Full register
Prohibited AI practices and the AI literacy duty
EU AI Act, Art. 5 and Art. 4 · In force since 02 February 2025 · EU · checked 23 Jul 2026
Who it binds. Any organisation placing AI on the EU market or using AI output in the EU, wherever it is established.
What you need in place. A documented inventory of AI in use, screened against the prohibited categories, and evidence that staff who operate or oversee AI have been trained to a level matched to their role.
Source: Regulation (EU) 2024/1689
General purpose AI model obligations
EU AI Act, Chapter V · In force since 02 August 2025 · EU · checked 23 Jul 2026
Who it binds. Providers of general purpose AI models placed on the EU market. Deployers inherit the evidence burden through their supply contracts.
What you need in place. Technical documentation, a training-data summary, and a copyright policy from your model provider. Fine-tuning a model can make you a provider yourself.
Source: Regulation (EU) 2024/1689
Transparency duties for chatbots, synthetic media and emotion recognition
EU AI Act, Art. 50 · Applies from 02 August 2026 · EU · checked 23 Jul 2026
Who it binds. Anyone operating EU-facing chatbots or generative systems, publishing synthetic media, or running emotion recognition or biometric categorisation.
What you need in place. Disclosure that a person is dealing with AI, machine-readable marking of AI-generated content, deepfake labelling, and notice to people subject to emotion recognition or biometric categorisation.
Note. This date held while the high-risk dates moved. Article 50 is several separate rules binding different actors with different exceptions, so treating it as one disclosure switch produces both over-compliance and under-compliance.
Source: Regulation (EU) 2024/1689
Connected-product data access by design
EU Data Act, Art. 3 · Applies from 12 September 2026 · EU · checked 23 Jul 2026
Who it binds. Manufacturers and sellers of connected products and related services placed on the EU market from this date.
What you need in place. Products designed so that the data they generate is accessible to the user by default, with pre-contract information on what data is produced and how to reach it.
Note. The Data Act has applied generally since 12 September 2025. This date adds the design duty for newly placed products. Cloud switching and interoperability terms phase in further to 12 September 2027.
Source: Regulation (EU) 2023/2854
Marking duties reach legacy systems; new prohibitions apply
EU AI Act, Art. 50(2) and Art. 5 (Digital Omnibus) · 02 December 2026 · EU · checked 23 Jul 2026
Adopted, pending Official Journal publication
Who it binds. Providers of generative systems already on the market before 02 August 2026, plus all operators in scope of the new prohibitions.
What you need in place. Technical marking retrofitted to systems already in service, and controls that prevent generation of non-consensual intimate imagery and child sexual abuse material.
Note. The new prohibitions sit in the adopted Digital Omnibus text and carry the highest penalty tier. They take legal effect once the Omnibus is published in the Official Journal and enters into force. If your models can synthesise images or audio, the safeguard needs to be technical and contractual rather than a policy line.
Source: Council of the EU, final adoption 29 June 2026
National AI regulatory sandboxes operational
EU AI Act, Art. 57 (Digital Omnibus) · 02 August 2027 · EU · checked 23 Jul 2026
Adopted, pending Official Journal publication
Who it binds. Each Member State must have at least one AI regulatory sandbox running. Relevant to providers preparing high-risk conformity work.
What you need in place. Nothing directly. This is the date the supporting machinery your conformity route depends on is meant to exist.
Note. The Digital Omnibus moved this deadline out by a year. Late supporting machinery drove the earlier delay, so if it slips again the 2027 and 2028 high-risk dates are the ones to watch.
Source: Council of the EU, 29 June 2026
High-risk obligations for standalone systems
EU AI Act, Chapter III, Annex III (Digital Omnibus) · 02 December 2027, moved from 02 August 2026 · EU · checked 23 Jul 2026
Adopted, pending Official Journal publication
Who it binds. Providers and deployers of standalone high-risk systems, including employment and worker management, creditworthiness assessment, education, and access to essential services.
What you need in place. Risk-management system, data governance, technical documentation, logging, human-oversight design, accuracy and resilience evidence, and conformity assessment.
Note. The Digital Omnibus set a fixed date here, replacing the conditional trigger first proposed. The deferral of sixteen months was driven by late harmonised standards and unfinished national authority designations rather than any change to the requirements. Until the Omnibus is published in the Official Journal, the original 02 August 2026 date remains the law on the books, so plan against the new date while treating it as adopted.
Source: Council of the EU, 29 June 2026
High-risk obligations for AI embedded in regulated products
EU AI Act, Annex I with EU MDR (Digital Omnibus) · 02 August 2028, moved from 02 August 2027 · EU · checked 23 Jul 2026
Adopted, pending Official Journal publication
Who it binds. Manufacturers of regulated products with embedded AI, including medical devices under the EU MDR and IVDR.
What you need in place. An AI Act conformity assessment run through the existing product conformity route, matched to your notified body and your technical file.
Note. For medical device manufacturers this is one assessment against two frameworks. Building the AI Act evidence apart from the MDR technical file creates duplicate work and contradiction risk at audit.
Source: Council of the EU, 29 June 2026
Automated decisions with legal or similar effect
GDPR, Art. 22 · In force · EU · checked 23 Jul 2026
Who it binds. Anyone making solely automated decisions that produce legal or similarly significant effects on people.
What you need in place. A lawful basis, meaningful information about the logic involved, and a route to human review.
Note. Already in force and already enforced. Most AI scoring and screening deployments engage this before the AI Act reaches them.
Source: Regulation (EU) 2016/679
Cyber risk management and incident reporting
NIS2 Directive (EU) 2022/2555 · In force, national transposition varies · EU · checked 23 Jul 2026
Who it binds. Essential and important entities in scope sectors, with thresholds set by each Member State.
What you need in place. Board-accountable cyber risk management, supply-chain security, and incident reporting inside the national deadlines.
Note. The transposition deadline was 17 October 2024 and Member States have moved at different speeds, so a group operating across several of them faces several national regimes at once rather than one date.
Source: Directive (EU) 2022/2555
AI management system certification
ISO/IEC 42001:2023 · Voluntary standard · Global · checked 23 Jul 2026
Who it binds. Voluntary. Increasingly requested in enterprise procurement and diligence.
What you need in place. A management system covering AI policy, risk assessment, impact assessment, and lifecycle controls, audited on a three-year certification cycle with annual surveillance.
Note. The fastest route to evidencing AI governance to a buyer or an acquirer, because it produces an artefact a third party has tested.
Source: ISO/IEC 42001:2023
Change control and lifecycle expectations for AI-enabled devices
FDA, AI-enabled device software · Guidance, no statutory date · US · checked 23 Jul 2026
Who it binds. Manufacturers of AI-enabled device software functions submitting to the FDA.
What you need in place. A predetermined change control plan describing the modifications you intend to make, the methods used to implement them, and the impact assessment.
Note. The predetermined change control plan recommendations were finalised in December 2024. The broader lifecycle-management guidance remains in draft. These are recommendations with no statutory deadline, so there is nothing to count down to.
Source: FDA, Federal Register, 04 December 2024
Trinidad and Tobago Data Protection Act 2011: partial commencement
Data Protection Act 2011 (Act No. 13 of 2011) · In force in part since 2012, remainder outstanding · Trinidad and Tobago · checked 23 Jul 2026
Who it binds. Organisations processing personal data in Trinidad and Tobago.
What you need in place. The General Privacy Principles and the provisions proclaimed in 2012 apply now. Handle personal data consistently with them and prepare for the remaining provisions once proclaimed.
Note. Only part of the Act was proclaimed in 2012. The enforcement and penalty provisions are still not in force and no date has been announced for them. Treat the principles as binding today and watch for proclamation of the rest.
Source: Parliament of Trinidad and Tobago, Data Protection Act 2011
Cybersecurity expectations for financial institutions
CBTT Cybersecurity Best Practices Guideline · Issued Sept 2023, updated Jul 2025 · Trinidad and Tobago · checked 23 Jul 2026
Who it binds. Institutions regulated by the Central Bank of Trinidad and Tobago.
What you need in place. Governance, risk management, awareness and training, continuity, testing, and incident management across the twenty stated requirements, with an annual self-assessment return due by 31 March.
Note. A supervisory guideline with an annual return rather than a statute, so treat the 31 March return as the recurring obligation.
Source: Central Bank of Trinidad and Tobago
Cybersecurity of public telecommunications networks
TATT telecom cybersecurity framework · Framework published 30 Jan 2026, conformance date not yet set · Trinidad and Tobago · checked 23 Jul 2026
Who it binds. Concessionaires operating public telecommunications networks in Trinidad and Tobago.
What you need in place. Cybersecurity measures matched to the published framework, with conformance reporting on a timeframe the Authority will set.
Note. The framework was published on 30 January 2026 after two consultation rounds. A fixed conformance deadline had not been announced at publication, so the reporting date is not yet confirmed.
Source: Telecommunications Authority of Trinidad and Tobago
Automated decision-making rules recast
UK, Data (Use and Access) Act 2025 · In force since 05 February 2026 · United Kingdom · checked 23 Jul 2026
Who it binds. Organisations making significant automated decisions about people in the UK.
What you need in place. Safeguards for qualifying automated decisions under new Articles 22A to 22D of the UK GDPR, including information, human intervention, and a route to contest.
Note. It replaces the former near-prohibition with a permission-plus-safeguards model, so UK and EU automated-decision rules now differ and need separate handling.
Source: Data (Use and Access) Act 2025