AI Governance for Consumer Goods: The Regulatory Record
The laws, rules, and court rulings that shape how consumer goods companies govern AI, in one place. This is the reference behind The Governed Enterprise, an AI governance playbook written specifically for consumer goods, from food and beverage to cosmetics, pet food, and household products, and the compliance issues each one faces. Statutes and litigation appear together because they move together. The oldest entries predate AI by decades, which is the point: most of what binds a CPG company today was written for something else and applied to AI afterward.
Entries summarize laws, rules, and rulings as of the review date above. Each entry links to its source, and the source governs. Terms of art link to the glossary. Nothing on this page is legal advice. See the disclaimer.
What binds next
EU high-risk obligations for AI embedded in regulated products
The Digital Omnibus deferred this deadline from August 2, 2027 by twelve months. The obligations cover AI embedded in products already subject to the EU product safety legislation listed in Annex I Section A, such as medical devices and toys. The same amendment moved the Machinery Regulation from Section A to Section B, which takes AI embedded in machinery outside the direct scope of the high-risk regime.
EffectiveAug 2, 2028 · 698 days out
What it means for CPGRead the machinery carve-out carefully before treating it as relief. AI in line equipment escapes the AI Act's conformity assessment, and the Commission gained the power to impose AI-specific health and safety requirements through delegated acts under the Machinery Regulation instead. The obligation may return through a different door and with a different regulator behind it. Meanwhile the underlying work does not change: start with an inventory of what is actually embedded in the line equipment, because most sites do not know.
EU high-risk obligations for standalone Annex III systems
The Digital Omnibus deferred this deadline from August 2, 2026 by sixteen months. The obligations cover standalone high-risk systems listed in Annex III, including employment, education, critical infrastructure, and credit scoring. They require conformity assessment, risk management, data governance, technical documentation, logging, human oversight, and registration.
EffectiveDec 2, 2027 · 454 days out
What it means for CPGIn Europe this reaches the hiring and workforce management stack. Running conformity assessment across several systems and multiple facilities takes quarters, not weeks. And the extra time came from a standards delay. The bar itself never moved.
Colorado automated decision-making technology duties
Substantive obligations under SB 26-189 commence January 1, 2027. The Attorney General must adopt clarifying rules by that date, and the Colorado Department of Law filed proposed rules on August 11, 2026. Deployers owe pre-use notice, an adverse-action process with rights to correct data and to meaningful human review where commercially reasonable, and three-year record retention. The Attorney General holds exclusive enforcement authority and there is no private right of action.
EffectiveJan 1, 2027 · 119 days out
What it means for CPGA rejected Colorado candidate must be able to see that ADMT was involved, correct inaccurate data, and request human review. Building that takes a workflow, a response-time commitment, and a retained record. The retention period is three years, so the applicant tracking system has to hold the record that long.
Colorado Chatbot Safety Act reaches consumer-facing conversational AI
HB 26-1263 makes Colorado the first state with a standalone statute governing conversational AI services offered to the public. The act defines such a service as an AI system accessible to the general public that primarily simulates human conversation through adaptive textual, visual, or aural communication. An operator is a person or entity that develops and makes such a service publicly available, or that offers one to a consumer. Every operator must disclose to a user that the service is artificial intelligence, estimate the age of account holders and users, implement a protocol for prompts involving suicidal ideation or self-harm, and report annually to the Attorney General on that protocol. An operator may not state that output is provided by, endorsed by, or equivalent to the services of certain licensed or certified professionals. Where an operator knows a user is a minor, further duties attach covering disclosures, engagement rewards, sexually explicit content, simulated emotional dependence, and parental account controls. Commencement is tiered. The act itself took effect on August 12, 2026, the default date for Colorado legislation enacted without a safety clause after the General Assembly adjourned on May 13. The substantive operator obligations bind on January 1, 2027, and annual reporting to the Attorney General begins July 1, 2027.
EffectiveJan 1, 2027 · 119 days out
What it means for CPGThe operator definition has two prongs and the second is the one to read closely. A company that offers a conversational AI service to a consumer is an operator whether or not it built the service, so a brand running a product usage assistant, a service bot, or a recipe helper on its own site should assume it is inside the definition rather than outside it. Any narrowing will come from the Attorney General's rulemaking. Two duties bind regardless of who wrote the model. The service has to say it is AI, and a real self-harm protocol has to sit behind it, documented well enough to describe in an annual filing. The licensed-professional prohibition is the third thing to check, against any bot that answers a question about nutrition, dosage, or a skin condition.
Illinois requires independent audits of frontier AI developers
SB 315, the Artificial Intelligence Safety Measures Act, makes Illinois the third state after California and New York to impose safety and transparency duties on developers of frontier models, and the first to require an annual independent third-party audit. It reaches large frontier developers, defined by annual gross revenue above 500 million dollars and training compute above a stated threshold. From January 1, 2027 a covered developer may not develop, deploy, or operate a frontier model in Illinois without a current disclosure statement on file. The published frontier AI framework, the transparency reports, and the audit obligation begin January 1, 2028. The Attorney General enforces and there is no private right of action.
EffectiveJan 1, 2027 · 119 days out
What it means for CPGNo consumer goods company is a large frontier developer, so this is a diligence question rather than a duty. Its value is that three states now use the same template, and Illinois adds the one element the others lack, which is verification by someone outside the developer. From January 2028 a model vendor's safety posture becomes an audited fact a buyer can ask for, rather than a claim on a security questionnaire.
California ADMT opt-out and access rights complete their phase-in
The CPPA's automated decision-making technology regulations complete their phase-in, with full opt-out provisions due. The rules apply to CCPA-covered businesses using ADMT for significant decisions, including decisions affecting employment, contracting opportunities, or compensation.
EffectiveJan 1, 2027 · 119 days out
What it means for CPGOpt-out is the provision that touches system design. A screening or compensation process that cannot function without ADMT needs an alternative path, and building that alternative takes longer than writing the notice.
EU Product Liability Directive applies to software and AI systems
Directive (EU) 2024/2853 replaces the 1985 product liability regime. Member States must transpose it by December 9, 2026, and it governs products placed on the market or put into service after that date. The definition of a product now covers software, AI systems, digital manufacturing files, and raw materials. Strict no-fault liability applies, recoverable damage extends to destruction or corruption of data and to medically recognized psychological harm, and courts may order disclosure of evidence and presume defectiveness where a claimant faces excessive technical difficulty.
EffectiveDec 9, 2026 · 96 days out
What it means for CPGThis is the entry that turns AI governance into a balance sheet question. A defective AI component inside a consumer product carries strict liability, with no need for the claimant to prove negligence, and the liability cannot be disclaimed in terms of sale. Two consequences follow for a brand owner. Vendor contracts written before this date allocate a risk that the Directive reallocates by statute, so indemnities need rereading. And a system updated or substantially modified after December 9, 2026 can pull an older product into the new regime, which makes your definition of substantial modification a liability decision rather than a technical one.
EU prohibition on AI-generated intimate imagery and new legacy transparency duties
The Digital Omnibus adds an Article 5 prohibition covering AI systems used to generate non-consensual intimate imagery and child sexual abuse material, carrying the maximum penalty tier. On the same date the grace period for legacy systems expires, and Article 50(2) machine-readable marking reaches systems already on the market before August 2, 2026. The extension runs four months, shorter than the six the Commission originally proposed.
EffectiveDec 2, 2026 · 89 days out
What it means for CPGAny generative image or audio capability in the marketing stack needs technical and contractual safeguards against this use before December. Separately, every AI content tool already in production has to be retrofitted with machine-readable marking. The retrofit is the one that will slip, because it means going back to vendors who shipped before anyone asked for it.
Connecticut Artificial Intelligence Responsibility and Transparency Act
Substitute SB 5, An Act Concerning Online Safety, enacted as Public Act 26-15 and known to the General Assembly's AI Caucus as the CART Act, reaches automated employment decisions, AI companions, frontier developers, synthetic content provenance, and platforms used by minors. Its employment framework phases in from October 1, 2026 through October 1, 2027. The first phase amends the Fair Employment Practices Act so that use of automated employment decision technology is not a defense to a discrimination claim, though anti-bias testing may be considered in mitigation, and adds a WARN Act AI disclosure requirement. Interactive disclosure and pre-decision notice follow in 2027.
EffectiveOct 1, 2026 · 27 days out
What it means for CPGConnecticut is the first state to say plainly that documented anti-bias testing can reduce exposure. That changes the economics of testing. It stops being a compliance cost and starts being something you can put in front of a court. The WARN provision is separate and easy to miss: AI's role in a workforce reduction becomes reportable.
Colorado files proposed rules for automated decisions and chatbots
The Colorado Department of Law filed proposed rules with the Secretary of State implementing both SB 26-189, the Automated Decision-Making Technology Act, and HB 26-1263, the Chatbot Safety Act. Codified at 4 CCR 904-6, the rules would take effect January 1, 2027 alongside both statutes. SB 26-189 requires the Attorney General to adopt rules before that date. HB 26-1263 does not, and the Department opened a rulemaking anyway to settle the content of the annual report and the reach of the operator definition. Written comments run from August 11 to October 26, 2026, with the public rulemaking hearing on the closing date.
What it means for CPGTwo definitions get fixed here that decide how much work January brings. Read the ADMT rules for what counts as a consequential decision and for what meaningful human review has to look like in practice, because those set the size of the build. Read the chatbot rules for the operator boundary, which decides whether a brand running a vendor's widget owes anything at all. The working deadline is September 4 rather than October 26, since only comments received by then will be considered for the revised draft presented at the hearing, and interim updates are due to be posted by September 23. Every timely comment enters the official rulemaking record and is published, so filing one is a choice to make deliberately rather than by default.
EU AI Act transparency obligations apply
Article 50 transparency duties took effect on schedule. Systems that interact with people must disclose that they are AI, and synthetic image, audio, video, and text output must be marked in a machine-readable format. The Digital Omnibus did not move this date. It deferred only the machine-readable marking duty under Article 50(2), and only for systems already on the market on August 2, 2026, to December 2, 2026.
What it means for CPGAny consumer-facing chatbot on an EU storefront, and any AI-generated product imagery or ad copy running in the EU, needs disclosure and machine-readable marking now. Agencies and content vendors need this written into their statements of work. The Commission's final Article 50 guidelines and the Code of Practice on transparency, both recorded here, set out what an adequate implementation looks like. The deployer half of the duty stays with the brand owner whoever supplies the tool.
California AI Transparency Act becomes operative
SB 942, signed in September 2024 and amended by AB 853 in October 2025, became operative on the same day as the EU's Article 50 duties. The alignment was deliberate. Covered providers, meaning publicly accessible generative AI systems with more than one million monthly users in California, must offer a free AI detection tool, provide a manifest disclosure option, and apply latent provenance disclosures to AI-generated or AI-altered image, audio, and video. Stripping provenance data is prohibited. Large online platform and hosting platform duties follow on January 1, 2027, and capture device duties reach devices first produced for sale in California from January 1, 2028.
What it means for CPGThe million-user threshold means almost no CPG company is a covered provider. The value runs the other way, through diligence. Your generative image and video vendors either publish a detection tool and embed compliant provenance metadata or they do not, and that is now a checkable fact rather than a vendor claim. Prefer the ones that comply, because their output is the output whose origin you can prove when a retailer, a regulator, or a plaintiff asks. Watch the January 2027 platform obligations separately: they touch where your AI-assisted creative is distributed, not only where it is made.
Regulation (EU) 2026/1744, the Digital Omnibus on AI, enters into force
The Regulation was signed on July 8, published in the Official Journal on July 24, and entered into force on the third day following publication. It amends the AI Act, the civil aviation regulation, and the Machinery Regulation. Beyond the deferred high-risk dates, it expands the AI Office's supervisory reach over general-purpose AI models and systems built on them, extends the legal basis for processing special categories of personal data for bias detection to providers and deployers of all AI systems under a strict necessity standard, moves the Machinery Regulation from Annex I Section A to Section B, postpones national regulatory sandboxes to August 2, 2027, and keeps the database registration duty for systems self-assessed as non-high-risk.
What it means for CPGThe deferral stopped being a proposal and became law five days before the deadline it moved. Two provisions deserve attention beyond the dates. The bias-detection change gives a deployer a lawful basis to process protected-characteristic data for testing, which is the permission that has blocked disparate impact analysis in European operations for years. And the grace period turns on whether at least one unit of a given type and model was lawfully placed on the market before the application date, so the question of which of your systems qualifies has a documentary answer someone should write down now.
Commission's draft guidelines on high-risk classification remain unadopted
The Commission published draft guidelines helping providers and deployers assess whether a system is high-risk, developed from a public consultation and from Member State input through the AI Board, and presented on the AI Act Single Information platform. A targeted stakeholder consultation closed on July 23, 2026, and the feedback is to be incorporated before the Commission adopts a final version. The guidelines are not legally binding, and they carry the Commission's interpretation and will guide enforcement. Article 6(5) required this guidance by February 2, 2026, so it is running late alongside the harmonized standards that CEN and CENELEC have yet to deliver.
What it means for CPGClassification is the question that decides whether the December 2027 obligations reach a given system at all, and the official answer does not exist yet. Two categories sit close to the line in a consumer goods operation: quality and safety inspection on a production line, and anything touching hiring or workforce management. Classify them now on your own reasoning, write down why, and keep the record. When the final guidelines land, a documented position is a thing you revise. An undocumented one is a thing you start.
Commission publishes final guidelines on the Article 50 transparency duties
The final Guidelines on transparency obligations for providers and deployers of certain AI systems replaced the May 2026 consultation draft. They are the reference national market surveillance authorities use when assessing whether a provider or deployer has met Article 50. Content generated before August 2, 2026 needs no retroactive labeling, and disproportionate effort such as auditing existing content databases or modifying printed packaging is not expected. The business-to-business and industrial carve-out from the Article 50(2) marking duty survives, subject to three cumulative conditions.
What it means for CPGTwo clarifications land on a consumer goods marketing operation directly. Packaging already printed with AI-assisted artwork does not have to be reprinted, which closes off the most expensive reading of the rule. And the business-to-business carve-out is narrower than it sounds, so an asset that begins as trade material and ends on a product page should be produced as consumer-facing content from the start.
Workday's late bias reports push the Mobley class certification schedule
Judge Rita Lin granted the plaintiffs a two-month extension of the class certification deadlines, finding good cause because Workday produced three internal bias evaluation reports on the eve of certification, after the deposition of the data scientist who helped prepare them. The reports analyze a random sampling of applicant data. Workday had generally asserted privilege over bias audit data and instructed that data scientist not to answer certain questions on that basis, and the court noted that the reports raise an unlitigated question of whether their production waives that privilege. The court set the class certification motion for September 14, 2026, the decertification motion for November 10, and the certification hearing for March 9, 2027.
What it means for CPGPrivilege over bias testing held in May and started leaking in July. A vendor that has curated its testing under counsel can still be compelled to produce the reports themselves, and producing them opens the underlying data to a waiver argument. The lesson transfers directly to an employer running its own testing: the privilege structure protects the analysis until the day you want to rely on it, and relying on it is what puts it in front of the other side. Decide in advance which testing is meant to be shielded and which is meant to be evidence, because one document cannot be both.
Code of Practice on transparency of AI-generated content assessed as adequate
The Commission concluded that the Code of Practice on Transparency of AI-generated Content adequately covers the obligations in Articles 50(2), (4), and (5), and the AI Board adopted its adequacy assessment the following day. The Code was published on June 10, 2026 and is open for signature. It is voluntary, and it is the only EU-wide instrument assessed as adequate for demonstrating compliance with the marking, detection, and labeling duties. Adherence is not conclusive evidence of compliance, and anyone taking a different route has to satisfy each national market surveillance authority on its own terms.
What it means for CPGSignature is a supplier question before it is an internal one. A generative image or copy vendor that has signed gives a buyer one defined account of what its marking does and where it holds up. A vendor that has not signed is asking the buyer to defend a bespoke method to whichever authority looks first. For a brand selling into several member states, one assessed standard is worth more than an adequate approach that has to be argued twenty-seven times.
FTC proposes a Section 5 policy statement on suppression of accuracy in AI systems
The Commission issued the proposed statement on July 1 under Executive Order 14365, and the Federal Register published it on July 7 as Matter No. P264200. Comments closed July 31, 2026, and forty were received. Its position is that an AI system steered toward undisclosed objectives, rather than the objectives a consumer requests or reasonably expects, is deceptive under Section 5. The statement extends that reasoning to outputs altered to satisfy state law, framing such alterations as a potential conflict with federal law. It remains proposed, and a policy statement creates no new legal obligation on its own.
What it means for CPGWatch this one as a conflict rather than as a rule. A deployer told by a state statute to constrain a model's outputs, and told by the FTC that undisclosed constraint is deceptive, is being pulled in two directions with no safe harbor between them. The answer available today is disclosure. Say what the system was tuned to do and why, in language a consumer can read, and keep the record of who decided it.
Council of the EU gives final approval to the Digital Omnibus on AI
The Council signed off on the amendment package, following the Parliament vote on June 16. Standalone high-risk obligations under Annex III move to December 2, 2027. AI embedded in regulated products under Annex I moves to August 2, 2028. A new prohibition on AI-generated non-consensual intimate imagery enters Article 5.
What it means for CPGSixteen more months for anyone who scoped EU conformity assessment work to an August 2026 deadline. The obligations themselves are unchanged. Watch the grandfathering: systems placed on the market before the new dates stay exempt until they are substantially modified, and no one has defined substantial modification for you. Write down how your company defines it, and do it before someone needs the answer.
Mobley v. Workday: court lets core discrimination claims proceed
Judge Rita Lin of the Northern District of California largely denied Workday's motion to dismiss the Third Amended Complaint. She held that California's Fair Employment and Housing Act reaches applicants screened from outside the state, because Workday designs, develops, and operates its screening tools from its California headquarters. FEHA claims continue alongside ADEA and ADA claims.
What it means for CPGThe theory that survived is agency: a screening vendor acts on the employer's behalf. For a CPG company running high-volume plant and warehouse hiring through a third-party platform, selecting that platform stops being purely a procurement decision. In law the screening logic belongs to the employer who deployed it.
European Parliament adopts the Digital Omnibus on AI
Parliament endorsed the amendment package by 423 votes to 57, with 174 abstentions, after trilogue negotiations reached provisional agreement on May 7.
What it means for CPGThe vote margin signals that the deferral was not contested on substance. Treat the new dates as settled and reallocate the runway to conformity assessment and human-oversight design rather than pausing the program.
Mobley discovery ruling shields vendor bias-testing data
Magistrate Judge Laurel Beeler denied a motion to compel Workday's internal bias-testing data, holding it privileged because counsel curated it to give legal advice. She also denied a motion to compel customer applicant data, finding Workday lacked control of it under Rule 34. She did order production of Workday's own EEO-1 and OFCCP filings, holding them relevant to what Workday knew about demographic disparities from using the same AI tools it sells.
What it means for CPGStructuring bias testing under counsel can protect the work product. That cuts both ways. The vendor's testing may never be available to defend your decisions either, which leaves you running disparate impact analysis on your own applicant population instead of leaning on a validation study you cannot see. The third holding matters more than it looks: Workday's own EEO-1 and OFCCP filings became discoverable as evidence of what it knew. A CPG employer's equivalent filings sit in the same position.
Colorado repeals and replaces its AI Act before it ever took effect
Governor Jared Polis signed SB 26-189, replacing the 2024 Colorado AI Act with a narrower regime built around covered automated decision-making technology. Duties to conduct impact assessments, maintain a risk management program, and affirmatively prevent algorithmic discrimination are gone. What remains is pre-use notice, an adverse-action process with a right to correct data and to meaningful human review, and three-year record retention, all operative from January 1, 2027.
What it means for CPGThe first comprehensive state AI law was also the first one repealed. Take that as a reading on how settled the area is. For CPG employers the scope is now specific: screening, ranking, and evaluating Colorado candidates and employees is covered. Routine scheduling and clerical routing are expressly excluded.
EU institutions reach provisional agreement on the AI Omnibus
Parliament and Council reached political agreement on targeted AI Act amendments after an April 28 trilogue collapsed. Member State representatives confirmed the deal in the Council on May 13.
What it means for CPGThis entry is superseded by the formal adoption in June and the publication in July. It is kept here because the April breakdown and May recovery are the reason many compliance calendars carried two conflicting deadlines through the spring.
Colorado court suspends enforcement of SB 24-205
The District of Colorado granted a joint motion by xAI and the Colorado Attorney General suspending enforcement of the 2024 AI Act pending the close of the legislative session and a ruling on xAI's preliminary injunction motion.
What it means for CPGThree weeks later the legislature replaced the statute outright and the suspension became academic. Keep the sequence anyway. A company sued, the federal government joined, the state suspended enforcement, the legislature rewrote the law. Other states will have noticed how quickly that worked.
DOJ intervenes against a state AI law for the first time
The Justice Department moved to intervene in xAI's suit against the Colorado Attorney General, filing its own complaint alleging that SB 24-205 violates the Equal Protection Clause by compelling discrimination based on protected characteristics. The court granted the intervention.
What it means for CPGThis is the first practical use of the AI Litigation Task Force created under Executive Order 14365. A multi-state CPG employer should expect more state AI laws to face federal challenge, and should build compliance programs that survive either outcome rather than betting on preemption.
xAI sues to enjoin the Colorado AI Act
xAI filed in the District of Colorado against Attorney General Philip Weiser, challenging the constitutionality of SB 24-205 ahead of its June 30, 2026 effective date.
What it means for CPGThis was the first direct constitutional challenge to a comprehensive state AI statute. The theory, that a state law regulating algorithmic discrimination reaches beyond state borders and compels speech, will be recycled against California and Connecticut.
FDA issues its first warning letter over AI agents in manufacturing
The FDA cited Purolea Cosmetics Lab, a homeopathic drug manufacturer, for inappropriate use of AI agents in pharmaceutical manufacturing. The firm had used AI to create drug product specifications, procedures, and master production and control records, then used that output without review, which the agency treated as a violation of 21 CFR 211.22(c). The company has since ceased drug production.
What it means for CPGFDA is applying existing manufacturing oversight to agentic systems and is not waiting for AI-specific guidance to do it. The holding is narrow and portable: AI output used for a CGMP purpose has to be reviewed and cleared by a qualified person in the quality unit, and that review has to be documented. If you run AI agents in batch release, deviation handling, or quality documentation, the practical test is whether you can produce those review records on the day an investigator asks.
White House releases a National Policy Framework for AI
The administration published legislative recommendations to Congress for a unified federal approach to AI regulation, following the December executive order and an earlier failed attempt to attach a state-law moratorium to a budget bill.
What it means for CPGLegislative recommendations carry no force. Congress has not passed comprehensive AI legislation, and preemption of state AI law remains distant. Staff and budget against the patchwork as it stands.
Commerce evaluation of onerous state AI laws comes due, and does not appear
Executive Order 14365 required the Commerce Secretary to identify onerous state AI laws within 90 days and recommend referrals to the DOJ task force. The evaluation was not publicly released on the deadline.
What it means for CPGNo published target list means no state law can be treated as safely dormant. Scope compliance state by state, and assume every statute on this page stays live until something specific happens to it.
Supreme Court declines Thaler v. Perlmutter
The Court denied certiorari, leaving intact the ruling that upheld the Copyright Office's refusal to register a work generated without human authorship.
What it means for CPGPurely machine-generated marketing assets, package art, and campaign copy carry no copyright protection. A brand that wants to own its creative needs a documented record of human authorship. That record has to be created while the work is being made. It cannot be reconstructed afterward, and the agency producing the asset is usually the only party in a position to keep it.
India amends IT Rules for synthetically generated information
The Ministry of Electronics and Information Technology notified the Information Technology Amendment Rules, 2026 on February 10 under Gazette notification G.S.R. 120(E), and they came into force ten days later. The amendments define synthetically generated information and fold it into the due diligence obligations of intermediaries, mandating labeling, metadata and provenance requirements, grievance redressal, and takedown windows measured in hours. This follows the AI Governance Guidelines issued by MeitY in late 2025, which chose a sectoral model over a single AI act.
What it means for CPGA CPG brand running AI-generated creative in India needs labeling and a grievance channel. India's approach, soft law across the ecosystem and hard rules where harm is visible, is the pattern several other markets are copying.
Court authorizes collective notice in Mobley v. Workday
The court formally authorized notice to a nationwide ADEA collective covering anyone who applied for a job through Workday since September 24, 2020 and was 40 or older at the time. Race and disability claims remain in the case but are not certified.
What it means for CPGThe collective is defined by the platform rather than by the employer. Every company that ran hiring through the platform in that window sits inside the factual record even without being named, which makes retention of your own applicant data and screening configuration a present concern.
South Korea's AI Framework Act takes effect
The Act on the Development of Artificial Intelligence and Establishment of Trust took effect after a one-year transition, making Korea the second jurisdiction after the EU with an economy-wide AI law. It applies extraterritorially, imposes obligations on high-impact AI including employment uses, and requires generative AI providers to notify users in advance and label output. A grace period defers most fines for at least a year.
What it means for CPGEmployment is a named high-impact category, so a CPG company hiring in Korea is in scope. Foreign operators may need to designate a Korean representative. Put Korean-language notices and content labeling into the market-entry checklist. Retrofitting them after launch costs more and takes longer.
DOJ establishes the AI Litigation Task Force
Attorney General Pam Bondi issued a memorandum creating a task force whose mandate is to challenge state AI laws, as directed by Executive Order 14365.
What it means for CPGA federal body now exists whose purpose is to unsettle the state law your compliance program is built on. That argues for governance controls tied to your own risk posture rather than to the text of any single state statute.
Texas Responsible Artificial Intelligence Governance Act takes effect
HB 149 took effect, adding Subtitle D to the Business and Commerce Code. Most of its prohibitions bind government rather than business. The duty to tell a consumer they are dealing with AI, the ban on social scoring, and the limits on biometric identification all apply to governmental entities. The duties that reach a private company are narrow and turn on intent. No person may develop or deploy an AI system intending to incite self-harm or crime, to unlawfully discriminate against a protected class, or to produce unlawful sexual material. Disparate impact alone does not establish intent. The Attorney General enforces exclusively, after written notice and a 60-day cure period, and the Act creates no private right of action.
What it means for CPGTexas carries a heavy CPG manufacturing and distribution footprint, and the practical reach is narrower than the statute's length suggests. An intent standard with an express disparate-impact carve-out is hard to meet, and with no private right of action the realistic exposure is an Attorney General inquiry that arrives with a cure window attached. Two provisions still earn attention. The Act gives a defendant a safe harbor for substantially complying with the NIST Artificial Intelligence Risk Management Framework Generative AI Profile, which converts a voluntary framework into a documented legal defense. And the amendments to the state biometric statute exempt biometric identifiers used to train an AI model, until that identifier is put to a commercial purpose, at which point the possession and destruction duties attach.
Illinois requires notice when AI is used in employment decisions
Amendments to the Illinois Human Rights Act took effect requiring employers to notify applicants and employees when AI is used in hiring, recruitment, and other employment decisions, and prohibiting AI use that produces discriminatory outcomes including through proxies such as ZIP code.
What it means for CPGThe ZIP code provision matters for CPG hiring. A screening model that weights commute distance or location for plant and warehouse roles can encode a protected characteristic without naming it. That correlation is now expressly on the record as a compliance concern.
California frontier AI, training data, and ADMT rules take effect
A cluster of California requirements became operative: SB 53 frontier model duties for developers training above 10^26 FLOPS, AB 2013 training data transparency, and the CPPA's automated decision-making technology regulations layered on top of the CCPA as amended by the CPRA, with certain opt-out provisions phasing through January 2027.
What it means for CPGMost CPG companies are deployers rather than frontier developers, so SB 53 is a vendor diligence question rather than a direct duty. The ADMT rules are the direct exposure: pre-use notice, access rights, and opt-out for significant decisions including employment and compensation.
Executive Order 14365 sets a national AI policy framework
The order established federal policy favoring a uniform national approach to AI regulation, directed the Attorney General to create an AI Litigation Task Force, required Commerce to identify onerous state laws, contemplated conditioning federal funding, and directed the FTC to issue a Section 5 policy statement on AI. Carve-outs cover child safety, AI compute infrastructure, and state government AI procurement.
What it means for CPGExecutive orders do not preempt state law. Preemption flows from acts of Congress. What a CPG compliance program gets from this is turbulence: more litigation, more uncertainty about which statutes survive, and the same obligations on the books throughout.
European Commission proposes the Digital Omnibus on AI
The Commission published a simplification package amending the AI Act, GDPR, ePrivacy, NIS2, and the Data Act. The headline proposal deferred high-risk obligations, prompted by delays in designating national competent authorities and finalizing harmonized standards.
What it means for CPGRead the stated reason for the delay. The standards and conformity assessment infrastructure that high-risk compliance depends on was not ready. The obligations did not soften. The machinery to comply with them did not exist yet.
California applies FEHA to automated decision systems in employment
Civil Rights Council regulations took effect applying California's anti-discrimination law to automated decision systems used in employment. Employers are responsible for discriminatory outcomes produced by third-party vendor tools, and must retain ADS-related records including inputs, outputs, criteria, and bias testing results for four years.
What it means for CPGFour years of retention on screening inputs and outputs is a system change, not a policy update. Check whether your applicant tracking system retains model inputs and scores today. Most do not, and adding it takes a vendor conversation and a release cycle. California is also the largest state footprint most CPG companies have, so this is rarely a corner case.
China's AI content labeling measures take effect
The Cyberspace Administration of China's Measures for Labeling AI-Generated Content, issued March 14, 2025 alongside mandatory national standard GB 45438-2025, took effect. Providers must apply explicit visible labels and embed implicit labels in file metadata.
What it means for CPGChina moved first on machine-readable provenance and the EU followed with Article 50. A brand producing AI-assisted creative for multiple markets should build labeling into the asset pipeline once, at the point of generation, rather than retrofitting per jurisdiction.
EU AI Act obligations for general-purpose AI models apply
Transparency and documentation obligations for general-purpose AI model providers, along with governance structures and the penalty regime, became applicable in the second phase of the Act's rollout.
What it means for CPGThis phase lands on model providers rather than on CPG deployers. Its value to a deployer is contractual. Your vendor now owes documentation it did not owe before, which means you can require that documentation in the agreement and point to a legal obligation when procurement meets resistance.
White House publishes the AI Action Plan
The administration released its AI Action Plan, setting the deregulatory posture that later produced the December executive order and the March 2026 legislative framework.
What it means for CPGFederal direction shifted toward removing barriers rather than adding obligations. State legislatures moved the other way. That divergence defines the US environment a CPG governance program has to operate in, more than any single statute does.
Kadrey v. Meta: fair use, on a failure of proof
Judge Vince Chhabria granted summary judgment for Meta two days after the Bartz ruling, but rested the outcome on the plaintiffs' failure to prove market harm rather than on a broad endorsement of training as fair use. The opinion signaled that stronger economic evidence could change the result. The case remains active and is proceeding through further pleading and discovery.
What it means for CPGThis decision and Bartz disagree about which fair use factor governs, and the disagreement is unresolved. A CPG company relying on a vendor's fair use assurance is relying on district court reasoning that no appellate court has reviewed.
Bartz v. Anthropic: training is fair use, holding pirated copies is not
Judge William Alsup found training on lawfully acquired books transformative and protected, while retention of a pirated library was not. The case settled for 1.5 billion dollars. Judge Araceli Martinez-Olguin granted final approval on July 20, 2026, following Alsup's retirement, overruling objections that the sum was too small. Payment runs to roughly 3,000 dollars per work across a Works List of 482,460 works, more than 91 percent of which were claimed. Some authors and publishers opted out and are pursuing separate suits that remain pending.
What it means for CPGThe court drew its line at data provenance rather than at anything the model does. That makes the diligence question for a CPG company licensing an AI tool narrow and answerable. Where did the training data come from, and can the vendor document it? One consequence of the settlement is that Alsup's reasoning never reached an appeals court, so it binds no one.
Japan enacts the AI Promotion Act
Japan adopted a deliberately light-touch framework encouraging cooperation with government safety measures and allowing the government to name companies publicly for human rights violations involving AI, without monetary penalties.
What it means for CPGPublicity is the whole enforcement mechanism here. For a consumer-facing brand operating in Japan, being named costs more than most fines would, and it costs it faster.
Thomson Reuters v. Ross Intelligence rejects fair use
Judge Stephanos Bibas, sitting by designation in the District of Delaware, issued the first merits decision on fair use in AI training, granting partial summary judgment to Thomson Reuters. The court found Westlaw headnotes protectable and Ross's use non-transformative, weighing heavily that the resulting product competed directly with the source. The case is on appeal to the Third Circuit.
What it means for CPGThe Third Circuit ruling will be the first appellate word on AI training and fair use, and it will sit above every district court decision that currently guides vendor risk assessments. Read it narrowly when it lands. Judge Bibas noted expressly that Ross was not a generative tool, so the reasoning may not carry cleanly to generative vendors. Treat any vendor indemnity written before that ruling as provisional.
EU AI Act prohibitions and AI literacy duties apply
The first phase of the Act became applicable, banning a defined set of AI practices outright and requiring providers and deployers to ensure a sufficient level of AI literacy among staff operating AI systems.
What it means for CPGNothing gets filed for the AI literacy duty, which is why it gets missed. It reaches anyone in a European plant, office, or commercial team who operates an AI system. HR and site leadership own it, and the evidence is training records.
South Korea promulgates its AI Framework Act
Korea became the first Asia-Pacific jurisdiction to adopt comprehensive AI legislation, with a one-year transition before the Act took effect in January 2026.
What it means for CPGThis entry is superseded by the effective date entry above. It is retained because the one-year transition model, promulgate then phase, is the structure most jurisdictions outside the EU have adopted.
FDA issues draft guidance on AI in regulatory decision-making
The FDA published its first guidance on using AI to produce information supporting regulatory decisions about drug and biological product safety, effectiveness, or quality, built around a risk-based credibility assessment framework tied to context of use. A companion draft addressed AI-enabled device software across the product lifecycle.
What it means for CPGNo equivalent AI-specific guidance exists for food or cosmetics. The credibility framework is nonetheless the clearest statement of how the agency thinks about AI in a regulated safety decision, and it maps directly onto contamination detection, allergen monitoring, and formulation screening.
Canada's AI and Data Act dies on the order paper
AIDA, introduced as Part 3 of Bill C-27 in June 2022, died when Parliament was prorogued. It has not been reintroduced. Canada entered 2026 without an AI statute, relying on privacy law, sectoral regulation, and policy instruments.
What it means for CPGA CPG company operating in Canada governs AI through PIPEDA, Quebec's Law 25, and sector regulators, not through an AI act. A February 2026 consultation summary points toward future rules on safety evaluation, red-teaming, human oversight, and lifecycle traceability.
Brazil's Senate approves AI Bill 2338/2023
The Senate approved a risk-based framework closely aligned with the EU AI Act. The bill then moved into a longer legislative process including a dedicated committee and public hearings, and has not been enacted.
What it means for CPGBrazil is a significant CPG market and the bill tracks the EU model, so a company already building for the AI Act would inherit most of the work. Nothing binds yet.
FTC launches Operation AI Comply
The Commission announced five simultaneous enforcement actions against deceptive AI claims and has brought more than a dozen since, spanning administrations. Matters have included overstated accuracy claims, automation claims, and business opportunity marketing, with an 18 million dollar judgment against Air AI proposed in March 2026.
What it means for CPGThe FTC did not need new authority. Section 5 substantiation applies to an AI claim exactly as it applies to a product efficacy claim. A brand advertising AI-powered personalization, shade matching, or formulation needs a substantiation file with test methodology and accuracy data before the claim runs, and the claim's scope cannot exceed the training scope.
EU AI Act enters into force
The world's first economy-wide AI regulation entered into force, classifying systems by risk with staggered application dates. Penalties reach 3 percent of global annual revenue or 15 million euros for high-risk violations, and 7 percent or 35 million euros for prohibited practices.
What it means for CPGClassification follows the consequence of failure. Product category has nothing to do with it. An AI vision system inspecting food for contamination, a quality system on a cosmetics line, and a tool screening job applicants are all high-risk. Nothing about being a consumer goods company puts a system outside the perimeter.
Colorado enacts the first comprehensive state AI law
SB 24-205 imposed duties on developers and deployers of high-risk AI to use reasonable care to prevent algorithmic discrimination, conduct impact assessments, and maintain a risk management program. It was repealed and replaced in May 2026 before ever taking effect.
What it means for CPGThis entry is kept in the record because it set the vocabulary every subsequent state bill borrowed, and because its collapse is the clearest available evidence that early comprehensive state AI statutes are not durable planning assumptions.
ISO/IEC 42001 published
The first certifiable AI management system standard was published, giving organizations an auditable structure for AI governance modeled on the management system approach used in ISO 9001 and ISO 27001.
What it means for CPGNo regulator requires it. Retail customers and enterprise partners ask about it anyway, and the question now appears on supplier questionnaires. Certification is the cheapest way to answer AI governance diligence once instead of writing a bespoke response for every account.
Bletchley Declaration signed at the UK AI Safety Summit
Twenty-eight countries and the EU signed a declaration on frontier AI risk, establishing the first multilateral statement of shared concern and launching the summit series.
What it means for CPGNo binding obligation followed for deployers. What survived was institutional. The national AI safety institutes founded in its wake now produce the technical evaluations that later regulation leans on.
China's Interim Measures for Generative AI Services take effect
Providers of publicly accessible generative AI must ensure content is lawful and truthful, label AI-generated output, and register their algorithms with regulators.
What it means for CPGAlgorithm registration gates market access. A brand deploying a consumer-facing generative tool in China files before launch, and that filing belongs on the launch schedule alongside customs and labeling rather than in a compliance backlog.
NYC Local Law 144 enforcement begins
Employers and employment agencies may not use automated employment decision tools for hiring or promotion in New York City unless the tool has passed an independent bias audit within the previous year, with results published and candidates notified.
What it means for CPGThis was the first US law to require a published bias audit. For a CPG company with New York corporate or commercial hiring, the audit is annual, independent, and public, which means a competitor or a journalist can read your tool's impact ratios.
UK publishes its pro-innovation AI White Paper
The UK proposed a non-binding, principles-based approach with existing sector regulators governing AI within their remits, declining a single AI regulator or uniform rules. Successive governments have kept this posture. As of mid-2026 no AI bill sits before Parliament, and ministers have signaled none in the short to medium term.
What it means for CPGFor a CPG company with UK operations, AI is governed at the point of use through UK GDPR, equality law, consumer protection, and product safety. There is no separate AI compliance regime to build against, which makes the existing frameworks the whole of the obligation.
NIST releases the AI Risk Management Framework 1.0
NIST published a voluntary framework organized around four functions, govern, map, measure, and manage, giving US organizations a common structure and vocabulary for AI risk.
What it means for CPGThe framework is voluntary, and it is the most widely adopted governance scaffold in US industry. A CPG program that adopts it gets a defensible structure and a vocabulary its auditors, insurers, and enterprise customers already speak.
Modernization of Cosmetics Regulation Act enacted
MoCRA gave FDA meaningful authority over cosmetics for the first time in eighty years, requiring facility registration, product listing, safety substantiation, and adverse event reporting.
What it means for CPGAI systems that generate safety documentation, auto-populate registrations, or screen formulations for compliance now operate inside a regulated regime. Substantiation is the operative word: a model's output is not substantiation, and the record has to show what evidence supports the safety determination.
New York City enacts Local Law 144
The Council passed the first US bias audit mandate for automated employment decision tools, with enforcement beginning July 2023 after an extended rulemaking.
What it means for CPGThe eighteen-month gap between enactment and enforcement is the pattern worth noting. Employment AI laws are routinely passed before the audit methodology exists, and the rulemaking is where the actual obligation gets defined.
European Commission proposes the AI Act
The Commission published the first draft of a risk-tiered economy-wide AI regulation, beginning a three-year legislative process that concluded with entry into force in August 2024.
What it means for CPGThe process ran three years from proposal to law, and another two to four years passed before the substantive obligations bound anyone. That cadence is the planning horizon for comprehensive AI legislation anywhere, and it is why the pending column on this page matters.
California voters approve the CPRA
The California Privacy Rights Act amended the CCPA, created the California Privacy Protection Agency as an independent enforcement body, added a right to correct inaccurate personal information, expanded restrictions on sensitive personal information, and extended protections to employees and job applicants.
What it means for CPGTwo provisions reach CPG directly. Sensitive personal information covers health-adjacent product data and loyalty program inference. Employee and applicant coverage is what makes HR AI a privacy question in California, not only an employment question.
Illinois Artificial Intelligence Video Interview Act takes effect
Enacted in 2019, the Act requires employers to explain how AI video interview analysis works, obtain candidate consent before using it, restrict who may view the recordings, and delete them within thirty days of a candidate request.
What it means for CPGThis was the first US law written specifically for an AI hiring use case. For CPG companies running high-volume seasonal and hourly hiring, the consent and deletion mechanics have to be built into the applicant workflow, and a vendor's standard terms of service almost certainly do not cover them.
California Consumer Privacy Act signed
The CCPA established rights to know what personal information is collected, to deletion, and to opt out of sale, creating the first broad US state privacy regime.
What it means for CPGAI systems that synthesize consumer data across e-commerce, loyalty, and service touchpoints can trigger obligations even where no single data point would. The synthesis is the processing.
GDPR becomes applicable
The General Data Protection Regulation, adopted in April 2016, became applicable across the EU. Article 22 gives individuals a right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects, with rights to human intervention and to contest the decision.
What it means for CPGArticle 22 governed automated decisions five years before generative AI reached the enterprise, and it still does. Any EU hiring, performance, or scheduling system that decides without a human in the chain sits inside it, independent of anything the AI Act requires.
Food Safety Modernization Act signed
FSMA shifted federal food safety regulation from responding to contamination to preventing it, requiring hazard analysis, preventive controls, validation, monitoring, and documented corrective action.
What it means for CPGThis is the framework that governs AI in food safety today, in the absence of AI-specific FDA guidance. A model performing contamination detection or allergen monitoring is a preventive control, which means it must be validated, monitored, and documented to the same standard as any other. A modeled value is not a tested value, and the distinction is legally significant.
Illinois Biometric Information Privacy Act enacted
BIPA requires informed written consent before collecting biometric identifiers, mandates retention and destruction schedules, and provides a private right of action with statutory damages.
What it means for CPGThe private right of action makes BIPA the most litigated biometric statute in the country. For CPG operations, the exposure sits in plant time-and-attendance systems, facial or voice analysis in hiring, and warehouse safety monitoring, all of which predate any AI-specific rule.
Americans with Disabilities Act signed
The ADA prohibits employment discrimination on the basis of disability and requires reasonable accommodation in the application process.
What it means for CPGBehavioral scoring in AI video interviews raises this directly. A model that scores eye contact, facial expression, or speech cadence can penalize a candidate for a disability. The employer remains accountable, and the accommodation obligation attaches to the screening step, not only to the job.
Uniform Guidelines on Employee Selection Procedures adopted
Federal agencies adopted uniform standards for validating employee selection procedures, including the four-fifths rule: a selection rate for any group below eighty percent of the highest group's rate is generally regarded as evidence of adverse impact.
What it means for CPGEvery AI hiring bias audit conducted today measures against this 1978 benchmark. A CPG company that has never validated a selection procedure now has an automated one, and the validation standard did not change because the tool did.
Age Discrimination in Employment Act enacted
The ADEA prohibits employment discrimination against workers aged 40 and older, and supports both disparate treatment and disparate impact claims.
What it means for CPGThe ADEA is the statute behind the certified collective in Mobley v. Workday. A screening model trained on the profile of a current workforce will reproduce that workforce's age distribution, and the resulting pattern is actionable under a law nearly sixty years old.
Civil Rights Act Title VII enacted
Title VII prohibits employment discrimination based on race, color, religion, sex, and national origin, and reaches facially neutral practices that produce disparate impact without business justification.
What it means for CPGDisparate impact is why an AI hiring tool can violate Title VII with no discriminatory intent anywhere in its design. This is the foundation the EEOC has repeatedly confirmed applies to AI: employers remain responsible for outcomes and cannot transfer that liability to a vendor.
Federal Insecticide, Fungicide, and Rodenticide Act enacted
FIFRA governs the registration, distribution, sale, and use of pesticides, and EPA registration determines what claims a product label may carry.
What it means for CPGFor household cleaning and disinfectant brands, an AI content tool that generates an antiviral claim for a product registered only for antibacterial use commits a registration violation. The tool's fluency is irrelevant. Claim language has to come from a pre-approved, registration-accurate library.
Federal Food, Drug, and Cosmetic Act enacted
The FDCA established FDA authority over the safety and labeling of food, drugs, devices, and cosmetics, including the boundary between a cosmetic claim and a drug claim.
What it means for CPGThat boundary is where AI-generated marketing copy fails most often. A skincare product that repairs DNA damage or a hair treatment that reverses hair loss has crossed into drug claim territory, and FDA and FTC enforce the line with warning letters regardless of who or what wrote the sentence.
Federal Trade Commission Act enacted
Section 5 prohibits unfair or deceptive acts or practices in commerce. It is the authority behind every AI advertising enforcement action the FTC has brought.
What it means for CPGThe oldest entry on this page is also the most active. The Commission has needed no new AI rulemaking, because a claim about what an AI product does is a claim, and it requires the same substantiation as a claim about what a moisturizer does.
No entries match those filters. Clear one and try again.
Changelog
Sep 4 2026Added the July 13 order in Mobley v. Workday extending the class certification schedule after Workday produced three internal bias evaluation reports on the eve of certification, with the certification hearing now set for March 9, 2027. Added the Commission's draft guidelines on high-risk classification, whose targeted consultation closed July 23 and which remain unadopted past their February 2, 2026 statutory deadline. Corrected the FTC policy statement entry to record issuance on July 1 and Federal Register publication on July 7, and confirmed it remains proposed with forty comments received. Linked terms of art to the new glossary.
Aug 17 2026Recorded the Commission's final Article 50 guidelines of July 20 and the adequacy assessment of the Code of Practice on transparency of AI-generated content. Added the Colorado Chatbot Safety Act and the Illinois Artificial Intelligence Safety Measures Act, both effective January 1, 2027, and the Colorado Department of Law's proposed rules for automated decision-making technology and conversational AI. Restated the India IT Amendment Rules with their notification and commencement dates. Confirmed the Mobley v. Workday docket and the FTC's proposed policy statement, whose comment period closed July 31.
Aug 8 2026Recorded Regulation (EU) 2026/1744, the Digital Omnibus on AI, in force July 27. Added the EU Product Liability Directive, effective December 9, 2026; the California AI Transparency Act, operative August 2, 2026; and the FTC's proposed Section 5 policy statement on accuracy suppression. Revised the 2028 entry: the Omnibus moved the Machinery Regulation to Annex I Section B, which takes AI embedded in machinery outside the AI Act's direct high-risk regime. Restated the Article 50(2) grace period for legacy systems as four months and the Bartz Works List as 482,460 works.
Aug 6 2026Confirmed the live litigation and draft guidance entries against their sources. Corrected the Thomson Reuters v. Ross decision date and the FDA warning letter entry, and closed Bartz v. Anthropic following final approval on July 20.