The United States does not have a single comprehensive AI law the way the EU does. Instead, AI regulation in the US happens through a mix of existing agency authority, executive branch guidance, and a fast-growing set of state statutes — a patchwork that is genuinely more complex to navigate than a unified framework, even though it is often mischaracterized as "no regulation." This is general information, not legal advice; consult qualified counsel for jurisdiction-specific compliance.
What changed in 2026
- More states passed AI-specific statutes. Following early movers, additional states advanced laws covering algorithmic decision-making in employment, insurance, and consumer transactions, each with its own definitions and thresholds.
- Agencies clarified that existing law already applies. Financial regulators, employment authorities, and consumer protection agencies each issued guidance confirming that current statutes — fair lending, anti-discrimination, unfair-practices law — apply to AI-driven decisions without needing new AI-specific legislation.
- Federal procurement rules tightened. Government agencies purchasing or using AI systems faced stricter internal requirements around testing, documentation, and risk assessment, which indirectly shaped how vendors build compliance programs.
- Litigation became a real enforcement channel. Private lawsuits over AI-driven hiring decisions, biased outputs, and copyright disputes started producing case law that businesses now have to track alongside statutes.
How the patchwork breaks down
| Layer |
Who acts |
Typical focus |
| Federal agencies |
FTC, EEOC, CFPB, and sector regulators |
Applying existing consumer, employment, and financial law to AI |
| Executive guidance |
White House, federal agencies |
Risk management frameworks, procurement standards |
| State legislatures |
Individual state governments |
AI-specific statutes on high-risk decisions, disclosure, biometric use |
| Private litigation |
Courts |
Case-by-case rulings on discrimination, copyright, and liability |
Why states are moving faster than Congress
Comprehensive federal AI legislation has repeatedly stalled, while states have moved because they can act on narrower, more politically tractable slices of the problem — employment discrimination, insurance underwriting, biometric privacy — without needing to resolve every open question about AI at once. The result is that a company's actual compliance obligations depend heavily on which states its users or employees are in, similar to how US privacy law developed state by state before any federal privacy statute existed.
What this means for compliance in practice
A national business cannot rely on a single federal checklist. Practical compliance means mapping which states you operate in or serve, identifying which of their AI-specific laws apply to your use cases, and layering that against existing federal law that already governs the underlying decision — a hiring tool, for instance, has to satisfy both any new state AI statute and long-standing federal anti-discrimination law regardless of new AI rules. This is exactly the kind of cross-cutting question a written AI usage policy is meant to resolve internally, so different teams are not making inconsistent calls.
How this compares with the EU approach
Unlike the EU's single risk-tiered framework covered in AI regulation in the EU, the US approach is bottom-up and reactive — sectoral agencies and state legislatures respond to specific harms rather than starting from a unified risk taxonomy. Businesses operating on both sides of the Atlantic often find it more efficient to build toward the stricter EU standard as a baseline, then verify state-by-state US requirements are also met.
FAQ
Is there a federal AI law in the US?
Not a single comprehensive one as of 2026. AI is regulated through existing federal agency authority, executive guidance, and state statutes rather than one overarching statute — verify current status, since this is an active area of legislative activity.
Which US states have the most developed AI regulation?
Colorado and California have been among the most active in passing AI-specific statutes, but the list is growing; check current state legislation directly since new laws are being introduced regularly.
Do federal agencies enforce AI rules even without new AI legislation?
Yes. Agencies like the FTC and EEOC have stated that existing consumer protection and anti-discrimination law already applies to AI-driven decisions, and have brought enforcement actions on that basis.
How should a multi-state company approach AI compliance?
Map applicable state laws for every jurisdiction you operate in, layer federal sectoral law on top, and centralize the resulting rules into one internal policy rather than handling it ad hoc per team.
Where to go next