AI Regulation Tracker

Every AI bill, rule, and enforcement action. Tracked.

Real-time legislative intelligence across 32 jurisdictions and 53 US states. See live source coverage →

Ask the tracker

Natural language — cited answers from the corpus

Total tracked

4610

Legislation

2129

Enforcement

77

Critical

124

By jurisdiction

3684 items across US

US State Coverage

International

Filters

4610 results

Page 1

policy paper US 9/10

The White House outlines America's AI Action Plan for global technological dominance, focusing on accelerating innovation, building infrastructure, and leading in international AI diplomacy and security.

This White House AI Action Plan for July 2025 outlines a national strategy to achieve global AI dominance, emphasizing economic and national security. It proposes three pillars: accelerating innovation by reducing regulation and fostering open-source AI, building robust American AI infrastructure including semiconductors and secure data centers, and leading international AI diplomacy, particularly against Chinese influence, through export controls and national security evaluations. The plan, presented by the Trump administration, is aspirational, setting strategic goals primarily for the U.S. government.

government Effective: 2025-07-01
agency report EU 9/10

The European Commission announces that it will begin enforcing the AI Act rules and new transparency requirements from August 2, 2026, led by its AI Office.

The European Commission has announced that it will begin enforcing the rules of the AI Act and new transparency requirements starting on August 2, 2026. This enforcement will be led by the Commission's AI Office, signaling a critical phase for compliance with the landmark AI regulation across the EU.

governance eu ai act Effective: 2026-08-02
enforcement action US 9/10

OFAC designates two individuals and several entities, including a VPN service and Cuban organizations, adding them to the Specially Designated Nationals (SDN) List for cyber and Cuba-related reasons, prohibiting transactions by U.S. persons.

The Treasury Department's OFAC has updated its Specially Designated Nationals and Blocked Persons List, adding two individuals (Dmytro Rashevskyi and Yevgeniy Vladimirovich Silayev) and several entities, including a VPN service and various Cuban organizations. These designations are based on cyber-related activities and Cuba sanctions programs. The action prohibits U.S. persons from engaging in transactions with the listed individuals and entities and blocks their property and interests in property within U.S. jurisdiction, effective immediately.

Effective: 2026-07-13
legislation BR PL 3.066/2025 enacted 9/10

Brazil's Senate approved a bill to increase penalties for digital sexual violence against minors, including cases involving AI and deepfakes, classifying many as heinous crimes.

Brazil's Senate has approved PL 3.066/2025, which significantly stiffens penalties for digital sexual violence against children and adolescents, with the bill now moving for presidential sanction. The legislation specifically addresses the use of artificial intelligence, deepfakes, and other digital tools as aggravating factors for these crimes. It reclassifies several related offenses as 'heinous crimes,' leading to harsher sentences and reduced benefits for convicts, aiming to deter the exploitation and abuse of minors online. The bill also changes terminology from 'child pornography' to 'sexual violence against children or adolescents' to better reflect the gravity of the acts.

content
enforcement action KR 9/10

South Korea's PIPC sanctioned Coupang and CFS with significant penalties for multiple violations of the Personal Information Protection Act, including a major data breach affecting 33 million users, insufficient security, delayed notifications, and undermining CPO independence.

The South Korean Personal Information Protection Commission (PIPC) issued substantial administrative sanctions against Coupang and Coupang Fulfillment Services (CFS) for severe breaches of the Personal Information Protection Act (PIPA). This action, including a penalty of KRW 624.681 billion for Coupang, resulted from a data breach affecting over 33 million users and 4.33 million third parties, caused by inadequate security management, delayed notifications, and undermining the Chief Privacy Officer's role. The PIPC also found failures in data destruction and evidence preservation. This indicates an active enforcement posture by the PIPC.

data privacy Effective: 2026-06-10
guidance US 9/10

CISA warns of critical vulnerabilities (CVSS 9.8) in Yarbo's mobile application and cloud infrastructure, allowing remote access and control of a global robot fleet, and recommends immediate user updates and security measures.

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an advisory regarding critical vulnerabilities (CVSS 9.8) in Yarbo's mobile application and cloud infrastructure that control its global robot fleet. These flaws involve hard-coded credentials and missing authorization, enabling attackers to gain fleet-wide access, monitor telemetry, and send operational commands. CISA recommends users update the Yarbo app to version 3.17.4 or later and implement defensive cybersecurity measures, while Yarbo is deploying server-side authorization fixes. The enforcement risk score is low (25) as CISA is issuing an advisory rather than an enforcement action.

security Effective: 2026-06-11
legislation US / TX HB581 enacted 9/10

Texas HB581 prohibits the creation of artificial sexual material harmful to minors, taking effect on September 1, 2025.

Texas House Bill 581 has been enacted and will become effective on September 1, 2025. This law prohibits the use of artificial intelligence to create sexual material that is harmful to minors. The enactment indicates a strong regulatory stance against the misuse of AI for generating illicit content, particularly concerning child protection, and carries a high enforcement risk.

content Effective: 2025-09-01
regulation US 9/10

BIS implements new export controls on advanced computing and semiconductor manufacturing items, expands controls for supercomputer and semiconductor end uses in China, and requires licenses for certain U.S. person activities supporting IC development/production in the PRC.

The U.S. Bureau of Industry and Security (BIS) has issued a final rule significantly tightening export controls on advanced computing chips and semiconductor manufacturing equipment. The rule expands licensing requirements for transactions involving these items intended for supercomputer and semiconductor manufacturing end-uses, particularly impacting 28 Chinese entities. Additionally, U.S. persons supporting the development or production of certain ICs in the PRC now require a license. A Temporary General License is established to mitigate immediate supply chain disruptions, allowing limited manufacturing in China for items ultimately used outside the country, and BIS provides guidance on due diligence certificates for compliance programs.

governance
regulation US 9/10

This U.S. interim final rule revises export controls on advanced computing items and semiconductor manufacturing equipment to restrict China's military modernization capabilities.

The U.S. Bureau of Industry and Security (BIS) has issued an interim final rule (IFR) that amends the Export Administration Regulations (EAR). This rule strengthens controls on advanced computing integrated circuits (ICs), computers containing these ICs, and semiconductor manufacturing items. The primary objective is to make existing controls more effective and less burdensome while protecting U.S. national security by limiting China's access to critical technologies that could be used for military modernization. This IFR is part of a broader effort by BIS to refine export controls initiated with the October 7, 2022 IFR.

military
enforcement action HR 9/10

Croatia's data protection agency fined a telecommunications operator EUR 4.5 million for General Data Protection Regulation (GDPR) violations related to personal data transfers.

The Croatian Personal Data Protection Agency (AZOP) issued a significant administrative fine of EUR 4.5 million to a telecommunications operator for infringements of the General Data Protection Regulation (GDPR). The violations specifically concerned the unlawful transfer of personal data, underscoring the strict enforcement of data protection rules by EU member state authorities.

data privacy eu ai act Effective: 2025-11-14
enforcement action BR 9/10

Brazilian agencies ANPD, MPF, and Senacon issued recommendations to X (Twitter) to prevent and remove non-consensual sexualized synthetic content generated by its AI tool, Grok.

Brazilian federal agencies, including the National Data Protection Authority (ANPD), Federal Public Ministry (MPF), and National Consumer Secretariat (Senacon), issued joint recommendations to X (formerly Twitter). The recommendations require X to immediately prevent its AI tool, Grok, from generating non-consensual sexualized or eroticized synthetic content, particularly involving minors or identifiable adults. X must also establish procedures within 30 days to identify and remove existing illicit content, suspend involved accounts, provide a transparent complaint mechanism, and conduct a Data Protection Impact Assessment for Grok's generative features. Non-compliance could lead to further administrative and judicial action.

safety
legislation US / CO SB26-189 in committee 9/10

Colorado SB26-189 is a bill introduced in the Senate concerning the use of automated decision-making technology in consequential decisions.

Colorado Senate Bill 26-189, introduced on May 1, 2026, aims to regulate the use of automated decision-making technology, particularly in consequential decisions. It is currently under consideration and assigned to the Senate Business, Labor, & Technology Committee, with subjects including Labor & Employment and Telecommunications & Information Technology.

governance colorado sb205
agency report US / WI 94288 enacted 8/10

The City of Madison, Wisconsin, passed a one-year moratorium in 2025 on data center development, specifically targeting AI infrastructure siting, marking a first for US cities.

The City of Madison, Wisconsin, enacted a one-year moratorium in 2025 on new data center construction, with a particular focus on facilities intended for AI infrastructure. This action is significant as it represents the first city-level moratorium in the US specifically aimed at regulating the physical siting of AI-related infrastructure, indicating an emerging trend of local government involvement in AI governance. The moratorium creates an immediate and binding obligation for data center developers in Madison.

governance Effective: 2025
agency report US 8/10

FCC updates its Covered List to ban new foreign-produced advanced robotic devices and connected power inverters due to national security and cybersecurity risks.

The Federal Communications Commission (FCC) has added foreign-produced advanced robotic devices (mobile robots, humanoids, quadrupeds) and connected power inverters to its Covered List, effective July 28, 2026. This action, based on national security determinations by an Executive Branch interagency body, prohibits these new device models from receiving FCC equipment authorization, effectively banning their entry into the U.S. market. The ban aims to mitigate supply chain vulnerabilities and cybersecurity risks to critical infrastructure. An exemption allows for 'Conditional Approval' by the Department of War or Homeland Security for devices found not to pose such unacceptable risks.

safety Effective: 2026-07-28
policy paper US 8/10

An international alert warns countries and companies about North Korean IT workers using AI to obfuscate identities and fund illicit weapons programs, urging compliance with sanctions.

This international alert, issued by multiple governments including the U.S. State Department and FBI, warns global entities about North Korean IT workers who use advanced methods, including AI, to disguise their identities and secure remote work. Their earnings are then remitted to fund North Korea’s illegal nuclear weapons and ballistic missile programs. These workers also pose an insider threat, engaging in data exfiltration and cryptocurrency theft. The alert reiterates that contracting with and paying these workers may violate domestic laws and UN Security Council Resolution 2397, which requires repatriation of such individuals.

safety Effective: 2026-07-31
agency report EU 8/10

The European Commission announces that its AI Office and national authorities will begin enforcing the Artificial Intelligence (AI) Act and new transparency rules from August 2, 2026.

The European Commission has announced that enforcement of the Artificial Intelligence (AI) Act and new transparency requirements will officially commence on August 2, 2026. This means that providers and deployers of AI systems in the EU must ensure full compliance with the Act's provisions, as the AI Office, in conjunction with national authorities, will begin active oversight and enforcement.

governance eu ai act Effective: 2026-08-02
agency report GB 8/10

The UK's financial regulators have launched a new oversight regime for designated Critical Third Parties to enhance system-wide operational resilience in financial services.

The UK's Financial Conduct Authority (FCA), Bank of England, and Prudential Regulation Authority (PRA) have implemented a new oversight regime for Critical Third Parties (CTPs) that provide essential services to UK financial firms. This regime, now live, aims to strengthen operational resilience across the interconnected financial system by directly overseeing CTPs. CTPs are expected to identify and manage risks, test resilience, and engage openly with regulators and firms, particularly during incidents, while firms must continue managing their dependencies on these critical services.

governance
agency report EU 8/10

The European Commission has made preliminary findings that TikTok is in breach of the Digital Services Act for failing to ensure safe accounts for minors.

The European Commission announced preliminary findings against TikTok on July 24, 2026, alleging a breach of the Digital Services Act (DSA). The breach concerns TikTok's failure to ensure safe accounts for minors, indicating a formal enforcement action is underway by the EU's primary regulatory body for online platforms. This action is part of the EU's broader effort to enforce digital regulations, implicitly affecting the AI systems used by large platforms for content moderation and user safety.

safety Effective: 2026-07-24
enforcement action EU 8/10

The European Commission fined Google €890 million for breaching the Digital Markets Act by self-preferencing its services and restricting alternative channels on Google Play.

The European Commission issued Google two fines totaling €890 million for violating the Digital Markets Act (DMA). The breaches include Google's self-preferencing of its own services in Google Search and imposing restrictions on businesses in Google Play that prevent them from directing consumers to alternative, potentially cheaper, purchasing options. This enforcement action highlights the EU's active stance in ensuring fair competition under the DMA.

competition eu ai act Effective: 2026-07-23
enforcement action IT 8/10

Italy's Garante fined two energy companies €7.72 million for denying contracts based on opaque scores, affirming individuals' right to know the basis of automated decisions.

The Italian Data Protection Authority (Garante) sanctioned Hera Comm Spa and EstEnergy Spa for a total of €7.72 million. The fines were imposed because the companies denied contracts based on a scoring system, and the Garante affirmed the right of individuals to be informed about the score that led to the denial, emphasizing transparency in automated decision-making affecting consumers.

transparency
agency report EU 8/10

The European Commission fined AliExpress €550 million for failing to diligently assess and mitigate risks of illegal, unsafe, or counterfeit products under the Digital Services Act.

The European Commission has fined AliExpress €550 million for failing to meet its obligations under the Digital Services Act (DSA). The platform was found to have breached its duty to diligently assess and mitigate risks associated with the sale of illegal, unsafe, or counterfeit products. This enforcement action highlights the EU's commitment to holding large online platforms accountable for consumer safety and product integrity.

liability eu dsa Effective: 2026-07-20
news analysis EU 8/10

The European Commission fined AliExpress €550 million for breaching the Digital Services Act.

The European Commission announced a €550 million fine against AliExpress for violating the Digital Services Act (DSA). This action highlights the Commission's active enforcement of the DSA against major online platforms.

Effective: 2026-07-20
enforcement action EU 8/10

The European Commission accepted X's action plan to comply with Digital Services Act transparency obligations and researcher data access requirements, following a prior breach and fine.

The European Commission has accepted X’s action plan addressing its breaches of the Digital Services Act regarding transparency and researcher data access. Following a December 2025 fine, X committed to improving its advertising repository and providing free, effective data access to eligible researchers, including allowing scraping of public data. X must implement these measures and submit an independent audit within six months.

transparency
enforcement action EU 8/10

The European Commission issued binding specification measures to Google under the Digital Markets Act, targeting AI interoperability on Android and Google Search data sharing.

The European Commission has taken a significant step by issuing binding measures against Google under the Digital Markets Act (DMA). These measures specifically address AI interoperability within Google's Android ecosystem and the sharing of data from Google Search, aiming to ensure fair competition and openness in the digital market, especially concerning AI technologies. This action creates immediate compliance obligations for Google.

competition eu ai act Effective: 2026-07-16
guidance US 8/10

CISA has issued an advisory for ABB Ability Edgenius, warning of a Linux kernel vulnerability (CVE-2026-31431) allowing privilege escalation in critical infrastructure.

The Cybersecurity and Infrastructure Security Agency (CISA) has released an advisory concerning a critical vulnerability (CVE-2026-31431) in ABB Ability Edgenius, an edge computing platform used in critical manufacturing that provides AI-driven recommendations. This Linux kernel flaw could allow a local attacker to gain root privileges and full control over affected systems. ABB has released an update (Edgenius 3.2.4.1) to fix the issue, and CISA recommends immediate application of the patch and implementing mitigations like limiting SSH access. This advisory highlights the ongoing cybersecurity risks in AI-enabled industrial control systems.

safety Effective: 2026-07-14
Page 1 of 185

Get daily alerts

Subscribe to receive daily intelligence briefs on the bills and regulations that matter to your team.

Start 14-day trial