The shape of US AI regulation
Unlike the EU's single horizontal statute, the United States regulates AI through a layered, fragmented model. Three layers stack on top of each other:
- Federal — executive-branch policy, government-wide procurement and use rules via the Office of Management and Budget (OMB), and agency-specific action. Legislation has been proposed but no comprehensive federal AI law has been enacted.
- State — the fastest-moving layer, with comprehensive laws (Colorado), transparency statutes (California), and government-use rules (Utah), plus dozens of narrower bills.
- Sector — existing law applied to AI: unfair/deceptive-practices enforcement by the FTC, health-data rules under HIPAA, credit rules under the FCRA/ECOA, and more.
Federal posture & OMB guidance
The federal approach has shifted with successive executive orders, but the durable, operational core sits in OMB guidance to federal agencies on how the government itself develops, buys, and uses AI. The key memoranda — M-24-10 (governance and risk management for federal AI use) and M-24-18 (responsible AI acquisition) — established, for federal agencies:
- A Chief AI Officer and agency AI governance structures.
- Inventories of AI use cases, published annually.
- Minimum risk-management practices for "rights-impacting" and "safety-impacting" AI — including impact assessments, testing, ongoing monitoring, and human oversight, echoing the NIST AI RMF.
- Procurement conditions that push these expectations onto federal contractors.
Because federal procurement is enormous, these rules act as a de-facto standard for any vendor selling AI to the US government, even though they are not general-purpose law binding on private industry. NIST's AI RMF and the AI Safety Institute provide the technical backbone the federal posture leans on.
State laws — the fastest-moving layer
In the absence of a federal statute, states have moved first. The three most consequential for enterprises are Colorado, California, and Utah.
Colorado AI Act (SB 24-205)
Effective 30 Jun 2026The first US comprehensive, EU-style AI law. It targets "high-risk AI systems" that make, or are a substantial factor in, a consequential decision (affecting employment, education, financial/lending services, housing, insurance, healthcare, legal services, or government services). It imposes a duty of reasonable care to protect consumers from algorithmic discrimination, with concrete obligations on both sides of the market:
- Developers — provide documentation, disclosures, and known-risk information to deployers; make a public statement about high-risk systems.
- Deployers — implement a risk-management policy and program, complete impact assessments, notify consumers when a high-risk system is used in a consequential decision, provide an opportunity to correct data and appeal to human review, and disclose to the Colorado Attorney General upon discovering algorithmic discrimination.
Enforced exclusively by the Colorado Attorney General (no private right of action). Widely watched as a template for other states; its effective date has been the subject of amendment discussion.
California — AB 2013 & SB 942
Eff. 1 Jan 2026California legislates AI through several targeted statutes rather than one law:
- AB 2013 — Generative AI: training-data transparency. Requires developers of generative AI systems made available to Californians to publicly post a high-level summary of the datasets used to train the system (sources, whether it includes personal or copyrighted data, size, time period). Applies from 1 January 2026, including to systems released since 2022.
- SB 942 — California AI Transparency Act. Requires covered providers of widely used generative AI to offer a free AI-detection tool and to include latent and manifest disclosures / provenance metadata marking content as AI-generated.
California has also enacted laws on AI in employment decisions, healthcare communications, deepfakes/election content, and digital-likeness rights — plus CPPA rulemaking on automated decision-making technology under the CCPA.
Utah AI Policy Act (SB 149)
Effective 1 May 2024One of the earliest state AI laws in force. It centres on consumer transparency: a person or business that uses generative AI to interact with consumers must, if asked, clearly disclose that the consumer is interacting with AI and not a human; for regulated occupations (e.g. licensed professions), disclosure must be proactive and prominent. It also created an Office of Artificial Intelligence Policy and an "AI Learning Laboratory" regulatory sandbox, and clarified that businesses cannot blame an AI tool to escape liability under consumer-protection law.
Other notable states
The landscape is broad and growing: Illinois (BIPA biometric privacy; AI in video-interview and employment law), New York City (Local Law 144 — bias audits for automated employment decision tools), Texas (the Responsible AI Governance Act, TRAIGA), and Tennessee (the ELVIS Act on voice/likeness) are among the most cited. Many states have also enacted deepfake and election-integrity provisions.
Sector rules — existing law applied to AI
Even without AI-specific statutes, established regulators apply existing authority to AI:
| Regulator / rule | How it reaches AI |
|---|---|
| FTC (Section 5, FTC Act) | Treats unfair or deceptive AI claims and practices as enforceable — overstated capabilities, biased or harmful automated decisions, and misuse of data to train models. Has ordered algorithmic disgorgement (deletion of models built on ill-gotten data). |
| HIPAA (HHS / OCR) | AI that processes protected health information is subject to the Privacy and Security Rules — covered entities and business associates must safeguard PHI used to train or run models, with BAAs in place. |
| FCRA / ECOA (CFPB) | AI used in credit and lending decisions must meet adverse-action notice and anti-discrimination requirements; "black-box" models do not excuse a lack of specific reasons. |
| EEOC | AI in hiring and employment is subject to anti-discrimination law (Title VII, ADA); vendors and employers can be liable for disparate impact. |
| SEC / FINRA | Scrutinise AI in trading, advice ("AI washing"), and disclosures in financial services. |
What it means for a security & compliance team
- Comply to the strictest applicable rule. If you serve consumers nationally, design to Colorado's high-risk duties and California's transparency requirements rather than the lowest common denominator.
- Transparency is the common thread. Disclosing AI interactions (Utah), marking synthetic content (California SB 942), and publishing training-data summaries (California AB 2013) all demand you know where generative AI is used across the business.
- Inventory first. Colorado impact assessments, OMB-style use-case inventories, and sector obligations all begin with the same artefact: a complete, current inventory of AI systems, their purpose, and their data flows.
- Reuse one control set. The NIST AI RMF underpins the federal posture and maps cleanly to Colorado's risk-management program and the EU AI Act — build the evidence once and reuse it.
References
- Colorado SB 24-205 — Consumer Protections for AI (Colorado AI Act)Full bill text and status.
- California AB 2013 — Generative AI: Training Data TransparencyTraining-data summary requirement (eff. 1 Jan 2026).
- California SB 942 — California AI Transparency ActAI-detection tool and provenance disclosure.
- Utah SB 149 — Artificial Intelligence Policy ActConsumer-disclosure duties (eff. 1 May 2024).
- OMB — Office of Information and Regulatory Affairs (AI memoranda M-24-10 / M-24-18)Federal AI governance and acquisition guidance.
- FTC — Business guidance on AIEnforcement posture on AI claims and practices.
- HHS — HIPAAPrivacy and Security Rules governing PHI in AI systems.
- NCSL — AI state-legislation trackerComprehensive, regularly updated survey of state AI bills.