The changelog

Q3 2026 (July – September) — quarter in progress

The EU AI Act reached general application — the moment most of the rulebook stopped being homework and started being law — while the UN convened every state at one AI governance table for the first time. This quarter is still live; entries below reflect what is verified so far.

  • 2026-08-02 · EU — EU AI Act general application. The main body of the Act now applies: transparency-tier duties, governance structures, and Member State sandboxes operational. High-risk tiers follow the deferred schedule. So what: If you deferred your AI Act program to “when it applies” — it applies. The remaining runway (Annex III: Dec 2027) is for the high-risk stack only. (Regulation (EU) 2024/1689, Art 113)
  • 2026-07-06 · Global — First UN Global Dialogue on AI Governance convenes in Geneva. The forum created by the Global Digital Compact held its inaugural session — the first standing venue where every UN member state discusses AI governance. So what: Watch this venue for the interoperability agenda: if common reporting baselines emerge anywhere, it will be here. (A/RES/79/325)
  • 2026-08-01 · US states — California AI Transparency Act obligations reported in force. Provenance/disclosure duties for large GenAI providers reported effective this quarter per the research snapshot. So what: GenAI providers with California users: verify current scope and compliance dates directly — this entry is flagged for confirmation.

Q2 2026 (April – June)

The first-mover era ended in Colorado: the pioneering state AI act was repealed and replaced with a disclosure regime before it ever applied — a lesson in how hard duty-based state regulation is to hold. Federal attention narrowed to frontier-model security.

  • 2026-05-01 · US states — Colorado repeals and replaces its AI Act (SB 26-189). After two delays, the duty-based 2024 act was replaced by a disclosure-centered law before its obligations ever took effect. So what: Rebase any Colorado compliance work on the replacement regime — and treat single-state duty frameworks as politically fragile when planning multi-state programs. (Colorado SB 26-189)
  • 2026-06-01 · US federal — EO 14409 on frontier-model cybersecurity. Executive action focused on securing frontier models — weights, infrastructure, adversarial threats. So what: Frontier labs and their cloud providers: expect security-of-weights expectations to harden into contract language. Check current implementing rules. (Executive Order 14409)

Q1 2026 (January – March)

The binding-law era went multi-jurisdictional in one month: Texas, California, and Illinois obligations landed January 1, and Korea’s AI Basic Act — the world’s second horizontal AI statute — took effect three weeks later. The summit series reached the Global South.

  • 2026-01-01 · US states — Texas TRAIGA, California SB 53, and Illinois HB 3773 take effect. Three major state regimes began applying: Texas’s prohibited-uses framework, California’s frontier-transparency law, and Illinois’s AI employment-discrimination amendment. So what: Multi-state deployers now face materially different duty shapes per state — the Rules Wizard exists for exactly this. Hiring AI in Illinois and frontier work touching California got new floors. (TX HB 149; CA SB 53 (2025); IL HB 3773)
  • 2026-01-22 · Asia-Pacific — South Korea’s AI Basic Act takes effect. High-impact AI duties, generative-AI labeling, and national governance structures went live — the second comprehensive horizontal AI law in operation. So what: If Korea is in your market list, classify against “high-impact AI” now; the EU-style compliance artifacts mostly reuse, but the categories differ.
  • 2026-02-19 · Global — AI Impact Summit, New Delhi. The summit series continued in India with development and inclusion at the center; Geneva planned as the next stop (2027). So what: The summit agenda is drifting from frontier safety toward capacity and access — relevant to where voluntary-commitment pressure lands next.
  • 2026-03-01 · US federal — White House legislative framework for AI. The administration circulated a national AI framework push, continuing the preemption agenda over state laws. So what: The state patchwork’s future is genuinely uncertain — build state compliance you can defend, but architect it so a federal floor could replace it. Check current status.

Q4 2025 (October – December)

Brussels blinked on dates, not on substance: the Digital Omnibus proposed deferring the high-risk application calendar while leaving the architecture intact. New York joined the frontier-regulation club, and Washington escalated its preemption posture.

  • 2025-11-19 · EU — Digital Omnibus proposes deferring AI Act high-risk dates. The simplification package moved Annex III high-risk application to 2 Dec 2027 and Annex I to 2 Aug 2028, among wider changes. So what: Re-baseline your high-risk roadmap to the new dates — but do not slow the program: conformity assessment lead times consume the extension quickly. Verify final adopted details. (EU AI Act (as amended); see timeline)
  • 2025-12-01 · US states — New York signs the RAISE Act. Frontier-model safety duties — protocols and incident reporting — enacted at state level, effective early 2027. So what: Frontier developers: the CA SB 53 + NY RAISE pair starts to look like a de facto national baseline. Diary the 2027 effective date.
  • 2025-12-01 · US federal — EO 14365 pushes a national AI framework. Executive action toward federal preemption of state AI laws; litigation and legislative maneuvering followed. So what: Preemption is now a live planning scenario, not a rumor — track it before signing multi-year state-specific compliance tooling. (Executive Order 14365)

Q3 2025 (July – September)

The densest quarter of the era: GPAI obligations and the penalty regime went live in the EU with the Code of Practice as the compliance route, Washington published its deregulatory Action Plan while the Senate killed state-law preemption 99–1, China’s labeling regime took effect, and the UN built its permanent AI machinery.

  • 2025-08-02 · EU — AI Act GPAI rules, governance, and penalties apply. Model-provider duties (Art 53), systemic-risk obligations (Art 55), AI Office supervision, and fines became enforceable. So what: Foundation-model providers serving the EU needed documentation, copyright policy, and training-content summaries from this date; legacy models have until Aug 2027. (EU AI Act Arts 51–56, 99–101)
  • 2025-07-10 · EU — GPAI Code of Practice published. Three chapters — transparency, copyright, safety & security — offering a presumption-style route to Art 53/55 compliance. So what: Signing (or documenting equivalent means) became the practical GPAI compliance decision of the year.
  • 2025-07-23 · US federal — America’s AI Action Plan. 90+ federal actions centered on exports, permitting, and procurement posture. So what: US federal compliance pressure shifted from safety mandates to procurement and export alignment — reallocate attention accordingly.
  • 2025-07-01 · US federal — Senate strips state-AI-law moratorium, 99–1. The proposed 10-year preemption of state AI laws was removed from the tax bill almost unanimously. So what: State law remained the binding U.S. reality — the patchwork is the compliance target, not a transitional nuisance.
  • 2025-09-01 · China — AI content labeling measures take effect. Explicit and implicit (metadata) labels required for AI-generated content across platforms. So what: Anyone serving synthetic content into China needed generation-pipeline marking — and the EU’s Art 50(2) deadline (Dec 2026) rewards building it once, properly.
  • 2025-08-26 · Global — UN establishes the Scientific Panel and Global Dialogue on AI. Resolution A/RES/79/325 created the IPCC-style panel and the universal governance forum. So what: The UN track became institutional rather than declaratory — slower than summits, harder to reverse. (A/RES/79/325)

Q2 2025 (April – June)

A consolidation quarter: the export-control whiplash concluded with the AI Diffusion Rule’s rescission, and the ISO ecosystem filled in the assessment layer around 42001.

  • 2025-05-13 · US federal — AI Diffusion Rule rescinded. The three-tier chip/model-weight export framework issued in January was withdrawn by the new administration ahead of its compliance date. So what: Compute-governance compliance built against the Rule was sunk cost; successor policy arrived piecemeal — a standing lesson in not over-building against unsettled rules.
  • 2025-05-01 · Standards — ISO/IEC 42005 (AI impact assessment) published. The impact-assessment companion to 42001 arrived mid-2025, giving the AIMS ecosystem its assessment methodology. So what: Impact-assessment templates could finally anchor to a standard — and auditors began asking whether yours does. Exact publication date: check ISO records. (ISO/IEC 42005:2025)

Q1 2025 (January – March)

The divergence quarter: Washington revoked its 2023 AI order in week one and pivoted to deregulation, while Brussels switched on the first binding obligations of the AI Act era — the eight prohibitions and the AI-literacy duty — and published the guidelines to interpret them.

  • 2025-01-20 · US federal — EO 14110 revoked; EO 14179 issued days later. The incoming administration revoked the 2023 AI executive order and replaced the posture with “Removing Barriers to American Leadership in AI.” So what: Federal AI-safety mandates evaporated overnight; programs built on EO 14110 hooks needed new anchors (NIST RMF remained the stable one). (EO 14148; EO 14179)
  • 2025-02-02 · EU — AI Act prohibitions and AI-literacy duty apply. The eight Art 5 bans and the Art 4 literacy obligation became enforceable — with the top penalty tier (€35M/7%) behind the prohibitions. So what: Screening portfolios against Art 5 stopped being optional; workplace emotion recognition and social-scoring adjacency became legal emergencies, not roadmap items. (EU AI Act Arts 4, 5)
  • 2025-02-04 · EU — Commission guidelines on prohibited practices and the AI-system definition. Interpretive guidance (C(2025) 884 and companion) drew the fine lines: dark patterns vs persuasion, the definition’s reach over classical software. So what: Boundary cases got citable answers — classification memos written before February deserved a re-read. (C(2025) 884)
  • 2025-02-10 · Global — Paris AI Action Summit. The series pivoted from safety to action and investment; the US and UK declined to sign the declaration. So what: The international consensus era ended visibly — compliance strategies premised on converging global norms needed a rethink.
  • 2025-02-11 · EU — AI Liability Directive withdrawn. The Commission removed the AILD proposal from its work programme. So what: AI liability in the EU now runs through the revised Product Liability Directive and national law — update contract and insurance assumptions.

Q4 2024 (October – December)

Asia moved first on the next generation of horizontal law: Korea passed the AI Basic Act and Brazil’s Senate approved PL 2338 in the same month the U.S. election set up the sharpest policy reversal in AI governance history.

  • 2024-12-26 · Asia-Pacific — South Korea passes the AI Basic Act. The second comprehensive horizontal AI statute, with a January 2026 effective date. So what: A one-year runway started for Korea-market classification and labeling work.
  • 2024-12-10 · Global — Brazil’s Senate approves PL 2338. The EU-inspired risk-based bill cleared the Senate and moved to the Chamber of Deputies. So what: Latin America’s largest market signaled its regulatory direction — worth a watching brief even before enactment.
  • 2024-11-05 · US federal — US election sets up an AI-policy reversal. The incoming administration campaigned against the 2023 AI executive order; revocation followed in January. So what: Q4 was the moment to de-risk programs anchored to EO 14110 — the stable anchors (NIST RMF, state law, contracts) were visible in advance.

Q3 2024 (July – September)

The foundation quarter this changelog starts from: the EU AI Act entered into force and the phased countdown began; NIST shipped its GenAI Profile; and the treaty track opened for signature in Strasbourg while the UN adopted the Global Digital Compact.

  • 2024-08-01 · EU — EU AI Act enters into force. Regulation (EU) 2024/1689 began its phased application: prohibitions Feb 2025, GPAI Aug 2025, general application Aug 2026. So what: Every later deadline in this changelog descends from this date — the day AI governance got a calendar. (Regulation (EU) 2024/1689)
  • 2024-07-26 · US federal — NIST Generative AI Profile (AI 600-1). Twelve GenAI risk categories with suggested actions — the RMF operationalized for the ChatGPT era. So what: GenAI risk assessments got a shared taxonomy; vendor security questionnaires began citing it within months. (NIST AI 600-1)
  • 2024-09-05 · Global — Council of Europe Framework Convention opens for signature. The first binding international AI treaty — human rights, democracy, rule of law — began collecting signatures. So what: A rights-based floor beneath national laws became possible; entry into force awaits ratifications (check current status). (CETS No. 225)
  • 2024-09-22 · Global — UN adopts the Global Digital Compact. Committed the UN to a scientific panel and a global dialogue on AI governance. So what: The institutional UN machinery that materialized in 2025–26 was chartered here.
  • 2024-08-09 · US states — Illinois amends its Human Rights Act for AI (HB 3773). AI-driven employment discrimination becomes a civil-rights violation, effective January 2026. So what: A second architecture for state AI law emerged: amend existing rights law instead of writing an AI act. (IL HB 3773)