Organizations should map where they operate, whose data they process, whether AI influences consequential decisions, and whether they act as a provider, deployer, developer, or vendor.
EU AI ACT
Prohibitions, AI literacy, GPAI and core rules
Prohibited-practice and AI-literacy duties have applied since February 2025; GPAI duties since August 2025; most remaining provisions and enforcement applied from August 2026.
New York City Local Law 144 restricts use of covered automated employment decision tools without a recent independent bias audit, public summary, and required notices.
Anti-discrimination, consumer protection, financial, health, employment, safety, cybersecurity, recordkeeping, and contractual duties may apply even without an AI-specific law.
InventoryIdentify owned, embedded, experimental, and vendor-provided AI systems.
ClassifyRecord purpose, people affected, geography, system role, data, and risk tier.
AssignName accountable business owners and independent review functions.
ControlDefine approvals, testing, human oversight, monitoring, incidents, and exceptions.
EvidenceRetain decisions, test results, versions, notices, approvals, and vendor documentation.
This is a governance readiness baseline developed by The Neitsch Group. It is not itself a universal statutory checklist.
REGULATORY HORIZON
Key milestones through 2030.
Confirmed dates are distinguished from planning horizons. Monitor official sources because legislative and implementation dates can change.
IN FORCE / IMMEDIATE
Operationalize transparency and baseline governance
EU AI Act transparency rules apply from August 2026, alongside existing privacy, employment, consumer, sector, and contractual duties. Build the inventory, classification, literacy, disclosure, and evidence foundation now.
CONFIRMED EU MILESTONE
High-risk systems in sensitive areas
EU requirements apply to specified high-risk uses including employment, education, essential services, biometrics, critical infrastructure, migration, and law enforcement. Expected work includes risk management, data governance, logging, documentation, human oversight, accuracy, robustness, and cybersecurity.
CONFIRMED EU MILESTONE
High-risk AI embedded in regulated products
The extended transition applies to high-risk systems that are safety components of products covered by specified EU product-safety legislation.
PLANNING HORIZON
State, sector, procurement and assurance expansion
Expect overlapping requirements around impact assessment, consequential decisions, notice, contestability, testing, vendor diligence, cybersecurity, and documentation. Maintain a regulatory register rather than designing around one statute.
TARGET OPERATING STATE
Continuous, evidence-led governance
Move from periodic policy exercises to a governed system lifecycle: discovery, classification, approval, data controls, evaluation, monitoring, incident response, change control, retirement, and board reporting.
Answer eight questions. The score combines inherent exposure with missing governance controls. Your answers stay in this browser and are not submitted.
0–29 Managed30–54 Material gaps55–100 Priority exposure