All posts
AI Governance8 min readAug 16, 2026

US AI regulations

Ashish / CEO/Co-Founder
US AI regulations

The short answer: the US regulates AI, but not through one comprehensive federal law

The United States does not currently have one comprehensive federal AI statute. The Congressional Research Service describes the federal position more narrowly: the US has not enacted federal legislation establishing broad regulatory authorities or prohibitions for AI development or use, although federal law does include targeted AI-related provisions (CRS).

For organizations, that means the practical question is not “Is there a US AI law?” It is:

  • Which federal laws, agency actions, standards, or procurement rules touch our AI use?
  • Which state laws apply based on where we operate, sell, or make decisions about people?
  • Which developments are binding now, enacted but date-dependent, merely policy direction, or still proposed?
  • Which changes could be affected by federal preemption efforts?

That status distinction matters. A statute, an executive order, a voluntary framework, an enforcement action, and a bill in Congress do not create the same obligations.

The federal layer: laws, executive policy, agencies, and standards

Federal AI activity is real, but it is not one uniform private-sector compliance regime.

Some federal activity is targeted legislation. For example, the TAKE IT DOWN Act became Public Law 119-12 on May 19, 2025. It addresses certain nonconsensual intimate visual depictions, including specified AI-created “digital forgeries,” and requires covered platforms to establish a notice-and-removal process. That is an AI-related federal law, but not a general generative AI statute.

Some activity is executive policy. Executive Order 14179 revoked Executive Order 14110 and directed the development of an AI Action Plan, review of actions taken under the revoked order, and revision of specified OMB AI memoranda. The order is important for federal policy direction, but it does not itself create a comprehensive AI law for private organizations.

Federal AI policy can also matter through government operations and procurement. In April 2025, OMB issued revised policies on federal agencies’ AI use and AI procurement (White House release). These are federal-government operating and acquisition policies, so agencies and federal suppliers should review applicable solicitations, contract terms, and agency requirements rather than assuming a universal private-sector rule.

Agencies can also use existing authority in AI-related contexts. The FTC’s action against allegedly unsupported AI-detection accuracy claims in the Workado matter illustrates that existing consumer-protection authorities can apply to AI-related marketing claims (FTC). That is an enforcement signal, not a new AI-specific rule for every AI claim.

Standards are another layer. NIST describes the AI Risk Management Framework as voluntary guidance for incorporating trustworthiness considerations into AI design, development, use, and evaluation, organized around Govern, Map, Measure, and Manage. It can support governance work, but using it does not automatically satisfy legal obligations.

The state layer: why AI laws by state matter

State law is central to US AI regulation because many AI obligations are emerging at the state level.

Colorado and Texas show why organizations should not wait for a single federal rule before assessing exposure. Colorado’s AI Act imposes requirements from February 1, 2026 on developers and deployers of defined high-risk AI systems, including reasonable-care duties addressing algorithmic discrimination, with specified documentation, assessment, notice, and consumer-rights measures and exclusive enforcement by the Colorado Attorney General (Colorado SB24-205).

Texas’s Responsible Artificial Intelligence Governance Act took effect January 1, 2026. It includes selected disclosure requirements, prohibited uses, enforcement mechanisms, a regulatory sandbox, and an AI council (Texas HB 149).

These examples are selective, not a complete list. The operational lesson is broader: organizations operating across states may need to assess differing laws, effective dates, use-case scopes, covered roles, and enforcement models. A model used only for internal productivity may present a different profile from a system used to make or support consequential decisions about individuals, generate synthetic media, or interact directly with consumers.

State laws also remain relevant while federal preemption efforts are unresolved. Executive-branch activity may change the landscape, but it should not be treated as automatically eliminating state-law obligations unless that result is established through enacted law, court action, or official implementation.

Binding law, policy signal, proposal, or preemption risk: how to read AI regulatory status

Not every item described as “AI regulation” has the same force. Business and governance teams should classify each development before deciding what to operationalize.

CategoryExampleCurrent statusWho it may affectWhat organizations should do
Targeted federal lawTAKE IT DOWN ActPublic Law 119-12, enacted May 19, 2025; addresses certain nonconsensual intimate visual depictions, including specified AI-created digital forgeriesCovered platforms and organizations handling relevant user-generated or hosted contentVerify covered-platform status, notice-and-removal duties, and operative dates before implementing controls
State AI lawColorado AI ActRequirements apply from February 1, 2026 to developers and deployers of defined high-risk AI systemsOrganizations developing or deploying covered high-risk systems under the statute’s definitionsAssess whether systems fall within defined high-risk use, then review documentation, assessment, notice, consumer-rights, and governance measures
State AI lawTexas TRAIGATook effect January 1, 2026; includes selected disclosures, prohibited uses, enforcement mechanisms, sandbox, and AI councilOrganizations whose AI activities fall within the statute’s scope and exceptionsReview the statute for specific covered uses, disclosure triggers, prohibited practices, and enforcement exposure
Executive policyExecutive Order 14179Revoked EO 14110; directed AI Action Plan work, review of prior actions, and revision of specified OMB memorandaFederal agencies first; private organizations indirectly depending on policy, procurement, or agency actionMonitor implementation, but do not treat the order itself as a general private-sector AI compliance regime
Federal agency use and procurement policyOMB revised AI use and procurement policiesFederal-government operating and acquisition policiesFederal agencies, contractors, and vendors depending on solicitations, contract terms, and agency requirementsReview relevant procurement documents and agency-specific requirements
Voluntary standardNIST AI RMFVoluntary framework for AI risk management; core functions are Govern, Map, Measure, ManageDevelopers, deployers, users, and governance teams seeking a risk-management structureUse as governance reference where appropriate, without treating it as universal legal compliance
Agency enforcement signalFTC Workado AI-detection claims actionExisting consumer-protection authority applied to allegedly unsupported AI-detection accuracy claimsOrganizations making AI-related marketing, performance, or accuracy claimsSubstantiate AI claims and avoid overstating capabilities
Preemption-related uncertaintyExecutive Order 14365Directs executive-branch activity concerning state AI laws, including evaluation, possible litigation, funding-condition activity, agency proceedings, and a legislative recommendation; does not itself enact broad statutory preemptionOrganizations subject to state AI laws or planning multistate AI governanceMonitor federal action, but continue assessing state obligations unless a specific law is preempted or otherwise changed through official action

The most common governance mistake is treating all entries in the table as equal. Binding laws may require near-term compliance work. Voluntary standards may help structure controls. Agency actions may signal enforcement risk. Proposed legislation and preemption activity require monitoring, not assumptions.

Which AI uses are most likely to trigger obligations?

Applicability depends on role, location, use case, and legal context. Use this as a triage checklist for counsel, compliance owners, security, product, and governance teams—not as a statutory determination.

  • Role: Are you developing, deploying, procuring, reselling, integrating, or merely using the AI system?
  • State footprint: Which states do you operate in, sell into, employ people in, or make decisions about users or consumers in?
  • Decision impact: Does the system affect employment, credit, housing, healthcare, education, insurance, legal, or similar consequential decisions?
  • AI modality: Does it involve generative AI, synthetic media, deepfakes, AI-created intimate imagery, or consumer-facing chatbots?
  • Public-sector exposure: Are you selling to a federal agency, state agency, public institution, or regulated government contractor?
  • Claims and disclosures: Are you making accuracy, detection, safety, autonomy, or human-oversight claims about the system?
  • Documentation: Do you need risk assessments, model or system documentation, approval records, notices, consumer-rights workflows, or monitoring evidence?
  • Ownership: Who tracks changes in law, agency guidance, effective dates, contract requirements, and enforcement signals?

This checklist is intentionally broader than any single law. Its purpose is to identify where legal review and governance work are most likely to be needed.

What organizations should do next

Organizations do not need to wait for regulatory certainty to improve AI governance. Sensible next steps are operational:

  1. Inventory AI systems and use cases. Include internally built tools, vendor systems, embedded product features, pilots, and employee-used AI services.
  2. Classify by risk and role. Separate developer, deployer, procurer, and user roles where relevant, and flag systems that support consequential decisions or consumer interactions.
  3. Map state exposure. Track where systems are used, where affected individuals are located, and which state effective dates or scope tests need review.
  4. Separate status categories. Maintain different workflows for binding obligations, enacted laws with effective dates, voluntary frameworks, enforcement signals, proposals, and preemption developments.
  5. Document decisions. Keep records of risk assessments, approvals, disclosures, human review, monitoring, vendor due diligence, and claim substantiation where appropriate.
  6. Use existing controls where possible. AI governance should connect to privacy, security, vendor risk, product review, compliance, and audit evidence processes rather than operate as a standalone spreadsheet.
  7. Monitor federal and state change. Watch for federal preemption developments, agency action, procurement changes, and updates to state AI laws.
  8. Get legal review for applicability. Governance controls help teams prepare, but they do not replace legal determinations about whether a specific law applies.

Ciphrix’s role in this environment is operational: helping teams turn shifting AI regulation into inventories, risk classifications, reusable controls, documentation, evidence collection, and monitoring workflows. It should support—not replace—legal analysis, control ownership, or independent compliance judgment.

Get started

Ready to see Ciphrix in action?

Built by AWS Security Leaders | AWS Partner | Certified companies across 3 continents