AI LAW RADAR · Daily Last verified 21 Aug 2026

What changed

111 entries · newest first

Every material change to the register, dated and sourced — new instruments, deadline shifts, and the verifications behind them. See the full field-level revision history, or follow RSS · JSON Feed.

addition

Kyrgyzstan has had the deepest AI regime in Central Asia since 6 February 2026, and a single 20,000-som offence behind it

Kyrgyzstan sat on the sweep-gap list as a 403. It is not blocked. cbd.minjust.gov.kg, the Ministry of Justice's Centralised Bank of Legal Information, is a single-page app whose JSON API answers in full once an Origin and Referer header are supplied - POST /api/v1/GetDocuments with {"searchByTextRu": "..."} full-text searches all 208,757 acts - and without them every call returns a bare "Forbidden". Behind that header check is a regime the tracker had entirely missed. Chapter 23 of the Digital Code of the Kyrgyz Republic (Code No. 178 of 31 July 2025) runs seven articles, 191 to 197, and it has been binding since 6 February 2026: commencement Law No. 179 of the same date gives the Code effect six months after its own publication in «Эркин-Тоо» No. 58 (3714) of 5 August 2025, and the ЦБД record card records 6 February 2026. That timing rewrites the Central Asian sequence this tracker published earlier today only in part - Kazakhstan's AI Law still took effect first, on 18 January 2026, and Uzbekistan's second on 21 January - but Kyrgyzstan adopted its text five months before Kazakhstan's was even published, so the notes on both neighbours now carry that caveat. On substance Kyrgyzstan is the deepest of the three. Art. 193 subjects EVERY AI system applied in the country - no risk gate - to a danger assessment run by its owner at design, before first application and on any unplanned change, and requires the result and the methodology to be published on the owner's website and as open data. Systems the assessment puts in the «повышенной опасности» tier take the full weight: the art. 194(5) owner duties, and an art. 195 gate that no EU-style notified body mediates - the owner adopts a declaration of conformity, signs it with a qualified digital signature and posts it publicly before first use. Art. 196 binds the deployer separately and gives anyone whose rights a decision touches a free right to information sufficient to understand and check how the result about them was reached. Art. 197 applies at any danger level and covers chatbot disclosure, emotion and biometric classification notice, and deepfake labelling, with a wide creativity-and-teaching carve-out from the labelling limb. The classification is comparative and self-executed rather than annex-driven, which is the same structural choice Kazakhstan made, and art. 194(3) expressly exempts systems whose role is purely auxiliary. Unlike Kazakhstan, the implementing layer is finished: Cabinet of Ministers Resolution No. 770 of 2 December 2025 approved five sets of requirements under arts. 193 and 194, and Order No. 1181-т of 31 December 2025 approved the declaration content. The finding worth carrying is the enforcement gap, and it is wider than Kazakhstan's. Law No. 180 inserted exactly one AI article into the Code of Offences, art. 228-10, and it penalises only the art. 192(2) prohibition on designing, developing or applying AI to cause targeted and knowingly unlawful harm - 200 расчетных показателей for a natural person and 650 for a legal person, and the расчетный показатель has been 100 som since 2006, so 20,000 and 65,000 som, about 230 and 745 US dollars. No fine attaches to a missing danger assessment, a missing declaration, an absent risk-management system, a refused explanation, an undisclosed chatbot or an unlabelled deepfake. Kazakhstan at least fines failure to flag misleading synthetic output; Kyrgyzstan does not. What is left is regulator-ordered suspension under arts. 194(5)(7) and 196(1)(7), termination on a court act, and civil liability - including, for digital wellbeing services, an elective statutory compensation of 100 to 400 расчетных показателей under art. 127(2) that spares the consumer proof of loss.

addition

Kazakhstan is Central Asia's real first: a standalone AI statute in force since 18 January 2026, banning seven capabilities but penalising only two failures

Kazakhstan was a blank on this map because every official .kz host appeared to time out. It was not a block: adilet.zan.kz serves an incomplete TLS chain, omitting its GoGetSSL G2 intermediate, and once that intermediate is supplied from the certificate's own AIA URL the host verifies and answers in about a second. Behind it sits a law the tracker had missed. Law of the Republic of Kazakhstan No. 230-VIII ЗРК of 17 November 2025 «Об искусственном интеллекте» is a standalone 31-article AI statute, published in «Егемен Қазақстан» and «Казахстанская правда» No. 222 on 18 November 2025 and in force sixty days later, on 18 January 2026 — three days before Uzbekistan's ЎРҚ-1115. The changelog entry published earlier today calling Uzbekistan the Central Asian first has been corrected accordingly. Art. 17(3) bans seven AI capabilities outright, tracking EU AI Act art. 5 closely enough to compare but framed as a prohibition on creation and operation rather than on placing on the market. Two departures from the EU model are structural: art. 17(1) leaves the minimal/medium/high risk classification to the system's own owner under the general rules on classifying informatisation objects, with no statutory annex; and art. 17(2) adds a second axis of autonomy whose highest tier — systems whose decisions a human cannot correct or reverse — is not regulated here at all but deferred to future laws. Art. 18 is the substantive duty: continuous lifecycle risk management, updated not less than once a year, with immediate suspension or termination once a prohibited-capability risk is identified. Art. 21 requires users to be told that goods, works and services are produced using AI, and permits dissemination of synthetic outputs only with machine-readable marking plus a perceptible warning — though the machine-readable standard is delegated to the authorised body under art. 22 and has not yet been issued. The enforcement side is deliberately narrow, and that is the finding worth carrying. Companion Law No. 232-VIII inserted KoAP art. 641-1, and it reaches exactly two failures: not informing users about synthetic outputs capable of misleading them, and not managing the risks of a HIGH-risk system where harm followed. Breaching the art. 17(3) prohibitions is not itself an enumerated offence; it bites only indirectly, through the art. 18(2) suspension duty, through audit under art. 20(2), through the personal-data offences, or through the criminal law. Fines run 15/20/30/100 MRP by size on a first offence and 30/50/70/200 on repetition, which is modest money — the real sanction is the suspension or prohibition of the system that accompanies a repeat, imposed by the AI authorised body itself under new KoAP art. 692-3. Finally, the automated-decision provision is art. 19-1 of the 2013 Personal Data Law, not art. 20 as previously assumed: added by Law No. 231-VIII and in force the same 18 January 2026, it bans automated processing that creates, changes or ends a person's rights or legitimate interests without consent or a statutory basis, with no contract exception and no written-consent formality, and gives three working days to answer an objection — against Uzbekistan's ten and Russia's thirty.

addition

Uzbekistan enters the tracker: an AI statute with a duty that has no penalty (corrected same day — Kazakhstan, not Uzbekistan, is the Central Asian first)

Correction issued 21 August 2026: this entry originally called Uzbekistan Central Asia's first AI statute. It is not. Kazakhstan's standalone Law No. 230-VIII of 17 November 2025 entered into force on 18 January 2026, three days earlier; see the Kazakhstan entry of the same date. The rest of this entry stands. Law No. ЎРҚ-1115 of 21 January 2026 wrote artificial intelligence into Uzbekistan's 2003 Law on Informatization, and it is in force — art. 4 commences it on official publication, which the official Uzbek consolidated text records as National Database of Legislation, 21.01.2026, No. 03/26/1115/0063. New art. 7¹ carries two flat rules with no sector, size or nationality limb: AI-created information resources and AI-based information systems must not damage a person's life, health, freedom, honour, dignity or other inalienable rights, and legally significant decisions affecting rights and freedoms may not rest exclusively on their conclusions. The second is a human-in-the-loop mandate on the decision-maker, not a right the person has to invoke — and it has no consent or contract exit. Art. 7¹ carries no penalty at all: the only sanction the act created is a new part two of KoAO art. 46², 50–100 base calculation units plus confiscation, and its text couples unlawful AI processing of personal data WITH dissemination in the media, telecom networks or the Internet, so internal AI processing falls back to part one. Third row: art. 24 of the 2019 Personal Data Law (ЗРУ-547), in force 1 October 2019 by its own art. 36 and word-for-word identical in the 2019 and current 2026 redactions, bars solely automated decisions producing legal consequences unless there is written consent, a contract, or a legislative basis — it has the contract limb Russia's 152-FZ art. 16 lacks — and gives the owner/operator ten days to answer an objection, a third of Russia's thirty. Verified against the official Uzbek-language texts on lex.uz; the Russian versions there are marked unofficial translations.

lex.uz ↗

correction

Korea: the AI Basic Act grace period has no carve-out in the MSIT release, and its end date is not fixed

This morning's entry recorded the MSIT administrative-fine grace period as running to ~22 Jan 2027 "except for cases involving loss of life or fundamental human-rights violations". Re-read of the cited primary release (MSIT English press release, nttSeqNo=1191) shows it contains no such exception, and no reference to loss of life or human rights at all. Two corrections: the carve-out is removed as unsourced, and the release's own words — "efforts are currently underway to gather opinions to finalize the detailed operation plan and duration of this grace period" — make ~22 Jan 2027 a floor, not a confirmed end date. What the release does confirm stands: a grace period of at least one year from the 22 Jan 2026 in-force date. kr-aibasic-highimpact also had a stale source_url pointing at the Dec 2024 passage release (nttSeqNo=1071), which says nothing about fines; it now points at nttSeqNo=1191.

msit.go.kr ↗

correction

MSIT's one-year AI Basic Act fine grace period is now confirmed in a primary release

Both rows previously flagged the MSIT enforcement grace period as practitioner-sourced and unconfirmed in an MSIT primary release. An MSIT English-language notice (bbsSeqNo=42, nttSeqNo=1191) now confirms MSIT will implement a grace period of at least one year from the Act's 22 January 2026 in-force date before administrative fines are imposed, with exceptions for cases involving loss of life or fundamental human-rights violations.

msit.go.kr ↗

Added

Russia's first AI statute is on the books, and none of its duties starts on the commencement date being reported

Federal Law No. 243-FZ of 26 July 2026 on supporting the development of artificial intelligence technologies regulates only large foundational models — not fewer than 1 billion parameters, general-purpose, and serving as the basis for other software. Art. 13(1) puts the Law in force on 1 September 2026 and that is the date in general circulation, but art. 13(2) defers arts. 8, 9 and 10, together with art. 5(2) points 3-5 and art. 6 parts 2-5, to 1 March 2027; what commences in September is the subject matter, aims, definitions, principles, coordination and support powers, and a bare liability referral. The three deferred duties are recorded separately because they bind different parties: art. 8 imposes security measures, operating rules and technical documentation only on developers whose model has been granted sovereign or national status; art. 9(3) requires platforms accessed by more than 500,000 users in Russia within twenty-four hours to give users the means of placing an AI warning, which is an enablement duty rather than a labelling mandate; art. 10(1) requires anyone providing the ability to use such a model to notify users who owns the rights in the outputs and on what terms they may be accessed, used and retained. The Law states no penalty: art. 11 is a referral to general legislation and the Code of Administrative Offences carries no article on large foundational models.

publication.pravo.gov.ru ↗

Added

Russia has barred solely automated decisions since 2007, and art. 16 of 152-FZ has no contract exception

Art. 16 of Federal Law No. 152-FZ of 27 July 2006 forbids decisions taken on the basis of solely automated processing that produce legal consequences for a person or otherwise affect their rights and legitimate interests, and admits only two ways out: the written consent of the data subject, in the heavy art. 9(4) form that carries the identity-document particulars, or a federal law that also lays down measures protecting the person. There is no contract limb, so the automated credit refusal or tenancy screen taken in the course of contracting is not excused, and the second trigger limb carries no significance threshold at all. The operator explains the procedure of the decision and its possible legal consequences, offers the chance to object, and answers the objection within thirty days — but nothing requires the decision to be changed, and there is no logic-disclosure right anywhere in the Law. In force since 26 January 2007, 180 days after publication in Rossiyskaya Gazeta No. 165 of 29 July 2006. Enforcement runs through KoAP art. 13.11(2) for the missing written consent and art. 13.11(4) for the explanation duty; Roskomnadzor draws the protocol but a judge imposes the fine.

pravo.gov.ru ↗

correction

Saudi Arabia's AI-training exception is narrower than recorded: Art.30 of the Implementing Regulation adds six controls, not one

A primary-source read of the Implementing Regulation in Umm Al-Qura shows Art.30 subjects the Art.26(4) AI-training exception to six cumulative controls, of which only the record-keeping duty had been captured. Two of the others are material to scope: Art.30(2) withholds the exception where the work is used within a purely commercial frame, unless the use is insubstantial in relation to the work or does not affect its normal exploitation; and Art.30(5) prohibits adaptation, republication, making the work available to the public, and unnecessary inclusion of the work in the final products without the rightholder's permission. The record-keeping duty is also narrower than stated: the records are produced to a competent body examining a dispute relating to that use, not to any authority on demand. Art.60 of the Law confirmed as the commencement rule — the Regulation applies from the Law's own entry into force, so Art.30 binds from 12 Aug 2026 rather than from its 31 Jul 2026 publication, and the row's date is unchanged.

uqn.gov.sa ↗

correction

Niger: an ordonnance of the same date repeals unspecified provisions of Loi 2022-59, so art. 52 is placed under a supersession watch

Reading the signed original of Décret n° 2026-310/PRN/PM confirms the dissolution of the HAPDP (art. 1(9)) and the transfer of its missions to the Ministries of Justice and of the Interior (art. 2(8)), and confirms that the décret itself does not touch art. 52. But its fifth recital cites Ordonnance n° 2026-30 du 8 juin 2026, which abrogates certain laws creating regulatory authorities and certain provisions of Loi n° 2022-59 itself. That text could not be obtained from any official host, and the HAPDP's own legislation index has not been updated since the dissolution, so which provisions are repealed is unverified and the earlier statement that art. 52 is unaffected cannot be supported. The row stays live at medium confidence with the repeal risk recorded. Separately, the art. 31 prior-authorisation regime and the arts. 92 to 94 sanctions were vested in the HAPDP and now have no named holder.

africadataprotection.org ↗

correction

Saudi Arabia's Copyright Law Implementing Regulation attaches a record-keeping duty to the Art.26(4) AI-training exception

The Executive Regulation of the Copyright Law (Royal Decree M/169), published in Umm Al-Qura on 31 July 2026, adds Article 30, which conditions the Art.26(4) AI-training exception on several further requirements, including a duty on the AI developer to keep records of the work's type, source, purpose and date of use, producible to a competent authority on request. This refines the row's prior framing that Saudi Arabia imposes no restrictive AI obligations on deployers/providers.

uqn.gov.sa ↗

correction

Niger dissolves the HAPDP, its data-protection regulator, transferring competencies to the Justice and Interior ministries

Décret n° 2026-310/PRN/PM of 8 June 2026, signed by President Abdourahamane Tiani, dissolved nine public entities including the Haute Autorité de Protection des Données à caractère Personnel (HAPDP), the authority that administered Loi n° 2022-59's art. 31 prior-authorisation regime and its arts. 92-94, 102, 108-110 enforcement powers. Data-protection matters now fall within the remit of the Ministries of Justice and Interior; the decree does not amend the substantive text of art. 52 itself.

africadataprotection.org ↗

Added

Switzerland and Türkiye join — two large non-EU European economies whose automated-decision rules forbid nothing

The African sweep that closed with the Malabo parties left a gap much closer to the EU row, and this pass fills it. Switzerland and Türkiye are the two largest European economies outside the EU and the EEA, neither is covered by the GDPR, and until now neither carried a row — so a reader checking whether an automated hiring sift or a credit engine was regulated in Zurich or Istanbul found nothing on the tracker, and the honest answer in both places is that it is regulated, but not by a prohibition. That is the finding the two rows share. Swiss revFADP art. 21 is titled, in the official English of the Fedlex consolidated text, «Duty to provide information in the case of an automated individual decision» — the rubric almost every secondary account silently rewrites as «automated individual decision-making». Nothing in it forbids a solely automated decision. It requires the controller to inform, and it arms two safeguards, a point of view and a review by a natural person, only on request. Its exception is the detail worth carrying: art. 21(3)(a) disapplies the article where the decision is directly connected with a contract between controller and data subject and the data subject's request is granted, which means the declined loan, the rejected policy and the failed tenancy screen are the cases the exception does not reach. Turkish KVKK art. 11(g) goes further in the same direction and is drafted as an objection right rather than as a rule about what may be done — the controller may take the decision and the data subject objects afterwards — with no exception architecture, no human-intervention right, no right to contest and no logic-disclosure limb anywhere in art. 11. Its trigger is narrower than the European one, requiring a result «against the person», so a favourable automated decision produces no right at all. Both rows also correct a date and a penalty that the secondary literature routinely gets wrong. Türkiye's article is in force from 7 October 2016, not from the 7 April 2016 publication of Law No. 6698: art. 32 puts arts. 8, 9, 11, 13, 14, 15, 16, 17 and 18 into force six months after publication, and that tranche carries the right and its entire enforcement route together. And no fine attaches to art. 11 at all — art. 18(1) penalises five things and breaching a data subject's rights is not among them, so the route runs through an art. 15(5) Board remediation order and only then to art. 18(1)(c) for non-compliance, at a statutory 25,000 to 1,000,000 lira whose printed figures are a decade out of date because art. 18 fines are uprated every calendar year under the Misdemeanour Law. The Swiss penalty is mis-stated in the opposite direction. The widely quoted CHF 250,000 is real but is aimed at a natural person, is prosecuted only on complaint, and does not cover every breach of art. 21: art. 60(1)(b)(1) reaches the art. 21(1) duty to inform and para. 2 appears nowhere in the list, so a controller who refuses a request for human review commits no offence. Where the undertaking is fined instead of the individual, art. 64(2) caps that at CHF 50,000 and allows it only as a proportionality shortcut. The FDPIC has no administrative fining power; prosecution is a cantonal matter under art. 65 with a five-year limitation under art. 66. Both entries were verified against primary text — the Fedlex consolidated English of SR 235.1 at status 1 September 2023, and the Authority's own English text of Law No. 6698 — and both are recorded as high confidence. The current-year Turkish fine figures are deliberately not published in the row: only the statutory band and the revaluation mechanism are, because the Authority's annual announcement was not retrieved for this check.

Added

The four remaining Malabo Convention parties join — three on their own statutes, Namibia on the treaty alone

Four African Union Convention parties join the tracker in one pass, and the pass answered a structural question that opened it. When Mozambique was added on art. 14(5) of the Malabo Convention, four further parties were recorded as bound and untracked — Namibia, Zambia, Mauritius and Mauritania — with the worry that four more per-country treaty rows would be a pattern rather than a one-off, and that the Convention might belong on the tracker as a single African Union regional row instead. Reading the four national statutes dissolved the worry. Three of the four have their own automated-decision bar in national law, so they are ordinary national rows on the same footing as the eleven Convention parties already tracked, and the treaty runs behind them as background rather than as the operative rule. Only Namibia is the Mozambique shape. The pattern is two treaty rows, not five. Zambia joins with zm-dpa2021-s62. Section 62(1) of the Data Protection Act, 2021 (Act No. 3 of 2021) bars any decision based solely on automated processing, including profiling, producing legal effects concerning the data subject or similarly affecting them, with three exceptions at s. 62(2) — contract necessity, authorisation by any written law, explicit consent — and, where one is relied on, a s. 62(3) safeguard duty carrying the full triad the Convention omits: human intervention on the part of the controller, the right to express a point of view, and the right to contest the decision. Section 62(4) adds a separate bar on automated processing of sensitive personal data absent express consent, public interest or statutory permission with safeguards. The explanation limb is reactive only — s. 58(2)(d) gives access to information about the basic logic involved in any automatic processing in case of automated decision making, while the s. 64 duty to inform at direct collection runs (a) to (f) and carries no automated-decision item — so a Zambian controller must explain when asked and need not volunteer that a machine decided. Section 57 is the sleeper: notification to the Commissioner of any third-party agreement allowing that third party to trade on a data subject's profile. The Zambian date and the Zambian penalty both had to be traced rather than assumed. Section 1 is a bare enabling clause and the 24 March 2021 assent date on the face of the Act is not the operative date; the appointing instrument is Statutory Instrument No. 22 of 2021, the Data Protection Act (Commencement) Order, 2021, made by the Minister of Transport and Communication on 31 March 2021, whose para. 2 brings the Act into operation on the date of publication of the Order — published 1 April 2021, which is the date carried. On penalty, the Act penalises by Part: s. 18(1) covers Part IV at up to one hundred million penalty units or 2% of turnover, and s. 55(1) covers Part VIII at 2% of turnover or two million penalty units. Section 62 sits in Part IX, and Part IX has no equivalent clause. Section 77, the general penalty, reaches only a person who commits an offence for which no specified penalty is provided, so it presupposes an offence rather than creating one. No offence attaches to s. 62. The commonly repeated figure of a fine plus three years' imprisonment for automated-decision breaches in Zambia is s. 77 misapplied; the real remedies are a s. 68 complaint to the Commissioner, a s. 69 appeal to the High Court and s. 72 compensation. Mauritius joins with mu-dpa2017-s38, and it is the fullest automated-decision regime of any Convention party. Section 38(1) of the Data Protection Act 2017 (Act 20/2017) carries the GDPR right in GDPR order, with the three exceptions at s. 38(2) and the controller's own safeguard duty at s. 38(5) confined to the contract and explicit-consent limbs — the legal-authorisation route being policed instead by the safeguards the authorising law must itself lay down. Section 38(3) goes further than GDPR art. 22(4): automated processing intended to evaluate certain personal aspects shall not be based on special categories of personal data at all, with no consent or substantial-public-interest escape. The explanation duty runs three times over: proactively at s. 23(1)(g) with the logic involved and the significance and envisaged consequences, reactively at s. 37(2)(h) inside the right of access, and again at s. 38(4), which requires the s. 23 information to state the existence of processing for such a decision and its envisaged effects whenever an exception is used. Section 34(2)(a) makes an impact assessment mandatory beforehand. And unlike Zambia, the penalty reaches it: s. 43(1) catches «any person who commits an offence under this Act for which no specific penalty is provided or who otherwise contravenes this Act» — a fine not exceeding 200,000 rupees and imprisonment not exceeding 5 years, drafted with «and» rather than «or» between them, which on a literal reading makes both cumulative. The Act binds the State under s. 3(1) and treats each Ministry as separate from every other under s. 3(2). In force since 15 January 2018 by Proclamation No. 3 of 2018, not the 8 December 2017 passage, the 22 December 2017 assent or the 23 December 2017 gazetting. Mauritania joins with mr-loi2017020-art19, and its first paragraph has no counterpart anywhere else on the tracker. Article 19 of Loi n° 2017-020 du 22 juillet 2017 opens by barring any judicial decision involving an assessment of a person's conduct from being founded on automated processing intended to evaluate certain aspects of their personality — a rule addressed to courts, cutting off algorithmic input into sentencing, bail and every other judicial appraisal of behaviour. Its second paragraph is the general bar, and it is art. 2 of France's Loi n° 78-17 in its pre-2018 wording carried across whole: no exception limb of any kind — no contract, no consent, no legal authorisation — no profiling definition, and an «effets juridiques» threshold with no «significantly affects» limb, so a purely commercial automated refusal falls outside it where it would be caught in Zambia, Mauritius or under the Convention. There is no logic item anywhere: the art. 53 right of access runs to five items and the information duty at collection to nine, and neither carries one, and there is no right to human intervention and none to contest. Mauritania is the Angola shape at a different latitude — the machine decision is forbidden and never has to be explained. Scope under art. 3 is the means-in-territory test rather than the GDPR's targeting test. The penal articles, arts. 84 to 98, were read one by one and none of them names art. 19 or cross-refers to it, so no criminal penalty attaches; what reaches it is art. 80, letting the Autorité de Protection des Données à caractère personnel impose pecuniary sanctions proportionate to gravity, up to ten million ouguiyas on a first breach and fifty million or 5% of pre-tax turnover on a repeat within five years. Those figures predate the 1 January 2018 redenomination at ten old ouguiya to one new, so in present-day currency they are MRU 1,000,000 and MRU 5,000,000. The row is carried at medium confidence for two reasons that are not about the text of art. 19: the transitional regime at arts. 99 and 100 runs from a compound trigger, entry into force and the effective establishment of the Authority, and the Authority was stood up years late; and every figure in the Law is denominated in the old currency. Namibia joins with na-malabo-art14-5, and it is the Mozambique shape exactly — the obligation arrives by treaty because there is no statute for it to arrive by. Namibia never signed the Convention; it acceded on 25 January 2019 and deposited on 1 February 2019, and its signature column on the African Union's status list is empty. Reception is more direct than in Mozambique: art. 144 of the Constitution provides that unless otherwise provided by the Constitution or an Act of Parliament, the general rules of public international law and international agreements binding upon Namibia under the Constitution shall form part of the law of Namibia — automatic incorporation with no publication precondition, where Mozambique's art. 18 conditions entry into the domestic order on official publication. Two qualifications cut the other way and keep the row at medium confidence alongside the same self-executing question art. 14 raises inside itself: the phrase «under this Constitution» routes incorporation through art. 63(2)(e), the National Assembly's power to agree to ratification of or accession to international agreements, and the opening words make art. 144 expressly subject to displacement by an Act of Parliament — an Act of Parliament on precisely this subject being pending. The Data Protection Bill, drafted in successive versions since 2013 and most recently circulated as the Data Protection Bill 2023, carries its own solely-automated-decision provision with consent and contract exceptions and a human-intervention safeguard; the Ministry of Information and Communication Technology said in August 2025 it was in its final stages and would be tabled between September and October 2025. It has not been enacted, and until it is the Convention is the only automated-decision rule in force in Namibia. When it passes, this row is superseded rather than duplicated. Article 13 of the Constitution was checked and ruled out: it gives a privacy right against interference with homes, correspondence and communications, and no data-processing regime. The dating of all four is anchored the same way, and it is worth restating because it is counter-intuitive. Art. 36 of the Convention brings it into force thirty days after the depositary receives the fifteenth instrument of ratification, and there is no separate per-State entry-into-force clause — so a party that deposited earlier is bound from the collective date, not from its own deposit. The fifteenth deposit is Mauritania's, on 9 May 2023, which puts the Convention in force on 8 June 2023 for all sixteen parties, Mauritius (deposited 2018), Namibia (2019) and Zambia (2021) included. Mauritania is therefore both bound by art. 14(5) and the reason art. 14(5) binds anyone. Where a national statute and the Convention both apply and diverge, the national statute is carried as the operative rule and the treaty is recorded behind it. The divergence is real and it is not academic: art. 14(5) admits no contract, consent or legal-authorisation exception, while s. 62(2) in Zambia and s. 38(2) in Mauritius admit all three. A controller relying on explicit consent in Lusaka or Port Louis is on solid statutory ground and unresolved treaty ground. That tension is recorded rather than resolved. With these four, all sixteen States that have deposited an instrument of ratification of the Convention now carry a row — Angola, Cabo Verde, Congo, Côte d'Ivoire, Ghana, Guinea, Mauritania, Mauritius, Mozambique, Namibia, Niger, Rwanda, São Tomé and Príncipe, Senegal, Togo and Zambia. The coverage gap opened by the Mozambique row is closed. What remains open is a structure question rather than a data one: whether the Convention should additionally exist as a single African Union regional row alongside the fourteen national-statute rows and the two treaty-only rows, or whether per-country rows remain the right shape now that the treaty-only cases have turned out to be two rather than five. 142 -> 146 obligations / 51 -> 55 regions / 85 -> 89 countries.

Added

Mozambique joins on a treaty, not a statute — the Malabo Convention's automated-decision bar, in force since 2023

Mozambique joins the tracker with mz-malabo-art14-5, and it is the first row whose obligation arrives by treaty rather than by legislation. Mozambique has no national data-protection statute — a Proposta de Lei establishing a Regime Jurídico de Proteção de Dados Pessoais and creating an Autoridade Nacional de Proteção de Dados was approved by the Council of Ministers on 3 March 2026 and is still before the Assembleia da República — but it ratified the African Union Convention on Cyber Security and Personal Data Protection (Malabo, 27 June 2014) on 2 December 2019 by Resolução n.º 5/2019 of the Assembleia da República and deposited its instrument with the Chairperson of the African Union Commission on 21 January 2020. Art. 18 of the Constitution of the Republic of Mozambique puts validly approved and ratified treaties into the domestic legal order on official publication, with the rank of ordinary legislation. Art. 14(5) of the Convention provides that a person shall not be subject to a decision which produces legal effects concerning them or significantly affects them to a substantial degree and which is based solely on automated processing of data intended to evaluate certain personal aspects relating to them. The date is computed from the instrument. Art. 36 makes the Convention enter into force thirty days after the depositary receives the fifteenth instrument of ratification, with no separate per-State clause. On the African Union's own status list the fifteenth deposit is Mauritania's, on 9 May 2023, which puts entry into force at 8 June 2023 — the date carried here. Mozambique's signature, ratification and deposit all precede it, so the treaty's own date governs rather than the deposit. Two things make this row unusual in opposite directions. Art. 14(5) is the most absolute automated-decision bar on the tracker: it has no contract limb, no consent limb and no legal-authorisation limb, where art. 15(2) of Directive 95/46/EC — its ancestor — and every Lusophone and Francophone row derived from it carry at least two. But the Convention never requires an explanation. The art. 16 information duty runs (a) to (h) and the art. 17 access right runs (a) to (d), and neither carries an automated-decision or logic item; art. 18 gives objection on legitimate grounds and art. 19 rectification, blocking and erasure. There is no right to human intervention and no right to contest. Mozambique is the Angola shape reached by a different road: the machine decision is forbidden and never has to be explained. The row is carried at medium confidence, and the reason is domestication rather than dating. Art. 8(1) frames the Convention's personal-data chapter as a commitment by each State Party «to establishing a legal framework», and art. 14(1) is drafted the same programmatic way — «State Parties shall undertake to prohibit». Art. 14(5) is not: it states a rule about what may be done to a person, and reads as self-executing where its own paragraph 1 does not. No Mozambican court has been shown to apply it, no domestic instrument repeats it, no supervisory authority has been established, and no penalty attaches — art. 12(2)(h) leaves sanction amounts to national law, and Mozambique has set none. No monetary range is recorded rather than one imported from a peer jurisdiction. What Mozambique does have was checked and ruled out. The personal-data chapter of Lei n.º 3/2017, de 9 de Janeiro (Lei de Transacções Electrónicas) at arts. 63-65 covers accuracy and purpose limitation, notice on indirect collection, security, access, reasoned refusal and objection, a bar on cross-institution sharing and a designated responsible individual — and nothing about automated decisions or profiling. The words «perfil» and «perfis» do not occur in the Law, and every occurrence of «automatizado» is UNCITRAL automated-message-system vocabulary about contract formation, input errors and automated calling systems. INTIC, the national ICT institute, publishes the same enumeration of the country's current framework — Constitution art. 71, Lei 3/2017 arts. 63-65, Decreto n.º 67/2017 on e-government interoperability, and the regulation on intermediate electronic service providers — and none of it regulates automated decision-making. Guinea-Bissau was swept in the same pass and is a closed negative: it signed the Convention on 31 January 2015 but has never ratified it, has no data-protection law and no data-protection authority, and the legislation index of ARN, its national regulator, carries only the 2013 telecommunications decrees. Four further Convention parties — Mauritius, Namibia, Zambia and Mauritania — are bound by art. 14(5) and are not yet tracked; they are recorded as a follow-up coverage gap, Namibia most sharply, since it has no national data-protection statute and should be the same shape as this row.

Added

Cabo Verde joins as the Lusophone prohibition rewritten to the GDPR's shape — and Angola loses its uniqueness claim

Cabo Verde joins the tracker with cv-lei133-art23, from art. 23.º of Lei n.º 133/V/2001, de 22 de janeiro, in the consolidated text republished by Lei n.º 121/IX/2021, de 17 de março, in force in this wording since 16 April 2021 (art. 6 of the amending Law: thirty days after publication in Boletim Oficial I Série n.º 28 of 17 March 2021). It is the third Lusophone row after Angola and São Tomé e Príncipe and the only one of the three rewritten since the GDPR. The 2021 amendment replaced nos. 1 and 2 of the article and cut the Lei 67/98 evaluative limb — processing «destinado a avaliar determinados aspectos da sua personalidade, designadamente a sua capacidade profissional, o seu crédito, a confiança de que é merecedora ou o seu comportamento» — putting «incluindo a definição de perfis» in its place, with profiling defined at art. 5(1)(j) in GDPR art. 4(4) terms. The bar therefore no longer asks what the processing was for: any solely automated decision producing effects in a person's legal sphere or significantly affecting them is caught, which is wider than either Lusophone sibling. Scope was rewritten with it, from the means-in-territory test Angola and São Tomé still use to a GDPR art. 3 shape reaching controllers with no presence in Cabo Verde that offer goods or services to, or monitor the behaviour of, people who are there. Art. 14(1)(c) gives a right to know the logic underlying the automated processing as regards automated decisions including profiling, cross-referring art. 23(1) by name — more than São Tomé's «razões» and more than Angola, which gives nothing — but the art. 13 information duty carries no automated-decision item, so the right is reactive, and there is no right to human intervention and no right to contest. Art. 50(1)(b) names art. 23 in the enumerated list of administrative infractions: coima 100,000$00 to 1,000,000$00, negligence always punishable, with accessory prohibition of the processing under art. 69 and qualified disobedience under art. 62 for defying a CNPD order to stop. This row also corrects a claim published on 18 August. The Angola entry said art. 29(3) — the limb letting the Agência de Protecção de Dados licence an otherwise-prohibited automated decision and write the safeguards itself — had no analogue in any other tracked statute. Cabo Verde's art. 23(3) is the same clause, naming the Comissão Nacional de Proteção de Dados, and both descend from art. 13(3) of Portugal's Lei 67/98. The regulator-licence route is a shared Lusophone inheritance, not an Angolan invention; São Tomé e Príncipe is the member of the group that dropped it. The Angola and São Tomé entries and both sets of jurisdiction notes have been amended accordingly.

Added

Burundi writes the strongest automated-decision rule on the tracker — and the first that says «intelligence artificielle» out loud

Burundi joins the tracker with bi-loi103-art19-20, from Loi n°1/03 du 10 mars 2026 portant protection des données à caractère personnel, promulgated at Gitega and in force the same day. Three things make it the strongest automated-decision regime tracked so far. First, art. 20 is a permission rule: decisions with legal or important effects are authorised only under a legislative or regulatory act with appropriate safeguards, with consent, or where strictly necessary to conclude or perform a contract. Second, where such a decision is permitted the data subject may have it reformulated — they file written observations and «une nouvelle décision motivée est prise par un être humain, qui remplace entièrement la première». That is a right to have the machine's decision vacated and retaken, which goes past the GDPR's right to obtain human intervention. Third, art. 19 requires the underlying logic to be explained «en termes clairs et simples» and, where the system only assists a human, requires the controller to describe what the human decider actually contributed and on what methods and criteria — a rubber-stamp rule with no analogue elsewhere on the tracker. Art. 17(7) also makes processing «à l'aide de l'intelligence artificielle pour la prise de décision automatisée» a mandatory disclosure at collection, the first time a tracked data-protection statute names AI in an operative duty, though art. 4 does not define the term. Enforcement is indirect — the penal chapter names no article, so arts. 19-20 run through art. 48's unfair, unlawful or non-transparent processing offence, up to five years and 10,000,000 Burundian francs for a natural person and 20,000,000 for a private legal person, doubled for a responsable majeur de traitement. Two forward deadlines come from art. 53: existing processing has until 10 September 2026 in the private sector and 10 March 2027 in the public sector. Read in the signed and sealed original, 32 bilingual French-Kirundi pages, published by the regulator ARCT on gov.bi.

Added

São Tomé e Príncipe: the same Lusophone prohibition as Angola, without the regulator's escape hatch

São Tomé e Príncipe joins the tracker with st-lei32016-art13, the second Lusophone row and the closest textual sibling to Angola's. Art. 13.º of Lei n.º 3/2016 reproduces the Portuguese Lei 67/98 prohibition almost word for word — no decision producing effects in a person's legal sphere or significantly affecting them may be taken exclusively on automated processing intended to evaluate aspects of their personality, namely professional capacity, credit, trustworthiness or conduct. The comparison is what makes the row worth having. São Tomé keeps only the parent law's two exceptions, contract and authorising statute, and gives its Agência Nacional de Protecção de Dados Pessoais no power to licence a prohibited decision — the art. 29(3) limb that still leaves Angola alone on the tracker. It is also the more transparent of the two: art. 11(1)(c) lets the data subject obtain knowledge of the reasons underlying the automated processing of their data, where Angola's Law carries no logic or reasons limb anywhere. And where Angola's art. 29 sits outside both contravention lists, São Tomé's art. 32(1) names art. 13 explicitly, so breach is an administrative infraction of 25,000,000 to 50,000,000 dobras as written in the 2016 text, applied by the Agência, with accessory prohibition of the processing and a qualified-disobedience crime for defying an order to stop. Approved 15 February 2016, promulgated 18 March, published in the Diário da República n.º 39 of 10 May 2016; art. 47 sends entry into force to the general rule rather than fixing a date, and that residual is stated on the entry rather than smoothed over.

Added

The DRC completes the pair: Angola forbids the automated decision, Kinshasa makes you explain it

The Democratic Republic of the Congo joins the tracker with cd-codenum-art209, drawn from Ordonnance-loi n° 23/010 du 13 mars 2023 portant Code du numérique. Read next to the Angolan row added the same day, it splits the GDPR's automated-decision package cleanly in two. Angola's Lei 22/11 art. 29 forbids the solely automated evaluative decision and never once requires anyone to explain the logic. The DRC never forbids it and requires the logic three times over: art. 209 on request, art. 220 up front at collection, art. 235 where the data were collected elsewhere — each time «des informations utiles concernant la logique sous-jacente, ainsi que l'importance et les conséquences prévues de ce traitement pour la personne concernée». Art. 245 adds the DPIA trigger for systematic automated evaluation including profiling. What is missing is any art. 22 analogue: the rights section runs from art. 209 to the general opposition right in art. 213 without ever reaching a prohibition, there is no human-intervention or contest right, and art. 187's prior-authorisation list does not cover profiling. Scope under art. 184 is the widest on the African rows — the State, provinces, decentralised entities, legal and natural persons, and processing carried out on the national territory or abroad. Enforcement is two-step: a warning and a mise en demeure of at most eight days under art. 256, then 8,000,000 to 200,000,000 Congolese francs under art. 257, with a 5% of turnover limb reserved for violations that led to death or attempted murder and a cease-processing injunction for those endangering national security. In force since 13 March 2023 under art. 390, the date of promulgation. Read in the certified copy issued by the Cabinet of the President of the Republic, cross-checked against a born-digital rendering covering arts. 186-390.

Added

Angola opens Lusophone Africa — and brings the first automated-decision prohibition a regulator can licence

Angola joins the tracker with ao-lei2211-art29, the first Lusophone African row and the first row of any lineage where the supervisory authority can itself permit an automated decision the statute otherwise forbids. Lei n.º 22/11, de 17 de Junho, da Protecção de Dados Pessoais descends from Portugal's Lei 67/98 rather than from the Directive 95/46/EC transpositions that shape the Francophone rows or the GDPR that shapes Cameroon's. Art. 29(1) is the classical prohibition — no decision producing effects in a person's legal sphere or significantly affecting them may be taken exclusively on automated processing intended to evaluate aspects of their personality, namely professional capacity, credit, trustworthiness or conduct — and its legal-effects-or-significant-effect threshold makes it narrower than Equatorial Guinea's art. 13(b) or Cameroon's art. 44, both of which bite without one. Art. 29(2) is the familiar contract exception. Art. 29(3) is not familiar at all: the decision may also be permitted quando a Agência de Protecção de Dados o autorize, definindo medidas de garantia da defesa dos interesses legítimos do titular dos dados — where the Agência authorises it and writes the safeguards itself. Every other prohibition on the tracker admits only exceptions fixed in the statute; Angola hands the regulator a case-by-case licensing power over automated decision-making, and whatever protection the data subject gets in that case is whatever the authorisation says. What Angola does not give is disclosure. The art. 25 information duty and the art. 26 access right both run without any automated-decision or logic item, so an Angolan data subject has no route to learn that a machine decided at all — the mirror image of Equatorial Guinea, where the disclosure limb reaches el programa utilizado but nothing forbids the machine. Enforcement of art. 29 is indirect and worth stating plainly: art. 51 lists the finable contraventions by article number (arts. 14-17, 20, 30-32 at USD 75,000-150,000; arts. 6-11, 18, 19, 21-24 at USD 65,000-130,000, trebled for legal persons) and art. 29 is in neither list. A person's remedies are the art. 47 complaint to the Agência, art. 48 judicial reparation for moral or material harm, and the art. 58 crime of qualified disobedience — up to 3 years' imprisonment for failing to interrupt, cease or block a processing after being notified to do so. Art. 55(1)(a) additionally criminalises omitting a request for authorisation to the Agência, which on its face reaches a controller relying on the art. 29(3) route without ever having asked. The date recorded is 17 June 2011: art. 67 puts the Law in force on the date of publication, and it was published in the Diário da República, I Série, n.º 114, of that day, having been approved on 24 May 2011 and promulgated on 8 June 2011. Read in full in the official gazette scan published by the Agência de Protecção de Dados itself — 18 pages, image-only, no text layer, read as page images. A revision of Lei 22/11 went to public consultation on the Government's consultapublica.gov.ao portal from 17 March to 17 April 2025 and is closed; nothing has been gazetted, so the 2011 text is the operative rule and the draft is a watch item rather than a dated entry.

Added

Equatorial Guinea — the widest evaluation-challenge trigger on the tracker, and Chad closed negative across all 98 articles

Equatorial Guinea joins the tracker with gq-ley1-2016-art13b, and it breaks the Central African pattern. Every other row in the block — Cameroon, Chad, the Central African Republic, Gabon, Congo-Brazzaville — is Francophone and drawn from Directive 95/46/EC or from the GDPR. Ley núm. 1/2016, de 22 de julio, de Protección de Datos Personales is Hispanophone and drawn from the Spanish LOPD, and it shows in the shape of the rule. Art. 13(b), Impugnación de valoraciones, does two things no other tracked provision does at once: it makes the controller disclose el programa utilizado, the program used in the processing, not merely the logic involved; and it lets the data subject challenge todo acto administrativo o decisión involving an evaluation of their conduct or behaviour and a definition of their characteristics or personality, with no requirement that the decision be solely automated and no legal-effects threshold. On trigger width it is the broadest evaluation-challenge right on the tracker. On depth it is among the thinnest: there is no prohibition on automated decisions anywhere in the Law, no human-intervention right, and no duty to tell anyone up front that a machine is scoring them, so the right is purely reactive — the same structural weakness recorded for the Central African Republic a heartbeat earlier, reached from a completely different legal ancestry. Enforcement is administrative and sits with the Ministro de Telecomunicaciones y Nuevas Tecnologías; the Órgano Rector de Protección de Datos Personales that art. 15 designates as guardian of the rights still awaits its creating Decree. Refusing an art. 13(b) request is an infracción grave: 500,001 to 5,000,000 FCFA, suspension of the processing, and sealing of the premises for up to fifteen working days. The date recorded is 22 July 2016, the date the Law carries on its face; the Disposición Final gives a twenty-day vacatio from publication in the Boletín Oficial del Estado, whose issue date is not stated in the official copy and is not published online, so the in-force day is a range in August or September 2016 rather than a verified date — hence medium confidence. Read in the official scanned copy published by the Ministerio de la Función Pública y la Reforma Administrativa, a 45-page image-only scan read as page images. The same heartbeat closed Chad negative: Loi n° 007/PR/2015 was read across all 98 articles and its implementing Décret n° 075/PR/2019 across all 16, and neither carries an automated-decision or profiling rule of any kind — not even the art. 12(a) access limb that the Central African Republic has.

Added

Central African Republic — a data-protection statute that lets you contest an automated decision but never forbids one, and defines profiling without regulating it

The Central African Republic is the twenty-second African jurisdiction on the tracker and the forty-fourth in the atlas region set, and it is the first that had to be added for what its statute does not say. Loi 24.001 du 25 janvier 2024 portant protection des données à caractère personnel is a full modern data-protection law — fifty-eight articles, an independent administrative authority, a data protection officer, turnover-based administrative fines, a nine-article penal chapter — and it contains no rule against automated decisions at all. The word automatisé occurs three times in the whole text. Twice it is in the art. 6 definitions. The third and only operative occurrence is the third indent of the art. 30 access right, which gives the data subject the information allowing them to know and to contest the mechanism of the automated processing where a decision is taken on its foundation and produces legal effects in respect of them. That indent is Directive 95/46/EC art. 12(a) verbatim; what is missing is Directive art. 15, the prohibition that every other Francophone African statute on the tracker carries in some form — Senegal, Côte d'Ivoire, Benin, Burkina Faso, Mali, Niger, Togo, Guinea, Madagascar, Congo-Brazzaville, Gabon, Morocco and Algeria all state that a decision producing legal effects may not be taken on the sole foundation of an automated processing. The Central African Republic took the access half of the template and left the bar behind. The result is the only jurisdiction on the tracker where automated decision-making is lawful without qualification and the data subject's sole remedy is to ask, after the fact, how it was done. Two details sharpen the finding. The first is that the omission is not obviously deliberate drafting economy, because art. 6 imports the GDPR art. 4(4) definition of Profilage in full, including the prediction of work performance, economic situation, health, preferences, interests, reliability, behaviour, location and movements — and then never uses the defined term anywhere in the operative text. A GDPR-lineage definition sits orphaned inside a Directive-lineage rights chapter, which makes the Central African Republic the first entry on the tracker to define profiling without regulating it. The second is that the art. 35 information duty owed at collection, which in the Directive-derived statutes is where the logic of an automated decision usually has to be disclosed proactively, lists only identity, purpose, whether the data are obligatory or optional, categories, recipients and the rights of objection, access and rectification. Nothing about automated logic. So the art. 30 right can only be triggered by a person who already suspects a machine decided, and art. 31 then removes it entirely for public-security and offence-detection processing. On dates: art. 58 is unusually clean for the region, providing in terms that the Law takes effect from the date of its promulgation, so unlike Morocco, Congo-Brazzaville, Gabon and Cameroon there is no publication-to-force assumption to make. The residual uncertainty is the opposite one — the promulgation date does not survive in the scanned regulator copy, whose signature page over President Touadéra's signature is stamped and handwritten, so 25 January 2024 is taken from ARCEP's own regulation index citing the file it hosts. Confidence is medium on that ground alone. Two structural notes for the region file: art. 57 gave the Ministry twelve months from promulgation to stand up the supervisory agency, a deadline that expired on 25 January 2025 with the Ministry discharging its missions in the meantime, and arts. 24 to 27 are the first transfer regime on the tracker to draw the free-flow perimeter around CEMAC and CEEAC rather than around a national adequacy list, which matters for anyone modelling Central African data flows as a bloc rather than a set of countries.

Added

Cameroon — the first GDPR-shaped automated-decision right in Francophone Africa, and the only African statute that criminalises profiling

Cameroon is the twenty-first African jurisdiction on the tracker and the forty-third in the atlas region set, and it changes the shape of the African block in three ways. The first is lineage. Every Francophone African row added so far — Senegal, Côte d'Ivoire, Benin, Burkina Faso, Mali, Niger, Togo, Guinea, Madagascar, Congo-Brazzaville, Gabon, Morocco and Algeria — states its automated-decision rule in the Directive 95/46/EC form: a judicial limb, a second limb about decisions taken on the sole foundation of an automated processing, and a deeming clause for contract decisions. Loi n° 2024/017 du 23 décembre 2024 does none of that. Art. 44 is a GDPR art. 22 right of objection, held by the data subject rather than a prohibition addressed to decision-makers, and art. 44(3) carries all three limbs of the art. 22(3) safeguard — human intervention, the right to express a point of view, the right to contest the decision. The Francophone-equals-Directive assumption that has held for thirteen consecutive rows does not survive Cameroon; the dividing line is the date of the statute, not the legal family. The second is scope. Art. 44 states no threshold at all: no requirement that the decision produce legal effects, as in Congo, Gabon, Togo, Senegal, Morocco and Algeria, and no significant-effect limb either, which makes the Cameroonian trigger wider than the GDPR's own. Its exception list is correspondingly narrower — informed prior explicit consent, or authorisation by a law carrying appropriate safeguards, and nothing else. There is no contract carve-out anywhere in art. 44, which is the single most commonly used escape hatch in the Directive-derived statutes. The third is enforcement, and it is the finding worth reading twice. Art. 65 punishes the controller or processor who carries out or causes to be carried out a processing of personal data for profiling purposes with three to ten years' imprisonment and a fine of one million to twenty million francs CFA. That is an offence attaching to profiling itself, not to any breach of the art. 44 right, and read with the definition of profilage in the Law's definitions article — automated processing used to evaluate personal aspects relating to a natural person, notably health, preferences, location and economic situation — it reaches ordinary commercial scoring and segmentation. Nothing comparable exists anywhere else in the African block, where the automated-decision article is typically reached, if at all, only by an administrative catch-all: in Ghana, Uganda, Madagascar, Congo-Brazzaville, Gabon, Morocco and Algeria no penal article touches it. Legal persons face up to one billion francs CFA under art. 71. On dates: the Law was promulgated on 23 December 2024 and carries no commencement article, art. 75 providing only for registration, publication under the urgency procedure and insertion in the Journal Officiel in French and English. Art. 73 gave controllers eighteen months from promulgation to conform, so the conformance window closed on 23 June 2026 and the duty is now fully operative. The row is dated from promulgation, consistent with how the Rwandan and Indonesian transitional windows were treated, with the June 2026 date recorded in the entry's status note. The text was read page by page in the certified true copy published by the Presidency of the Republic.

Added

Madagascar, Congo-Brazzaville and Gabon — and the correction of a claim that Guinea's judicial limb stood alone

Madagascar, the Republic of the Congo and Gabon are the eighteenth, nineteenth and twentieth African jurisdictions on the tracker and the fortieth, forty-first and forty-second in the atlas region set. All three were read article by article in an official text, and all three carry an operative automated-decision bar. Madagascar's Loi n° 2014-038 states it as a founding principle at art. 3, in the general-provisions chapter, with the wide trigger — any administrative and private decision involving an appraisal of human conduct — and no carve-out of any kind. Congo's Loi n° 29-2019 states it at art. 13 on the narrow Directive 95/46/EC trigger confined to decisions producing legal effects, with the familiar deeming clause for contract decisions and for decisions satisfying the person's own requests. Gabon's Loi n° 025/2023 states it at art. 77 on the same narrow trigger, appended, as its 2011 predecessor was, to the article on offence and conviction data. Two findings are worth separating out. The first is Gabon's: the recast defines Intelligence Artificielle in its definitions article, along with raw and input data in the field of artificial intelligence and the artificial neuron, and pairs the bar with the full GDPR transparency package at art. 43 — the existence of automated decision-making including profiling, meaningful information about the underlying logic, and the significance and envisaged consequences — plus a distinct right to know the reasoning underlying the processing where its results are applied. No other data-protection statute in the Francophone African block defines artificial intelligence at all. The second is a correction. The Guinea entry published on 17 August said that art. 27's omission of the word "seul" from its judicial limb was unique on the tracker. It is not. Madagascar's art. 3, Congo's art. 13, Gabon's art. 77 and Algeria's art. 11 all drop the qualifier from the judicial limb while keeping it in the limb that follows, which makes the asymmetry a shared inheritance of the Francophone family rather than a Guinean innovation. The Guinea row and its jurisdiction notes have been amended; what remains true of Guinea, and is now stated on that narrower basis, is that it alone combines the strict judicial limb with a wide second limb, no exception of any kind, and a general penalty article reaching 7 per cent of turnover. A third observation follows from Madagascar and is recorded here because it bears on how the remaining Francophone jurisdictions should be read: Madagascar is not an ECOWAS member and never has been, yet it takes the wide "appréciation sur un comportement humain" trigger that Côte d'Ivoire, Burkina Faso, Niger, Mali and Guinea take. The ECOWAS Supplementary Act can therefore no longer be treated as the hinge that decides which drafting a Francophone state adopts.

Added

Togo and Guinea: two art. 27s that split the ECOWAS family, and Guinea's catch-all penalty at 7% of turnover

Togo and Guinea are the sixteenth and seventeenth African jurisdictions on the tracker and the thirty-eighth and thirty-ninth in the atlas region set. Both automated-decision rules happen to sit at art. 27 of their statutes, and the coincidence is where the resemblance ends. Togo's Loi n° 2019-014 du 29 octobre 2019 did not take the wider ECOWAS Supplementary Act drafting that Côte d'Ivoire, Burkina Faso, Niger and Mali use. Its second limb is confined to decisions producing legal effects — the Directive 95/46/EC art. 15 trigger — and it carries the Moroccan and Algerian carve-out deeming contract decisions with an opportunity to present observations, and decisions satisfying the data subject's own requests, outside the bar. Togo is a founding ECOWAS member and its Law postdates the Supplementary Act by nine years, which is precisely why every statute in this block is read article by article rather than inferred from membership. Guinea's Loi n° L/2016/037/AN du 28 juillet 2016 goes the other way and is now the strictest formulation tracked. It takes the wider ECOWAS trigger in its second limb, states no exception of any kind, and — alone among every provision on the tracker — omits the word "sole" from its judicial limb: no judicial decision appraising the conduct of a natural person may have as its foundation an automated processing intended to evaluate aspects of that person's personality, full stop. The qualifier appears in the second limb of the same article, so its absence from the first is a drafting choice on the face of the enacted text. Enforcement diverges just as sharply. Togo's art. 27 is administratively enforced only: its fifteen offences in arts. 79 to 93 each name their own conduct and none reaches an automated decision, leaving the Instance de protection's art. 71 fine of up to 100,000,000 francs CFA and art. 72 astreinte of up to 5,000,000 francs CFA per day. Guinea's art. 56, by contrast, is a general catch-all — any controller or processor who does not respect the provisions of the Law is fined 50,000,000 to 150,000,000 Guinean francs, rising on recidivism within five years to 1,500,000,000 Guinean francs or 7% of pre-tax turnover for an undertaking. It is the only penalty in the Francophone block that reaches the automated-decision article directly, and the highest turnover ceiling in it against 5% in Côte d'Ivoire, Niger and Burkina Faso. Guinea also carries the only express commencement rule in the block: art. 65 attaches force to the date of promulgation, which the signature block stamps as 28 July 2016, resolving against the widely repeated "26 juillet 2016" citation. Both entries are medium confidence for stated reasons. Togo's enacted text is signed "Fait à Lomé, le 30 octobre 2019" in a gazette issue dated 29 October 2019, a one-day discrepancy on the face of the gazette itself; Guinea's promulgation date is a rubber stamp on a scanned signature page and the Journal Officiel citation could not be established. Neither jurisdiction's statute names a predecessor in its abrogation clause, so nothing on the tracker is superseded. The Directive family now splits seven ways with the ECOWAS Supplementary Act as the hinge: narrow legal-effects trigger with a contract carve-out in Morocco, Algeria and Togo; wide administrative-or-private trigger with no carve-out at all in Côte d'Ivoire, Mali, Burkina Faso and Guinea; and the wide trigger with consent, contract and legal-authorisation exceptions in Niger.

Added

Burkina Faso closes the Francophone West Africa sweep: art. 15 of Loi 001-2021/AN, and art. 31's prior authorisation for predictive AI

Burkina Faso is the fifteenth African jurisdiction on the tracker and the thirty-seventh in the atlas region set, and it completes the six-jurisdiction Francophone West Africa block. Loi n° 001-2021/AN du 30 mars 2021 abrogates Loi n° 010-2004/AN of 20 April 2004, the statute this sweep originally targeted. Its art. 15 takes the wider ECOWAS Supplementary Act drafting shared with Côte d'Ivoire and Niger — no judicial decision appraising human conduct may be founded on an automated processing giving a definition of a person's profile or personality and intended to evaluate aspects of that personality, and no administrative or private decision appraising human conduct may rest on the sole foundation of such a processing — and, like Côte d'Ivoire and Mali, it states no exception whatever. What sets Burkina Faso apart sits in the two provisions around it. Art. 19 gives every person the right to know and to contest the information and the reasoning used in processing, automated or not, whose results are relied on against them, and requires that where the processing falls within artificial intelligence the criteria and the nature of the personal data founding it be indicated from the point of collection. And art. 31 subjects to prior authorisation by the Commission de l'informatique et des libertés any processing that assists administrative or private decision-making and involves an appraisal of human conduct, defines a person's profile or personality, or rests on artificial-intelligence techniques for predictive purposes — an ex ante licensing gate on predictive AI, and the only one in any data-protection statute on the tracker. This entry also corrects the Niger row published earlier today. Niger's art. 52 was described as the only provision anywhere on the tracker naming artificial intelligence; Burkina Faso's art. 19 carries the same clause in materially identical words and predates Niger's Law by twenty months, so Burkina Faso is the source of that drafting and Niger the follower. The Niger entry has been amended accordingly. Enforcement in Burkina Faso is wholly administrative in substance: art. 79 creates no offence and simply refers breaches to the Penal Code's provisions on computing and ICT offences, while arts. 63 to 77 give the CIL a warning, a mise en demeure, an injunction to cease, blocking, a flat-rate fine and withdrawal of the authorisation. That flat-rate fine is measured in turnover rather than currency — one per cent of pre-tax turnover for the last closed financial year on a first failure and five per cent on recidivism — which no other Francophone row does. The specific fines in arts. 67 to 75 run up to 100,000,000 francs CFA, and the 5,000,000 to 20,000,000 francs CFA fine for processing without the prior formalities is what reaches a missing art. 31 authorisation. Confidence is medium: laws in Burkina Faso are promulgated by presidential decree and neither the promulgation decree for Loi n° 001-2021/AN nor the Journal officiel date could be established, because cil.bf serves a maintenance page on every path and legiburkina.bf, jo.gov.bf and sgg.gov.bf do not resolve. The enacted text was read in the copy published by the CIL itself, retrieved from the Internet Archive capture of 10 July 2025 of the CIL's own document store.

Added

Mali joins the tracker: art. 2 of Loi 2013-015, the only automated-decision bar on the tracker stated as a founding principle rather than a right

Mali is the fourteenth African jurisdiction on the tracker and the thirty-sixth in the atlas region set, and it is the structural outlier of the whole corpus. Its automated-decision rule is not in a rights chapter or an obligations chapter: it is the third paragraph of art. 2 of Loi n° 2013-015 du 21 mai 2013, in Chapitre I, the chapter headed "De l'objet". Article 2 declares that informatics must be at the service of every person and must respect human identity, human rights, private life and public and individual freedoms, states that everyone has a right to the protection of their personal data, and then provides that no decision inducing legal effects with regard to a person may be taken on the sole basis of a computerised processing intended to define the profile of the person concerned or to evaluate certain aspects of their personality. It is the leanest formulation in the Francophone family in three ways: one limb only, with no separate bar addressed to the courts, which Senegal, Morocco, Algeria, Côte d'Ivoire, Niger and Benin all carry; no exception of any kind, which it shares only with Côte d'Ivoire; and the older formula "traitement informatique" rather than "traitement automatisé". The companion right is art. 12, which entitles any person to obtain from a controller the communication in intelligible form of all the data concerning them and any available information as to their origin, and the information and the reasoning used in computerised processing whose results are relied on against them — free of charge, on the spot or remotely, answered without delay, with a copy conforming to the content of the processing delivered on request. That reasoning right is the same one Niger states inside its art. 52, which makes Mali and Niger the only Francophone rows carrying it. The date is the date of the Journal officiel de la République du Mali that carries the Law, numéro 26 of 28 June 2013 at pp. 1002 to 1011, read directly; the Law was adopted by the Assemblée nationale on 9 May 2013 and promulgated at Bamako on 21 May 2013, and it contains no commencement article — Chapitre X consists of art. 69 alone, which only empowers the Autorité to supply practical implementation matters by deliberation. Enforcement is the weakest of any row on the tracker. No offence reaches art. 2: art. 58 refers the classification of offences to the Penal Code and other laws, and the Law's own fines in arts. 65 and 66 name other conduct — unauthorised communication or access, purpose diversion, unfair collection, health-research processing, offence data, security failures and unconsented sensitive data. And the administrative list in art. 61 is exhaustive and carries no fine at all: a warning against a good-faith controller, a mise en demeure, an injunction to cease processing, and withdrawal of agrément. The Autorité may execute its decision of its own motion under art. 62 and may transact on any pecuniary sanction under art. 67, and its President may denounce infringers to the Procureur under art. 56. Confidence is medium: the Malian general publication-to-force rule was not read against a primary source, so it could not be confirmed whether force attaches on the day of publication or after a delay.

Added

Benin joins the tracker: art. 401 of the Code du numérique, the bridge between Africa's Directive and GDPR automated-decision lineages

Benin is the thirteenth African jurisdiction on the tracker and the thirty-fifth in the atlas region set. Article 401 of Loi n° 2017-20 du 20 avril 2018 portant code du numérique sits in Livre cinquième, the book devoted to the protection of personal data, and is recorded from the date the Law bears: the Code has no commencement article, abrogates Loi n° 2009-09 du 24 mai 2009, and ends with a bare execution clause. Its shape is the Directive 95/46/EC shape — a judicial limb barring a court from founding an appraisal of a person's conduct on an automated processing intended to evaluate aspects of their personality, a general limb barring decisions from resting on the sole basis of such a processing, and an exception — but three things are imported from the GDPR and they change its character. The general limb reaches decisions producing legal effects with regard to a person or significantly affecting them, so the legal-effects ceiling that caps Senegal, Morocco and Algeria is gone. Profiling is a defined term and is named inside the judicial limb itself. And Benin is the only Francophone row on the tracker with a full logic-disclosure right: arts. 415 and 416 and the access right each require the controller to disclose the existence of automated decision-making including profiling within the meaning of art. 401 and, at least in such cases, useful information about the underlying logic and about the significance and the envisaged consequences of the processing, with a copy due within sixty days of an access request. Art. 401 processing is also a named data protection impact assessment trigger. The exception is the strongest-conditioned of the Francophone family: contract-based and law-based decisions escape the bar only if the contract or the enabling provision itself contains appropriate measures safeguarding the legitimate interests of the person concerned, and the person must at least be permitted to put their point of view usefully — where Senegal, Morocco and Algeria simply deem contract decisions outside the bar and Niger admits consent, contract and legal authorisation outright. No offence reaches art. 401 itself: the fifteen offences in art. 460 do not name it, though two of them — failing to respect the Livre's provisions on informing data subjects, and failing to respect its provisions on access rights — catch a controller that withholds the art. 401 disclosures, and art. 461 punishes those with six months to ten years' imprisonment and a fine of 10,000,000 to 50,000,000 francs CFA. The bar itself runs through the APDP: warning and an eight-day mise en demeure under art. 452, then a pecuniary sanction, cessation injunction, withdrawal of authorisation or blocking under art. 454, capped by art. 455 at 50,000,000 francs CFA on a first failure and at 100,000,000 francs CFA or 5% of pre-tax turnover, within a limit of 100,000,000, on repetition within five years, with appeal to the administrative court and discretionary publication. Confidence is medium: the Beninese general publication-to-force rule was not read against a primary source and the Journal officiel date could not be established, so entry into force can only be 20 April 2018 or later. Text read in the edition printed by the APDP itself. One drafting slip is recorded: art. 461 opens by referring to "les infractions visées à l'article 445" where the offence list is art. 460, which the same article then cites correctly twice.

Added

Senegal joins the tracker: art. 48 of Loi 2008-12, the closest African sibling of Morocco's and Algeria's art. 11

Senegal is the twelfth African jurisdiction on the tracker and the thirty-fourth in the atlas region set. Article 48 of Loi n° 2008-12 du 25 janvier 2008 portant sur la protection des données à caractère personnel is recorded from the date the Law itself bears: the copy published by the Commission de Protection des Données Personnelles runs from the exposé des motifs to art. 78 and contains neither a commencement article nor a publication clause. Its three paragraphs are the Directive 95/46/EC art. 15 shape in its purest African form — an absolute bar on a court founding an appraisal of a person's conduct on an automated processing intended to evaluate aspects of their personality; a bar on any decision producing legal effects being taken on the sole basis of an automated processing intended to define the person's profile or evaluate aspects of their personality; and a deeming clause under which contract-formation and contract-performance decisions where the person could present observations, and decisions satisfying the person's own requests, are not treated as taken on that sole basis. That makes Senegal, Morocco and Algeria the closest trio on the tracker, and it splits the Francophone family in two: those three keep the Directive's own drafting, while Côte d'Ivoire's art. 25 and Niger's art. 52 take the wider ECOWAS Supplementary Act A/SA.1/01/10 art. 42 drafting in which the legal-effects threshold disappears and any administrative or private decision appraising human conduct is caught. Senegal predates that Supplementary Act by two years. There is no right to know the logic of an automated processing — the art. 58 information list does not reach it — and no human-review right. Senegal is also the only jurisdiction on the tracker whose data-protection statute creates no offences at all: art. 75 is the entire penal chapter and simply refers infringements to the Penal Code and to the cybercrime law, Loi n° 2008-11 adopted the same day, so no penalty figure can be attributed to art. 48 from the statute itself. What is left is the CDP: warning and mise en demeure under art. 29; on non-compliance, provisional withdrawal of the authorisation for three months becoming definitive on expiry, and a fine of 1,000,000 to 100,000,000 francs CFA under art. 30; in urgency, interruption or blocking for up to three months and temporary or definitive prohibition under art. 31; appeal to the Conseil d'Etat under art. 32. Confidence is medium and one step weaker than Morocco's: no Senegalese official-gazette host resolved, so the date of the Journal officiel carrying the Law could not be established, and entry into force can only be 25 January 2008 or later.

Added

Niger joins the tracker: art. 52 of Loi 2022-59, the only rule anywhere on the tracker that names artificial intelligence inside a data-protection automated-decision article

Niger is the eleventh African jurisdiction on the tracker and the thirty-third in the atlas region set. Article 52 of Loi n° 2022-59 du 16 décembre 2022 relative à la protection des données à caractère personnel is recorded from the date of promulgation printed on the enacted text, "Fait à Niamey, le 16 décembre 2022": art. 112 combines abrogation and publication in a single bare clause and defers nothing. That article also settles a supersession question the sweep was opened on — Loi n° 2022-59 abrogates Loi n° 2017-28 du 3 mai 2017 as modified by Loi n° 2019-71 du 24 décembre 2019, so the 2017 statute is no longer operative and is not tracked. The provision opens with the same two limbs as Côte d'Ivoire's art. 25, word for word: no judicial decision appraising a person's conduct may be founded on an automated processing intended to evaluate aspects of their personality, and no administrative or private decision appraising human conduct may rest on the sole foundation of an automated processing giving a definition of the person's profile or personality. It then goes further than any other African row in two directions. It confers a right to know and to contest the information and the reasoning used in any processing, automated or not, whose results are relied on against the person. And it adds a sentence that exists nowhere else on the tracker: where that processing falls within artificial intelligence, the criteria and the nature of the personal data founding it must be indicated to the person from the point of collection — a disclosure duty that bites at collection rather than at the decision. In exchange Niger admits what Côte d'Ivoire does not: an automated individual decision is permitted on explicit consent, on contract necessity, or where authorised by a legislative or regulatory provision, which is the GDPR art. 22(2) exception set grafted onto a Directive-era bar. Profiling is a defined term in art. 1 and art. 31 puts any profiling or behavioural-analysis processing under prior HAPDP authorisation. Niger is also the first Directive-family row where a criminal penalty reaches part of the automated-decision article: art. 102 punishes obstructing the exercise of a right conferred by the Law with three months to two years' imprisonment and a fine of 1,000,000 to 20,000,000 francs CFA, which catches a refusal of the right to know and contest, though not the two bars themselves. Those run through arts. 92 to 94 — warning, mise en demeure, interruption, blocking, temporary or definitive prohibition, withdrawal of authorisation, and a pecuniary sanction capped at 100,000,000 francs CFA, rising on repetition within two years to 200,000,000 francs CFA or 5% of pre-tax turnover within a limit of 500,000,000. Confidence is medium because no Nigerien official-gazette host resolved: the date of the Journal officiel carrying the Law could not be established, so the promulgation date is used and the true entry into force can only be that date or later. The text was read article by article in the enacted signed copy published by the HAPDP and cross-read against the HAPDP's April 2026 consolidated version, which shows that none of Loi n° 2023-31, Ordonnance n° 2024-16 or Ordonnance n° 2024-29 has touched art. 52.

Added

Côte d'Ivoire joins the tracker: art. 25 of Loi 2013-450, the widest automated-decision bar in Africa and the only one with no exception at all

Côte d'Ivoire is the tenth African jurisdiction on the tracker and the thirty-second in the atlas region set. Article 25 of Loi n° 2013-450 du 19 juin 2013 relative à la protection des données à caractère personnel has been in force since publication in the Journal officiel de la République de Côte d'Ivoire of 8 August 2013 at pp. 474 to 482 — the Law sets no commencement date and its final article, art. 54, is a bare publication clause. The provision belongs to the Directive 95/46/EC art. 15 lineage, which reaches West Africa through art. 42 of the ECOWAS Supplementary Act A/SA.1/01/10, and it joins Morocco's and Algeria's art. 11 to make that the third three-member family on the continent. It is also the outlier of the family in both directions. It is the widest rule tracked in Africa, because its second limb is not confined to decisions producing legal effects and carries no significant-effect threshold either: no administrative or private decision involving an appraisal of human conduct may have as its sole foundation an automated processing giving a definition of the profile or the personality of the person concerned. Its first limb forbids a court to found an appraisal of a person's conduct on an automated processing intended to evaluate aspects of their personality. And it is the barest rule tracked anywhere on the tracker, because the Law states no exception whatever — where Morocco and Algeria both deem contract-formation and contract-performance decisions with an opportunity to present observations outside the bar, Côte d'Ivoire supplies no contract carve-out, no consent exception and no observations proviso. There is no right to know the logic underlying an automated processing, which Morocco has in art. 7(c), and no human-review right. No penal article reaches art. 25: the Law's three offences are confined to sensitive-data processing (arts. 21), unconsented direct marketing (art. 22) and obstruction of the regulator (art. 45). What is left is the administrative route in arts. 49 to 51 — warning, mise en demeure, interruption or blocking of the processing, temporary or definitive prohibition, provisional or definitive withdrawal of the authorisation, and a pecuniary sanction capped at 10,000,000 francs CFA, rising on a repeated failure within five years to 100,000,000 francs CFA or, for an undertaking, 5% of pre-tax turnover for the last closed financial year within a limit of 500,000,000 francs CFA. Art. 46 confers the functions of the Autorité de protection on ARTCI, the telecommunications and ICT regulator. Confidence is medium on the same narrow ground as Morocco and Algeria: the Ivorian general publication-to-force rule could not be read in a primary source, so the entry uses the date of the Journal officiel that carries the Law.

Added

Algeria joins the tracker: art. 11 of Loi 18-07, the only African rule that binds the courts themselves

Algeria is the ninth African jurisdiction on the tracker and the thirty-first in the atlas region set. Article 11 of Loi n° 18-07 of 10 June 2018 has been in force since publication in Journal officiel n° 34 of that day — the Law sets no commencement date and its final article, art. 76, is a bare publication clause. The provision belongs to the Directive 95/46/EC art. 15 lineage that so far only Morocco represented, and it is the stronger of the pair: its first limb forbids a court to found an appraisal of a person's conduct on an automated processing intended to evaluate aspects of their personality, with no exception at all, and its second limb bars any other decision producing legal effects from resting on the sole basis of an automated processing intended to profile the person or evaluate aspects of their personality. The only relief is a deeming clause: contract-formation and contract-performance decisions for which the person could present observations, and decisions satisfying the person's own requests, are not treated as taken on that sole basis. Like Morocco's art. 11, and unlike Rwanda's art. 21, no penal article reaches it — the enumerated offences in arts. 56 to 74 name every other operative article and omit this one, and art. 47's fixed 500,000 DA fine is confined to the data-subject rights and the notification duties. What is left is art. 46: warning, mise en demeure, provisional or definitive withdrawal of the declaration receipt or authorisation, and a fine of unstated amount, imposed by the Autorité nationale and appealable to the Conseil d'Etat. Confidence is medium on the same narrow ground as Morocco: the Algerian general publication-to-force rule in art. 4 of the Code civil could not be read in a primary source, because the 1975 Journal officiel volumes are image scans, and Loi n° 05-10 of 2005 amends the Code civil without touching art. 4.

correction

Chile Ley 21.719 (Art. 8° bis automated-decision right) — 1 December 2026 date still stands, but a government postponement is now under active evaluation

The 1 December 2026 entry-into-force date remains the legally operative one on the face of Ley 21.719 — no decree or amending law has changed it. But on 4 August 2026 co-Minister of Economy Daniel Mas publicly confirmed the government is evaluating a postponement, because the new Agencia de Protección de Datos Personales still has no seated Consejo Directivo: the Senate rejected the President's first slate of three nominees in May 2026 for lack of the required two-thirds quorum, and the June 2026 statutory deadline to appoint the board has lapsed. No amending bill has yet been introduced.

emol.com ↗

correction

Germany KI-MIG row corrected: EU AI Act Annex I high-risk deadline is 2 August 2028, not 2027

The status_note previously said the Annex I product-embedded high-risk obligations apply from 'Aug 2, 2027'. Under the Digital Omnibus (Regulation (EU) 2026/1744, in force since 27 July 2026), the Annex I deadline was deferred from 2 August 2026 to 2 August 2028, not 2027 — 2027-08-02 is not the Annex I date. Corrected to 'Aug 2, 2028' to match the eu-aia-highrisk-annex1 row.

eur-lex.europa.eu ↗

Added

Uganda joins the tracker: s. 27 of the Data Protection and Privacy Act, 2019, and Ghana loses its monopoly on hard African deadlines

Uganda is the eighth African jurisdiction on the tracker and the twenty-ninth in the atlas region set. Section 27 of the Data Protection and Privacy Act, 2019 (Act 9 of 2019) has been in force since 3 May 2019 — the Act sets no commencement date of its own, so s. 14(1) of the Acts of Parliament Act (Cap. 2) supplies the date of publication in the Gazette, and the Act was published in Uganda Gazette no. 21 of that day. The provision belongs to the UK Data Protection Act 1998 s. 12 lineage that already gave us Ghana's s. 41 and Tanzania's s. 36: a data subject may by written notice require that no decision significantly affecting them be taken solely by automatic means, and, whether or not such a notice has been served, a controller that has taken such a decision must notify the data subject as soon as reasonably practicable and must answer a reconsideration demand. Until today Ghana was the only African row with hard deadlines. Uganda now matches both of Ghana's twenty-one-day clocks — twenty-one days for the data subject to demand reconsideration after being notified, twenty-one days for the controller to report the steps it has taken — and adds a third that no other African row has: under s. 27(5) a data subject who is not satisfied with the controller's answer shall complain in writing to the Authority within fourteen days. That is the tightest end-to-end sequence on the continent. The trade-off is the same one Ghana makes: s. 27(4) excludes pre-contractual consideration, contract formation and contract performance outright, without requiring the safeguards that the GDPR-shaped exceptions in Kenya, Nigeria and Rwanda demand, so the rule simply does not reach the automated credit, insurance and hiring-shortlist decisions that sit inside a contractual frame. Nothing in s. 27 is backed by a fine: Part VIII creates only three offences, none of which touches automated decision-taking, and the sanction route is the Authority's power under s. 32 to direct a remedy. Text verified in the enacted copy published by the Ministry of ICT and National Guidance, including the Clerk to Parliament's certification and the President's assent page of 25 February 2019.

Added

Rwanda, Tanzania and Morocco join the Africa set — and the three lineages of African automated-decision law are now all represented

Three more African automated-decision provisions are now tracked, taking the continent from four rows to seven and the atlas from 61 countries to 63. Rwanda's Law No. 058/2021 art. 21, in force since its publication in the Official Gazette of 15 October 2021, is a standing prohibition in the GDPR art. 22 shape: no decision based solely on automated processing, including profiling, that may produce legal or significant consequences, unless it rests on explicit consent, on a contract, or on a law laying down safeguards. What makes it unusual is the paragraph that survives those exceptions — evaluative automated processing may not be grounded in sensitive personal data unless an art. 10 ground is met, a limit none of the other African rows carries. What it lacks is any remedy: where Nigeria grants human intervention and the right to contest, and Kenya grants written notification plus a fresh non-automated decision, Rwanda states the right and stops. Tanzania's Personal Data Protection Act, 2022 s. 36 came into operation on 1 May 2023, appointed by Government Notice No. 326 of 2023 and printed on the face of the Chapter 44 republication. It belongs to the same UK Data Protection Act 1998 lineage as Ghana's Act 843 s. 41 and is the closest pair on the tracker: a request-based right in subsection (1), and in subsection (2) an automatic duty to notify the data subject that a solely-automated decision was taken and to entertain a demand that it be reconsidered. The difference is the clock. Ghana fixes twenty-one days in each direction; Tanzania says only that notification must come as soon as practicable and sets no period at all for the controller's answer. Ghana therefore remains the only African row with hard deadlines. The Act also reaches Zanzibar, but only for union matters. Morocco's Loi 09-08 art. 11 is the oldest drafting on the tracker in this family and the only one descended from Directive 95/46/EC. Its first paragraph binds courts directly — no judicial decision appraising a person's conduct may be founded on automated processing intended to evaluate aspects of their personality — which nothing else on the tracker does. Its second paragraph extends the bar to any other decision producing legal effects, and its carve-out for contract formation and performance is conditioned on the person having been able to make observations, the same safeguard South Africa uses in POPIA s. 71(3). It is narrower than every peer in one respect: it reaches only decisions producing legal effects, with no significant-effect limb. The date recorded is the Bulletin Officiel publication of 5 March 2009; the Law has no commencement clause, and confidence is medium for that reason rather than because the text is in doubt. Uganda and Egypt remain unswept and are carried forward.

Added

Ghana joins the Africa set: Act 843 s. 41 forces a twenty-one-day reconsideration answer on solely-automated decisions

Section 41 of Ghana's Data Protection Act, 2012 (Act 843) is the country's operative automated-decision rule and is now tracked. Its shape is older than its regional peers' — it descends from the UK Data Protection Act 1998 rather than from GDPR Art. 22 — so the headline right is exercised by written notice: an individual may at any time require in writing that no decision significantly affecting them be based solely on processing by automatic means. The part that bites hardest does not depend on that notice. Section 41(2) applies despite its absence: where a controller has taken a solely-automated decision that significantly affects an individual, it must as soon as reasonably practicable tell the individual the decision was taken on that basis, and the individual may then demand reconsideration by written notice within twenty-one days of that notification. Section 41(3) gives the controller twenty-one days from that demand to state in writing what steps it will take. Those are the only hard clocks in any of the four African provisions the tracker now carries: Kenya's s. 35 says only 'a reasonable period', and South Africa's s. 71 and Nigeria's s. 37 set no deadline at all. Cutting the other way, the s. 41(4) carve-out is the widest of the four, excluding decisions made in considering whether to enter a contract, with a view to entering one, or in performance of one, with no requirement of compensating safeguards. Enforcement is indirect: the Commission may order compliance on a data subject's complaint under s. 41(5) or serve an enforcement notice under s. 75, and only failure to comply with that notice is an offence, carrying up to 150 penalty units or one year's imprisonment under s. 80(1). Commencement needed care. The Act does not commence itself — s. 99 leaves the date to the Minister by Gazette publication, and the '18 May 2012' printed on the Act is its gazette notification, not its commencement. The ministerial instrument is not published online anywhere official, so the date recorded here, 16 October 2012, is the one stated by the Data Protection Commission itself, the authority the Act creates. Ghana is the tracker's fourth African jurisdiction and its 61st country.

Added

Nigeria completes the Africa sweep: NDPA 2023 s. 37 gives a right to human intervention against solely-automated decisions

Nigeria was examined in this morning's Africa sweep alongside South Africa and Kenya but held back because no official host would serve the Act text. That gap is now closed. Section 37 of the Nigeria Data Protection Act, 2023 gives a data subject the right not to be subject to a decision based solely on automated processing of personal data, including profiling, which produces legal or similar significant effects. The right yields where the decision is necessary for entering into or performing a contract with the data subject, is authorised by a written law that establishes suitable safeguards, or is authorised by the data subject's consent — but s. 37(3) then requires the controller to implement suitable measures including the rights to obtain human intervention on the part of the data controller, to express the data subject's point of view, and to contest the decision. That makes it the strongest of the tracker's three African provisions on remedy: South Africa's POPIA s. 71 offers only representations plus disclosure of the underlying logic, and Kenya's Data Protection Act s. 35, while it alone requires written notification and allows a demand for a fresh non-automated decision, is otherwise the same shape. Section 65 defines automated decision-making as a decision based solely on automated processing by automated means, without any human involvement. Commencement is printed on the face of the enacted Act — [12th Day of June, 2023] — so the section has been in force since that date; the Act was published as Act No. 37 in the Federal Republic of Nigeria Official Gazette No. 119, Vol. 110 of 1 July 2023, at pages A719 to A758. The Commission's sanction under s. 48 is the greater of ₦10,000,000 and 2% of preceding-year annual gross revenue for a data controller or processor of major importance, or the greater of ₦2,000,000 and 2% for one that is not; failure to comply with a compliance order is a separate offence under s. 49 carrying the same fine ceiling or up to one year's imprisonment. The text was read in the Federal Government Printer's gazette PDF published by the Nigeria Data Protection Commission, the supervisory authority established by s. 4 of the Act; ndpc.gov.ng itself returns HTTP 403 to non-browser clients, so the citation resolves through the Internet Archive's byte-for-byte capture of that NDPC-hosted file. No secondary or NGO copy was used. The NDPC General Application and Implementation Directive 2025 may add implementation detail on automated decision-making but every archived capture replays 503, so it is not reflected here.

Added

Africa joins the tracker: South Africa's bar on solely-automated profiling decisions and Kenya's right to a re-decision

Until today none of the tracker's 113 obligations covered an African jurisdiction. Two go live, both already in force. South Africa enters through s. 71 of the Protection of Personal Information Act 4 of 2013, which bars a decision producing legal consequences or a substantial effect where it is based solely on automated processing intended to profile the person — the statute names performance at work, creditworthiness, reliability, location, health, personal preferences and conduct — unless the contract or law exception applies and appropriate measures give the data subject an opportunity to make representations plus sufficient information about the underlying logic of the processing. Commencement is not on the face of the Act: s. 115 leaves it to the President, and Proclamation No. R. 21 of 2020 (Government Gazette No. 43461, 22 June 2020) set 1 July 2020 for ss. 55 to 109, which contains s. 71, with the s. 114(1) transitional year closing on 1 July 2021. Breach runs through an enforcement notice, then an administrative fine of up to R10 million under s. 109 or, on non-compliance with the notice, an offence carrying up to ten years. Kenya enters through s. 35 of the Data Protection Act No. 24 of 2019, in force on its stated commencement date of 25 November 2019. It is the closer GDPR Art. 22 analogue of the two: the controller must notify the data subject in writing once a solely-automated decision with legal or significant effect has been taken, and the data subject can then require the decision to be reconsidered or a new decision taken that is not based solely on automated processing. The Data Commissioner's penalty is capped at KES 5 million or one per cent of an undertaking's preceding-year annual turnover, whichever is lower. Both texts were read at official sources — the gazetted Act on gov.za and the commencement proclamation published by the Information Regulator for South Africa, and the Office of the Data Protection Commissioner's copy of the Act for Kenya. Nigeria's Data Protection Act 2023 was examined in the same sweep but no copy is reachable on an official host, so it stays unpublished pending verification.

Added

Philippines and Thailand join the tracker: a consent bar on solely-automated decisions, and algorithmic ranking disclosure for platforms

Closes the ASEAN half of the coverage-symmetry sweep that added Indonesia yesterday. The Philippines enters through the Implementing Rules and Regulations of the Data Privacy Act of 2012, in force since 9 September 2016 (IRR Sec. 72, fifteen days after Official Gazette publication on 25 August 2016). IRR Sec. 48 is the sharpest provision: a controller must notify the National Privacy Commission once automated processing becomes the sole basis for a decision that would significantly affect a data subject, filing the methods and logic used and the decisions to be made — and no decision with legal effects may be taken solely on the basis of automated processing without the data subject's consent. IRR Sec. 34 adds a right to be informed of the existence of automated decision-making and profiling, meaningful information about the logic involved and its significance and envisaged consequences, and a right to object to automated processing or profiling. Fines follow NPC Circular No. 2022-01: 0.5 to 3 per cent of annual gross income for an infraction of Sec. 16 rights affecting more than 1,000 subjects, capped at PHP 5,000,000. Thailand enters on a different axis. The Royal Decree on the Operation of Digital Platform Service Businesses That Are Subject to Prior Notification, B.E. 2565, has been in force since 21 August 2023 — 240 days after publication in the Government Gazette on 23 December 2022 (Sec. 2) — and its Sec. 17 obliges intermediary platforms and online search engines to publish the main parameters of the algorithms or criteria they use to rank or recommend goods and services, to present advertisements, and to collect, moderate and publish user reviews. Enforcement is structural rather than monetary: Sec. 33 empowers the competent official to prohibit the service until compliance, and to strike the operator from the notification registry after ninety days of non-compliance. Thailand's PDPA has no GDPR Art. 22 analogue, so no solely-automated-decision right is tracked there. Malaysia was reviewed in the same pass and is not yet publishable: the Personal Data Protection Department has issued a final Automated Decision-Making and Profiling Guideline, but its operative date could not be extracted from the published text and is being verified separately.

Added

Indonesia joins the tracker: an objection right against solely-automated decisions and a mandatory impact assessment, both already in force

Extends the automated-decision coverage-symmetry cluster — Brazil LGPD Art. 20, China PIPL Art. 24, Korea PIPA Art. 37-2, Argentina Ley 25.326 Art. 20 and Chile's forthcoming Ley 19.628 Art. 8° bis — to the largest ASEAN jurisdiction, which the tracker had carried only as guidance-only on the strength of the non-binding Komdigi AI-ethics circular. Undang-Undang Nomor 27 Tahun 2022 tentang Pelindungan Data Pribadi entered into force on the day it was promulgated, 17 October 2022 (Art. 76; Lembaran Negara 2022 No. 196, Tambahan Lembaran Negara No. 6820), and the two-year alignment window that Art. 74 allowed controllers and processors closed on 17 October 2024, so the duties are fully exigible today. Art. 10(1) lets a data subject object to a decision taken solely on automated processing, including profiling, where it produces legal effects or has a significant impact; Art. 34(1) requires a personal-data-protection impact assessment for high-risk processing, and Art. 34(2)(a) puts automated decision-making with legal or significant effect at the head of that list. The two articles are not enforced alike: Art. 57(1) enumerates the sanctioned provisions and includes Art. 34(1) but not Art. 10, so the administrative fine of up to 2 per cent of annual revenue attaches to the impact-assessment duty, while the objection right runs through the supervisory body and the dispute-resolution route of Chapter XIII. No Government Regulation implementing the Act has been issued, which leaves the Art. 10(2) objection procedure, the Art. 34(3) assessment procedure and the Art. 57(5) fine procedure without detailed rules — verified against the Sekretariat Negara legal database, which returns no such regulation, and the Komdigi record for the Act, whose implementing-regulation section is empty. The statutory text was read in the full-text record published by the JDIH of the Kementerian Komunikasi dan Digital, the ministry of record; the Sekretariat Negara salinan is a scanned image without a text layer and peraturan.bpk.go.id refused every request.

Added

Chile joins the tracker: platform-algorithm duties in the Labour Code, and an automated-decision right from 1 December 2026

Completes the LATAM coverage-symmetry sweep begun on 15 August 2026, which had left Chile unresolved because the Biblioteca del Congreso Nacional text service returned HTTP 429 on every attempt. The same LeyChile service answers without the quota error on the backend host the LeyChile front end itself calls, so both candidate laws could be read in full. Two entries added. Chapter X of the Código del Trabajo, inserted by Ley 21.431 (published 11 March 2022) and in force since 1 September 2022 under its first transitional article, bans discrimination through automated decision-making in work allocation, bonuses and pay, treats apparently neutral conduct with disproportionate effect as discrimination, requires workers to be told the compliance mechanisms adopted, gives workers access to and portability of their ratings data within fifteen working days, and requires platforms to open the programming of the algorithm, its decision logic and its training data to the Dirección del Trabajo on request; the Dirección del Trabajo enforces it with the Art. 506 fines, doubled on repeat offence. Ley 21.719 (published 13 December 2024) inserts Art. 8° bis into Ley 19.628, a GDPR-style right to object to and not be subject to solely-automated decisions and profiling with legal or significant effects, backed by rights to an explanation, human intervention and review even where an exception applies; its first transitional article defers commencement to the first day of the twenty-fourth month after publication, i.e. 1 December 2026, so it is tracked as a scheduled date with fines of up to 20,000 UTM or 2–4% of turnover once the Agencia de Protección de Datos Personales takes up enforcement. Chile now appears as its own jurisdiction and moves from 'proposed' to 'binding sectoral' on the atlas.

Added

LATAM sweep: Mexico's platform algorithmic-management duties and Argentina's ban on solely-automated profiling decisions

Coverage-symmetry follow-up to the CAC Algorithmic Recommendation Provisions (cn-algo-recommendation), sweeping Mexico, Colombia, Chile and Argentina for in-force peers of the recommendation off-switch (CAC Art. 17), algorithmic work dispatch (Art. 20) and algorithmic price discrimination (Art. 21). Two entries added. Mexico: Capítulo IX Bis of the Ley Federal del Trabajo, added by the DOF decree of 24 December 2024 and in force since 22 June 2025 under Transitorio Primero, requires digital-platform employers to publish an algorithmic work-management policy covering how tasks are assigned, how ratings and incentives bite, and which categories affect allocation (Art. 291-J), and to route deactivation reviews through staff with autonomy and review power rather than algorithms (Art. 291-P), with fines of 1,000–25,000 and 500–25,000 UMA respectively under Art. 997-B. Argentina: Art. 20 of Ley 25.326 voids judicial decisions and administrative acts founded solely on automated profiling of the data subject, in force since November 2000 and the country's only in-force constraint on automated decision-making; Argentina now appears as its own jurisdiction. Colombia and Chile returned no publishable in-force peer this pass — Arts. 29 and 30 of Ley 2466 de 2025 (automated-supervision transparency and a right to human review for delivery-platform workers) are enacted but deferred by Art. 67 to twelve months after a reglamentación that has not yet been issued, so no date is publishable, and Chile's Ley 21.431 could not be verified because the Biblioteca del Congreso Nacional text service was rate-limited throughout; both are tracked for a later pass.

Added

China: CAC Algorithmic Recommendation Provisions — in force since 1 March 2022

Closes the coverage gap logged alongside cn-pipl-art24. The Provisions on the Administration of Algorithmic Recommendation in Internet Information Services (Order No. 9 of the CAC, MIIT, Ministry of Public Security and SAMR, signed 31 December 2021, published 4 January 2022, effective 1 March 2022 per Art. 35) are China's operative algorithm-governance regime and were untracked. They bind any provider using generative/synthetic, personalised-push, ranking, retrieval-filtering or scheduling-decision algorithms to supply internet information services in the PRC: conspicuous disclosure that recommendation is in use plus publication of the basic principles, purpose and main mechanisms (Art. 16); a non-personalised option or convenient off-switch and user control over personal-characteristic tags (Art. 17); periodic review of mechanisms, models, data and outputs and a ban on addiction- or overspending-inducing models (Art. 8); labelling of unlabelled algorithmically generated or synthesised information before onward transmission (Art. 9). Providers with public-opinion attributes or social-mobilisation capacity must also file in the CAC algorithm filing system within 10 working days of launch with an algorithm self-assessment report (Art. 24), display the filing number (Art. 26) and run a security assessment (Art. 27). Art. 21 bans algorithmic price discrimination against consumers; Arts. 18-20 add duties towards minors, the elderly and gig workers under algorithmic dispatch. Art. 31 penalty: warning, circulated criticism, rectification order, and on refusal or serious circumstances suspension of information updates plus RMB 10,000-100,000; Art. 32 routes the remaining breaches to the underlying laws (PIPL Art. 66 reaches RMB 50,000,000 or 5% of turnover). Verified against the full Chinese text at the CAC publication (https://www.cac.gov.cn/2022-01/04/c_1642894606364259.htm). Impact tier: all entities.

Added

China: PIPL Art. 24 automated-decision-making duties — in force since 1 November 2021

Continues the coverage-symmetry sweep of automated-decision duties that sit inside data-protection statutes rather than AI-specific acts (peers already tracked: br-lgpd-art20, kr-pipa-art37-2-adm, uk-duaa-adm, ca-quebec-law25, au-adm-privacy-app). China's five existing rows were all CAC AI instruments, so the general ADM duty was uncovered. PIPL Art. 24 requires transparency and fair results in automated decision-making, bans unreasonable differential treatment in transaction prices and other transaction conditions, requires a non-personalised option or a convenient refusal route for automated push delivery and commercial marketing, and gives individuals a right to an explanation of, and a right to refuse, decisions made solely by automated means where those decisions have a major effect on their rights and interests. Art. 55(2) requires a personal information protection impact assessment before automated decision-making, retained with the processing record for at least three years (Art. 56). Verified against the official NPC text on npc.gov.cn and against the Cyberspace Administration of China republication (identical wording), which is the cited link because npc.gov.cn does not serve https: Art. 24, Art. 55, the Art. 73(2) definition of automated decision-making, the Art. 66 penalty tiers, and Art. 74, which puts the commencement date of 1 November 2021 on the face of the statute. Coverage gap logged for follow-up: the CAC Provisions on the Administration of Algorithmic Recommendation in Internet Information Services (in force 1 March 2022) are still untracked.

cac.gov.cn ↗

Updated

Vietnam: Decision 33/2026/QD-TTg — the 46 high-risk AI systems list is now in force

Scheduled lifecycle flip: vn-highrisk-dec33 moves from 'dateset' to 'force' on its stated commencement date of 15 August 2026. Re-verified on the day against the Government legal-document portal record for the Decision, which states Ngay ban hanh (issued) 30-06-2026 and Ngay co hieu luc (effective) 15-08-2026. From today, new deployments of any of the 46 designated high-risk AI systems require a pre-deployment conformity assessment under Law 134/2025/QH15 and Decree 142/2026/ND-CP. Systems already in operation get a transition period: 1 March 2027 for most sectors, 1 September 2027 for healthcare, education and finance. No change to the date, source, penalty or scope fields.

correction

NY RAISE Act: superseded by March 2026 chapter amendment moving oversight to a new DFS office

Daily verification found the row's source_url still pointed to the original 19 December 2025 signing (Ch. 699) and status_note was blank. A chapter amendment, S8828 (Ch. 96), was introduced 6 January 2026, passed both chambers, and was signed by Governor Hochul on 27 March 2026, superseding the original text. The amendment moves rulemaking and critical-incident-report oversight from the Division of Homeland Security and Emergency Services to a new office within the NY Department of Financial Services (DFS); the 1 January 2027 effective date is unchanged.

nysenate.gov ↗

Added

Brazil: LGPD Art. 20 gives a right to review of solely-automated decisions — in force since 18 September 2020

Closes AIL-207, found in the AIL-206 coverage-symmetry sweep of automated-decision duties sitting inside data-protection statutes (peers: kr-pipa-art37-2-adm, uk-duaa-adm, ca-quebec-law25, au-adm-privacy-app). Brazil previously had only br-pl2338 (proposed), so the tracker showed zero in-force Brazilian coverage. LGPD Art. 20, as amended by Lei 13.853/2019, lets a data subject request review of decisions taken solely on the basis of automated processing that affect their interests, including profiling for personal, professional, consumer or credit purposes, and requires the controller to disclose the criteria and procedures used, subject to trade secrecy; where secrecy is invoked the ANPD may audit for discriminatory effects. Note the amendment deleted the original "por pessoa natural" requirement, so this is not a guaranteed human-review right. The in-force date was traced through the Art. 65 amendment chain on Planalto rather than taken from secondary sources: Lei 13.853/2019 set 24 months after publication (LGPD published DOU 15.8.2018); MP 959/2020 art. 4 moved that to 3 May 2021 and was in force from 29.4.2020; the conversion law Lei 14.058/2020, published DOU 18.9.2020 and effective on publication, carries no amendment to Lei 13.709, so the postponement lapsed and the general articles took effect 18 September 2020. Sanctions under Arts. 52-54 commenced 1 August 2021 per Art. 65 I-A (Lei 14.010/2020), and the penalty field reflects that. Coverage-symmetry check of ANPD normative acts found no AI- or ADM-specific resolução as of 2026-08-14.

Added

South Korea: PIPA Art. 37-2 gives data subjects the right to object to, and demand an explanation of, fully automated AI decisions

Coverage-symmetry sweep off uk-si-2026-425-ico-ai-code: automated-decision-making duties that sit inside data-protection statutes rather than AI-specific acts. Korea's Personal Information Protection Act Art. 37-2, inserted by Act No. 19234 (promulgated 14 March 2023), took effect 15 March 2024 under Addenda Art. 1(1) — one year after promulgation, six months later than the bulk of that amendment. It expressly covers decisions made by 'a completely automated system (including a system to which artificial intelligence technologies are applied)' that significantly affect a data subject's rights or duties: the data subject may object and request an explanation, and the controller must then either not apply the decision absent compelling reason or take measures such as human re-processing. Controllers must also disclose the criteria and procedures for automated decisions. Verified against the official English text of PIPA published by the Personal Information Protection Commission (PIPA2023.pdf, Enforcement Date 15 Sep 2023 edition, which carries both Art. 37-2 and the Addenda commencement rule) and cited to law.go.kr. Penalty confirmed at PIPA Art. 75(2) 24: administrative fine up to KRW 30 million for breach of Art. 37-2(3). This is separate from Korea's AI Basic Act entries — the trigger is personal-data processing, not AI-operator status.

Corrected

Data fix: Vietnam Decision 33/2026 entry used jurisdiction_label 'VN', splitting Vietnam into two jurisdictions

vn-highrisk-dec33 carried jurisdiction_label 'VN' while vn-ai-law-risk and vn-ai-law-labelling carried 'Vietnam', so the same country appeared twice in jurisdiction facets and counts. Normalised to 'Vietnam'. No substantive change to the obligation.

Added

UK: SI 2026/425 adds a statutory duty on the ICO to produce an AI and automated-decision-making code of practice

Found via a legislation.gov.uk 2026 title search while checking whether the UK AI (Regulation) Bill had been enacted (it has not). The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026 (SI 2026/425) were made 16 April 2026, laid 21 April and came into force 12 May 2026. They require the Information Commissioner to prepare a statutory code of practice covering the development and use of AI and automated decision-making under the UK GDPR and DPA 2018, expressly including guidance on children's personal data. The code has not yet been issued, so its own start date is TBD; the instrument's in-force date is what is tracked here. Regulation 3 carves national security out of the s.124B review panel's remit.

Added

Coverage sweep (AIL-204): Washington, Oregon and California added to the DE HB 191 nonhuman-entity title-protection class

Following the Delaware HB 191 addition, swept US states for enacted statutes barring AI/nonhuman entities from professional licensure or protected-title use. Confirmed and added three: Oregon HB 2748 (2025 c.378 §2, codified ORS 678.027, in force 2026-01-01 — first state to enact this class, bars nonhuman entities from nursing titles/abbreviations, Class C misdemeanor under ORS 678.990); Washington HB 2155 (amending RCW 18.79.030, in force 2026-06-11 — bars nonhuman entities from RN/APRN/LPN titles, enforced as unlicensed practice under RCW 18.130.190, gross misdemeanor/felony); California AB 489 (Bus. & Prof. Code §§ 4999.8-4999.9, in force 2026-01-01 — structurally distinct: extends existing health-profession title-protection crimes to AI/GenAI developers and deployers across all licensed healing-arts professions, not a standalone nonhuman-entity bar, but included under Coverage Symmetry as the title-protection analogue). All three verified against official legislature/state-code primary sources with bill text fetched and quoted directly. Ruled out: New York SB 7263 (unauthorized-practice liability bill) — not yet enacted as of 2026-08-14, still on Senate third reading as of 2026-03-04; excluded pending passage.

Added

Delaware added: HB 191 bars AI agents from medical/nursing licensure and protected titles

Delaware had no entries in the tracker. A full sweep of all 1,961 records of the 153rd General Assembly surfaced HB 191, signed and approved 23 April 2026 as 85 Del. Laws ch. 250. The Act amends 24 Del. C. §§ 1920, 1720 and 1773 to provide that a nonhuman entity, "including an agent powered by artificial intelligence", may not be licensed or certified to practice professional, advanced practice or practical nursing, medicine, or as a physician assistant, and may not use the associated protected titles (Nurse, RN, LPN, APRN, CRNA, CNS, CNP, CNM, Doctor/Dr., Physician, Surgeon, MD, DO, Physician Assistant/PA). There is no delayed-effective-date clause, so the entry is published in force from 23 April 2026. Penalties come from the existing enforcement provisions: unlawful practice of medicine is a class F felony carrying a $1,000–$5,000 fine and up to 3 years (24 Del. C. § 1766(a)), other Chapter 17 violations are a class B misdemeanor (§ 1766(c)), and nursing practice or title misuse carries up to $1,000 and up to 1 year (§ 1925). Verified against the Laws of Delaware session-law text and delcode.delaware.gov; not sourced from any secondary summary.

new

Brazil's ECA Digital carries algorithmic duties that have been in force since March, and its first transparency report is due 17 September 2026

Lei 15.211/2025, the ECA Digital, was sanctioned on 17 September 2025 and has been in force since 17 March 2026 - Art. 41-A originally said six months after publication, and Lei 15.352/2026 replaced that with the express date. We had no entry for it because it reads at first as a child-online-safety statute, but the consolidated text on Planalto imposes duties squarely on algorithmic systems, so it belongs here. Art. 17 s.4 requires the default parental-supervision settings of services directed at or likely accessed by minors to include control over personalised recommendation systems with an option to switch them off (item V) and regular review of the artificial-intelligence tools in the service, with specialists and competent bodies participating, against technical criteria that ensure safety and suitability for minors, with non-essential functionalities capable of being disabled (item VIII). Art. 22 bans profiling for advertising directed at minors and the use of emotional analysis or augmented, extended and virtual reality for that purpose; Art. 26 bans building behavioural profiles of minors from personal, group or collective data, including data collected during age verification; and Art. 30 II requires a provider removing content to tell the user whether the content was identified by human or automated analysis. Decreto 12.622/2025 designates the ANPD as the autonomous enforcement authority under Art. 34 and Decreto 12.880/2026 is the implementing regulation. Penalties under Art. 35 run to 10% of the economic group's Brazilian turnover or, absent turnover, R$10 to R$1,000 per registered user, capped at R$50,000,000 per infraction, with suspension and prohibition of activities reserved to the courts. The Art. 31 semi-annual transparency report is tracked separately because it carries its own near-term date. It binds internet application providers with more than 1,000,000 registered child and adolescent users connecting from Brazil, and must be published in Portuguese on the provider's own site covering complaint channels and volumes, moderation counts by type, the measures used to identify child accounts under Art. 24 s.3 and illicit acts under Art. 27, technical improvements for data protection and parental consent, and the methods and results of impact and risk assessments. The statute sets no publication date, so Despacho Decisorio CD/ANPD 122/2026, published in the Diario Oficial da Uniao on 11 August 2026, supplies the calendar until specific regulation supervenes: the first report covers 1 January to 30 June 2026, or 17 March to 30 June for providers without earlier data, and must be published by 17 September 2026; from the second report the periods follow the civil semesters, due 1 August and 1 February. This is Brazil's second and third in-scope entry after br-lgpd-art20, alongside the still-proposed AI bill br-pl2338.

planalto.gov.br ↗

Updated

Colorado AI Act entry now records the FTC's proposed Section 5 policy statement as a live federal-preemption pressure

The Colorado AI Act (SB 26-189) entry already carried the consent-based enforcement stay in xAI v. Weiser. A second, independent source of pressure on the same statute is now recorded: the FTC's proposed 'Policy Statement Concerning the Suppression of Accuracy in Artificial Intelligence Systems', published in the Federal Register on 7 July 2026 under docket FTC-2026-0859. The notice names Colorado's revised Artificial Intelligence Act by name and treats output steering undertaken in attempted compliance with such a State law as potentially deceptive under Section 5 of the FTC Act — an implicit preemption threat. The comment period closed 31 July 2026 and drew opposing filings, including a multistate attorney-general coalition comment. Nothing about the Colorado statute changes: the entry keeps its 1 January 2027 date, its scope and its lifecycle, because the FTC has neither finalised the statement nor obtained a ruling, and the Federal Register notice creates no obligation of its own. It is carried as status context so readers tracking the 2027 date can see that a federal challenge to that regime is live. Verified against the Federal Register notice; the regulations.gov comment docket and ftc.gov comment index both refuse automated retrieval from the pipeline host, so the coalition filing itself is described without a date or a headcount.

federalregister.gov ↗

Updated

In force today — Colorado's psychotherapy AI restrictions and Saudi Arabia's AI training exemption

Two entries move from scheduled to in force on 12 August 2026. Colorado HB 26-1195 restricts the delivery of psychotherapy by artificial intelligence without a licensed professional's real-time involvement, and requires disclosure and written consent; the Act carried no safety clause, so the general post-session effective date governs, and the General Assembly's bill record now carries it as session law Chapter 358 with an effective date of 08/12/2026. Enforcement sits exclusively with the Colorado Attorney General as an unfair trade practice, at $20,000 per violation after a 60-day cure period, and is unaffected by the federal court order pausing enforcement of SB 26-189. Saudi Arabia's Copyright Law (Royal Decree M/169) enters into force the same day under Art.61, 180 days after publication in Umm Al-Qura issue 5144 of 13 February 2026. Its Art.26(4) is a permission rather than a duty: reproduction of an original work to develop AI products and algorithms needs no authorisation or compensation, provided the work was lawfully published, the original copy lawfully obtained, and the copying stays within what the purpose requires. The Implementing Regulation was published ahead of that date.

leg.colorado.gov ↗

Updated

California AB 853 split into its three statutory tranches, and a 2028 capture-device deadline surfaced

California's AB 853 (approved 13 October 2025) layers three separate start dates onto the California AI Transparency Act, and we were carrying them as a single in-force row dated 2 August 2026, which hid both future deadlines from the tracker. The enacted text on leginfo sets them out expressly. The covered-provider duties in Bus. & Prof. Code s 22757.3 - a free AI-detection tool and latent disclosures for a GenAI system with over 1,000,000 monthly visitors or users that is publicly accessible in California - became operative on 2 August 2026 under s 22757.6 and stay tracked as us-ca-sb942. From 1 January 2027, s 22757.3.1 requires a large online platform to detect provenance data, expose it through a user interface, let users inspect or download it, and stop knowingly stripping provenance data or digital signatures, while s 22757.3.2 bars a GenAI hosting platform from knowingly making available a model that omits those disclosures; us-ca-ab853 now carries that 2027 date. From 1 January 2028, s 22757.3.3 requires capture device manufacturers to offer a latent disclosure and embed it by default in devices first produced for sale in the state on or after that day; that tranche is new as us-ca-ab853-capture-device and had no entry before today. Two scope corrections came out of the same reading: the large online platform test is 2,000,000 unique monthly users over the preceding 12 months under s 22757.1(h)(1), not the 1,000,000 figure that applies to covered providers, and capture device manufacturers face no size threshold at all. Penalties across the chapter are $5,000 per violation with each day a discrete violation, enforced by the Attorney General, a city attorney or a county counsel under s 22757.4.

leginfo.legislature.ca.gov ↗

Updated

Connecticut's online safety act split into its four statutory tranches

Connecticut Substitute Senate Bill 5 became Public Act No. 26-15, an act concerning online safety, signed by the Governor on 27 May 2026. We were carrying it as a single row dated 1 October 2026 with its three later start dates mentioned only in a note, so those deadlines did not appear anywhere in the tracker. Reading the enacted public act, each section carries its own effective-date parenthetical, and the private-sector duties fall into four tranches. From 1 October 2026: s 1 subscription-based provider disclosures, s 2 frontier developer duties, s 15 provenance data and detectability of synthetic digital content for a generative provider with more than 1,000,000 monthly users that is publicly accessible for personal use, and s 38 controls on state agency use and procurement of AI. From 1 January 2027, ss 4 to 6 govern artificial intelligence companions, with heightened duties where the user is under eighteen, including a clear and conspicuous statement at the start of each interaction that the companion is not a licensed mental health professional, and bars on romantic or erotic interaction, on discouraging a minor from seeking mental health services or adult help, and on manipulative techniques that extend engagement. From 1 October 2027, the automated employment-related decision technology duties in ss 8 to 10 attach; those sections are themselves effective 1 October 2026, but each duty is written to apply only to technology deployed in the state on or after 1 October 2027, which is the date that matters to developers and deployers. From 1 January 2028, s 39 restricts personalised recommendation feeds for covered users under eighteen unless the operator uses commercially reasonable and technically feasible age determination or obtains verifiable parental consent. Enforcement across the act runs through the unfair or deceptive trade practice route in Conn. Gen. Stat. s 42-110b(a), reserved to the Attorney General for ss 1, 5, 6, 15 and 8 to 11. The entry title has also been corrected: the act is Public Act 26-15, an act concerning online safety, not an AI Responsibility and Transparency Act, and the source now cites the enacted public act rather than the bill status page.

cga.ct.gov ↗

correction

Saudi Arabia AI training exemption — source URL corrected, Implementing Regulation now published

The cited Umm Al-Qura URL (uqn.gov.sa/decisions-and-regulations/4000303) was found on re-fetch to resolve to Cabinet Resolution No. 560, an earlier decision approving the draft law and referencing only the superseded 2003 decree (M/41) — not the enacted Royal Decree M/169 text. The source_url is corrected to the Umm Al-Qura gazette page publishing the Copyright Law itself (Art.26 and Art.61 confirmed present). Separately, the Art.60 Implementing Regulation (Executive Regulation of the Copyright System, 98 articles across 13 chapters) has now been published in Umm Al-Qura, ahead of the Law's 12 August 2026 entry into force; the entry no longer describes it as merely 'due around Aug 2026'.

uqn.gov.sa ↗

correction

Vietnam Decision 33 — MoST explainer guidance located (published 3 Jul 2026); earlier "none published" note corrected

The status note previously stated that no supplementary MoST guidance had been published as of 9 August 2026. That was incorrect when written, not overtaken by events: MoST's own portal (mst.gov.vn) published explainer content on 3 July 2026 covering all 6 sectors designated under Decision 33/2026/QD-TTg and both transition deadlines (1 March 2027 / 1 September 2027), with a further notice on 8 July 2026 — five weeks before the check that reported none existed. The material is contextual guidance, not a new binding regulation, so the obligation's substance (46 systems, effective 15 August 2026) is unchanged; the negative claim has been replaced with the dated MoST citation.

vanban.chinhphu.vn ↗

Updated

Canada — new federal privacy bill C-36 carries AI-transparency provisions

AIDA (Bill C-27) remains dead on prorogation and was not itself reintroduced. However, a separate federal bill, C-36 (Protecting Privacy and Consumer Data Act, 45th Parliament), had first reading 15 June 2026 and is at second reading in the House as of 11 August 2026; it amends PIPEDA and includes AI-related transparency provisions (e.g. disclosure for automated/algorithmic decision tools). It is a privacy-law vehicle rather than an AIDA-style comprehensive AI act, and is not yet enacted, so Canada's status is unchanged for now, but the entry's status note is updated to reflect this development.

parl.ca ↗

correction

Singapore MAS agentic-AI entry corrected — SAFR is voluntary, not the binding instrument

The entry previously described SAFR (Safeguards for Agentic Finance at Runtime) as MAS's binding supervisory framework for agentic AI. Re-checked against MAS's own parliamentary reply of 5 August 2026 and its 13 November 2025 AI Risk Management Guidelines consultation paper: SAFR, published 3 July 2026, is an industry-led voluntary information paper, not a binding instrument. The binding track is MAS's proposed AI Risk Management Guidelines, still in consultation, which propose a 12-month compliance transition once issued but carry no MAS-confirmed finalization date — 'Q4 2026' was market/analyst expectation, not a MAS commitment. The parliamentary reply itself states MAS will continue to review and update existing supervisory expectations for AI agents, rather than declaring a new codified binding rule already in force. Title, summary, status note and law_short updated to separate the voluntary SAFR paper from the still-pending binding Guidelines; confidence remains medium pending the Guidelines' finalization. The Singapore jurisdiction record was brought in line with the same correction.

mas.gov.sg ↗

Added

Three more AI-training copyright exceptions on the Radar — Japan Art.30-4, Singapore s.244, EU DSM Art. 4

The copyright and training-data themes launched with only the Saudi exemption and the EU AI Act's general-purpose AI model duties. The three other statutory regimes that actually govern whether protected works can be mined for model training are now carried as entries, each read against its own primary text. Japan's Copyright Act Art.30-4 (in force 1 January 2019) is the broadest: exploitation for information analysis with no rightholder opt-out and no non-commercial limit, bounded only by the proviso for unreasonable prejudice to the copyright owner. Singapore's Copyright Act 2021 s.244 (in force 21 November 2021) permits copying for computational data analysis — s.243 names training a program as an example — gated on lawful access to a non-infringing source copy, with contracting-out void under s.187. The EU's DSM Directive Art. 4 (transposition deadline 7 June 2021) permits commercial mining of lawfully accessible works but only where the rightholder has not reserved the use by machine-readable means; that reservation is precisely what AI Act Art. 53(1)(c) requires model providers to respect, so the two EU entries cross-reference rather than duplicate. The United Kingdom was checked and produced no entry: the Data (Use and Access) Act 2025 ss.135-137 place reporting duties on the Secretary of State rather than on AI developers, and CDPA s.29A remains confined to non-commercial research.

eur-lex.europa.eu ↗

Updated

Two new themes — Copyright & intellectual property, and Training data & TDM

The Radar's topic taxonomy previously had no home for IP-side instruments, so the Saudi AI training exemption (Copyright Law Art.26(4)) shipped untagged and was absent from every topic filter. Two themes are now defined. Copyright covers rules that restrict or expressly permit the use of protected works to build and run AI systems; Training data & TDM covers sourcing, mining permissions and training-content disclosure. Both are seeded with the Saudi exemption and with the EU AI Act's general-purpose AI model duties, whose Article 53(1)(c) copyright-policy limb and Article 53(1)(d) public training-content summary are now named in that entry rather than left implicit. Article 53 duties have applied since 2 August 2025 under Article 113(b). Verified against the Official Journal text of Regulation (EU) 2024/1689.

eur-lex.europa.eu ↗

correction

Saudi Arabia AI training exemption re-verified against the statutory text — three conditions added, source upgraded to the Official Gazette

The Saudi Copyright Law entry (Royal Decree M/169, Art.26(4)) was first published citing law-firm briefings. Re-verified against the Arabic statutory text: Art.26(4) permits reproduction of an original work for developing AI products and algorithms without author authorization or compensation only where the work was lawfully published, the original copy was lawfully obtained, and the copying stays within what the purpose requires — those three conditions are in the statute itself, not left to the Implementing Regulation, and are now stated in the entry. Art.61 (180 days from Official Gazette publication; Umm Al-Qura issue 5144 of 13 Feb 2026) confirms the 12 August 2026 in-force date and rules out the '1 August 2026' figure circulating in one briefing. Art.60 puts the Implementing Regulation within 180 days of the Law's issuance, applying from entry into force — around Aug 2026, correcting an earlier '~Feb 2027' estimate. Art.59 repeals the 2003 Copyright Law (M/41). Singapore's country record was also brought in line with the binding MAS agentic-AI position confirmed on 5 Aug 2026.

uqn.gov.sa ↗

Added

New EU deadline 2 Aug 2030 — legacy high-risk AI intended for public authorities must be brought into compliance

The Digital Omnibus on AI (Regulation (EU) 2026/1744, Article 1(39)(a)) replaces Article 111(2) of the EU AI Act. Alongside the general grace period for high-risk systems placed on the market before the Chapter III application dates, the replaced text sets a hard backstop: providers and deployers of high-risk AI systems intended to be used by public authorities have until 2 August 2030 to meet the AI Act's requirements and obligations. Recital (39) confirms the grace period runs at type-and-model level, with a significant change in design ending it. Verified against the OJ PDF (OJ L, 24.7.2026). This is now the furthest-out dated duty tracked for the EU; breaches sit in the Article 99(4) tier (up to 3% of turnover or EUR 15M).

eur-lex.europa.eu ↗

Added

New EU deadline 2 Dec 2026 — Art. 50(2) marking retrofit for synthetic-content systems already on the market

The Digital Omnibus on AI (Regulation (EU) 2026/1744, Article 1(39)(b)) adds a new Article 111(4) to the EU AI Act giving providers of AI systems, including general-purpose AI systems, that generate synthetic audio, image, video or text and were placed on the market before 2 August 2026 until 2 December 2026 to implement the Article 50(2) marking obligation. Recital (38) frames it as a four-month transitional period. Verified against the OJ PDF (OJ L, 24.7.2026). Breaches sit in the Article 99(4) tier (up to 3% of turnover or EUR 15M), not the 7% Article 5 tier that applies to the new CSAM/NCII prohibitions sharing the same date.

eur-lex.europa.eu ↗

Updated

Illinois SB 343 signed into law as Public Act 104-0805 — no AI provisions

Governor Pritzker signed the bill on 2026-08-07 as Public Act 104-0805. As previously tracked, the enacted text contains no AI or algorithmic-pricing provisions, so no AI obligation exists under this bill number.

ilga.gov ↗

Updated

AI Kill Switch Act assigned bill number H.R. 9917

The bill introduced by Reps. Lieu and Moran on 2026-07-23 has been indexed as H.R. 9917 and referred to the House Committee on Homeland Security. No change to lifecycle or substantive obligations.

govinfo.gov ↗

correction

UK DUAA s.138 commencement — SI citation corrected

The row cited SI 2026/82 as the commencement instrument for section 138 (non-consensual deepfake creation/request offences). The correct instrument is SI 2026/31 (Commencement No. 5 Regulations 2026); SI 2026/82 (Commencement No. 6) instead commences the separate automated decision-making reform tracked under uk-duaa-adm. The in-force date of 2026-02-06 is unchanged.

legislation.gov.uk ↗

correction

Illinois SB 343 — AI rental-pricing language removed from the bill before transmittal to the Governor

Senate Floor Amendment No. 1 (adopted 2026-05-21) had added the algorithmic rental-price-coordination ban this row tracks, but House Committee Amendment No. 1 (adopted 2026-05-29) replaced that content entirely with unrelated Cook County / Calumet City eminent-domain provisions. The bill sent to Gov. Pritzker on 2026-06-30 contains no AI provisions. Confidence raised to high now that the current bill text is confirmed; status_note updated to explain the amendment history. No AI obligation currently exists under this bill number.

ilga.gov ↗

correction

Rhode Island H 7349 — effective date confirmed as signing date

The row's status_note previously flagged the effective date as unconfirmed pending Rhode Island Legislature source review. Secondary reporting on the enacted law confirms the act took effect upon passage on June 22, 2026, matching the date already tracked. Status note updated to remove the TBD language; no change to the tracked date or lifecycle.

transparencycoalition.ai ↗

Added

Added California AB 853 — AI Transparency Act Phase 2 (Aug 2, 2026)

Added new entry for AB 853, which extends the California AI Transparency Act duties to large online platforms and device manufacturers. Phase 1 (AI detection tools, manifest disclosures) is in force from August 2, 2026; Phase 2 (additional large-platform obligations) activates January 1, 2027.

leginfo.legislature.ca.gov ↗

correction

Rhode Island S 2195 — source citation corrected to enacted Substitute A text

The row cited the as-introduced bill text (LC003227), which lacks the AG-reporting and penalty language reflected in the row's status_note. The enacted version is Substitute A. Source updated to the Substitute A PDF; no change to the tracked date, lifecycle, or facts, which already matched the enacted text.

webserver.rilegislature.gov ↗

correction

China AI Agents Opinions — upgraded to the CAC's own primary text

The row previously cited an English-language gov.cn news writeup. The Cyberspace Administration of China has published the authoritative Chinese-language full text of the AI Agent Standardized Application and Innovative Development Implementation Opinions on its own domain. Source updated to the CAC original and confidence raised from medium to high; no change to the tracked date or substance.

cac.gov.cn ↗

correction

UK AI (Regulation) Bill [HL] confidence upgraded to high

UK Parliament's Bills API confirms the Bill remains at first reading in the House of Lords with no progress since introduction. DSIT's published Blueprint for AI Regulation favours an AI Growth Lab / sector-sandbox approach over government-sponsored AI legislation, corroborating the existing assessment that the Bill is unlikely to advance as drafted. Confidence raised from medium to high; no change to the tracked facts or dates.

bills-api.parliament.uk ↗

Added

Add UK DUAA ADM reform, UK DUAA s.138 deepfake offences, China AI Agents Opinions

Three obligations identified as coverage gaps and added to the register. UK: the Data (Use and Access) Act 2025 automated decision-making reform (ss.22A-22D of the UK GDPR, in force 5 February 2026 by SI 2026/82), which replaces the Art. 22 default prohibition with notification, representation, human-review and contest duties. UK: DUAA 2025 s.138, in force 6 February 2026, which inserts ss.66E-66H into the Sexual Offences Act 2003 and criminalises creating or requesting a non-consensual intimate deepfake even where it is never shared — distinct from the Crime and Policing Act 2026 offences, which target tool suppliers. China: the CAC/NDRC/MIIT AI Agents Implementation Opinions of 8 May 2026.

legislation.gov.uk ↗

Added

Illinois SB 343 added: algorithmic rental price-coordination ban (awaiting signature)

Illinois SB 343 amends the Illinois Antitrust Act to ban algorithmic coordination of rental prices. It passed the 104th General Assembly and is on Governor Pritzker's desk with a 29 August 2026 action deadline, so it is tracked as proposed with no effective date. Four of the five companion AI bills have been signed; SB 343 had not been as of 28 July 2026.

ilga.gov ↗

correction

Algorithmic price-coordination bans reclassified; UK deepfake offence scope widened to everyone

Three rows carried topic tags that no theme page defines and were therefore untagged and unreachable from any topic: the NJ FAIR Act, Maryland's Protection From Predatory Pricing Act and Illinois SB 343. All three ban a use of an algorithm outright, so they now sit under Prohibited AI practices, and that page covers the price-coordination family. Separately, UK DUAA 2025 s.138 was scoped to deployers, though the offence binds any person in the UK who creates or requests a non-consensual intimate deepfake; it is now scoped to everyone. No dates, sources or facts changed.

legislation.gov.uk ↗

correction

RAISE Act bill citation corrected to S6953-B/A6453-B

The row previously cited the RAISE Act as S1169-A. The bill actually signed into law by Governor Hochul on 19 December 2025 is S6953-B/A6453-B. The tracked effective date (1 January 2027) is unaffected.

governor.ny.gov ↗

correction

Australia ADM transparency citation corrected to APP 1.7-1.9

The row previously cited the automated decision-making transparency duty as APP 1.3. The Privacy and Other Legislation Amendment Act 2024 (Cth), Schedule 1, cl.88 actually inserts the new duty as APP 1.7-1.9, per the Federal Register of Legislation text and the ATO Legal Database. The 10 December 2026 commencement date is unaffected.

legislation.gov.au ↗

Updated

South Korea high-impact AI grace period confirmed via official government briefing

An official Korea Policy Briefing (korea.kr) release directly quotes MSIT confirming an at-least-one-year fines grace period running from the AI Basic Act's 22 January 2026 effective date. Confidence raised from medium to high; no other fields changed.

korea.kr ↗

Updated

Georgia SB 540 effective date confirmed via official Senate press release

An official Georgia Senate press release confirms SB 540's 1 July 2027 effective date. Confidence raised from medium to high; no other fields changed.

senatepress.net ↗

Updated

Rhode Island H 7538 effective-date uncertainty resolved

The row previously carried a placeholder status note pending confirmation of the effective date. Law-firm trackers citing the enacted text (R.I. Gen. Laws ch. 23-106) confirm it was signed 22 June 2026 and is effective upon passage. Status note updated and confidence raised from medium to high.

webserver.rilegislature.gov ↗

correction

Tennessee SB 1700 corrected: enacted as a study mandate, not a chatbot-safety law

Primary-source review found that Senate amendments adopted 14 April 2026 stripped SB 1700's original companion-chatbot safety restrictions before passage. As signed (Public Chapter 1082), the law only directs TACIR to study potential AI/chatbot regulation, with no report deadline and no compliance obligation on AI operators. The row is corrected to reflect this; it no longer carries a 2027-01-01 compliance date.

wapp.capitol.tn.gov ↗

correction

Rhode Island S 2195 effective date corrected to 1 January 2027

The row previously used the 22 June 2026 signing date as a placeholder pending confirmation. Primary and corroborating legislative-tracking sources confirm the Act's general effective date is 1 January 2027, with the separate annual AG reporting duty beginning 1 July 2027. Date and lifecycle updated accordingly.

webserver.rilegislature.gov ↗

correction

Washington HB 1170 penalty and enforcement mechanism confirmed

The row previously flagged the penalty amount and enforcement mechanism as unverified. Washington legislative bill reports confirm the law (Chapter 167, Laws of 2026) is enforced exclusively by the state Attorney General under the Consumer Protection Act (ch. 19.86 RCW), with civil penalties up to $100,000 per covered provider.

lawfilesext.leg.wa.gov ↗

Updated

EU Digital Omnibus published in the Official Journal as Regulation (EU) 2026/1744

The Digital Omnibus amending the AI Act was published in the Official Journal as Regulation (EU) 2026/1744, ending the period in which the original Article 113 dates stood pending publication. Three tracked entries move off 'proposed' to fixed future application dates: the Annex III high-risk obligations are deferred to 2 December 2027, the Annex I product-embedded high-risk obligations to 2 August 2028, and the new Article 5 prohibition covering AI-generated CSAM and intimate imagery applies from 2 December 2026.

eur-lex.europa.eu ↗

Added

Six US state synthetic-media and digital-likeness laws added

Coverage expands across the deepfake and digital-replica cluster: Washington's Forged Digital Likeness Protection Act (SB 5886) and AI Content Disclosure Act (HB 1170), Hawaii's Deepfake Protection and Synthetic Performer Disclosure law (HB 2137 / Act 247), New York's Synthetic Performer Disclosure Law (S.8420-A) and Deceased Performer Digital Replica Consent Law (S.8391), and Maryland's Deepfake Identity Fraud law (SB 8 / Ch. 445). Each row links to its enacted text.

data.capitol.hawaii.gov ↗

Added

Fifteen US companion-AI, chatbot and mental-health AI laws added

The 2026 US state session produced a dense cluster of conversational-AI statutes, now tracked in full. The common core is disclosure that the system is not human, a protocol when a conversation turns to self-harm, and additional safeguards for minors — in Hawaii (Act 248), Iowa (SF 2417), Washington (HB 2225), Oregon (SB 1546), Georgia (SB 540), Colorado (HB 26-1263), Idaho (SB 1297), Rhode Island (S 2195), Nebraska (LB 525), Connecticut (SB 5) and Tennessee (SB 1700). A second line addresses AI in mental-health care: Tennessee SB 1580, Rhode Island H 7349, Colorado HB 26-1195. Three new theme pages cover this material.

olis.oregonlegislature.gov ↗

Added

Ten US laws on AI in prior authorization, utilization review and health claims added

A near-uniform rule runs through this group: an algorithm may inform a coverage decision but may not be its sole basis, with licensed human review before an adverse determination. Washington SB 5395, Iowa HF 2635, Alabama SB 63, Georgia SB 444 and Colorado HB 26-1139 carry the human-review requirement; Maryland HB 820 adds quarterly regulator audits; Utah SB 319 and Indiana HB 1271 add disclosure of AI use; Illinois SB 3114 extends the logic to claim downcoding; and Rhode Island H 7538 covers AI transcription in the clinic. A new Healthcare theme page groups them.

app.leg.wa.gov ↗

Added

Five further US state AI laws added across housing, education and pricing

Illinois' Artificial Intelligence Safety Measures Act (SB 315), New Jersey's FAIR Act banning algorithmic rent-setting (A3497/S451), California's AB 2148 requiring K-12 school employees and contractors to be natural persons, Illinois' SB 2909 restricting AI in teacher evaluation, and Maryland's HB 895 on surveillance and predatory pricing. Algorithmic pricing is now tracked across two jurisdictions but does not yet have its own theme page.

pub.njleg.gov ↗

Added

Vietnam, Australia and two EU instruments added

Vietnam's Decision 33 publishes a list of 46 high-risk AI systems, applicable 15 August 2026. Australia's automated decision-making transparency requirement under the Privacy Act reforms is tracked as a separate row. On the EU side, the Annex I product-embedded high-risk obligations are now a distinct entry from Annex III, and Implementing Regulation (EU) 2026/1755 sets out the GPAI enforcement and investigation procedures, applicable from 10 August 2026.

eur-lex.europa.eu ↗

Updated

China Anthropomorphic AI Measures now in force (15 Jul 2026)

The Interim Measures for the Administration of Anthropomorphic Artificial Intelligence Interaction Services entered into force on 15 July 2026, confirmed from the Digital Policy Alert primary-source record. Lifecycle updated from 'dateset' to 'force'; status note updated to reflect in-force date.

digitalpolicyalert.org ↗

Updated

DIFC Regulation 10/11 public consultation closed 18 Jul 2026

The 30-day public consultation on proposed amendments to DIFC Data Protection Regulation 10 (strengthening AI/autonomous-system certification and the Autonomous Systems Officer role) and the new Regulation 11 (Commissioner accreditation powers), launched 18 June 2026 under Consultation Paper No. 3 of 2026, closed on 18 July 2026. The final amended regulations are pending adoption. Status note updated to reflect the closed consultation.

difc.com ↗

Updated

Brazil PL 2338: still in Special Commission awaiting rapporteur's opinion; plenary vote not before late 2026

As of July 2026, PL 2338/2023 remains in the Chamber of Deputies' Special Commission on Artificial Intelligence (rapporteur: Deputy Aguinaldo Ribeiro, PP-PB) awaiting the rapporteur's formal opinion; the bill has not been voted on. The Camara's official tracking page shows status 'Aguardando Parecer do Relator(a)' with no scheduled plenary date. Status note updated to reflect the current committee stage and expected timeline.

camara.leg.br ↗

correction

NY RAISE Act: incident reporting corrected to NYDFS (not AG/DHSES) after chapter amendment

The chapter amendment to the RAISE Act (signed 27 March 2026) restructured incident reporting: Critical Safety Incident reports now go to a new office within NYDFS (not the AG or DHSES), and NYDFS has discretion to share them with the AG and other governmental entities. The summary previously stated 'NY AG/DHSES'; corrected to reflect that NYDFS is the primary recipient of 72h reports, with the AG retaining civil-penalty enforcement authority.

dwt.com ↗

Updated

EU Digital Omnibus: Council formally adopted 29 Jun 2026; OJ publication pending

The Council of the EU formally adopted the Digital Omnibus AI simplification package on 29 June 2026 (Parliament adopted 16 June 2026). The regulation will be published in the Official Journal in July 2026 and enters into force 3 days after publication. Upon entry into force: the deferral of Annex III (standalone) high-risk AI obligations to 2 December 2027 takes legal effect; the new Art. 5 prohibition on AI-generated CSAM and non-consensual intimate imagery applies from 2 December 2026; and the Art. 50(2) marking deferral for pre-August 2026 systems to 2 December 2026 is confirmed. Status notes updated to reflect completed inter-institutional adoption; confidence raised from low to medium as OJ publication is the sole remaining step.

consilium.europa.eu ↗

correction

Vietnam AI Law: confidence upgraded to high; grace periods clarified from primary law text

Primary law text (Art. 35, Law 134/2025/QH15) confirms a 12-month grace period for all sectors (compliance to 1 March 2027) and an 18-month grace period specifically for health, education and finance sectors (compliance to 1 September 2027). Implementing Decree 142/2026/ND-CP, effective 1 May 2026, provides procedural details. With the Law and its implementing decree both in force and confirmed from the official English law translation, confidence for both obligations is upgraded from medium to high. The vn-ai-law-risk status note is updated to specify the September 2027 endpoint for health/education/finance sectors.

english.luatvietnam.vn ↗

Added

China: Anthropomorphic AI Interactive Services Measures — new obligation, effective 15 Jul 2026

The CAC and four co-regulators (NDRC, MIIT, MPS, SAMR) jointly issued the Interim Measures for the Management of Anthropomorphic Interactive Services of Artificial Intelligence on 10 April 2026, effective 15 July 2026. The Measures require providers to disclose AI identity to users, prohibit virtual intimate relationships for minors under 14, mandate addiction-monitoring and emotion-management systems, and impose usage-time warnings after two consecutive hours. This is China's first dedicated regulation targeting AI companion and emotionally interactive services.

cac.gov.cn ↗

Updated

India IT Rules updated: Feb 2026 amendment introduces 3-hour takedown and SGI definition

MeitY notified the IT (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 (G.S.R. 120(E)) on 10 February 2026; the rules came into force on 20 February 2026. The amendment introduces a statutory 'synthetically generated information' (SGI) definition, mandates provenance-metadata labels on AI-generated content, and tightens the government-ordered takedown window from 36 hours to 3 hours (2 hours for CSAM and non-consensual intimate imagery). The obligation date has been updated from 2025-11-15 to 2026-02-20 to reflect the current operative version, and the source URL updated to the 2026 MeitY notification.

meity.gov.in ↗

Updated

DIFC opens public consultation on amended Data Protection Regulations (closes 18 Jul 2026)

On 18 Jun 2026 the DIFC Commissioner announced a 30-day consultation on proposed amendments to the Data Protection Regulations. The proposed changes strengthen Regulation 10 (certification obligations for autonomous/AI systems and the Autonomous Systems Officer role) and introduce a new Regulation 11 empowering the Commissioner to recognise external accreditation schemes. Regulation 10 itself remains in force; general certification guidance is still pending. Status note updated to reflect the open consultation.

gulfnews.com ↗

correction

EU GPAI obligations — confidence upgraded to high after CoP finalisation

The AI Office published the final General-Purpose AI Code of Practice on 10 July 2025; the European Commission and AI Board confirmed it as an adequate compliance tool under Art. 53. With the final CoP in place and GPAI enforcement via Art. 101 beginning 2 August 2026, the residual uncertainty that drove the 'medium' rating is resolved. Confidence updated to high.

digital-strategy.ec.europa.eu ↗

correction

RAISE Act chapter amendment confirmed; confidence upgraded to high

The chapter amendment to the RAISE Act (S1169-A) was signed 27 March 2026, finalising the law's text after the original signing on 19 December 2025. With both the original signing and the chapter amendment confirmed, the 1 January 2027 effective date is legally settled and federal preemption has not materialised. Confidence updated from medium to high.

governor.ny.gov ↗

correction

Corrected South Korea AI Basic Act grace period: runs to ~22 Jan 2027

MSIT indicated a one-year enforcement grace period beginning on the Act's effective date of 22 January 2026. Both obligation rows previously stated the grace period ran 'through ~2026', which understates the window; the correct expiry is approximately 22 January 2027. Status notes updated accordingly.

cooley.com ↗

Updated

Global data pass — every map jurisdiction verified to primary sources

Verified the AI-regulation status of all 30+ shaded jurisdictions and upgraded every non-EU/US obligation to primary-source standard, with checked dates and confidence flags.

artificialintelligenceact.eu ↗

Want these in your inbox? Get an email when an obligation in your profile changes — or follow the feed.