Regulator watch
What regulators + courts have actually done.
Curated feed of 25 dated events relevant to AI compliance. Court rulings, agency guidance, enforcement actions, regulation milestones. Every entry has a date + a primary or authoritative secondary source URL. No commentary, no spin. We update this when material new guidance lands.
Note: Not exhaustive — best-effort coverage with a focus on high-signal AI + data-protection + cybersecurity events from 2020 onward. If we missed something material, email regulators@promethean.software.
2026
2 Aug 2026
Regulation milestone
European Union
AI Act high-risk obligations applicable
Annex III high-risk AI systems must comply with Chapter II obligations (Articles 9-15: risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy + robustness + cybersecurity). Conformity-assessment + CE-marking requirements operative.
Primary source ↗
2025
15 Nov 2025
Regulation milestone
European Parliament + Council
PSD3 + PSR trilogue political agreement
Provisional political agreement reached on the proposed payment-services package (PSR COM(2023) 366 + PSD3 COM(2023) 367). OJ publication expected H1 2026. PSR applies ~20 days post-publication; PSD3 transposition ~18 months. AI-driven fraud + SCA exemption articles confirmed in the PSR.
Primary source ↗Sectors: FintechRegs: PSD3 + PSR1 Nov 2025
Regulator guidance
European Commission + EU AI Office
AI Office operational guidance + first national-AI-authority designations
The European AI Office (within the Commission) issues first operational guidance under the AI Act. National competent authorities designated by member states (mostly the existing DPA, sometimes a sector regulator). Cross-border coordination procedures formalised.
Primary source ↗Regs: EU AI Act1 Sept 2025
Regulation milestone
Texas Legislature
Texas SB 1188 (89R) effective — AI-use disclosure in healthcare
Healthcare practitioners using AI for diagnostic purposes must disclose AI use to patients, operate within scope of licence, review AI-generated records per Texas Medical Board standards. EHR data-localization provision effective 1 January 2026.
Primary source ↗Sectors: Healthtech2 Aug 2025
Regulation milestone
European Union
AI Act Chapter V applies — GPAI obligations effective
General-purpose AI model providers must maintain technical documentation, training-data summary, copyright policy. National competent authorities designated. GPAI Code of Practice published shortly before this date; voluntary adherence begins.
Primary source ↗Regs: EU AI Act2 Feb 2025
Regulation milestone
European Union
AI Act Chapter II applies — Art. 5 prohibited practices effective
Prohibitions on: social scoring, manipulative subliminal techniques, untargeted scraping for biometric databases, emotion recognition in workplace + education (with medical/safety exceptions), real-time remote biometric ID by law enforcement (narrow exceptions). AI-literacy obligations also begin.
Primary source ↗17 Jan 2025
Regulation milestone
European Union
DORA becomes applicable
Regulation (EU) 2022/2554 applies from this date. Financial entities must have ICT risk-management framework + register of contractual arrangements + incident-classification process. First CTPP designations expected through 2025-2026.
Primary source ↗Sectors: Fintech · InsurTech · CybersecurityRegs: DORA6 Jan 2025
Regulator guidance
US HHS OCR
HIPAA Security Rule Notice of Proposed Rulemaking
First substantive modernisation of the HIPAA Security Rule since 2013. Proposes removing addressable/required distinction, mandatory encryption, MFA, asset inventory + network mapping, vulnerability management with response timelines. Final rule expected late 2025 / 2026.
Primary source ↗Sectors: HealthtechRegs: HIPAA
2024
26 Dec 2024
Regulator guidance
European Data Protection Board
EDPB Opinion 28/2024 on AI models + personal data
Opinion on the use of personal data in the development + deployment of AI models. Addresses lawful-basis questions (legitimate interests for training), accountability + transparency obligations, anonymity claims for models trained on personal data. Influences national-DPA enforcement practice.
Primary source ↗3 Dec 2024
Regulator guidance
US FDA
FDA PCCP Final Guidance
Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence-Enabled Device Software Functions. Allows planned model updates within a pre-approved envelope. Reduces friction for AI-incorporating SaMD post-clearance.
Primary source ↗Sectors: Healthtech17 Oct 2024
Regulation milestone
European Union
NIS2 transposition deadline
Directive (EU) 2022/2555 transposition deadline. Most member states transposed on time; a handful slipped (the Commission has opened infringement proceedings against late states). NIS2 measures apply from 18 October 2024 in transposing states.
Primary source ↗Sectors: Cybersecurity · Energy · Fintech · Govtech · HealthtechRegs: NIS228 Sept 2024
Regulation milestone
California — Governor Newsom
California SB 1120 signed (Physicians Make Decisions Act)
Prohibits health-plan insurers from using algorithms as the sole basis for denying or modifying medically necessary care in utilization-review decisions. Requires licensed clinician review of AI-assisted UR decisions. Effective 1 January 2025.
Primary source ↗Sectors: Healthtech · InsurTech29 Jul 2024
Regulator guidance
American Bar Association
ABA Formal Opinion 512 — Generative AI tools
First ABA-level ethics opinion on attorney use of generative AI. Covers competence, confidentiality, communication, candour to tribunal, supervision, and reasonable fees. Sets baseline national-level guidance that state-bar opinions are building on.
Primary source ↗Sectors: LegalTech12 Jul 2024
Official publication
European Union
EU AI Act published in the Official Journal
Regulation (EU) 2024/1689 published in OJ L 2024/1689. Entry into force 1 August 2024 (20 days after publication). Phased applicability: Art. 5 prohibitions Feb 2025, GPAI Aug 2025, high-risk Annex III Aug 2026, Art. 6(1) extended Aug 2027.
Primary source ↗Regs: EU AI Act8 May 2024
Regulation milestone
European Union
REMIT II enters into force
Regulation (EU) 2024/1106 amending REMIT (Reg. 1227/2011). Expanded scope to intraday markets + new product types. New algorithmic-trading-notification + documentation obligations. Enhanced ACER powers including direct on-site inspections.
Primary source ↗2 May 2024
Regulator guidance
US HUD
HUD guidance on AI + algorithm-based tenant screening
Two guidance documents on algorithmic tenant screening + housing advertising. Reiterates that the Fair Housing Act's disparate-impact doctrine (24 CFR §100.500) applies to AI-driven housing decisions. Cited extensively in subsequent tenant-screening class actions.
Primary source ↗Sectors: PropTech9 Apr 2024
Official publication
European Union
eIDAS 2 adopted (Regulation (EU) 2024/1183)
Revised eIDAS framework introducing the European Digital Identity Wallet (EUDIW). Member states must offer the wallet to citizens by end of 2026; mandatory acceptance by regulated relying parties from 21 November 2027. Major govtech + fintech integration milestone.
Primary source ↗Sectors: Govtech · Fintech · HealthtechRegs: eIDAS17 Jan 2024
Regulator guidance
US CMS
CMS Interoperability + Prior Authorization Final Rule (CMS-0057-F)
Payers must publish prior-auth metrics, support FHIR-based PA APIs, and provide decisioning rationale. Phased compliance: prior-auth process + metrics 1 January 2026; API requirements 1 January 2027.
Primary source ↗Sectors: Healthtech
2023
7 Dec 2023
Court ruling
Court of Justice of the European Union
CJEU C-634/21 (SCHUFA Holding) — automated scoring is Art. 22
An automated probability value (credit score) is itself a solely-automated decision under GDPR Art. 22(1) when the third party who receives it 'draws strongly on' the value to establish/implement/terminate a contractual relationship. Materially expands Art. 22 scope.
Primary source ↗28 Sept 2023
Regulator guidance
EIOPA
EIOPA supervisory statement on differentiated pricing
Concerns flagged on price walking, post-renewal inertia uplifts, AI-driven personalisation that disproportionately affects vulnerable consumers. Pricing-AI scrutinised under IDD Art. 25 POG + Solvency II governance.
Primary source ↗5 Jul 2023
Regulation milestone
New York City
NYC Local Law 144 (AEDT) enforcement begins
Employers using Automated Employment Decision Tools in NYC must conduct annual bias audits + provide candidate notice. Audit results must be publicly published. Enforcement delayed from January 2023.
Primary source ↗Sectors: HR Tech18 May 2023
Regulator guidance
US EEOC
EEOC technical assistance on AI in hiring
'Select Issues: Assessing Adverse Impact in Software, Algorithms, and Artificial Intelligence Used in Employment Selection Procedures Under Title VII'. Establishes that employers using AI in selection remain responsible for disparate-impact compliance — vendor validation does not shift employer liability.
Primary source ↗Sectors: HR Tech31 Mar 2023
Regulator guidance
US HUD
HUD Discriminatory Effects Standard reinstated (24 CFR §100.500)
Final rule reinstating the 2013 disparate-impact test (replaced under prior administration). Confirms that practices with disparate effect on protected classes are unlawful under FHA unless justified by legitimate non-discriminatory interest that cannot be served by less discriminatory alternative.
Primary source ↗Sectors: PropTech
2021
17 Jun 2021
Regulator guidance
EIOPA
EIOPA AI Governance Principles published
Supervisory expectations on AI use in insurance: explainability, fairness/non-discrimination, governance, robustness, oversight + control. Reference document for national-supervisor AI inspections in insurtech.
Primary source ↗
2020
5 Feb 2020
Court ruling
Hague District Court (Netherlands)
NJCM v The Netherlands — SyRI welfare-fraud algorithm struck down
The Dutch welfare-fraud risk-detection algorithm SyRI violated Art. 8 ECHR because the legislation underpinning it failed to give sufficient safeguards against arbitrary interference with private life. Landmark European precedent on public-sector algorithmic governance.
Primary source ↗