What North American governments asked of software buyers this autumn
EditorialBy TrustList Editorial
Of 80 items tagged to North America, 17 record a government asking something of businesses; only 8 carry a date, and 4 of those fall on 1 January 2027.
About What North American governments asked of software buyers this autumn
What North American governments asked of software buyers this autumn
Between 1 September and 8 October 2026 our news desk published 80 items tagged to a place in the United States, Canada or Mexico. Seventeen of them record a government, regulator or court asking something of businesses that buy software. The other 63 are vendor product changes, takeovers, layoff notices, grant calls and deadlines. This piece counts the seventeen.
Four of the seventeen come from US federal bodies. Nine come from states and cities: seven from a single state or city, two from attorneys general or states acting together. Two come from Canada and two from Mexico. By main subject, five are about privacy and data, four about competition and consumer protection, two about tax and payments, two about employment and immigration, two about data centres and clocks, one about AI rules and one is a security directive. Only eight of the seventeen carry a calendar date for an obligation, and four of those eight land on the same day, 1 January 2027.
The most specific cases are worth naming early. California's regulator says more than 550,000 residents had signed up to its data-broker deletion platform by the start of October (California's DROP). Connecticut's AI and data-privacy amendments came into force on 1 October (Connecticut's AI and privacy acts). Canada's lawful-access bill sits in the Senate with Signal saying it will not comply (Bill C-22). Mexico's lower house passed a digital payments law by 327 votes to 122 (Mexico's digital payments law). The FTC wrote to 24 healthcare firms to say CMS price rules are no safe harbour (the FTC letters). The Department of Homeland Security proposed a school fee for each student's first Optional Practical Training recommendation (the DHS fee proposal).
How we counted
The data is our own records as of 8 October 2026: every news, business-news and HR-news item we published since 1 September that carries a US, Canadian or Mexican place tag. We read each one and sorted it. The seventeen counted here are items where a legislature, executive, regulator, agency, group of attorneys general or court did something that changes what a business must, may or should do. They were published between 28 September and 7 October. Each is counted once, by its main subject: California's employer AI laws are also employment law, and Connecticut's acts also cover AI, but neither is counted twice.
Forty items were left out as global vendor changes. They carry a US tag because the vendor is American: a Microsoft, Google, AWS, GitHub or Cloudflare product change, a patch or a price move. They matter to buyers, but they say nothing about what North American governments asked, and including them would have made the count a measure of where vendors are headquartered. A further 23 items cover takeovers, layoffs, grant calls and deadlines. We use some of them below where a government clock sits inside them, but we do not add them to the seventeen.
A caution on sources: several of the items rest on a single official release or on press reports, and our records say so. The figures below are the regulators' and the parties' own, not ours.
Privacy and data: four of five items are about data someone else holds
California's Delete Request and Opt-out Platform lets a resident ask every registered data broker to delete their information in one request. The regulator, CalPrivacy, says more than 650 brokers are registered, that processing began on 1 August, and that brokers have up to 90 days to report a result for each record. Each result comes back as one of five statuses: deleted, exempt, opted out, record not found or pending. The fine for failing to delete is $200 a day per consumer. Our item (California's DROP passes 550,000 sign-ups) is marked as resting on the regulator's own FAQ, so the sign-up and deletion rates are CalPrivacy's figures.
The same state widens the right to delete from 1 January 2027. SB 923, signed on 27 September, extends the CCPA right to delete to personal information a business obtained from third parties, and requires online-only businesses to accept requests through a webform. It also allows suppression lists, so that a deleted record is not re-imported with the next purchased file. CalPrivacy says the change brings California in line with Delaware, Indiana, Maryland and New Jersey. See California widens the right to delete.
Connecticut acted earlier. Public Acts 26-64 and 26-15 took effect on 1 October 2026. On the privacy side they limit pricing with personal data, require signs where facial recognition is used, and ban the sale of precise geolocation data. Data brokers must register with the Department of Consumer Protection by 1 January 2027. The AI half of the package is covered in the next section. The full list is in Connecticut's new AI and data-privacy rules.
Canada's contribution is a different kind of ask. Bill C-22, the Lawful Access Act, was introduced on 12 March, passed the House of Commons on 18 June and is at second reading in the Senate. Signal told lawmakers it would rather stop operating in Canada or accept throttling than change its app, and Tailscale and Windscribe have also opposed the bill. According to BetaKit's account, which our item flags as not yet independently verified, the bill would require messaging companies to retain user data and let the government reach encryption keys. Anyone running or reselling messaging, VPN or secure collaboration tools used in Canada should read Signal says it won't comply with Bill C-22.
The fifth item is an enforcement settlement rather than a rule. Forty-five attorneys general settled with Labcorp on 24 September over the 2019 breach at its debt collector, and the terms read as a checklist for anyone who outsources patient data: a contract inventory, cybersecurity standards written into contracts, segregated client data, audits, a right to terminate, and a third-party assessor. Connecticut's attorney general called data security a "non-delegable duty" for organisations covered by HIPAA. See the Labcorp settlement.
Counted together, four of the five privacy items (DROP, SB 923, Connecticut's broker and geolocation rules, and Labcorp) are about data a business did not collect itself: broker data, purchased data, enrichment feeds and data held by a vendor. That is the pattern a buyer of marketing, sales or customer-data software would miss by reading the items one at a time.
AI rules and the workplace
California's governor signed four employment-related AI and surveillance bills on 30 September: SB 947, SB 951, AB 1331 and AB 1883. Employers may not rely only on AI to discipline or fire, must disclose when AI causes a mass layoff, and face new limits on workplace surveillance. The detail is in California signs AI-at-work laws. Only one start date is reported, and from a law firm, not the governor: Ogletree Deakins puts SB 947 at 1 July 2027. The start dates of the other three have not been confirmed, and our item says law firms disagree on whether the surveillance laws apply immediately or from 1 January 2027. The same firm reports civil penalties of up to $500 per violation under AB 1883 and AB 1331.
Connecticut's Public Act 26-15 covers the same ground from another angle. Employers must give written notice when AI is used to make decisions affecting employees, and discrimination through AI is treated as employment discrimination. CT Mirror reports a written framework for automated employment decisions is due by 1 October 2027, and that the chatbot and minors rules start on 1 January 2027.
The federal items in this group are about immigration. Representative Beth Van Duyne's bill, H.R. 10643, would raise the maximum civil penalty for willful H-1B violations from $5,000 to $100,000, and from $35,000 to $250,000 where US workers are displaced. The minimum sponsorship ban would rise from two to five years, and from three to ten where displacement is involved. It has five co-sponsors, all Republicans from Texas, and has not passed; current penalties still apply (House bill would lift H-1B penalties).
The DHS proposal (DHS proposes a $70,000 school fee) would make every school certified under the Student and Exchange Visitor Program pay $70,000 before it first recommends an F-1 student for Optional Practical Training, and $30,000 for each later recommendation, STEM extensions included. The fee is owed by the school, but DHS acknowledges schools may pass it to students or employers. Comments run 30 days after publication in the Federal Register, scheduled for 8 October; one law firm gives the closing date as 9 November and other reports say 7 November. If the rule is finalised it takes effect 60 days after publication of the final rule. Nothing is payable yet.
Competition and consumer protection
Four items fall here, and none of them is a technology rule in the narrow sense. They all reach software through pricing, contracts and cancellation.
California's COMPETE Act, AB 1776, was signed on 30 September and takes effect on 1 January 2027. It amends the Cartwright Act so that monopolisation and monopsonisation by a single firm are unlawful under state law. Only the Attorney General and district attorneys can enforce it, a safe harbour covers market power gained through superior products or business acumen, and monopsony is included, which reaches dominant buyers as well as sellers. See California's COMPETE Act.
The RealPage ruling shows the enforcement side. A federal court in North Carolina refused to dismiss the antitrust case brought by California and other states against RealPage and several large landlords over rent-pricing software. The California Attorney General describes the coalition as bipartisan and made up of nine states. The ruling was on motions to dismiss, not the merits, and our item notes that only the Attorney General's release had been read (RealPage's algorithmic rent-pricing case survives dismissal).
The FTC's letters to 24 healthcare services companies cite Section 5 of the FTC Act and name four kinds of conduct: incomplete or late pricing information, disclosures that leave out physician or facility fees, inaccurate statements about price, and too little advance notice before scheduled services. The release sets no compliance deadline and states no penalty, and it does not say how the recipients were chosen (FTC writes to 24 healthcare firms).
New York City is the only municipality in the group. Its Department of Consumer and Worker Protection began enforcing a click-to-cancel rule on 1 October 2026: clear subscription terms, a disclosure of consumers' rights, cancellation by the same method as sign-up, and no charge for returning free items. Civil penalties start at $525 and refunds may be ordered (New York City's click-to-cancel rule).
Tax and payments: Mexico
Both Mexican items concern the same Chamber of Deputies session week, and both are still bills. On 1 October the Finance and Public Credit Committee cleared a Customs Law reform and a digital payments law (Mexico's customs valuation reform and digital payments law). The customs reform removes the 50% threshold that conditions some precautionary seizures when the declared value falls below the transaction value of identical goods, and lowers the infringement presumption line in article 177 from 50% to 20%. Under 20%, an importer may ask to replace a seizure with a cash deposit or a customs guarantee account; at 20% or more only a cash deposit is offered. The reform is due from 1 January 2027, and customs provisions setting the procedures are due by 31 December 2026.
On 6 October the full Chamber passed the Ley de Economia Digital para Pagos Digitales y Electronicos by 327 votes to 122, rejecting all 92 floor amendments, so the text goes to the Senate unchanged. Businesses and public authorities must enable acceptance of digital and electronic payments, every level of government must take digital payment for public services, and the Treasury may name strategic sectors where digital payment is the only form accepted; toll booths and petrol stations were the reported examples. The same session passed the Customs Law reform by 334 votes to 119. One outlet gave 127 votes against the payments law and two gave 122, which our item flags. Reports give no Senate date and no start date for the payments law (Mexico's lower house passes digital payments law).
Security directives and infrastructure
The one security directive in the count is a US advisory. The FBI and the US Secret Service say the FortiBleed credential campaign against internet-facing FortiGate firewalls and SSL VPN gateways is continuing and has locked some organisations out of their own devices. SOCRadar verified more than 86,644 compromised devices in 194 countries. There is no CVE and no fixed software version, so the remedy is configuration and credential work, not a patch. The agencies add that changing passwords is not enough because attackers create their own administrator accounts (FBI warns FortiBleed is still hitting exposed FortiGate VPNs).
Maryland's governor signed an executive order on 23 September creating a Data Center Task Force. Every proposed data centre of 25 MW or more is reviewed as soon as it seeks any State action, whether a permit, an incentive or a letter of support, and receives a public determination of Aligned, Conditionally Aligned or Not Aligned. The governor also backs repealing the Data Center Sales and Use Tax Exemption, enacted in 2020, in the next legislative session. The order sets no end date for the review and the repeal needs the General Assembly (Maryland's data centre review).
The last item in the count is the plainest: Alberta and most of British Columbia stop changing clocks on 1 November 2026, moving permanently to UTC-6 and UTC-7. Microsoft adds two new Windows time zones in the October update, and devices without it will show the wrong time after 1 November (Alberta and British Columbia stop changing clocks).
What governments offered instead
Not everything the North American public sector sent businesses was a requirement. Two items from the wider 80 are offers with dates: Tennessee's SBIR/STTR Matching Fund, open from 5 to 16 October, which matches a qualifying federal award by up to half (Grant calls with dates), and the state's QUBIT quantum infrastructure grant, closing on 23 October. QUBIT leads must be Tennessee universities, development districts, Oak Ridge National Laboratory or public utilities, with companies in as consortium partners (Tennessee's QUBIT grant). We keep them out of the seventeen because they ask nothing of a software buyer, but both have closing dates inside the next three weeks.
Government clocks inside takeovers and layoffs
A second group of items does not record a government action, but government timetables run through it.
Several pending takeovers name the approvals they wait for. Weave's merger proxy sets a 22 October stockholder vote, needs expiry of the US Hart-Scott-Rodino waiting period and other antitrust and foreign-investment approvals the proxy does not name, and has an outside date of 18 February 2027, extended automatically to 18 May 2027 (Weave's 22 October vote). PTC's sale to Schneider Electric is subject to shareholder, HSR and CFIUS approval, with closing anticipated by the third quarter of 2027 (Schneider Electric and PTC). AMD's purchase of World Labs expects regulatory approvals and closing by the end of 2026 (AMD and World Labs), and Salesforce expects its Listen Labs purchase to close in its fiscal fourth quarter, which runs from November 2026 to January 2027, subject to required regulatory clearance (Salesforce and Listen Labs).
Others say less. Zeta Global's purchase of the Toronto company Senso gives no closing date and nothing about approvals (Zeta Global and Senso), and Plurilock holders vote in November (Takeovers with dates). Where a deal has closed, the customer questions are contractual: Capgemini's sale of its US government unit to ITC Federal calls for checks on contract novation, security clearances and key personnel (Capgemini Government Solutions and other completed takeovers). Databricks says the Row Zero standalone product stays available, with no end date or pricing stated (Databricks and Row Zero). Inworld says Ultravox customers will move to its voice technology (Inworld and Ultravox), and Infillion's release does not address Foursquare's Places API or SDK customers (Infillion and Foursquare). Inseego completed its purchase of Nokia's fixed wireless access business on 1 October (Inseego and Nokia).
Layoff items carry their own statutory clock. The US WARN Act requires 60 days' notice of large layoffs, and the state lists show Oracle cutting 441 roles at three California sites from 13 November 2026 and 359 permanent roles in Seattle from the same date (the week to 2 October, Oracle's Seattle notice). Microsoft filed a WARN notice for 277 jobs in Redmond, and Workday filed an 8-K for a reduction of about 2.5% of its workforce (the week to 1 October). FICO said in its own 8-K that it will cut about 15% of positions (FICO's restructuring). These matter to a software buyer as support and roadmap signals, and California's SB 951 will add a further question to future notices: whether an AI system caused the cuts.
What the list shows that a buyer would not guess
The asks come through very different routes. Statute (California, Connecticut), executive order (Maryland), city rule (New York City), bills still moving (Mexico, Canada, H.R. 10643), an agency proposal (DHS), a court (RealPage), a multistate settlement (Labcorp), agency letters (FTC) and an advisory (FBI and Secret Service) are not the same kind of ask. Only statute, executive order and city rule bind a business, and several of those start later; a buyer who reads every item as a requirement will overstate the load. Of the nine state and city items, five carry a dated obligation. Federal items carry one in four: the DHS comment window, and no more.
Obligations stack on 1 January 2027. California's SB 923 and COMPETE Act, Connecticut's data-broker registration and chatbot rules, and the start of Mexico's customs reform all arrive that day, and Mexico's customs provisions are due on 31 December. A company with Californian customers, Connecticut data-broker status and Mexican imports faces them together. Before that, 1 November (the Alberta and British Columbia clocks) and the DHS comment window, reported as 7 or 9 November, are the nearest future dates. Connecticut's and New York City's rules have been in force since 1 October, and DROP processing since 1 August.
State rules diverge more than the headlines suggest. California reaches purchased data through deletion (SB 923) and broker data through DROP, while Connecticut reaches the sale of precise geolocation data and requires broker registration. On workplace AI, California requires human review before AI-only discipline or dismissal, with SB 947 reported for 1 July 2027, while Connecticut requires written notice to employees and a framework by 1 October 2027. SB 923 itself brings California in line with Delaware, Indiana, Maryland and New Jersey on the deletion standard, which tells you California was behind them on that point and that a single national approach to deletion does not exist yet.
Six items still lack a final date. Mexico's payments law waits on the Senate with no date. Canada's Bill C-22 is at Senate second reading. H.R. 10643 has not passed. The DHS fee is a proposal that takes effect 60 days after a final rule. Three of California's four AI-at-work laws have unconfirmed start dates. Maryland's tax exemption repeal needs a legislative session. The other four items (the FTC letters, RealPage, Labcorp and the FortiBleed advisory) are enforcement or advisory with no compliance date to meet, so a buyer cannot wait for a date before acting on them.
Most of the load falls on data and suppliers, not on software features. Five of the seventeen items are about data, and four of those name data held by someone else. Only one item is an AI rule in the strict sense. The North American government items of this autumn mostly ask a business to know where its data came from and what its suppliers do with it.
Related on TrustList:
- Connecticut’s new AI and data-privacy rules take effect on 1 October; data brokers must register by 1 January
- California's DROP passes 550,000 sign-ups as data brokers process deletions
- California widens the right to delete: from 1 January, businesses must also delete data they bought and offer a webform
Categories & features
- United States
- Canada
- Mexico
- California
- Connecticut
- Maryland
- New York City,
- Regulatory Compliance
- Data Privacy Law
- Privacy Law
- Employment Law
- Immigration Management
- Digital Payments
- Tax Compliance
- Artificial Intelligence - AI
TrustList Weekly
The week in software and IT, in one email
The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More United StatesThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.