Skip to content

Regulatory horizon

What is coming, and when

UK and EU cyber security and AI obligations, each with a date, a status, who it affects and the primary source it was checked against.

Last verified 25 August 2026 · 11 obligations tracked

Why this exists

Regulatory deadlines in cyber security and AI move, and the moves are not always well publicised. The EU AI Act’s Annex III high-risk obligations were deferred from 2 August 2026 to 2 December 2027 by Regulation (EU) 2026/1744, which entered into force days before the original date. Every entry below carries the source it was verified against and the day it was read.

How this is maintained

Dates live in a single source file with a verified date and a source URL per entry, and a build check fails if an entry has not been re-read within thirty days. Nothing here is hardcoded into a page. Where a date could not be confirmed against the primary text directly, that is stated rather than glossed.

Current caveat: EUR-Lex served HTTP 202 with an empty body to automated requests during this verification pass, so the AI Act dates were taken from the European Commission's own regulatory-framework-ai page rather than the Official Journal text directly. Re-check against EUR-Lex by hand before launch.

Regulatory horizon

Every obligation we track

Last verified 25 August 2026 · 11 obligations tracked

UK and EU cyber security and AI governance obligations, with the date each applies, who it affects and the source it was verified against on 25 August 2026.
ObligationDateStatusWho it hitsSource
EU AI ActAnnex III standalone high-risk system obligations applyDeferred from 2 August 2026 by Regulation (EU) 2026/1744, the Digital Omnibus on AI, which entered into force on 27 July 2026. A 16-month deferral, granted because harmonised standards and national competent authorities were not ready. The obligation was postponed, not withdrawn.14 months awayDeferredProviders and deployers of AI used in employment, education, credit and insurance scoring, essential services, law enforcement, migration and the administration of justice.How we handle this ->European Commission, Shaping Europe's digital futureRead 25 August 2026
EU AI ActAnnex I high-risk obligations apply to AI embedded in regulated productsDeferred by Regulation (EU) 2026/1744, the Digital Omnibus on AI. A 12-month deferral.22 months awayDeferredManufacturers placing AI inside products already covered by EU product-safety law - medical devices, machinery, lifts, toys, vehicles.How we handle this ->European Commission, Shaping Europe's digital futureRead 25 August 2026
UK Cyber Security and Resilience BillBefore Parliament. Not yet law, and no commencement date is set.Introduced to the Commons on 12 November 2025. Passed Commons stages and moved to the Lords. Commencement is staged from Royal Assent, with the substantive duties left to secondary legislation. The government has said it intends to consult on implementation during 2026.Before ParliamentIf enacted as drafted: existing NIS sectors plus medium and large managed service providers, data centres, large load controllers and designated critical suppliers. Initial incident notification within 24 hours, fuller report within 72.How we handle this ->GOV.UK, Cyber Security and Resilience Bill factsheets (page last updated 30 June 2026)Read 25 August 2026
EU AI ActArticle 50 transparency obligations apply2 months agoIn forceAny provider or deployer whose AI interacts with people or generates synthetic audio, image, video or text. Chatbots must disclose they are machines; synthetic media must be machine-readably marked.How we handle this ->European Commission, Shaping Europe's digital futureRead 25 August 2026
Cyber EssentialsRequirements for IT Infrastructure v3.3 and the Danzell question set applyStricter marking on MFA and on timely security updates, where a shortfall is now an automatic fail rather than a finding. Greater emphasis on passwordless authentication and passkeys. Scoping tightened: any specified device connected to the internet is in scope.5 months agoIn forceEvery organisation certifying or recertifying. Applies to all applications registered from 27 April 2026.How we handle this ->IASME, Cyber Essentials delivery partner for the NCSCRead 25 August 2026
EU AI ActGeneral-purpose AI model obligations and the governance regime apply14 months agoIn forceProviders of general-purpose AI models, and every organisation that builds on one and inherits its documentation obligations.How we handle this ->European Commission, Shaping Europe's digital futureRead 25 August 2026
PCI DSS v4.xThe 51 future-dated requirements are mandatory in every assessment18 months agoIn forceEvery organisation that stores, processes or transmits cardholder data. v3.2.1 was retired on 31 March 2024.How we handle this ->PCI Security Standards CouncilRead 25 August 2026
EU AI ActProhibited AI practices banned, and AI literacy obligations apply20 months agoIn forceEvery organisation placing AI on the EU market or using AI whose output is used in the EU.How we handle this ->European Commission, Shaping Europe's digital futureRead 25 August 2026
DORADigital Operational Resilience Act applies in full21 months agoIn forceBanks, insurers, investment firms and other EU financial entities, plus the ICT third-party providers that serve them.How we handle this ->European Commission, Directorate-General for Financial StabilityRead 25 August 2026
NIS2Member State transposition deadline passedTransposition remains incomplete. The European Commission has referred Ireland, Spain, France and the Netherlands to the Court of Justice for failing to transpose. Obligations therefore bite on different dates in different Member States, which matters if you operate across borders.since 2024In forceEssential and important entities across energy, transport, health, water, digital infrastructure, public administration and space.How we handle this ->European Commission, NIS2 transposition trackerRead 25 August 2026
ISO/IEC 42001Certifiable nowPublished December 2023 as the first international AI management system standard. It is not a legal obligation, but it is the most direct way to evidence the governance the EU AI Act assumes you already have.since 2023In forceAny organisation developing, providing or using AI that needs to evidence responsible practice to a regulator, a customer or an investor.How we handle this ->ISORead 25 August 2026

Free tools

Work out which of these actually reach you.

Nothing is gated. Each one shows you the answer before it asks you for anything, and every date and rate carries the source it came from.

Every tool we publish lives at cloudgap.ai/tools.