Skip to content

US AI regulation, state and sector

The patchwork as it actually stands — state statutes, sector regulators and agency guidance — each read from the text that binds rather than from the press release.

There is no American AI act. What exists instead is a set of statutes written by different legislatures for different reasons, and the only way to know what any of them requires of you is to read the one that applies. A summary that flattens them into “US states are regulating AI” is worse than nothing, because it hides the thing that actually decides your obligations: which body is bound, from which date, under which enforcement mechanism, and whether a private plaintiff can sue you or only an attorney general can.

These pages each take one instrument and read it. Section numbers are named in the sentence and the primary text is linked, dates and status are stated rather than implied, and where the law is unresolved the page says that it is unresolved instead of guessing. None of this is legal advice; it is a map of where to look, written so that the conversation with a lawyer starts further along.

California SB 53: the Transparency in Frontier AI Act

Who counts as a large frontier developer under SB 53, what it must publish, and the fifteen-day incident report that is the operative duty.

10 min read

California AB 3030: AI Disclaimers in Patient Communications

The disclaimer and human-contact instructions AB 3030 requires when generative AI writes a clinical message to a patient, and the review exemption that switches them off.

9 min read

California SB 896: Generative AI Inside State Government

The risk-analysis and disclosure duties SB 896 places on California state agencies, and why it matters to vendors who are not themselves bound by it.

9 min read

California AB 1836: Digital Replicas of Deceased Performers

The consent requirement AB 1836 added to California's post-mortem publicity right for AI-generated replicas, the damages floor, and the expression carve-outs.

9 min read

Illinois BIPA and Facial Recognition: What Section 15 Requires

The written-release, retention-schedule and disclosure duties BIPA section 15 places on a face-matching feature, and why a photograph carve-out does not save you.

10 min read

BIPA Statutory Damages: the $1,000 and $5,000 Figures

The two per-violation figures in BIPA section 20, the accrual fight that multiplied them, and the 2024 amendment whose retroactivity is still contested.

10 min read

Illinois HB 3773: AI in Employment Decisions from 2026

How HB 3773 folds employer AI use into the Illinois Human Rights Act, the zip-code proxy ban, and the notice duty that awaits IDHR rules.

9 min read

NYC Local Law 144: What the Bias Audit Must Calculate

The selection rates, scoring rates and impact ratios a Local Law 144 audit must produce, the intersectional categories, and the one-year freshness rule.

10 min read

NYC Local Law 144: What Counts as an AEDT

The substantial-factor test in the DCWP rules, applied to resume screeners, scheduling tools, transcription and LLM-based ranking, with the boundary cases named.

9 min read

NYC Local Law 144: the Two Disclosure Duties

The public audit summary and the ten-business-day candidate notice are separate obligations with separate penalties, and most employers satisfy only one.

9 min read

New York's RAISE Act: Frontier AI Safety Reporting

What the RAISE Act asks large frontier developers to publish and report, the thresholds that define them, and the status you must verify before relying on any of it.

9 min read

Utah's AI Policy Act: the Generative AI Disclosure Duty

What Utah's AI Policy Act requires you to disclose, the 2025 amendments that narrowed it to high-risk interactions, and the separate rule for licensed occupations.

9 min read

Texas TRAIGA: What Changed on 1 January 2026

TRAIGA's intent-based prohibitions, the government disclosure duties, the AG-only enforcement with a sixty-day cure, and the sandbox that came with it.

10 min read

Connecticut's AI Bill: What Passed, and What Did Not

Connecticut's comprehensive AI bill has repeatedly passed the Senate and died in the House; here is what is actually in force in the state instead.

9 min read

Virginia's CDPA: the AI Profiling Opt-Out and What It Does Not Reach

The one right in Virginia's privacy statute that bites directly on an automated decision, and the four definitions that decide whether it applies to yours.

9 min read

Washington's My Health My Data Act and AI-Inferred Health Data

Why a model that infers a health status from non-health data creates regulated consumer health data at the moment of inference, and what the Act then requires.

9 min read

AI Hiring in New Jersey: What Actually Binds an Employer Today

New Jersey has no enacted AI hiring disclosure statute; what applies is the Law Against Discrimination as read by the Division on Civil Rights in its January 2025 guidance.

9 min read

The Massachusetts AG Advisory: AI Under Chapter 93A

How Massachusetts regulates AI products without an AI statute, by applying the existing unfair-and-deceptive-practices law, and what the April 2024 advisory says is already unlawful.

9 min read

The FTC's AI-Washing Theory Under Section 5

The legal theory behind the FTC's AI cases — deception plus the substantiation doctrine — the actions it has been applied in, and the remedy problem that shapes all of them.

10 min read

Which US States Have a Binding AI-Specific Statute

A dated snapshot separating enacted AI statutes from vetoed, pending and dead bills, with the citation and effective date for each one.

10 min read

California's ADMT Regulations Under the CCPA

What the Privacy Protection Agency's automated decision-making technology rules require — pre-use notice, opt-out, access — and the narrowing that decides whether they apply to you at all.

10 min read

Colorado's AI Act: What Must Be in the Consumer Notice

The specific fields the Colorado AI Act requires in a pre-use notice and in an adverse-decision notice, and the records you need to be able to produce them.

9 min read

Colorado's AI Act: the Rebuttable Presumption and the NIST Defence Are Not the Same Thing

The Colorado AI Act contains two distinct liability shields with different triggers, and the one that names NIST AI RMF and ISO 42001 is the affirmative defence, not the presumption.

9 min read

California SB 1001: What the Bot Disclosure Law Actually Requires

The B.O.T. Act imposes a disclosure duty only where a bot is used with intent to mislead in a commercial transaction or an election, and the two-intent structure is what most summaries drop.

9 min read

Illinois's AI Video Interview Act, Revisited

What the 2020 Act requires of an employer analysing interview video, the 2022 demographic-reporting amendment, and the remedy question the statute never answers.

9 min read

Maryland's HB 1202: Consent for Facial Recognition in Interviews

What Maryland's 2020 law requires an employer to obtain before using facial recognition in an interview, what its waiver must contain, and the questions the section leaves open.

8 min read

Delaware's Personal Data Privacy Act and AI Profiling

Delaware's profiling opt-out is limited to solely automated decisions, its applicability threshold is the lowest in the country, and it reaches nonprofits — three features that decide who is caught.

9 min read

Oregon's Consumer Privacy Act: the Automated Decision Opt-Out

Oregon's profiling opt-out uses Virginia's wording but sits inside a much narrower exemption structure, which is what decides how many controllers are actually caught.

9 min read

Colorado's AI Act: Enforcement Without a Private Right of Action

Colorado's AI Act routes enforcement exclusively through the Attorney General, which changes who can bring a claim, what a violation costs, and where the residual private exposure actually comes from.

9 min read

New York's SHIELD Act and AI Vendor Security Requirements

How the SHIELD Act's reasonable-security-program duty applies when your product sends a New York resident's private information to a third-party model API.

9 min read

Minnesota's Deepfake Election Law: The Elements of the Offence

What Minnesota Statutes section 609.771 actually criminalises, element by element, and the First Amendment challenge that has been pending against it.

9 min read

State Deepfake-in-Elections Laws: a Dated Snapshot

A dated, source-linked list of enacted state election-deepfake statutes, the two drafting patterns they split into, and how to read a tracker without repeating a number nobody can verify.

9 min read

The FDA's Predetermined Change Control Plan for AI/ML Devices

The mechanism that lets an AI-enabled medical device be modified within a pre-authorised boundary without a new marketing submission, and the three documents that boundary is made of.

10 min read

The FDA's AI/ML SaMD Action Plan: What It Committed To

The five commitments in the FDA's January 2021 action plan for AI/ML-based software as a medical device, and which of them have since produced a published document.

9 min read

Where the EU MDR and the AI Act Overlap for Medical Device Software

Why AI-based medical device software is high-risk under the AI Act by operation of Article 6(1) and Annex I, and how Articles 8, 43 and 47 let one conformity assessment carry both regimes.

10 min read

AI-Enabled Devices and the FDA's 510(k) Pathway

What substantial equivalence has to show for an AI-enabled device, why the predicate comparison is awkward when the predicate is not an AI device, and when a model change forces a new 510(k).

10 min read

SR 11-7's Effective Challenge Requirement, Applied to AI Models

The one concept in the Federal Reserve and OCC model risk guidance that is hardest to satisfy for an opaque model: independent validation with real authority to force a change.

10 min read

Third-Party AI Model Risk for Banks: the 2023 Interagency Guidance

How the June 2023 interagency third-party risk management guidance applies to a bank buying an AI model or an AI-powered vendor tool, stage by stage through the relationship lifecycle.

10 min read

Federal Reserve Guidance on Generative AI in Banking

What the Federal Reserve has actually issued about generative AI — which is no dedicated guidance — and which existing supervisory letters therefore carry the obligation.

9 min read

Adverse Action Notices When an AI Model Denies Credit

Why a generic adverse action reason code fails Regulation B when the decision came from a model, and what a compliant notice has to contain instead.

10 min read

FINRA Guidance on AI Use by Broker-Dealers

What Regulatory Notice 24-09 tells member firms about generative AI, and which existing FINRA rules it points at — supervision, communications, books and records, and vendor management.

9 min read

The SEC's AI Washing Enforcement Actions, Dated

The SEC's enforcement matters against firms and individuals for overstating their use of AI, what each was charged with, and which provisions the agency used.

9 min read

EEOC Guidance on AI and Title VII Disparate Impact

How the EEOC applied the Uniform Guidelines and the four-fifths rule to algorithmic selection tools, and what changed about that position in 2025.

10 min read

DOL Guidance on AI in Hiring, Scheduling and Wage Decisions

What Field Assistance Bulletin 2024-1 says about AI timekeeping, break tracking and scheduling under the FLSA, and why the recordkeeping duty never moves to the vendor.

10 min read

The NAIC Model Bulletin on Insurers' Use of AI

What the NAIC's December 2023 model bulletin requires an insurer to have written down, how it becomes binding in a given state, and what a market conduct examiner will ask for.

10 min read

Colorado's Algorithm Testing Rule for Insurers

How SB 21-169 and the Division of Insurance regulations require life insurers to estimate race from names and geography and test their models against it — and why that is legally unusual.

10 min read

HIPAA Business Associate Agreement Clauses for an AI Vendor

The clauses a BAA needs when the business associate is an LLM provider: training prohibitions, subcontractor flow-down, breach timing, and the return-or-destroy problem a trained model creates.

11 min read

HIPAA's Minimum Necessary Standard Applied to an AI Assistant

How § 164.502(b) constrains what PHI belongs in a context window, which exception clinical assistants wrongly assume covers them, and how retrieval design becomes a compliance control.

10 min read

What FERPA's School Official Exception Covers for an AI Vendor

The three conditions at 34 C.F.R. § 99.31(a)(1)(i)(B) an AI vendor must meet to receive education records without consent, and the vendor terms that destroy the exception.

10 min read

COPPA and AI Products Used by Children Under 13

When an AI chat or tutoring product falls under the COPPA Rule, what verifiable parental consent actually requires, and what the 2025 amendments changed about retention and training.

11 min read

FCC Rules on AI-Generated Voice in Robocalls

The February 2024 declaratory ruling that treats AI-cloned voices as artificial voices under the TCPA, what consent it therefore requires, and what a 2025 Supreme Court decision did to the ruling's weight.

10 min read

FAA Guidance on AI in Aviation Software Certification

Why DO-178C has no objectives a learned model can satisfy, what the FAA's 2024 AI safety assurance roadmap commits to, and which questions remain genuinely open.

10 min read

NHTSA and AI in Autonomous Vehicle Safety Assessment

What the Standing General Order actually requires, why self-certification means no federal agency approves an automated driving system, and where the defect authority fills the gap.

10 min read

OMB Memorandum M-24-10 and What Replaced It

The minimum risk-management practices M-24-10 imposed before an agency could deploy rights-impacting or safety-impacting AI, how M-25-21 restructured them in 2025, and which duties come from statute instead.

11 min read

GSA Guidance on Generative AI Use in Federal Agencies

What GSA controls in federal AI adoption — schedules, FedRAMP, shared evaluation platforms — and the acquisition terms an agency is expected to negotiate for a generative AI service.

10 min read

State Bar Ethics Opinions on AI Use by Lawyers

What the named ethics opinions on generative AI actually require — competence, informed consent for confidential inputs, independent verification, and fees — with issuer and date for each.

11 min read

AI-Fabricated Citations: The Court Sanctions Orders, Dated

The named orders in which courts have sanctioned lawyers for filing AI-invented case citations, what each one imposed, and which power the court used.

9 min read

IRS Rules That Bite When AI Helps Prepare a Return

Which existing preparer obligations — Circular 230, section 6695(g) due diligence, section 7216 disclosure consent — apply when an AI tool touches a return, and where the IRS has said nothing.

9 min read

What the Basel Committee Has Actually Said About AI and ML

The Basel Committee has published observations on AI/ML risk, not a standard — here is what exists, what binds, and why national guidance like SR 11-7 still governs.

8 min read

PCI DSS When an AI Assistant Can See a Payment Flow

How PCI DSS scoping and storage rules apply when a model, its prompts and its logs sit anywhere near cardholder data, and why prompt retention is the failure that matters.

9 min read

NYDFS on AI Cybersecurity Risk: What the 2024 Letter Requires

The New York Department of Financial Services' October 2024 industry letter, the four AI risks it names, and the Part 500 sections each one maps onto.

9 min read

NYDFS Circular Letter No. 7 (2024): AI in Underwriting and Pricing

What New York insurers must be able to demonstrate about external consumer data and AI systems used in underwriting and pricing, and what the circular stops short of requiring.

9 min read

The Telemarketing Sales Rule and AI-Generated Sales Calls

How the FTC's TSR treats a call where an AI voice does the talking — the prerecorded-message rule, do-not-call, and the misrepresentation provisions that reach synthetic personas.

9 min read

Other topics