Software Development Compliance ChecklistMay 2026 Edition
Designed for creators and deployers of AI software, this checklist guides you through current compliance steps under the EU AI Act, US state AI laws, federal AI policy (Executive Order 14365), GDPR, CCPA/CPRA, HIPAA, COPPA, and more.
π Last Updated: May 19, 2026. Reflects the EU Digital Omnibus political agreement (May 7, 2026), the Colorado AI Act enforcement stay (April 27, 2026) and pending replacement SB 26-189, Texas TRAIGA in force, Executive Order 14365 and the National Policy Framework for AI (March 20, 2026), and the pending HIPAA Security Rule final rule.
This checklist is a planning aid, not legal advice. Regulatory positions shift quickly. Confirm specific obligations with qualified counsel.
π Last Updated: May 19, 2026. Reflects the EU Digital Omnibus political agreement (May 7, 2026), the Colorado AI Act enforcement stay (April 27, 2026) and pending replacement SB 26-189, Texas TRAIGA in force, Executive Order 14365 and the National Policy Framework for AI (March 20, 2026), and the pending HIPAA Security Rule final rule.
This checklist is a planning aid, not legal advice. Regulatory positions shift quickly. Confirm specific obligations with qualified counsel.
Completion Score
0%
Check items as you complete them. Your progress saves automatically in this browser.
Changelog
May 19, 2026
- EU AI Act: added Digital Omnibus political agreement (May 7, 2026), revised high-risk timeline, new non-consensual content prohibition, post-market monitoring items.
- US AI laws: added Executive Order 14365 and federal policy section; Colorado AI Act marked as enforcement-stayed with SB 26-189 replacement; added Texas TRAIGA and California SB 53 sections.
- Privacy: HIPAA Security Rule reframed as pending; added Reproductive Health Rule vacatur and Part 2 alignment; EU Digital Omnibus package; Texas Genomic Act.
- Built out audit, documentation, and maintenance sections; added ISO/IEC 42001 throughout.
- Accessibility: WCAG 2.2 AA pass (focus indicators, skip link, dialog semantics, reduced motion, target sizes, status not by color alone).
- Features: completion score, visible save indicator, JSON export/import, print-to-PDF, this changelog.
December 2025 (prior baseline)
- Initial EU AI Act, US state AI, COPPA 2025, HIPAA NPRM, CCPA/CPRA ADMT, and OWASP Top 10:2025 coverage.
Regulatory content is current as of the dates shown per section. Verify status before relying on it; positions are shifting quickly in 2026.
Official Legal Resources (Updated May 2026)
πͺπΊ EU AI Act and Digital Omnibus
- EU AI Act - Official Text (EUR-Lex)
- European Commission AI Policy Overview
- AI Act Implementation Timeline
- GPAI Code of Practice (July 2025)
- Council press release on Digital Omnibus agreement (May 7, 2026)
πΊπΈ US Federal AI Policy
πΊπΈ US State AI Laws
- Colorado AI Act SB 24-205
- Colorado SB 25B-004 (effective date extension)
- Texas TRAIGA HB 149
- California CPPA ADMT Regulations
- Illinois HB 3773 AI in Employment