Hub
Timeline
The Governance Inflection: A Complete Timeline of Global AI Regulation, 2025–2026
Compliance & GovernanceTimeline

The Governance Inflection: A Complete Timeline of Global AI Regulation, 2025–2026

From the EU AI Act's full enforcement to WAICO's founding — the 18 months that rewired the rules of artificial intelligence

Society OS Research20 July 202616 min read read

Key Insight: The 18 months from January 2025 to July 2026 produced more binding AI law than the preceding decade — and fractured global governance into at least three incompatible regulatory blocs.

The history of technology governance is punctuated by moments when the pace of institutional response finally catches the pace of technological change. The 18 months between January 2025 and July 2026 represent one such inflection point for artificial intelligence — a period in which theoretical frameworks became binding law, voluntary principles became enforceable penalties, and the geopolitical contest over who writes the rules of AI hardened into institutional form.

What follows is a definitive chronological account of the regulatory events, legislative milestones, and institutional formations that have reshaped the global AI governance landscape. This is not a survey of what regulators intend to do. It is a record of what they have already done — and what the consequences are for every organisation operating at the frontier of artificial intelligence.

"The 18 months from January 2025 to July 2026 produced more binding AI law than the preceding decade — and fractured global governance into at least three incompatible regulatory blocs."

2025: The Year of Activation

February 2025 — EU AI Act: Prohibitions Enter Force

The European Union's AI Act (Regulation 2024/1689), adopted in June 2024, began its phased implementation in earnest on February 2, 2025. This date marked the activation of the Act's most categorical provisions: the outright prohibition of AI systems classified as posing "unacceptable risk." The banned categories include social scoring systems operated by public authorities, real-time remote biometric identification in public spaces (with narrow law-enforcement exceptions), AI systems that exploit psychological vulnerabilities to manipulate behaviour, and systems that infer sensitive attributes — political opinions, religious beliefs, sexual orientation — from biometric data.

These prohibitions are not aspirational. Violations carry penalties of up to €35 million or 7% of global annual turnover, whichever is higher. For the largest AI developers, this represents a material financial exposure that has already reshaped product roadmaps and deployment strategies across the European market.

August 2025 — GPAI Obligations Activate

The second major activation date under the EU AI Act arrived on August 2, 2025, when obligations for General-Purpose AI (GPAI) models came into force. Providers of GPAI models — the foundation models that underpin most commercial AI applications — became subject to mandatory technical documentation requirements, copyright compliance obligations, and transparency disclosures to downstream deployers. Providers of GPAI models deemed to pose "systemic risk" (defined by a training compute threshold of 10²⁵ FLOPs) face additional requirements: adversarial testing, incident reporting to the EU AI Office, and cybersecurity measures.

The EU AI Office, established within the European Commission, assumed its coordinating role as the primary enforcement body for GPAI obligations. Its creation represents the first dedicated supranational AI regulatory institution with binding authority over global technology companies.

January 2025 — United States: The Deregulatory Pivot

On January 20, 2025, President Donald Trump signed Executive Order 14179, revoking the Biden administration's October 2023 AI Executive Order and signalling a fundamental reorientation of U.S. AI policy. Where the previous administration had emphasised safety testing, red-teaming requirements, and mandatory reporting for frontier models, EO 14179 prioritised the removal of what it characterised as "barriers to American AI leadership." The order directed federal agencies to review and rescind regulations deemed inconsistent with a "minimally burdensome" approach to AI governance.

The practical effect was immediate: the voluntary commitments that major AI developers had made to the Biden White House — including pre-deployment safety evaluations and information-sharing with the government — lost their institutional anchor. The NIST AI Risk Management Framework (AI RMF), published in January 2023, remained the operational standard for many organisations, but its voluntary status became more pronounced as the federal government retreated from prescriptive oversight.

Late 2025 — Early 2026: The State-Level Surge

California's Layered Compliance Architecture

In the absence of comprehensive federal AI legislation, California moved to fill the regulatory vacuum with a suite of laws taking effect on January 1, 2026. Three statutes of particular significance came into force simultaneously:

  • SB 53 — Transparency in Frontier AI Act: Requires developers of frontier AI models to implement safety and security protocols, conduct pre-deployment testing, and publish transparency reports on known hazards. The law applies to models trained above a compute threshold and represents California's most direct attempt to regulate the development — not merely the deployment — of advanced AI.
  • AB 2013 — AI Training Data Transparency Act: Mandates that developers of generative AI systems publish summaries of the datasets used to train their models, including the sources, categories, and any known limitations. This provision directly addresses the opacity that has characterised foundation model development and creates a disclosure baseline that downstream deployers can reference.
  • SB 942 — AI Transparency Act: Requires that AI-generated content be detectable as such, mandating that providers of generative AI systems offer tools enabling users to identify AI-generated text, images, audio, and video. The law creates a technical infrastructure requirement — watermarking or equivalent detection mechanisms — that has significant implications for content platforms and media organisations.

Texas — TRAIGA Takes Effect

Texas enacted the Responsible Artificial Intelligence Governance Act (TRAIGA), which became effective January 1, 2026. The law focuses primarily on government use of AI and establishes a set of prohibited AI behaviours applicable to state agencies and their contractors. TRAIGA prohibits the use of AI systems that engage in deceptive practices, manipulate users through psychological exploitation, or make consequential decisions about individuals without meaningful human oversight. While narrower in scope than California's legislation, TRAIGA signals that AI governance is no longer a coastal preoccupation — it is becoming a bipartisan legislative priority across the United States.

The 18 months from January 2025 to July 2026 produced more binding AI law than the preceding decade — and fractured global governance into at least three incompatible regulatory blocs.

January 2026: Asia-Pacific Moves First on Agentic AI

Singapore — The World's First Agentic AI Governance Framework

In January 2026, Singapore's Infocomm Media Development Authority (IMDA) published what became the world's first comprehensive governance framework specifically designed for agentic AI — systems capable of autonomous reasoning, multi-step planning, and real-world action without continuous human direction. The framework's publication was not a reactive measure. Singapore had been developing its AI governance architecture since 2019, and the agentic framework represented the logical extension of its Model AI Governance Framework into the domain of autonomous systems.

The framework is structured around four governance pillars: upfront risk assessment and bounding of agent capabilities; meaningful human accountability at defined intervention checkpoints; technical controls including sandboxing, least-privilege access, and real-time monitoring; and end-user transparency obligations. Critically, the framework introduced a five-tier taxonomy of graduated autonomy levels, providing organisations with a structured vocabulary for classifying and communicating the degree of independence their AI agents exercise.

An updated version (Version 1.5), released on May 20, 2026, incorporated feedback from over 60 organisations and expanded guidance on systemic risks specific to multi-agent environments — including "agent sprawl" (the uncontrolled proliferation of autonomous agents within an organisation) and "collaborative failures" (miscoordination or emergent collusion between agents operating in shared environments). The framework's preference for deterministic, structurally-enforced limits over prompt-layer instructions reflects a sophisticated understanding of the attack surface that agentic systems present.

"Singapore's agentic AI framework introduced a five-tier taxonomy of graduated autonomy — providing the first structured vocabulary for classifying how independently an AI agent operates, and who bears accountability when it acts."

South Korea — The AI Basic Act Enters Force

On January 22, 2026, South Korea's "Framework Act on the Development of Artificial Intelligence and the Establishment of a Foundation for Trustworthiness" — universally referred to as the AI Basic Act — took effect. The legislation is notable for its tripartite classification of AI systems: generative AI (subject to mandatory disclosure and content labelling), high-impact AI (systems in critical sectors requiring pre-deployment impact assessments and human oversight mechanisms), and high-performance AI (systems exceeding 10²⁶ FLOPs, subject to lifecycle risk management and mandatory reporting to the Ministry of Science and ICT).

The Act's extraterritorial reach is significant. Any AI activity that affects South Korean users or the domestic market falls within its scope, regardless of where the developer is headquartered. Foreign AI businesses meeting specified thresholds — including annual revenue exceeding 1 trillion KRW or more than one million average daily users in Korea — must appoint a local representative responsible for government inquiries and safety reporting. The government implemented a one-year grace period for most compliance-related fines during 2026, except in cases of serious social harm, providing industry with adaptation time while preserving the Act's deterrent function.

February–June 2026: The Regulatory Architecture Matures

February 2026 — EU AI Act: Implementation Guidance Published

February 2, 2026 marked a procedural milestone under the EU AI Act: the European Commission was required to publish specific guidelines on the practical implementation of Article 6, which governs the classification of high-risk AI systems. The Commission also released a standardised template for post-market monitoring plans — the documentation that deployers of high-risk AI systems must maintain to demonstrate ongoing compliance. These guidance documents are not merely administrative; they define the operational reality of compliance for the thousands of organisations deploying AI systems in regulated sectors across the EU.

March 2026 — GPAI Code of Practice: Second Draft

The second draft of the Code of Practice for General-Purpose AI models was published on March 3, 2026. The Code, developed through a multi-stakeholder process convened by the EU AI Office, translates the Act's GPAI obligations into operational requirements. It addresses copyright compliance procedures, transparency documentation standards, and the specific technical and organisational measures required of providers of systemic-risk GPAI models. The Code's development process — involving AI developers, civil society organisations, and academic researchers — represents an attempt to build technical legitimacy into regulatory requirements before they become enforceable.

May 2026 — Colorado Rewrites Its AI Law

Colorado's original AI legislation (SB 24-205), which had attracted significant industry criticism for its broad "high-risk AI system" framework and developer duty-of-care provisions, was repealed and replaced by Senate Bill 26-189, signed into law on May 14, 2026, and effective January 1, 2027. The replacement law narrows the regulatory focus to "automated decision-making technology" (ADMT) used in "consequential decisions" — determinations affecting access to employment, education, housing, financial services, insurance, healthcare, and essential government services.

The revised framework shifts from a risk-management model to a transparency-and-rights model: consumers must receive clear notice of ADMT use, meaningful explanations following adverse outcomes, and the right to request human review and reconsideration. Enforcement rests exclusively with the Colorado Attorney General, with no private right of action. The law's evolution from SB 24-205 to SB 26-189 illustrates the iterative nature of AI legislation — and the significant influence that industry engagement can have on regulatory design.

June 2026 — US Executive Order 14409: National Security Pivot

On June 2, 2026, President Trump signed Executive Order 14409, "Promoting Advanced Artificial Intelligence Innovation and Security." The order represents a significant evolution in the administration's AI posture: while maintaining its commitment to avoiding "overly burdensome" regulation, EO 14409 acknowledges that frontier AI models present genuine national security risks that require active government engagement.

The order directs the NSA and DHS to develop a classified benchmarking process for identifying "covered frontier models" based on their advanced cyber capabilities. Developers of such models are invited into a voluntary framework that includes providing the government with pre-release access for up to 30 days. The order also establishes an AI Cybersecurity Clearinghouse within the Treasury Department to coordinate vulnerability scanning and patch distribution across the AI industry. Critically, the order directs the Attorney General to establish an "AI Litigation Task Force" to challenge state laws deemed "onerous" or preempted by federal policy — a direct signal that the administration intends to use legal mechanisms to consolidate AI governance at the federal level.

June 2026 — EU Parliament Extends Compliance Deadline

In June 2026, the European Parliament approved amendments extending the compliance deadline for certain standalone high-risk AI systems under Annex III to December 2, 2027. The extension applies to systems used in areas such as biometrics, critical infrastructure, education, employment, and migration — but does not reduce the substantive obligations these systems must ultimately meet. The amendment reflects the practical reality that many organisations deploying AI in regulated sectors require more time to implement the technical documentation, conformity assessment, and human oversight mechanisms the Act demands.

Singapore's agentic AI framework introduced a five-tier taxonomy of graduated autonomy — providing the first structured vocabulary for classifying how independently an AI agent operates, and who bears accountability when it acts.

July 2026: The Governance Architecture Bifurcates

July 1, 2026 — China: Ethics-Safety Guidelines Activate

China's TC260 technical committee introduced its "Ethics-Safety Guidelines for Artificial Intelligence Applications 1.0," effective July 1, 2026. While technically voluntary, the guidelines function as a de facto compliance baseline: they inform regulatory expectations, shape enforcement priorities, and serve as the reference standard for security assessments conducted by the Cyberspace Administration of China (CAC). The guidelines address algorithmic transparency, content labelling, and the ethical obligations of AI developers operating in China's domestic market.

July 6–7, 2026 — UN Global Dialogue on AI Governance, Geneva

The inaugural session of the United Nations Global Dialogue on AI Governance convened at the Palexpo convention center in Geneva, Switzerland, on July 6–7, 2026. Established by UN General Assembly Resolution A/RES/79/325, the Dialogue provides an inclusive platform for all 193 UN Member States, alongside private sector, academic, and civil society representatives, to deliberate on international AI governance. The event was co-chaired by the Permanent Representatives of El Salvador and Estonia, and supported by a joint secretariat involving the ITU, UNESCO, and the UN Office for Digital and Emerging Technologies.

The Dialogue's four thematic clusters — AI opportunities and implications, bridging AI divides, safe and trustworthy AI, and human rights — reflect the breadth of concerns that developing nations bring to AI governance discussions. A significant contribution was the presentation of the preliminary report by the Independent International Scientific Panel on Artificial Intelligence, comprising 40 global experts, which provided an evidence base for policymakers navigating the governance landscape. A second session is scheduled for New York in May 2027.

July 15, 2026 — China: Anthropomorphic AI and Agentic AI Rules Take Effect

Two significant Chinese regulatory instruments took effect simultaneously on July 15, 2026. The first, the Interim Measures for the Administration of AI Anthropomorphic Interactive Services, represents the world's first national framework specifically targeting emotionally interactive AI — systems that simulate human personality traits to provide "continuous emotional interaction." The measures impose mandatory anti-addiction mechanisms (including interaction limits and mandatory notifications after two hours of continuous use), prohibit virtual intimate relationships with minors, require crisis intervention protocols for users exhibiting signs of self-harm, and mandate explicit disclosure that users are interacting with AI rather than humans.

The practical impact was immediate and dramatic. Major platforms including ByteDance's Doubao and Alibaba's Qwen shut down their personalised AI agent features rather than attempt compliance. Industry analysts identified a fundamental "architecture problem": the features that make AI companions feel personal — persistent cross-session memory and stable persona maintenance — are structurally incompatible with the regulation's requirements for anti-addiction interruptions and engagement resets. The shutdown affected millions of users and demonstrated that regulatory design choices can have rapid, large-scale consequences for deployed AI products.

The second instrument, the Implementation Opinions on the Standardized Application and Innovative Development of Intelligent Agents, jointly issued by the CAC, NDRC, and MIIT, establishes China's first dedicated governance framework for AI agents. Unlike previous rules that grouped all generative AI together, this framework treats AI agents — defined as systems capable of autonomous perception, memory, decision-making, and execution — as a distinct regulatory category. Systems deployed in sensitive sectors including healthcare, transportation, and public safety are subject to mandatory compliance testing and strict oversight requirements.

July 16, 2026 — WAICO Founded in Shanghai

The most geopolitically significant event in the 18-month timeline occurred on July 16, 2026, when the World Artificial Intelligence Cooperation Organization (WAICO) was formally established in Shanghai, with 29 founding member states. The organisation, first proposed by China in July 2025 and reiterated by President Xi Jinping at the 33rd APEC meeting, represents a deliberate institutional counterweight to Western-led AI governance frameworks — the G7's Hiroshima AI Process, the OECD AI Principles, and the emerging U.S.-led "Pax Silica" initiative.

WAICO's founding members include Algeria, Belarus, Brazil, Cambodia, China, Ethiopia, Indonesia, Kazakhstan, Kenya, Malaysia, Pakistan, Russia, South Africa, and 15 other nations — a coalition that spans the Global South and includes several major emerging economies. The organisation's stated objectives emphasise "inclusive innovation," equitable access to AI capabilities, and governance norms that reflect the priorities of developing nations rather than the regulatory preferences of the EU or United States. China has pledged 5,000 AI training opportunities for individuals from member states over five years and committed to establishing international AI application cooperation centres in partnership with ASEAN, the Arab League, the African Union, and CELAC.

UN Secretary-General António Guterres attended the signing ceremony — a signal of the organisation's legitimacy — though the UN did not formally join WAICO. The organisation's creation means that enterprises operating globally now face a tripartite governance landscape: EU-aligned jurisdictions governed by the AI Act and its risk-based framework; U.S.-aligned jurisdictions governed by a patchwork of state laws and voluntary federal frameworks; and WAICO-aligned jurisdictions that may adopt domestic regulations tailored to the organisation's standards. Compliance with the EU AI Act or OECD principles does not guarantee compliance in WAICO-aligned markets.

"WAICO's founding means that global AI governance has formally bifurcated. Enterprises operating across jurisdictions now face three incompatible regulatory blocs — and compliance with one does not guarantee compliance with the others."

August 2026: The EU AI Act Reaches Full Enforcement

August 2, 2026 — The Major Application Date

The most consequential single date in the EU AI Act's implementation timeline arrives on August 2, 2026 — just days after this article's publication. On this date, the majority of the Act's remaining provisions become enforceable, including:

  • Article 50 Transparency Obligations: AI-generated content — including deepfakes, chatbot interactions, and synthetic media — must be labelled as such. Providers of AI systems that generate or manipulate content must implement technical measures enabling detection of AI-generated output.
  • High-Risk AI Enforcement: Enforcement begins for the majority of high-risk AI systems under Annex III, covering applications in biometrics, critical infrastructure, education, employment, essential private and public services, law enforcement, migration, and administration of justice.
  • Regulatory Sandboxes: Member States are required to ensure that at least one AI regulatory sandbox is operational at the national level, providing a controlled environment for testing innovative AI applications under regulatory supervision.

WAICO's founding means that global AI governance has formally bifurcated. Enterprises operating across jurisdictions now face three incompatible regulatory blocs — and compliance with one does not guarantee compliance with the others.

  • Financial Penalties: The full penalty regime becomes enforceable, with fines for prohibited AI practices reaching up to €35 million or 7% of global annual turnover.

The November 2, 2026 deadline for watermarking requirements on AI-generated audio, video, image, and text content follows three months later, with the December 2, 2026 deadline addressing new prohibitions on non-consensual sexual deepfakes and child sexual abuse material.

The Structural Consequences: What the Timeline Reveals

Three Incompatible Regulatory Blocs

The 18-month timeline reveals a governance landscape that has fractured along geopolitical lines. The EU's risk-based, rights-protective framework; the U.S.'s deregulatory, innovation-first approach with aggressive state-level variation; and the emerging WAICO bloc's emphasis on inclusive access and alternative governance norms represent three fundamentally different answers to the question of how AI should be governed. These are not merely different regulatory styles — they reflect different underlying values about the relationship between technology, the state, and the individual.

For multinational organisations, the practical consequence is a compliance architecture of unprecedented complexity. A foundation model provider operating globally must simultaneously satisfy the EU AI Act's GPAI obligations, California's training data transparency requirements, South Korea's high-performance AI reporting mandates, and — if operating in WAICO-aligned markets — governance standards that are still being defined. The ISO/IEC 42001 AI management system standard has emerged as a practical tool for organisations seeking a certifiable framework that can be mapped to multiple regulatory requirements, but it does not resolve the fundamental incompatibilities between blocs.

The Agentic Governance Gap

The most significant structural gap in the current governance landscape is the absence of comprehensive frameworks for agentic AI — systems capable of autonomous, multi-step action in the real world. The EU AI Act was designed primarily for predictive and assistive AI; its risk classification system does not map cleanly onto agents that can initiate transactions, communicate with external parties, and execute complex workflows without human direction at each step. Singapore's agentic AI framework is the most sophisticated response to this gap, but it is non-binding and applies only within Singapore's jurisdiction.

China's July 2026 agentic AI opinions represent the first binding national framework for AI agents, but their scope is limited to specific high-risk sectors. The result is a global governance gap precisely at the point where AI capability is advancing most rapidly — a gap that the next 18 months of regulatory activity will need to address.

The Infrastructure Dimension

The governance timeline cannot be read in isolation from the infrastructure competition that underlies it. Hyperscaler capital expenditure on AI infrastructure is projected to exceed $1 trillion by 2027, and the competition for compute, energy, and semiconductor fabrication capacity has become a primary arena of great-power rivalry. WAICO's founding coincided with the debut of Huawei's Atlas 950 SuperPoD at the 2026 World Artificial Intelligence Conference — a signal that China's AI governance ambitions are backed by a domestic infrastructure strategy designed to reduce dependence on Western semiconductor supply chains.

The governance frameworks being built today are not merely regulatory instruments — they are infrastructure for the next phase of AI development. The jurisdictions that establish credible, workable governance frameworks will attract AI investment and talent; those that fail to do so will find themselves governed by the standards of others.

Looking Forward: The Next Inflection Points

The governance timeline does not end in July 2026. Several significant milestones lie immediately ahead:

  • August 2, 2026: EU AI Act full enforcement — the most consequential single date in global AI governance history.
  • November 2, 2026: EU AI Act watermarking requirements for AI-generated content.
  • December 2, 2026: EU AI Act prohibitions on non-consensual deepfakes and CSAM.
  • January 1, 2027: Colorado SB 26-189 takes effect; California CCPA ADMT regulations enter full enforcement.
  • December 2, 2027: EU AI Act high-risk AI (Annex III) full compliance deadline.
  • May 2027: Second session of the UN Global Dialogue on AI Governance, New York.
  • August 2, 2028: EU AI Act compliance deadline for AI systems integrated into regulated products.

The 18 months documented in this timeline represent the opening phase of a governance transformation that will unfold over the next decade. The frameworks being built now — their risk classifications, their liability allocations, their enforcement mechanisms — will shape the trajectory of AI development for a generation. Understanding the timeline is not merely an exercise in regulatory compliance. It is a prerequisite for strategic clarity in an era when the rules of artificial intelligence are being written in real time.

Sources & Further Reading

  1. 1.
  2. 2.
  3. 3.
  4. 4.
  5. 5.
  6. 6.
  7. 7.
  8. 8.
  9. 9.
  10. 10.
  11. 11.
  12. 12.
AI GovernanceEU AI ActWAICODigital SovereigntyRegulationGlobal PolicyAgentic AI
The engine behind the Signal

Where this connects to Society OS

The Sovereign Intelligence Hub is the free, open front door of Society OS — the sovereign operating system that turns the ideas you just read into working governance. Where this piece names a problem, Society OS is building the machinery to solve it: AI agents that act with your authority, trust you can verify, and compliance that runs as code.

The 42-Protocol Stack

The governance engine beneath every article — led by the Sovereign Trinity: Human-Twin-Agent identity, HEARTrank trust, and WISE Contracts that execute law, not just code.

F-ACT — the open agent standard

The vendor-neutral framework for governing AI agents before they act: Authority, Scope, Data, Audit, Revocation — free to read, cite and implement.

The Sovereign Platform

Put it to work: govern a fleet of AI agents with verifiable authority, tamper-evident evidence, and compliance-as-code across your whole operation.

Explore membershipRead the F-ACT standard

Related Reading

I'm Giving Away the Patents. Here's Why.
Compliance & Governance

I'm Giving Away the Patents. Here's Why.

10 min

The Standard That Governs AI Agents Now Belongs to Everyone
Compliance & Governance

The Standard That Governs AI Agents Now Belongs to Everyone

8 min

The Governance Gap: Why Regulation Can't Keep Pace with AI
Compliance & Governance

The Governance Gap: Why Regulation Can't Keep Pace with AI

18 min

The Sovereign Intelligence Hub — Society OS

© 1989–2026 Society OS Pty Ltd. All rights reserved.