Risk visibility before enforcement
AI laws, privacy rules, and cybersecurity requirements β tracked for you.
Tracks 47+ regulations across 23+ jurisdictions with plain-English summaries and searchable timelines β free for compliance teams.
EU AI Act High-Risk Deadline
High-risk AI system obligations take effect August 2, 2026 β is your company ready?
Live database
Latest Regulatory Updates
We track changes so you don't have to
- California AI Transparency ActCalifornia, United StatesAI Regulation3 weeks agoView β
- Generative artificial intelligence: training data transparencyCalifornia, United StatesAI Regulation3 weeks agoView β
- California Delete ActCalifornia, United StatesPrivacy3 weeks agoView β
- California Age-Appropriate Design Code ActCalifornia, United StatesAge Verification3 weeks agoView β
- Information privacy: connected devicesCalifornia, United StatesCybersecurity3 weeks agoView β
Go Pro
Unlock personalized alerts, exports, and deeper timeline coverage.
$29/monthRuleWatch Pro adds saved alert preferences by jurisdiction and category, full historical timelines, filtered CSV/JSON exports, and API access without adding onboarding friction.
| Regulation | Jurisdiction | Category | Status | Effective | Actions |
|---|---|---|---|---|---|
| FTC Safeguards Rule Update The FTC Safeguards Rule requires covered non-bank financial institutions to maintain a written information security program with risk assessments, qualified oversight, access controls, encryption, and monitoring. Updated requirements also added mandatory breach reporting to the FTC for certain notification events. The rule affects lenders, mortgage brokers, auto dealers, and other financial institutions under FTC jurisdiction. United StatesCybersecurityAmended | United States | Cybersecurity | Amended | May 13, 2024 | View details |
| NYDFS Part 500 Cybersecurity Regulation New York requires covered financial entities to maintain a risk-based cybersecurity program, governance controls, incident reporting, and documented policies. The 2023 amendments strengthened board and senior-governance accountability, privileged-access management, asset inventory, vulnerability management, and incident notice requirements. Larger Class A companies face additional controls such as independent audits and enhanced monitoring. New York, United StatesCybersecurityAmended | New York, United States | Cybersecurity | Amended | Nov 1, 2023 | View details |
| Virginia Data Breach Notification Law Virginia requires entities and state agencies that suffer qualifying breaches involving personal information to notify affected residents and, in many cases, the Attorney General. It affects businesses and public bodies that own or license personal information and sets timelines, notice content expectations, and substitute-notice rules. Virginia, United StatesCybersecurityAmended | Virginia, United States | Cybersecurity | Amended | Jul 1, 2019 | View details |
| Texas Cybersecurity Program Texas gives certain businesses a safe harbor from exemplary damages after a breach if they implemented and maintained a qualifying cybersecurity program. It affects Texas businesses that handle sensitive personal information and pushes them toward recognized cybersecurity frameworks and scaled security controls. Texas, United StatesCybersecurityIn Effect | Texas, United States | Cybersecurity | In Effect | Sep 1, 2025 | View details |
| Security of Critical Infrastructure ERP Act 2024 Australia's 2024 ERP Act updates the Security of Critical Infrastructure regime with stronger powers to manage consequences of incidents and to address deficient risk management programs. It affects operators of critical infrastructure and critical telecommunications assets, including some data storage systems that hold business-critical data. The reforms are part of the broader cyber legislative package tied to the 2023-2030 Cyber Security Strategy. AustraliaCybersecurityIn Effect | Australia | Cybersecurity | In Effect | Nov 29, 2024 | View details |
| NIST Cybersecurity Framework 2.0 NIST CSF 2.0 updates the widely used cybersecurity framework and broadens it beyond critical infrastructure to organizations of any size or sector. It adds the Govern function and refines guidance for identifying, protecting against, detecting, responding to, and recovering from cyber risk. Although voluntary, it is frequently used in procurement, governance, and regulatory crosswalks. United StatesCybersecurityIn Effect | United States | Cybersecurity | In Effect | Feb 26, 2024 | View details |
| SEC Cybersecurity Disclosure Rules The SEC requires public companies to disclose material cybersecurity incidents on Form 8-K and to describe cybersecurity risk management, strategy, and governance in annual reports. It affects Exchange Act reporting companies and pushes boards and management to formalize oversight and reporting processes. The rules also require Inline XBRL tagging for the new disclosures. United StatesCybersecurityIn Effect | United States | Cybersecurity | In Effect | Sep 5, 2023 | View details |
| NIS2 Directive NIS2 expands the EU cybersecurity framework to more sectors and entities and requires management-approved cybersecurity risk management measures and incident reporting. It affects essential and important entities across energy, transport, health, digital infrastructure, public administration, manufacturing, and other critical sectors. The directive also increases supervisory and penalty powers and coordinates cross-border cooperation. European UnionCybersecurityIn Effect | European Union | Cybersecurity | In Effect | Jan 16, 2023 | View details |
| New York SHIELD Act The SHIELD Act broadened New York breach-notification rules and requires reasonable administrative, technical, and physical safeguards for private information. New York, United StatesCybersecurityIn Effect | New York, United States | Cybersecurity | In Effect | Mar 21, 2020 | View details |
| Information privacy: connected devices California requires manufacturers of connected devices sold in the state to equip those devices with reasonable security features suited to the device and the data it handles. It affects IoT manufacturers and is aimed at reducing unauthorized access to devices and the information they collect, transmit, or store. California, United StatesCybersecurityIn Effect | California, United States | Cybersecurity | In Effect | Jan 1, 2020 | View details |
| Florida Information Protection Act Florida requires covered entities and government agencies to investigate breaches involving personal information and to notify affected individuals, the Department of Legal Affairs, and sometimes consumer reporting agencies. It affects organizations that maintain electronic personal information and sets breach-notification timelines, reporting thresholds, and recordkeeping duties. Florida, United StatesCybersecurityIn Effect | Florida, United States | Cybersecurity | In Effect | Jul 1, 2014 | View details |
Pro Intelligence
What Pro members are watching
Pro members get instant email alerts when these regulations change.
Pricing
Start free. Upgrade when regulations matter most.
Every team gets full browse + search access free. Pro adds proactive monitoring so you never miss a change.
Full regulation browsing β no account required.
Everything in Free, plus proactive monitoring.
Subscribe for regulation alerts
Get notified when laws change
Join 500+ compliance professionals tracking regulations with RuleWatch. Free weekly digest.