CABIER Global Assurance · Regulatory Trajectory
Regulatory Trajectory
Every instrument sits in one of four stages: in force, enacted and in transition, proposed, or stalled. Only the first two drive controls and scoring. Pending and stalled items are shown so they are never mistaken for law.
Mapping only, not legal advice. Items marked pending need checking against the primary source before reliance.
Four stages
In force
Binding now. Mapped to controls and evidence and used in scoring.
Enacted, in transition
Law, with obligations phasing in. Controls are built ahead of the date; scoring starts on it.
Proposed or in consultation
Tracked for readiness only. Never used as an operative control.
Stalled
No current legislative path. Shown so it is not mistaken for law; the operative control stays with existing supervisory guidance.
Trajectory
Filter by jurisdiction. The Trust Gate column shows where an operative instrument lands in AssureCore.
DORA
EU
In force
Applies from 17 January 2025
Gate: Resilience
NIS2
EU
In force
Transposition deadline 17 October 2024
Gate: Security
MiCA
EU
In force
Transitional period ends 1 July 2026
Gate: Regulatory
AI Act, general-purpose models
EU
Enacted, in transition
Obligations from 2 August 2025; enforcement from 2 August 2026
Gate: Policy
AI Act, high-risk (Annex III)
EU
Enacted, in transition
2 December 2027 (proposed amendment)Pending primary-source verification
Gate: Policy
AMLR and AMLA
EU
Enacted, in transition
AMLA operational 1 July 2025; AMLR applies 10 July 2027
Gate: Regulatory
OSFI B-10 third-party risk
Canada
In force
Effective 1 May 2024
Gate: Resilience
OSFI E-21 operational resilience
Canada
Enacted, in transition
Full adherence by 1 September 2026
Gate: Resilience
AIDA
Canada
Stalled
Died on the order paper, January 2025
Gate: None (not operative)
SEC cyber incident disclosure
US
In force
Effective December 2023
Gate: Evidence
GENIUS Act (payment stablecoins)
US
Enacted, in transition
Implementing rules pendingPending primary-source verification
Gate: Regulatory
CLARITY Act (market structure)
US
Stalled
Did not clear the summer recess, 2026Pending primary-source verification
Gate: None (not operative)
Operational resilience (FCA, PRA)
UK
In force
Impact tolerances from 31 March 2025
Gate: Resilience
Cryptoasset regime
UK
Proposed or in consultation
Draft statutory instrument and consultationsPending primary-source verification
Gate: None (readiness only)
Cyber Security and Resilience Bill
UK
Proposed or in consultation
Before ParliamentPending primary-source verification
Gate: None (readiness only)
Jurisdiction trust profiles
Where the operative weight sits in each jurisdiction.
Canada
Prudential-led. OSFI guidance (B-10, B-13, E-21, E-23) carries the operative weight for AI and resilience while federal AI legislation is stalled. Provincial securities regulators govern crypto platforms.
United States
Supervisory guidance and state charters, not a single AI statute. SR 11-7 model risk, interagency third-party guidance, SEC disclosure and state breach laws are the operative controls. Pending federal market-structure legislation is tracked, not relied on.
European Union
Statute-led and connected. DORA, NIS2, the AI Act, MiCA and AMLR overlap on the same institution, so one control often answers several instruments.
United Kingdom
Principles and accountability. SMCR places outcomes on named people; operational resilience sets impact tolerances; the crypto and cyber regimes are still in progress.
Last regulatory review: 26 September 2026. Mapping only – not legal advice.
Each instrument with its issuer, control, evidence and source.
Open the regulatory packs