Live intelligence page — updated automatically every morning by Di1’s agentic AI research pipeline. This information is provided without warranty and for educational purposes only. Last updated: September 26, 2026 at 06:18.
⏳ Compliance Countdown
| 4 days | NAIC AI Systems Evaluation Tool pilot concludes (2026-09-30) – 12-state NAIC pilot of the AI Systems Evaluation Tool runs March–September 2026, with tool revisions to follow in September/October 2026. source |
| 4 days | UK workplace monitoring technologies consultation closes (2026-09-30) – UK government consultation on workplace monitoring technologies (including AI-driven workforce analytics) closes for comment. source |
| 5 days | Connecticut AI Responsibility and Transparency Act (SB 5) — First Effective Date (2026-10-01) – First of three phased effective dates for Connecticut's AI Responsibility and Transparency Act. source |
| 17 days | NIST NVD Modernization RFI Comment Deadline (2026-10-13) – Deadline for stakeholders to submit written comments on NIST's Request for Information on AI-enabled vulnerability management and NVD modernization, via the Federal e-Rulemaking Portal. source |
| 19 days | NIST SP 1353 draft comment period closes (2026-10-15) – Comment period closes for NIST's draft Quick-Start Guide for using AI in CSF 2.0 analysis and reporting. source |
| 30 days | Colorado ADMT/Chatbot rules comment portal closes / public rulemaking hearing (2026-10-26) – Comment portal for Colorado's proposed ADMT Act and Chatbot Safety Act rules closes, coinciding with the public rulemaking hearing. source |
| 34 days | EDPB web scraping/GenAI guidance consultation closes (2026-10-30) – Public consultation period on EDPB draft guidance for web scraping in generative AI closes. source |
| 36 days | NAIC Fall National Meeting — AI Systems Evaluation Tool adoption consideration (2026-11-01) – NAIC will consider the revised AI Systems Evaluation Tool for formal adoption at its Fall National Meeting in November 2026. source |
| 67 days | EU AI Act Article 5 prohibitions on non-consensual intimate imagery and CSAM generation/manipulation apply (2026-12-02) – Prohibitions related to generation or manipulation of non-consensual intimate material and CSAM under the EU AI Act become applicable. source |
| 97 days | California SB 867 companion-chatbot toy ban takes effect (2027-01-01) – Five-year prohibition on offering or selling physical toys designed/marketed for children under 16 that include a companion chatbot; ban runs through January 1, 2031. source |
| 97 days | Colorado ADMT Act and Chatbot Safety Act rules take effect (2027-01-01) – Colorado's Automated Decision-Making Technology Act and Chatbot Safety Act, along with their implementing rules, become effective. source |
| 97 days | Illinois Artificial Intelligence Safety Measures Act (SB 315) Takes Effect (2027-01-01) – Law takes effect requiring third-party safety audits for large AI developers (>$500M revenue), publication of AI risk frameworks, reporting of critical safety incidents within 72 hours (24 hours for imminent threats), annual independent audits, and whistleblower protections. source |
| 97 days | Louisiana Data Privacy Act (LDPA) takes effect (2027-01-01) – Louisiana's new comprehensive consumer privacy law, following a controller/processor framework similar to Texas/Virginia/Colorado, takes effect January 1, 2027, enforced by the state attorney general. source |
| 97 days | New York RAISE Act takes effect (2027-01-01) – New York's Responsible AI Safety and Education Act (signed December 2025) goes into effect, creating an oversight office within the state Department of Financial Services to assess large frontier AI developers and enforce transparency requirements. source |
| 97 days | Utah Digital Content Provenance Standards Act takes effect (2027-01-01) – Utah's law mandating content provenance/metadata standards for AI-generated content becomes enforceable. source |
| 116 days | EU Machinery Regulation (EU) 2023/1230 supersedes Machinery Directive 2006/42/EC (2027-01-20) – New EU Machinery Regulation takes full legal effect, replacing the 2006 Machinery Directive; ISO 10218:2025 robot safety standard becomes mandatory for EU market access once formally listed in the Official Journal, relevant to embodied/physical AI security convergence and supplier readiness gaps. source |
| 128 days | Washington AI Provenance Law takes effect (2027-02-01) – Washington's AI content provenance law requiring cryptographic metadata and consumer-visible cues for AI-generated content becomes enforceable. source |
| 129 days | GPAI Code of Practice watermark interoperability deadline (2027-02-02) – Code of Practice signatories relying on watermarking for Article 50 transparency compliance must implement an interoperability solution for watermark detection. source |
| 156 days | NY AI Annual Reporting bill — first reports due (if enacted) (2027-03-01) (proposed) – Proposed NY bill S8706-B would require businesses with 50+ NY employees and all publicly traded companies to file annual reports on AI's impact on hiring/employment decisions, with first reports due as early as March 1, 2027 if enacted. source |
| 187 days | NY RAISE Act — employee notification deadline (2027-04-01) – Large AI developers covered by New York's RAISE Act must notify employees of their rights/obligations within 90 days after the Jan 1, 2027 effective date, upon hire, and via workplace postings. source |
| 278 days | Connecticut AI Responsibility and Transparency Act (SB 5) — Second Effective Date (2027-07-01) – Second of three phased effective dates for Connecticut's AI Responsibility and Transparency Act. source |
| 310 days | EU AI Act GPAI legacy provider compliance deadline (2027-08-02) – Providers of general-purpose AI models placed on the market before Aug 2, 2025 must fully comply with GPAI obligations under Article 111(3). source |
Reporting Window: September 11–26, 2026
A. REGULATION & POLICY
1. European Commission designates ChatGPT a “Very Large Online Search Engine” (VLOSE) under the DSA
The Commission formally designated ChatGPT under the Digital Services Act, triggering the heaviest DSA compliance tier — systemic risk assessment and mitigation obligations, including risks to fundamental rights. This runs parallel to, and independent of, OpenAI’s EU AI Act GPAI obligations, meaning the same product now faces two separate EU risk-assessment regimes with overlapping but distinct audit trails. Practical impact: GRC teams tracking OpenAI/ChatGPT as a vendor should expect new DSA-driven transparency reports (systemic risk audits, ad-targeting disclosures) alongside existing GPAI documentation — treat these as separate compliance artifacts, not duplicates.
Source: https://cdt.org/insights/cdt-europes-ai-bulletin-september-2026
2. Dutch DPA fines Uber €800M+ for automated account-deactivation decisions
Autoriteit Persoonsgegevens fined Uber for GDPR violations tied to fully automated decisions (deactivating driver accounts based on algorithmic behavior/review scoring) without adequate human review. This is one of the largest GDPR-AI enforcement actions to date and reinforces that “automated decision-making” liability (GDPR Art. 22) predates and stacks on top of EU AI Act high-risk obligations. Practical impact: Any HR/ops system using algorithmic scoring to trigger adverse actions (account suspension, termination, access revocation) needs a documented human-review step — this is now a proven enforcement pattern, not theoretical risk.
Source: https://cdt.org/insights/cdt-europes-ai-bulletin-september-2026
3. European Commission unveils proposed EU KIDS Act
New Commission proposal targets AI companions and conversational chatbots interacting with minors: bans on addictive design patterns, a requirement that a minor’s prior interaction data cannot be reused in later sessions, and mandatory risk testing for health/safety/fundamental-rights impacts. This complements (and will need reconciling with) the wave of US state child-safety chatbot laws (California SB 1119, SB 867). Practical impact: Vendors of companion/chatbot products serving EU users should start scoping session-isolation and design-pattern audits now
Also live: AI Threat Landscape · Di1 blog · Need help applying this to your organization? Book a consultation.

