REGULATORY WATCH

Privacy, AI governance and data protection developments across the US and the EU, from regulators, legislatures and courts.

⚖️ Latest developments 🌐 Jurisdictions 📚 Law library
148
Last 30 days
19
High or critical
32
Enforcement actions
72
Laws tracked
All types Enforcement Legislation Rulemaking Guidance Litigation
Any impact Critical High Moderate Any time 7 days 30 days 90 days
Topic: cybersecurity · clear
21 developments
Low Enforcement In effect EC · Oct 2, 2026
Ecuador orders security expert Ola Bini deported and bans return for 10 years
Ecuadorian immigration authorities detained free software developer Ola Bini in Quito and ordered his immediate deportation, prohibiting his return for a decade. The decision was based on a secret report alleging threats to public…
Ecuadorian immigration authorities
Low Guidance Announced United States (federal) · Sep 30, 2026 · effective Sep 9, 2026
FBI announces new Cyber Strategy emphasizing public‑private collaboration and rapid threat‑intel sharing
On September 9, 2026 the FBI published its Cyber Strategy, outlining four pillars that include investigating adversaries, supporting victims, and expanding partnerships. The strategy stresses the importance of private‑sector telemetry…
Federal Bureau of Investigation
Moderate Guidance Published European Union · Sep 28, 2026
ENISA launches podcast series on Frontier AI and publishes guidance note on cybersecurity in the Frontier AI era
ENISA announced a new podcast series to discuss the latest cybersecurity developments, with the first episode focusing on Frontier AI. In July 2026 the agency also published a note providing recommendations for national authorities and EU…
ENISA
Moderate Guidance Published United States (federal) · Sep 28, 2026
Federal Register restricts automated scraping, requires CAPTCHA and API use
The Federal Register warns that aggressive automated scraping of its sites is limited to access via developer APIs. Human users must complete a CAPTCHA to continue, and may be asked to do so repeatedly as a security measure.
Department of Defense · Privacy Act of 1974
Moderate Guidance Published United States (federal) · Sep 25, 2026
DoD updates SORN for DON Child and Youth Program to align with cybersecurity policies
The Department of Defense is modifying and reissuing the system of records titled "DON Child and Youth Program" (NM01754-3) under the Privacy Act of 1974. The updates incorporate DoD standard routine uses A through J, expand the collection…
Department of Defense · Privacy Act of 1974
Moderate Guidance Published United States (federal) · Sep 25, 2026
CMS re-establishes matching program with Treasury's Do Not Pay Working System under Privacy Act
The Centers for Medicare & Medicaid Services announced the re-establishment of a data matching program with the Do Not Pay Working System, administered by the Treasury's Bureau of Fiscal Service. The notice cites subsection (e)(12) of the…
U.S. Department of Health and Human Services, Centers for Medicare & Medicaid Services · Privacy Act of 1974
Low Investigation Announced United States (federal) · Sep 24, 2026
Senate Judiciary Subcommittee holds hearing on Flock Safety AI surveillance network
The Senate Judiciary Committee’s Subcommittee on Crime and Counterterrorism conducted a hearing on Flock Safety’s nationwide AI surveillance system. Experts highlighted the extensive data collection, facial tracking, and cybersecurity…
Moderate Guidance Published European Union · Sep 22, 2026 · effective Sep 22, 2026
ENISA releases 2026 Threat Landscape report highlighting AI-enabled cyber threats and supply‑chain risks
ENISA's 2026 Threat Landscape report analyses incidents from 1 January to 31 December 2025, noting a rise in ransomware, AI‑driven malicious activity, and supply‑chain attacks. The report finds public administration to be the most targeted…
ENISA · NIS2 Directive
Low Executive order Announced California · Sep 18, 2026
California Governor Newsom issues executive order on AI to spur dialogue and address harms
Governor Gavin Newsom issued an executive order calling for a thoughtful conversation about artificial intelligence and its potential harms. The order supports expanding reporting requirements under SB 53 (2025) for loss‑of‑control…
Governor Gavin Newsom · SB 53 (2025)
Low Guidance Announced Global · Sep 18, 2026
EFF warns that cloud TEEs undermine end‑to‑end encryption in messaging apps
The EFF explains that while trusted execution environments (TEEs) can protect data on cloud servers, they do not provide the same mathematical guarantees as end‑to‑end encryption. Sending message content to a TEE for AI processing creates…
Moderate Proposed regulation Proposed United States (federal) · Sep 18, 2026
EFF urges lawmakers to base AI cybersecurity rules on established best practices
The EFF recommends that any new AI cybersecurity legislation focus on proven security measures such as sandboxing, monitoring, and logging to mitigate risks demonstrated by recent AI lab incidents. It calls for minimum safety requirements…
Moderate Guidance Announced New York · Sep 17, 2026 · effective Jan 1, 2027
NY Attorney General urges workers to file whistleblower complaints on unsafe AI development
New York Attorney General Letitia James issued an alert encouraging employees with knowledge of unsafe or illegal AI development to submit confidential whistleblower complaints. The alert references the Responsible AI Safety and Education…
New York Attorney General's Office · New York SHIELD Act
Moderate FRAMEWORK UPDATE Published European Union · Sep 17, 2026 · effective Aug 2, 2026
EU AI Board discusses AI Act implementation and publishes Action Plan on cybersecurity and AI
On 17 September 2026 the EU AI Board met under the Irish Presidency to review priorities for EU AI policy and AI Act enforcement. The meeting included an update on the Commission’s Action Plan on cybersecurity and AI and on transparency…
European Commission · EU AI Act
Low New law Signed California · Sep 11, 2026
California Governor signs AB 2071 and AB 2298 to add digital literacy and cybersecurity to school curricula
Governor Newsom signed a package of 12 bills, including AB 2071 and AB 2298, that require digital wellness and cybersecurity education in California schools. The bills aim to protect children online through education rather than bans.
AB 2071
Moderate Final regulation In effect European Union · Sep 11, 2026 · effective Sep 11, 2026
EU Cyber Resilience Act reporting obligations take effect for manufacturers
As of September 11, 2026, manufacturers of products with digital elements are subject to new incident reporting obligations under the EU Cyber Resilience Act. The obligations require manufacturers to report cybersecurity incidents related…
European Commission · Cyber Resilience Act
Moderate Guidance Announced European Union · Sep 11, 2026
ENISA launches Single Reporting Platform for Cyber Resilience Act reporting
ENISA has deployed the initial operating capability of the Single Reporting Platform (SRP) to support the Cyber Resilience Act (CRA) reporting obligations. From 11 September 2026 manufacturers and open‑source software stewards must report…
ENISA · Cyber Resilience Act
Moderate Guidance In effect France · Sep 10, 2026 · effective Sep 1, 2026
CNIL guidance on data‑protection obligations under the electronic invoicing reform effective 1 Sept 2026
The CNIL explains the data‑protection implications of the French electronic invoicing reform that entered into force on 1 Sept 2026. It details which personal data may be processed, the roles of issuers, receivers and certified platforms…
CNIL · réforme relative à la facturation électronique
Moderate Guidance Published France · Sep 10, 2026
CNIL releases Volume 2 of “L’Agence Privacy” to educate adolescents on cybercrime and data privacy
On 10 September 2026 the French data‑protection authority CNIL published the second volume of its educational comic series “L’Agence Privacy”. The free online and paper resource targets teenagers and parents, covering risks such as…
CNIL
Moderate Data protection authority action Announced Spain · Sep 2, 2026
AEPD to host data‑protection session at XX Jornadas STIC on 24 Nov 2026
The Spanish Data Protection Agency (AEPD) will hold a dedicated data‑protection space on 24 November 2026 during the XX Jornadas STIC conference in Madrid. The event, organized by the Centro Criptológico Nacional, the Centro Nacional de…
Agencia Española de Protección de Datos
Low Executive order Announced United States (federal) · Aug 18, 2026
White House issues NSPM to enable private-sector offensive cyber operations against transnational cybercrime
On August 12, 2026 the Administration published a National Security Presidential Memorandum establishing a program for vetted private companies to conduct offensive cyber operations against foreign cyber‑enabled transnational criminal…
U.S. Departments of Justice and Homeland Security · Executive Order 14390
Older →
Coming up
Oct 2026
13
FHFA proposes to rescind SORN FHFA-12 and consolidate records under SORN FHFA-11
United States (federal) · effective
Oct 2026
26
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
United States (federal) · effective
Oct 2026
28
HHS modifies ORR Unaccompanied Children system of records, effective Oct 28, 2026
United States (federal) · effective
Nov 2026
2
DOI establishes new matching program under Privacy Act of 1974
United States (federal) · effective
Nov 2026
5
Treasury exempts new tip intake records from certain Privacy Act provisions
United States (federal) · effective
Nov 2026
6
Treasury proposes new system of records for federal student aid data
United States (federal) · effective
Nov 2026
16
NARA proposes revisions to System of Records NARA 44 for reasonable accommodation requests
United States (federal) · effective
Jan 2027
1
Colorado governor signs SB 26-189, revising AI Act to regulate ADMT in employment
Colorado · effective
Jan 2027
1
NY Attorney General urges workers to file whistleblower complaints on unsafe AI development
New York · effective
Jan 2027
1
Delaware Governor signs HB 380, amending the DPDPA effective Jan 1 2027
Delaware · effective
Jan 2027
1
California Legislature passes SB 690 to limit pen register lawsuits under CIPA
California · effective
Jan 2027
1
Colorado AI Act (SB 26-189, replacing SB 24-205)
Colorado · law takes effect
By jurisdiction
United States (federal)66 new · 16 laws European Union18 new · 14 laws California14 new · 5 laws France12 new · 0 laws New York6 new · 2 laws Global6 new · 0 laws Italy4 new · 0 laws Spain4 new · 0 laws Texas2 new · 3 laws Vermont2 new · 2 laws Ireland2 new · 0 laws Utah1 new · 2 laws
All jurisdictions →
Topics this month
privacy · 107security · 59ai governance · 46transparency · 29data minimization · 27children · 26profiling · 24automated decision making · 22cybersecurity · 16consent · 14targeted advertising · 14data governance · 13