By March 2026, lawmakers in 45 states had introduced 1,561 AI-related bills, more than the full total for 2024, according to legislative tracker MultiState. No comprehensive federal AI law exists to unify any of it.
That gap is the defining fact of AI governance in the United States right now. Executive orders set direction without creating enforceable obligations. States write the actual rules, then rewrite them again as litigation and lobbying reshape the text. Colorado passed a landmark AI law, delayed it twice, then repealed and replaced it before it ever took effect. Texas took a narrower, prohibition-based path and is already enforcing it.
This piece maps what currently applies at the federal and state level, where voluntary frameworks like ISO/IEC 42001 and NIST AI RMF fit into a program built for a moving target, and specifically what evidence regulators and auditors expect to see when they ask you to prove it.
Why the US Has No Single AI Law and What Fills the Gap
Ask a compliance officer in Frankfurt or Dublin which law governs their AI systems and they will name one regulation. Ask the same question in Denver, Austin, or New York, and the honest answer is “it depends which state, which sector, and which use case.”
The United States does not regulate AI the way the EU does, through a single risk-tiered statute. Instead, governance runs through four separate channels that overlap and occasionally contradict each other: executive branch policy, state legislation, federal agency enforcement of existing law, and voluntary frameworks that carry no legal force but shape what “reasonable” governance looks like when a regulator or plaintiff’s attorney comes asking.
Executive Order 14110, the Biden administration’s comprehensive AI policy order, was rescinded in January 2025. It should never appear in a current compliance program as active federal policy. What replaced it is a deregulatory sequence: Executive Order 14179 reoriented federal AI policy toward innovation, the July 2025 AI Action Plan set priorities without binding force, and Executive Order 14365 in December 2025 directed the Department of Justice to identify and challenge state AI laws it considers preempted or unconstitutional.
None of this removes existing obligations. It adds a layer of uncertainty about which state rules will survive litigation, on top of the rules themselves.
State requirements are continuing to develop, making it important for compliance teams to track US state AI laws and compliance requirements as they apply to their operations.
Federal AI Policy: Executive Orders, Litigation and the Push for Preemption
The federal government’s current posture is best understood as an attempt to win through litigation and legislative pressure what it has not yet won through statute.
The DOJ’s AI Litigation Task Force, announced January 9, 2026 under Executive Order 14365, exists specifically to challenge state AI laws. Its first major test came fast: on April 9, 2026, xAI sued Colorado Attorney General Philip Weiser over the original Colorado AI Act, and on April 24 the Department of Justice took the unusual step of intervening in support of xAI, marking the first time the federal government has moved to invalidate a state AI law in court. A federal magistrate stayed enforcement of the Colorado law three days later.
On the legislative side, the White House released its National Policy Framework for Artificial Intelligence on March 20, 2026, a four-page set of recommendations, not a bill, urging Congress to establish a “minimally burdensome national standard” that would preempt state AI development laws. Congress has twice declined to pass a broad moratorium on state AI regulation.
The most detailed federal proposal to date is the Great American AI Act, a bipartisan discussion draft released June 4, 2026 by Reps. Jay Obernolte and Lori Trahan. Its Section 121 would preempt state and local laws regulating AI model development for three years, while explicitly preserving generally applicable laws and state rules governing AI use and deployment. That distinction matters: even under the most preemption-friendly federal proposal currently on the table, laws like Colorado’s notice-and-disclosure requirements or Illinois’s video-interview consent rules, which govern deployment rather than model development, would likely survive.
A competing bill, the GUARDRAILS Act, was introduced the same week by Rep. Beyer and House Democrats to block federal preemption of state AI regulation entirely. Neither bill has passed. Congress has enacted exactly one AI-specific statute: the TAKE IT DOWN Act, addressing non-consensual intimate imagery, including AI-generated deepfakes.
The practical takeaway for a compliance team: the direction of federal policy is toward preemption, but direction is not law. Until a preemption bill actually passes, every state statute currently in force remains fully enforceable, and the safest planning assumption is that it will stay that way for the foreseeable future.
The State AI Law Patchwork: Colorado, Texas, California, Illinois and NYC
State law is where AI governance in the US actually bites right now, and it bites differently depending on which state and which use case.
Colorado offers the clearest lesson in how fast this landscape moves. SB 24-205, signed in May 2024, was the country’s first comprehensive AI law, built around a “high-risk AI system” classification, mandatory risk management programs, and a duty of care to avoid algorithmic discrimination. It was delayed twice and never took effect. Facing the xAI litigation and a federal enforcement stay, the Colorado legislature repealed and replaced it in three weeks with SB 26-189, signed May 14, 2026. The new law, formally the Automated Decision-Making Technology Act, drops the high-risk classification, the duty of care, and mandatory impact assessments in favor of a narrower notice-and-disclosure model.
Organizations using consequential automated decision-making systems should also review the Colorado AI Act compliance requirements for automated decision-making systems.
Developers of covered automated decision-making technology (ADMT) must give deployers documentation on intended use, known limitations, and training data categories. Consumers get a right to a plain-language explanation within 30 days of an adverse consequential decision and a right to request meaningful human review. SB 26-189 takes effect January 1, 2027, though enforcement remains stayed pending resolution of xAI LLC v. Weiser, and the Colorado AG opened a pre-rulemaking comment period running June 23 through July 13, 2026.
Texas took the opposite design choice. The Texas Responsible AI Governance Act (TRAIGA), effective January 1, 2026, does not classify systems by risk tier or mandate impact assessments. It prohibits specific harmful uses outright: developing AI to incite self-harm or criminal activity, government social scoring, and generating child sexual abuse material. Enforcement sits exclusively with the Texas Attorney General, civil penalties run from $10,000 to $200,000 per violation, and a 60-day cure period gives organizations a chance to fix a violation before penalties apply. Where Colorado asks for documentation and process, Texas asks a simpler question: are you doing one of the prohibited things or not.
California regulates through accumulation rather than a single statute. The AI Transparency Act (SB 942 and AB 853) requires disclosure when content is AI-generated. Civil Rights Department regulations, effective October 2025, restrict discriminatory AI use in employment decisions. Deepfake disclosure rules apply to political advertising. The Health Care Services AI Act requires providers to disclose when generative AI is used in patient communications and to give patients a way to reach a human. CCPA amendments extend automated decision-making technology rights that overlap conceptually with Colorado’s ADMT model, though the two statutes are not aligned in scope or terminology.
Illinois and New York City each regulate a single high-stakes use case rather than AI broadly. Illinois requires employers to notify job candidates and obtain consent before using AI to analyze video interviews, with defined data retention and destruction rules. NYC Local Law 144 requires an independent bias audit of any automated employment decision tool before it is used for hiring or promotion within the city, with results published publicly.
The pattern across all five: none of these laws share a common risk taxonomy, a common definition of a covered system, or a common audit standard. An organization operating across state lines cannot build one compliance document and reuse it everywhere.
For organizations using automated employment decision tools in New York City, the NYC Local Law 144 bias audit requirements provide a more detailed view of the audit, notice, and documentation obligations.
Sector-Specific Federal Enforcement: FTC, EEOC, and Financial Services
Federal agencies do not need new AI legislation to bring an enforcement action. They apply existing authority to AI-specific facts, and that enforcement is often more immediate than anything moving through Congress or a state legislature.
The FTC continues pursuing “AI washing” cases, meaning unsubstantiated marketing claims about AI capabilities, on a bipartisan basis under Chairman Andrew Ferguson, including a January 2026 resolution with Growth Cave over misrepresented automation claims. The standard the FTC applies is not new: every specific claim about an AI system’s accuracy, capability, or autonomy needs documented substantiation, treated with the same rigor as a financial disclosure.
Governance also extends to how AI capabilities are represented to customers and the market. See our checklist covering FTC requirements for substantiating AI claims before publishing performance, safety, or fairness claims.
Employment is the most heavily regulated use case in the country, not because of any single AI statute but because Title VII, the ADA and the ADEA already apply to any employment decision, algorithmic or not. The EEOC has made clear that using an AI tool does not change an employer’s liability if the tool produces a discriminatory outcome. Stack that federal exposure on top of NYC Local Law 144’s bias audits, Illinois’s consent requirements, and California’s civil rights regulations, and hiring becomes the single area where the most independent legal regimes converge on one process.
Employment is one of the areas where AI governance requirements have become particularly specific. Our guide covers AI hiring compliance, bias audits and evidence requirements across the major regimes affecting automated hiring tools.
Financial services faces the most mature and most quantified expectations in the country. The Treasury Department’s February 2026 framework translates NIST AI RMF principles into 230 operational control objectives spanning model lifecycle governance, identity resolution, and data governance, explicitly designed to integrate with SOC 2 and the NIST Cybersecurity Framework rather than exist as a separate silo. Insurers face a parallel expectation through the NAIC AI Model Bulletin, adopted by a growing number of state insurance regulators as the baseline for how carriers should govern AI used in underwriting and claims.
Insurance organizations face additional sector-specific expectations, covered in our guide to NAIC AI governance requirements for insurers.
Where ISO 42001, EU AI Act and NIST AI RMF Fit Into a US Compliance Strategy
No US law currently mandates ISO/IEC 42001 certification or NIST AI RMF adoption. That is a genuinely different situation from the one Colorado’s original law created, where compliance with NIST AI RMF or ISO 42001 functioned as an affirmative defense against algorithmic discrimination claims. SB 26-189 repealed that defense along with the rest of the old statute. Framework alignment in Colorado today is a best practice, not a shield.
That does not make the frameworks optional in practice. NIST AI RMF 1.0, released in January 2023, has become the reference point regulators and auditors default to even without a statutory mandate, precisely because Treasury built its financial services control framework on top of it. When an examiner, a plaintiff’s expert, or an enterprise customer’s procurement team asks how you manage AI risk, answering in NIST AI RMF’s vocabulary of Govern, Map, Measure, and Manage gets you understood immediately.
For a practical view of how US organizations can operationalize the framework, see our guide to implementing the NIST AI RMF through inventory, risk assessment, and monitoring.
ISO/IEC 42001:2023 plays a different role. It is the only certifiable AI management system standard, meaning a third-party auditor can issue a certificate attesting that your AI governance program meets a defined bar. For organizations selling into enterprise or government accounts where a vendor questionnaire asks for a certification rather than a self-attestation, ISO 42001 answers a question NIST AI RMF cannot, because NIST AI RMF was never designed to be certified against.
The EU AI Act (Regulation 2024/1689) becomes directly relevant the moment a US company places an AI system on the EU market, sells to EU customers, or has an AI system whose output is used in the EU, regardless of where the company is headquartered.
US organizations are not governed only by US requirements. Companies whose AI systems or outputs reach the European market should also understand when the EU AI Act applies to US companies and the records and controls it requires.
The Digital Omnibus on AI, formally adopted by the Council on June 29, 2026 following Parliament’s approval on June 16, deferred the compliance date for stand-alone high-risk AI systems under Annex III to December 2, 2027 and for AI embedded in regulated products under Annex I to August 2, 2028. Publication in the Official Journal was expected mid-to-late July 2026. Critically, Article 50 transparency obligations, the requirement to disclose that a user is interacting with an AI system, were not deferred and remain live from August 2, 2026. A US company with no EU high-risk exposure can still trigger Article 50 duties through a customer-facing chatbot alone.
Used together, the three frameworks cover different gaps: NIST AI RMF gives you a shared risk vocabulary domestic regulators already recognize, ISO 42001 gives you a certifiable management system external parties can verify, and the EU AI Act gives you the risk classification and documentation depth needed if your systems touch the EU market at all.
Building an AI Governance Program That Survives Regulatory Change
Colorado rewrote its flagship AI law twice before it ever took effect. Any program built to satisfy one statute’s specific language is a program that needs rebuilding every time a legislature reconvenes. The more durable approach is to build to the evidence categories in the table above, then map jurisdiction-specific obligations onto that foundation as they change.
In practice, that means five steps in sequence. First, build and maintain a live inventory of every AI system in use, who owns it, and which jurisdictions’ users it touches, since almost every law’s applicability turns on scope questions an inventory answers directly. Second, classify each system against the risk tiers that matter for your footprint, EU AI Act high-risk categories if you have EU exposure, Colorado’s consequential-decision domains if you have Colorado users, and internal risk tiers for everything else.
Third, document human review and escalation paths before a regulator asks for them, not after. Fourth, generate consumer-facing notices and adverse-outcome explanations as a standard workflow output rather than a one-off legal drafting exercise, since Colorado and the EU AI Act both build recurring disclosure duties into ordinary operations rather than a single filing. Fifth, treat monitoring as a scheduled, evidenced activity with its own audit trail, not a status update in a quarterly meeting.
This is also where the case for governance tooling over spreadsheets gets concrete rather than abstract. Govern365.ai’s AI model registry keeps that inventory current automatically as systems are added or retired, and its compliance dashboards map each registered system against ISO 42001 clauses, EU AI Act risk categories, and NIST AI RMF functions at the same time, so a Colorado notice requirement and an EU Article 50 disclosure duty for the same chatbot surface as one workflow rather than two separate compliance projects.
A Gartner report from February 2026 sized the global AI governance software market at $492 million for 2026, projecting growth past $1 billion by 2030, with organizations using structured governance tooling reporting a 3.4x effectiveness multiplier over ad hoc, spreadsheet-based approaches. The scale of that gap tracks with what the evidence table above shows: the artifacts regulators want overlap heavily across frameworks, but only if your systems are structured to produce them once and reuse them, rather than reconstructed from scratch for each new statute.
For mid-market organizations with limited compliance resources, our guide to building an AI governance program with a lean risk team provides a practical implementation path.
Common Mistakes in US AI Governance Programs
Three mistakes show up repeatedly in organizations that treat US AI governance as simpler than it is.
The first is citing Executive Order 14110 or its Biden-era safety testing requirements as active federal policy. It was rescinded in January 2025. Any vendor contract, internal policy, or audit response that still references it is citing dead law, and a sharp counterparty will notice.
The second is assuming federal preemption has already happened because the White House and multiple bills point in that direction. As of this writing, no preemption legislation has passed. The Great American AI Act is a discussion draft. The National Policy Framework is a set of recommendations. State attorneys general in Texas, California, and elsewhere retain full enforcement authority today, and waiting for Congress to resolve the preemption fight is not a compliance strategy, it is a bet.
The third is treating Colorado’s SB 26-189 as equivalent to the high-risk system regime SB 24-205 originally created. The obligations changed substantially: no more mandatory impact assessments, no more statutory duty of care, no more NIST/ISO affirmative defense. Organizations that built compliance programs around the old law’s risk-tier language need to rebuild around ADMT’s narrower notice-and-disclosure model, not simply relabel existing documents.
Frequently Asked Questions
Is there a single federal AI law in the United States?
No. The United States has no comprehensive federal AI statute. Federal AI policy currently runs through executive orders, agency enforcement of existing laws, and non-binding frameworks. Congress has enacted only one AI-specific law, the TAKE IT DOWN Act, addressing non-consensual intimate imagery. Broader bills, including the Great American AI Act discussion draft, remain unintroduced or unpassed.
Is the Colorado AI Act still in effect?
The original Colorado AI Act (SB 24-205) was repealed before it ever took effect. Its replacement, SB 26-189, takes effect January 1, 2027, but enforcement is currently stayed pending federal litigation in xAI LLC v. Weiser. Organizations should build toward the statute’s text now rather than wait for the litigation to resolve.
Do NIST AI RMF and ISO 42001 satisfy any legal requirement in the US?
Not directly. No US federal or state law currently mandates NIST AI RMF or ISO 42001 certification. Colorado’s original AI Act included a NIST/ISO-based affirmative defense, but that provision was repealed along with the rest of SB 24-205. The frameworks remain the most practical way to operationalize the documentation and oversight duties that state laws and federal agencies do expect.
What evidence do regulators actually ask for in an AI governance audit?
Most US requirements converge on five artifact types: a system inventory identifying what AI is in use and where, documented risk or impact assessments, evidence of human review for consequential decisions, records of consumer notices and disclosures, and a change log showing ongoing monitoring rather than a one-time assessment.
Does the EU AI Act apply to US companies?
It can. The EU AI Act applies to any organization that places an AI system on the EU market or whose AI system’s output is used in the EU, regardless of where the company is headquartered. US companies with EU customers, EU-based subsidiaries, or AI systems accessible to EU users should assess extraterritorial exposure separately from their US compliance work.
What happens if my organization ignores state AI laws while waiting for federal preemption?
State laws remain fully enforceable unless and until Congress passes preemptive legislation, which has not happened. The White House’s National Policy Framework is a set of recommendations, not law. Attorneys general in Texas, California, Colorado, and other states retain authority to enforce their statutes today, and generally applicable consumer protection laws add exposure even in states without AI-specific statutes.
Which industries face the most AI governance scrutiny in the US right now?
Employment and financial services lead. AI used in hiring or promotion decisions intersects with NYC Local Law 144, Illinois video-interview rules, California civil rights regulations, and federal anti-discrimination law enforced by the EEOC. Financial services faces the Treasury Department’s February 2026 NIST-aligned control framework and, for insurers, the NAIC AI Model Bulletin.
How often do AI governance requirements change in the US?
Frequently enough that a static compliance document is a liability. Colorado rewrote its flagship AI law twice within two years before it took effect. Treat AI governance as a monitored program with a defined review cadence, not a project with a completion date.
Conclusion
There is no single US AI law to comply with, and there will not be one soon. What exists instead is a set of evidence expectations that repeat across nearly every statute, agency action, and framework covered here: know what AI you run, document how you assessed it, show a human reviewed the consequential decisions, and prove you kept watching after launch.
Start by pulling together an inventory of every AI system touching a consequential decision in your organization, then check it against the evidence table above for the states and frameworks that actually apply to you.
Govern365.ai, maps that inventory against ISO 42001, the EU AI Act, and NIST AI RMF automatically and keeps the evidence current as the laws keep changing. Start your 14-day free trial to see your own AI systems mapped against the frameworks that matter for your business.
