Regulator watch

What regulators + courts have actually done.

Curated feed of 25 dated events relevant to AI compliance. Court rulings, agency guidance, enforcement actions, regulation milestones. Every entry has a date + a primary or authoritative secondary source URL. No commentary, no spin. We update this when material new guidance lands.

Note: Not exhaustive — best-effort coverage with a focus on high-signal AI + data-protection + cybersecurity events from 2020 onward. If we missed something material, email regulators@promethean.software.

2026

  • 2 Aug 2026

    Regulation milestone

    European Union

    AI Act high-risk obligations applicable

    Annex III high-risk AI systems must comply with Chapter II obligations (Articles 9-15: risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy + robustness + cybersecurity). Conformity-assessment + CE-marking requirements operative.

    Primary source ↗

2025

  • 15 Nov 2025

    Regulation milestone

    European Parliament + Council

    PSD3 + PSR trilogue political agreement

    Provisional political agreement reached on the proposed payment-services package (PSR COM(2023) 366 + PSD3 COM(2023) 367). OJ publication expected H1 2026. PSR applies ~20 days post-publication; PSD3 transposition ~18 months. AI-driven fraud + SCA exemption articles confirmed in the PSR.

    Primary source ↗
    Sectors: FintechRegs: PSD3 + PSR
  • 1 Nov 2025

    Regulator guidance

    European Commission + EU AI Office

    AI Office operational guidance + first national-AI-authority designations

    The European AI Office (within the Commission) issues first operational guidance under the AI Act. National competent authorities designated by member states (mostly the existing DPA, sometimes a sector regulator). Cross-border coordination procedures formalised.

    Primary source ↗
    Regs: EU AI Act
  • 1 Sept 2025

    Regulation milestone

    Texas Legislature

    Texas SB 1188 (89R) effective — AI-use disclosure in healthcare

    Healthcare practitioners using AI for diagnostic purposes must disclose AI use to patients, operate within scope of licence, review AI-generated records per Texas Medical Board standards. EHR data-localization provision effective 1 January 2026.

    Primary source ↗
    Sectors: Healthtech
  • 2 Aug 2025

    Regulation milestone

    European Union

    AI Act Chapter V applies — GPAI obligations effective

    General-purpose AI model providers must maintain technical documentation, training-data summary, copyright policy. National competent authorities designated. GPAI Code of Practice published shortly before this date; voluntary adherence begins.

    Primary source ↗
    Regs: EU AI Act
  • 2 Feb 2025

    Regulation milestone

    European Union

    AI Act Chapter II applies — Art. 5 prohibited practices effective

    Prohibitions on: social scoring, manipulative subliminal techniques, untargeted scraping for biometric databases, emotion recognition in workplace + education (with medical/safety exceptions), real-time remote biometric ID by law enforcement (narrow exceptions). AI-literacy obligations also begin.

    Primary source ↗
    Sectors: HR Tech · EdTechRegs: EU AI Act
  • 17 Jan 2025

    Regulation milestone

    European Union

    DORA becomes applicable

    Regulation (EU) 2022/2554 applies from this date. Financial entities must have ICT risk-management framework + register of contractual arrangements + incident-classification process. First CTPP designations expected through 2025-2026.

    Primary source ↗
    Sectors: Fintech · InsurTech · CybersecurityRegs: DORA
  • 6 Jan 2025

    Regulator guidance

    US HHS OCR

    HIPAA Security Rule Notice of Proposed Rulemaking

    First substantive modernisation of the HIPAA Security Rule since 2013. Proposes removing addressable/required distinction, mandatory encryption, MFA, asset inventory + network mapping, vulnerability management with response timelines. Final rule expected late 2025 / 2026.

    Primary source ↗
    Sectors: HealthtechRegs: HIPAA

2024

  • 26 Dec 2024

    Regulator guidance

    European Data Protection Board

    EDPB Opinion 28/2024 on AI models + personal data

    Opinion on the use of personal data in the development + deployment of AI models. Addresses lawful-basis questions (legitimate interests for training), accountability + transparency obligations, anonymity claims for models trained on personal data. Influences national-DPA enforcement practice.

    Primary source ↗
    Sectors: AdTech · HR Tech · EdTechRegs: GDPR
  • 3 Dec 2024

    Regulator guidance

    US FDA

    FDA PCCP Final Guidance

    Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence-Enabled Device Software Functions. Allows planned model updates within a pre-approved envelope. Reduces friction for AI-incorporating SaMD post-clearance.

    Primary source ↗
    Sectors: Healthtech
  • 17 Oct 2024

    Regulation milestone

    European Union

    NIS2 transposition deadline

    Directive (EU) 2022/2555 transposition deadline. Most member states transposed on time; a handful slipped (the Commission has opened infringement proceedings against late states). NIS2 measures apply from 18 October 2024 in transposing states.

    Primary source ↗
  • 28 Sept 2024

    Regulation milestone

    California — Governor Newsom

    California SB 1120 signed (Physicians Make Decisions Act)

    Prohibits health-plan insurers from using algorithms as the sole basis for denying or modifying medically necessary care in utilization-review decisions. Requires licensed clinician review of AI-assisted UR decisions. Effective 1 January 2025.

    Primary source ↗
    Sectors: Healthtech · InsurTech
  • 29 Jul 2024

    Regulator guidance

    American Bar Association

    ABA Formal Opinion 512 — Generative AI tools

    First ABA-level ethics opinion on attorney use of generative AI. Covers competence, confidentiality, communication, candour to tribunal, supervision, and reasonable fees. Sets baseline national-level guidance that state-bar opinions are building on.

    Primary source ↗
    Sectors: LegalTech
  • 12 Jul 2024

    Official publication

    European Union

    EU AI Act published in the Official Journal

    Regulation (EU) 2024/1689 published in OJ L 2024/1689. Entry into force 1 August 2024 (20 days after publication). Phased applicability: Art. 5 prohibitions Feb 2025, GPAI Aug 2025, high-risk Annex III Aug 2026, Art. 6(1) extended Aug 2027.

    Primary source ↗
    Regs: EU AI Act
  • 8 May 2024

    Regulation milestone

    European Union

    REMIT II enters into force

    Regulation (EU) 2024/1106 amending REMIT (Reg. 1227/2011). Expanded scope to intraday markets + new product types. New algorithmic-trading-notification + documentation obligations. Enhanced ACER powers including direct on-site inspections.

    Primary source ↗
    Sectors: EnergyRegs: REMIT
  • 2 May 2024

    Regulator guidance

    US HUD

    HUD guidance on AI + algorithm-based tenant screening

    Two guidance documents on algorithmic tenant screening + housing advertising. Reiterates that the Fair Housing Act's disparate-impact doctrine (24 CFR §100.500) applies to AI-driven housing decisions. Cited extensively in subsequent tenant-screening class actions.

    Primary source ↗
    Sectors: PropTech
  • 9 Apr 2024

    Official publication

    European Union

    eIDAS 2 adopted (Regulation (EU) 2024/1183)

    Revised eIDAS framework introducing the European Digital Identity Wallet (EUDIW). Member states must offer the wallet to citizens by end of 2026; mandatory acceptance by regulated relying parties from 21 November 2027. Major govtech + fintech integration milestone.

    Primary source ↗
    Sectors: Govtech · Fintech · HealthtechRegs: eIDAS
  • 17 Jan 2024

    Regulator guidance

    US CMS

    CMS Interoperability + Prior Authorization Final Rule (CMS-0057-F)

    Payers must publish prior-auth metrics, support FHIR-based PA APIs, and provide decisioning rationale. Phased compliance: prior-auth process + metrics 1 January 2026; API requirements 1 January 2027.

    Primary source ↗
    Sectors: Healthtech

2023

  • 7 Dec 2023

    Court ruling

    Court of Justice of the European Union

    CJEU C-634/21 (SCHUFA Holding) — automated scoring is Art. 22

    An automated probability value (credit score) is itself a solely-automated decision under GDPR Art. 22(1) when the third party who receives it 'draws strongly on' the value to establish/implement/terminate a contractual relationship. Materially expands Art. 22 scope.

    Primary source ↗
    Sectors: Fintech · HR Tech · InsurTech · PropTechRegs: GDPR
  • 28 Sept 2023

    Regulator guidance

    EIOPA

    EIOPA supervisory statement on differentiated pricing

    Concerns flagged on price walking, post-renewal inertia uplifts, AI-driven personalisation that disproportionately affects vulnerable consumers. Pricing-AI scrutinised under IDD Art. 25 POG + Solvency II governance.

    Primary source ↗
    Sectors: InsurTechRegs: IDD
  • 5 Jul 2023

    Regulation milestone

    New York City

    NYC Local Law 144 (AEDT) enforcement begins

    Employers using Automated Employment Decision Tools in NYC must conduct annual bias audits + provide candidate notice. Audit results must be publicly published. Enforcement delayed from January 2023.

    Primary source ↗
    Sectors: HR Tech
  • 18 May 2023

    Regulator guidance

    US EEOC

    EEOC technical assistance on AI in hiring

    'Select Issues: Assessing Adverse Impact in Software, Algorithms, and Artificial Intelligence Used in Employment Selection Procedures Under Title VII'. Establishes that employers using AI in selection remain responsible for disparate-impact compliance — vendor validation does not shift employer liability.

    Primary source ↗
    Sectors: HR Tech
  • 31 Mar 2023

    Regulator guidance

    US HUD

    HUD Discriminatory Effects Standard reinstated (24 CFR §100.500)

    Final rule reinstating the 2013 disparate-impact test (replaced under prior administration). Confirms that practices with disparate effect on protected classes are unlawful under FHA unless justified by legitimate non-discriminatory interest that cannot be served by less discriminatory alternative.

    Primary source ↗
    Sectors: PropTech

2021

  • 17 Jun 2021

    Regulator guidance

    EIOPA

    EIOPA AI Governance Principles published

    Supervisory expectations on AI use in insurance: explainability, fairness/non-discrimination, governance, robustness, oversight + control. Reference document for national-supervisor AI inspections in insurtech.

    Primary source ↗
    Sectors: InsurTechRegs: IDD

2020

  • 5 Feb 2020

    Court ruling

    Hague District Court (Netherlands)

    NJCM v The Netherlands — SyRI welfare-fraud algorithm struck down

    The Dutch welfare-fraud risk-detection algorithm SyRI violated Art. 8 ECHR because the legislation underpinning it failed to give sufficient safeguards against arbitrary interference with private life. Landmark European precedent on public-sector algorithmic governance.

    Primary source ↗
    Sectors: GovtechRegs: GDPR