Morning Glance logo

AI Regulation in the United States: A Living Guide to Laws, Agencies, and Enforcement

AI Regulation in the United States: A Living Guide

The United States still does not have one comprehensive federal AI law. Instead, AI is governed through a layered system: federal statutes that apply to particular conduct, agency enforcement under older laws, executive orders that direct the federal government, and a growing collection of state and local requirements.

That distinction matters. A headline about an executive order, a proposed bill, or an agency policy statement does not necessarily create a new legal duty for every company. At the same time, a business can face real liability today when its use of AI violates consumer-protection, employment, civil-rights, antitrust, communications, privacy, biometric, or intellectual-property law.

The practical question is therefore not simply, “Is AI regulated?” It is: Which rule applies to this system, in this location, for this use, and when does it become enforceable?

This guide explains the U.S. framework as it stands on August 20, 2026. It is general information, not legal advice.

AI regulation United States

Why It Matters

AI regulation in the United States is easy to misread because different types of government action are often reported as though they have the same force. They do not.

  • A statute passed by Congress or a state legislature can create binding duties.
  • A regulation issued under valid agency authority can also be binding.
  • An enforcement action applies existing law to specific conduct and can reveal how an agency interprets its authority.
  • An executive order generally directs federal agencies and federal operations; it is not automatically a nationwide code for private AI use.
  • A proposed bill, framework, or policy statement may shape the debate without yet changing anyone’s legal obligations.

For companies, the cost of confusing those categories can be significant. Teams may ignore a state rule that already applies, or spend months preparing for a federal proposal that has not become law. A better approach starts with the use case and works outward to the relevant jurisdictions and regulators.

What Is Actually Federal AI Law in 2026?

There is no U.S. equivalent of the European Union’s single, cross-sector AI Act. Federal regulation remains sectoral and conduct-based.

Existing federal laws already reach AI

The absence of a comprehensive AI act does not create a legal vacuum. The technology used to make a decision or deliver a service usually does not exempt the underlying conduct from existing law.

The Federal Trade Commission can challenge unfair or deceptive practices under Section 5 of the FTC Act. That can include false claims about an AI product’s accuracy, capabilities, privacy, or expected results. The FTC’s rule against fake reviews and testimonials also covers reviews generated by AI when they misrepresent the experience of a real person.

Federal employment and civil-rights laws continue to apply when employers use algorithms for recruiting, screening, promotion, discipline, or termination. An employer cannot avoid liability for unlawful discrimination by outsourcing a decision to software.

The Telephone Consumer Protection Act applies to calls that use AI-generated voices. The Federal Communications Commission has confirmed that voice-cloning technology falls within the law’s restrictions on artificial or prerecorded voices, including applicable consent requirements and exemptions.

Antitrust law also applies when algorithms facilitate unlawful coordination or the exchange of competitively sensitive information. The Justice Department’s RealPage litigation and proposed settlements illustrate a broader principle: putting pricing decisions into software does not place them outside competition law.

Copyright, privacy, biometric, financial-services, healthcare, product-safety, and sector-specific laws may apply as well. Their coverage depends on the data, output, decision, industry, and parties involved—not simply on whether a product is marketed as “AI.”

The TAKE IT DOWN Act creates a targeted federal duty

The TAKE IT DOWN Act is an important AI-related federal statute, but it is not a comprehensive AI law. It addresses nonconsensual intimate visual depictions, including qualifying digital forgeries and AI-generated deepfakes.

Since May 19, 2026, covered platforms must provide a process for people to request removal. After receiving a valid request, a platform generally must remove the content and known identical copies within 48 hours. The FTC enforces the platform-removal provisions.

Executive orders set federal policy and agency priorities

Executive Order 14179, signed January 23, 2025, revoked the previous administration’s 2023 AI order and directed the development of a new national AI action plan. The White House released that plan in July 2025, emphasizing innovation, infrastructure, adoption, national security, and a lighter regulatory approach.

Executive Order 14365, signed December 11, 2025, pushed more directly for a uniform national AI policy. Among other steps, it directed the Justice Department to create an AI Litigation Task Force, instructed the Commerce Department to evaluate state AI laws, linked some federal broadband funding decisions to state AI policy, and called for possible FCC and FTC action.

These directions can have major practical consequences, especially for federal contractors, grant recipients, regulated industries, and companies involved in agency proceedings. But the order does not, by itself, erase every state AI law or create a general federal licensing system for private AI models.

A June 2, 2026 executive order on advanced AI focused on cybersecurity, federal coordination, benchmarking, and voluntary collaboration with the private sector. It expressly avoided mandatory federal licensing, preclearance, or permitting of AI models.

The national legislative framework is still a proposal

On March 20, 2026, the White House released a national AI legislative framework covering issues such as children, creators, free speech, innovation, workforce policy, and federal preemption. It is a set of recommendations to Congress, not a statute. Its ideas become binding only if Congress enacts legislation and the law survives any relevant legal challenges.

AI regulations Guide

How Federal Agencies Enforce AI-Related Conduct

Federal agencies do not need the words “artificial intelligence” in every statute they enforce. Their authority generally follows the conduct and industry.

Federal Trade Commission

The FTC is the main federal consumer-protection regulator for many commercial AI products. Its cases and guidance focus on deceptive marketing, unfair practices, privacy, data security, fake reviews, and unsupported performance claims. Companies should be able to substantiate claims about accuracy, bias, safety, cost savings, and automated decision-making.

Equal Employment Opportunity Commission and Justice Department

Federal civil-rights laws apply to AI-assisted employment decisions. Employers remain responsible for discriminatory outcomes within the scope of those laws, including when a vendor supplies the tool. The Justice Department also applies antitrust and civil-rights law to algorithmic conduct within its jurisdiction.

Federal Communications Commission

The FCC treats AI-generated voices as artificial voices under the TCPA. Businesses using voice cloning for calls must assess consent, identification, opt-out, and other communications-law requirements before deployment.

Sector regulators

Financial, healthcare, insurance, education, and other regulated uses may trigger additional federal and state rules. A model used to draft marketing copy presents a different legal profile from one used to deny credit, recommend treatment, set insurance terms, or rank job candidates.

State and Local AI Laws to Know

State law is not one uniform category. Some laws regulate high-impact decisions, while others focus on synthetic media, healthcare disclosures, government use, biometric data, employment, or particular consumer interactions. The following are selected high-impact examples, not a complete inventory.

Jurisdiction

Law

Main requirement

Status

Colorado

SB 26-189

Documentation, notice, data correction, and human review for covered consequential decisions

Main duties: Jan. 1, 2027

California

SB 53

Frontier AI frameworks, transparency reports, incident reporting, and whistleblower protections

In force in 2026

California

SB 942

Detection tools plus visible-option and latent provenance disclosures for covered media

Operative Jan. 1, 2026

Texas

HB 149 (TRAIGA)

Prohibited uses and selected government and healthcare disclosures

Effective Jan. 1, 2026

New York City

Local Law 144

Bias audit, public summary, and notice for covered hiring tools

Enforced since July 5, 2023

Illinois

PA 103-0804

No discriminatory AI use in covered employment decisions; notice required

Effective Jan. 1, 2026

Colorado replaced its original comprehensive AI law

Colorado’s 2024 AI law was widely described as the first broad state framework for high-risk AI. In May 2026, however, the state repealed and replaced that structure through SB 26-189.

The replacement law focuses on covered automated decision-making technology used for consequential decisions. Beginning January 1, 2027, it requires documentation and disclosures from covered developers and deployers. Consumers affected by adverse outcomes receive rights that include access to certain personal data, correction of factually incorrect data, and a request for meaningful human review and reconsideration. The Colorado attorney general has enforcement authority; the law does not create a general private right of action.

The publication point is simple: businesses should not describe the original SB 24-205 framework as the law companies must implement in 2027. SB 26-189 is now the relevant statute.

California regulates both frontier models and synthetic media

California’s SB 53, the Transparency in Frontier Artificial Intelligence Act, applies to frontier-model developers meeting statutory thresholds. It requires public transparency reports for frontier models and, for large frontier developers, a published frontier AI framework addressing catastrophic risk. It also establishes critical-safety-incident reporting and whistleblower protections. Enforcement of the principal developer obligations rests with the California attorney general, with civil penalties available for specified violations.

California’s SB 942, operative since January 1, 2026, takes a different approach. Covered providers of widely used, publicly accessible generative AI systems must make a free detection tool available for image, video, and audio generated or altered by their systems. They must offer users an option for a visible disclosure and include a technically feasible latent provenance disclosure in covered media. The law does not simply require every piece of AI-generated content on the internet to carry a visible label.

Texas regulates prohibited uses and selected disclosures

The Texas Responsible Artificial Intelligence Governance Act, or TRAIGA, took effect January 1, 2026. It prohibits specified uses, including certain intentional manipulation, unlawful discrimination, and prohibited sexual content. It also imposes disclosure requirements for state-government AI interactions and for AI used in relation to healthcare services or treatment.

The Texas attorney general has exclusive enforcement authority unless additional enforcement is recommended to another state agency. The law does not provide a private right of action.

Employment rules can be more specific than general AI laws

New York City’s Local Law 144 has been enforced since July 5, 2023. Employers and employment agencies cannot use a covered automated employment decision tool unless it has undergone a bias audit within the previous year, a summary of the results is publicly available, and required notices have been provided.

Illinois added another layer on January 1, 2026. The Illinois Human Rights Act prohibits employers from using AI in specified employment decisions when it has the effect of unlawful discrimination and requires notice when AI is used for those purposes. Illinois also has a separate Artificial Intelligence Video Interview Act for covered applicant interviews.

The Federal Preemption Fight: What Has and Has Not Happened

Federal preemption means federal law displaces conflicting state law. Congress can expressly preempt state requirements when it legislates within its constitutional authority. Courts may also find implied preemption in particular circumstances. An executive order can direct agencies to pursue a preemption strategy, but it does not automatically invalidate every state statute.

The current dispute developed in several stages:

1. In July 2025, the Senate voted 99–1 to remove a proposed 10-year restriction on state AI regulation from the federal budget legislation. No blanket congressional moratorium became law.

2. The December 2025 executive order directed federal agencies to challenge or discourage state laws the administration views as obstructing national AI policy.

3. The March 2026 White House framework asked Congress to create a national approach, including federal preemption in some areas. Congress has not enacted that framework.

4. In July 2026, the FTC requested public comment on a proposed policy statement about the suppression of accuracy in AI systems. The proposal discusses Section 5 of the FTC Act and argues that conflicting state rules may be preempted in some circumstances. It refers to Colorado’s AI law as an example.

As of August 20, 2026, that FTC document remains a proposed policy statement. It is not a case against Colorado, a final rule, or a court judgment striking down the state’s law. Any article describing it as a completed federal block on Colorado law overstates what has happened.

For compliance teams, the safe assumption is that applicable state and local laws remain relevant unless Congress validly preempts them, a court rules that a particular provision cannot stand, or another legally effective action changes the result.

How to Assess an AI System’s Legal Exposure

Instead of asking whether a company is “an AI company,” begin with the system’s actual role.

Hiring and workplace decisions

Check federal and state discrimination law, disability accommodation rules, notice requirements, audit requirements, recordkeeping, and vendor responsibilities. New York City and Illinois deserve special attention, but they are not the only jurisdictions with employment-related rules.

Consumer-facing assistants and marketing tools

Review whether users are clearly told when they are interacting with AI where disclosure is required. Test claims about performance and savings. Examine privacy practices, dark patterns, subscriptions, endorsements, and whether generated reviews or testimonials imply a real experience that never occurred.

Healthcare and financial decisions

Treat these as high-consequence uses. Existing professional, privacy, anti-discrimination, safety, and sector-specific rules may matter more than a statute labeled as an “AI law.” Human oversight does not cure every problem, but unclear responsibility and unreviewable adverse decisions create avoidable risk.

Synthetic media and voice cloning

Check federal nonconsensual-intimate-image obligations, state deepfake and election laws, California provenance requirements, right-of-publicity issues, copyright, fraud, and FCC consent rules for calls. The requirements vary by medium and purpose.

Frontier-model development

Developers meeting California’s thresholds should map model-training compute, revenue, deployment, safety-evaluation, documentation, incident-reporting, cybersecurity, and whistleblower obligations. Smaller developers may still face transparency, consumer-protection, contract, and sector-specific duties.

What Companies Should Do Now

Inventory AI uses, not just AI vendors. Record where models affect people, money, access, safety, employment, or legal rights.

Assign an owner and a jurisdiction. Every high-impact use should have a responsible business owner and a list of places where it operates.

Separate binding rules from proposals. Track statutes, effective dates, regulations, litigation, guidance, and bills in different categories.

Document claims and testing. Keep evidence for statements about accuracy, bias, privacy, security, and performance.

Review vendor contracts. Address data use, model changes, audit support, incident notification, records, indemnity, and cooperation with regulators.

Design notice and appeal paths early. They are difficult to add after an automated workflow is already in production.

Recheck the law before launch. This area changes quickly, and requirements may be amended before their operative dates.

For systems that can take actions across accounts, data, or software, legal review should sit alongside technical controls. See Morning Glance’s guide to AI agent security risks for the operational side of that problem.

U.S. Regulation Compared With the EU AI Act

The EU AI Act creates a single risk-based framework across the European Union, although many of its obligations phase in over time and other EU laws continue to apply. The United States relies on overlapping federal, state, and local authority.

For multinational companies, compliance with the EU AI Act does not automatically satisfy U.S. law. The EU framework may require a risk classification and conformity process, while a U.S. analysis may turn on employment discrimination, state privacy, biometrics, consumer deception, voice-call consent, or a city-specific audit rule. The same AI system can therefore require two different legal maps.

What Happens Next

Three developments are especially important to watch.

First, Congress may act on a national framework or another preemption proposal. The failed 2025 moratorium shows that broad state-law restrictions face political resistance, but the issue remains active.

Second, federal agencies may finalize policies or begin proceedings directed by the December 2025 executive order. Agency authority, procedure, and any claimed preemptive effect may then be tested in court.

Third, states will continue amending laws before and after effective dates. Colorado’s 2026 replacement law is a reminder that a signed statute is not always the final compliance design.

The Bottom Line

AI regulation in the United States is already real, but it is not one rulebook. The enforceable framework is a patchwork of existing federal law, targeted AI statutes, agency action, and state and local requirements.

The best way to stay compliant is to avoid broad claims such as “AI is unregulated” or “the federal government has blocked state AI laws.” Start with the use case, identify the jurisdictions, confirm the effective dates, and distinguish binding law from proposals and political direction.

In this area, staying current is part of staying compliant.

Frequently Asked Questions

Is there a comprehensive federal AI law in the United States?

No. Congress has enacted targeted laws that reach specific AI-related harms, and many existing federal statutes apply to AI-assisted conduct. But there is no single cross-sector federal AI act comparable to the EU AI Act.

Are executive orders binding on private AI companies?

Usually not as a general private-sector code. Executive orders direct the executive branch and can affect federal procurement, grants, enforcement priorities, and rulemaking. A private company may feel their effects through contracts or later agency action, but the order itself does not automatically create every obligation discussed in it.

Did the federal government invalidate state AI laws?

No blanket invalidation has occurred. The administration is pursuing a national policy and has directed agencies to examine state laws, but no comprehensive federal preemption statute or nationwide court ruling has erased state AI regulation.

What happened to the Colorado AI Act?

Colorado repealed and replaced its original SB 24-205 framework in May 2026. The principal requirements in SB 26-189 take effect January 1, 2027 and focus on covered automated decision-making technology used for consequential decisions.

Which regulators matter most?

It depends on the use. The FTC, EEOC, FCC, Justice Department, state attorneys general, sector regulators, and local enforcement agencies can all matter. A hiring tool and an AI-generated marketing campaign will not have the same regulator or risk profile.

Does an AI label solve the legal problem?

No. Disclosure can be required and useful, but it does not cure discrimination, deception, privacy violations, unsafe design, unlawful calls, copyright infringement, or other prohibited conduct.

Is this article legal advice?

No. It is a general guide to the regulatory structure as of August 20, 2026. Organizations should obtain advice for their specific systems, industries, and jurisdictions.

Official Sources

Source note: This article prioritizes enacted text and official government guidance. Because AI law changes quickly, verify current requirements before making a compliance decision.

Get the Morning Glance briefing—AI Policy & Safety context without the noise.

Report an error

AI Regulation in the United States: A Living Guide to Morning Glance | Morning Glance