A status tracker is only useful if it is honest about uncertainty, and honest about resolution once uncertainty clears. The single largest open question this tracker carried for months, whether the Digital Omnibus delay would move the EU AI Act's 2 August 2026 high-risk deadline, is resolved: it moved. The Omnibus entered into force on 27 July 2026, six days before the original date. Annex III now applies from 2 December 2027 and Annex I from 2 August 2028. This tracker previously recorded the opposite, and that entry was wrong. We label each entry with its current status and the date we last checked it against an official source. Confirm any single deadline against the cited source before you rely on it for a compliance or insurance decision.
Key takeaways
- EU AI Act, in force in stages: the Article 5 prohibitions since 2 February 2025, the GPAI model obligations since 2 August 2025, and the Article 50 transparency obligations plus enforcement powers since 2 August 2026. The Annex III high-risk obligations, including Article 26 deployer duties, now apply from 2 December 2027, and Annex I product obligations from 2 August 2028.
- EU Digital Omnibus, resolved: the proposal published 19 November 2025 as COM(2025) 836 reached political agreement on 7 May 2026, was given final approval by the Council on 29 June 2026, and entered into force on 27 July 2026. It took legal effect for the Annex III high-risk deadline, which is now 2 December 2027.
- US states diverge: Texas TRAIGA and California SB 53 are both in force from 1 January 2026, while Colorado moved to a narrower disclosure model under SB26-189, signed 14 May 2026, with the developer and deployer duties beginning on 1 January 2027. Both the 30 June 2026 extension under SB25B-004, signed 28 August 2025, and the SB26-189 rewrite were verified at leg.colorado.gov on 17 August 2026.
- Council of Europe Framework Convention, signed not yet in force: opened for signature 5 September 2024; entry into force awaits five ratifications including at least three Council of Europe member states. Individual signature and ratification dates previously listed here could not be read at the Council of Europe treaty office on 17 August 2026 and have been removed.
- Voluntary frameworks carry no deadline but govern insurability: ISO/IEC 42001:2023, the NIST AI RMF 1.0, and the AIUC-1 agent standard are the controls underwriters such as Munich Re (aiSure), Armilla, and AIUC reference when pricing AI liability cover.
How to read this tracker
Each entry uses one of five status labels. In force means the obligation is currently applicable. Applies later means the instrument is adopted but a specific provision has a future application date. Proposed change means a draft measure could alter a date or obligation but has not been adopted. Signed, not in force means a treaty or law has been signed or ratified by some parties but is not yet binding. Voluntary means there is no statutory deadline or penalty, but the framework carries weight through procurement and insurance.
EU AI Act: the master timeline
The EU AI Act (Regulation 2024/1689) applies in phases. The two phases that matter most for operators in 2026 are the general-purpose AI rules and the high-risk rules.[1]
| Milestone | Date | Status (verified 17 Aug 2026) |
|---|---|---|
| Prohibited practices (Article 5) apply | 2 February 2025 | In force |
| GPAI model obligations apply (new models) | 2 August 2025 | In force |
| Article 50 transparency applies; enforcement powers begin | 2 August 2026 | In force. Annex III was deferred to 2 December 2027 by Regulation (EU) 2026/1744 |
| GPAI models placed before 2 Aug 2025 must comply | 2 August 2027 | Applies later |
| Article 6(1) high-risk product classification rule applies | 2 August 2027 | Applies later |
The GPAI obligations took effect on 2 August 2025. The Commission's enforcement actions against GPAI providers, including requests for information, model access, and recalls, began a year later on 2 August 2026, on schedule. The voluntary General-Purpose AI Code of Practice, whose final version the AI Office published on 10 July 2025, gives providers a practical route to demonstrate compliance across its three chapters on transparency, copyright, and safety and security.[1]
The Digital Omnibus: how the uncertainty resolved
For most of 2026, the single biggest source of uncertainty in the European timeline was the Digital Omnibus on AI, a Commission proposal published on 19 November 2025. It responded to a delay in the harmonised standards needed to support the high-risk requirements and to the slow set-up of competent authorities in member states, both of which put the smooth entry into application on 2 August 2026 at risk.[2]
The Parliament and Council reached political agreement on the substance on 7 May 2026, the Council gave final approval on 29 June 2026, and the act entered into force on 27 July 2026. The Annex III high-risk obligations now apply from 2 December 2027 and the Annex I product obligations from 2 August 2028. An earlier version of this tracker recorded the opposite, that the procedure had not completed in time and that the original 2 August 2026 date governed for high-risk systems. That entry was wrong and is superseded here. Sourcing note, 17 August 2026: the amending regulation is cited on this page as Regulation (EU) 2026/1744, published at OJ L on 24 July 2026. That number and publication date could not be confirmed at eur-lex.europa.eu on 17 August 2026 because the site could not be read from this session. The number is kept because it is how a reader finds the act; the entry into force date and the two new application dates are the operative facts and are stated above.[2]
| Element | Position before 2 Aug 2026 | Actual outcome |
|---|---|---|
| High-risk rules trigger (Annex III) | Originally 2 August 2026, with a delay to 2 December 2027 proposed | Deferred to 2 December 2027. The amending act entered into force 27 July 2026, six days before the original date. |
| Annex I product high-risk obligations | Originally 2 August 2027 | Deferred to 2 August 2028 by Regulation (EU) 2026/1744 |
| Legislative status | Political agreement 7 May 2026, Council final approval 29 June 2026 | Published at OJ L, 2026/1744 on 24 July 2026, in force 27 July 2026 |
For a deeper treatment of the Omnibus mechanics and how the trilogue resolved, see the master brief on the European edition: the Digital Omnibus explained.
United States: a moving state patchwork
There is no comprehensive federal AI statute. The binding obligations in 2026 sit at state level, and they are diverging in both substance and timing.[3]
| Law | Effective date | Status (verified 17 Aug 2026) |
|---|---|---|
| Texas Responsible AI Governance Act (TRAIGA) | 1 January 2026 | In force |
| California Transparency in Frontier AI Act (SB 53) | 1 January 2026 | In force |
| Colorado AI Act (SB 24-205, as amended by SB26-189) | 1 January 2027 | Applies later (rewritten 14 May 2026) |
TRAIGA, enacted 22 June 2025, took effect on 1 January 2026. It prohibits developing or deploying AI for certain unlawful purposes, including intentional unlawful discrimination and the generation of illegal or explicit material, and requires government entities to disclose AI interactions to the public before or at the time of the interaction.[4]
California's SB 53, signed 29 September 2025, also took effect on 1 January 2026. It targets large frontier developers, those with annual gross revenue above USD 500 million, requiring them to publish a frontier AI framework describing how they manage and mitigate catastrophic risk, publish transparency reports about their frontier models, and report critical safety incidents to California regulators.[5]
The Colorado AI Act is the clearest example of why a tracker beats a static guide. Originally due on 1 February 2026, it was postponed to 30 June 2026 by SB 25B-004 (signed 28 August 2025), then rewritten by SB26-189 (signed 14 May 2026), which sets the developer and deployer duties to begin on 1 January 2027. SB26-189 also rewrote the substance: it removed the deployer duties to maintain risk management programmes and conduct impact assessments, and the duty of care to prevent algorithmic discrimination, replacing the original comprehensive risk-based regime with a narrower disclosure-and-transparency model. Developers must give deployers specified information about automated decision-making technologies, and deployers must notify consumers when a high-risk system makes a consequential decision and inform them of a right to appeal.[6]
International and treaty layer
Above national law sits a treaty and a cluster of intergovernmental principles. None of these creates a direct operator deadline today, but they shape how national regimes converge.
| Instrument | Key date | Status (verified 17 Aug 2026) |
|---|---|---|
| Council of Europe Framework Convention on AI | Opened for signature 5 Sep 2024 | Signed, not yet in force |
| OECD AI Principles (revised 2024) | Original 2019, updated May 2024 | In force as soft-law principles |
| African Union Continental AI Strategy | Endorsed by the AU Assembly, Jul 2024 | Coordination framework, not directly binding on member states |
| New Zealand: no dedicated AI statute | Government confirmed no AI-specific law, 2024; National AI Strategy, July 2025 | By policy choice, not a gap; relies on Privacy Act 2020, Human Rights Act 1993 |
| Hong Kong: no dedicated AI statute | PCPD ethical AI guidance, Aug 2021; HKMA and SFC generative AI circulars, 2023-2024 | Sectoral guidance; binding floor runs through the PDPO, Cap. 486 |
| Kenya: no dedicated AI statute | National AI Strategy 2025-2030 launched Mar 2025; Data Protection Act, 2019 in force | Policy direction only; binding floor runs through section 35, Data Protection Act |
| Ireland: EU AI Act applies directly, no domestic statute needed | HSA one of 15 designated national competent authorities; DPC lead GDPR authority for most global AI providers' EU entities | Same EU regime as all member states; disproportionate enforcement weight via company registration concentration |
| Colombia: no dedicated AI statute | CONPES 3975, national policy document on digital transformation and AI; DNP Ethical Framework for AI; SIC enforcement under Law 1581 of 2012 | Policy direction only; binding floor runs through SIC's Habeas Data powers, no AI-specific penalty regime yet |
| Norway: EEA incorporation of the EU AI Act | EU AI Act incorporation into the EEA Agreement pending an EEA Joint Committee decision; Datatilsynet AI regulatory sandbox running since 2021 | Applies later; national implementing timeline not yet finalised |
| Thailand: no enacted horizontal AI statute | Draft Royal Decree on AI Business Operations (ETDA), under development since 2022; National AI Strategy and Action Plan 2022-2027; PDPA B.E. 2562 in force | Proposed change; binding floor today runs through the PDPA, enforced by the PDPC |
Added 10 August 2026: Norway and Thailand are added above as two further reference points on opposite ends of the same spectrum. Norway is an EEA, not EU, member, so the EU AI Act (Regulation 2024/1689) reaches Norwegian operators only once incorporated into the EEA Agreement by an EEA Joint Committee decision and transposed into Norwegian law, a timeline that has not yet been finalised; Datatilsynet, Norway's data protection authority, has run a real AI regulatory sandbox since 2021 and is the most likely candidate for a national AI market surveillance role. Thailand has no enacted horizontal AI statute: its draft Royal Decree on Business Operations That Use Artificial Intelligence Systems, under development by the Electronic Transactions Development Agency (ETDA) since 2022, remains in draft form, so the operative binding floor today runs through the Personal Data Protection Act B.E. 2562 (2019), enforced by the Personal Data Protection Committee (PDPC). Full analysis at the Norway operator guide and the Thailand operator guide on this site.
Added 7 August 2026: Colombia is added above alongside New Zealand, Hong Kong, and Kenya as a further example of the sectoral, data-protection-led pattern rather than a horizontal AI statute. Colombia's CONPES 3975 is a national policy document coordinated by MinTIC and the DNP, setting strategic direction without creating enforceable operator obligations. Its approval date could not be confirmed at dnp.gov.co on 17 August 2026 and the November 2020 date previously given here has been withdrawn. DNP's 2021 Ethical Framework for Artificial Intelligence adds voluntary principles on the same non-binding basis. The binding floor runs through the Superintendencia de Industria y Comercio's (SIC) existing powers under Law 1581 of 2012, the Habeas Data law, which apply to any AI system processing personal data regardless of AI-specific legislation. Full analysis at the Colombia operator guide on this site.
Added 27 July 2026: Ireland is added above as a different kind of entry from the no-statute pattern of New Zealand, Hong Kong, and Kenya. Ireland is a full EU member state and the EU AI Act applies to it directly with no domestic transposition required. What earns it a spotlight is company registration concentration: Google, Meta, Microsoft, TikTok, and LinkedIn all maintain their EU or international headquarters in Dublin, which makes the Irish Data Protection Commission, as lead authority under the GDPR one-stop-shop mechanism, a disproportionately consequential regulator for how these companies train and deploy AI across the entire EU market. Domestically, the Health and Safety Authority is one of the 15 national competent authorities designated on 16 September 2025, working alongside the Central Bank of Ireland for financial services AI. Central coordination and the single point of contact sit with a National AI Office due by 2 August 2026. Full analysis at the Ireland operator guide on this site.
Added 24 July 2026: Hong Kong and Kenya are added above as two further examples of the sectoral, data-protection-led pattern this tracker has been tracking since New Zealand was added on 8 July 2026. Neither jurisdiction has enacted a horizontal AI statute. Hong Kong's binding floor runs through the Personal Data (Privacy) Ordinance, Cap. 486, plus non-binding PCPD ethical AI guidance (August 2021) and sector circulars from the HKMA and SFC. Kenya's binding floor runs through section 35 of the Data Protection Act, 2019, the automated-decision-making right enforced by the Office of the Data Protection Commissioner, with the National AI Strategy 2025-2030 (launched March 2025) setting direction rather than binding obligations. Full analysis at the Hong Kong operator guide and the Kenya operator guide on this site.
Added 8 July 2026: New Zealand is included above as a deliberate contrast to the EU AI Act model. The government confirmed in 2024 that it would not introduce AI-specific legislation, relying instead on existing law (the Privacy Act 2020, the Human Rights Act 1993) plus voluntary guidance, including the Algorithm Charter for Aotearoa New Zealand and MBIE's National AI Strategy published July 2025. Full analysis at the New Zealand operator guide on this site.
The Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law was opened for signature on 5 September 2024. It enters into force on the first day of the month following a three-month period after five signatories, including at least three Council of Europe member states, have ratified it, and that threshold has not been confirmed as met, so the Convention is not yet binding in force. Sourcing note, 17 August 2026: this tracker previously stated that Japan signed on 11 February 2025 and that the European Union ratified on 15 May 2026. The Council of Europe treaty office, which is the only authoritative record of signature and ratification, could not be read from this session on 17 August 2026, and those two specific claims are therefore not confirmed. They have been removed rather than repeated. Check the treaty office signature list directly before relying on any statement about who is party to CETS 225, including any statement made here.[7]
Voluntary frameworks and the insurance layer
The frameworks below carry no statutory deadline, but for an operator that wants to be insurable they are the operative reference. Underwriters use them as evidence of reasonable care when pricing and binding AI liability cover.
| Framework or product | Identifier and date | Status (verified 17 Aug 2026) |
|---|---|---|
| AI management system standard | ISO/IEC 42001:2023 (published Dec 2023) | Voluntary, certification accelerating |
| AI risk management framework | NIST AI RMF 1.0 (AI 100-1, Jan 2023) | Voluntary |
| Generative AI profile | NIST AI 600-1 (July 2024) | Voluntary |
| AI agent security standard | AIUC-1 (first agent standard) | Voluntary, first policy Feb 2026 |
ISO/IEC 42001:2023, the AI management system standard published in December 2023, is the closest analogue to ISO 27001 for AI governance. Certification is voluntary. Named vendor certifications previously listed here could not be confirmed at the certifying bodies and have been removed. The NIST AI RMF 1.0 (NIST AI 100-1, January 2023) and its Generative AI Profile (NIST AI 600-1, July 2024) provide the GOVERN, MAP, MEASURE, and MANAGE functions that map cleanly onto both ISO/IEC 42001 controls and the EU AI Act's risk-management expectations.[8]
AIUC-1 is presented as the first security and reliability standard built specifically for AI agents, created by the Artificial Intelligence Underwriting Company (AIUC) with input from Orrick, Stanford, the Cloud Security Alliance, MIT, and MITRE. It verifies agents across data protection, operational boundaries, attack resistance, and error prevention. AIUC, the Artificial Intelligence Underwriting Company, came out of stealth in July 2025 with a USD 15 million seed round led by Nat Friedman at NFDG. AIUC-1 comprises 51 requirements and 130 controls across six pillars. The first AIUC-1-backed insurance policy was announced for ElevenLabs on 12 February 2026; no carrier or reinsurer is named at source. A claim that AIUC was founded in 2024, an additional named investor, and a named vendor certification previously appeared here and could not be confirmed; all three have been removed.[9]
On the carrier side, Munich Re's aiSure has been written with Mosaic Insurance since 26 February 2026 at an initial capacity of EUR, USD or CAD 15 million. Armilla is a Lloyd's coverholder; its Affirmative AI Liability Insurance is underwritten by certain underwriters at Lloyd's with limits up to USD 25 million per organisation, and Armilla states that coverage may not be available in all jurisdictions. For how AI performance cover is structured, see the aiSure analysis on agentinsured.eu, and for the certification-to-underwriting bridge see agentcertified.eu.[10]
What operators should do with this tracker
First, separate what moved from what did not. The Annex III high-risk obligations, including the Article 26 deployer duties, now fall on 2 December 2027. The Article 50 transparency duties, the Article 5 prohibitions and the GPAI obligations did not move and are live law today. Building Article 26 documentation now is still the prudent position, but the deadline that binds today is Article 50. Second, if you operate in the United States, map your footprint against Texas and California now (both in force) and diarise Colorado for 1 January 2027 against the narrower SB 189 obligations rather than the original text. Third, do not wait for treaties: the Council of Europe Convention sets direction, not an operator deadline. Fourth, build to the voluntary frameworks anyway, because ISO/IEC 42001, the NIST AI RMF, and AIUC-1 are what determine whether you can buy AI liability cover and at what price. Fifth, if you operate outside the jurisdictions with binding statutes, including Colombia, do not assume the absence of a specific AI law means no obligations apply: general data protection and consumer protection law is already the operative floor. For the underlying liability theory that ties these together, see the NIST AI RMF reasonable-care guide and the US-EU-UK liability comparison.
Frequently asked questions
Did the EU AI Act's 2 August 2026 deadline actually take effect?
Yes, but not in the direction this tracker previously recorded. The Digital Omnibus on AI was adopted and entered into force on 27 July 2026, six days before the original deadline, and it deferred the Annex III high-risk obligations to 2 December 2027 and the Annex I product obligations to 2 August 2028. The 2 August 2026 date therefore did not govern for high-risk systems. What did take effect on 2 August 2026, unchanged, are the Article 50 transparency obligations and the enforcement powers. The Article 5 prohibitions have applied since 2 February 2025 and the GPAI model obligations since 2 August 2025. An earlier version of this answer said the Omnibus was not adopted in time and that Article 26 and Article 99 entered into application on 2 August 2026; that was wrong.
Has the Colorado AI Act been delayed or changed?
Both. Originally due 1 February 2026, SB 24-205 was postponed to 30 June 2026 by SB 25B-004 (signed 28 August 2025), then to 1 January 2027 by SB 189 (signed 14 May 2026). SB 189 also rewrote the law, removing the deployer duties to maintain risk management programmes and conduct impact assessments and the duty of care against algorithmic discrimination, shifting to a narrower disclosure model: developers supply specified information about automated decision-making technologies, and deployers notify consumers when a high-risk system makes a consequential decision and of a right to appeal.
Which US state AI laws are already in force in 2026?
Texas TRAIGA, enacted 22 June 2025, took effect 1 January 2026; it prohibits AI developed or deployed for certain harmful purposes and requires government entities to disclose AI interactions. California SB 53, the Transparency in Frontier AI Act signed 29 September 2025, also took effect 1 January 2026; it requires large frontier developers (over USD 500 million revenue) to publish a frontier AI framework, file transparency reports, and report critical safety incidents. Colorado's law is now deferred to 1 January 2027.
Is the Council of Europe AI Framework Convention in force yet?
Not yet. It opened for signature on 5 September 2024 and enters into force on the first day of the month following a three-month period after five signatories, including at least three Council of Europe member states, have ratified. That threshold has not been confirmed as met. Specific signature and ratification dates previously given here could not be read at the Council of Europe treaty office on 17 August 2026 and have been removed; check the treaty office list directly.
What is the AIUC-1 standard and is it being used by AI insurers?
AIUC-1 is described as the first security and reliability standard built specifically for AI agents, from the Artificial Intelligence Underwriting Company with input from Orrick, Stanford, the Cloud Security Alliance, MIT, and MITRE. It verifies agents across data protection, operational boundaries, attack resistance, and error prevention. AIUC came out of stealth in July 2025 with a USD 15 million seed round led by Nat Friedman at NFDG. AIUC-1 comprises 51 requirements and 130 controls across six pillars. The first AIUC-1-backed policy was announced for ElevenLabs on 12 February 2026, with no carrier or reinsurer named at source. It sits alongside ISO/IEC 42001 and the NIST AI RMF as a voluntary benchmark underwriters reference.
Do voluntary frameworks like ISO/IEC 42001 and the NIST AI RMF have deadlines?
No. ISO/IEC 42001:2023 (published December 2023) and the NIST AI RMF 1.0 (January 2023) with its Generative AI Profile (July 2024) are voluntary, with no statutory effective date or penalties. Their force comes from procurement and insurance: customers increasingly require ISO/IEC 42001 certification, and underwriters use these frameworks plus AIUC-1 as evidence of reasonable care when pricing AI liability cover. Adoption is accelerating in 2026 as audits have operationalised and major vendors have certified.
How often is this AI regulation status tracker verified?
It is verified against official sources and updated when a status materially changes. Every entry carries a status label and a last-verified date; this version was re-verified on 17 August 2026, and where a source could not be read the entry now says so rather than repeating an unconfirmed figure. Because several US state laws have shifted dates more than once, treat the dates as accurate at the verification date and confirm against the issuing body's own record before relying on any single deadline for a decision.
Why was Ireland added to this tracker if it has no AI-specific law of its own?
Ireland is included not because it has a distinct legal regime, since the EU AI Act applies uniformly across all member states as a directly effective regulation, but because it is the registered EU home of a disproportionate share of the world's largest AI providers, including Google, Meta, Microsoft, TikTok, and LinkedIn. Under the GDPR one-stop-shop mechanism, the Irish Data Protection Commission is the lead EU supervisory authority for these companies, giving Irish regulatory decisions outsized practical weight across the whole European market.
Where does Colombia stand on AI regulation as of August 2026?
Colombia has no enacted, standalone AI statute as of August 2026. Its governance rests on CONPES 3975, a national policy document led by MinTIC and the DNP, a voluntary Ethical Framework for Artificial Intelligence, and the SIC's existing enforcement powers over AI systems that process personal data under Law 1581 of 2012. Full analysis at the Colombia operator guide on this site.
References
- EU Regulation 2024/1689 (the EU AI Act). Phased application: Article 5 prohibitions from 2 February 2025; GPAI model obligations from 2 August 2025 with Commission enforcement powers over GPAI providers from 2 August 2026; most remaining rules from 2 August 2026; Article 6(1) high-risk product classification rule from 2 August 2027. General-Purpose AI Code of Practice final version published by the AI Office on 10 July 2025 (transparency, copyright, safety and security chapters). Implementation timeline at artificialintelligenceact.eu/implementation-timeline and digital-strategy.ec.europa.eu.
- Digital Omnibus on AI, amending Regulation (EU) 2024/1689. Political agreement 7 May 2026, Council final approval 29 June 2026, entry into force 27 July 2026. Annex III high-risk obligations apply from 2 December 2027 and Annex I from 2 August 2028. The amending regulation number and Official Journal date cited on this page could not be confirmed at eur-lex.europa.eu on 17 August 2026; the site could not be read from this session. Confirm at eur-lex.europa.eu before relying on the citation.
- There is no comprehensive federal AI statute in the United States as of August 2026. Binding obligations sit at state level. Confirm each state law against its own legislature's bill record.
- Texas Responsible Artificial Intelligence Governance Act (TRAIGA), enacted 22 June 2025, effective 1 January 2026. Prohibits AI developed or deployed for certain unlawful purposes; requires government entities to disclose AI interactions. Bill record at capitol.texas.gov.
- California Transparency in Frontier Artificial Intelligence Act (SB 53), signed 29 September 2025, effective 1 January 2026. Requires large frontier developers (annual gross revenue above USD 500 million) to publish a frontier AI framework, file transparency reports, and report critical safety incidents to California regulators. Official text at leginfo.legislature.ca.gov.
- Colorado AI Act (SB 24-205). Original effective date 1 February 2026; postponed to 30 June 2026 by SB 25B-004 (signed 28 August 2025); rewritten by SB26-189 (signed 14 May 2026), which removed the deployer risk-management-programme, impact-assessment and duty-of-care obligations in favour of a disclosure model with developer and deployer duties from 1 January 2027. Both amending bills verified at leg.colorado.gov, 17 August 2026.
- Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (CETS No. 225). Opened for signature 5 September 2024. Entry into force on the first day of the month following a three-month period after five signatories, including at least three Council of Europe member states, ratify. Individual signature and ratification dates previously cited here could not be read at the Council of Europe treaty office on 17 August 2026 and have been withdrawn. Check the treaty office signature list at coe.int directly.
- ISO/IEC 42001:2023, AI management system standard, published December 2023; voluntary certification. NIST AI Risk Management Framework 1.0 (NIST AI 100-1), January 2023, and NIST AI 600-1 Generative AI Profile, July 2024. iso.org and nist.gov/artificial-intelligence.
- AIUC-1, AI agent security and reliability standard from the Artificial Intelligence Underwriting Company (AIUC), aiuc.com. AIUC came out of stealth in July 2025 with a USD 15 million seed round led by Nat Friedman at NFDG. AIUC-1 comprises 51 requirements and 130 controls across six pillars. First AIUC-1-backed policy announced for ElevenLabs on 12 February 2026, with no carrier or reinsurer named at source.
- Munich Re aiSure, written with Mosaic Insurance since 26 February 2026 at an initial capacity of EUR, USD or CAD 15 million. Armilla, a Lloyd's coverholder; Affirmative AI Liability Insurance underwritten by certain underwriters at Lloyd's with limits up to USD 25 million per organisation. See agentinsured.eu/articles/munich-re-aisure-ai-performance-insurance-europe.
- New Zealand Ministry of Business, Innovation and Employment (MBIE). Responsible AI Guidance for Businesses; National AI Strategy, published July 2025. New Zealand government confirmed no dedicated AI statute planned, 2024. Added 8 July 2026; full analysis at agentliability.co/articles/new-zealand-ai-regulation-operators-guide-2026.html.
- Office of the Privacy Commissioner for Personal Data (PCPD), Hong Kong. Guidance on the Ethical Development and Use of Artificial Intelligence, August 2021. Personal Data (Privacy) Ordinance, Cap. 486. Hong Kong Monetary Authority and Securities and Futures Commission generative AI circulars, 2023-2024. Added 24 July 2026; full analysis at agentliability.co/articles/hong-kong-ai-regulation-2026-operators-guide.html.
- Ministry of Information, Communications and the Digital Economy (Kenya). National Artificial Intelligence Strategy 2025-2030, launched March 2025. Data Protection Act, No. 24 of 2019, section 35. African Union Continental AI Strategy, endorsed July 2024. Added 24 July 2026; full analysis at agentliability.co/articles/kenya-ai-regulation-2026-operators-guide.html.
- Department of Enterprise, Trade and Employment (Ireland), National AI Strategy, AI, Here for Good, published July 2021, refreshed November 2024. Health and Safety Authority, one of 15 national competent authorities designated 16 September 2025. Data Protection Commission (Ireland), lead EU supervisory authority under GDPR Article 56 one-stop-shop for Google, Meta, Microsoft, TikTok, and LinkedIn's EU entities. Added 27 July 2026; full analysis at agentliability.co/articles/ireland-ai-regulation-operators-guide-2026.html.
- Consejo Nacional de Política Económica y Social (CONPES), Colombia. Documento CONPES 3975: Política Nacional para la Transformación Digital y la Inteligencia Artificial. Departamento Nacional de Planeación (DNP), Marco Ético para la Inteligencia Artificial en Colombia. Approval dates could not be confirmed at dnp.gov.co on 17 August 2026 and the dates previously given here have been withdrawn. Ley 1581 de 2012 (Habeas Data), Superintendencia de Industria y Comercio (SIC) enforcement powers. Added 7 August 2026; full analysis at agentliability.co/articles/colombia-ai-regulation-operators-guide-2026.html.