| Widely repeated claim | Actual position | Instrument | Market |
|---|---|---|---|
| Colorado AI Act applies from 2026 | Never took effect | SB 26-189 | US |
| FINMA 08/2024 is a circular | A supervisory communication | FINMA-RS 2023/1, 2018/3 | CH |
| Swiss regulator fines firms CHF 250,000 | Criminal, on individuals | DSG arts 60–63, 64(2) | CH |
| Switzerland has a 72-hour deadline | No such deadline | DSG/LPD art. 24(1) | CH |
| Swiss law mandates AI-agent logging | Derivative only | DSG arts 21(2), 8(3) | CH |
| NIS2 applies in Norway | NIS1 applies | Digitalsikkerhetsloven | NO |
| AI Act high-risk duties began Aug 2026 | Deferred; transparency not | Reg. (EU) 2026/1744 | EU |
| Denmark designated AI Act authorities | Only the art. 5 bans | L 111 lapsed | DK |
| German boards must "approve" measures | Implement and supervise | § 38(1) BSIG | DE |
| German e-invoices kept ten years | Eight | § 14b UStG | DE |
| French platforms are "PDP" | Obsolete since Jul 2026 | Décret n° 2026-677 | FR |
| Polish micro-entrepreneurs are deferred | In scope since Apr 2026 | Druk nr 2321, not passed | PL |
| Estonia mandated B2B e-invoicing | A buyer's right to demand | In force 1 Jul 2025 | EE |
| Slovakia has a penalty-free Q1 2027 | Drafted, not enacted | LP/2026/282, unapproved | SK |
| UK suppliers must send e-invoices | Authorities receive | SI 2019/624 | UK |
| There is a SOC 2 for AI | There is not | ISO/IEC 42001 is certifiable | Cross-market |
| NIST has an agentic profile or a 2.0 | Neither; a CSA product | NIST AI RMF 1.0 | US |
| A regulation governs "AI agents" | None names them | UK GDPR 22A–22D | Cross-market |
| A workflow-definition standard exists | Exports are proprietary | Open Workflow Spec. v1.0.3 | Cross-market |
| Human-in-the-loop is a differentiator | Commodity | Relay.app closure | Cross-market |
Does the Colorado AI Act apply from February 2026?
No — it never took effect at all. SB 24-205 was signed in May 2024 with a February 2026 operative date, delayed twice, suspended in litigation, then repealed and reenacted by SB 26-189, signed 14 May 2026 and effective 1 January 2027. Nobody ever complied with it, because it never applied. Material describing its duty of care or impact assessments describes a repealed law. US ADMT compliance.
Is FINMA 08/2024 a circular?
No — it is a supervisory communication (Aufsichtsmitteilung; in French a communication sur la surveillance), expressly not a Rundschreiben, not a circulaire, and not binding regulation. Dated 18 December 2024, it states seven expectation areas. "The FINMA AI circular" is wrong, and immediately visible to a supervisory-law reader. The binding instruments are FINMA-RS 2023/1 (operational risks and resilience, in force 2024) and FINMA-RS 2018/3 (outsourcing), the latter reaching every third-party AI solution. German · French.
Can the Swiss data protection authority fine a company CHF 250,000 for a missing DPIA?
No, and the claim is wrong twice over. Arts 60–63 DSG/LPD are criminal provisions: fines to CHF 250,000 fall on natural persons, not as administrative fines on the undertaking, and under art. 64(2) the company is condemned in their place only where a fine of at most CHF 50,000 applies and identifying the individuals would need disproportionate investigation. Second, the EDÖB/PFPDT levies no fines: it renders decisions, and prosecution is cantonal under art. 63. A missing DPIA (art. 22), register (art. 12) or breach notification (art. 24) is not punishable as such. French · German.
Is there a 72-hour breach notification deadline in Switzerland?
No — no 72-hour deadline exists in Swiss law. Art. 24(1) DSG/LPD requires notification to the EDÖB/PFPDT «so rasch als möglich» / «dans les meilleurs délais», and only where the breach is likely to cause a high risk to the data subject — a higher trigger than the GDPR's, and not counted in hours. The clock measured in hours is a different one: arts 74a ff. ISG/LSI require critical-infrastructure operators to report a cyberattack to the BACS/OFCS within 24 hours, since 1 April 2025. One incident can start both. German · French.
Does Swiss law require you to log AI agent activity?
Not expressly — no Swiss provision lists the fields of a log for private controllers. The obligation is derivative: art. 21(2) DSG/LPD gives a right to review of an automated decision by a natural person, which presupposes that the basis of the decision can be reconstructed; art. 8(3) sets minimum data-security requirements, concretised by the DSV/OPDo; and FINMA expects institutions to explain and reproduce results. Re-running an agent manufactures a second decision, not an explanation of the first. German · French.
Does NIS2 apply in Norway?
No. Directive (EU) 2022/2555 is marked EEA-relevant but has not been incorporated into the EEA Agreement — there is no EEA Joint Committee decision, so Norway need not implement it. What applies is the digitalsikkerhetslov, in force 1 October 2025, implementing NIS1: seven sectors, registration with NSM and the sector authority, incident reporting within 24 hours. NIS2 still reaches Norwegian suppliers contractually, because EU customers pass down their supply-chain duties. Digitalsikkerhetsloven.
Did the EU AI Act's high-risk obligations start applying in August 2026?
No — they were deferred, and the transparency obligations were not. Regulation (EU) 2026/1744, the digital omnibus, was published in the Official Journal on 24 July 2026 and in force on 27 July 2026. It moved standalone Annex III high-risk obligations to 2 December 2027 and Annex I embedded systems to 2 August 2028, but left the transparency obligations applying from 2 August 2026. National guidance lagged: Denmark's Agency for Digital Government still showed pre-omnibus dates. The AI Act in Denmark.
Has Denmark designated its AI Act supervisory authorities?
Only for the Article 5 prohibitions. LOV nr 467 af 14/05/2025 covers the prohibited practices and essentially nothing else: market surveillance of high-risk systems is undesignated and the penalty provisions unenacted. The framework bill L 111, introduced 18 February 2026, reached first reading and lapsed at the general election of 24 March 2026, unreintroduced as at 2 September 2026. The gap is in designation and enforcement, not in the obligations — a regulation applies directly. The AI Act in Denmark.
Must German management "approve" the NIS2 risk-management measures?
No — § 38(1) BSIG requires management to implement the § 30 measures and supervise their implementation ("umsetzen und überwachen"), not to "approve" them ("billigen"). The approval wording comes from the ministerial draft and the directive; it did not survive into the enacted law, but is still repeated in commentary. Liability under § 38(2) runs towards the entity itself and under company law, the BSIG applying only subsidiarily. Denmark is the real contrast: NIS 2-loven § 7 does place approval on the management body. § 38 BSIG and management liability.
Is the German e-invoice retention period ten years?
No — eight years, under § 14b UStG. The period was shortened from ten to eight, and numerous guides still say ten. Under the BMF letter of 15 October 2025, at least the structured part must be retained unaltered in its original form — for ZUGFeRD, the PDF/A-3 file with its embedded XML, not a data set extracted from it. The e-invoice receipt obligation.
Is "PDP" still the term for a French e-invoicing platform?
No — since 27 July 2026 the official term is plateforme agréée (PA). Décret n° 2026-677 and the arrêté of the same date, published in the Journal officiel on 28 July 2026, replaced opérateur de plateforme de dématérialisation partenaire (PDP), and the tax administration has switched, including in its own page titles. Using "PDP" as the current term dates a document to before summer 2026. What changed on 1 September 2026.
Do Polish micro-entrepreneurs have a KSeF deferral to 2027?
No. Micro-entrepreneurs under art. 7(1)(1) of the Prawo przedsiębiorców came into the obligation on 1 April 2026, on the same terms as everyone else. The bill that would have excluded them until 31 December 2027 — Sejm druk nr 2321 — stalled after first reading on 13 March 2026 and was not passed. It is nevertheless cited as binding law, including in advisory material. Penalties under art. 106ni of the VAT Act begin 1 January 2027. KSeF, automation and AI.
Did Estonia make B2B e-invoicing mandatory in 2025?
No — there is no general B2B e-invoicing obligation in Estonia. Since 1 July 2025 a buyer has the right to demand an e-invoice: where the buyer is registered in the commercial register as an e-invoice recipient, the seller must issue one unless the parties agree otherwise. The duty arises from the buyer's choice, not from the law, and its reach is narrow — roughly 15,000 entities are registered. The 2027 general mandate is a Ministry of Finance intention document, not enacted. E-invoicing in Estonia.
Is there a penalty-free period for Slovak e-invoicing in early 2027?
Drafted, not enacted — do not plan around it. A Ministry of Finance draft amendment (LP/2026/282, May 2026) would defer the five-day buyer-side reporting duty to 1 July 2030 and introduce a penalty-free period from 1 January to 31 March 2027. It has not been approved, and the Financial Administration's August 2026 materials mention no such period. The obligation applies from 1 January 2027, with fines to €100,000 for repeated breaches. Slovak e-invoicing from 2027.
Do UK public procurement rules require suppliers to send e-invoices?
No — that is the wrong way round. The Public Procurement (Electronic Invoices etc.) Regulations 2019 (SI 2019/624), in force 18 April 2019 and extended to sub-central authorities and utilities on 18 April 2020, oblige contracting authorities to receive and process compliant invoices to EN 16931. They impose no duty on suppliers to send them. Much published material states the reverse. UK e-invoicing from 2029.
Is there a SOC 2 for AI?
No. There is no AICPA attestation standard or criteria set specific to AI, and no "SOC for AI" report. The Trust Services Criteria have not been amended, and NIST AI RMF, ISO 42001 and the EU AI Act have not been incorporated into SOC 2. Auditors map AI controls into the existing criteria instead. ISO/IEC 42001 is the only certifiable AI management system standard. US ADMT compliance.
Is there a NIST AI RMF agentic profile, or a version 2.0?
Neither, from NIST. NIST AI RMF 1.0 (January 2023) remains current — there is no 2.0 — and it is voluntary, not a regulation. The Generative AI Profile (NIST AI 600-1, July 2024) is final. The "NIST AI RMF Agentic Profile" circulating online is a Cloud Security Alliance work product; citing it as NIST is an avoidable credibility cost. FINRA on AI agents.
Which regulation governs AI agents?
None names them. No regulation anywhere uses "AI agent" as a regulated category. The obligations arrive through regimes that already governed whatever the agent touches: UK GDPR Articles 22A–22D since 5 February 2026, Swiss DSG art. 21, Danish NIS 2-loven § 7 management approval, California's ADMT regulations, and the EU AI Act as amended by Regulation (EU) 2026/1744. Each asks the same question — what did the system do, on what basis, with whose authorisation — and each applies now. AI agent governance.
Is there an industry standard for workflow definitions?
No — every automation vendor's export is a private format, and none will import a competitor's. The nearest thing is the Open Workflow Specification, at v1.0.3, formerly Serverless Workflow, governed under the CNCF and the Linux Foundation. Its implementations — Apache EventMesh, SonataFlow, Synapse and others — are cloud-native developer orchestration engines, not SaaS integration platforms: no Zapier, Make or n8n adoption, and no native importers exist. BPMN 2.0 is the only broadly implemented portable notation, and only within BPM. Workflow portability.
Is a human-in-the-loop approval step a differentiator between platforms?
No — it is commodity. n8n has send-and-wait, Zapier's human-in-the-loop step is generally available, Power Automate has start-and-wait-for-approval, Camunda has user tasks, Temporal has signals. The demonstration is uncomfortable: Relay.app had the richest human-in-the-loop model in the market — four step types, dynamic role assignment, interactive Slack approvals, per-step escalation — and is switched off at 23:59 PT on 14 September 2026. What differs is what survives the wait: an in-memory pause a deploy destroys, or a durable checkpoint. Approval checkpoints.
Where this library is itself uncertain
A register of corrections is worth less if it hides its own soft spots. Five items here are undecided, unverified or time-sensitive: a plan depending on any of them needs a check date, not a citation.
- France, the PLF 2027. The 1 September 2027 wave is in force in law, but the projet de loi de finances pour 2027 had not been tabled at the time of writing. Every previous postponement of this reform arrived through a finance act. Nothing is announced — but that is the window to watch.
- United Kingdom, the commencement date. HMRC’s roadmap update names April 2029, but no legislation sets a commencement date and the implementation roadmap promised at Budget 2026 is unpublished. Treat April 2029 as the planning date and the Finance Act as the confirmation.
- Norway, the forskrifter. The Act and the 1 January 2027 send obligation are adopted; the regulations under the bokføringsforskrift are not. Skattedirektoratet was to propose format and exemption criteria by 15 December 2026, about two weeks before the duty bites. EHF 3.0 over Peppol is expected but not yet fixed.
- Denmark, whether L 111 returns. A reintroduced bill could change the designation and penalty picture within one parliamentary session. Check its status on ft.dk before any decision turning on Danish designation or sanction.
- Kenya, the eTIMS exemption list. Salaries and wages, imported goods and services, airline ticketing, financial institution interest and charges, businesses below the KES 5 million threshold and non-residents without a Kenyan permanent establishment fall outside the requirement. Verify the current list against the gazetted Legal Notice 64 of 2024 before relying on a specific exemption.
Everything else here rests on a named instrument. These errors mostly enter at the draft stage — a ministerial draft says billigen, a bill proposes a penalty-free window — and survive because secondary sources cite each other rather than the enacted text.
Changes to this register
8 September 2026 — United Kingdom, the 2029 month. This register previously carried an entry saying that no primary source named a month for the UK e-invoicing mandate, and that April 2029 was an inference by professional bodies from the tax-year start. That was wrong. HMRC’s Transformation Roadmap: update 2026, published 2 July 2026 and updated 27 July 2026, states that the government “will also mandate e-invoicing for all VAT invoices from April 2029”. The position had been reached from the November 2025 consultation response, Budget 2025 and HMRC’s Tax Update 2026 of 23 June 2026, none of which names a month; the roadmap update, published nine days after the last of those, was missed. The entry has been withdrawn and the UK article rewritten. The register now carries twenty claims.
Sources
Each correction above names the instrument that decides it; the linked article carries the full source list for that market and the date the position was verified.
This page is for information and does not constitute legal advice. Position as at 8 September 2026.
Markets in English
In local languages
- Polska
- Deutschland
- France
- Schweiz / Suisse
- United Kingdom
- United States
- Danmark
- Belgique / België
- Norge
- Slovensko
- Eesti
- Kenya