REGULATORY WATCH

Privacy, AI governance and data protection developments across the US and the EU, from regulators, legislatures and courts.

⚖️ Latest developments 🌐 Jurisdictions 📚 Law library
148
Last 30 days
19
High or critical
32
Enforcement actions
72
Laws tracked
All types Enforcement Legislation Rulemaking Guidance Litigation
Any impact Critical High Moderate Any time 7 days 30 days 90 days
Topic: ai governance · clear
46 developments
Moderate Guidance Published Ireland · Sep 28, 2026
Data Protection Commission releases AI Insights Report covering 2021‑2025 supervision
The Irish Data Protection Commission published a report on its supervision of AI products and services from 2021 to 2025, noting a rise in AI engagements and improvements in lawful basis, transparency and data‑minimisation. The report…
Data Protection Commission
Moderate Guidance Published European Union · Sep 28, 2026
ENISA launches podcast series on Frontier AI and publishes guidance note on cybersecurity in the Frontier AI era
ENISA announced a new podcast series to discuss the latest cybersecurity developments, with the first episode focusing on Frontier AI. In July 2026 the agency also published a note providing recommendations for national authorities and EU…
ENISA
Moderate FRAMEWORK UPDATE Published European Union · Sep 28, 2026
EU Commission releases two reports on generative AI and digital education impacts
The European Commission published two reports examining the implications of generative AI for education and the state of digital transformation in European schools. The findings will inform the Commission's work on the Union of Skills and…
European Commission
Moderate Guidance Announced United States (federal) · Sep 24, 2026
DraftKings uses AI to target losing gamblers with online behavioral advertising
DraftKings employs AI and machine learning on customers' betting records to identify likely losing gamblers and serve them targeted promotions. The practice exemplifies online behavioral advertising that leverages first‑party data to…
Low Investigation Announced United States (federal) · Sep 24, 2026
Senate Judiciary Subcommittee holds hearing on Flock Safety AI surveillance network
The Senate Judiciary Committee’s Subcommittee on Crime and Counterterrorism conducted a hearing on Flock Safety’s nationwide AI surveillance system. Experts highlighted the extensive data collection, facial tracking, and cybersecurity…
Moderate Proposed regulation Announced New York · Sep 24, 2026
NY Attorney General urges Congress to enact AI safety legislation
New York Attorney General Letitia James, leading a coalition of 25 state AGs, called on Congress to immediately establish a comprehensive regulatory framework for AI development. The letter cites recent incidents where AI agents escaped…
New York Attorney General's Office
Moderate Enforcement Published Spain · Sep 23, 2026
Spanish Data Protection Agency issues warning to company over AI-driven resume screening
On 23 September 2026 the AEPD sent a formal warning to a company planning to use an AI tool for analysing CVs and assigning scores. The agency stresses that data protection must be built in from the start, including DPIA for high‑risk…
Agencia Española de Protección de Datos (AEPD) · Reglamento General de Protección de Datos (RGPD)
Moderate New law Signed California · Sep 23, 2026
California SB 1119 signed into law regulating AI chatbots for minors
The Future of Privacy Forum report notes that California’s SB 1119 was recently signed into law by Governor Newsom. The law targets chatbot interactions with minors, requiring disclosures, crisis‑response protocols, age assurance, parental…
SB 1119
Moderate Guidance Published European Union · Sep 23, 2026
EU Commission hosts fifth roundtable on Digital Services Act implementation
On 23 September 2026 the European Commission held an online roundtable with about 60 civil society organisations and researchers to discuss the implementation of the Digital Services Act. The discussion focused on systemic risks…
European Commission · Digital Services Act
Moderate Guidance Announced United States (federal) · Sep 22, 2026
WBUR reports driver’s license data appearing on dark web, raising AI‑enabled fraud risks
WBUR discussed a breach where images of driver’s licenses have been posted on the dark web. The episode highlighted risks of new account fraud, especially when combined with AI tools that can synthesize voice, images, or video. It also…
Low Guidance Announced Global · Sep 22, 2026
Future of Privacy Forum opens nominations for 17th Annual Privacy Papers for Policymakers Awards
The Future of Privacy Forum (FPF) announced that submissions for the 17th Privacy Papers for Policymakers Award are open until October 16, 2026. The award seeks privacy, AI‑governance, and youth‑online research that emphasizes data…
Moderate Guidance Published European Union · Sep 22, 2026 · effective Sep 22, 2026
ENISA releases 2026 Threat Landscape report highlighting AI-enabled cyber threats and supply‑chain risks
ENISA's 2026 Threat Landscape report analyses incidents from 1 January to 31 December 2025, noting a rise in ransomware, AI‑driven malicious activity, and supply‑chain attacks. The report finds public administration to be the most targeted…
ENISA · NIS2 Directive
Moderate Proposed regulation Proposed European Union · Sep 21, 2026
EU Commission proposes KIDS Act to impose age‑based restrictions and safety‑by‑design for children online
On September 17, 2026 the European Commission published a proposal for a new EU KIDS Act that would ban users under 15 from creating accounts on certain social networking and video‑sharing services, with limited exceptions. The draft…
European Commission · Digital Services Act
Moderate Proposed regulation Proposed European Union · Sep 21, 2026
EU proposes Article 88c/88bis to allow unrestricted AI use of personal data
A leaked Irish Presidency document proposes that personal data used "in the context of AI" be automatically lawful, removing consent requirements. The draft Article 88c (now 88bis) would permit AI companies to process any personal data for…
European Commission · General Data Protection Regulation
Low Executive order Announced California · Sep 18, 2026
California Governor Newsom issues executive order on AI to spur dialogue and address harms
Governor Gavin Newsom issued an executive order calling for a thoughtful conversation about artificial intelligence and its potential harms. The order supports expanding reporting requirements under SB 53 (2025) for loss‑of‑control…
Governor Gavin Newsom · SB 53 (2025)
Low Guidance Published Global · Sep 18, 2026
How to limit Siri AI access in iOS 27
Apple’s iOS 27 introduces a more powerful Siri AI that can access data from native and third‑party apps and may send information to Apple’s Private Cloud Compute. Users can mitigate privacy risks by disabling Siri, turning off app content…
Low Guidance Published Global · Sep 18, 2026
Secure Messaging and AI Remain In Conflict Despite the Promise of TEEs
The EFF warns that cloud‑based trusted execution environments (TEEs) do not provide the same privacy guarantees as end‑to‑end encryption. When AI features offload message data to TEEs, the content leaves the device and is exposed to…
Low Guidance Announced Global · Sep 18, 2026
EFF warns that cloud TEEs undermine end‑to‑end encryption in messaging apps
The EFF explains that while trusted execution environments (TEEs) can protect data on cloud servers, they do not provide the same mathematical guarantees as end‑to‑end encryption. Sending message content to a TEE for AI processing creates…
Moderate Proposed regulation Proposed United States (federal) · Sep 18, 2026
EFF urges lawmakers to base AI cybersecurity rules on established best practices
The EFF recommends that any new AI cybersecurity legislation focus on proven security measures such as sandboxing, monitoring, and logging to mitigate risks demonstrated by recent AI lab incidents. It calls for minimum safety requirements…
Moderate Guidance Announced New York · Sep 17, 2026 · effective Jan 1, 2027
NY Attorney General urges workers to file whistleblower complaints on unsafe AI development
New York Attorney General Letitia James issued an alert encouraging employees with knowledge of unsafe or illegal AI development to submit confidential whistleblower complaints. The alert references the Responsible AI Safety and Education…
New York Attorney General's Office · New York SHIELD Act
← NewerOlder →
Coming up
Oct 2026
13
FHFA proposes to rescind SORN FHFA-12 and consolidate records under SORN FHFA-11
United States (federal) · effective
Oct 2026
26
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
United States (federal) · effective
Oct 2026
28
HHS modifies ORR Unaccompanied Children system of records, effective Oct 28, 2026
United States (federal) · effective
Nov 2026
2
DOI establishes new matching program under Privacy Act of 1974
United States (federal) · effective
Nov 2026
5
Treasury exempts new tip intake records from certain Privacy Act provisions
United States (federal) · effective
Nov 2026
6
Treasury proposes new system of records for federal student aid data
United States (federal) · effective
Nov 2026
16
NARA proposes revisions to System of Records NARA 44 for reasonable accommodation requests
United States (federal) · effective
Jan 2027
1
Colorado governor signs SB 26-189, revising AI Act to regulate ADMT in employment
Colorado · effective
Jan 2027
1
NY Attorney General urges workers to file whistleblower complaints on unsafe AI development
New York · effective
Jan 2027
1
Delaware Governor signs HB 380, amending the DPDPA effective Jan 1 2027
Delaware · effective
Jan 2027
1
California Legislature passes SB 690 to limit pen register lawsuits under CIPA
California · effective
Jan 2027
1
Colorado AI Act (SB 26-189, replacing SB 24-205)
Colorado · law takes effect
By jurisdiction
United States (federal)66 new · 16 laws European Union18 new · 14 laws California14 new · 5 laws France12 new · 0 laws New York6 new · 2 laws Global6 new · 0 laws Italy4 new · 0 laws Spain4 new · 0 laws Texas2 new · 3 laws Vermont2 new · 2 laws Ireland2 new · 0 laws Utah1 new · 2 laws
All jurisdictions →
Topics this month
privacy · 107security · 59ai governance · 46transparency · 29data minimization · 27children · 26profiling · 24automated decision making · 22cybersecurity · 16consent · 14targeted advertising · 14data governance · 13