
The short answer: the US regulates AI, but not through one comprehensive federal law
The United States does not currently have one comprehensive federal AI statute. The Congressional Research Service describes the federal position more narrowly: the US has not enacted federal legislation establishing broad regulatory authorities or prohibitions for AI development or use, although federal law does include targeted AI-related provisions (CRS).
For organizations, that means the practical question is not “Is there a US AI law?” It is:
- Which federal laws, agency actions, standards, or procurement rules touch our AI use?
- Which state laws apply based on where we operate, sell, or make decisions about people?
- Which developments are binding now, enacted but date-dependent, merely policy direction, or still proposed?
- Which changes could be affected by federal preemption efforts?
That status distinction matters. A statute, an executive order, a voluntary framework, an enforcement action, and a bill in Congress do not create the same obligations.
The federal layer: laws, executive policy, agencies, and standards
Federal AI activity is real, but it is not one uniform private-sector compliance regime.
Some federal activity is targeted legislation. For example, the TAKE IT DOWN Act became Public Law 119-12 on May 19, 2025. It addresses certain nonconsensual intimate visual depictions, including specified AI-created “digital forgeries,” and requires covered platforms to establish a notice-and-removal process. That is an AI-related federal law, but not a general generative AI statute.
Some activity is executive policy. Executive Order 14179 revoked Executive Order 14110 and directed the development of an AI Action Plan, review of actions taken under the revoked order, and revision of specified OMB AI memoranda. The order is important for federal policy direction, but it does not itself create a comprehensive AI law for private organizations.
Federal AI policy can also matter through government operations and procurement. In April 2025, OMB issued revised policies on federal agencies’ AI use and AI procurement (White House release). These are federal-government operating and acquisition policies, so agencies and federal suppliers should review applicable solicitations, contract terms, and agency requirements rather than assuming a universal private-sector rule.
Agencies can also use existing authority in AI-related contexts. The FTC’s action against allegedly unsupported AI-detection accuracy claims in the Workado matter illustrates that existing consumer-protection authorities can apply to AI-related marketing claims (FTC). That is an enforcement signal, not a new AI-specific rule for every AI claim.
Standards are another layer. NIST describes the AI Risk Management Framework as voluntary guidance for incorporating trustworthiness considerations into AI design, development, use, and evaluation, organized around Govern, Map, Measure, and Manage. It can support governance work, but using it does not automatically satisfy legal obligations.
The state layer: why AI laws by state matter
State law is central to US AI regulation because many AI obligations are emerging at the state level.
Colorado and Texas show why organizations should not wait for a single federal rule before assessing exposure. Colorado’s AI Act imposes requirements from February 1, 2026 on developers and deployers of defined high-risk AI systems, including reasonable-care duties addressing algorithmic discrimination, with specified documentation, assessment, notice, and consumer-rights measures and exclusive enforcement by the Colorado Attorney General (Colorado SB24-205).
Texas’s Responsible Artificial Intelligence Governance Act took effect January 1, 2026. It includes selected disclosure requirements, prohibited uses, enforcement mechanisms, a regulatory sandbox, and an AI council (Texas HB 149).
These examples are selective, not a complete list. The operational lesson is broader: organizations operating across states may need to assess differing laws, effective dates, use-case scopes, covered roles, and enforcement models. A model used only for internal productivity may present a different profile from a system used to make or support consequential decisions about individuals, generate synthetic media, or interact directly with consumers.
State laws also remain relevant while federal preemption efforts are unresolved. Executive-branch activity may change the landscape, but it should not be treated as automatically eliminating state-law obligations unless that result is established through enacted law, court action, or official implementation.
Binding law, policy signal, proposal, or preemption risk: how to read AI regulatory status
Not every item described as “AI regulation” has the same force. Business and governance teams should classify each development before deciding what to operationalize.
| Category | Example | Current status | Who it may affect | What organizations should do |
|---|---|---|---|---|
| Targeted federal law | TAKE IT DOWN Act | Public Law 119-12, enacted May 19, 2025; addresses certain nonconsensual intimate visual depictions, including specified AI-created digital forgeries | Covered platforms and organizations handling relevant user-generated or hosted content | Verify covered-platform status, notice-and-removal duties, and operative dates before implementing controls |
| State AI law | Colorado AI Act | Requirements apply from February 1, 2026 to developers and deployers of defined high-risk AI systems | Organizations developing or deploying covered high-risk systems under the statute’s definitions | Assess whether systems fall within defined high-risk use, then review documentation, assessment, notice, consumer-rights, and governance measures |
| State AI law | Texas TRAIGA | Took effect January 1, 2026; includes selected disclosures, prohibited uses, enforcement mechanisms, sandbox, and AI council | Organizations whose AI activities fall within the statute’s scope and exceptions | Review the statute for specific covered uses, disclosure triggers, prohibited practices, and enforcement exposure |
| Executive policy | Executive Order 14179 | Revoked EO 14110; directed AI Action Plan work, review of prior actions, and revision of specified OMB memoranda | Federal agencies first; private organizations indirectly depending on policy, procurement, or agency action | Monitor implementation, but do not treat the order itself as a general private-sector AI compliance regime |
| Federal agency use and procurement policy | OMB revised AI use and procurement policies | Federal-government operating and acquisition policies | Federal agencies, contractors, and vendors depending on solicitations, contract terms, and agency requirements | Review relevant procurement documents and agency-specific requirements |
| Voluntary standard | NIST AI RMF | Voluntary framework for AI risk management; core functions are Govern, Map, Measure, Manage | Developers, deployers, users, and governance teams seeking a risk-management structure | Use as governance reference where appropriate, without treating it as universal legal compliance |
| Agency enforcement signal | FTC Workado AI-detection claims action | Existing consumer-protection authority applied to allegedly unsupported AI-detection accuracy claims | Organizations making AI-related marketing, performance, or accuracy claims | Substantiate AI claims and avoid overstating capabilities |
| Preemption-related uncertainty | Executive Order 14365 | Directs executive-branch activity concerning state AI laws, including evaluation, possible litigation, funding-condition activity, agency proceedings, and a legislative recommendation; does not itself enact broad statutory preemption | Organizations subject to state AI laws or planning multistate AI governance | Monitor federal action, but continue assessing state obligations unless a specific law is preempted or otherwise changed through official action |
The most common governance mistake is treating all entries in the table as equal. Binding laws may require near-term compliance work. Voluntary standards may help structure controls. Agency actions may signal enforcement risk. Proposed legislation and preemption activity require monitoring, not assumptions.
Which AI uses are most likely to trigger obligations?
Applicability depends on role, location, use case, and legal context. Use this as a triage checklist for counsel, compliance owners, security, product, and governance teams—not as a statutory determination.
- Role: Are you developing, deploying, procuring, reselling, integrating, or merely using the AI system?
- State footprint: Which states do you operate in, sell into, employ people in, or make decisions about users or consumers in?
- Decision impact: Does the system affect employment, credit, housing, healthcare, education, insurance, legal, or similar consequential decisions?
- AI modality: Does it involve generative AI, synthetic media, deepfakes, AI-created intimate imagery, or consumer-facing chatbots?
- Public-sector exposure: Are you selling to a federal agency, state agency, public institution, or regulated government contractor?
- Claims and disclosures: Are you making accuracy, detection, safety, autonomy, or human-oversight claims about the system?
- Documentation: Do you need risk assessments, model or system documentation, approval records, notices, consumer-rights workflows, or monitoring evidence?
- Ownership: Who tracks changes in law, agency guidance, effective dates, contract requirements, and enforcement signals?
This checklist is intentionally broader than any single law. Its purpose is to identify where legal review and governance work are most likely to be needed.
What organizations should do next
Organizations do not need to wait for regulatory certainty to improve AI governance. Sensible next steps are operational:
- Inventory AI systems and use cases. Include internally built tools, vendor systems, embedded product features, pilots, and employee-used AI services.
- Classify by risk and role. Separate developer, deployer, procurer, and user roles where relevant, and flag systems that support consequential decisions or consumer interactions.
- Map state exposure. Track where systems are used, where affected individuals are located, and which state effective dates or scope tests need review.
- Separate status categories. Maintain different workflows for binding obligations, enacted laws with effective dates, voluntary frameworks, enforcement signals, proposals, and preemption developments.
- Document decisions. Keep records of risk assessments, approvals, disclosures, human review, monitoring, vendor due diligence, and claim substantiation where appropriate.
- Use existing controls where possible. AI governance should connect to privacy, security, vendor risk, product review, compliance, and audit evidence processes rather than operate as a standalone spreadsheet.
- Monitor federal and state change. Watch for federal preemption developments, agency action, procurement changes, and updates to state AI laws.
- Get legal review for applicability. Governance controls help teams prepare, but they do not replace legal determinations about whether a specific law applies.
Ciphrix’s role in this environment is operational: helping teams turn shifting AI regulation into inventories, risk classifications, reusable controls, documentation, evidence collection, and monitoring workflows. It should support—not replace—legal analysis, control ownership, or independent compliance judgment.
