Your checklist

Choose one or more answers to each question. Each rule says what to do, who it is for, and who enforces it.

Where do you work or sell?
What do you use AI for?

96 rules in our list. Pick a place and a use to narrow it down.

In force now 70

  1. EUIn force since February 2, 2025

    Do not use AI to read emotions at work or school

    AI systems that infer people’s emotions are banned in workplaces and in schools and universities, except for medical or safety reasons.

    Who
    Anyone who provides or uses such AI in the EU, including employers and schools.
    Enforced by
    National authorities, enforcing since August 2, 2026; fines up to €35 million or 7% of worldwide turnover, whichever is higher (for SMEs, whichever is lower).
    Law
    AI Act, Article 5(1)(f)
  2. EUIn force since August 2, 2026

    Tell people when they are talking to an AI

    If you provide an AI system that talks directly with people, design it so they are told they are interacting with AI, unless that is obvious.

    Who
    Providers of AI systems used in the EU.
    Enforced by
    National authorities, or the EU AI Office for chatbots built on the provider’s own general-purpose AI model or in very large online platforms; fines up to €15 million or 3% of worldwide turnover, whichever is higher (whichever is lower for SMEs and small mid-caps).
    Law
    AI Act, Article 50(1)
  3. EUIn force since August 2, 2026

    Mark AI-generated content so machines can detect it

    Providers of AI that generates audio, images, video or text must mark the output in a machine-readable way as AI-made. Systems already on the market before August 2, 2026 have until December 2, 2026. Tools that only assist standard editing are exempt.

    Who
    Providers of generative AI systems in the EU, including general-purpose AI.
    Enforced by
    National authorities, or the EU AI Office for generative AI built on the provider’s own general-purpose AI model or in very large online platforms; fines up to €15 million or 3% of worldwide turnover, whichever is higher (whichever is lower for SMEs and small mid-caps).
    Law
    AI Act, Article 50(2)
  4. EUIn force since August 2, 2026

    Label deepfakes and AI-written news-style text

    If you use AI to create or alter a deepfake image, audio or video, disclose that it is AI-made or manipulated; for obvious art, satire or fiction a light disclosure is enough. If you use AI to write or alter text published to inform the public on matters of public interest, disclose it, unless it went through human review or editorial control and someone holds editorial responsibility.

    Who
    Businesses and organisations that use AI to make such content in the EU; purely personal, non-professional use is exempt.
    Enforced by
    National authorities; fines up to €15 million or 3% of worldwide turnover, whichever is higher (whichever is lower for SMEs and small mid-caps).
    Law
    AI Act, Article 50(4)
  5. EUIn force since February 2, 2025

    Help your staff understand the AI they use

    Take steps to support the AI literacy of staff and others who operate or use AI for you, suited to their knowledge and to how the AI is used. Since July 27, 2026 you no longer have to guarantee a particular skill level.

    Who
    Providers and deployers of AI systems in the EU, which includes any business using AI at work.
    Enforced by
    National authorities; the AI Act sets no EU-wide fine for this duty, so penalties come from national law.
    Law
    AI Act, Article 4, as replaced by Regulation (EU) 2026/1744
  6. EUIn force since February 2, 2025

    Do not build AI that manipulates or exploits people

    AI that uses subliminal, manipulative or deceptive techniques, or exploits people’s age, disability or social or economic situation, to distort their decisions in a way that causes or is likely to cause significant harm is banned.

    Who
    Anyone who provides or uses such AI in the EU.
    Enforced by
    National authorities, enforcing since August 2, 2026; fines up to €35 million or 7% of worldwide turnover, whichever is higher (for SMEs, whichever is lower).
    Law
    AI Act, Article 5(1)(a) and (b)
  7. EUIn force since February 2, 2025

    Do not use AI social scores to treat people unfairly

    AI that scores people over time on their social behaviour or personal traits is banned when the score leads to unjustified or disproportionate harm, or to harm in a context unrelated to where the data came from. Ordinary performance reviews are usually not social scoring.

    Who
    Anyone who provides or uses such AI in the EU, including private companies.
    Enforced by
    National authorities, enforcing since August 2, 2026; fines up to €35 million or 7% of worldwide turnover, whichever is higher (for SMEs, whichever is lower).
    Law
    AI Act, Article 5(1)(c)
  8. EUIn force since February 2, 2025

    Do not scrape faces from the web to build face recognition

    AI that creates or expands facial recognition databases by untargeted scraping of face images from the internet or CCTV footage is banned.

    Who
    Anyone who provides or uses such AI in the EU.
    Enforced by
    National authorities, enforcing since August 2, 2026; fines up to €35 million or 7% of worldwide turnover, whichever is higher (for SMEs, whichever is lower).
    Law
    AI Act, Article 5(1)(e)
  9. EUIn force since February 2, 2025

    Do not use AI to predict crime from profiling alone

    AI that assesses or predicts the risk that a person will commit a crime based solely on profiling, or on their personality traits, is banned. AI that supports a human assessment already based on objective, verifiable facts is allowed.

    Who
    Anyone who provides or uses such AI in the EU, including private companies.
    Enforced by
    National authorities, enforcing since August 2, 2026; fines up to €35 million or 7% of worldwide turnover, whichever is higher (for SMEs, whichever is lower).
    Law
    AI Act, Article 5(1)(d)
  10. EUIn force since February 2, 2025

    Do not use biometrics to guess race, religion or union ties

    AI that sorts individual people by biometric data, such as face or voice, to infer their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation is banned.

    Who
    Anyone who provides or uses such AI in the EU, including employers.
    Enforced by
    National authorities, enforcing since August 2, 2026; fines up to €35 million or 7% of worldwide turnover, whichever is higher (for SMEs, whichever is lower).
    Law
    AI Act, Article 5(1)(g)
  11. EUIn force since August 2, 2026

    Tell people when you use emotion or biometric AI on them

    If you use AI that recognises emotions or sorts people into categories from biometric data, inform the people exposed to it and handle their data under the GDPR. Emotion recognition at work or school is banned anyway, except for medical or safety reasons.

    Who
    Businesses and organisations that use such systems in the EU.
    Enforced by
    National authorities; fines up to €15 million or 3% of worldwide turnover, whichever is higher (whichever is lower for SMEs and small mid-caps).
    Law
    AI Act, Article 50(3)
  12. EUIn force since August 2, 2025

    Document your AI model and publish a training-data summary

    If you put a general-purpose AI model on the EU market, keep technical documentation and give developers who build on it the information they need. Follow EU copyright law, including publishers’ opt-outs from text and data mining, and publish a summary of the training content. Models on the market before August 2, 2025 have until August 2, 2027.

    Who
    Providers of general-purpose AI models offered in the EU, wherever they are based; providers outside the EU need an EU representative. Open-source models skip the documentation duties unless they pose systemic risk, but must still follow copyright law and publish the summary.
    Enforced by
    European Commission (AI Office), with powers to fine since August 2, 2026: up to €15 million or 3% of worldwide turnover, whichever is higher.
    Law
    AI Act, Articles 53, 54 and 111(3); text and data mining opt-outs under the Copyright Directive (EU) 2019/790, Article 4(3)
  13. EUIn force since August 2, 2025

    Test and report risks of the most powerful AI models

    A general-purpose model is presumed to have systemic risk if it was trained with more than 10²⁵ operations, and the Commission can also designate one. If yours has it, notify the Commission, evaluate and adversarially test the model, and assess and reduce its risks. Report serious incidents to the AI Office and keep strong cybersecurity.

    Who
    Providers of general-purpose AI models with systemic risk offered in the EU.
    Enforced by
    European Commission (AI Office), with powers to fine since August 2, 2026: up to €15 million or 3% of worldwide turnover, whichever is higher.
    Law
    AI Act, Articles 51, 52 and 55
  14. EUIn force since May 25, 2018

    Do not let AI alone make big decisions about people

    People have the right not to be subject to decisions made solely by automated processing, including profiling, with legal or similarly significant effects, such as automatically rejecting a job application. Such decisions are allowed only when needed for a contract, authorised by law or with explicit consent, and then people get human intervention, a way to contest and meaningful information about the logic.

    Who
    Any organisation processing personal data in the EU, or of people in the EU, including employers and schools.
    Enforced by
    National data protection authorities; fines up to €20 million or 4% of worldwide turnover, whichever is higher.
    Law
    GDPR (Regulation (EU) 2016/679), Article 22, with Articles 13 to 15
  15. EUIn force since August 2, 2026

    Explain decisions made with high-risk AI when asked

    Some AI counts as high-risk, such as AI for hiring, managing staff, education, credit or essential services. If a decision based on it seriously affects someone, they can ask you to explain the AI’s role and the main reasons for the decision, and you must answer clearly. The AI Act’s other duties for this AI start on December 2, 2027.

    Who
    Businesses and organisations in the EU that use such AI to decide about people. It applies where other EU law, such as the GDPR, does not already give this right.
    Enforced by
    National authorities; the AI Act sets no EU-wide fine for this right, so penalties come from national law (in Germany, up to €50,000).
    Law
    AI Act, Article 86, with Annex III
  16. EUIn force since February 17, 2024

    Explain how your platform’s recommendations work

    If your online platform recommends content, explain in your terms, in plain language, the main factors your recommender systems use and how users can change them. Very large platforms and search engines must also offer at least one feed option not based on profiling.

    Who
    Online platforms serving people in the EU, except micro and small companies; the extra option applies to services with more than 45 million monthly users in the EU.
    Enforced by
    National Digital Services Coordinators, or the European Commission for very large platforms; fines up to 6% of worldwide turnover.
    Law
    Digital Services Act (Regulation (EU) 2022/2065), Articles 27 and 38
  17. GermanyIn force since August 2, 2026

    Explain high-risk AI decisions, or Germany can fine you

    Germany backs the EU right to an explanation with its own fine. If a decision based on high-risk AI, for example in hiring, staff management, education or credit, seriously affects someone and they ask, explain the AI’s role and the main reasons. Failing to do so can cost up to €50,000. The EU has moved most other high-risk duties to December 2, 2027.

    Who
    Businesses and other private organisations using high-risk AI in Germany, such as employers, private schools and lenders. Public bodies cannot be fined.
    Enforced by
    Federal Network Agency (Bundesnetzagentur) in most cases, BaFin for finance and state authorities for the media; fines up to €50,000.
    Law
    KI-MIG (KI-Marktüberwachungs-und-Innovationsförderungs-Gesetz), sections 15(2), 15(3) and 17, with AI Act Article 86
  18. GermanyIn force since June 18, 2021

    Tell the works council early about planned AI

    If your workplace has a works council (Betriebsrat), inform it in good time, with the documents it needs, when you plan work processes that use AI. Discuss the effects on staff early enough that its suggestions can still change the plan.

    Who
    Private employers in Germany that have a works council.
    Enforced by
    Labour courts; fines up to €10,000 for information that is missing, wrong, incomplete or late (section 121). Obstructing the works council is a crime (section 119).
    Law
    Works Constitution Act (Betriebsverfassungsgesetz), section 90(1) no. 3 and (2), as amended in 2021
  19. GermanyIn force since June 18, 2021

    Let the works council bring in an AI expert

    When your works council has to assess the introduction or use of AI, the law treats calling in an outside expert as necessary, so you cannot refuse on the ground that one is not needed. You still agree on the details, and you can agree on a standing AI expert.

    Who
    Private employers in Germany that have a works council.
    Enforced by
    Labour courts. Obstructing the works council is a crime (section 119).
    Law
    Works Constitution Act, section 80(3), as amended in 2021
  20. GermanyIn force since June 18, 2021

    Get works council consent for AI-made selection rules

    General rules for choosing whom to hire, transfer, regrade or dismiss need your works council’s consent, also when AI is used to draw them up. In businesses with more than 500 employees, the works council can demand such rules. If you cannot agree, a conciliation board decides.

    Who
    Private employers in Germany that have a works council.
    Enforced by
    A conciliation board (Einigungsstelle) settles disputes, and labour courts enforce.
    Law
    Works Constitution Act, section 95(1), (2) and (2a), as amended in 2021
  21. GermanyGeneral lawIn force since January 19, 1972

    Agree with the works council before AI that tracks staff

    You need your works council’s agreement before you introduce or use technical systems designed to monitor how employees behave or perform, which includes AI tools that log or analyse staff activity. If you cannot agree, a conciliation board decides.

    Who
    Private employers in Germany that have a works council.
    Enforced by
    A conciliation board settles disputes, and labour courts can stop a system introduced without agreement. Obstructing the works council is a crime (section 119).
    Law
    Works Constitution Act, section 87(1) no. 6 and (2)
  22. GermanyIn force since November 7, 2020

    Label automated bot posts on social networks

    If you run a social media account that looks like a person but posts automatically through software, clearly mark each automated post as sent by a program. Social networks must also take care that such posts are labelled.

    Who
    Anyone offering content on social networks in Germany, such as businesses, publishers and campaigns, and the networks themselves.
    Enforced by
    State media authorities (Landesmedienanstalten); fines up to €500,000 for unlabelled bot posts.
    Law
    Interstate Media Treaty (Medienstaatsvertrag), sections 18(3) and 93(4)
  23. GermanyIn force since November 7, 2020

    Explain how your algorithm picks and ranks content

    If you run a search engine, social network, news aggregator or similar service, publish in plain language the main criteria for selecting and ranking content and how your algorithms work, easy to find and always available.

    Who
    Services that gather and present others’ content (media intermediaries) and reach at least 1 million users a month in Germany. Services focused on goods and services are exempt.
    Enforced by
    State media authorities; fines up to €500,000.
    Law
    Interstate Media Treaty, sections 91 and 93(1)
  24. FranceIn force since June 11, 2023

    Label AI faces or bodies in paid posts “Images virtuelles”

    If you are paid to promote something online and your post includes an AI-made image of a face or body, add the words “Images virtuelles”, clear and easy to read on every format. Retouched faces or bodies need “Images retouchées” instead.

    Who
    Commercial influencers: people or companies paid to promote goods, services or causes online to a French audience, including those based abroad.
    Enforced by
    Criminal courts; up to one year in prison and a €4,500 fine.
    Law
    Law no. 2023-451 of June 9, 2023 on commercial influence, article 5, as amended in 2024
  25. FranceIn force since May 23, 2024

    Get consent or clearly label AI fakes of real people

    Do not publish or share AI-made images, video or audio that reproduce a real person’s image or words without their consent, unless it is obvious, or clearly stated, that the content was made by AI.

    Who
    Anyone in France, including businesses, publishers and influencers.
    Enforced by
    Criminal courts; up to one year in prison and €15,000, or two years and €45,000 if shared online.
    Law
    Criminal Code (Code pénal), article 226-8, as amended by Law no. 2024-449 of May 21, 2024 (SREN)
  26. FranceIn force since May 23, 2024

    Never share sexual deepfakes of a person without consent

    Sharing AI-made sexual images, video or audio that reproduce a real person’s image or voice without their consent is a crime, even if it is labelled as fake.

    Who
    Anyone in France.
    Enforced by
    Criminal courts; up to two years in prison and €60,000, or three years and €75,000 if shared online.
    Law
    Criminal Code, article 226-8-1, added by Law no. 2024-449 of May 21, 2024 (SREN)
  27. FranceGeneral lawIn force since January 1, 2018

    Consult the works council before rolling out AI at work

    Inform and consult your works council (CSE) before introducing new technologies such as AI tools, and on changes that affect staff numbers, organisation or working conditions.

    Who
    Employers in France with at least 50 employees and a works council (comité social et économique).
    Enforced by
    Obstructing the works council is a crime, with a fine of up to €7,500 (article L2317-1).
    Law
    Labour Code (Code du travail), article L2312-8
  28. FranceGeneral lawIn force since January 1, 2018

    Tell the works council before AI hiring or tracking tools

    Inform your works council before you use recruitment-assistance methods or automated staff-management systems, and before changing them. Inform and consult it before deciding to deploy any tool that can monitor employees’ activity.

    Who
    Employers in France with at least 50 employees and a works council.
    Enforced by
    Obstructing the works council is a crime, with a fine of up to €7,500 (article L2317-1).
    Law
    Labour Code, article L2312-38
  29. FranceGeneral lawIn force since May 1, 2008

    Tell job candidates before using AI to assess them

    Before using any recruitment method or technique on candidates, including AI tools, tell them which ones you will use. Methods must be relevant to the job, results stay confidential, and no data may be collected through a tool they were not told about.

    Who
    All employers and recruiters in France, of any size.
    Enforced by
    These articles set no penalty of their own.
    Law
    Labour Code, articles L1221-8 and L1221-9
  30. FranceGeneral lawIn force since May 1, 2008

    Tell staff before any AI tool collects data about them

    No information about an individual employee may be collected by a device or tool they were not told about beforehand, including AI monitoring and analytics tools.

    Who
    All employers in France.
    Enforced by
    This article sets no penalty of its own.
    Law
    Labour Code, article L1222-4
  31. FranceIn force since June 1, 2019

    Explain your automated decision rules when asked

    A decision with legal or similarly significant effects on someone may rest solely on automated processing only in the GDPR’s contract and explicit-consent cases. Then, if the person asks, you must tell them the rules that define the processing and its main characteristics, except secrets protected by law.

    Who
    Any organisation in France that takes solely automated decisions about people. Public bodies have stricter duties.
    Enforced by
    The data protection authority (CNIL); fines up to €20 million or 4% of worldwide turnover, whichever is higher.
    Law
    Data Protection Act (Loi Informatique et Libertés, law no. 78-17), article 47
  32. HungaryGeneral lawIn force since November 16, 2013

    Never make or share fake recordings to smear someone

    It is a crime in Hungary to make, or make available to others, a false or altered audio or image recording of someone in order to damage their honour. This covers AI deepfakes and cloned voices.

    Who
    Anyone in Hungary; a case starts only if the victim asks for it.
    Enforced by
    Police, prosecutors and criminal courts; up to one year in prison for making such a recording, two years for making it available, or three years if it reaches a large audience or causes significant harm.
    Law
    Criminal Code (2012. évi C. törvény), sections 226/A and 226/B
  33. US federalIn force since May 19, 2026

    Remove reported intimate deepfakes within 48 hours

    Give people a clear, plain-language way to report intimate images of themselves posted without consent, including AI-made fakes. Remove a valid reported image within 48 hours, and make reasonable efforts to remove known identical copies.

    Who
    Public websites, apps and online services that mainly host content from users, with no size threshold. Broadband providers and email are excluded.
    Enforced by
    Federal Trade Commission; civil penalties of up to $53,088 per violation. Removals made in good faith are protected.
    Law
    TAKE IT DOWN Act (Public Law 119-12), section 3
  34. US federalIn force since May 19, 2025

    Never post AI-made intimate images of real people

    It is a federal crime to knowingly publish online an intimate image of an identifiable real person without their consent, including realistic fakes made with AI.

    Who
    Anyone, people and businesses alike.
    Enforced by
    Department of Justice; fines and up to two years in prison, or three years if the person shown is a minor.
    Law
    TAKE IT DOWN Act (Public Law 119-12), section 2, 47 U.S.C. 223(h)
  35. US federalGeneral lawIn force since October 21, 2024

    Do not post or buy fake reviews, including AI-written ones

    Do not write, create, sell or buy reviews or testimonials that falsely suggest the reviewer exists, used the product or had the experience described. The FTC says this covers AI-generated fake reviews.

    Who
    Businesses selling to US consumers.
    Enforced by
    Federal Trade Commission; civil penalties of up to $53,088 per knowing violation.
    Law
    FTC Rule on the Use of Consumer Reviews and Testimonials, 16 CFR part 465
  36. US federalIn force since February 8, 2024

    Get consent before calling people with an AI voice

    Calls that use AI-generated or cloned voices count as artificial-voice calls under the federal robocall law, so they need the called person’s prior express consent, unless it is an emergency or an exemption applies. The message must also identify the caller.

    Who
    Anyone placing calls to people in the US.
    Enforced by
    Federal Communications Commission, state attorneys general and private lawsuits; $500 per call, or up to $1,500 if willful.
    Law
    FCC Declaratory Ruling FCC 24-17, applying the Telephone Consumer Protection Act, 47 U.S.C. 227(b)
  37. CaliforniaIn force since August 2, 2026

    Embed hidden AI labels and offer a free checking tool

    If you make a generative AI system that people in California can use, add hidden provenance data to the images, video and audio it creates or alters, where technically feasible. Also offer a free disclosure verification tool, your own or a compliant third-party one. Since September 30, 2026 this applies however many users you have; AI built mainly as assistive technology is exempt until 2029.

    Who
    Makers of generative AI systems publicly available in California.
    Enforced by
    Attorney General, city attorneys or county counsel; $5,000 per violation, with each day a separate violation. Falsely claiming the assistive-technology exemption costs $50,000 per violation.
    Law
    California AI Transparency Act, Business and Professions Code sections 22757 to 22757.6 (SB 942, Chapter 291, Statutes of 2024; amended by AB 853, Chapter 674, Statutes of 2025, and SB 1000, Chapter 861, Statutes of 2026)
  38. CaliforniaIn force since January 1, 2026

    Companion chatbots must disclose AI and handle crises

    Tell users the chatbot is AI, not human, if they could be misled; keep and publish a suicide and self-harm protocol that refers users to crisis services; and warn that companion chatbots may not suit some minors. Until December 31, 2026, also remind known minors every three hours that it is AI and to take a break, and block sexual content for them. Yearly reports start July 1, 2027.

    Who
    Operators of companion chatbot platforms available in California.
    Enforced by
    People harmed can sue for the greater of their damages or $1,000 per violation.
    Law
    SB 243 (Chapter 677, Statutes of 2025), Business and Professions Code sections 22601 to 22606; amended by SB 1119 (Chapter 190, Statutes of 2026) from January 1, 2027
  39. CaliforniaIn force since July 1, 2019

    Do not let a bot pretend to be human to sell or sway votes

    If you use a bot online to push a sale or influence a vote in California, it must clearly disclose that it is a bot.

    Who
    Anyone using bots to talk with people in California online.
    Enforced by
    This section names no penalty or enforcer.
    Law
    Business and Professions Code sections 17940 to 17943 (SB 1001, Chapter 892, Statutes of 2018)
  40. CaliforniaIn force since January 1, 2026

    Publish frontier AI safety plans and report incidents

    If you train frontier AI models, publish a transparency report when you deploy a new or substantially changed one. Report critical safety incidents to the state’s Office of Emergency Services within 15 days, or within 24 hours to the right authority if lives are at risk. Developers with over $500 million in yearly revenue must also publish and follow a frontier AI framework and run an anonymous internal reporting channel.

    Who
    Frontier developers: anyone who has trained a model using more than 10²⁶ operations. None may gag or punish staff who report catastrophic risks.
    Enforced by
    Attorney General; civil penalties of up to $1 million per violation, scaled to its severity.
    Law
    Transparency in Frontier Artificial Intelligence Act, SB 53 (Chapter 138, Statutes of 2025), Business and Professions Code sections 22757.10 to 22757.16 and Labor Code sections 1107 to 1107.2
  41. CaliforniaIn force since January 1, 2025

    Spell out digital replica uses in performer contracts

    A contract term can let a digital replica of a person’s voice or likeness replace work they would have done in person. Such a term is unenforceable if it lacks a reasonably specific description of the uses and the person had no lawyer or union negotiating for them.

    Who
    Anyone contracting with a person in California for personal or professional services, such as actors, voice artists and creators. It covers new performances fixed from January 1, 2025.
    Enforced by
    No regulator or fine; such a term cannot be enforced.
    Law
    AB 2602 (Chapter 259, Statutes of 2024), Labor Code section 927
  42. CaliforniaIn force since January 1, 2026

    Post a summary of the data used to train your AI

    Before each public release of a generative AI system, or a substantial change to it, post documentation on your website about its training data. It must include a high-level summary of the datasets: their sources or owners, whether they include copyrighted or personal information, and whether they were bought or licensed.

    Who
    Developers of generative AI systems or services released since January 1, 2022 and publicly available to Californians, including anyone who substantially modifies one. AI used only for security, aircraft operation or national security is exempt.
    Enforced by
    The law names no penalty or enforcer. A federal court refused to block it in March 2026; xAI’s appeal is set for argument on November 18, 2026.
    Law
    AB 2013 (Chapter 817, Statutes of 2024), Civil Code sections 3110 and 3111, amended by AB 1170 (Chapter 67, Statutes of 2025)
  43. CaliforniaIn force since January 1, 2026

    Do not make or help spread sexual deepfakes

    Do not create or share sexually explicit deepfakes of a real person when you know, or should know, that they did not consent or were a minor, and do not knowingly help others do it. A service mainly for making sexual deepfakes is presumed to know there was no consent. Companies that keep such a service running are presumed liable if they do not stop within 30 days of notice.

    Who
    Anyone, including people and businesses that run or serve deepfake services.
    Enforced by
    The person shown can sue for profits, actual damages or $1,500 to $50,000 per work, up to $250,000 with malice, plus punitive damages and fees. Public prosecutors can seek $25,000 per violation, or $50,000 with malice.
    Law
    AB 621 (Chapter 673, Statutes of 2025), Civil Code section 1708.86
  44. CaliforniaIn force since January 1, 2025

    Let users report sexual deepfakes and act within 30 days

    Let California account holders report sexually explicit images or videos of themselves that were made or altered digitally without their consent. Confirm each report within 48 hours, update within 7 days, block the material while you check, and decide within 30 days, or 60 days if the delay is beyond your control. Remove it at once if the report holds up.

    Who
    Social media platforms with users in California; end-to-end encrypted messaging services and charities are excluded.
    Enforced by
    The law names no penalty or enforcer.
    Law
    SB 981 (Chapter 292, Statutes of 2024), Business and Professions Code sections 22670 and 22671
  45. CaliforniaIn force since January 1, 2025

    Say when a robocall uses an artificial voice

    Before an automatic dialing device plays a prerecorded message, a live, natural voice must state the nature of the call and the caller’s name, address and phone number. It must ask whether the person consents to hear the message, and say if the message uses an artificial voice, such as an AI-generated one.

    Who
    Anyone placing calls with automatic dialing-announcing devices to people in California.
    Enforced by
    California Public Utilities Commission; fines of up to $500 per violation, or disconnection of the line.
    Law
    AB 2905 (Chapter 316, Statutes of 2024), Public Utilities Code section 2874
  46. CaliforniaIn force since January 1, 2025

    Get estate consent for AI replicas of dead celebrities

    Do not use a digital replica of a deceased personality’s voice or likeness in a film, video or sound recording without consent from whoever holds their rights. News, sports, criticism, satire, parody, documentaries, biographies and fleeting uses are excepted.

    Who
    Studios, labels, advertisers, AI companies and anyone else using such a replica in California.
    Enforced by
    No regulator; the rights holders can sue for $10,000 or their actual damages, whichever is greater.
    Law
    AB 1836 (Chapter 258, Statutes of 2024), Civil Code section 3344.1
  47. CaliforniaIn force since October 1, 2025

    Do not let AI tools discriminate; keep their data 4 years

    Using an automated decision system that discriminates against job applicants or workers is unlawful, even when a vendor runs it for you. Keep the system’s data with your employment records for four years. Evidence of anti-bias testing can count for or against you.

    Who
    Employers covered by California’s Fair Employment and Housing Act, usually those with 5 or more employees, plus employment agencies and unions.
    Enforced by
    Civil Rights Department complaints and lawsuits under the Fair Employment and Housing Act; damages rather than a fixed fine.
    Law
    Civil Rights Council regulations, California Code of Regulations title 2, sections 11008.1, 11009(f) and 11013(c)
  48. CaliforniaIn force since January 1, 2026

    Do a risk assessment before using AI to judge people

    Do and document a privacy risk assessment, and review it at least every three years, before you use automated decision-making for significant decisions such as jobs, loans, housing, education or health care. The same applies to automated tools that infer workers’, students’ or applicants’ performance, health, behaviour or location from systematic observation, and to training such tools or face recognition on personal data. Uses that began before 2026 need one by December 31, 2027.

    Who
    Businesses covered by the California Consumer Privacy Act.
    Enforced by
    California Privacy Protection Agency or the Attorney General: up to $2,663 per violation, or $7,988 if intentional (2025 amounts).
    Law
    CCPA regulations, California Code of Regulations title 11, sections 7150, 7155 and 7157
  49. ColoradoIn force since July 1, 2023

    Let people opt out of profiling for big decisions

    Let people opt out of profiling that feeds decisions with legal or similarly significant effects, such as on loans, housing, insurance, education or health care. If a human is meaningfully involved you may refuse, but you must then explain the decision, the data used and the logic in plain language. Assess the risks in writing before such profiling.

    Who
    Businesses serving Colorado residents that handle the data of more than 100,000 of them a year, or of 25,000 or more while earning money or discounts from selling personal data.
    Enforced by
    Attorney General and district attorneys.
    Law
    Colorado Privacy Act, C.R.S. 6-1-1306(1)(a) and 6-1-1309, with the Attorney General’s rules (4 CCR 904-3, rule 9.04)
  50. ConnecticutIn force since October 1, 2026

    Say whether AI played a part in mass layoffs

    When you file a federal mass-layoff (WARN) notice, also tell the Connecticut Labor Department whether the layoffs are related to your use of AI or another technological change.

    Who
    Employers that must file a federal WARN notice, usually those with 100 or more workers.
    Enforced by
    Connecticut Labor Department, in the form the Labor Commissioner sets. The act sets no penalty.
    Law
    Public Act 26-15, section 26
  51. ConnecticutIn force since October 1, 2026

    An AI tool is no excuse for discrimination

    If an automated tool helps make a job decision, its use is no defence against a discrimination complaint. Evidence of anti-bias testing can be taken into account.

    Who
    Employers in Connecticut.
    Enforced by
    Commission on Human Rights and Opportunities and the courts.
    Law
    Public Act 26-15, sections 13 and 14 (amending C.G.S. 46a-60(b)(1) and 46a-81c)
  52. ConnecticutIn force since October 1, 2026

    Do not punish staff who warn about catastrophic AI risks

    Do not adopt or enforce any policy or contract that lets you punish staff for reporting a specific and substantial danger from catastrophic AI risk, or for whistleblowing to authorities, and tell your risk staff their rights. Developers with over $500 million in yearly revenue need an anonymous internal reporting channel by January 1, 2027.

    Who
    Frontier AI developers doing business in Connecticut: those training models with more than 10²⁶ operations.
    Enforced by
    Attorney General; civil penalty of up to $1,000 per violation.
    Law
    Public Act 26-15, section 2
  53. ConnecticutIn force since October 1, 2026

    Spell out the terms before charging for an AI subscription

    Before you start or renew an AI subscription, give the customer a written notice of the key terms, including usage limits and any right to cut features, and get their written acceptance.

    Who
    Anyone selling AI subscriptions to Connecticut residents.
    Enforced by
    Attorney General, as an unfair trade practice; customers cannot sue under this section.
    Law
    Public Act 26-15, section 1
  54. ConnecticutIn force since October 1, 2026

    Add provenance data to AI images, audio and video

    Where commercially and technically reasonable, embed provenance data in images, audio and video your AI creates or materially alters, and make it hard to remove, for example with the C2PA standard.

    Who
    Makers of generative AI systems for images, audio or video that the public can use for personal purposes and that have more than one million users a month. Business-to-business tools, games, and pure upscaling or compression tools are excluded.
    Enforced by
    Attorney General, as an unfair trade practice; no private lawsuits.
    Law
    Public Act 26-15, section 15
  55. ConnecticutIn force since October 1, 2026

    Label prices raised by algorithms using personal data

    If an automated process uses a customer’s personal data to set a price shown online, and the price is not a discount, show the notice “THIS PRICE WAS INCREASED BY A PRICE SETTING DEVICE USING YOUR PERSONAL DATA”. Retailers and delivery apps may not set personal prices from tracking data at all, except for cost differences, supply and demand, and open discount or loyalty schemes.

    Who
    Businesses selling to people in Connecticut, for the label; retailers and delivery apps, for the ban. Insurers, banks and other financial institutions are excluded.
    Enforced by
    Attorney General only, as an unfair trade practice; no private lawsuits.
    Law
    Public Act 26-64, section 11
  56. ConnecticutIn force since October 1, 2026

    Remove intimate deepfakes in 48 hours, or face state fines

    Set up a written process, explained in a plain-language notice on your platform, for victims or the Attorney General to report synthetic intimate images. Remove a valid report within 48 hours and make reasonable efforts to remove copies.

    Who
    Public websites and apps that mainly host content shared by users, as defined in the federal TAKE IT DOWN Act.
    Enforced by
    Attorney General, in court; civil penalties of up to $25,000 a day for each person harmed.
    Law
    Public Act 26-55, section 2
  57. ConnecticutIn force since July 1, 2026

    Let people challenge automated profiling decisions

    Let people opt out of profiling used for automated decisions with legal or similarly significant effects. If you made such a decision, where feasible let them question the result, tell them the reason and let them review their data; for housing decisions, let them correct the data and get the decision re-evaluated. Do an impact assessment for such profiling.

    Who
    Businesses covered by the Connecticut Data Privacy Act: those serving people in Connecticut that handle the data of at least 35,000 consumers, process sensitive data, or sell personal data. It protects people as consumers, not as workers.
    Enforced by
    Attorney General only, as an unfair trade practice; no private lawsuits.
    Law
    Connecticut Data Privacy Act, C.G.S. 42-518 and 42-522, as amended by Public Act 25-113 (impact assessments for processing from August 1, 2026)
  58. ConnecticutIn force since July 1, 2026

    Say in your privacy notice if you train AI on personal data

    Your privacy notice must state whether you collect, use or sell personal data to train large language models.

    Who
    Businesses covered by the Connecticut Data Privacy Act: those serving people in Connecticut that handle the data of at least 35,000 consumers, process sensitive data, or sell personal data. It protects people as consumers, not as workers.
    Enforced by
    Attorney General only, as an unfair trade practice; no private lawsuits.
    Law
    Connecticut Data Privacy Act, C.G.S. 42-520, as amended by Public Act 25-113
  59. ConnecticutIn force since October 1, 2026

    Post signs if you use face recognition on your premises

    If you use face recognition on your premises against security threats, fraud or crime, match faces only against your own database. Post clearly legible signs at each public entrance saying it is in use, with a link or QR code to your face recognition policy, which must give the Attorney General’s contact details.

    Who
    Businesses covered by the Connecticut Data Privacy Act: those serving people in Connecticut that handle the data of at least 35,000 consumers, process sensitive data, or sell personal data. It protects people as consumers, not as workers.
    Enforced by
    Attorney General only, as an unfair trade practice; no private lawsuits.
    Law
    Public Act 26-64, section 16 (C.G.S. 42-524)
  60. IllinoisIn force since January 1, 2026

    Do not let AI discriminate at work, and say you use it

    Do not use AI in recruiting, hiring, promotion, training, discipline, firing or other job decisions in a way that leads to discrimination against protected groups, even if unintended. Do not use ZIP codes as a stand-in for them, and tell employees when you use AI for these decisions.

    Who
    Employers with at least one employee in Illinois on each working day of 20 or more weeks this year or last. Draft rules on the notice were withdrawn in June 2026, so its exact form is not yet set.
    Enforced by
    Illinois Department of Human Rights: a worker or applicant can file a charge within 2 years, and the case then goes to the Human Rights Commission or a court. Remedies include damages, hiring or reinstatement, back pay and legal fees.
    Law
    Illinois Human Rights Act, 775 ILCS 5/2-102(L), added by Public Act 103-0804 (HB 3773)
  61. IllinoisIn force since January 1, 2020

    Get consent before AI analyses video job interviews

    Before AI analyses an applicant’s recorded video interview, tell them AI may be used and get their consent. If you rely only on AI to decide who gets an in-person interview, report the race and ethnicity of the people interviewed and hired to the state every year.

    Who
    Employers that use AI to analyse video interviews for jobs based in Illinois.
    Enforced by
    The Department of Commerce and Economic Opportunity collects the yearly reports; the official summaries name no fine.
    Law
    Artificial Intelligence Video Interview Act, 820 ILCS 42 (HB 2557 of 2019; yearly reports added by HB 53 of 2021, from January 1, 2022)
  62. IllinoisIn force since August 9, 2024

    Describe AI replica uses clearly in performer contracts

    A contract clause that allows a digital replica of a person’s voice or likeness is invalid if it does not clearly describe the intended uses and the person had no lawyer or union representing them.

    Who
    Anyone contracting with performers or other individuals in Illinois for their voice or likeness.
    Enforced by
    No regulator or fine; such a clause cannot be enforced.
    Law
    Digital Voice and Likeness Protection Act (HB 4762 of 2024)
  63. New YorkIn force since November 5, 2025

    Add crisis help and “not human” notices to AI companions

    If your chatbot acts as an ongoing AI companion, it must detect signs of suicidal thoughts or self-harm and refer users to crisis services such as the 988 line. It must also tell users clearly that they are not talking to a human, at the start of a conversation and at least every three hours while it continues.

    Who
    Businesses that offer AI companions to people in New York for personal use: AI that remembers past chats, asks unprompted emotional questions and keeps up personal conversations. Customer-service, productivity and research tools are excluded.
    Enforced by
    Attorney General; civil penalties of up to $15,000 a day, paid into a suicide prevention fund.
    Law
    General Business Law, article 47 (sections 1700 to 1704), added by Chapter 58 of 2025, Part U
  64. New YorkIn force since July 8, 2025

    Label prices set by an algorithm using personal data

    If an algorithm uses a customer’s personal data to set the price you offer them, show this notice clearly next to the price: “THIS PRICE WAS SET BY AN ALGORITHM USING YOUR PERSONAL DATA”.

    Who
    Businesses offering personalised algorithmic prices to New York consumers. Insurers, financial institutions under the federal Gramm-Leach-Bliley Act, and lower prices for existing subscriptions are excluded.
    Enforced by
    Attorney General, enforcing since November 10, 2025: a cease-and-desist letter first, then court fines of up to $1,000 per violation. A federal court upheld the law in October 2025, and an appeal is pending.
    Law
    Algorithmic Pricing Disclosure Act, General Business Law section 349-a (Chapter 58 of 2025, Part X)
  65. New YorkIn force since June 9, 2026

    Disclose AI-generated performers in your ads

    If you make an ad and know it includes a synthetic performer, a realistic human made with AI or other software who is not a real, recognisable person, say so clearly in the ad.

    Who
    Anyone who produces or creates commercial ads. Audio-only ads, ads for films, TV shows and video games, and AI used only to translate a real performer’s speech are excluded; outlets that only publish ads are exempt.
    Enforced by
    $1,000 for a first violation and $5,000 for each later one; the law does not name the enforcer.
    Law
    General Business Law section 396-b, as amended by Chapter 617 of 2025
  66. New YorkIn force since December 11, 2025

    Get consent before using a dead performer’s AI replica

    Before you use a digital replica, a realistic computer-made voice or likeness, of a deceased performer in an audiovisual work, a sound recording or a live musical performance, get consent from whoever holds their publicity rights, usually the heirs. A disclaimer is no longer enough.

    Who
    Anyone using a replica of a performer who lived in New York when they died, on or after May 29, 2021, such as studios, labels, advertisers and AI companies.
    Enforced by
    No regulator; the rights holders can sue for $2,000 or their damages, whichever is greater, plus the profits made from the use.
    Law
    Civil Rights Law section 50-f, as amended by Chapter 616 of 2025
  67. New YorkIn force since January 1, 2025

    Spell out digital replica terms in performer contracts

    A contract clause can let you use a digital replica of a person’s voice or likeness instead of work they would have done in person. Such a clause is void if it does not describe the intended uses reasonably specifically, unless the person had a lawyer or a union contract covering such replicas.

    Who
    Any business contracting with a person for personal or professional services in New York, such as actors, voice artists and creators. It applies to contracts made or changed from January 1, 2025.
    Enforced by
    No regulator or fine; such a clause cannot be enforced.
    Law
    General Obligations Law section 5-302
  68. NYCIn force since July 5, 2023

    Audit AI hiring tools for bias and tell candidates

    Before you use an automated tool to screen job candidates or employees for promotion, have an independent bias audit done within the past year and post a summary of the results on your website. Tell candidates and employees who live in New York City at least 10 business days before use, including what the tool will assess and how to ask for an alternative process or accommodation.

    Who
    Employers and employment agencies using such tools for jobs in New York City.
    Enforced by
    Department of Consumer and Worker Protection; up to $500 for a first violation and $500 to $1,500 for each later one. Each day of non-compliant use counts as a separate violation.
    Law
    Local Law 144 of 2021 (Administrative Code 20-870 to 20-874)

Coming up 26

  1. EUStarts December 2, 2026

    Do not offer or use AI that makes sexual deepfakes

    AI systems that create or alter realistic sexual or intimate images, video or audio of an identifiable person without their explicit consent, or child sexual abuse material, are banned. Providers are covered when this is the intended purpose or a foreseeable result their safeguards do not reliably prevent; users are covered when they use AI for this.

    Who
    Anyone who provides or uses such AI systems in the EU.
    Enforced by
    National authorities, or the EU AI Office for AI built on the provider’s own general-purpose AI model or in very large online platforms; fines up to €35 million or 7% of worldwide turnover, whichever is higher (for SMEs, whichever is lower).
    Law
    AI Act, Article 5(1)(ba) and (bb) and 5(1a) to (1b), inserted by Regulation (EU) 2026/1744 (Digital Omnibus on AI)
  2. EUStarts December 2, 2026

    Platforms: keep humans in charge of algorithmic management

    Gig-work platforms must explain their automated monitoring and decision systems to the people working through them, keep them under human oversight, and not use them to process data such as emotional state, private conversations or union activity. Only a human may decide to restrict, suspend or close a worker’s account. EU countries must put this into national law by December 2, 2026.

    Who
    Digital labour platforms, such as ride-hailing or delivery apps, organising work in the EU. The data and human-review rules also protect self-employed platform workers.
    Enforced by
    Under each country’s national law; data protection authorities can fine breaches of the data rules at GDPR levels.
    Law
    Platform Work Directive (EU) 2024/2831, Articles 7 to 15 (deadline for national laws)
  3. CaliforniaStarts January 1, 2027

    Say in layoff notices when AI caused the cuts

    If a mass layoff, relocation or closure is caused wholly or substantially by AI or other automation, the 60-day notice must say so under the line “This notice is for a technology displacement”. It must give the number, job type and work location of those jobs, the tasks that will be automated and the kind of technology used.

    Who
    Employers with a California site that has employed 75 or more people in the past year.
    Enforced by
    Existing Cal/WARN remedies, as SB 951 adds no new penalty: workers not given notice are owed back pay and benefits for up to 60 days, and a missing notice to officials can cost up to $500 a day. Workers, unions and local governments can sue.
    Law
    SB 951 (Chapter 860, Statutes of 2026), Labor Code section 1401
  4. CaliforniaStarts January 1, 2027

    No surveillance tools in workplace bathrooms

    Employers may not use surveillance tools to monitor workers in workplace bathrooms, except under a court order, and workers may leave such tools behind when they go in. Simple badges or alarms without audio, video or built-in AI are allowed.

    Who
    All California employers, public and private.
    Enforced by
    Labor Commissioner and public prosecutors; up to $500 per violation.
    Law
    AB 1331 (Chapter 851, Statutes of 2026), Labor Code sections 1560 to 1565
  5. CaliforniaStarts January 1, 2027

    Do not use AI to read workers’ emotions or neural data

    Employers may not use AI-powered workplace surveillance tools to recognise, infer or predict workers’ emotional state, or to collect neural data, meaning measurements of the nervous system. Tools used to keep people safe are not banned.

    Who
    All California employers, public and private.
    Enforced by
    Labor Commissioner, public prosecutors or the worker; up to $500 per violation.
    Law
    AB 1883 (Chapter 853, Statutes of 2026), Labor Code sections 1580 to 1583
  6. CaliforniaStarts January 1, 2027

    Big platforms must show whether content is AI-made

    Detect provenance data in content on your platform, clearly show whether it says the content was made or substantially altered by AI or captured by a camera or recorder, and let users inspect that data. Where technically feasible, do not knowingly strip it.

    Who
    Public-facing social media, file-sharing, mass-messaging and stand-alone search services with more than 2 million unique monthly users over the past 12 months. Broadband and telecom services are excluded.
    Enforced by
    Attorney General, city attorneys or county counsel; $5,000 per violation, with each day a separate violation.
    Law
    Business and Professions Code section 22757.3.1, added by AB 853 (Chapter 674, Statutes of 2025) and amended by AB 2713 (Chapter 856, Statutes of 2026)
  7. CaliforniaStarts January 1, 2027

    Do not knowingly host AI models that skip hidden labels

    If your site or app offers generative AI model weights or source code for download, do not knowingly make available a system that does not add the hidden provenance data California requires.

    Who
    Generative AI hosting platforms, paid or free, that offer downloads to people in California.
    Enforced by
    Attorney General, city attorneys or county counsel; $5,000 per violation.
    Law
    Business and Professions Code section 22757.3.2 (AB 853, Chapter 674, Statutes of 2025)
  8. CaliforniaStarts January 1, 2027

    Assess, limit and audit companion chatbots for children

    From January 1, 2027, check users’ ages or give everyone the child protections. From July 1, 2027, if children may use your companion chatbot, assess child risks before each release, publish a child safety policy and run a crisis protocol. Set parent-controlled limits such as one-hour sessions, block romance, sexual content and purchase pressure, and do not sell children’s data. Independent audits are due from 2029.

    Who
    Anyone who makes a companion chatbot available in California; most duties apply only if children under 18 may use it. Colleges offering it only for education, and employers offering it only to staff, are excluded.
    Enforced by
    Public prosecutors; up to $5,000 per affected child for each negligent violation and $15,000 for each intentional one. Harmed children or their parents can sue for damages.
    Law
    Adam’s Law, SB 1119 (Chapter 190, Statutes of 2026), Business and Professions Code sections 21810 to 21818
  9. CaliforniaStarts January 1, 2027

    Do not make or sell toys with companion chatbots

    Until January 1, 2031, do not make, sell, exchange or offer to retailers any toy that includes a companion chatbot. A toy here means a product made for play by children under 16.

    Who
    Toy makers, sellers and distributors in California.
    Enforced by
    People harmed can sue for their actual damages or $1,000 per violation, whichever is greater, plus a court order and legal fees.
    Law
    SB 867 (Chapter 189, Statutes of 2026), Business and Professions Code section 22604.5
  10. CaliforniaStarts January 1, 2027

    Do not train AI on students’ data from your school app

    If your website, service or app is designed or marketed for preschool, school or college use, do not use the student information it creates or gathers, including persistent identifiers, to train generative AI or develop any AI system. The rules for colleges start on July 1, 2027.

    Who
    Operators of education websites, services and apps that know they are used for school purposes in California, and companies working for them.
    Enforced by
    Students or parents who suffer damages can sue, also as a class, for their actual damages or $500 per violation, whichever is greater, after giving the operator 60 days’ written notice to fix it.
    Law
    AB 1159 (Chapter 182, Statutes of 2026), Business and Professions Code sections 22584, 22586 and 22587 and following
  11. CaliforniaStarts January 1, 2027

    Give notice and an opt-out before automated decisions

    If software makes significant decisions about people without real human involvement, such as hiring, pay, promotion, firing or school admissions, give a notice before use, offer an opt-out, and explain the logic and result on request. In most cases an appeal to a human who can overturn the decision can replace the opt-out.

    Who
    Businesses covered by the California Consumer Privacy Act, such as those with over $26,625,000 in yearly revenue or that buy, sell or share data on 100,000 or more consumers.
    Enforced by
    California Privacy Protection Agency or the Attorney General: up to $2,663 per violation, or $7,988 if intentional (2025 amounts).
    Law
    CCPA regulations, California Code of Regulations title 11, sections 7200 and 7220 to 7222
  12. ColoradoStarts January 1, 2027

    Explain automated decisions and offer a human review

    Before technology that processes personal data materially influences a decision about someone’s job, education, housing, financial or lending services, insurance, health care or essential government services, tell them clearly; a prominent notice where they apply is enough. After a bad outcome, explain its role within 30 days and, on request, let them correct their data and get a human review where commercially reasonable.

    Who
    Businesses in Colorado that use such technology in decisions about people in Colorado, including workers and job applicants. Developers that sell it must give users documentation and update notices; both keep records for 3 years.
    Enforced by
    Attorney General only, as a deceptive trade practice. Until January 1, 2030, a 60-day chance to fix after a warning, except for knowing or repeated violations. No new right to sue, but discrimination claims still apply.
    Law
    SB 26-189, which replaced the 2024 Colorado AI Act
  13. ColoradoStarts January 1, 2027

    Tell users your chatbot is AI and handle crises

    Tell users clearly that your chatbot is AI at the start of each day’s first chat, at least every three hours or with a notice that stays visible, and whenever they ask. Have a suicide and self-harm protocol that refers users to crisis services, and never present its answers as coming from a licensed professional such as a doctor, lawyer or therapist. Yearly reports to the Attorney General start July 1, 2027.

    Who
    Operators of public chatbots in Colorado that mainly simulate human conversation. Customer-service, shopping, productivity, developer, school and narrow-topic tools, voice assistants and game bots are excluded.
    Enforced by
    Attorney General, as a deceptive trade practice under Colorado’s AI law; no new right to sue.
    Law
    HB 26-1263 (signed May 29, 2026), section 2
  14. ColoradoStarts January 1, 2027

    Estimate ages and protect minors on your chatbot

    Use reasonable methods to estimate users’ ages, and do not ignore clear signs that a user is a minor. For minors, keep a regular AI notice, give no surprise rewards to drive engagement, block sexual content, stop the bot claiming to be human or sentient or role-playing romance, and give minors and parents privacy and account tools.

    Who
    Operators of public chatbots in Colorado that mainly simulate human conversation. Customer-service, shopping, productivity, developer, school and narrow-topic tools, voice assistants and game bots are excluded.
    Enforced by
    Attorney General, as a deceptive trade practice under Colorado’s AI law; no new right to sue.
    Law
    HB 26-1263 (signed May 29, 2026), section 2
  15. ConnecticutStarts January 1, 2027

    AI companions must say they are not human and handle crises

    An AI companion needs a published protocol that detects talk of suicide, self-harm or violence and refers users to help such as the 988 line, and it must not claim to be human. If it could be mistaken for a person, show a clear AI notice: always visible, or at the start of each day’s first chat and then hourly for minors and every three hours for adults.

    Who
    Operators of AI companion chatbots used in Connecticut.
    Enforced by
    Attorney General only, as an unfair trade practice; no private lawsuits.
    Law
    Public Act 26-15, sections 4 to 6
  16. ConnecticutStarts January 1, 2027

    Protect minors who use your AI companion

    If you know or have reason to believe a user is under 18, use measures that meet industry standards to keep your AI companion safe for them. It must not encourage self-harm, suicide, violence, disordered eating or drug use, discourage seeking help, engage in romantic or sexual talk, or use manipulative engagement tactics. Give minors and parents tools to manage screen time and account settings.

    Who
    Operators of AI companions used in Connecticut; customer-service, game, voice-assistant and narrow-task bots are excluded.
    Enforced by
    Attorney General only, as an unfair trade practice; no private lawsuits.
    Law
    Public Act 26-15, section 6
  17. IllinoisStarts January 1, 2027

    Report frontier AI incidents and get yearly safety audits

    Large frontier AI developers must publish a safety framework, file disclosure statements with the state emergency management agency and send it regular summaries of catastrophic-risk assessments. Report critical safety incidents to that agency and the Attorney General within 72 hours, or 24 hours if lives are at risk. Yearly independent audits start on January 1, 2028.

    Who
    Developers of the largest frontier AI models. Staff who raise safety concerns get confidential reporting channels and whistleblower protection.
    Enforced by
    Civil penalties of up to $1 million for a first violation and $3 million for each later one.
    Law
    Artificial Intelligence Safety Measures Act (SB 315, signed July 6, 2026)
  18. New YorkStarts January 1, 2027

    Report frontier AI incidents within 72 hours

    If you develop frontier AI models, trained with more than 10²⁶ operations, publish a transparency report when you release a new model and report critical safety incidents to the state within 72 hours. Developers with over $500 million in yearly revenue must also write, follow and publish a frontier AI safety framework and file disclosures with a new office at the Department of Financial Services.

    Who
    Frontier AI developers whose models are developed, deployed or operated at least partly in New York. Accredited universities doing academic research are exempt.
    Enforced by
    Attorney General; up to $1 million for a first violation and $3 million for each later one. No private lawsuits.
    Law
    RAISE Act, General Business Law article 44-B, as replaced by Chapter 96 of 2026
  19. CaliforniaStarts July 1, 2027

    Do not discipline or fire workers by software alone

    Do not rely solely on an automated decision system to discipline or fire. If you rely mainly on one, a human must corroborate the result, and the worker gets a written notice when told of the decision. Such systems also may not be used to infer protected traits, and workers can ask for their own data.

    Who
    Employers in California, including public employers such as cities and counties. It protects employees, not job applicants.
    Enforced by
    Labor Commissioner and public prosecutors; $500 per violation.
    Law
    SB 947, the No Robo Bosses Act of 2026 (Chapter 859, Statutes of 2026), Labor Code sections 1520 to 1526.7
  20. ConnecticutStarts October 1, 2027

    Tell people when an AI tool helps decide about their job

    If an automated tool is a substantial factor in a job decision, give the person a written notice before the decision. Tell people in plain language when they are interacting with such a tool.

    Who
    Businesses in Connecticut, such as employers, recruiters and staffing firms, that use automated tools in job decisions about Connecticut staff or applicants. Developers of tools sold for job decisions must give users the information they need.
    Enforced by
    Attorney General only, as an unfair trade practice. For violations up to December 31, 2027, the Attorney General may first give 60 days to fix them. No private lawsuits.
    Law
    Public Act 26-15, sections 7 to 12
  21. EUStarts December 2, 2027

    AI for hiring and managing staff becomes “high-risk”

    Employers using AI to recruit, manage or evaluate workers must follow its instructions, have trained people oversee it and keep its logs for at least six months. They must inform workers and their representatives before using it, and tell candidates and staff when it is used in decisions about them. AI types already on the market before then are covered only after a significant design change.

    Who
    Employers and other organisations that use such AI in the EU.
    Enforced by
    National authorities; fines up to €15 million or 3% of worldwide turnover, whichever is higher (whichever is lower for SMEs and small mid-caps).
    Law
    AI Act, Article 26 and Annex III (date moved by the 2026 Digital Omnibus)
  22. EUStarts December 2, 2027

    Certify HR AI as high-risk before you sell it

    If you sell AI for recruiting, promotion, firing, task allocation or monitoring workers, it must meet the high-risk requirements: risk management, data quality, documentation, logging, human oversight and accuracy. It must also pass a conformity assessment, carry the CE mark and be registered in the EU database.

    Who
    Providers placing such AI on the EU market, including companies that sell it under their own name or substantially change it.
    Enforced by
    National authorities; fines up to €15 million or 3% of worldwide turnover, whichever is higher (whichever is lower for SMEs and small mid-caps).
    Law
    AI Act, Articles 6(2), 8 to 17, 43 and 47 to 49, and Annex III point 4 (date moved by Regulation (EU) 2026/1744)
  23. EUStarts December 2, 2027

    Treat AI for admissions, grading and exams as high-risk

    This covers AI that admits or places students, grades their work, decides what level of education they can reach, or watches for cheating in tests. If you use it, follow the maker’s instructions, have trained staff oversee it, keep its logs for at least six months and tell students it is used. Public bodies, and private bodies providing a public service, must first assess its impact on people’s rights.

    Who
    Schools, universities, training providers and exam bodies using such AI in the EU; the makers must pass a conformity assessment before selling it. AI on the market before then is covered only after a significant design change, except that AI for public authorities must comply by August 2, 2030.
    Enforced by
    National authorities; fines up to €15 million or 3% of worldwide turnover, whichever is higher (whichever is lower for SMEs and small mid-caps).
    Law
    AI Act, Annex III point 3 and Articles 26, 27 and 111(2) (dates set by Regulation (EU) 2026/1744)
  24. EUStarts December 2, 2027

    Treat face recognition and emotion AI as high-risk

    This covers AI that identifies people remotely from their face or other biometrics, sorts them by sensitive or protected traits, or recognises emotions, where such uses are not banned. If you use it, follow the maker’s instructions, have trained staff oversee it, keep its logs and tell the people exposed to it. Simple ID checks that only confirm a person is who they claim to be are excluded.

    Who
    Businesses and organisations using such AI in the EU, such as shops, venues and security firms; the makers must pass a conformity assessment before selling it. AI on the market before then is covered only after a significant design change.
    Enforced by
    National authorities; fines up to €15 million or 3% of worldwide turnover, whichever is higher (whichever is lower for SMEs and small mid-caps).
    Law
    AI Act, Annex III point 1 and Article 26 (date set by Regulation (EU) 2026/1744)
  25. EUStarts December 2, 2027

    Treat AI credit scoring and insurance pricing as high-risk

    If you use AI to judge people’s creditworthiness or set their credit score, or to assess risk and set prices for life or health insurance, first assess its impact on people’s rights. Then follow the maker’s instructions, have trained staff oversee it, keep its logs for at least six months and tell people it is used in decisions about them. AI used only to detect fraud is excluded.

    Who
    Banks, lenders, insurers and other businesses using such AI in the EU; the makers must pass a conformity assessment before selling it. AI on the market before then is covered only after a significant design change.
    Enforced by
    National authorities; fines up to €15 million or 3% of worldwide turnover, whichever is higher (whichever is lower for SMEs and small mid-caps).
    Law
    AI Act, Annex III point 5(b) and (c) and Articles 26 and 27 (date set by Regulation (EU) 2026/1744)

Next deadlines

The next rules to start, everywhere we track.

  1. European UnionDo not offer or use AI that makes sexual deepfakes
  2. European UnionPlatforms: keep humans in charge of algorithmic management
  3. CaliforniaSay in layoff notices when AI caused the cuts
  4. CaliforniaNo surveillance tools in workplace bathrooms
  5. CaliforniaDo not use AI to read workers’ emotions or neural data
  6. CaliforniaBig platforms must show whether content is AI-made

What this checker covers

We aim to list every rule that fits the scope below, and we say openly what is not in it yet.

Covered

  • Binding laws and regulations about AI, automated decisions, AI-made content, chatbots and AI developers.
  • Rules already in force, and rules that are law with a set start date.
  • Duties for businesses, employers, platforms and AI makers in the places listed above.
  • For Germany, France and Hungary: national rules that add to EU law, and who enforces the AI Act there.
  • A few general laws that are the main rule for an AI use in a country, marked “General law”.

Not covered yet

  • Rules for a single sector, such as health care, insurance, banking, elections or law firms.
  • Rules that bind only public bodies, such as government agencies, state schools or public broadcasters.
  • Bills that have not passed, official guidance and voluntary codes.
  • Most general laws that are not about AI but still apply to it, such as data protection, anti-discrimination or consumer law.
  • Other US states, and countries not listed above, including the United Kingdom.
  • National laws of EU countries other than Germany, France and Hungary.

How we check these rules

We read each rule in the official text, the law itself or the regulator’s own page, and link it. Where an earlier summary disagrees with the signed text, we follow the signed text. We last checked all 96 rules, from 69 official sources, on October 1, 2026.

Two notes on dates. California laws that set no start date of their own take effect on January 1 of the next year, so we list the bills signed in September 2026 from January 1, 2027. The EU dates follow the European Commission’s timeline, which includes the changes made by the 2026 Digital Omnibus; the article pages we link still show the 2024 wording.

One note on sources. Illinois’s legislature website could not be reached when we checked, so the Illinois entries rest on official summaries by the Governor, the Attorney General and state agencies. We will check them against the law texts as soon as the site is reachable.

For every AI law, bill, order and court ruling we have covered, including ones that are not yet in force, see the AI laws tracker and the AI calendar.

This is a plain-language guide, not legal advice. Laws have exceptions and details we leave out, and they change. Check the official text, or ask a lawyer, before you act. If you spot a mistake, tell us through the corrections policy.