Intelligence library · verified corpus

Meridian Atlas.

The regulatory foundation behind LegisGate™ — where you operate, which instruments bind today, and what is on the horizon for counsel.

389

Curated laws & guidance

16

Regions

Global footprint

192

Industry tags

Sector depth

358

In force now

27

On the horizon

Pending + monitor

2621

Enforcement rows

Real-world actions

Live Meridian snapshot · 100% with official source URLs · updated Oct 4, 2026, 8:30 AM

This atlas reads the LegisGate™ intelligence library — the Meridian™ corpus, the same database that powers obligation reports, deadline alerts, and the rules engine. Each chart answers a question a business owner should ask before deploying AI across markets or industries.

Global coverage by region

Where your regulatory surface area lives — bars are jurisdiction clusters in Meridian.

Jurisdictions with deep standalone coverage (e.g. Singapore, Brazil, Switzerland) are broken out of their parent region; everything else rolls up to the regional cluster.

Why this matters

Your compliance stack is the union of everywhere you have users, employees, data, or contracts—not just headquarters. Dense bars (EU & EEA, US Federal, US States, UK) mean more curated laws, findings, and enforcement context for deployments touching those markets. Thin or empty regions flag expansion risk: entering a market without Meridian depth means slower diligence and more reliance on ad-hoc research.

Industry depth

How many Meridian instruments tag each sector — tall bars mean curated vertical substance.

Why this matters

Sector tags are how LegisGate™ knows whether obligations are tuned for your business model. Healthcare, financial services, and public-sector bars reflect deep templates—not generic privacy copy. If your industry is tall here, reports can cite sector-specific duties and enforcement patterns. If your vertical is in 'Other sectors,' prioritize confirming coverage before you treat the library as exhaustive for that niche.

Binding law vs. standards

Statutory/regulatory instruments compared with guidance documents and standards.

  • Binding instruments: 293
  • Standards & guidance: 94

Why this matters

Binding instruments (laws, regulations, treaties) carry enforcement and penalty exposure—what boards and insurers care about. Standards and guidance shape procurement, customer diligence, and best practice; they matter contractually even when not directly enforceable. A portfolio heavy on binding rows means statutory cliff dates and regulator actions dominate your roadmap; a guidance-heavy mix signals norm-setting and certification pressure.

Status horizon

What is enforceable today versus what is coming—plan budget before effective dates.

  • In Force: 335
  • Partially In Force: 23
  • Pending: 27
  • Superseded: 4

Why this matters

'In force' rows are obligations you can be held to now—policy, controls, and vendor terms should already reflect them. 'Pending' and 'Monitor' rows are your 6–18 month horizon: effective dates, rulemaking, and signed-but-not-yet-operative bills. Operations teams often miss horizon items until a deadline hits; this split tells you where to front-load legal review versus maintain watchlists for board reporting.

Compliance deadline wall

64 dated statutory obligations land in the next 24 months — rows link to their library dossiers.

  1. Oct 7, 2026RMI PDPA 2025 — Effective
  2. Dec 1, 2026Chile Law 19.628 — Law 21,719 applicable
  3. Dec 2, 2026Regulation (EU) 2024/1689 (Artificial Intelligence Act) — Legacy-system watermarking + new prohibited practices
  4. Dec 9, 2026Directive (EU) 2024/2853 — Transposition deadline
  5. Dec 10, 2026Australia Privacy Act — Phased - APP 1.7 to 1.9 not yet in operation
  6. Jan 1, 2027Artificial Intelligence Safety Measures Act, Pub. Act 104-0538 (Ill. 2026) — Effective
  7. Jan 1, 2027AU Continental AI Strategy — Phased implementation — midterm review of the Strategy (§ 3.2.3(v))
  8. Jan 1, 2027Australia Online Safety Act — Phased — uncommenced amendment
  9. Jan 1, 2027C.R.S. § 6-1-1701 et seq. — Attorney General rules due
  10. Jan 1, 2027C.R.S. § 6-1-1701 et seq. — Effective
  11. Jan 1, 2027Cal. Code Regs. tit. 11 (CPPA — automated decisionmaking technology and risk assessments) — Pre-Use Notices effective
  12. Jan 1, 2027California AI Transparency Act (BPC Chapter 25) — Platform obligations operative
  13. Jan 1, 2027Connecticut Public Act 26-15 — AI companions
  14. Jan 1, 2027Connecticut Public Act 26-15 — Large frontier developer reporting
  15. Jan 1, 2027Connecticut Public Act 26-15 (SB 5) — AI companions
  16. Jan 1, 2027Connecticut Public Act 26-15 (SB 5) — Large frontier developer reporting
  17. Jan 1, 2027Delaware Personal Data Privacy Act — Amendment effective
  18. Jan 1, 2027E2SSB 5395 — Effective — sections 3 and 7 commence
  19. Jan 1, 2027E2SSB 5395 — Expires — sections 2 and 6
  20. Jan 1, 2027Iowa Code ch. 514F (health insurance utilization review) as amended by 2026 Iowa Acts ch. 1087 — Applies
  21. Jan 1, 2027La. Rev. Stat. §§ 51:1780.1–51:1780.5 — Effective
  22. Jan 1, 2027Municipal Freedom of Information and Protection of Privacy Act, R.S.O. 1990, c. M.56 — S.O. 2026, c. 2, Sched. 11 adds privacy impact assessment (s. 28(3)-(6)), privacy safeguards (s. 30(5)), and breach reporting/notification (s. 30.1) duties
  23. Jan 1, 2027N.Y. Gen. Bus. Law art. 44-B (§§ 1420–1429) (Responsible AI Safety and Education Act) — Effective
  24. Jan 1, 2027New Hampshire Data Privacy Act — Phased — future
  25. Jan 1, 2027O.C.G.A. Tit. 33, Ch. 46 (private review agents) — Act 411 AI adverse-determination limits — Effective
  26. Jan 1, 2027Okla. Stat. tit. 75A — Effective
  27. Jan 1, 2027Oregon SB 1546 (2026) — Effective
  28. Jan 1, 2027Rhode Island S 2195 — Effective
  29. Jan 1, 2027Sri Lanka PDPA — Phased — s. 2, s. 3, Part I and Part III
  30. Jan 1, 2027Utah Code Ann. tit. 13, chs. 72b, 72c (Digital Voyeurism Prevention Act; Digital Content Provenance Standards Act) — Effective (core)
  31. Jan 1, 2027Washington ESHB 2225 (AI companion chatbots) — Effective
  32. Jan 17, 2027Albania Law 124/2024 — Phased (delayed provisions)
  33. Feb 1, 2027Washington E2SHB 1170 (AI disclosures and content provenance) — Effective
  34. Apr 1, 2027Maryland Online Data Privacy Act — Phased
  35. May 1, 2027APDPA — Effective
  36. May 1, 2027OSFI Guideline E-23 (2027) — Guideline E-23 (2027) becomes effective for all Federally Regulated Financial Institutions
  37. May 13, 2027Digital Personal Data Protection Act, 2023 — Core operational rules
  38. May 26, 2027EU Medical Devices Regulation (EU) 2017/745 — Extended transitional deadline for Class III and implantable Class IIb devices under old certificates
  39. Jul 1, 20272026 Ga. Laws Act 518, amending O.C.G.A. tit. 39, ch. 5 (artificial intelligence companion chatbots) — Effective
  40. Jul 1, 2027Cal. Bus. & Prof. Code div. 8, ch. 22.6, §§ 22601 to 22606 (Companion Chatbots) — § 22603 OSP reporting commencement hold to July 1, 2027 — Annual reporting
  41. Jul 1, 2027Conversational AI Services Act (Iowa Code ch. 554J) — applies July 1, 2027 — Effective
  42. Jul 1, 2027Idaho Code §§ 48-2101 to 48-2105 (Conversational AI Safety Act) — Effective
  43. Jul 1, 2027Ky. Rev. Stat. § 367.3611 et seq. — Amended
  44. Jul 1, 2027Nebraska Conversational AI Safety Act (LB 525) — Operative — Conversational Artificial Intelligence Safety Act
  45. Jul 31, 2027La. Rev. Stat. §§ 51:1780.1–51:1780.5 — Phased
  46. Aug 2, 2027Regulation (EU) 2024/1689 (Artificial Intelligence Act) — AI regulatory sandboxes (member states)
  47. Aug 6, 2027EIOPA Opinion / guidance on the use of artificial intelligence by the insurance sector — EIOPA's 2-year supervisory convergence review under §4.1
  48. Sep 1, 2027Global Digital Compact — Phased — high-level review of the Compact during the eighty-second session (para. 74)
  49. Oct 1, 2027Connecticut Public Act 26-15 — AEDT notice operative
  50. Oct 1, 2027Connecticut Public Act 26-15 (SB 5) — AEDT notice operative
  51. Oct 10, 2027Bangladesh PDPA 2026 — Phased commencement (earliest)
  52. Nov 27, 2027Ley N.º 7593/2025 (Paraguay) — In force
  53. Nov 27, 2027Paraguay Law 6534/2020 — Ley N° 7593/2025 in force; Ley 6534 art. 4 repealed
  54. Dec 2, 2027Regulation (EU) 2024/1689 (Artificial Intelligence Act) — Annex III high-risk standalone systems
  55. Dec 11, 2027Regulation (EU) 2024/2847 — Full applicability
  56. Dec 23, 2027FedRAMP Authorization Act (Pub. L. 117-263) — Repeal (scheduled)
  57. Jan 1, 2028Artificial Intelligence Safety Measures Act, Pub. Act 104-0538 (Ill. 2026) — Framework and audit duties
  58. Jan 1, 2028AU Continental AI Strategy — Phased implementation — Phase II commences (§ 3.2.1)
  59. Jan 1, 2028California AI Transparency Act (BPC Chapter 25) — Capture device obligations
  60. Jan 1, 2028Utah Code Ann. tit. 13, chs. 72b, 72c (Digital Voyeurism Prevention Act; Digital Content Provenance Standards Act) — Effective (devices)
  61. Jan 1, 2028Vt. Stat. Ann. tit. 9, §§ 2415a–2415k — Effective
  62. May 26, 2028EU Medical Devices Regulation (EU) 2017/745 — Extended transitional deadline for other Class IIb, Class IIa, and Class I devices
  63. Jun 30, 2028Alberta PIPA — Regulation expires unless repassed
  64. Aug 2, 2028Regulation (EU) 2024/1689 (Artificial Intelligence Act) — Annex I product-embedded high-risk AI

Also published on the LegisGate™ AI Tracker — calendar, legislative movement, and global signals — with RSS and JSON feeds.

Why this matters

Most teams discover effective dates from enforcement headlines — after the budget cycle that should have funded the work. This wall is assembled from the key-date field of laws in Meridian, so it updates as laws are amended or delayed. Note the January 1, 2027 cluster: Colorado SB 26-189 (ADMT), NY RAISE Act, and a wave of state effective dates hit the same day. If you operate multi-state, that is one program deadline, not many.

Enforcement is accelerating — especially on AI

1,847 documented actions (named party or fine, with a date) out of 2,621 curated enforcement-intelligence rows; 219 are AI-specific.

  • Documented actions
  • AI-specific

Why this matters

These counts are deliberately conservative: a row only registers here when it names a sanctioned party or a fine amount and carries an action date — reference digests and posture notes are excluded. The current-year bar is year-to-date, so read the trajectory, not the final height. The blue bars, actions specifically involving algorithms or automated decisions, compress a decade of typical enforcement ramp into roughly three years. That is the board-deck fact: not 'AI regulation is coming,' but counted, dated actions already compounding.

Global convergence index

Obligation themes ranked by how many distinct jurisdictions now impose them — computed across the full Meridian.

Consent requirements

88 jurisdictions · 98 laws & guidance

e.g. 740 ILCS 14 · PIPEDA · Act on the Protection of Personal Information (Act No. 57 of 2003)

AI transparency & disclosure

72 jurisdictions · 104 laws & guidance

e.g. Regulation (EU) 2024/1689 (Artificial Intelligence Act) · Regulation (EU) 2016/679 (General Data Protection Regulation) · C.R.S. § 6-1-1701 et seq.

Automated decision-making rights

68 jurisdictions · 72 laws & guidance

e.g. Regulation (EU) 2016/679 (General Data Protection Regulation) · C.R.S. § 6-1-1701 et seq. · Cal. Civ. Code § 1798.100 et seq.

Cross-border transfer controls

64 jurisdictions · 65 laws & guidance

e.g. Act on the Protection of Personal Information (Act No. 57 of 2003) · ADGM Data Protection Regulations 2021 · Albania Law 124/2024

Risk & impact assessments

50 jurisdictions · 57 laws & guidance

e.g. Regulation (EU) 2024/1689 (Artificial Intelligence Act) · Regulation (EU) 2016/679 (General Data Protection Regulation) · UK GDPR (assimilated Regulation (EU) 2016/679)

Vendor & deployer accountability

49 jurisdictions · 57 laws & guidance

e.g. Regulation (EU) 2024/1689 (Artificial Intelligence Act) · C.R.S. § 6-1-1701 et seq. · Tex. Bus. & Com. Code ch. 552

Breach notification duties

42 jurisdictions · 43 laws & guidance

e.g. Health Insurance Portability and Accountability Act — 45 CFR Parts 160 & 164 · Act on the Protection of Personal Information (Act No. 57 of 2003) · Albania Law 124/2024

Children & minors protections

26 jurisdictions · 27 laws & guidance

e.g. Tex. Bus. & Com. Code ch. 552 · 2026 Ga. Laws Act 518, amending O.C.G.A. tit. 39, ch. 5 (artificial intelligence companion chatbots) · APDPA

Biometric & facial-recognition limits

17 jurisdictions · 19 laws & guidance

e.g. Tex. Bus. & Com. Code ch. 552 · 740 ILCS 14 · APDPA

Human oversight of automated decisions

13 jurisdictions · 14 laws & guidance

e.g. C.R.S. § 6-1-1701 et seq. · All Emergency Medicine AI Summit — Statement of Principles v2.0 · Canada ADM Directive

Why this matters

Regulators copy each other. When an obligation theme spreads across dozens of jurisdictions, it stops being a compliance line item and becomes a product requirement: build it once, satisfy many jurisdictions. This index is recomputed from the library itself, so as new laws land in Meridian the convergence picture updates — telling you which controls to standardize globally versus handle per-market.

Deepest enforcement dossiers

Laws with the most documented enforcement actions — where regulator behavior is best evidenced.

Why this matters

Enforcement depth tells you which laws have a track record you can pattern-match against: what triggers an investigation, what fines actually look like, and which controls regulators credit. GDPR's dossier is the deepest because European authorities publish decisions; US federal frameworks accumulate through agency actions and settlements. When a finding in your report cites one of these laws, the recommendation behind it is grounded in documented outcomes, not speculation.

Instrument mix (full Meridian taxonomy)

Instrument types in the library—laws, regulations, standards, treaties, programs.

Why this matters

Type diversity shows whether your foundation is statute-heavy or includes soft-law and voluntary guidance documents. Product teams selling globally use this to calibrate customer-facing claims ('compliant with…') versus internal controls. Compliance leads use it to assign owners: legal for Law/Regulation rows, security/architecture for Standard rows, policy for Guidance/Program rows.

The engine behind the atlas

Numbers above are database reads — here is the machinery keeping it current. Three layers, three numbers: the enforcement rows above are the curated, analyst-graded corpus; live intelligence rows are the raw ingestion cache the curation pipeline draws from; the research reserve is the annex archive of reference material preserved for future synthesis.

219,249

Audited changes (90 days)

Append-only changelog

249

Jurisdictions tracked

Countries, states, cantons

4,714

Live intelligence rows

Ingestion cache

19,720

Research reserve

Annex archive for synthesis

Meridian writes are recorded in an append-only audit log — the same provenance discipline that keeps AI-drafted analysis out of customer reports.

How to use this as a business owner

  1. Start with region + industry together. Your report scope is the overlap of where you operate and what you do. A fintech deploying chatbots in the EU and California inherits both bars—not the global average.
  2. Weight binding instruments higher in roadmap priority. They drive penalties, private litigation, and regulator attention. Standards still matter for enterprise sales and audits.
  3. Watch the horizon count. Pending laws are where proactive teams win—policy and vendor contracts updated before effective dates, not after enforcement headlines.
  4. Enforcement rows ground the abstract. 2,621 curated enforcement actions connect statutory text to what regulators actually pursue—essential for board-level risk conversations and insurance questionnaires.

Browse the full library at /intelligence-library · US state AI safety layers at /us-ai-safety-map · not legal advice

Talk to usWe're here to help