Which rules apply to you

See which AI and data rules apply to your business.

Answer six quick questions and get a plain list of the AI, data protection and cybersecurity rules that apply to your organisation, each with the date it takes effect, what to have in place, and its source. The answer is immediate and anonymous. There is nothing to sign up for and no email to give.

Instant · Anonymous · No sign-up

1. Where do you operate or place products and services?
2. Your role with AI
3. Sector
4. Do you use generative AI or chatbots that deal with people or produce content?
5. Do any AI uses fall in high-risk areas: hiring, credit, education, essential services, or biometrics?
6. Do you make automated decisions about individuals with legal or significant effects?
Answer the questions and select Show the rules that apply to me. Results are immediate, anonymous, and indicative rather than a substitute for a jurisdiction-specific reading.

Obligations this check draws on

Prohibited AI practices and the AI literacy duty

EU AI Act, Art. 5 and Art. 4 · In force since 02 Feb 2025 · checked 23 Jul 2026

Applies to any organisation placing AI on the EU market or using AI output in the EU. Requires an inventory screened against prohibited categories and evidence that staff who operate or oversee AI are trained to their role. Regulation (EU) 2024/1689

General purpose AI model obligations

EU AI Act, Chapter V · In force since 02 Aug 2025 · checked 23 Jul 2026

Binds providers of general purpose AI models on the EU market; deployers inherit the evidence burden through contracts. Fine-tuning a model can make you a provider. Regulation (EU) 2024/1689

Transparency duties for chatbots, synthetic media and emotion recognition

EU AI Act, Art. 50 · Applies from 02 Aug 2026 · checked 23 Jul 2026

Disclosure that a person is dealing with AI, marking of AI-generated content, deepfake labelling, and notice for emotion recognition or biometric categorisation. Regulation (EU) 2024/1689

Marking of legacy systems and new prohibitions

EU AI Act, Art. 50(2) and Art. 5 (Digital Omnibus) · 02 Dec 2026, adopted pending Official Journal publication · checked 23 Jul 2026

Marking reaches systems on the market before 02 Aug 2026, and new prohibitions bar generation of non-consensual intimate imagery and child sexual abuse material. Council of the EU, 29 June 2026

High-risk obligations for standalone systems

EU AI Act, Annex III (Digital Omnibus) · 02 Dec 2027, moved from 02 Aug 2026, adopted pending publication · checked 23 Jul 2026

Risk management, data governance, documentation, logging, human oversight, accuracy and resilience evidence, and conformity assessment for standalone high-risk systems. Council of the EU, 29 June 2026

High-risk obligations for AI embedded in regulated products

EU AI Act, Annex I with EU MDR (Digital Omnibus) · 02 Aug 2028, moved from 02 Aug 2027, adopted pending publication · checked 23 Jul 2026

One conformity assessment against two frameworks for regulated products with embedded AI, including medical devices. Council of the EU, 29 June 2026

Connected-product data access by design

EU Data Act, Art. 3 · Applies from 12 Sep 2026 · checked 23 Jul 2026

Connected products designed so their data is accessible to the user by default, with pre-contract information. General application began 12 Sep 2025. Regulation (EU) 2023/2854

Automated decisions with legal or similar effect

GDPR, Art. 22 · In force · checked 23 Jul 2026

A lawful basis, meaningful information about the logic, and a route to human review for solely automated decisions with significant effects. Regulation (EU) 2016/679

Cyber risk management and incident reporting

NIS2 Directive (EU) 2022/2555 · In force, transposition varies by Member State · checked 23 Jul 2026

Board-accountable cyber risk management, supply-chain security, and incident reporting for essential and important entities. Directive (EU) 2022/2555

Automated decision-making rules recast

UK, Data (Use and Access) Act 2025 · In force since 05 Feb 2026 · checked 23 Jul 2026

Safeguards for qualifying automated decisions under new Articles 22A to 22D of the UK GDPR. UK and EU rules now differ. Data (Use and Access) Act 2025

Change control for AI-enabled devices

FDA, AI-enabled device software · Guidance, no statutory date · checked 23 Jul 2026

A predetermined change control plan for AI-enabled device software submitted to the FDA. Recommendations finalised December 2024; lifecycle guidance in draft. FDA, Federal Register, 04 December 2024

Trinidad and Tobago Data Protection Act 2011

Partial commencement, remainder outstanding · checked 23 Jul 2026

The General Privacy Principles proclaimed in 2012 apply now. Enforcement and penalty provisions are not in force and no date is announced. Parliament of Trinidad and Tobago

CBTT cybersecurity expectations for financial institutions

CBTT Cybersecurity Best Practices Guideline · Issued 2023, updated 2025 · checked 23 Jul 2026

Governance, risk management, testing, and incident management with an annual self-assessment return due by 31 March. Central Bank of Trinidad and Tobago

TATT cybersecurity of public telecommunications networks

TATT telecom cybersecurity framework · Published 30 Jan 2026, conformance date not set · checked 23 Jul 2026

Cybersecurity measures matched to the published framework for telecom concessionaires, with conformance reporting on a timeframe the Authority will set. Telecommunications Authority of Trinidad and Tobago

AI management system certification

ISO/IEC 42001:2023 · Voluntary · checked 23 Jul 2026

A management system covering AI policy, risk and impact assessment, and lifecycle controls, on a three-year certification cycle. The fastest route to evidencing AI governance to a buyer or an acquirer. ISO/IEC 42001:2023