Skip to main content

Compliance deadlines for SaaS founders

The landing page shows the three nearest deadlines. This page is the full timeline: every pending rung plus the regulations already in effect, each with a breakdown page. Dates are verified against primary sources, not news coverage.

Last verified against primary sources:

Coming deadlines

  1. December 2, 2026in 119 daysEU

    EU AI Act — AI Content Marking & NCII/CSAM Ban

    Machine-readable marking of AI-generated content becomes mandatory for legacy systems Dec 2, 2026 — the same day the new ban on AI-generated non-consensual intimate imagery and CSAM applies.

    Read the breakdown →

  2. January 1, 2027in 149 daysUS-State

    Colorado ADMT Act (SB 26-189)

    Colorado repealed SB 24-205 and replaced it with SB 26-189, a transparency-and-disclosure law for automated decision-making technology (ADMT) used in consequential decisions. Effective January 1, 2027.

    Read the breakdown →

  3. December 2, 2027in 484 daysEU

    EU AI Act — High-Risk Obligations (Annex III)

    The full high-risk regime for stand-alone Annex III AI systems (employment, credit, education, essential services) applies Dec 2, 2027 following the Digital Omnibus deferral.

    Read the breakdown →

  4. August 2, 2028in 728 daysEU

    EU AI Act — Embedded High-Risk (Annex I)

    High-risk obligations for AI embedded in regulated products (medical devices, machinery, toys) apply Aug 2, 2028.

    Read the breakdown →

Already in effect

  • EU AI Actsince August 2, 2026

    EU rules for AI systems. Transparency duties (disclose AI use, label deepfakes/chatbots) apply Aug 2, 2026; high-risk obligations deferred to Dec 2027–Aug 2028.

  • About 20 US states now have comprehensive consumer-privacy laws (Colorado, Connecticut, Virginia, Oregon, Montana, and more). Most apply at 100K+ consumers; thresholds are trending downward.

  • EU accessibility requirements for digital products and services (WCAG 2.1 AA via EN 301 549). In force since June 28, 2025.

  • Texas privacy law with NO revenue or volume threshold - applies to most businesses serving Texas residents. Only SBA-defined small businesses are partly exempt.

  • CCPA / CPRA (California)since January 1, 2020

    California privacy law: notice, opt-out of sale/sharing, deletion, and Global Privacy Control honoring. Applies at $25M+ revenue, 100K+ CA consumers, or 50%+ revenue from data sales.

  • EU/EEA data protection law: lawful basis, privacy notice, data-subject rights (access, deletion, portability), and opt-in consent for non-essential cookies. UK applies the equivalent UK GDPR.

  • Opt-in consent required for non-essential cookies and trackers in the EU/EEA (ePrivacy Directive + GDPR). Accept and Reject must be equally easy.

  • Online subscriptions must provide clear disclosure, express consent, and easy cancellation (ROSCA + ~30 state auto-renewal laws). The FTC 'click-to-cancel' rule was vacated in July 2025.

  • US disability law applied to websites and apps. No small-business exemption; courts apply WCAG 2.1/2.2 AA. Record litigation volume in 2025.

See where your app stands

SaaSalyst scans your website in 30 seconds across 118 business readiness checks: compliance signals, security headers, SEO, accessibility, and AI readiness.

Scan Your App