— Resource · Data compliance deadlines

Data and AI compliance deadlines, 2026 to 2028.

One page with the dates that create work for data, security and AI teams: automated-decision rules, AI transparency, breach notices and log review. Every date links to its source. Last checked 1 October 2026.

Data Compliance Deadlines: compliance calendar planning with data and legal teams

— Coming up · Next deadlines

What is coming next.

Date Rule What changes Source
2 Dec 2026 EU AI Act, Article 50(2) End of the grace period for marking AI-generated content, only for systems on the market before 2 Aug 2026 European Commission
1 Jan 2027 Colorado SB 26-189 Automated decision-making law takes effect; Attorney General rules due the same day Colorado General Assembly
1 Jan 2027 California CCPA regulations (ADMT) Notice, opt-out and access for automated decision-making used in significant decisions (as reported) CPPA
Jul 2027 (target) HIPAA Security Rule update Still a proposed rule; the federal regulatory agenda targets final action around mid-2027 HHS proposed rule, Jan 2025 (as reported)
2 Dec 2027 EU AI Act, Annex III high-risk Obligations for high-risk systems such as employment and credit uses, after the Digital Omnibus delay EUR-Lex
31 Dec 2027 California CCPA risk assessments Risk assessments for ongoing high-risk processing completed; summary to the CPPA by 1 Apr 2028 (as reported) CPPA
1 Apr 2028 to 2030 California cybersecurity audits Audit certification phased by revenue: over $100M in 2028, $50M to $100M in 2029, under $50M in 2030 (as reported) CPPA
2 Aug 2028 EU AI Act, Annex I high-risk Obligations for AI that is a safety component of already-regulated products EUR-Lex

“As reported” means the date is consistently reported by several law firms or assessors, but we could not open the regulator’s own text directly when checking. Confirm with counsel before relying on it.

— Already in force · Rules that apply now

Already in force, and what they ask data teams for.

Rule Since What it requires Data evidence it needs
PCI DSS v4.0.1, Req. 10.4.1.1 and 10.5.1 Since 31 Mar 2025 Automated review of security-relevant logs; 12 months of audit log history, the latest 3 months immediately available (as reported by multiple PCI assessors) Security data lake, automated review, retention
SEC Regulation S-P (amended) Larger entities 3 Dec 2025; smaller 3 Jun 2026 Incident response programme and customer notice no later than 30 days after becoming aware of unauthorized access Customer data inventory, lineage, access logs
SEC Form 8-K Item 1.05 In force Material cybersecurity incidents disclosed within four business days of the materiality determination Incident evidence and timeline from logs
EU AI Act, Article 50 Since 2 Aug 2026 Transparency: people must know when they interact with AI, and AI-generated content is labelled Records of where AI is used and disclosed
EU AI Act, Digital Omnibus In force 27 Jul 2026 Regulation (EU) 2026/1744 moved the high-risk dates to 2 Dec 2027 and 2 Aug 2028 Plan the high-risk evidence now
DORA Applicable since 17 Jan 2025 ICT risk and resilience rules for EU financial entities Incident and third-party risk records
NIS2 Transposition deadline 17 Oct 2024 EU cybersecurity directive; obligations depend on each member state’s national law Security logging and incident reporting
CMMC Phase 1 since 10 Nov 2025; Phase 2 suspended 13 Jul 2026 Self-assessment requirements in defense contracts; third-party certification phase on hold pending review (as reported) Access control and audit evidence

Some frameworks are voluntary but increasingly expected: the NIST AI Risk Management Framework (January 2023) and its Generative AI Profile (July 2024), NIST’s AI Agent Standards Initiative launched in February 2026, and the OWASP Top 10 for Agentic Applications (December 2025). None of them is law, but they are what assessors and customers increasingly ask about.

— The pattern · One layer, many rules

Different rules. The same five pieces of evidence.

  1. Inventory: what data you hold, where, and who owns it.
  2. Lineage: where regulated data came from and where it went.
  3. Access: who and which AI agents can read it, and why.
  4. Decision records: inputs, model version, outcome and human review for automated decisions.
  5. Audit logs: kept as long as each rule requires and reviewed automatically.

A governed lakehouse produces all five from one place, instead of a separate project per regulation. That is what our AI governance and compliance work builds. For the security log side, see lakehouse security.

This page is general information, not legal advice. Your counsel or a qualified assessor decides how a rule applies to your business.

— Straight answers · FAQ

Questions we get asked first.

How often is this page updated?

We check the dates whenever a rule changes and at least monthly. The date at the top of the page shows the last check.

Why does it say “as reported” on some rows?

For those rows we could not open the regulator’s own document directly when checking, so we rely on consistent reporting from several law firms or assessors. Treat them as reliable but confirm with counsel before acting.

Is the EU AI Act transparency rule delayed to December 2026?

Not in general. Article 50’s transparency obligations have applied since 2 August 2026. The December 2026 date is a narrow grace period for marking AI-generated content, and only for systems already on the market before 2 August 2026.

Does a lakehouse make us compliant?

No tool does. A governed lakehouse produces the evidence these rules ask for: inventory, lineage, access controls, decision records and reviewed logs. Your counsel and assessors decide whether that meets the requirement.

Know your dates. Now build the evidence.

One call, your systems and the rules that apply on the table, and a straight read on what evidence you can already produce.