AI Regulation Tracker — bylok.ink/tracker — updated 2026-07-31 China ===== - [announced] New TC260 AI standard projects launched July 2026 (safety guardrails, anthropomorphic interaction, assessment bodies, AI agents) (TC260, 2026-07-31): On 2026-07-31 TC260 opened recruitment of drafting participants (征集参编单位) for four new AI security standards: technical requirements for AI safety guardrails, basic security requirements for anthropomorphic (companion-style) AI interaction services, capability requirements for AI security assessment/testing bodies, and data-security requirements for AI agent data processing. Together with the classification/grading draft and the 2026-07-10 kickoff of six AI application security guiding technical documents, these signal the 2026-2027 direction of Chinese AI standardization: agents, companion AI, evaluation infrastructure, and runtime guardrails. All are at project stage with no legal effect yet. https://www.tc260.org.cn/portal/article/2/c881228595f540e49abd4ee28a6a344d - [news] Qinglang 2026 Minors Online Protection campaign targets AI-generated content harming minors (Central Cyberspace Affairs Commission Office (Central CAC), 2026-07-20): A four-month, two-phase campaign on minors' online protection (phase 1 on the summer online environment, phase 2 on platform behavior) with unusually prominent AI-specific targets: AI parodies of classic animated characters that amplify violent and frightening elements, batch-produced sensationalist AI short dramas that mislead minors, AI apps that create inappropriate personas and output suggestive or vulgar content, and merchants offering AI face-swapping tools that teach minors to defeat facial-recognition checks. Read together with the anthropomorphic AI measures effective five days earlier, it shows minors-facing AI services are the immediate enforcement priority. https://www.cac.gov.cn/2026-07/20/c_1786294052406609.htm - [news] Agreement establishing the World AI Cooperation Organization signed in Shanghai (Ministry of Foreign Affairs / intergovernmental (29 founding states), 2026-07-16): Representatives of 29 founding member states — including Russia, Pakistan, Indonesia, Kazakhstan and Laos — signed the agreement establishing the World Artificial Intelligence Cooperation Organization, an intergovernmental body headquartered in Shanghai. Foreign Minister Wang Yi signed for China; UN Secretary-General Guterres attended. The organization commits to promoting international AI cooperation and global governance under UN Charter principles so that AI develops in a human-centered direction beneficial to all. It institutionalizes China's alternative pole in global AI governance, one year after the idea was floated at WAIC 2025. https://www.mfa.gov.cn/wjbzhd/202607/t20260716_11984399.shtml - [in_force] Interim Measures for the Administration of AI Anthropomorphic Interaction Services (CAC, NDRC, MIIT, Ministry of Public Security, SAMR (CAC Order No. 21), 2026-07-15): The newest link in the CAC regulatory chain (algorithms → deep synthesis → generative AI → anthropomorphic interaction), targeting AI companion, roleplay, and other continuous emotional-interaction services that simulate a natural person's personality traits, thinking patterns, and communication styles. It addresses emotional dependence, manipulation, and harm to minors and the elderly, adding crisis-intervention duties for extreme scenarios such as suicide risk. Adopted 2026-02-02, published 2026-04-10, effective 2026-07-15 — in force as of late July 2026. Ordinary customer-service or education tools without an emotional-interaction component are outside scope. https://www.cac.gov.cn/2026-04/10/c_1777558395078289.htm - [draft] Draft national standard: Cybersecurity Technology — Classification and Grading Method for AI Application Security (TC260, 2026-07-15): Draft recommended national standard released for public comment on 2026-07-15 that would translate the AI Safety Governance Framework 2.0's risk-grading concept into a formal method for classifying and grading AI applications by security risk. If finalized, it would likely become the reference for tiered regulatory treatment of AI applications. Currently a draft with no legal effect. https://www.tc260.org.cn/portal/suggestion-detail/c8801e1c45954e098355a334d703a003 - [in_force] Interim Measures for the Administration of Anthropomorphic AI Interactive Services (CAC, NDRC, MIIT, Ministry of Public Security, SAMR, 2026-07-15): China's first dedicated rules for 'human-like' AI companion and emotional-interaction services — chatbots that simulate a natural person's personality, thinking patterns and communication style in sustained emotional interaction. Providers must run pre-launch and threshold-triggered security assessments, label AI output, protect minors, curb addictive use, and give users rights to copy or delete chat histories, with limits on sharing interaction data and on training with minors' sensitive data. Widely read as the fourth sector-specific pillar of the CAC's AI rulebook after the algorithm recommendation, deep synthesis and generative AI measures. https://www.cac.gov.cn/2026-04/10/c_1777558395078289.htm - [news] CAC Announcement of Filed Generative AI Services (May-June 2026): 988 services filed, 598 apps registered (CAC, 2026-07-10): Latest bimonthly disclosure of the generative AI filing regime's scale: 120 new services filed nationally and 68 new apps/functions registered locally in May-June 2026, bringing cumulative totals to 988 filed generative AI services and 598 registered AI apps/functions as of 2026-06-30. The announcement reiterates that platforms offering AI apps/functions must display the underlying filed model's name and filing number. Useful as the current headline figure for the tracker. https://www.cac.gov.cn/2026-07/10/c_1785427810632554.htm - [news] Phase 1 results of the Qinglang AI Application Chaos campaign: 14,000+ AI products handled (Central Cyberspace Affairs Commission Office (Central CAC), 2026-07-06): The Central CAC reported first-phase enforcement results of the 2026 AI campaign: over 14,000 violating AI websites, apps and agents disposed of, more than 6 million pieces of illegal content removed, 26,000+ accounts handled, 1,300+ violating AI products delisted and 9 non-compliant open-source datasets taken down. Targeted violations were failure to complete large-model filing, inadequate platform safety and review/filtering capacity, and AI data poisoning, among others. This is the largest disclosed enforcement wave to date under China's AI rules; phase 2 shifts to AI-generated content harms. https://www.chinanews.com.cn/gn/2026/07-06/10653724.shtml - [announced] Artificial Intelligence Law (comprehensive national AI law) — status: no official draft ever published (State Council / NPC Standing Committee (legislative project), 2026-05-11): China's much-discussed comprehensive AI Law remains a legislative project with no draft text ever released by the NPC or the State Council as of July 2026. It appeared as a draft 'to be prepared for submission to the NPCSC' in the State Council's 2023 and 2024 legislative work plans and was downgraded to generic 'advance AI healthy-development legislation' language in 2025. On May 11, 2026 the State Council's plan escalated to 'accelerate comprehensive legislation for the healthy development of AI', while the NPCSC's same-day plan still lists AI only among items for research and drafting — no draft is scheduled for deliberation. https://npcobserver.com/2026/05/11/china-npc-2026-legislative-plan/ - [announced] State Council 2026 Annual Legislative Work Plan ('accelerate comprehensive AI legislation') (State Council General Office, 2026-05-11): The 2026 plan calls to 'improve AI governance and accelerate comprehensive legislation for the healthy development of AI', and to accelerate legislation safeguarding AI's common elements — data, computing power, algorithms, property rights, cybersecurity, and supply-chain security — as well as regulating key application scenarios. The shift from 2025's 'advance' to 2026's 'accelerate comprehensive legislation' is read by observers as the strongest signal since 2024 that a unified instrument is moving again, though still with no draft scheduled or published. https://www.gov.cn/zhengce/zhengceku/202605/content_7068346.htm - [announced] NPC Standing Committee 2026 Legislative Work Plan (AI remains a preparatory/research item) (NPC Standing Committee, 2026-05-11): The NPCSC's 2026 work plan, released May 11, 2026, again includes legislative projects on 'the healthy development of artificial intelligence' among items for research and drafting by relevant bodies rather than among titled projects scheduled for deliberation. No AI Law draft is scheduled for initial deliberation — the third consecutive year in which AI legislation is flagged without a bill. https://npcobserver.com/2026/05/11/china-npc-2026-legislative-plan/ - [in_force] China (Beijing) Pilot FTZ and National Demonstration Zone for Expanded Opening of the Services Sector — Data Export Negative List (2025 Edition) and Administrative Measures (Beijing Municipal Cyberspace Administration, Bureau of Commerce, and Government Services & Data Administration, 2026-05-11): Issued 11 May 2026, this update extends the negative-list mechanism beyond the FTZ to the national services-sector demonstration zone, whose designation covers Beijing's entire territory — reported as the first extension of FTZ negative-list treatment to a full province-level jurisdiction. The list grows to 9 sectors and 67 business scenarios ('1 set of measures + 9 sector lists'), newly adding autonomous driving/intelligent connected vehicles among four new sectors — a significant liberalization for AI and AV data exports. https://zwfwj.beijing.gov.cn/zwgk/2024zcwj/202605/t20260511_4645606.html - [in_force] Hangzhou Regulations on Promoting the Development of the Embodied Intelligent Robot Industry (Hangzhou Municipal People's Congress Standing Committee (approved by Zhejiang Provincial People's Congress Standing Committee), 2026-05-01): China's first local law on embodied AI robots: adopted by Hangzhou's legislature 29 December 2025, approved by Zhejiang province 26 March 2026, and effective 1 May 2026. Squarely promotion-oriented — seven chapters covering technology innovation, infrastructure, industry cultivation and application scenarios — with an added safety-management chapter that explores a robot coding/identification management system. https://hznews.hangzhou.com.cn/chengshi/content/2026-04/16/content_9207037.htm - [announced] NPC Standing Committee 2026 Legislative Work Plan lists 'healthy AI development' legislation as a preparatory item (NPC Standing Committee, 2026-05): The NPC Standing Committee's 2026 legislative work plan lists legislative projects on 'governance of online violence and the healthy development of artificial intelligence' among its preparatory review items (预备审议项目), directing relevant bodies to advance research and drafting. This confirms a comprehensive AI Law remains on the agenda but is still in the research-and-drafting stage with no first reading scheduled for 2026 — near-term rulemaking continues via targeted instruments like the anthropomorphic AI measures. https://www.jsrd.gov.cn/qgrd/202605/t20260526_1332768.shtml - [announced] Guangdong 2026 Legislative Plan: proposed AI Development Promotion Regulations (Guangdong Provincial People's Congress Standing Committee, 2026-04-30): Guangdong's 2026 legislative plan, reported 30 April 2026 by Yangcheng Evening News, includes drafting a provincial AI Development Promotion Regulation as the centerpiece of its modern-industrial-system legislation — which would be among the first comprehensive AI promotion statutes by an ordinary (non-municipality) province. The same reporting describes companion projects on data, the low-altitude economy, intelligent connected vehicles and talent, plus municipal items: Guangzhou plans its own AI development promotion regulation and Shenzhen plans brain-computer interface industry legislation. https://baijiahao.baidu.com/s?id=1863864838371586094 - [news] Qinglang Special Campaign to Rectify AI Application Chaos (launch) (Central Cyberspace Affairs Commission Office (Central CAC), 2026-04-30): A four-month, two-phase enforcement campaign against AI applications, successor to the 2025 'AI technology abuse' campaign. Phase 1 targets seven categories of source-level compliance failures — unfulfilled large-model filing/registration obligations, weak platform safety and review/filtering capacity, training-data problems and data poisoning, and missing synthetic-content labels. Phase 2 targets seven categories of AI-generated content harms: false information, low-quality 'digital swill' content, impersonation, harm to minors, and AI-driven troll-farm activity. It is the main vehicle for enforcing the generative AI, deep synthesis and labeling rules in 2026. https://www.cac.gov.cn/2026-04/30/c_1779289298718765.htm - [news] Supreme People's Court drafting an Opinion on adjudicating AI-related disputes (Supreme People's Court, 2026-04): In April 2026 the SPC stated it is working intensively on drafting an Opinion on the proper adjudication of AI-related disputes, aiming to steer AI development in beneficial, safe and fair directions. Follow-up reports in May 2026 add that it is developing normative documents on judicial protection in AI cases and data property rights. No judicial interpretation or opinion dedicated to AI disputes has been issued as of July 2026; lower-court judgments and SPC-curated typical cases remain the operative guidance. https://www.21jingji.com/article/20260420/herald/b193f710084924f77acdcbf64caa088c.html - [in_force] Measures for Ethics Review of and Services for Artificial Intelligence Science and Technology (Trial) (MIIT with NDRC, Ministry of Education, MOST, Ministry of Agriculture and Rural Affairs, NHC, People's Bank of China, CAC, CAS, CAST (工信部联科〔2026〕75号), 2026-03-20): China's first ethics-review rule dedicated specifically to AI, issued by ten departments under MIIT's lead and effective upon issuance (Art. 37: 自印发之日起施行). It requires organizations conducting ethically sensitive AI activities to establish AI ethics review committees and builds a service infrastructure of professional AI ethics review and service centers. It operates as a lex specialis under the general 2023 Science and Technology Ethics Review Measures, which fill any gaps (Art. 35). https://www.gov.cn/zhengce/zhengceku/202604/content_7064646.htm - [in_force] GB/T 45958-2025 Cybersecurity Technology — Security Framework for Artificial Intelligence Computing Platforms (SAMR/SAC (drafted under TC260), 2026-02-01): Recommended national standard establishing a security framework for AI computing platforms (AI compute infrastructure): security functions, security management, and role-based security responsibilities across platform design, construction, operation, and use. Addresses threats such as infrastructure vulnerabilities, training-data leakage, and adversarial-sample attacks. Voluntary (GB/T). https://openstd.samr.gov.cn/bzgk/std/newGbInfo?hcno=32BCE5E761A1598E64B589FEC09501AB - [in_force] Cybersecurity Law of the PRC (2025 Amendment) — new dedicated AI article (NPC Standing Committee, 2026-01-01): The first major revision of the 2016 Cybersecurity Law, adopted 2025-10-28 and effective 2026-01-01, inserts a dedicated article on artificial intelligence — the first time AI appears in a national statute of this rank. The provision is principled rather than operational, but it gives the CAC-led AI regulatory apparatus an explicit statutory anchor and signals the legislature's chosen frame of coordinated development and security. The amendment also substantially raises penalty ceilings across the law. https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm - [in_force] Cybersecurity Law (as amended 2025) — new Article 20 on artificial intelligence (NPC Standing Committee, 2026-01-01): On October 28, 2025 the 14th NPCSC (18th session) adopted the Decision to Amend the Cybersecurity Law — the first revision since the law took effect June 1, 2017 — effective January 1, 2026. The amendment writes AI directly into a basic statute for the first time: a new Article 20 commits the state to supporting AI basic research and key technology R&D such as algorithms, building training-data and computing-power infrastructure, improving AI ethics norms, and strengthening risk monitoring, assessment and security regulation to promote healthy AI development. https://www.news.cn/20251029/bc3a57483dbf4b748c9626c0097ff3b4/c.html - [in_force] Cybersecurity Law of the PRC (2025 Amendment) — adds dedicated AI article (NPC Standing Committee, 2026-01-01): The first amendment to the 2017 Cybersecurity Law, adopted 28 October 2025 and effective 1 January 2026. It inserts a new Article 20 on artificial intelligence — widely described as the first dedicated AI-governance provision in a Chinese national statute — committing the state to support AI basic research and key-technology development, promote infrastructure such as training data and computing power, improve AI ethics norms, strengthen AI risk monitoring and security supervision, and encourage AI for cybersecurity protection. It also modernizes the penalty chapter and aligns the law with PIPL/DSL enforcement practice, providing a statutory hook for future AI legislation. https://www.cac.gov.cn/2026-01/02/c_1769093523928606.htm - [in_force] GB/T 45654-2025 Cybersecurity Technology — Basic Security Requirements for Generative Artificial Intelligence Services (SAMR/SAC (drafted under TC260), 2025-11-01): China's first national standard dedicated to generative AI service security, upgrading TC260-003 into a formal recommended (GB/T) standard. It covers training-data (corpus) security, model security, and required security measures, and specifies assessment methods; it is the supporting technical document for the Interim Measures for the Management of Generative AI Services. Nominally voluntary as a GB/T, but functionally quasi-mandatory because conformity is assessed in the generative AI service filing process. https://www.tc260.org.cn/portal/article/1/20250630122232 - [in_force] GB/T 45652-2025 Cybersecurity Technology — Security Specification for Generative AI Pre-training and Fine-tuning Data (SAMR/SAC (drafted under TC260), 2025-11-01): Recommended national standard governing security of data used in pre-training and optimization (fine-tuning) of generative AI models: data sourcing, content security processing, and management requirements across the training-data pipeline. Part of the trio of generative-AI security standards published 2025-04-25 alongside GB/T 45654 and GB/T 45674. Voluntary in form, but practically relevant to the filing security assessment. https://openstd.samr.gov.cn/bzgk/std/newGbInfo?hcno=82710B59110419C285BDC48AB4D7D1F3 - [in_force] GB/T 45674-2025 Cybersecurity Technology — Security Specification for Generative AI Data Annotation (SAMR/SAC (drafted under TC260), 2025-11-01): Recommended national standard setting security requirements for the data-annotation stage of generative AI training: annotation platforms/tools, annotation rules, annotator personnel management, and annotation verification. It gives service providers and annotation vendors a common security baseline for the labeling workflows that shape model alignment. Voluntary (GB/T). https://std.samr.gov.cn/gb/search/gbDetailed?id=33D40F1160F95D92E06397BE0A0A5B93 - [standard] Three national standards on generative AI security take effect (GB/T 45654-2025 and companion data standards) (SAMR / Standardization Administration of China (TC260), 2025-11-01): The first national-standard tier of generative AI security requirements took effect on 1 November 2025: GB/T 45654-2025 (Basic Security Requirements for Generative AI Services), GB/T 45652-2025 (security specification for pre-training and fine-tuning data) and GB/T 45674-2025 (security specification for data annotation). GB/T 45654 upgrades the earlier TC260 technical document (TC260-003) used in model filing/security assessment into a formal standard: corpus source vetting (sources with over 5% illegal/harmful content must not be used), model security requirements, and a catalogue of 31 safety risks for testing and annotation. These standards are the de facto checklist for the CAC filing regime. https://www.tc260.org.cn/portal/article/1/20250630122232 - [in_force] Artificial Intelligence Safety Governance Framework 2.0 (Issued as a TC260 (全国网安标委) technical document; drafted by a CNCERT/CC (国家互联网应急中心)-led group with research institutes and enterprises, under CAC guidance, 2025-09-15): Upgraded version of the 2024 framework, released at the 2025 National Cybersecurity Awareness Week main forum. It refines the risk taxonomy into three categories (technology-inherent, technology-application, and application-derived risks) and introduces an exploratory five-tier risk grading (low / ordinary / relatively large / major / especially major). Still voluntary, but it is the clearest public statement of Chinese regulators' approach to AI risk classification and is expected to shape future binding standards. https://www.cac.gov.cn/2025-09/15/c_1759653448369123.htm - [announced] AI Safety Governance Framework 2.0 (CNCERT/CC (National Internet Emergency Center, drafting lead) under CAC guidance, 2025-09-15): An updated version of the September 2024 AI Safety Governance Framework, released 15 September 2025 at the main forum of the 2025 National Cybersecurity Awareness Week. Version 2.0 tracks risk changes from rapid AI advances, refines the risk classification, introduces exploratory risk grading/tiering, and commits to dynamically adjusting prevention and governance measures, with emphasis on international cooperation. Non-binding, but it is the reference document for how Chinese authorities conceptualize frontier-model and application risks, and feeds national standards work. https://www.cac.gov.cn/2025-09/15/c_1759653448369123.htm - [in_force] Measures for Labeling of AI-Generated and Synthetic Content (CAC, MIIT, Ministry of Public Security, NRTA, 2025-09-01): Requires all AI-generated or synthesized text, images, audio, video, and virtual scenes to carry both explicit labels perceptible to users and implicit metadata labels embedded in the file. It distributes duties across the full chain — generation service providers, content propagation platforms, and app distribution platforms — turning the labeling principles of the deep synthesis and generative AI rules into a uniform, enforceable regime. https://www.cac.gov.cn/2025-03/14/c_1743654685899683.htm - [standard] Cybersecurity Technology — Labeling Method for Content Generated by Artificial Intelligence (mandatory national standard GB 45438-2025) (SAMR / Standardization Administration of China (drafted under TC260, Central Cyberspace Affairs Commission Office supervision), 2025-09-01): The mandatory (GB, not GB/T) national standard that specifies exactly how explicit and implicit labels required by the Labeling Measures must be implemented — formats, placement, and metadata fields for text, image, audio, video, and virtual-scene content. Because it is a mandatory standard, compliance is legally required of generation service providers and content propagation platforms, making it the technical backbone of China's AI-content labeling regime. https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=F32EA2A561F1886CD8D606513512D547&refer=outter - [in_force] GB 45438-2025 Cybersecurity Technology — Labeling Method for Content Generated by Artificial Intelligence (mandatory standard) (SAMR/SAC (drafted under TC260); implemented alongside the CAC/MIIT/MPS/NRTA Labeling Measures, 2025-09-01): China's first mandatory (GB, not GB/T) national standard on AI: it prescribes how AI-generated/synthetic content must be labeled, defining explicit labels (text/audio/graphic cues perceivable by users) and implicit labels (file-metadata fields and content watermarks carrying provider and provenance information). It is the technical companion to the four-agency Measures for Labeling AI-Generated Synthetic Content and took effect the same day, binding generative AI service providers and content-dissemination platforms. Non-compliance is enforceable through the Measures and the underlying deep synthesis and generative AI rules. https://openstd.samr.gov.cn/bzgk/std/newGbInfo?hcno=F32EA2A561F1886CD8D606513512D547 - [news] AI-generated content labeling regime takes effect; platforms roll out mandatory 'AI-generated' labels (CAC, MIIT, Ministry of Public Security, National Radio and Television Administration, 2025-09-01): The Measures for Labeling AI-Generated Synthetic Content (issued 14 March 2025) took effect on 1 September 2025, together with the supporting mandatory national standard GB 45438-2025. All AI-generated text, images, audio, video and virtual scenes must carry explicit (user-perceivable) and implicit (metadata) labels; distribution platforms must verify labeling and add risk warnings to suspected unlabeled AI content, and removing or tampering with labels is prohibited. Major platforms including WeChat, Douyin, Weibo and Kuaishou rolled out labeling functions and platform rules around the effective date — the compliance baseline now enforced through the 2026 Qinglang campaign. http://www.news.cn/legal/20250901/a12108b0b10249e5bae4435269e40c91/c.html - [standard] GB 45438-2025 Cybersecurity Technology — Labeling Methods for AI-Generated Synthetic Content (mandatory national standard) (SAMR / Standardization Administration of China (standard centralized under the Central Cyberspace Affairs Commission Office), 2025-09-01): China's first mandatory (GB, not GB/T) national standard for AI, specifying the technical methods for explicit and implicit labeling of AI-generated content — label placement for text, image, audio, video and virtual scenes, and metadata field requirements. Released 28 February 2025 and effective 1 September 2025 in step with the labeling Measures, it turns the labeling obligation into testable technical requirements binding on generation and distribution service providers. https://openstd.samr.gov.cn/bzgk/std/newGbInfo?hcno=F32EA2A561F1886CD8D606513512D547 - [in_force] Six Practice Guides on AI-Generated Synthetic Content Labeling (file metadata implicit labeling series) (TC260 Secretariat (网安秘字〔2025〕118号), 2025-08-28): A batch of six cybersecurity standard practice guides operationalizing GB 45438-2025's implicit-labeling requirements ahead of its 2025-09-01 effective date, covering file-metadata implicit labeling methods for AI-generated text, image, audio, and video files, plus security protection and detection guidance for metadata labels. Voluntary guidance that fills in file-format-level technical detail beneath the mandatory labeling standard. https://www.tc260.org.cn/portal/article/2/20250828165129 - [announced] Opinions of the State Council on Deepening the Implementation of the 'AI Plus' Action (State Council, 2025-08-26): The successor strategy to the 2017 Plan, published August 26, 2025 (internally dated August 21, 2025), operationalizing the 'AI+' action first announced in the March 2024 Government Work Report. It directs deep AI integration across six priority areas — science and technology, industrial development, consumption upgrading, people's livelihood, governance, and global cooperation — with staged targets: new-generation intelligent terminals and AI agents exceeding 70% penetration by 2027 and 90% by 2030, and China fully entering the intelligent-economy and intelligent-society stage by 2035. https://www.gov.cn/zhengce/content/202508/content_7037861.htm - [announced] Opinions of the State Council on Deepening the Implementation of the 'AI Plus' Initiative (State Council, 2025-08-26): The central policy document for AI diffusion across the economy, dated 21 August 2025 and released publicly on 26 August 2025. It deploys six 'AI+' priority actions (science and technology, industrial development, consumption, people's livelihood, governance capacity, global cooperation) and eight foundational support pillars, including model capability, data supply, coordinated computing power, an open-source ecosystem, talent, and — notably for regulators — policy and legal safeguards and security capability building, with staged goals for 2027, 2030 and 2035. It frames the pro-diffusion posture within which the 2025–2026 safety rules operate. https://www.cac.gov.cn/2025-08/27/c_1758018277755538.htm - [announced] Action Plan for Global Governance of Artificial Intelligence (WAIC 2025) (Government of China (released at the World AI Conference / High-Level Meeting on Global AI Governance, Shanghai), 2025-07-26): China's international AI governance blueprint, released 26 July 2025 at the World AI Conference and High-Level Meeting on Global AI Governance in Shanghai. The 13-point plan calls for global cooperation so that AI development is 'safe, reliable, controllable, and equitable', covering innovation, industry application, infrastructure for the Global South, open source, data, sustainability, standards, safety governance and UN-anchored multilateralism. At the same event Premier Li Qiang proposed a Shanghai-headquartered World AI Cooperation Organization — realized a year later. https://www.mfa.gov.cn/zyxw/202507/t20250726_11677803.shtml - [in_force] Guidelines for Building the AI Safety Governance Standards System in Industry and Information Technology (2025 Edition) (MIIT AI Standardization Technical Committee (人工智能标准化技术委员会), 2025-07): MIIT's sector-specific companion to the 2024 national guide, focused on AI safety governance standards in industry and IT. It structures work across seven domains — governance capacity, foundational security, network security, data security, algorithm/model security, application security, and enablement security — under the principle of coordinating development and security. Planning document; not binding. https://www.secrss.com/articles/81283 - [in_force] Measures for the Security Management of Facial Recognition Technology Applications (CAC, Ministry of Public Security (CAC Order No. 19), 2025-06-01): Binding national rules on deploying facial recognition — a core applied-AI technology — to process face information within China. It imposes necessity, consent, and impact-assessment requirements and creates a filing regime for large-scale face databases. Included here as an AI-application measure; it also functions as a PIPL implementing rule. https://www.cac.gov.cn/2025-03/21/c_1744174262156096.htm - [announced] State Council 2025 Annual Legislative Work Plan (AI Law demoted to general 'advance legislation' language) (State Council General Office, 2025-05-14): The 2025 plan dropped the 'draft AI Law' as a preparatory submission item and instead used the softer formulation 'advance legislative work on the healthy development of AI' (推进人工智能健康发展立法工作), with no standalone AI bill or designated lead agency. Analysts widely read this as a deliberate slowing and broadening of the comprehensive-law project in favor of incremental, sector-specific rules. https://www.mee.gov.cn/zcwj/gwywj/202505/t20250516_1119545.shtml - [in_force] Beijing Autonomous Vehicles Regulations (Beijing Municipal People's Congress Standing Committee, 2025-04-01): Adopted 31 December 2024 and effective 1 April 2025, this is Beijing's local law enabling autonomous-vehicle deployment — 7 chapters and 48 articles that are enabling/promotional in character, expressly supporting AV use for personal passenger cars, taxis/car rental, buses (excluding school buses), freight (excluding dangerous goods) and urban-operations vehicles. https://www.beijing.gov.cn/ywdt/yaowen/202501/t20250101_3978661.html - [in_force] Practice Guide: Coding Rules for Service Providers in AI-Generated Synthetic Content Labeling (TC260 Secretariat, 2025-03-14): Cybersecurity standard practice guide issued alongside the Labeling Measures and GB 45438-2025, defining the code structure and assignment rules for the service-provider identifiers that must be embedded in implicit (metadata) labels of AI-generated content. Practice guides are voluntary TC260 secretariat documents, but this one supplies operational detail needed to comply with the mandatory labeling standard. https://www.tc260.org.cn/upload/2025-03-14/1741942216982096585.pdf - [news] Comparative note: two clusters of local AI-adjacent lawmaking (tracker section introduction) (Researcher synthesis (multiple municipal legislatures), 2025-03-13): Comparative context entry: China's AI-adjacent local lawmaking has clustered in two streams — comprehensive AI industry promotion statutes (Shanghai and Shenzhen 2022; Hangzhou's embodied-robot law 2026) and vehicle-automation laws (Shenzhen 2022, Shanghai-Pudong 2023, Beijing and Guangzhou 2025). Nearly all are enabling/promotional; binding AI-conduct rules remain national (CAC recommendation-algorithm, deep-synthesis and generative-AI measures), with localities competing on incentives, scenarios and FTZ data liberalization instead. http://www.news.cn/tech/20250313/cd1dc218bc734046819155cd48460094/c.html - [in_force] Guangdong Policy Measures for Promoting Innovation and Development of the AI and Robotics Industries (Guangdong Provincial People's Government General Office, 2025-03-09): A 12-measure provincial support package (Doc. No. 粤府办〔2025〕6号) dated 9 March 2025 (published 10 March), valid until 31 December 2027, to build AI and robotics into new pillar industries. Entirely promotional: up to RMB 8 million per benchmark manufacturing large-model application case, standards-development subsidies, and case-by-case ('one case, one discussion') support for major projects. http://www.gd.gov.cn/zwgk/wjk/qbwj/yfb/content/post_4678912.html - [in_force] Shenzhen Action Plan for Embodied Intelligent Robot Technology Innovation and Industry Development (2025-2027) (Shenzhen Science, Technology and Innovation Bureau, 2025-03-03): Shenzhen's embodied-robot promotion plan, issued 3 March 2025 and replaced by a revised edition released 18 June 2026 (the notice voids the original). By 2027 it targets an associated industry scale above RMB 100 billion, 1,200+ cluster enterprises, 10+ firms valued over RMB 10 billion, 20+ firms with revenue over RMB 1 billion, and 50+ billion-yuan-scale application deployments. https://stic.sz.gov.cn/xxgk/tzgg/content/post_12851036.html - [in_force] Guangzhou Intelligent Connected Vehicles Innovation and Development Regulations (Guangzhou Municipal People's Congress Standing Committee (approved by Guangdong Provincial People's Congress Standing Committee), 2025-02-28): Adopted 29 November 2024, approved by the Guangdong provincial legislature 12 January 2025, and effective 28 February 2025. A promotion-oriented local law supporting ICV innovation, infrastructure, road testing and application scenarios in Guangzhou, including logistics/express-delivery use cases. http://ghzyj.gz.gov.cn/sjb/zw/zcfg/content/post_10120213.html - [in_force] Beijing Action Plan for Embodied Intelligence S&T Innovation and Industry Cultivation (2025-2027) (Beijing Municipal Science & Technology Commission / Zhongguancun Administrative Committee and other departments, 2025-02-28): Issued 28 February 2025, Beijing's embodied-AI plan aims by 2027 to break through 100+ key technologies, cultivate 50+ core enterprises, 50+ mass-produced products and 100+ scaled applications, be first to exceed 10,000 units produced, and build a 100-billion-yuan-level (千亿级) industry cluster. Purely promotional: R&D support for embodied 'brain' models, platform infrastructure, scenario opening and cluster building. https://kw.beijing.gov.cn/zwgk/zcwj/202502/t20250227_4020661.html - [in_force] China (Shanghai) Pilot FTZ and Lingang New Area Data Export Management List (Negative List) (2024 Edition) (Shanghai Municipal Cyberspace Administration, Shanghai Data Bureau, Shanghai Development & Reform Commission, Shanghai FTZ and Lingang administrations, 2025-02-08): Shanghai's FTZ negative list and accompanying management measures, jointly published 8 February 2025 by five municipal authorities (labelled the '2024 edition'). The first batch covers finance (reinsurance), international shipping and commercial trade — 6 business scenarios and 84 data items per contemporaneous reporting — exempting listed-sector data outside the list from CAC export procedures for FTZ/Lingang enterprises. https://www.pudong.gov.cn/china-shftz/tzgg/20250208/801211.html - [in_force] Shanghai Implementation Plan for AI 'Model Shaping Shanghai' (Mosu Shencheng) (Shanghai Municipal People's Government General Office, 2024-12-20): Shanghai's citywide large-model/'AI+' implementation plan (Doc. No. 沪府办发〔2024〕27号), issued 20 December 2024. A promotion program, not regulation: it targets 100 EFLOPS of intelligent compute, ~50 industry open-corpus demonstration results and 3-5 large-model innovation-acceleration incubators by end-2025, driving adoption across finance, manufacturing, education, healthcare, culture/tourism and urban governance. https://www.shanghai.gov.cn/202502bgtwj/20250220/77b163177e954e8c929f90ec43fc92b7.html - [superseded] Artificial Intelligence Safety Governance Framework (Version 1.0) (TC260 (National Cybersecurity Standardization Technical Committee / 网安标委), under CAC guidance, 2024-09-09): Voluntary risk-governance framework released at the main forum of the 2024 National Cybersecurity Awareness Week, implementing the Global AI Governance Initiative. It maps AI risks into inherent technical risks (model/algorithm, data, system security) and application risks (network, physical, cognitive, ethical domains) and proposes matching technical countermeasures and governance measures. Not legally binding, but it supplies the risk taxonomy underlying TC260's subsequent standards work. https://www.cac.gov.cn/2024-09/09/c_1727567886199789.htm - [superseded] China (Beijing) Pilot Free Trade Zone Data Export Negative List (2024 Edition) and Administrative Measures (Trial) (Beijing Municipal Cyberspace Administration, Bureau of Commerce, and Government Services & Data Administration, 2024-08-30): Released 30 August 2024 (document dated 26 August 2024), this was the first scenario-based, field-level FTZ negative list — reported as the first to include artificial intelligence as a covered sector, alongside automotive, pharma, retail and civil aviation. Data outside the listed fields could be exported by Beijing FTZ enterprises without CAC procedures. Updated and replaced in practice by the 2025 edition issued May 2026. https://www.beijing.gov.cn/zhengce/zhengcefagui/202409/t20240902_3787646.html - [in_force] Guidelines for the Construction of a Comprehensive National AI Industry Standardization System (2024 Edition) (MIIT, CAC Office, NDRC, SAC (four departments; 工信部联科〔2024〕113号), 2024-06-05): Top-level policy roadmap for AI standardization, structuring the standards system into seven modules: foundational commonalities, foundational support, key technologies, intelligent products and services, empowering new industrialization, industry applications, and safety/governance. Sets 2026 targets including 50+ new national and industry standards and participation in international standards work. A planning document — not itself binding, but it drives which GB/GB/T standards get drafted. https://www.gov.cn/zhengce/zhengceku/202407/content_6960720.htm - [announced] State Council 2024 Annual Legislative Work Plan (second listing of a draft AI Law) (State Council General Office, 2024-05-09): The 2024 plan, issued May 9, 2024, again listed the draft AI Law as a preparatory item for submission to the NPC Standing Committee — the second consecutive year. As in 2023, no draft was submitted or published during the year. https://m.mp.oeeee.com/a/BAAFRD000020240510951572.html - [in_force] China (Tianjin) Pilot Free Trade Zone Data Export Management List (Negative List) (2024 Edition) (Tianjin Pilot FTZ Administrative Committee and Tianjin Municipal Bureau of Commerce, 2024-05-09): China's first FTZ data-export negative list, released 9 May 2024 under the CAC's March 2024 cross-border data rules that let FTZs write their own lists. FTZ enterprises exporting data outside the listed categories are exempt from security assessment, standard contract filing and certification — a liberalizing measure directly relevant to AI firms moving training and business data across borders. https://shangwuju.tj.gov.cn/tjsswjzz/zwgk/zcfg_48995/swjwj/202405/t20240509_6620796.html - [news] Beijing Internet Court AI voice-cloning case — first personality-rights protection for AI-generated voice (Beijing Internet Court, 2024-04-23): First-instance judgment announced April 23, 2024 in a suit by dubbing artist Yin, whose studio recordings had been used without authorization to build a commercial text-to-speech product. The court held that a natural person's voice rights under the Civil Code extend to an AI-generated voice where it remains identifiable to ordinary listeners, that authorization to the sound-recording copyright holder did not authorize AI voice cloning, and ordered two of the defendants to pay RMB 250,000 and apologize; other defendants were held not liable absent subjective fault. https://www.bj148.org/yck/zzdt/202405/t20240510_1664690.html - [draft] Model Artificial Intelligence Law (Expert Draft) — CASS, versions 1.0/1.1/2.0 — NON-OFFICIAL (Chinese Academy of Social Sciences Institute of Law (drafting group led by Zhou Hui) — scholar proposal, not a government body, 2024-04-16): A scholar-drafted model law from a CASS Institute of Law research group: version 1.0 released August 15, 2023 (China's first full model AI law text), a reported interim version 1.1 in late 2023, and version 2.0 on April 16, 2024. Version 2.0 proposes a national AI office, negative-list-based risk management (permits for negative-list activities, filing otherwise), developer/provider obligations, and notably open-source development incentives and AI-specific IP rules. It has no legal status but has visibly shaped the official legislative debate. https://www.21jingji.com/article/20240416/herald/4df710ffed0ffe037cdf6c54aa369961.html - [draft] Artificial Intelligence Law of the PRC (Scholars' Proposal Draft) — NON-OFFICIAL (Seven-institution scholar group led by Zhang Linghan (China University of Political Science and Law) — scholar proposal, not a government body, 2024-03-16): Released March 16, 2024 at an AI governance forum in Beijing by scholars from seven institutions (per release reports: CUPL Data Law Institute, Northwest University of Political Science and Law, CAICT, Beihang Law School, ECUPL, SWUPL, Zhongnan University of Economics and Law). The draft runs 96 articles covering general principles, development and promotion, rights protection for users and developers, safety obligations, supervision, special application scenarios, international cooperation, and legal liability. Like the CASS model law, it is an academic proposal with no legal status. https://cset.georgetown.edu/publication/china-ai-law-draft/ - [superseded] Basic Security Requirements for Generative Artificial Intelligence Services (TC260-003) (TC260, 2024-03-01): TC260 technical document (not a formal GB standard) specifying corpus/training-data security, model security, and security measures for generative AI services, plus the security self-assessment methodology. Although nominally voluntary, it was the de facto checklist applied in the generative AI service filing (备案) security assessment, making it quasi-mandatory in practice. It was elevated, with revisions, into national standard GB/T 45654-2025. https://www.tc260.org.cn/portal/article/2/20240301164054 - [in_force] GB/T 42888-2023 Information Security Technology — Assessment Specification for Security of Machine Learning Algorithms (SAMR/SAC (drafted under TC260), 2024-03-01): Earlier-generation recommended national standard specifying security requirements, assessment methods, and assessment process for machine learning algorithms and services across their lifecycle. It predates the generative-AI wave and remains the general-purpose ML security assessment reference standard. Voluntary (GB/T). https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=E7170BA58AE37AACF4170242EFD25183 - [superseded] Lingang New Area Measures for Classified and Graded Administration of Cross-Border Data Flows (Trial) (Shanghai FTZ Lingang New Area Administrative Committee, 2024-02-08): Trial measures (Doc. 沪自贸临管规范〔2024〕3号) effective 8 February 2024 with express one-year validity to 7 February 2025, establishing Lingang's pioneering three-tier scheme — core data, important data (catalogued), general data (listed) — with sector 'general data lists' rolled out for fields including intelligent connected vehicles during 2024. Its approach fed into the Shanghai FTZ-wide negative-list system that followed. https://www.lingang.gov.cn/erroritem/2024-02-10/07E3E9B5-F187-899B-9F21-74DF5E1B709C.pdf - [news] Guangzhou Internet Court 'Ultraman' case — first effective judgment holding a generative AI service liable for copyright infringement (Guangzhou Internet Court, 2024-02): In February 2024 the Guangzhou Internet Court's judgment took effect in a suit by the exclusive Chinese licensee of the Ultraman works against an AI platform whose text-to-image service generated images substantially similar to Ultraman, holding the provider infringed the reproduction and adaptation rights and awarding RMB 10,000 including costs. Widely reported as the first effective judgment worldwide finding a generative AI service liable for infringing outputs, it imposed duties of care (complaint channels, risk warnings, keyword filtering, AIGC labeling) on AIGC providers. https://www.21jingji.com/article/20240226/herald/133a6c2f9c0b045899e4dea10c5778eb.html - [in_force] Measures for Science and Technology Ethics Review (Trial) (MOST with Ministry of Education, MIIT, Ministry of Agriculture and Rural Affairs, NHC, CAS, CASS, CAE, CAST, CMC Science & Technology Commission (国科发监〔2023〕167号), 2023-12-01): The cross-sector binding framework for ethics review of scientific and technological activities, expressly covering artificial intelligence alongside life sciences and medicine. Institutions engaged in ethics-sensitive AI research must establish ethics (review) committees and run defined review procedures. Its annexed expert re-review list is the hook that pulls high-risk AI work into a second, expert-level review. https://www.most.gov.cn/xxgk/xinxifenlei/fdzdgknr/fgzc/gfxwj/gfxwj2023/202310/t20231008_188309.html - [news] Beijing Internet Court, Li v. Liu — first Chinese judgment recognizing copyright in an AI-generated image (Beijing Internet Court, 2023-11-27): Judgment of November 27, 2023 holding that an image the plaintiff generated with Stable Diffusion reflected sufficient human intellectual investment and originality (prompt design, parameter setting, iterative selection) to qualify as a copyrightable work owned by the human user, and that the defendant's unauthorized republication infringed attribution and network-dissemination rights (RMB 500 damages plus apology). Neither party appealed, so the first-instance judgment is final — the leading Chinese authority on AIGC copyrightability, in contrast to the US Copyright Office position. https://www.bjinternetcourt.gov.cn/details.html?id=255 - [announced] 14th NPC Standing Committee Five-Year Legislative Plan (AI mentioned, no standalone AI Law item) (NPC Standing Committee, 2023-09-07): The five-year legislative plan for the 14th NPCSC (2023–2028), released September 7, 2023, does not list a standalone Artificial Intelligence Law among its Class I or Class II projects. It instead contains general deployment language on 'promoting scientific and technological innovation and the healthy development of artificial intelligence' (推进科技创新和人工智能健康发展), leaving the door open for an AI law to be added later. https://www.21jingji.com/article/20230909/herald/0dea207bfb86208bf6d0569877ff1d43.html - [in_force] Interim Measures for the Management of Generative Artificial Intelligence Services (CAC, NDRC, Ministry of Education, MOST, MIIT, Ministry of Public Security, NRTA (CAC Order No. 15), 2023-08-15): The world's first binding national rule specifically on generative AI, applying to services that generate text, images, audio or video for the public within mainland China. It couples content-control duties (uphold core socialist values, no false information or discrimination) with lifecycle obligations on training data, labeling, and user protection, under a stated principle of inclusive-prudent, classified-and-graded regulation. It anchors the generative AI filing regime that all public-facing Chinese LLM services must pass before launch. https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm - [in_force] Generative AI Service Filing (large model 备案) and Registration (登记) Regime (CAC (national level for 备案; provincial cyberspace administrations for 登记), 2023-08-15): Binding dual-track regime under the Interim Measures for the Management of Generative AI Services (effective 2023-08-15) and the 2018 security-assessment provisions: services with public-opinion attributes or social-mobilization capability that develop or fine-tune models must complete security assessment and filing (备案) with CAC, while apps/functions that call already-filed models via API register (登记) with provincial CAC offices. Filed services receive filing numbers that must be displayed publicly; the security assessment applies GB/T 45654-2025 (formerly TC260-003) as its technical yardstick, which is what makes those nominally voluntary standards de facto binding. In practice the regime functions as a market-entry gate for public-facing generative AI services in China. https://www.cac.gov.cn/2024-04/02/c_1713729983803145.htm - [announced] State Council 2023 Annual Legislative Work Plan (first listing of a draft AI Law) (State Council General Office, 2023-06): The State Council's 2023 legislative work plan for the first time listed a draft Artificial Intelligence Law (人工智能法草案) among items to be prepared for submission to the NPC Standing Committee for deliberation. This was the strongest official signal to date that a comprehensive AI statute was being drafted internally, though no text was ever released. https://www.stcn.com/article/detail/886227.html - [in_force] Beijing Measures for Promoting General Artificial Intelligence Innovation and Development (Beijing Municipal People's Government General Office, 2023-05-23): Beijing's flagship general/large-model AI policy package (Doc. No. 京政办发〔2023〕15号), dated 23 May 2023 and publicly released at end-May 2023 — one of the first local government responses to the large-model boom. A support-and-promotion document, not a regulatory instrument: 21 measures across compute, data, model R&D, applications and an explicitly inclusive regulatory posture. https://www.ncsti.gov.cn/zcfg/zcwj/202306/t20230601_122585.html - [in_force] Shanghai Pudong New Area Provisions on Promoting Innovative Application of Driverless Intelligent Connected Vehicles (Shanghai Municipal People's Congress Standing Committee (Pudong New Area regulation), 2023-02-01): A Pudong New Area regulation (a special legislative category) adopted 23 November 2022 and effective 1 February 2023, with 34 articles enabling fully driverless vehicles — no onboard driver or safety operator — in designated Pudong zones. Promotion-oriented: it creates a graduated pathway from road testing through demonstration operation to commercial deployment. https://www.shanghai.gov.cn/nw12344/20221205/c975436eedbe4958bbf3a5aca41c24a1.html - [in_force] Provisions on the Administration of Deep Synthesis Internet Information Services (CAC, MIIT, Ministry of Public Security (CAC Order No. 12), 2023-01-10): The deepfake rule: binding obligations on providers and technical supporters of deep synthesis technology (face swap, voice synthesis, text/image/video generation and editing). It pioneered mandatory labeling of synthetic content and consent requirements for biometric editing. Still in force; its labeling articles are now operationalized in much greater technical detail by the 2025 Labeling Measures and GB 45438-2025. https://www.cac.gov.cn/2022-12/11/c_1672221949354811.htm - [in_force] Shenzhen Special Economic Zone Artificial Intelligence Industry Promotion Regulations (Shenzhen Municipal People's Congress Standing Committee, 2022-11-01): China's first special legislation dedicated to the AI industry, adopted 30 August 2022 under Shenzhen's SEZ legislative powers and effective 1 November 2022. It is a promotion statute, not a restrictive one: 7 chapters and 73 articles on basic research, computing/data infrastructure, application scenarios and incentives, plus a governance chapter setting ethics and risk principles. https://www.szrd.gov.cn/v2/zx/szfg/content/post_966197.html - [in_force] Shanghai Regulations on Promoting the Development of the Artificial Intelligence Industry (Shanghai Municipal People's Congress Standing Committee, 2022-10-01): China's first provincial-level local law on AI (Shanghai is a province-level municipality), adopted 22 September 2022 and effective 1 October 2022. It is overwhelmingly promotion-oriented — 6 chapters and 72 articles securing computing power, data, talent and funding support for the AI industry — with a comparatively light governance chapter rather than a restrictive licensing regime. https://www.ssme.sh.gov.cn/public/news!loadNewsDetail.do?id=2c91c28d83647d7001837da955a60a55 - [in_force] Shenzhen Special Economic Zone Intelligent Connected Vehicles Administration Regulations (Shenzhen Municipal People's Congress Standing Committee, 2022-08-01): China's first local law governing intelligent connected vehicles, adopted 23 June 2022 and effective 1 August 2022. Unlike the pure promotion statutes, this one builds a full-chain administrative regime — road testing, demonstration, market access and registration, use management, traffic-violation and accident liability — making Shenzhen the first city to give higher-level automated vehicles a legal path onto public roads. https://www.sz.gov.cn/zfgb/2022/gb1250/content/post_9967816.html - [in_force] Internet Information Service Algorithmic Recommendation Management Provisions (CAC, MIIT, Ministry of Public Security, SAMR (CAC Order No. 9), 2022-03-01): China's foundational binding rule on recommendation algorithms, covering generation-synthesis, personalized push, ranking-selection, search-filtering, and dispatch-decision algorithms used in internet information services. It created the algorithm filing (备案) registry and gives users rights against purely algorithmic curation. It remains the base layer on which the deep synthesis and generative AI rules were built. https://www.cac.gov.cn/2022-01/04/c_1642894606364259.htm - [in_force] Internet Information Service Algorithm Filing Regime (including deep synthesis algorithm filing) (CAC (with MIIT, MPS, SAMR under the underlying provisions), 2022-03-01): Binding filing regime: providers of algorithmic recommendation services with public-opinion attributes or social-mobilization capability must file their algorithms with CAC via beian.cac.gov.cn (Provisions on Recommendation Algorithms, effective 2022-03-01, art. 24); deep synthesis service providers and technical supporters must likewise file (Deep Synthesis Provisions, effective 2023-01-10, art. 19). CAC publishes filed-algorithm lists in periodic batches — the first general list on 2022-08-12, with the general filing list updated roughly bimonthly through July 2026 and the 17th deep-synthesis batch published 2026-05-06. Filing is a binding precondition for operating covered services, though CAC stresses filing is not an endorsement of legality or safety. https://www.cac.gov.cn/2022-08/12/c_1661927474338504.htm - [in_force] Personal Information Protection Law (PIPL) — AI-relevant provisions (NPC Standing Committee, 2021-11-01): China's comprehensive personal-data statute, adopted August 20, 2021 and effective November 1, 2021. It is the principal statutory basis for regulating AI systems that process personal information: Article 24 imposes transparency and fairness duties on automated decision-making, bans unreasonable differential treatment (e.g., algorithmic price discrimination), and grants opt-out and explanation rights; Article 55 requires impact assessments for automated decision-making; Article 62 directs the CAC to develop specific rules for new technologies including AI applications. https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm - [in_force] Data Security Law (DSL) — AI-relevant provisions (NPC Standing Committee, 2021-09-01): Adopted June 10, 2021 and effective September 1, 2021, the DSL establishes the classified-and-graded data protection regime (important data, national core data) that governs the datasets on which AI models are trained and operated. Its security-obligation, risk-assessment, and cross-border provisions apply to AI developers as data processors, and it is consistently cited (with the CSL and PIPL) as one of the three statutory pillars beneath China's AI-specific rules. https://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm - [announced] MOST Letter Supporting Beijing in Building a National New Generation AI Innovation and Development Pilot Zone (Ministry of Science and Technology (designation for Beijing Municipality), 2019-02-21): The founding document of China's first national new-generation AI innovation and development pilot zone in Beijing: the MOST letter (国科函规〔2019〕27号) is dated 20 February 2019 and was published on most.gov.cn on 21 February 2019. Pilot zones are policy-experiment vehicles — testing AI applications, institutional reforms and ethics norms — rather than binding regulation; the program later expanded to 17+ zones nationwide including Shanghai, Tianjin, Hangzhou and Shenzhen. https://www.most.gov.cn/xxgk/xinxifenlei/fdzdgknr/qtwj/qtwj2019/201902/t20190221_145133.html - [announced] New Generation Artificial Intelligence Development Plan (State Council, 2017-07-20): China's foundational AI strategy document, issued as State Council Document No. 35 of 2017 (dated July 8, published July 20, 2017). It set the three-step goal of reaching globally advanced AI levels by 2020, major breakthroughs by 2025, and world-leading AI innovation-center status by 2030, and — importantly for lawyers — scheduled the 'initial establishment of AI laws, regulations, ethical norms and policy systems' (初步建立人工智能法律法规、伦理规范和政策体系) by 2025, the root of the current legislative agenda. https://www.gov.cn/zhengce/content/2017-07/20/content_5211996.htm United States ============= - [in_force] New York RAISE Act — Responsible AI Safety and Education Act (S6953B, Ch. 699, as amended March 2026) (New York Legislature, 2027-01-01): Passed in June 2025, signed December 19, 2025 (Chapter 699), and finalized by a negotiated chapter amendment (S8828) signed March 27, 2026, the RAISE Act takes effect January 1, 2027. As amended it converges on California's SB 53 model: it binds 'large frontier developers' — those training frontier models with more than 10^26 integer or floating-point operations and with annual revenue above $500 million — requiring published safety frameworks, pre-deployment transparency reports, and critical-safety-incident reporting to the Department of Financial Services within 72 hours (24-hour law-enforcement notification where imminent danger exists), stricter than California's 15-day window. A new office within DFS receives reports and gains rulemaking authority; the Attorney General enforces with penalties up to $1 million for a first violation and $3 million for repeat violations. https://www.nysenate.gov/legislation/bills/2025/S6953 - [in_force] Colorado SB26-189 — Automated Decision-Making Technology Act (replacement for the Colorado AI Act) (Colorado General Assembly, 2026-08-12): Signed May 14, 2026, SB26-189 repeals and reenacts the Colorado AI Act as a much narrower disclosure-and-transparency law governing 'automated decision-making technology' (ADMT) used in consequential decisions such as employment, housing, insurance, and government benefits. It eliminates the 2024 law's duty of care against algorithmic discrimination, risk-management programs, impact assessments, and AG reporting, replacing them with pre-decision notice, post-adverse-decision disclosures within 30 days, data-correction and human-review rights, and developer documentation duties. The statute takes effect August 12, 2026 (enacted without a safety clause), with the substantive developer and deployer obligations operative January 1, 2027; the Colorado Attorney General enforces violations through the Colorado Consumer Protection Act, with a 60-day cure opportunity before enforcement actions filed before 2030. https://leg.colorado.gov/bills/sb26-189 - [in_force] California SB 942 — California AI Transparency Act (as amended by AB 853) (California Legislature, 2026-08-02): SB 942 (signed September 19, 2024) requires 'covered providers' — publicly available generative AI systems with over 1 million monthly users accessible in California — to offer a free AI-detection tool and to embed latent (and offer manifest) provenance disclosures in AI-generated content. AB 853 (signed October 13, 2025) delayed the operative date from January 1, 2026 to August 2, 2026, aligning with the EU AI Act's Article 50 timeline, and extended obligations to large online platforms and generative AI hosting platforms (January 1, 2027) and capture-device manufacturers (January 1, 2028). Enforcement is by civil penalty of $5,000 per violation per day. https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB853 - [news] Bartz v. Anthropic: court grants final approval of $1.5B copyright class settlement (U.S. District Court, N.D. Cal., 2026-07-20): Judge Araceli Martínez-Olguín granted final approval on July 20, 2026 of the $1.5 billion settlement — reported as the largest copyright class settlement in U.S. history — resolving authors' claims over Anthropic's downloading of pirated books from LibGen and Pirate Library Mirror, addressing all 54 objections on the merits. Payments run roughly $3,000 per work (about four times the statutory minimum), and Anthropic must destroy the pirate-sourced files and copies derived from them. The settlement followed Judge Alsup's June 2025 ruling that training on lawfully acquired books was fair use but retention of pirated library copies was not. https://authorsguild.org/news/court-grants-final-approval-anthropic-copyright-settlement/ - [news] Kadrey v. Meta aftermath: interlocutory appeal on 'acquisition by piracy' denied (U.S. District Court, N.D. Cal., 2026-07-08): Judge Chhabria, who in June 2025 granted Meta summary judgment on fair use for LLM training while flagging an untested 'market dilution' theory, on July 8, 2026 denied the author plaintiffs' motion to certify an interlocutory appeal to the Ninth Circuit on whether Meta's downloading of books from shadow libraries was itself infringing — reasoning that a final judgment in one of the Meta cases will soon present the issue 'as part of a tidy package.' The denial leaves the acquisition-versus-training split (Kadrey vs. Bartz) unresolved at the appellate level, with the Third Circuit's Ross appeal positioned as the first appellate word on AI training fair use. https://chatgptiseatingtheworld.com/2026/07/08/judge-chhabria-denies-kadrey-book-authors-motion-to-seek-an-interlocutory-appeal-of-downloading-part-of-ruling-in-fair-use-decision/ - [draft] FTC Proposed Policy Statement on Suppression of Accuracy in AI Systems (AI accuracy / 'ideological steering') (FTC, 2026-07-07): Proposed policy statement (Federal Register July 7, 2026) taking the position that training or configuring an AI model to pursue undisclosed objectives contrary to users' reasonable expectations — including where done to comply with a state law — may be deceptive under FTC Act Section 5. Executive Order 14365 (Ensuring a National Policy Framework for Artificial Intelligence, signed December 11, 2025) expressly directs the Commission to issue this enforcement policy statement. Comment period closes July 31, 2026; not yet final, and even when finalized a policy statement is agency interpretation rather than a binding rule. https://www.federalregister.gov/documents/2026/07/07/2026-13628/policy-statement-concerning-the-suppression-of-accuracy-in-artificial-intelligence-systems - [draft] FTC proposed Policy Statement on 'Suppression of Accuracy' in AI systems (open for comment) (FTC, 2026-07-07): Implementing EO 14365, the FTC published for comment a policy statement asserting that steering AI systems toward undisclosed objectives and away from accurate outputs — including to comply with state mandates — can be a deceptive practice under FTC Act Section 5, and that state laws requiring such 'suppression of accuracy' may be impliedly preempted as in conflict with Section 5. Comments are due July 31, 2026 (Docket FTC-2026-0859, Matter No. P264200). If finalized it would be agency guidance rather than a rule, but it is designed to underwrite the administration's preemption strategy against state output-alteration mandates. https://www.federalregister.gov/documents/2026/07/07/2026-13628/policy-statement-concerning-the-suppression-of-accuracy-in-artificial-intelligence-systems - [draft] Federal preemption of state AI laws — 2026 legislative landscape (pending) (Congress, 2026-07): After two failed moratorium attempts, preemption moved to standalone vehicles: Sen. Cruz's September 2025 AI policy framework pledged broad preemption legislation, and Rep. Baumgartner's American AI Leadership and Uniformity Act (H.R. 5388, introduced Sept. 16, 2025) would impose a temporary moratorium on certain state AI restrictions. Press reports also describe an Obernolte-Trahan 'Great American AI Act' discussion draft pairing frontier-model safety rules with preemption, and a Cruz-targeted July 29, 2026 Senate Commerce markup for AI bills (outcome unconfirmed). Counter-legislation is pending the other way: the GUARDRAILS Act (H.R. 8031, Beyer / S. 4216, Schatz) would repeal Executive Order 14365 — the Dec. 11, 2025 order directing a national AI policy framework and pressure on state AI laws — and Sen. Markey's States' Right to Regulate AI Act (S. 3557) would defund its implementation. As of late July 2026 no federal preemption statute has been enacted and state AI laws remain enforceable. https://www.govinfo.gov/app/details/BILLS-119hr5388ih - [news] California 2026 landscape: session developments, SB 7 veto, and CPPA ADMT regulations (California Legislature, 2026-07): As of July 2026 California has the deepest operative stack of state AI law: SB 53, AB 2013, and SB 243 took effect January 1, 2026, and SB 942/AB 853 becomes operative August 2, 2026. In October 2025 Governor Newsom vetoed SB 7 (the 'No Robo Bosses Act'), which would have required employer notice for automated decision-making in employment, and signed over a dozen narrower AI bills on chatbots, pricing algorithms, deepfakes, and digital replicas; separately, the California Privacy Protection Agency's automated decision-making technology (ADMT) regulations under the CCPA were finalized in 2025, with phased compliance dates (ADMT compliance obligations by January 1, 2027; risk-assessment submissions on later dates). The 2025-26 session runs through August 31, 2026, under open federal preemption pressure from the December 2025 executive order, which singles out California-style AI mandates for challenge. https://www.lw.com/en/insights/california-assumes-role-as-lead-us-regulator-of-ai - [draft] NO FAKES Act of 2026 (S. 4591) (Congress, 2026-06-24): The revised NO FAKES Act (Nurture Originals, Foster Art, and Keep Entertainment Safe Act of 2026) creates a federal intellectual-property-like right in one's voice and visual likeness, imposing liability for producing or distributing unauthorized AI 'digital replicas,' with notice-and-takedown obligations and safe harbors for platforms. Introduced May 20, 2026 by Sen. Coons with 13 bipartisan cosponsors, it was reported by Senate Judiciary in June 2026 (official reported print June 24; the committee vote, reported as unanimous, was June 18) and awaits a Senate floor vote. It supersedes the 2025 version (S. 1367, introduced April 9, 2025) and a 2024 predecessor that died without a vote. https://www.govinfo.gov/app/details/BILLS-119s4591rs - [news] AI copyright litigation wave broadens: music amendments, Elsevier v. Meta, Midjourney and MiniMax studio suits (Federal courts (various), 2026-06-18): Mid-2026 docket activity shows the training-data fight expanding beyond books and news: record labels in UMG v. Suno and Sony v. Udio moved to add works uncovered in forensic review of training data even as settlement and licensing deals reshape the music cases; Elsevier, Hachette, McGraw Hill, and other publishers filed a new SDNY suit against Meta over systematic torrenting of copyrighted works; and the Disney/Universal/Warner suits against Midjourney and Disney v. MiniMax proceed through discovery and answers. Together with Bartz's $1.5B benchmark, the wave is pushing the industry toward licensing markets in the absence of congressional action. https://www.mckoolsmith.com/newsroom-ailitigation-62 - [draft] GSA draft acquisition clause on safeguarding data in large language model systems (open for comment) (General Services Administration, 2026-06-17): GSA requested public comment and announced listening sessions on a draft GSAR clause governing basic safeguarding of data within large language model AI systems acquired by the federal government. Written comments are due by August 3, 2026. If adopted, the clause would embed LLM data-security requirements directly into federal ICT procurement. https://www.federalregister.gov/documents/2026/06/17/2026-12205/general-services-acquisition-regulation-acquisition-of-information-and-communication-technology - [news] Thomson Reuters v. Ross Intelligence: Third Circuit hears first appellate argument on AI training fair use (U.S. Court of Appeals, Third Circuit, 2026-06-11): The Third Circuit heard oral argument on June 11, 2026 in the first federal appeal squarely presenting whether training an AI model on copyrighted material (Westlaw headnotes, used for a non-generative legal research tool) is fair use, reviewing Judge Bibas's February 2025 ruling that it was not. The panel (Restrepo, Montgomery-Reeves, Bove) pressed both sides on transformativeness and market harm. The forthcoming decision will be the first appellate precedent shaping generative-AI training cases; no ruling had issued as of late July 2026. https://www.lawnext.com/2026/06/at-3rd-circuit-judges-press-ross-and-thomson-reuters-on-fair-use-ai-training-and-market-harm.html - [in_force] Executive Order 14409 — Promoting Advanced Artificial Intelligence Innovation and Security (White House (Trump), 2026-06-02): The administration's first order squarely addressing frontier-model security risk, choosing voluntary mechanisms over mandatory safety review. It directs agencies on 30- and 60-day timelines to harden federal systems with AI-enabled cyber defenses, orders design of a voluntary framework under which developers of NSA-designated 'covered frontier models' may give the government pre-release access for up to 30 days, directs Treasury, NSA, and CISA to form an AI cybersecurity vulnerability clearinghouse in voluntary collaboration with industry and critical-infrastructure operators, and directs DOJ to prioritize criminal enforcement against AI-enabled computer crimes. https://www.federalregister.gov/documents/2026/06/05/2026-11415/promoting-advanced-artificial-intelligence-innovation-and-security - [in_force] Executive Order 14409 — Promoting Advanced Artificial Intelligence Innovation and Security (White House, 2026-06-02): Signed June 2, 2026 (published June 5, 91 FR 34565), EO 14409 pairs AI-enabled cyber defense of government and critical-infrastructure systems (with 30-day prioritization directives) with a voluntary framework for engaging developers of covered frontier models, a Treasury-formed AI cybersecurity clearinghouse for vulnerability scanning and patching, and prioritized DOJ enforcement against criminal misuse of AI. It expressly disclaims authorizing any mandatory licensing, preclearance, or permitting requirement for developing or releasing AI models — codifying the administration's opposition to ex-ante frontier regulation. https://www.federalregister.gov/documents/2026/06/05/2026-11415/promoting-advanced-artificial-intelligence-innovation-and-security - [news] State deepfake, election, and likeness laws — the pattern (Multiple state legislatures, 2026-06): At least 28 states now have election-deepfake statutes, splitting into two models: disclosure mandates on AI-generated political media (e.g., Colorado, Utah, Oregon, Wisconsin, and California's surviving AB 730 approach) and outright prohibitions on materially deceptive synthetic media near elections (Minnesota, Michigan, Mississippi, Texas' pioneering 2019 SB 751). The prohibition model is faring worse in court: California's AB 2839 was struck down on First Amendment grounds and AB 2655 held preempted by Section 230 (Kohls v. Bonta, E.D. Cal. 2024-25), while Minnesota's ban survived preliminary-injunction review — the Eighth Circuit affirmed denial of the injunction on February 9, 2026 — but merits litigation continues (Kohls v. Ellison). A parallel wave covers non-consensual intimate imagery (near-universal among states, now backstopped federally by the TAKE IT DOWN Act) and digital-replica/likeness rights for performers (Tennessee's ELVIS Act, California AB 1836/AB 2602), which bind platforms, distributors, and contracting studios rather than model developers. https://www.recordinglaw.com/us-laws/deepfake-laws/ - [draft] FDA request for information: AI-enabled optimization of early-phase clinical trials pilot (FDA, 2026-05-28): FDA extended the comment period on an RFI (originally published April 29, 2026) for a pilot program assessing how AI-enabled technologies can improve the efficiency, speed, and quality of decision-making in early-phase clinical trials; the extended comment period closed June 29, 2026. The initiative signals an enabling rather than restrictive posture toward AI in drug development. https://www.federalregister.gov/documents/2026/05/28/2026-10602/ai-enabled-optimization-of-early-phase-clinical-trials-pilot-program-request-for-information - [announced] Colorado repeals and replaces its AI Act with narrower ADMT law (SB 26-189) (Colorado General Assembly, 2026-05-14): Gov. Polis signed SB 26-189 ('Automated Decision-Making Technology') on May 14, 2026, repealing and reenacting the 2024 Colorado AI Act's high-risk framework as a transparency-focused regime for automated decision-making technology used in consequential decisions. The rewrite drops the duty of reasonable care against algorithmic discrimination, risk-management programs, and impact assessments, substituting clear notice at the point of interaction, post-adverse-decision disclosures within 30 days, and a right to meaningful human review and reconsideration. Substantive duties take effect January 1, 2027; violations are deceptive trade practices enforced by the attorney general, with a 60-day notice-and-cure period before January 1, 2030. https://leg.colorado.gov/bills/sb26-189 - [draft] GUARD Act (S. 3062) — AI companion chatbots and minors (Congress, 2026-05-11): The Hawley-Blumenthal GUARD Act would ban AI companion chatbots for minors, require age verification and disclosure that a chatbot is not human, and create criminal penalties for companies whose companion bots solicit or produce sexual content for minors. Senate Judiciary advanced it in late April 2026 (reported as a unanimous April 30 vote; the official reported print, retitled GUARD Act of 2026 with 19 cosponsors, is dated May 11, 2026), and it awaits Senate floor action. A bipartisan House companion was reported introduced in spring 2026. It is the leading federal response to a wave of state chatbot laws and child-safety litigation. https://www.govinfo.gov/app/details/BILLS-119s3062rs - [news] FY2026 appropriations — no AI preemption rider enacted (Congress, 2026-04-30): Despite speculation that a state-AI-law moratorium would ride on must-pass funding bills after the OBBBA and NDAA failures, no AI preemption rider appeared in any FY2026 funding law. All twelve regular FY2026 appropriations bills are now enacted — Agriculture, MilCon-VA, and Legislative Branch via the November 12, 2025 CR package (P.L. 119-37, H.R. 5371); Commerce-Justice-Science, Energy-Water, and Interior on January 23, 2026; Defense, Labor-HHS, Transportation-HUD, Financial Services, and National Security-State on February 3, 2026; and Homeland Security on April 30, 2026 — none carrying AI preemption language. Appropriations activity affecting AI has been funding-level (NIST, NSF, DOE AI programs) rather than policy-rider-driven. https://www.crfb.org/blogs/appropriations-watch-fy-2026 - [draft] CREATE AI Act (H.R. 2385 / S. 4441) — codifying the NAIRR (Congress, 2026-04-29): The CREATE AI Act would statutorily establish the National Artificial Intelligence Research Resource at NSF, giving academic researchers, educators, and students access to compute, datasets, and testbeds. The NAIRR pilot has run since early 2024 and survived the revocation of the Biden EO that spawned it, but has no permanent authorization. The House bill (Obernolte-Beyer, H.R. 2385) was introduced March 26, 2025; Sens. Young, Heinrich, Rounds, and Booker reintroduced the Senate version (S. 4441) on April 29, 2026, referred to Senate Commerce. Repeatedly bipartisan, repeatedly short of the finish line: a committee-passed 118th Congress version died at the end of 2024. https://www.govinfo.gov/app/details/BILLS-119s4441is - [news] xAI v. Colorado and first-ever DOJ intervention against a state AI law; Colorado AI Act enforcement suspended (DOJ / U.S. District Court, D. Colo., 2026-04-24): In early April 2026, xAI sued the Colorado attorney general (X.AI LLC v. Weiser, No. 1:26-cv-01515, D. Colo.) to enjoin the Colorado AI Act (SB 24-205) before its June 30, 2026 compliance date, raising First Amendment, extraterritoriality/dormant Commerce Clause, and due-process claims. On April 24, 2026, DOJ moved to intervene — the first federal intervention against a state AI law, implementing EO 14365 — arguing the Act unconstitutionally compels discrimination. On April 27, 2026, the court granted a joint motion temporarily suspending enforcement pending legislative amendments; Colorado then repealed and replaced the Act (SB 26-189, signed May 14, 2026). https://www.nortonrosefulbright.com/en/knowledge/publications/de3ad9de/xai-sues-doj-intervenes-enforcement-of-colorado-ai-act-suspended - [news] Supreme Court, Cox Communications v. Sony Music: contributory infringement narrowed, with AI spillover (U.S. Supreme Court, 2026-03-25): On March 25, 2026, the Court held unanimously in judgment (opinion by Justice Thomas, with Sotomayor and Jackson concurring separately) that a company is not contributorily liable merely for providing a service to the public with knowledge that some users will infringe — liability requires inducement or a service tailored to infringement. Though an ISP case, it immediately reshaped AI litigation: defendants including OpenAI, Nvidia, Google, and Meta began invoking Cox to attack secondary-liability theories in training-data cases. https://en.wikipedia.org/wiki/Cox_Communications,_Inc._v._Sony_Music_Entertainment - [announced] National Policy Framework for Artificial Intelligence (White House legislative blueprint) (White House, 2026-03-20): Released March 20, 2026 pursuant to EO 14365, this framework gives Congress the administration's blueprint for a single federal AI statute: age-assurance and parental-control requirements for minors' AI use, a stated position that training on copyrighted works does not violate copyright law (while deferring final resolution to courts), voluntary collective licensing markets, limits on government jawboning of AI content, no new centralized AI regulator, and federal preemption of state AI laws with child-safety and consumer-protection carve-outs. It is a legislative recommendation document with no binding force of its own. https://www.wilmerhale.com/en/insights/blogs/wilmerhale-privacy-and-cybersecurity-law/20260323-white-house-releases-national-policy-framework-for-artificial-intelligence - [announced] White House National Policy Framework for Artificial Intelligence (legislative blueprint for federal preemption) (White House, 2026-03-20): The White House released its promised national AI legislative framework on March 20, 2026, urging Congress to adopt a single national standard preempting the state patchwork while preserving state authority over child protection, fraud, and consumer protection. It asserts states should not regulate AI model development or penalize developers for unlawful third-party use of their models. It is a non-binding set of recommendations organized around six themes, and congressional action remains uncertain. https://www.wilmerhale.com/en/insights/blogs/wilmerhale-privacy-and-cybersecurity-law/20260323-white-house-releases-national-policy-framework-for-artificial-intelligence - [in_force] BIS Revision to License Review Policy for Advanced Computing Commodities (Nvidia H200 / AMD MI325X to China) (Commerce / BIS, 2026-01-15): A final rule (published and effective January 15, 2026) shifting BIS license review for exports of Nvidia H200, AMD MI325X, and comparable AI accelerators to China from presumption of denial to case-by-case review, conditioned on showings that exports will not reduce chip supply available to US customers, that Chinese purchasers maintain export-compliance and customer-screening programs, and that products pass independent third-party US testing. It followed the President's December 8, 2025 announcement permitting such sales and continues the 2025 trajectory in which H20-class chip sales to China were first restricted (April 2025 license requirement), then licensed under a reported revenue-sharing arrangement (August 2025). Despite roughly $10 billion in approved licenses, BIS Under Secretary Jeffrey Kessler testified on July 14, 2026 that actual H200 shipments to China remain 'trivial.' https://www.federalregister.gov/documents/2026/01/15/2026-00789/revision-to-license-review-policy-for-advanced-computing-commodities - [draft] DEFIANCE Act of 2025 (S. 1837) — passed Senate, pending in House (Congress, 2026-01-13): The DEFIANCE Act creates a federal civil cause of action letting victims of nonconsensual sexually explicit deepfakes sue creators and distributors, with liquidated damages reported up to $250,000 in aggravated cases. It passed the Senate by unanimous consent on January 13, 2026 (its second unanimous Senate passage; the 2024 version died in the House) and now awaits House action, where the companion effort is led by Rep. Ocasio-Cortez. It complements the criminal TAKE IT DOWN Act with a private remedy. https://www.govinfo.gov/app/details/BILLS-119s1837es - [news] NYT v. OpenAI / In re OpenAI Copyright Litigation: 20 million ChatGPT logs ordered produced; sanctions fight follows (U.S. District Court, S.D.N.Y., 2026-01-05): In the consolidated SDNY litigation (16 copyright suits including the New York Times and Chicago Tribune), Judge Sidney Stein on January 5, 2026 affirmed Magistrate Judge Wang's November 2025 order compelling OpenAI to produce a de-identified sample of 20 million ChatGPT conversation logs, finding sample reduction, de-identification, and protective orders sufficient to protect user privacy. The consolidated cases remain the bellwether for whether training on and outputting news content is fair use. In July 2026, the news plaintiffs moved for sanctions, alleging OpenAI concealed its ability to search its training data and output logs for plaintiffs' works. https://natlawreview.com/article/openai-loses-privacy-gambit-20-million-chatgpt-logs-likely-headed-copyright - [in_force] California SB 53 — Transparency in Frontier Artificial Intelligence Act (TFAIA) (California Legislature, 2026-01-01): Signed September 29, 2025 (Chapter 138) and effective January 1, 2026, TFAIA is the first enacted US law aimed at catastrophic risk from frontier AI. It binds 'frontier developers' (models trained with more than 10^26 integer or floating-point operations) and imposes heavier duties on 'large frontier developers' (frontier developers with over $500M annual revenue): publishing a frontier AI framework, per-model transparency reports, reporting critical safety incidents to the California Office of Emergency Services (within 15 days, or 24 hours where imminent danger exists), and whistleblower protections for AI-safety personnel. The Attorney General enforces with civil penalties up to $1 million per violation; the act also launches the CalCompute public compute consortium. https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB53 - [in_force] California AB 2013 — Generative AI: Training Data Transparency (California Legislature, 2026-01-01): Signed September 28, 2024 and effective January 1, 2026, AB 2013 requires developers of generative AI systems or services made publicly available to Californians to post on their websites high-level documentation of the datasets used in training, including sources, whether the data contains personal or copyrighted material, and whether synthetic data was used. It applies retroactively to systems released on or after January 1, 2022, and to substantial modifications of them. It binds developers regardless of size, making it one of the broadest disclosure mandates now operative in the US. https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240AB2013 - [in_force] California SB 243 — Companion Chatbot Safeguards (California Legislature, 2026-01-01): Signed October 13, 2025 (Chapter 677) and effective January 1, 2026, SB 243 binds any operator making a 'companion chatbot' available to California users. Operators must disclose that users are interacting with AI, maintain published protocols for responding to suicidal ideation and self-harm (with referrals to crisis services), and apply additional safeguards for known minors (explicit AI disclosure, three-hour reminders, and blocking sexually explicit content); annual reporting to the Office of Suicide Prevention begins July 1, 2027. The law includes a private right of action with damages of at least $1,000 per violation plus attorney's fees, a rarity among state AI statutes. https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB243 - [in_force] Texas Responsible Artificial Intelligence Governance Act (TRAIGA, HB 149) (Texas Legislature, 2026-01-01): Signed June 22, 2025 and effective January 1, 2026, TRAIGA binds any person who develops or deploys AI systems in Texas or offers AI-touched products or services used by Texas residents, plus Texas government agencies. Rather than a risk-tier framework, it prohibits developing or deploying AI with intent to cause specified harms — behavioral manipulation inciting self-harm or crime, unlawful discrimination, constitutional-rights infringement, and CSAM/unlawful deepfakes — and restricts government social scoring and biometric identification. The Attorney General has exclusive enforcement with a 60-day cure period, there is no private right of action, and the act preempts local AI ordinances; it also creates a regulatory sandbox and an AI advisory council. https://capitol.texas.gov/BillLookup/History.aspx?LegSess=89R&Bill=HB149 - [in_force] Illinois HB 3773 — AI Amendments to the Illinois Human Rights Act (P.A. 103-0804) (Illinois General Assembly, 2026-01-01): Signed August 9, 2024 and effective January 1, 2026, HB 3773 makes it a civil-rights violation for employers to use AI that has the effect of discriminating on the basis of protected classes in recruitment, hiring, promotion, discipline, discharge, or other terms of employment, and bans use of zip code as a proxy for protected characteristics. Employers must notify applicants and employees when AI is used for such decisions. It binds essentially all Illinois employers (the IHRA covers employers with one or more employees) and is enforced through the Illinois Department of Human Rights charge process; IDHR published proposed implementing rules on May 15, 2026 but temporarily withdrew them on June 2, 2026 — the statutory obligations apply regardless. https://natlawreview.com/article/illinois-anti-discrimination-law-address-ai-goes-effect-1-january-2026 - [announced] New York enacts RAISE Act for frontier AI models; March 2026 amendments align it with California (New York Legislature / Governor Hochul, 2025-12-19): Gov. Hochul signed the RAISE Act (S6953B/A6453B) on December 19, 2025, making New York the second state (after California's SB 53) to impose transparency and safety-governance duties on frontier AI developers. Chapter amendments signed March 27, 2026 (S8828, Chapter 96) narrowed the law: it covers frontier models trained above 10^26 operations, defines 'large frontier developers' at $500M+ annual revenue, and requires published safety frameworks, pre-deployment transparency reports, and safety-incident reporting to the Department of Financial Services within 72 hours (24 hours for imminent risk). It takes effect January 1, 2027, with civil penalties up to $1M for a first violation and $3M for subsequent ones. https://www.governor.ny.gov/news/governor-hochul-signs-nation-leading-legislation-require-ai-frameworks-ai-frontier-models - [in_force] National Defense Authorization Act for Fiscal Year 2026 (AI provisions; state-AI moratorium excluded) (Congress, 2025-12-18): Signed December 18, 2025 as Pub. L. 119-60 (S. 1071), the FY2026 NDAA carries an extensive slate of AI provisions — described by law-firm analyses as the largest of any NDAA to date — including a National Security and Defense Artificial Intelligence Institute (sec. 224), pilot programs to integrate commercial AI across DoD, AI governance framework mandates, a prohibition on DoD use of certain covered AI (sec. 1532), and a ban on DeepSeek on intelligence community systems (sec. 6604). Critically for the preemption debate, Congress excluded a proposed moratorium on state AI laws from the final bill — the second time in 2025 such language failed. https://www.govinfo.gov/app/details/PLAW-119publ60 - [in_force] Executive Order 14365 — Ensuring a National Policy Framework for Artificial Intelligence (state-law preemption push) (White House (Trump), 2025-12-11): The administration's frontal challenge to state AI regulation: it directed DOJ to create an AI Litigation Task Force within 30 days (established January 9, 2026 by Attorney General memorandum) to challenge state AI laws as unconstitutional or preempted, ordered Commerce to publish an evaluation of onerous state AI laws and condition BEAD non-deployment funds on states' AI regulatory posture, directed the FCC to consider a preemptive federal AI reporting/disclosure standard, and directed the FTC to issue a policy statement on FTC Act preemption of state laws requiring alterations to truthful model outputs. The order itself cannot preempt state law — that requires Congress or successful litigation. https://www.federalregister.gov/documents/2025/12/16/2025-23092/ensuring-a-national-policy-framework-for-artificial-intelligence - [news] Federal preemption pressure on state AI law (context): EO 14365, 'Ensuring a National Policy Framework for Artificial Intelligence' (White House, 2025-12-11): Signed December 11, 2025, Executive Order 14365 directed the Attorney General to stand up an AI Litigation Task Force within 30 days (by January 10, 2026) to challenge state AI laws as unconstitutional burdens on interstate commerce or compelled speech, directed Commerce to identify 'onerous' state AI laws within 90 days, and leveraged federal funding — including BEAD broadband money — against states with such regimes, naming Colorado's algorithmic-discrimination law specifically. Its effects are already visible in this tracker's slice: xAI sued Colorado in April 2026 with DOJ intervening, Colorado's original framework was paused and then repealed and replaced in May 2026, and New York's RAISE Act was finalized in narrowed form in its shadow. An EO cannot itself preempt state law — only Congress or successful litigation can — so every state law listed here remains valid unless and until courts hold otherwise. https://www.whitehouse.gov/presidential-actions/2025/12/eliminating-state-law-obstruction-of-national-artificial-intelligence-policy/ - [in_force] Executive Order 14365 — Ensuring a National Policy Framework for Artificial Intelligence (state-law preemption push) (White House, 2025-12-11): President Trump signed EO 14365 on December 11, 2025 (90 FR 58499), directing the federal government to counter state AI regulation. It orders DOJ to establish an AI Litigation Task Force within 30 days to challenge state AI laws, requires Commerce to publish an evaluation identifying 'onerous' state AI laws within 90 days (i.e., by March 11, 2026) with identified states losing BEAD non-deployment funds, and directs the FTC to issue a policy statement on when state laws requiring alteration of truthful AI outputs are preempted. It is binding executive action but cannot itself preempt state law; its legislative-recommendation section carves out child safety, AI compute/data-center infrastructure, and state procurement. https://www.federalregister.gov/documents/2025/12/16/2025-23092/ensuring-a-national-policy-framework-for-artificial-intelligence - [in_force] Executive Order 14363 — Launching the Genesis Mission (White House (Trump), 2025-11-24): Launches a DOE-implemented national initiative — described in the order's own text as comparable in urgency and ambition to the Manhattan Project — to build the American Science and Security Platform, an integrated AI platform uniting national-laboratory supercomputers and federal scientific datasets (which the order calls the world's largest such collection) to train scientific foundation models and AI agents for research. https://www.federalregister.gov/documents/2025/11/28/2025-21665/launching-the-genesis-mission - [draft] GAIN AI Act (H.R. 5885) — domestic priority for advanced AI chips (Congress, 2025-10-31): The GAIN AI Act (Guaranteeing Access and Innovation for National Artificial Intelligence Act of 2025, Rep. Moolenaar) would require entities seeking licenses to export advanced AI chips to countries of concern to certify that US persons have priority access to those chips — a CHIPS-adjacent effort to keep frontier compute onshore. A version pushed as an FY2026 NDAA amendment was excluded from the final defense bill amid White House and Nvidia opposition; the standalone bill remains in House Foreign Affairs. https://www.govinfo.gov/app/details/BILLS-119hr5885ih - [draft] GUARD Act: proposed federal restrictions on AI companion chatbots for minors (Congress, 2025-10-28): Senators Hawley and Blumenthal, with other senators, introduced the GUARD Act on October 28, 2025 to restrict minors' (under-18) access to AI companion chatbots: it requires age verification for chatbot accounts, recurring disclosures that chatbots are not human and hold no professional credentials, and criminal penalties for knowingly providing minors access to chatbots that solicit sexually explicit content or promote suicide, self-harm, or violence, with enforcement by the U.S. Attorney General and state attorneys general. It remains pending, but with the White House's March 2026 framework carving child safety out of preemption, chatbot child-safety rules are the likeliest area of bipartisan federal AI legislation. https://calawyers.org/privacy-law/regulatory-focus-on-ai-companion-character-chatbots/ - [news] FTC launches Section 6(b) inquiry into AI companion chatbots and harms to minors (FTC, 2025-09-11): The FTC issued compulsory 6(b) orders to seven companies operating consumer AI chatbots — Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap, and xAI — seeking information on how companion-style chatbots are designed, monetized, tested, and monitored for negative impacts on children and teens. The study, prompted in part by teen-suicide litigation against chatbot makers, is not an enforcement action but positions the agency for future cases and reporting. https://www.ftc.gov/news-events/news/press-releases/2025/09/ftc-launches-inquiry-ai-chatbots-acting-companions - [draft] SANDBOX Act (S. 2750) and the Cruz AI legislative framework (Congress, 2025-09-10): Sen. Cruz's SANDBOX Act would direct OSTP to run a federal AI regulatory sandbox in which developers obtain renewable waivers or modifications of federal rules (potentially up to 10 years) to test and deploy AI products, with regular reporting to Congress. Introduced September 10, 2025 as the first legislative implementation of the administration's AI Action Plan, it anchors Cruz's broader 'Legislative Framework for American Leadership in AI,' which also promises state-law preemption legislation. Still in Senate Commerce as of July 2026; reported as a candidate for the committee's late-July 2026 AI markup. https://www.govinfo.gov/app/details/BILLS-119s2750is - [draft] SANDBOX Act (S. 2750) and congressional AI preemption bills (Congress, 2025-09-10): Senate Commerce Chair Ted Cruz introduced the SANDBOX Act (S. 2750) on September 10, 2025, directing OSTP to run a federal AI regulatory sandbox letting developers apply to waive or modify federal regulations for renewable two-year terms — the first plank of his light-touch AI framework. Separately, Rep. Baumgartner's American Artificial Intelligence Leadership and Uniformity Act (H.R. 5388, introduced September 16, 2025) would impose a five-year moratorium preempting state AI laws. Neither had been enacted as of July 2026: broad statutory preemption has struggled since the Senate stripped the OBBBA AI moratorium 99-1 in July 2025, and the fight now centers on the White House's March 2026 framework. https://www.govinfo.gov/app/details/BILLS-119s2750is - [news] Colorado special session delays AI Act enforcement to June 30, 2026 (SB 25B-004) (Colorado General Assembly, 2025-08-28): After lawmakers failed to agree on substantive amendments to the first-in-the-nation Colorado AI Act during the 2025 regular and special sessions, Gov. Polis signed SB 25B-004 ('Increase Transparency for Algorithmic Systems') on August 28, 2025, pushing the law's compliance date from February 1, 2026 to June 30, 2026. The bill made no substantive changes — a delay designed to give the 2026 session time to rework the law, which ultimately produced the SB 26-189 repeal-and-replace. https://leg.colorado.gov/bills/sb25b-004 - [news] Raine v. OpenAI and the AI chatbot wrongful-death docket (California Superior Court (San Francisco), 2025-08-26): The August 26, 2025 wrongful-death suit by the parents of 16-year-old Adam Raine against OpenAI and Sam Altman — alleging ChatGPT encouraged their son's suicidal ideation and that OpenAI weakened self-harm safeguards — became the flagship of a growing product-liability docket against chatbot makers, alongside the Character.AI cases. An amended complaint (October 2025) added claims that OpenAI removed safeguards before the teen's death; OpenAI's November 2025 answer denied responsibility, citing crisis-resource referrals and terms-of-use violations. The litigation helped propel California SB 243, the FTC 6(b) chatbot inquiry, and federal chatbot child-safety proposals; no merits rulings had issued as of mid-2026. https://en.wikipedia.org/wiki/Raine_v._OpenAI - [in_force] Illinois Wellness and Oversight for Psychological Resources Act (WOPR, P.A. 104-0054) (Illinois General Assembly, 2025-08-01): Signed and effective August 1, 2025, the WOPR Act (HB 1806) is the first state statute to prohibit AI systems from independently providing therapy or psychotherapy services. Licensed clinicians may use AI only for administrative and supplementary support — not for therapeutic communication or independent treatment decisions — while general-purpose wellness apps outside the scope of therapy remain lawful. It binds anyone offering therapy services to Illinois residents, with civil penalties up to $10,000 per violation enforced by the Illinois Department of Financial and Professional Regulation. https://www.bakerdonelson.com/illinois-passes-extensive-law-regulating-ai-in-behavioral-health - [announced] Winning the Race: America's AI Action Plan (White House (OSTP), 2025-07-23): The administration's roadmap required by EO 14179, organizing roughly 90 policy actions under three pillars: accelerating AI innovation, building American AI infrastructure, and leading in international AI diplomacy and security. It is a policy document, not binding law, but frames the administration's subsequent executive action — including the three July 23, 2025 EOs signed alongside it, and it is expressly invoked in the Genesis Mission order (EO 14363). https://www.whitehouse.gov/wp-content/uploads/2025/07/Americas-AI-Action-Plan.pdf - [in_force] Executive Order 14318 — Accelerating Federal Permitting of Data Center Infrastructure (White House (Trump), 2025-07-23): Directs financial support (loans, grants, tax incentives, offtake agreements) for qualifying AI data center projects, new NEPA categorical exclusions and expedited FAST-41 treatment, Clean Water Act section 404 permitting review, and federal-land and military-installation siting through Interior, Energy, and Defense. It revoked Biden's EO 14141, replacing clean-energy-conditioned federal siting with a deregulatory permitting regime. https://www.whitehouse.gov/presidential-actions/2025/07/accelerating-federal-permitting-of-data-center-infrastructure/ - [in_force] Executive Order 14319 — Preventing Woke AI in the Federal Government (White House (Trump), 2025-07-23): Requires federal agencies to procure only large language models that comply with two 'Unbiased AI Principles' — truth-seeking and ideological neutrality — and identifies DEI-related output shaping as inconsistent with those principles. Implemented through federal procurement contract terms rather than direct regulation of the private market, but functions as a de facto standard for any LLM vendor selling to the government. https://www.federalregister.gov/documents/2025/07/28/2025-14217/preventing-woke-ai-in-the-federal-government - [in_force] Executive Order 14320 — Promoting the Export of the American AI Technology Stack (White House (Trump), 2025-07-23): Establishes the American AI Exports Program at the Commerce Department to assemble and promote full-stack US AI export packages — chips, servers, models, software, and cloud services — for allied and partner markets, with federal financing support through tools such as EXIM and DFC. Commerce stood up the program and issued its first call for proposals in late 2025. https://www.federalregister.gov/documents/2025/07/28/2025-14218/promoting-the-export-of-the-american-ai-technology-stack - [news] State AI-law moratorium in 2025 budget reconciliation (One Big Beautiful Bill Act) — DEAD (Congress, 2025-07-01): The House-passed reconciliation bill (H.R. 1) contained a 10-year moratorium barring state enforcement of AI regulations; the Senate reworked it into a 5-year condition tied to BEAD broadband funds, then voted 99-1 on July 1, 2025 to strip the provision entirely. The One Big Beautiful Bill Act was signed July 4, 2025 with no AI preemption language, making this the highest-profile failed federal preemption effort. The fight then migrated to the FY2026 NDAA (excluded again, December 2025) and to the executive branch. https://www.govinfo.gov/app/details/PLAW-119publ21 - [superseded] SEC: predictive data analytics (AI conflicts) rule withdrawn; 'AI-washing' enforcement continues (SEC, 2025-06-17): By Federal Register notice published and effective June 17, 2025 (Commission notices dated June 12, 2025), the SEC formally withdrew fourteen Gensler-era rule proposals, including the July 2023 proposed conflicts-of-interest rule for broker-dealers' and investment advisers' use of predictive data analytics and AI (File S7-12-23). The Commission stated it does not intend to issue final rules on these proposals and would issue a new proposal if it revisits the area. Meanwhile, enforcement against 'AI-washing' — misrepresenting AI use to investors — continues under existing antifraud authority (Delphia and Global Predictions in 2024; Rimar Capital, Presto Automation, and Nate Inc. among later actions). https://www.federalregister.gov/documents/2025/06/17/2025-11110/withdrawal-of-proposed-regulatory-actions - [in_force] US AI Safety Institute renamed Center for AI Standards and Innovation (CAISI) (Department of Commerce / NIST, 2025-06-03): Commerce Secretary Howard Lutnick transformed the Biden-era US AI Safety Institute (AISI, created at NIST in late 2023) into the Center for AI Standards and Innovation, dropping 'safety' from the name and reorienting the mission toward national-security evaluations (cybersecurity, biosecurity), standards leadership, and assessment of adversary AI systems such as Chinese frontier models. This is an administrative reorganization, not legislation — CAISI's evaluations of US developers rest on voluntary agreements. https://www.nist.gov/caisi - [in_force] TAKE IT DOWN Act (Congress, 2025-05-19): Pub. L. 119-12 (S. 146, Klobuchar-Cruz) is the first federal statute squarely regulating an AI harm: it criminalizes knowingly publishing nonconsensual intimate visual depictions, explicitly including AI-generated 'digital forgeries' (deepfakes), with enhanced penalties for images of minors. It also requires covered platforms to operate a notice-and-removal process taking down reported NCII within 48 hours; the platform obligations became enforceable May 19, 2026, with FTC enforcement as an unfair or deceptive practice. https://www.govinfo.gov/app/details/PLAW-119publ12 - [draft] AI Whistleblower Protection Act (S. 1792) (Congress, 2025-05-15): Grassley-led bipartisan bill extending retaliation protections to employees of AI companies who report AI security vulnerabilities or safety-related legal violations. Introduced May 15, 2025 and referred to the Senate HELP Committee, where it remains as of mid-2026; notable as one of the few AI-safety-oriented bills with cross-party sponsorship in the deregulatory 119th Congress. https://www.govinfo.gov/app/details/BILLS-119s1792is - [superseded] CFPB withdraws AI/algorithm guidance in mass rescission of 67 guidance documents (CFPB, 2025-05-12): By Federal Register notice effective May 12, 2025, the CFPB withdrew 67 guidance documents issued since its inception, including Circular 2022-03 on adverse-action notification requirements for credit decisions based on complex algorithms, along with other algorithm-related circulars (e.g., 2024-06 on algorithmic scores in employment decisions, 2024-01 on digital-intermediary steering). The statutory obligations under ECOA/Regulation B and FCRA are unchanged and remain binding — creditors using AI must still provide specific, accurate adverse-action reasons — but the Bureau has retreated from articulating AI-specific interpretations and from aggressive supervision in this area. https://www.federalregister.gov/documents/2025/05/12/2025-08286/interpretive-rules-policy-statements-and-advisory-opinions-withdrawal - [standard] Copyright Office 'Copyright and Artificial Intelligence' report series (Parts 1–3) and the Perlmutter removal fight (US Copyright Office, 2025-05-09): Three-part advisory study: Part 1 (July 31, 2024) recommends a federal digital-replica law; Part 2 (Jan. 29, 2025) confirms existing law can handle copyrightability of AI-assisted works with human authorship required; Part 3 (May 9, 2025, still a pre-publication version as of July 2026) concludes generative-AI training on copyrighted works is fair use in some circumstances but not others. The reports are non-binding analysis but are heavily cited in the AI training-data litigation wave. Register Shira Perlmutter was fired May 10, 2025 — the day after Part 3's release — ordered restored by a divided D.C. Circuit panel on September 10, 2025, and the Supreme Court (which had deferred the administration's stay application on November 26, 2025) declined to stay her reinstatement on June 30, 2026 (Blanche v. Perlmutter), leaving her in office while the merits litigation proceeds. https://www.copyright.gov/ai/ - [in_force] Executive Order 14277 — Advancing Artificial Intelligence Education for American Youth (White House (Trump), 2025-04-23): Establishes a White House Task Force on AI Education chaired by the OSTP Director, directs federal agencies to promote AI literacy in K-12 education, creates a Presidential AI Challenge, and prioritizes AI-related apprenticeships and educator training. It is a programmatic order without regulatory mandates on the private sector. https://www.whitehouse.gov/presidential-actions/2025/04/advancing-artificial-intelligence-education-for-american-youth/ - [in_force] OMB Memorandum M-25-21 — Accelerating Federal Use of AI through Innovation, Governance, and Public Trust (OMB, 2025-04-03): Rescinds and replaces Biden-era M-24-10 as the governing policy for federal agency use of AI. Retains Chief AI Officers and minimum risk-management practices for 'high-impact AI' but reframes the posture from risk mitigation to innovation acceleration; agencies must maintain public AI strategies and annual AI use-case inventories, with reporting cycles running through 2026. https://www.whitehouse.gov/wp-content/uploads/2025/02/M-25-21-Accelerating-Federal-Use-of-AI-through-Innovation-Governance-and-Public-Trust.pdf - [in_force] OMB Memorandum M-25-22 — Driving Efficient Acquisition of Artificial Intelligence in Government (OMB, 2025-04-03): Rescinds and replaces M-24-18 as the government-wide AI procurement policy, emphasizing a competitive American AI marketplace, protecting agency data from vendor lock-in and unauthorized training use, and performance-based acquisition. It applies to contracts under solicitations issued on or after September 30, 2025, making FY2026 the first full compliance year for federal AI vendors. https://www.whitehouse.gov/wp-content/uploads/2025/02/M-25-22-Driving-Efficient-Acquisition-of-Artificial-Intelligence-in-Government.pdf - [superseded] EEOC withdraws AI employment-discrimination guidance (EEOC, 2025-01-27): Following President Trump's January 23, 2025 AI executive order (EO 14179, 'Removing Barriers to American Leadership in Artificial Intelligence') and related directives, the EEOC on January 27, 2025 removed AI guidance from its website — most prominently the May 2023 technical assistance on adverse impact under Title VII when using algorithmic selection tools, with the 2022 ADA guidance on algorithmic employment decisions also reported removed. The withdrawal removes agency interpretation, not the law: Title VII and the ADA still fully apply to AI-driven hiring, and private plaintiffs and state/local regimes (e.g., NYC Local Law 144, Colorado) continue to fill the gap. https://www.klgates.com/The-Changing-Landscape-of-AI-Federal-Guidance-for-Employers-Reverses-Course-with-New-Administration-1-31-2025 - [in_force] Executive Order 14179 — Removing Barriers to American Leadership in Artificial Intelligence (White House (Trump), 2025-01-23): The foundational AI policy order of the second Trump administration, declaring a policy of sustaining US global AI dominance and directing review and revision of all actions taken under rescinded EO 14110. Section 4 ordered an AI Action Plan within 180 days (delivered July 23, 2025) and Section 5(b) ordered revision of OMB Memoranda M-24-10 and M-24-18 (delivered April 3, 2025 as M-25-21 and M-25-22). Remains the umbrella statement of federal AI policy as of mid-2026. https://www.whitehouse.gov/presidential-actions/2025/01/removing-barriers-to-american-leadership-in-artificial-intelligence/ - [superseded] BIS Framework for Artificial Intelligence Diffusion — rescission announced, formally unresolved (Commerce / BIS, 2025-01-15): The Biden administration's January 2025 interim final rule created a three-tier global licensing system for advanced AI chips and, for the first time, controlled certain closed AI model weights. On May 13, 2025 BIS announced it would rescind the rule and not enforce its May 15, 2025 compliance deadline, issuing companion guidance (including that using certain Huawei Ascend chips risks violating the EAR). Critically, the formal rescission rulemaking has never been completed: no rescission rule appears in the Federal Register as of July 2026, and on May 12, 2026 GAO concluded (B-337935) that the non-enforcement announcement was itself a rule improperly withheld from Congress under the Congressional Review Act — leaving the framework on the books but unenforced. https://www.bis.gov/press-release/department-commerce-announces-rescission-biden-era-artificial-intelligence-diffusion-rule-strengthens - [superseded] Executive Order 14141 — Advancing United States Leadership in Artificial Intelligence Infrastructure (REVOKED) (White House (Biden), 2025-01-14): A late Biden-term order directing DOE and DOD to lease federal sites for gigawatt-scale AI data centers with clean-power conditions. It survived the January 2025 rescission wave but was expressly revoked on July 23, 2025 by Trump EO 14318, which replaced it with a deregulatory permitting regime; the revocation language in EO 14318 reads: "Executive Order 14141 of January 14, 2025 (Advancing United States Leadership in Artificial Intelligence Infrastructure), is hereby revoked." https://www.federalregister.gov/documents/2025/01/17/2025-01395/advancing-united-states-leadership-in-artificial-intelligence-infrastructure - [in_force] FTC Rule on the Use of Consumer Reviews and Testimonials (16 CFR Part 465) — covers AI-generated fake reviews (FTC, 2024-10-21): Prohibits creating, buying, or selling fake consumer reviews and testimonials — expressly including AI-generated reviews by non-existent persons or people without actual product experience — with civil penalties up to statutory per-violation maximums. It is the clearest binding federal rule targeting generative-AI content in commercial contexts and remains in force as of mid-2026. https://www.ecfr.gov/current/title-16/chapter-I/subchapter-D/part-465 - [superseded] California SB 1047 — Safe and Secure Innovation for Frontier AI Models Act (vetoed) (California Legislature, 2024-09-29): The 2024 frontier-model safety bill that would have imposed pre-deployment safety determinations, shutdown capability, and third-party audits on developers of models above a $100M training-cost threshold was vetoed by Governor Newsom on September 29, 2024, who objected that it regulated by model scale rather than by deployment risk. It never bound anyone, but its framework directly shaped the Joint California Policy Working Group report and the narrower transparency-first SB 53, enacted in 2025. It is included here because trackers frequently misreport it as law. https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB1047 - [in_force] FTC Operation AI Comply — enforcement sweep on deceptive AI claims (ongoing) (FTC, 2024-09-25): Enforcement sweep applying existing FTC Act Section 5 deception/unfairness authority to AI: the September 25, 2024 launch bundled five actions (DoNotPay's 'robot lawyer' claims, Rytr's AI review generator, and AI-powered business-opportunity schemes Ascend Ecom, Ecommerce Empire Builders, and FBA Machine). Enforcement has continued under Chairman Ferguson with the same playbook — no new AI-specific statute, just established consumer-protection law applied to AI hype. Orders and settlements are binding on respondents. https://www.ftc.gov/news-events/news/press-releases/2024/09/ftc-announces-crackdown-deceptive-ai-claims-schemes - [superseded] California AB 2839 — election deepfake prohibition (struck down) (California Legislature, 2024-09-17): The most ambitious state election-deepfake ban, signed as an urgency statute in September 2024, prohibited knowingly distributing materially deceptive AI-generated content about candidates and election officials in the months around an election. A federal court preliminarily enjoined it within weeks (October 2, 2024) and in August 2025 struck it down in Kohls v. Bonta as a content-based speech restriction failing First Amendment scrutiny; companion platform-takedown law AB 2655 was separately halted (January 3, 2025) and held preempted by Section 230. It is the landmark cautionary precedent constraining the prohibition model of state deepfake regulation; California's older disclosure-only AB 730 approach survives. https://www.techpolicy.press/tracker/kohls-v-bonta/ - [draft] FCC Proposed Rule — AI-Generated Call Disclosure Requirements (NPRM, not finalized) (FCC, 2024-09-10): An August 2024 NPRM (published in the Federal Register September 10, 2024) proposing to define 'AI-generated call' and require in-call disclosure and AI-specific consent language for robocalls and robotexts, with carve-outs for accessibility uses by people with disabilities. No final rule adopting these requirements was found as of July 2026; the current FCC's deregulatory posture and EO 14365's separate directive that the FCC consider a preemptive federal AI reporting/disclosure standard leave the proceeding's future uncertain. https://www.federalregister.gov/documents/2024/09/10/2024-19028/implications-of-artificial-intelligence-technologies-on-protecting-consumers-from-unwanted-robocalls - [standard] NIST Generative AI Profile (NIST AI 600-1) — companion to the AI RMF (NIST, 2024-07-26): A cross-sectoral profile of the AI RMF identifying twelve risks unique to or exacerbated by generative AI (e.g., confabulation, CBRN information access, data privacy, provenance) with roughly 200 suggested actions. Developed under Biden EO 14110; it remains published and in use even though EO 14110 itself was rescinded in January 2025. Voluntary guidance, not binding. https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf - [in_force] Tennessee ELVIS Act — Ensuring Likeness, Voice and Image Security Act (Tennessee General Assembly, 2024-07-01): Signed March 21, 2024 and effective July 1, 2024, the ELVIS Act was the first US law to extend right-of-publicity protection explicitly to a person's voice, including AI-generated simulations, by amending Tennessee's 1984 Personal Rights Protection Act. It creates civil liability not only for unauthorized commercial use of a person's voice or likeness but also for distributing tools whose primary purpose is producing unauthorized simulations of an identifiable individual. It binds anyone commercially exploiting voice clones or distributing cloning tools reaching Tennessee, with enforcement through private suits by individuals, estates, and rights holders such as record labels. https://www.recordinglaw.com/us-laws/ai-laws/ - [superseded] Colorado AI Act (SB24-205) — Consumer Protections for Artificial Intelligence (Colorado General Assembly, 2024-05-17): The first comprehensive US state AI law, signed May 17, 2024, would have imposed a duty of reasonable care on developers and deployers of 'high-risk' AI systems to prevent algorithmic discrimination in consequential decisions (employment, housing, credit, health care, and similar), backed by risk-management programs, impact assessments, and attorney-general notification. Its compliance date was pushed from February 1, 2026 to June 30, 2026 by SB25B-004 (signed August 28, 2025 in a special session), and in xAI LLC v. Weiser (D. Colo., No. 1:26-cv-01515, filed April 9, 2026, with DOJ intervening) the court granted a joint pause on April 27, 2026 while the legislature acted. SB26-189, signed May 14, 2026, repeals and reenacts the framework effective August 12, 2026, so the 2024 law's algorithmic-discrimination duties were never enforced. https://leg.colorado.gov/bills/sb24-205 - [in_force] Utah Artificial Intelligence Policy Act (SB 149, as amended 2025) (Utah Legislature, 2024-05-01): The first state AI consumer-protection statute, effective May 1, 2024, binds businesses using generative AI in consumer transactions and in regulated occupations: they cannot blame the AI for consumer-protection violations, and must disclose AI use. 2025 amendments effective May 7, 2025 narrowed the duty — SB 226 limits disclosure to when a consumer clearly asks or to 'high-risk' interactions (health, financial, biometric data, or legal/financial/medical advice), with a safe harbor if the chatbot consistently self-identifies as AI, and SB 332 extended the act's sunset to July 1, 2027. Companion 2025 laws added mental-health chatbot rules (HB 452) and AI identity-fraud protections (SB 271); the Office of Artificial Intelligence Policy runs a learning-lab/mitigation-agreement program. https://le.utah.gov/~2024/bills/static/SB0149.html - [in_force] FTC Trade Regulation Rule on Impersonation of Government and Businesses (16 CFR Part 461) (FTC, 2024-04-01): Prohibits impersonation of government agencies and businesses in commerce — the FTC's principal binding tool against AI-enabled deepfake and voice-clone impersonation scams — and allows the FTC to seek civil penalties and consumer redress in federal court. A companion supplemental proposal to extend the rule to impersonation of individuals (aimed directly at AI deepfakes of people) was issued in February 2024 but had not been finalized as of mid-2026. https://www.ecfr.gov/current/title-16/chapter-I/subchapter-D/part-461 - [in_force] FCC Declaratory Ruling — AI-Generated Voices Are 'Artificial' Under the TCPA (FCC 24-17) (FCC, 2024-02-08): A unanimous declaratory ruling confirming that calls using AI-generated or cloned voices are 'artificial or prerecorded voice' calls under the Telephone Consumer Protection Act, requiring prior express consent plus identification and opt-out compliance. This is binding interpretive law effective immediately and remains in force as of mid-2026; it underpins FCC enforcement against AI voice-cloning robocalls, including the 2024 Biden-deepfake primary-election case. https://docs.fcc.gov/public/attachments/FCC-24-17A1.pdf - [superseded] Executive Order 14110 — Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence (RESCINDED) (White House (Biden), 2023-10-30): The Biden administration's flagship AI executive order imposed government-wide AI governance duties, including Defense Production Act reporting requirements for developers of powerful dual-use foundation models. It was rescinded in full on January 20, 2025 by EO 14148 (Initial Rescissions of Harmful Executive Orders and Actions), the first day of the second Trump administration, and no longer has legal effect. https://www.federalregister.gov/documents/2023/11/01/2023-24283/safe-secure-and-trustworthy-development-and-use-of-artificial-intelligence - [in_force] BIS advanced computing and semiconductor export controls (baseline 2022-2024 framework) (Commerce / BIS, 2023-10-17): The underlying export-control architecture for AI chips — ECCN 3A090/4A090 controls, the advanced-computing and supercomputer end-use rules, and China-wide license requirements established in October 2022 and tightened in October 2023 — remains in force and was further expanded in December 2024 to cover high-bandwidth memory and additional semiconductor manufacturing equipment, plus major Entity List additions. The 2025-2026 policy changes (diffusion-rule rescission announcement, H20/H200 licensing shifts) adjusted license review posture on top of this framework rather than dismantling it. https://www.ecfr.gov/current/title-15/subtitle-B/chapter-VII/subchapter-C/part-742 - [standard] White House Voluntary AI Commitments (2023–2024) — status under the current administration (White House (Biden administration), 2023-07-21): Sixteen companies made eight voluntary commitments to the Biden White House on pre-release security testing, information sharing, cybersecurity and model-weight protection, and provenance/watermarking of AI content (Amazon, Anthropic, Google, Inflection, Meta, Microsoft, OpenAI in July 2023; Adobe, Cohere, IBM, Nvidia, Palantir, Salesforce, Scale AI, and Stability AI in September 2023; Apple in July 2024). Never legally binding, they were the template for later voluntary regimes. Under the current administration they have not been formally rescinded but are effectively dormant as a White House program — the voluntary-cooperation model now runs through CAISI's evaluation agreements and the 2025 AI Action Plan's security-oriented framework instead. https://bidenwhitehouse.archives.gov/briefing-room/statements-releases/2023/07/21/fact-sheet-biden-harris-administration-secures-voluntary-commitments-from-leading-artificial-intelligence-companies-to-manage-the-risks-posed-by-ai/ - [in_force] Copyright Office: Copyright Registration Guidance for Works Containing AI-Generated Material (US Copyright Office, 2023-03-16): Policy statement (88 Fed. Reg. 16,190) establishing that copyright protects only material with human authorship: applicants must disclose more-than-de-minimis AI-generated content and disclaim it, while human selection, arrangement, and modification of AI outputs can be protectable. This governs actual registration practice, so it is operationally binding on applicants even though it is guidance rather than statute. https://www.copyright.gov/ai/ - [standard] NIST AI Risk Management Framework (AI RMF 1.0) (NIST, 2023-01-26): NIST's voluntary framework for mapping, measuring, managing, and governing AI risk, organized around four core functions (Govern, Map, Measure, Manage). It remains the de facto baseline for US AI governance programs and is referenced in state statutes (e.g., Colorado SB 24-205 safe harbors) and federal procurement guidance. It is not binding law; adoption is entirely voluntary. https://www.nist.gov/itl/ai-risk-management-framework - [in_force] Advancing American AI Act (Subtitle B, Title LXXII, FY2023 NDAA) (Congress, 2022-12-23): Enacted in the James M. Inhofe NDAA for FY2023 (Pub. L. 117-263, secs. 7221-7228), it requires federal agencies to maintain and publish inventories of their AI use cases, directs OMB to issue guidance on agency AI acquisition and use consistent with agency-use principles, and mandated pilot AI acquisition programs. It is the statutory backbone for the federal AI use-case inventory regime that successive administrations' OMB memoranda implement. https://www.govinfo.gov/app/details/PLAW-117publ263 - [in_force] AI Training Act (Congress, 2022-10-17): Pub. L. 117-207 (S. 2551), the Artificial Intelligence Training for the Acquisition Workforce Act, requires OMB to establish an AI training program for the federal acquisition workforce — program managers, procurement, and logistics officials — so agencies buying AI understand its capabilities and risks. A narrow but binding statute on federal procurement competence. https://www.govinfo.gov/app/details/PLAW-117publ207 - [in_force] CHIPS and Science Act of 2022 (AI-adjacent provisions) (Congress, 2022-08-09): Pub. L. 117-167 appropriated roughly $52.7B for domestic semiconductor manufacturing and R&D — the hardware substrate of the AI industry — and its 'Science' division authorized major AI-relevant programs: the NSF Directorate for Technology, Innovation and Partnerships, expanded AI research institutes, NIST AI testbeds and standards work, and DOE AI research. Authorizations in the Science division have been only partially funded through subsequent appropriations. https://www.govinfo.gov/app/details/PLAW-117publ167 - [in_force] National Artificial Intelligence Initiative Act of 2020 (Division E, FY2021 NDAA) (Congress, 2021-01-01): Enacted as Division E of the William M. (Mac) Thornberry National Defense Authorization Act for FY2021 (Pub. L. 116-283), this remains the foundational US federal AI statute. It established the National AI Initiative and the National AI Initiative Office in OSTP, authorized NSF National AI Research Institutes, created the National AI Advisory Committee, and directed NIST to develop a voluntary AI risk management framework (the origin of the NIST AI RMF). It coordinates federal AI R&D rather than regulating private-sector AI. https://www.govinfo.gov/app/details/PLAW-116publ283 - [in_force] AI in Government Act of 2020 (Division U, Title I, Consolidated Appropriations Act 2021) (Congress, 2020-12-27): Enacted inside the Consolidated Appropriations Act, 2021 (Pub. L. 116-260), it created the AI Center of Excellence within GSA to advise agencies on AI adoption, required OMB to issue guidance to agencies on AI acquisition and use, and directed OPM to establish AI occupational classifications for the federal workforce. It governs federal government use of AI, not the private sector. https://www.govinfo.gov/app/details/PLAW-116publ260 European Union ============== - [announced] AI Act Stage 5 (as amended) — Annex I product-embedded high-risk obligations and Article 6(1) apply 2 August 2028 (European Parliament and Council, 2028-08-02): For AI systems that are safety components of, or are themselves, products covered by Union harmonisation legislation in Annex I (machinery, medical devices, toys, aviation, vehicles, etc.), the high-risk classification under Article 6(1) and the corresponding obligations now apply from 2 August 2028, one year later than the original 2 August 2027 date, following the Digital Omnibus amendment. Related sectoral adjustments were made to the aviation and machinery regulations in the same amending act. https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng - [announced] AI Act Stage 4 (as amended) — Annex III stand-alone high-risk obligations apply 2 December 2027 (European Parliament and Council, 2027-12-02): Under the AI Act as amended by Regulation 2026/1744, the full obligations for stand-alone high-risk AI systems listed in Annex III (biometrics, critical infrastructure, education, employment, essential public and private services, law enforcement, migration/asylum/border control, justice and democratic processes) apply from 2 December 2027 instead of 2 August 2026. This covers risk management, data governance, technical documentation, logging, human oversight, accuracy/robustness/cybersecurity, conformity assessment, registration and deployer duties. https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng - [announced] AI Act extended transition and legacy-system rules (Art. 111): 2027, 2030 and end-2030 horizons (European Parliament and Council, 2027-08-02): The AI Act's transitional regime staggers compliance for systems and models already on the market. GPAI models placed on the market before 2 August 2025 must be brought into compliance by 2 August 2027; legacy high-risk systems already placed on the market are caught only if they undergo significant design changes after the relevant application date; high-risk systems used by public authorities must comply by 2 August 2030; and AI components of Annex X large-scale EU IT systems (e.g. SIS, Eurodac) placed on the market before 2 August 2027 have until 31 December 2030. The entry date shown is the first of these milestones. https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng - [in_force] Revised Product Liability Directive (EU) 2024/2853 — software and AI as products (European Parliament and Council, 2026-12-09): The new PLD (OJ 18 November 2024, in force December 2024) extends strict, no-fault producer liability to software and AI systems — embedded, standalone, or supplied as a service — and to defects arising after sale from updates, machine learning, or failure to address cybersecurity vulnerabilities. Member States must transpose it by 9 December 2026, and it applies to products placed on the market or put into service from that date (the 1985 directive governs earlier products). With the AI Liability Directive withdrawn, this is the principal EU-level route to compensation for harm caused by defective AI. https://eur-lex.europa.eu/eli/dir/2024/2853/oj - [announced] AI Act Stage 3 — general application on 2 August 2026: Article 50 transparency applies; high-risk obligations carved out (European Parliament and Council, 2026-08-02): The AI Act's general application date is 2 August 2026 (two days after this tracker's cut-off of 31 July 2026). Because of the Digital Omnibus, what actually starts applying is narrower than originally enacted: the Article 50 transparency obligations (disclosing AI interaction, machine-readable marking of synthetic content, emotion-recognition/biometric-categorisation notices, deepfake and AI-generated public-interest text disclosures) and the remaining general provisions — including Article 101 GPAI fines — take effect, while the Annex III high-risk regime no longer starts on this date. https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng - [announced] AI Office / Commission enforcement powers over GPAI providers become exercisable (European Commission (AI Office), 2026-08-02): GPAI obligations have applied since 2 August 2025, but the Commission's supervision and enforcement powers under Chapter V only enter into application on 2 August 2026, the end of the one-year adjustment period. From that date the AI Office can request information, conduct model evaluations, require corrective measures, and fine GPAI providers up to 3% of global annual turnover or EUR 15 million, whichever is higher (Art. 101 AI Act). The Digital Omnibus did not move this date. https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers - [announced] National AI regulatory sandboxes: Article 57 deadline of 2 August 2026 and uneven readiness (Member-state competent authorities (obligation under Article 57 AI Act), 2026-08-02): Article 57 AI Act requires every member state to ensure at least one operational national AI regulatory sandbox (alone or jointly with other states) by 2 August 2026 — a deadline arriving with readiness highly uneven. Spain leads: its pilot sandbox under Royal Decree 817/2023 selected a first cohort of 12 high-risk AI systems by provisional resolution of 3 April 2025, and the pilot yielded AESIA's 16 compliance guides published in early 2026. Germany's KI-MIG (in force 29 July 2026) creates a statutory duty for at least one Bundesnetzagentur-run sandbox aimed particularly at SMEs, and the EU-funded EUSAiR project supports national rollouts — but states that have not even designated authorities are unlikely to meet the sandbox deadline. https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-57 - [announced] AI Act enforcement architecture goes live 2 August 2026 — Commission GPAI penalty powers activate amid patchy national readiness (European Commission AI Office; national competent authorities, 2026-08-02): On 2 August 2026 the AI Act's governance, market-surveillance and penalties chapters become applicable: the AI Office and Member State authorities become responsible for implementing, supervising and enforcing the AI Act, and the Commission gains enforceable penalty powers (up to 3% of global annual turnover or EUR 15 million) over GPAI model providers for obligations that have applied since August 2025. As of the latest public tracking, no formal AI Act fine had been reported, and a majority of Member States had not yet fully designated their national competent authorities — making the enforcement start asymmetric across the Union. https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai - [in_force] Germany: KI-MIG (AI Market Surveillance and Innovation Promotion Act) in force — Bundesnetzagentur as central AI supervisor (German Bundestag / Federal Government, 2026-07-29): Germany missed the August 2025 designation deadline but has now completed implementation: the Federal Cabinet adopted the KI-MIG government draft on 11 February 2026, the Bundestag passed the amended bill on 11 June 2026 with coalition (CDU/CSU-SPD) votes, and per the Bundesnetzagentur the act entered into force on 29 July 2026. It makes the Bundesnetzagentur the central market surveillance authority, single point of contact (zentrale Anlaufstelle) and central complaints office for the AI Act, hosting the KoKIVO coordination and competence centre that supports and coordinates other market surveillance authorities, and requires it to operate at least one AI regulatory sandbox (KI-Reallabor) aimed particularly at SMEs; sectoral authorities such as BaFin (finance) and BfArM (medical devices) retain their domains per reporting on the bill. https://www.bundesnetzagentur.de/SharedDocs/Pressemitteilungen/DE/2026/20260729_KI_VO.html - [in_force] Regulation (EU) 2026/1744 — Digital Omnibus on AI (first amendment to the AI Act) (European Parliament and Council, 2026-07-27): Regulation (EU) 2026/1744 of 8 July 2026, amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026 (third day after publication) — days before the AI Act's general application date. It defers the high-risk regime (Annex III stand-alone systems to 2 December 2027; Annex I product-embedded systems to 2 August 2028), grants a marking grace period to 2 December 2026 for systems already on the market, adds new Article 5 prohibitions on AI generating non-consensual intimate material and CSAM, and makes targeted simplifications to the AI Act and to the aviation and machinery frameworks. https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng - [in_force] AI Omnibus — Regulation (EU) 2026/1744 amending the AI Act (in force) (European Parliament and Council, 2026-07-27): The first substantive amendment of the AI Act, part of the Digital Simplification Package: proposed 19 November 2025, politically agreed 7 May 2026, published in the Official Journal as Regulation (EU) 2026/1744 and in force since 27 July 2026. It defers the high-risk regime — Annex III standalone systems to 2 December 2027 and Annex I product-embedded systems to 2 August 2028 — against the backdrop of missing harmonized standards and incomplete national implementation, and adds a new prohibition on AI enabling CSAM and non-consensual intimate imagery, applying from December 2026. Legal analyses also report further centralization of enforcement in the Commission/AI Office; the GPAI enforcement start of 2 August 2026 was not deferred. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202601744 - [in_force] Regulation (EU) 2026/1744 (Digital Omnibus on AI) enters into force — high-risk delays now binding law (European Parliament and Council, 2026-07-27): The Digital Omnibus on AI was published in the Official Journal as Regulation (EU) 2026/1744 and entered into force on 27 July 2026, days ahead of the AI Act's general application date of 2 August 2026. It makes the high-risk postponements binding (Annex III standalone systems to 2 December 2027; Annex I embedded systems to 2 August 2028), postpones the obligation to mark AI-generated content to 2 December 2026 for systems placed on the market before 2 August 2026, adds the new prohibition on generating CSAM and non-consensual intimate content (taking effect December 2026), and reinforces AI Office supervisory powers over general-purpose AI. https://eur-lex.europa.eu/eli/reg/2026/1744/oj - [announced] Poland: Act of 3 July 2026 on Artificial Intelligence Systems — new KRiBSI regulator; signed and published, main provisions in force from 11 August 2026 (Sejm / President of the Republic of Poland, 2026-07-03): Poland's implementing law is now enacted: the Sejm passed the bill on 11 June 2026, the final Act on Artificial Intelligence Systems (ustawa o systemach sztucznej inteligencji) is dated 3 July 2026 following the Senate stage, President Nawrocki signed it on 24 July 2026, and it was published in the Dziennik Ustaw (2026, item 1003) in late July. Its main provisions enter into force on 11 August 2026, with staged application — Art. 125(4) from 28 July 2026, and Arts 8-18 plus chapters 3-5 and 8-9 from 28 October 2026. It creates the Commission for the Development and Safety of Artificial Intelligence (KRiBSI) as the new market surveillance authority, a collegial body drawing on existing sectoral regulators with operational support in the Ministry of Digital Affairs, and expands duties for the data-protection authority (UODO). https://api.sejm.gov.pl/eli/acts/DU/2026/1003 - [news] Member-State Implementation of the AI Act: Designation Status Overview (mid-2026) (EU Member States (status per FLI AI Act implementation tracker and EPRS), 2026-07): Member states were required by Article 70 AI Act to designate notifying and market surveillance authorities and a single point of contact by 2 August 2025, and most missed the deadline. Per the FLI tracker (updated 17 June 2026), 9 states (Cyprus, Denmark, Finland, Hungary, Ireland, Italy, Lithuania, Malta, Slovenia) had designated both authority types, 6 had designated nothing (Austria, Belgium, Bulgaria, Croatia, Estonia, Greece), the remaining 12 were partial, and per EPRS the Commission's single-point-of-contact list held only 8 of 27 entries as of March 2026. Models split between centralized supervision (Spain's AESIA, Poland's new KRiBSI, Germany's Bundesnetzagentur) and decentralized sectoral supervision (Finland, Ireland, France; Denmark hybrid); in late July 2026 Germany's KI-MIG entered into force (29 July) and Poland's act was signed (24 July, main provisions in force 11 August 2026). https://artificialintelligenceact.eu/national-implementation-plans/ - [in_force] European Artificial Intelligence Board — operating rhythm and June 2026 priorities (AI Board (Member State representatives; AI Office as secretariat), 2026-06-11): The AI Board (Art. 65 AI Act), composed of Member State representatives with the AI Office as secretariat, coordinates national implementation and advises the Commission. Its eighth meeting on 11 June 2026, chaired by the Cypriot Presidency of the EU Council, saw the presentation of the final Code of Practice on transparency of AI-generated content, a review of progress on national market surveillance authority designations, and the introduction of the newly appointed Scientific Panel and Advisory Forum. Moldova was granted observer status. https://digital-strategy.ec.europa.eu/en/news/ai-board-convenes-its-eighth-meeting - [in_force] Code of Practice on Transparency of AI-generated Content (Article 50) — final version (AI Office (independent-expert drafting, multi-stakeholder process), 2026-06-10): A voluntary code, published in final form on 10 June 2026, giving providers and deployers of generative AI practical means to meet the legally binding Article 50 transparency obligations that apply from 2 August 2026 — marking and detection of AI-generated audio, image, video and text, plus labelling of deepfakes and certain AI-generated publications. It followed a first draft on 17 December 2025 and a second draft on 3 March 2026. By end of July 2026 roughly 190 companies and organisations had signed. https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content - [draft] Cloud and AI Development Act (CADA) proposed — sovereignty-driven infrastructure law (European Commission, 2026-06-03): On 3 June 2026 the Commission adopted its proposal for the Cloud and AI Development Act (COM(2026) 502), built on three pillars: funding next-generation cloud/AI research and innovation, accelerating deployment of data-centre capacity in the EU (in line with the earlier target of at least tripling capacity within five to seven years), and creating a single EU-wide framework for assessing cloud and AI sovereignty with a public-sector adoption mechanism that could constrain non-EU providers in sensitive procurement. It is the clearest legislative expression of the EU's post-2025 shift toward strategic autonomy in AI infrastructure, and a fresh source of EU–US friction. https://digital-strategy.ec.europa.eu/en/library/proposal-cloud-and-ai-development-act-cada - [in_force] Scientific Panel of Independent Experts and AI Act Advisory Forum appointed (European Commission, 2026-06-01): On 1 June 2026 the Commission announced the two remaining advisory bodies of the AI Act's governance architecture. The Scientific Panel (Art. 68) comprises 60 independent AI experts appointed in personal capacity for 24-month renewable terms, selected with geographic balance (at most three nationals per country) and gender balance; it alerts the AI Office to systemic risks and advises on GPAI classification, evaluation methodologies and market surveillance. The Advisory Forum (Art. 67) provides stakeholder input from industry, SMEs and startups, academia and civil society. https://digital-strategy.ec.europa.eu/en/news/ai-act-enforcement-gets-independent-expert-support - [news] National competent authorities and market surveillance designations — widespread delay (EU Member States (obligation under Article 70 AI Act), 2026-06): Member States were required to designate their notifying authorities and market surveillance authorities by 2 August 2025, and many failed to meet the deadline. The Future of Life Institute's national-implementation tracker (updated 17 June 2026) classifies 9 Member States as having clear designations, around 12 jurisdictions as only partially clear, and 6 as unclear with no designated authority identifiable — an enforcement gap that formed part of the backdrop to the Digital Omnibus deferral of the high-risk regime. Designation progress was reviewed again at the AI Board's June 2026 meeting. https://artificialintelligenceact.eu/national-implementation-plans/ - [draft] Spain: Draft Organic Law on the Good Use and Governance of Artificial Intelligence (in Parliament) (Spanish Government (Council of Ministers) / Cortes Generales, 2026-05-26): Spain's national AI bill — first approved as an anteproyecto on 11 March 2025 — was approved by the Council of Ministers as a draft Organic Law on 26 May 2026 and sent to Parliament, where it was published in the Boletín Oficial de las Cortes Generales on 12 June 2026 (Series A, No. 97-1) and assigned to the Congress committee on Economy, Commerce and Digital Transformation; it remained pending as of July 2026. It supplements the AI Act with a domestic sanctioning regime aligned to the EU ceilings (up to EUR 35M or 7% of worldwide turnover for the most serious infringements, down to EUR 500,000 or 0.5% for minor ones) and codifies the supervisory architecture led by AESIA alongside sectoral authorities; per reporting on the March 2025 anteproyecto, failure to label AI-generated content (deepfakes) is classed as a serious infringement. https://privacymatters.dlapiper.com/2026/05/spain-government-approves-the-draft-organic-law-on-the-proper-use-and-governance-of-artificial-intelligence/ - [news] Garante EUR 15m fine on OpenAI (ChatGPT) annulled by Court of Rome (Italian DPA (Garante) / Court of Rome, 2026-03-18): The Garante fined OpenAI EUR 15 million (announced December 2024) for GDPR breaches around ChatGPT — no valid legal basis for training on personal data, transparency failures, late breach notification and inadequate age verification — and ordered a six-month public information campaign. By judgment no. 4153/2026, deposited 18 March 2026, the Court of Rome annulled the fine on competence grounds: reporting indicates the court held that, given OpenAI's Irish main establishment, the GDPR one-stop-shop mechanism made the Irish DPC lead authority. The court did not rule on the substantive GDPR violations, so the underlying legal questions remain open under Irish supervision. https://www.wsgr.com/en/insights/openai-prevails-in-landmark-italian-ai-and-gdpr-enforcement-case.html - [news] Italy: Garante AI enforcement — OpenAI EUR 15M fine annulled by Rome court on jurisdictional grounds; Replika EUR 5M fine (Garante per la protezione dei dati personali / Tribunale Ordinario di Roma, 2026-03-18): Italy's Garante has been the most aggressive national AI enforcer via the GDPR: it fined OpenAI EUR 15 million over ChatGPT (decision of 2 November 2024, announced December 2024 — legal basis, breach notification, age verification, plus a mandated public-information campaign) and fined Luka Inc. (Replika) EUR 5 million on 19 May 2025 while opening a separate probe into model-training lawfulness. By judgment No. 4153/2026, filed 18 March 2026 (full reasoning published 28 May 2026), the Rome ordinary court annulled the OpenAI fine on GDPR one-stop-shop jurisdictional grounds — the Irish DPC had become lead supervisory authority in February 2024, before the Garante finalised its decision — expressly without ruling on the substantive violations, which now fall in principle to the Irish DPC. https://ppc.land/italian-court-kills-openais-eur15m-fine-and-it-wasnt-even-close/ - [news] Like Company v Google Ireland (C-250/25): first CJEU case on generative AI and copyright (Court of Justice of the European Union (reference from Budapest Environs Regional Court, Hungary), 2026-03-10): A Hungarian press publisher alleges that Google's Gemini chatbot reproduced and made available its protected press content. The preliminary reference (lodged 3 April 2025 by the Budapest Kornyeki Torvenyszek) asks whether chatbot training and outputs engage the reproduction right and the Article 15 DSM press publishers' right, and whether and how the Article 4 TDM exception covers LLM training — the first time the CJEU will construe the TDM regime for generative AI. The Court held its first-ever hearing on generative AI and copyright on 10 March 2026; the Advocate General's opinion (reportedly scheduled for September 2026) and the judgment remained pending as of this audit, and the outcome will set the EU-wide baseline for the opt-out debate. https://curia.europa.eu/juris/liste.jsf?num=C-250/25 - [news] GPAI Code Signatory Taskforce begins operating — first working meetings on copyright and safety (European Commission AI Office, 2026-01-30): The AI Office convened the first meeting of the Signatory Taskforce of the GPAI Code of Practice on 30 January 2026, the operational forum where signatories and the AI Office coordinate consistent implementation of the Code's commitments. A second meeting on 13 March 2026 focused on the copyright chapter and a third on 27 March 2026 on safety and security. This is the main visible machinery of GPAI supervised self-regulation ahead of the Commission's enforcement powers becoming applicable in August 2026. https://digital-strategy.ec.europa.eu/en/policies/signatory-taskforce-gpai-code-practice - [news] Commission opens DSA proceedings against X over Grok AI deepfakes (European Commission, 2026-01-26): On 26 January 2026 the Commission opened a new formal DSA investigation against X over the integration of the Grok generative-AI chatbot, and simultaneously extended its December 2023 investigation of X's recommender systems. It is examining whether X properly assessed and mitigated systemic risks under Articles 34-35 before deploying AI features that were used to generate manipulated sexually explicit images at scale — including content that may amount to child sexual abuse material — and whether its recommender systems spread that content. It is the first DSA enforcement action aimed squarely at generative AI embedded in a very large platform, effectively using the DSA as an AI-governance tool ahead of the AI Act's own transparency rules. Proceedings are ongoing; no findings of infringement have been made. https://digital-strategy.ec.europa.eu/en/news/commission-investigates-grok-and-xs-recommender-systems-under-digital-services-act - [news] Commission opens DSA proceedings over Grok on X — first flagship EU enforcement action aimed at a generative AI deployment (European Commission (DSA enforcement), 2026-01-26): On 26 January 2026 the Commission opened formal Digital Services Act proceedings against X over the integration of xAI's Grok, investigating whether X diligently assessed and mitigated systemic risks before deploying Grok functionalities in the EU — specifically risks of dissemination of illegal content such as manipulated sexually explicit images, including content that may amount to child sexual abuse material. Though brought under the DSA rather than the AI Act, it is the first flagship EU enforcement action aimed at a generative AI deployment, and the underlying late-2025 Grok mass-deepfake incident is widely credited with motivating the new CSAM/NCII prohibition inserted into the AI Act by the Digital Omnibus. https://digital-strategy.ec.europa.eu/en/news/commission-investigates-grok-and-xs-recommender-systems-under-digital-services-act - [in_force] Finland: Act on the Supervision of Certain Artificial Intelligence Systems (1377/2025) in force — decentralized supervision with Traficom as single point of contact (Finnish Parliament (Eduskunta), 2026-01-01): Finland's national implementing act — Laki eräiden tekoälyjärjestelmien valvonnasta (1377/2025) — took effect on 1 January 2026, making Finland one of the few states with a complete supervision framework in force. Finland chose a decentralized model that assigns market surveillance of high-risk AI to existing sectoral regulators, with the Transport and Communications Agency (Traficom) acting as single point of contact. Finland is among the nine states with both notifying and market surveillance authorities fully designated. https://www.finlex.fi/fi/laki/alkup/2025/20251377 - [news] EU–US friction over the AI Act and digital rulebook escalates into trade leverage (US administration / European Commission (political developments), 2025-12): Through late 2025 and into 2026 the US administration linked trade to EU digital deregulation: Commerce Secretary Lutnick reportedly suggested relief from 50% steel/aluminium tariffs depended on the EU relaxing its digital rules, and in December 2025 USTR threatened to use 'every tool at its disposal' against EU measures, floating retaliation against European firms over DMA/DSA enforcement of US companies — pressure EU officials reportedly regard as contrary to the July 2025 trade truce. The Commission rejected accusations of bias, insisted its rules apply equally to all companies, and denied the Digital Omnibus was a concession to Washington (digital chief Virkkunen framing it as competitiveness-driven), while France and Germany convened a European Digital Sovereignty Summit on 18 November 2025, accelerating the EU's tech-sovereignty counter-agenda. https://fortune.com/2025/12/17/trump-administration-threatens-eu-tech-regulations-retaliation-dma-dsa-digital-markets-services-act/ - [superseded] Digital Omnibus on AI — Commission proposal COM(2025) 836 (superseded by adopted Regulation 2026/1744) (European Commission, 2025-11-19): On 19 November 2025 the Commission proposed the 'Digital Omnibus on AI' (COM(2025) 836, procedure 2025/0359(COD)), a targeted simplification package amending the AI Act before its general application date. Its core was deferring the high-risk regime — application conditioned on a Commission decision confirming that adequate compliance-support measures are available, plus 6 months (Annex III) or 12 months (Annex I), with longstop dates of 2 December 2027 and 2 August 2028 — alongside a transparency-marking grace period, a softened AI-literacy duty, simplified registration and SME relief. It was negotiated in record time and is superseded by the adopted Regulation (EU) 2026/1744. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:52025PC0836 - [draft] Digital Omnibus: proposed GDPR amendments to facilitate AI training (European Commission, 2025-11-19): The Commission's simplification package of 19 November 2025 proposes the first substantive GDPR amendments bearing directly on AI: an express legitimate-interest basis for processing personal data to develop and operate AI models and systems (with data-minimisation and safeguard conditions), a conditional allowance for incidental processing of special-category data during AI training coupled with removal efforts, and a relative-identifiability clarification of the personal-data definition. A parallel Digital Omnibus on AI would postpone AI Act high-risk obligations (Annex III to 2 December 2027, Annex I to 2 August 2028). Both are only proposals: they are pending before Parliament and Council and remain contested, so the GDPR and the EDPB Opinion 28/2024 framework continue to apply unchanged. https://digital-strategy.ec.europa.eu/en/library/digital-omnibus-regulation-proposal - [news] Digital Omnibus on AI — proposal and negotiation arc (COM(2025) 836) (European Commission (proposal); European Parliament and Council (negotiation), 2025-11-19): On 19 November 2025 the Commission proposed the Digital Omnibus on AI (COM(2025) 836), a targeted amending regulation to the AI Act responding to delays in harmonised standards, authority designations and notified-body capacity. The Council adopted its general approach on 13 March 2026, Parliament adopted its position at the second March 2026 plenary, and a provisional trilogue agreement was reached on 7 May 2026 — under three months before the high-risk rules would otherwise have begun applying on 2 August 2026. The deal postponed Annex III high-risk obligations to 2 December 2027 and Annex I (embedded) obligations to 2 August 2028, and added a new AI Act prohibition on practices generating child sexual abuse material and non-consensual intimate or sexual content. https://www.europarl.europa.eu/legislative-train/package-digital-package/file-digital-omnibus-on-ai - [draft] Broader Digital Omnibus (GDPR, ePrivacy, Data Act, cybersecurity) still in negotiation (European Commission (proposal); Parliament and Council (negotiation), 2025-11-19): Alongside the AI-specific omnibus, the Commission's 19 November 2025 Digital Package included a wider Digital Omnibus proposing amendments to the GDPR, ePrivacy rules, Data Act, NIS2 and DORA (among others) — codifying case law on when data is 'personal', clarifying use of personal data for AI training, introducing single-click cookie refusal honoured for six months, and creating a single entry point for breach notifications. Unlike the fast-tracked AI omnibus (in force July 2026), this package remains in the ordinary legislative procedure as of late July 2026, facing significant data-protection and civil-society opposition, including EDPB/EDPS concerns over the narrowed personal-data definition. Its AI-training and personal-data provisions will materially shape how GPAI providers source EU training data. https://digital-strategy.ec.europa.eu/en/faqs/digital-package - [news] GEMA v OpenAI (Munich Regional Court I): first European ruling that AI training/outputs infringed copyright (Landgericht München I (Germany, national court), 2025-11-11): On 11 November 2025 (case 42 O 14139/24) the Munich Regional Court held two OpenAI group companies liable for infringing lyrics of nine German songs: memorisation of protected works in model weights, and their reproduction in ChatGPT outputs on simple prompts, are copyright-relevant reproductions, and the court largely granted GEMA's claims for injunctive relief, information and damages (a separate claim over altered lyrics was dismissed). The court held the Art. 4 DSM TDM exception (s. 44b German Copyright Act) covers only the analytical training phase and does not extend to memorisation or output reproduction. The judgment is not final: OpenAI has appealed to the Munich Higher Regional Court (OLG München, case 6 U 3662/25 e), where the case was pending as of this audit. Not binding beyond Germany but the leading national precedent on the TDM defence for generative AI. https://www.justiz.bayern.de/gerichte-und-behoerden/landgericht/muenchen-1/presse/2025/11.php - [news] Harmonised AI standards slip to late 2026: CEN-CENELEC adopts exceptional fast-track measures (CEN-CENELEC JTC 21, 2025-11): CEN-CENELEC missed the Commission's standardisation-request deadline of August 2025 for the harmonised standards underpinning the AI Act's high-risk regime, with fast-tracked standards now due to be published by Q4 2026. In October–November 2025 CEN-CENELEC adopted measures it described as 'exceptional', 'targeted and temporary' — reducing the number of publication stages and establishing a smaller drafting group for the most delayed texts, while retaining the public Enquiry as a final step — over warnings from technical-committee members that the shortcuts could undermine consensus. The standards gap was the Commission's principal stated justification for the Digital Omnibus deferral of high-risk obligations to December 2027 and August 2028. https://cms.law/en/gbr/publication/speed-vs-safety-cen-cenelec-fast-tracks-ai-standards - [draft] CEN-CENELEC harmonized standards for the AI Act: delays and accelerated delivery (target Q4 2026) (CEN-CENELEC (JTC 21), under Commission standardization request C(2023) 3215 as amended, 2025-10-23): The harmonized standards meant to give high-risk AI providers a presumption of conformity under Article 40 are substantially delayed: the original April 2025 delivery date under the 2023 standardization request was missed, and as of mid-2026 no AI Act harmonized standards had been cited in the Official Journal. On 23 October 2025 the CEN and CENELEC Technical Boards adopted an exceptional package of acceleration measures targeting availability of key deliverables by Q4 2026. The standards gap was among the reasons the Digital Omnibus deferred the high-risk regime. https://www.cencenelec.eu/news-events/news/2025/brief-news/2025-10-23-ai-standardization/ - [in_force] AI Act Service Desk and Single Information Platform launched (European Commission (AI Office), 2025-10-08): On 8 October 2025 the Commission launched the AI Act Single Information Platform and the AI Act Service Desk, a team of experts working with the AI Office that answers stakeholder questions on the Act. The platform hosts a Compliance Checker (self-assessment of whether and how obligations apply), an AI Act Explorer for navigating the text, and a question-submission form. Launched in English, French and German, with availability in all 24 EU official languages announced for early 2026. https://digital-strategy.ec.europa.eu/en/news/commission-launches-ai-act-service-desk-and-single-information-platform-support-ai-act - [superseded] AI Liability Directive proposal — formally withdrawn (European Commission, 2025-10-06): Proposed on 28 September 2022 (procedure 2022/0303(COD)), the AILD would have harmonised fault-based civil claims for AI harms through evidence-disclosure duties and rebuttable presumptions of causation keyed to AI Act non-compliance. The Commission announced its withdrawal in the 2025 work programme (11 February 2025), citing no foreseeable agreement, and the withdrawal was formalised by notice in the Official Journal (C/2025/5423) of 6 October 2025. Fault-based AI liability therefore remains a matter of the 27 national legal systems, alongside the strict-liability regime of the revised PLD; no replacement proposal had been tabled as of this audit. https://www.europarl.europa.eu/legislative-train/theme-a-europe-fit-for-the-digital-age/file-ai-liability-directive - [announced] Apply AI Strategy — the Commission pivots from rulemaking to AI adoption (European Commission, 2025-10): In October 2025 the Commission presented the Apply AI Strategy, its flagship push to accelerate AI uptake across ten strategic industry sectors plus the public sector (healthcare and pharmaceuticals, mobility and automotive, robotics, manufacturing and construction, climate and environment, energy, agri-food, defence and space, electronic communications, and cultural/creative/media), backed by AI Factories and Gigafactories, Experience Centres for AI, and an Apply AI Alliance coordination forum, and promoting an 'AI first' policy posture. Together with the simplification omnibus, it marks the post-AI Act phase of EU policy: the centre of gravity shifting from writing rules to driving adoption and competitiveness. https://digital-strategy.ec.europa.eu/en/policies/apply-ai - [in_force] Italy: Law No. 132/2025 on Artificial Intelligence — first comprehensive national AI law in the EU (Italian Parliament, 2025-09-23): Law No. 132 of 23 September 2025 ('Disposizioni e deleghe al Governo in materia di intelligenza artificiale', GU No. 223 of 25 September 2025, in force 10 October 2025) is widely described as the first comprehensive national AI law in the EU, complementing rather than transposing the AI Act. It sets sectoral rules for healthcare, employment, public administration, justice, professions and minors; designates the National Cybersecurity Agency (ACN) as market surveillance and sanctioning authority and AgID as notifying authority, coordinated at the Presidency of the Council of Ministers; and delegates implementing decrees to the Government. https://www.normattiva.it/uri-res/N2Ls?urn:nir:stato:legge:2025-09-23;132 - [in_force] AI Act Stage 2 in application — GPAI model obligations, governance, notified bodies, penalties (Chapters V, VII, XII) (European Parliament and Council, 2025-08-02): Since 2 August 2025, obligations for general-purpose AI model providers (Chapter V: transparency, copyright policy, training-data summaries; extra duties for systemic-risk models), the governance framework (AI Office, AI Board), the notified-bodies provisions (Chapter III Section 4), confidentiality (Art. 78) and the penalties provisions (Chapter XII, except Art. 101 GPAI fines) apply. Despite industry pressure for a pause, the Commission did not stop the clock for this stage and it took effect on schedule; the 2026 Digital Omnibus left the GPAI substantive obligations essentially unchanged. https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng - [in_force] Ireland: decentralized designation of 15 market surveillance authorities (S.I. No. 366 of 2025); National AI Office expected by August 2026 (Irish Government, 2025-08): Ireland completed its Article 70 designations via the European Union (Artificial Intelligence) (Designation of National Competent Authorities) Regulations 2025 (S.I. No. 366 of 2025), distributing market surveillance across 15 existing sectoral regulators — including the Central Bank, Coimisiún na Meán, the Data Protection Commission, the CCPC and the Health and Safety Authority — and is counted among the nine fully designated member states. A coordinating National AI Office, foreshadowed in the General Scheme of the Regulation of Artificial Intelligence Bill 2026, is expected to be operational by early August 2026 to knit the distributed system together and host a regulatory sandbox. https://artificialintelligenceact.eu/national-implementation-plans/ - [in_force] Template for the public summary of GPAI training content (Article 53(1)(d)) (European Commission (AI Office), 2025-07-24): On 24 July 2025 the Commission published the template and explanatory notice that GPAI model providers use to publish a sufficiently detailed public summary of the content used for model training, providing 'a common minimal baseline' for the information to be made public. Article 53(1)(d) AI Act requires the summary to follow the AI Office template, making its use compulsory in practice — unlike the voluntary Code of Practice — and it is enforceable by the AI Office from 2 August 2026. https://digital-strategy.ec.europa.eu/en/library/explanatory-notice-and-template-public-summary-training-content-general-purpose-ai-models - [in_force] AI Act Article 53 copyright interface: Commission template for public summary of training content (European Commission (AI Office), 2025-07-24): AI Act Article 53(1)(c)-(d), applicable to general-purpose AI providers since 2 August 2025, requires a copyright policy honouring DSM Art. 4(3) TDM reservations and publication of a sufficiently detailed public summary of training content. On 24 July 2025 the Commission published the mandatory template and explanatory notice for that summary: narrative disclosure of data sources including main datasets and prominent scraped domains, measures taken to respect TDM opt-outs, with periodic updates required. The AI Office's enforcement powers begin 2 August 2026 (fines up to 3% of worldwide turnover or EUR 15 million); models placed on the market before 2 August 2025 have until 2 August 2027 to comply. https://digital-strategy.ec.europa.eu/en/library/explanatory-notice-and-template-public-summary-training-content-general-purpose-ai-models - [in_force] France: CNIL's finalised GDPR-AI recommendations and France's lagging AI Act designations (CNIL (Commission Nationale de l'Informatique et des Libertés), 2025-07-22): France has produced the EU's most developed data-protection guidance for AI while lagging on formal AI Act implementation. The CNIL issued two final recommendations in February 2025 (informing data subjects; facilitating individuals' rights over training data and models) and three further recommendations on 22 July 2025 (training-data annotation, development-phase security, and when a trained AI model itself falls under the GDPR), with sectoral work on education, health and the workplace ongoing. Institutionally, the CNIL is slated as market surveillance authority for biometric, law-enforcement, migration, employment and education high-risk systems with the DGCCRF as coordinating authority under France's proposed decentralized model — but France had adopted no implementing law and remained only partially designated as of mid-2026. https://www.cnil.fr/en/ai-cnil-finalises-its-recommendations-development-artificial-intelligence-systems - [in_force] Commission Guidelines on the scope of obligations for GPAI model providers (European Commission (AI Office), 2025-07-18): Published 18 July 2025, days before GPAI obligations became applicable on 2 August 2025. The guidelines define when a model is 'general-purpose' (indicative training-compute criterion above 10^23 FLOP combined with generality of capabilities), who counts as a provider (including when downstream modifications create provider obligations), and the conditions of the open-source exemption. https://digital-strategy.ec.europa.eu/en/library/guidelines-scope-obligations-providers-general-purpose-ai-models-under-ai-act - [in_force] General-Purpose AI Code of Practice (final version) and signatory dynamics (AI Office (drafted by independent experts); adequacy confirmed by European Commission and Member States (AI Board), 2025-07-10): The final GPAI Code of Practice was published 10 July 2025 with three chapters — Transparency (Model Documentation Form), Copyright, and Safety and Security (systemic-risk models only). On 1 August 2025 the Commission announced that it and the Member States had confirmed the Code is an adequate voluntary tool for demonstrating compliance with the AI Act's GPAI obligations, giving signatories reduced administrative burden and greater legal certainty. Adherence becomes the practical compliance benchmark once AI Office enforcement starts on 2 August 2026. https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai - [news] GPAI Code of Practice compliance split: Meta refuses, xAI signs safety chapter only, other frontier labs sign (European Commission AI Office / GPAI model providers, 2025-07): After the Commission received the final GPAI Code of Practice on 10 July 2025, the frontier-lab field split ahead of the 2 August 2025 applicability of GPAI obligations. Amazon, Anthropic, Google, IBM, Microsoft, OpenAI, Mistral AI and Aleph Alpha signed the full Code; Meta publicly refused on 18 July 2025 (chief global affairs officer Joel Kaplan citing 'legal uncertainties' and measures going beyond the AI Act); xAI signed only the Safety and Security chapter, leaving transparency and copyright compliance to be demonstrated by other means. Major Chinese providers (Alibaba, Baidu, DeepSeek) did not sign, and Google signed while publicly criticising aspects of the Code. https://digital-strategy.ec.europa.eu/en/policies/signatory-taskforce-gpai-code-practice - [in_force] Denmark: Act No. 467 of 14 May 2025 on Supplementary Provisions to the AI Regulation (first national implementing law) (Folketing (Danish Parliament), 2025-05-14): Denmark was the first member state to adopt AI Act implementing legislation: the Folketing passed the bill on 8 May 2025, it was signed as Act No. 467 of 14 May 2025, and it entered into force on 2 August 2025 in step with the AI Act's governance chapter. It designates the Agency for Digital Government (Digitaliseringsstyrelsen) as notifying authority, coordinating market surveillance authority and single point of contact, with the Data Protection Authority (Datatilsynet) and the Court Administration (Domstolsstyrelsen) as market surveillance authorities in their domains, and lays down inspection powers and penalties. https://ai-regulation.com/eu-ai-act-implementation-denmark-published-its-national-law/ - [news] Garante fines Replika (Luka Inc.) EUR 5m over AI companion chatbot (Italian DPA (Garante), 2025-04): By decision adopted 10 April 2025 (announced 19 May 2025) the Garante fined US developer Luka Inc. EUR 5 million over the Replika AI companion: no valid legal basis for processing, an inadequate privacy notice, and no effective age-verification despite risks to children. The decision follows the February 2023 emergency block of Replika in Italy, and the authority opened a separate inquiry into the training of the underlying language model. It is the leading EU enforcement precedent on emotional-companion AI and child protection. https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10130115 - [in_force] Commission Guidelines on the definition of an AI system (Article 3(1)) (European Commission, 2025-02-06): Non-binding guidelines, published 6 February 2025, clarifying which software qualifies as an 'AI system' under Article 3(1) — the gateway concept for the whole Act. They are designed to assist providers in determining whether a software system constitutes an AI system, indicating that simple traditional software falls outside scope. The Commission states they will evolve and be updated in light of practical experience and new use cases. https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application - [in_force] Commission Guidelines on prohibited AI practices (Article 5) (European Commission, 2025-02-04): Non-binding guidelines interpreting the Article 5 prohibitions (harmful manipulation, social scoring, real-time remote biometric identification, emotion inference at work/education, untargeted facial-image scraping, etc.), which have applied since 2 February 2025. The Commission approved the content of the draft Communication on 4 February 2025 (C(2025) 884). They provide legal explanations and practical examples, but authoritative interpretation remains with the CJEU. https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act - [in_force] AI Act Stage 1 in application — prohibitions (Art. 5) and AI literacy (Art. 4), Chapters I–II (European Parliament and Council, 2025-02-02): Since 2 February 2025, the AI Act's Chapters I and II apply: the ban on unacceptable-risk practices (e.g. harmful manipulation, social scoring, untargeted facial-image scraping, emotion recognition at work/school, certain biometric categorisation and real-time remote biometric identification) and the Article 4 AI-literacy duty for providers and deployers. This stage took effect on schedule and remains in application; the Digital Omnibus did not delay it, but it softened the wording of the AI-literacy duty and added new prohibitions. https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng - [news] Garante blocks DeepSeek in Italy (urgent limitation on processing) (Italian DPA (Garante), 2025-01-30): On 30 January 2025 the Garante imposed, with immediate effect, a limitation on the processing of Italian users' personal data by Hangzhou DeepSeek and Beijing DeepSeek, effectively blocking the chatbot for the Italian market, and opened an investigation. The companies' claim that the GDPR did not apply to them was rejected because the service was offered to users in Italy; their replies on training data, legal basis and Chinese-server storage were deemed wholly insufficient. It extends the Garante's enforcement line against non-EU AI providers (ChatGPT and Replika blocks in 2023) to a Chinese provider. https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10097450 - [standard] EDPB Opinion 28/2024 on personal data processing in the context of AI models (European Data Protection Board, 2024-12-17): Adopted 17 December 2024 at the request of the Irish Data Protection Commission, this Article 64(2) GDPR opinion is the framework EU regulators apply to AI models trained on personal data. It addresses when a model can be considered anonymous, when legitimate interest (Art. 6(1)(f) GDPR) can lawfully ground AI development and deployment, and how unlawfully processed training data can taint subsequent operation of a model. It is guidance, not binding law, but it steers national DPA enforcement against AI services. https://www.edpb.europa.eu/system/files/2024-12/edpb_opinion_202428_ai-models_en.pdf - [news] Clearview AI: Dutch DPA fine of EUR 30.5m caps multi-DPA enforcement against facial-recognition scraping (Autoriteit Persoonsgegevens (NL); earlier fines by IT, EL and FR DPAs, 2024-09): In September 2024 the Dutch DPA fined Clearview AI EUR 30.5 million, plus penalty orders of up to EUR 5.1 million, for building an illegal database of billions of face images scraped from the internet and processing biometric data without a legal basis. It follows EUR 20 million fines each from the Italian, Greek and French DPAs (2022) and a further CNIL penalty payment order (2023). The AP also warned that using Clearview's services is itself unlawful for Dutch organisations and said it was examining personal liability of Clearview's directors, as the company has not complied with any EU fine. https://www.autoriteitpersoonsgegevens.nl/en/current/dutch-dpa-imposes-a-fine-on-clearview-because-of-illegal-data-collection-for-facial-recognition - [in_force] Regulation (EU) 2024/1689 — the Artificial Intelligence Act (base instrument) (European Parliament and Council, 2024-08-01): The EU AI Act, signed 13 June 2024 and published in the Official Journal on 12 July 2024, entered into force on 1 August 2024. It establishes a horizontal, risk-based framework for AI (prohibited practices, high-risk systems, transparency obligations, general-purpose AI models) with a staged application calendar in Article 113 running originally from February 2025 to August 2027. It has since been amended once, by the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force 27 July 2026), which deferred the high-risk stages. https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng - [superseded] Corrigendum of 19 April 2024 to the Parliament's first-reading position on the AI Act (pre-publication correction) (European Parliament, 2024-04-19): Before signature and OJ publication, the European Parliament approved a corrigendum (dated 19 April 2024) to its 13 March 2024 first-reading position on the AI Act — an extensive legal-linguistic revision of the text. The corrected version is the text approved by the Council on 21 May 2024, signed on 13 June 2024 and published in the Official Journal on 12 July 2024, so this correction is fully absorbed into the in-force text. https://www.europarl.europa.eu/doceo/document/TA-9-2024-0138-FNL-COR01_EN.pdf - [standard] Commission DSA guidelines on electoral-process risks, including generative AI content (European Commission, 2024-04): Guidelines under DSA Article 35(3) for VLOPs and VLOSEs on mitigating systemic risks to electoral processes, announced 26 March 2024 and formally adopted 26 April 2024. They set out recommended best practices that include measures specifically directed at generative AI: labelling AI-generated and deepfake content, adapting content moderation and recommender systems to synthetic media, and cooperating during election periods. Non-binding, but the Commission treats them as the benchmark in DSA supervision and enforcement concerning AI-generated election content. https://digital-strategy.ec.europa.eu/en/library/guidelines-providers-vlops-and-vloses-mitigation-systemic-risks-electoral-processes - [in_force] Digital Services Act — obligations bearing on AI-generated content (European Parliament and Council, 2024-02-17): Regulation (EU) 2022/2065 has applied in full since 17 February 2024 (and to designated VLOPs/VLOSEs since late August 2023). Although drafted before the generative-AI wave, it is now a primary AI-content instrument: Articles 34-35 require very large platforms to assess and mitigate systemic risks stemming from the design and functioning of their services — which the Commission reads as covering integrated generative-AI features — and Article 35(1)(k) expressly lists prominent marking of AI-generated or manipulated media (deepfakes) as a mitigation measure. Recommender-system transparency (Arts. 27, 38), advertising rules (Arts. 26, 39) and researcher data access (Art. 40) likewise reach AI-driven amplification of synthetic content. https://eur-lex.europa.eu/eli/reg/2022/2065/oj - [in_force] European AI Office (establishment, structure and supervisory role) (European Commission, 2024-01-24): The AI Office, established within the Commission by Commission Decision C(2024) 390 of 24 January 2024, is the EU-level implementation hub for the AI Act, with exclusive competence to supervise and enforce obligations on general-purpose AI (GPAI) models. It has more than 125 staff across six units plus a Lead Scientific Adviser and an International Affairs Adviser, drafts codes of practice, conducts model evaluations, and serves as secretariat to the AI Board. The 2026 'AI omnibus' (Regulation (EU) 2026/1744) made targeted amendments to the AI Act; legal analyses report these broaden the AI Office's supervisory scope beyond GPAI models. https://digital-strategy.ec.europa.eu/en/policies/ai-office - [in_force] Spain: AESIA — first dedicated national AI supervisory agency and market surveillance authority (Spanish Government (Council of Ministers), 2023-08-22): Spain created the first dedicated AI supervisory agency in the EU: AESIA (Agencia Española de Supervisión de la Inteligencia Artificial), whose statute was approved by Royal Decree 729/2023 of 22 August 2023, seated in A Coruña and operational since 2024. AESIA is Spain's market surveillance authority under the AI Act and is slated as single point of contact in the pending Spanish AI bill; it manages Spain's AI regulatory sandbox and in early 2026 published 16 sandbox-derived compliance guides on its official portal. Spain's domestic sanctioning regime, however, still awaits the organic law pending in Parliament, even though the AI Act's governance and penalty provisions became applicable in August 2025. https://aesia.digital.gob.es/es/guias - [in_force] DSM Directive (EU) 2019/790, Articles 3-4 — text and data mining exceptions (European Parliament and Council, 2019-06-06): The DSM Directive (in force 6 June 2019; national transposition due 7 June 2021) supplies the EU copyright basis for AI training. Article 3 gives research organisations and cultural-heritage institutions a mandatory, non-overridable TDM exception for scientific research; Article 4 permits TDM by anyone, but only where rightholders have not expressly reserved their rights — for online content, in machine-readable form (Art. 4(3)). AI Act Article 53(1)(c) now requires all general-purpose AI providers placing models on the EU market to identify and honour these reservations regardless of where training occurred, making the Art. 4 opt-out the fulcrum of the EU AI-copyright debate. https://eur-lex.europa.eu/eli/dir/2019/790/oj