Regulatory Change Tracker

The rules are changing faster than the stack.

Thirteen UK, EU and US regimes now shape how lawfully, and how easily, you can keep running on US-controlled infrastructure. Each is listed with what it asks of you and what it means for your stack.

Status

Jurisdiction

Showing 13 of 13 regimes. Regimes that apply in both the EU and the UK appear under either the EU filter or the UK filter.

DORA

high

EU · Operational resilience · In force · Jan 2025

Manage ICT concentration risk and prove a tested exit from every critical provider.

Relevance to your stack

If you are a financial entity, every critical ICT provider needs a documented, tested exit plan. Concentration on a single US hyperscaler is the exact risk the regime was written to address.

Read the official text

NIS2

high

EU · Cybersecurity · Transposing · 2024 to 2026

Be accountable for the security and sovereignty of your whole supply chain.

Relevance to your stack

Management is personally accountable for supply chain security. That extends past your direct vendors to the sub-processors they rely on.

Read the official text

EU AI Act

critical

EU · AI governance · Phasing · full application Aug 2026

Document AI data governance, sources and audit trails for high-risk systems.

Relevance to your stack

Applies to UK businesses placing AI systems on the EU market. Requires system classification, conformity assessment and an inventory of what data reaches which model.

Read the official text

Artificial Intelligence (Regulation) Bill

medium

UK · AI governance · Private member's bill · introduced Mar 2025

Prepare for a UK cross-sector AI framework, while sector regulators act under existing law.

Relevance to your stack

The UK still has no cross-sector AI statute. This is a private member's bill rather than a government one, so treat it as direction of travel. Existing regulators already expect an AI inventory and risk documentation under current law.

Read the official text

GDPR / UK GDPR

critical

EU/UK · Data protection · In force · since 2018

Have a lawful basis, a record of processing, and control over every processor you use.

Relevance to your stack

Every US tool holding personal data is a processor you must document, contract with and be able to account for. The obligation does not stop at your direct vendor.

Read the official text

Schrems II transfers

critical

EU/UK · International transfers · In force · CJEU ruling Jul 2020

Run a Transfer Impact Assessment before relying on any US-jurisdiction processor.

Relevance to your stack

Using a US-jurisdiction SaaS tool requires a documented Transfer Impact Assessment showing whether supplementary measures are sufficient given US surveillance law. Most organisations have never written one.

Read the official text

US CLOUD Act

critical

US · Government data access · In force · since 2018

Understand that EU data residency does not by itself put data beyond US legal reach.

Relevance to your stack

US authorities can compel a US-headquartered provider to produce data it controls, wherever in the world that data is stored. Choosing an EU region from a US provider does not remove this exposure.

Read the official text

EU Data Act

medium

EU · Data governance · Applicable · 12 Sep 2025

Remove cloud lock-in and block unlawful third-country government access to EU data.

Relevance to your stack

Gives you switching and portability rights against your cloud provider, and obliges providers to resist unlawful third-country access requests. Useful leverage when negotiating an exit.

Read the official text

Data (Use and Access) Act 2025

medium

UK · Data protection · In force · Part 5 from 5 Feb 2026

Work to the reformed UK regime, including its own test for international transfers.

Relevance to your stack

UK reform is done, not pending. The Act introduces a UK data protection test for transfers rather than the EU essential equivalence test. EU adequacy for the UK was renewed in December 2025 and runs to 27 December 2031.

Read the official text

EUCS

medium

EU · Cloud certification · Framework · Oct 2025

Meet residency, key-control and transparency criteria for cloud sovereignty.

Relevance to your stack

The common yardstick buyers increasingly ask about. Residency, key control and resistance to foreign legal compulsion are scored separately, so EU hosting alone does not pass.

Read the official text

eIDAS 2.0

low

EU · Digital identity · In force · wallet rolling out

Move toward sovereign identity and EU Digital Identity Wallet readiness.

Relevance to your stack

If your identity layer is Okta, Auth0 or Microsoft Entra, wallet acceptance and sovereign identity support become a roadmap question rather than a switch you can flip.

Read the official text

EU Digital Markets Act

low

EU · Competition · In force · Mar 2024

Use your new portability and interoperability rights against gatekeeper platforms.

Relevance to your stack

Works in your favour. If you depend on a designated gatekeeper, portability and interoperability obligations make an exit materially cheaper than it was.

Read the official text

Cloud & AI Development Act

medium

EU · Cloud certification · Proposed · 3 Jun 2026 · around Q4 2027

Prepare for four sovereignty assurance tiers tied to procurement eligibility.

Relevance to your stack

Grades sovereignty across four assurance levels and ties them to public procurement eligibility. If you sell to the public sector, your own stack becomes a bid qualifier.

Read the official text

Why this matters

6 critical or high-impact regimes are already in force or applying. Each shapes how lawfully, and how easily, you can keep running on US-jurisdiction providers. A formal compliance review with qualified counsel is the right next step.

This tool provides an indicative operational resilience analysis for informational purposes only, not legal advice, GDPR auditing or compliance certification. Confirm anything you act on with qualified counsel.

Prove your position

Know which of these actually apply to you.

Run the assessment and your answers are mapped to the regimes that care about the domains where you scored, with the gaps flagged.