Regulatory Updates

Stay Current on AI & Privacy Regulation

We track state and federal regulatory changes affecting AI governance and privacy compliance, and share updates here as they develop.

Stay Current on AI & Privacy Regulation

AI and privacy requirements continue to evolve across federal and state jurisdictions. We monitor regulatory developments, enforcement activity, and new compliance requirements to help organizations understand what is changing and what actions they may need to take.

Latest Regulatory Updates

California CCPA Regulations Take Effect

Privacy | California | January 1, 2026

California's updated CCPA regulations took effect on January 1, 2026. The changes introduce requirements covering privacy risk assessments, cybersecurity audits, and automated decisionmaking technology (ADMT), with certain requirements phased in over subsequent years.

What organizations should consider: Review data-processing activities, risk assessment processes, consumer rights workflows, and AI-driven decisionmaking practices to determine whether the new requirements apply.

New U.S. Federal Direction on AI Innovation & Security

AI Governance | Federal | June 2, 2026

A June 2, 2026 Executive Order established additional federal direction for advancing AI innovation, cybersecurity, and the use of AI across government and critical infrastructure.

What organizations should consider: Continue monitoring federal AI policy developments while strengthening AI governance, security controls, risk management, and accountability practices.

Federal AI Policy Framework Continues to Develop

AI Governance | Federal | March 2026

The White House released legislative recommendations for a national policy framework for artificial intelligence in March 2026, addressing areas including AI innovation, national security, and the regulatory environment.

What organizations should consider: Organizations using or developing AI should maintain adaptable governance programs that can respond to evolving federal and state requirements.

FTC Enforcement Highlights Risks in AI Marketing Claims

AI & Privacy | Federal | May 21, 2026

The Federal Trade Commission announced settlements involving companies accused of making deceptive claims about an AI-powered advertising service and the collection and use of consumer information.

What organizations should consider: Validate AI-related marketing claims, data-use disclosures, consent practices, and representations made to customers before deploying or promoting AI-enabled products.

What These Changes Mean for Your Organization

Regulatory developments can affect more than legal teams. Changes may require updates to AI governance frameworks, privacy notices, data inventories, vendor agreements, risk assessments, employee training, and incident response procedures.

Our regulatory monitoring helps organizations move from awareness to action by identifying relevant requirements and translating them into practical compliance steps.

Areas We Monitor

AI Governance
AI regulations, governance requirements, risk management, transparency, security, and emerging standards.

Privacy Compliance
State and federal privacy laws, consumer rights, data processing requirements, notices, and contractual obligations.

Enforcement & Regulatory Actions
Significant enforcement actions, regulatory guidance, settlements, and compliance trends that may affect organizations.

Upcoming Requirements
Important effective dates, compliance deadlines, and regulatory changes organizations should prepare for in advance.

Need Help Interpreting a Regulatory Change?

Our team can help assess how emerging AI and privacy requirements may apply to your organization and identify practical next steps.

Explore Our AI Governance & Privacy Compliance Services