Artificial Intelligence in the United States
Law / proposed law in the United States
Law / proposed law in the United States
AI laws and Proposed Laws
In the US, artificial intelligence (AI) is regulated at both the federal and state levels. While the US lacks a unified federal AI law, the states have been active in modifying existing laws to account for AI and, in some cases, passing targeted AI-specific legislation.
This section outlines the major enacted laws at both federal and state levels, highlighting how states have taken the lead in adapting existing legal frameworks and introducing AI-specific laws in the absence of a comprehensive federal approach.
Federal AI legislation landscape
The federal regulatory landscape for AI remains limited in scope. Although a significant volume of AI-related legislation has been introduced in Congress, only one standalone statute intended to regulate the posting and distribution of AI-generated content has been enacted to date:
- Tools to Address Known Exploitation by Immobilizing Technological Deepfakes on Websites and Networks Act (TAKE IT DOWN Act): Although the statute does not regulate AI systems directly, it requires online platforms to delete flagged non-consensual intimate imagery, including AI-generated deepfakes, within 48 hours. The law creates criminal penalties for distributing such content and empowers the Federal Trade Commission (FTC) to enforce compliance.
Accordingly, federal policy is more defined by proposals than binding obligations, and most operational guidance continues to come from executive actions and agency-level enforcement.
Potential federal framework
On 20 March 2026, the White House released a National Policy Framework for Artificial Intelligence, a set of non-binding legislative recommendations urging Congress to enact a uniform national AI standard that would preempt conflicting state laws. The Framework is organised around a broad set of objectives, including protecting children and empowering parents; safeguarding American communities (such as streamlining data-centre construction while protecting residential ratepayers, and augmenting enforcement against AI-enabled impersonation scams); respecting intellectual property and supporting creators; preventing censorship and protecting free speech; enabling innovation and ensuring American AI dominance; and educating Americans and developing an AI-ready workforce. The Framework does not itself create new legal obligations, but it signals the Administrationâs priorities for the AI legislation it hopes Congress will advance.
This Framework grew out of Executive Order 14365, âEnsuring a National Policy Framework for Artificial Intelligenceâ (the EO), which President Trump signed on 11 December 2025 with the stated aim of creating American dominance in the field. The EO sought to replace the existing patchwork of state lawsâwhich the Trump Administration views as burdensome and detrimental to innovationâwith a unified standard, and it directed federal officials to develop the legislative recommendations that became the March 2026 Framework.
To achieve this, the EO outlined a two-pronged strategy: challenging existing state AI laws in court and establishing a new federal regulatory framework that would preempt them. Pursuant to the EO, on 9 January 2026, the Attorney General (AG) established an AI Litigation Task Force to raise legal challenges to state laws that are viewed as unconstitutional or otherwise conflicting with federal regulations; as of mid-2026, however, the Task Force had not yet filed any lawsuits. The EO also directed the Secretary of Commerce to publish, within 90 days, an evaluation identifying âonerousâ state AI laws for possible referral to the Task Force. The federal framework the EO envisioned focuses on key areas such as child safety, censorship prevention, and copyright protection, while preempting conflicting state-level regulations.
State-level AI legislation landscape
The lack of comprehensive federal AI legislation has led to a proliferation of state-level laws and regulations, with many more bills working their way through state legislatures in 2026. Some of these laws establish frameworks and requirements that impact both public- and private-sector use of AI technologies.
In 2025, all 50 states, Puerto Rico, the Virgin Islands, and Washington, D.C., introduced AI-related legislation. According to the National Conference of State Legislatures, 38 states adopted or enacted approximately 100 AIârelated measures. What materially changes in 2026 is enforceability: several major state AI laws take effect, significantly increasing the need for crossâstate governance frameworks, comprehensive inventories, and demonstrable evidence of controls.
These laws and regulations impose transparency and disclosure obligations, prohibit deceptive use of generative AI, and seek to mitigate algorithmic discrimination in certain domains. The following list includes the principal state laws shaping AI regulation in the US and a few examples of some of the narrower AI-focused laws:
California
- California has enacted significant AI-related legislation, establishing new requirements for transparency, safety, and accountability across various AI applications. Californiaâs SB53, the Transparency in Frontier Artificial Intelligence Act (TFAIA), was signed into law on 29 September 2025, and took effect on 1 January 2026. It requires large frontier AI developers to publish transparency reports and annually update a public frontier AI safety framework describing how they assess and mitigate âcatastrophic riskâ, secure unreleased model weights, and respond to critical safety incidents. Further, Californiaâs AB2013, Generative Artificial Intelligence: Training Data Transparency Act (TDTA) was signed into law 28 September 2024, and took effect 1 January 2026. The TDTA requires AI developers to publicly post a high-level summary of the datasets used to train generative AI systems or services made available to the public since January 2022, enumerating specific categories of required disclosures.
- During 2025, the California state legislature continued to pass many AI-related bills, most of which took effect on 1 January 2026. Signed into law on 13 October 2025, the California AI Transparency Act (AB853) mandates that developers of generative AI must embed âprovenance dataâ into digital content to verify its authenticity and origin. (This law has staggered effective dates through 1 January 2028.) AB489, signed into law on 11 October 2025, prohibits the use of AI to falsely imply that advice or services are being provided by a licensed healthcare professional. Further, enacted on 13 October 2025, SB243 imposes specific safety protocols on âcompanion botsâ, requiring them to prevent harmful conversations and regularly remind users that they are interacting with an AI. Other new laws, also enacted on 13 October 2025, create liability for services that enable deepfake pornography (AB621) and bar defendants from claiming an AI âautonomously caused the harmâ in civil actions (AB316).
Connecticut
- Connecticut enacted Substitute Senate Bill No. 5 (SB5), âAn Act Concerning Online Safetyâ (Public Act No. 26-15), which Governor Ned Lamont signed in May 2026. Rather than a single broad governance statute, the 67-page law links together several separate AI measures, but taken together it establishes Connecticut as a major AI-regulation state. SB5 addresses, among other things: safeguards and disclosure requirements for AI âcompanionâ chatbots, including extensive child-protection provisions; âprovenance dataâ transparency obligations for large generative-AI providers of synthetic audio, image, and video content; disclosure requirements for automated employment-related decision technology, together with an amendment providing that the use of such technology is not a defence to an employment-discrimination claim; whistleblower protections for employees of frontier-model developers; an AI regulatory sandbox; and governance requirements for state agenciesâ use of AI. Its provisions take effect on a staggered basis, with several effective 1 October 2026 and others on 1 January 2027.
Colorado
- On 14 May 2026, Governor Jared Polis signed a new, narrower Colorado Automated Decision-Making Technology in Consequential Decisions Act (enacted as SB 189 and retaining the âColorado AI Actâ short title), which takes effect 1 January 2027 and repeals and replaces the Stateâs broad 2024 Colorado AI Act before that earlier law ever took effect. As originally enacted, in May 2024, the Colorado Act had been recognised as the first comprehensive statute in the US specifically targeting âhigh-riskâ AI systems, requiring developers and deployers of qualifying AI applications to use reasonable care in preventing algorithmic discrimination, mandate clear documentation of AI activities, and hold entities accountable for the outputs of their AI systems in critical areas such as employment, healthcare, lending, housing, and government services. Its effective date was first delayed from 1 February 2026 to 30 June 2026 and then, following the enactment of SB 189 signed on 14 May 2026, postponed again to 1 January 2027. SB 189 also significantly narrowed the law before it took effect, eliminating the original risk-based frameworkâincluding the duty to use reasonable care to prevent algorithmic discrimination, deployer risk management programmes and impact assessments, and certain reporting obligations to the AGâand replacing it with a narrower set of disclosure and transparency requirements focused on automated decision-making technology (ADMT). As revised, developers must provide deployers with specified information about the ADMT they supply (such as intended uses, potentially harmful uses, and categories of training data), and the law preserves limited individual rights to access and correct data and to obtain meaningful human review of adverse automated decisions.
Illinois
- In August 2025, Illinois enacted the Wellness and Oversight for Psychological Resources Act, which imposes significant restrictions on the use of AI in mental healthcare. The law, effective immediately, broadly prohibits any entity without a professional licence from offering therapy services, a rule that explicitly includes services delivered via AI, and bars licensed healthcare professionals from delegating therapeutic decisions to AI systems. More recently, on 6 July 2026, Governor JB Pritzker signed SB 315, a frontier model safety law that closely resembles Californiaâs TFAIA and New Yorkâs RAISE Actârequiring large frontier developers to implement and publicly post a frontier AI framework, publish transparency reports, and report critical safety incidents. Notably, however, SB 315 also imposes a third-party independent audit requirement found in neither the California nor the New York law, obligating large frontier developers to retain independent auditors to assess their compliance annually. The law takes effect on 1 January 2027, with transparency-reporting and audit obligations beginning 1 January 2028.
Kentucky
- Signed and effective on 24 March 2025, Kentuckyâs AI Governance Act (SB4) establishes a comprehensive framework for AI use within state government. It calls for adoption of uniform AI policy standards and creates a governance committee to oversee ethical, transparent, and responsible AI use across state agencies. It includes provisions for human oversight, public disclosure, and protection of personal and business information.
Nevada
- On 5 June 2025, Nevada enacted AB406, which makes it a deceptive trade practice to misrepresent the capabilities of AI in mental healthcare. The law prohibits offering AI systems that are programmed to perform services that would constitute the practice of professional mental healthcare if done by a person. Furthermore, providers are barred from marketing or otherwise representing that their AI systems are capable of delivering such care. AB406 took effect on 1 July 2025.
New York
- New York enacted the Responsible AI Safety and Education (RAISE) Act on 19 December 2025, which establishes a comprehensive regulatory framework for developers of large-scale âfrontierâ AI models. Effective on 1 January 2027, this law requires large developers to implement and publicly disclose a detailed âsafety and security protocolâ designed to mitigate the risk of âcritical harmâ, defined as events causing mass injury or over USD 1 billion in damages. It also requires developers to report any âsafety incidentâ that demonstrates an increased risk of such harm to the state attorney general within 72 hours.
- Further, New York enacted a first-of-its-kind law requiring advertisers to disclose the use of AI-generated individuals in commercial advertising on 11 December 2025. The law mandates a conspicuous disclosure when a âsynthetic performerââa digitally created asset made with generative AI to resemble a human who is not an identifiable personâis featured in a visual or audiovisual advertisement. This rule is narrowly targeted at AI-generated actors and does not apply to audio-only ads, deepfakes of real performers, or AI enhancements of real performers. This law takes effect on 9 June 2026.
- Enacted on 11 December 2021, New York Cityâs Local Law 144 regulates the use of âautomated employment decision toolsâ (AEDTs) in hiring and promotion decisions. Effective since 5 July 2023, the law imposes three core obligations on employers: they must conduct an annual independent bias audit to assess whether the tool has a disparate impact on candidates based on race, ethnicity, or sex; they must post a summary of the audit results publicly on their websites; and they must provide notice to candidates that an AEDT is being used and of their right to request an alternative screening process.
Texas
- Texas enacted the Texas Responsible AI Governance Act (TRAIGA) on 22 June 2025, establishing foundational duties for state agencies, developers, and deployers of AI systems operating within Texas. The law went into effect on 1 January 2026, and prohibits state agencies from certain uses of social scoring and biometric data. Developers and deployers face prohibitions on the intentional misuse of AI for certain types of behavioural manipulation, unlawful discrimination, deepfakes, and infringement of constitutional rights. TRAIGA provides protections for organisations that follow recognised frameworks, such as the National Institute of Standards and Technology (NIST) AI Risk Management Framework, as well as a 60-day cure period for violations, and the creation of a regulatory sandbox.
Utah
- Utah employed a relatively comprehensive approach to AI oversight by adopting, and making effective, the AI Policy Act (SB149) on 1 May 2024. This legislation requires professionals in regulated occupationsâsuch as law, medicine, and financial servicesâto disclose their use of generative AI tools during high-risk interactions, such as when providing sensitive advice or handling personal data. Additionally, consumers must be informed if they explicitly enquire whether they are interacting with AI.
A handful of other U.S. states have considered and rejected broad AI laws. In addition, numerous other states and localities have enacted specific statutes or municipal ordinances that regulate discrete aspects of AI. The following list includes several such examples:
Maine
- Maine enacted âAn Act to Ensure Transparency in Consumer Transactions Involving Artificial Intelligenceâ (the Maine AI Chatbot Disclosure Act) on 12 June 2025. Effective 23 September 2025, the law establishes targeted disclosure requirements for AIâdriven interactions. It generally prohibits businesses (and other persons) from using an AI chatbotâor similar text or voiceâbased computer technologyâin trade or commerce in a manner that may mislead or deceive a reasonable consumer into believing they are interacting with a human, unless the business provides a clear and conspicuous disclosure that the interaction involves AI.
Maryland
- Maryland enacted HB820 on 20 May 2025, regulating how health insurance plans and related entities may use AI in coverage and treatment decisions made in utilisation management and review decisions. Effective 1 October 2025, the law requires covered entities to ensure that the AI toolâs determinations are grounded in the enrolleeâs individual clinical information, do not replace the role of a healthcare provider, and are applied fairly and equitably without resulting in unfair discrimination.
Pennsylvania
- On 7 July 2025, Pennsylvania enacted Act 35 (formerly SB649) to address the malicious use of AI-generated deepfakes. Effective 5 September 2025, the law establishes criminal penalties for generating (or creating and distributing) a forged digital likeness with intent to defraud or injure, or with knowledge and intent to facilitate fraud or injury by anotherâincluding where the actor knows or reasonably should know the audio or visual at issue is forged.
Illinois
- Illinois enacted HB3773 on 9 August 2024, amending the Illinois Human Rights Act to regulate the use of AI in employment decisions, prohibiting discriminatory practices. Effective 1 January 2026, the law requires employers to provide notice to applicants and workers if they use AI for hiring, discipline, discharge, or other workplace-related purposes.
This continued surge in state legislative activity reflects a wide range of approaches and prioritiesâfrom establishing task forces to study AIâs impact to imposing specific obligations on companies deploying AI systems. This dynamic landscape may underscore the growing value of state-level action in the absence of federal guidance, and organisations are encouraged to closely monitor both enacted laws and pending legislation in the jurisdictions in which they operate.
Regulatory guidance / voluntary codes in the United States
Over many years, and especially from 2022 onward, the US federal government issued Presidential Executive Orders, voluntary frameworks and reports, and agency-level enforcement and guidance to set priorities and shape AI governance. States have also issued guidance and voluntary codes of conduct.
Presidential Executive Orders and Official Statements
In addition to the March 2026 National Policy Framework and the Executive Order described in the Law / proposed law section, the Trump Administration has issued other orders and documents focusing on AI, the most significant of which are described in the paragraphs that follow.
In January 2025, the Trump Administration issued EO 14179, titled âRemoving Barriers to American Leadership in Artificial Intelligenceâ, which revoked an executive order from the Biden Administration that had focused in part on civil rights and algorithmic discrimination. The new EO called for the elimination or revision of prior AI-related policies deemed inconsistent with promoting innovation and leadership in the US. It emphasised the development of AI systems that are âfree from ideological bias or engineered social agendasâ, and directed agencies to align their policies accordingly within 180 days.
In July 2025, the White House released âAmericaâs AI Action Planâ which establishes a strategic framework for achieving US global dominance in AI. The plan identifies over 90 federal policy actions across three pillars: accelerating AI innovation through deregulation and support for open-source models, building American AI infrastructure including energy capacity and semiconductor manufacturing, and leading in international AI diplomacy while securing strategic advantages over adversaries. The plan emphasises removing regulatory barriers that hinder private sector innovation, empowering American workers to benefit from AI opportunities, and ensuring AI systems reflect American values and free speech principles.
On 20 March 2026, the White House released a National Policy Framework for Artificial Intelligence, a set of non-binding legislative recommendations intended to guide Congress toward a uniform national AI standard preempting the existing patchwork of state laws. The Framework addresses six objectives: protecting children and empowering parents; safeguarding American communities; respecting intellectual property and supporting creators; preventing censorship and protecting free speech; enabling innovation and American AI dominance; and educating Americans and developing an AI-ready workforce. It does not itself create new legal obligations, and its recommendations track pending congressional proposals, including Senator Marsha Blackburnâs updated TRUMP AMERICA AI Act.
In June 2026, the Administration issued an Executive Order titled âPromoting Advanced Artificial Intelligence Innovation and Securityâ, signed on 2 June 2026, which establishes a voluntary framework for frontier AI developers to engage with the federal government. Under that framework, developers may work with agencies to determine whether a model meets a classified benchmark for designation as a âcovered frontier modelâ and may grant agencies access to such models for 30 days prior to wider release; the EO expressly states that it does not authorise any new mandatory government licensing, pre-clearance, or permitting requirement for the development, release, or distribution of AI models. The order also directs measures to strengthen federal cybersecurity defences and to prioritise enforcement against the use of AI to unlawfully access or damage computer systems.
Several notable federal bills remain pending in the 119th Congress, none of which had become law as of mid-2026. The most far-reaching is Senator Blackburnâs TRUMP AMERICA AI Act, released as a 291-page discussion draft on 18 March 2026, which would impose a duty of care on AI developers enforceable by the FTC, establish a new products-liability framework, require third-party political-bias audits for high-risk systems, declare that unauthorised use of copyrighted works for AI training is not fair use, repeal Section 230 of the Communications Decency Act, and incorporate several existing bills (including the GUARD Act, the NO FAKES Act, the TRAIN Act, and the Kids Online Safety Act); notably, despite its framing around ending the state âpatchworkâ, the draft does not expressly preempt all state AI laws and in places preserves statesâ authority to enact stricter rules. Other proposals reflect the opposite approach: the GUARDRAILS Act (H.R.8031/S.4216, introduced March 2026) would repeal EO 14365 outright and bar the use of federal funds to implement it.
A significant bipartisan counterpart is the Great American AI Act (GAAIA), which Representatives Jay Obernolte (R-CA) and Lori Trahan (D-MA) released as a roughly 269-page discussion draft on 4 June 2026, though it has not yet been formally introduced in Congress. The draft is organised into titles addressing frontier AI and government, workforce, cybersecurity, and research and international cooperation. Among other things, it would require large frontier-model developers to publish a âfrontier AI frameworkâ and transparency reports and to report critical safety incidents (Section 111); create a federal system in which the Director of the Centre for AI Standards and Innovation would license and oversee âindependent verification organisationsâ that large frontier developers must retain to perform audits and assessments (Section 112); and protect employees and contractors from retaliation for reporting AI violations (Section 113). Title I would preempt state laws specifically regulating the development of AI models for three years, while leaving intact laws of general applicability and many other state AI laws.
Voluntary AI-related frameworks
In parallel, voluntary frameworks continue to guide ethical and responsible AI development. Most notably:
- AI Bill of Rights (October 2022): Issued by the White House Office of Science and Technology Policy (OSTP) during the Biden Administration, the âBlueprint for an AI Bill of Rights: Making Automated Systems Work for the American Peopleâ is a set of principles aimed at guiding ethical AI use and protecting the public from harmful AI practices. While not enforceable, its core principles have influenced corporate ethics policies and state-level legislation. The Trump Administration has moved away from the principles expressed therein.
- NIST AI Risk Management Framework (AI RMF 1.0) (January 2023): This voluntary and non-binding framework, released by the US Department of Commerceâs NIST, is designed to mitigate AI risks. Widely adopted by both private companies and government agencies as a best-practice guide, the Risk Management Framework (RMF) encourages organisations to assess and mitigate risks based on the context and potential impact of the AI system. Notably, the Trump Administration, through the White Houseâs July 2025 AI Action Plan, recommends that NIST revise the AI RMF 1.0 to remove references to certain topics including misinformation, DEI, and climate change.
- NIST Generative AI Profile (July 2024): NIST released this voluntary guide as a supplement to the RMF. It tailors the RMFâs core principlesââmapâ, âmeasureâ, âmanageâ, and âgovernââto the risks of generative AI, such as misinformation, deepfakes, and IP concerns. It offers over 400 recommended actions across the generative AI lifecycle and emphasises stakeholder engagement, transparency, and responsible deployment.
- NIST AI 100-4 (November 2024): In furtherance of the Biden Administrationâs Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence, NIST issued the report âReducing Risks Posed by Synthetic Content: An Overview of Technical Approaches to Digital Content Transparencyâ as a technical overview of methods to increase transparency and reduce the risks associated with AI-generated content. It provides foundational guidance for developing future standards and applies its concepts to the AI RMF. It aims to improve trust in digital media by examining technical approaches for content authentication, provenance tracking, synthetic content detection, and the prevention of harmful AI-generated materials.
- NIST Cybersecurity Framework AI Profile (December 2025): Issued as a preliminary draft, NISTâs Cyber AI Profile provides guidelines for managing cybersecurity risks associated with AI systems and for leveraging AI to improve cybersecurity capabilities. It applies the core functions of the NIST Cybersecurity Framework (CSF) 2.0 to help organisations strategically adopt AI while addressing emerging cybersecurity risks. It organises its guidance into three focus areas: securing AI components, using AI for cyber defence, and thwarting AI-enabled attacks.
- NIST Possible Approach for Evaluating AI Standards Development (January 2026): NIST issued the grant contractor report, âA Possible Approach for Evaluating AI Standards Developmentâ, as a conceptual paper proposing a framework to measure the effectiveness and impact of AI standards. While the report presents a non-prescriptive approach intended to foster discussion, it introduces a formal âtheory of changeâ model to help stakeholders evaluate how AI standards achieve goals such as promoting innovation and public trust. It outlines a process for identifying the inputs, activities, outputs, and outcomes of standards development and measuring their impact against a âcounterfactualâ, or what would have happened in the absence of the standard.
Federal agency action
Several federal agencies are also leveraging their statutory authorities to address emerging risks, ensure compliance, and hold organisations accountable for the misuse or misrepresentation of AI technologies. Enforcement actions by agencies such as the FTC, Securities and Exchange Commission (SEC), Department of Justice (DOJ), Food and Drug Administration (FDA), and Department of Health & Human Services (HHS) have aimed to help shape responsible AI practices. These actions span a range of issuesâfrom consumer protection and investor transparency to employment discrimination and medical device safety. The following outlines the roles of some of the key federal agencies in AI oversight and highlights their regulatory focus areas.
FTC
The FTCâs mission is to protect consumers and promote fair competition. The agency has targeted deceptive practices and misleading claims about AIâoften referred to as âAI washingâ. The agency has now brought numerous enforcement actions against companies that exaggerate the capabilities of their AI systems or falsely market products as AI-powered to gain consumer trust. The FTC has also focused its enforcement on privacy issues with AI systems and the misuse of generative AI for scams and fake reviews. In addition, the agency has explored antitrust issues relating to algorithmic pricing and the market for cloud computing.
SEC
The SECâs regulatory focus on AI centres around ensuring transparency, managing conflicts of interest, and protecting investors. It requires firms to clearly disclose how AI is used, particularly when it influences investment decisions or client interactions, to police false or misleading AI statements to investors or clients. The SEC addresses organisational claims about AI capabilities that are misleading to investors, and requires compliance with existing securities laws, applying a technology-neutral, risk-based approach to oversight. Like the FTC, the SEC has been bringing enforcement actions relating to âAI washingâ.
DOJ
The DOJ enforces a broad array of federal criminal and civil laws, intensifying its focus on misconduct related to AI, particularly âAI washingâ. In April 2025, the DOJ, working in parallel with the SEC, brought securities and wire fraud charges against the former CEO of a technology startup for allegedly defrauding investors of over USD 42 million by falsely claiming his company used advanced AI when its services were actually being performed manually. This enforcement posture underscores the significance of the DOJâs late 2024 guidance on how companies should manage risks associated with AI and other emerging technologies. In certain cases, when considering punishment for criminal wrongdoing, federal prosecutors would use this guidance in considering the efficacy of a companyâs relevant compliance programme. The agency has also brought law enforcement actions involving AI-related mistakes and misuse, sometimes working with agencies like the SEC. Given that DOJ also enforces civil rights laws, it has signalled in the past that AI systems used in areas like housing, employment, and lending must comply with anti-discrimination statutes.
FDA
The FDA plays a central role in regulating AI in both the medical device and drug development contexts, proactively establishing regulatory infrastructure to ensure compliance and safety. In January 2025, the agency released a draft guidance, âConsiderations for the Use of Artificial Intelligence to Support Regulatory Decision-Making for Drug and Biological Productsâ, which introduces a risk-based credibility assessment framework for AI models used in this context. It outlines a seven-step process for assessing AI model credibility, discusses challenges such as data quality and algorithmic bias, and highlights the need for life cycle maintenance of AI models to ensure their continued reliability. The FDA has also adopted a separate risk-based framework for the regulation of Software as a Medical Device (SaMD), focusing on the intended use of the software and the potential impact on patient health, which includes evaluating the softwareâs clinical functionality, reliability, and performance. The FDA strongly encourages sponsors to engage with the agency early in the development process to discuss the use of AI in the context of drug development.
HHS
The HHS, through its Office for Civil Rights (OCR), plays a central role in governing the use of AI and other advanced technologies that implicate protected health information. OCR administers and enforces the HIPAA Privacy, Security, and Breach Notification Rules, and has increasingly framed these authorities to account for evolving technological and cybersecurity risks. In particular, OCR has moved to modernise HIPAA Security Rule requirements to reflect changes in the digital health ecosystem, explicitly citing the growing sophistication of cyber threats, the expanded use of automated and dataâintensive systems, and the need for stronger safeguards around electronic protected health information.
Appointed supervisory authority in the United States
The US has no centralised federal regulator specifically dedicated to AI. Instead, federal oversight of AI remains distributed across multiple agencies and advisory bodies. For example, the Trump Administrationâs December 2025 EO pushed a national policy framework and strategies to challenge state AI laws but did not suggest the need for a new regulator to oversee such efforts; it relies instead on existing agencies and officials.
Similarly, most states do not charge a single agency with oversight or responsibility for AI-related matters. A growing number of states have adopted AI-specific statutes that embed regulatory or enforcement authority in existing agencies or frameworks, such as consumer protection, and that sometimes designate specialised oversight bodies in particular market sectors.
For example, Coloradoâs AG will enforce the Stateâs new automated decision-making technology law under the Colorado Consumer Protection Act, with no private right of action, and the Texas Attorney General has exclusive authority to enforce the Texas Responsible AI Governance Act (TRAIGA); Utah, meanwhile, has designated oversight through its Department of Commerce and an emerging Office of AI Policy. New Yorkâs RAISE Act will create a new agency, within a larger, existing one, to implement that law. At the local level, New York Cityâs Local Law 144 assigns enforcement to NYCâs Department of Consumer and Worker Protection (DCWP).
In other states, AGs are actively leveraging existing consumer protection, privacy, and anti-discrimination laws to investigate and enforce against AI-related harms. In addition to engaging AGs, several states have empowered consumer protection agencies or other regulatory bodies to oversee AI-related compliance, resulting in a decentralised enforcement landscape where responsibilities vary by jurisdiction.
Definitions in the United States
In the US, the definition of AI varies across jurisdictions and legal frameworks.
At the federal level, definitions of AI have appeared in several laws, including the National AI Initiative Act, reflected in 15 U.S.C. § 9401, which defines AI as follows:
â(3) ARTIFICIAL INTELLIGENCE â The term âartificial intelligenceâ means a machine-based system that can, for a given set of human-defined objectives, make predictions, recommendations or decisions influencing real or virtual environments. Artificial intelligence systems use machine and human-based inputs to:
(A) perceive real and virtual environments;
(B) abstract such perceptions into models through analysis in an automated manner; and
(C) use model inference to formulate options for information or action.â
State laws have also used different definitions of AI. Below are two variants.
Connecticutâs SB5 defines âartificial intelligenceâ as:
â[A]ny machine-based system that, for any explicit or implicit objective, infers from the inputs such system receives how to generate outputs, including, but not limited to, content, decisions, predictions, or recommendations, that can influence physical or virtual environments.â (Conn. Pub. Act No. 26-15, § 17).
Utahâs AI Policy Act carves out Generative AI as:
âAn artificial system that: (i) is trained on data; (ii) interacts with a person using text, audio, or visual communication; and (iii) generates nonscripted outputs similar to outputs created by a human, with limited or no human oversight.â (Utah Code § 13-2-12(1)(a))
Prohibited activities in the United States
As noted in the Law / proposed law section, the US has not enacted a comprehensive federal law that explicitly outlines prohibited uses of AI. However, certain AI-related activities are restricted or prohibited under existing laws and proposed legislation. Enforcement actions have been taken under broader legal authorities such as consumer protection, civil rights, and securities laws.
At the federal level, two of the many proposed bills aiming to prohibit specific AI practices are:
- The Preventing Algorithmic Collusion Act (2025), which would ban the use of pricing algorithmsâincluding those powered by AIâto incorporate nonpublic competitor data to facilitate price-fixing
- The Transparency and Responsibility for Artificial Intelligence Networks Act (TRAIN Act) (2025), which would create an administrative subpoena process allowing copyright owners to compel AI developers to disclose copies of, or records sufficient to identify, copyrighted works used to train generative artificial intelligence models
- The Guidelines for User Age-verification and Responsible Dialogue Act (GUARD Act) (2025), which would require AI chatbots to implement age-verification measures, bar minors from accessing AI âcompanionâ chatbots, mandate disclosures that users are interacting with a non-human system lacking professional credentials, and prohibit chatbots that encourage self-harm or engage minors in sexual conduct. The U.S. Senate Judiciary Committee unanimously advanced the bill on 30 April 2026, and it was reported to the Senate on 11 May 2026.
While these bills have not become law, federal agencies have used existing statutes that prohibit deceptive or harmful AI practices. For example:
- The FTC has taken enforcement action against companies for âAI washingâ (misleading claims about AI capabilities) and is studying the business practices of companies that offer companion chatbots, focusing on their effect on children
- The SEC has charged firms for misrepresenting the role of AI in investment strategies
- The DOJ has pursued criminal charges in cases involving fraudulent claims about AI functionality
At the state level, some jurisdictions have enacted laws that explicitly prohibit certain AI uses, such as:
- Utahâs AI Policy Act, which prohibits the undisclosed use of generative AI in regulated occupations (e.g. legal, medical), requires clear disclosure when AI is used in consumer interactions, and holds individuals liable for AI-driven misconduct under state consumer protection laws
- New York Cityâs Local Law 144, which prohibits the use of automated employment decision tools without prior bias audits and candidate notification
- California and Illinois, which have passed laws restricting the unauthorized use of AI-generated digital replicas and require transparency in political advertising
Overall, while the US lacks a unified list of federally prohibited AI activities, a growing patchwork of federal enforcement actions and state-level statutes is continuing to define the boundaries of acceptable AI use.
High-risk AI in the United States
Unlike in the EU, the risk categorisation of AI technologies in the US is not defined by a single, harmonised legislative or regulatory taxonomy. Whether a specific AI technology or use is considered âhigh-riskâ will depend on, and will matter only if, jurisdiction-specific laws or rules include a relevant definition. As originally enacted, the Colorado AI Act was the only legislation that adopted a risk stratification system categorising certain uses of AI as âhigh-riskâ. However, amendments enacted in May 2026 (SB 189) removed this risk-based framework before it took effect, replacing it with narrower transparency requirements for automated decision-making technology that take effect on 1 January 2027.
Controls on generative AI in the United States
As the US does not have a comprehensive federal law regulating generative AI, controls on generative AI are emerging through a combination of enforcement actions, state and local legislation, and agency rules or guidance.
At the federal level, several agencies, including the FTC and SEC, have taken enforcement actions against deceptive claims about AI. The FTC will be enforcing the TAKE IT DOWN Act, which covers certain types of deepfakes, and has issued rules about impersonation scams and fake reviews that would cover the use of generative AI tools.
At the state level, several jurisdictions have enacted targeted controls on generative AI. These laws include transparency obligations on AI developers, prohibitions on AI-generated deepfakes, disclosure requirements for consumer-bot interactions, and restrictions on chatbot use for mental health or companionship, among other things. Three examples are:
- Californiaâs Generative AI Training Data Transparency Act, which requires disclosure of high-level details about the training data used in generative AI systems
- Connecticutâs SB5, which requires large generative-AI providers (generative AI systems with more than one million monthly users) to embed tamper-resistant âprovenance dataâ in AI-created or materially altered audio, image, or video content, and which separately imposes safeguards and disclosures for AI companion chatbots and disclosure requirements for automated employment-related decision technology
- Utahâs AI Policy Act, which prohibits the undisclosed use of generative AI in regulated occupations and mandates clear disclosure when AI is used in consumer interactions
Enforcement / fines in the United States
Federal and state agencies can vary widely in how they enforce AI-related laws â not only because the laws themselves differ, but also due to the distinct enforcement powers that each agency holds.
For example, the DOJ and SEC jointly charged the founder of an AI startup with securities and wire fraud involving false claims about AI capabilities. Each agency sought several forms of relief, with the DOJ seeking a prison sentence and the SEC seeking civil fines.
The FTCâs cases involving deceptive marketing of AI tools have resulted in injunctions and sometimes monetary payments.
At the state level, enforcement is similarly fragmented, with available relief dependent on the agencies and laws involved. For example, Texas and Utah have enacted AI-specific laws that include statutory penalties:
- Texasâs TRAIGA, which the Texas Attorney General enforces exclusively (with no private right of action) following a 60-day notice-and-cure period, and which authorizes civil penalties of USD 10,000 to 12,000 for curable violations, USD 80,000 to 200,000 for uncurable violations, and USD 2,000 to 40,000 per day for ongoing violations, in addition to injunctive relief, attorneysâ fees, and investigative costs
User transparency in the United States
In the context of AI, transparency may involve different types of disclosures, such as the use of a machine learning tool to make consequential decisions about consumers or the use of a chatbot to interact with consumers. The US does not currently have a federal law that specifically mandates transparency in AI systems. Some laws of general applicability, like broad consumer protection laws, may require disclosures about AI to avoid consumer deception. On the state and local level, however, a patchwork of laws has developed requiring transparency in different situations. For example:
- Californiaâs Generative AI: Training Data Transparency Act mandates disclosure of high-level details about the training data used in generative AI systems
- Californiaâs TFAIA requires large âfrontierâ AI developers to publish transparency reports and annually update a public frontier AI safety framework describing how they assess and mitigate âcatastrophic riskâ, secure unreleased model weights, and respond to critical safety incidents
- Utahâs AI Policy Act mandates verbal or written disclosure when consumers interact with generative AI in regulated service contexts
- New Yorkâs RAISE Act requires large developers to implement and publicly disclose a âsafety and security protocolâ and report any âsafety incidentâ to mitigate risk
- New York Cityâs Local Law 144 requires employers to notify candidates when automated employment decision tools are used, and to publish the results of bias audits
These efforts may reflect a growing consensus that transparency is key to responsible AI deployment, particularly in applications such as employment, healthcare, and consumer services. However, the scope and enforcement of transparency obligations vary significantly across jurisdictions, contributing to a fragmented compliance landscape.
Fairness / unlawful bias in the United States
As with transparency, there is no federal law in the US that specifically addresses fairness, bias, or other forms of algorithmic discrimination in AI systems. Under the Biden Administration, federal agencies sought to address these issues by applying existing civil rights, employment, and consumer protection laws to AI use cases. However, this activity has almost entirely ended, and agency-issued guidance on these subjects has in some cases been removed from public websites. Meanwhile, however, several states have enacted or proposed legislation to directly address algorithmic discrimination. For example:
- Californiaâs Fair Employment and Housing Act applies to employersâ use of â[AI], algorithms, and other automated-decision systemsâ in employment decisions
- Coloradoâs new automated decision-making technology law, which splits liability for algorithmic discrimination between developers and deployers under the Colorado Anti-Discrimination Actâholding each responsible only to the extent of its relative fault, depending on whether a Covered ADMT was used as intended and documentedâand voids contractual indemnification clauses that attempt to shift liability for unlawful algorithmic discrimination in consequential decisions
- Illinois has enacted workplace AI legislation that prohibits the use of AI in hiring or employment decisions that could result in discrimination
- New Jersey issued guidance clarifying that the New Jersey Law Against Discrimination (LAD) applies to âalgorithmic discriminationâ resulting from the use of AI and other decision-making tools, including in employment
- New York Cityâs Local Law 144 requires annual bias audits for automated employment decision tools and mandates candidate notification
These state and local efforts, combined with prior federal activity, may reflect a growingâthough not entirely sharedâbelief that AI systems can perpetuate or amplify existing societal biases, and that legal frameworks are evolving to ensure fairness, particularly in domains like employment, housing, and healthcare.
Human oversight in the United States
Human oversight of AI systems is not federally mandated in the US, but some states have passed related laws, particularly for high-risk applications.
At the federal level, the NIST AI RMF encourages organizations to implement human oversight mechanisms throughout the AI lifecycle. It defines oversight as the ability for humans to understand, monitor, and, when necessary, intervene in AI system operations. While not legally binding, the framework is widely adopted across industries and referenced in agency guidance.
Since the Biden Administration, some federal enforcement agencies, such as the FTC and SEC, have continued to stress the value of human accountability, particularly in cases where AI is used to make decisions that affect consumers or investors. However, these expectations are grounded in broader legal principles, rather than AI-specific statutes.
At the state level, human oversight is more explicitly addressed in certain laws, such as:
- Illinoisâs Wellness and Oversight for Psychological Resources Act, which safeguards human oversight in mental healthcare by barring any entity without a professional licenceâincluding where services are delivered via AIâfrom offering therapy services and by prohibiting licensed professionals from delegating therapeutic decisions to AI systems
- Californiaâs Physicians Make Decisions Act, which prohibits healthcare coverage denials made on the sole basis of an AI or algorithmic tool
- New York Cityâs Local Law 144, which mandates that employers using automated employment decision tools conduct bias audits and provide human-readable explanations of how such tools may influence hiring decisions
These developments reflect a growing belief that human oversight may be a key to ensuring accountability, safety, and fairness in AI use.
AI laws and Proposed Laws
In the US, artificial intelligence (AI) is regulated at both the federal and state levels. While the US lacks a unified federal AI law, the states have been active in modifying existing laws to account for AI and, in some cases, passing targeted AI-specific legislation.
This section outlines the major enacted laws at both federal and state levels, highlighting how states have taken the lead in adapting existing legal frameworks and introducing AI-specific laws in the absence of a comprehensive federal approach.
Federal AI legislation landscape
The federal regulatory landscape for AI remains limited in scope. Although a significant volume of AI-related legislation has been introduced in Congress, only one standalone statute intended to regulate the posting and distribution of AI-generated content has been enacted to date:
- Tools to Address Known Exploitation by Immobilizing Technological Deepfakes on Websites and Networks Act (TAKE IT DOWN Act): Although the statute does not regulate AI systems directly, it requires online platforms to delete flagged non-consensual intimate imagery, including AI-generated deepfakes, within 48 hours. The law creates criminal penalties for distributing such content and empowers the Federal Trade Commission (FTC) to enforce compliance.
Accordingly, federal policy is more defined by proposals than binding obligations, and most operational guidance continues to come from executive actions and agency-level enforcement.
Potential federal framework
On 20 March 2026, the White House released a National Policy Framework for Artificial Intelligence, a set of non-binding legislative recommendations urging Congress to enact a uniform national AI standard that would preempt conflicting state laws. The Framework is organised around a broad set of objectives, including protecting children and empowering parents; safeguarding American communities (such as streamlining data-centre construction while protecting residential ratepayers, and augmenting enforcement against AI-enabled impersonation scams); respecting intellectual property and supporting creators; preventing censorship and protecting free speech; enabling innovation and ensuring American AI dominance; and educating Americans and developing an AI-ready workforce. The Framework does not itself create new legal obligations, but it signals the Administrationâs priorities for the AI legislation it hopes Congress will advance.
This Framework grew out of Executive Order 14365, âEnsuring a National Policy Framework for Artificial Intelligenceâ (the EO), which President Trump signed on 11 December 2025 with the stated aim of creating American dominance in the field. The EO sought to replace the existing patchwork of state lawsâwhich the Trump Administration views as burdensome and detrimental to innovationâwith a unified standard, and it directed federal officials to develop the legislative recommendations that became the March 2026 Framework.
To achieve this, the EO outlined a two-pronged strategy: challenging existing state AI laws in court and establishing a new federal regulatory framework that would preempt them. Pursuant to the EO, on 9 January 2026, the Attorney General (AG) established an AI Litigation Task Force to raise legal challenges to state laws that are viewed as unconstitutional or otherwise conflicting with federal regulations; as of mid-2026, however, the Task Force had not yet filed any lawsuits. The EO also directed the Secretary of Commerce to publish, within 90 days, an evaluation identifying âonerousâ state AI laws for possible referral to the Task Force. The federal framework the EO envisioned focuses on key areas such as child safety, censorship prevention, and copyright protection, while preempting conflicting state-level regulations.
State-level AI legislation landscape
The lack of comprehensive federal AI legislation has led to a proliferation of state-level laws and regulations, with many more bills working their way through state legislatures in 2026. Some of these laws establish frameworks and requirements that impact both public- and private-sector use of AI technologies.
In 2025, all 50 states, Puerto Rico, the Virgin Islands, and Washington, D.C., introduced AI-related legislation. According to the National Conference of State Legislatures, 38 states adopted or enacted approximately 100 AIârelated measures. What materially changes in 2026 is enforceability: several major state AI laws take effect, significantly increasing the need for crossâstate governance frameworks, comprehensive inventories, and demonstrable evidence of controls.
These laws and regulations impose transparency and disclosure obligations, prohibit deceptive use of generative AI, and seek to mitigate algorithmic discrimination in certain domains. The following list includes the principal state laws shaping AI regulation in the US and a few examples of some of the narrower AI-focused laws:
California
- California has enacted significant AI-related legislation, establishing new requirements for transparency, safety, and accountability across various AI applications. Californiaâs SB53, the Transparency in Frontier Artificial Intelligence Act (TFAIA), was signed into law on 29 September 2025, and took effect on 1 January 2026. It requires large frontier AI developers to publish transparency reports and annually update a public frontier AI safety framework describing how they assess and mitigate âcatastrophic riskâ, secure unreleased model weights, and respond to critical safety incidents. Further, Californiaâs AB2013, Generative Artificial Intelligence: Training Data Transparency Act (TDTA) was signed into law 28 September 2024, and took effect 1 January 2026. The TDTA requires AI developers to publicly post a high-level summary of the datasets used to train generative AI systems or services made available to the public since January 2022, enumerating specific categories of required disclosures.
- During 2025, the California state legislature continued to pass many AI-related bills, most of which took effect on 1 January 2026. Signed into law on 13 October 2025, the California AI Transparency Act (AB853) mandates that developers of generative AI must embed âprovenance dataâ into digital content to verify its authenticity and origin. (This law has staggered effective dates through 1 January 2028.) AB489, signed into law on 11 October 2025, prohibits the use of AI to falsely imply that advice or services are being provided by a licensed healthcare professional. Further, enacted on 13 October 2025, SB243 imposes specific safety protocols on âcompanion botsâ, requiring them to prevent harmful conversations and regularly remind users that they are interacting with an AI. Other new laws, also enacted on 13 October 2025, create liability for services that enable deepfake pornography (AB621) and bar defendants from claiming an AI âautonomously caused the harmâ in civil actions (AB316).
Connecticut
- Connecticut enacted Substitute Senate Bill No. 5 (SB5), âAn Act Concerning Online Safetyâ (Public Act No. 26-15), which Governor Ned Lamont signed in May 2026. Rather than a single broad governance statute, the 67-page law links together several separate AI measures, but taken together it establishes Connecticut as a major AI-regulation state. SB5 addresses, among other things: safeguards and disclosure requirements for AI âcompanionâ chatbots, including extensive child-protection provisions; âprovenance dataâ transparency obligations for large generative-AI providers of synthetic audio, image, and video content; disclosure requirements for automated employment-related decision technology, together with an amendment providing that the use of such technology is not a defence to an employment-discrimination claim; whistleblower protections for employees of frontier-model developers; an AI regulatory sandbox; and governance requirements for state agenciesâ use of AI. Its provisions take effect on a staggered basis, with several effective 1 October 2026 and others on 1 January 2027.
Colorado
- On 14 May 2026, Governor Jared Polis signed a new, narrower Colorado Automated Decision-Making Technology in Consequential Decisions Act (enacted as SB 189 and retaining the âColorado AI Actâ short title), which takes effect 1 January 2027 and repeals and replaces the Stateâs broad 2024 Colorado AI Act before that earlier law ever took effect. As originally enacted, in May 2024, the Colorado Act had been recognised as the first comprehensive statute in the US specifically targeting âhigh-riskâ AI systems, requiring developers and deployers of qualifying AI applications to use reasonable care in preventing algorithmic discrimination, mandate clear documentation of AI activities, and hold entities accountable for the outputs of their AI systems in critical areas such as employment, healthcare, lending, housing, and government services. Its effective date was first delayed from 1 February 2026 to 30 June 2026 and then, following the enactment of SB 189 signed on 14 May 2026, postponed again to 1 January 2027. SB 189 also significantly narrowed the law before it took effect, eliminating the original risk-based frameworkâincluding the duty to use reasonable care to prevent algorithmic discrimination, deployer risk management programmes and impact assessments, and certain reporting obligations to the AGâand replacing it with a narrower set of disclosure and transparency requirements focused on automated decision-making technology (ADMT). As revised, developers must provide deployers with specified information about the ADMT they supply (such as intended uses, potentially harmful uses, and categories of training data), and the law preserves limited individual rights to access and correct data and to obtain meaningful human review of adverse automated decisions.
Illinois
- In August 2025, Illinois enacted the Wellness and Oversight for Psychological Resources Act, which imposes significant restrictions on the use of AI in mental healthcare. The law, effective immediately, broadly prohibits any entity without a professional licence from offering therapy services, a rule that explicitly includes services delivered via AI, and bars licensed healthcare professionals from delegating therapeutic decisions to AI systems. More recently, on 6 July 2026, Governor JB Pritzker signed SB 315, a frontier model safety law that closely resembles Californiaâs TFAIA and New Yorkâs RAISE Actârequiring large frontier developers to implement and publicly post a frontier AI framework, publish transparency reports, and report critical safety incidents. Notably, however, SB 315 also imposes a third-party independent audit requirement found in neither the California nor the New York law, obligating large frontier developers to retain independent auditors to assess their compliance annually. The law takes effect on 1 January 2027, with transparency-reporting and audit obligations beginning 1 January 2028.
Kentucky
- Signed and effective on 24 March 2025, Kentuckyâs AI Governance Act (SB4) establishes a comprehensive framework for AI use within state government. It calls for adoption of uniform AI policy standards and creates a governance committee to oversee ethical, transparent, and responsible AI use across state agencies. It includes provisions for human oversight, public disclosure, and protection of personal and business information.
Nevada
- On 5 June 2025, Nevada enacted AB406, which makes it a deceptive trade practice to misrepresent the capabilities of AI in mental healthcare. The law prohibits offering AI systems that are programmed to perform services that would constitute the practice of professional mental healthcare if done by a person. Furthermore, providers are barred from marketing or otherwise representing that their AI systems are capable of delivering such care. AB406 took effect on 1 July 2025.
New York
- New York enacted the Responsible AI Safety and Education (RAISE) Act on 19 December 2025, which establishes a comprehensive regulatory framework for developers of large-scale âfrontierâ AI models. Effective on 1 January 2027, this law requires large developers to implement and publicly disclose a detailed âsafety and security protocolâ designed to mitigate the risk of âcritical harmâ, defined as events causing mass injury or over USD 1 billion in damages. It also requires developers to report any âsafety incidentâ that demonstrates an increased risk of such harm to the state attorney general within 72 hours.
- Further, New York enacted a first-of-its-kind law requiring advertisers to disclose the use of AI-generated individuals in commercial advertising on 11 December 2025. The law mandates a conspicuous disclosure when a âsynthetic performerââa digitally created asset made with generative AI to resemble a human who is not an identifiable personâis featured in a visual or audiovisual advertisement. This rule is narrowly targeted at AI-generated actors and does not apply to audio-only ads, deepfakes of real performers, or AI enhancements of real performers. This law takes effect on 9 June 2026.
- Enacted on 11 December 2021, New York Cityâs Local Law 144 regulates the use of âautomated employment decision toolsâ (AEDTs) in hiring and promotion decisions. Effective since 5 July 2023, the law imposes three core obligations on employers: they must conduct an annual independent bias audit to assess whether the tool has a disparate impact on candidates based on race, ethnicity, or sex; they must post a summary of the audit results publicly on their websites; and they must provide notice to candidates that an AEDT is being used and of their right to request an alternative screening process.
Texas
- Texas enacted the Texas Responsible AI Governance Act (TRAIGA) on 22 June 2025, establishing foundational duties for state agencies, developers, and deployers of AI systems operating within Texas. The law went into effect on 1 January 2026, and prohibits state agencies from certain uses of social scoring and biometric data. Developers and deployers face prohibitions on the intentional misuse of AI for certain types of behavioural manipulation, unlawful discrimination, deepfakes, and infringement of constitutional rights. TRAIGA provides protections for organisations that follow recognised frameworks, such as the National Institute of Standards and Technology (NIST) AI Risk Management Framework, as well as a 60-day cure period for violations, and the creation of a regulatory sandbox.
Utah
- Utah employed a relatively comprehensive approach to AI oversight by adopting, and making effective, the AI Policy Act (SB149) on 1 May 2024. This legislation requires professionals in regulated occupationsâsuch as law, medicine, and financial servicesâto disclose their use of generative AI tools during high-risk interactions, such as when providing sensitive advice or handling personal data. Additionally, consumers must be informed if they explicitly enquire whether they are interacting with AI.
A handful of other U.S. states have considered and rejected broad AI laws. In addition, numerous other states and localities have enacted specific statutes or municipal ordinances that regulate discrete aspects of AI. The following list includes several such examples:
Maine
- Maine enacted âAn Act to Ensure Transparency in Consumer Transactions Involving Artificial Intelligenceâ (the Maine AI Chatbot Disclosure Act) on 12 June 2025. Effective 23 September 2025, the law establishes targeted disclosure requirements for AIâdriven interactions. It generally prohibits businesses (and other persons) from using an AI chatbotâor similar text or voiceâbased computer technologyâin trade or commerce in a manner that may mislead or deceive a reasonable consumer into believing they are interacting with a human, unless the business provides a clear and conspicuous disclosure that the interaction involves AI.
Maryland
- Maryland enacted HB820 on 20 May 2025, regulating how health insurance plans and related entities may use AI in coverage and treatment decisions made in utilisation management and review decisions. Effective 1 October 2025, the law requires covered entities to ensure that the AI toolâs determinations are grounded in the enrolleeâs individual clinical information, do not replace the role of a healthcare provider, and are applied fairly and equitably without resulting in unfair discrimination.
Pennsylvania
- On 7 July 2025, Pennsylvania enacted Act 35 (formerly SB649) to address the malicious use of AI-generated deepfakes. Effective 5 September 2025, the law establishes criminal penalties for generating (or creating and distributing) a forged digital likeness with intent to defraud or injure, or with knowledge and intent to facilitate fraud or injury by anotherâincluding where the actor knows or reasonably should know the audio or visual at issue is forged.
Illinois
- Illinois enacted HB3773 on 9 August 2024, amending the Illinois Human Rights Act to regulate the use of AI in employment decisions, prohibiting discriminatory practices. Effective 1 January 2026, the law requires employers to provide notice to applicants and workers if they use AI for hiring, discipline, discharge, or other workplace-related purposes.
This continued surge in state legislative activity reflects a wide range of approaches and prioritiesâfrom establishing task forces to study AIâs impact to imposing specific obligations on companies deploying AI systems. This dynamic landscape may underscore the growing value of state-level action in the absence of federal guidance, and organisations are encouraged to closely monitor both enacted laws and pending legislation in the jurisdictions in which they operate.