Obligations this check draws on
Prohibited AI practices and the AI literacy duty
EU AI Act, Art. 5 and Art. 4 · In force since 02 Feb 2025 · checked 23 Jul 2026
Applies to any organisation placing AI on the EU market or using AI output in the EU. Requires an inventory screened against prohibited categories and evidence that staff who operate or oversee AI are trained to their role. Regulation (EU) 2024/1689
General purpose AI model obligations
EU AI Act, Chapter V · In force since 02 Aug 2025 · checked 23 Jul 2026
Binds providers of general purpose AI models on the EU market; deployers inherit the evidence burden through contracts. Fine-tuning a model can make you a provider. Regulation (EU) 2024/1689
Transparency duties for chatbots, synthetic media and emotion recognition
EU AI Act, Art. 50 · Applies from 02 Aug 2026 · checked 23 Jul 2026
Disclosure that a person is dealing with AI, marking of AI-generated content, deepfake labelling, and notice for emotion recognition or biometric categorisation. Regulation (EU) 2024/1689
Marking of legacy systems and new prohibitions
EU AI Act, Art. 50(2) and Art. 5 (Digital Omnibus) · 02 Dec 2026, adopted pending Official Journal publication · checked 23 Jul 2026
Marking reaches systems on the market before 02 Aug 2026, and new prohibitions bar generation of non-consensual intimate imagery and child sexual abuse material. Council of the EU, 29 June 2026
High-risk obligations for standalone systems
EU AI Act, Annex III (Digital Omnibus) · 02 Dec 2027, moved from 02 Aug 2026, adopted pending publication · checked 23 Jul 2026
Risk management, data governance, documentation, logging, human oversight, accuracy and resilience evidence, and conformity assessment for standalone high-risk systems. Council of the EU, 29 June 2026
High-risk obligations for AI embedded in regulated products
EU AI Act, Annex I with EU MDR (Digital Omnibus) · 02 Aug 2028, moved from 02 Aug 2027, adopted pending publication · checked 23 Jul 2026
One conformity assessment against two frameworks for regulated products with embedded AI, including medical devices. Council of the EU, 29 June 2026
Connected-product data access by design
EU Data Act, Art. 3 · Applies from 12 Sep 2026 · checked 23 Jul 2026
Connected products designed so their data is accessible to the user by default, with pre-contract information. General application began 12 Sep 2025. Regulation (EU) 2023/2854
Automated decisions with legal or similar effect
GDPR, Art. 22 · In force · checked 23 Jul 2026
A lawful basis, meaningful information about the logic, and a route to human review for solely automated decisions with significant effects. Regulation (EU) 2016/679
Cyber risk management and incident reporting
NIS2 Directive (EU) 2022/2555 · In force, transposition varies by Member State · checked 23 Jul 2026
Board-accountable cyber risk management, supply-chain security, and incident reporting for essential and important entities. Directive (EU) 2022/2555
Automated decision-making rules recast
UK, Data (Use and Access) Act 2025 · In force since 05 Feb 2026 · checked 23 Jul 2026
Safeguards for qualifying automated decisions under new Articles 22A to 22D of the UK GDPR. UK and EU rules now differ. Data (Use and Access) Act 2025
Change control for AI-enabled devices
FDA, AI-enabled device software · Guidance, no statutory date · checked 23 Jul 2026
A predetermined change control plan for AI-enabled device software submitted to the FDA. Recommendations finalised December 2024; lifecycle guidance in draft. FDA, Federal Register, 04 December 2024
Trinidad and Tobago Data Protection Act 2011
Partial commencement, remainder outstanding · checked 23 Jul 2026
The General Privacy Principles proclaimed in 2012 apply now. Enforcement and penalty provisions are not in force and no date is announced. Parliament of Trinidad and Tobago
CBTT cybersecurity expectations for financial institutions
CBTT Cybersecurity Best Practices Guideline · Issued 2023, updated 2025 · checked 23 Jul 2026
Governance, risk management, testing, and incident management with an annual self-assessment return due by 31 March. Central Bank of Trinidad and Tobago
TATT cybersecurity of public telecommunications networks
TATT telecom cybersecurity framework · Published 30 Jan 2026, conformance date not set · checked 23 Jul 2026
Cybersecurity measures matched to the published framework for telecom concessionaires, with conformance reporting on a timeframe the Authority will set. Telecommunications Authority of Trinidad and Tobago
AI management system certification
ISO/IEC 42001:2023 · Voluntary · checked 23 Jul 2026
A management system covering AI policy, risk and impact assessment, and lifecycle controls, on a three-year certification cycle. The fastest route to evidencing AI governance to a buyer or an acquirer. ISO/IEC 42001:2023