Obligations this check draws on
Prohibited AI practices and the AI literacy duty
EU AI Act, Art. 5 and Art. 4 · In force since 02 Feb 2025 · checked 01 Sep 2026
Applies to any organisation placing AI on the EU market or using AI output in the EU. Requires an inventory screened against prohibited categories and evidence that staff who operate or oversee AI are trained to their role. Regulation (EU) 2024/1689
General purpose AI model obligations
EU AI Act, Chapter V · In force since 02 Aug 2025 · checked 01 Sep 2026
Binds providers of general purpose AI models on the EU market; deployers inherit the evidence burden through contracts. Fine-tuning a model can make you a provider. Regulation (EU) 2024/1689
Transparency duties for chatbots, synthetic media and emotion recognition
EU AI Act, Art. 50 · In force since 02 Aug 2026 · checked 01 Sep 2026
Disclosure that a person is dealing with AI, marking of AI-generated content, deepfake labelling, and notice for emotion recognition or biometric categorisation. Regulation (EU) 2024/1689
Marking of legacy systems and new prohibitions
EU AI Act, Art. 50(2) and Art. 5 (Digital Omnibus) · 02 Dec 2026, in force since 27 July 2026 · checked 01 Sep 2026
Marking reaches systems on the market before 02 Aug 2026, and new prohibitions bar generation of non-consensual intimate imagery and child sexual abuse material. Regulation (EU) 2026/1744, OJ 24 July 2026
High-risk obligations for standalone systems
EU AI Act, Annex III (Digital Omnibus) · 02 Dec 2027, moved from 02 Aug 2026, in force since 27 July 2026 · checked 01 Sep 2026
Risk management, data governance, documentation, logging, human oversight, accuracy and resilience evidence, and conformity assessment for standalone high-risk systems. Regulation (EU) 2026/1744, OJ 24 July 2026
High-risk obligations for AI embedded in regulated products
EU AI Act, Annex I with EU MDR (Digital Omnibus) · 02 Aug 2028, moved from 02 Aug 2027, in force since 27 July 2026 · checked 01 Sep 2026
One conformity assessment against two frameworks for regulated products with embedded AI, including medical devices. Regulation (EU) 2026/1744, OJ 24 July 2026
Connected-product data access by design
EU Data Act, Art. 3 · Applies from 12 Sep 2026 · checked 01 Sep 2026
Connected products designed so their data is accessible to the user by default, with pre-contract information. General application began 12 Sep 2025. Switching charges, including data egress charges, go entirely on 12 Jan 2027. Regulation (EU) 2023/2854
Automated decisions with legal or similar effect
GDPR, Art. 22 · In force · checked 01 Sep 2026
A lawful basis, meaningful information about the logic, and a route to human review for solely automated decisions with significant effects. Regulation (EU) 2016/679
Cyber risk management and incident reporting
NIS2 Directive (EU) 2022/2555 · In force, transposition varies by Member State · checked 01 Sep 2026
Board-accountable cyber risk management, supply-chain security, and incident reporting for essential and important entities. Directive (EU) 2022/2555
Automated decision-making rules recast
UK, Data (Use and Access) Act 2025 · In force since 05 Feb 2026 · checked 01 Sep 2026
Safeguards for qualifying automated decisions under new Articles 22A to 22D of the UK GDPR. UK and EU rules now differ. Data (Use and Access) Act 2025
Change control for AI-enabled devices
FDA, AI-enabled device software · Guidance, no statutory date · checked 01 Sep 2026
A predetermined change control plan for AI-enabled device software submitted to the FDA. Recommendations finalised 04 Dec 2024 and reissued 18 Aug 2025; lifecycle guidance still in draft. FDA, Federal Register, 04 December 2024
Trinidad and Tobago Data Protection Act 2011
Partial commencement, remainder outstanding · checked 01 Sep 2026
The General Privacy Principles proclaimed in 2012 apply now. Enforcement and penalty provisions are not in force and no date is announced. Parliament of Trinidad and Tobago
CBTT cybersecurity expectations for financial institutions
CBTT Cybersecurity Best Practices Guideline · Issued Sept 2023, self-assessment circular July 2025 · checked 01 Sep 2026
Governance, risk management, testing, and incident management with an annual self-assessment return due by 31 March. Central Bank of Trinidad and Tobago
TATT cybersecurity of public telecommunications networks
TATT Cybersecurity Framework for Public Telecom Networks and Broadcasting Facilities · Final v1.0 published 30 Jan 2026, conformance date not set · checked 01 Sep 2026
Cybersecurity measures matched to the published framework for telecom concessionaires, with conformance reporting on a timeframe the Authority will set. TATT Cybersecurity Framework, Final v1.0, 30 Jan 2026
Cybersecurity as a licence condition
TATT Standard Concession, Version 3.0 · Issued 12 June 2026 · checked 01 Sep 2026
Conditions A46 to A48 require telecom and broadcasting concessionaires in Trinidad and Tobago to submit an annual cybersecurity framework or plan, or independent attestation, and to notify the Authority within 24 hours of a material incident. TATT Standard Concession, Version 3.0, 12 June 2026
AI management system certification
ISO/IEC 42001:2023 · Voluntary · checked 01 Sep 2026
A management system covering AI policy, risk and impact assessment, and lifecycle controls, on a three-year certification cycle. The fastest route to evidencing AI governance to a buyer or an acquirer. Adopted as EN ISO/IEC 42001:2026 in March 2026, but not cited in the Official Journal, so it carries no presumption of conformity under the AI Act. ISO/IEC 42001:2023