EU AI Act in 2026: Which Deadlines Moved—and Which Duties Did Not?
A dated owner’s map of the EU AI Act after the 2026 AI Omnibus, separating live transparency and GPAI rules from delayed high-risk duties.
Dated implementation radar
Time-stamped, official-source explainers for EU and US requirements that can alter product, data, cyber and market-access decisions.
Which trigger, date or role determines whether this change reaches the business?
Evidence cutoff: 12 August 2026. Read each article's status note and recheck its official sources before acting.
Start here
Begin with a representative mechanism, then use the grouped paths below to go deeper.
Design before pressure
A Canadian laboratory breach investigation shows why payment, returned data and regulator findings answer different incident questions.
A health-privacy settlement shows why reputation response authority should be separated from access to customer facts.
California's workplace guidance shows how smoke, doors and ventilation can control operations far beyond an evacuation or damage map.
A list of AI tools becomes more useful when it records the decision use, affected people, data path, owner and material-change triggers.
A source-to-claim record for checking environmental statements received from suppliers before they reach products, sales material or customers.
A source-bounded guide to separating a public vulnerability signal from asset applicability, remediation choices, exceptions and recheck ownership.
A UK-source-bounded guide separating section 54 framework facts from entity, group and supplier evidence questions that remain unassessed.
Check the live trigger
A Hamburg regulator's retailer decision shows how access configuration, retention, and sensitive workplace notes can become one connected governance problem.
Canadian privacy findings involving an app's background location collection show how an abandoned business plan can leave a live data practice behind.
CNIL's platform provider decision shows why layered notices and consent design can become the practical object of regulatory scrutiny, not a footer detail.
An ICO penalty notice shows how a hidden spreadsheet tab turned a redaction mistake into a safety and workforce problem.
A voice-assistant order shows why a deletion request may have a different technical meaning once children's voice and location data feed algorithmic systems.
A battery-passport project needs a governed product and lifecycle data path, not a supplier file detached from category, version and correction authority.
Before treating a data carrier as the solution, map which product rules apply and who creates, validates, updates and corrects each data element.
A DORA-related subcontracting map should connect an ICT service to its function, sub-provider, change route and exit dependency without assuming every vendor is in scope.
A regulatory-radar guide to mapping role, purpose, user journey, requested attributes, evidence, data boundaries and change governance before integration.
A supplier questionnaire can inform a NIS2-related review, but scope, supplier criticality, evidence, ownership and national implementation remain separate questions.
A source-aware method for connecting packaging facts, supplier statements, public wording, product versions and review decisions without claiming substantiation.
An EU-source-bounded analysis separating PLD liability from CRA cybersecurity while preserving version, evidence and unresolved product questions.
A 2026 CBAM trigger map for EU importers, covering the definitive phase, the annual 50-tonne threshold, authorisation and the first declaration.
A current CSDDD map after Directive (EU) 2026/470, separating the new thresholds and 2029 application date from supplier-request pressure.
A current EUDR trigger map for operators, traders and downstream businesses, including the December 2026 and June 2027 application dates.
A practical General Product Safety Regulation map for online sellers, importers and marketplaces, covering listing data, responsible persons and evidence.
A dated PPWR milestone map for packaging manufacturers, importers, brands and online sellers after the Regulation’s 12 August 2026 application date.
A current FinCEN BOI map separating the operative March 2025 rule from the August 2026 final rule awaiting Federal Register publication.
A scoped guide to the European Accessibility Act for consumer e-commerce, including the service microenterprise exemption and national-law limits.
A practical CRA preparation map for digital-product businesses, separating September 2026 reporting from the December 2027 main obligations.
What business owners should verify under the EU Data Act now, before the connected-product design and cloud switching milestones arrive.
A business-owner map of selected U.S. federal and state privacy and cyber triggers, including California’s 2026 rules and DROP duties.
A practical change-control design for supplier, origin, ownership, routing and payment shifts that can alter trade risk after onboarding.
A practical UFLPA evidence map for U.S. importers, covering the rebuttable presumption, traceability records, supplier controls and detention readiness.
Optional analytics
Privacy-limited Cloudflare Web Analytics is off unless you allow it. It is not used for advertising, cross-site tracking or profiling.
Analytics has not been selected.
Read the analytics details. You can change this choice at any time.