Regulatory Watch
New laws, rules, guidance, enforcement actions and court decisions in privacy, AI and cybersecurity. Every item links to its primary source.
Showing 24 of 214 developments
ADTP REGULATORY BRIEF
HUD announces intent to establish eVMS system of records under the Privacy Act
HUD’s proposed eVMS system will centralize personal and financial data for housing assistance, impacting privacy and data‑handling practices.
ADTP REGULATORY BRIEF
Federal Register limits automated access; CAPTCHA required for flagged requests
The notice implements security measures to curb automated scraping of federal documents.
ADTP REGULATORY BRIEF
Federal Register proposes limiting automated scraping, requiring API use and CAPTCHAs
The proposal impacts developers by mandating API‑only programmatic access and adding CAPTCHA verification to protect site security.
ADTP REGULATORY BRIEF
FBI announces new Cyber Strategy emphasizing public‑private collaboration and rapid threat‑intel sharing
The strategy signals increased FBI engagement with private sector to improve cyber threat detection and response.
ADTP REGULATORY BRIEF
Senator Markey Introduces Facial Recognition and Biometric Technology Moratorium Act of 2026
The bill seeks to ban federal biometric surveillance, addressing privacy and civil‑rights concerns around facial recognition.
ADTP REGULATORY BRIEF
EFF discusses privacy implications of Apple Siri AI features in iOS 27
Understanding Siri’s data handling helps users protect privacy as AI features expand on mobile devices.
ADTP REGULATORY BRIEF
San Francisco announces new ALPR policy with limited safeguards, no warrant requirement, 30‑day data transfer deadline
The policy's weak safeguards raise significant privacy concerns over citywide location tracking.
ADTP REGULATORY BRIEF
Federal Register restricts automated scraping; requires API use and CAPTCHA verification
Increased security measures on federal sites affect developers and researchers who rely on automated data collection.
ADTP REGULATORY BRIEF
Agency seeks comment on proposed information collection for protection of human subjects
The request for comment could shape future data‑privacy and security requirements for institutions handling human‑subjects data and API access.
ADTP REGULATORY BRIEF
San Francisco Police Department proposes expanded drone surveillance policy, drawing criticism from EFF
The proposed SFPD drone policy could enable widespread surveillance without adequate privacy protections, raising civil liberties concerns.
ADTP REGULATORY BRIEF
U.S. lawmakers introduce AI AGENT Act and California SB 1106 defining AI agents
The proposals mark the first U.S. legislative attempts to define and regulate AI agents, shaping future AI governance.
ADTP REGULATORY BRIEF
California Privacy Protection Agency adopts multiple regulations including Conflict of Interest Code Amendments and Data Broker Registration Fee
Adopted CPPA regulations expand enforcement tools for the CCPA and Delete Act, affecting data brokers and other entities.
ADTP REGULATORY BRIEF
ENISA launches podcast series on Frontier AI and publishes guidance note on cybersecurity in the Frontier AI era
The launch and accompanying guidance highlight ENISA’s effort to inform stakeholders about AI‑related cybersecurity risks and recommended actions.
ADTP REGULATORY BRIEF
Commission designates ChatGPT, Reddit, Roblox as VLOPs/VLOSE under the Digital Services Act
The designations trigger new DSA compliance duties for major online services, affecting their risk‑management and user‑protection obligations.
ADTP REGULATORY BRIEF
Federal Register restricts automated scraping, requires CAPTCHA and API use
The notice informs users of new access controls that impact automated data collection from federal publications.
ADTP REGULATORY BRIEF
DoD updates SORN for DON Child and Youth Program to align with cybersecurity policies
The notice updates how children's health and personal data are handled, adding cybersecurity safeguards and expanded uses.
ADTP REGULATORY BRIEF
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
The notice establishes a new Privacy Act system of records for handling personal data of Peace Corps applicants and volunteers.
ADTP REGULATORY BRIEF
CMS re-establishes matching program with Treasury's Do Not Pay Working System under Privacy Act
The program expands data sharing for fraud prevention, raising privacy and security considerations for covered entities.
ADTP REGULATORY BRIEF
Senate Judiciary Subcommittee holds hearing on Flock Safety AI surveillance network
The hearing spotlights growing privacy and security risks of AI‑driven license‑plate and facial‑recognition surveillance used by police.
ADTP REGULATORY BRIEF
FTC seeks public comment on updating impersonation rule for platforms
The proposed rule change could impose new obligations on online platforms to curb impersonation scams, impacting privacy and security practices.
ADTP REGULATORY BRIEF
NY AG secures $2.3M settlement and reforms from Labcorp after data breach
The settlement forces Labcorp to adopt stronger data‑security and vendor‑risk controls, aiming to protect millions of consumers’ sensitive health information.
ADTP REGULATORY BRIEF
NY Attorney General urges Congress to enact AI safety legislation
The call highlights growing AI safety risks and pushes for federal regulation to protect public safety and national security.
ADTP REGULATORY BRIEF
SBA seeks comments on modified matching program under Privacy Act
SBA is updating its data‑matching program and inviting feedback, which may affect how personal data are shared between agencies.
ADTP REGULATORY BRIEF
WBUR reports driver’s license data appearing on dark web, raising AI‑enabled fraud risks
The exposure of driver’s license images on the dark web creates new AI‑driven identity‑theft threats and endangers vulnerable individuals.
Source: LiveThreat Regulatory Intelligence, analysed by ADTP. Briefs summarize the linked source and are not legal advice; the linked source is the authority. Dates appear only when the source states them.