Trump Rules Out US-China AI Joint Venture Over Technology-Sharing Concerns
Trump rejects a U.S.-China AI joint venture over technology-sharing concerns while bilateral AI risk dialogue continues. Here is what it...
Understand AI regulation in the United States in 2026, including federal rules, state AI laws, privacy, discrimination and practical compliance requirements.
Editorial standard: This guide prioritizes primary federal, state, regulator and standards-body sources. It distinguishes enacted law from regulations, executive actions, agency guidance, legislative proposals and voluntary frameworks.
Important: This article provides general educational information and is not legal advice. Whether a requirement applies depends on the organization, AI system, use case, data, sector and jurisdiction.
AI regulation in the United States is not governed by one comprehensive federal AI statute that applies uniformly to every artificial intelligence system. Instead, organizations may face existing federal consumer-protection, civil-rights, employment, financial, healthcare and privacy requirements, targeted federal legislation, state and local AI laws, and sector-specific rules.
For businesses, the central question is therefore not simply, "What is the U.S. AI law?" A more useful question is:
What does this AI system do, what information does it use, who does it affect, where is it deployed, and which legal requirements apply to that activity?
The United States regulates artificial intelligence through multiple legal and regulatory layers.
Existing federal statutes can apply when AI is used in areas such as hiring, lending, housing, healthcare, advertising and consumer services. Federal agencies enforce those laws within their respective authority. States and local governments have added further requirements concerning automated decisions, employment technology, privacy, biometric information, synthetic media, frontier models and other specific AI applications.
Federal AI policy has also changed substantially since 2025. In January 2025, the White House issued Executive Order 14179 on American AI leadership, which established a new federal policy direction and directed development of an AI Action Plan.
The White House subsequently published America's AI Action Plan in July 2025. It sets out federal policy initiatives involving AI innovation, infrastructure and international leadership. The Action Plan is a policy document, not a comprehensive statute regulating all private-sector AI.
In December 2025, Executive Order 14365 on a national AI policy framework directed federal officials to challenge certain state AI laws and prepare legislative recommendations for a more uniform national framework. Those actions influence federal policy, but an executive order does not automatically repeal or invalidate every state AI requirement.
Understanding the distinction between law, regulation, executive policy, guidance and voluntary standards is therefore fundamental to understanding AI regulation in the United States.
Several current and upcoming requirements illustrate why businesses need to track both legal status and compliance dates.
|
Law or requirement |
Legal status |
Key date |
Main relevance |
|
TAKE IT DOWN Act |
Federal law in force |
Platform duties applied from May 19, 2026 |
Non-consensual intimate imagery and certain digital forgeries |
|
California CCPA ADMT regulations |
Regulations effective |
ADMT significant-decision compliance from Jan. 1, 2027 |
Automated decisions, notices and consumer rights |
|
Colorado SB 26-189 |
Enacted |
Major requirements begin Jan. 1, 2027 |
ADMT used in consequential decisions |
|
Texas HB 149 |
Law in force |
Jan. 1, 2026 |
AI disclosures and prohibited uses |
|
NYC Local Law 144 |
Law and rule in force |
Enforcement began July 5, 2023 |
Automated employment decision tools |
|
Illinois Public Act 103-0804 |
Law in force |
Jan. 1, 2026 |
AI use in employment |
The federal TAKE IT DOWN Act became law on May 19, 2025. Covered-platform removal requirements became operative in 2026, and the Federal Trade Commission began enforcing those platform obligations on May 19, 2026. Covered platforms must maintain a process for qualifying removal requests and remove covered material and known identical copies within the statutory timeframe after receiving a valid request.
California's automated decision-making rules have a different timetable. The California Privacy Protection Agency's updated regulations became effective January 1, 2026. However, businesses already using ADMT for significant decisions must comply with the ADMT-specific requirements by January 1, 2027, according to the approved regulatory text. See the final California ADMT regulations.
Colorado changed direction during 2026. SB 26-189 repealed and reenacted the earlier Colorado framework and established revised requirements concerning automated decision-making technology used in consequential decisions.
Texas took another approach. HB 149, the Texas Responsible Artificial Intelligence Governance Act, became effective January 1, 2026 and establishes disclosure requirements for specified AI users together with prohibitions on certain uses of AI.
Understanding AI laws and regulations begins with understanding where legal authority comes from.
Congress creates federal statutes. Some laws directly address specific technology-related harms, while many existing statutes regulate underlying conduct regardless of whether artificial intelligence is involved.
Consumer protection provides a clear example.
The Federal Trade Commission has applied existing law to allegedly deceptive or unfair conduct involving AI. Through Operation AI Comply, the FTC announced enforcement actions involving AI-enabled fake reviews, alleged "AI Lawyer" services and businesses making allegedly deceptive claims about AI-supported earning opportunities.
That does not mean the FTC regulates every artificial intelligence system. Its authority depends on the applicable law and conduct.
Other federal agencies can become relevant according to the use case.
|
Federal authority |
Main AI-related area |
Why it may matter |
|
FTC |
Consumer protection |
Authority over unfair or deceptive practices within its jurisdiction |
|
EEOC |
Employment |
Federal employment-discrimination laws |
|
CFPB |
Credit and financial services |
ECOA, Regulation B and consumer-finance requirements |
|
HUD |
Housing |
Fair Housing Act requirements |
|
HHS |
Healthcare and health information |
HIPAA and other health-sector responsibilities where applicable |
|
DOJ |
Civil rights |
Enforcement within its statutory authority |
|
U.S. Copyright Office |
Copyright |
Copyright registration policy and AI-related legal analysis |
The important principle is simple: using AI does not automatically exempt an organization from laws governing the underlying activity.
State legislation increasingly targets specific AI applications or risks.
Some requirements focus on automated systems used in employment, finance or other consequential decisions. Others address biometric information, privacy, frontier AI, synthetic content, child safety or public-sector use.
Local governments can create an additional regulatory layer. New York City's rules governing automated employment decision tools are an important example. According to New York City Department of Consumer and Worker Protection guidance, Local Law 144 requires certain automated employment decision tools to undergo a bias audit and requires notice to affected candidates or employees. Enforcement began July 5, 2023.
National organizations should therefore examine where applicants, employees, customers and other affected people are located, not simply where the organization is headquartered.
These instruments do not have the same legal status.
|
Instrument |
General meaning |
|
Law |
Binding obligation created through valid legislation |
|
Regulation |
Binding rule issued under legal authority |
|
Executive order |
Presidential directive governing executive-branch action within legal authority |
|
Agency guidance |
Agency explanation or interpretation whose legal effect depends on its basis and context |
|
Framework |
Structured risk-management or governance guidance, commonly voluntary |
|
Standard |
Technical or organizational benchmark that may become binding if incorporated into law, regulation, policy or contract |
The NIST AI Risk Management Framework illustrates the final category. NIST describes the AI RMF as voluntary rather than a generally mandatory compliance law.

Businesses should be able to support claims concerning AI accuracy, capabilities, safety, performance and commercial benefits.
Describing a product as "AI-powered" does not remove ordinary consumer-protection obligations.
The FTC's enforcement activity demonstrates this principle. Operation AI Comply targeted allegedly deceptive or unfair conduct involving AI products, AI-related earnings claims and technology that facilitated fake reviews.
Organizations should therefore examine both what an AI system actually does and how marketing, sales and product teams describe it.
Existing civil-rights laws can apply when automated tools influence employment, housing, credit or other regulated decisions.
In employment, the EEOC's Artificial Intelligence and the ADA resources address how software, algorithms and AI used to evaluate applicants and employees can raise disability-discrimination concerns.
Housing decisions can raise similar issues. HUD guidance on rental applicant screening explains that the Fair Housing Act applies to tenant-screening practices using machine learning and other forms of artificial intelligence.
Credit decisions also remain subject to existing law. The CFPB's guidance on complex algorithms and adverse-action notices states that creditors using complex models must still comply with applicable ECOA and Regulation B requirements to provide specific reasons for adverse actions.
Organizations using AI in decisions affecting people should therefore examine the applicable legal requirements addressing AI bias rather than assuming general ethical principles are sufficient.
AI systems can create privacy issues at multiple points, including collection, prompting, model training, inference, retention, sharing, vendor access and generated outputs.
The United States does not currently have one comprehensive federal AI privacy statute governing every organization. Privacy obligations may instead arise through sector-specific federal law, state privacy legislation, biometric rules, contracts and other applicable requirements.
Healthcare illustrates why context matters. HHS guidance on HIPAA business associates specifically identifies a third-party AI chatbot used on a healthcare provider's patient portal as a potential business associate when its services involve protected health information.
Before personal, confidential or sensitive information enters an AI service, organizations should understand what information is involved, whether the provider can retain or reuse it, whether it contributes to model training and which legal or contractual restrictions apply.
Copyright questions should be divided into at least two separate issues: protection of AI-assisted outputs and use of copyrighted material during AI training.
The U.S. Copyright Office's January 2025 copyrightability report concluded that AI-assisted works may receive copyright protection when sufficient human-authored expressive elements are present. Material whose expressive elements are determined entirely by a machine does not receive copyright protection simply because a person entered prompts.
Questions concerning copyrighted material used to train AI remain more unsettled and fact-specific. The Copyright Office continues to identify generative AI training as a separate policy and legal issue. Its official Copyright and Artificial Intelligence study page lists Part 3 on generative AI training as a pre-publication report.
Businesses should therefore avoid assuming that every AI output is copyrightable or that every use of copyrighted material in training has one settled legal answer.
The TAKE IT DOWN Act addresses specific forms of non-consensual intimate visual material, including qualifying digital forgeries.
The federal statutory text creates criminal prohibitions and platform-related obligations within its defined scope. From May 19, 2026, covered platforms became subject to the removal-process requirements enforced by the FTC.
The Act should not be described as a universal federal ban covering every type of AI-generated deepfake. Its application depends on statutory definitions and the type of content involved.
Federal policy should be distinguished from enforceable private-sector law.
The January 2025 White House AI executive order established a policy aimed at strengthening U.S. AI leadership and directed preparation of an AI Action Plan.
The resulting America's AI Action Plan was released in July 2025. It covers areas including innovation, AI infrastructure and international strategy, but it is not itself a comprehensive statute imposing one set of private-sector requirements.
Federal policy shifted further in December 2025 when Executive Order 14365 directed creation of an AI Litigation Task Force and called for federal action concerning state AI legislation considered inconsistent with national policy.
The important compliance point is that policy direction and legal effect are not the same thing. Organizations should not assume that a federal preference for regulatory uniformity automatically removes existing state requirements.
State AI laws demonstrate several different regulatory approaches.
|
Jurisdiction |
Regulatory approach |
Main area |
Practical issue |
|
California |
Privacy, ADMT and frontier-AI regulation |
Significant decisions and advanced AI development |
Multiple rules may require separate applicability analysis |
|
Colorado |
Consequential-decision regulation |
ADMT |
Developers and deployers may have different duties |
|
Texas |
Broad AI governance statute |
Disclosure and prohibited uses |
Coverage depends on statutory definitions |
|
New York City |
Employment-specific local regulation |
Hiring and promotion tools |
Bias audit and notice requirements |
|
Illinois |
Civil-rights and employment approach |
Employment AI |
Discrimination and notice obligations |
California combines privacy regulation with technology-specific AI legislation.
The California Privacy Protection Agency's ADMT regulations became effective January 1, 2026. The approved regulatory text states that businesses using ADMT to make significant decisions before January 1, 2027 must comply with the ADMT requirements no later than January 1, 2027. Read the approved regulatory text.
California also enacted SB 53, the Transparency in Frontier Artificial Intelligence Act. According to the Governor of California's official SB 53 announcement, the law includes requirements involving frontier-model safety frameworks, specified critical safety incidents and whistleblower protections.
California expanded its framework again in September 2026. The Governor's office states that SB 813 creates a framework for independent verification organizations and AB 1405 creates a state registry and standards for AI auditors. See California's September 2026 AI oversight update.
These measures do not apply identically to every company using AI. Scope must be evaluated law by law.
Businesses should be cautious with older summaries of Colorado AI regulation.
Colorado SB 26-189 repealed and reenacted the earlier framework and introduced revised requirements for automated decision-making technology used in consequential decisions.
The law defines ADMT broadly enough to include technology that processes personal data and generates outputs such as predictions, recommendations, rankings or scores used to make, guide or assist certain decisions.
Key requirements begin January 1, 2027, meaning organizations should distinguish between enacted future obligations and requirements already enforceable today.
Texas HB 149, known as the Texas Responsible Artificial Intelligence Governance Act, became effective January 1, 2026.
The official enrolled-bill summary identifies mandatory disclosure requirements for certain users of AI, including specified governmental agencies and healthcare service providers. It also prohibits defined uses involving issues such as unlawful discrimination, certain biometric practices and impairment of constitutional rights.
The statute does not impose the same obligation on every organization using an AI tool. Applicability depends on the statutory definitions and conduct involved.
New York State and New York City requirements should be analyzed separately.
New York City's Local Law 144 regulates qualifying automated employment decision tools. The NYC Department of Consumer and Worker Protection explains that use of a covered tool requires a bias audit and candidate notice, subject to the law and implementing rules.
Organizations should not describe pending New York State legislation as current statewide private-sector law unless it has actually been enacted.
Illinois added explicit AI provisions to its employment-discrimination framework.
Illinois Public Act 103-0804 became effective January 1, 2026. The law addresses AI used in recruitment, hiring, promotion, discipline and other employment activities where the use subjects employees to discrimination based on protected classes. It also establishes notice requirements for covered employment uses of AI.
Other states regulate AI through privacy, biometric, employment, synthetic-media and consumer-protection laws. Organizations operating nationally should therefore maintain a current jurisdictional map rather than assuming all states follow the same model.
Specific AI compliance requirements depend on the system and applicable law.
The activities below provide a practical governance approach. They are not a claim that every U.S. organization is legally required to implement every control in exactly the same way.
Maintain an inventory of internally developed, purchased, embedded and experimental AI systems.
For each system, record its provider, internal owner, purpose, users, affected people, relevant data, jurisdictions and role in decision-making.
A useful analysis follows this sequence:
AI system → use case → data → affected people → sector → jurisdiction → applicable requirements
This approach is usually more reliable than beginning with a generic list of AI laws.
Review data inputs, sensitive information, retention, secondary use, model training, security and vendor access.
Determine whether applicable laws, contracts or internal commitments impose specific restrictions, assessment requirements, disclosures or safeguards.
Identify whether the system influences employment, credit, housing, healthcare or another decision where civil-rights or anti-discrimination requirements may apply.
Testing should reflect the specific system, affected population and legal context.
Determine what disclosures are required, to whom they must be given and when.
Consumer disclosures, candidate notices, AI-interaction notifications and information concerning automated decisions may apply differently across jurisdictions.
Human review should have a defined purpose.
Organizations should establish who can review an AI-supported decision, what evidence reviewers receive, when escalation occurs and whether an outcome can be reconsidered or overridden.
Simply placing a human somewhere in the workflow does not automatically remove legal risk.
Maintain records appropriate to the technology and applicable requirements, including intended purpose, limitations, assessments, testing, incidents, material changes and vendor information.
Some records may be required by law. Others may serve as evidence of sound governance.
The following matrix provides a practical way to identify areas requiring deeper review.
|
Question about the AI system |
Why it matters |
|
Does it influence hiring, promotion or employment? |
Federal employment law and state or local employment-AI requirements may apply |
|
Does it affect lending or credit? |
ECOA, Regulation B and consumer-finance requirements may become relevant |
|
Does it affect access to housing? |
Fair Housing Act requirements may apply |
|
Does it process PHI for a covered healthcare entity? |
HIPAA and business-associate analysis may be required |
|
Does it make or assist a consequential decision? |
State ADMT or consequential-decision laws may apply |
|
Does it process sensitive personal information? |
Privacy, biometric or sector-specific rules may become relevant |
|
Does it generate or host intimate synthetic imagery? |
TAKE IT DOWN Act and state synthetic-media laws may need review |
|
Are affected individuals located in multiple states? |
Multiple jurisdictions may need to be mapped |
|
Does a third-party AI provider process organizational data? |
Vendor contracts, data use and documentation need assessment |
|
Has the AI system's purpose materially changed? |
A previously low-risk system may move into a regulated use case |
A "yes" does not establish that a law has been violated or necessarily applies. It indicates where additional legal and compliance analysis may be appropriate.
Professionals responsible for AI governance, compliance, privacy, HR, risk and technology oversight need to distinguish enforceable requirements from recommendations and voluntary frameworks.
AI Law & Regulation Essentials Training provides structured education on AI law, regulation, governance and compliance concepts.
Training can strengthen regulatory literacy. It does not replace organization-specific legal advice or make an organization automatically compliant.
|
AI use case |
Principal issues to consider |
|
Hiring and employment |
Employment discrimination, disability accommodation, candidate notices and local AEDT requirements |
|
Lending |
ECOA, Regulation B, adverse-action explanations, privacy and model governance |
|
Healthcare |
HIPAA where applicable, sensitive information and vendor arrangements |
|
Housing |
Fair Housing Act, tenant screening and advertising |
|
Marketing |
Consumer protection, claim substantiation, endorsements and privacy |
|
Customer service |
Privacy, consumer protection and disclosure requirements |
|
Generative AI |
Copyright, confidential information, privacy and output reliability |
|
Content platforms |
TAKE IT DOWN Act where applicable and state synthetic-media requirements |
|
Public-sector AI |
Government procurement, assessment and agency-specific requirements |
The issues listed above do not automatically apply to every deployment in each category.
The NIST AI RMF provides organizations with a structured approach to identifying and managing AI risk.
Its core consists of four functions:
Govern, Map, Measure and Manage.
The NIST AI RMF Core explains that these functions support governance, contextual understanding of risks, evaluation of AI systems and ongoing risk management.
Generally, no.
NIST states that the AI Risk Management Framework is intended for voluntary use. Its companion AI RMF Playbook is also voluntary and provides suggested actions rather than a mandatory legal checklist.
A voluntary framework can nevertheless become relevant when incorporated into a contract, procurement requirement, internal organizational policy or another binding obligation.
A law or applicable regulation creates binding legal obligations within its scope.
A framework provides a structure for managing risk.
Using NIST AI RMF can therefore support governance, but adopting it does not automatically establish compliance with every applicable federal, state or sector-specific law.

Identify AI systems that are developed, purchased, embedded in software or used experimentally within the organization.
Determine whether the technology supports ordinary productivity or influences decisions concerning employment, credit, housing, healthcare, eligibility or other significant outcomes.
Connect each deployment with relevant federal statutes, sector requirements, state laws and local rules.
Evaluate privacy, security, discrimination and other risks appropriate to the system.
Testing may include performance, reliability or fairness analysis depending on the use case and applicable requirements.
Implement legally required notices and establish meaningful review or escalation mechanisms.
Understand data handling, model changes, documentation, contractual protections and responsibility allocation.
Record assessments, approvals, testing, limitations, exceptions, incidents and significant system changes.
Monitor system performance together with legislative, regulatory and enforcement developments.
Review the analysis when the model, data, vendor, intended purpose, affected population or jurisdiction changes materially.
This sequence is a practical AI compliance and governance approach, not a universal ten-step legal mandate imposed on every organization.
One of the most significant mistakes is assuming that because the United States lacks one comprehensive federal AI statute, artificial intelligence is largely unregulated.
Existing law can still apply.
Another mistake is treating voluntary governance frameworks as if they were binding law. NIST AI RMF can support risk management, but it is not generally a mandatory U.S. AI statute.
Organizations can also create avoidable risk by overlooking state and local rules, failing to identify AI embedded in third-party software, using sensitive information without appropriate assessment, making unsupported AI-performance claims, relying on ineffective human review or failing to document significant AI-system changes.
Regulatory status is also important. A proposed bill is not enacted law. An enacted law may have a future compliance date. An executive-policy preference does not automatically repeal existing state requirements.
Colorado's 2026 legislation is a clear example of why regulatory summaries require continuing review. Colorado SB 26-189 substantially changed the state's earlier AI framework.
AI compliance should be treated as an ongoing process.
A regulatory tracker can record:
jurisdiction and authority;
legal instrument;
current status;
enactment date;
effective or compliance date;
covered AI activity;
important exemptions;
responsible internal owner;
date last verified.
Primary government and regulator sources should be prioritized when determining whether legislation has actually been enacted or an obligation has changed.
Organizations should also reassess systems when their use evolves.
A general productivity assistant, for example, may present a different legal profile if it later begins ranking job applicants, determining customer eligibility, analyzing medical information or influencing credit decisions.
Vendor updates, new datasets, integrations and material changes in system purpose can all justify renewed compliance analysis.
AI regulation in the United States is a multi-layered legal environment rather than a single national AI rulebook.
Existing federal laws can apply to AI used in consumer services, employment, finance, housing, healthcare and other regulated activities. Targeted legislation such as the TAKE IT DOWN Act creates additional obligations in defined areas, while states and local governments continue adopting separate AI rules.
Federal policy is also evolving. Executive actions since 2025 indicate a preference for stronger national coordination, but policy direction should not be confused with legislation already enacted by Congress or with the current legal status of state requirements.
For organizations, compliance begins with the facts of the deployment:
AI system → purpose → data → affected people → sector → jurisdiction → applicable law
Strong AI governance therefore depends on knowing where AI is used, distinguishing binding obligations from voluntary practices, documenting significant decisions, managing third-party dependencies and monitoring regulatory change.
Professionals responsible for AI governance, legal risk, privacy or compliance can strengthen their understanding through AI Law & Regulation Essentials Training.
Training can support professional understanding of AI law and regulation, but it does not replace qualified legal advice or guarantee organizational compliance.
No comprehensive federal statute currently governs every artificial intelligence system across all industries. U.S. AI regulation instead combines existing federal statutes, targeted legislation, agency enforcement, state and local laws, and federal policy actions.
The answer depends on the use case. Relevant requirements may involve consumer protection, civil rights, employment, credit, housing, healthcare, privacy, copyright, synthetic media and state automated-decision laws.
There is no single general-purpose federal AI regulator. Depending on the activity, the FTC, EEOC, CFPB, HUD, HHS, DOJ and other authorities may regulate AI-related conduct under existing law.
Typical activities include identifying AI systems, determining applicable law, assessing privacy and discrimination risk, implementing required notices, documenting controls, managing vendors and monitoring changes. Specific legal duties depend on the use case and jurisdiction.
Privacy requirements can affect information collected, entered, inferred, stored, shared or reused through AI. Applicability depends on the organization, sector, data, purpose and jurisdiction.
Federal employment, credit, housing, disability and other civil-rights laws can apply to AI-supported decisions. State and local laws may add additional audits, notices or review requirements.
They can. Applicability depends on each statute's coverage and jurisdictional provisions. A company's headquarters location alone does not determine whether another state's requirements apply.
Generally, no. NIST describes AI RMF as voluntary. It can become relevant through contracts, procurement requirements, internal policies or other binding arrangements.
Federal employment-discrimination laws remain applicable. New York City's Local Law 144 regulates certain automated employment decision tools, while Illinois law now expressly addresses specified employment uses of AI.
Organizations should understand the AI system's purpose, provider, data, affected individuals, jurisdictions, limitations and decision-making role before determining which legal and governance controls are appropriate.
Monitor authoritative federal, state and local sources, maintain a regulatory tracker, record future compliance dates and reassess both vendors and systems after significant changes.
No. Training can help professionals understand regulatory concepts and recognize issues that require specialist review. It does not replace legal advice tailored to a specific organization.
Trump rejects a U.S.-China AI joint venture over technology-sharing concerns while bilateral AI risk dialogue continues. Here is what it...
AI Law
Compare AI laws around the world in 2026, including binding laws, proposed rules, regulatory frameworks, effective dates and business implications...
OpenAI shelved GPT-6.1 Astra after safety tests flagged scope, authorization and action-reporting issues. See what is confirmed and what remains...