United States · Last reviewed 2026-10-11

US AI regulation: federal rules, state laws and what to watch

The United States does not have one comprehensive AI law. Instead, companies face a mix of federal agency enforcement, executive actions that change with administrations, and a growing, fast-moving set of state laws.

The federal picture

Federal agencies apply laws that already exist. The FTC polices deceptive or unfair AI claims, the EEOC looks at discrimination in hiring tools, and financial regulators look at fair lending. Federal policy has also pushed back against some state AI laws. Reports say the federal government intervened in a legal challenge to Colorado's law, so state rules can change quickly.

The NIST AI Risk Management Framework is voluntary, but it is widely used as a practical benchmark and is a sensible starting point for internal governance.

State laws worth knowing

Other states have passed laws on deepfakes, chatbots, healthcare AI and government use, and the list keeps growing.

Where scrutiny is highest

Across states and agencies, the areas that draw the most attention are consequential decisions about people: employment, lending, housing, insurance, healthcare and education. If your AI touches these, expect more rules and more questions.

Practical steps

  1. Map where your users and customers are, because state law follows them.
  2. Classify your AI uses and flag any consequential decisions.
  3. Document how your system was built, tested and monitored.
  4. Give clear notices when people interact with AI or are subject to automated decisions.
  5. Set a reminder to re-check state laws every quarter, since they are changing fast.

Official sources: your state attorney general pages, the FTC website and NIST.

This article is general information, not legal advice. Rules change often, so check official sources before you rely on it.