Chapter 1 · How We Got HereThe Handbook
Every obligation in this book traces back to a legislature, not a headline.
01Chapter 1 of 7

How We Got Here

You do not need this chapter to do the work. You need it to understand why the work looks the way it does.

Read it once. It explains where these rules came from, why Europe is further along, and what lands in 2027.


Europe Started First

Data protection as a fundamental right

The European Union treats data protection as a fundamental right in its own name — listed separately from privacy in the EU Charter.

That framing has a practical consequence. Europe regulates data protection horizontally, across every sector at once, rather than industry by industry.

The General Data Protection Regulation

The General Data Protection Regulation — GDPR — took effect in May 2018. It replaced a directive that had been in place since 1995.

It established machinery that European practitioners have now run for years:

  • Documented legal basis for every processing activity
  • Purpose limitation and data minimization
  • Impact assessments before high-risk processing
  • Rules governing automated decisions about people

Two provisions matter most for what follows:

ProvisionRequirement
Article 22Governs automated decisions with significant effects
Article 35Requires an impact assessment before high-risk processing

Neither mentions artificial intelligence. Both apply to it.

The United Kingdom diverged

After leaving the EU, the UK kept an adapted version of the same regulation. It is enforced by the Information Commissioner's Office — the ICO.

  • Similar to the EU version, not identical
  • The differences have widened since 2020
  • The Data (Use and Access) Act 2025 rewrote the automated-decision rules specifically. Section 80 replaced Article 22 with new Articles 22A–22D and commenced on February 5, 2026 — it widens when a solely automated decision with significant effects is permitted, against a set of required safeguards

If your footprint covers both, you track two bodies of law.


The United States Went Sector by Sector

There is no comprehensive federal privacy law in the United States. There are sectoral laws instead.

LawCovers
HIPAA — Health Insurance Portability and Accountability ActHealth information
GLBA — the Privacy Rule and Safeguards RuleFinancial institutions
FERPA — Family Educational Rights and Privacy ActEducation records
COPPA — Children's Online Privacy Protection ActChildren's data
FCRA — Fair Credit Reporting ActConsumer reporting

Read those names in full and the pattern is obvious. Protection. Privacy. Rights. Safeguards.

All of it is data privacy and data protection law.

The consequence for practitioners: if your background is US compliance, your privacy experience is probably deep in one or two of these and unfamiliar in the rest. That is how the law is structured, not a gap in your training.


Then the States Borrowed From Europe

Beginning with California, US states began passing comprehensive privacy laws. They borrowed heavily from the European model.

Concepts that arrived in recognizably European form:

  • Data protection assessments
  • Sensitive data categories
  • Profiling restrictions
  • Purpose limitation
  • Consumer rights and opt-outs

A US practitioner encountering a "data protection assessment" requirement in Colorado or Virginia is meeting something European colleagues have completed many times.

This is the bridge. The state privacy laws brought European concepts into US practice. The AI laws now build on those same concepts.


AI-Specific Laws Arrive

The United States moved first, in pieces

Purpose-built AI laws — statutes written for AI systems and automated decision-making, rather than general privacy laws that merely reach them — are already in force across a spread of US states. They sit on top of the general privacy and sector laws covered above, which reach AI deployments today regardless.

Any single count of them goes stale within a legislative session, so this handbook does not print one. What matters for scoping is not the total but which of them reach your deployments, and that is a question about where your people are and what your tools do.

A few examples:

LawEffective
NYC Local Law 144 — bias audits for hiring tools2023
Utah AI Policy ActMay 2024
Illinois HB 3773 — AI employment discriminationJan 1, 2026
Texas TRAIGA — the Texas Responsible Artificial Intelligence Governance ActJan 1, 2026
California AB 2013 — training-data transparencyJan 1, 2026
California SB 53 — frontier-model safetyJan 1, 2026

State laws vary considerably in scope:

  • Some reach any organization deploying AI
  • Others cover only government use
  • Several were narrowed substantially during drafting

Texas is worth knowing as an example. Its Responsible AI Governance Act was cut back significantly before passage, and private-sector obligations are far lighter than the original draft suggested.

You cannot assume a state law applies. You cannot assume it doesn't.

The European Union passed the first comprehensive AI law

The EU AI Act was adopted in 2024. It phases in over several years.

The critical structural point: it sits on top of the General Data Protection Regulation. It does not replace it.

A single high-risk deployment in Europe can require both:

  • A Data Protection Impact Assessment — DPIA — under GDPR Article 35
  • A Fundamental Rights Impact Assessment — FRIA — under AI Act Article 27

One examines risk to data. The other examines risk to people.

They ask different questions. Neither substitutes for the other.

But not every high-risk deployment owes both. The DPIA duty turns on the processing; the FRIA duty turns on who you are as well as what the system does, and reaches a much narrower set of deployers. The categories are set out later in this chapter and in the FRIA handout — read them before assuming you are in scope, and before assuming you are not.


The Assessment Obligations Are Older Than People Think

One category deserves separating out, because organizations consistently misjudge it.

Most assessment requirements are already live.

RequirementMandatory since
Data Protection Impact Assessment — EUMay 2018
Data Protection Impact Assessment — UKMay 2018
Virginia data protection assessmentJanuary 2023
Colorado data protection assessmentJuly 2023
Connecticut data protection assessmentJuly 2023
Texas data protection assessmentJuly 2024
California risk assessment requirementsJanuary 2026
Fundamental Rights Impact AssessmentDecember 2027

Only the last one is future work — and it is the one attracting most of the attention.

A note on the UK date. The obligation did not begin at Brexit. It applied from May 2018 while the UK was an EU member state, and carried into UK GDPR when the transition period ended.

An organization planning for December 2027 while carrying an unmet obligation from 2018 has its attention in the wrong place.

Chapter 6 covers what these documents are and what goes into them.


Enforcement Is Already Happening

Not warnings. Decisions, with orders attached.

MatterSubject and penaltyWhat the regulator ordered produced
Massachusetts — Earnest OperationsAI loan underwriting · 2025 · $2.5MA written AI governance system. Documented fair-lending testing. Risk assessments. A named oversight team.
Hungary — Budapest BankEmotion analysis on calls · 2022 · HUF 250MA completed impact assessment, a documented legal basis, and demonstrable safeguards — or stop the processing.
Italy — FoodinhoAlgorithmic rider scoring · 2021 · €2.6MHuman intervention in algorithmic decisions, and periodic checks on the algorithm's accuracy.
Germany — Berlin bankAutomated credit decision · 2023 · €300KThe specific data, factors, and criteria behind a single automated decision, on request.

Different countries. Different sectors. Different years.

In each case the regulator asked for the same categories of material:

  • The assessment
  • The documented legal basis
  • A record of what the system did and why

None of it could be produced quickly. None of it should be created after the request arrived.

Remediation is different. A regulator expects gaps to be addressed immediately, and starting that work is the right response.

But a document dated after the request answers a different question than the one being asked. The record shows what you did at the time. Remediation shows what you are doing now. Both matter. They are not interchangeable.


The run-up to 2027
  1. May 2018
    GDPR applies

    Impact assessments and automated-decision rules take effect across the EU. Most unmet obligations still date from here.

  2. January 1, 2026
    California risk assessments

    California risk assessment requirements take effect.

  3. July 1, 2026
    Connecticut, CTDPA amendments

    PA 25-113 takes effect; the dedicated profiling impact assessment follows on August 1, 2026.

  4. October 1, 2026
    Connecticut, Online Safety Act

    PA 26-15 begins staging — automated employment decision tools, provenance, AI subscription notices. A separate instrument from the CTDPA amendments above.

  5. December 2, 2026
    Two new EU prohibitions

    AI Act Article 5(1)(ba) and (bb) apply — non-consensual intimate imagery and child sexual abuse material. Highest penalty tier.

  6. January 1, 2027
    The US state cluster

    At least eighteen state requirements take effect on one date — automated decisions, two new comprehensive privacy frameworks and a third whose thresholds drop, health and insurance AI, companion chatbots, frontier models, and content provenance.

  7. December 2, 2027
    EU AI Act high-risk deployers

    Article 26 deployer obligations attach for standalone Annex III systems. Article 27 adds a Fundamental Rights Impact Assessment only for public bodies and private entities providing public services — for any Annex III system except point 2 — and for any deployer of an Annex III point 5(b) or 5(c) system.

  8. August 2, 2028
    Annex I high-risk systems

    The same Chapter III duties reach systems that are high-risk as safety components of Annex I, Section A products. Section B products are handled by their own sectoral legislation.

Two of these are the subject of this chapter. The rest are already in force.

What Lands in 2027

Three dates, and a fourth just past the horizon. They are listed here in the order they arrive, which is not the order they get attention.

December 2, 2026 — two new EU prohibitions

Regulation (EU) 2026/1744 added Article 5(1), points (ba) and (bb): AI systems that generate or manipulate intimate imagery of an identifiable person without their explicit consent, and systems that generate child sexual abuse material. These sit in the highest penalty tier — €35M or 7% of turnover — and this is the nearest AI Act date on the calendar, not the furthest.

January 1, 2027 — the US state cluster

At least eighteen separate state requirements take effect on this single date, across seventeen instruments. They cover very different subject matter, which is the point worth noticing.

Automated decision-making

LawWhat it requires
Colorado SB 26-189A pre-use notice wherever a covered ADMT materially influences a consequential decision. Where that decision produces an adverse outcome, a plain-language explanation within 30 days, and — on the consumer's request — instructions for correcting materially inaccurate personal data and an opportunity for meaningful human review and reconsideration, to the extent commercially reasonable. Correction does not extend to opinions, predictions or scores
California — CCPA automated decision-making regulationsPre-use notice, opt-out, and access rights for significant decisions (11 CCR §§ 7200–7222). The risk assessment half of the same regulations has applied since January 1, 2026; the first attestation to the CPPA is due April 1, 2028

Colorado's turns on seven covered domains (§ 6-1-1701(6)): education enrollment or opportunity; employment or an employment opportunity creating or potentially creating an employer-employee relationship; the lease or purchase of residential real estate in Colorado; a financial or lending service; insurance, including underwriting, pricing, coverage and claims adjudication; health-care services; and essential government services and public benefits.

Two words to avoid there. It is not "housing" — the repealed SB 24-205 used that word and the replacement narrowed it to residential real estate. And it is not just "lending" — limb (d) reaches financial services more broadly. A consequential decision is one relating to access to, eligibility for, selection for or compensation for a covered domain, subject to nine express exclusions at § 6-1-1701(3)(b) — among them low-stakes and routine decisions, advertising and content moderation, manual-analysis spreadsheets, and outputs that merely summarise or organise information for human review. Deployers must also keep compliance records for at least three years.

The law was signed May 14, 2026, replacing the original after it was repealed. It removes the earlier duty-of-care standard, the risk-management-programme requirement and the annual impact assessment.

The cure period runs to you, not only to your vendor. Until January 1, 2030, the Attorney General must issue a notice of violation to a developer or deployer before any enforcement action — but only "if a cure is deemed possible by the Attorney General", and no cure period is required at all where the Attorney General finds and can demonstrate a knowing or repeated violation. Where one is given, suit follows if the violation is not cured within 60 days of receipt.

Not all of the act waits for 2027. It takes effect January 1, 2027 and applies to consequential decisions made on or after that date — except for the provisions SECTION 5(2) put into effect on passage, which include both Attorney General rulemaking mandates (§§ 6-1-1704(4) and 6-1-1705(3)), the insurance-commissioner rule authority, the joinder provision and the appropriation. Those rules are due by January 1, 2027, the same day the duties begin, and the authority to write them has been live since May 14, 2026.

Comprehensive privacy laws

StateNote
LouisianaNew omnibus law (Act 502 / SB 386). Applies at $25M gross revenue, or 75,000 consumers, households or devices, or 50% of revenue from selling personal data
OklahomaNew omnibus privacy law, Enrolled S.B. 546 (2026). The act carries no short title — there is no "Oklahoma Consumer Data Privacy Act" to cite
DelawareNot new — an amendment. 85 Del. Laws c. 463 lowers the applicability threshold to 10,000 consumers (5,000 where more than 20% of revenue comes from selling personal data) and extends coverage to third parties who acquire personal data from a controller. It also drops the data protection assessment trigger at § 12D-108(a) from 100,000 consumers to 50,000 — the number that matters most if your programme is scoped to assessments

The first two follow the familiar consensus framework, with state-specific differences worth reading. Delaware is the one to watch if you concluded you were under the threshold: the threshold moved.

AI in healthcare and insurance

LawWhat it requires
Georgia SB 444An AI system may be used to automate tasks and participate in decision-making, but may not issue an adverse determination until a natural person conducts a utilization review in which a clinical peer participates. Favourable determinations are unconstrained, and the duty runs to utilization review rather than coverage decisions at large
Utah SB 319Insurers must disclose AI use in authorization review — to the department, to network providers and to enrollees. An adverse preauthorization determination regarding clinical or medical necessity must be made by an individual who either knows the enrollee's condition or consults a specialist who does, who does not rely solely on a recommendation from any other source, and who exercises independent medical judgment — that last requirement excepted where the specialist route is used
Iowa HF 2635Peer review of prior-authorization denials and downgrades (§ 514F.8A), and — after a hearing — commissioner-ordered payment of the claim with 10% interest where an audit breached the rules (§ 514F.8C(2)(e)). Both are administrative remedies; there is no private right of action. The separate prohibition on AI as the sole basis for a medical-necessity denial, delay or downgrade sits at § 514F.8(2A) and has applied since July 1, 2026
Washington SB 5395A version swap rather than a new duty: the second versions of RCW 48.43.830 and 48.43.535 take effect as the first versions expire. The prior-authorization rules they carry — AI may not be the sole means of denying, delaying or modifying care, and only a licensed clinician may deny on medical necessity — are already in force under the expiring text. Read the incoming sections rather than assuming they are identical.

Companion chatbots

LawWhat it requires
Washington HB 2225Disclosure that the bot is not human, crisis protocols for suicidal ideation and self-harm, public reporting of crisis referrals
Oregon SB 1546Notice that the user is interacting with artificially generated output, a crisis protocol for suicidal ideation and self-harm with a 988 referral, and annual public reporting of crisis referrals — all running to every user — plus additional protections for minors, and a private right of action
Connecticut PA 26-15, §§ 5–6AI companion disclosure and minor-safety duties
Rhode Island S 2195Crisis protocols and a recurring three-hour notification that the companion is not human

On remedies, the two run opposite to how they are usually described. Washington's duty runs to all users, not only minors, and § 6 declares a violation an unfair or deceptive act affecting the public interest for the purposes of the Consumer Protection Act, chapter 19.86 RCW — but the act creates no cause of action of its own, so a private suit proceeds under RCW 19.86.090 and must still establish injury to business or property and causation. Oregon is the one with a direct action: SB 1546 § 2 gives an injured individual the greater of actual damages or $1,000 per violation, plus an injunction and attorney fees.

Frontier models and content provenance

LawWhat it requires
New York RAISE ActSafety and transparency obligations on large frontier AI developers
Illinois SB 315The Artificial Intelligence Safety Measures Act becomes operative: § 18 disclosure statements and fees, § 10(c) transparency reports published on deploying a new or substantially modified frontier model, § 15 critical-safety-incident reporting, and § 20 whistleblower protections. Only the § 10(a) frontier AI framework and the § 10(d) annual independent third-party audit wait for January 1, 2028
Connecticut PA 26-15, § 2(c)Large frontier developers — group annual gross revenue over $500 million — must have an internal anonymous safety-reporting process in place by this date. Section 2 itself has been in force since October 1, 2026, including the § 2(b) ban on contracts permitting retaliation against covered employees and the § 2(d) notice and posting duty, both carrying a civil penalty of up to $1,000 per violation
California AI Transparency Act — platform provisionsLarge platforms must detect and label machine-readable provenance on AI-generated content
Utah HB 276Digital Voyeurism Prevention Act and Digital Content Provenance Standards Act take effect

What that spread tells you

Eighteen requirements. One date. And no single theme.

  • Employment and lending decisions
  • Health insurance authorization and peer review
  • Consumer and companion chatbots
  • Frontier model safety and internal reporting
  • Content labeling and provenance
  • Two new general privacy frameworks, and a third whose threshold drops

You cannot scope this by watching one category of law. An organization tracking only "AI hiring rules" misses the insurance provisions. One tracking only privacy misses the chatbot duties.

The obligations attach based on what your tools actually do — not on which regulatory conversation you happen to be following.

December 2, 2027 — EU AI Act high-risk deployers

Obligations for deployers of standalone Annex III high-risk systems become applicable, following the deferral made by Regulation (EU) 2026/1744 — the Digital Omnibus on AI. Systems that are high-risk because they are safety components of products covered by the Union harmonisation legislation in Annex I, Section A follow later, on August 2, 2028. Section B products — aviation, motor vehicles, rail, marine equipment and machinery — sit outside Chapter III altogether under Article 2(2); their AI requirements run through the sectoral legislation instead, not through Articles 26 and 27.

Annex III lists eight areas. The ones most deployments land in:

PointArea
3Education and vocational training
4Employment, workers' management and access to self-employment
5(b)Creditworthiness and credit scoring
5(c)Risk assessment and pricing for life and health insurance

Point 5 as a whole is access to and enjoyment of essential private services and essential public services and benefits; creditworthiness and insurance are two of its sub-points, not separate areas. The point numbers matter — Article 27 turns on them.

Article 26 deployer obligations attach on that date, for every deployer of such a system.

Article 27 is narrower, and the difference matters. A Fundamental Rights Impact Assessment is owed only by deployers that are bodies governed by public law, private entities providing public services, or deployers of the systems at Annex III points 5(b) and (c) — creditworthiness assessment and credit scoring, and risk assessment and pricing for life and health insurance. Systems in the Annex III point 2 area, critical infrastructure, are carved out.

A private employer that is neither a public body nor a provider of public services, running a high-risk hiring tool, owes Article 26 duties and no Article 27 assessment — recruitment is Annex III point 4, and only points 5(b) and (c) pull an ordinary private deployer in. The same tool inside a public authority, or a private body delivering a public service, does carry the assessment: for those two categories any Annex III system except point 2 triggers it. Establish which category you are in first, then look at the point number.


The Penalty Structure

InstrumentBreachMaximum
EU AI ActProhibited practices€35M or 7% of turnover
EU AI ActDeployer and provider duties€15M or 3% of turnover
GDPRSerious violations€20M or 4% of turnover
GDPRLesser violations, incl. missing DPIA€10M or 2% of turnover

The two instruments are independent.

A single deployment can breach both. The exposure is cumulative, not alternative.


The Short Version

If you read nothing else in this chapter:

  • Europe built the foundation, starting in 2018
  • The United States regulated by sector, then by state
  • State privacy laws imported the European concepts
  • AI-specific laws build on those same concepts
  • The EU AI Act sits on top of GDPR, not instead of it
  • Enforcement has already begun in several jurisdictions
  • At least eighteen state requirements take effect January 1, 2027
  • Two new EU prohibited practices land earlier, on December 2, 2026
  • EU AI Act high-risk deployer duties follow on December 2, 2027, and Annex I product-embedded systems on August 2, 2028

This is not a new discipline. It is data protection law, extended to a new technology, arriving faster than most organizations have built the practice to absorb it.

Chapter 2 covers where to start.


Sources

All statutory provisions should be read in their current form. Where a secondary source is cited below, it is named — verify against the primary text before relying on any specific requirement.

European law

  • General Data Protection Regulation, Regulation (EU) 2016/679 — Articles 22 and 35
  • EU Artificial Intelligence Act, Regulation (EU) 2024/1689 — Articles 26 and 27, with Annex III for the high-risk categories
  • UK General Data Protection Regulation and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025. Section 80 (automated decision-making) was commenced on February 5, 2026 by the Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026, SI 2026/82, reg. 2(j) (with reg. 5, which preserves the earlier rules for decisions taken before that date)
  • Regulation (EU) 2026/1744 of 8 July 2026 (the Digital Omnibus on AI) amended Article 113. As amended, Chapter III Sections 1, 2 and 3, with the exception of Article 6(5), apply from 2 December 2027 for systems high-risk under Article 6(2) and Annex III, and from 2 August 2028 for systems high-risk under Article 6(1) and Annex I, Section A — Article 2(2) as amended puts Section B products outside Chapter III altogether. The same Regulation added Article 5(1), points (ba) and (bb), which apply from 2 December 2026. Confirm the current dates before planning against them.
  • The Article 27(1) deployer categories — bodies governed by public law, private entities providing public services, and deployers of Annex III points 5(b) and (c), excluding the Annex III point 2 area — are read directly from the consolidated text of the Act as amended.

Penalty thresholds

Each figure in the penalty table comes from one of two provisions. Read both before quoting the numbers.

ThresholdProvision
€35M or 7% — prohibited practices under Article 5EU AI Act, Article 99(3)
€15M or 3% — operator obligations, including deployer duties under Article 26EU AI Act, Article 99(4)(e)
€20M or 4% — serious violationsGDPR, Article 83(5)
€10M or 2% — lesser violations, including a missing assessmentGDPR, Article 83(4)

Both instruments set maximums rather than fixed amounts, and both are expressed as the higher of a fixed sum or a percentage of worldwide annual turnover. The tiers are more granular than the table above — the AI Act adds a €7.5M or 1% tier at Article 99(5) for supplying incorrect or misleading information to an authority, and caps SMEs at the lower of the amount or the percentage under Article 99(6). Check which tier applies to a specific breach rather than assuming the headline figure.

United States — requirements effective January 1, 2027

Each row was checked against the enacting jurisdiction's own record.

RequirementVerification status
Colorado SB 26-189Colorado General Assembly bill record. Rerevised May 9, 2026; Signed Act May 14, 2026. Attorney General rules on post-adverse-outcome disclosure and on correction and human review are due the same day the duties begin. See the litigation note below.
California — CCPA automated decision-making regulations11 CCR art. 11 (§§ 7200, 7220–7222; there is no § 7201–7219). The risk assessment provisions at §§ 7150–7157 took effect January 1, 2026; the first attestation to the CPPA is due April 1, 2028.
California AI Transparency Act — platform provisionsSB 942 as amended by AB 853. Provider duties ran from August 2, 2026; platform duties from January 1, 2027; capture devices from January 1, 2028.
New York RAISE ActN.Y. Gen. Bus. Law art. 44-B (§§ 1420–1429). L 2025 ch 699 as amended by L 2026 ch 96, which repealed and re-added §§ 1420–1429 and set the January 1, 2027 date in place of the original ninetieth-day clause.
Louisiana Data Privacy Act2026 La. Acts 502 (SB 386).
Oklahoma comprehensive privacy lawEnrolled S.B. 546 (2026), codified at Okla. Stat. tit. 75A §§ 300 et seq.; § 309 carries the data protection assessment duty; effective January 1, 2027. The act has no short title — do not cite it as the "Oklahoma Consumer Data Privacy Act".
Delaware — DPDPA amendments85 Del. Laws c. 463 (HB 380), signed September 2, 2026, amending 6 Del. C. §§ 12D-102, -103, -104, -106, -107, -108, -109, -110 and -111, and adding a new § 12D-107A (duties of third parties). Thresholds at § 12D-103(a) move from 35,000 to 10,000, and from 10,000 to 5,000 where more than 20% of gross revenue comes from the sale of personal data; the § 12D-108(a) assessment trigger moves from 100,000 to 50,000. The bill-detail page's original synopsis says 15,000 and is wrong for the enacted text.
Georgia SB 4442026 Ga. Laws Act 411, signed May 5, 2026; O.C.G.A. § 33-46-7.1 in full — one commencement date, no phasing. § 33-46-7.1(c) permits AI to participate in decision-making and bars it only from issuing an adverse determination.
Utah SB 319S.B. 319 S1, Health Insurance Preauthorization Amendments, Laws of Utah 2026, ch. 240, § 3 (enrolled copy): "This bill takes effect on January 1, 2027." Signed March 19, 2026; the effective date is corroborated by the Legislature's own passed-bills table for the 2026 General Session. The enacted vehicle is the first substitute — read S.B. 319 S1, not the introduced text.
Iowa HF 26352026 Iowa Acts ch. 1087, signed May 13, 2026 — Iowa Code §§ 514F.8A and 514F.8C(2)(e) from January 1, 2027. The AI prohibition is a different section, § 514F.8(2A), in force since July 1, 2026; § 514F.8E makes the ch. 505 and 507B remedies exclusive.
Washington HB 22252026 Wash. Sess. Laws ch. 168, in its entirety. § 6 supplies the unfair-or-deceptive-act and public-interest elements of a chapter 19.86 RCW claim; it creates no cause of action of its own.
Washington SB 53952026 Wash. Sess. Laws ch. 157, §§ 9–10: sections 2 and 6 expire January 1, 2027 and sections 3 and 7 take effect the same day. Only RCW 48.43.830 is reenacted; 48.43.535 is amended in alternate versions.
Oregon SB 1546Or. Laws 2026 ch. 85, in its entirety. The enrolled act has no effective-date clause; ORS 171.022 defaults to January 1 of the year after passage, and OLIS records "Effective date, January 1, 2027". § 2 creates a private right of action.
Connecticut PA 26-15§§ 5–6 (AI companions) and § 2(c) (large frontier developer reporting).
Rhode Island S 21952026 R.I. Pub. Laws ch. 376, codified at R.I. Gen. Laws tit. 6 ch. 63; signed June 22, 2026.
Illinois SB 315Pub. Act 104-0538, signed July 6, 2026; § 99 sets the January 1, 2027 effective date. §§ 10(c), 15, 18 and 20 bind from that date; only §§ 10(a) and 10(d) carry express January 1, 2028 triggers.
Utah HB 276Enrolled copy, Artificial Intelligence Modifications, enacting Utah Code chs. 13-72b (Digital Voyeurism Prevention Act) and 13-72c (Digital Content Provenance Standards Act); every enacted section marked effective 01/01/27.

On counting. Eighteen is the number of distinct requirements listed above, across seventeen instruments — Connecticut's PA 26-15 contributes two, in different subject areas. It is a floor, not a census: sessions continue, and a requirement that commences on January 1, 2027 inside an act whose headline date is different will not necessarily surface in a date scan.

United States — laws already in effect

  • New York City Local Law 144 of 2021 — automated employment decision tools
  • Utah Artificial Intelligence Policy Act
  • Illinois HB 3773 — amending the Illinois Human Rights Act
  • California AB 2013 and SB 53
  • Connecticut — two separate instruments, frequently conflated. PA 25-113 amended the Connecticut Data Privacy Act (Conn. Gen. Stat. §§ 42-515 et seq.) in stages — earlier sections ran from July 1 and October 1, 2025, and the principal CTDPA amendments took effect July 1, 2026 — with a dedicated profiling impact assessment applying to processing activities created or generated on or after August 1, 2026. PA 26-15, An Act Concerning Online Safety, stages separately from October 1, 2026 — the automated employment decision tool framework, provenance, AI subscription notices, and for frontier developers a ban on contracts permitting retaliation against covered employees (§ 2(b)) plus a covered-employee notice and posting duty (§ 2(d)), each carrying a civil penalty of up to $1,000 per violation — with further duties on January 1, 2027 and the principal AEDT notice duties on October 1, 2027
  • Texas HB 149, Responsible Artificial Intelligence Governance Act

Assessment effective dates

  • Data Protection Impact Assessment — GDPR Article 35, applicable from May 25, 2018 in both the EU and the UK
  • Virginia Consumer Data Protection Act — effective January 1, 2023
  • Colorado Privacy Act — effective July 1, 2023
  • Connecticut Data Privacy Act — effective July 1, 2023
  • Texas Data Privacy and Security Act — effective July 1, 2024
  • California risk assessment requirements — effective January 1, 2026
  • Fundamental Rights Impact Assessment — EU AI Act Article 27

Enforcement decisions referenced

MatterCitation
Massachusetts — AI loan underwriting, 2025, $2.5MMassachusetts Office of the Attorney General, In re Earnest Operations LLC, Assurance of Discontinuance, July 10, 2025
Hungary — emotion analysis on customer service calls, 2022, HUF 250MHungarian National Authority for Data Protection and Freedom of Information (NAIH), Decision NAIH-85-3/2022 (Budapest Bank)
Italy — algorithmic rider scoring, 2021, €2.6MGarante per la protezione dei dati personali, order no. 234/2021 (Foodinho)
Germany — automated credit decision, Berlin, 2023, €300KBerlin Commissioner for Data Protection and Freedom of Information (BlnBDI), administrative fine, May 31, 2023 — GDPR Articles 5(1)(a), 15(1)(h), 22(3)

These are publicly reported enforcement actions, described here for information only. Nothing in this chapter is a prediction of any outcome for any organization.

A note on Colorado

The Colorado framework has been unusually unstable, and a reader planning against the January 2027 date should know why.

  • The original law, SB 24-205, was enacted in 2024 with an effective date later extended
  • xAI sued the Colorado Attorney General in the District of Colorado on April 9, 2026 (X. AI LLC v. Weiser, No. 1:26-cv-01515); the United States intervened on April 24, 2026. On the parties' joint, unopposed motion the court entered a minute order on April 27, 2026 under which the Attorney General will not initiate enforcement — including any investigation — for alleged violations occurring on or before 14 days after the court rules on a preliminary-injunction motion xAI must file within 28 days of final adoption of implementing rulemaking. Because it was stipulated, the order reflects no view on the merits
  • The legislature then repealed and reenacted it as SB 26-189
  • The replacement narrows the statute substantially — the duty-of-care standard, risk management programs, and annual impact assessments from the original are gone
  • The replacement takes effect January 1, 2027, and applies to decisions made on or after that date

The stay reaches the replacement, not just the repealed statute. Its own terms run to violations of SB 24-205 or of any legislation replacing or amending it enacted during that session — which is SB 26-189. So the forbearance and the January 2027 date interact, and the interaction is the thing to watch.

Litigation over the framework was ongoing at the time of writing. This handbook does not state whether the preliminary-injunction motion has since been filed or decided, or whether the Attorney General has adopted the rules that start its clock — none of that could be confirmed at a primary source as at the version date. Confirm the current position on the docket before planning around this date specifically.

A standing note on verification

Effective dates move. Colorado's original AI law was repealed and replaced before it took effect. The EU AI Act's high-risk deployer date was deferred by more than a year. Nothing in this chapter should be treated as settled without checking the current position.


Use and reuse

Free to use, share, and adapt within your organization. Attribution appreciated, not required. No warranty of any kind — this is practitioner guidance, not legal advice, and sufficiency is determined by your counsel.

LegisGate · Regulatory Intelligence for AI Deployments · legisgate.com

Written by compliance and audit practitioners who spent decades on the other side of the table.

Version 1.1 · Current as of September 2026 · Verify time-sensitive claims against current sources before relying on them.

Contents
Talk to usWe're here to help
How AI Regulation Got Here | LegisGate