Intelligence library · verified corpus

Meridian Atlas.

The regulatory foundation behind LegisGate™ — where you operate, which instruments bind today, and what is on the horizon for counsel.

381

Curated laws & guidance

17

Regions

Global footprint

189

Industry tags

Sector depth

366

In force now

15

On the horizon

Pending + monitor

11472

Enforcement rows

Real-world actions

Live Meridian snapshot · 100% with official source URLs · updated Aug 22, 2026, 12:05 PM

This atlas reads the LegisGate™ intelligence library — the Meridian™ corpus, the same database that powers obligation reports, deadline alerts, and the rules engine. Each chart answers a question a business owner should ask before deploying AI across markets or industries.

Global coverage by region

Where your regulatory surface area lives — bars are jurisdiction clusters in Meridian.

Jurisdictions with deep standalone coverage (e.g. Singapore, Brazil, Switzerland) are broken out of their parent region; everything else rolls up to the regional cluster.

Why this matters

Your compliance stack is the union of everywhere you have users, employees, data, or contracts—not just headquarters. Dense bars (EU & EEA, US Federal, US States, UK) mean more curated laws, findings, and enforcement context for deployments touching those markets. Thin or empty regions flag expansion risk: entering a market without Meridian depth means slower diligence and more reliance on ad-hoc research.

Industry depth

How many Meridian instruments tag each sector — tall bars mean curated vertical substance.

Why this matters

Sector tags are how LegisGate™ knows whether obligations are tuned for your business model. Healthcare, financial services, and public-sector bars reflect deep templates—not generic privacy copy. If your industry is tall here, reports can cite sector-specific duties and enforcement patterns. If your vertical is in 'Other sectors,' prioritize confirming coverage before you treat the library as exhaustive for that niche.

Binding law vs. standards

Statutory/regulatory instruments compared with guidance documents and standards.

  • Binding instruments: 288
  • Standards & guidance: 92

Why this matters

Binding instruments (laws, regulations, treaties) carry enforcement and penalty exposure—what boards and insurers care about. Standards and guidance shape procurement, customer diligence, and best practice; they matter contractually even when not directly enforceable. A portfolio heavy on binding rows means statutory cliff dates and regulator actions dominate your roadmap; a guidance-heavy mix signals norm-setting and certification pressure.

Status horizon

What is enforceable today versus what is coming—plan budget before effective dates.

  • In Force: 354
  • Partially In Force: 12
  • Pending: 13
  • Monitor: 2

Why this matters

'In force' rows are obligations you can be held to now—policy, controls, and vendor terms should already reflect them. 'Pending' and 'Monitor' rows are your 6–18 month horizon: effective dates, rulemaking, and signed-but-not-yet-operative bills. Operations teams often miss horizon items until a deadline hits; this split tells you where to front-load legal review versus maintain watchlists for board reporting.

Compliance deadline wall

37 dated statutory obligations land in the next 24 months — rows link to their library dossiers.

  1. Aug 23, 2026Law No. 133 of 2011 on personal data protection (Moldova) — prior regime; see also Law 195/2024 commencement trackSuccessor law
  2. Aug 23, 2026Moldova Law 195/2024Effective
  3. Sep 11, 2026Regulation (EU) 2024/2847Reporting obligations
  4. Oct 1, 2026Connecticut Artificial Intelligence Responsibility and Transparency Act — Public Act 26-15Provenance / AEDT framework
  5. Oct 1, 2026Public Act 26-15 — soft twin retired; use connecticut-cart-actEffective
  6. Dec 1, 2026Chile Law 19.628Law 21,719 applicable
  7. Dec 2, 2026Regulation (EU) 2024/1689 (Artificial Intelligence Act)Legacy-system watermarking + new prohibited practices
  8. Dec 9, 2026Directive (EU) 2024/2853Transposition deadline
  9. Dec 10, 2026Australia Privacy ActAPP 1.7 automated decision transparency
  10. Jan 1, 20272026 Wash. Sess. Laws ch. 168 (artificial intelligence companion chatbots)Effective
  11. Jan 1, 2027Artificial Intelligence Safety Measures Act, Pub. Act 104-0538 (Ill. 2026)Effective
  12. Jan 1, 2027C.R.S. § 6-1-1701 et seq.AG rulemaking deadline
  13. Jan 1, 2027C.R.S. § 6-1-1701 et seq.Effective
  14. Jan 1, 2027Cal. Code Regs. tit. 11 (CPPA — automated decisionmaking technology and risk assessments)Pre-Use Notices effective
  15. Jan 1, 2027California AI Transparency Act (BPC Chapter 25)Platform obligations operative
  16. Jan 1, 2027Connecticut Artificial Intelligence Responsibility and Transparency Act — Public Act 26-15AI companions
  17. Jan 1, 2027N.Y. Gen. Bus. Law art. 44-B (§§ 1420–1429) (Responsible AI Safety and Education Act)Effective
  18. Jan 1, 2027O.C.G.A. Tit. 33, Ch. 46 (private review agents) — Act 411 AI adverse-determination limitsEffective
  19. Jan 1, 2027Or. Laws 2026, ch. 85 (artificial intelligence companions)Effective
  20. Jan 1, 2027Rhode Island S 2195Effective
  21. Jan 1, 2027Utah Code Ann. tit. 13, chs. 72b, 72c (Digital Voyeurism Prevention Act; Digital Content Provenance Standards Act)Effective (core)
  22. Jan 17, 2027Albania Law 124/2024Delayed provisions
  23. Feb 1, 20272026 Wash. Sess. Laws ch. 167 (AI disclosures / content provenance) — effective February 1, 2027Effective
  24. May 13, 2027Digital Personal Data Protection Act, 2023Core operational rules
  25. Jul 1, 20272026 Ga. Laws Act 518, amending O.C.G.A. tit. 39, ch. 5 (artificial intelligence companion chatbots)Effective
  26. Jul 1, 2027Cal. Bus. & Prof. Code div. 8, ch. 22.6, §§ 22601 to 22606 (Companion Chatbots) — § 22603 OSP reporting commencement hold to July 1, 2027Annual reporting
  27. Jul 1, 2027Conversational AI Services Act (Iowa Code ch. 554J) — applies July 1, 2027Effective
  28. Jul 1, 2027Conversational Artificial Intelligence Safety Act (109th Leg., Slip Law §§ 12–18) — operative July 1, 2027; Neb. Rev. Stat. chapter numbers not published on slip lawEffective
  29. Jul 1, 2027Idaho Code §§ 48-2101 to 48-2105 (Conversational AI Safety Act)Effective
  30. Aug 2, 2027Regulation (EU) 2024/1689 (Artificial Intelligence Act)AI regulatory sandboxes (member states)
  31. Oct 1, 2027Connecticut Artificial Intelligence Responsibility and Transparency Act — Public Act 26-15AEDT notice operative
  32. Dec 2, 2027Regulation (EU) 2024/1689 (Artificial Intelligence Act)Annex III high-risk standalone systems
  33. Dec 11, 2027Regulation (EU) 2024/2847Full applicability
  34. Jan 1, 2028Artificial Intelligence Safety Measures Act, Pub. Act 104-0538 (Ill. 2026)Framework and audit duties
  35. Jan 1, 2028California AI Transparency Act (BPC Chapter 25)Capture device obligations
  36. Jan 1, 2028Utah Code Ann. tit. 13, chs. 72b, 72c (Digital Voyeurism Prevention Act; Digital Content Provenance Standards Act)Effective (devices)
  37. Aug 2, 2028Regulation (EU) 2024/1689 (Artificial Intelligence Act)Annex I product-embedded high-risk AI

Also published on the LegisGate™ AI Tracker — calendar, legislative movement, and global signals — with RSS and JSON feeds.

Why this matters

Most teams discover effective dates from enforcement headlines — after the budget cycle that should have funded the work. This wall is assembled from the key-date field of laws in Meridian, so it updates as laws are amended or delayed. Note the January 1, 2027 cluster: Colorado SB 26-189 (ADMT), NY RAISE Act, and a wave of state effective dates hit the same day. If you operate multi-state, that is one program deadline, not many.

Enforcement is accelerating — especially on AI

512 documented actions (named party or fine, with a date) out of 11,472 curated enforcement-intelligence rows; 29 are AI-specific.

  • Documented actions
  • AI-specific

Why this matters

These counts are deliberately conservative: a row only registers here when it names a sanctioned party or a fine amount and carries an action date — reference digests and posture notes are excluded. The current-year bar is year-to-date, so read the trajectory, not the final height. The blue bars, actions specifically involving algorithms or automated decisions, compress a decade of typical enforcement ramp into roughly three years. That is the board-deck fact: not 'AI regulation is coming,' but counted, dated actions already compounding.

Global convergence index

Obligation themes ranked by how many distinct jurisdictions now impose them — computed across the full Meridian.

Consent requirements

79 jurisdictions · 88 laws & guidance

e.g. 740 ILCS 14 · Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5 · Act on the Protection of Personal Information (Act No. 57 of 2003)

Cross-border transfer controls

60 jurisdictions · 61 laws & guidance

e.g. Act on the Protection of Personal Information (Act No. 57 of 2003) · Albania Law 124/2024 · Australia Privacy Act

AI transparency & disclosure

48 jurisdictions · 80 laws & guidance

e.g. Regulation (EU) 2024/1689 (Artificial Intelligence Act) · Regulation (EU) 2016/679 (General Data Protection Regulation) · C.R.S. § 6-1-1701 et seq.

Automated decision-making rights

36 jurisdictions · 40 laws & guidance

e.g. Regulation (EU) 2016/679 (General Data Protection Regulation) · C.R.S. § 6-1-1701 et seq. · Cal. Civ. Code § 1798.100 et seq.

Risk & impact assessments

32 jurisdictions · 37 laws & guidance

e.g. Regulation (EU) 2024/1689 (Artificial Intelligence Act) · Regulation (EU) 2016/679 (General Data Protection Regulation) · UK GDPR (assimilated Regulation (EU) 2016/679)

Breach notification duties

29 jurisdictions · 30 laws & guidance

e.g. Health Insurance Portability and Accountability Act — 45 CFR Parts 160 & 164 · Act on the Protection of Personal Information (Act No. 57 of 2003) · Albania Law 124/2024

Vendor & deployer accountability

29 jurisdictions · 36 laws & guidance

e.g. Regulation (EU) 2024/1689 (Artificial Intelligence Act) · C.R.S. § 6-1-1701 et seq. · Tex. Bus. & Comm. Code Ch. 552

Children & minors protections

13 jurisdictions · 14 laws & guidance

e.g. 2026 Ga. Laws Act 518, amending O.C.G.A. tit. 39, ch. 5 (artificial intelligence companion chatbots) · 2026 Wash. Sess. Laws ch. 168 (artificial intelligence companion chatbots) · APDPA

Biometric & facial-recognition limits

8 jurisdictions · 8 laws & guidance

e.g. 740 ILCS 14 · APDPA · FTC Act §5

Human oversight of automated decisions

7 jurisdictions · 8 laws & guidance

e.g. C.R.S. § 6-1-1701 et seq. · Lei nº 13.709, de 14 de agosto de 2018 (Lei Geral de Proteção de Dados Pessoais) · CMS AI Playbook v4 — Auditable Data Lineage and Oversight

Why this matters

Regulators copy each other. When an obligation theme spreads across dozens of jurisdictions, it stops being a compliance line item and becomes a product requirement: build it once, satisfy many jurisdictions. This index is recomputed from the library itself, so as new laws land in Meridian the convergence picture updates — telling you which controls to standardize globally versus handle per-market.

Deepest enforcement dossiers

Laws with the most documented enforcement actions — where regulator behavior is best evidenced.

Why this matters

Enforcement depth tells you which laws have a track record you can pattern-match against: what triggers an investigation, what fines actually look like, and which controls regulators credit. GDPR's dossier is the deepest because European authorities publish decisions; US federal frameworks accumulate through agency actions and settlements. When a finding in your report cites one of these laws, the recommendation behind it is grounded in documented outcomes, not speculation.

Instrument mix (full Meridian taxonomy)

Instrument types in the library—laws, regulations, standards, treaties, programs.

Why this matters

Type diversity shows whether your foundation is statute-heavy or includes soft-law and voluntary guidance documents. Product teams selling globally use this to calibrate customer-facing claims ('compliant with…') versus internal controls. Compliance leads use it to assign owners: legal for Law/Regulation rows, security/architecture for Standard rows, policy for Guidance/Program rows.

The engine behind the atlas

Numbers above are database reads — here is the machinery keeping it current. Three layers, three numbers: the enforcement rows above are the curated, analyst-graded corpus; live intelligence rows are the raw ingestion cache the curation pipeline draws from; the research reserve is the annex archive of reference material preserved for future synthesis.

294,024

Audited changes (90 days)

Append-only changelog

247

Jurisdictions tracked

Countries, states, cantons

4,616

Live intelligence rows

Ingestion cache

18,431

Research reserve

Annex archive for synthesis

Meridian writes are recorded in an append-only audit log — the same provenance discipline that keeps AI-drafted analysis out of customer reports.

How to use this as a business owner

  1. Start with region + industry together. Your report scope is the overlap of where you operate and what you do. A fintech deploying chatbots in the EU and California inherits both bars—not the global average.
  2. Weight binding instruments higher in roadmap priority. They drive penalties, private litigation, and regulator attention. Standards still matter for enterprise sales and audits.
  3. Watch the horizon count. Pending laws are where proactive teams win—policy and vendor contracts updated before effective dates, not after enforcement headlines.
  4. Enforcement rows ground the abstract. 11,472 curated enforcement actions connect statutory text to what regulators actually pursue—essential for board-level risk conversations and insurance questionnaires.

Browse the full library at /intelligence-library · US state AI safety layers at /regulatory-map · not legal advice

Talk to usWe're here to help