Trackers
Trackers

AI Regulation in USA: 2026 Update

AI regulation in the USA is evolving rapidly, with no single federal AI law yet in force but a dense and growing patchwork of executive orders, agency guidance, sector-specific rules, and state legislation shaping what businesses can and cannot do with artificial intelligence. Companies operating in the US market face real compliance exposure today, even in the absence of a comprehensive statute. This guide covers the current federal framework, the most significant state laws, sector-specific requirements, enforcement trends, and practical steps for businesses building or deploying AI systems in the United States.

The federal AI regulatory landscape in the USA

The United States has taken a sector-led, agency-driven approach to AI governance rather than enacting a single omnibus AI statute comparable to the European Union';s AI Act. The primary federal instrument shaping AI policy has been executive action. A landmark executive order on the safe, secure, and trustworthy development and use of artificial intelligence directed federal agencies to develop sector-specific guidance, risk assessments, and procurement standards for AI systems. That order established reporting requirements for developers of the most powerful AI models and tasked agencies including the National Institute of Standards and Technology (NIST), the Federal Trade Commission (FTC), the Equal Employment Opportunity Commission (EEOC), and the Consumer Financial Protection Bureau (CFPB) with producing AI-specific guidance within their existing mandates.

NIST published the AI Risk Management Framework (AI RMF), a voluntary but widely adopted standard that organises AI risk into four core functions: govern, map, measure, and manage. While the AI RMF is not legally binding, federal procurement increasingly references it, and regulators cite it as a benchmark for reasonable AI governance practices. Businesses supplying AI-enabled products or services to the federal government should treat the AI RMF as a de facto compliance floor.

Congress has introduced numerous AI-related bills but has not yet passed comprehensive federal AI legislation. The legislative landscape remains fragmented, with proposals addressing algorithmic transparency, deepfakes, AI in hiring, and national security applications advancing at different speeds through different committees. Businesses should monitor legislative developments closely, as the passage of even one major bill could reshape compliance obligations across industries.

Key federal agencies and their AI enforcement roles

Several federal agencies have asserted jurisdiction over AI-related conduct using existing statutory authority, and enforcement actions have already been brought.

The FTC has authority under Section 5 of the FTC Act to act against unfair or deceptive practices, which it has applied to AI-generated content, biased algorithmic systems, and misleading claims about AI capabilities. The FTC has issued guidance warning companies against using AI to deceive consumers, manipulate behaviour, or engage in discriminatory targeting. Enforcement actions and consent orders in this space have established that AI is not a shield against consumer protection liability.

The EEOC has clarified that employment discrimination law - including Title VII of the Civil Rights Act, the Age Discrimination in Employment Act, and the Americans with Disabilities Act - applies fully to AI-assisted hiring, promotion, and performance management tools. Employers using AI-driven applicant screening or workforce analytics tools carry the same legal exposure as those using human decision-makers, and the EEOC has signalled active interest in investigating algorithmic bias complaints.

The CFPB has addressed AI in credit decisioning, emphasising that the Equal Credit Opportunity Act requires lenders to provide specific, accurate reasons for adverse credit decisions even when those decisions are made by complex AI models. Citing "the model said so" is not a compliant adverse action notice. The CFPB has also raised concerns about AI-powered chatbots in financial services that may mislead consumers about the nature of the advice they receive.

The Food and Drug Administration (FDA) regulates AI and machine learning software as a medical device (SaMD) under existing device law, with a published action plan for AI/ML-based software that introduces a concept of predetermined change control plans to manage iterative model updates without requiring full re-approval for each change.

The Department of Transportation and the National Highway Traffic Safety Administration (NHTSA) oversee AI in autonomous vehicles, with standing guidance on safety assessment and incident reporting for automated driving systems.

State AI laws: the most significant jurisdictions

In the absence of federal legislation, states have moved aggressively. The result is a compliance map that varies significantly by state and by use case.

Colorado enacted the Colorado AI Act, one of the most comprehensive state AI laws to date, modelled in part on the EU AI Act';s risk-based approach. It imposes obligations on developers and deployers of high-risk AI systems - defined as systems that make or substantially assist consequential decisions in areas such as employment, education, housing, credit, healthcare, and insurance. Covered entities must conduct impact assessments, disclose AI use to affected individuals, provide a mechanism for human review of adverse AI decisions, and notify the Attorney General of known algorithmic discrimination. The law applies to any business that deploys covered AI systems to Colorado residents, regardless of where the business is incorporated.

California has enacted multiple AI-related statutes. The California Consumer Privacy Act (CCPA) and its amendment, the California Privacy Rights Act (CPRA), grant consumers rights to opt out of automated decision-making that produces significant effects, to request human review, and to obtain explanations of AI-driven decisions. Separate California legislation addresses AI-generated deepfakes in political advertising and in intimate imagery, disclosure requirements for AI-generated content, and restrictions on the use of AI in certain employment contexts. The California Privacy Protection Agency (CPPA) has been developing regulations on automated decision-making technology (ADMT) that would impose additional transparency and opt-out requirements.

Illinois has the Artificial Intelligence Video Interview Act, which requires employers using AI to analyse video interviews to disclose this use to applicants, obtain consent, and limit the sharing of interview data. Illinois also has the Biometric Information Privacy Act (BIPA), which applies to AI systems that collect or process biometric identifiers such as facial geometry or voiceprints, with a private right of action that has generated substantial litigation.

Texas, Virginia, and several other states have enacted or are advancing consumer privacy laws with automated decision-making provisions that affect AI deployments. New York City has Local Law 144, which requires employers using automated employment decision tools to conduct annual bias audits and disclose AI use to candidates.

In practice, a company deploying AI in hiring, lending, healthcare, or consumer-facing applications across multiple US states must map its AI systems against a matrix of state laws that differ in scope, definitions, and enforcement mechanisms.

Sector-specific AI compliance requirements

Beyond horizontal AI laws, sector-specific rules create layered obligations for businesses in regulated industries.

In financial services, AI models used in credit underwriting, fraud detection, anti-money laundering, and trading are subject to existing model risk management guidance. The Office of the Comptroller of the Currency (OCC), the Federal Reserve, and the FDIC have all issued guidance on model risk management - most notably the interagency guidance on model risk management known as SR 11-7 - that applies to AI and machine learning models used by banks and their service providers. This guidance requires model validation, documentation, ongoing monitoring, and governance structures that many AI vendors are not accustomed to providing.

In healthcare, AI tools used in clinical decision support, diagnostic imaging, and patient triage are regulated as medical devices by the FDA where they meet the statutory definition of a device. Non-device AI in healthcare - such as administrative automation or population health analytics - is subject to HIPAA requirements on the use and disclosure of protected health information, including when that information is used to train or fine-tune AI models. The use of patient data to train AI without proper authorisation is a HIPAA violation regardless of the AI context.

In education, the Family Educational Rights and Privacy Act (FERPA) governs the use of student data in AI systems deployed by educational institutions. EdTech companies using AI to personalise learning or assess student performance must ensure their data practices comply with FERPA';s restrictions on disclosure and use.

In the defence and national security sector, the Department of Defense has its own AI ethics principles and acquisition policies, and AI systems used in defence contracting are subject to additional security and assurance requirements.

If your business operates across multiple regulated sectors or deploys AI systems that touch several of these domains simultaneously, the compliance picture becomes complex quickly. Reaching out to specialised counsel early is advisable. We can help structure the compliance approach correctly from the outset - contact us at info@vlolawfirm.com.

Practical compliance steps for businesses deploying AI in the USA

Building a defensible AI compliance programme in the US market requires addressing several concrete workstreams, regardless of whether a comprehensive federal law is yet in force.

The first priority is AI inventory and risk classification. Businesses should catalogue all AI systems they develop or deploy, document their intended use cases and the decisions they influence, and classify each system by the risk level it presents - particularly whether it affects employment, credit, housing, healthcare, education, or other consequential domains. This inventory forms the foundation of any compliance programme and is required explicitly by laws such as the Colorado AI Act.

Impact assessments are increasingly required or expected. The Colorado AI Act mandates them for high-risk AI. The CPPA';s proposed ADMT regulations contemplate them for California. The NIST AI RMF recommends them as part of the "map" function. An impact assessment documents the purpose of the AI system, the data it uses, the population it affects, the potential for discriminatory or harmful outcomes, and the mitigations in place. Conducting and documenting these assessments before deployment - not after a complaint - is the practical standard regulators expect.

Transparency and disclosure obligations are proliferating. Businesses should audit their customer-facing and employee-facing communications to ensure that AI use is disclosed where required, that consumers and applicants understand when AI is influencing decisions about them, and that opt-out or human review mechanisms are available where mandated. This includes reviewing privacy policies, terms of service, adverse action notices, and hiring communications.

Vendor and third-party AI governance is a frequently overlooked area. Many businesses deploy AI through third-party platforms, APIs, or software-as-a-service tools without fully understanding the AI components embedded in those products. Under most applicable laws, the deployer - not the developer - bears primary compliance responsibility for how an AI system affects individuals. Contracts with AI vendors should address data use, model documentation, bias testing, incident notification, and audit rights.

Bias testing and ongoing monitoring are required by several state laws and expected by federal agencies. AI systems used in employment, credit, and other high-stakes domains should be tested for disparate impact across protected classes before deployment and monitored on an ongoing basis. Where bias is detected, businesses must be able to demonstrate that they investigated and took corrective action.

Incident response planning for AI-specific failures - including model drift, adversarial attacks, data poisoning, and outputs that cause harm - is an emerging compliance expectation. Businesses should define what constitutes an AI incident, establish escalation procedures, and understand any notification obligations that may apply under state AI laws or sector-specific regulations.

Enforcement trends and litigation risk in AI regulation

Enforcement of AI-related obligations in the USA is active and accelerating, even without comprehensive federal legislation.

The FTC has brought enforcement actions against companies making false or misleading claims about AI capabilities, using AI to facilitate deceptive practices, and deploying AI in ways that cause consumer harm. Consent orders have included requirements to delete unlawfully collected data, conduct algorithmic audits, and implement AI governance programmes.

EEOC investigations into AI-driven employment discrimination are ongoing. Several private lawsuits have been filed against employers and AI vendors alleging that algorithmic hiring tools produce discriminatory outcomes in violation of Title VII and state anti-discrimination laws. Courts have generally allowed these cases to proceed, establishing that plaintiffs can challenge AI-driven employment decisions under existing civil rights frameworks.

BIPA litigation in Illinois has produced some of the largest class action settlements in US history, and AI systems that collect biometric data - including facial recognition, voice analysis, and emotion detection tools - are squarely within BIPA';s scope. Companies deploying such systems in Illinois without proper consent and data governance face substantial class action exposure.

State attorneys general are also active. Several have issued civil investigative demands to AI companies and have signalled that enforcement of state AI and consumer protection laws is a priority. The Colorado Attorney General';s office has enforcement authority under the Colorado AI Act.

A common mistake among foreign companies entering the US market is assuming that the absence of a federal AI law means AI is unregulated in the United States. In practice, the combination of agency enforcement, state legislation, and private litigation creates a compliance environment that is demanding and consequential.

FAQ

What AI-specific laws apply to businesses operating across multiple US states?

There is no single federal AI law that applies uniformly across all states. Businesses must comply with a combination of federal agency requirements - such as FTC consumer protection rules, EEOC employment discrimination guidance, and CFPB credit decisioning requirements - and an expanding set of state laws. Colorado';s AI Act, California';s CPRA automated decision-making provisions, Illinois';s BIPA and AI Video Interview Act, and New York City';s Local Law 144 are among the most significant current requirements. A business deploying AI in hiring, lending, or consumer-facing applications across multiple states should conduct a state-by-state compliance mapping exercise, as the obligations differ in scope, definitions, and enforcement mechanisms. Treating the most demanding applicable state law as the baseline is a practical starting point.

How long does it take to build an AI compliance programme, and what does it cost?

The timeline and cost depend heavily on the number of AI systems in use, the sectors in which the business operates, and the maturity of existing data governance and risk management infrastructure. A focused compliance review for a single AI application in a single sector can typically be completed within a few weeks. A comprehensive enterprise-wide AI governance programme covering multiple systems, multiple states, and multiple regulated industries is a multi-month undertaking. Professional fees for legal and technical advisory work vary widely based on scope. Businesses that have invested in data governance, model documentation, and vendor management programmes will find the incremental cost of AI compliance lower than those starting from scratch. Delaying compliance work until after a regulatory inquiry or litigation is filed is consistently more expensive than proactive investment.

Should a business wait for federal AI legislation before building a compliance programme?

Waiting for federal legislation is not a viable strategy. State laws are already in force and enforceable, federal agencies are actively using existing authority to pursue AI-related violations, and private litigation under civil rights, consumer protection, and biometric privacy statutes is producing real financial exposure now. A federal AI law, if enacted, is likely to set a floor rather than a ceiling, leaving state laws with stronger protections in place. Businesses that build AI governance programmes aligned with the NIST AI RMF, the Colorado AI Act, and applicable sector-specific requirements will be well positioned to adapt to federal legislation when it arrives, rather than facing a compliance gap at the point of enactment.

Conclusion

AI regulation in the USA is not a future concern - it is a present compliance reality shaped by agency enforcement, state legislation, and active litigation. The regulatory environment will continue to develop as federal legislation advances and state laws multiply. Businesses that invest in AI governance now, map their systems against applicable requirements, and build transparency and accountability into their AI deployments will be better positioned to operate in this environment.

VLO Law Firms advises international clients on AI regulation in the USA. We can assist with AI compliance programme design, risk classification, impact assessments, vendor contract review, and regulatory response. To request a consultation, contact: info@vlolawfirm.com