— Resource · Data compliance deadlines
Data and AI compliance deadlines, 2026 to 2028.
One page with the dates that create work for data, security and AI teams: automated-decision rules, AI transparency, breach notices and log review. Every date links to its source. Last checked 1 October 2026.
— Coming up · Next deadlines
What is coming next.
| Date | Rule | What changes | Source |
|---|---|---|---|
| 2 Dec 2026 | EU AI Act, Article 50(2) | End of the grace period for marking AI-generated content, only for systems on the market before 2 Aug 2026 | European Commission |
| 1 Jan 2027 | Colorado SB 26-189 | Automated decision-making law takes effect; Attorney General rules due the same day | Colorado General Assembly |
| 1 Jan 2027 | California CCPA regulations (ADMT) | Notice, opt-out and access for automated decision-making used in significant decisions (as reported) | CPPA |
| Jul 2027 (target) | HIPAA Security Rule update | Still a proposed rule; the federal regulatory agenda targets final action around mid-2027 | HHS proposed rule, Jan 2025 (as reported) |
| 2 Dec 2027 | EU AI Act, Annex III high-risk | Obligations for high-risk systems such as employment and credit uses, after the Digital Omnibus delay | EUR-Lex |
| 31 Dec 2027 | California CCPA risk assessments | Risk assessments for ongoing high-risk processing completed; summary to the CPPA by 1 Apr 2028 (as reported) | CPPA |
| 1 Apr 2028 to 2030 | California cybersecurity audits | Audit certification phased by revenue: over $100M in 2028, $50M to $100M in 2029, under $50M in 2030 (as reported) | CPPA |
| 2 Aug 2028 | EU AI Act, Annex I high-risk | Obligations for AI that is a safety component of already-regulated products | EUR-Lex |
“As reported” means the date is consistently reported by several law firms or assessors, but we could not open the regulator’s own text directly when checking. Confirm with counsel before relying on it.
— Already in force · Rules that apply now
Already in force, and what they ask data teams for.
| Rule | Since | What it requires | Data evidence it needs |
|---|---|---|---|
| PCI DSS v4.0.1, Req. 10.4.1.1 and 10.5.1 | Since 31 Mar 2025 | Automated review of security-relevant logs; 12 months of audit log history, the latest 3 months immediately available (as reported by multiple PCI assessors) | Security data lake, automated review, retention |
| SEC Regulation S-P (amended) | Larger entities 3 Dec 2025; smaller 3 Jun 2026 | Incident response programme and customer notice no later than 30 days after becoming aware of unauthorized access | Customer data inventory, lineage, access logs |
| SEC Form 8-K Item 1.05 | In force | Material cybersecurity incidents disclosed within four business days of the materiality determination | Incident evidence and timeline from logs |
| EU AI Act, Article 50 | Since 2 Aug 2026 | Transparency: people must know when they interact with AI, and AI-generated content is labelled | Records of where AI is used and disclosed |
| EU AI Act, Digital Omnibus | In force 27 Jul 2026 | Regulation (EU) 2026/1744 moved the high-risk dates to 2 Dec 2027 and 2 Aug 2028 | Plan the high-risk evidence now |
| DORA | Applicable since 17 Jan 2025 | ICT risk and resilience rules for EU financial entities | Incident and third-party risk records |
| NIS2 | Transposition deadline 17 Oct 2024 | EU cybersecurity directive; obligations depend on each member state’s national law | Security logging and incident reporting |
| CMMC | Phase 1 since 10 Nov 2025; Phase 2 suspended 13 Jul 2026 | Self-assessment requirements in defense contracts; third-party certification phase on hold pending review (as reported) | Access control and audit evidence |
Some frameworks are voluntary but increasingly expected: the NIST AI Risk Management Framework (January 2023) and its Generative AI Profile (July 2024), NIST’s AI Agent Standards Initiative launched in February 2026, and the OWASP Top 10 for Agentic Applications (December 2025). None of them is law, but they are what assessors and customers increasingly ask about.
— The pattern · One layer, many rules
Different rules. The same five pieces of evidence.
- Inventory: what data you hold, where, and who owns it.
- Lineage: where regulated data came from and where it went.
- Access: who and which AI agents can read it, and why.
- Decision records: inputs, model version, outcome and human review for automated decisions.
- Audit logs: kept as long as each rule requires and reviewed automatically.
A governed lakehouse produces all five from one place, instead of a separate project per regulation. That is what our AI governance and compliance work builds. For the security log side, see lakehouse security.
This page is general information, not legal advice. Your counsel or a qualified assessor decides how a rule applies to your business.
— Straight answers · FAQ
Questions we get asked first.
How often is this page updated?
We check the dates whenever a rule changes and at least monthly. The date at the top of the page shows the last check.
Why does it say “as reported” on some rows?
For those rows we could not open the regulator’s own document directly when checking, so we rely on consistent reporting from several law firms or assessors. Treat them as reliable but confirm with counsel before acting.
Is the EU AI Act transparency rule delayed to December 2026?
Not in general. Article 50’s transparency obligations have applied since 2 August 2026. The December 2026 date is a narrow grace period for marking AI-generated content, and only for systems already on the market before 2 August 2026.
Does a lakehouse make us compliant?
No tool does. A governed lakehouse produces the evidence these rules ask for: inventory, lineage, access controls, decision records and reviewed logs. Your counsel and assessors decide whether that meets the requirement.
Know your dates. Now build the evidence.
One call, your systems and the rules that apply on the table, and a straight read on what evidence you can already produce.
