US AI regulation, state and sector
The patchwork as it actually stands — state statutes, sector regulators and agency guidance — each read from the text that binds rather than from the press release.
There is no American AI act. What exists instead is a set of statutes written by different legislatures for different reasons, and the only way to know what any of them requires of you is to read the one that applies. A summary that flattens them into “US states are regulating AI” is worse than nothing, because it hides the thing that actually decides your obligations: which body is bound, from which date, under which enforcement mechanism, and whether a private plaintiff can sue you or only an attorney general can.
These pages each take one instrument and read it. Section numbers are named in the sentence and the primary text is linked, dates and status are stated rather than implied, and where the law is unresolved the page says that it is unresolved instead of guessing. None of this is legal advice; it is a map of where to look, written so that the conversation with a lawyer starts further along.
California SB 53: the Transparency in Frontier AI Act
Who counts as a large frontier developer under SB 53, what it must publish, and the fifteen-day incident report that is the operative duty.
10 min read
California AB 3030: AI Disclaimers in Patient Communications
The disclaimer and human-contact instructions AB 3030 requires when generative AI writes a clinical message to a patient, and the review exemption that switches them off.
9 min read
California SB 896: Generative AI Inside State Government
The risk-analysis and disclosure duties SB 896 places on California state agencies, and why it matters to vendors who are not themselves bound by it.
9 min read
California AB 1836: Digital Replicas of Deceased Performers
The consent requirement AB 1836 added to California's post-mortem publicity right for AI-generated replicas, the damages floor, and the expression carve-outs.
9 min read
Illinois BIPA and Facial Recognition: What Section 15 Requires
The written-release, retention-schedule and disclosure duties BIPA section 15 places on a face-matching feature, and why a photograph carve-out does not save you.
10 min read
BIPA Statutory Damages: the $1,000 and $5,000 Figures
The two per-violation figures in BIPA section 20, the accrual fight that multiplied them, and the 2024 amendment whose retroactivity is still contested.
10 min read
Illinois HB 3773: AI in Employment Decisions from 2026
How HB 3773 folds employer AI use into the Illinois Human Rights Act, the zip-code proxy ban, and the notice duty that awaits IDHR rules.
9 min read
NYC Local Law 144: What the Bias Audit Must Calculate
The selection rates, scoring rates and impact ratios a Local Law 144 audit must produce, the intersectional categories, and the one-year freshness rule.
10 min read
NYC Local Law 144: What Counts as an AEDT
The substantial-factor test in the DCWP rules, applied to resume screeners, scheduling tools, transcription and LLM-based ranking, with the boundary cases named.
9 min read
NYC Local Law 144: the Two Disclosure Duties
The public audit summary and the ten-business-day candidate notice are separate obligations with separate penalties, and most employers satisfy only one.
9 min read
New York's RAISE Act: Frontier AI Safety Reporting
What the RAISE Act asks large frontier developers to publish and report, the thresholds that define them, and the status you must verify before relying on any of it.
9 min read
Utah's AI Policy Act: the Generative AI Disclosure Duty
What Utah's AI Policy Act requires you to disclose, the 2025 amendments that narrowed it to high-risk interactions, and the separate rule for licensed occupations.
9 min read
Texas TRAIGA: What Changed on 1 January 2026
TRAIGA's intent-based prohibitions, the government disclosure duties, the AG-only enforcement with a sixty-day cure, and the sandbox that came with it.
10 min read
Connecticut's AI Bill: What Passed, and What Did Not
Connecticut's comprehensive AI bill has repeatedly passed the Senate and died in the House; here is what is actually in force in the state instead.
9 min read
Virginia's CDPA: the AI Profiling Opt-Out and What It Does Not Reach
The one right in Virginia's privacy statute that bites directly on an automated decision, and the four definitions that decide whether it applies to yours.
9 min read
Washington's My Health My Data Act and AI-Inferred Health Data
Why a model that infers a health status from non-health data creates regulated consumer health data at the moment of inference, and what the Act then requires.
9 min read
AI Hiring in New Jersey: What Actually Binds an Employer Today
New Jersey has no enacted AI hiring disclosure statute; what applies is the Law Against Discrimination as read by the Division on Civil Rights in its January 2025 guidance.
9 min read
The Massachusetts AG Advisory: AI Under Chapter 93A
How Massachusetts regulates AI products without an AI statute, by applying the existing unfair-and-deceptive-practices law, and what the April 2024 advisory says is already unlawful.
9 min read
The FTC's AI-Washing Theory Under Section 5
The legal theory behind the FTC's AI cases — deception plus the substantiation doctrine — the actions it has been applied in, and the remedy problem that shapes all of them.
10 min read
Which US States Have a Binding AI-Specific Statute
A dated snapshot separating enacted AI statutes from vetoed, pending and dead bills, with the citation and effective date for each one.
10 min read
California's ADMT Regulations Under the CCPA
What the Privacy Protection Agency's automated decision-making technology rules require — pre-use notice, opt-out, access — and the narrowing that decides whether they apply to you at all.
10 min read
Colorado's AI Act: What Must Be in the Consumer Notice
The specific fields the Colorado AI Act requires in a pre-use notice and in an adverse-decision notice, and the records you need to be able to produce them.
9 min read
Colorado's AI Act: the Rebuttable Presumption and the NIST Defence Are Not the Same Thing
The Colorado AI Act contains two distinct liability shields with different triggers, and the one that names NIST AI RMF and ISO 42001 is the affirmative defence, not the presumption.
9 min read
California SB 1001: What the Bot Disclosure Law Actually Requires
The B.O.T. Act imposes a disclosure duty only where a bot is used with intent to mislead in a commercial transaction or an election, and the two-intent structure is what most summaries drop.
9 min read
Illinois's AI Video Interview Act, Revisited
What the 2020 Act requires of an employer analysing interview video, the 2022 demographic-reporting amendment, and the remedy question the statute never answers.
9 min read
Maryland's HB 1202: Consent for Facial Recognition in Interviews
What Maryland's 2020 law requires an employer to obtain before using facial recognition in an interview, what its waiver must contain, and the questions the section leaves open.
8 min read
Delaware's Personal Data Privacy Act and AI Profiling
Delaware's profiling opt-out is limited to solely automated decisions, its applicability threshold is the lowest in the country, and it reaches nonprofits — three features that decide who is caught.
9 min read
Oregon's Consumer Privacy Act: the Automated Decision Opt-Out
Oregon's profiling opt-out uses Virginia's wording but sits inside a much narrower exemption structure, which is what decides how many controllers are actually caught.
9 min read
Colorado's AI Act: Enforcement Without a Private Right of Action
Colorado's AI Act routes enforcement exclusively through the Attorney General, which changes who can bring a claim, what a violation costs, and where the residual private exposure actually comes from.
9 min read
New York's SHIELD Act and AI Vendor Security Requirements
How the SHIELD Act's reasonable-security-program duty applies when your product sends a New York resident's private information to a third-party model API.
9 min read
Minnesota's Deepfake Election Law: The Elements of the Offence
What Minnesota Statutes section 609.771 actually criminalises, element by element, and the First Amendment challenge that has been pending against it.
9 min read
State Deepfake-in-Elections Laws: a Dated Snapshot
A dated, source-linked list of enacted state election-deepfake statutes, the two drafting patterns they split into, and how to read a tracker without repeating a number nobody can verify.
9 min read
The FDA's Predetermined Change Control Plan for AI/ML Devices
The mechanism that lets an AI-enabled medical device be modified within a pre-authorised boundary without a new marketing submission, and the three documents that boundary is made of.
10 min read
The FDA's AI/ML SaMD Action Plan: What It Committed To
The five commitments in the FDA's January 2021 action plan for AI/ML-based software as a medical device, and which of them have since produced a published document.
9 min read
Where the EU MDR and the AI Act Overlap for Medical Device Software
Why AI-based medical device software is high-risk under the AI Act by operation of Article 6(1) and Annex I, and how Articles 8, 43 and 47 let one conformity assessment carry both regimes.
10 min read
AI-Enabled Devices and the FDA's 510(k) Pathway
What substantial equivalence has to show for an AI-enabled device, why the predicate comparison is awkward when the predicate is not an AI device, and when a model change forces a new 510(k).
10 min read
SR 11-7's Effective Challenge Requirement, Applied to AI Models
The one concept in the Federal Reserve and OCC model risk guidance that is hardest to satisfy for an opaque model: independent validation with real authority to force a change.
10 min read
Third-Party AI Model Risk for Banks: the 2023 Interagency Guidance
How the June 2023 interagency third-party risk management guidance applies to a bank buying an AI model or an AI-powered vendor tool, stage by stage through the relationship lifecycle.
10 min read
Federal Reserve Guidance on Generative AI in Banking
What the Federal Reserve has actually issued about generative AI — which is no dedicated guidance — and which existing supervisory letters therefore carry the obligation.
9 min read
Adverse Action Notices When an AI Model Denies Credit
Why a generic adverse action reason code fails Regulation B when the decision came from a model, and what a compliant notice has to contain instead.
10 min read
FINRA Guidance on AI Use by Broker-Dealers
What Regulatory Notice 24-09 tells member firms about generative AI, and which existing FINRA rules it points at — supervision, communications, books and records, and vendor management.
9 min read
The SEC's AI Washing Enforcement Actions, Dated
The SEC's enforcement matters against firms and individuals for overstating their use of AI, what each was charged with, and which provisions the agency used.
9 min read
EEOC Guidance on AI and Title VII Disparate Impact
How the EEOC applied the Uniform Guidelines and the four-fifths rule to algorithmic selection tools, and what changed about that position in 2025.
10 min read
DOL Guidance on AI in Hiring, Scheduling and Wage Decisions
What Field Assistance Bulletin 2024-1 says about AI timekeeping, break tracking and scheduling under the FLSA, and why the recordkeeping duty never moves to the vendor.
10 min read
The NAIC Model Bulletin on Insurers' Use of AI
What the NAIC's December 2023 model bulletin requires an insurer to have written down, how it becomes binding in a given state, and what a market conduct examiner will ask for.
10 min read
Colorado's Algorithm Testing Rule for Insurers
How SB 21-169 and the Division of Insurance regulations require life insurers to estimate race from names and geography and test their models against it — and why that is legally unusual.
10 min read
HIPAA Business Associate Agreement Clauses for an AI Vendor
The clauses a BAA needs when the business associate is an LLM provider: training prohibitions, subcontractor flow-down, breach timing, and the return-or-destroy problem a trained model creates.
11 min read
HIPAA's Minimum Necessary Standard Applied to an AI Assistant
How § 164.502(b) constrains what PHI belongs in a context window, which exception clinical assistants wrongly assume covers them, and how retrieval design becomes a compliance control.
10 min read
What FERPA's School Official Exception Covers for an AI Vendor
The three conditions at 34 C.F.R. § 99.31(a)(1)(i)(B) an AI vendor must meet to receive education records without consent, and the vendor terms that destroy the exception.
10 min read
COPPA and AI Products Used by Children Under 13
When an AI chat or tutoring product falls under the COPPA Rule, what verifiable parental consent actually requires, and what the 2025 amendments changed about retention and training.
11 min read
FCC Rules on AI-Generated Voice in Robocalls
The February 2024 declaratory ruling that treats AI-cloned voices as artificial voices under the TCPA, what consent it therefore requires, and what a 2025 Supreme Court decision did to the ruling's weight.
10 min read
FAA Guidance on AI in Aviation Software Certification
Why DO-178C has no objectives a learned model can satisfy, what the FAA's 2024 AI safety assurance roadmap commits to, and which questions remain genuinely open.
10 min read
NHTSA and AI in Autonomous Vehicle Safety Assessment
What the Standing General Order actually requires, why self-certification means no federal agency approves an automated driving system, and where the defect authority fills the gap.
10 min read
OMB Memorandum M-24-10 and What Replaced It
The minimum risk-management practices M-24-10 imposed before an agency could deploy rights-impacting or safety-impacting AI, how M-25-21 restructured them in 2025, and which duties come from statute instead.
11 min read
GSA Guidance on Generative AI Use in Federal Agencies
What GSA controls in federal AI adoption — schedules, FedRAMP, shared evaluation platforms — and the acquisition terms an agency is expected to negotiate for a generative AI service.
10 min read
State Bar Ethics Opinions on AI Use by Lawyers
What the named ethics opinions on generative AI actually require — competence, informed consent for confidential inputs, independent verification, and fees — with issuer and date for each.
11 min read
AI-Fabricated Citations: The Court Sanctions Orders, Dated
The named orders in which courts have sanctioned lawyers for filing AI-invented case citations, what each one imposed, and which power the court used.
9 min read
IRS Rules That Bite When AI Helps Prepare a Return
Which existing preparer obligations — Circular 230, section 6695(g) due diligence, section 7216 disclosure consent — apply when an AI tool touches a return, and where the IRS has said nothing.
9 min read
What the Basel Committee Has Actually Said About AI and ML
The Basel Committee has published observations on AI/ML risk, not a standard — here is what exists, what binds, and why national guidance like SR 11-7 still governs.
8 min read
PCI DSS When an AI Assistant Can See a Payment Flow
How PCI DSS scoping and storage rules apply when a model, its prompts and its logs sit anywhere near cardholder data, and why prompt retention is the failure that matters.
9 min read
NYDFS on AI Cybersecurity Risk: What the 2024 Letter Requires
The New York Department of Financial Services' October 2024 industry letter, the four AI risks it names, and the Part 500 sections each one maps onto.
9 min read
NYDFS Circular Letter No. 7 (2024): AI in Underwriting and Pricing
What New York insurers must be able to demonstrate about external consumer data and AI systems used in underwriting and pricing, and what the circular stops short of requiring.
9 min read
The Telemarketing Sales Rule and AI-Generated Sales Calls
How the FTC's TSR treats a call where an AI voice does the talking — the prerecorded-message rule, do-not-call, and the misrepresentation provisions that reach synthetic personas.
9 min read
Other topics
- LLM fundamentals & architecture
- Tokens, tokenization & context windows
- Prompt engineering
- Reasoning models & test-time compute
- Multimodal AI: vision, audio, video
- RAG & retrieval
- Embeddings & vector search
- AI agents & tool use
- Structured output & function calling
- Fine-tuning & post-training
- Local inference errors, string by string
- Running local models day to day
- Testing code that calls an LLM
- Snapshot and property testing for model output
- Regression suites for prompts
- Eval gates in CI
- Flaky tests against a model
- Determinism and the cost of testing
- Contract and streaming tests
- Testing tool calls and retrieval
- Inference, serving & latency
- Rolling out a prompt change
- Testing AI systems in practice
- Forecasting a time series
- Machine learning on tabular data
- Geospatial data and models
- Understanding audio that is not speech
- Understanding video
- Core computer vision tasks
- Machine learning on graphs
- Point clouds and 3D
- Evaluation, benchmarks & LLM-as-judge
- Sensor and IoT data
- Logs and event streams
- Models over biological sequences
- Machine learning on molecules
- Embedding and searching code
- Extracting invoices and purchase orders
- Receipts, statements and tax forms
- Insurance policies and contracts
- Deeds, court filings and patents
- Extracting from medical records
- Observability & LLMOps
- CVs, certificates and identity documents
- Shipping, customs and technical documents
- Meetings, email, chat and filled-in forms
- Building an extraction pipeline
- Business, property and inspection documents
- Contract clauses and insurance claims
- Regulated and compliance documents
- Consumer, travel and closing documents
- Mapping one chat API onto another
- SDK and framework migrations
- Hallucination & failure modes
- Re-embedding and model deprecation
- Cutting over between providers
- Parity gaps, shims and legacy endpoints
- Moving between model versions
- Migrating vector stores and caches
- Mapping capabilities and parameters
- Migrating pipelines and agents
- Contracts, runbooks and rollback
- Auditing a codebase before a cutover
- Compliance and fine-tune migration
- LLM cost engineering
- Routing, cost tracking and multi-tenancy
- What a migration does to your prompts
- AI security & prompt injection
- Privacy, compliance & data residency
- AI governance, policy & society
- Building reliable AI applications
- AI hardware, GPUs & compute
- Open-weight models & local inference
- AI for developers & coding agents
- AI in industry: vertical playbooks
- AGI, superintelligence, alignment & the long future
- Machine learning foundations
- NLP fundamentals & classical tasks
- Data engineering for AI
- Synthetic data & dataset curation
- AI product design & UX
- Search, ranking & recommendation
- Enterprise adoption & change management
- AI careers, skills & teams
- Reading AI research
- AI in science & discovery
- Robotics & embodied AI
- AI economics, markets & business models
- AI myths, hype & media literacy
- Context engineering
- Shipping AI features: patterns & anti-patterns
- Build it: end-to-end AI tutorials
- Python for AI: hands-on recipes
- TypeScript, React and the web
- Frameworks and SDKs
- Errors and troubleshooting
- AI facts, numbers and statistics
- The history of AI
- The maths behind AI
- Architectures beyond the transformer
- Reinforcement learning
- Diffusion and generative media
- Speech, audio and voice engineering
- Benchmarks, one at a time
- AI search visibility
- Infrastructure and operations
- Databases and storage for AI
- Knowledge graphs and structured knowledge
- Classical ML in production
- Regulation, jurisdiction by jurisdiction
- Prompt recipes and pattern library
- AI for people who do not write code
- Writing, media and creative work
- Edge and on-device AI
- Interpretability and model internals
- Field notes
- OpenAI model behaviour
- Claude model behaviour
- Gemini model behaviour
- Llama model behaviour
- Mistral model behaviour
- Qwen model behaviour
- DeepSeek model behaviour
- Cohere model behaviour
- Grok model behaviour
- Small model behaviour
- Hybrid model architectures
- Token cost by language and script
- Transliteration, romanization and script handling
- Locale-correct output
- Multilingual generation quality
- Multilingual pipelines
- The EU AI Act, article by article
- AI under the GDPR and EU data law
- International AI governance and standards
- AI litigation and enforcement
- Running AI workloads on AWS
- Running AI workloads on Google Cloud
- Running AI workloads on Azure
- AI at the edge: Workers, Vercel and Netlify
- Serving models on Kubernetes
- Operating AI infrastructure
- Quantization formats and what they cost
- llama.cpp, flag by flag
- Ollama and the desktop local-model runtimes
- Local models on Apple Silicon
- Hardware for local inference
- Running speech and embedding models locally
- Model files, adapters and conversion
- VRAM arithmetic for local models