Data tool
Which AI rules apply to me?
Pick where you work or sell and what you use AI for. You get the AI rules that apply, what they ask you to do and from when, with a link to the official text.
Your checklist
Choose one or more answers to each question. Each rule says what to do, who it is for, and who enforces it.
40 rules match your choices.
In force now 29
- In force since February 2, 2025
Do not use AI to read emotions at work or school
AI systems that infer people’s emotions are banned in workplaces and in schools and universities, except for medical or safety reasons.
- Who
- Anyone who provides or uses such AI in the EU, including employers and schools.
- Enforced by
- National authorities, enforcing since August 2, 2026; fines up to €35 million or 7% of worldwide turnover, whichever is higher (for SMEs, whichever is lower).
- Law
- AI Act, Article 5(1)(f)
Official text AI Act, Article 5 (EU AI Act Service Desk) - In force since February 2, 2025
Help your staff understand the AI they use
Take steps to support the AI literacy of staff and others who operate or use AI for you, suited to their knowledge and to how the AI is used. Since July 27, 2026 you no longer have to guarantee a particular skill level.
- Who
- Providers and deployers of AI systems in the EU, which includes any business using AI at work.
- Enforced by
- National authorities; the AI Act sets no EU-wide fine for this duty, so penalties come from national law.
- Law
- AI Act, Article 4, as replaced by Regulation (EU) 2026/1744
Official text AI Omnibus enters into force (European Commission) - In force since February 2, 2025
Do not use AI social scores to treat people unfairly
AI that scores people over time on their social behaviour or personal traits is banned when the score leads to unjustified or disproportionate harm, or to harm in a context unrelated to where the data came from. Ordinary performance reviews are usually not social scoring.
- Who
- Anyone who provides or uses such AI in the EU, including private companies.
- Enforced by
- National authorities, enforcing since August 2, 2026; fines up to €35 million or 7% of worldwide turnover, whichever is higher (for SMEs, whichever is lower).
- Law
- AI Act, Article 5(1)(c)
Official text AI Act, Article 5 (EU AI Act Service Desk) - In force since February 2, 2025
Do not use AI to predict crime from profiling alone
AI that assesses or predicts the risk that a person will commit a crime based solely on profiling, or on their personality traits, is banned. AI that supports a human assessment already based on objective, verifiable facts is allowed.
- Who
- Anyone who provides or uses such AI in the EU, including private companies.
- Enforced by
- National authorities, enforcing since August 2, 2026; fines up to €35 million or 7% of worldwide turnover, whichever is higher (for SMEs, whichever is lower).
- Law
- AI Act, Article 5(1)(d)
Official text AI Act, Article 5 (EU AI Act Service Desk) - In force since February 2, 2025
Do not use biometrics to guess race, religion or union ties
AI that sorts individual people by biometric data, such as face or voice, to infer their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation is banned.
- Who
- Anyone who provides or uses such AI in the EU, including employers.
- Enforced by
- National authorities, enforcing since August 2, 2026; fines up to €35 million or 7% of worldwide turnover, whichever is higher (for SMEs, whichever is lower).
- Law
- AI Act, Article 5(1)(g)
Official text AI Act, Article 5 (EU AI Act Service Desk) - In force since August 2, 2026
Tell people when you use emotion or biometric AI on them
If you use AI that recognises emotions or sorts people into categories from biometric data, inform the people exposed to it and handle their data under the GDPR. Emotion recognition at work or school is banned anyway, except for medical or safety reasons.
- Who
- Businesses and organisations that use such systems in the EU.
- Enforced by
- National authorities; fines up to €15 million or 3% of worldwide turnover, whichever is higher (whichever is lower for SMEs and small mid-caps).
- Law
- AI Act, Article 50(3)
Official text AI Act, Article 50 (EU AI Act Service Desk) - In force since May 25, 2018
Do not let AI alone make big decisions about people
People have the right not to be subject to decisions made solely by automated processing, including profiling, with legal or similarly significant effects, such as automatically rejecting a job application. Such decisions are allowed only when needed for a contract, authorised by law or with explicit consent, and then people get human intervention, a way to contest and meaningful information about the logic.
- Who
- Any organisation processing personal data in the EU, or of people in the EU, including employers and schools.
- Enforced by
- National data protection authorities; fines up to €20 million or 4% of worldwide turnover, whichever is higher.
- Law
- GDPR (Regulation (EU) 2016/679), Article 22, with Articles 13 to 15
Official text GDPR, Regulation (EU) 2016/679 (EUR-Lex) - In force since August 2, 2026
Explain decisions made with high-risk AI when asked
Some AI counts as high-risk, such as AI for hiring, managing staff, education, credit or essential services. If a decision based on it seriously affects someone, they can ask you to explain the AI’s role and the main reasons for the decision, and you must answer clearly. The AI Act’s other duties for this AI start on December 2, 2027.
- Who
- Businesses and organisations in the EU that use such AI to decide about people. It applies where other EU law, such as the GDPR, does not already give this right.
- Enforced by
- National authorities; the AI Act sets no EU-wide fine for this right, so penalties come from national law (in Germany, up to €50,000).
- Law
- AI Act, Article 86, with Annex III
Official text AI Act, Article 86 (EU AI Act Service Desk) - In force since August 2, 2026
Explain high-risk AI decisions, or Germany can fine you
Germany backs the EU right to an explanation with its own fine. If a decision based on high-risk AI, for example in hiring, staff management, education or credit, seriously affects someone and they ask, explain the AI’s role and the main reasons. Failing to do so can cost up to €50,000. The EU has moved most other high-risk duties to December 2, 2027.
- Who
- Businesses and other private organisations using high-risk AI in Germany, such as employers, private schools and lenders. Public bodies cannot be fined.
- Enforced by
- Federal Network Agency (Bundesnetzagentur) in most cases, BaFin for finance and state authorities for the media; fines up to €50,000.
- Law
- KI-MIG (KI-Marktüberwachungs-und-Innovationsförderungs-Gesetz), sections 15(2), 15(3) and 17, with AI Act Article 86
Official text KI-MIG (Gesetze im Internet) - In force since June 18, 2021
Tell the works council early about planned AI
If your workplace has a works council (Betriebsrat), inform it in good time, with the documents it needs, when you plan work processes that use AI. Discuss the effects on staff early enough that its suggestions can still change the plan.
- Who
- Private employers in Germany that have a works council.
- Enforced by
- Labour courts; fines up to €10,000 for information that is missing, wrong, incomplete or late (section 121). Obstructing the works council is a crime (section 119).
- Law
- Works Constitution Act (Betriebsverfassungsgesetz), section 90(1) no. 3 and (2), as amended in 2021
Official text Works Constitution Act, section 90 (Gesetze im Internet) - In force since June 18, 2021
Let the works council bring in an AI expert
When your works council has to assess the introduction or use of AI, the law treats calling in an outside expert as necessary, so you cannot refuse on the ground that one is not needed. You still agree on the details, and you can agree on a standing AI expert.
- Who
- Private employers in Germany that have a works council.
- Enforced by
- Labour courts. Obstructing the works council is a crime (section 119).
- Law
- Works Constitution Act, section 80(3), as amended in 2021
Official text Works Constitution Act, section 80 (Gesetze im Internet) - In force since June 18, 2021
Get works council consent for AI-made selection rules
General rules for choosing whom to hire, transfer, regrade or dismiss need your works council’s consent, also when AI is used to draw them up. In businesses with more than 500 employees, the works council can demand such rules. If you cannot agree, a conciliation board decides.
- Who
- Private employers in Germany that have a works council.
- Enforced by
- A conciliation board (Einigungsstelle) settles disputes, and labour courts enforce.
- Law
- Works Constitution Act, section 95(1), (2) and (2a), as amended in 2021
Official text Works Constitution Act, section 95 (Gesetze im Internet) - In force since January 19, 1972
Agree with the works council before AI that tracks staff
You need your works council’s agreement before you introduce or use technical systems designed to monitor how employees behave or perform, which includes AI tools that log or analyse staff activity. If you cannot agree, a conciliation board decides.
- Who
- Private employers in Germany that have a works council.
- Enforced by
- A conciliation board settles disputes, and labour courts can stop a system introduced without agreement. Obstructing the works council is a crime (section 119).
- Law
- Works Constitution Act, section 87(1) no. 6 and (2)
Official text Works Constitution Act, section 87 (Gesetze im Internet) - In force since January 1, 2018
Consult the works council before rolling out AI at work
Inform and consult your works council (CSE) before introducing new technologies such as AI tools, and on changes that affect staff numbers, organisation or working conditions.
- Who
- Employers in France with at least 50 employees and a works council (comité social et économique).
- Enforced by
- Obstructing the works council is a crime, with a fine of up to €7,500 (article L2317-1).
- Law
- Labour Code (Code du travail), article L2312-8
Official text Labour Code, article L2312-8 (Code du travail numérique) - In force since January 1, 2018
Tell the works council before AI hiring or tracking tools
Inform your works council before you use recruitment-assistance methods or automated staff-management systems, and before changing them. Inform and consult it before deciding to deploy any tool that can monitor employees’ activity.
- Who
- Employers in France with at least 50 employees and a works council.
- Enforced by
- Obstructing the works council is a crime, with a fine of up to €7,500 (article L2317-1).
- Law
- Labour Code, article L2312-38
Official text Labour Code, article L2312-38 (Code du travail numérique) - In force since May 1, 2008
Tell job candidates before using AI to assess them
Before using any recruitment method or technique on candidates, including AI tools, tell them which ones you will use. Methods must be relevant to the job, results stay confidential, and no data may be collected through a tool they were not told about.
- Who
- All employers and recruiters in France, of any size.
- Enforced by
- These articles set no penalty of their own.
- Law
- Labour Code, articles L1221-8 and L1221-9
Official text Labour Code, article L1221-8 (Code du travail numérique) - In force since May 1, 2008
Tell staff before any AI tool collects data about them
No information about an individual employee may be collected by a device or tool they were not told about beforehand, including AI monitoring and analytics tools.
- Who
- All employers in France.
- Enforced by
- This article sets no penalty of its own.
- Law
- Labour Code, article L1222-4
Official text Labour Code, article L1222-4 (Code du travail numérique) - In force since June 1, 2019
Explain your automated decision rules when asked
A decision with legal or similarly significant effects on someone may rest solely on automated processing only in the GDPR’s contract and explicit-consent cases. Then, if the person asks, you must tell them the rules that define the processing and its main characteristics, except secrets protected by law.
- Who
- Any organisation in France that takes solely automated decisions about people. Public bodies have stricter duties.
- Enforced by
- The data protection authority (CNIL); fines up to €20 million or 4% of worldwide turnover, whichever is higher.
- Law
- Data Protection Act (Loi Informatique et Libertés, law no. 78-17), article 47
Official text Data Protection Act, article 47 (CNIL) - In force since January 1, 2025
Spell out digital replica uses in performer contracts
A contract term can let a digital replica of a person’s voice or likeness replace work they would have done in person. Such a term is unenforceable if it lacks a reasonably specific description of the uses and the person had no lawyer or union negotiating for them.
- Who
- Anyone contracting with a person in California for personal or professional services, such as actors, voice artists and creators. It covers new performances fixed from January 1, 2025.
- Enforced by
- No regulator or fine; such a term cannot be enforced.
- Law
- AB 2602 (Chapter 259, Statutes of 2024), Labor Code section 927
Official text AB 2602 (California Legislature) - In force since October 1, 2025
Do not let AI tools discriminate; keep their data 4 years
Using an automated decision system that discriminates against job applicants or workers is unlawful, even when a vendor runs it for you. Keep the system’s data with your employment records for four years. Evidence of anti-bias testing can count for or against you.
- Who
- Employers covered by California’s Fair Employment and Housing Act, usually those with 5 or more employees, plus employment agencies and unions.
- Enforced by
- Civil Rights Department complaints and lawsuits under the Fair Employment and Housing Act; damages rather than a fixed fine.
- Law
- Civil Rights Council regulations, California Code of Regulations title 2, sections 11008.1, 11009(f) and 11013(c)
Official text Automated-decision systems regulations (California Civil Rights Department) - In force since January 1, 2026
Do a risk assessment before using AI to judge people
Do and document a privacy risk assessment, and review it at least every three years, before you use automated decision-making for significant decisions such as jobs, loans, housing, education or health care. The same applies to automated tools that infer workers’, students’ or applicants’ performance, health, behaviour or location from systematic observation, and to training such tools or face recognition on personal data. Uses that began before 2026 need one by December 31, 2027.
- Who
- Businesses covered by the California Consumer Privacy Act.
- Enforced by
- California Privacy Protection Agency or the Attorney General: up to $2,663 per violation, or $7,988 if intentional (2025 amounts).
- Law
- CCPA regulations, California Code of Regulations title 11, sections 7150, 7155 and 7157
Official text CCPA regulations (California Privacy Protection Agency) - In force since October 1, 2026
Say whether AI played a part in mass layoffs
When you file a federal mass-layoff (WARN) notice, also tell the Connecticut Labor Department whether the layoffs are related to your use of AI or another technological change.
- Who
- Employers that must file a federal WARN notice, usually those with 100 or more workers.
- Enforced by
- Connecticut Labor Department, in the form the Labor Commissioner sets. The act sets no penalty.
- Law
- Public Act 26-15, section 26
- In force since October 1, 2026
An AI tool is no excuse for discrimination
If an automated tool helps make a job decision, its use is no defence against a discrimination complaint. Evidence of anti-bias testing can be taken into account.
- Who
- Employers in Connecticut.
- Enforced by
- Commission on Human Rights and Opportunities and the courts.
- Law
- Public Act 26-15, sections 13 and 14 (amending C.G.S. 46a-60(b)(1) and 46a-81c)
- In force since October 1, 2026
Post signs if you use face recognition on your premises
If you use face recognition on your premises against security threats, fraud or crime, match faces only against your own database. Post clearly legible signs at each public entrance saying it is in use, with a link or QR code to your face recognition policy, which must give the Attorney General’s contact details.
- Who
- Businesses covered by the Connecticut Data Privacy Act: those serving people in Connecticut that handle the data of at least 35,000 consumers, process sensitive data, or sell personal data. It protects people as consumers, not as workers.
- Enforced by
- Attorney General only, as an unfair trade practice; no private lawsuits.
- Law
- Public Act 26-64, section 16 (C.G.S. 42-524)
Official text Public Act 26-64 (Connecticut General Assembly) - In force since January 1, 2026
Do not let AI discriminate at work, and say you use it
Do not use AI in recruiting, hiring, promotion, training, discipline, firing or other job decisions in a way that leads to discrimination against protected groups, even if unintended. Do not use ZIP codes as a stand-in for them, and tell employees when you use AI for these decisions.
- Who
- Employers with at least one employee in Illinois on each working day of 20 or more weeks this year or last. Draft rules on the notice were withdrawn in June 2026, so its exact form is not yet set.
- Enforced by
- Illinois Department of Human Rights: a worker or applicant can file a charge within 2 years, and the case then goes to the Human Rights Commission or a court. Remedies include damages, hiring or reinstatement, back pay and legal fees.
- Law
- Illinois Human Rights Act, 775 ILCS 5/2-102(L), added by Public Act 103-0804 (HB 3773)
Official text Labor Day Report 2026, page 17 (Illinois Attorney General) - In force since January 1, 2020
Get consent before AI analyses video job interviews
Before AI analyses an applicant’s recorded video interview, tell them AI may be used and get their consent. If you rely only on AI to decide who gets an in-person interview, report the race and ethnicity of the people interviewed and hired to the state every year.
- Who
- Employers that use AI to analyse video interviews for jobs based in Illinois.
- Enforced by
- The Department of Commerce and Economic Opportunity collects the yearly reports; the official summaries name no fine.
- Law
- Artificial Intelligence Video Interview Act, 820 ILCS 42 (HB 2557 of 2019; yearly reports added by HB 53 of 2021, from January 1, 2022)
Official text Governor’s bill actions, August 9, 2019 (State of Illinois) - In force since August 9, 2024
Describe AI replica uses clearly in performer contracts
A contract clause that allows a digital replica of a person’s voice or likeness is invalid if it does not clearly describe the intended uses and the person had no lawyer or union representing them.
- Who
- Anyone contracting with performers or other individuals in Illinois for their voice or likeness.
- Enforced by
- No regulator or fine; such a clause cannot be enforced.
- Law
- Digital Voice and Likeness Protection Act (HB 4762 of 2024)
Official text AI Task Force report, December 2024 (Illinois Department of Innovation and Technology) - In force since January 1, 2025
Spell out digital replica terms in performer contracts
A contract clause can let you use a digital replica of a person’s voice or likeness instead of work they would have done in person. Such a clause is void if it does not describe the intended uses reasonably specifically, unless the person had a lawyer or a union contract covering such replicas.
- Who
- Any business contracting with a person for personal or professional services in New York, such as actors, voice artists and creators. It applies to contracts made or changed from January 1, 2025.
- Enforced by
- No regulator or fine; such a clause cannot be enforced.
- Law
- General Obligations Law section 5-302
Official text General Obligations Law section 5-302 (New York State Senate) - In force since July 5, 2023
Audit AI hiring tools for bias and tell candidates
Before you use an automated tool to screen job candidates or employees for promotion, have an independent bias audit done within the past year and post a summary of the results on your website. Tell candidates and employees who live in New York City at least 10 business days before use, including what the tool will assess and how to ask for an alternative process or accommodation.
- Who
- Employers and employment agencies using such tools for jobs in New York City.
- Enforced by
- Department of Consumer and Worker Protection; up to $500 for a first violation and $500 to $1,500 for each later one. Each day of non-compliant use counts as a separate violation.
- Law
- Local Law 144 of 2021 (Administrative Code 20-870 to 20-874)
Official text Automated employment decision tools (NYC Department of Consumer and Worker Protection)
Coming up 11
- Starts December 2, 2026
Platforms: keep humans in charge of algorithmic management
Gig-work platforms must explain their automated monitoring and decision systems to the people working through them, keep them under human oversight, and not use them to process data such as emotional state, private conversations or union activity. Only a human may decide to restrict, suspend or close a worker’s account. EU countries must put this into national law by December 2, 2026.
- Who
- Digital labour platforms, such as ride-hailing or delivery apps, organising work in the EU. The data and human-review rules also protect self-employed platform workers.
- Enforced by
- Under each country’s national law; data protection authorities can fine breaches of the data rules at GDPR levels.
- Law
- Platform Work Directive (EU) 2024/2831, Articles 7 to 15 (deadline for national laws)
Official text Platform Work Directive (EU) 2024/2831 (EUR-Lex) - Starts January 1, 2027
Say in layoff notices when AI caused the cuts
If a mass layoff, relocation or closure is caused wholly or substantially by AI or other automation, the 60-day notice must say so under the line “This notice is for a technology displacement”. It must give the number, job type and work location of those jobs, the tasks that will be automated and the kind of technology used.
- Who
- Employers with a California site that has employed 75 or more people in the past year.
- Enforced by
- Existing Cal/WARN remedies, as SB 951 adds no new penalty: workers not given notice are owed back pay and benefits for up to 60 days, and a missing notice to officials can cost up to $500 a day. Workers, unions and local governments can sue.
- Law
- SB 951 (Chapter 860, Statutes of 2026), Labor Code section 1401
Official text SB 951 (California Legislature) - Starts January 1, 2027
No surveillance tools in workplace bathrooms
Employers may not use surveillance tools to monitor workers in workplace bathrooms, except under a court order, and workers may leave such tools behind when they go in. Simple badges or alarms without audio, video or built-in AI are allowed.
- Who
- All California employers, public and private.
- Enforced by
- Labor Commissioner and public prosecutors; up to $500 per violation.
- Law
- AB 1331 (Chapter 851, Statutes of 2026), Labor Code sections 1560 to 1565
Official text AB 1331 (California Legislature) - Starts January 1, 2027
Do not use AI to read workers’ emotions or neural data
Employers may not use AI-powered workplace surveillance tools to recognise, infer or predict workers’ emotional state, or to collect neural data, meaning measurements of the nervous system. Tools used to keep people safe are not banned.
- Who
- All California employers, public and private.
- Enforced by
- Labor Commissioner, public prosecutors or the worker; up to $500 per violation.
- Law
- AB 1883 (Chapter 853, Statutes of 2026), Labor Code sections 1580 to 1583
Official text AB 1883 (California Legislature) - Starts January 1, 2027
Give notice and an opt-out before automated decisions
If software makes significant decisions about people without real human involvement, such as hiring, pay, promotion, firing or school admissions, give a notice before use, offer an opt-out, and explain the logic and result on request. In most cases an appeal to a human who can overturn the decision can replace the opt-out.
- Who
- Businesses covered by the California Consumer Privacy Act, such as those with over $26,625,000 in yearly revenue or that buy, sell or share data on 100,000 or more consumers.
- Enforced by
- California Privacy Protection Agency or the Attorney General: up to $2,663 per violation, or $7,988 if intentional (2025 amounts).
- Law
- CCPA regulations, California Code of Regulations title 11, sections 7200 and 7220 to 7222
Official text CCPA regulations (California Privacy Protection Agency) - Starts January 1, 2027
Explain automated decisions and offer a human review
Before technology that processes personal data materially influences a decision about someone’s job, education, housing, financial or lending services, insurance, health care or essential government services, tell them clearly; a prominent notice where they apply is enough. After a bad outcome, explain its role within 30 days and, on request, let them correct their data and get a human review where commercially reasonable.
- Who
- Businesses in Colorado that use such technology in decisions about people in Colorado, including workers and job applicants. Developers that sell it must give users documentation and update notices; both keep records for 3 years.
- Enforced by
- Attorney General only, as a deceptive trade practice. Until January 1, 2030, a 60-day chance to fix after a warning, except for knowing or repeated violations. No new right to sue, but discrimination claims still apply.
- Law
- SB 26-189, which replaced the 2024 Colorado AI Act
Official text SB 26-189 (Colorado General Assembly) - Starts July 1, 2027
Do not discipline or fire workers by software alone
Do not rely solely on an automated decision system to discipline or fire. If you rely mainly on one, a human must corroborate the result, and the worker gets a written notice when told of the decision. Such systems also may not be used to infer protected traits, and workers can ask for their own data.
- Who
- Employers in California, including public employers such as cities and counties. It protects employees, not job applicants.
- Enforced by
- Labor Commissioner and public prosecutors; $500 per violation.
- Law
- SB 947, the No Robo Bosses Act of 2026 (Chapter 859, Statutes of 2026), Labor Code sections 1520 to 1526.7
- Starts October 1, 2027
Tell people when an AI tool helps decide about their job
If an automated tool is a substantial factor in a job decision, give the person a written notice before the decision. Tell people in plain language when they are interacting with such a tool.
- Who
- Businesses in Connecticut, such as employers, recruiters and staffing firms, that use automated tools in job decisions about Connecticut staff or applicants. Developers of tools sold for job decisions must give users the information they need.
- Enforced by
- Attorney General only, as an unfair trade practice. For violations up to December 31, 2027, the Attorney General may first give 60 days to fix them. No private lawsuits.
- Law
- Public Act 26-15, sections 7 to 12
- Starts December 2, 2027
AI for hiring and managing staff becomes “high-risk”
Employers using AI to recruit, manage or evaluate workers must follow its instructions, have trained people oversee it and keep its logs for at least six months. They must inform workers and their representatives before using it, and tell candidates and staff when it is used in decisions about them. AI types already on the market before then are covered only after a significant design change.
- Who
- Employers and other organisations that use such AI in the EU.
- Enforced by
- National authorities; fines up to €15 million or 3% of worldwide turnover, whichever is higher (whichever is lower for SMEs and small mid-caps).
- Law
- AI Act, Article 26 and Annex III (date moved by the 2026 Digital Omnibus)
Official text AI Act overview (European Commission) - Starts December 2, 2027
Check HR AI against the high-risk rules before you sell it
If you sell AI for recruiting, promotion, firing, task allocation or monitoring workers, it must meet the high-risk requirements: risk management, data quality, documentation, logging, human oversight and accuracy. It must also pass a conformity assessment, carry the CE mark and be registered in the EU database.
- Who
- Providers placing such AI on the EU market, including companies that sell it under their own name or substantially change it.
- Enforced by
- National authorities; fines up to €15 million or 3% of worldwide turnover, whichever is higher (whichever is lower for SMEs and small mid-caps).
- Law
- AI Act, Articles 6(2), 8 to 17, 43 and 47 to 49, and Annex III point 4 (date moved by Regulation (EU) 2026/1744)
Official text AI Act overview (European Commission) - Starts December 2, 2027
Treat face recognition and emotion AI as high-risk
This covers AI that identifies people remotely from their face or other biometrics, sorts them by sensitive or protected traits, or recognises emotions, where such uses are not banned. If you use it, follow the maker’s instructions, have trained staff oversee it, keep its logs and tell the people exposed to it. Simple ID checks that only confirm a person is who they claim to be are excluded.
- Who
- Businesses and organisations using such AI in the EU, such as shops, venues and security firms; the makers must pass a conformity assessment before selling it. AI on the market before then is covered only after a significant design change.
- Enforced by
- National authorities; fines up to €15 million or 3% of worldwide turnover, whichever is higher (whichever is lower for SMEs and small mid-caps).
- Law
- AI Act, Annex III point 1 and Article 26 (date set by Regulation (EU) 2026/1744)
Official text AI Act, Annex III (EU AI Act Service Desk)
Next deadlines
The next rules to start, everywhere we track.
- European UnionDo not offer or use AI that makes sexual deepfakes
- European UnionPlatforms: keep humans in charge of algorithmic management
- CaliforniaSay in layoff notices when AI caused the cuts
- CaliforniaNo surveillance tools in workplace bathrooms
- CaliforniaDo not use AI to read workers’ emotions or neural data
- CaliforniaBig platforms must show whether content is AI-made
What this checker covers
We aim to list every rule that fits the scope below, and we say openly what is not in it yet.
Covered
- Binding laws and regulations about AI, automated decisions, AI-made content, chatbots and AI developers.
- Rules already in force, and rules that are law with a set start date.
- Duties for businesses, employers, platforms and AI makers in the places listed above.
- For Germany, France and Hungary: national rules that add to EU law, and who enforces the AI Act there.
- A few general laws that are the main rule for an AI use in a country, marked “General law”.
Not covered yet
- Rules for a single sector, such as health care, insurance, banking, elections or law firms.
- Rules that bind only public bodies, such as government agencies, state schools or public broadcasters.
- Bills that have not passed, official guidance and voluntary codes.
- Most general laws that are not about AI but still apply to it, such as data protection, anti-discrimination or consumer law.
- Other US states, and countries not listed above, including the United Kingdom.
- National laws of EU countries other than Germany, France and Hungary.
How we check these rules
We read each rule in the official text, the law itself or the regulator’s own page, and link it. Where an earlier summary disagrees with the signed text, we follow the signed text. We last checked all 96 rules, from 69 official sources, on October 1, 2026.
Two notes on dates. California laws that set no start date of their own take effect on January 1 of the next year, so we list the bills signed in September 2026 from January 1, 2027. The EU dates follow the European Commission’s timeline, which includes the changes made by the 2026 Digital Omnibus; the article pages we link still show the 2024 wording.
One note on sources. Illinois’s legislature website could not be reached when we checked, so the Illinois entries rest on official summaries by the Governor, the Attorney General and state agencies. We will check them against the law texts as soon as the site is reachable.
For every AI law, bill, order and court ruling we have covered, including ones that are not yet in force, see the AI laws tracker and the AI calendar.
This is a plain-language guide, not legal advice. Laws have exceptions and details we leave out, and they change. Check the official text, or ask a lawyer, before you act. If you spot a mistake, tell us through the corrections policy.