{
  "id": 12730,
  "url": "https://www.gao.gov/products/gao-26-108606",
  "title": "Cybersecurity Regulations: Multiple Sectors Are Subject to Potentially Duplicative Reporting Requirements",
  "summary": "What GAO Found GAO identified 117 cybersecurity regulations established by 37 federal agencies for private entities, spanning nine critical infrastructure sectors. Most of those regulations either contain the same kind of reporting requirement applicable to a sector or the same reporting requirement as at least one other regulation, which may lead to duplication. Specifically, 80 of the 117 regulations (about 70 percent) had at least 125 total reporting requirements (see figure), with some regul",
  "authors": null,
  "category": "policy",
  "topics": "regulation",
  "orgs": null,
  "regions": "us",
  "published_at": "2026-07-22T11:27:47.000Z",
  "fetched_at": "2026-07-23T05:10:49.458Z",
  "source_slug": "x-us-gao-reports",
  "source_name": "US GAO Reports",
  "source_homepage": "https://www.gao.gov",
  "ethics_ai_record_url": "https://ethics.ai/record/12730",
  "original_url": "https://www.gao.gov/products/gao-26-108606",
  "evidence_status": "source-only",
  "attribution": "via ethics.ai"
}