Appearance
AI Governance Framework Updates
The AI governance landscape is moving fast. This page tracks the dates, amendments, and revisions that actually affect compliance programs, grouped by framework. For the full framework guides, see the frameworks overview.
How we use this page
Entries are written as dated, load-bearing facts that change how you should run your program. If an update just adds a new sample document or reference, we do not track it here — we update the framework guide directly.
EU AI Act
- 2024-07-12 — EU AI Act published in the Official Journal of the European Union.
- 2024-08-01 — Regulation entered into force; the phased application timeline begins.
- 2025-02-02 — Prohibited AI practices (Article 5) and AI literacy (Article 4) apply.
- 2025-08-02 — General-purpose AI (GPAI) obligations begin to apply for new models.
- 2026-07-12 — CEN/CENELEC approve EN 18286:2026, the quality management system standard for EU AI Act regulatory purposes and the first JTC 21 AI Act standard to reach final approval. Presumption of conformity attaches once EN 18286:2026 is cited in the Official Journal of the European Union (not yet cited). See the EN 18286 guide.
- 2026-07-24 — Digital Omnibus on AI published in the Official Journal as Regulation (EU) 2026/1744 (adopted by the European Parliament 16 June, Council 29 June 2026), in force from 27 July 2026. It defers the high-risk deadlines (Annex III to 2 December 2027, Annex I to 2 August 2028) and adds new Article 5(1)(ba)/(bb) prohibitions.
- 2026-12-02 — (Omnibus application date) New Article 5 NCII/CSAM prohibitions apply; legacy synthetic-content systems must meet Article 50(2) marking.
- 2027-12-02 — (deferred from 2 August 2026 by the Omnibus) Standalone Annex III / Article 6(2) high-risk obligations apply.
- 2028-08-02 — (deferred from 2 August 2027 by the Omnibus) Annex I Section A / Article 6(1) high-risk obligations apply.
See the EU AI Act guide and the How to comply with the EU AI Act step-by-step.
ISO/IEC 42001
- 2023-12 — ISO/IEC 42001:2023 published — first certifiable international management system standard for AI.
- 2024 onwards — early accredited certification bodies begin offering ISO 42001 audits under IAF signatory schemes (ANAB programs opened 2024).
- 2025 — ISO/IEC 42006:2025 published: the requirements for bodies auditing and certifying AI management systems. Accreditation bodies begin transitioning their ISO 42001 certification programs onto it.
- 2026-01 — first UKAS-accredited ISO/IEC 42001 certifications; accreditation coverage continues to broaden.
- 2026 — CEN/CENELEC adopt the standard as EN ISO/IEC 42001:2026. A European Standard, but not the AI Act QMS route: the Article 17 quality management system standard is the bespoke EN 18286, whose Annex C maps its clauses to this EN edition. See EN 18286 vs ISO 42001.
See the ISO 42001 guide and the How to comply with ISO 42001 step-by-step.
ISO/IEC 27701
- 2019 — ISO/IEC 27701:2019 published as a privacy extension to ISO 27001/27002.
- 2025 — ISO/IEC 27701:2025 published: the revised edition this documentation cites; the 2019 edition is withdrawn. Programs built on the 2019 extension model should plan the transition.
See the ISO 27701 guide.
NIST AI RMF
- 2023-01-26 — AI Risk Management Framework 1.0 (NIST.AI.100-1) published.
- 2023 — AI RMF Playbook published with categories and subcategories.
- 2024-07 — NIST AI 600-1 Generative AI Profile published as the first cross-sectoral companion to AI RMF 1.0.
- 2025-12-16 — NIST releases the preliminary draft Cyber AI Profile (NIST IR 8596), a CSF 2.0 profile for AI-related cyber risk across three focus areas (securing AI systems, AI-enabled cyber defense, thwarting AI-enabled attacks); companion SP 800-53 control overlays for securing AI systems are in development.
See the NIST AI RMF guide and the How to comply with NIST AI RMF step-by-step.
Colorado SB 26-189
- 2024-05-17 — SB 24-205, the Colorado AI Act, is signed: a high-risk-AI regime at C.R.S. §§ 6-1-1701–1707 with an original effective date of February 1, 2026.
- 2025-08-28 — SB 25B-004 (2025 special session) delays SB 24-205's effective date to June 30, 2026.
- 2026-05-14 — SB 26-189 (Session Law ch. 131) is signed: it repeals and reenacts part 17 of article 1 of title 6 as an automated-decision-making-technology regime (developer transparency package and update notices; deployer pre-use notice, post-adverse-outcome disclosures within 30 days, consumer correction and meaningful human review, records; liability allocation by relative fault; Attorney General enforcement through the Colorado Consumer Protection Act) and adds § 10-3-1104.9(3)(e). Its rulemaking authorities and certain related provisions take effect on signing. SB 24-205 never applied.
- 2026-05-29 — HB 26-1263 (Session Law ch. 208) adds conversational-AI service operator duties, and its own § 6-1-1708, to the same part 17. Its petition clause provides a conditional August 12, 2026 effective date (if the stated adjournment assumption holds and no referendum petition is filed), with staggered operative dates. A separate regime, not covered by the Modulos framework; part 17's final codified disposition is pending.
- 2027-01-01 — SB 26-189 takes effect and applies to consequential decisions made on or after this date. The two mandatory Attorney General rulemakings (post-adverse-outcome disclosures, § 6-1-1704(4); consumer rights, § 6-1-1705(3)) are due on or before this date; the Modulos framework will be updated when the rules are adopted.
- 2028-01 — Annual Attorney General enforcement reporting begins.
- 2030-01-01 — The 60-day cure-and-reporting subsection, § 6-1-1706(3), is repealed.
See the Colorado SB 26-189 guide.
CCPA ADMT Regulations
- 2025-07-24 — The California Privacy Protection Agency (CalPrivacy) adopts the CCPA regulations on automated decisionmaking technology (ADMT) and risk assessments, adding the ADMT and significant-decision definitions to § 7001, Article 10 (§§ 7150–7157), and Article 11 (§§ 7200–7222) to Cal. Code Regs. tit. 11, among other changes. The regulations implement the CCPA (Civ. Code § 1798.100 et seq.); they are not a new statute.
- 2025-09-22 — The Office of Administrative Law approves the regulations.
- 2026-01-01 — The regulations take effect. Article 10 applies: a risk assessment is conducted before a business initiates processing that uses ADMT for a significant decision, or that processes personal information it intends to use to train such ADMT.
- 2027-01-01 — A business that used ADMT for a significant decision before this date must be in compliance with Article 11 (Pre-use Notice, opt-out of ADMT with its conditional exceptions, access to ADMT) no later than this date; a business that uses ADMT on or after it must be in compliance any time it is using ADMT for a significant decision (§ 7200(b)). The odd-year adjustment of the CCPA monetary thresholds also takes effect.
- 2027-12-31 — Deadline for the risk assessment of processing that began before January 1, 2026 and continues (§ 7155(b)).
- 2028-04-01 — First submission to the Agency of the § 7157(b) information about risk assessments conducted in 2026 and 2027; later submissions fall due by April 1 following any year in which the business conducted risk assessments. The information required in the filings is information about the assessments, not the assessments or reports themselves; the reports are required on request of the Agency or the Attorney General.
See the CCPA ADMT Regulations guide.
NYC Local Law 144
- 2021-11-10 — The New York City Council passes Local Law 144 of 2021 (Int 1894-2020); it is returned unsigned by the Mayor on December 13, 2021 and becomes law. It adds §§ 20-870–874 to the Administrative Code, conditioning covered use of an automated employment decision tool on a bias audit no more than one year before use, public posting of the audit summary and distribution date before use, 10-business-day notice to candidates and employees who reside in the city, and the data disclosures of § 20-871(b)(3).
- 2023-01-01 — The law takes effect.
- 2023-04-06 — DCWP adopts the implementing rules, 6 RCNY §§ 5-300–5-304, after two rounds of proposals (September 23, 2022 and December 23, 2022): the three-prong "substantially assist or replace" test, the selection-rate, scoring-rate, and impact-ratio calculations across sex, race/ethnicity, and intersectional EEO-1 categories, the 2 percent exclusion, the historical-data, pooling, and test-data rules, the published-results elements, the notice channels, and the employment-section data posting, written-request, 30-day response, and explained-nondisclosure duties.
- 2023-06-29 — DCWP publishes its Automated Employment Decision Tools: Frequently Asked Questions, the only agency guidance issued to date: the "used in the city" test, the sourcing-versus-screening boundary, no imputed demographic data, no approved-auditor list, deployer responsibility, and the non-position-specific website notice.
- 2023-07-05 — DCWP enforcement begins.
- 2025-12-02 — The New York State Comptroller publishes an audit of DCWP's enforcement of the law: 75 percent of test calls to 311 on AEDT issues were misrouted, and the Comptroller's auditors found at least 17 potential violations among 32 companies DCWP had reviewed. DCWP concurred and committed to fixing 311 routing, written enforcement policies, tool demonstrations during investigations, and proactive enforcement.
See the NYC Local Law 144 guide.
OWASP Top 10 for LLM / Agentic
- 2023-08 — OWASP Top 10 for LLM Applications v1.0 published.
- 2024-11-18 — OWASP Top 10 for LLM Applications 2025 (v2.0) released by the OWASP GenAI Security project.
- 2025-12-09 — OWASP GenAI Security Project announces the Top 10 for Agentic Applications 2026, the first published Agentic Top 10.
See the OWASP for AI hub, the OWASP Top 10 for LLM, and the OWASP Top 10 for Agentic.
Singapore MGF for Agentic AI
- 2026-05-20 — IMDA publishes the Model AI Governance Framework for Agentic AI v1.5 (updated 5 June 2026): voluntary best-practice guidance structured around four dimensions applied as an iterative loop.
See the Singapore MGF for Agentic AI guide.
GDPR and EU data-protection guidance on AI
- 2018-05-25 — GDPR enters into application.
- 2024-12-17 — EDPB Opinion 28/2024 on AI models: model anonymity, legitimate interest as a legal basis for AI development, and the consequences of unlawfully processed training data.
- AI systems processing personal data must comply with GDPR in parallel with the EU AI Act. See EU AI Act vs GDPR.
Cyber Resilience Act
- 2024-11-20 — The Cyber Resilience Act (Regulation (EU) 2024/2847) is published in the Official Journal; it enters into force on 10 December 2024.
- 2025-11-28 — Commission Implementing Regulation (EU) 2025/2392 adopted: the technical descriptions of the important and critical product categories that determine each product's conformity-assessment tier.
- 2026-06-11 — Chapter IV (Articles 35–51) applies: the machinery for notifying conformity assessment bodies stands up ahead of the product deadlines.
- 2026-07-27 — The Commission publishes non-binding practical guidance on CRA implementation (C(2026) 5252): scope, substantial modification, support periods, and reporting obligations, with worked examples and particular attention to microenterprises and small enterprises.
- 2026-09-11 — Article 14 reporting applies: manufacturers report actively exploited vulnerabilities and severe incidents to the coordinator CSIRT and ENISA via the single reporting platform (24-hour early warning, 72-hour notification, final report). Applies to all in-scope products, including those placed on the market before 11 December 2027.
- 2027-12-11 — The remaining manufacturer duties apply. Products placed on the market before this date are caught only on substantial modification (Article 14 excepted). No harmonized standard has yet been cited in the Official Journal; the EN 40000 series is still in drafting under standardization request M/606.
See the Cyber Resilience Act guide.
NIS2
- 2023-01-16 — NIS2 Directive (EU) 2022/2555 entered into force.
- 2024-10-17 — Member State transposition deadline. National laws now apply to essential and important entities.
See the NIS2 guide.
DORA
- 2023-01-16 — DORA (Regulation (EU) 2022/2554) entered into force.
- 2025-01-17 — DORA applies to financial entities in the EU.
See the DORA guide.
How to track framework changes in Modulos
Modulos tracks framework versions and notifies projects when regulatory updates affect them, so you can assess impact before deadlines.
Framework versioning
Templates evolve. Projects pin a version, upgrade deliberately, and freeze near audit.
Template versions
v1.0
Initial
v1.1
Update
v1.2
Latest
Project pin
My Project
Pinned to v1.0
My Project
Updated to v1.2
Freeze updates
Freeze framework updatesPrevents new template versions from entering the project. Normal editing remains available.
Pin a version, upgrade when ready, freeze near audit. The project pin is the boundary between regulatory drift and a stable scope.
Disclaimer
This page is for general informational purposes and does not constitute legal advice. Confirm dates and obligations with official sources and qualified counsel.