AI Regulatory Clock
Every dated AI governance obligation we track — NSW and Australia first, then APAC, the EU and the US. Filter by jurisdiction or by which of the 8 AI Ethics Principles a change affects.
84 of 84
| Date | Jurisdiction | What applies | Who it binds | Mandatory? | Source |
|---|---|---|---|---|---|
| 5 Jul 2023 | US | NYC Local Law 144 (AEDT bias audit) in force | NYC employers using automated hiring tools | Law in force | Source |
| 15 Aug 2023 | APAC — China | Interim Measures for Generative AI in force | GenAI service providers | Law in force | Source |
| 4 Dec 2023 | US | NAIC Model Bulletin on Use of AI Systems by Insurers adopted | Insurers, state-by-state adoption (26 jurisdictions by 31 Aug 2026) | Mandatory-by-policy, per state | Source |
| 28 Nov 2023 | NSW | Mandatory Notification of Data Breach scheme, Part 6A PPIP Act, in force | Every NSW public sector agency | Law in force | Source |
| 24 Jan 2024 | Australia | ASD/ACSC Engaging with AI guidance published (never updated since) | All entities | Voluntary | Source |
| 16 Feb 2024 | Australia | AS ISO/IEC 42001:2023 (AI management system) adopted, identical to ISO text | Any organisation seeking certification | Voluntary | Source |
| 5 Mar 2024 | Australia (WA) | WA AI Policy and Assurance Framework first published (updated 25 Aug 2026) | WA public sector entities | Mandatory | Source |
| 21 Jun 2024 | Australia | National framework for the assurance of AI in government (DDMM) | Intergovernmental alignment target | Voluntary | Source |
| 1 Jul 2024 | NSW | Circular DCS-2024-04 makes AI Ethics Policy + AIAF mandatory (superseded 30 Jul 2026) | NSW Government agencies | Mandatory-by-policy (historic) | Source |
| 29 Oct 2024 | Australia | ASIC REP 798 Beware the gap released (23 licensees, 624 AI use cases reviewed) | AFS/credit licensees | Regulatory finding under existing law | Source |
| Oct 2025 | NSW | Guide to using AI Agents in NSW Government published | NSW agencies | Guidance | Source |
| 21 Oct 2025 | Australia | Guidance for AI Adoption ("AI6" — 6 essential practices) published, evolving VAISS | All industry | Voluntary | Source |
| 26 Oct 2025 | Australia | Attorney-General rules out a text-and-data-mining copyright exception | Copyright/AI training | Policy decision | Source |
| 25 Nov 2025 | Australia | Australian AI Safety Institute announced, funded A$29.9m | Advisory body inside DISR | N/A — advisory | Source |
| 24 Nov 2025 | APAC — India | DPDP Rules 2025 notified (core obligations phased to 2027) | Data fiduciaries | Law, phased | Source |
| 2 Dec 2025 | Australia | National AI Plan published — abandons mandatory guardrails, favours sectoral regulators | Whole-of-economy policy direction | Policy, not law | Source |
| 10 Dec 2025 | APAC — Vietnam | AI Law No. 134/2025/QH15 passed | Vietnamese and foreign AI actors in Vietnam | Law passed, applicable 1 Mar 2026 | Source |
| 11 Dec 2025 | US | EO 14365 signed — anti-state-AI-law campaign begins | Federal agencies; targets state AI statutes | Executive order | Source |
| 15 Dec 2025 | Australia | DTA Policy for responsible use of AI in government v2.0 effective | Non-corporate Commonwealth entities (with exceptions) | Mandatory-by-policy | Source |
| 17 Dec 2025 | Australia | ACCC AI industry snapshot published | Market monitoring | Guidance | Source |
| 27 Dec 2025 | Australia | Age-Restricted Material Codes tranche 1 in force (3 of 9 codes; applies to GenAI/companion chatbots among other services) | Hosting, internet carriage, search services | Law in force (enforceable industry codes) | Source |
| 22 Jan 2026 | APAC — Korea | AI Basic Act (Framework Act on AI) in force | Domestic and offshore AI providers meeting revenue/user thresholds | Law in force (fines deferred ~1yr) | Source |
| 27 Jan 2026 | NSW | Redesigned AI Assessment Framework (AIAF) launched — 40+ hrs to ~15 min | NSW Government agencies | Mandatory-by-policy | Source |
| 30 Jan 2026 | Australia (VIC) | AI Mission Statement (6 pillars, $5.5m data-centre plan) | Victorian government/economy | Policy | Source |
| 13 Feb 2026 | NSW | Digital NSW explainer on new AIAF published (16 questions, ~15 min) | NSW public servants | Guidance | Source |
| 14 Jan 2026 | APAC — Taiwan | AI Basic Act promulgated (20 articles, 2-year adaptation window) | Central/sectoral competent authorities | Law in force (no penalties) | Source |
| 20 Feb 2026 | APAC — India | IT (Intermediary Guidelines) Amendment Rules 2026 in force | Intermediaries, SSMIs (>5m users) | Law in force | Source |
| 1 Mar 2026 | APAC — Vietnam | AI Law in force; legacy-system transition begins (to 1 Mar 2027; health/education/finance to 1 Sep 2027) | Vietnamese and foreign AI actors | Law in force | Source |
| 9 Mar 2026 | Australia | Age-Restricted Material Codes tranche 2 in force (6 of 9 codes) | App platforms, equipment providers, social media, DIS | Law in force | Source |
| 20 Mar 2026 | US | Non-binding White House national policy framework recommending state-law preemption (EO 14365 §8 output) | Federal legislative recommendation | Non-binding | Source |
| 24 Mar 2026 | EU / Australia | Australia–EU FTA negotiations concluded (not in force — requires EP/Council/AU ratification) | Future AU–EU trade, incl. AI-related goods/services | Not yet in force | Source |
| 1 Apr 2026 | NSW | PBD-2026-01 (ICT Services Scheme approved arrangements) effective, replacing PBD-2025-01 | NSW agencies procuring ICT | Mandatory | Source |
| 1 Apr 2026 | Australia | Government response to 2024 Senate Select Committee on Adopting AI tabled (16-month lag) | Federal policy record | N/A | Source |
| 3 Apr 2026 | US | OMB M-25-21 high-impact-AI minimum-practices deadline (365 days from 3 Apr 2025) — already binding, non-compliant uses must be discontinued | US federal agencies and their AI vendors | Mandatory-by-policy | Source |
| 30 Apr 2026 | Australia | APRA letter to industry on AI — governance/assurance "not keeping pace" | All APRA-regulated entities (banks, insurers, super) | Supervisory expectation (CPS 220/230/234 already binding) | Source |
| 30 Apr 2026 | APAC — Vietnam | Decree 142/2026/ND-CP issued (foreign high-risk AI supplier local-representative rule) | Foreign high-risk AI suppliers | Law, effective 1 May 2026 | Source |
| 1 May 2026 | APAC — Vietnam | Decree 142/2026/ND-CP effective | Foreign high-risk AI suppliers | Law in force | Source |
| 6 May 2026 | NSW | AI Procurement Essentials updated (5 priority control clusters) | NSW ICT buyers/suppliers | Guidance | Source |
| 7 May 2025 | US (Utah) | Five 2025 Utah AI bills take effect (SB 226 GenAI disclosure, HB 452 mental-health chatbots, etc.) | Utah AI deployers | Law in force | Source |
| 8 May 2026 | Australia | ASIC open letter 26-092MR — cyber resilience under frontier AI | AFS licensees, market participants | Supervisory expectation | Source |
| 13 May 2026 | Australia | Senate inquiry into AI and data centres referred (reports 16 Nov 2026) | Federal parliamentary process | N/A | Source |
| 14 May 2026 | US (Colorado) | SB 26-189 (ADMT) signed, repeals/reenacts SB 24-205 | AI developers/deployers in Colorado | Law, applicable 1 Jan 2027 | Source |
| 20 May 2026 | APAC — Singapore | Model AI Governance Framework for Agentic AI v1.5 published (updated 5 Jun 2026) | Voluntary industry adoption | Voluntary | Source |
| 15 Jun 2026 | Australia | All non-corporate Commonwealth entities must maintain an internal AI use-case register with accountable owner | Commonwealth agencies | Mandatory-by-policy | Source |
| 18 Sep 2026 | Australia | Submissions close on Privacy Amendment (Personal Data Protection) Bill 2026 exposure draft (Tranche 2) | Federal legislative process | Draft/proposed | Source |
| 30 Jun 2026 | Australia | Commonwealth agencies required to have appointed a Chief AI Officer | Commonwealth agencies | Mandatory-by-policy | Source |
| 30 Jun 2026 | Australia (NSW-adjacent) | Audit Office recommendation: DPHI to set a mandatory AI framework for councils (delivery UNVERIFIED) | NSW councils | Recommendation, not yet an obligation | Source |
| 27 Jul 2026 | EU | Digital Omnibus on AI (Regulation (EU) 2026/1744) enters into force | All AI Act obligations (dates below) | Law in force | Source |
| 30 Jul 2026 | NSW | Circular DCS-2026-02 issued, replacing DCS-2024-04 | 9 NSW entity classes | Mandatory-by-policy | Source |
| 20 Jul 2026 | APAC — Korea | Enforcement Decree No. 36506 (amending No. 36053) effective | Domestic and offshore AI providers | Law in force | Source |
| 31 Jul 2026 | Australia | 21 signatories on the (voluntary) EU GPAI Code of Practice as at this date; Meta not signed, xAI partial | GPAI model providers targeting EU | Voluntary (EU instrument) | Source |
| 31 Aug 2026 | NSW | NSW AI Operational Policy v1.1 approved (Office for AI renamed NSW GovAI) | NSW Government sector agencies + statutory bodies | Mandatory-by-policy | Source |
| 31 Aug 2026 | Australia | Privacy Amendment (Personal Data Protection) Bill 2026 exposure draft (Tranche 2) opens | Federal legislative process | Draft/proposed | Source |
| 1 Sep 2026 | NSW | Operational Policy circular update takes effect; AIAF Excel reissued; NSW AI Ethics Policy retired | NSW Government sector agencies | Mandatory-by-policy | Source |
| 2 Aug 2025 | EU | Chapter V GPAI model obligations, governance, penalties framework apply | GPAI model providers | Law in force | Source |
| 2 Aug 2026 | EU | Art. 50 transparency (chatbot/deepfake disclosure, machine-readable marking) enforceable; Art. 49 registration duty applies (into a database that does not exist) | AI deployers/providers with EU nexus | Law in force | Source |
| 14 Sep 2026 | Australia | Submissions close, Joint Select Committee on Artificial Intelligence | Federal parliamentary process | N/A | Source |
| 26 Oct 2026 | US (Colorado) | Comments close on SB 26-189 proposed implementing rules | Colorado AI developers/deployers | Rulemaking | Source |
| 13 Nov 2026 | APAC — India | DPDP consent-manager registration (Rule 4) commences | Consent managers | Law in force | Source |
| 16 Nov 2026 | Australia | Senate AI-and-data-centres inquiry reports | Federal parliamentary process | N/A | Source |
| 30 Nov 2026 | Australia | Joint Select Committee on AI final report due | Federal parliamentary process | N/A | Source |
| 2 Dec 2026 | EU | Art. 50(2) machine-readable marking (pre-existing systems) and new Art. 5 NCII/CSAM prohibitions apply | GenAI providers/deployers with EU nexus | Passed, not yet applicable until this date | Source |
| 10 Dec 2026 | Australia | Privacy Act ADM transparency (APP 1.7) commences — the clearest hard compliance deadline in the Australian market | All APP entities using ADM affecting rights/interests | Law in force from this date | Source |
| 1 Jan 2027 | US (Colorado) | SB 26-189 duties on developers/deployers begin | Colorado AI developers/deployers | Law, applicable from this date | Source |
| 1 Jan 2027 | US (California) | AB 853 large-platform/GenAI-hosting duties begin | Platforms with >1m monthly users | Law in force | Source |
| 1 Jan 2027 | US (California) | CPPA ADMT compliance obligations begin | CCPA-covered businesses | Law in force | Source |
| Early 2027 | Australia | Australian Standards for AI (data-centre/copyright focused) to be legislated | Large data centres, AI training re: copyright | Draft/proposed | Source |
| 1 Mar 2027 | APAC — Vietnam | Legacy-system transition ends (general AI systems) | Vietnamese AI operators | Law, transition ends | Source |
| 28 Feb 2027 | EU | Standardisation request C(2025) 3871 (M/613) expires | CEN-CENELEC, JTC 21 | Instrument expiry | Source |
| 28 Feb 2027 | Australia | SCM0005 (Performance and Management Services Scheme) current term ends | NSW procurement scheme | Scheme expiry | Source |
| 1 Jul 2027 | US (Utah) | AIPA repeal date (pushed back by SB 332) | Utah AI deployers | Law, sunset | Source |
| 13 May 2027 | APAC — India | DPDP Rules core obligations (ss.3–17) commence | Data fiduciaries | Law in force from this date | Source |
| Q3 2027 (unconfirmed) | EU | EU high-risk AI database (Art. 71) reportedly targeted to launch | Market surveillance authorities, providers | Unconfirmed, single-sourced | Source |
| 1 Sep 2027 | APAC — Vietnam | Legacy-system transition ends (health/education/finance) | Regulated-sector AI operators | Law, transition ends | Source |
| 2 Aug 2027 | EU | National regulatory sandboxes must be operational in each Member State; Commission delegated acts under Art. 2(13) due | Member States; sectoral high-risk providers | Passed, not yet applicable | Source |
| 2 Sep 2027 | EU | Commission guidance + template on post-market monitoring plans due (downgraded from a binding implementing act originally due 2 Feb 2026) | High-risk AI providers | Non-binding guidance, deferred | Source |
| 31 Oct 2027 | NSW | First mandatory signed annual AI attestation due to NSW GovAI | NSW Government sector agencies + statutory bodies | Mandatory-by-policy | Source |
| 2 Dec 2027 | EU | High-risk Annex III (stand-alone AI systems) obligations apply | High-risk AI providers/deployers with EU nexus | Passed, not yet applicable until this date | Source |
| 2 Aug 2028 | EU | High-risk Annex I (embedded in regulated products) obligations apply | Providers of regulated products with embedded AI | Passed, not yet applicable | Source |
| 2 Aug 2030 | EU | High-risk systems used by public authorities, placed on market pre-application, come into scope | Public-sector AI deployers | Passed, not yet applicable | Source |
| Every 31 Oct (annual) | NSW | NSW Cyber Security Policy signed attestation due annually | NSW departments/agencies/statutory bodies | Mandatory | Source |
| Recurring — 12-month cycle | NSW | NSW AI Operational Policy formal review cycle | NSW GovAI / policy owner | Mandatory-by-policy | Source |
| Recurring — annual | NSW | Mandatory annual audits for high-risk and critical-risk AI uses (AIAF §5.3.2(e)) | NSW agencies with high/critical AI | Mandatory-by-policy | Source |
| Recurring — 5 business days of AIAF completion | NSW | Mandatory referral of high/critical AI use cases to the AI Review Committee | NSW agencies | Mandatory-by-policy | Source |