The dated obligations that reach an ordinary American business — and the vendor dates that break things on the same calendar. Free, no login.
Last reviewed 18 September 2026
Most AI compliance calendars list statutes. This one also lists the vendor dates — the model your system calls being retired, the introductory price ending — because in practice those break a business on exactly the same calendar, and nobody puts them side by side.
Scope is deliberately US-first and operator-first. Obligations that only bind frontier AI developers are marked as such, because they almost certainly do not reach you.
These are live today. The most commonly missed one is the California privacy risk assessment — the duty started on 1 January 2026 and most small and mid-size businesses have not done one.
Required where automated decision-making is used for significant decisions, where personal traits are inferred, or where such systems are trained. The duty is already running.
Reaches: any business meeting CCPA thresholds that uses AI in consequential decisions.
AI disclosure, protections for minors and a self-harm protocol. Carries a private right of action at $1,000 per violation — one of the few US AI laws an individual can sue under directly.
Reaches: operators of companion-style chatbots.
Texas enforcement sits solely with the Attorney General, runs through a complaint portal that has been accepting complaints since 1 January 2026, and includes a mandatory 60-day cure period. Illinois bars discriminatory effect in employment AI and prohibits zip-code proxies.
Reaches: businesses operating in TX; employers using AI in hiring or promotion in IL.
The first of twelve state chatbot laws to take effect. Iowa is one of four states (with Colorado, Idaho and Nebraska) whose law reaches any publicly accessible conversational AI — not just companion apps. The duty falls on whoever deploys the bot, not the vendor who built it.
Reaches: any business running a public-facing chatbot with Iowa users — including ordinary customer support.
Content provenance and disclosure duties for covered generative AI systems.
Requires an AI/ML policy and a "no less protective" flow-down to vendors. Contractual rather than statutory — which means repurchase remedies, not fines.
Reaches: mortgage sellers and servicers.
Four-year record retention, and third-party liability reaching the vendor supplying the tool.
Reaches: employers using automated decision systems in California.
The earliest of the state disclosure duties still in force.
Four model retirements sit in this window alongside the regulatory dates. A retired model returns a hard error if you pinned the dated snapshot, or gets silently substituted if you are on a floating alias — with no log event either way.
Implementing SB 26-189 and HB 26-1263. The earliest signal of which way the rules are moving.
claude-sonnet-4-5-20250929. Calls to a retired model fail.
Around thirty AI bills passed on 31 August must be signed or vetoed. Whatever survives is the 2026 California AI stack.
Ran March to September 2026 inside existing market-conduct and financial examinations, not as a separate AI track. Pilot states: CA, CO, CT, FL, IA, LA, MD, PA, RI, VT, VA, WI.
Reaches: insurers and the vendors supplying them.
Employer use of an automated employment decision tool stops shielding the employer from a discriminatory-practice claim. Also effective the same day: an employer issuing a mass-layoff notice must disclose whether AI informed the decision; frontier-developer whistleblower protections; and AI subscription notice duties for providers above one million monthly users.
Reaches: employers operating in or hiring into Connecticut.
Same failure modes as above.
Docket FDA-2026-N-7874. Covers a two-axis risk framework, premarket evaluation and postmarket monitoring.
Comments close 11:59 PM MT; hearing at 10:00 AM in Denver, hybrid with Zoom. Any attendee may testify, and the recording joins the public record.
Notice given 28 August 2026 following the acquisition of Anysphere. Not a legal deadline — a sub-supplier continuity event, and a reminder that a change of control upstream can end model supply downstream.
Also the venue where a nine-component compliance report and attestation draft may advance.
Including a kids' chatbot safety bill carrying a private right of action, a training-data transparency act, and a ban on AI surveillance pricing.
1 January 2027 is the single densest date on this calendar. If you only diary one thing from this page, diary that.
Pre-use notice, a two-method opt-out, and a right to access the logic and parameters behind the decision. Existing uses must comply by this date; uses starting after it comply immediately.
Reaches: CCPA-covered businesses using ADMT for significant decisions.
Also bars inferring veteran status, ancestral history, religious beliefs or disability status. The obligation lands on the employer, not the vendor.
Reaches: employers using workplace monitoring or sentiment tooling in California.
SB 189 — narrowed ADMT disclosure. HB 26-1263 Chatbot Safety Act — age estimation, AI disclosure, minor safeguards, self-harm protocol, no impersonation of licensed professionals, and an annual report to the Attorney General. HB 26-1139 — AI in health care, including clinician review of AI-assisted denials.
Of twelve state chatbot laws, all but Iowa take effect on 1 January or 1 July 2027. All share one structure: AI-identity disclosure and self-harm controls for every user, plus enhanced protections for minors. The duty attaches to the deployer.
Reaches: anyone putting conversational AI in front of the public.
3.8 Flash runs at $0.75 input / $3.75 output per million tokens through 31 December 2026, then $1.50 / $7.50. The same doubling hits 3.6 and 3.7 Flash. Announced months ahead — it is simply in nobody's diary.
New York's RAISE Act (72-hour critical-incident reporting to DFS) and the first substantive provisions of Illinois SB 315. These bind frontier AI developers, not ordinary businesses — listed here because they shape what your vendors can commit to.
Class certification proceedings are ongoing in the Northern District of California. A 2024 ruling allowed claims against Workday to proceed on an agency theory — the question of whether a software vendor can be treated as an agent of the employers using its tools. No liability has been determined. Watched here because the agency question, if it holds, reaches any vendor whose product scores, ranks or filters people. Date from secondary reporting; not confirmed against the court docket.
Idaho and Nebraska both enacted "Conversational AI Safety Acts" effective this date. Colorado's first Operator Annual Report to the Attorney General is also due.
Plain-language disclosure when an automated employment decision tool interacts directly with applicants or employees, plus state-agency AI inventories and impact assessments.
Far enough out to feel irrelevant, close enough that the evidence these dates require is being created — or not created — right now.
First US requirement for independent frontier-AI audits. Useful now as the reference form of the audit artifact to ask a frontier vendor for.
Covers assessments conducted during 2026–27 — the work being done, or skipped, today. Applies first to businesses above $100M gross revenue; the submission must name a member of executive management as responsible. Lower revenue tiers follow on 1 April 2029 and 1 April 2030.
This calendar is a snapshot, reviewed periodically. Terms Watch is the weekly diff — what changed, and what it means for an agreement you have already signed. Free, one email a week.
With your consent this site uses Google Analytics to measure traffic and anonymous, aggregate tool usage — including your score or result band, but never the text you type and never anything identifying you or your company. Google sets a cookie and processes your IP address. See our privacy note.