AI Regulation in the United States: Laws, Rules & Compliance Requirements

Understand AI regulation in the United States in 2026, including federal rules, state AI laws, privacy, discrimination and practical compliance requirements.

  • Sep 30, 2026
  • 20 min read
AI regulation in the United States illustrated with a U.S. map, AI governance framework, legal documents, regulatory layers, risk controls, compliance checks, documentation, and monitoring indicators.

Editorial standard: This guide prioritizes primary federal, state, regulator and standards-body sources. It distinguishes enacted law from regulations, executive actions, agency guidance, legislative proposals and voluntary frameworks.

 

Important: This article provides general educational information and is not legal advice. Whether a requirement applies depends on the organization, AI system, use case, data, sector and jurisdiction.

 

AI regulation in the United States is not governed by one comprehensive federal AI statute that applies uniformly to every artificial intelligence system. Instead, organizations may face existing federal consumer-protection, civil-rights, employment, financial, healthcare and privacy requirements, targeted federal legislation, state and local AI laws, and sector-specific rules.

 

For businesses, the central question is therefore not simply, "What is the U.S. AI law?" A more useful question is:

 

What does this AI system do, what information does it use, who does it affect, where is it deployed, and which legal requirements apply to that activity?

Introduction

The United States regulates artificial intelligence through multiple legal and regulatory layers.

 

Existing federal statutes can apply when AI is used in areas such as hiring, lending, housing, healthcare, advertising and consumer services. Federal agencies enforce those laws within their respective authority. States and local governments have added further requirements concerning automated decisions, employment technology, privacy, biometric information, synthetic media, frontier models and other specific AI applications.

 

Federal AI policy has also changed substantially since 2025. In January 2025, the White House issued Executive Order 14179 on American AI leadership, which established a new federal policy direction and directed development of an AI Action Plan.

 

The White House subsequently published America's AI Action Plan in July 2025. It sets out federal policy initiatives involving AI innovation, infrastructure and international leadership. The Action Plan is a policy document, not a comprehensive statute regulating all private-sector AI.

 

In December 2025, Executive Order 14365 on a national AI policy framework directed federal officials to challenge certain state AI laws and prepare legislative recommendations for a more uniform national framework. Those actions influence federal policy, but an executive order does not automatically repeal or invalidate every state AI requirement.

 

Understanding the distinction between law, regulation, executive policy, guidance and voluntary standards is therefore fundamental to understanding AI regulation in the United States.

U.S. AI Regulation at a Glance

Several current and upcoming requirements illustrate why businesses need to track both legal status and compliance dates.

Law or requirement

Legal status

Key date

Main relevance

TAKE IT DOWN Act

Federal law in force

Platform duties applied from May 19, 2026

Non-consensual intimate imagery and certain digital forgeries

California CCPA ADMT regulations

Regulations effective

ADMT significant-decision compliance from Jan. 1, 2027

Automated decisions, notices and consumer rights

Colorado SB 26-189

Enacted

Major requirements begin Jan. 1, 2027

ADMT used in consequential decisions

Texas HB 149

Law in force

Jan. 1, 2026

AI disclosures and prohibited uses

NYC Local Law 144

Law and rule in force

Enforcement began July 5, 2023

Automated employment decision tools

Illinois Public Act 103-0804

Law in force

Jan. 1, 2026

AI use in employment

The federal TAKE IT DOWN Act became law on May 19, 2025. Covered-platform removal requirements became operative in 2026, and the Federal Trade Commission began enforcing those platform obligations on May 19, 2026. Covered platforms must maintain a process for qualifying removal requests and remove covered material and known identical copies within the statutory timeframe after receiving a valid request.

 

California's automated decision-making rules have a different timetable. The California Privacy Protection Agency's updated regulations became effective January 1, 2026. However, businesses already using ADMT for significant decisions must comply with the ADMT-specific requirements by January 1, 2027, according to the approved regulatory text. See the final California ADMT regulations.

 

Colorado changed direction during 2026. SB 26-189 repealed and reenacted the earlier Colorado framework and established revised requirements concerning automated decision-making technology used in consequential decisions.

 

Texas took another approach. HB 149, the Texas Responsible Artificial Intelligence Governance Act, became effective January 1, 2026 and establishes disclosure requirements for specified AI users together with prohibitions on certain uses of AI.

How AI Regulation Works in the United States

Understanding AI laws and regulations begins with understanding where legal authority comes from.

Federal laws and agency enforcement

Congress creates federal statutes. Some laws directly address specific technology-related harms, while many existing statutes regulate underlying conduct regardless of whether artificial intelligence is involved.

 

Consumer protection provides a clear example.

 

The Federal Trade Commission has applied existing law to allegedly deceptive or unfair conduct involving AI. Through Operation AI Comply, the FTC announced enforcement actions involving AI-enabled fake reviews, alleged "AI Lawyer" services and businesses making allegedly deceptive claims about AI-supported earning opportunities.

 

That does not mean the FTC regulates every artificial intelligence system. Its authority depends on the applicable law and conduct.

 

Other federal agencies can become relevant according to the use case.

Federal authority

Main AI-related area

Why it may matter

FTC

Consumer protection

Authority over unfair or deceptive practices within its jurisdiction

EEOC

Employment

Federal employment-discrimination laws

CFPB

Credit and financial services

ECOA, Regulation B and consumer-finance requirements

HUD

Housing

Fair Housing Act requirements

HHS

Healthcare and health information

HIPAA and other health-sector responsibilities where applicable

DOJ

Civil rights

Enforcement within its statutory authority

U.S. Copyright Office

Copyright

Copyright registration policy and AI-related legal analysis

The important principle is simple: using AI does not automatically exempt an organization from laws governing the underlying activity.

State and local AI laws

State legislation increasingly targets specific AI applications or risks.

 

Some requirements focus on automated systems used in employment, finance or other consequential decisions. Others address biometric information, privacy, frontier AI, synthetic content, child safety or public-sector use.

 

Local governments can create an additional regulatory layer. New York City's rules governing automated employment decision tools are an important example. According to New York City Department of Consumer and Worker Protection guidance, Local Law 144 requires certain automated employment decision tools to undergo a bias audit and requires notice to affected candidates or employees. Enforcement began July 5, 2023.

 

National organizations should therefore examine where applicants, employees, customers and other affected people are located, not simply where the organization is headquartered.

Executive orders, guidance and voluntary frameworks

These instruments do not have the same legal status.

Instrument

General meaning

Law

Binding obligation created through valid legislation

Regulation

Binding rule issued under legal authority

Executive order

Presidential directive governing executive-branch action within legal authority

Agency guidance

Agency explanation or interpretation whose legal effect depends on its basis and context

Framework

Structured risk-management or governance guidance, commonly voluntary

Standard

Technical or organizational benchmark that may become binding if incorporated into law, regulation, policy or contract

The NIST AI Risk Management Framework illustrates the final category. NIST describes the AI RMF as voluntary rather than a generally mandatory compliance law.

Federal AI Laws and Rules Businesses Need to Understand

Infographic titled Federal AI Laws and Rules Businesses Need to Understand, outlining 5 key compliance areas: Consumer, Civil Rights, Privacy, Copyright, and Deepfakes.

Consumer protection and deceptive AI practices

Businesses should be able to support claims concerning AI accuracy, capabilities, safety, performance and commercial benefits.

 

Describing a product as "AI-powered" does not remove ordinary consumer-protection obligations.

 

The FTC's enforcement activity demonstrates this principle. Operation AI Comply targeted allegedly deceptive or unfair conduct involving AI products, AI-related earnings claims and technology that facilitated fake reviews.

 

Organizations should therefore examine both what an AI system actually does and how marketing, sales and product teams describe it.

Civil rights and AI discrimination

Existing civil-rights laws can apply when automated tools influence employment, housing, credit or other regulated decisions.

 

In employment, the EEOC's Artificial Intelligence and the ADA resources address how software, algorithms and AI used to evaluate applicants and employees can raise disability-discrimination concerns.

 

Housing decisions can raise similar issues. HUD guidance on rental applicant screening explains that the Fair Housing Act applies to tenant-screening practices using machine learning and other forms of artificial intelligence.

 

Credit decisions also remain subject to existing law. The CFPB's guidance on complex algorithms and adverse-action notices states that creditors using complex models must still comply with applicable ECOA and Regulation B requirements to provide specific reasons for adverse actions.

 

Organizations using AI in decisions affecting people should therefore examine the applicable legal requirements addressing AI bias rather than assuming general ethical principles are sufficient.

Privacy and data protection requirements

AI systems can create privacy issues at multiple points, including collection, prompting, model training, inference, retention, sharing, vendor access and generated outputs.

 

The United States does not currently have one comprehensive federal AI privacy statute governing every organization. Privacy obligations may instead arise through sector-specific federal law, state privacy legislation, biometric rules, contracts and other applicable requirements.

 

Healthcare illustrates why context matters. HHS guidance on HIPAA business associates specifically identifies a third-party AI chatbot used on a healthcare provider's patient portal as a potential business associate when its services involve protected health information.

 

Before personal, confidential or sensitive information enters an AI service, organizations should understand what information is involved, whether the provider can retain or reuse it, whether it contributes to model training and which legal or contractual restrictions apply.

Copyright and intellectual property

Copyright questions should be divided into at least two separate issues: protection of AI-assisted outputs and use of copyrighted material during AI training.

 

The U.S. Copyright Office's January 2025 copyrightability report concluded that AI-assisted works may receive copyright protection when sufficient human-authored expressive elements are present. Material whose expressive elements are determined entirely by a machine does not receive copyright protection simply because a person entered prompts.

 

Questions concerning copyrighted material used to train AI remain more unsettled and fact-specific. The Copyright Office continues to identify generative AI training as a separate policy and legal issue. Its official Copyright and Artificial Intelligence study page lists Part 3 on generative AI training as a pre-publication report.

 

Businesses should therefore avoid assuming that every AI output is copyrightable or that every use of copyrighted material in training has one settled legal answer.

AI-generated deepfakes and non-consensual intimate imagery

The TAKE IT DOWN Act addresses specific forms of non-consensual intimate visual material, including qualifying digital forgeries.

 

The federal statutory text creates criminal prohibitions and platform-related obligations within its defined scope. From May 19, 2026, covered platforms became subject to the removal-process requirements enforced by the FTC.

 

The Act should not be described as a universal federal ban covering every type of AI-generated deepfake. Its application depends on statutory definitions and the type of content involved.

Federal AI Policy and the Changing U.S. Regulatory Direction

Federal policy should be distinguished from enforceable private-sector law.

 

The January 2025 White House AI executive order established a policy aimed at strengthening U.S. AI leadership and directed preparation of an AI Action Plan.

 

The resulting America's AI Action Plan was released in July 2025. It covers areas including innovation, AI infrastructure and international strategy, but it is not itself a comprehensive statute imposing one set of private-sector requirements.

 

Federal policy shifted further in December 2025 when Executive Order 14365 directed creation of an AI Litigation Task Force and called for federal action concerning state AI legislation considered inconsistent with national policy.

 

The important compliance point is that policy direction and legal effect are not the same thing. Organizations should not assume that a federal preference for regulatory uniformity automatically removes existing state requirements.

State AI Laws and Regulations Businesses Should Know

State AI laws demonstrate several different regulatory approaches.

Jurisdiction

Regulatory approach

Main area

Practical issue

California

Privacy, ADMT and frontier-AI regulation

Significant decisions and advanced AI development

Multiple rules may require separate applicability analysis

Colorado

Consequential-decision regulation

ADMT

Developers and deployers may have different duties

Texas

Broad AI governance statute

Disclosure and prohibited uses

Coverage depends on statutory definitions

New York City

Employment-specific local regulation

Hiring and promotion tools

Bias audit and notice requirements

Illinois

Civil-rights and employment approach

Employment AI

Discrimination and notice obligations

California

California combines privacy regulation with technology-specific AI legislation.

 

The California Privacy Protection Agency's ADMT regulations became effective January 1, 2026. The approved regulatory text states that businesses using ADMT to make significant decisions before January 1, 2027 must comply with the ADMT requirements no later than January 1, 2027. Read the approved regulatory text.

 

California also enacted SB 53, the Transparency in Frontier Artificial Intelligence Act. According to the Governor of California's official SB 53 announcement, the law includes requirements involving frontier-model safety frameworks, specified critical safety incidents and whistleblower protections.

 

California expanded its framework again in September 2026. The Governor's office states that SB 813 creates a framework for independent verification organizations and AB 1405 creates a state registry and standards for AI auditors. See California's September 2026 AI oversight update.

 

These measures do not apply identically to every company using AI. Scope must be evaluated law by law.

Colorado

Businesses should be cautious with older summaries of Colorado AI regulation.

 

Colorado SB 26-189 repealed and reenacted the earlier framework and introduced revised requirements for automated decision-making technology used in consequential decisions.

 

The law defines ADMT broadly enough to include technology that processes personal data and generates outputs such as predictions, recommendations, rankings or scores used to make, guide or assist certain decisions.

 

Key requirements begin January 1, 2027, meaning organizations should distinguish between enacted future obligations and requirements already enforceable today.

Texas

Texas HB 149, known as the Texas Responsible Artificial Intelligence Governance Act, became effective January 1, 2026.

 

The official enrolled-bill summary identifies mandatory disclosure requirements for certain users of AI, including specified governmental agencies and healthcare service providers. It also prohibits defined uses involving issues such as unlawful discrimination, certain biometric practices and impairment of constitutional rights.

 

The statute does not impose the same obligation on every organization using an AI tool. Applicability depends on the statutory definitions and conduct involved.

New York and New York City

New York State and New York City requirements should be analyzed separately.

 

New York City's Local Law 144 regulates qualifying automated employment decision tools. The NYC Department of Consumer and Worker Protection explains that use of a covered tool requires a bias audit and candidate notice, subject to the law and implementing rules.

 

Organizations should not describe pending New York State legislation as current statewide private-sector law unless it has actually been enacted.

Illinois

Illinois added explicit AI provisions to its employment-discrimination framework.

 

Illinois Public Act 103-0804 became effective January 1, 2026. The law addresses AI used in recruitment, hiring, promotion, discipline and other employment activities where the use subjects employees to discrimination based on protected classes. It also establishes notice requirements for covered employment uses of AI.

 

Other states regulate AI through privacy, biometric, employment, synthetic-media and consumer-protection laws. Organizations operating nationally should therefore maintain a current jurisdictional map rather than assuming all states follow the same model.

What Are the Main AI Compliance Requirements for Businesses?

Specific AI compliance requirements depend on the system and applicable law.

 

The activities below provide a practical governance approach. They are not a claim that every U.S. organization is legally required to implement every control in exactly the same way.

Identify and inventory AI systems

Maintain an inventory of internally developed, purchased, embedded and experimental AI systems.

 

For each system, record its provider, internal owner, purpose, users, affected people, relevant data, jurisdictions and role in decision-making.

Determine which laws apply

A useful analysis follows this sequence:

 

AI system → use case → data → affected people → sector → jurisdiction → applicable requirements

 

This approach is usually more reliable than beginning with a generic list of AI laws.

Assess privacy and data obligations

Review data inputs, sensitive information, retention, secondary use, model training, security and vendor access.

 

Determine whether applicable laws, contracts or internal commitments impose specific restrictions, assessment requirements, disclosures or safeguards.

Assess discrimination risks

Identify whether the system influences employment, credit, housing, healthcare or another decision where civil-rights or anti-discrimination requirements may apply.

 

Testing should reflect the specific system, affected population and legal context.

Establish transparency controls

Determine what disclosures are required, to whom they must be given and when.

 

Consumer disclosures, candidate notices, AI-interaction notifications and information concerning automated decisions may apply differently across jurisdictions.

Establish meaningful human oversight

Human review should have a defined purpose.

 

Organizations should establish who can review an AI-supported decision, what evidence reviewers receive, when escalation occurs and whether an outcome can be reconsidered or overridden.

 

Simply placing a human somewhere in the workflow does not automatically remove legal risk.

Document and monitor AI systems

Maintain records appropriate to the technology and applicable requirements, including intended purpose, limitations, assessments, testing, incidents, material changes and vendor information.

 

Some records may be required by law. Others may serve as evidence of sound governance.

AI Regulatory Applicability Matrix

The following matrix provides a practical way to identify areas requiring deeper review.

Question about the AI system

Why it matters

Does it influence hiring, promotion or employment?

Federal employment law and state or local employment-AI requirements may apply

Does it affect lending or credit?

ECOA, Regulation B and consumer-finance requirements may become relevant

Does it affect access to housing?

Fair Housing Act requirements may apply

Does it process PHI for a covered healthcare entity?

HIPAA and business-associate analysis may be required

Does it make or assist a consequential decision?

State ADMT or consequential-decision laws may apply

Does it process sensitive personal information?

Privacy, biometric or sector-specific rules may become relevant

Does it generate or host intimate synthetic imagery?

TAKE IT DOWN Act and state synthetic-media laws may need review

Are affected individuals located in multiple states?

Multiple jurisdictions may need to be mapped

Does a third-party AI provider process organizational data?

Vendor contracts, data use and documentation need assessment

Has the AI system's purpose materially changed?

A previously low-risk system may move into a regulated use case

A "yes" does not establish that a law has been violated or necessarily applies. It indicates where additional legal and compliance analysis may be appropriate.

Build stronger regulatory understanding

Professionals responsible for AI governance, compliance, privacy, HR, risk and technology oversight need to distinguish enforceable requirements from recommendations and voluntary frameworks.

 

AI Law & Regulation Essentials Training provides structured education on AI law, regulation, governance and compliance concepts.

 

Training can strengthen regulatory literacy. It does not replace organization-specific legal advice or make an organization automatically compliant.

AI Compliance Requirements by Use Case

AI use case

Principal issues to consider

Hiring and employment

Employment discrimination, disability accommodation, candidate notices and local AEDT requirements

Lending

ECOA, Regulation B, adverse-action explanations, privacy and model governance

Healthcare

HIPAA where applicable, sensitive information and vendor arrangements

Housing

Fair Housing Act, tenant screening and advertising

Marketing

Consumer protection, claim substantiation, endorsements and privacy

Customer service

Privacy, consumer protection and disclosure requirements

Generative AI

Copyright, confidential information, privacy and output reliability

Content platforms

TAKE IT DOWN Act where applicable and state synthetic-media requirements

Public-sector AI

Government procurement, assessment and agency-specific requirements

The issues listed above do not automatically apply to every deployment in each category.

NIST AI RMF and Other AI Governance Frameworks

What the NIST AI Risk Management Framework does

The NIST AI RMF provides organizations with a structured approach to identifying and managing AI risk.

 

Its core consists of four functions:

 

Govern, Map, Measure and Manage.

 

The NIST AI RMF Core explains that these functions support governance, contextual understanding of risks, evaluation of AI systems and ongoing risk management.

Is NIST AI RMF legally required?

Generally, no.

 

NIST states that the AI Risk Management Framework is intended for voluntary use. Its companion AI RMF Playbook is also voluntary and provides suggested actions rather than a mandatory legal checklist.

 

A voluntary framework can nevertheless become relevant when incorporated into a contract, procurement requirement, internal organizational policy or another binding obligation.

Frameworks versus laws

A law or applicable regulation creates binding legal obligations within its scope.

 

A framework provides a structure for managing risk.

 

Using NIST AI RMF can therefore support governance, but adopting it does not automatically establish compliance with every applicable federal, state or sector-specific law.

How to Build a U.S. AI Compliance Program

Infographic titled "How to Build a U.S. AI Compliance Program" outlining a 10-step process: 01 Inventory, 02 Classify, 03 Map, 04 Assess, 05 Test, 06 Oversee, 07 Vendors, 08 Document, 09 Monitor, and 10 Reassess.

Step 1: Create an AI inventory

Identify AI systems that are developed, purchased, embedded in software or used experimentally within the organization.

Step 2: Classify AI use cases

Determine whether the technology supports ordinary productivity or influences decisions concerning employment, credit, housing, healthcare, eligibility or other significant outcomes.

Step 3: Map applicable laws and jurisdictions

Connect each deployment with relevant federal statutes, sector requirements, state laws and local rules.

Step 4: Perform relevant assessments

Evaluate privacy, security, discrimination and other risks appropriate to the system.

Step 5: Test material risks

Testing may include performance, reliability or fairness analysis depending on the use case and applicable requirements.

Step 6: Establish transparency and oversight

Implement legally required notices and establish meaningful review or escalation mechanisms.

Step 7: Manage AI vendors

Understand data handling, model changes, documentation, contractual protections and responsibility allocation.

Step 8: Document controls and decisions

Record assessments, approvals, testing, limitations, exceptions, incidents and significant system changes.

Step 9: Monitor systems and regulatory changes

Monitor system performance together with legislative, regulatory and enforcement developments.

Step 10: Reassess periodically

Review the analysis when the model, data, vendor, intended purpose, affected population or jurisdiction changes materially.

 

This sequence is a practical AI compliance and governance approach, not a universal ten-step legal mandate imposed on every organization.

Common AI Compliance Mistakes to Avoid

One of the most significant mistakes is assuming that because the United States lacks one comprehensive federal AI statute, artificial intelligence is largely unregulated.

 

Existing law can still apply.

 

Another mistake is treating voluntary governance frameworks as if they were binding law. NIST AI RMF can support risk management, but it is not generally a mandatory U.S. AI statute.

 

Organizations can also create avoidable risk by overlooking state and local rules, failing to identify AI embedded in third-party software, using sensitive information without appropriate assessment, making unsupported AI-performance claims, relying on ineffective human review or failing to document significant AI-system changes.

 

Regulatory status is also important. A proposed bill is not enacted law. An enacted law may have a future compliance date. An executive-policy preference does not automatically repeal existing state requirements.

 

Colorado's 2026 legislation is a clear example of why regulatory summaries require continuing review. Colorado SB 26-189 substantially changed the state's earlier AI framework.

How to Keep Up With U.S. AI Regulatory Changes

AI compliance should be treated as an ongoing process.

 

A regulatory tracker can record:

  • jurisdiction and authority;

  • legal instrument;

  • current status;

  • enactment date;

  • effective or compliance date;

  • covered AI activity;

  • important exemptions;

  • responsible internal owner;

  • date last verified.

 

Primary government and regulator sources should be prioritized when determining whether legislation has actually been enacted or an obligation has changed.

 

Organizations should also reassess systems when their use evolves.

 

A general productivity assistant, for example, may present a different legal profile if it later begins ranking job applicants, determining customer eligibility, analyzing medical information or influencing credit decisions.

 

Vendor updates, new datasets, integrations and material changes in system purpose can all justify renewed compliance analysis.

Conclusion

AI regulation in the United States is a multi-layered legal environment rather than a single national AI rulebook.

 

Existing federal laws can apply to AI used in consumer services, employment, finance, housing, healthcare and other regulated activities. Targeted legislation such as the TAKE IT DOWN Act creates additional obligations in defined areas, while states and local governments continue adopting separate AI rules.

 

Federal policy is also evolving. Executive actions since 2025 indicate a preference for stronger national coordination, but policy direction should not be confused with legislation already enacted by Congress or with the current legal status of state requirements.

 

For organizations, compliance begins with the facts of the deployment:

 

AI system → purpose → data → affected people → sector → jurisdiction → applicable law

 

Strong AI governance therefore depends on knowing where AI is used, distinguishing binding obligations from voluntary practices, documenting significant decisions, managing third-party dependencies and monitoring regulatory change.

 

Professionals responsible for AI governance, legal risk, privacy or compliance can strengthen their understanding through AI Law & Regulation Essentials Training.

 

Training can support professional understanding of AI law and regulation, but it does not replace qualified legal advice or guarantee organizational compliance.

Frequently Asked Questions

No comprehensive federal statute currently governs every artificial intelligence system across all industries. U.S. AI regulation instead combines existing federal statutes, targeted legislation, agency enforcement, state and local laws, and federal policy actions.

The answer depends on the use case. Relevant requirements may involve consumer protection, civil rights, employment, credit, housing, healthcare, privacy, copyright, synthetic media and state automated-decision laws.

There is no single general-purpose federal AI regulator. Depending on the activity, the FTC, EEOC, CFPB, HUD, HHS, DOJ and other authorities may regulate AI-related conduct under existing law.

Typical activities include identifying AI systems, determining applicable law, assessing privacy and discrimination risk, implementing required notices, documenting controls, managing vendors and monitoring changes. Specific legal duties depend on the use case and jurisdiction.

Privacy requirements can affect information collected, entered, inferred, stored, shared or reused through AI. Applicability depends on the organization, sector, data, purpose and jurisdiction.

Federal employment, credit, housing, disability and other civil-rights laws can apply to AI-supported decisions. State and local laws may add additional audits, notices or review requirements.

They can. Applicability depends on each statute's coverage and jurisdictional provisions. A company's headquarters location alone does not determine whether another state's requirements apply.

Generally, no. NIST describes AI RMF as voluntary. It can become relevant through contracts, procurement requirements, internal policies or other binding arrangements.

Federal employment-discrimination laws remain applicable. New York City's Local Law 144 regulates certain automated employment decision tools, while Illinois law now expressly addresses specified employment uses of AI.

Organizations should understand the AI system's purpose, provider, data, affected individuals, jurisdictions, limitations and decision-making role before determining which legal and governance controls are appropriate.

Monitor authoritative federal, state and local sources, maintain a regulatory tracker, record future compliance dates and reassess both vendors and systems after significant changes.

No. Training can help professionals understand regulatory concepts and recognize issues that require specialist review. It does not replace legal advice tailored to a specific organization.