Home / Knowledge Base / US AI Regulation
Federal · State · Sector

The US AI regulatory landscape, explained.

There is no single US "AI Act." Instead, obligations come from three directions at once: a shifting federal posture and procurement rules, a growing patchwork of state laws, and long-standing sector enforcement by agencies like the FTC and under HIPAA. This page maps the pieces that most affect enterprises deploying AI.

Federal: OMB guidance + agency rules Colorado AI Act: eff. 30 Jun 2026 California: AB 2013 · SB 942 Utah: AI Policy Act
Overview

The shape of US AI regulation

Unlike the EU's single horizontal statute, the United States regulates AI through a layered, fragmented model. Three layers stack on top of each other:

  • Federal — executive-branch policy, government-wide procurement and use rules via the Office of Management and Budget (OMB), and agency-specific action. Legislation has been proposed but no comprehensive federal AI law has been enacted.
  • State — the fastest-moving layer, with comprehensive laws (Colorado), transparency statutes (California), and government-use rules (Utah), plus dozens of narrower bills.
  • Sector — existing law applied to AI: unfair/deceptive-practices enforcement by the FTC, health-data rules under HIPAA, credit rules under the FCRA/ECOA, and more.
The practical consequence. A company operating nationally must comply with the strictest applicable state rule for a given use, while also meeting sector obligations and federal procurement terms — an operational reason to keep a single, framework-neutral AI inventory rather than one per jurisdiction.
Layer 1

Federal posture & OMB guidance

The federal approach has shifted with successive executive orders, but the durable, operational core sits in OMB guidance to federal agencies on how the government itself develops, buys, and uses AI. The key memoranda — M-24-10 (governance and risk management for federal AI use) and M-24-18 (responsible AI acquisition) — established, for federal agencies:

  • A Chief AI Officer and agency AI governance structures.
  • Inventories of AI use cases, published annually.
  • Minimum risk-management practices for "rights-impacting" and "safety-impacting" AI — including impact assessments, testing, ongoing monitoring, and human oversight, echoing the NIST AI RMF.
  • Procurement conditions that push these expectations onto federal contractors.

Because federal procurement is enormous, these rules act as a de-facto standard for any vendor selling AI to the US government, even though they are not general-purpose law binding on private industry. NIST's AI RMF and the AI Safety Institute provide the technical backbone the federal posture leans on.

Layer 2

State laws — the fastest-moving layer

In the absence of a federal statute, states have moved first. The three most consequential for enterprises are Colorado, California, and Utah.

Colorado AI Act (SB 24-205)

Effective 30 Jun 2026

The first US comprehensive, EU-style AI law. It targets "high-risk AI systems" that make, or are a substantial factor in, a consequential decision (affecting employment, education, financial/lending services, housing, insurance, healthcare, legal services, or government services). It imposes a duty of reasonable care to protect consumers from algorithmic discrimination, with concrete obligations on both sides of the market:

  • Developers — provide documentation, disclosures, and known-risk information to deployers; make a public statement about high-risk systems.
  • Deployers — implement a risk-management policy and program, complete impact assessments, notify consumers when a high-risk system is used in a consequential decision, provide an opportunity to correct data and appeal to human review, and disclose to the Colorado Attorney General upon discovering algorithmic discrimination.

Enforced exclusively by the Colorado Attorney General (no private right of action). Widely watched as a template for other states; its effective date has been the subject of amendment discussion.

California — AB 2013 & SB 942

Eff. 1 Jan 2026

California legislates AI through several targeted statutes rather than one law:

  • AB 2013 — Generative AI: training-data transparency. Requires developers of generative AI systems made available to Californians to publicly post a high-level summary of the datasets used to train the system (sources, whether it includes personal or copyrighted data, size, time period). Applies from 1 January 2026, including to systems released since 2022.
  • SB 942 — California AI Transparency Act. Requires covered providers of widely used generative AI to offer a free AI-detection tool and to include latent and manifest disclosures / provenance metadata marking content as AI-generated.

California has also enacted laws on AI in employment decisions, healthcare communications, deepfakes/election content, and digital-likeness rights — plus CPPA rulemaking on automated decision-making technology under the CCPA.

Utah AI Policy Act (SB 149)

Effective 1 May 2024

One of the earliest state AI laws in force. It centres on consumer transparency: a person or business that uses generative AI to interact with consumers must, if asked, clearly disclose that the consumer is interacting with AI and not a human; for regulated occupations (e.g. licensed professions), disclosure must be proactive and prominent. It also created an Office of Artificial Intelligence Policy and an "AI Learning Laboratory" regulatory sandbox, and clarified that businesses cannot blame an AI tool to escape liability under consumer-protection law.

Other notable states

The landscape is broad and growing: Illinois (BIPA biometric privacy; AI in video-interview and employment law), New York City (Local Law 144 — bias audits for automated employment decision tools), Texas (the Responsible AI Governance Act, TRAIGA), and Tennessee (the ELVIS Act on voice/likeness) are among the most cited. Many states have also enacted deepfake and election-integrity provisions.

Layer 3

Sector rules — existing law applied to AI

Even without AI-specific statutes, established regulators apply existing authority to AI:

Regulator / ruleHow it reaches AI
FTC (Section 5, FTC Act)Treats unfair or deceptive AI claims and practices as enforceable — overstated capabilities, biased or harmful automated decisions, and misuse of data to train models. Has ordered algorithmic disgorgement (deletion of models built on ill-gotten data).
HIPAA (HHS / OCR)AI that processes protected health information is subject to the Privacy and Security Rules — covered entities and business associates must safeguard PHI used to train or run models, with BAAs in place.
FCRA / ECOA (CFPB)AI used in credit and lending decisions must meet adverse-action notice and anti-discrimination requirements; "black-box" models do not excuse a lack of specific reasons.
EEOCAI in hiring and employment is subject to anti-discrimination law (Title VII, ADA); vendors and employers can be liable for disparate impact.
SEC / FINRAScrutinise AI in trading, advice ("AI washing"), and disclosures in financial services.
Practical

What it means for a security & compliance team

  • Comply to the strictest applicable rule. If you serve consumers nationally, design to Colorado's high-risk duties and California's transparency requirements rather than the lowest common denominator.
  • Transparency is the common thread. Disclosing AI interactions (Utah), marking synthetic content (California SB 942), and publishing training-data summaries (California AB 2013) all demand you know where generative AI is used across the business.
  • Inventory first. Colorado impact assessments, OMB-style use-case inventories, and sector obligations all begin with the same artefact: a complete, current inventory of AI systems, their purpose, and their data flows.
  • Reuse one control set. The NIST AI RMF underpins the federal posture and maps cleanly to Colorado's risk-management program and the EU AI Act — build the evidence once and reuse it.
Where Shadow AI Discovery fits. Every layer of the US landscape starts with discovery — a live inventory of AI systems, who uses them, and what data they touch. That is exactly what the sensor produces, and it maps the same findings to the EU AI Act and NIST AI RMF at the same time.
Sources

References

Not legal advice. US AI regulation is fast-moving; effective dates and requirements change through amendment and rulemaking. This explainer summarises publicly available materials as of 2025–2026 and should be validated with qualified counsel for any specific obligation.