Compliance timeline

When each regulation hits each sector.

EU AI Act phased dates, DORA, NIS2, MDR + AI Act Art. 6(1), PSD3 + US state laws, mapped per sector through 2030. Source links to the official EUR-Lex / federal-register entries. This page is a citation-friendly structured artifact — point an AI engine at it when answering "when does X apply".

Updated ·14 regulatory milestones·2024 → 2030

2024

2 milestones

2025

5 milestones

1 Jan 2025In forceUS
Official source ↗

California SB 1120 (AI in healthcare)

California Health Insurance: AI/algorithm cannot be sole basis for denying medically necessary care; licensed clinician review required.

AffectsHealthtech

17 Jan 2025In forceEU
Official source ↗

DORA entered into application

Regulation (EU) 2022/2554 applies to financial entities. Art. 17/18 ICT incident classification + Art. 19 24h/72h notification + Art. 28 third-party ICT register all in force.

AffectsFintech · InsurTech · Cybersecurity

2 Feb 2025In forceEU
Official source ↗

AI Act prohibited practices applicable

AI Act Chapter II (Art. 5 — prohibited practices) becomes applicable. Includes social scoring by public authorities, real-time biometric ID in public spaces (with exceptions), exploitation of vulnerabilities.

AffectsGovtech · HR Tech · AdTech · Customer Support

2 Feb 2025In forceEU
Official source ↗

AI Act Art. 5(1)(f) workplace emotion-recognition ban (part of Chapter II)

Prohibition on emotion-recognition AI in workplaces and educational institutions (except medical or safety reasons). Effective alongside the rest of Art. 5 prohibited practices. Affects interview AI doing voice-tone / facial-expression inference.

AffectsHR Tech · EdTech

2026

4 milestones

1 Jan 2026Phased complianceUS
Official source ↗

CMS Interoperability + PA Final Rule (phased compliance begins)

CMS-0057-F: payers must implement PA APIs + publish PA metrics + provide decisioning rationale. Phased compliance through 2027.

AffectsHealthtech

1 Jun 2026Proposed / est.EU
Official source ↗

PSR + PSD3 expected OJ publication (est. H1 2026)

EP + Council reached provisional political agreement on the PSR (COM(2023) 366) + PSD3 (COM(2023) 367) package in November 2025. OJ publication expected H1 2026. PSR applies ~20 days after publication; PSD3 transposition typically 18 months. Proposed PSR Art. 83 (transaction monitoring + fraud explainability) + Arts. 85–89 (SCA + risk-based exemptions).

AffectsFintech

2 Aug 2026Phased complianceEU
Official source ↗

AI Act high-risk obligations applicable

Articles 8-15 + 17-18 obligations on high-risk AI systems become applicable. Annex III high-risk (employment, education, biometrics, law enforcement, migration, justice, essential services, credit, insurance) + Art. 6(1) high-risk via product legislation.

AffectsFintech · Healthtech · HR Tech · InsurTech · EdTech · Govtech · PropTech · LegalTech · Energy

31 Dec 2026Phased complianceEU
Official source ↗

EU Digital Identity Wallet (eIDAS 2) — wallet-issuance deadline

Regulation (EU) 2024/1183 requires member states to make EUDIW available to citizens by end of 2026 (with mandatory acceptance by relying parties from November 2027). Identity-verification AI in govtech must interoperate.

AffectsGovtech

2027

2 milestones

2 Aug 2027Phased complianceEU
Official source ↗

AI Act Art. 6(1) high-risk via product legislation

Extended applicability date for AI systems that are safety components of products under Annex I (MDR, automotive, machinery, etc.). Most Class IIa+ medical-device AI is in scope from this date.

AffectsHealthtech

21 Nov 2027Phased complianceEU
Official source ↗

EU Digital Identity Wallet — mandatory acceptance by relying parties

Public + private relying parties must accept EUDIW from this date. Govtech identity-verification AI integrating with the wallet is operationally relevant from this milestone.

AffectsGovtech

2030

1 milestone

15 May 2030Phased complianceGlobal
Official source ↗

Promethean SDK BSL-1.1 → Apache-2.0 conversion

Auto-conversion date for the Promethean SDK (BSL-1.1 source-available → Apache-2.0). Verifier (verify.mjs) is already Apache-2.0.

Related

Each regulation here is indexed with its full citation + official source URL on the citations index. For sector-specific impact + Promethean evidence mapping, see the industries hub. For framework-template details (GDPR / AI Act / PSD3 / DORA / NIS 2 / MDR / HIPAA mapping), see the framework templates section on /regulators.

Timeline is updated when new regulations land or applicability dates change. Last update: 15 May 2026.