AI regulation, September 2026: the briefing
What changed in August, what the register corrected, what comes next, and what we refused to believe. Published September 4, 2026.
August was the month the AI Act grew an enforcer and the month the world's regulators mostly caught their breath after August 2. The bigger news for anyone using this register is the correction column: three instruments were missing or misdescribed, and all three now sit on their pages with citations. The next date that bites is October 1, 2026, in Connecticut.
What changed in August
On August 2 the EU's Article 50 transparency duties went into application and the Commission's AI Office formally began enforcing the act alongside national authorities, with its power to fine general-purpose model providers becoming applicable the same day. California's AI Transparency Act reached its operative date on purpose that morning too, making August 2 the first synchronized compliance date across the Atlantic. The rest of the month was digestion: guidance, explainers, and the first compliance-program rewrites. No fines exist yet under the AI Act, whatever syndicated content claims.
Three corrections to the register
The largest is Connecticut. The register had recorded the state's comprehensive framework as stalled after the 2025 veto threat. It was wrong by June: SB 5, the Artificial Intelligence Responsibility and Transparency Act, Public Act 26-15, was signed May 27, 2026 and is the broadest state AI law enacted this year, covering automated employment decision tools, AI companions, frontier-developer whistleblowers, content provenance, AI-related layoff disclosures, and online safety for minors. Most of it takes effect October 1, 2026. The entry, the state tracker, the calendar, and the law index are updated.
Second, the Digital Omnibus on AI is no longer a political agreement. It was published in the Official Journal on July 24 as Regulation (EU) 2026/1744 and has been in force since July 27, which means the high-risk deferrals to December 2027 and August 2028 are binding text, not a deal that could still move. The EU entry and the glossary now cite the regulation.
Third, the United States has a second AI executive order. Signed June 2, "Promoting Advanced Artificial Intelligence Innovation and Security" asks agencies to design a voluntary framework under which developers of covered frontier models give the government up to 30 days of pre-release access for national-security vetting, and creates an AI cybersecurity clearinghouse. It is the first federal frontier-model mechanism of any kind, and it lives on the federal entry.
What comes next
October 1, 2026: Connecticut's first wave, including the amendment that makes an algorithm no defense to a discrimination claim. December 2, 2026: the EU's marking grace period for pre-August generative systems ends and the ban on non-consensual intimate imagery generators takes effect. January 1, 2027: Colorado's replacement statute, New York's frontier law, Illinois' Safety Measures Act, Connecticut's AI companion rules, and Peru's first sector wave all land on one day. The calendar carries every date through 2028.
Watchlist, unverified
Four threads are being tracked but not yet filed, because a single source is not a citation: South Korea moving to ban unauthorized digital clones of faces and voices through competition law; the Philippines classifying photorealistic synthetic media as biometric data; California's end-of-session AI bills, which sit on the governor's desk until September 30; and the state chatbot-law wave, with roughly a hundred bills introduced across more than thirty legislatures this year. Each gets an entry when a primary text or two independent legal analyses confirm it.
What we refused to believe
Two widely syndicated claims this month were fabricated: that a UK AI bill cleared the House of Commons with Royal Assent expected in October, and that the AI Office had already issued tens of millions of euros in fines. Parliament's own tracker and the Commons Library disprove the first; the second appears nowhere credible. Both came from content mills producing "regulation roundups" at volume. That is the environment this register exists in, and it is why every entry links to primary text.