The Regulatory
Horizon

The fear is of autonomy. The reflex is the record.

Not one instrument says what makes that record believable.

When a government decides a machine acted without a person, it does not reach for a ban. It reaches for a duty to record, to disclose, to keep a human in the loop — and to prove the human was there. Every instrument on this page is that reflex, at one of three stages of hardening.

Tier 1
Implemented

In force today. A duty a regulator can enforce, and in most of these cases already has.

Tier 2
Decided and dated

Enacted or adopted, with a fixed effective date. Certain law. The only question is the calendar.

Tier 3
Coming

Proposed, in consultation, or in committee. Given with its formal status and no invented date.

Every item quoted from its primary source · Last verified 18 September 2026
01The horizon on one page

Seventeen dates. Each one adds a duty to keep, produce, or prove a record.

WhenWhat landsWhereThe record duty it carries
NOWIn force today
SEC 17a-4 · FINRA 4511 · HIPAA audit controls · 21 CFR Part 11 · Reg B · GDPR Art. 22 · DORA · EU AI Act Art. 5, GPAI, Art. 50 · Cyber Resilience Act reporting · UK GDPR Arts. 22A–D · Korea AI Basic Act · China and India synthetic-content labelling · California, Texas, Illinois and New York state acts · NAIC bulletin in 24 states · Colorado officer attestation · OMB M-26-14 — the full inventory is section 02
US
US · EU · UK
KR · CN · IN
middot; EU
US · EU · UK
KR · CN · IN
middot; UK
KR
US · EU · UK
KR · CN · IN
middot; CN
US · EU · UK
KR · CN · IN
middot; IN
Records that exist, are complete, are unaltered, and can be produced. Each regime demands one or two of these. None demands all four.
1 OCT 2026
Connecticut Public Act 26-64 — surveillance-pricing disclosure
CT
A stated notice: “this price was increased by a price setting device using your personal data.”
2 DEC 2026
EU AI Act Article 50 marking deadline for systems placed on the market before August 2026 · Article 5 prohibitions extended to NCII and CSAM generation
EU
Machine-readable provenance on synthetic output.
9 DEC 2026
EU Product Liability Directive 2024/2853 — software is a product
EU
Fail to disclose the relevant evidence and the product is presumed defective. The record, or the presumption.
10 DEC 2026
Australia Privacy Act APP 1.7–1.9 — automated-decision transparency
AU
The privacy policy must describe every decision a computer program makes and the personal information it uses.
1 JAN 2027
Colorado SB26-189 automated decisions, three-year records | Colorado HB26-1263 chatbots | Colorado HB26-1139 AI in utilization review | New York RAISE Act frontier-model protocols and test records | California CCPA automated decision-making rules | CMS-0057-F prior-authorization APIs | Washington HB 2225 and Oregon ch. 85 chatbots | Utah SB 319 AI in health coverage
CO · NY · CA
WA · OR · UT
US federal
Decision records. Human review. Incident reports within 72 hours. Test records kept for the life of the model plus five years.
20 JAN 2027
EU Machinery Regulation 2023/1230 — AI enters machinery safety law by name
EU
Safety decision-making data kept one year. The tracing log of interventions and software versions kept five.
26 MAR 2027
European Health Data Space — general application
EU
Access logging on health data begins its phase-in.
1 MAY 2027
Canada OSFI Guideline E-23 — model risk management
CA
An “accurate, evergreen” inventory of every model, with documentation and monitoring.
1 JUL 2027
California SB 1119, “Adam’s Law” — companion chatbots | California SB 243 first annual reports
CA
Risk assessments documented. Independent audits certified under penalty of perjury. Conversation records preserved for three years.
2 DEC 2027
EU AI Act Annex III — high-risk systems: Article 12 logging, Article 14 human oversight, Articles 19 and 26(6) retention, Article 49 registration, Article 73 incident reporting
EU
The logging duty itself. “Automatic recording of events over the lifetime of the system.”
11 DEC 2027
EU Cyber Resilience Act — full application
EU
Conformity, vulnerability handling and technical documentation for every product with digital elements — AI software included.
1 JAN 2028
Illinois PA 104-0568 — every downcoding determination reviewed by a natural person | California SB 813 — criteria for independent verification organisations
IL · CA
Proof that a person reviewed. Standards for who may verify.
1 APR 2028
California CCPA — risk-assessment attestations
CA
Attested assessments, filed.
2 AUG 2028
EU AI Act Annex I — AI embedded in machinery, vehicles and medical devices
EU
Logging inside the product.
1 JAN 2029
California AB 1405 — AI Auditor Registry | SB 1119 first audits due
CA
Registered auditors. Audit records retained ten years.
26 MAR 2029
European Health Data Space — logging component mandatory in EHR systems
EU
Per access: who, what, and when.

Every date on this calendar moves a duty from Tier 2 to Tier 1. None of them moves the question of what makes the record believable.

02Tier 1 — Implemented, by industry

What a regulator can enforce today, in the regulator’s own words.

Financial services$2.3 billion · 95 actions · recordkeeping alone
SEC Rule 17a-4(f)(2)(i)
In force · enforced since 2021
“A complete time-stamped audit trail that includes all modifications to and deletions of the record … the identity of the individual.”17 C.F.R. § 240.17a-4
$2.3 billion in penalties across 95 off-channel actions — SEC, 7 April 2026
FINRA Rule 4511, Advisers Act Rule 204-2 and CFTC Rule 1.31(c) — systems that “ensure the authenticity” of the record — carry the same duty across broker-dealers, advisers and derivatives.
FINRA 2026 Regulatory Oversight Report
Published · effective practices for GenAI and agents
“Storing prompt and output logs for accountability … tracking which model version was used and when.”FINRA, 2026 Annual Regulatory Oversight Report
EU DORA
In force since 17 January 2025
Financial entities shall “record all ICT-related incidents” and keep a register of every ICT third-party arrangement.Regulation (EU) 2022/2554
On 31 July 2026 the three European Supervisory Authorities called for “robust governance and risk management frameworks … to support the effective management and mitigation of cyber risks associated with frontier AI models.”
Federal Reserve SR 26-2 · OCC 2026-13
17 April 2026 · the gap
Generative and agentic AI “are not within the scope of this guidance.”Federal Reserve, SR 26-2
US banks have no supervisory guidance on agents. The rescission of SR 11-7 removed the model-risk framework and put nothing in its place for autonomous systems.
Insurance24 states and DC · officer attestation since 1 July 2026
Colorado Regulation 10-1-1
In force · first attested reports due from 1 July 2026
A “documented up-to-date inventory, including version control,” and an annual report “signed by an officer attesting to compliance.”Colorado Division of Insurance
NAIC Model Bulletin on AI Systems
Adopted in 24 states and DC as of 31 August 2026
A written AI systems program, with inventories and documentation produced on examination.NAIC adoption map
New York DFS Circular Letter 7 requires “comprehensive documentation for their use of all AIS,” auditable under Insurance Law § 309.
Texas Department of Insurance B-0003-26
12 June 2026
“TDI expects a person to review and agree with all decisions before action is taken.”Texas Department of Insurance
EIOPA Opinion on AI governance
6 August 2025
Retain “training and testing data and the modelling methodologies to enable their reproducibility and traceability.”EIOPA
HealthcareThe log itself is now the penalty
HIPAA Security Rule § 164.312(b), (c)(1)
In force · enforced for the audit log itself
“Record and examine activity” in systems holding health information, and protect it from “improper alteration or destruction.”45 C.F.R. § 164.312
Ambry Genetics $700,000, 17 September 2026 · Gulf Coast $1.19 million · OHSU $200,000 for a late record
Section 1557, § 92.210
In force since 1 May 2025
An “ongoing duty to make reasonable efforts to identify uses of patient care decision support tools.”45 C.F.R. § 92.210
CMS-0057-F · CMS WISeR
In force since 1 January 2026
A “specific reason for denied prior authorization decisions, regardless of the method used.”CMS Interoperability and Prior Authorization Final Rule
Under WISeR, AI screens prior authorization in six states, and “all recommendations for non-payment are determined by appropriately licensed clinicians.”
Illinois Wellness and Oversight for Psychological Resources Act
In force · $10,000 per violation
AI may not make therapeutic decisions.Illinois IDFPR
Life sciencesFDA’s first AI-agent warning letter · 2 April 2026
21 CFR 11.10(e)
In force · audit-trail warning letters March to May 2026
“Secure, computer-generated, time-stamped audit trails … Record changes shall not obscure previously recorded information.”21 C.F.R. § 11.10(e)
Warning letters on the audit trail alone: Intas (30 March 2026), Ava (14 April 2026), GC America (14 May 2026).
FDA warning letter, Purolea
2 April 2026
“Any output or recommendations from an AI agent must be reviewed and cleared by an authorized human.”FDA
ICH E6(R3)
EU 23 July 2025 · FDA 9 September 2025
Changes to clinical-trial data must be “traceable” and “should not obscure the original entry.”ICH E6(R3) Good Clinical Practice
Decisions about people€824,990,000 · 21 August 2026
GDPR Article 22
In force · enforced at scale
“There was no human assessment here. This occurred between 2018 and 2022.”Autoriteit Persoonsgegevens, on the Uber fine
Uber, €824,990,000 — drivers deactivated by software, with no human assessment
The Court of Justice, in Dun & Bradstreet (27 February 2025): the data subject is owed “the procedure and principles actually applied.”
UK GDPR Articles 22A–22D
Commenced 5 February 2026
“Provide the data subject with information about decisions,” “enable … representations,” “obtain human intervention,” “contest such decisions.”Data (Use and Access) Act 2025, s. 80
Regulation B, § 1002.12
In force · 25-month retention
Retain all “written or recorded information used in evaluating the application.”12 C.F.R. § 1002.12
Illinois HB 3773 · NYC Local Law 144
Illinois 1 January 2026 · NYC since July 2023
Notice to employees of AI use in employment decisions; annual bias audits of automated hiring tools.Illinois Human Rights Act · NYC Local Law 144
Machines$27,874 per violation per day
NHTSA Standing General Order 2021-01
Third amendment effective 16 June 2025
Crash reports within five days; “materially new or materially different information” triggers an update; penalties “up to $27,874 per violation per day.”NHTSA
Cruise: $1.5 million civil penalty and a $500,000 deferred-prosecution agreement for an incomplete report
California DMV autonomous-vehicle regulations
28 April 2026
Reporting of “system failures, vehicle immobilizations and hard braking events.”California DMV
UN Regulation 157 · EU 2022/1426
In force
Event data recorders with “adequate protection against manipulation (e.g. data erasure).”UN R157, DSSAD
UN R155 requires a “data forensic capability” in every type-approved vehicle.
Consumer-facing AITell the person they are talking to a machine
EU AI Act Article 50
In force since 2 August 2026
Persons must be “informed that they are interacting with an AI system.”Regulation (EU) 2024/1689
New York GBL Article 47 · California SB 243
5 November 2025 · 1 January 2026
The user “is not communicating with a human” — $15,000 per day in New York; $1,000 per violation and a private right of action in California.NY GBL § 1702 · Cal. Bus. & Prof. Code § 22602
California’s AI Transparency Act (SB 942) became operative 2 August 2026. The full set of six state chatbot statutes is on the Clocks.
UK Online Safety Act, s. 23
In force
“A duty to make and keep a written record … of every risk assessment.”Online Safety Act 2023
Federal Trade Commission
Orders 2025–2026 · Section 6(b) inquiry, 11 September 2025
Consent orders against Air AI, Workado and DoNotPay impose substantiation and record-retention duties; the companion-chatbot inquiry is open.FTC
Governments regulating themselvesThe first federal tamper-evidence duty for logs
OMB Memorandum M-26-14
22 May 2026 · Intermediate maturity 18 November 2026 · Advanced 7 April 2027
Agency logs must support “determining the identity used for performing operations,” carry a “consistently accurate timestamp,” and be “encrypted in transit and at rest, and regularly hashed for veracity.”Office of Management and Budget
This is the first federal instrument to state that a log must be provably unaltered. It applies to the government’s own systems — the duty it will expect of everyone else, stated first for itself.
OMB M-25-21 · UK Algorithmic Transparency Recording Standard
In force · 152 UK records as of 9 September 2026
AI use-case inventories; for high-impact AI, pre-deployment testing, impact assessments, and “timely human review and a chance to appeal.”OMB M-25-21
EU Cyber Resilience Act, Article 14
Reporting duties in force since 11 September 2026
Actively exploited vulnerabilities and severe incidents: early warning within 24 hours, notification within 72 hours, final report within 14 days.Regulation (EU) 2024/2847
Applies to every product with digital elements placed on the EU market — AI software included.
03Tier 2 — Decided and dated

Certain law. The only question is the calendar.

The instruments with the heaviest record content, in the order they land.

EU Product Liability Directive 2024/2853
9 December 2026
“The defectiveness of the product shall be presumed where … the defendant fails to disclose relevant evidence.”Article 10(2)(a)
Software is a product. The company that cannot produce the record of what its system did loses the presumption. The record is the defence.
EU Machinery Regulation 2023/1230
20 January 2027
“Recording of data on the safety related decision-making process … retained for one year”; the tracing log of interventions and software versions “for five years.”Annex III, 1.2.1
Colorado SB26-189 · HB26-1263 · HB26-1139
1 January 2027
Coverage denials cannot rely “solely on the output of an AI system without human review”; insurers report “the process for human oversight of adverse coverage determinations” and maintain “audit information.”Colorado HB26-1139
SB26-189 requires three-year records of automated decisions; the Attorney General’s rules were filed 11 August 2026.
New York RAISE Act
1 January 2027
“Maintain unredacted protocols and test records for duration of model deployment plus five years”; safety incidents reported “within 72 hours.”New York S6953-B
Utah SB 319
1 January 2027
Disclose AI use “to the department, to each health care provider … and to each enrollee”; adverse determinations made by a physician “exercising independent medical judgment.”Utah SB 319 (2026)
Canada OSFI Guideline E-23
1 May 2027
A “comprehensive inventory of models … accurate, evergreen, and subject to robust controls.”OSFI
California SB 1119, “Adam’s Law”
Chaptered 10 September 2026 · 1 July 2027
“Perform and document a comprehensive risk assessment”; independent child-safety audits certified “under penalty of perjury”; conversation records preserved for three years after a child’s death or serious self-harm.California SB 1119 (2026)
EU AI Act, Annex III and Annex I
2 December 2027 · 2 August 2028
“High-risk AI systems shall technically allow for the automatic recording of events (logs) over the lifetime of the system.”Article 12(1) · dates fixed by Regulation (EU) 2026/1744
Article 14 human oversight, six-month minimum log retention, Article 49 registration and Article 73 incident reporting land the same day. Penalty tier: €15 million or 3% of worldwide turnover.
Illinois PA 104-0568
1 January 2028
“All downcoding determinations be reviewed by a natural person.”Illinois Public Act 104-0568
California AB 1405 · SB 813
Chaptered 9 September 2026 · 1 January 2028 and 2029
An AI Auditor Registry from 1 January 2029, with audit records “retained 10 years minimum”; criteria for independent verification organisations by 1 January 2028.California AB 1405 · SB 813 (2026)
European Health Data Space
26 March 2027 · logging 26 March 2029
Every access to electronic health data logged: the identity of the accessor, the categories of data, and the time.Regulation (EU) 2025/327
04Tier 3 — Coming

Proposed, in consultation, in committee. Each with its formal status and no invented date.

WhereWhatStatus
US federal
FTC Policy Statement on Suppression of Accuracy in AI Systems — steering an AI toward undisclosed objectives is Section 5 deception; disclosures must be “clear and conspicuous,” not “buried in terms of service.”
Proposed 1 July 2026. Comments closed 31 July. Final adoption pending.
US federal
FINRA Regulatory Notice 26-14 — AI-generated communications; members “maintain evidence that these supervisory procedures have been implemented and carried out.”
Comments closed 11 September 2026. Next step: SEC filing.
US federal
NIST AI Agent Standards Initiative — agent identity and authorization; sector listening sessions; CAISI red-teaming findings.
Launched 17 February 2026. Voluntary standards in progress — the likely seed of any later mandate.
US federal
National AI Legislative Framework — the White House position that “a patchwork of conflicting state laws would undermine American innovation.”
Announced 20 March 2026. No bill number, no sponsor. Forty-four state Attorneys General oppose. Nothing enacted.
US federal
HHS HTI-5 — proposes to “fully remove the artificial intelligence (AI) ‘model card’ requirements.”
Comments closed 27 February 2026. No final rule. A loosening.
US courts
Proposed Federal Rule of Evidence 707 — machine-generated evidence held to expert-witness standards of reliability.
Information item only at the June 2026 Standing Committee. Earliest effective date 1 December 2028.
US states
NAIC AI Risk Evaluation Supplement v5.0 and a third-party data and models framework.
Comments to 29 September 2026. Working-group call 8 October 2026.
US states
Colorado Attorney General rules under SB26-189 and HB26-1263.
Comments to 26 October 2026. Adoption before 1 January 2027.
EU
ISO/IEC 24970, AI system logging and prEN 18229-1, the harmonised logging standard under the AI Act.
ISO ballot opened 28 August 2026. The logging standard lands within months.
EU
Digital Omnibus — would permit automated decisions where “necessary for contract performance,” and unify incident reporting across NIS2, DORA, GDPR and the CRA.
Proposal of 19 November 2025. Parliament and Council positions pending. A loosening of the text, arriving as enforcement of the current text reached €825 million.
EU
GMP Annex 22 on AI — would require human review of every critical output in pharmaceutical manufacturing.
Draft. Not adopted as of July 2026.
China
Initiative on Global AI Agent Governance; agent-security standards from TC260.
Announced July 2026. Standards in draft.
Korea
AI Basic Act — in force since 22 January 2026.
Fines deferred for one year. Enforcement from about January 2027.

Two currents run against each other, and both are real.

Tightening
Sector regulators, courts, the states, the EU and Asia.
“A computer should not make decisions on its own that have major consequences for you. These decisions should have been looked at first by a human being.”
Dutch Data Protection Authority · 21 August 2026
“Our frameworks were not built to contemplate autonomous agents, and relying on a human in the loop for all agent actions is unlikely to be realistic.”
Bank of England · 30 June 2026
“Any output or recommendations from an AI agent must be reviewed and cleared by an authorized human.”
FDA · 2 April 2026
Logs “regularly hashed for veracity.”
OMB M-26-14 · 22 May 2026
Loosening
The US federal executive — with no preemption enacted.
Generative and agentic AI “are not within the scope of this guidance.”
Federal Reserve SR 26-2 · 17 April 2026
“The SEC will not prescribe the specific models that firms must employ — we are not a merit regulator.”
SEC Chairman · 10 September 2026
Nothing “shall be construed to authorize … a mandatory governmental licensing, preclearance, or permitting requirement.”
Executive Order 14409 · 2 June 2026
The loosening does not reach the record rules that carry the largest penalties: 17a-4, HIPAA, Part 11, GDPR.
The durable duties
05The duty, in their words

Every duty on this page asks for one of four things. Each one, TIE demonstrates.

“automatic recording of events” · “record and examine activity” · “time-stamped audit trails” · “recording of data on the safety related decision-making process”
Recorded
“a complete time-stamped audit trail” · “all written or recorded information” · “accurate and complete”
Complete
“all modifications to and deletions” · “shall not obscure previously recorded information” · “improper alteration or destruction” · “regularly hashed for veracity” · “protection against manipulation”
Unchanged
“fails to disclose relevant evidence” → presumed defective · “available for agency review” · “meaningful information about the logic” · audits “under penalty of perjury”
Verifiable

Every tier is the same reflex at a different stage of hardening. The law has finished telling you to keep the record.

What makes it believable, TIE proves.

What a believable record requires →
Sources, all primary, last verified 18 September 2026

This page carries only instruments confirmed against their primary text. Proposed measures appear with their formal status and no projected date. Items that could not be confirmed against a primary source on the verification date are not listed. Reviewed on each horizon date and monthly between them.