China, the United States, and the European Union — statutes, measures, standards, and what is coming next.
Updated 2026-07-31 · primary sources linked
The AI Act13
AI Act Stage 5 (as amended) — Annex I product-embedded high-risk obligations and Article 6(1) apply 2 August 2028
European Parliament and Council · 2028-08-02announced
For AI systems that are safety components of, or are themselves, products covered by Union harmonisation legislation in Annex I (machinery, medical devices, toys, aviation, vehicles, etc.), the high-risk classification under Article 6(1) and the corresponding obligations now apply from 2 August 2028, one year later than the original 2 August 2027 date, following the Digital Omnibus amendment. Related sectoral adjustments were made to the aviation and machinery regulations in the same amending act.
—One-year deferral: 2 Aug 2027 (original Art. 113(3)(c)) becomes 2 Aug 2028 for Annex I embedded high-risk systems (amended Art. 113(3)(c)(ii))
—Regulation 2026/1744 amends aviation Regulation (EU) 2018/1139 and adds delegated-act powers to Art. 8 of Machinery Regulation (EU) 2023/1230, requiring the Commission to reflect the AI Act's high-risk requirements in the machinery framework, with those delegated acts to apply by 2 Aug 2028
—The amending act also narrows the 'safety component' definition (Art. 3(14)) to systems fulfilling a genuine safety function, tightening the scope of embedded high-risk classification
—Alignment with sectoral conformity-assessment regimes is the stated rationale for the longer runway
New date, the Machinery Regulation delegated-act mechanism (Article 3 of Regulation 2026/1744) and the safety-component redefinition verified directly in the EUR-Lex OJ text; also confirmed by the Commission policy page. The earlier unverified 'carve-out' characterisation was replaced with the verified mechanism.
AI Act Stage 4 (as amended) — Annex III stand-alone high-risk obligations apply 2 December 2027
European Parliament and Council · 2027-12-02announced
Under the AI Act as amended by Regulation 2026/1744, the full obligations for stand-alone high-risk AI systems listed in Annex III (biometrics, critical infrastructure, education, employment, essential public and private services, law enforcement, migration/asylum/border control, justice and democratic processes) apply from 2 December 2027 instead of 2 August 2026. This covers risk management, data governance, technical documentation, logging, human oversight, accuracy/robustness/cybersecurity, conformity assessment, registration and deployer duties.
—Sixteen-month deferral from the original 2 Aug 2026 date, enacted because harmonised standards and national governance/conformity-assessment frameworks were not ready
—Deferral is a fixed date in the amended Act: the proposal's standards-readiness trigger (Commission decision + 6 months, longstop 2 Dec 2027) was converted to a fixed date in negotiations
—Registration in the EU database is retained — including, in simplified form, for providers self-assessing Annex III systems as non-high-risk under Art. 6(3) (streamlined Annex VIII content)
—Article 50 transparency duties applying from 2 Aug 2026 are unaffected by this deferral
New date verified in the amended Art. 113(3)(c)(i) in the OJ text of Regulation 2026/1744; the proposal's conditional-trigger design verified in COM(2025) 836 on EUR-Lex; confirmed by the Commission policy page (updated 31 July 2026).
AI Act extended transition and legacy-system rules (Art. 111): 2027, 2030 and end-2030 horizons
European Parliament and Council · 2027-08-02announced
The AI Act's transitional regime staggers compliance for systems and models already on the market. GPAI models placed on the market before 2 August 2025 must be brought into compliance by 2 August 2027; legacy high-risk systems already placed on the market are caught only if they undergo significant design changes after the relevant application date; high-risk systems used by public authorities must comply by 2 August 2030; and AI components of Annex X large-scale EU IT systems (e.g. SIS, Eurodac) placed on the market before 2 August 2027 have until 31 December 2030. The entry date shown is the first of these milestones.
—2 Aug 2027: compliance deadline for pre-existing GPAI models (placed on market before 2 Aug 2025) — Art. 111(3), unchanged by the Omnibus
—Legacy high-risk systems: Regulation 2026/1744 replaced Art. 111(2) so the reference date is now the (deferred) date of application of Chapter III under Art. 113, and clarified the grace applies at the level of a system's type and model; obligations attach only upon significant design changes after that date
—2 Aug 2030: public-authority providers/deployers of high-risk systems must comply (retained in the replaced Art. 111(2)); 31 Dec 2030: Annex X large-scale IT system components placed on market before 2 Aug 2027 (Art. 111(1))
—A new Art. 111(4) adds the 2 Dec 2026 marking-grace for synthetic-content systems on the market before 2 Aug 2026; combined with the Omnibus deferrals, full application of the Act stretches to end-2030
Article 111 milestones verified in the EUR-Lex OJ text of the base act; the re-anchoring of Art. 111(2) to the deferred Chapter III application dates, the type-and-model clarification, the retained 2 Aug 2030 deadline and the new Art. 111(4) verified directly in the OJ text of Regulation 2026/1744 (amendment (39)). Previously flagged as unverified; now confirmed.
AI Act Stage 3 — general application on 2 August 2026: Article 50 transparency applies; high-risk obligations carved out
European Parliament and Council · 2026-08-02announced
The AI Act's general application date is 2 August 2026 (two days after this tracker's cut-off of 31 July 2026). Because of the Digital Omnibus, what actually starts applying is narrower than originally enacted: the Article 50 transparency obligations (disclosing AI interaction, machine-readable marking of synthetic content, emotion-recognition/biometric-categorisation notices, deepfake and AI-generated public-interest text disclosures) and the remaining general provisions — including Article 101 GPAI fines — take effect, while the Annex III high-risk regime no longer starts on this date.
—Article 50 transparency duties proceed from 2 Aug 2026 as scheduled; breach fines up to EUR 15 million or 3% of worldwide turnover (Art. 99(4) statutory ceilings)
—Grace period: providers of AI systems placed on the market before 2 Aug 2026 have until 2 December 2026 to comply with Art. 50(2) machine-readable marking (new Art. 111(4) inserted by Regulation 2026/1744)
—Annex III high-risk obligations were due on this date but are deferred to 2 Dec 2027 by Regulation 2026/1744; the Member State regulatory-sandbox deadline moved to 2 Aug 2027 (amended Art. 57(1))
—Commission enforcement powers over GPAI (incl. Art. 101 fines) become applicable on this date
Status 'announced' because the stage enters into application 2 Aug 2026, immediately after the tracking date. All carve-outs, the 2 Dec 2026 marking grace, and the 2 Aug 2027 sandbox deadline verified directly in the OJ text of Regulation 2026/1744; fine ceilings verified in Art. 99(4) of the base act; confirmed by the Commission policy page (updated 31 July 2026).
Regulation (EU) 2026/1744 — Digital Omnibus on AI (first amendment to the AI Act)
European Parliament and Council · 2026-07-27in force
Regulation (EU) 2026/1744 of 8 July 2026, amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026 (third day after publication) — days before the AI Act's general application date. It defers the high-risk regime (Annex III stand-alone systems to 2 December 2027; Annex I product-embedded systems to 2 August 2028), grants a marking grace period to 2 December 2026 for systems already on the market, adds new Article 5 prohibitions on AI generating non-consensual intimate material and CSAM, and makes targeted simplifications to the AI Act and to the aviation and machinery frameworks.
—New application dates in amended Art. 113: Annex III high-risk 2 Dec 2027 (was 2 Aug 2026); Annex I embedded high-risk 2 Aug 2028 (was 2 Aug 2027); national sandboxes operational by 2 Aug 2027
—Article 50 transparency kept at 2 Aug 2026, with Art. 50(2) marking grace to 2 Dec 2026 for systems on the market before 2 Aug 2026 (new Art. 111(4)); new NCII/CSAM prohibitions apply from 2 Dec 2026
—Simplifications: Art. 4 AI literacy reframed as supporting measures, bias-detection special-category data processing extended beyond high-risk providers (new Art. 4a, strict-necessity safeguards), simplified EU-database registration for self-assessed non-high-risk Annex III systems (streamlined Annex VIII), SME measures extended to small mid-caps (SMCs, new definitions)
—Penalties: Article 99 fine tiers and amounts unchanged (the SME lower-of rule is extended to SMCs); the penalties framework has applied since 2 Aug 2025
All points verified directly against the EUR-Lex OJ text (CELEX 32026R1744; OJ L, 2026/1744, 24.7.2026; marked 'In force'; 'Done at Strasbourg, 8 July 2026'; entry into force on the third day following publication). The operative marking-grace deadline is 2 December 2026 as stated in the amended text.
Regulation (EU) 2026/1744 (Digital Omnibus on AI) enters into force — high-risk delays now binding law
European Parliament and Council · 2026-07-27in force
The Digital Omnibus on AI was published in the Official Journal as Regulation (EU) 2026/1744 and entered into force on 27 July 2026, days ahead of the AI Act's general application date of 2 August 2026. It makes the high-risk postponements binding (Annex III standalone systems to 2 December 2027; Annex I embedded systems to 2 August 2028), postpones the obligation to mark AI-generated content to 2 December 2026 for systems placed on the market before 2 August 2026, adds the new prohibition on generating CSAM and non-consensual intimate content (taking effect December 2026), and reinforces AI Office supervisory powers over general-purpose AI.
—In force 27 July 2026, ahead of the AI Act's 2 August 2026 general application date
—Annex III high-risk obligations now apply 2 Dec 2027; Annex I embedded-product obligations 2 Aug 2028
—Marking of AI-generated content postponed to 2 Dec 2026 for systems placed on the market before 2 Aug 2026; transparency rules otherwise apply from 2 Aug 2026
—New AI Act prohibition on practices generating CSAM or non-consensual intimate content, taking effect December 2026
Audited 31 July 2026: the regulation number (2026/1744), entry into force on 27 July 2026, and the 2 Dec 2027 / 2 Aug 2028 high-risk dates are confirmed on the Commission's official AI Act policy page (digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai), which also states the new prohibition takes effect December 2026. The marking postponement and its pre-2-Aug-2026 qualifier are confirmed by the EP Legislative Train page. EUR-Lex blocks automated fetching, so the ELI could not be machine-verified, but it is the canonical deterministic ELI for the confirmed number; OJ publication of 24 July 2026 follows from the third-day entry-into-force clause and law-firm reporting — do a manual click-check of the ELI before publication.
Digital Omnibus on AI — Commission proposal COM(2025) 836 (superseded by adopted Regulation 2026/1744)
European Commission · 2025-11-19superseded
On 19 November 2025 the Commission proposed the 'Digital Omnibus on AI' (COM(2025) 836, procedure 2025/0359(COD)), a targeted simplification package amending the AI Act before its general application date. Its core was deferring the high-risk regime — application conditioned on a Commission decision confirming that adequate compliance-support measures are available, plus 6 months (Annex III) or 12 months (Annex I), with longstop dates of 2 December 2027 and 2 August 2028 — alongside a transparency-marking grace period, a softened AI-literacy duty, simplified registration and SME relief. It was negotiated in record time and is superseded by the adopted Regulation (EU) 2026/1744.
—Rationale: delayed harmonised standards and delayed national governance/conformity-assessment frameworks made the 2 Aug 2026 high-risk deadline unworkable (also recital 2 of the final act)
—Legislative track (EUR-Lex procedure record): EP amendments decision 26 Mar 2026; political agreement 7 May 2026; EP first-reading position 16 June 2026; Council approval 29 June 2026; signed 8 July 2026; OJ 24 July 2026
—Final text converted the proposal's standards-conditioned trigger into fixed deferral dates, tightened the proposed marking grace from 2 Feb 2027 to 2 Dec 2026, added Parliament-driven NCII/CSAM prohibitions, and extended the amendments to the Machinery Regulation 2023/1230 (the proposal amended only 2024/1689 and 2018/1139)
—Article 99 fine tiers and amounts were not changed, though the final act extends the SME lower-of fine rule to small mid-caps (new Art. 99(6a)) and adds a fine ground for Art. 25(2)/(4) breaches
Proposal text verified directly on EUR-Lex: the conditional-trigger design (Commission decision + 6/12 months, longstops 2 Dec 2027 / 2 Aug 2028) and the proposed 2 Feb 2027 marking grace are in the proposed Art. 113(d) and transitional provisions. Proposal date confirmed on the Commission library page. Milestones from the EUR-Lex procedure record for 2025/0359/COD; a previously listed 'Council mandate 13 Mar 2026' could not be verified there and was removed.
Digital Omnibus on AI — proposal and negotiation arc (COM(2025) 836)
European Commission (proposal); European Parliament and Council (negotiation) · 2025-11-19news
On 19 November 2025 the Commission proposed the Digital Omnibus on AI (COM(2025) 836), a targeted amending regulation to the AI Act responding to delays in harmonised standards, authority designations and notified-body capacity. The Council adopted its general approach on 13 March 2026, Parliament adopted its position at the second March 2026 plenary, and a provisional trilogue agreement was reached on 7 May 2026 — under three months before the high-risk rules would otherwise have begun applying on 2 August 2026. The deal postponed Annex III high-risk obligations to 2 December 2027 and Annex I (embedded) obligations to 2 August 2028, and added a new AI Act prohibition on practices generating child sexual abuse material and non-consensual intimate or sexual content.
—Proposed 19 Nov 2025 as part of the Commission's Digital Package on simplification; amends Regulation (EU) 2024/1689 (AI Act)
—Provisional Parliament–Council agreement 7 May 2026; Parliament plenary approved 16 June 2026 (423/57/174)
—Core deal: high-risk deadlines moved to 2 Dec 2027 (Annex III) and 2 Aug 2028 (Annex I embedded); new prohibition on AI practices generating CSAM and non-consensual intimate or sexual content, widely reported as a response to the late-2025 Grok deepfake incident
—Also reinforces AI Office powers and reinstates a simplified, proportionate registration obligation for non-high-risk AI systems
European Parliament Legislative Train Schedule (official EP tracker); audited 31 July 2026 — all dates verified against the page: proposal 19 Nov 2025 (COM(2025) 836), Council general approach 13 Mar 2026, trilogue agreement 7 May 2026, IMCO/LIBE approval 2 Jun 2026, plenary 16 Jun 2026 (423 for, 57 against, 174 abstentions). Staged instrument: entry dated to the Commission proposal; final adopted act covered in a separate entry. An earlier unverified Coreper-endorsement date was removed in audit.
Broader Digital Omnibus (GDPR, ePrivacy, Data Act, cybersecurity) still in negotiation
European Commission (proposal); Parliament and Council (negotiation) · 2025-11-19draft
Alongside the AI-specific omnibus, the Commission's 19 November 2025 Digital Package included a wider Digital Omnibus proposing amendments to the GDPR, ePrivacy rules, Data Act, NIS2 and DORA (among others) — codifying case law on when data is 'personal', clarifying use of personal data for AI training, introducing single-click cookie refusal honoured for six months, and creating a single entry point for breach notifications. Unlike the fast-tracked AI omnibus (in force July 2026), this package remains in the ordinary legislative procedure as of late July 2026, facing significant data-protection and civil-society opposition, including EDPB/EDPS concerns over the narrowed personal-data definition. Its AI-training and personal-data provisions will materially shape how GPAI providers source EU training data.
—Proposed 19 Nov 2025 as part of the Digital Package with the Data Union Strategy and European Business Wallets
—Would ease GDPR constraints on AI training data and codify a narrower reading of 'personal data'; single-click cookie refusal honoured for six months
—Still a draft under ordinary legislative procedure as of late July 2026, with EDPB/EDPS and civil-society opposition
—Split fates: the AI omnibus was fast-tracked into force while the data/privacy omnibus remains contested
Commission Digital Package FAQ (primary) verified for the package components and the GDPR/ePrivacy/Data Act/NIS2/DORA scope and key changes. Status audited 31 July 2026: the EP Legislative Train package page still lists the broader Digital Omnibus as tabled/in progress while the AI omnibus is marked close to adoption — no provisional agreement identified; flag for re-verification. EDPB/EDPS concerns corroborated by legal commentary; the specific April 2026 Amnesty campaign detail was not re-verified and has been dropped from the claim set.
AI Act Stage 2 in application — GPAI model obligations, governance, notified bodies, penalties (Chapters V, VII, XII)
European Parliament and Council · 2025-08-02in force
Since 2 August 2025, obligations for general-purpose AI model providers (Chapter V: transparency, copyright policy, training-data summaries; extra duties for systemic-risk models), the governance framework (AI Office, AI Board), the notified-bodies provisions (Chapter III Section 4), confidentiality (Art. 78) and the penalties provisions (Chapter XII, except Art. 101 GPAI fines) apply. Despite industry pressure for a pause, the Commission did not stop the clock for this stage and it took effect on schedule; the 2026 Digital Omnibus left the GPAI substantive obligations essentially unchanged.
—Applied on schedule 2 August 2025 per Article 113, third paragraph, point (b); delayed national designation of authorities and conformity-assessment frameworks is a stated driver of the Digital Omnibus (recital 2 of Regulation 2026/1744)
—GPAI models placed on the market before 2 Aug 2025 have until 2 Aug 2027 to comply (Art. 111(3) transitional rule)
—Article 101 fines for GPAI providers are excepted from this stage and apply only from 2 August 2026
—Regulation 2026/1744 gave the AI Office exclusive competence over AI systems built on a GPAI model by the same provider (or same undertaking) and over AI systems constituting or integrated into designated VLOPs/VLOSEs, with sectoral exceptions
Dates verified in Articles 113(3)(b) and 111(3) of the OJ text of the Act. AI Office exclusive-competence expansion (same-provider GPAI systems; VLOP/VLOSE-embedded systems) verified directly in the OJ text of Regulation 2026/1744 (new Art. 75 provisions and recitals).
AI Act Stage 1 in application — prohibitions (Art. 5) and AI literacy (Art. 4), Chapters I–II
European Parliament and Council · 2025-02-02in force
Since 2 February 2025, the AI Act's Chapters I and II apply: the ban on unacceptable-risk practices (e.g. harmful manipulation, social scoring, untargeted facial-image scraping, emotion recognition at work/school, certain biometric categorisation and real-time remote biometric identification) and the Article 4 AI-literacy duty for providers and deployers. This stage took effect on schedule and remains in application; the Digital Omnibus did not delay it, but it softened the wording of the AI-literacy duty and added new prohibitions.
—Applied on schedule 2 February 2025 per Article 113, third paragraph, point (a); confirmed as in application by the European Commission
—Fines for prohibited practices: up to EUR 35 million or 7% of worldwide annual turnover (Art. 99(3); fine provisions applicable from 2 Aug 2025)
—Regulation 2026/1744 added Article 5 prohibitions on AI systems generating non-consensual intimate material and CSAM (new Art. 5(1)(ba)/(bb), 5(1a)/(1b)), which apply from 2 December 2026
—Regulation 2026/1744 replaced Article 4 so providers and deployers must take measures to support the development of AI literacy, rather than ensure a sufficient level
Application date and fine ceiling verified in the EUR-Lex OJ text of the Act; status confirmed on the Commission policy page (digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai, updated 31 July 2026). Omnibus changes to Arts 4 and 5 and the 2 Dec 2026 application date for the new prohibitions verified directly in the OJ text of Regulation 2026/1744 (amended Art. 113(3)(a)).
Regulation (EU) 2024/1689 — the Artificial Intelligence Act (base instrument)
European Parliament and Council · 2024-08-01in force
The EU AI Act, signed 13 June 2024 and published in the Official Journal on 12 July 2024, entered into force on 1 August 2024. It establishes a horizontal, risk-based framework for AI (prohibited practices, high-risk systems, transparency obligations, general-purpose AI models) with a staged application calendar in Article 113 running originally from February 2025 to August 2027. It has since been amended once, by the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force 27 July 2026), which deferred the high-risk stages.
—OJ publication 12 July 2024 (OJ L, 2024/1689); entry into force 1 August 2024 (twentieth day after publication); no obligations applied at entry into force
—Article 113 staged application: prohibitions/AI literacy (2 Feb 2025); GPAI, governance, notified bodies, penalties except Art 101 (2 Aug 2025); general application (2 Aug 2026); originally Art 6(1) embedded high-risk (2 Aug 2027)
—Amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI): Annex III high-risk deferred to 2 Dec 2027, Annex I embedded high-risk to 2 Aug 2028
—Also amends sectoral acts (incl. aviation Regulation 2018/1139) and interacts with product legislation such as the Machinery Regulation via Annex I; both interfaces further adjusted by the 2026 Omnibus
Verified against the EUR-Lex OJ text (CELEX 32024R1689): title, OJ date 12.7.2024, Article 113 stages and Article 99 fine ceilings read directly from the text. EUR-Lex lists exactly one amending act (32026R1744) plus four language-specific corrigenda. Amendment dates confirmed on the Commission AI policy page (digital-strategy.ec.europa.eu, updated 31 July 2026).
Corrigendum of 19 April 2024 to the Parliament's first-reading position on the AI Act (pre-publication correction)
European Parliament · 2024-04-19superseded
Before signature and OJ publication, the European Parliament approved a corrigendum (dated 19 April 2024) to its 13 March 2024 first-reading position on the AI Act — an extensive legal-linguistic revision of the text. The corrected version is the text approved by the Council on 21 May 2024, signed on 13 June 2024 and published in the Official Journal on 12 July 2024, so this correction is fully absorbed into the in-force text.
—Corrigendum reference TA-9-2024-0138-FNL-COR01, correcting the 13 March 2024 plenary text (procedure 2021/0106(COD))
—Purely a pre-publication lawyer-linguist revision; the OJ text of 12 July 2024 is the corrected, authoritative version
—EUR-Lex lists four post-publication corrigenda to the OJ text of Regulation 2024/1689 (9 Oct 2025; 19 Dec 2025; 27 Mar 2026; 4 May 2026) — all are language-specific (ES/DE/FR/GA/LT/HU/SK/SL/SV; NL/SL; CS; ES/NL) and none affects the English version as of 31 July 2026
Source URL replaced with the official European Parliament document (verified to load; supersedes the unofficial tracker previously cited). The 13 March 2024 adopted text and procedure reference verified on europarl.europa.eu. Language-version corrigenda checked individually on EUR-Lex (CELEX 32024R1689R(01)–R(04)); the 19 April date of the EP corrigendum is the standard citation but was not machine-extractable from the PDF this session.
Adjacent law15
Revised Product Liability Directive (EU) 2024/2853 — software and AI as products
European Parliament and Council · 2026-12-09in force
The new PLD (OJ 18 November 2024, in force December 2024) extends strict, no-fault producer liability to software and AI systems — embedded, standalone, or supplied as a service — and to defects arising after sale from updates, machine learning, or failure to address cybersecurity vulnerabilities. Member States must transpose it by 9 December 2026, and it applies to products placed on the market or put into service from that date (the 1985 directive governs earlier products). With the AI Liability Directive withdrawn, this is the principal EU-level route to compensation for harm caused by defective AI.
—Software and AI expressly within the definition of 'product'; digital manufacturing files and integrated services covered
—Rebuttable presumptions of defectiveness/causation plus a court-ordered evidence-disclosure mechanism ease the claimant's burden in technically complex AI cases
—Compensable damage includes destruction or corruption of data; no minimum damage threshold
—Liability can attach to importers, authorised representatives, fulfilment service providers and, in some cases, online platforms when no EU manufacturer is reachable
EUR-Lex canonical ELI link (official text; EUR-Lex serves empty pages to automated fetches but the ELI format is deterministic). Entry date is the transposition/application deadline — the operative stage as of mid-2026; the directive itself entered into force in December 2024.
Garante EUR 15m fine on OpenAI (ChatGPT) annulled by Court of Rome
Italian DPA (Garante) / Court of Rome · 2026-03-18news
The Garante fined OpenAI EUR 15 million (announced December 2024) for GDPR breaches around ChatGPT — no valid legal basis for training on personal data, transparency failures, late breach notification and inadequate age verification — and ordered a six-month public information campaign. By judgment no. 4153/2026, deposited 18 March 2026, the Court of Rome annulled the fine on competence grounds: reporting indicates the court held that, given OpenAI's Irish main establishment, the GDPR one-stop-shop mechanism made the Irish DPC lead authority. The court did not rule on the substantive GDPR violations, so the underlying legal questions remain open under Irish supervision.
—Landmark first major generative-AI GDPR fine, annulled in 2026 without a ruling on the merits
—Annulment turned on the Garante's competence (one-stop-shop/main-establishment rules), limiting national DPA action against AI providers with an EU establishment
—Judgment no. 4153/2026 of the Court of Rome, deposited 18 March 2026
—Supervision of OpenAI's EU processing now rests primarily with the Irish DPC
Law-firm analysis; wsgr.com blocks automated fetches (403) so the page could not be re-fetched. Annulment, judgment number 4153/2026 and 18 March 2026 deposit date independently corroborated in this audit via multiple Italian sources (ANSA, Repubblica, Altalex, AIPolicy.it), which reference annulment for lack of competence of the Italian authority. The Rome judgment is not published in English; the Garante decision was removed from its website.
Like Company v Google Ireland (C-250/25): first CJEU case on generative AI and copyright
Court of Justice of the European Union (reference from Budapest Environs Regional Court, Hungary) · 2026-03-10news
A Hungarian press publisher alleges that Google's Gemini chatbot reproduced and made available its protected press content. The preliminary reference (lodged 3 April 2025 by the Budapest Kornyeki Torvenyszek) asks whether chatbot training and outputs engage the reproduction right and the Article 15 DSM press publishers' right, and whether and how the Article 4 TDM exception covers LLM training — the first time the CJEU will construe the TDM regime for generative AI. The Court held its first-ever hearing on generative AI and copyright on 10 March 2026; the Advocate General's opinion (reportedly scheduled for September 2026) and the judgment remained pending as of this audit, and the outcome will set the EU-wide baseline for the opt-out debate.
—Will determine whether LLM training falls within Art. 4 DSM and how memorisation/outputs are treated at EU level
—Also raises territoriality of EU copyright for models trained outside the EU
—Judgment expected to discipline divergent national case law such as GEMA v OpenAI
Official CJEU case file (curia.europa.eu blocks automated access — 403 in this audit — but this is the canonical case-number link; verify in a browser). Hearing date of 10 March 2026, parties, referring court and lodging date corroborated via search and Bird & Bird's hearing report (twobirds.com, which blocks bots). AG opinion date of 3 September 2026 rests on a single aggregated report — treat as indicative.
Commission opens DSA proceedings against X over Grok AI deepfakes
European Commission · 2026-01-26news
On 26 January 2026 the Commission opened a new formal DSA investigation against X over the integration of the Grok generative-AI chatbot, and simultaneously extended its December 2023 investigation of X's recommender systems. It is examining whether X properly assessed and mitigated systemic risks under Articles 34-35 before deploying AI features that were used to generate manipulated sexually explicit images at scale — including content that may amount to child sexual abuse material — and whether its recommender systems spread that content. It is the first DSA enforcement action aimed squarely at generative AI embedded in a very large platform, effectively using the DSA as an AI-governance tool ahead of the AI Act's own transparency rules. Proceedings are ongoing; no findings of infringement have been made.
—Tests whether DSA systemic-risk duties apply to on-platform generative-AI features — a question with precedential weight for all VLOPs
—Focus areas: ad hoc risk assessment before Grok's deployment, mitigation of illegal sexual content and gender-based violence, recommender amplification
—Potential remedies include fines up to 6% of global turnover and binding compliance measures
Official Commission news page (URL, 26 January 2026 date and content verified by direct fetch in this audit); press release IP/26/203. Original entry described this solely as an 'extension' of existing proceedings — corrected: the Commission opened a new formal investigation on Grok and extended the December 2023 recommender-systems investigation.
Digital Omnibus: proposed GDPR amendments to facilitate AI training
European Commission · 2025-11-19draft
The Commission's simplification package of 19 November 2025 proposes the first substantive GDPR amendments bearing directly on AI: an express legitimate-interest basis for processing personal data to develop and operate AI models and systems (with data-minimisation and safeguard conditions), a conditional allowance for incidental processing of special-category data during AI training coupled with removal efforts, and a relative-identifiability clarification of the personal-data definition. A parallel Digital Omnibus on AI would postpone AI Act high-risk obligations (Annex III to 2 December 2027, Annex I to 2 August 2028). Both are only proposals: they are pending before Parliament and Council and remain contested, so the GDPR and the EDPB Opinion 28/2024 framework continue to apply unchanged.
—Would partially codify (and go beyond) EDPB Opinion 28/2024 on legitimate interest for AI training
—Incidental special-category data in training sets would be tolerated subject to safeguards and removal efforts
—Nothing is in force: draft awaiting first readings; timeline for adoption uncertain
Official Commission library page for the Digital Omnibus regulation proposal (URL and 19 November 2025 date verified by direct fetch in this audit); the parallel AI package is at digital-strategy.ec.europa.eu/en/library/digital-omnibus-ai-regulation-proposal. Substantive GDPR/AI Act detail cross-checked against Latham & Watkins analysis. COM numbers not included — confirm against EUR-Lex if needed.
GEMA v OpenAI (Munich Regional Court I): first European ruling that AI training/outputs infringed copyright
Landgericht München I (Germany, national court) · 2025-11-11news
On 11 November 2025 (case 42 O 14139/24) the Munich Regional Court held two OpenAI group companies liable for infringing lyrics of nine German songs: memorisation of protected works in model weights, and their reproduction in ChatGPT outputs on simple prompts, are copyright-relevant reproductions, and the court largely granted GEMA's claims for injunctive relief, information and damages (a separate claim over altered lyrics was dismissed). The court held the Art. 4 DSM TDM exception (s. 44b German Copyright Act) covers only the analytical training phase and does not extend to memorisation or output reproduction. The judgment is not final: OpenAI has appealed to the Munich Higher Regional Court (OLG München, case 6 U 3662/25 e), where the case was pending as of this audit. Not binding beyond Germany but the leading national precedent on the TDM defence for generative AI.
—First European merits ruling against an AI developer over model training and outputs
—Memorisation-as-reproduction reasoning directly narrows the practical scope of the Art. 4 TDM exception
—Under appeal: OpenAI's Berufung is pending before OLG München (6 U 3662/25 e); no final decision
Official Munich Regional Court I press release (11/2025), in German — URL and holdings verified by direct fetch in this audit; GEMA's own release is at gema.de/de/w/grundsatzurteil-gema-gegen-openai (also verified). The original entry's claims of a Munich Higher Regional Court 'confirmation' and a pending BGH case 'I ZR 281/25' could not be substantiated and are contradicted by German reporting (appeal pending at OLG, nothing before the BGH) — removed.
AI Liability Directive proposal — formally withdrawn
European Commission · 2025-10-06superseded
Proposed on 28 September 2022 (procedure 2022/0303(COD)), the AILD would have harmonised fault-based civil claims for AI harms through evidence-disclosure duties and rebuttable presumptions of causation keyed to AI Act non-compliance. The Commission announced its withdrawal in the 2025 work programme (11 February 2025), citing no foreseeable agreement, and the withdrawal was formalised by notice in the Official Journal (C/2025/5423) of 6 October 2025. Fault-based AI liability therefore remains a matter of the 27 national legal systems, alongside the strict-liability regime of the revised PLD; no replacement proposal had been tabled as of this audit.
—Withdrawal leaves a deliberate gap: professional-use AI harms and pure economic loss largely fall outside the revised PLD
—Parliament (JURI) had explored converting it into a broader software-liability regulation before withdrawal
—National courts are expected to use AI Act compliance as a de facto standard of care
European Parliament Legislative Train file (official EP tracker). URL and content re-verified by direct fetch in this audit: status 'withdrawn', OJ notice C/2025/5423 published 6 October 2025 confirmed.
AI Act Article 53 copyright interface: Commission template for public summary of training content
European Commission (AI Office) · 2025-07-24in force
AI Act Article 53(1)(c)-(d), applicable to general-purpose AI providers since 2 August 2025, requires a copyright policy honouring DSM Art. 4(3) TDM reservations and publication of a sufficiently detailed public summary of training content. On 24 July 2025 the Commission published the mandatory template and explanatory notice for that summary: narrative disclosure of data sources including main datasets and prominent scraped domains, measures taken to respect TDM opt-outs, with periodic updates required. The AI Office's enforcement powers begin 2 August 2026 (fines up to 3% of worldwide turnover or EUR 15 million); models placed on the market before 2 August 2025 have until 2 August 2027 to comply.
—Template is the operative bridge between the AI Act and DSM copyright law — it exists in particular to help rightholders enforce TDM opt-outs
—Balances transparency against trade secrets via narrative rather than dataset-level disclosure
—The voluntary GPAI Code of Practice (July 2025) contains a copyright chapter operationalising the same duties — covered in this tracker's GPAI slice
Official Commission library page; URL and 24 July 2025 publication date re-verified by direct fetch in this audit. Note: the proposed Digital Omnibus on AI (draft) would adjust some AI Act deadlines for high-risk systems but nothing affecting these GPAI duties is in force.
Garante fines Replika (Luka Inc.) EUR 5m over AI companion chatbot
Italian DPA (Garante) · 2025-04news
By decision adopted 10 April 2025 (announced 19 May 2025) the Garante fined US developer Luka Inc. EUR 5 million over the Replika AI companion: no valid legal basis for processing, an inadequate privacy notice, and no effective age-verification despite risks to children. The decision follows the February 2023 emergency block of Replika in Italy, and the authority opened a separate inquiry into the training of the underlying language model. It is the leading EU enforcement precedent on emotional-companion AI and child protection.
—Multiple GDPR violations identified, including legal basis, transparency and data-protection-by-design failures
—Age verification found ineffective despite documented risks to minors
—Separate investigation opened into LLM training-data processing
Garante docweb link as cited via IAPP reporting; garanteprivacy.it drops automated connections and this audit could not confirm the specific docweb number — verify in a browser before publication. Fine amount, 10 April 2025 adoption and 19 May 2025 announcement corroborated by Reuters, EDPB national-news reporting and the Garante's own English press release located via search. The precise GDPR-article list in the original entry could not be re-verified and was generalised.
Garante blocks DeepSeek in Italy (urgent limitation on processing)
Italian DPA (Garante) · 2025-01-30news
On 30 January 2025 the Garante imposed, with immediate effect, a limitation on the processing of Italian users' personal data by Hangzhou DeepSeek and Beijing DeepSeek, effectively blocking the chatbot for the Italian market, and opened an investigation. The companies' claim that the GDPR did not apply to them was rejected because the service was offered to users in Italy; their replies on training data, legal basis and Chinese-server storage were deemed wholly insufficient. It extends the Garante's enforcement line against non-EU AI providers (ChatGPT and Replika blocks in 2023) to a Chinese provider.
—Art. 3(2) GDPR territorial scope applied to a Chinese AI service offered to EU users
—Concerns: legal basis and sources of training data, transparency, and transfers/storage on servers in China
—Urgency procedure under Art. 58(2)(f) GDPR; investigation continues
Official Garante press release (docweb 10097450, identified via multiple secondary sources in this audit; Italian, with English version available). garanteprivacy.it drops automated connections so the link could not be fetched directly — verify in a browser. Bird & Bird analysis corroborates; a follow-up Garante measure of 1 February 2025 is docweb 10098477.
EDPB Opinion 28/2024 on personal data processing in the context of AI models
European Data Protection Board · 2024-12-17standard
Adopted 17 December 2024 at the request of the Irish Data Protection Commission, this Article 64(2) GDPR opinion is the framework EU regulators apply to AI models trained on personal data. It addresses when a model can be considered anonymous, when legitimate interest (Art. 6(1)(f) GDPR) can lawfully ground AI development and deployment, and how unlawfully processed training data can taint subsequent operation of a model. It is guidance, not binding law, but it steers national DPA enforcement against AI services.
—Model anonymity requires that both direct extraction of training data and obtaining it via queries be insignificantly likely, assessed case by case
—Legitimate interest is available for AI training only after a documented three-step test (purpose, necessity, balancing) with mitigating measures
—Unlawful processing in the development phase can undermine the lawfulness of deployment unless the model is genuinely anonymised
—Requested by the Irish DPC, which supervises several major AI providers with EU main establishment in Ireland
Official EDPB PDF. edpb.europa.eu returns HTTP 403 to automated fetches, so the link could not be re-fetched in this audit, but the filename matches the EDPB's published file and all substantive content was independently confirmed. Non-binding consistency guidance, not a legal act.
Clearview AI: Dutch DPA fine of EUR 30.5m caps multi-DPA enforcement against facial-recognition scraping
Autoriteit Persoonsgegevens (NL); earlier fines by IT, EL and FR DPAs · 2024-09news
In September 2024 the Dutch DPA fined Clearview AI EUR 30.5 million, plus penalty orders of up to EUR 5.1 million, for building an illegal database of billions of face images scraped from the internet and processing biometric data without a legal basis. It follows EUR 20 million fines each from the Italian, Greek and French DPAs (2022) and a further CNIL penalty payment order (2023). The AP also warned that using Clearview's services is itself unlawful for Dutch organisations and said it was examining personal liability of Clearview's directors, as the company has not complied with any EU fine.
—Benchmark GDPR enforcement line against AI-driven biometric scraping predating the AI Act's remote-biometric rules
—Extraterritorial application: Clearview has no EU establishment yet was fined under Art. 3(2) GDPR
—Non-compliance across jurisdictions pushed the AP to consider directors' personal liability
Official Dutch DPA English press release. autoriteitpersoonsgegevens.nl returns 403 to automated fetches, so the link could not be re-fetched in this audit; URL matches the AP's published page and all substantive facts are well corroborated. Month precision; announced 3 September 2024.
Commission DSA guidelines on electoral-process risks, including generative AI content
European Commission · 2024-04standard
Guidelines under DSA Article 35(3) for VLOPs and VLOSEs on mitigating systemic risks to electoral processes, announced 26 March 2024 and formally adopted 26 April 2024. They set out recommended best practices that include measures specifically directed at generative AI: labelling AI-generated and deepfake content, adapting content moderation and recommender systems to synthetic media, and cooperating during election periods. Non-binding, but the Commission treats them as the benchmark in DSA supervision and enforcement concerning AI-generated election content.
—First Commission instrument to operationalise DSA systemic-risk duties for generative AI
—Followed by platform stress-tests ahead of the June 2024 European Parliament elections
Official Commission library page (URL re-verified by direct fetch in this audit; the page states formal adoption on 26 April 2024, while the Commission announced the guidelines on 26 March 2024 — entry dated at month precision to the formal adoption). Guidance, not binding law.
Digital Services Act — obligations bearing on AI-generated content
European Parliament and Council · 2024-02-17in force
Regulation (EU) 2022/2065 has applied in full since 17 February 2024 (and to designated VLOPs/VLOSEs since late August 2023). Although drafted before the generative-AI wave, it is now a primary AI-content instrument: Articles 34-35 require very large platforms to assess and mitigate systemic risks stemming from the design and functioning of their services — which the Commission reads as covering integrated generative-AI features — and Article 35(1)(k) expressly lists prominent marking of AI-generated or manipulated media (deepfakes) as a mitigation measure. Recommender-system transparency (Arts. 27, 38), advertising rules (Arts. 26, 39) and researcher data access (Art. 40) likewise reach AI-driven amplification of synthetic content.
—Systemic-risk duties (Arts. 34-35) are the operative hook for generative-AI features inside platforms — now being tested in the X/Grok proceedings
—Deepfake marking appears in the DSA as a mitigation measure, complementing the AI Act Art. 50 labelling duties that apply from 2 August 2026
—Non-compliance can draw fines up to 6% of global annual turnover
EUR-Lex canonical ELI link (official text). Date shown is the full-application date.
DSM Directive (EU) 2019/790, Articles 3-4 — text and data mining exceptions
European Parliament and Council · 2019-06-06in force
The DSM Directive (in force 6 June 2019; national transposition due 7 June 2021) supplies the EU copyright basis for AI training. Article 3 gives research organisations and cultural-heritage institutions a mandatory, non-overridable TDM exception for scientific research; Article 4 permits TDM by anyone, but only where rightholders have not expressly reserved their rights — for online content, in machine-readable form (Art. 4(3)). AI Act Article 53(1)(c) now requires all general-purpose AI providers placing models on the EU market to identify and honour these reservations regardless of where training occurred, making the Art. 4 opt-out the fulcrum of the EU AI-copyright debate.
—Art. 4 opt-out mechanics (what counts as machine-readable; robots.txt vs. metadata standards) remain unsettled and are before the CJEU in C-250/25
—German first-instance case law (GEMA v OpenAI, under appeal) holds that memorisation in model weights falls outside the TDM exception
—Rightholder pressure for remuneration and opt-out reform continued through 2025-2026, but no legislative proposal amending Arts. 3-4 was confirmed as of this audit — verify before publication
AI Office / Commission enforcement powers over GPAI providers become exercisable
European Commission (AI Office) · 2026-08-02announced
GPAI obligations have applied since 2 August 2025, but the Commission's supervision and enforcement powers under Chapter V only enter into application on 2 August 2026, the end of the one-year adjustment period. From that date the AI Office can request information, conduct model evaluations, require corrective measures, and fine GPAI providers up to 3% of global annual turnover or EUR 15 million, whichever is higher (Art. 101 AI Act). The Digital Omnibus did not move this date.
—Commission page (updated 28 April 2026) confirms: obligations applicable since 2 Aug 2025; Commission enforcement powers, including fines, enter into application 2 Aug 2026
—Fines up to 3% of global annual turnover or EUR 15m, whichever is higher, per Art. 101 AI Act
—Models placed on the market before 2 Aug 2025 must comply by 2 Aug 2027 (confirmed on the same page)
—GPAI is enforced centrally by the Commission/AI Office, not by national market surveillance authorities (Art. 88)
Official Commission policy page, re-verified live (last update 28 April 2026): all three dates (2025 obligations, 2026 enforcement, 2027 legacy compliance) confirmed verbatim. Fine levels are statutory (Art. 101 AI Act), not stated on the page. Status 'announced' because the powers become exercisable days after the audit snapshot.
AI Act enforcement architecture goes live 2 August 2026 — Commission GPAI penalty powers activate amid patchy national readiness
European Commission AI Office; national competent authorities · 2026-08-02announced
On 2 August 2026 the AI Act's governance, market-surveillance and penalties chapters become applicable: the AI Office and Member State authorities become responsible for implementing, supervising and enforcing the AI Act, and the Commission gains enforceable penalty powers (up to 3% of global annual turnover or EUR 15 million) over GPAI model providers for obligations that have applied since August 2025. As of the latest public tracking, no formal AI Act fine had been reported, and a majority of Member States had not yet fully designated their national competent authorities — making the enforcement start asymmetric across the Union.
—Commission/AI Office GPAI enforcement powers and the AI Act penalty regime (up to 3% of global turnover or EUR 15m for GPAI providers) apply from 2 Aug 2026
—GPAI obligations have applied since 2 Aug 2025; models placed on the market before that date have until 2 Aug 2027 to comply
—No formal AI Act fines publicly reported as of mid-2026
—Authority designations remained incomplete into mid-2026 (only 9 of 27 fully designated per tracker data of 17 June 2026), fragmenting day-one enforcement capacity
Commission AI Act policy page (primary) verified for the 2 Aug 2026 governance/enforcement applicability. Readiness figures corrected in audit: per artificialintelligenceact.eu national implementation tracker (last updated 17 June 2026), 9 Member States had designated both market-surveillance and notifying authorities, 12 had partial clarity, and 6 (incl. Austria, Belgium, Bulgaria, Croatia, Estonia, Greece) had designated none — an earlier '24 of 27 designated' figure was contradicted by that tracker and removed. Fine amounts per Art. 101 AI Act; treat country-level detail as reported, not official.
AI Omnibus — Regulation (EU) 2026/1744 amending the AI Act (in force)
European Parliament and Council · 2026-07-27in force
The first substantive amendment of the AI Act, part of the Digital Simplification Package: proposed 19 November 2025, politically agreed 7 May 2026, published in the Official Journal as Regulation (EU) 2026/1744 and in force since 27 July 2026. It defers the high-risk regime — Annex III standalone systems to 2 December 2027 and Annex I product-embedded systems to 2 August 2028 — against the backdrop of missing harmonized standards and incomplete national implementation, and adds a new prohibition on AI enabling CSAM and non-consensual intimate imagery, applying from December 2026. Legal analyses also report further centralization of enforcement in the Commission/AI Office; the GPAI enforcement start of 2 August 2026 was not deferred.
—High-risk deadlines deferred: Annex III to 2 Dec 2027; Annex I embedded systems to 2 Aug 2028 — both confirmed on the Commission's AI Act policy page
—New prohibition on AI enabling CSAM/non-consensual intimate imagery applies from December 2026 ('prohibition 9' on the Commission page)
—Article 50 transparency obligations still apply from 2 Aug 2026, and the GPAI enforcement start date of 2 Aug 2026 was not deferred
—Regulation number and 27 July 2026 entry into force confirmed via the Commission's AI Act page, which links the final text at EUR-Lex (OJ L, 2026/1744)
Source URL is the EUR-Lex link the Commission's own AI Act policy page (digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai) gives for the final text; EUR-Lex does not render for automated fetch but the citation is Commission-confirmed. AUDIT: unverifiable staging details from the original entry (Council approval 29 June, signature 8 July, OJ publication 24 July 2026), the regulatory-sandbox deadline change, the Art. 50 machine-readable-marking grace period to 2 Dec 2026, and the Machinery/aviation amendments were removed — none could be confirmed against official sources.
Code of Practice on Transparency of AI-generated Content (Article 50) — final version
AI Office (independent-expert drafting, multi-stakeholder process) · 2026-06-10in force
A voluntary code, published in final form on 10 June 2026, giving providers and deployers of generative AI practical means to meet the legally binding Article 50 transparency obligations that apply from 2 August 2026 — marking and detection of AI-generated audio, image, video and text, plus labelling of deepfakes and certain AI-generated publications. It followed a first draft on 17 December 2025 and a second draft on 3 March 2026. By end of July 2026 roughly 190 companies and organisations had signed.
—Supports Art. 50 obligations applicable from 2 Aug 2026; binding obligations apply regardless of signature
—Two-part structure: provider-side marking/detection rules and deployer-side labelling of deepfakes and AI-generated text
—Approximately 190 signatories by end of July 2026 (Commission page, updated 31 July 2026)
—Final version presented to the AI Board on 11 June 2026 as the compliance vehicle for the August transparency deadline
Official Commission policy page, re-verified live (final publication 10 June 2026, draft dates, ~190 signatories, two-part structure all confirmed). AUDIT: second-draft date corrected from 5 March to 3 March 2026 per the official page; the claimed Digital Omnibus grace period to 2 Dec 2026 for machine-readable marking is not mentioned on the page and could not be verified elsewhere — removed.
Cloud and AI Development Act (CADA) proposed — sovereignty-driven infrastructure law
European Commission · 2026-06-03draft
On 3 June 2026 the Commission adopted its proposal for the Cloud and AI Development Act (COM(2026) 502), built on three pillars: funding next-generation cloud/AI research and innovation, accelerating deployment of data-centre capacity in the EU (in line with the earlier target of at least tripling capacity within five to seven years), and creating a single EU-wide framework for assessing cloud and AI sovereignty with a public-sector adoption mechanism that could constrain non-EU providers in sensitive procurement. It is the clearest legislative expression of the EU's post-2025 shift toward strategic autonomy in AI infrastructure, and a fresh source of EU–US friction.
—Proposal adopted 3 June 2026 (COM(2026) 502), after reported slippage from an earlier announced timetable
—Three pillars: cutting-edge cloud/AI RD&I funding, accelerated EU data-centre deployment, and an EU-wide cloud/AI sovereignty assessment framework
—Sovereignty criteria plus a public-sector adoption mechanism could restrict non-EU hyperscalers in sensitive workloads — a new EU–US flashpoint
—Feedback period reported open into late August 2026 (verify on the Commission's Have Your Say portal)
Official Commission library page for the proposal (primary); audited 31 July 2026 — 3 June 2026 date, COM(2026) 502 and SWD(2026) 502, and the three objectives (RD&I, capacity, autonomy/sovereignty framework) verified against the page. The reported feedback/consultation window (into late August 2026) was not visible on the Commission's consultations listing and rests on secondary reporting — verify on the Have Your Say portal before citing. The claim that the file slipped from an earlier announced slot rests on reporting, not official text.
GPAI Code Signatory Taskforce begins operating — first working meetings on copyright and safety
European Commission AI Office · 2026-01-30news
The AI Office convened the first meeting of the Signatory Taskforce of the GPAI Code of Practice on 30 January 2026, the operational forum where signatories and the AI Office coordinate consistent implementation of the Code's commitments. A second meeting on 13 March 2026 focused on the copyright chapter and a third on 27 March 2026 on safety and security. This is the main visible machinery of GPAI supervised self-regulation ahead of the Commission's enforcement powers becoming applicable in August 2026.
—First taskforce meeting 30 Jan 2026; copyright-chapter meeting 13 Mar 2026; safety-and-security meeting 27 Mar 2026
—Chaired by the AI Office; facilitates coherent application of the Code among signatories
—Functions as the compliance-dialogue channel before formal GPAI enforcement powers activate on 2 Aug 2026
Official Commission policy page (primary source); audited 31 July 2026 — all three meeting dates and the AI Office chairing role verified against the page. The AI Office publishes the taskforce Vademecum including the participant list.
Commission opens DSA proceedings over Grok on X — first flagship EU enforcement action aimed at a generative AI deployment
European Commission (DSA enforcement) · 2026-01-26news
On 26 January 2026 the Commission opened formal Digital Services Act proceedings against X over the integration of xAI's Grok, investigating whether X diligently assessed and mitigated systemic risks before deploying Grok functionalities in the EU — specifically risks of dissemination of illegal content such as manipulated sexually explicit images, including content that may amount to child sexual abuse material. Though brought under the DSA rather than the AI Act, it is the first flagship EU enforcement action aimed at a generative AI deployment, and the underlying late-2025 Grok mass-deepfake incident is widely credited with motivating the new CSAM/NCII prohibition inserted into the AI Act by the Digital Omnibus.
—Formal DSA proceedings opened 26 Jan 2026 over X's risk assessment and mitigation for Grok's functionalities
—Suspected failures include not conducting and transmitting an ad hoc risk-assessment report for Grok's functionalities before EU deployment
—Commission simultaneously extended its December 2023 investigation into X's recommender systems
—Signals the Commission's use of the DSA's mature toolkit against platform-integrated AI while AI Act enforcement ramps up; the Grok incident also shaped the AI Act's new CSAM/NCII prohibition
Official Commission news item (primary; press release IP/26/203); audited 31 July 2026 — opening date, scope (including the ad hoc risk-assessment report obligation) and the simultaneous extension of the December 2023 recommender-systems investigation all verified against the page. DSA action, not AI Act action — included as the leading enforcement signal for generative AI in the EU. An unverified claim about parallel UK ICO investigations was removed in audit.
EU–US friction over the AI Act and digital rulebook escalates into trade leverage
US administration / European Commission (political developments) · 2025-12news
Through late 2025 and into 2026 the US administration linked trade to EU digital deregulation: Commerce Secretary Lutnick reportedly suggested relief from 50% steel/aluminium tariffs depended on the EU relaxing its digital rules, and in December 2025 USTR threatened to use 'every tool at its disposal' against EU measures, floating retaliation against European firms over DMA/DSA enforcement of US companies — pressure EU officials reportedly regard as contrary to the July 2025 trade truce. The Commission rejected accusations of bias, insisted its rules apply equally to all companies, and denied the Digital Omnibus was a concession to Washington (digital chief Virkkunen framing it as competitiveness-driven), while France and Germany convened a European Digital Sovereignty Summit on 18 November 2025, accelerating the EU's tech-sovereignty counter-agenda.
—US reportedly tied tariff relief and trade-truce goodwill to relaxation of EU digital regulation, including AI and platform rules
—December 2025: explicit US retaliation threats over DMA/DSA enforcement against American tech companies (USTR: 'every tool at its disposal')
—Commission denied bias and denied the Digital Omnibus was a response to US pressure; critics inside the EU disagreed
—Franco-German European Digital Sovereignty Summit (18 Nov 2025) marks the counter-movement toward strategic tech autonomy
No single primary source exists for this political dynamic. Audited 31 July 2026: the Fortune article (17 Dec 2025) verifies the USTR 'every tool at its disposal' threat, the DMA/DSA focus, targets incl. Spotify/SAP/Siemens/Mistral, and the Commission's equal-application response. The Lutnick tariff linkage and the truce-violation framing come from separate contemporaneous reporting and are attributed as reported, not re-verified; an unverified claim about a 2026 Franco-German joint task force was removed. All framing attributed to reporting, not official EU text.
AI Act Service Desk and Single Information Platform launched
European Commission (AI Office) · 2025-10-08in force
On 8 October 2025 the Commission launched the AI Act Single Information Platform and the AI Act Service Desk, a team of experts working with the AI Office that answers stakeholder questions on the Act. The platform hosts a Compliance Checker (self-assessment of whether and how obligations apply), an AI Act Explorer for navigating the text, and a question-submission form. Launched in English, French and German, with availability in all 24 EU official languages announced for early 2026.
—Central implementation-support hub at ai-act-service-desk.ec.europa.eu (live and operational as of the audit)
—Compliance Checker, AI Act Explorer, and direct question channel to the Service Desk, all confirmed on the launch announcement and the live platform
—Answers are guidance, not legally binding interpretations
—Platform also carries FAQs, news updates and guidance resources supporting AI Act application
Official Commission press announcement, re-verified live (launch date 8 Oct 2025, three tools, EN/FR/DE at launch, 24-language rollout announced for early 2026). AUDIT: hosting of the formally adopted prohibited-practices guidelines (C(2025) 5052) on the platform could not be verified — removed.
Apply AI Strategy — the Commission pivots from rulemaking to AI adoption
European Commission · 2025-10announced
In October 2025 the Commission presented the Apply AI Strategy, its flagship push to accelerate AI uptake across ten strategic industry sectors plus the public sector (healthcare and pharmaceuticals, mobility and automotive, robotics, manufacturing and construction, climate and environment, energy, agri-food, defence and space, electronic communications, and cultural/creative/media), backed by AI Factories and Gigafactories, Experience Centres for AI, and an Apply AI Alliance coordination forum, and promoting an 'AI first' policy posture. Together with the simplification omnibus, it marks the post-AI Act phase of EU policy: the centre of gravity shifting from writing rules to driving adoption and competitiveness.
—Sectoral flagships across 10 strategic industry sectors plus the public sector; Experience Centres for AI and AI Factories as delivery infrastructure
—Apply AI Alliance is the main coordination forum for AI providers, industry, academia and the public sector; includes a 'buy European' push for the public sector
—Signals the Commission's strategic turn from regulation to adoption and competitiveness after the AI Act
Official Commission policy page (primary); audited 31 July 2026 — sector list, AI Factories, Experience Centres (transformed European Digital Innovation Hubs), Apply AI Alliance and the 'AI first policy' concept all verified against the page. The page does not display the exact adoption date; October 2025 presentation is consistent with contemporaneous reporting — month-level date used deliberately.
General-Purpose AI Code of Practice (final version) and signatory dynamics
AI Office (drafted by independent experts); adequacy confirmed by European Commission and Member States (AI Board) · 2025-07-10in force
The final GPAI Code of Practice was published 10 July 2025 with three chapters — Transparency (Model Documentation Form), Copyright, and Safety and Security (systemic-risk models only). On 1 August 2025 the Commission announced that it and the Member States had confirmed the Code is an adequate voluntary tool for demonstrating compliance with the AI Act's GPAI obligations, giving signatories reduced administrative burden and greater legal certainty. Adherence becomes the practical compliance benchmark once AI Office enforcement starts on 2 August 2026.
—23 signatories listed on the Commission page (updated 23 April 2026), incl. OpenAI, Google, Microsoft, Amazon, Anthropic, IBM, Mistral AI, Aleph Alpha, Cohere and ServiceNow
—xAI signed only the Safety and Security chapter and must show transparency/copyright compliance by alternative adequate means; Meta publicly declined to sign (July 2025)
—Adequacy confirmed via Commission announcement of 1 August 2025: 'the Commission and the Member States' deemed the Code an adequate voluntary tool
—Signatories established a Signatory Taskforce, chaired by the AI Office, to facilitate coherent application of the Code
Official Commission page, re-verified live (chapters, xAI partial signature, taskforce, signatory benefits all confirmed). Adequacy date confirmed via Commission announcement of 1 Aug 2025 (digital-strategy.ec.europa.eu/en/news/eu-rules-general-purpose-ai-models-start-apply-bringing-more-transparency-safety-and-accountability). AUDIT: original entry claimed 26 signatories; the Commission page lists 23 (plus xAI's partial signature) — corrected. Taskforce founding year could not be verified and was removed.
GPAI Code of Practice compliance split: Meta refuses, xAI signs safety chapter only, other frontier labs sign
European Commission AI Office / GPAI model providers · 2025-07news
After the Commission received the final GPAI Code of Practice on 10 July 2025, the frontier-lab field split ahead of the 2 August 2025 applicability of GPAI obligations. Amazon, Anthropic, Google, IBM, Microsoft, OpenAI, Mistral AI and Aleph Alpha signed the full Code; Meta publicly refused on 18 July 2025 (chief global affairs officer Joel Kaplan citing 'legal uncertainties' and measures going beyond the AI Act); xAI signed only the Safety and Security chapter, leaving transparency and copyright compliance to be demonstrated by other means. Major Chinese providers (Alibaba, Baidu, DeepSeek) did not sign, and Google signed while publicly criticising aspects of the Code.
—Signatories of the full Code include Amazon, Anthropic, Google, IBM, Microsoft, OpenAI, Mistral AI, Aleph Alpha
—Meta was the only major Western frontier lab to publicly refuse outright (18 July 2025)
—xAI signed only the Safety and Security chapter — a partial-adherence posture the AI Office must now police
—Adherence offers a streamlined, Commission/AI Board-endorsed route to demonstrate AI Act compliance; non-signatories must demonstrate compliance by alternative means
Official Commission signatory-taskforce page confirms the Code framework and key dates but does not display the signatory list inline (participant list lives in the taskforce Vademecum). Meta's refusal, Kaplan's stated reasons, and OpenAI/Anthropic/Microsoft signing intentions verified via Euronews, 23 July 2025 (https://www.euronews.com/my-europe/2025/07/23/meta-wont-sign-eus-ai-code-but-who-will); the full signatory list and xAI's safety-chapter-only signature reflect the Commission's 1 August 2025 signatory publication and contemporaneous reporting. Month-level date used; individual signature dates not all verified.
Member states8
National AI regulatory sandboxes: Article 57 deadline of 2 August 2026 and uneven readiness
Member-state competent authorities (obligation under Article 57 AI Act) · 2026-08-02announced
Article 57 AI Act requires every member state to ensure at least one operational national AI regulatory sandbox (alone or jointly with other states) by 2 August 2026 — a deadline arriving with readiness highly uneven. Spain leads: its pilot sandbox under Royal Decree 817/2023 selected a first cohort of 12 high-risk AI systems by provisional resolution of 3 April 2025, and the pilot yielded AESIA's 16 compliance guides published in early 2026. Germany's KI-MIG (in force 29 July 2026) creates a statutory duty for at least one Bundesnetzagentur-run sandbox aimed particularly at SMEs, and the EU-funded EUSAiR project supports national rollouts — but states that have not even designated authorities are unlikely to meet the sandbox deadline.
—Every member state must have at least one operational AI sandbox by 2 August 2026 (joint sandboxes allowed)
—Spain's RD 817/2023 pilot is the EU's first: 12 projects selected by provisional resolution of 3 April 2025; produced AESIA's 16 sandbox-derived guides (early 2026)
—Germany's KI-MIG (in force 29 July 2026) obliges the BNetzA to run at least one KI-Reallabor with SME focus; EUSAiR supports national set-up
—States that have not designated authorities are unlikely to meet the sandbox deadline, compounding Art. 70 delays
Primary source verified: Commission AI Act Service Desk confirms the 'operational by 2 August 2026' deadline and joint-sandbox option. Spain's first-cohort date (provisional resolution 3 April 2025, 12 projects) and the 16 AESIA guides verified via Spanish official/secondary sources (aesia.digital.gob.es/es/guias); Germany's sandbox duty verified via the BNetzA release of 29 July 2026. An earlier claim that Lithuania had run sandbox pilots could not be verified and was dropped; EUSAiR per secondary reports.
Member-State Implementation of the AI Act: Designation Status Overview (mid-2026)
EU Member States (status per FLI AI Act implementation tracker and EPRS) · 2026-07news
Member states were required by Article 70 AI Act to designate notifying and market surveillance authorities and a single point of contact by 2 August 2025, and most missed the deadline. Per the FLI tracker (updated 17 June 2026), 9 states (Cyprus, Denmark, Finland, Hungary, Ireland, Italy, Lithuania, Malta, Slovenia) had designated both authority types, 6 had designated nothing (Austria, Belgium, Bulgaria, Croatia, Estonia, Greece), the remaining 12 were partial, and per EPRS the Commission's single-point-of-contact list held only 8 of 27 entries as of March 2026. Models split between centralized supervision (Spain's AESIA, Poland's new KRiBSI, Germany's Bundesnetzagentur) and decentralized sectoral supervision (Finland, Ireland, France; Denmark hybrid); in late July 2026 Germany's KI-MIG entered into force (29 July) and Poland's act was signed (24 July, main provisions in force 11 August 2026).
—Art. 70 designation deadline of 2 Aug 2025 missed by most member states, exposing laggards to possible infringement action
—As of June 2026: 9 states fully designated, 12 partial, 6 with no designated authority (Austria, Belgium, Bulgaria, Croatia, Estonia, Greece)
—Only 8 of 27 single points of contact on the Commission's list as of March 2026 (EPRS, 18 March 2026)
—National laws in force: Denmark (Aug 2025), Italy (Oct 2025), Finland (Jan 2026), Germany (29 July 2026); Poland's act signed 24 July 2026 (in force 11 Aug 2026); Spain's bill still in Parliament
FLI tracker verified directly (page last updated 17 June 2026; 9-full and 6-none lists match exactly). The 8-of-27 figure verified against the EPRS blog 'Enforcement of the AI Act', epthinktank.eu, 18 March 2026 ('the list comprised eight single contact points, out of 27'). Late-July Germany/Poland updates verified against the Bundesnetzagentur press release of 29 July 2026 and Dz.U. 2026 item 1003 (Sejm ELI API). Official Commission SPOC list at digital-strategy.ec.europa.eu is the primary record.
National competent authorities and market surveillance designations — widespread delay
EU Member States (obligation under Article 70 AI Act) · 2026-06news
Member States were required to designate their notifying authorities and market surveillance authorities by 2 August 2025, and many failed to meet the deadline. The Future of Life Institute's national-implementation tracker (updated 17 June 2026) classifies 9 Member States as having clear designations, around 12 jurisdictions as only partially clear, and 6 as unclear with no designated authority identifiable — an enforcement gap that formed part of the backdrop to the Digital Omnibus deferral of the high-risk regime. Designation progress was reviewed again at the AI Board's June 2026 meeting.
—Art. 70 deadline of 2 Aug 2025 missed by a large majority of Member States
—June 2026 tracker snapshot: 9 clear (incl. Cyprus, Denmark, Finland, Ireland, Italy), ~12 partial/pending, 6 unclear (incl. Austria, Belgium, Greece); counts are a tracker assessment, not an official scoreboard
—Models vary: some states centralize in one regulator (e.g. Cyprus), others spread competence across existing sectoral bodies (e.g. Finland)
—All 27 Member States have, by contrast, designated their fundamental-rights authorities under Art. 77
FLI AI Act tracker per-country overview (secondary but maintained; last updated 17 June 2026), verified directly — it confirms the 9/12/6 split and the missed deadline. AUDIT: original source (Norton Rose Fulbright dataprotectionreport.com article) returns HTTP 403 to automated access and was replaced; its '~8 of 27 met the deadline' figure could not be re-verified and was generalized. No consolidated primary EU source lists all designations; treat counts as approximate.
Italy: Garante AI enforcement — OpenAI EUR 15M fine annulled by Rome court on jurisdictional grounds; Replika EUR 5M fine
Garante per la protezione dei dati personali / Tribunale Ordinario di Roma · 2026-03-18news
Italy's Garante has been the most aggressive national AI enforcer via the GDPR: it fined OpenAI EUR 15 million over ChatGPT (decision of 2 November 2024, announced December 2024 — legal basis, breach notification, age verification, plus a mandated public-information campaign) and fined Luka Inc. (Replika) EUR 5 million on 19 May 2025 while opening a separate probe into model-training lawfulness. By judgment No. 4153/2026, filed 18 March 2026 (full reasoning published 28 May 2026), the Rome ordinary court annulled the OpenAI fine on GDPR one-stop-shop jurisdictional grounds — the Irish DPC had become lead supervisory authority in February 2024, before the Garante finalised its decision — expressly without ruling on the substantive violations, which now fall in principle to the Irish DPC.
—OpenAI fined EUR 15M (decision 2 Nov 2024, announced Dec 2024) — first major EU generative-AI GDPR fine
—Rome court judgment No. 4153/2026 (18 March 2026) annulled the fine on GDPR one-stop-shop jurisdiction grounds; substance never examined
—Replika (Luka Inc.) fined EUR 5M on 19 May 2025 for lack of legal basis and age-verification failures; separate probe into training-data lawfulness continues
—Shows pre-AI-Act national AI enforcement runs through the GDPR — and is constrained by its jurisdictional limits
Judgment verified against the source article (court, 18 March 2026 filing, one-stop-shop reasoning citing EDPB Opinion 8/2019, no ruling on the merits) and corroborated by Italian legal press (Altalex, diritto.it, aipolicy.it: sentenza n. 4153/2026 annulling the Garante decision of 2 Nov 2024). Original fines: OpenAI decision 2 Nov 2024 announced Dec 2024; Replika 19 May 2025 (garanteprivacy.it holds the primary decisions). The court ruling itself is not published at a stable public URL.
Italy: Law No. 132/2025 on Artificial Intelligence — first comprehensive national AI law in the EU
Italian Parliament · 2025-09-23in force
Law No. 132 of 23 September 2025 ('Disposizioni e deleghe al Governo in materia di intelligenza artificiale', GU No. 223 of 25 September 2025, in force 10 October 2025) is widely described as the first comprehensive national AI law in the EU, complementing rather than transposing the AI Act. It sets sectoral rules for healthcare, employment, public administration, justice, professions and minors; designates the National Cybersecurity Agency (ACN) as market surveillance and sanctioning authority and AgID as notifying authority, coordinated at the Presidency of the Council of Ministers; and delegates implementing decrees to the Government.
—ACN = market surveillance, inspection and sanctions; AgID = notifying authority and conformity-assessment accreditation
—New criminal provisions, including an offence for harmful dissemination of AI-generated/manipulated content (deepfakes) and AI-related aggravating circumstances
—Copyright amendments (human-creativity requirement, text-and-data-mining rules) and sectoral rules for health, labour, justice and public administration
—Government delegated to adopt aligning decrees; up to EUR 1 billion earmarked for equity investment in AI, cyber and telecom firms
Primary source verified: Normattiva confirms title, GU No. 223 of 25 Sept 2025 and entry into force 10 October 2025, with chapters on sectoral provisions, authorities, copyright, criminal provisions and government delegations. Implementing legislative decrees under the delegations were still awaited as of mid-2026.
Ireland: decentralized designation of 15 market surveillance authorities (S.I. No. 366 of 2025); National AI Office expected by August 2026
Irish Government · 2025-08in force
Ireland completed its Article 70 designations via the European Union (Artificial Intelligence) (Designation of National Competent Authorities) Regulations 2025 (S.I. No. 366 of 2025), distributing market surveillance across 15 existing sectoral regulators — including the Central Bank, Coimisiún na Meán, the Data Protection Commission, the CCPC and the Health and Safety Authority — and is counted among the nine fully designated member states. A coordinating National AI Office, foreshadowed in the General Scheme of the Regulation of Artificial Intelligence Bill 2026, is expected to be operational by early August 2026 to knit the distributed system together and host a regulatory sandbox.
—Most decentralized model in the EU: 15 existing regulators designated as market surveillance authorities (S.I. No. 366 of 2025)
—Counted among the nine states with both notifying and market surveillance authorities designated
—Coordinating National AI Office expected by early August 2026, per the General Scheme of the Regulation of AI Bill 2026
—Full national implementing legislation still to follow
FLI tracker verified (15 MSAs; among the 9 fully designated; National AI Office expected by 2 Aug 2026 as new single point of contact — some Irish reports say operational by 1 Aug 2026). S.I. No. 366 of 2025 identified via secondary reports; irishstatutebook.ie blocks automated access, so the SI's exact making date is unconfirmed — date kept approximate to the August 2025 designation stage.
France: CNIL's finalised GDPR-AI recommendations and France's lagging AI Act designations
CNIL (Commission Nationale de l'Informatique et des Libertés) · 2025-07-22in force
France has produced the EU's most developed data-protection guidance for AI while lagging on formal AI Act implementation. The CNIL issued two final recommendations in February 2025 (informing data subjects; facilitating individuals' rights over training data and models) and three further recommendations on 22 July 2025 (training-data annotation, development-phase security, and when a trained AI model itself falls under the GDPR), with sectoral work on education, health and the workplace ongoing. Institutionally, the CNIL is slated as market surveillance authority for biometric, law-enforcement, migration, employment and education high-risk systems with the DGCCRF as coordinating authority under France's proposed decentralized model — but France had adopted no implementing law and remained only partially designated as of mid-2026.
—Feb 2025: final CNIL recommendations on informing data subjects and honouring GDPR rights over training datasets and AI models
—22 July 2025: recommendations on data annotation, AI development security, and when a trained model itself falls under the GDPR
—CNIL slated as future MSA for biometrics, law enforcement, migration, employment, education; DGCCRF as coordinating authority (proposal, not yet law)
—France among the late states: no national implementing law and incomplete designations as of mid-2026
Primary source verified: CNIL page confirms the three 22 July 2025 recommendations (GDPR applicability of models, annotation, secure development) and the ongoing work programme; the February 2025 pair are the earlier finalised recommendations. The recommendations are non-binding regulator guidance, not legislation — 'in_force' reflects their final published state. CNIL/DGCCRF designation plans per the FLI tracker (verified: France 'proposes decentralized model with DGCCRF as coordinating authority'), not yet a statutory designation.
Spain: AESIA — first dedicated national AI supervisory agency and market surveillance authority
Spanish Government (Council of Ministers) · 2023-08-22in force
Spain created the first dedicated AI supervisory agency in the EU: AESIA (Agencia Española de Supervisión de la Inteligencia Artificial), whose statute was approved by Royal Decree 729/2023 of 22 August 2023, seated in A Coruña and operational since 2024. AESIA is Spain's market surveillance authority under the AI Act and is slated as single point of contact in the pending Spanish AI bill; it manages Spain's AI regulatory sandbox and in early 2026 published 16 sandbox-derived compliance guides on its official portal. Spain's domestic sanctioning regime, however, still awaits the organic law pending in Parliament, even though the AI Act's governance and penalty provisions became applicable in August 2025.
—First purpose-built national AI agency in the EU; statute by Royal Decree 729/2023, seat in A Coruña, operational since 2024
—Market surveillance authority for Spain; single-point-of-contact role to be codified in the pending organic law
—Manages the Spanish AI regulatory sandbox and published 16 sandbox-derived compliance guides (early 2026)
—Domestic sanctioning regime still awaits the pending Spanish AI bill; sectoral supervisors (AEPD, CGPJ, Banco de España, CNMV, electoral board) retain AI competences
Date staged to the statute (RD 729/2023, 22 Aug 2023; BOE is the primary instrument). Source URL replaced: the original White & Case tracker link is bot-blocked (HTTP 403); the AESIA official guides page verifies the 16 guides (2 introductory + technical guides plus checklists) and their sandbox-pilot origin. Publication timing (Feb 2026) per law-firm coverage (HSF Kramer, Feb 2026); AESIA's page notes the guides will be updated once the EU digital omnibus amending the AI Act is adopted. 'Operational since mid-2024' and exact SPOC status rest on secondary trackers — hedged accordingly.
Implementation & standards14
Germany: KI-MIG (AI Market Surveillance and Innovation Promotion Act) in force — Bundesnetzagentur as central AI supervisor
German Bundestag / Federal Government · 2026-07-29in force
Germany missed the August 2025 designation deadline but has now completed implementation: the Federal Cabinet adopted the KI-MIG government draft on 11 February 2026, the Bundestag passed the amended bill on 11 June 2026 with coalition (CDU/CSU-SPD) votes, and per the Bundesnetzagentur the act entered into force on 29 July 2026. It makes the Bundesnetzagentur the central market surveillance authority, single point of contact (zentrale Anlaufstelle) and central complaints office for the AI Act, hosting the KoKIVO coordination and competence centre that supports and coordinates other market surveillance authorities, and requires it to operate at least one AI regulatory sandbox (KI-Reallabor) aimed particularly at SMEs; sectoral authorities such as BaFin (finance) and BfArM (medical devices) retain their domains per reporting on the bill.
—Cabinet draft 11 Feb 2026; Bundestag passage 11 June 2026; in force 29 July 2026 (BNetzA)
—BNetzA is central market surveillance authority, single point of contact and central complaints office, hosting the KoKIVO competence centre
—Statutory duty to run at least one BNetzA KI-Reallabor (sandbox), aimed particularly at SMEs (Art. 57 compliance)
—Sectoral authorities (BaFin, BfArM, etc.) retain their remits per reporting on the bill
Status updated from 'draft' — the researcher's entry was stale: entry into force 29 July 2026 verified via the BNetzA press release (source URL, replacing the bot-blocked DLA Piper blog) and the Federal Government's 30 July 2026 statement; Bundestag passage 11 June 2026 verified via bundestag.de (first reading 20 March, committee hearing 23 March 2026). Cabinet date is 11 February 2026 per BMDS; some trackers (FLI, DLA) say 10 February. Earlier claims about an independent chamber for justice/biometrics-sensitive AI could not be verified against accessible sources and were dropped; BaFin/BfArM carve-outs rest on secondary reporting.
Poland: Act of 3 July 2026 on Artificial Intelligence Systems — new KRiBSI regulator; signed and published, main provisions in force from 11 August 2026
Sejm / President of the Republic of Poland · 2026-07-03announced
Poland's implementing law is now enacted: the Sejm passed the bill on 11 June 2026, the final Act on Artificial Intelligence Systems (ustawa o systemach sztucznej inteligencji) is dated 3 July 2026 following the Senate stage, President Nawrocki signed it on 24 July 2026, and it was published in the Dziennik Ustaw (2026, item 1003) in late July. Its main provisions enter into force on 11 August 2026, with staged application — Art. 125(4) from 28 July 2026, and Arts 8-18 plus chapters 3-5 and 8-9 from 28 October 2026. It creates the Commission for the Development and Safety of Artificial Intelligence (KRiBSI) as the new market surveillance authority, a collegial body drawing on existing sectoral regulators with operational support in the Ministry of Digital Affairs, and expands duties for the data-protection authority (UODO).
—Sejm passed the bill 11 June 2026; final act dated 3 July 2026; signed by President Nawrocki 24 July 2026; published as Dz.U. 2026 item 1003
—Main provisions in force 11 August 2026; Arts 8-18 and chapters 3-5, 8-9 apply from 28 October 2026
—Creates KRiBSI, a newly built collegial regulator, as market surveillance authority — like Lithuania, a single-MSA model
—Secretariat support within the Ministry of Digital Affairs; expanded role for the UODO president
Status updated from 'draft/pending Senate' — the researcher's entry was stale. Verified via the official Sejm ELI record for Dz.U. 2026 poz. 1003 (title, act date 3 July 2026, entry into force 11 Aug 2026, staged provisions) and Polish reporting of the 24 July 2026 presidential signature; Sejm passage 11 June 2026 per the FLI tracker. Human-readable records: dziennikustaw.gov.pl/DU/2026/1003 and ISAP (both block automated access). The reported 31 March 2026 Council of Ministers adoption and the KRiBSI composition drawn from UOKiK/KNF/KRRiT/UKE rest on secondary sources (Taylor Wessing, bot-blocked; Digital Policy Alert) and were not independently verified.
European Artificial Intelligence Board — operating rhythm and June 2026 priorities
AI Board (Member State representatives; AI Office as secretariat) · 2026-06-11in force
The AI Board (Art. 65 AI Act), composed of Member State representatives with the AI Office as secretariat, coordinates national implementation and advises the Commission. Its eighth meeting on 11 June 2026, chaired by the Cypriot Presidency of the EU Council, saw the presentation of the final Code of Practice on transparency of AI-generated content, a review of progress on national market surveillance authority designations, and the introduction of the newly appointed Scientific Panel and Advisory Forum. Moldova was granted observer status.
—Adequacy of the GPAI Code of Practice was confirmed by 'the Commission and the Member States' on 1 Aug 2025 — the Board is the Member State coordination body
—Eighth meeting (11 June 2026): final transparency code presented, market-surveillance progress reviewed, Tech Sovereignty Package discussed
—Scientific Panel and AI Act Advisory Forum formally presented to the Board
—Moldova granted observer status; entry date is the eighth meeting
Official Commission news item (published 12 June 2026), re-verified live: date, Cypriot chairmanship, Moldova observer status, transparency code presentation, Scientific Panel/Advisory Forum introduction and market-surveillance agenda all confirmed.
Scientific Panel of Independent Experts and AI Act Advisory Forum appointed
European Commission · 2026-06-01in force
On 1 June 2026 the Commission announced the two remaining advisory bodies of the AI Act's governance architecture. The Scientific Panel (Art. 68) comprises 60 independent AI experts appointed in personal capacity for 24-month renewable terms, selected with geographic balance (at most three nationals per country) and gender balance; it alerts the AI Office to systemic risks and advises on GPAI classification, evaluation methodologies and market surveillance. The Advisory Forum (Art. 67) provides stakeholder input from industry, SMEs and startups, academia and civil society.
—60 experts with frontier-AI, engineering, technical-auditing and societal-impact expertise; 24-month renewable terms in personal capacity
—Selection applied geographic balance (at most 3 nationals per country) and gender balance; most members come from academia, public-sector-linked organisations, research or civil society
—Panel's core responsibilities include alerting the AI Office to systemic risks (the AI Act's qualified-alert mechanism) and supporting cross-border market surveillance
—Advisory Forum includes the EU Fundamental Rights Agency, ENISA and standardisation bodies as permanent participants; both bodies presented to the AI Board on 11 June 2026
Official Commission announcement of 1 June 2026, re-verified live, with panel details cross-checked on digital-strategy.ec.europa.eu/en/policies/ai-scientific-panel. AUDIT: the original entry's composition claims ('at least one per EU/EFTA-EEA country', '80% from EU/EFTA-EEA') are not supported by the official pages, which instead state 'at most 3 nationals from each country' — corrected.
Spain: Draft Organic Law on the Good Use and Governance of Artificial Intelligence (in Parliament)
Spanish Government (Council of Ministers) / Cortes Generales · 2026-05-26draft
Spain's national AI bill — first approved as an anteproyecto on 11 March 2025 — was approved by the Council of Ministers as a draft Organic Law on 26 May 2026 and sent to Parliament, where it was published in the Boletín Oficial de las Cortes Generales on 12 June 2026 (Series A, No. 97-1) and assigned to the Congress committee on Economy, Commerce and Digital Transformation; it remained pending as of July 2026. It supplements the AI Act with a domestic sanctioning regime aligned to the EU ceilings (up to EUR 35M or 7% of worldwide turnover for the most serious infringements, down to EUR 500,000 or 0.5% for minor ones) and codifies the supervisory architecture led by AESIA alongside sectoral authorities; per reporting on the March 2025 anteproyecto, failure to label AI-generated content (deepfakes) is classed as a serious infringement.
—Anteproyecto approved 11 March 2025; organic bill approved and sent to Parliament 26 May 2026; published in the BOCG 12 June 2026, still pending mid-2026
—Fines aligned to AI Act ceilings — up to EUR 35M or 7% of global turnover for the most serious infringements
—Headline national add-on (per anteproyecto reporting): unlabelled AI-generated content/deepfakes classed as a serious infringement
—Organic-law rank due to fundamental-rights impact; AESIA lead with sectoral supervisors (AEPD, CGPJ, Banco de España, CNMV, electoral board)
Staged date is the 26 May 2026 Council of Ministers approval, verified against the DLA Piper source (which also confirms the EUR 35M/7% ceiling and AESIA/AEPD/CGPJ architecture); BOCG publication of 12 June 2026 (Series A No. 97-1) and committee assignment verified via Spanish parliamentary reporting. The deepfake-labelling infringement traces to the 11 March 2025 anteproyecto (espanadigital.gob.es / La Moncloa) and was not re-verified in the 2026 bill text — hedged accordingly.
Finland: Act on the Supervision of Certain Artificial Intelligence Systems (1377/2025) in force — decentralized supervision with Traficom as single point of contact
Finnish Parliament (Eduskunta) · 2026-01-01in force
Finland's national implementing act — Laki eräiden tekoälyjärjestelmien valvonnasta (1377/2025) — took effect on 1 January 2026, making Finland one of the few states with a complete supervision framework in force. Finland chose a decentralized model that assigns market surveillance of high-risk AI to existing sectoral regulators, with the Transport and Communications Agency (Traficom) acting as single point of contact. Finland is among the nine states with both notifying and market surveillance authorities fully designated.
—Implementing act 1377/2025 effective 1 January 2026
Act number and title verified on Finlex (primary source, upgraded from the FLI tracker link); the 1 January 2026 entry into force, Traficom SPOC role and decentralized model verified against the FLI implementation tracker (updated 17 June 2026).
Harmonised AI standards slip to late 2026: CEN-CENELEC adopts exceptional fast-track measures
CEN-CENELEC JTC 21 · 2025-11news
CEN-CENELEC missed the Commission's standardisation-request deadline of August 2025 for the harmonised standards underpinning the AI Act's high-risk regime, with fast-tracked standards now due to be published by Q4 2026. In October–November 2025 CEN-CENELEC adopted measures it described as 'exceptional', 'targeted and temporary' — reducing the number of publication stages and establishing a smaller drafting group for the most delayed texts, while retaining the public Enquiry as a final step — over warnings from technical-committee members that the shortcuts could undermine consensus. The standards gap was the Commission's principal stated justification for the Digital Omnibus deferral of high-risk obligations to December 2027 and August 2028.
—Original standardisation deadline of Aug 2025 missed; fast-tracked harmonised standards due by Q4 2026
—Fast-track measures: fewer publication stages, smaller drafting group for the most delayed drafts, public Enquiry retained as final step
—Technical-committee members warned the acceleration could undermine consensus and seriously harm standardisation
—Standards delay was the core stated rationale for postponing high-risk obligations via Regulation (EU) 2026/1744
Secondary source (CMS law-firm analysis, 13 Nov 2025); audited 31 July 2026 — article date, Q4 2026 expectation, the 'exceptional'/'targeted and temporary' characterisation, and the reduced-stages/smaller-drafting-group measures all verified against the article. Committee-member concerns are paraphrased (the article warns the process could undermine consensus and seriously harm standardisation); an earlier direct quote not found in the article was removed. CEN-CENELEC does not publish a consolidated public timeline page; corroborated by the Commission's Digital Omnibus justification citing standards delays.
CEN-CENELEC harmonized standards for the AI Act: delays and accelerated delivery (target Q4 2026)
CEN-CENELEC (JTC 21), under Commission standardization request C(2023) 3215 as amended · 2025-10-23draft
The harmonized standards meant to give high-risk AI providers a presumption of conformity under Article 40 are substantially delayed: the original April 2025 delivery date under the 2023 standardization request was missed, and as of mid-2026 no AI Act harmonized standards had been cited in the Official Journal. On 23 October 2025 the CEN and CENELEC Technical Boards adopted an exceptional package of acceleration measures targeting availability of key deliverables by Q4 2026. The standards gap was among the reasons the Digital Omnibus deferred the high-risk regime.
—Acceleration measures (23 Oct 2025): direct publication after a positive Enquiry vote (skipping the Formal Vote) and a small drafting group of already-active experts to finalize six badly delayed drafts
—Launch of the Enquiry for prEN 18286 (AI quality management systems) announced as the immediate next step, as a key deliverable for conformity assessment
—No Art. 40 presumption of conformity exists yet because no AI Act harmonised standard has been cited in the OJ; the Digital Omnibus deferral of high-risk obligations reflects this readiness gap
—CEN-CENELEC stress the fast-track is 'an exceptional and temporary measure' with the Enquiry stage still open to all national members and stakeholders
Official CEN-CENELEC announcement, re-verified live (all acceleration details confirmed; entry date is the decision date). AUDIT: the original entry's per-standard stage claims (EN 18286 'at approval', prEN 18228/18229-1/18282 'at Enquiry') and the 'critics inside JTC 21' claim came from a secondary tracker and could not be verified — removed. 'M/613' amendment number also unverified — removed.
Template for the public summary of GPAI training content (Article 53(1)(d))
European Commission (AI Office) · 2025-07-24in force
On 24 July 2025 the Commission published the template and explanatory notice that GPAI model providers use to publish a sufficiently detailed public summary of the content used for model training, providing 'a common minimal baseline' for the information to be made public. Article 53(1)(d) AI Act requires the summary to follow the AI Office template, making its use compulsory in practice — unlike the voluntary Code of Practice — and it is enforceable by the AI Office from 2 August 2026.
—Implements Art. 53(1)(d) AI Act, which requires the public summary to be drawn up 'according to a template provided by the AI Office' — so it applies to all GPAI providers, including Code of Practice non-signatories
—Requires disclosure of main datasets and data-source categories at a prescribed level of aggregation
—Applies to models placed on the market from 2 Aug 2025; providers of models placed on the market earlier must comply by 2 Aug 2027
Official Commission library page, re-verified live (publication 24 July 2025, 'common minimal baseline' purpose confirmed). Mandatory character follows from the statutory text of Art. 53(1)(d) rather than the landing page. AUDIT: the detailed 'top domain names scraped' disclosure claim sits in the template document itself and was retained only in generalized form.
Commission Guidelines on the scope of obligations for GPAI model providers
European Commission (AI Office) · 2025-07-18in force
Published 18 July 2025, days before GPAI obligations became applicable on 2 August 2025. The guidelines define when a model is 'general-purpose' (indicative training-compute criterion above 10^23 FLOP combined with generality of capabilities), who counts as a provider (including when downstream modifications create provider obligations), and the conditions of the open-source exemption.
—Indicative 10^23 FLOP training-compute criterion for identifying GPAI models; the systemic-risk presumption threshold remains 10^25 FLOP under Art. 51
—Clarifies that only significant modifications of a model trigger provider obligations for the modifier
—Sets out conditions for the open-source exemption from certain Art. 53 obligations
—Available in all 24 EU official languages with an approving Commission communication (confirmed on the page)
Official Commission library page, re-verified live (publication 18 July 2025, 24 languages, approving communication confirmed). The FLOP thresholds are in the guideline documents themselves, not on the landing page.
Denmark: Act No. 467 of 14 May 2025 on Supplementary Provisions to the AI Regulation (first national implementing law)
Folketing (Danish Parliament) · 2025-05-14in force
Denmark was the first member state to adopt AI Act implementing legislation: the Folketing passed the bill on 8 May 2025, it was signed as Act No. 467 of 14 May 2025, and it entered into force on 2 August 2025 in step with the AI Act's governance chapter. It designates the Agency for Digital Government (Digitaliseringsstyrelsen) as notifying authority, coordinating market surveillance authority and single point of contact, with the Data Protection Authority (Datatilsynet) and the Court Administration (Domstolsstyrelsen) as market surveillance authorities in their domains, and lays down inspection powers and penalties.
—First EU member state to legislate for the AI Act; in force 2 August 2025
—Digitaliseringsstyrelsen is notifying authority, coordinating market surveillance authority and single point of contact
—Datatilsynet and the Danish Court Administration complete the market surveillance framework
—Establishes inspection powers and penalties for AI Act violations
Verified: article confirms 8 May 2025 adoption, 2 Aug 2025 entry into force and all three authorities; act number 'Lov nr. 467 af 14-05-2025' confirmed via ft.dk (bill L 154, 2024-25 session) and the FLI tracker. Official text is Lov nr. 467 af 14/05/2025 on retsinformation.dk (ELI: retsinformation.dk/eli/lta/2025/467; official site blocks automated access, so the resolving secondary source is retained as the link).
Commission Guidelines on the definition of an AI system (Article 3(1))
European Commission · 2025-02-06in force
Non-binding guidelines, published 6 February 2025, clarifying which software qualifies as an 'AI system' under Article 3(1) — the gateway concept for the whole Act. They are designed to assist providers in determining whether a software system constitutes an AI system, indicating that simple traditional software falls outside scope. The Commission states they will evolve and be updated in light of practical experience and new use cases.
—Published alongside the prohibited-practices guidelines to support the first tranche of obligations applicable from 2 Feb 2025
—Key test is capacity to infer from inputs, distinguishing AI systems from classical rule-based software
Official Commission library page, re-verified live (6 Feb 2025 date, non-binding and living-document language confirmed; page references the approving draft Communication — document number C(2025) 924 is consistent with contemporaneous records though not displayed on the page).
Commission Guidelines on prohibited AI practices (Article 5)
European Commission · 2025-02-04in force
Non-binding guidelines interpreting the Article 5 prohibitions (harmful manipulation, social scoring, real-time remote biometric identification, emotion inference at work/education, untargeted facial-image scraping, etc.), which have applied since 2 February 2025. The Commission approved the content of the draft Communication on 4 February 2025 (C(2025) 884). They provide legal explanations and practical examples, but authoritative interpretation remains with the CJEU.
—Interpret prohibitions carrying the Act's highest fines: up to EUR 35m or 7% of global turnover
—Published 4 Feb 2025 alongside the AI-system-definition guidelines to support the first tranche of obligations applicable from 2 Feb 2025
—Non-binding on courts; intended to guide providers, deployers and national enforcers
—The 2026 AI omnibus added a new prohibition (AI enabling CSAM and non-consensual intimate imagery) not covered by these guidelines, applying from December 2026
Official Commission library page, re-verified live (4 Feb 2025 publication, non-binding character, CJEU caveat confirmed). New CSAM/nudification prohibition and its December 2026 application date confirmed on the Commission's AI Act policy page. AUDIT: the original entry's claim of a formally adopted version 'C(2025) 5052 final of 29.7.2025' could not be verified on any accessible official source and was removed; only C(2025) 884 (approval of draft content) is corroborated.
European AI Office (establishment, structure and supervisory role)
European Commission · 2024-01-24in force
The AI Office, established within the Commission by Commission Decision C(2024) 390 of 24 January 2024, is the EU-level implementation hub for the AI Act, with exclusive competence to supervise and enforce obligations on general-purpose AI (GPAI) models. It has more than 125 staff across six units plus a Lead Scientific Adviser and an International Affairs Adviser, drafts codes of practice, conducts model evaluations, and serves as secretariat to the AI Board. The 2026 'AI omnibus' (Regulation (EU) 2026/1744) made targeted amendments to the AI Act; legal analyses report these broaden the AI Office's supervisory scope beyond GPAI models.
—Exclusive EU-level supervisor and enforcer for GPAI models under Chapter V (Art. 88 AI Act); national authorities handle other AI systems
—Six units (incl. Regulation and Compliance, AI Safety) plus Lead Scientific Adviser and International Affairs Adviser; over 125 staff per the Commission page
—Runs the AI Pact, the AI Act Service Desk / Single Information Platform, and code-of-practice processes; can restrict availability of a model and fine for non-compliance
—Commission page confirms the 'AI omnibus' was adopted in 2026 introducing targeted AI Act amendments; the reported extension of supervision to same-undertaking GPAI-based systems and VLOP/VLOSE-embedded systems rests on law-firm analyses of the final text
Official Commission policy page, re-verified live (confirms 125+ staff, 6 units + 2 advisers, AI Pact, Service Desk, codes of practice, and adoption of the AI omnibus). Establishing act C(2024) 390 of 24.1.2024; date given is the decision date. AUDIT: the original entry's claims about an 'EU SEND' submission platform and the precise omnibus scope expansion could not be verified on any official page and were removed or hedged.