data protection assessmentJanuary 2023
Colorado data protection assessmentJuly 2023
Connecticut data protection assessmentJuly 2023
Texas data protection assessmentJuly 2024
California risk assessment requirementsJanuary 2026
Fundamental Rights Impact AssessmentDecember 2027

Only the last one is future work — and it is the one attracting most of the attention.

A note on the UK date. The obligation did not begin at Brexit. It applied from May 2018 while the UK was an EU member state, and carried into UK GDPR when the transition period ended.

An organization planning for December 2027 while carrying an unmet obligation from 2018 has its attention in the wrong place.

Chapter 6 covers what these documents are and what goes into them.


Enforcement Is Already Happening

Not warnings. Decisions, with orders attached.

MatterSubject and penaltyWhat the regulator ordered produced
Massachusetts — Earnest OperationsAI loan underwriting · 2025 · $2.5MA written AI governance system. Documented fair-lending testing. Risk assessments. A named oversight team.
Hungary — Budapest BankEmotion analysis on calls · 2022 · HUF 250MA completed impact assessment, a documented legal basis, and demonstrable safeguards — or stop the processing.
Italy — FoodinhoAlgorithmic rider scoring · 2021 · €2.6MHuman intervention in algorithmic decisions, and periodic checks on the algorithm's accuracy.
Germany — Berlin bankAutomated credit decision · 2023 · €300KThe specific data, factors, and criteria behind a single automated decision, on request.

Different countries. Different sectors. Different years.

In each case the regulator asked for the same categories of material:

  • The assessment
  • The documented legal basis
  • A record of what the system did and why

None of it could be produced quickly. None of it should be created after the request arrived.

Remediation is different. A regulator expects gaps to be addressed immediately, and starting that work is the right response.

But a document dated after the request answers a different question than the one being asked. The record shows what you did at the time. Remediation shows what you are doing now. Both matter. They are not interchangeable.


The run-up to 2027
  1. May 2018
    GDPR applies

    Impact assessments and automated-decision rules take effect across the EU. Most unmet obligations still date from here.

  2. January 1, 2026
    California risk assessments

    California risk assessment requirements take effect.

  3. October 1, 2026
    Connecticut, staged

    Private-sector AI obligations begin phasing in.

  4. January 1, 2027
    The US state cluster

    At least ten state requirements take effect on one date — automated decisions, two comprehensive privacy laws, health and insurance AI, companion chatbots, frontier models, and content provenance.

  5. December 2, 2027
    EU AI Act high-risk deployers

    Article 26 deployer obligations attach for standalone Annex III systems; Article 27 adds a Fundamental Rights Impact Assessment for certain deployers.

Two of these are the subject of this chapter. The rest are already in force.

What Lands in 2027

Two dates.

January 1, 2027 — the US state cluster

At least ten state requirements take effect on this single date. They cover very different subject matter, which is the point worth noticing.

Automated decision-making

LawWhat it requires
Colorado SB 26-189Notice, explanation, correction, and human review rights where automated technology materially influences consequential decisions
California — CCPA automated decision-making regulationsRisk assessments, pre-use notices, and consumer opt-outs for significant decisions

Colorado's applies to employment, housing, education, lending, insurance, healthcare, and essential government services. Deployers must provide consumer notices, keep compliance records for at least three years, support consumer rights, and offer meaningful human review after some adverse decisions.

The law was signed May 14, 2026, replacing the original after it was repealed. It removes the earlier duty-of-care standard and the annual impact assessment requirement. Developers get a 60-day cure period, which sunsets January 1, 2030.

Comprehensive privacy laws

StateNote
LouisianaApplies at $25M revenue, or 75,000 consumers, or 50% of revenue from selling personal information
OklahomaNew omnibus privacy law

Both follow the familiar consensus framework, with state-specific differences worth reading.

AI in healthcare and insurance

LawWhat it requires
Georgia SB 444Coverage decisions may not be based solely on AI; a clinical peer must participate before an adverse determination
Utah SB 319Insurers must disclose AI use in authorization review; adverse determinations require independent medical judgment

Companion chatbots

LawWhat it requires
Washington HB 2225Disclosure that the bot is not human, crisis protocols for suicidal ideation and self-harm, public reporting of crisis referrals
Oregon SB 1546Protections for minors interacting with chatbot products

Washington's duty runs to all users, not only minors, and violations are unfair or deceptive acts carrying a private right of action.

Frontier models and content provenance

LawWhat it requires
New York RAISE ActSafety and transparency obligations on large frontier AI developers
California AI Transparency Act — platform provisionsLarge platforms must detect and label machine-readable provenance on AI-generated content

What that spread tells you

Ten laws. One date. And no single theme.

  • Employment and lending decisions
  • Health insurance authorization
  • Consumer chatbots
  • Frontier model safety
  • Content labeling
  • Two general privacy frameworks

You cannot scope this by watching one category of law. An organization tracking only "AI hiring rules" misses the insurance provisions. One tracking only privacy misses the chatbot duties.

The obligations attach based on what your tools actually do — not on which regulatory conversation you happen to be following.

December 2, 2027 — EU AI Act high-risk deployers

Obligations for deployers of standalone Annex III high-risk systems become applicable, following the deferral agreed in 2026.

Annex III categories include:

  • Employment and workforce management
  • Creditworthiness assessment
  • Insurance risk assessment
  • Education
  • Access to essential services

Article 26 deployer obligations attach on that date. For certain deployer categories, Article 27 also requires a Fundamental Rights Impact Assessment before the system is put into use.


The Penalty Structure

InstrumentBreachMaximum
EU AI ActProhibited practices€35M or 7% of turnover
EU AI ActDeployer and provider duties€15M or 3% of turnover
GDPRSerious violations€20M or 4% of turnover
GDPRLesser violations, incl. missing DPIA€10M or 2% of turnover

The two instruments are independent.

A single deployment can breach both. The exposure is cumulative, not alternative.


The Short Version

If you read nothing else in this chapter:

  • Europe built the foundation, starting in 2018
  • The United States regulated by sector, then by state
  • State privacy laws imported the European concepts
  • AI-specific laws build on those same concepts
  • The EU AI Act sits on top of GDPR, not instead of it
  • Enforcement has already begun in several jurisdictions
  • At least ten state laws take effect January 1, 2027
  • EU AI Act high-risk deployer duties follow on December 2, 2027

This is not a new discipline. It is data protection law, extended to a new technology, arriving faster than most organizations have built the practice to absorb it.

Chapter 2 covers where to start.


Sources

All statutory provisions should be read in their current form. Where a secondary source is cited below, it is named — verify against the primary text before relying on any specific requirement.

European law

  • General Data Protection Regulation, Regulation (EU) 2016/679 — Articles 22 and 35
  • EU Artificial Intelligence Act, Regulation (EU) 2024/1689 — Articles 26 and 27, with Annex III for the high-risk categories
  • UK General Data Protection Regulation and the Data Protection Act 2018
  • The December 2027 date for standalone Annex III high-risk deployer obligations reflects the deferral agreed in 2026. Confirm the current date before planning against it.

Penalty thresholds

Each figure in the penalty table comes from one of two provisions. Read both before quoting the numbers.

ThresholdProvision
€35M or 7% — prohibited practicesEU AI Act, Article 99
€15M or 3% — deployer and provider obligationsEU AI Act, Article 99
€20M or 4% — serious violationsGDPR, Article 83
€10M or 2% — lesser violations, including a missing assessmentGDPR, Article 83

Both provisions set maximums rather than fixed amounts, and both are expressed as the higher of a fixed sum or a percentage of worldwide annual turnover. The tiers within each Article are more granular than the table above; check which tier applies to a specific breach rather than assuming the headline figure.

United States — laws effective January 1, 2027

LawVerification status
Colorado SB 26-189Confirmed against the Colorado General Assembly record. Passed May 9, 2026; signed May 14, 2026. See litigation note below.
California — CCPA automated decision-making regulationsConfirmed. Related risk assessment requirements took effect January 1, 2026.
California AI Transparency Act — platform provisionsConfirmed.
New York RAISE ActConfirmed.
Louisiana Data Privacy ActConfirmed.
Oklahoma comprehensive privacy lawConfirmed.
Georgia SB 444Confirmed against the Georgia legislative record.
Utah SB 319Confirmed.
Washington HB 2225Confirmed against the Washington State Legislature record.
Oregon SB 1546Confirmed against the Oregon legislative record. Or. Laws 2026 ch. 85.

United States — laws already in effect

  • New York City Local Law 144 of 2021 — automated employment decision tools
  • Utah Artificial Intelligence Policy Act
  • Illinois HB 3773 — amending the Illinois Human Rights Act
  • California AB 2013 and SB 53
  • Connecticut — private sector AI obligations, staged from October 1, 2026
  • Texas HB 149, Responsible Artificial Intelligence Governance Act

Assessment effective dates

  • Data Protection Impact Assessment — GDPR Article 35, applicable from May 25, 2018 in both the EU and the UK
  • Virginia Consumer Data Protection Act — effective January 1, 2023
  • Colorado Privacy Act — effective July 1, 2023
  • Connecticut Data Privacy Act — effective July 1, 2023
  • Texas Data Privacy and Security Act — effective July 1, 2024
  • California risk assessment requirements — effective January 1, 2026
  • Fundamental Rights Impact Assessment — EU AI Act Article 27

Enforcement decisions referenced

MatterCitation
Massachusetts — AI loan underwriting, 2025, $2.5MMassachusetts Office of the Attorney General, In re Earnest Operations LLC, Assurance of Discontinuance, July 10, 2025
Hungary — emotion analysis on customer service calls, 2022, HUF 250MHungarian National Authority for Data Protection and Freedom of Information (NAIH), Decision NAIH-85-3/2022 (Budapest Bank)
Italy — algorithmic rider scoring, 2021, €2.6MGarante per la protezione dei dati personali, order no. 234/2021 (Foodinho)
Germany — automated credit decision, Berlin, 2023, €300KBerlin Commissioner for Data Protection and Freedom of Information (BlnBDI), administrative fine, May 31, 2023 — GDPR Articles 5(1)(a), 15(1)(h), 22(3)

These are publicly reported enforcement actions, described here for information only. Nothing in this chapter is a prediction of any outcome for any organization.

A note on Colorado

The Colorado framework has been unusually unstable, and a reader planning against the January 2027 date should know why.

  • The original law, SB 24-205, was enacted in 2024 with an effective date later extended
  • A federal court enjoined its enforcement in April 2026 in xAI v. Weiser
  • The legislature then repealed and reenacted it as SB 26-189
  • The replacement narrows the statute substantially — the duty-of-care standard, risk management programs, and annual impact assessments from the original are gone
  • The replacement takes effect January 1, 2027, and applies to decisions made on or after that date

Litigation over the framework was ongoing at the time of writing. Confirm the current position before planning around this date specifically.

A standing note on verification

Effective dates move. Colorado's original AI law was repealed and replaced before it took effect. The EU AI Act's high-risk deployer date was deferred by more than a year. Nothing in this chapter should be treated as settled without checking the current position.


Use and reuse

Free to use, share, and adapt within your organization. Attribution appreciated, not required. No warranty of any kind — this is practitioner guidance, not legal advice, and sufficiency is determined by your counsel.

LegisGate · Regulatory Intelligence for AI Deployments · legisgate.com

Written by compliance and audit practitioners who spent decades on the other side of the table.

Version 1.0 · Current as of August 2026 · Verify time-sensitive claims against current sources before relying on them.

Contents
Talk to usWe're here to help
How AI Regulation Got Here | LegisGate