Compliance deadlines for SaaS founders
The landing page shows the three nearest deadlines. This page is the full timeline: every pending rung plus the regulations already in effect, each with a breakdown page. Dates are verified against primary sources, not news coverage.
Last verified against primary sources:
Coming deadlines
- December 2, 2026in 119 daysEU
EU AI Act — AI Content Marking & NCII/CSAM Ban
Machine-readable marking of AI-generated content becomes mandatory for legacy systems Dec 2, 2026 — the same day the new ban on AI-generated non-consensual intimate imagery and CSAM applies.
- January 1, 2027in 149 daysUS-State
Colorado ADMT Act (SB 26-189)
Colorado repealed SB 24-205 and replaced it with SB 26-189, a transparency-and-disclosure law for automated decision-making technology (ADMT) used in consequential decisions. Effective January 1, 2027.
- December 2, 2027in 484 daysEU
EU AI Act — High-Risk Obligations (Annex III)
The full high-risk regime for stand-alone Annex III AI systems (employment, credit, education, essential services) applies Dec 2, 2027 following the Digital Omnibus deferral.
- August 2, 2028in 728 daysEU
EU AI Act — Embedded High-Risk (Annex I)
High-risk obligations for AI embedded in regulated products (medical devices, machinery, toys) apply Aug 2, 2028.
Already in effect
- EU AI Actsince August 2, 2026
EU rules for AI systems. Transparency duties (disclose AI use, label deepfakes/chatbots) apply Aug 2, 2026; high-risk obligations deferred to Dec 2027–Aug 2028.
- US State Comprehensive Privacy Lawssince January 1, 2026
About 20 US states now have comprehensive consumer-privacy laws (Colorado, Connecticut, Virginia, Oregon, Montana, and more). Most apply at 100K+ consumers; thresholds are trending downward.
- European Accessibility Act (EAA)since June 28, 2025
EU accessibility requirements for digital products and services (WCAG 2.1 AA via EN 301 549). In force since June 28, 2025.
- Texas Data Privacy & Security Act (TDPSA)since July 1, 2024
Texas privacy law with NO revenue or volume threshold - applies to most businesses serving Texas residents. Only SBA-defined small businesses are partly exempt.
- CCPA / CPRA (California)since January 1, 2020
California privacy law: notice, opt-out of sale/sharing, deletion, and Global Privacy Control honoring. Applies at $25M+ revenue, 100K+ CA consumers, or 50%+ revenue from data sales.
- GDPR (General Data Protection Regulation)since May 25, 2018
EU/EEA data protection law: lawful basis, privacy notice, data-subject rights (access, deletion, portability), and opt-in consent for non-essential cookies. UK applies the equivalent UK GDPR.
- Cookie Consent (EU ePrivacy)since May 25, 2018
Opt-in consent required for non-essential cookies and trackers in the EU/EEA (ePrivacy Directive + GDPR). Accept and Reject must be equally easy.
- FTC Negative Option / ROSCA (Auto-Renewal)since December 29, 2010
Online subscriptions must provide clear disclosure, express consent, and easy cancellation (ROSCA + ~30 state auto-renewal laws). The FTC 'click-to-cancel' rule was vacated in July 2025.
- ADA Title III - Web Accessibilitysince July 26, 1990
US disability law applied to websites and apps. No small-business exemption; courts apply WCAG 2.1/2.2 AA. Record litigation volume in 2025.
See where your app stands
SaaSalyst scans your website in 30 seconds across 118 business readiness checks: compliance signals, security headers, SEO, accessibility, and AI readiness.
Scan Your App