Regulatory horizon
What is coming, and when
UK and EU cyber security and AI obligations, each with a date, a status, who it affects and the primary source it was checked against.
Last verified 25 August 2026 · 11 obligations tracked
Why this exists
Regulatory deadlines in cyber security and AI move, and the moves are not always well publicised. The EU AI Act’s Annex III high-risk obligations were deferred from 2 August 2026 to 2 December 2027 by Regulation (EU) 2026/1744, which entered into force days before the original date. Every entry below carries the source it was verified against and the day it was read.
How this is maintained
Dates live in a single source file with a verified date and a source URL per entry, and a build check fails if an entry has not been re-read within thirty days. Nothing here is hardcoded into a page. Where a date could not be confirmed against the primary text directly, that is stated rather than glossed.
Current caveat: EUR-Lex served HTTP 202 with an empty body to automated requests during this verification pass, so the AI Act dates were taken from the European Commission's own regulatory-framework-ai page rather than the Official Journal text directly. Re-check against EUR-Lex by hand before launch.
Regulatory horizon
Every obligation we track
Last verified 25 August 2026 · 11 obligations tracked
| Obligation | Date | Status | Who it hits | Source |
|---|---|---|---|---|
| EU AI ActAnnex III standalone high-risk system obligations applyDeferred from 2 August 2026 by Regulation (EU) 2026/1744, the Digital Omnibus on AI, which entered into force on 27 July 2026. A 16-month deferral, granted because harmonised standards and national competent authorities were not ready. The obligation was postponed, not withdrawn. | 14 months away | Deferred | Providers and deployers of AI used in employment, education, credit and insurance scoring, essential services, law enforcement, migration and the administration of justice.How we handle this -> | European Commission, Shaping Europe's digital futureRead 25 August 2026 |
| EU AI ActAnnex I high-risk obligations apply to AI embedded in regulated productsDeferred by Regulation (EU) 2026/1744, the Digital Omnibus on AI. A 12-month deferral. | 22 months away | Deferred | Manufacturers placing AI inside products already covered by EU product-safety law - medical devices, machinery, lifts, toys, vehicles.How we handle this -> | European Commission, Shaping Europe's digital futureRead 25 August 2026 |
| UK Cyber Security and Resilience BillBefore Parliament. Not yet law, and no commencement date is set.Introduced to the Commons on 12 November 2025. Passed Commons stages and moved to the Lords. Commencement is staged from Royal Assent, with the substantive duties left to secondary legislation. The government has said it intends to consult on implementation during 2026. | Before Parliament | If enacted as drafted: existing NIS sectors plus medium and large managed service providers, data centres, large load controllers and designated critical suppliers. Initial incident notification within 24 hours, fuller report within 72.How we handle this -> | GOV.UK, Cyber Security and Resilience Bill factsheets (page last updated 30 June 2026)Read 25 August 2026 | |
| EU AI ActArticle 50 transparency obligations apply | 2 months ago | In force | Any provider or deployer whose AI interacts with people or generates synthetic audio, image, video or text. Chatbots must disclose they are machines; synthetic media must be machine-readably marked.How we handle this -> | European Commission, Shaping Europe's digital futureRead 25 August 2026 |
| Cyber EssentialsRequirements for IT Infrastructure v3.3 and the Danzell question set applyStricter marking on MFA and on timely security updates, where a shortfall is now an automatic fail rather than a finding. Greater emphasis on passwordless authentication and passkeys. Scoping tightened: any specified device connected to the internet is in scope. | 5 months ago | In force | Every organisation certifying or recertifying. Applies to all applications registered from 27 April 2026.How we handle this -> | IASME, Cyber Essentials delivery partner for the NCSCRead 25 August 2026 |
| EU AI ActGeneral-purpose AI model obligations and the governance regime apply | 14 months ago | In force | Providers of general-purpose AI models, and every organisation that builds on one and inherits its documentation obligations.How we handle this -> | European Commission, Shaping Europe's digital futureRead 25 August 2026 |
| PCI DSS v4.xThe 51 future-dated requirements are mandatory in every assessment | 18 months ago | In force | Every organisation that stores, processes or transmits cardholder data. v3.2.1 was retired on 31 March 2024.How we handle this -> | PCI Security Standards CouncilRead 25 August 2026 |
| EU AI ActProhibited AI practices banned, and AI literacy obligations apply | 20 months ago | In force | Every organisation placing AI on the EU market or using AI whose output is used in the EU.How we handle this -> | European Commission, Shaping Europe's digital futureRead 25 August 2026 |
| DORADigital Operational Resilience Act applies in full | 21 months ago | In force | Banks, insurers, investment firms and other EU financial entities, plus the ICT third-party providers that serve them.How we handle this -> | European Commission, Directorate-General for Financial StabilityRead 25 August 2026 |
| NIS2Member State transposition deadline passedTransposition remains incomplete. The European Commission has referred Ireland, Spain, France and the Netherlands to the Court of Justice for failing to transpose. Obligations therefore bite on different dates in different Member States, which matters if you operate across borders. | since 2024 | In force | Essential and important entities across energy, transport, health, water, digital infrastructure, public administration and space.How we handle this -> | European Commission, NIS2 transposition trackerRead 25 August 2026 |
| ISO/IEC 42001Certifiable nowPublished December 2023 as the first international AI management system standard. It is not a legal obligation, but it is the most direct way to evidence the governance the EU AI Act assumes you already have. | since 2023 | In force | Any organisation developing, providing or using AI that needs to evidence responsible practice to a regulator, a customer or an investor.How we handle this -> | ISORead 25 August 2026 |
Free tools
Work out which of these actually reach you.
Nothing is gated. Each one shows you the answer before it asks you for anything, and every date and rate carries the source it came from.
- Open
EU AI Act scope checker
Six questions. Which obligations reach you, and the date each takes effect.
- Open
Security leadership cost model
What a CISO costs fully loaded, on your own assumptions.
Every tool we publish lives at cloudgap.ai/tools.
Start
Three ways in, depending on how close the deadline is.
- Book it
Book a discovery call
Thirty minutes, no deck. We work out whether there is a real engagement here, and say so if there is not.
- Go
Check the EU AI Act applies
Six questions, a dated list of the obligations that reach you, and a calendar file so the deadlines land somewhere you will see them again.
- Go
Request a roadmap
You know the obligation and the deadline. We scope the sprints, the deliverables and the dates.
Or just email a human: hello@cloudgap.ai
We reply within24 hours