Accessibility Regulation, Mid-2026: Two US Deadlines Moved, the EAA Did Not
Two US web accessibility deadlines moved this spring, both within a month of each other, both by exactly one year, and both after the affected organizations had spent two years planning around the original dates.
If your compliance calendar was built before April 2026, it is now wrong. Here is the current state of every deadline that matters, and — more importantly — what the extensions actually change about your legal exposure. The short answer on that second question is: less than the headlines suggest.
ADA Title II: Extended to April 2027 and April 2028
The DOJ's 2024 Title II rule requires state and local government entities to make their web content and mobile applications conform to WCAG 2.1 Level AA. The rule took effect in June 2024 with delayed compliance dates: April 24, 2026 for entities serving populations of 50,000 or more, and April 26, 2027 for smaller entities and special districts.
On April 17, 2026 — one week before the first deadline — the DOJ announced an interim final rule extending both dates by one year. It was published in the Federal Register on April 20, 2026.
The current deadlines:
- Large entities (population 50,000+): April 26, 2027
- Small entities and special districts (under 50,000): April 26, 2028
The substantive requirements did not change. WCAG 2.1 Level AA remains the standard. The scope still covers web content and mobile apps that public entities provide directly or through third-party arrangements — which includes vendor-supplied systems, meaning software companies selling into the public sector are still on the hook through their customers' contracts. The narrow exceptions in the 2024 rule (archived content, certain third-party posts, individualized password-protected documents) are unchanged.
Only the dates moved.
HHS Section 504: Extended to May 2027 and May 2028
The Department of Health and Human Services followed the same path three weeks later.
The HHS Office for Civil Rights Section 504 rule requires recipients of federal financial assistance — hospitals, community health centers, primary care practices, and a wide range of health and human services organizations — to conform their websites, web content, and mobile applications to WCAG 2.1 Level AA.
The original deadlines were May 11, 2026 for recipients with 15 or more employees and May 10, 2027 for those with fewer than 15.
On May 7, 2026, four days before the first deadline, OCR published an interim final rule granting a one-year extension. The stated reasoning: a significant number of recipients — community health centers, hospitals large and small, primary care centers — would not have met the deadline.
The current deadlines:
- 15 or more employees: May 11, 2027
- Fewer than 15 employees: May 10, 2028
As with Title II, the WCAG 2.1 AA standard itself is unchanged.
What the Extensions Do Not Change
This is the part worth reading carefully, because "the deadline moved" is being read as "the risk moved." It did not.
The ADA already applied. The 2024 Title II rule created a specific technical standard and a specific compliance date. It did not create the underlying obligation. Title II's prohibition on disability discrimination in public services has applied to digital services for years, and courts have been reading it that way for longer than the rule has existed. An extension of the technical rule's compliance date does not suspend the statute underneath it.
Private litigation continues on its own track. Plaintiffs filed thousands of federal web accessibility suits in 2025 — one widely cited count put federal website-accessibility filings at 3,117 for the year, up 27% over 2024, with roughly 70% targeting e-commerce. None of that litigation depends on the DOJ rule's compliance date. Private plaintiffs sue under the statute, and the statute has no new deadline.
Section 504's underlying prohibition is also unchanged. Same structure: the rule sets a technical conformance date; the nondiscrimination requirement it implements predates it.
Nothing about a remediation timeline got easier. Bringing a large public-sector or health system web estate to WCAG 2.1 AA is a multi-year program — inventory, audit, prioritization, remediation, vendor renegotiation, and process changes so the fixed things stay fixed. Organizations that were behind for the 2026 date will be behind for 2027 unless they change what they are doing. An extra twelve months only helps teams that use it.
What to do: Treat the extension as recovered schedule, not recovered scope. Specifically: complete your content and application inventory now (this is the step organizations most often skip and most often regret), get vendor accessibility conformance into contract renewals happening this year, and put automated checks in the deployment pipeline so remediated pages do not regress before the new deadline arrives.
The European Accessibility Act: One Year In
The EAA has been in force since June 28, 2025 for new products and services. Unlike the US rules, nothing about it moved.
Enforcement under the EAA is decentralized. There is no single EU-wide regulator and no single EU-wide penalty schedule. Each member state transposed the directive into national law, designated a market surveillance authority, and set its own sanctions. National maximum penalties vary widely — from roughly €60,000 in Ireland to figures approaching €900,000 in Sweden. Germany's Bundesnetzagentur can impose fines up to €100,000 per individual violation.
What has actually happened in year one is less dramatic than the penalty ceilings suggest, and it is worth being accurate about it: as of mid-2026, there are no publicly confirmed fines issued specifically under national EAA implementing laws that can be independently verified.
What has happened is market surveillance. Authorities have opened inspections, issued formal information requests to companies inside and outside the EU, and sent legal notices to major retailers. Regulators in France, Sweden, and the Netherlands have been among the more visibly active. Accessibility statements — the public conformance declarations the EAA requires — are being read and checked, and procurement teams are increasingly asking vendors for measurable evidence of conformance rather than an assertion.
This pattern is what the directive prescribes. Article 20 requires national authorities to assess suspected non-compliance and, where requirements are not met, to first require corrective action within a reasonable timeframe. Fines are the escalation, not the opening move. Authorities can also order withdrawal of non-compliant products, bar them from the national market, require audits, and publicly name organizations that fall short.
The reasonable read is not "the EAA has no teeth." It is that year one was the corrective-action year, and the enforcement machinery is now built and running. Organizations that received an information request and did nothing are the ones who will produce the first fine headlines.
Also worth remembering: the June 28, 2030 deadline for products and services already on the market before June 2025 has not moved either. That five-year window is now four years and eleven months.
The Deadline Table
| Regime | Who | Standard | Deadline |
|---|---|---|---|
| ADA Title II | US public entities, pop. 50,000+ | WCAG 2.1 AA | April 26, 2027 |
| ADA Title II | US public entities, under 50,000 | WCAG 2.1 AA | April 26, 2028 |
| HHS Section 504 | Federal assistance recipients, 15+ employees | WCAG 2.1 AA | May 11, 2027 |
| HHS Section 504 | Federal assistance recipients, under 15 employees | WCAG 2.1 AA | May 10, 2028 |
| EAA | New products/services in the EU | EN 301 549 (WCAG 2.1 AA) | In force since June 28, 2025 |
| EAA | Products/services predating June 2025 | EN 301 549 (WCAG 2.1 AA) | June 28, 2030 |
Every one of these references WCAG 2.1 Level AA. Not 2.2, and certainly not the WCAG 3.0 Working Draft. If you are building to WCAG 2.2 AA — which is a superset of 2.1 AA — you are ahead of all six rows.
The Practical Position
The regulatory picture across the US and EU has converged on a single technical standard, and it is one your team can build and test against today. What differs across the six deadlines above is timing and enforcement mechanism, not the target.
That convergence is the useful fact. A single conformance program — continuous scanning of deployed pages, accessibility checks gating pull requests, periodic manual testing with assistive technology — satisfies the technical requirement in every jurisdiction on that table simultaneously. Reachablr covers the continuous half of that: URL scanning against WCAG 2.1 and 2.2 rules, code scanning on the repository, and PR gating so remediated work does not quietly regress between audits.
Two of these deadlines just moved a year. The third did not, and the litigation risk under all of them never moved at all.
Related Posts
Your Accessibility Tree Is Now Your AI Agent Interface
AI agents that drive web interfaces work far better against the accessibility tree than against screenshots — one team reported per-action latency dropping from 2–5 seconds to under 500ms with an order-of-magnitude cut in token cost. The semantics that make a site usable with a screen reader are the same ones that make it usable by an agent. Here is what that means for how you build.
AI-Generated Code Is Inaccessible by Default — and It's Now Your Largest Source of Accessibility Debt
AI coding assistants now write a large share of new frontend code, and they produce accessible markup only when accessibility is explicitly in the prompt. Here is why generated UI code fails WCAG so reliably, what the research actually shows about LLM accessibility performance, and the three controls that keep AI velocity from becoming compliance debt.
The 2026 WebAIM Million: Web Accessibility Is Getting Worse, Not Better
WebAIM's 2026 analysis of the top one million home pages found detectable WCAG failures on 95.9% of them — up from 94.8% — with 56.1 errors per page. The same six failure types have dominated for seven straight years, and every one of them is automatically detectable. Here is what the data says and what to do about it.
Scan Your Site for Free
Reachablr scans live URLs, analyzes your source code, checks every pull request, and auto-fixes React and JavaScript — WCAG 2.1 AA coverage across your entire development workflow.
Get Started Free