AI Governance Institute
All governance templates →What AI regulations apply to a US-based SaaS company?

Implementation Kit

US AI Regulation Checklist and SaaS Applicability Matrix

The regulatory picture for a US-based SaaS company: a landscape map of federal and key state law, a sector-specific rule checklist, and a matrix mapping product features to the rules they trigger.

Who this is for: The compliance or legal owner at a US SaaS company working out which AI rules bite.

Download the kit (Markdown) ↓3 artifacts. Every table also copies as CSV.

1. US AI regulatory landscape map

Spreadsheet

The federal and state instruments that could apply, with their trigger and status.

Template

InstrumentLevelTriggerApplies to us?Key obligationsStatus
FTC Act Section 5 (unfair/deceptive)FederalAI claims; biased or harmful outcomessubstantiate claims; avoid unfair practices
EEOC / Title VII (employment)FederalAI in hiring or HR decisionsadverse-impact analysis
Colorado AI Act (SB205)State (CO)high-risk AI affecting CO consumersrisk mgmt, impact assessment, disclosure
California ADMT / privacy rulesState (CA)automated decision-making on CA residentsnotice, opt-out, risk assessment
NYC Local Law 144City (NYC)automated employment decision toolsannual bias audit; notice
Illinois BIPA / AI video interview actState (IL)biometrics; AI video interviewsconsent; disclosure
Sector rules (see sector checklist)Federal/Statefinancial, health, insurance usesector-specific

Worked example

InstrumentApplies to us?Note
FTC Act Section 5Yesour marketing makes AI accuracy claims; substantiation file needed
EEOC / Title VIIYes (via customers)our screening feature is an ADT for customers; we support their audits
Colorado SB205Yescustomers use our tool for consequential decisions on CO consumers
California ADMTYesprovide opt-out and notice tooling to customers
NYC LL144Yesbias audit support feature shipped
Illinois BIPAMonitoringno biometric features today; flagged if added

Acceptance criteria

  • Federal, state, and city instruments are all considered, not just federal.
  • Each row states whether the obligation falls on us directly or via our customers.
  • "Monitoring" rows name the feature or expansion that would make them apply.

2. Sector-specific AI rule checklist

Spreadsheet

Extra obligations that attach when the product is used in a regulated sector.

Template

SectorRule / regulatorTriggerObligationDo we support it?
Financial servicesECOA / Reg B; fair lending; model risk (SR 11-7 analogues)credit or lending decisionsadverse-action reasons; model validation; disparate-impact testing
HealthcareFDA (SaMD); HIPAA; ONCclinical decision support; PHIclearance where applicable; PHI safeguards; transparency
EmploymentEEOC; state ADT lawshiring, promotion, terminationadverse-impact analysis; audit support; candidate notice
Insurancestate insurance codes; NAIC model bulletinunderwriting, pricing, claimsdocumentation; unfair discrimination testing; governance

Worked example

SectorRuleApplies?What we ship
Financial servicesECOA / Reg BYesreason-code export; model documentation pack; disparate-impact report
EmploymentEEOC + NYC LL144 + ILYesbias audit export; candidate notice templates
InsuranceNAIC model bulletinMonitoringgovernance documentation available; no dedicated testing feature yet
HealthcareFDA SaMDNoproduct not used for clinical decisions; contractual prohibition

Acceptance criteria

  • Every sector the product is sold into has its rules assessed.
  • For each applicable rule, the product capability that supports customer compliance is named.
  • Sectors that are contractually out of scope are recorded as such.

3. Product feature to regulation matrix

Spreadsheet

Maps each AI feature to the rules it triggers, so product changes surface compliance impact.

Template

FeatureWhat it doesRegulations triggeredCompliance requirementsOwner
<feature>

Worked example

FeatureWhat it doesRegulations triggeredCompliance requirementsOwner
Applicant rankingscores/ranks job applicantsEEOC/Title VII, NYC LL144, IL, CO SB205adverse-impact testing; bias audit export; candidate notice; risk assessmentProduct + Compliance
Churn predictionflags at-risk customersFTC Section 5 (if used for pricing/denial)no protected-class proxies; documentationProduct
AI chat assistantanswers user questionsFTC Section 5; state chatbot disclosure lawsdisclosure that it is AI; accuracy controlsProduct

Acceptance criteria

  • Every shipped AI feature has a row.
  • A new feature or a material change to one triggers a review of this matrix before launch.
  • Each row names the compliance requirements and an owner.

Governance controls this kit produces evidence for

Completing the artifacts above gives you a head start on the evidence requirements for these controls.

CMP-008
CMP-008

The landscape map is the federal (and state) AI regulatory monitoring and pre-deployment vetting record.

CMP-001
CMP-001

The feature-to-regulation matrix is multi-jurisdiction compliance mapping at the feature level.

CMP-010
CMP-010

Financial-sector rows cover AI use in regulated reporting and risk modeling.

SCT-004
SCT-004

Insurance-sector rows map to insurance-sector AI documentation standards.

HOC-001
HOC-001

Feature-level applicability depends on classifying each feature's risk and impact.

This kit backs one playbook. Read the full guidance for the reasoning behind each artifact.

Decide what to implement next

Assess your governance gaps, then create an action plan with owners and target dates. Build and export without an account; sign in when you want to save your plan.

Start the AI governance assessment →