Data tool
Which AI rules apply to me?
Pick where you work or sell and what you use AI for. You get the AI rules that apply, what they ask you to do and from when, with a link to the official text.
Your checklist
Choose one or more answers to each question. Each rule says what to do, who it is for, and who enforces it.
24 rules match your choices.
In force now 17
- In force since August 2, 2026
Tell people when they are talking to an AI
If you provide an AI system that talks directly with people, design it so they are told they are interacting with AI, unless that is obvious.
- Who
- Providers of AI systems used in the EU.
- Enforced by
- National authorities, or the EU AI Office for chatbots built on the provider’s own general-purpose AI model or in very large online platforms; fines up to €15 million or 3% of worldwide turnover, whichever is higher (whichever is lower for SMEs and small mid-caps).
- Law
- AI Act, Article 50(1)
Official text AI Act, Article 50 (EU AI Act Service Desk) - In force since August 2, 2026
Mark AI-generated content so machines can detect it
Providers of AI that generates audio, images, video or text must mark the output in a machine-readable way as AI-made. Systems already on the market before August 2, 2026 have until December 2, 2026. Tools that only assist standard editing are exempt.
- Who
- Providers of generative AI systems in the EU, including general-purpose AI.
- Enforced by
- National authorities, or the EU AI Office for generative AI built on the provider’s own general-purpose AI model or in very large online platforms; fines up to €15 million or 3% of worldwide turnover, whichever is higher (whichever is lower for SMEs and small mid-caps).
- Law
- AI Act, Article 50(2)
Official text AI Act implementation timeline (European Commission) - In force since February 2, 2025
Help your staff understand the AI they use
Take steps to support the AI literacy of staff and others who operate or use AI for you, suited to their knowledge and to how the AI is used. Since July 27, 2026 you no longer have to guarantee a particular skill level.
- Who
- Providers and deployers of AI systems in the EU, which includes any business using AI at work.
- Enforced by
- National authorities; the AI Act sets no EU-wide fine for this duty, so penalties come from national law.
- Law
- AI Act, Article 4, as replaced by Regulation (EU) 2026/1744
Official text AI Omnibus enters into force (European Commission) - In force since February 2, 2025
Do not build AI that manipulates or exploits people
AI that uses subliminal, manipulative or deceptive techniques, or exploits people’s age, disability or social or economic situation, to distort their decisions in a way that causes or is likely to cause significant harm is banned.
- Who
- Anyone who provides or uses such AI in the EU.
- Enforced by
- National authorities, enforcing since August 2, 2026; fines up to €35 million or 7% of worldwide turnover, whichever is higher (for SMEs, whichever is lower).
- Law
- AI Act, Article 5(1)(a) and (b)
Official text AI Act, Article 5 (EU AI Act Service Desk) - In force since February 2, 2025
Do not scrape faces from the web to build face recognition
AI that creates or expands facial recognition databases by untargeted scraping of face images from the internet or CCTV footage is banned.
- Who
- Anyone who provides or uses such AI in the EU.
- Enforced by
- National authorities, enforcing since August 2, 2026; fines up to €35 million or 7% of worldwide turnover, whichever is higher (for SMEs, whichever is lower).
- Law
- AI Act, Article 5(1)(e)
Official text AI Act, Article 5 (EU AI Act Service Desk) - In force since February 2, 2025
Do not use AI to predict crime from profiling alone
AI that assesses or predicts the risk that a person will commit a crime based solely on profiling, or on their personality traits, is banned. AI that supports a human assessment already based on objective, verifiable facts is allowed.
- Who
- Anyone who provides or uses such AI in the EU, including private companies.
- Enforced by
- National authorities, enforcing since August 2, 2026; fines up to €35 million or 7% of worldwide turnover, whichever is higher (for SMEs, whichever is lower).
- Law
- AI Act, Article 5(1)(d)
Official text AI Act, Article 5 (EU AI Act Service Desk) - In force since August 2, 2025
Document your AI model and publish a training-data summary
If you put a general-purpose AI model on the EU market, keep technical documentation and give developers who build on it the information they need. Follow EU copyright law, including publishers’ opt-outs from text and data mining, and publish a summary of the training content. Models on the market before August 2, 2025 have until August 2, 2027.
- Who
- Providers of general-purpose AI models offered in the EU, wherever they are based; providers outside the EU need an EU representative. Open-source models skip the documentation duties unless they pose systemic risk, but must still follow copyright law and publish the summary.
- Enforced by
- European Commission (AI Office), with powers to fine since August 2, 2026: up to €15 million or 3% of worldwide turnover, whichever is higher.
- Law
- AI Act, Articles 53, 54 and 111(3); text and data mining opt-outs under the Copyright Directive (EU) 2019/790, Article 4(3)
Official text AI Act overview (European Commission) - In force since August 2, 2025
Test and report risks of the most powerful AI models
A general-purpose model is presumed to have systemic risk if it was trained with more than 10²⁵ operations, and the Commission can also designate one. If yours has it, notify the Commission, evaluate and adversarially test the model, and assess and reduce its risks. Report serious incidents to the AI Office and keep strong cybersecurity.
- Who
- Providers of general-purpose AI models with systemic risk offered in the EU.
- Enforced by
- European Commission (AI Office), with powers to fine since August 2, 2026: up to €15 million or 3% of worldwide turnover, whichever is higher.
- Law
- AI Act, Articles 51, 52 and 55
Official text AI Act overview (European Commission) - In force since April 22, 2026
Get parents’ separate consent to train AI on kids’ data
If your site, app or service is aimed at children under 13, or you know you collect their data, get a parent’s separate, verifiable consent before disclosing a child’s personal information to third parties. The FTC says disclosing it to train or develop AI needs this consent.
- Who
- Operators of websites, apps and online services, including education technology, aimed at children under 13 or knowingly collecting their data.
- Enforced by
- Federal Trade Commission and state attorneys general; civil penalties of up to $53,088 per violation.
- Law
- Children’s Online Privacy Protection Rule, 16 CFR 312.5(a)(2), as amended in 2025
Official text COPPA Rule amendments (Federal Trade Commission) - In force since August 2, 2026
Embed hidden AI labels and offer a free checking tool
If you make a generative AI system that people in California can use, add hidden provenance data to the images, video and audio it creates or alters, where technically feasible. Also offer a free disclosure verification tool, your own or a compliant third-party one. Since September 30, 2026 this applies however many users you have; AI built mainly as assistive technology is exempt until 2029.
- Who
- Makers of generative AI systems publicly available in California.
- Enforced by
- Attorney General, city attorneys or county counsel; $5,000 per violation, with each day a separate violation. Falsely claiming the assistive-technology exemption costs $50,000 per violation.
- Law
- California AI Transparency Act, Business and Professions Code sections 22757 to 22757.6 (SB 942, Chapter 291, Statutes of 2024; amended by AB 853, Chapter 674, Statutes of 2025, and SB 1000, Chapter 861, Statutes of 2026)
Official text SB 1000 (California Legislature) - In force since January 1, 2026
Publish frontier AI safety plans and report incidents
If you train frontier AI models, publish a transparency report when you deploy a new or substantially changed one. Report critical safety incidents to the state’s Office of Emergency Services within 15 days, or within 24 hours to the right authority if lives are at risk. Developers with over $500 million in yearly revenue must also publish and follow a frontier AI framework and run an anonymous internal reporting channel.
- Who
- Frontier developers: anyone who has trained a model using more than 10²⁶ operations. None may gag or punish staff who report catastrophic risks.
- Enforced by
- Attorney General; civil penalties of up to $1 million per violation, scaled to its severity.
- Law
- Transparency in Frontier Artificial Intelligence Act, SB 53 (Chapter 138, Statutes of 2025), Business and Professions Code sections 22757.10 to 22757.16 and Labor Code sections 1107 to 1107.2
Official text SB 53 (California Legislature) - In force since January 1, 2026
Post a summary of the data used to train your AI
Before each public release of a generative AI system, or a substantial change to it, post documentation on your website about its training data. It must include a high-level summary of the datasets: their sources or owners, whether they include copyrighted or personal information, and whether they were bought or licensed.
- Who
- Developers of generative AI systems or services released since January 1, 2022 and publicly available to Californians, including anyone who substantially modifies one. AI used only for security, aircraft operation or national security is exempt.
- Enforced by
- The law names no penalty or enforcer. A federal court refused to block it in March 2026; xAI’s appeal is set for argument on November 18, 2026.
- Law
- AB 2013 (Chapter 817, Statutes of 2024), Civil Code sections 3110 and 3111, amended by AB 1170 (Chapter 67, Statutes of 2025)
Official text Civil Code section 3111 (California Legislature) - In force since January 1, 2026
Do not make or help spread sexual deepfakes
Do not create or share sexually explicit deepfakes of a real person when you know, or should know, that they did not consent or were a minor, and do not knowingly help others do it. A service mainly for making sexual deepfakes is presumed to know there was no consent. Companies that keep such a service running are presumed liable if they do not stop within 30 days of notice.
- Who
- Anyone, including people and businesses that run or serve deepfake services.
- Enforced by
- The person shown can sue for profits, actual damages or $1,500 to $50,000 per work, up to $250,000 with malice, plus punitive damages and fees. Public prosecutors can seek $25,000 per violation, or $50,000 with malice.
- Law
- AB 621 (Chapter 673, Statutes of 2025), Civil Code section 1708.86
Official text AB 621 (California Legislature) - In force since January 1, 2026
Do a risk assessment before using AI to judge people
Do and document a privacy risk assessment, and review it at least every three years, before you use automated decision-making for significant decisions such as jobs, loans, housing, education or health care. The same applies to automated tools that infer workers’, students’ or applicants’ performance, health, behaviour or location from systematic observation, and to training such tools or face recognition on personal data. Uses that began before 2026 need one by December 31, 2027.
- Who
- Businesses covered by the California Consumer Privacy Act.
- Enforced by
- California Privacy Protection Agency or the Attorney General: up to $2,663 per violation, or $7,988 if intentional (2025 amounts).
- Law
- CCPA regulations, California Code of Regulations title 11, sections 7150, 7155 and 7157
Official text CCPA regulations (California Privacy Protection Agency) - In force since October 1, 2026
Do not punish staff who warn about catastrophic AI risks
Do not adopt or enforce any policy or contract that lets you punish staff for reporting a specific and substantial danger from catastrophic AI risk, or for whistleblowing to authorities, and tell your risk staff their rights. Developers with over $500 million in yearly revenue need an anonymous internal reporting channel by January 1, 2027.
- Who
- Frontier AI developers doing business in Connecticut: those training models with more than 10²⁶ operations.
- Enforced by
- Attorney General; civil penalty of up to $1,000 per violation.
- Law
- Public Act 26-15, section 2
- In force since October 1, 2026
Add provenance data to AI images, audio and video
Where commercially and technically reasonable, embed provenance data in images, audio and video your AI creates or materially alters, and make it hard to remove, for example with the C2PA standard.
- Who
- Makers of generative AI systems for images, audio or video that the public can use for personal purposes and that have more than one million users a month. Business-to-business tools, games, and pure upscaling or compression tools are excluded.
- Enforced by
- Attorney General, as an unfair trade practice; no private lawsuits.
- Law
- Public Act 26-15, section 15
- In force since July 1, 2026
Say in your privacy notice if you train AI on personal data
Your privacy notice must state whether you collect, use or sell personal data to train large language models.
- Who
- Businesses covered by the Connecticut Data Privacy Act: those serving people in Connecticut that handle the data of at least 35,000 consumers, process sensitive data, or sell personal data. It protects people as consumers, not as workers.
- Enforced by
- Attorney General only, as an unfair trade practice; no private lawsuits.
- Law
- Connecticut Data Privacy Act, C.G.S. 42-520, as amended by Public Act 25-113
Official text Public Act 25-113 (Connecticut General Assembly)
Coming up 7
- Starts December 2, 2026
Do not offer or use AI that makes sexual deepfakes
AI systems that create or alter realistic sexual or intimate images, video or audio of an identifiable person without their explicit consent, or child sexual abuse material, are banned. Providers are covered when this is the intended purpose or a foreseeable result their safeguards do not reliably prevent; users are covered when they use AI for this.
- Who
- Anyone who provides or uses such AI systems in the EU.
- Enforced by
- National authorities, or the EU AI Office for AI built on the provider’s own general-purpose AI model or in very large online platforms; fines up to €35 million or 7% of worldwide turnover, whichever is higher (for SMEs, whichever is lower).
- Law
- AI Act, Article 5(1)(ba) and (bb) and 5(1a) to (1b), inserted by Regulation (EU) 2026/1744 (Digital Omnibus on AI)
Official text AI Act implementation timeline (European Commission) - Starts January 1, 2027
Do not knowingly host AI models that skip hidden labels
If your site or app offers generative AI model weights or source code for download, do not knowingly make available a system that does not add the hidden provenance data California requires.
- Who
- Generative AI hosting platforms, paid or free, that offer downloads to people in California.
- Enforced by
- Attorney General, city attorneys or county counsel; $5,000 per violation.
- Law
- Business and Professions Code section 22757.3.2 (AB 853, Chapter 674, Statutes of 2025)
Official text AB 853 (California Legislature) - Starts January 1, 2027
Do not train AI on students’ data from your school app
If your website, service or app is designed or marketed for preschool, school or college use, do not use the student information it creates or gathers, including persistent identifiers, to train generative AI or develop any AI system. The rules for colleges start on July 1, 2027.
- Who
- Operators of education websites, services and apps that know they are used for school purposes in California, and companies working for them.
- Enforced by
- Students or parents who suffer damages can sue, also as a class, for their actual damages or $500 per violation, whichever is greater, after giving the operator 60 days’ written notice to fix it.
- Law
- AB 1159 (Chapter 182, Statutes of 2026), Business and Professions Code sections 22584, 22586 and 22587 and following
Official text AB 1159 (California Legislature) - Starts January 1, 2027
Explain automated decisions and offer a human review
Before technology that processes personal data materially influences a decision about someone’s job, education, housing, financial or lending services, insurance, health care or essential government services, tell them clearly; a prominent notice where they apply is enough. After a bad outcome, explain its role within 30 days and, on request, let them correct their data and get a human review where commercially reasonable.
- Who
- Businesses in Colorado that use such technology in decisions about people in Colorado, including workers and job applicants. Developers that sell it must give users documentation and update notices; both keep records for 3 years.
- Enforced by
- Attorney General only, as a deceptive trade practice. Until January 1, 2030, a 60-day chance to fix after a warning, except for knowing or repeated violations. No new right to sue, but discrimination claims still apply.
- Law
- SB 26-189, which replaced the 2024 Colorado AI Act
Official text SB 26-189 (Colorado General Assembly) - Starts January 1, 2027
Report frontier AI incidents and get yearly safety audits
Large frontier AI developers must publish a safety framework, file disclosure statements with the state emergency management agency and send it regular summaries of catastrophic-risk assessments. Report critical safety incidents to that agency and the Attorney General within 72 hours, or 24 hours if lives are at risk. Yearly independent audits start on January 1, 2028.
- Who
- Developers of the largest frontier AI models. Staff who raise safety concerns get confidential reporting channels and whistleblower protection.
- Enforced by
- Civil penalties of up to $1 million for a first violation and $3 million for each later one.
- Law
- Artificial Intelligence Safety Measures Act (SB 315, signed July 6, 2026)
Official text Governor’s announcement of SB 315 (State of Illinois) - Starts January 1, 2027
Report frontier AI incidents within 72 hours
If you develop frontier AI models, trained with more than 10²⁶ operations, publish a transparency report when you release a new model and report critical safety incidents to the state within 72 hours. Developers with over $500 million in yearly revenue must also write, follow and publish a frontier AI safety framework and file disclosures with a new office at the Department of Financial Services.
- Who
- Frontier AI developers whose models are developed, deployed or operated at least partly in New York. Accredited universities doing academic research are exempt.
- Enforced by
- Attorney General; up to $1 million for a first violation and $3 million for each later one. No private lawsuits.
- Law
- RAISE Act, General Business Law article 44-B, as replaced by Chapter 96 of 2026
Official text S8828, RAISE Act amendments (New York State Senate) - Starts December 2, 2027
Certify HR AI as high-risk before you sell it
If you sell AI for recruiting, promotion, firing, task allocation or monitoring workers, it must meet the high-risk requirements: risk management, data quality, documentation, logging, human oversight and accuracy. It must also pass a conformity assessment, carry the CE mark and be registered in the EU database.
- Who
- Providers placing such AI on the EU market, including companies that sell it under their own name or substantially change it.
- Enforced by
- National authorities; fines up to €15 million or 3% of worldwide turnover, whichever is higher (whichever is lower for SMEs and small mid-caps).
- Law
- AI Act, Articles 6(2), 8 to 17, 43 and 47 to 49, and Annex III point 4 (date moved by Regulation (EU) 2026/1744)
Official text AI Act overview (European Commission)
Next deadlines
The next rules to start, everywhere we track.
- European UnionDo not offer or use AI that makes sexual deepfakes
- European UnionPlatforms: keep humans in charge of algorithmic management
- CaliforniaSay in layoff notices when AI caused the cuts
- CaliforniaNo surveillance tools in workplace bathrooms
- CaliforniaDo not use AI to read workers’ emotions or neural data
- CaliforniaBig platforms must show whether content is AI-made
What this checker covers
We aim to list every rule that fits the scope below, and we say openly what is not in it yet.
Covered
- Binding laws and regulations about AI, automated decisions, AI-made content, chatbots and AI developers.
- Rules already in force, and rules that are law with a set start date.
- Duties for businesses, employers, platforms and AI makers in the places listed above.
- For Germany, France and Hungary: national rules that add to EU law, and who enforces the AI Act there.
- A few general laws that are the main rule for an AI use in a country, marked “General law”.
Not covered yet
- Rules for a single sector, such as health care, insurance, banking, elections or law firms.
- Rules that bind only public bodies, such as government agencies, state schools or public broadcasters.
- Bills that have not passed, official guidance and voluntary codes.
- Most general laws that are not about AI but still apply to it, such as data protection, anti-discrimination or consumer law.
- Other US states, and countries not listed above, including the United Kingdom.
- National laws of EU countries other than Germany, France and Hungary.
How we check these rules
We read each rule in the official text, the law itself or the regulator’s own page, and link it. Where an earlier summary disagrees with the signed text, we follow the signed text. We last checked all 96 rules, from 69 official sources, on October 1, 2026.
Two notes on dates. California laws that set no start date of their own take effect on January 1 of the next year, so we list the bills signed in September 2026 from January 1, 2027. The EU dates follow the European Commission’s timeline, which includes the changes made by the 2026 Digital Omnibus; the article pages we link still show the 2024 wording.
One note on sources. Illinois’s legislature website could not be reached when we checked, so the Illinois entries rest on official summaries by the Governor, the Attorney General and state agencies. We will check them against the law texts as soon as the site is reachable.
For every AI law, bill, order and court ruling we have covered, including ones that are not yet in force, see the AI laws tracker and the AI calendar.
This is a plain-language guide, not legal advice. Laws have exceptions and details we leave out, and they change. Check the official text, or ask a lawyer, before you act. If you spot a mistake, tell us through the corrections policy.