# US AI Regulation Checklist and SaaS Applicability Matrix

The regulatory picture for a US-based SaaS company: a landscape map of federal and key state law, a sector-specific rule checklist, and a matrix mapping product features to the rules they trigger.

**Who this is for:** The compliance or legal owner at a US SaaS company working out which AI rules bite.

Source playbook: https://aigovernance.com/playbook/ai-regulations-us-saas

---

## US AI regulatory landscape map

_The federal and state instruments that could apply, with their trigger and status._

### Template

| Instrument | Level | Trigger | Applies to us? | Key obligations | Status |
|---|---|---|---|---|---|
| FTC Act Section 5 (unfair/deceptive) | Federal | AI claims; biased or harmful outcomes | | substantiate claims; avoid unfair practices | |
| EEOC / Title VII (employment) | Federal | AI in hiring or HR decisions | | adverse-impact analysis | |
| Colorado AI Act (SB205) | State (CO) | high-risk AI affecting CO consumers | | risk mgmt, impact assessment, disclosure | |
| California ADMT / privacy rules | State (CA) | automated decision-making on CA residents | | notice, opt-out, risk assessment | |
| NYC Local Law 144 | City (NYC) | automated employment decision tools | | annual bias audit; notice | |
| Illinois BIPA / AI video interview act | State (IL) | biometrics; AI video interviews | | consent; disclosure | |
| Sector rules (see sector checklist) | Federal/State | financial, health, insurance use | | sector-specific | |

### Worked example

| Instrument | Applies to us? | Note |
|---|---|---|
| FTC Act Section 5 | Yes | our marketing makes AI accuracy claims; substantiation file needed |
| EEOC / Title VII | Yes (via customers) | our screening feature is an ADT for customers; we support their audits |
| Colorado SB205 | Yes | customers use our tool for consequential decisions on CO consumers |
| California ADMT | Yes | provide opt-out and notice tooling to customers |
| NYC LL144 | Yes | bias audit support feature shipped |
| Illinois BIPA | Monitoring | no biometric features today; flagged if added |

### Acceptance criteria

- Federal, state, and city instruments are all considered, not just federal.
- Each row states whether the obligation falls on us directly or via our customers.
- "Monitoring" rows name the feature or expansion that would make them apply.

---

## Sector-specific AI rule checklist

_Extra obligations that attach when the product is used in a regulated sector._

### Template

| Sector | Rule / regulator | Trigger | Obligation | Do we support it? |
|---|---|---|---|---|
| Financial services | ECOA / Reg B; fair lending; model risk (SR 11-7 analogues) | credit or lending decisions | adverse-action reasons; model validation; disparate-impact testing | |
| Healthcare | FDA (SaMD); HIPAA; ONC | clinical decision support; PHI | clearance where applicable; PHI safeguards; transparency | |
| Employment | EEOC; state ADT laws | hiring, promotion, termination | adverse-impact analysis; audit support; candidate notice | |
| Insurance | state insurance codes; NAIC model bulletin | underwriting, pricing, claims | documentation; unfair discrimination testing; governance | |

### Worked example

| Sector | Rule | Applies? | What we ship |
|---|---|---|---|
| Financial services | ECOA / Reg B | Yes | reason-code export; model documentation pack; disparate-impact report |
| Employment | EEOC + NYC LL144 + IL | Yes | bias audit export; candidate notice templates |
| Insurance | NAIC model bulletin | Monitoring | governance documentation available; no dedicated testing feature yet |
| Healthcare | FDA SaMD | No | product not used for clinical decisions; contractual prohibition |

### Acceptance criteria

- Every sector the product is sold into has its rules assessed.
- For each applicable rule, the product capability that supports customer compliance is named.
- Sectors that are contractually out of scope are recorded as such.

---

## Product feature to regulation matrix

_Maps each AI feature to the rules it triggers, so product changes surface compliance impact._

### Template

| Feature | What it does | Regulations triggered | Compliance requirements | Owner |
|---|---|---|---|---|
| <feature> | | | | |

### Worked example

| Feature | What it does | Regulations triggered | Compliance requirements | Owner |
|---|---|---|---|---|
| Applicant ranking | scores/ranks job applicants | EEOC/Title VII, NYC LL144, IL, CO SB205 | adverse-impact testing; bias audit export; candidate notice; risk assessment | Product + Compliance |
| Churn prediction | flags at-risk customers | FTC Section 5 (if used for pricing/denial) | no protected-class proxies; documentation | Product |
| AI chat assistant | answers user questions | FTC Section 5; state chatbot disclosure laws | disclosure that it is AI; accuracy controls | Product |

### Acceptance criteria

- Every shipped AI feature has a row.
- A new feature or a material change to one triggers a review of this matrix before launch.
- Each row names the compliance requirements and an owner.

---

## Governance controls this kit produces evidence for

- **CMP-008**: The landscape map is the federal (and state) AI regulatory monitoring and pre-deployment vetting record.
- **CMP-001**: The feature-to-regulation matrix is multi-jurisdiction compliance mapping at the feature level.
- **CMP-010**: Financial-sector rows cover AI use in regulated reporting and risk modeling.
- **SCT-004**: Insurance-sector rows map to insurance-sector AI documentation standards.
- **HOC-001**: Feature-level applicability depends on classifying each feature's risk and impact.
