Question 28 of 53
What AI regulations apply to a US-based SaaS company?
By Cody Maxwell · AI Governance Institute · March 2026 · Updated October 2026 · Last verified October 1, 2026
Identify federal, state, and international AI requirements for a US SaaS business. Map obligations by use case and customer location.
▸Editorial status
- September 13, 2026 · Substantive update — The article mentions California has 'multiple AI-related bills progressing through the legislature' but does not cover the California AI Transparency Act (SB 942 as amended by AB 853), which is now enacted and operative from August 2, 2026. The law imposes specific, concrete obligations on SaaS companies that are providers or distributors of generative AI systems serving California consumers, including mandatory free detection tools, latent disclosures in generated content, license terms prohibiting removal of disclosure capabilities, and a 96-hour access revocation requirement. A reader relying on this article would miss these obligations entirely. (AI Governance Institute pipeline)
- October 1, 2026 · Correction — Correction: Colorado's 2024 AI Act never took effect and was repealed in May 2026. SB 26-189 replaces it from 1 January 2027. NYC Local Law 144 covers jobs located in New York City. (Cody Maxwell)
If you only do 3 things, do this:
- 1.Your EU customer base determines whether the EU AI Act applies to you. If you have EU customers, map your AI features against the risk tiers. This is not optional.
- 2.Use case drives US obligations more than geography. Employment, credit, healthcare, and education AI are each governed by specific rules regardless of where your company is based.
- 3.The Illinois Biometric Information Privacy Act (BIPA) and NYC Local Law 144 are the state and local rules most likely to affect US SaaS companies today. Colorado's SB 26-189 joins them on 1 January 2027.
The Situation
Who this is for: Legal, compliance, and product teams at US SaaS companies offering AI features or building AI-powered products
When you need this: When building AI features, entering new markets, or when a customer asks about regulatory compliance
The Decision
Which AI regulations actually apply to our product and customer base, and what do they require us to do?
The Steps
- 1Map your customer locations: US-only, EU, UK, or global, which determines jurisdictional scope
- 2Map your AI use cases: employment, credit, healthcare, education, and financial services each have sector-specific rules
- 3For US customers: check applicable state laws (Colorado SB 26-189 for automated decisions from 1 January 2027; Illinois BIPA for biometric data; NYC Local Law 144 for hiring AI)
- 4For EU customers: assess EU AI Act risk tiers for your features and review GDPR automated decision-making obligations under Article 22
- 5For any use case involving personal data decisions: assess the Fair Credit Reporting Act (FCRA), the California Consumer Privacy Act (CCPA), and applicable state privacy laws
- 6Build a regulatory applicability matrix and update it when you add use cases or enter new markets
The Artifacts
- —US AI regulatory landscape map (federal + key state laws)
- —Sector-specific AI rule checklist (financial services, healthcare, employment)
- —EU AI Act applicability assessment for SaaS providers
- —Regulatory applicability matrix template (product features × applicable regulations)
The Output
A documented regulatory map for your specific product and customer base, identifying which rules apply, what they require, and a process to update it as you expand.
Federal-level rules and agency guidance
At the federal level, there is no comprehensive US AI regulation equivalent to the EU AI Act. Instead, existing laws apply to AI through agency guidance and enforcement. The FTC has issued guidance on AI in advertising, consumer products, and fraud, and has brought enforcement actions against AI-related deceptive practices. The Equal Employment Opportunity Commission (EEOC) has published guidance on AI in employment decisions under Title VII and the Americans with Disabilities Act (ADA). The Consumer Financial Protection Bureau (CFPB) applies the FCRA and the Equal Credit Opportunity Act (ECOA) to AI used in credit decisions.
For SaaS companies, the most immediately relevant federal rules are the FCRA (if your AI influences credit, employment, housing, or insurance decisions), Title VII and ADA guidance (if your AI is used in hiring or HR contexts), and FTC consumer protection requirements (if your AI makes consumer-facing claims). The SEC has signaled that AI-related disclosures in public filings are subject to existing materiality requirements.
State laws that matter today
Colorado's 2024 AI Act (SB 24-205) never took effect. In May 2026 the state repealed it and passed SB 26-189, a narrower law that applies from 1 January 2027. It covers automated decision-making technology used in consequential decisions about consumers, such as employment, education, credit, housing, healthcare, or legal services. Deployers must give notice before use, explain adverse outcomes, and offer human review.
Illinois' Biometric Information Privacy Act (BIPA) applies to AI that processes biometric data, including facial recognition. Violations have resulted in significant class action settlements. NYC Local Law 144 requires independent bias audits for automated employment decision tools used in hiring or promotion for jobs located in New York City. California has multiple AI-related bills progressing through the legislature. Building to the most stringent applicable standard (typically NYC Local Law 144 now, plus Colorado SB 26-189 from 2027, for US-focused SaaS) positions you well against most incoming state requirements.
EU and international exposure
If you have European customers, the EU AI Act applies to you regardless of where your company is based. The key question is whether your AI features would be classified as high-risk under Annex III. Features used in employment decisions (resume screening, performance evaluation), credit or insurance decisions, or education are likely high-risk. Features used in customer service, marketing, or productivity tools are typically limited or minimal risk, with only transparency obligations.
GDPR Article 22 restricts solely automated decision-making that produces legal or similarly significant effects on EU data subjects. If your SaaS product makes or significantly influences decisions about EU users, you need a compliant legal basis, a process for human review on request, and the ability to explain the decision. Many SaaS companies have this obligation but have not implemented the required processes.
California AI Transparency Act: generative AI disclosure obligations
The California AI Transparency Act (SB 942, as amended by AB 853) takes effect August 2, 2026, and applies to providers and distributors of covered generative AI systems serving California consumers. If your SaaS product includes generative AI features, you are likely a covered provider. The law requires you to offer a free, publicly accessible detection tool that can identify content your system generated, and to embed hidden labels (latent disclosures) in all covered AI-generated content so its AI origin can still be traced after it is shared.
License agreements for your generative AI system must include terms that prohibit licensees from removing or disabling those disclosure capabilities. If you discover a licensee has stripped or circumvented the required disclosures, you must revoke their access within 96 hours. These contractual and enforcement obligations require changes to standard SaaS terms of service and an internal process for monitoring and acting on disclosure violations.
Turn this guidance into an implementation plan
Get the free Excel tracker for all 132 governance controls. Score maturity, assign owners, and set deadlines, including this playbook's 6 related controls.
- 132 controls in Excel
- Score maturity and assign owners
- Track deadlines and regulation coverage
Includes AI Governance Weekly every Thursday. Unsubscribe anytime.
Governance Controls
Operational controls that implement the guidance in this playbook.
