AI & DATA GOVERNANCE • 2026–2030

Know what is coming.
Know where you stand.

A practical regulatory horizon and a scored readiness check for organizations developing, buying, or deploying AI.

Required nowBy year-end 20262027–2030Risk checker

THE BASELINE • REQUIRED NOW WHERE APPLICABLE

Governance obligations are already operating.

Organizations should map where they operate, whose data they process, whether AI influences consequential decisions, and whether they act as a provider, deployer, developer, or vendor.

EU AI ACT

Prohibitions, AI literacy, GPAI and core rules

Prohibited-practice and AI-literacy duties have applied since February 2025; GPAI duties since August 2025; most remaining provisions and enforcement applied from August 2026.

  • Classify systems and organizational role
  • Train personnel using or overseeing AI
  • Address transparency and provider/deployer duties
European Commission source ↗
PRIVACY & DATA PROTECTION

Lawful, transparent data use

GDPR, CCPA/CPRA and other privacy laws continue to govern personal data used to train, configure, operate, monitor, or evaluate AI.

  • Purpose, lawful basis, minimization and retention
  • Rights handling and vendor controls
  • Security and risk assessment where required
California Privacy Protection Agency ↗
AUTOMATED EMPLOYMENT

Bias audit and notice duties

New York City Local Law 144 restricts use of covered automated employment decision tools without a recent independent bias audit, public summary, and required notices.

  • Determine whether the tool is covered
  • Complete and publish the bias audit
  • Give candidate or employee notice
NYC enforcement guidance ↗
SECTOR & CONTRACT

Existing rules still reach AI

Anti-discrimination, consumer protection, financial, health, employment, safety, cybersecurity, recordkeeping, and contractual duties may apply even without an AI-specific law.

  • Map decisions to existing obligations
  • Preserve evidence and oversight
  • Challenge vendor representations
NIST AI RMF reference ↗

BY 31 DECEMBER 2026

The minimum defensible position.

  1. InventoryIdentify owned, embedded, experimental, and vendor-provided AI systems.
  2. ClassifyRecord purpose, people affected, geography, system role, data, and risk tier.
  3. AssignName accountable business owners and independent review functions.
  4. ControlDefine approvals, testing, human oversight, monitoring, incidents, and exceptions.
  5. EvidenceRetain decisions, test results, versions, notices, approvals, and vendor documentation.

This is a governance readiness baseline developed by The Neitsch Group. It is not itself a universal statutory checklist.

REGULATORY HORIZON

Key milestones through 2030.

Confirmed dates are distinguished from planning horizons. Monitor official sources because legislative and implementation dates can change.

IN FORCE / IMMEDIATE

Operationalize transparency and baseline governance

EU AI Act transparency rules apply from August 2026, alongside existing privacy, employment, consumer, sector, and contractual duties. Build the inventory, classification, literacy, disclosure, and evidence foundation now.

CONFIRMED EU MILESTONE

High-risk systems in sensitive areas

EU requirements apply to specified high-risk uses including employment, education, essential services, biometrics, critical infrastructure, migration, and law enforcement. Expected work includes risk management, data governance, logging, documentation, human oversight, accuracy, robustness, and cybersecurity.

CONFIRMED EU MILESTONE

High-risk AI embedded in regulated products

The extended transition applies to high-risk systems that are safety components of products covered by specified EU product-safety legislation.

PLANNING HORIZON

State, sector, procurement and assurance expansion

Expect overlapping requirements around impact assessment, consequential decisions, notice, contestability, testing, vendor diligence, cybersecurity, and documentation. Maintain a regulatory register rather than designing around one statute.

TARGET OPERATING STATE

Continuous, evidence-led governance

Move from periodic policy exercises to a governed system lifecycle: discovery, classification, approval, data controls, evaluation, monitoring, incident response, change control, retirement, and board reporting.

Authoritative anchors: European Commission AI Act timeline, California Privacy Protection Agency, NYC DCWP, and NIST AI RMF. NIST AI RMF is voluntary guidance unless incorporated into another obligation.

5-MINUTE GOVERNANCE RISK CHECKER

How exposed is your organization?

Answer eight questions. The score combines inherent exposure with missing governance controls. Your answers stay in this browser and are not submitted.

0–29 Managed30–54 Material gaps55–100 Priority exposure

Educational screening only. The score does not determine compliance, legal exposure, certification, or the applicability of any law.

THE SCORE IS A STARTING POINT

Turn uncertainty into a defensible plan.

We can help validate applicability, prioritize gaps, and define the work ahead.

Book a conversation ↗