Regulations · United States
AI REGULATION

United States

DEVELOPING

The US takes a decentralized approach to AI regulation with executive orders, agency guidance, and a growing patchwork of state-level AI laws.

KEY LEGISLATION 5 laws
Executive Order 14110 on Safe, Secure, and Trustworthy AI ENACTED
2023-10
Requires AI safety testing, red-teaming for dual-use models, and establishes reporting requirements for large AI systems
NIST AI Risk Management Framework ENACTED
2023-01
Voluntary framework for identifying and managing AI risks across the AI lifecycle
Colorado AI Act (SB 24-205) ENACTED
2024-05
First comprehensive state AI law requiring impact assessments for high-risk AI systems
California SB 1047 (vetoed) PROPOSED
2024-09
Would have required safety testing for large AI models; vetoed by Governor Newsom
AI LEAD Act PROPOSED
2024-06
Proposed federal framework for AI governance and accountability
ANALYSIS

Regulatory Landscape

The United States has taken a distinctly decentralized approach to AI regulation, relying on executive action, voluntary industry commitments, and existing regulatory authorities rather than comprehensive federal legislation. This reflects both the political difficulty of passing tech legislation through Congress and a philosophical preference for innovation-friendly governance.

The Biden administration’s Executive Order 14110, issued in October 2023, represented the most significant federal AI action to date, requiring safety testing for powerful models and establishing reporting requirements. However, the Trump administration in 2025 revoked this order, creating uncertainty about federal AI governance direction.

Key Laws

At the federal level, the US relies primarily on the NIST AI Risk Management Framework (voluntary), FTC enforcement actions against deceptive AI practices, and sector-specific rules from agencies like the FDA (AI in healthcare) and EEOC (AI in hiring). No comprehensive federal AI legislation has been enacted.

State-level activity has been far more aggressive. Colorado enacted the first comprehensive state AI law in 2024, while California’s legislature has produced dozens of AI bills addressing deepfakes, automated decision-making, and AI transparency. The vetoed SB 1047 highlighted tensions between safety advocates and the AI industry over model-level regulation.

Enforcement

Enforcement currently occurs through existing consumer protection authorities (FTC), sector-specific regulators, and state attorneys general. The FTC has pursued cases against companies making false AI claims and violating data practices in AI training.

Business Impact

The regulatory patchwork creates compliance complexity for AI companies operating across states. Companies must navigate a growing web of state laws with different requirements for impact assessments, disclosures, and bias testing. The absence of federal preemption means this complexity will likely increase, driving demand for AI governance tools and compliance frameworks.