Question 34 of 53
How do we prepare for AI regulation over the next 12 months?
By Cody Maxwell · AI Governance Institute · September 2026 · Last verified September 13, 2026
Identify regulations becoming enforceable in your jurisdictions over the next year. Assess gaps and fund a remediation plan.
▸Editorial status
- September 13, 2026 · Substantive update — The article mentions California's AI legislation pipeline as active but provides no specifics. The California AI Transparency Act (SB 942 as amended by AB 853) has a concrete operative date of 2 August 2026 and imposes specific, distinctive obligations (free detection tool, latent disclosures, 96-hour license revocation) that fall squarely within the article's 12-month planning horizon and gap assessment framing. A practitioner relying on this article to prepare for near-term regulation would miss a significant, actionable California deadline. (AI Governance Institute pipeline)
- September 7, 2026 · Substantive update — Reworked the EU AI Act near-term deadline paragraph for the Regulation (EU) 2026/1744 deferral. (Cody Maxwell)
If you only do 3 things, do this:
- 1.Build a 12-month regulatory calendar specific to your jurisdictions and use cases. Generic "AI regulation is coming" awareness is not preparation. Specific deadlines with owners are.
- 2.Run a gap assessment against each incoming obligation before the deadline, not at it. A gap assessment at the deadline leaves you no remediation time.
- 3.Assign a named person to monitor regulatory developments. This is not a once-a-year activity. Regulators publish guidance, interpretations, and enforcement priorities continuously.
The Situation
Who this is for: Compliance and legal teams responsible for anticipating and preparing for AI regulatory obligations
When you need this: During annual planning cycles, when new AI regulation is announced in your jurisdiction, or when board or executive leadership asks about regulatory preparedness
The Decision
What regulatory changes are coming for us in the next 12 months, where are our gaps, and what do we need to do now to be ready?
The Steps
- 1Identify which regulations become effective or enforceable in your key jurisdictions over the next 12 months
- 2For each upcoming obligation, assess your current compliance state: ready, gap identified, or not started
- 3Build a remediation roadmap: what needs to be done, by when, owned by whom, and at what cost?
- 4Prioritize by risk: regulations with enforcement penalties and short deadlines first
- 5Allocate resources (staff, budget, external counsel) for the remediation activities on the critical path
- 6Implement a quarterly regulatory monitoring process so you're not caught off-guard again
The Artifacts
- —12-month AI regulatory calendar (key obligations and deadlines by jurisdiction)
- —Compliance gap assessment template (incoming obligation × current state × required action)
- —Remediation roadmap template (action, owner, deadline, cost, dependencies)
- —Regulatory monitoring process template (sources, cadence, owner, escalation)
- —Board and executive regulatory briefing template
The Output
A 12-month regulatory calendar for your specific jurisdictions and use cases, a gap assessment for each incoming obligation, a funded remediation roadmap, and a monitoring process that keeps you current.
Key deadlines in the near term
The EU AI Act's high-risk obligations were the headline near-term deadline until Regulation (EU) 2026/1744 deferred them. Stand-alone Annex III systems now have until 2 December 2027, and embedded product systems until 2 August 2028, for conformity assessments, technical documentation, and EU database registration. GPAI model obligations became applicable in August 2025 and were not deferred. All of these apply to non-EU organizations with EU market exposure.
In the US, the state-level regulatory calendar is accelerating. Colorado SB 205 is in effect. New York City's Local Law 144 on AI in hiring is in effect and being enforced. Illinois BIPA continues to generate significant class action exposure for biometric AI. California's AI-related legislation pipeline is active. Financial services and healthcare organizations face ongoing guidance from sector regulators that imposes AI-specific obligations without waiting for comprehensive AI legislation.
Running a gap assessment against an incoming regulation
A gap assessment maps each specific obligation in an incoming regulation against your current state. For each obligation, the assessment should answer: do we have a process, policy, or control that satisfies this requirement? If yes, is it documented and operating? If not, what would it take to build it?
The output is a prioritized list of gaps with effort and risk estimates. High-effort, high-risk gaps on short timelines are your critical path items. Low-effort gaps can often be resolved quickly: mandatory disclosure language, for example, requires a policy update and a template, not a major project. Separating the quick wins from the complex buildouts allows you to show early progress while managing the longer-term work.
Building a regulatory monitoring process
Compliance teams that learn about regulatory changes from press coverage are behind. The organizations with the most effective regulatory monitoring have direct subscriptions to relevant agency publications, track active legislation in their key jurisdictions through government and legal databases, and have established relationships with outside counsel who specialize in AI law and provide proactive alerts.
Monitoring needs to cover three categories: binding requirements (laws and regulations that create compliance obligations), guidance (interpretive documents from regulators that signal enforcement priorities and expected practices), and enforcement actions (cases that reveal how regulators apply the rules in practice). Enforcement actions are often the most informative: they demonstrate which obligations regulators are prioritizing, what documentation they expect to see, and what remediation they consider adequate.
California AI Transparency Act: what providers need to build before August 2026
The California AI Transparency Act (SB 942, as amended by AB 853) becomes operative on 2 August 2026, placing it within a typical 12-month preparation window for teams acting now. The law applies to providers of covered generative AI systems serving California consumers, including non-California developers whose systems reach California users. Three obligations stand out as requiring new technical or contractual infrastructure: a free, publicly accessible AI-detection tool capable of identifying content your system generated; latent disclosures embedded in all covered AI-generated content so provenance survives distribution; and license terms that expressly prohibit licensees from stripping or disabling those disclosure capabilities.
The revocation requirement deserves particular attention in your gap assessment. If you discover a licensee has removed or circumvented required disclosure functionality, you must revoke that licensee's access within 96 hours. Organizations that distribute generative AI through resellers or API partners will need contract language, a monitoring mechanism, and an operational process capable of executing revocation on that timeline. Teams that rely on quarterly contract reviews or manual enforcement will likely not meet that window without process changes.
Governance Controls
Operational controls that implement the guidance in this playbook.
Recent Coverage
News and developments relevant to this playbook topic.
Not sure where to start? Answer 3 questions and get a tailored compliance action plan.
What applies to me? →More guidance like this, every week
New playbook articles, governance controls, and the regulatory changes driving them. Every Thursday.
