Your checklist

Choose one or more answers to each question. Each rule says what to do, who it is for, and who enforces it.

Where do you work or sell?
What do you use AI for?

24 rules match your choices.

In force now 17

  1. EUIn force since August 2, 2026

    Tell people when they are talking to an AI

    If you provide an AI system that talks directly with people, design it so they are told they are interacting with AI, unless that is obvious.

    Who
    Providers of AI systems used in the EU.
    Enforced by
    National authorities, or the EU AI Office for chatbots built on the provider’s own general-purpose AI model or in very large online platforms; fines up to €15 million or 3% of worldwide turnover, whichever is higher (whichever is lower for SMEs and small mid-caps).
    Law
    AI Act, Article 50(1)
  2. EUIn force since August 2, 2026

    Mark AI-generated content so machines can detect it

    Providers of AI that generates audio, images, video or text must mark the output in a machine-readable way as AI-made. Systems already on the market before August 2, 2026 have until December 2, 2026. Tools that only assist standard editing are exempt.

    Who
    Providers of generative AI systems in the EU, including general-purpose AI.
    Enforced by
    National authorities, or the EU AI Office for generative AI built on the provider’s own general-purpose AI model or in very large online platforms; fines up to €15 million or 3% of worldwide turnover, whichever is higher (whichever is lower for SMEs and small mid-caps).
    Law
    AI Act, Article 50(2)
  3. EUIn force since February 2, 2025

    Help your staff understand the AI they use

    Take steps to support the AI literacy of staff and others who operate or use AI for you, suited to their knowledge and to how the AI is used. Since July 27, 2026 you no longer have to guarantee a particular skill level.

    Who
    Providers and deployers of AI systems in the EU, which includes any business using AI at work.
    Enforced by
    National authorities; the AI Act sets no EU-wide fine for this duty, so penalties come from national law.
    Law
    AI Act, Article 4, as replaced by Regulation (EU) 2026/1744
  4. EUIn force since February 2, 2025

    Do not build AI that manipulates or exploits people

    AI that uses subliminal, manipulative or deceptive techniques, or exploits people’s age, disability or social or economic situation, to distort their decisions in a way that causes or is likely to cause significant harm is banned.

    Who
    Anyone who provides or uses such AI in the EU.
    Enforced by
    National authorities, enforcing since August 2, 2026; fines up to €35 million or 7% of worldwide turnover, whichever is higher (for SMEs, whichever is lower).
    Law
    AI Act, Article 5(1)(a) and (b)
  5. EUIn force since February 2, 2025

    Do not scrape faces from the web to build face recognition

    AI that creates or expands facial recognition databases by untargeted scraping of face images from the internet or CCTV footage is banned.

    Who
    Anyone who provides or uses such AI in the EU.
    Enforced by
    National authorities, enforcing since August 2, 2026; fines up to €35 million or 7% of worldwide turnover, whichever is higher (for SMEs, whichever is lower).
    Law
    AI Act, Article 5(1)(e)
  6. EUIn force since February 2, 2025

    Do not use AI to predict crime from profiling alone

    AI that assesses or predicts the risk that a person will commit a crime based solely on profiling, or on their personality traits, is banned. AI that supports a human assessment already based on objective, verifiable facts is allowed.

    Who
    Anyone who provides or uses such AI in the EU, including private companies.
    Enforced by
    National authorities, enforcing since August 2, 2026; fines up to €35 million or 7% of worldwide turnover, whichever is higher (for SMEs, whichever is lower).
    Law
    AI Act, Article 5(1)(d)
  7. EUIn force since August 2, 2025

    Document your AI model and publish a training-data summary

    If you put a general-purpose AI model on the EU market, keep technical documentation and give developers who build on it the information they need. Follow EU copyright law, including publishers’ opt-outs from text and data mining, and publish a summary of the training content. Models on the market before August 2, 2025 have until August 2, 2027.

    Who
    Providers of general-purpose AI models offered in the EU, wherever they are based; providers outside the EU need an EU representative. Open-source models skip the documentation duties unless they pose systemic risk, but must still follow copyright law and publish the summary.
    Enforced by
    European Commission (AI Office), with powers to fine since August 2, 2026: up to €15 million or 3% of worldwide turnover, whichever is higher.
    Law
    AI Act, Articles 53, 54 and 111(3); text and data mining opt-outs under the Copyright Directive (EU) 2019/790, Article 4(3)
  8. EUIn force since August 2, 2025

    Test and report risks of the most powerful AI models

    A general-purpose model is presumed to have systemic risk if it was trained with more than 10²⁵ operations, and the Commission can also designate one. If yours has it, notify the Commission, evaluate and adversarially test the model, and assess and reduce its risks. Report serious incidents to the AI Office and keep strong cybersecurity.

    Who
    Providers of general-purpose AI models with systemic risk offered in the EU.
    Enforced by
    European Commission (AI Office), with powers to fine since August 2, 2026: up to €15 million or 3% of worldwide turnover, whichever is higher.
    Law
    AI Act, Articles 51, 52 and 55
  9. CaliforniaIn force since August 2, 2026

    Embed hidden AI labels and offer a free checking tool

    If you make a generative AI system that people in California can use, add hidden provenance data to the images, video and audio it creates or alters, where technically feasible. Also offer a free disclosure verification tool, your own or a compliant third-party one. Since September 30, 2026 this applies however many users you have; AI built mainly as assistive technology is exempt until 2029.

    Who
    Makers of generative AI systems publicly available in California.
    Enforced by
    Attorney General, city attorneys or county counsel; $5,000 per violation, with each day a separate violation. Falsely claiming the assistive-technology exemption costs $50,000 per violation.
    Law
    California AI Transparency Act, Business and Professions Code sections 22757 to 22757.6 (SB 942, Chapter 291, Statutes of 2024; amended by AB 853, Chapter 674, Statutes of 2025, and SB 1000, Chapter 861, Statutes of 2026)
  10. CaliforniaIn force since January 1, 2026

    Publish frontier AI safety plans and report incidents

    If you train frontier AI models, publish a transparency report when you deploy a new or substantially changed one. Report critical safety incidents to the state’s Office of Emergency Services within 15 days, or within 24 hours to the right authority if lives are at risk. Developers with over $500 million in yearly revenue must also publish and follow a frontier AI framework and run an anonymous internal reporting channel.

    Who
    Frontier developers: anyone who has trained a model using more than 10²⁶ operations. None may gag or punish staff who report catastrophic risks.
    Enforced by
    Attorney General; civil penalties of up to $1 million per violation, scaled to its severity.
    Law
    Transparency in Frontier Artificial Intelligence Act, SB 53 (Chapter 138, Statutes of 2025), Business and Professions Code sections 22757.10 to 22757.16 and Labor Code sections 1107 to 1107.2
  11. CaliforniaIn force since January 1, 2026

    Post a summary of the data used to train your AI

    Before each public release of a generative AI system, or a substantial change to it, post documentation on your website about its training data. It must include a high-level summary of the datasets: their sources or owners, whether they include copyrighted or personal information, and whether they were bought or licensed.

    Who
    Developers of generative AI systems or services released since January 1, 2022 and publicly available to Californians, including anyone who substantially modifies one. AI used only for security, aircraft operation or national security is exempt.
    Enforced by
    The law names no penalty or enforcer. A federal court refused to block it in March 2026; xAI’s appeal is set for argument on November 18, 2026.
    Law
    AB 2013 (Chapter 817, Statutes of 2024), Civil Code sections 3110 and 3111, amended by AB 1170 (Chapter 67, Statutes of 2025)
  12. CaliforniaIn force since January 1, 2026

    Do not make or help spread sexual deepfakes

    Do not create or share sexually explicit deepfakes of a real person when you know, or should know, that they did not consent or were a minor, and do not knowingly help others do it. A service mainly for making sexual deepfakes is presumed to know there was no consent. Companies that keep such a service running are presumed liable if they do not stop within 30 days of notice.

    Who
    Anyone, including people and businesses that run or serve deepfake services.
    Enforced by
    The person shown can sue for profits, actual damages or $1,500 to $50,000 per work, up to $250,000 with malice, plus punitive damages and fees. Public prosecutors can seek $25,000 per violation, or $50,000 with malice.
    Law
    AB 621 (Chapter 673, Statutes of 2025), Civil Code section 1708.86
  13. CaliforniaIn force since January 1, 2026

    Do a risk assessment before using AI to judge people

    Do and document a privacy risk assessment, and review it at least every three years, before you use automated decision-making for significant decisions such as jobs, loans, housing, education or health care. The same applies to automated tools that infer workers’, students’ or applicants’ performance, health, behaviour or location from systematic observation, and to training such tools or face recognition on personal data. Uses that began before 2026 need one by December 31, 2027.

    Who
    Businesses covered by the California Consumer Privacy Act.
    Enforced by
    California Privacy Protection Agency or the Attorney General: up to $2,663 per violation, or $7,988 if intentional (2025 amounts).
    Law
    CCPA regulations, California Code of Regulations title 11, sections 7150, 7155 and 7157
  14. ConnecticutIn force since October 1, 2026

    Do not punish staff who warn about catastrophic AI risks

    Do not adopt or enforce any policy or contract that lets you punish staff for reporting a specific and substantial danger from catastrophic AI risk, or for whistleblowing to authorities, and tell your risk staff their rights. Developers with over $500 million in yearly revenue need an anonymous internal reporting channel by January 1, 2027.

    Who
    Frontier AI developers doing business in Connecticut: those training models with more than 10²⁶ operations.
    Enforced by
    Attorney General; civil penalty of up to $1,000 per violation.
    Law
    Public Act 26-15, section 2
  15. ConnecticutIn force since October 1, 2026

    Add provenance data to AI images, audio and video

    Where commercially and technically reasonable, embed provenance data in images, audio and video your AI creates or materially alters, and make it hard to remove, for example with the C2PA standard.

    Who
    Makers of generative AI systems for images, audio or video that the public can use for personal purposes and that have more than one million users a month. Business-to-business tools, games, and pure upscaling or compression tools are excluded.
    Enforced by
    Attorney General, as an unfair trade practice; no private lawsuits.
    Law
    Public Act 26-15, section 15
  16. ConnecticutIn force since July 1, 2026

    Say in your privacy notice if you train AI on personal data

    Your privacy notice must state whether you collect, use or sell personal data to train large language models.

    Who
    Businesses covered by the Connecticut Data Privacy Act: those serving people in Connecticut that handle the data of at least 35,000 consumers, process sensitive data, or sell personal data. It protects people as consumers, not as workers.
    Enforced by
    Attorney General only, as an unfair trade practice; no private lawsuits.
    Law
    Connecticut Data Privacy Act, C.G.S. 42-520, as amended by Public Act 25-113

Coming up 7

  1. EUStarts December 2, 2026

    Do not offer or use AI that makes sexual deepfakes

    AI systems that create or alter realistic sexual or intimate images, video or audio of an identifiable person without their explicit consent, or child sexual abuse material, are banned. Providers are covered when this is the intended purpose or a foreseeable result their safeguards do not reliably prevent; users are covered when they use AI for this.

    Who
    Anyone who provides or uses such AI systems in the EU.
    Enforced by
    National authorities, or the EU AI Office for AI built on the provider’s own general-purpose AI model or in very large online platforms; fines up to €35 million or 7% of worldwide turnover, whichever is higher (for SMEs, whichever is lower).
    Law
    AI Act, Article 5(1)(ba) and (bb) and 5(1a) to (1b), inserted by Regulation (EU) 2026/1744 (Digital Omnibus on AI)
  2. CaliforniaStarts January 1, 2027

    Do not knowingly host AI models that skip hidden labels

    If your site or app offers generative AI model weights or source code for download, do not knowingly make available a system that does not add the hidden provenance data California requires.

    Who
    Generative AI hosting platforms, paid or free, that offer downloads to people in California.
    Enforced by
    Attorney General, city attorneys or county counsel; $5,000 per violation.
    Law
    Business and Professions Code section 22757.3.2 (AB 853, Chapter 674, Statutes of 2025)
  3. CaliforniaStarts January 1, 2027

    Do not train AI on students’ data from your school app

    If your website, service or app is designed or marketed for preschool, school or college use, do not use the student information it creates or gathers, including persistent identifiers, to train generative AI or develop any AI system. The rules for colleges start on July 1, 2027.

    Who
    Operators of education websites, services and apps that know they are used for school purposes in California, and companies working for them.
    Enforced by
    Students or parents who suffer damages can sue, also as a class, for their actual damages or $500 per violation, whichever is greater, after giving the operator 60 days’ written notice to fix it.
    Law
    AB 1159 (Chapter 182, Statutes of 2026), Business and Professions Code sections 22584, 22586 and 22587 and following
  4. ColoradoStarts January 1, 2027

    Explain automated decisions and offer a human review

    Before technology that processes personal data materially influences a decision about someone’s job, education, housing, financial or lending services, insurance, health care or essential government services, tell them clearly; a prominent notice where they apply is enough. After a bad outcome, explain its role within 30 days and, on request, let them correct their data and get a human review where commercially reasonable.

    Who
    Businesses in Colorado that use such technology in decisions about people in Colorado, including workers and job applicants. Developers that sell it must give users documentation and update notices; both keep records for 3 years.
    Enforced by
    Attorney General only, as a deceptive trade practice. Until January 1, 2030, a 60-day chance to fix after a warning, except for knowing or repeated violations. No new right to sue, but discrimination claims still apply.
    Law
    SB 26-189, which replaced the 2024 Colorado AI Act
  5. IllinoisStarts January 1, 2027

    Report frontier AI incidents and get yearly safety audits

    Large frontier AI developers must publish a safety framework, file disclosure statements with the state emergency management agency and send it regular summaries of catastrophic-risk assessments. Report critical safety incidents to that agency and the Attorney General within 72 hours, or 24 hours if lives are at risk. Yearly independent audits start on January 1, 2028.

    Who
    Developers of the largest frontier AI models. Staff who raise safety concerns get confidential reporting channels and whistleblower protection.
    Enforced by
    Civil penalties of up to $1 million for a first violation and $3 million for each later one.
    Law
    Artificial Intelligence Safety Measures Act (SB 315, signed July 6, 2026)
  6. New YorkStarts January 1, 2027

    Report frontier AI incidents within 72 hours

    If you develop frontier AI models, trained with more than 10²⁶ operations, publish a transparency report when you release a new model and report critical safety incidents to the state within 72 hours. Developers with over $500 million in yearly revenue must also write, follow and publish a frontier AI safety framework and file disclosures with a new office at the Department of Financial Services.

    Who
    Frontier AI developers whose models are developed, deployed or operated at least partly in New York. Accredited universities doing academic research are exempt.
    Enforced by
    Attorney General; up to $1 million for a first violation and $3 million for each later one. No private lawsuits.
    Law
    RAISE Act, General Business Law article 44-B, as replaced by Chapter 96 of 2026
  7. EUStarts December 2, 2027

    Certify HR AI as high-risk before you sell it

    If you sell AI for recruiting, promotion, firing, task allocation or monitoring workers, it must meet the high-risk requirements: risk management, data quality, documentation, logging, human oversight and accuracy. It must also pass a conformity assessment, carry the CE mark and be registered in the EU database.

    Who
    Providers placing such AI on the EU market, including companies that sell it under their own name or substantially change it.
    Enforced by
    National authorities; fines up to €15 million or 3% of worldwide turnover, whichever is higher (whichever is lower for SMEs and small mid-caps).
    Law
    AI Act, Articles 6(2), 8 to 17, 43 and 47 to 49, and Annex III point 4 (date moved by Regulation (EU) 2026/1744)

Next deadlines

The next rules to start, everywhere we track.

  1. European UnionDo not offer or use AI that makes sexual deepfakes
  2. European UnionPlatforms: keep humans in charge of algorithmic management
  3. CaliforniaSay in layoff notices when AI caused the cuts
  4. CaliforniaNo surveillance tools in workplace bathrooms
  5. CaliforniaDo not use AI to read workers’ emotions or neural data
  6. CaliforniaBig platforms must show whether content is AI-made

What this checker covers

We aim to list every rule that fits the scope below, and we say openly what is not in it yet.

Covered

  • Binding laws and regulations about AI, automated decisions, AI-made content, chatbots and AI developers.
  • Rules already in force, and rules that are law with a set start date.
  • Duties for businesses, employers, platforms and AI makers in the places listed above.
  • For Germany, France and Hungary: national rules that add to EU law, and who enforces the AI Act there.
  • A few general laws that are the main rule for an AI use in a country, marked “General law”.

Not covered yet

  • Rules for a single sector, such as health care, insurance, banking, elections or law firms.
  • Rules that bind only public bodies, such as government agencies, state schools or public broadcasters.
  • Bills that have not passed, official guidance and voluntary codes.
  • Most general laws that are not about AI but still apply to it, such as data protection, anti-discrimination or consumer law.
  • Other US states, and countries not listed above, including the United Kingdom.
  • National laws of EU countries other than Germany, France and Hungary.

How we check these rules

We read each rule in the official text, the law itself or the regulator’s own page, and link it. Where an earlier summary disagrees with the signed text, we follow the signed text. We last checked all 96 rules, from 69 official sources, on October 1, 2026.

Two notes on dates. California laws that set no start date of their own take effect on January 1 of the next year, so we list the bills signed in September 2026 from January 1, 2027. The EU dates follow the European Commission’s timeline, which includes the changes made by the 2026 Digital Omnibus; the article pages we link still show the 2024 wording.

One note on sources. Illinois’s legislature website could not be reached when we checked, so the Illinois entries rest on official summaries by the Governor, the Attorney General and state agencies. We will check them against the law texts as soon as the site is reachable.

For every AI law, bill, order and court ruling we have covered, including ones that are not yet in force, see the AI laws tracker and the AI calendar.

This is a plain-language guide, not legal advice. Laws have exceptions and details we leave out, and they change. Check the official text, or ask a lawyer, before you act. If you spot a mistake, tell us through the corrections policy.