Currently free during beta - premium features coming soon. Subscribe now to lock in early access.
Live Monitoring

EU Regulatory Change Monitoring & Compliance Tracker

Free regulatory monitoring tool tracking DORA, NIS2, GDPR, EU AI Act, and 20 more compliance frameworks. AI-powered summaries from 18 official sources. Weekly digest delivered every Monday.

EU AI Act enforcement: Aug 2026 DORA RTS live now Data Act: Sep 2026
4430
Changes Tracked
24
Frameworks
18
Official Sources
21/25
Feeds Healthy
What we monitor

Built for compliance teams

Everything you need to stay on top of regulatory changes.

Real-time Monitoring

Daily automated scans of 18 official regulatory sources including EUR-Lex, EBA, EDPB, ESMA, BaFin, BSI, ANSSI, and more.

24 Frameworks

Intelligent matching across DORA, NIS2, GDPR, EU AI Act, CRA, DSA, and more using CELEX codes and keyword analysis.

AI Summaries

Every regulatory change gets an AI-generated plain-language summary explaining what changed, who's affected, and what to do.

Weekly Digest

Curated weekly email with all changes grouped by framework. AI summaries included. Delivered every Monday.

Three-Tier Matching

CELEX exact match, CELEX prefix detection for delegated acts, and keyword analysis. High-confidence results you can trust.

Instant Alerts

Get notified immediately when critical regulatory changes are detected. Never miss an important update.

Frameworks

Covering the regulations that matter

DORA

Digital Operational Resilience Act · 55 changes

NIS2

Network and Information Security Directive · 12 changes

GDPR

General Data Protection Regulation · 9 changes

CSRD

Corporate Sustainability Reporting Directive · 1 changes

MaRisk

MaRisk (Minimum Requirements for Risk Management) · 8 changes

ISO27001

ISO/IEC 27001 Information Security

EU_AI_ACT

EU Artificial Intelligence Act · 8 changes

CRA

Cyber Resilience Act · 152 changes

DSA

Digital Services Act · 6 changes

DMA

Digital Markets Act · 23 changes

eIDAS2

eIDAS 2.0 (EU Digital Identity) · 2 changes

SOC2

SOC 2 (Service Organization Controls)

PCI_DSS

PCI DSS (Payment Card Industry)

HIPAA

HIPAA (Health Insurance Portability)

ISO42001

ISO/IEC 42001 AI Management System

AMLD6

6th Anti-Money Laundering Directive · 2 changes

PSD3

Payment Services Directive 3 / PSR

DATA_ACT

EU Data Act · 2 changes

GPSR

General Product Safety Regulation

CER

Critical Entities Resilience Directive · 4 changes

EUDR

EU Deforestation Regulation · 1 changes

CVE

Vulnerabilities & CVEs · 709 changes

BREACH

Breaches & Incidents · 1911 changes

AI_SAFETY

AI Security & Safety · 1525 changes

Latest

Recent regulatory changes

View all changes →
arXiv: SpecTrum: Specification-Guided Differential Fuzzing for Ethereum Consensus Clients
A new academic paper, titled SpecTrum: Specification-Guided Differential Fuzzing for Ethereum Consensus Clients, has been published on arXiv. The paper introduces a novel fuzzing technique that use...
Read analysis →
arXiv: BullsEye: Directed Firmware Fuzzing
The publication introduces BullsEye, a novel directed fuzzing framework designed to improve the security testing of firmware, particularly for embedded systems and Internet of Things (IoT) devices....
Read analysis →
arXiv: MemCatalyst: Amplifying Data Auditing on Vision-Language Models via Data Poisoning
This publication, dated August 2026, is a research paper introducing MemCatalyst, a method that uses data poisoning to amplify data auditing on vision-language models. It is not a regulatory rule o...
Read analysis →
arXiv: Benchmarking Automated Security Patch Backporting: How Far Are We?
This publication introduces a benchmark for evaluating automated security patch backporting, a process where fixes for vulnerabilities in newer software versions are adapted to older, still-support...
Read analysis →
arXiv: MobileWorldSafety: Benchmarking GUI Agent Safety Against Environmental Injection Attacks in Android Apps
A new academic paper, MobileWorldSafety, introduces a framework for testing the security of AI-powered graphical user interface agents on Android devices against environmental injection attacks. Th...
Read analysis →
arXiv: An Emulation Anchored Digital Twin Testbed for Cyberattack and Defense Analysis in Hospital IT OT Environments
This publication introduces a technical framework, not a new regulation, but it has direct compliance implications. The paper details a digital twin testbed that emulates hospital IT and operationa...
Read analysis →
arXiv: Unclonable encryption from BB84 states: a simultaneous Goldreich-Levin reduction
A new academic paper, titled "Unclonable encryption from BB84 states: a simultaneous Goldreich-Levin reduction," has been published on arXiv. The paper presents a theoretical advance in quantum cry...
Read analysis →
arXiv: Towards the Impossibility of Imperfectly Complete Key Agreement in the QROM
A new academic paper, published on arXiv, presents a theoretical proof that challenges the feasibility of a specific class of cryptographic protocols known as "imperfectly complete key agreement" w...
Read analysis →
arXiv: HarnessRisk: A Lifecycle-Oriented Benchmark for Agent Harness Safety
The publication introduces HarnessRisk, a new benchmark framework designed to evaluate the safety of AI agent harnesses—the software layers that connect large language models to external tools and ...
Read analysis →
arXiv: The Last Mile of Deepfake Speech Detection: An Industry-Academia Experience Report
This publication is an industry-academia experience report detailing the practical challenges of deploying deepfake speech detection systems in real-world settings. It is not a new regulation or le...
Read analysis →

Never miss a regulatory change

Join compliance professionals who rely on our weekly digest. Free during beta - premium features coming soon.