Law / United States

United States

The United States has 55 states Each state has law of its own, on a page of its own. All 55 are listed below.

32 of 47 named instruments researched to a stage, across all six areas of law we track: 25 in force, 1 enacted but not yet in force and 6 proposed. As of 22 September 2026.

When they take effect25 of 32 carry a date, 7 do not. Earlier is before 2014.
Before 2014: 16 instruments (16 in force) earlier 2014: 0 instruments 2015: 2 instruments (2 in force) ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 2 instruments (2 in force) 2023: 1 instrument (1 in force) 2024: 1 instrument (1 in force) 2025: 2 instruments (2 in force) 2026: 1 instrument (1 in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blockedcourt decision

  1. AI law 2
  2. Privacy law 8
  3. Scraping law 2
  4. Cybersecurity law 4
  5. Age gating law 6
  6. News aggregation law 10

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law2 instruments, 2 proposed

Research summary (186 words)

As of 14 August 2026, no enacted federal statute imposes a general duty to disclose that content is AI-generated or to label or watermark synthetic output.

Federal action is narrow and piecemeal: the TAKE IT DOWN Act (2025) imposes a takedown, not a labeling, duty specific to nonconsensual intimate imagery including AI deepfakes, and is named here but deliberately not catalogued as an instrument, because tagging a victim-triggered removal duty as an AI-transparency obligation would report a federal labeling duty that does not exist to anything filtering this corpus by law family; an FCC rulemaking proposing AI-content disclosure in broadcast political ads was never finalized and its status under the current Commission is unresolved; and a bipartisan Senate bill, the AI Labeling Act of 2026, would impose a general labeling duty but has not moved past committee referral.

FTC Act Section 5 is deliberately excluded: it polices AI-related deception after the fact through the FTC's general unfair-or-deceptive-practices authority, and is not an affirmative disclosure or labeling mandate, so it does not belong in a transparency and output-labeling inventory even though it is sometimes tagged as disclosure-related.

AI transparency

AI Labeling Act of 2026

S. 4915, 119th Congressofficial GovInfo bill text (introduced version)

Proposed: draft date not recorded. In committee, dated 24 June 2026, as of 12 September 2026. Binds private bodies.

What this law does

As introduced, would require providers of generative AI systems to attach a visible disclosure to AI-generated image, video, and audio content, plus a machine-readable provenance record of the system used and the creation time, and would direct developers and major social media platforms to cooperate so users can identify content authenticity.

Introduced 24 June 2026 by a bipartisan group of senators and referred to the Senate Commerce Committee, with no committee vote or floor action found; it is the closest thing to a marquee federal AI-labeling proposal as of the date shown.

What it requires

FCC AI Political Ad Disclosure Rulemaking, Docket 24-211

FCC 24-74, MB Docket No. 24-211official Federal Register notice

Proposed: draft date not recorded. A published draft that has not reached a legislature, dated 5 August 2024, as of 12 September 2026. Binds private bodies.

What this law does

As proposed and never adopted as a final rule, would require on-air and written disclosure of AI-generated content in radio and television political advertisements by entities with existing public-file obligations.

The Notice of Proposed Rulemaking was adopted 10 July 2024 on a 3-2 party-line vote with the now-Chairman dissenting; whether the current, differently constituted Commission has formally terminated or continued the docket is not confirmed, so its procedural status remains open and it is treated here as stalled but not confirmed dead.

What it requires

Privacy law8 instruments, 8 in force

Research summary (228 words)

The United States has no comprehensive federal personal-data-protection statute; privacy protection at the federal level is sectoral, keyed to industry or data category (health under Health Insurance Portability and Accountability Act (HIPAA), financial services under Gramm-Leach-Bliley Act (GLBA), children's data under COPPA, video-viewing records under the Video Privacy Protection Act), with the FTC's Section 5 unfair-or-deceptive-practices authority as the general enforcement backstop.

No dedicated federal biometric-privacy statute exists, but two federal instruments now single out biometric identifiers, including voiceprints and facial images, for heightened, sector-specific treatment: the FTC's 2025 amended COPPA Rule for children's data and the DOJ's Data Security Program (28 CFR Part 202), the first general federal restriction on exporting sensitive personal data, effective April 8, 2025 against a defined list of countries of concern.

Breach notification duties are similarly sectoral (HIPAA, the amended GLBA Safeguards Rule), and the TAKE IT DOWN Act adds a federal duty to remove a nonconsensual intimate visual depiction of an identifiable person, authentic or AI-generated, within 48 hours of a valid request. The DOJ rule and the COPPA amendments are both still in their first year of enforcement, and several federal privacy and biometric bills remain pending in Congress.

Whether publicly available personal data is covered or carved out has no single federal answer: each sectoral statute draws its own line (GLBA excludes publicly available information from nonpublic personal information, while no general carve-out or coverage rule exists).

Breach notification

GLBA Safeguards Rule Breach Notification Amendment

16 CFR Section 314.4(j)eCFR, current regulatory text, 16 CFR Section 314.4(j)

In force since 13 May 2024. Binds private bodies.

What this law does

Requires a financial institution covered by the FTC's Safeguards Rule to notify the FTC as soon as possible, and no later than 30 days after discovery, of a security event involving unauthorized acquisition of unencrypted customer information affecting 500 or more consumers. The notification requirement in Section 314.4(j) took effect on May 13, 2024, per 16 CFR 314.5's own effective-date provision.

What it requires

HIPAA Breach Notification Rule

45 CFR Part 164, Subpart D (Sections 164.400-164.414)eCFR, current regulatory text, 45 CFR Part 164 Subpart D

In force since 23 September 2009. Binds public and private bodies.

What this law does

Requires a covered entity to notify each affected individual, and in some cases HHS and the media, following discovery of a breach of unsecured protected health information, without unreasonable delay and no later than 60 calendar days after discovery. First effective under a 2009 interim final rule; the 2013 Health Insurance Portability and Accountability Act (HIPAA) Omnibus Rule finalized these requirements with a general compliance date of September 23, 2013.

What it requires

Cross border transfer

DOJ Data Security Program (Bulk Sensitive Personal Data Rule)

28 CFR Part 202Federal Register final rule text, via govinfo.gov

In force since 8 April 2025. Binds private bodies.

What this law does

Prohibits U.S. persons from engaging in data-brokerage transactions involving bulk U.S. sensitive personal data or government-related data with a country of concern or covered person, and restricts, subject to required security measures, vendor, employment, and investment-agreement transactions that would give such a country or person access to bulk sensitive personal data, including biometric identifiers such as facial images or voice prints collected on more than 1,000 U.S. persons, or human genomic data on more than 100.

What it requires

Data subject rights

Children's Online Privacy Protection Rule (COPPA), including 2025 biometric identifier amendments

16 CFR Part 312, as amended effective June 23, 2025eCFR, current regulatory text, 16 CFR Part 312, and the Federal Register final rule for the 2025 amendments

In force since 21 April 2000. Binds private bodies.

What this law does

Requires operators of websites and online services directed to children under 13, or that have actual knowledge they are collecting personal information from such children, to give notice and obtain verifiable parental consent before collecting, using, or disclosing a child's personal information, and to give parents a means to review and delete it.

The FTC's 2025 amendments, effective June 23, 2025, add biometric identifiers, including voiceprints and facial templates, to the covered definition of personal information.

What it requires

Enforcement supervision

FTC Act Section 5, Unfair or Deceptive Acts or Practices (privacy and data-security enforcement)

15 U.S.C. Section 45Official U.S. Code text (Office of the Law Revision Counsel), 15 U.S.C. Section 45

In force since 26 September 1914. Binds private bodies.

What this law does

Prohibits unfair or deceptive acts or practices in or affecting commerce and empowers the FTC, not private plaintiffs, to investigate and enforce against them. This is the primary federal vehicle for privacy and data-security enforcement in the absence of a comprehensive statute, reaching misrepresentations about data collection or protection and unfair data practices that cause substantial, unavoidable consumer injury.

The Commission's 2023 Policy Statement on Biometric Information applies this authority to biometric identifiers, including those derived from photographs, videos, or voice recordings.

What it requires

Sensitive categories

HIPAA Privacy Rule

45 CFR Part 164, Subpart E (Sections 164.500-164.534)eCFR, current regulatory text, 45 CFR Part 164 Subpart E

In force since 14 April 2003. Binds public and private bodies.

What this law does

Restricts covered entities (health plans, health care clearinghouses, and most health care providers) and their business associates from using or disclosing protected health information except as the Rule permits or requires, and conditions most non-routine disclosures on individual authorization.

Its de-identification safe harbor is the one place federal law names biometric identifiers, including voice prints and full-face photographic images, as identifiers that must be stripped before health data is treated as de-identified.

What it requires

TAKE IT DOWN Act

Pub. L. 119-12, S. 146, 119th Cong. (2025)Official Congress.gov bill page for S.146, 119th Congress

In force 4 months, effective 19 May 2026. Binds public and private bodies.

What this law does

Criminalizes the knowing nonconsensual publication of an intimate visual depiction of an identifiable individual, including an AI-generated depiction, and requires covered platforms to establish a process to remove such content within 48 hours of a valid request from the depicted individual or their representative, enforced by the FTC as an unfair or deceptive practice. The Act's criminal prohibition on nonconsensual publication took effect immediately upon its enactment on May 19, 2025.

The Section 3 platform notice-and-removal duty described by this row's own penalty and enforcement fields did not take effect until May 19, 2026, one year after enactment.

What it requires

Video Privacy Protection Act

18 U.S.C. Section 2710Official U.S. Code text (Office of the Law Revision Counsel), 18 U.S.C. Section 2710

In force since 5 November 1988. Binds private bodies.

What this law does

Prohibits a video tape service provider from knowingly disclosing a consumer's personally identifiable information about video-viewing history to a third party without informed, written consent, and arms an aggrieved consumer with a private right of action for statutory damages of at least $2,500, punitive damages, and attorneys' fees.

A 2013 amendment allowed ongoing consent through an electronic means, enabling social-media sharing features; the statute has driven a large wave of litigation since 2022 over website tracking-pixel disclosures of video-viewing activity.

What it requires

Scraping law2 instruments, 2 in force

Research summary (690 words)

The United States has no federal scraping-specific statute.

Computer-misuse law is read narrowly for open-web scraping: the Ninth Circuit held in hiQ Labs v. LinkedIn (31 F.4th 1180, 2022, on remand after Van Buren v. United States, 593 U.S. 374, 2021) that the Computer Fraud and Abuse Act's without-authorization clause does not reach a computer presumptively open to all comers, though hiQ's own dispute ultimately ended in a stipulated judgment holding it liable on state contract and trespass claims instead.

There is no codified text-and-data-mining exception; fair use does that work and is currently split on appeal between a transformative-training holding (Bartz v. Anthropic, N.D. Cal. 2025) and a same-market, non-transformative holding against a directly competing product (Thomson Reuters v. ROSS Intelligence, D. Del., on appeal to the Third Circuit).

Fair use itself is not catalogued here as its own instrument, for the same reason as FTC Act Section 5 below: 17 U.S.C. Section 107 sits under the aggregation topic, and an instrument takes exactly one topic. Two consequences of that doctrine matter most to a scraper.

Train only on content acquired legally, because training on pirated copies was held outside fair use regardless of how transformative the model is; and treat training a product that competes directly with the scraped source, on that source's own compiled work product, as the fact pattern where fair use has actually failed.

There is no general federal privacy statute reaching scraped personal data and no sui generis database right, the latter because Feist Publications v. Rural Telephone (499 U.S. 340, 1991) holds copyright protects only originality in selection and arrangement and never facts themselves, so a scraped factual compilation's only protection, if any, is contract or state misappropriation law; state law fills both gaps, so California, Colorado, and Utah have their own pages.

State common-law torts, not federal statute, are the durable route once a target objects: trespass to chattels requires actual interference with system operation, and the century-old International News Service misappropriation doctrine survives narrowly through a five-factor hot-news test.

FTC Act Section 5 (15 U.S.C. § 45) is the federal enforcement vehicle for unfair or deceptive use of scraped personal data, and it is what stands in for a general federal privacy statute: there is no publicly-available exemption to define, because there is no general statute to exempt from, unlike PIPL Art. 27 or General Data Protection Regulation (GDPR) Art. 6(1)(f); it is not catalogued here as its own instrument because it sits under the privacy topic, and an instrument takes exactly one topic.

Terms of service are enforceable against a scraper on a conspicuous-notice test rather than a categorical rule: a browsewrap binds only where the site gave reasonably conspicuous notice and the user manifested assent, the line drawn in Specht v. Netscape Communications (2d Cir. 2002) and Nguyen v. Barnes and Noble (9th Cir. 2014), and applied again in Chabolla v. ClassPass (9th Cir., Feb.

27, 2025, split 2-1, secondary-sourced), which held a sign-in wrap unenforceable because the terms sat in small grey type outside the sign-up flow and the action button said nothing about agreeing. Meta Platforms v. Bright Data is not authority on that question: Bright Data held registered accounts and had clicked to agree, so the court decided the scope of terms already formed, holding that terms governing a user's own use did not reach scraping performed while logged off.

That belongs to whether logging in changes the analysis, which it does, rather than to whether a browsewrap forms a contract at all. robots.txt carries no independent federal legal weight; that dimension is a genuine gap here, not a considered no-effect finding.

No federal statute yet governs using scraped data to train an artificial-intelligence model, though a bill introduced in the 119th Congress, the TRAIN Act (S. 2455, with a House companion, H.R. 7209), would create a subpoena process letting copyright owners learn whether their works were used to train a model, and remains before committee with no vote taken; the training question is instead decided today under the general copyright fair-use doctrine described above, and because no codified text-and-data-mining exception exists, no opt-out mechanism against mining is recognized either.

Computer misuse

Computer Fraud and Abuse Act (unauthorized access and the gates-based authorization test)

18 U.S.C. § 1030official text, Office of the Law Revision Counsel (uscode.house.gov)

In force since 12 October 1984. Binds public and private bodies.

What this law does

The Computer Fraud and Abuse Act (CFAA) prohibits intentionally accessing a protected computer without authorization, or exceeding authorized access.

The Supreme Court held in Van Buren v. United States (593 U.S. 374, 2021) that exceeding authorized access is a gates-up-or-down inquiry into files or areas an existing permission structure puts off limits, not a purpose-based test, and the Ninth Circuit held in hiQ Labs v. LinkedIn (31 F.4th 1180, 2022) that without authorization does not reach a computer presumptively open to all comers, so a public, unauthenticated page has erected no gate at all.

The line runs through revocation: in Facebook v. Power Ventures (844 F.3d 1058, 9th Cir. 2016), discussed inside the hiQ opinion, liability attached once the scraper, after an individualized cease-and-desist, circumvented an IP block to keep reaching password-protected profiles. hiQ's own case did not end there: on remand it entered a stipulated consent judgment (N.D. Cal., filed Dec.

2022, secondary-sourced) holding it liable for breaching LinkedIn's User Agreement and for California trespass to chattels and misappropriation, for $500,000 and a permanent injunction, despite winning the CFAA claim outright. Section 1030 was added by the Counterfeit Access Device and Computer Fraud and Abuse Act of 1984, Pub.

L. 98-473, title II, § 2102(a); the without-authorization and exceeds-authorized-access language the courts above construe was already present in that original 1984 enactment, so the section dates to its original commencement rather than to the 1986 amendments that broadened its reach to protected computers generally.

What it requires

Digital Millennium Copyright Act, anti-circumvention provisions

17 U.S.C. § 1201official text, Office of the Law Revision Counsel (uscode.house.gov)

In force since 28 October 1998. Binds public and private bodies.

What this law does

Section 1201 prohibits circumventing a technological measure that effectively controls access to a copyrighted work. It functions as an escalation point rather than a scraping-specific rule: it is invoked once a target has put up a technical access barrier and a collector defeats it, the same fact pattern that also triggers Computer Fraud and Abuse Act (CFAA) and state computer-misuse exposure once notice and continued access or circumvention are shown, as in Facebook v. Power Ventures.

Section 1201 was added by title I of the Digital Millennium Copyright Act, Pub. L. 105-304, approved October 28, 1998; the anti-circumvention prohibition in subsection (a)(1)(A) itself carried a built-in two-year delayed effective date, so it did not bind conduct until October 28, 2000, the same window in which the Librarian of Congress ran the first rulemaking under subsection (a)(1)(C) to identify exempt classes of works.

What it requires

Cybersecurity law4 instruments, 3 in force, 1 enacted but not yet in force

Research summary (834 words)

At the federal layer the United States has no single cross-sector product-security or cyber-resilience statute comparable to the Cyber Resilience Act or the United Kingdom's Product Security and Telecommunications Infrastructure Act.

What exists instead is a set of regimes that each bind a specifically defined class of regulated entity, a financial institution, an Securities and Exchange Commission (SEC) reporting company, a critical-infrastructure operator, or a medical-device sponsor, rather than any developer who simply ships or distributes software.

The Federal Trade Commission's Safeguards Rule under the Gramm-Leach-Bliley Act, 16 CFR 314.3 and 314.4(a) through (i), requires a financial institution over which the FTC has jurisdiction under Gramm-Leach-Bliley Act section 505(a)(7) to develop, implement, and maintain a written information security program: a designated Qualified Individual, a periodic risk assessment, access controls, encryption of customer information, multi-factor authentication, oversight of service providers, a written incident response plan, and at least annual reporting to the board of directors.

The Rule's separate breach-notification duty, 16 CFR 314.4(j), effective May 13, 2024, is already this jurisdiction's privacy row and is not repeated here.

The Securities and Exchange Commission requires an SEC reporting company to describe its cybersecurity risk management processes and its board's and management's oversight of cybersecurity risk in its annual report under Item 106 of Regulation S-K, and to report, within four business days of determining that a cybersecurity incident is material, that incident under Item 1.05 of Form 8-K. The Cyber Incident Reporting for Critical Infrastructure Act of 2022, 6 U.S.C. 681b, enacted in March 2022, directs the Cybersecurity and Infrastructure Security Agency to issue regulations requiring a covered entity across sixteen critical-infrastructure sectors to report a covered cyber incident within 72 hours and a ransom payment within 24 hours, but the Agency has not yet published the final rule implementing that duty.

Nobody is bound to report under it until the rule takes effect, and the statute is recorded below at the stage it has actually reached rather than the one it will reach: the proposed rule is docket CISA-2022-0010, published 4 April 2024, the statutory deadline for a final rule passed on 4 October 2025, and the Agency held further town halls in June 2026 before finalising.

Section 524B of the Federal Food, Drug, and Cosmetic Act, 21 U.S.C. 360n-2, in effect since March 29, 2023, requires the sponsor of a premarket submission for a cyber device (a device with sponsor-installed software, internet connectivity, and a technological characteristic that could be vulnerable to a cybersecurity threat) to submit a plan for monitoring and coordinated disclosure of postmarket vulnerabilities, maintain secure design and patching processes, and provide a software bill of materials; the Food and Drug Administration administers this as a premarket-submission completeness requirement rather than through a separate penalty schedule.

There is no general federal statute imposing a reasonable-security duty on a business simply because it holds personal data; the closest analogue is the Federal Trade Commission's own Section 5 unfairness authority applied to data-security failures, already this jurisdiction's privacy row rather than a second row here, since that row already carries the general federal privacy and data-security enforcement vehicle rather than being split the way a state safeguards statute is split between the two topics.

The Internet of Things Cybersecurity Improvement Act of 2020, Public Law 116-207, is a federal-procurement standard rather than a market-wide manufacturer duty: since December 5, 2022 it bars a federal agency, not a manufacturer, from procuring or renewing a contract for an Internet of Things device that does not meet standards the National Institute of Standards and Technology developed under the Act, so it does not reach a vendor who sells only outside the federal government.

None of the regimes above creates a private right of action. The National Institute of Standards and Technology's Cybersecurity Framework and the Federal Communications Commission's Cyber Trust Mark labeling program are voluntary and are not law. Two further federal incident regimes are recorded below.

The banking agencies' joint computer-security incident notification rule, adopted by the Office of the Comptroller of the Currency, the Federal Reserve Board and the Federal Deposit Insurance Corporation in identical terms and in force since 1 May 2022, requires a banking organization to notify its primary federal regulator within 36 hours of determining that a notification incident has occurred, and requires a bank service provider, which is where a cloud or AI vendor serving a bank is reached, to notify each affected bank customer as soon as possible once a disruption lasting four hours or more is determined or likely.

DFARS 252.204-7012, the clause 48 CFR 204.7304 requires in every Department of Defense contract in its scope, requires a contractor to report a cyber incident within 72 hours of discovering it and to preserve forensic images for at least 90 days from submitting that report. The lint does not reach that clause: its bound party is a defense contractor, a class no role in the activity vocabulary names, and it is recorded here with no activity flagged rather than flagged on a guess.

Vulnerability and incident reporting

Computer-Security Incident Notification Requirements for Banking Organizations and Their Bank Service Providers

12 CFR Part 53 (OCC); 12 CFR Part 225, Subpart N (Federal Reserve Board); 12 CFR Part 304, Subpart C (FDIC)Electronic Code of Federal Regulations

In force since 1 May 2022. Binds private bodies.

What this law does

The Comptroller of the Currency, the Federal Reserve Board, and the Federal Deposit Insurance Corporation issued this Computer-Security Incident Notification rule as one joint final rule, codified in parallel at 12 CFR Part 53 for the Comptroller, 12 CFR Part 225, Subpart N for the Board, and 12 CFR Part 304, Subpart C for the Corporation. For the Comptroller, a banking organization is a national bank, Federal savings association, or Federal branch or agency of a foreign bank.

For the Board, a banking organization is a bank holding company, savings and loan holding company, state member bank, the United States operations of a foreign banking organization, or an Edge or agreement corporation. For the Corporation, a banking organization is an insured state nonmember bank, insured state licensed branch of a foreign bank, or insured State savings association.

None of the three agencies treats a designated financial market utility as a banking organization or as a bank service provider. A bank service provider is a bank service company or other person that performs covered services under the Bank Service Company Act. A computer-security incident is any occurrence that results in actual harm to the confidentiality, integrity, or availability of an information system or the information the system processes, stores, or transmits.

A notification incident is a computer-security incident that has materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade, a banking organization's ability to carry out banking operations, activities, or processes, or to deliver banking products and services to a material portion of its customer base, a business line whose failure would result in a material loss of revenue, profit, or franchise value, or operations whose failure or discontinuance would threaten the financial stability of the United States.

A banking organization must notify its primary federal regulator about a notification incident as soon as possible and no later than 36 hours after the banking organization determines that a notification incident has occurred.

A bank service provider must separately notify at least one bank-designated point of contact at each affected banking organization customer as soon as possible when the bank service provider determines that it has experienced a computer-security incident that has materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade, covered services provided to that banking organization for four or more hours.

This bank service provider notification duty does not apply to scheduled maintenance, testing, or a software update previously communicated to the banking organization customer. The rule's own regulatory text became effective on April 1, 2022. Both notification duties began binding their subjects on the May 1, 2022 compliance date.

What it requires

Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA)

6 U.S.C. 681-681g (CIRCIA)United States Code, 6 U.S.C. 681b, official House Office of the Law Revision Counsel text

Commencement not set. Binds public and private bodies.

What this law does

The Cyber Incident Reporting for Critical Infrastructure Act of 2022 is a federal statute enacted March 15, 2022 that would require a covered entity to report a covered cyber incident and a ransom payment to the Cybersecurity and Infrastructure Security Agency. A covered entity must report a covered cyber incident to the Agency not later than 72 hours after the covered entity reasonably believes the incident has occurred.

A covered entity that makes a ransom payment must report the payment to the Agency not later than 24 hours after the payment is made, even where the underlying attack is not itself a covered cyber incident. A covered entity must also submit a prompt supplemental report whenever substantial new information becomes available or a later ransom payment is made, continuing until the covered entity reports the incident concluded, and must preserve data relevant to the incident or payment.

The statute leaves the definition of covered entity, and the effective date of all four of these duties, to a final rule the Agency must issue. The Agency published a notice of proposed rulemaking on April 4, 2024 at 89 FR 23644, docket CISA-2022-0010, proposing to define covered entity by a small-business size standard or by one of several sector-based criteria across sixteen critical infrastructure sectors.

The statute required the Agency to issue the final rule not later than 18 months after that publication, a deadline of October 4, 2025, and the Agency has not met it. As of September 20, 2026 the Agency has not published a final rule, and its own published status page states that it continues to work on the final rule after multiple lapses in its own funding disrupted the rulemaking.

Until the final rule takes effect none of these four duties binds anyone, and the Agency asks entities only to volunteer cyber incident information in the meantime.

The proposed rule states that a cloud service provider or a managed service provider is not itself obligated to report merely because a compromise of its own systems caused the impact at a customer, since the reporting duty runs to the covered entity whose systems were affected rather than to the vendor, unless that vendor independently meets the covered-entity criteria in its own right.

What it requires

SEC Cybersecurity Risk Management, Governance, and Incident Disclosure (Regulation S-K Item 106; Form 8-K Item 1.05)

17 CFR 229.106; 17 CFR 249.308 (Form 8-K Item 1.05)Electronic Code of Federal Regulations

In force since 18 December 2023. Binds private bodies.

What this law does

An Securities and Exchange Commission (SEC) reporting company must describe, in its annual report under Regulation S-K Item 106, its processes for assessing and managing cybersecurity risk. It must also describe its board's and management's oversight of that risk. This duty applies beginning with annual reports for fiscal years ending on or after December 15, 2023. Under Item 1.05 of Form 8-K, the same company must determine, without unreasonable delay after discovering a cybersecurity incident, whether the incident is material.

If the incident is material, the company must file a Form 8-K describing it within four business days of that determination. The United States Attorney General may authorize a delay of up to 30 days, and a further 30 days, where disclosure would pose a substantial risk to national security or public safety, and in extraordinary circumstances a final 60 days where the continuing risk is to national security, up to 120 days in total.

Registrants other than smaller reporting companies had to comply with Item 1.05 from December 18, 2023, and smaller reporting companies from June 15, 2024.

What it requires

Safeguarding Covered Defense Information and Cyber Incident Reporting (DFARS 252.204-7012)

48 CFR 252.204-7012Electronic Code of Federal Regulations, 48 CFR 252.204-7012, current text as amended through May 30, 2024 (89 FR 46821)

In force since 26 August 2015. Binds private bodies.

What this law does

The clause requires a contractor to provide adequate security on every covered contractor information system that processes, stores, or transmits covered defense information. For a system that is not part of an information technology service the government operates on its own behalf, that duty means implementing the safeguards in NIST Special Publication 800-171. The contractor must rapidly report a cyber incident, defined as reporting within 72 hours of discovery of the incident.

That report is made to the Department of Defense at its DIBNet portal, dibnet.dod.mil. Filing that report requires a DoD-approved medium assurance certificate. The contractor must preserve and protect forensic images of the affected information systems and related monitoring and packet-capture data for at least 90 days from the date it submits the cyber incident report.

Malicious software isolated in connection with a reported incident must be submitted to the Department of Defense Cyber Crime Center rather than to the contracting officer. The clause must be included without alteration in a subcontract that involves covered defense information or operationally critical support, including a subcontract for a commercial product or service.

A contractor using an external cloud service provider must require that provider to meet security requirements equivalent to the FedRAMP Moderate baseline and to comply with the clause's duties on incident reporting, malicious software, media preservation, forensic access, and damage assessment.

What it requires

Age gating law6 instruments, 2 in force, 4 proposed

Research summary (128 words)

Federal law addresses children's online privacy mainly through the Children's Online Privacy Protection Act (COPPA) and its 2025 FTC rule amendments, which require verifiable parental consent before a covered operator collects personal information from a child under 13. Congress has not enacted a comprehensive age verification, social media minor access, or app store age verification statute.

The House passed the Kids Internet and Digital Safety (KIDS) Act in June 2026, consolidating the Kids Online Safety Act and COPPA 2.0 among other bills, while the Senate's standalone Kids Online Safety Act (which passed the Senate 91-3 in the 118th Congress) remains in committee, and a bipartisan federal App Store Accountability Act has been introduced in both chambers. None of the pending bills had become law as of July 2026.

Age-appropriate design code

S. 1748, Kids Online Safety Act (KOSA)

S. 1748, 119th Congressofficial bill text and status, Congress.gov

Proposed: draft date not recorded. In committee, dated 5 August 2026, as of 12 September 2026. Binds private bodies.

What this law does

Would impose a duty of care on covered online platforms to prevent and mitigate specified harms to minors, require default safeguards and parental tools for known minors, and mandate transparency reporting. An earlier version passed the Senate 91-3 in July 2024 (118th Congress) but died in the House.

Reintroduced May 14, 2025 by Senators Blackburn and Blumenthal with Senate leadership support; pending in the Senate Commerce Committee as of July 2026, and partially consolidated into the House-passed KIDS Act without its duty of care provision.

Note and primary source

App store age verification (AV)

H.R. 3149, App Store Accountability Act (federal)

H.R. 3149, 119th Congressofficial bill text, Congress.gov

Proposed: draft date not recorded. In committee, dated 11 December 2025, as of 13 September 2026. Binds private bodies.

What this law does

Would require a covered app store provider (one with 5,000,000 or more United States users) to verify a user's age category and, for a minor, obtain verifiable parental consent before the minor may download or purchase an app or make an in-app purchase, and would require an app developer to rely on the app store's age-category signal and honor its parental-consent status.

Preempts state app store age-verification laws and designates the Federal Trade Commission as primary enforcer, with state attorneys general also authorized to sue. Forwarded, as amended, by the House Energy and Commerce Subcommittee on Commerce, Manufacturing, and Trade to the full Committee on December 11, 2025; the full Committee has not reported it as of September 2026.

Note and primary source

S. 1586, App Store Accountability Act (federal)

S. 1586, 119th Congressofficial bill text, Congress.gov

Proposed: draft date not recorded. In committee, dated 1 May 2025, as of 13 September 2026. Binds private bodies.

What this law does

Companion bill to H.R. 3149 with identical text as introduced. Would require a covered app store provider (one with 5,000,000 or more United States users) to verify a user's age category and, for a minor, obtain verifiable parental consent before the minor may download or purchase an app or make an in-app purchase, and would require an app developer to rely on the app store's age-category signal and honor its parental-consent status.

Preempts state app store age-verification laws and designates the Federal Trade Commission as primary enforcer, with state attorneys general also authorized to sue. Read twice and referred to the Senate Committee on Commerce, Science, and Transportation on May 1, 2025; no committee action has been recorded since.

Note and primary source

Social media and minors

Amended COPPA Rule (2025)

16 C.F.R. Part 312, as amended, 90 Fed. Reg. 16918 (Apr. 22, 2025)Federal Register final rule

In force since 23 June 2025. Binds private bodies.

What this law does

Requires separate verifiable parental consent for disclosing a child's personal information to third parties for targeted advertising, adds a text plus consent method, and expands recordkeeping and data retention limits. Operators had until April 22, 2026 to come into full compliance.

Note and primary source

H.R. 7757, Kids Internet and Digital Safety (KIDS) Act

H.R. 7757, 119th Congressofficial bill text and status, Congress.gov

Proposed: draft date not recorded. Before the second chamber, dated 13 July 2026, as of 12 September 2026. Binds private bodies.

What this law does

Consolidates the Kids Online Safety Act, the Children and Teens' Online Privacy Protection Act (COPPA 2.0), a data broker registry, and other child safety bills. Would require default privacy and safety settings for minors, age verification for access to mature content, and AI chatbot disclosure. Passed the House 267-117 on June 29, 2026, without KOSA's original duty of care provision; pending in the Senate.

Note and primary source

News aggregation law10 instruments, 10 in force

Research summary (204 words)

United States federal law does not recognize a press-publisher neighbouring right or any mandatory platform-publisher compensation framework. No equivalent to the EU's Article 15 Digital Single Market (DSM) Directive exists.

The primary legal framework for news aggregation is the Copyright Act's four-factor fair-use doctrine (17 U.S.C. § 107), applied case-by-case: search-engine thumbnails (Perfect 10, 2007) and book-indexing snippets (Authors Guild v. Google, 2015) qualify as transformative fair use, while commercial news-clipping services that substitute for licensed feeds do not (AP v. Meltwater, 2013).

The hot-news misappropriation doctrine, originating in INS v. Associated Press (1918) as a federal common-law unfair-competition claim, survives today only as a narrow state common-law cause of action, but the Second Circuit in Barclays Capital v. Theflyonthewall.com (2011) held that most such claims are preempted by § 301 unless they contain genuine 'extra elements' beyond copyright's exclusive rights.

The Journalism Competition and Preservation Act (JCPA), which would have created an antitrust safe harbor for collective publisher bargaining with large platforms, died in the 118th Congress in January 2025 without a floor vote. Automated scraping of publicly available news pages does not violate the Computer Fraud and Abuse Act per the Ninth Circuit (hiQ v. LinkedIn, 2022), though copyright infringement and breach-of-contract claims remain viable.

Hot news misappropriation

Barclays Capital Inc. v. Theflyonthewall.com, Inc.

650 F.3d 876 (2d Cir. 2011)FindLaw Second Circuit

Decided 20 June 2011 by the U.S. Court of Appeals for the Second Circuit. Binds public and private bodies.

What this court held

The Second Circuit reversed the district court and held that Barclays' hot-news misappropriation claim against a financial news aggregator that redistributed analyst recommendations was preempted by the Copyright Act.

The court narrowed the NBA v. Motorola test: a defendant must itself 'endeavor to free-ride on the plaintiff's gathering efforts,' and merely redistributing information already gathered is insufficient to survive § 301 preemption, largely confining viable hot-news claims to situations where the defendant competes in the gathering itself.

Note and primary source

Copyright Act, federal preemption, 17 U.S.C. § 301

17 U.S.C. § 301Legal Information Institute (Cornell)

In force since 1 January 1978. Binds public and private bodies.

What this law does

Section 301 preempts all state law rights that are equivalent to the exclusive rights under the Copyright Act in works fixed in a tangible medium. Under Barclays Capital, most state hot-news misappropriation claims are preempted unless they contain genuine 'extra elements' beyond the act of copying and redistributing protected expression. There is no US federal press-publisher neighbouring right.

The EU-style ancillary copyright (Article 15 Digital Single Market (DSM) Directive) has no counterpart in US federal law, and § 301 blocks states from creating functional equivalents.

Note and primary source

International News Service v. Associated Press

248 U.S. 215 (1918)Cornell LII full-text mirror of 248 U.S. 215 (this instrument's url)

Decided 23 December 1918 by the Supreme Court of the United States. Binds public and private bodies.

What this court held

The Supreme Court held that a wire service copying factual news content from a competitor's public bulletins and distributing it to customers constituted actionable unfair competition (misappropriation), even though bare facts are not copyrightable. This decision established the 'hot-news' doctrine, though the Supreme Court later abandoned federal common law in Erie R.R. v. Tompkins (1938), leaving hot-news claims to state law and Copyright Act preemption analysis.

Note and primary source

National Basketball Association v. Motorola, Inc.

105 F.3d 841 (2d Cir. 1997)openjurist.org full-text mirror of 105 F.3d 841 (this instrument's url)

Decided 30 January 1997 by the U.S. Court of Appeals for the Second Circuit. Binds public and private bodies.

What this court held

The Second Circuit articulated a five-element test for a hot-news misappropriation claim to survive Copyright Act § 301 preemption: (1) plaintiff generates time-sensitive information at cost; (2) the information is highly time-sensitive; (3) defendant free-rides on plaintiff's efforts; (4) defendant offers a direct substitute; and (5) free-riding threatens plaintiff's continued incentive to produce.

Motorola's real-time sports pager service passed none of the elements and was found not to misappropriate NBA game scores.

Note and primary source

Snippet reproduction

Associated Press v. Meltwater U.S. Holdings, Inc.

931 F. Supp. 2d 537 (S.D.N.Y. 2013)Justia district court

Decided 21 March 2013 by the U.S. District Court for the Southern District of New York. Binds public and private bodies.

What this court held

Judge Denise Cote held that Meltwater's commercial news-monitoring service, which crawled publisher websites and delivered headlines, ledes, and excerpts to paid enterprise subscribers, was not protected by fair use. Unlike a search engine, Meltwater did not transform the content but directly substituted for AP's licensed syndication feed, failing three of the four fair-use factors.

The decision is the leading case establishing that commercial snippet aggregation targeting the news-licensing market is copyright infringement.

Note and primary source

Authors Guild, Inc. v. Google, Inc.

804 F.3d 202 (2d Cir. 2015)Justia appellate

Decided 16 October 2015 by the U.S. Court of Appeals for the Second Circuit. Binds public and private bodies.

What this court held

The Second Circuit held that Google's mass digitization of tens of millions of books and display of limited snippets in search results constituted transformative fair use, because the scanning created new public benefit (full-text search, computational corpus analysis) without substantially substituting for sales of original works.

The case is the leading authority establishing that large-scale ingestion of copyrighted works for indexing and limited display can be fair use, which informs how courts evaluate news aggregation and AI training on news corpora.

Note and primary source

Copyright Act, fair use, 17 U.S.C. § 107

17 U.S.C. § 107Legal Information Institute (Cornell)

In force since 1 January 1978. Binds public and private bodies.

What this law does

The federal fair-use statute is the primary framework for evaluating whether news aggregators, search engines, and AI training pipelines may reproduce copyrighted content without a license. Courts weigh four factors: purpose and character of the use (especially transformativeness), nature of the copyrighted work, amount and substantiality taken, and effect on the market for the original.

Commercial, non-transformative snippet aggregation that substitutes for licensed feeds fails fair use (Meltwater); transformative indexing and limited display may succeed (Google Books, Perfect 10).

Note and primary source

Perfect 10, Inc. v. Amazon.com, Inc.

508 F.3d 1146 (9th Cir. 2007)CourtListener full-text mirror of 508 F.3d 1146 (this instrument's url)

Decided 3 December 2007 by the U.S. Court of Appeals for the Ninth Circuit. Binds public and private bodies.

What this court held

The Ninth Circuit held that Google's thumbnail-sized image search results were highly transformative fair use because they function as pointers to information rather than substitutes for original images. The court also articulated the 'server test': inline linking or framing of images hosted on a third-party server does not constitute copyright infringement by the linker because the linker does not copy or serve the underlying content. This is the foundational authority on linking and framing liability in the Ninth Circuit.

Note and primary source

Text and data mining (TDM) opt-out

Field v. Google, Inc.

412 F. Supp. 2d 1106 (D. Nev. 2006)CourtListener database (this instrument's url) confirms the citation, 412 F. Supp. 2d 1106, and a decision date of 2006-01-19.

Decided 19 January 2006 by the U.S. District Court for the District of Nevada. Binds public and private bodies.

What this court held

The court granted Google summary judgment, holding that caching of copyrighted web pages was both fair use and covered by an implied license. Because the plaintiff was aware of the industry-standard robots.txt and noarchive meta-tag protocols for excluding crawlers and chose not to deploy them, he impliedly consented to Google's caching, establishing that robots.txt opt-out is a legally meaningful mechanism for controlling search-engine indexing and snippet display.

Note and primary source

hiQ Labs, Inc. v. LinkedIn Corp.

938 F.3d 985 (9th Cir. 2019), affirmed on remand (9th Cir. Apr. 18, 2022)Decision date April 18, 2022 confirmed from search results

Decided 18 April 2022 by the U.S. Court of Appeals for the Ninth Circuit. Binds public and private bodies.

What this court held

The Ninth Circuit held that automated scraping of publicly accessible web pages does not violate the Computer Fraud and Abuse Act (18 U.S.C. § 1030) because a website that permits general public access implicitly authorizes access to that public data, meaning 'without authorization' under the Computer Fraud and Abuse Act (CFAA) requires more than a cease-and-desist.

Publishers cannot rely on the CFAA alone to block news aggregators from indexing publicly available content, though state contract claims and copyright infringement claims remain live theories.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.