Contacts
1207 Delaware Avenue, Suite 1228 Wilmington, DE 19806
Let's discuss your project
Business Address: 1207 Delaware Avenue, Suite 1228 Wilmington, DE 19806

AI Regulation Tracker 2026: Every Binding AI Law, Rule and Order, Sourced and Dated

AI Regulation Tracker 2026

Last updated: August 13, 2026, 14:00 UTC — Update frequency: weekly, plus same-week entry for any binding instrument that takes effect or is signed · Entries: 12 | Maintained by: Axis Intelligence Research & Sarah Mitchell

Every row in this tracker carries a link to the instrument itself — an official journal, a legislature’s bill record, an executive order, a regulator’s own publication. Where we could not fetch the primary document, the row says so and stays flagged rather than being quietly filled in. Three rows currently carry a flag.

Quick Answer

As of August 13, 2026, twelve binding or agenda-setting AI instruments are tracked across four jurisdictions. The EU AI Act’s Article 50 transparency duties and the AI Office’s enforcement powers over general-purpose AI providers became applicable on August 2, 2026. Axis Intelligence Research finds a median Regulatory Enactment-to-Enforcement Lag™ of 232 days across the seven binding instruments where both dates are documented.

Key Findings

  1. According to the European Commission, the AI Office’s supervision and enforcement powers over general-purpose AI model providers became applicable on 2 August 2026, two years after the AI Act entered into force.
  2. The AI Omnibus Regulation entered into force on 27 July 2026 and moved Annex III high-risk obligations to 2 December 2027 and Annex I embedded-product obligations to 2 August 2028.
  3. Colorado’s SB 24-205, the first comprehensive US state AI law, was repealed and reenacted by SB 26-189 on 14 May 2026 before it ever took effect.
  4. Executive Order 14365, signed 11 December 2025, directs the Attorney General to establish an AI Litigation Task Force whose sole responsibility is challenging state AI laws.
  5. Axis Intelligence Research finds an inaugural median Regulatory Enactment-to-Enforcement Lag™ of 232 days (n=7, range 94 to 731 days) across binding AI instruments tracked as of 13 August 2026.

The Axis Metric: Regulatory Enactment-to-Enforcement Lag™ (REEL™)

What it measures. The number of days between the date a binding AI instrument enters into force and the date its obligations become applicable to private parties.

Formula. REEL = obligation_applicable_date − entry_into_force_date, in calendar days, computed per entry. The published reading is the median across all rows where reel_computable = yes.

Why it exists. “When does this law take effect?” has become an unusually bad question, because for most AI instruments there are two answers. The statute is live, and the duties are not. A compliance team reading only the entry-into-force date budgets for the wrong quarter; a team reading only the applicability date misses that obligations may already bind them without a regulator able to act. REEL puts a number on that gap, per instrument, and makes it comparable across jurisdictions.

Inaugural baseline, as of 13 August 2026. Median 232 days. n=7. Mean 305.6 days. Range 94 to 731 days.

EntryInstrumentInto forceObligations applyREEL (days)
AXR-011California SB 53 (TFAIA)2025-09-292026-01-0194
AXR-004China, anthropomorphic AI interim measures2026-04-102026-07-1596
AXR-007Connecticut PA 26-15 (SB 5)2026-05-272026-10-01127
AXR-008Colorado SB 26-1892026-05-142027-01-01232
AXR-010Korea AI Framework Act2025-01-212026-01-22366
AXR-002EU AI Omnibus (Annex III tranche)2026-07-272027-12-02493
AXR-001EU AI Act, Art. 50 and Chapter V enforcement2024-08-012026-08-02731

Source: Axis Intelligence Research, computed from ai-regulation-tracker.csv, 13 August 2026. Per-row primary sources are in the CSV.

This is a baseline reading. No prior reading exists, and no historical comparison is implied or available.

What REEL does not capture. It ignores tranches within a single instrument beyond the first private-party obligation date — the EU Omnibus, for example, has a second tranche running to 2 August 2028 that is recorded in the CSV but not double-counted in the median. It says nothing about enforcement intensity once the date arrives. And a short lag is not the same as a strict regime: China’s 96 days sit on top of an existing filing pipeline that already carried the compliance machinery, which is a large part of why the runway could be short.

What Changed on August 2, 2026 in the EU?

Two things became applicable at once, and a third did not.

Article 50 transparency duties — informing people they are interacting with a machine, and marking AI-generated content — came into effect, and from 2 August 2026 the AI Office and Member State authorities became responsible for implementing, supervising and enforcing the AI Act, with the AI Office holding enforcement powers over GPAI models including the power to request technical documentation, evaluate models, require corrective measures and issue fines.

The GPAI obligations themselves are not new. The AI Act’s rules on general-purpose AI models became effective in August 2025. What arrived a year later was the machinery to act on them. That one-year offset is the single largest REEL contributor in the table and the reason so many 2025 compliance decks read as though nothing was in force.

What did not arrive: high-risk obligations. The AI Omnibus, adopted 19 November 2025, reaching political agreement on 7 May 2026 and entering into force on 27 July 2026, moved high-risk use cases in sensitive areas including biometrics, critical infrastructure, education, employment and border control to 2 December 2027, and systems integrated into products such as lifts or toys to 2 August 2028.

The Omnibus also added obligations rather than only deferring them. It introduced a prohibition on AI systems that generate non-consensual sexually explicit content or child sexual abuse material, such as nudification apps, taking effect in December 2026, and reinforced the AI Office’s powers by centralising oversight of AI systems built on GPAI models. “Delay” is the wrong summary of a regulation that added a ninth prohibition and expanded the supervisor’s reach.

What Is the US Federal Position on State AI Laws?

There is no federal AI statute. There is an executive strategy aimed at the states, and it is explicit about it.

Executive Order 14365, signed 11 December 2025, directs the Attorney General to establish an AI Litigation Task Force within 30 days whose sole responsibility is to challenge state AI laws inconsistent with the order’s policy, including on the grounds that they unconstitutionally regulate interstate commerce or are preempted by federal regulation. It directs Commerce to publish an evaluation of onerous state AI laws within 90 days and to condition BEAD non-deployment funds on states not appearing in it. It directs the FCC Chairman to open a proceeding on whether to adopt a preemptive federal reporting and disclosure standard, and the FTC Chairman to issue a policy statement on when state laws requiring alterations to truthful model outputs are preempted by the FTC Act’s deception prohibition.

The order names its targets. Its purpose section identifies a Colorado law banning algorithmic discrimination as an example of state regulation that may force models to produce false results.

It also names its exclusions, which matter more than the naming of targets for anyone forecasting the shape of a federal bill. The legislative recommendation the order commissions is directed not to propose preempting state laws on child safety protections, AI compute and data centre infrastructure other than generally applicable permitting reform, or state government procurement and use of AI. That is a carve-out list, and carve-out lists are where negotiated federal frameworks usually land.

A second order followed. Executive Order 14409, signed 2 June 2026, is a security instrument rather than a preemption one: it directs a classified benchmarking process to determine the threshold at which a model is designated a “covered frontier model,” and a voluntary framework under which developers could give the federal government access for up to 30 days before release. Section 3(c) states plainly that nothing in it authorises a mandatory licensing, preclearance, or permitting requirement for releasing new models. The distinction between a voluntary pre-release access framework and a licensing regime is the whole design of that section, and it is worth reading before treating the order as a gate.

Which US States Have Binding AI Obligations?

Three tracked so far, with a fourth that was repealed before it bit.

California. SB 53, the Transparency in Frontier Artificial Intelligence Act, took effect 1 January 2026. Every frontier developer must publish a transparency report before deploying a frontier model. Critical safety incidents go to Cal OES within 15 days — or 24 hours where there is imminent risk of death or serious physical injury. A frontier model is one trained using more than 10^26 integer or floating-point operations, the same threshold Korea uses for high-performance AI and the one the prior federal executive order used.

Connecticut. Public Act 26-15 (SB 5), the Artificial Intelligence Responsibility and Transparency Act, signed 27 May 2026, first provisions effective 1 October 2026. It covers automated employment-related decision technology, AI companion chatbots, content provenance, and whistleblower protections for frontier-developer staff, and it adds an AI-related disclosure to state WARN filings. Enforcement runs through the Attorney General as an unfair or deceptive trade practice; there is no private right of action. This entry carries a source_inconsistency flag — secondary accounts disagree on both the passage date and the signing date, and the Connecticut General Assembly’s bill status system blocks automated retrieval, so we have not confirmed the dates against the record itself.

Colorado. SB 24-205 was the first comprehensive state AI law in the country and never took effect. Its start date moved from 1 February 2026 to 30 June 2026, a federal magistrate stayed enforcement on 27 April 2026 after the Attorney General stipulated to the stay, and on 14 May 2026 Governor Polis signed SB 26-189, which repeals and reenacts the framework entirely. What replaced it is narrower: duties attach to automated decision-making technology that materially influences a consequential decision, and the duty of care, mandatory risk management programmes and impact assessments are gone. Effective 1 January 2027. The stay entry carries a pending_primary flag — we have not yet retrieved the docket or the order.

The Colorado sequence is the one to watch, because it is the first complete cycle: comprehensive state law, industry pressure, federal executive hostility, litigation, stay, replacement statute. Two years from enactment to repeal, with zero days of the original framework in force.

How Is AI Regulated Outside the US and EU?

Korea. The Framework Act on the Development of Artificial Intelligence and Establishment of Trust, Act No. 20676, promulgated 21 January 2025, took effect with its Enforcement Decree on 22 January 2026 — a 366-day runway written into the Act’s own addendum. It applies extraterritorially, with a domestic representative requirement triggered above stated revenue and daily-user thresholds. High-performance AI is designated at cumulative training compute of at least 10^26 FLOPs.

China. The Interim Measures for the Administration of AI Anthropomorphic Interaction Services, promulgated 10 April 2026 by the CAC together with NDRC, MIIT, MPS and SAMR, took effect 15 July 2026. They cover services that simulate a natural person’s personality and provide continuous emotional interaction — virtual companions and emotional-support bots — with disclosure duties, content governance, minor protection and anti-dependency safeguards. This entry carries a pending_primary flag: the official text is Chinese-language only and the CAC URL was located through secondary reporting rather than fetched directly. The 96-day runway is the second shortest in the table, which is what happens when a new obligation layers onto a filing pipeline that already exists rather than requiring one to be built.

Tracker Entries (Reverse Chronological)

2026-08-02 — EU: AI Act Article 50 and GPAI enforcement powers become applicable · AXR-001 Transparency duties under Article 50 apply, and the AI Office and Member State authorities assume supervision and enforcement responsibility. The AI Office can request technical documentation, evaluate models, require corrective measures and issue fines. REEL 731 days. Primary source: European Commission, AI Act

2026-07-27 — EU: AI Omnibus Regulation enters into force · AXR-002 Annex III high-risk obligations move to 2 December 2027; Annex I embedded-product obligations to 2 August 2028. Adds a ninth Article 5 prohibition covering nudification apps and CSAM-generating systems, effective December 2026. Reinforces AI Office powers over vertically integrated providers. REEL 493 days to the Annex III tranche. Primary source: AI Omnibus Regulation, OJ L_202601744

2026-07-20 — EU: Commission publishes Article 50 transparency guidelines · AXR-003 Guidance on scope, definitions, obligations and exceptions for the transparency duties applying from 2 August. Non-binding; excluded from REEL. Primary source: European Commission guidelines

2026-07-15 — China: Interim Measures on AI Anthropomorphic Interaction Services take effect · AXR-004 · pending_primary Disclosure, content governance, minor protection and anti-dependency duties for virtual companion and emotional-interaction services. Jointly issued 10 April 2026 by CAC, NDRC, MIIT, MPS and SAMR. REEL 96 days. Primary source: Cyberspace Administration of China — not directly fetched; Chinese-language only.

2026-07-07 — EU: Commission presents Action Plan on Cybersecurity and AI · AXR-005 Coordinated approach to cybersecurity risks from advanced models, including a call to expand EU model-evaluation capacity expected operational by 2027 and an ENISA secure testing platform for critical sectors. Non-binding; excluded from REEL. Primary source: EU Action Plan on Cybersecurity and Artificial Intelligence

2026-06-02 — US federal: Executive Order 14409 signed · AXR-006 Directs classified benchmarking to define “covered frontier model,” a voluntary framework for up to 30 days of pre-release federal access, a Treasury-led AI cybersecurity clearinghouse, and prioritised DOJ enforcement of computer-crime statutes against AI-enabled intrusion. Section 3(c) disclaims any mandatory licensing or preclearance requirement. Directs agencies, not private parties; excluded from REEL. Primary source: Executive Order 14409

2026-05-27 — Connecticut: Public Act 26-15 (SB 5) signed · AXR-007 · source_inconsistency AEDT disclosure duties, AI companion chatbot rules, content provenance, frontier-developer whistleblower protections, and an AI disclosure added to WARN filings. AG enforcement as an unfair or deceptive trade practice; no private right of action. First provisions effective 1 October 2026. REEL 127 days. Primary source: Connecticut General Assembly, SB 5 bill status — site blocks automated retrieval; dates unconfirmed against the record.

2026-05-14 — Colorado: SB 26-189 signed, repealing and reenacting the Colorado AI Act · AXR-008 Replaces the high-risk system and algorithmic discrimination framework with duties tied to automated decision-making technology that materially influences a consequential decision. Duty of care, risk management programmes and impact assessments removed. Effective 1 January 2027. REEL 232 days. Primary source: Colorado General Assembly, SB26-189

2026-04-27 — Colorado: federal court stays enforcement of the Colorado AI Act · AXR-009 · pending_primary A federal magistrate judge stayed enforcement after the Attorney General stipulated to the stay, weeks before the law’s 30 June 2026 effective date. The statute was repealed and reenacted three weeks later. Primary source: docket and order not yet retrieved. This entry rests on secondary legal reporting and will be upgraded or removed at the next review.

2026-01-22 — Korea: AI Framework Act and Enforcement Decree take effect · AXR-010 Transparency, high-impact AI and generative AI duties with extraterritorial application and a domestic representative requirement above stated thresholds. High-performance AI designated at cumulative training compute of at least 10^26 FLOPs. REEL 366 days. Primary source: Framework Act on the Development of Artificial Intelligence and Establishment of Trust, English translation (CSET)

2026-01-01 — California: SB 53 (TFAIA) takes effect · AXR-011 Transparency report required before deploying a frontier model; critical safety incidents reported to Cal OES within 15 days, or 24 hours where imminent risk of death or serious physical injury exists. Large frontier developers publish a frontier AI framework and transmit catastrophic-risk assessment summaries. Frontier model threshold: more than 10^26 operations of training compute. REEL 94 days. Primary source: California SB-53, chaptered text

2025-12-11 — US federal: Executive Order 14365 signed · AXR-012 Establishes the DOJ AI Litigation Task Force to challenge state AI laws; directs a Commerce evaluation of onerous state laws, BEAD funding conditions, an FCC proceeding on a preemptive federal reporting and disclosure standard, and an FTC policy statement on preemption of state laws requiring alteration of truthful outputs. The commissioned legislative recommendation is directed not to preempt state laws on child safety, compute and data centre infrastructure, or state procurement. Directs agencies, not private parties; excluded from REEL. Primary source: Executive Order 14365 Archive (entries older than the current tracking window)

No archived entries. This tracker launched on 13 August 2026 with a backfill window opening 11 December 2025, the date of Executive Order 14365. Entries will move to this archive twelve months after their entry date.

How We Curate This List

What counts as an entry. A binding AI-specific instrument — statute, regulation, administrative measure, executive order, or court order materially altering enforceability — that is (a) adopted, signed, promulgated, or takes effect, and (b) documented in a fetchable primary source. Formal regulator guidance and government action plans are included where they change how a binding instrument will be applied, and are labelled as non-binding.

What does not count. Introduced bills that have not passed. Draft measures out for consultation. Voluntary codes and industry pledges. Company compliance announcements. Sector-specific rules that regulate an outcome rather than the AI system — an employment discrimination statute applied to a hiring tool is not an AI regulation entry; a statute imposing duties on the hiring tool as such is. Law-firm client alerts and news aggregation are used to locate primary sources and are never the cited source of a fact.

Primary source hierarchy. Official journals and government gazettes; legislature bill records; executive orders published by the issuing government; regulator publications on the regulator’s own domain; official English translations published by a government or a recognised research institution where no official English text exists. Where no primary document can be fetched, the row publishes with a pending_primary flag rather than being filled from secondary reporting.

Verification flags are published, not hidden. pending_primary means we have not fetched the source document. source_inconsistency means credible sources disagree on a date, figure, or status and we have not resolved it against the record. Three of twelve entries currently carry a flag. Flags are cleared only by retrieving the document, never by picking the more common secondary account.

Known fetch constraints. cga.ct.gov blocks automated retrieval, so Connecticut bill records must be confirmed manually. cac.gov.cn publishes in Chinese only. Both constraints are recorded in the affected rows rather than worked around.

REEL™ inclusion rule. REEL is computed only for binding instruments that impose obligations on private parties with a deferred applicability date. Executive orders directing federal agencies are excluded and marked reel_computable = no, as are guidance documents and action plans. Where an instrument has multiple obligation tranches, REEL uses the first private-party applicability date; later tranches are recorded in the CSV but not counted twice.

Corrections. Errors are corrected with a dated note at the bottom of this page. Report one to [email protected].

About This Dataset

ai-regulation-tracker-august-13-2026.csv is the canonical fact table for this page. Every figure in the prose above exists as a row in it, at the same value and the same date. Twelve entry rows plus one metric row, 21 columns, UTF-8, one header row, ISO 8601 dates, long format.

Provenance columns on every row: source_org, source_document, source_url, retrieved_date, is_primary, axis_calculated, verification_flag, method_note.

Temporal coverage: 2025-12-11 to 2026-08-02. Spatial coverage: European Union, United States (federal and state), China, Republic of Korea.

Licence: CC BY 4.0. Cite as: Axis Intelligence Research, AI Regulation Tracker, 2026.

Download the CSV →

Cite This Tracker

APA — Axis Intelligence Research. (2026). AI regulation tracker. https://axis-intelligence.com/ai-regulation-tracker/

MLA — Axis Intelligence Research. “AI Regulation Tracker.” Axis Intelligence Research, 2026, axis-intelligence.com/ai-regulation-tracker/.

Chicago — Axis Intelligence Research. “AI Regulation Tracker.” Accessed August 13, 2026. https://axis-intelligence.com/ai-regulation-tracker/.

Frequently Asked Questions

Is the EU AI Act delayed?

No. One track moved. High-risk obligations under Annex III were pushed to 2 December 2027 and Annex I embedded-product obligations to 2 August 2028 by the AI Omnibus, which entered into force 27 July 2026. Article 50 transparency duties and the AI Office’s GPAI enforcement powers landed on 2 August 2026 as scheduled, and the Omnibus added a new Article 5 prohibition rather than removing one.

What happened to the Colorado AI Act?

SB 24-205 was repealed before it ever took effect. Its effective date moved from 1 February to 30 June 2026, a federal magistrate stayed enforcement on 27 April 2026, and SB 26-189 repealed and reenacted the framework on 14 May 2026. The replacement takes effect 1 January 2027 and drops the duty of care, risk management programmes and impact assessments.

Is there a federal US AI law?

No AI-specific federal statute is tracked here as of 13 August 2026. Federal activity runs through executive orders — EO 14365 on preempting state AI laws and EO 14409 on frontier model security — which direct agencies rather than imposing duties on private parties. Binding US obligations currently sit in state law.

What is the compute threshold that triggers frontier AI obligations?

California SB 53 defines a frontier model at more than 10^26 integer or floating-point operations of training compute. Korea designates high-performance AI at cumulative training compute of at least 10^26 FLOPs. The two thresholds are stated at the same order of magnitude; the definitions of what compute counts differ and should be read in each statute.

How often is this tracker updated?

Weekly, with a same-week entry for any binding instrument that is signed or takes effect. Flagged entries are re-checked at every weekly review. The next scheduled review is 20 August 2026.

Where do the numbers in the monthly recap come from?

Exclusively from ai-regulation-tracker.csv. Monthly Bilan articles recompute every figure from the CSV rows rather than restating prose from this page.

Others Pages

Axis Intelligence Research

Stay ahead on tech & data

Get notified when we publish or update datasets, trackers, research, and reports across technology, business, AI, cybersecurity, finance, infrastructure, energy, and more.

Research updates only. No spam. Unsubscribe anytime.