This article summarises publicly available guidance from regulators and official sources. It is general educational information only and does not constitute legal or professional advice. Requirements vary by jurisdiction. Consult your regional authority or a qualified professional for advice specific to your situation.
A business looking for one US AI regulator or one national AI law will not find a complete answer. The relevant authority usually depends on what the system does, while state and city coverage may depend on the affected person's residence, workplace or opportunity rather than the location of the business's headquarters.
In short: As checked on 4 September 2026, the United States does not have one comprehensive, cross-sector federal AI statute for private businesses. Existing federal laws are applied by agencies according to the activity involved. Separate state and city rules can add obligations when an AI-assisted decision concerns their residents, workers, applicants or local jobs.
Start with the AI use, then locate the affected person
The most reliable jurisdiction test has two axes: the business function and the connection to a state or city. The product label, model type and vendor's location are rarely enough on their own.
The first question is what decision or representation the AI system influences. Marketing claims point towards the Federal Trade Commission. Employment decisions point towards the Equal Employment Opportunity Commission and employment laws. Consumer credit points towards the Equal Credit Opportunity Act and Regulation B. Protected health information can bring the Department of Health and Human Services Office for Civil Rights into the picture.
The second question is whose opportunity, data or employment is affected and where that person or position is located. California's privacy law protects California residents, including resident employees and applicants. Colorado's new automated decision law includes specified Colorado-connected consumers and opportunities. New York City's hiring rule uses a job-location test for its main trigger and a residence test for candidate notices.
This produces an important result for non-US businesses. A company does not become irrelevant to US rules merely because it has no US headquarters. A remote role linked to a New York City office, an employment decision evaluated by a business operating in Colorado, or personal information about a California resident can create a jurisdictional question that the incorporation address does not answer.
Federal authority follows the business function
There is no single federal agency that regulates every commercial use of AI. A 2026 Government Accountability Office report described the United States as lacking a comprehensive legal framework governing AI, privacy or their intersection, with different laws covering different sectors. The White House has separately asked Congress to establish a federal framework and pre-empt some state AI laws, but those legislative recommendations are a proposal rather than enacted legislation. See the GAO's 2026 report.
| AI use | Authority or reference body | Existing basis | What the primary source establishes |
|---|---|---|---|
| Claims made to customers about an AI product | Federal Trade Commission | FTC Act and other consumer-protection authorities | The FTC has brought cases alleging that specific AI performance claims were deceptive or unsupported. |
| Recruitment, screening, monitoring, promotion or dismissal | Equal Employment Opportunity Commission | Federal employment discrimination laws, including Title VII and the Americans with Disabilities Act | The EEOC says those laws apply when AI or other technologies are used in employment decisions. |
| Consumer credit decisions | Consumer Financial Protection Bureau and other Regulation B enforcement agencies | Equal Credit Opportunity Act and Regulation B | The current regulation requires adverse-action reasons to be specific and to identify the principal reasons. It is not an AI-specific rule. |
| AI services handling protected health information for a regulated healthcare organisation | HHS Office for Civil Rights | HIPAA Privacy and Security Rules | HHS identifies certain third-party AI chatbots handling protected health information as potential business associates. |
| General AI risk-management structure | National Institute of Standards and Technology | AI Risk Management Framework | NIST describes the framework as voluntary. NIST does not enforce it as an AI law. |
FTC action concerns claims and conduct, not an AI licence
The FTC has used its existing consumer-protection authority in specific AI-related cases. Its final DoNotPay order addressed claims that the service could perform like a human lawyer without sufficient supporting evidence. Its final Workado order addressed advertised accuracy claims for an AI content detector. The orders apply to the respondents, while the cases show the kinds of representations the agency has challenged. See the FTC's DoNotPay final order announcement and Workado final order announcement.
These actions do not establish a general federal approval process for AI products. They show the FTC applying existing law to particular alleged representations and practices. Whether another claim crosses the same line depends on its wording, evidence, audience and surrounding facts.
EEOC materials connect AI hiring to existing discrimination laws
The EEOC states that federal employment discrimination laws apply to AI and other technologies in the same way that they apply to other employment practices. Its examples cover recruitment, screening, monitoring, productivity assessment, pay, promotion and dismissal. See the EEOC's current explanation of its role in AI.
The agency has also published technical assistance concerning disability discrimination and algorithmic employment tools. That material describes possible screening-out, accommodation and disability-inquiry issues under the Americans with Disabilities Act. It is technical assistance based on existing law, not a separate AI statute. See the EEOC's AI and ADA resources.
The EEOC has acted in court as well as through guidance. In its 2024 amicus brief in Mobley v Workday, the agency argued that an AI software vendor could fall within established employment-law theories when it performs functions delegated by employers. An amicus position is an agency's legal argument to a court, not a final rule or a holding that resolves every vendor relationship. See the EEOC's filed brief.
Credit explanations come from Regulation B, not an AI rule
For consumer credit, the durable primary source is Regulation B. Section 1002.9 states that an adverse-action explanation must be specific and identify the principal reasons for the action. The regulation does not create a different standard for an AI model. See the CFPB's current text and official interpretation of section 1002.9.
Status matters here because older AI summaries often cite CFPB Circular 2022-03 as if it were current guidance. The CFPB's withdrawn-guidance register records both circulars as withdrawn on the same date, 12 May 2025: Circular 2022-03 on adverse-action notification for decisions based on complex algorithms, and Circular 2023-03 on adverse-action notification and the proper use of the sample forms. Neither is current CFPB guidance. The withdrawals did not remove Regulation B from the Code of Federal Regulations, which is why the regulation rather than the circulars is the durable source. See the CFPB's withdrawn-guidance register and the Circular 2023-03 page.
HHS guidance is limited to the HIPAA-regulated setting
HHS says the HIPAA Rules apply to covered entities and business associates, not to every organisation that handles health-related information. Its current business-associate guidance includes the example of a third-party AI chatbot on a provider's patient portal when the service involves protected health information, such as symptom assessment, medical reminders or appointment scheduling. See the HHS business-associate guidance.
HHS cloud guidance says a cloud service provider that creates, receives, maintains or transmits electronic protected health information on behalf of a covered entity or business associate can itself be a business associate. The document also says OCR does not endorse, certify or recommend particular technology products. See the HHS cloud-computing guidance.
That boundary is important. The fact that software is used in a healthcare practice does not, by itself, answer whether HIPAA applies to the organisation, the information or the vendor relationship.
NIST supplies a voluntary framework, not another enforcement layer
The NIST AI Risk Management Framework is a voluntary risk-management resource. NIST describes AI RMF 1.0 as rights-preserving, non-sector-specific and use-case agnostic, and says organisations may adapt it to their circumstances. See NIST's AI RMF 1.0 publication.
The framework organises risk work under four functions: Govern, Map, Measure and Manage. Those functions can provide a common vocabulary for internal governance, but using them does not determine whether a business has met an FTC, EEOC, HHS or state-law standard. NIST expressly states that the framework and its AI RMF Playbook are intended for voluntary use.
Three location-based rules with practical reach
A durable state-law check begins with the law's coverage language, not a saved list of state names. The most useful questions concern the protected person, the decision, the regulated organisation and the relevant effective date.
Each row below is drawn from the instrument or the enforcing body's own material: Colorado SB 26-189, the CPPA's approved CCPA regulation text and completed rulemaking record, and NYC DCWP's AEDT FAQ.
| Jurisdiction | Instrument and status on 4 September 2026 | Main connection described by the authority | AI use addressed |
|---|---|---|---|
| Colorado | SB 26-189 became law on 14 May 2026 and is scheduled to take effect on 1 January 2027. Implementing rules were still proposed. | The law includes Colorado residents and specified people whose access, eligibility or opportunity in Colorado is evaluated by a person doing business in Colorado. | Automated decision-making technology that materially influences consequential decisions in listed domains. |
| California | Final CCPA regulations took effect on 1 January 2026, with the ADMT-specific requirements beginning on 1 January 2027. | The CCPA protects California residents and applies only to organisations within its definition of a covered business or another regulated role. | Automated decision-making technology used for significant decisions involving areas such as employment, housing, financial services, education and healthcare. |
| New York City | Local Law 144 took effect on 1 January 2023; DCWP began enforcement on 5 July 2023. | DCWP ties use “in the city” to the job or employment agency location, while its notice guidance separately refers to candidates and employees who reside in New York City. | Defined automated employment decision tools used to assess candidates for hiring or employees for promotion. |
Colorado replaced its original AI act before it commenced
Colorado's current reference point is SB 26-189, not the unamended 2024 act. The General Assembly records that SB 26-189 became law on 14 May 2026, while the Attorney General says it repeals and re-enacts the earlier provisions and takes effect on 1 January 2027. See the Colorado General Assembly bill record and the Attorney General's ADMT rulemaking page.
The signed act covers automated decision-making technology that materially influences consequential decisions in specified domains. Its consumer definition includes a Colorado-resident employee or applicant and certain people whose access, eligibility or opportunity in Colorado is evaluated by a person doing business in Colorado. The exact definitions, exclusions and federal-law carve-outs are in the signed text of SB 26-189.
As of the check date, the Attorney General had filed proposed rules and was accepting comments through 26 October 2026. Those proposed rules were not final and should not be described as operative requirements.
California coverage starts with the CCPA business and resident tests
California's final ADMT regulations are part of the CCPA regime rather than a law covering every small business. The California Privacy Protection Agency says the CCPA protects California residents, including resident employees and job applicants. It applies to for-profit entities doing business in California that meet at least one statutory threshold, as well as specified related entities, service providers, contractors and recipients. See the CPPA's coverage FAQ.
The CPPA records the completed rulemaking as effective on 1 January 2026. See the completed rulemaking page. The ADMT compliance date sits in the regulations themselves rather than on that page: a business using ADMT for a significant decision before 1 January 2027 “must be in compliance with the requirements of this Article no later than January 1, 2027”, and one that starts on or after that date must comply from the outset. See the approved regulation text.
Those dates distinguish an adopted regulation from a future compliance milestone. They also prevent the California rule from being overstated as a universal employment-AI law for every organisation dealing with someone in the state.
New York City's trigger is not simply the candidate's location
DCWP's FAQ gives a more precise location test than the shorthand claim that Local Law 144 follows every New York City candidate. According to DCWP, an AEDT is used “in the city” when the job is based in a New York City office at least part time, when a fully remote job is associated with a New York City office, or when the relevant employment agency connection meets its stated test. The FAQ separately says New York City resident candidates and employees receive the required notice when the law applies. See the DCWP FAQ.
DCWP says covered employers and employment agencies cannot use a defined AEDT unless it has undergone a bias audit within the previous year, a summary is publicly available and required notices have been provided. Its FAQ also says the employer or employment agency, rather than the software vendor, is ultimately responsible for the bias-audit condition. See the agency's Local Law 144 reference page.
A non-US headquarters does not settle US exposure
The recurring location question is not “Is the company American?” It is “What US-connected activity, person, data or opportunity does the system affect?” Each authority answers that question differently.
For federal consumer-protection law, relevant facts can include representations made to US customers and conduct affecting US commerce. For employment, the worker, applicant, employing entity and location of the job can matter. For privacy, the individual's residence and the organisation's statutory status can control. For New York City's AEDT law, DCWP's published test looks to the job or employment-agency connection before applying its separate resident-notice rule.
These are screening questions, not a conclusion that a particular foreign company is within US jurisdiction. Cross-border corporate structures, choice-of-law clauses, intermediaries and the division of responsibility between a customer and vendor can change the analysis. The cited authority or qualified US counsel is the appropriate source for a scenario-specific conclusion.
Where the published guidance stops
Agency publications do not answer every mixed or novel AI scenario. General statutes can reach conduct involving AI without defining every model, workflow or allocation of responsibility. Technical assistance and amicus briefs express agency positions, but they are not interchangeable with statutes, regulations or final court judgments.
State coverage can also turn on definitions that resist a one-line summary. A system may assist a decision without meeting a law's defined threshold. An applicant may live in one place, seek a job connected to another and interact with a vendor elsewhere. Colorado's rulemaking was unfinished on the check date, while California's ADMT compliance date had not yet arrived.
Output errors or invented facts from generative AI do not create one standalone “AI hallucination law.” The relevant legal question follows what happened to the output, such as whether it became a customer representation, employment input, credit decision or use of protected health information. This page therefore assigns that subject to the applicable functional authority rather than treating it as a separate jurisdiction.
Questions that identify the relevant source
A business, vendor or adviser examining a particular system can organise the jurisdictional question around the following facts:
- What decision, claim or data-processing activity does the system influence?
- Is the system making a decision, materially influencing it or only supplying information for human review?
- Which people are affected, and where do they reside, work or seek an opportunity?
- Is a job tied to a particular office even if it can be performed remotely?
- Does the organisation meet the coverage definition or threshold in the cited statute?
- Is the source an enacted law, an in-force regulation, agency guidance, an enforcement order, a court filing, a voluntary framework or a proposal?
- Which party uses the output, and which party merely supplies the technology?
- Has the authority published amendments, withdrawals, final rules or new effective dates since the last review?
These questions do not determine compliance. They identify the primary document and the facts that an authority or adviser would need before offering a specific view.
How this was researched
This guide is researched against primary regulatory sources and official regulator guidance, checked against those documents as of the date shown, and written for a business with no dedicated compliance function. We report what a named authority has published and link the document so you can read it yourself. We do not tell you what your legal obligations are.
Read our full methodology and independence and disclosure policy.
Related reading: our AI governance by region.
Related reading: Claude AI Review: Pricing, Features, and Business Verdict and Is Claude Pro Worth It? An Honest Assessment for Business Users.
Free tools: AI Privacy Risk Scorer to score your current AI tool setup against data-privacy best practice | AI Policy Generator to generate a customised AI policy for your business.
Is there a single federal AI regulator in the United States?
No. Federal authority is divided by activity and existing law. The FTC addresses consumer protection, the EEOC addresses employment discrimination, the CFPB administers federal consumer financial law, and HHS OCR administers HIPAA privacy and security rules for regulated entities.
Is the NIST AI Risk Management Framework legally required?
NIST describes AI RMF 1.0 and its Playbook as voluntary resources. Another law, contract or procurement programme could refer to a framework, but the NIST publication does not make itself a universal legal requirement.
Does an AI vendor's state determine which state law applies?
Not by itself. California focuses on covered organisations and California residents, Colorado includes specified Colorado-connected people and opportunities, and New York City publishes a job-location test for AEDT use. The governing text for each jurisdiction supplies the actual connection.
Does New York City Local Law 144 apply whenever a candidate lives in the city?
DCWP's FAQ does not describe candidate residence as the sole trigger. It first ties use “in the city” to the job or employment-agency location, then separately describes notices for New York City resident candidates and employees when the law applies.
Are the CFPB's older AI adverse-action circulars still current guidance?
Circular 2022-03 appears on the CFPB's withdrawn-guidance register, and Circular 2023-03 is archived. The current Regulation B text remains the primary source for the specific-reasons requirement.
Can a business rely on an AI vendor's assurance that its product is compliant?
An assurance does not answer the statutory coverage or role questions. HHS cloud-computing guidance says HHS does not certify particular cloud products, and New York City's DCWP guidance on automated employment decision tools says employers and employment agencies retain responsibility for the Local Law 144 bias-audit condition. The effect of any vendor representation or contract is scenario-specific.
Methodology and checked date
This reference was desk-researched against primary government materials and checked on 4 September 2026. Sources reviewed included FTC final-order announcements, EEOC publications and a filed court brief, the current text of Regulation B, HHS OCR guidance, NIST AI RMF materials, enacted state legislation, completed California regulations, and New York City DCWP guidance.
The page separates enacted law, regulation, enforcement action, agency guidance, court advocacy, voluntary framework and legislative proposal. One further state statute was reviewed but is not summarised here: its official legislature site was unreachable on the check date, so its terms could not be confirmed against the primary source and are therefore not stated. It does not rely on the ten retired Need to Know AI pages as evidence. Their subjects were used only to identify the questions that required fresh primary-source verification.
For the practical layer, continue with Need to Know AI's implementation resources on AI registers, vendor due diligence, staff policy and human-review design. Those resources can help organise records and decisions, but they do not determine whether a legal requirement applies.
The information in this article is general in nature. It reflects a summary of publicly available guidance and does not constitute legal, privacy, or professional advice. Your obligations will depend on your specific situation, jurisdiction, and business circumstances. Do not rely on this article as a substitute for qualified legal or professional advice.
Use the AI vendor due diligence checklist to put the data-handling questions raised by these agencies and state laws to a vendor in writing.
Use the AI vendor due diligence...