A working glossary, a tracker of real AI enforcement actions, and a timeline of what regulation applies when. Bookmark it. We keep it current so you do not have to.
The dates that matter for AI compliance planning, in force and upcoming. Status reflects the legal landscape as of July 2026, which is moving quickly.
Employers using automated employment decision tools for NYC roles must obtain independent bias audits and post candidate notices. The first enforced algorithmic hiring law in the US.
Bans on social scoring, manipulative AI, and most real time biometric identification take effect, along with AI literacy obligations for organizations whose staff operate AI systems.
Transparency, documentation, and copyright obligations for general purpose AI models, plus the governance structure that stands up EU level enforcement.
Illinois HB 3773 prohibits discriminatory AI in employment decisions. Texas RAIGA restricts intentionally harmful AI uses. California requires generative AI training data disclosures (AB 2013), companion chatbot safeguards (SB 243), and bars AI from posing as licensed health professionals (AB 489).
The first comprehensive US state AI law, requiring reasonable care against algorithmic discrimination in consequential decisions. Delayed from February 2026, and now facing a federal litigation task force created by a December 2025 executive order targeting state AI laws. Watch this one closely.
Conformity assessments, technical documentation, registration, and quality management for high risk AI systems. A postponement to December 2027 has been proposed but is not law. California’s SB 942 AI content transparency requirements also land on this date.
Obligations reach high risk AI embedded in regulated products such as medical devices and machinery under Article 6(1).
Real penalties, settlements, and active litigation involving AI systems. This is what ungoverned AI actually costs.
The EEOC’s first AI hiring discrimination settlement. Recruiting software automatically rejected older applicants. The lesson: automated rejection is still rejection under the ADEA.
Rite Aid was barred from using facial recognition for five years after deploying it without reasonable safeguards, disproportionately flagging women and people of color as shoplifters.
Delphia and Global Predictions paid combined penalties for overstating their use of AI. Claiming more AI than you actually have is now a securities problem, not just a marketing one.
The first state attorney general settlement over generative AI in clinical settings, resolving claims that the company overstated the accuracy of its hospital documentation AI.
The Netherlands fined Clearview for building a facial recognition database from scraped photos without a legal basis, one of several European actions against the company.
Settlement over an algorithmic tenant screening score that disadvantaged Black and Hispanic applicants using housing vouchers. SafeRent also agreed to stop scoring voucher applicants.
A federal court certified a nationwide collective action alleging Workday’s AI screening discriminated against applicants over 40. The case tests whether an AI vendor can be liable as an agent of the employers it serves.
This tracker is informational, not legal advice. Amounts reflect public settlements and penalties at the time of listing.
Forty four terms that show up in board conversations, regulatory texts, and vendor pitches, defined in plain language with the business consequence attached.
The documented map of who owns each AI decision: who approves deployment, who monitors behavior, who responds to incidents. Without one, accountability defaults to whoever is standing closest when something breaks.
AI systems that plan and take multi step actions toward goals with limited human direction. Agents raise governance stakes because errors compound across actions instead of stopping at a single output.
Also called an AI review board. The cross functional body with authority to approve, condition, or halt AI deployments. Effective boards pair builders with legal, compliance, risk, and security under a written charter.
The structures, processes, and accountability that direct how an organization builds, buys, and operates AI. Not a document. An operating capability, like financial controls for models.
Any event where an AI system causes or nearly causes harm: a biased decision, a harmful output, a privacy breach, a hallucinated fact acted upon. Mature organizations define, log, and learn from them.
The working knowledge staff need to use AI responsibly. An explicit legal obligation under the EU AI Act since February 2025 for organizations whose personnel operate AI systems.
Deliberate adversarial testing that tries to make an AI system fail: produce harmful outputs, leak data, or be manipulated. The point is finding failures before users and attackers do.
Systematic unfairness in AI outputs against particular groups, usually inherited from training data or design choices. The basis of most AI enforcement actions to date, from hiring to tenant screening.
A structured pre deployment evaluation of an AI system’s potential effects on people, similar in spirit to a privacy impact assessment. Required in various forms by emerging state and international rules.
The EU AI Act’s list of high risk use cases, including employment, education admissions and scoring, credit, and essential services. If your system fits a category here, the Act’s heaviest obligations apply.
The records proving what an AI system did and what humans decided about it: approvals, overrides, changes, incidents. When a regulator asks, the audit trail is the difference between an answer and a scramble.
An independent statistical evaluation of whether an automated decision tool produces disparate outcomes across protected groups. Required annually for automated hiring tools used on New York City candidates under Local Law 144.
The first comprehensive US state AI law, requiring developers and deployers of high risk AI to use reasonable care against algorithmic discrimination. Effective June 30, 2026, though facing federal legal challenge.
The EU AI Act’s process for demonstrating a high risk system meets requirements before it goes to market, roughly analogous to CE marking for products. Documentation heavy by design.
The policies and controls over data quality, access, provenance, and lifecycle. AI governance sits on top of it: a model is only as governable as the data feeding it.
The documented origin and chain of custody of data: where it came from, under what consent, with what transformations. Increasingly a disclosure obligation, including California’s AB 2013 for generative AI training data.
An organization that uses an AI system built by someone else. Deployers carry their own legal obligations under the EU AI Act and US law. Buying the tool does not transfer the accountability.
The world’s first comprehensive AI law, phasing in from February 2025 through 2027. It classifies AI by risk and attaches obligations accordingly, with penalties reaching 35 million euros or 7 percent of global turnover.
The ability to give a meaningful account of why an AI system produced a given output. Matters legally when people are entitled to reasons, such as adverse action notices in lending and hiring.
The federal law protecting student education records. AI tools that touch student data, from advising chatbots to enrollment analytics, must operate within it, a frequent blind spot in campus AI adoption.
A large model trained on broad data that many applications build on. Governance challenge: your risk inherits from a model you did not train and cannot fully inspect.
The EU AI Act’s term for models usable across many tasks, like large language models. Providers carry transparency, documentation, and copyright obligations that took effect in August 2025.
A structured comparison of your current AI practices against a target framework such as NIST AI RMF, producing a prioritized remediation roadmap. Typically the first two to four weeks of governance work.
A confident but false output from a generative model. Becomes a governance problem the moment outputs feed decisions, documents, or customers without a defined human check.
Under the EU AI Act, a system in an Annex III category or a regulated product, triggering conformity assessment, documentation, monitoring, and human oversight obligations. US state laws use similar concepts for consequential decisions.
A designed decision point where a person reviews or can override AI output before it takes effect. The design part matters: nominal review that always clicks approve fails both audits and courts.
The risk of AI deriving sensitive conclusions from data that seems innocuous, such as health status inferred from purchase patterns or device telemetry. A defining governance issue for data and analytics organizations.
The international standard for AI management systems, the certifiable counterpart to NIST AI RMF’s practice guidance. Increasingly requested in enterprise procurement as evidence of governance maturity.
New York City’s automated employment decision tool law, enforced since July 2023. Requires annual independent bias audits and candidate notice for AI used in hiring or promotion for NYC roles.
A short standardized document describing a model’s purpose, training data, performance, limitations, and appropriate uses. The minimum documentation any deployed model should carry.
Degradation of model performance as the world changes around it. Why monitoring and scheduled reviews are governance requirements, not nice to haves: a model validated last year may be failing quietly today.
The single registry of every AI system in use, including vendor and embedded AI, with owner, purpose, data touched, and risk tier. The foundational governance artifact. You cannot govern what you have not listed.
The discipline of identifying, measuring, and controlling risks from model use, born in banking under SR 11-7 and now extending to AI broadly. Financial services organizations often extend existing MRM to cover AI.
The US National Institute of Standards and Technology’s AI Risk Management Framework, organized around four functions: Govern, Map, Measure, Manage. Voluntary, but rapidly becoming the de facto benchmark US organizations are assessed against.
AI uses banned outright by the EU AI Act since February 2025, including social scoring, manipulative techniques exploiting vulnerabilities, and most real time remote biometric identification. The 35 million euro penalty tier.
Under the EU AI Act, the organization that develops an AI system or has it developed and places it on the market. Providers carry the heaviest obligations, but deployers are not exempt.
The umbrella term for developing and using AI consistent with fairness, transparency, privacy, and safety commitments. Governance is how responsible AI stops being a value statement and becomes an operating practice.
Classifying AI systems by potential harm so oversight effort matches risk: full review for consequential systems, streamlined intake for routine ones. What keeps governance from becoming a bottleneck.
AI adopted by staff or teams outside sanctioned channels, from personal chatbot accounts to unapproved vendor features. A leading source of data leakage and the reason inventories must look beyond official projects.
The EU AI Act’s required evidence package for high risk systems: design, data, testing, risk management, and performance records maintained throughout the lifecycle. Assembled after the fact, it is expensive. Maintained as you go, it is routine.
Testing, evaluation, verification, and validation: the family of activities that produce evidence an AI system works as claimed. NIST AI RMF weaves TEVV through the entire lifecycle rather than treating it as a launch gate.
The data a model learns from. Its quality, representativeness, and legal basis determine much of a model’s risk profile, which is why data questions dominate both audits and litigation.
Requirements to tell people they are interacting with AI or consuming AI generated content, appearing in the EU AI Act, California law, and sector rules. The cheapest compliance obligation to meet and the most embarrassing to miss.
The body governing research involving human subjects at universities and academic medical centers. AI research and AI tools that touch human subject data increasingly require IRB engagement, a growing intersection campus governance must manage.
The free AI governance maturity assessment scores your organization against the NIST AI RMF functions in about ten minutes.