Amendments, Delays and Tracking the Effective Date

Amendments, delays, and tracking the effective date are central to managing compliance with the Colorado AI Act. The regulatory landscape is evolving, and understanding how these elements affect your organisation’s AI governance framework is essential. This lesson focuses on how to handle regulatory changes, accommodate delays, and maintain accurate records of compliance timelines.

Lesson concept diagram

Understanding Regulatory Amendments

Regulations such as the EU AI Act and the Digital Omnibus on AI introduce new obligations that may require updates to existing AI systems or processes. For example, the EU AI Act’s Article 5 prohibited practices have been in force since 2 February 2025. Organisations must ensure that any AI systems deployed or updated after this date comply with these restrictions. Similarly, the machine-readable marking requirement for generative AI systems placed on the market before 2 August 2026 must be implemented by 2 December 2026. These deadlines must be monitored closely, especially when systems are already in production.

  • Ensure that AI systems reviewed for compliance are checked against the latest versions of applicable regulations.
  • Update internal documentation and risk assessments to reflect any new or amended obligations.
  • Train staff on new or revised compliance requirements, particularly those affecting AI developers or deployers.

Managing Delays and Extensions

Some obligations have been delayed or extended, such as the high-risk AI obligations under Annex III of the Digital Omnibus, which now apply from 2 December 2027. Similarly, embedded-product AI obligations begin on 2 August 2028. These extensions provide organisations with additional time to implement necessary controls, but they must not be treated as opportunities to delay compliance indefinitely. Instead, these dates must be integrated into planning cycles and risk management frameworks.

Organisations must maintain records of these delays and ensure that they are not misinterpreted as exemptions. For example, a delay in implementing high-risk AI controls does not mean that these controls are not required. The delay simply shifts the timeline. Regular audits and compliance reviews must be scheduled to ensure readiness by the new deadlines.

  • Document any regulatory delays or extensions clearly in your compliance records.
  • Update your AI governance plan to reflect revised deadlines and adjust timelines accordingly.
  • Ensure that senior leadership is informed of any delays and their implications for risk exposure.
Amendments, Delays and Tracking the Effective Date

Tracking Effective Dates

Effective dates play a central role in AI governance. The EU AI Act’s transparency duties, for example, apply from 2 August 2026. This date marks the start of obligations for AI systems that must provide information to users or regulators. The machine-readable marking requirement for generative AI systems placed on the market before this date must be met by 2 December 2026. These dates must be tracked through a centralised compliance calendar or system.

Organisations must also monitor the implementation of ISO/IEC 42001:2023, which is the AI management system standard. The first UKAS-accredited certification body, BSI, became operational on 15 January 2026. This means that organisations planning to seek certification must ensure that their AI governance frameworks meet the standard’s requirements by the relevant deadlines. The certification process is governed by ISO/IEC 42006:2025, which outlines the roles and responsibilities of certification bodies.

Effective date tracking must include not only regulatory deadlines but also internal milestones such as training completion, documentation updates, and system modifications. A centralised tracking tool or spreadsheet can help ensure that no deadlines are missed. Regular reviews of these dates should be part of your governance cycle, especially when new AI systems are being developed or deployed.

  • Use a centralised tool or system to track all regulatory deadlines and internal compliance milestones.
  • Assign ownership of compliance tasks to specific individuals or teams to ensure accountability.
  • Review and update tracking systems at least quarterly or whenever new obligations are introduced.

By understanding how to handle amendments, delays, and effective dates, compliance and governance staff can ensure that their organisations meet regulatory expectations. These practices are not merely procedural but are foundational to maintaining AI systems that are both lawful and responsible.