RUDI Perspective · Policy & Governance
What should AI policy actually govern?
Before legislators debate restrictions or safeguards, they need to identify the capability at issue and the policy problem they are trying to solve.
01 / The technology
First, establish what we’re actually regulating.
A system that identifies a face, generates a video, steers a vehicle, or predicts a molecular structure may be described as artificial intelligence. That shared label does not tell legislators which capability, activity, or consequence needs their attention.
Before debating whether AI needs more or less regulation, we should be able to say what part of it we mean. Four overlapping areas offer a useful starting point. They are a map of capabilities and applications, not an exhaustive technical classification or four separate legal categories.
Perceive & identify
Computer vision
Systems that interpret images and video: facial recognition, medical imaging, satellite analysis, and perception for autonomous machines.
Create & synthesize
Generative AI, including diffusion models
Systems that generate text, code, images, audio, video, or candidate designs. Uses range from everyday drafting to synthetic media and scientific research.
Act in the physical world
Robotics and autonomous control
Systems that connect perception and decisions to physical action: industrial robots, drones, and autonomous vehicles.
Predict & investigate
Predictive and scientific AI
Systems that estimate outcomes or support discovery: credit scoring, demand forecasting, drug development, and biological modeling.
These areas overlap (Exhibit 1). Generative models can support robotic control. Computer vision can use transformers. Scientific systems can combine predictive tasks with generative methods; AlphaFold 3, for example, uses a diffusion-based architecture to predict biomolecular structures. A rule aimed at one technical method can therefore reach applications well beyond the one its authors had in mind. [1]
Exhibit 1
Transformer and diffusion methods appear in all four areas, so a rule defined only by either method could reach all four.
Selected published systems, by method and area, with year of first publication
| Method | Computer vision | Generative AI | Robotics and control | Predictive and scientific |
|---|---|---|---|---|
| Transformers | Vision TransformerImage recognition, 2020 | Transformer architectureBasis of large language models, 2017 | RT-2Robot actions from vision and language, 2023 | AlphaFold 2Protein structure prediction, 2021 |
| Diffusion models | DiffusionDetObject detection, 2022 | Latent diffusionImage generation, 2021 | Diffusion PolicyRobot motion planning, 2023 | AlphaFold 3Biomolecular structure prediction, 2024 |
That matters when legislators define the scope of a bill. Two systems might identify people in the same setting, with similar consequences, while using different model architectures. A definition tied too closely to one architecture could subject those systems to different safeguards for reasons unrelated to the people affected.
Technical differences can justify different treatment when they change a system’s capabilities, risks, or the ways it can be tested and controlled. Our argument is that legislators should explain that connection. The method used to build a system should not become an accidental substitute for the activity they intended to regulate.
02 / The policy question
Then ask which legislative domain we’re evaluating.
Once we identify the technology, we still need to identify the public concern. Is the issue an adversary’s access to advanced chips, a person’s ability to challenge an automated decision, or responsibility for a machine that causes physical harm? Each question calls for different evidence and a different policy response (Exhibit 2).
Exhibit 2
Each legislative domain starts from a different public concern and needs different evidence.
Six domains for organizing the legislative discussion
| Legislative domain | Central question |
|---|---|
| National security | Which capabilities, components, or deployments create strategic threats or dependencies? |
| Civil rights and civil liberties | When should automated decisions, identification, and surveillance be restricted or subject to safeguards? |
| Safety and accountability | What evidence of safety is needed, and who is responsible when an AI-enabled system causes harm? |
| Transparency and provenance | When should people know AI was used, and what evidence about an output’s origin or a decision should be preserved? |
| Economic competition | How can policy address market concentration and barriers to entry while preserving innovation? |
| International governance | Which risks require coordination across borders, and where do countries need common rules or strategic restrictions? |
These domains overlap too (Exhibit 3). Facial recognition used in a military setting may raise national-security questions; its use by domestic law enforcement also raises questions about privacy, due process, and civil liberties. An autonomous vehicle raises safety questions even when its perception system uses methods found in ordinary image-recognition software.
Exhibit 3
The same capability raises different legislative questions depending on where it is used.
Machine perception, traced from setting to legislative domain
One capability
Machine perception: recognizing people and objects in images and video
- Identifying people in a military settingNational securityWhich capabilities, components, or deployments create strategic threats or dependencies?
- Identifying people for domestic law enforcementCivil rights and civil libertiesWhen should automated decisions, identification, and surveillance be restricted or subject to safeguards?
- Perceiving the road in an autonomous vehicleSafety and accountabilityWhat evidence of safety is needed, and who is responsible when an AI-enabled system causes harm?
The purpose of separating the domains is to make the discussion specific enough to evaluate. A national-security rationale should identify the strategic threat. A civil-rights proposal should identify the decision, the affected people, and the protection they need. Calling both “AI regulation” does not resolve either question.
03 / National security
Distinguish capabilities, competition, and components.
National security is a major domain of AI policy because it reaches from the supply of computing hardware to the use of systems in intelligence and defense. Even here, there is more than one problem to solve (Exhibit 4).
Capabilities: what can a system enable?
Legislators may be concerned about military applications, cyber operations, biological misuse, or intelligence analysis. The relevant question is what a system enables a particular actor to do, under what conditions, and with what evidence. A model’s name, size, or technical family is only useful if it helps establish that connection.
Competition: what capacity does a country need?
This includes research, manufacturing, infrastructure, and the people needed to develop and use the technology. The CHIPS and Science Act, signed in August 2022, provided funding for U.S. semiconductor manufacturing and research. It illustrates how legislation can build industrial capacity rather than simply impose restrictions on AI users. [2]
Competition between countries is also different from competition among firms. A policy that strengthens a national industry still needs scrutiny for how it affects smaller companies, access to infrastructure, and concentration within the market.
Components: who can obtain the necessary inputs?
Advanced chips, manufacturing equipment, computing infrastructure, and access to sensitive systems can become objects of policy in their own right. The RESTRICT Act (H.R. 6879), introduced in December 2025, illustrates this approach: the introduced bill would restrict advanced-chip exports to countries of concern while providing a controlled pathway for eligible U.S. firms’ overseas facilities. This is an example of the proposal as introduced, not a statement of current export requirements. [3]
These approaches should be judged against their intended effects. A restriction on access needs a plausible account of what it prevents and how it will be enforced. An investment program needs an account of the capacity it will create. Neither, by itself, answers how an employer should use AI to assess a job applicant.
Exhibit 4
National security covers three distinct problems, and each calls for a different instrument and a different test of success.
Components feed capabilities that can be deployed; national capacity sits underneath all three
| Components | Capabilities | Competition | |
|---|---|---|---|
| The question | Who can obtain the necessary inputs? | What can a system enable a particular actor to do? | What capacity does the country need? |
| Typical instruments | Export controls, licensing, end-use checks on chips and equipment | Pre-deployment testing, misuse safeguards, limits on specific military or intelligence uses | Research funding, manufacturing incentives, infrastructure, workforce development |
| Example | RESTRICT Act, proposed December 2025 | Executive Order 14409, June 2026: voluntary pre-release government access to frontier models with advanced cyber capabilities | CHIPS and Science Act, enacted August 2022 |
| Judge it by | What does it prevent, and can it be enforced? | Does the evidence connect the system to the threat? | What capacity will it create, and who will be able to use it? |
04 / Legislative examples
Existing measures show how differently the problem can be defined.
Looking at actual measures helps distinguish the technology being discussed from the legal obligation being proposed (Exhibits 5 and 6). The following examples illustrate different choices of scope; they are not interchangeable models or endorsements of every provision.
Exhibit 5
Rules attach at different layers of the AI stack, with different obligations for suppliers, deploying organizations, and platforms.
Selected measures placed at the layer they address; dashed tags indicate proposals, voluntary arrangements, or duties that start later
- Content and outputsWhat people see, hear, or receive
- Uses and decisionsWhere a system affects a job, a loan, a benefit, or a right
- Models and capabilitiesWhat a trained model can do
- Chips and computeThe hardware that trains and runs models
Explore the 24-measure legislative referenceLaws, proposals, and voluntary arrangements · sources checked October 11, 2026
Exhibit 6
These 24 measures differ in legal force, scope, and timing. Enacted laws, proposed rules, and voluntary arrangements need to be read differently.
Selected measures and published timelines, sources reviewed October 11, 2026. Scope thresholds, exceptions, and transition provisions apply.
- In force
- Phasing in
- Enacted, not yet effective
- Delayed
- Voluntary
- Proposed
- Not yet in force
- Enacted amendment
| Measure | Who is affected | Status, October 2026 |
|---|---|---|
| Components: chips and compute | ||
| Export rule for advanced computing chipsUnited States, Commerce | Chip exporters | In forceEffective January 15, 2026; case-by-case licensing for H200-class chips to China ↓ |
| RESTRICT ActUnited States, Congress | Chip exporters | ProposedH.R. 6879, introduced December 18, 2025; described here as introduced ↓ |
| Models and capabilities | ||
| AI Act, general-purpose AI rulesEuropean Union | Model providers | Phasing inObligations apply from August 2, 2025; models already marketed before that date have until August 2, 2027 ↓ |
| Transparency in Frontier AI Act (SB 53)California | Frontier developers | In forceEffective January 1, 2026 ↓ |
| RAISE ActNew York | Frontier developers | Enacted, not yet effective2025 act amended March 27, 2026; effective January 1, 2027 ↓ |
| AI Safety Measures Act (SB 315)Illinois | Large frontier developers | Enacted, not yet effectiveEffective January 1, 2027; frontier frameworks and independent audits begin in 2028 ↓ |
| Executive Order 14409United States, federal | Frontier developers that opt in | VoluntarySigned June 2, 2026; pre-release access framework, no licensing ↓ |
| Uses and decisions | ||
| Local Law 144New York City | Employers, employment agencies | In forceEnforced since July 2023; a December 2025 state audit found enforcement ineffective ↓ |
| AI in employment (HB 3773)Illinois | Employers | In forceEffective January 1, 2026 ↓ |
| Responsible AI Governance Act (HB 149)Texas | Government agencies; developers and deployers | In forceEffective January 1, 2026; bars specified harmful intents and some government uses ↓ |
| AI Act (SB 24-205), replaced by SB 26-189Colorado | Developers and deployers | Enacted, duties pendingReplaces the 2024 act; substantive duties begin January 1, 2027; implementing rules are being developed ↓ |
| Automated decisionmaking regulationsCalifornia | Businesses | Phasing inEffective January 1, 2026; automated-decision duties from January 1, 2027 ↓ |
| AI Act, high-risk uses (Annex III)European Union | Providers and deployers | DelayedMoved from August 2026 to December 2, 2027 by Regulation (EU) 2026/1744 ↓ |
| AI Basic Act, high-impact AISouth Korea | AI business operators | Phasing inIn force January 22, 2026; MSIT announced at least a one-year grace period for administrative fines ↓ |
| Content and outputs | ||
| AI Act, Article 50 transparencyEuropean Union | Providers and deployers | Phasing inApplies since August 2, 2026; Article 50(2) marking duties for systems marketed before that date transition to December 2, 2026 ↓ |
| TAKE IT DOWN ActUnited States, federal | Individuals; covered platforms | In forceEnacted May 19, 2025; platform removal duty since May 19, 2026 ↓ |
| AI Transparency Act: SB 1000 amendmentCalifornia | Generative AI providers; large platforms | Enacted amendmentAmendment signed September 30, 2026; updates requirements for identifying AI-generated content ↓ |
| Labeling measures for AI-generated contentChina | Service providers, platforms | In forceEffective September 1, 2025 ↓ |
| IT Rules amendment on synthetic contentIndia | Online intermediaries | In forceEffective February 20, 2026 ↓ |
| Federal and state authority | ||
| Executive Order 14365United States, federal | Federal agencies | In forceSigned December 11, 2025; directs a DOJ task force to challenge state AI laws; does not itself repeal state statutes ↓ |
| Policy statement on AI accuracyUnited States, FTC | AI developers and deployers | ProposedJuly 2026 proposal addresses deceptive AI marketing and conflicts with state requirements; cited as a proposal ↓ |
| Legislative recommendations on federal preemptionUnited States, White House | States | ProposedWhite House recommendations issued March 20, 2026; recommendations do not themselves enact preemption ↓ |
| Across borders | ||
| AI Framework ConventionCouncil of Europe | Ratifying parties | Not yet in forceEntry into force requires five ratifications, including three Council of Europe member states ↓ |
| U.S.–China Super Intelligence DialogueUnited States and China | Both governments | VoluntaryThe September 25, 2026 U.S. readout announces a dialogue and planned incident channel ↓ |
Enacted local law · New York City
Define a consequential use: automated hiring.
Local Law 144 of 2021 sets conditions for covered automated employment decision tools, including a recent bias audit, public information about the audit, and required notices. The focus is a defined use in hiring or promotion, with obligations for employers and employment agencies. It gives legislators a concrete example to examine: what counts as a covered tool, what the audit reveals, and whether the requirements protect the people being assessed. [4] Other jurisdictions draw that line much more broadly (Exhibit 7).
Exhibit 7
These six measures cover different decisions. Some focus on employment; others also name education, healthcare, infrastructure, or public authority.
Decision areas named in these selected measures, with the year the relevant duties generally apply. “Not named” does not mean an activity is unregulated; “covered” does not mean every use in that area is covered.
- Covered
- Partly covered
- Not named
| Decision area | New York CityLocal Law 144, 2023 | IllinoisHB 3773, 2026 | ColoradoSB 26-189, 2027 | CaliforniaADMT rules, 2027 | European UnionAI Act, Dec. 2027 | South KoreaAI Basic Act, 2026 |
|---|---|---|---|---|---|---|
| Employment | Partly covered | Covered | Covered | Covered | Covered | Covered |
| Education | Not named | Not named | Covered | Covered | Covered | Partly covered |
| Lending and financial services | Not named | Not named | Covered | Covered | Covered | Covered |
| Insurance | Not named | Not named | Covered | Not named | Partly covered | Not named |
| Housing | Not named | Not named | Covered | Covered | Not named | Not named |
| Healthcare | Not named | Not named | Covered | Covered | Partly covered | Covered |
| Government services and benefits | Not named | Not named | Covered | Not named | Covered | Covered |
| Justice and elections | Not named | Not named | Not named | Not named | Covered | Not named |
| Law enforcement and biometric identification | Not named | Not named | Not named | Not named | Covered | Partly covered |
| Migration and border control | Not named | Not named | Not named | Not named | Covered | Not named |
| Critical infrastructure | Not named | Not named | Not named | Not named | Covered | Covered |
| Areas named | 1 | 1 | 7 | 5 | 10 | 7 |
Enacted regulation · European Union · Phased application
Separate safety duties from disclosure duties.
The EU AI Act uses several kinds of obligations. Article 14 addresses human oversight of high-risk systems. Article 50 covers transparency for specified AI interactions and generated or manipulated content, including deepfakes, with qualifications and exceptions. [5]
These provisions ask different questions. Can a person oversee the operation of a consequential system? Does someone know they are interacting with AI or viewing synthetic content? A disclosure requirement alone cannot establish safety, and a safety assessment cannot answer every question about deception or provenance.
Enacted federal law · United States · May 2025
Address a defined harm and a route to removal.
The TAKE IT DOWN Act addresses nonconsensual intimate imagery, including qualifying digital forgeries. It establishes criminal prohibitions and requires covered platforms to remove covered imagery within 48 hours of a valid removal request. Its definition of digital forgery reaches multiple technological methods. [6]
This makes the scope different from a general rule for generative models. The legislative focus is the depiction, the conduct, and the platform’s response. Legislators can examine those boundaries without treating every use of the underlying technology as the same activity.
Existing federal law and a separate agency study · United States
Examine market conduct using existing legal tools.
The Sherman Act already addresses anticompetitive agreements and monopolization. Separately, the FTC’s January 2025 staff report examined partnerships between major cloud providers and AI developers, including implications for access to computing resources and switching between providers. The report is research, not a new law or a finding that every partnership is unlawful. [7]
The question for legislators is whether a specific gap in existing authority or enforcement requires action. The presence of AI does not, on its own, identify that gap.
International governance introduces another instrument. The Council of Europe’s AI Framework Convention opened for signature in September 2024 and addresses human rights, democracy, and the rule of law across the AI lifecycle. It is a treaty framework with its own scope and ratification process; signature should not be read as proof that identical domestic obligations apply in every country. [8]
05 / Choosing a response
Define the gap before choosing the instrument.
A useful policy discussion should now be able to name the capability or activity, the domain of concern, and the people or institutions affected. Only then can legislators judge whether the response calls for a new statute, an amendment, agency rulemaking under existing authority, procurement standards, public investment, or an international agreement (Exhibit 8).
Exhibit 8
Different gaps call for different instruments. A new AI statute is only one of them.
A sequence for framing a proposal, and the instruments that match common gaps
- Name the capability or activity
- Identify the domain of concern
- Identify who is affected and who controls the decision
- Check what existing law already covers
- Define the gap, then choose the instrument
| If the gap is | Consider | Example in this article |
|---|---|---|
| Existing law may apply, but its reach is untested | Study and enforcement under existing authority | Sherman Act; FTC study of AI partnerships [7] |
| People lack notice about automated hiring or access to bias-audit results | Notice and audit duties for a defined use | New York City Local Law 144 [4] |
| People cannot tell when content is synthetic | Disclosure and provenance duties | EU AI Act, Article 50 [5] |
| A specific harm has no adequate remedy | A statute aimed at the conduct | TAKE IT DOWN Act [6] |
| Rivals can obtain strategic inputs | Export controls or licensing | RESTRICT Act proposal [3] |
| Domestic capacity is missing | Public investment | CHIPS and Science Act [2] |
| Public buyers cannot evaluate what they purchase | Procurement standards and training | OMB memorandum M-25-22 on AI acquisition [9] |
| The risk crosses borders | An international agreement | Council of Europe AI Framework Convention [8] |
Consider two systems used to identify people. If they create comparable risks in the same setting, a difference in model architecture needs a relevant justification before it produces different protections. Now consider that same capability used to inspect a manufactured component. The purpose, potential harm, and appropriate oversight change, even if some of the underlying methods remain similar (Exhibit 9).
Exhibit 9
Two tests for drawing distinctions: comparable uses get comparable safeguards, and a change in use can justify different oversight.
The two tests applied to systems that identify people and inspect parts
Consistency
Same use, different methods
Identifying a person in a police investigation
- System A: transformer modelVerification, notice, and a way to challenge the match
- System B: convolutional modelVerification, notice, and a way to challenge the match
Comparable safeguards, unless the difference in architecture changes the risk or how the system can be tested and controlled.
Specificity
Same capability, different uses
Computer vision
- Identifies a personVerification, notice, and a way to challenge the match
- Inspects a manufactured componentDefect review before the product ships
Different oversight, because the purpose and potential harm change even when the methods are similar.
This is the distinction we want AI policy to make: consistency where the capability and consequences are comparable, and specificity where the use changes the stakes. Legislators should also ask who controls the relevant decision. Developers, application builders, deploying organizations, and distributors may each hold different information and different powers to prevent harm.
RUDI’s work adds a practical concern to this discussion. Oversight depends on people who can exercise it. A public buyer needs enough expertise to question a vendor. An employee reviewing an automated recommendation needs time, evidence, and authority to reject it. A smaller organization needs requirements it can understand and implement. Education and institutional capacity belong alongside restrictions and remedies.
Our approach to responsible AI brings those questions into the work of an organization. The legislative discussion should begin with the same discipline: identify what the system does, explain the concern, and make clear what the proposed response is expected to change.
Sources & further reading
This is RUDI’s perspective on how to frame the discussion. The domains and recommendations are our analysis. Primary sources below support the technical and legislative examples; reviewed October 11, 2026. Examples describe selected provisions and historical enactment or introduction, rather than a complete compliance guide.
- Research on overlapping capabilities: Transformer architecture, Vision Transformer, AlphaFold 2, latent diffusion, DiffusionDet, RT-2 robotic control, Diffusion Policy, and AlphaFold 3.Examples of transformer and diffusion methods in vision, generation, robotics, and scientific prediction, used in Exhibit 1.
- NIST: CHIPS for America implementation strategySeptember 2022 account of semiconductor manufacturing and research investment under enacted legislation.
- RESTRICT Act, H.R. 6879: introduced bill text119th Congress, introduced December 18, 2025. The article describes this version’s proposed export controls; it does not claim that the proposal is enacted law.
- New York City: automated employment decision toolsDepartment of Consumer and Worker Protection guidance, with links to Local Law 144 and its implementing rule.
- European Commission AI Act Service Desk: Article 14, human oversight, and Article 50, transparency.Read the provisions, exceptions, and applicable transition dates together; the Act has phased application.
- TAKE IT DOWN Act, Public Law 119-12Enacted May 19, 2025. Sections 2–4 address prohibited conduct, covered platforms’ removal process, and definitions.
- U.S. Department of Justice: antitrust laws; FTC: January 2025 AI partnerships staff report.Existing statutory authority and a separate study of cloud-provider and AI-developer relationships.
- Council of Europe: AI Framework ConventionTreaty framework opened for signature September 5, 2024. The Council of Europe currently lists the European Union as its only party. Entry into force requires five ratifications, including three Council of Europe member states.
- Office of Management and Budget: M-25-22, Driving Efficient Acquisition of Artificial Intelligence in GovernmentApril 3, 2025 guidance to federal agencies on acquiring AI systems and services.
- Executive Order 14409, Promoting Advanced Artificial Intelligence Innovation and SecuritySigned June 2, 2026. Section 3 directs a voluntary framework for pre-release government access to covered frontier models and states that it creates no mandatory licensing or preclearance requirement.
- EU AI Act, Regulation (EU) 2024/1689; Article 113, application dates; Article 111, existing systems and modelsGeneral-purpose model obligations apply from August 2, 2025, with an August 2, 2027 transition for models marketed before that date. Read with the July 2026 amendment below.
- Regulation (EU) 2026/1744 amending the AI Act (Digital Omnibus on AI)Published July 24, 2026; in force July 27, 2026. Moves Annex III high-risk obligations to December 2, 2027 and Annex I obligations to August 2, 2028.
- South Korea: AI Basic Act, official English translation; MSIT implementation announcementIn force January 22, 2026. Article 2(4) defines high-impact AI; MSIT announced at least a one-year grace period for administrative fines. That grace period does not change the Act’s effective date.
- China: Measures for Labeling AI-Generated Synthetic ContentCyberspace Administration of China notice, March 14, 2025; effective September 1, 2025. In Chinese.
- India: FAQ on the IT (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026Ministry of Electronics and Information Technology, February 10, 2026. Rules on synthetically generated information in force February 20, 2026.
- White House fact sheet on the September 2026 U.S.–China state visitSeptember 25, 2026. Announces the U.S.–China Super Intelligence Dialogue and a bilateral channel for incidents. Cited as the U.S. government’s account of the arrangement.
- Executive Order 14365, Ensuring a National Policy Framework for Artificial IntelligenceSigned December 11, 2025; 90 Fed. Reg. 58499. Section 3 directs an AI Litigation Task Force to challenge state AI laws.
- White House: National Policy Framework for Artificial Intelligence, Legislative RecommendationsMarch 20, 2026. Non-binding recommendations asking Congress to preempt certain state AI laws.
- FTC: Proposed Policy Statement Concerning the Suppression of Accuracy in Artificial Intelligence SystemsFederal Register proposal published July 7, 2026, with a July 31 comment deadline. The article describes this proposal; the notice does not establish final adoption.
- Bureau of Industry and Security: Revision to License Review Policy for Advanced Computing CommoditiesFederal Register, January 15, 2026. Case-by-case license review for specified advanced chips to China and Macau, with conditions.
- California SB 53, Transparency in Frontier Artificial Intelligence Act; official 2026 implementation summarySigned September 29, 2025; effective January 1, 2026. Duties differ for frontier developers and large frontier developers.
- New York S8828, chapter amendment to the RAISE ActSigned March 27, 2026, as Chapter 96 of the Laws of 2026; amends Chapter 699 of the Laws of 2025; effective January 1, 2027.
- Illinois Public Act 104-0538, Artificial Intelligence Safety Measures Act (SB 315)Approved July 6, 2026; effective January 1, 2027.
- Illinois Public Act 103-0804 (HB 3773)Amends the Illinois Human Rights Act to address AI in employment decisions; effective January 1, 2026.
- New York State Comptroller: Enforcement of Local Law 144Audit released December 2, 2025, on New York City’s enforcement of its automated employment decision tool law.
- Texas HB 149, Texas Responsible Artificial Intelligence Governance ActSigned June 2025; effective January 1, 2026.
- Colorado SB 26-189, Automated Decision-Making Technology; Colorado Attorney General: implementation and rulemakingSigned May 14, 2026; replaces the 2024 framework. The Attorney General identifies January 1, 2027 as the start of the new substantive requirements and reports ongoing rulemaking. This table reports the statutory timeline, not a conclusion about pending litigation.
- California Privacy Protection Agency: regulations on automated decisionmaking technology, risk assessments, and cybersecurity auditsEffective January 1, 2026; automated decisionmaking requirements apply from January 1, 2027. Sections 7001(ddd) and 7200 define the covered decisions and compliance timeline. Approved regulatory text.
- California SB 1000, AI Transparency Act amendments; September 30, 2026 signing announcementThe official announcement confirms enactment and the content-transparency purpose. This example describes the amendment without assigning a single compliance date to its different provisions.