This Week in ICT & Cybersecurity — Washington (#26, 2026)

FCC moves to strengthen STIR/SHAKEN and robocall rules; new NG911 reliability requirements finalized; Senate Commerce to consider broadband, disaster communications, and connected vehicle legislation.

This Week in ICT & Cybersecurity — Washington (#26, 2026)

July 05, 2026 to July 11, 2026

This is Queen Street Analytics' weekly digest of regulatory developments, legislative discussions and other government-related news concerning ICT, cloud computing, digital infrastructure, social media platforms, digital privacy, AI, cybersecurity, blockchain, Web3 and cryptocurrencies. Once a week, we break down the most important updates in this space in under five minutes.

Want to track other GR news in adjacent industries? Don't miss this week's updates in Finance and Defence. Also consider subscribing to our ICT & Cybersecurity - Ottawa edition covering critical GR news north of the border.

📋 In This Week's Newsletter

• 🏛️ This Week's Congressional Calendar
• 🇺🇸 Federal Government News
• 📜 Legislative Updates
• 📚 What We're Reading This Week


This Week's Congressional Calendar

Federal Government News

FCC Proposes STIR/SHAKEN Rule Enhancements and Robocall Mitigation Requirements

The FCC issued an extensive proposed rulemaking to require voice service providers to strengthen Know-Your-Upstream-Provider (KYUP) controls and provide more robust documentation and due diligence throughout the entire call path. The proposal would further formalize STIR/SHAKEN attestation requirements, clarify definitions across IP- and non-IP-based systems, and extend compliance duties to major IP transport and aggregation facilities. The rulemaking also targets improvements in Governance Authority oversight, elimination of legacy implementation loopholes, expanded operational recordkeeping, and more rigorous reporting and compliance reviews. The Commission seeks public comment on the proposals, with a deadline of August 10, 2026, for initial comments and September 8, 2026, for replies.

Sources: www.federalregister.gov
ad-card
Discover comprehensive lobbying data and insights with LobbyIQ. Explore now!

FCC Finalizes NG911 Reliability and Interoperability Framework

The Federal Communications Commission published final rules that update the reliability framework for Next Generation 911 (NG911) services. New requirements extend to Emergency Services IP networks (ESInets), Next Generation Core Services (NGCS) providers, and associated infrastructure, mandating updated best practices for physical diversity, operational integrity, and automated monitoring. Required certifications now move from annual to one-time, and 911 Authorities are granted access to filed certifications with confidentiality protections. The final rule also establishes a one-time interoperability reporting requirement for NGCS and ESInet operators, while eliminating duplicative legacy filing obligations. The effective date is August 10, 2026, with certain sections triggered by later compliance notices.

Sources: www.federalregister.gov

FCC Proposes Expanded NG911 Interoperability and Direct Video Calling Accessibility Framework

The FCC issued a Second Further Notice of Proposed Rulemaking seeking comment on additional interoperability standards and requirements for Next Generation 911 (NG911) providers. Proposed regulations would require core service and ESInet providers to conduct multi-party, multi-state interoperability testing of 911 traffic, including voice, video, data, and text, within three years of final rules. The Commission is also seeking input on frameworks that allow 911 Authorities to signal readiness for direct video calling (DVC) in American Sign Language, addressing technical, operational, and accessibility issues. The FCC requests input on implementation costs, technical architectures, potential pilot programs, and coordination with Department of Justice regulatory requirements. Comments are due August 10, 2026.

Sources: www.federalregister.gov

FCC Approves Implementation of Submarine Cable Security Rules

The Office of Management and Budget approved new FCC information collection requirements for submarine cable landing license applicants and licensees, with the rules covering regulatory updates for national security and supply chain risk mitigation. Effective July 8, 2026, the rules will require comprehensive disclosures regarding ownership, foreign adversary relationships, affiliate certifications, and reporting on cable capacity, including domestic facilities and submarine line terminal equipment. Operators must now file ongoing compliance updates, and certain activities will be suspended absent adequate reporting on governance and technical security.

Sources: www.federalregister.gov

FCC Prohibits Importation and Marketing of Communications Equipment on the Covered List

The FCC’s Public Safety and Homeland Security Bureau and the Office of Engineering and Technology issued a joint notice effecting a ban on importation and marketing of any equipment added to the Covered List in 2024 or earlier and previously authorized under earlier procedures. The prohibition, which takes effect July 16, 2026, targets equipment considered an “unacceptable risk to the national security of the United States,” including items integrated with Kaspersky Lab software and specific hardware cited in congressional findings. The action temporarily suspends the ban for certain video surveillance devices used on “critical infrastructure” until definitions are finalized, but affirms that entities must immediately halt imports and marketing for all other targeted categories.

Sources: www.federalregister.gov

Legislative Updates

Protecting Consumers from Deceptive AI Act

H.R. 8893, the Protecting Consumers from Deceptive AI Act, advanced out of committee by a 35-0 vote. The bill would address deceptive practices involving artificial intelligence under the jurisdiction of the House Committee on Science, Technology, Communications.

Sources: www.congress.gov

Protecting Communities from Data Center Impacts Act of 2026

H.R. 9629, titled the Protecting Communities from Data Center Impacts Act of 2026, was referred to the House Committee on Energy and Commerce on July 9. The bill addresses potential impacts resulting from data center operations in surrounding communities.

Sources: www.congress.gov

To require artificial intelligence chatbot providers to provide data privacy and security

H.R. 9619 was referred to the House Committee on Energy and Commerce on July 9. The legislation would require AI chatbot providers to ensure data privacy and security in their operations.

Sources: www.congress.gov

Intelligence Authorization Act for Fiscal Year 2027

H.R. 9624, the Intelligence Authorization Act for Fiscal Year 2027, was referred to the House Permanent Select Committee on Intelligence on July 9.

Sources: www.congress.gov

EMRTAI Authorization Act of 2026

H.R. 9616, the EMRTAI Authorization Act of 2026, was referred to the House Committee on Energy and Commerce. The bill’s text and intent pertain to telecommunications program authorizations.

Sources: www.congress.gov

BRACE Act

H.R. 9615, titled the BRACE Act, was introduced and referred to the House Committee on Energy and Commerce on July 9.

Sources: www.congress.gov

Amending the Fair Credit Reporting Act Relating to Identity Theft and Credit Restoration

H.R. 9639 was referred to the House Committee on Financial Services. The bill would expand Fair Credit Reporting Act tools for vulnerable consumers and address identity fraud outcomes.

Sources: www.congress.gov
ad-card
Get your updated contact lists from Queen Street Analytics. Subscribe here!

What We're Reading This Week

.