AI Regulation in the United States
The United States takes a sector-by-sector, agency-by-agency approach to AI regulation rather than a unified federal law. The Biden administration's Executive Order 14110 (2023) directed agencies to develop AI standards and prompted NIST's AI Risk Management Framework, but was revoked in January 2025. Today, federal AI oversight is fragmented: the FTC uses consumer protection authority to challenge AI-related deception and bias, the SEC requires disclosure of material AI risks, the FDA regulates AI as a medical device, and OSHA is examining AI in workplace safety.
State-level regulation is accelerating and producing the most concrete compliance obligations. Colorado's AI Act (SB205, effective February 2026) is the first comprehensive state AI law, covering high-risk AI systems that make consequential decisions about consumers in employment, credit, housing, education, and healthcare. California's AI Transparency Act requires disclosure of AI-generated content. Illinois' BIPA has been applied to AI systems processing biometric data. New York City's Local Law 144 mandates bias audits for AI tools used in employment decisions.
The NIST AI Risk Management Framework — structured around four functions: Govern, Map, Measure, and Manage — is the most widely adopted voluntary standard for US organizations and is referenced in federal procurement requirements and sector-specific guidance. For organizations without the structure of an EU compliance obligation, NIST AI RMF alignment provides a practical baseline for demonstrating governance maturity.
Key themes
- 1.No single federal AI law — agency-by-agency and state-by-state compliance
- 2.NIST AI RMF as the de facto voluntary standard
- 3.Colorado AI Act (SB205) and active state legislation
- 4.SEC, FTC, and FDA enforcement using existing authority
Regulatory frameworks and guidance(48)
America's AI Action Plan
America’s AI Action Plan sets the White House’s priorities for advancing and governing AI. It directs federal work on AI security infrastructure, agency coordination, and cybersecurity readiness. The plan primarily covers federal agencies and their AI operators. Federal AI contractors and suppliers may also be affected.
California AI Auditor Registration Act (AB 1405)
AB 1405 creates California’s first registry for independent AI auditors. Auditors must enroll with a new state agency and disclose their credentials and methods. They must also follow recognized independence standards. From January 1, 2029, only registered auditors may perform covered audits in California.
California Generative AI Transparency Requirements - AB 2013
California AB 2013 requires public training-data disclosures from developers of generative AI systems accessible to the California public. Developers must publish the documentation on their websites. The disclosures explain training datasets’ origins and composition. The requirement applies regardless of where the developer is headquartered.
California AI Transparency Act (SB 942 as amended by AB 853)
The California AI Transparency Act requires covered generative AI providers to offer a free detection tool. They must also embed latent disclosures in generated content. The law covers developers and distributors serving California consumers. License terms must permit access revocation within 96 hours when licensees remove or disable required disclosure capabilities.
California Health Care Services AI Act Disclosure Requirements
California requires covered healthcare providers to disclose when patient communications are generated by AI. They must also explain how patients can reach a human representative. The requirements help patients understand whether AI is providing health information or services.
California Senate Bill 420: Automated Decision Systems (State AI Transparency Act)
California SB 420 would require impact assessments before high-risk automated decision systems enter public use. Introduced under the State AI Transparency Act, it covers organizations operating those systems in California. The proposal adds transparency and reporting duties. The Attorney General or Civil Rights Department could enforce it through civil actions.
California SB 53 Foundation Model Safety and Security Protocol
California SB 53 would require safety and security protocols for foundation models presenting critical risk. Covered developers would need to create, follow, and publicly disclose those protocols. The bill also requires catastrophic risk testing and ongoing monitoring for critical safety incidents.
California Independent Verification Organizations Act (SB 813)
California SB 813 establishes a state framework for certifying independent AI verification organizations. The California Artificial Intelligence Standards and Safety Commission will recognize these organizations and set their standards. Companies using AI in hiring, insurance, and other high-stakes activities can hire recognized auditors to check compliance with state law.
California Transparency in Frontier AI Act
The California Transparency in Frontier AI Act covers large frontier model developers operating in or serving California. They must publish safety and security frameworks for their most capable systems. Duties include risk assessment disclosures, transparency reports to the public and authorities, and timely reporting of qualifying safety incidents.
Colorado AI Act SB205
Colorado SB 205 imposes duties on developers and deployers of high-risk AI. Requirements include algorithmic impact assessments, transparency notices, and consumer rights for consequential decisions. It was the first US state statute to establish these affirmative duties.
Colorado Senate Bill 189: Automated Decision-Making Technology Act
Colorado SB 189 repeals SB 205 and replaces it with the Automated Decision-Making Technology Act, effective January 1, 2027. It covers a broader category of technology used for consequential decisions affecting Colorado consumers. The replacement removes mandatory risk management programs, annual impact assessments, and the reasonable-care standard for algorithmic discrimination.
Commerce Department Evaluation of State AI Laws
The December 11, 2025 executive order gives Commerce 90 days to evaluate state AI laws conflicting with federal policy. The review targets compelled changes to truthful outputs and disclosures that may implicate First Amendment protections. Identified laws may be referred to the AI Litigation Task Force for possible federal preemption action.
Proposed CPPA Regulations on Cybersecurity, Risk Assessments, and Automated Decision-Making Technologies
The California Privacy Protection Agency Board finalized proposed rules in May 2025. They cover cybersecurity audits, privacy risk assessments, and automated decision-making. Covered businesses would include those conducting consequential automated decisions or personal-data processing posing significant consumer risks. If adopted, the rules would add consumer opt-outs and mandatory assessments.
Executive Order 14318: Accelerating Federal Permitting of Data Center Infrastructure
President Trump’s Executive Order 14318 directs federal agencies to accelerate data center permitting for domestic AI development. It covers agencies responsible for relevant land use, environmental reviews, and energy approvals. The administration identified permitting delays as barriers to AI infrastructure growth.
Executive Order 14319: Preventing Woke AI in the Federal Government
President Trump’s Executive Order 14319 directs agencies to avoid AI with ideological bias or viewpoint-discriminatory outputs. It covers federal procurement, deployment, and contracting. The order rescinds or modifies earlier guidance viewed as imposing political or ideological constraints on AI development.
Executive Order 14110 on Safe, Secure, and Trustworthy Artificial Intelligence
This US presidential directive sets federal requirements for safe AI development and deployment. It includes frontier-model safety reporting, NIST standards development, and coordination across agencies.
Federal Reporting and Disclosure Standard for AI Models (FCC Proceeding Directive)
This national AI policy directive instructs the FCC to consider federal reporting and disclosure standards for AI models. An adopted standard would preempt conflicting state AI laws. A parallel AI Litigation Task Force would challenge state laws deemed inconsistent with the federal framework.
Federal Communications Commission AI Model Reporting and Disclosure Proceeding
The FCC is opening a proceeding on possible federal AI model reporting and disclosure standards. It follows Commerce’s evaluation of state AI laws. An adopted standard could preempt conflicting state disclosure and reporting requirements.
FDA AI/ML Software as Medical Device Guidance
FDA’s action plan and guidance address AI/ML Software as a Medical Device. They introduce a total product lifecycle approach and predetermined change control plans. Adaptive clinical algorithms also face transparency and monitoring requirements.
FTC AI Enforcement Policy
The FTC applies existing consumer protection and competition statutes to AI harms. Its statements, guidance, and enforcement address deceptive claims, discriminatory automated decisions, and unfair data practices.
U.S. General Services Administration AI Strategies and Compliance Plan
The GSA AI Strategies and Compliance Plan establishes governance for internal agency AI use. An AI Governance Board and oversight committee review and approve use requests. Requirements cover privacy controls, security reviews, use-case intake, and compliance evidence.
Guaranteeing and Upholding Americans' Right to Decide Responsible AI Laws and Standards Act (GUARDRAILS Act)
The bipartisan GUARDRAILS Act was introduced on March 20, 2026. It would repeal Executive Order 14365 and prevent federal agencies from preempting state AI laws. If enacted, it would preserve states’ authority to establish and enforce their own requirements.
H.R.8094 - AI Foundation Model Transparency Act of 2026
Bipartisan lawmakers introduced H.R.8094 on March 26, 2026. It would require large foundation model developers to disclose training data, model design, limitations, risks, and evaluation methods. The bill seeks public scrutiny through transparency without directly restricting model use or deployment.
Illinois AI Safety Measures Act (SB 315)
The Illinois AI Safety Measures Act was signed on July 7, 2026. It requires annual independent frontier-model safety audits from AI developers earning more than $500 million annually. Results must be public, and the Illinois Attorney General can enforce civil penalties. It is described as the first US state law requiring these audits.
Illinois Biometric Information Privacy Act, AI Provisions
Illinois BIPA, 740 ILCS 14, restricts collection, storage, use, and disclosure of biometric identifiers and information. It affects AI processing facial geometry, voiceprints, iris scans, and similar data. BIPA has generated extensive biometric privacy litigation.
Illinois High-Impact AI Governance Principles and Disclosure Act
Illinois HB 3529 would establish the High-Impact AI Governance Principles and Disclosure Act. It targets private businesses using consequential AI in areas such as employment, credit, and housing. Proposed duties include impact assessments, governance records, and public disclosures, backed by civil penalties.
New York's Responsible AI Safety and Education Act (RAISE Act) for Large Developers
The pending New York RAISE Act would regulate large frontier model developers above specified computing thresholds. It covers developers operating in or directing services to New York. Proposed requirements include written safety protocols, independent third-party audits, and safeguards against critical harms.
NIST AI 600-1 Generative AI Profile
This companion to NIST AI RMF 1.0 addresses generative AI risks. It covers large language models and multimodal foundation models.
NIST ITL AI Program: Guidance and Templates for Public-Facing AI Documentation (Initial Public Draft)
NIST’s initial public draft provides guidance and templates for publicly disclosed AI system documentation. It supports developers, deployers, and procurers needing governance records, transparency, or audit evidence. Public comments close September 16, 2026.
NIST Artificial Intelligence Risk Management Framework Playbook
The NIST AI RMF Playbook translates the AI Risk Management Framework Core into a structured set of suggested actions organized under the four functions: Govern, Map, Measure, and Manage. It is designed for organizations deploying or developing AI systems who need practical implementation guidance rather than high-level principles. Compliance teams can use it to build risk workflows, establish control checkpoints, and produce governance documentation aligned to the AI RMF.
NIST Artificial Intelligence Technology Evaluation Program
NIST’s AITE program organizes federal AI testing, benchmarking, and validation, particularly for high-impact applications. It serves developers, agencies, and enterprises seeking standardized evaluations. Topics include testing methods, provenance controls, data governance, and enterprise validation.
New York City Local Law 144 of 2021, Automated Employment Decision Tools
NYC employers and employment agencies using covered automated tools for hiring or promotion must arrange annual bias audits. They must publish results and notify candidates before use.
OCC Updated Model Risk Management Guidance (2026)
The Office of the Comptroller of the Currency has issued updated model risk management guidance establishing revised expectations for how national banks and federal savings associations develop, validate, monitor, and govern models. The guidance applies to all institutions supervised by the OCC that use models in material business decisions, with particular relevance where AI or machine learning is embedded in credit underwriting, pricing, fraud detection, or compliance monitoring workflows. Institutions are expected to maintain rigorous validation programs, clear governance structures, and documented controls proportionate to the risk a given model presents.
OMB Memorandum M-26-04: Increasing Public Trust in AI Through Unbiased AI Principles
OMB Memorandum M-26-04 sets unbiased AI principles for federal systems interacting with or affecting the public. It covers executive agencies procuring, developing, or operating AI. Agencies must address algorithmic bias and maintain transparency and accountability in AI-supported decisions.
Protecting Consumers From Deceptive AI Act
The Protecting Consumers From Deceptive AI Act was introduced federally on April 23, 2026. It would direct NIST to develop watermarking, fingerprinting, and provenance standards for AI-generated audio and visual content. NIST would also support AI-modified content labels and frameworks for identifying generated text. The bill targets platforms, developers, and synthetic-media distributors.
SEC AI Governance Guidance
SEC rules, guidance, and proposals address investment advisers, broker-dealers, and public companies using AI. Topics include predictive-analytics conflicts, securities disclosures, and examination priorities for algorithmic systems.
Sectoral AI Governance Act of 2026
The Sectoral AI Governance Act of 2026 is a proposed US federal law that would authorize federal regulatory agencies to issue rules governing algorithmic decision-making systems within their existing enforcement domains. It applies to any organization deploying AI systems that could materially contribute to violations of federal law in regulated sectors. If enacted, it would require regulated deployers to align AI governance controls with sector-specific agency rulemaking.
Texas Responsible AI Governance Act
Texas enacted its Responsible AI Governance Act on June 22, 2025. This entry describes rules focused on state government AI use, including accountability, transparency, and risk management. It notes that the enacted version removed most private-sector obligations from earlier proposals.
U.S. Autonomous and Intelligent Government Entities for National Trust Act (AI AGENT Act, Discussion Draft)
The Senate’s AI AGENT Act discussion draft would require FTC registration of custodial agents before access to large online platforms. It targets organizations operating agents for consumers or other principals. Proposed duties cover registration, disclosure, access controls, revocation conditions, and platform management of agent interactions.
Executive Order: Eliminating State Law Obstruction of National Artificial Intelligence Policy
This executive order directs agencies to challenge state AI laws conflicting with national policy. It establishes an AI Litigation Task Force and a 90-day Commerce review of burdensome state rules. FCC and FTC work would develop federal reporting standards and policies intended to preempt conflicting requirements.
Executive Order 14179: Removing Barriers to American Leadership in Artificial Intelligence
Executive Order 14179 directs agencies to develop an AI Action Plan prioritizing US development and deployment leadership. It shapes conditions for private AI businesses operating in the US. The order revokes earlier safety-focused directives and emphasizes deregulation and competitiveness.
U.S. Executive Order: Ensuring a National Policy Framework for Artificial Intelligence
The December 11, 2025 executive order directs a unified national AI policy and challenges to conflicting state laws. It requires Commerce’s state-law evaluation and an FTC statement on unfair or deceptive AI practices within 90 days. It also establishes an AI Litigation Task Force. Federal agencies and entities subject to challenged state rules may be affected.
U.S. Federal Court Ruling on Attorney-Client Privilege and AI Chatbot Communications (Rakoff, S.D.N.Y. 2026)
A Manhattan federal judge ruled that third-party AI chatbot communications did not qualify for attorney-client privilege. Former GWG Holdings CEO Bradley Heppner had to produce 31 AI-generated legal documents in a securities fraud case. The ruling illustrates potential disclosure exposure for AI-assisted legal research and drafting.
Treasury Department AI Risk Management Framework for Financial Services
Treasury’s February 2026 framework translates NIST AI RMF principles into 230 financial-sector control objectives. It covers Treasury-supervised institutions, including banks, asset managers, insurers, and payment processors developing or deploying AI. Controls address model lifecycles, identity resolution, data governance, and compatibility with SOC 2 and NIST cybersecurity requirements.
U.S. Executive Order: Promoting Advanced Artificial Intelligence Innovation and Security
This presidential action creates classified evaluations of frontier models’ cyber capabilities and a designation for covered models. Designated developers must provide federal access 30 days before public or commercial release. Confidentiality and cybersecurity protocols govern that access. The action primarily affects large frontier-model developers with potential cybersecurity implications.
Utah Artificial Intelligence Policy Act (SB 149)
Utah SB 149 requires AI interaction disclosures for covered businesses and people in regulated occupations. Missing disclosures or deceptive AI use can create liability under existing consumer protection law. It also establishes an AI Policy Office in the Department of Commerce to develop policy and coordinate guidance.
Washington State SB 5395 and SB 5886 (AI in Health Care and Right of Publicity)
Washington enacted two relevant statutes in 2026. SB 5395 prohibits healthcare providers from relying solely on AI to deny care through prior authorization. SB 5886 extends publicity rights to AI-generated likenesses, affecting organizations producing or deploying representations of individuals.
White House Artificial Intelligence Oversight Framework
Reporting describes an advanced-model oversight framework finalized by the White House in August 2026. It sets pre-deployment evaluation expectations for developers and deployers operating within or supplying the federal government. The full text was unavailable at the reporting date, leaving its precise scope and requirements unconfirmed.
