What Is AI Inference? How AI Produces Outputs
AI inference is the process where a trained AI model generates new outputs by reasoning and making predictions on new...
Here is the paradox at the heart of US AI policy: as of 2026, Congress has passed only one AI-specific federal law, yet state lawmakers have introduced well over a thousand AI-related bills and enacted more than a hundred, according to White & Case. Where the European Union built a single, sweeping AI Act, the United States has done almost the opposite, producing a fast-shifting mix of light-touch federal policy, a growing patchwork of state laws, and an active fight over who gets to regulate at all.
For anyone building, deploying, or working with AI in America, that fragmentation is the whole story. And with about one in five U.S. workers already using AI on the job, according to the Pew Research Center, understanding how AI is governed has become more important than ever. This guide explains how US AI policy actually works: the federal government's deregulatory approach, the state laws where the real rules currently live, the preemption battle between them, and what is changing in 2026. It is written for tech and compliance professionals, and it is general information, not legal advice.
The single most important fact about US AI policy is that there is no single AI law. Instead of one rulebook, you face a moving target: federal policy pulling toward deregulation, states pulling toward their own rules, and courts left to sort out the conflict.
The United States has no broad federal statute governing artificial intelligence. Instead, AI is governed by a combination of existing federal laws, a patchwork of state laws, voluntary frameworks, and a series of executive actions setting policy direction, according to White & Case.
This is the mirror image of the European Union, whose AI Act establishes a single binding, risk-based legal framework across the whole bloc, as provided in the EU Artificial Intelligence Act. The US approach is bottom-up and fragmented rather than top-down and unified, and in the current administration it leans firmly toward promoting innovation over imposing new rules. Understanding US AI policy means understanding three moving parts at once: what the federal government is doing, what the states are doing, and how the two are colliding.
At the federal level, the defining posture is deregulatory. The administration's stated goal is to sustain US leadership in AI through what it repeatedly calls a "minimally burdensome" national approach, and it has pursued this through executive action rather than sweeping new law.
The sequence is worth knowing. On his third day in office in January 2025, the President revoked the previous administration's 2023 AI safety executive order and directed agencies to remove barriers to AI. In July 2025, the administration followed with America's AI Action Plan, a strategy document focused on reducing regulatory friction and accelerating AI development, according to White & Case. In December 2025, The White House issued what became the most consequential action yet: an executive order setting out a national policy framework and targeting state AI laws, which we cover in detail below. In March 2026 the White House followed with legislative recommendations urging Congress to codify a uniform federal standard, and in June 2026 it issued a further order focused on the cybersecurity of advanced AI systems.
Two federal building blocks matter alongside these policy statements. The first AI-specific law Congress has actually passed is the TAKE IT DOWN Act, signed in May 2025. As outlined by Congress.gov, it prohibits the nonconsensual publication of intimate images, including AI-generated deepfakes, and requires online platforms to remove such content within 48 hours of notice, with enforcement against platforms beginning in May 2026. The second is the voluntary AI Risk Management Framework, developed by NIST, which serves as the federal government's primary guidance for responsible AI development without carrying the force of law.
The underlying philosophy tying these together is that existing federal laws are enough to handle AI's risks, so new, AI-specific regulation should be minimal and a fragmented state-by-state approach should be avoided.
Federal AI policy in 2026 is defined less by what Washington has enacted than by what it has chosen not to: no broad AI law, no new AI regulator, and an explicit preference for letting innovation run with light-touch oversight.
Because the federal government has largely declined to regulate AI directly, states have rushed to fill the gap, and this is where the binding rules currently live. SAccording to an analysis by White & Case, state lawmakers introduced well over a thousand AI-related bills in 2025, resulting in dozens of states enacting at least one AI law. A few laws stand out.
Colorado passed the first broad state AI law. The Colorado AI Act requires developers and deployers of "high-risk" AI systems, such as those used in hiring and lending, to use reasonable care to protect people from algorithmic discrimination. According to Colorado Public Radio, after amendment, the law takes effect on June 30, 2026, and is the only state law named directly in the federal executive order targeting state regulation.
California has moved on transparency, with its Transparency in Frontier Artificial Intelligence Act taking effect on January 1, 2026, alongside a separate AI Transparency Act addressing the labeling of AI-generated content according to White & Case.
Texas enacted its Responsible Artificial Intelligence Governance Act, also effective January 1, 2026. Lawmakers substantially narrowed the bill during passage, limiting most obligations to government use of AI. According to White & Case, it still prohibits behavioral manipulation, unlawful discrimination, and generating illegal deepfakes, while offering an affirmative defense to companies that follow the NIST framework
Beyond these, Illinois has amended its civil rights law to bar employers from using AI in discriminatory ways, New York City requires bias audits of automated hiring tools, and many states have passed laws on deepfakes, covering both nonconsensual intimate imagery and election-related synthetic media. States are also applying existing consumer protection, civil rights, and deceptive-practices laws to AI conduct.
The pattern is a growing, uneven patchwork, with the most activity in algorithmic accountability, AI in hiring, transparency, and deepfakes, and meaningful differences from one state to the next.
If you want to know what rules actually bind your AI system in the US today, look to the states, not Washington. That is where the enforceable obligations are, and where they differ depending on where you operate.
The central drama of US AI policy right now is a jurisdictional one: the federal government wants to rein in state AI laws, and the states are resisting.
The federal push escalated sharply with the December 2025 executive order. It directs the Department of Justice to establish an AI Litigation Task Force to challenge state AI laws in court, orders the Commerce Department to identify state laws deemed too burdensome, tasks the Federal Trade Commission with examining when state rules requiring changes to AI outputs might count as deceptive practices, and moves to condition federal funding, including billions in broadband money, on states not enforcing AI laws the administration considers onerous according to The White House. The March 2026 legislative framework then asked Congress to pass a law preempting burdensome state rules outright.
As reported by White & Case, an executive order cannot, by itself, override state law. That legal constraint places a hard limit on this strategy. And Congress has repeatedly refused to supply that preemption. A proposed ten-year moratorium on state AI laws was stripped from a major budget bill when the Senate voted 99 to 1 against it, and a similar effort attached to defense legislation also failed. The federal push faces further questions over the Tenth Amendment, the Dormant Commerce Clause, the legality of conditioning funds on state cooperation, and the limits of FTC and FCC authority.
As White & Case explains, the upshot is clear and important: state AI laws remain fully enforceable for now, and businesses are advised to continue complying with them until the courts or Congress change the picture.
The preemption fight is unresolved, and that uncertainty is itself the current state of US AI policy. Until a court strikes a state law down or Congress passes a preemption statute, the safe assumption is that state rules still bind you.
A frequent misconception is that, without a dedicated AI law, AI is a regulatory free-for-all in the US. It is not. Existing federal laws already reach AI. The Federal Trade Commission Act's ban on unfair and deceptive practices applies to how companies market and deploy AI, civil rights laws such as Title VII apply when AI is used in hiring, and privacy and intellectual property laws apply to how AI systems handle data and content.
The accountability principle behind these laws has real force. According to the American Bar Association, organizations are responsible for what their AI does, a principle underscored internationally when a tribunal held a company liable for false information its chatbot gave a customer. IBM notes that AI can produce confident but incorrect information, making it the responsibility of the people and companies deploying it to catch those errors. In other words, "the AI did it" is not a defense under laws that already exist.
Seeing the US approach next to the EU's clarifies what makes it distinctive. The EU Artificial Intelligence Act establishes a single, binding, risk-based legal framework that imposes obligations according to how risky an AI use is, including transparency duties like labeling AI-generated content. The United States has no such law, favoring a deregulatory federal posture layered over a state patchwork.
That makes the US a deliberate alternative to the EU model, offering other countries a lighter-touch template. Yet the US remains a signatory to the OECD AI Principles, the shared international baseline on trustworthy AI adopted by dozens of governments, even as its federal policy has leaned toward deregulation according to OECD. As the World Economic Forum, Future of Jobs Report 2025 highlights, the US approach prioritizes innovation and flexibility but sacrifices consistency, legal certainty, and the stronger guardrails of a single national law, while demand for responsible AI skills continues to rise.
If you build or use AI in the US, the fragmented picture translates into a few concrete priorities.
As White & Case advises, the absence of a single federal rulebook means organizations should focus on the state AI laws that apply based on where they operate and whose residents they affect, particularly in Colorado, California, and Texas. They should also continue complying with those laws because they remain enforceable for now. Third, remember that existing federal laws already bind you: do not deceive consumers about AI, and do not let AI produce discriminatory outcomes in areas like hiring.
Beyond compliance, treat the NIST AI Risk Management Framework as a sensible voluntary baseline, since it is widely referenced and even serves as an affirmative defense under some state laws according to NIST. Build a flexible compliance program that can adapt as executive orders, court rulings, and possible federal legislation reshape the landscape. And if you also operate in the EU, plan for the stricter EU AI Act, since meeting the higher bar generally covers the lower one.
EU AI Act Compliance Training
Learn how to achieve compliance with the EU AI Act through effective AI governance, risk classification, documentation, monitoring and walk away with a recognized PDF certificate — free with the course. Self-paced, role-ready, and built to make you confident about Ai Act.
Learn More →US AI policy in 2026 is best understood not as a settled framework but as a contest. The federal government is betting on light-touch, innovation-first policy and is actively trying to clear away the state rules it sees as obstacles, while states are legislating quickly to fill the vacuum and defending their authority to do so. For now, the states hold the enforceable rules, existing federal laws still apply, and the courts and Congress will decide how the conflict resolves. For businesses and professionals, the message is to comply with the state laws that bind you, lean on frameworks like NIST, keep humans accountable for AI, and stay nimble, because in the US, AI policy is still very much being written.
Not a broad one. As of 2026, the only AI-specific federal statute Congress has enacted is the TAKE IT DOWN Act, which targets nonconsensual intimate imagery including deepfakes (Source: Congress.gov). There is no single, cross-sector federal AI law; instead, the US relies on existing laws, state laws, voluntary frameworks, and executive actions.
Through a fragmented mix: existing federal laws (such as consumer protection and civil rights law), a growing patchwork of state laws, the voluntary NIST AI Risk Management Framework, and executive orders setting policy direction (Source: White & Case). Unlike the EU, it has no single binding AI law, and federal policy currently leans deregulatory.
It is the first AI-specific federal law, signed in May 2025. It prohibits the nonconsensual online publication of intimate images, including AI-generated deepfakes, and requires online platforms to remove such content within 48 hours of a valid request, with platform enforcement beginning in May 2026 (Source: Congress.gov). It passed with near-unanimous support in Congress.
It is an executive order setting a national AI policy framework and seeking to limit state AI laws, directing the Justice Department to challenge state laws in court, the Commerce Department to identify burdensome ones, and federal agencies to condition certain funding on states not enforcing them (Source: The White House). It reflects the administration's pro-innovation, "minimally burdensome" approach.
Not through an executive order alone. Preemption of state law generally requires an act of Congress or a court ruling, so the December 2025 order cannot by itself invalidate state laws (Source: White & Case). Congress has repeatedly declined to pass preemption, including a moratorium the Senate rejected 99 to 1, so state laws remain enforceable for now.
The most significant include Colorado's AI Act (algorithmic discrimination in high-risk systems, effective June 30, 2026), California's Transparency in Frontier Artificial Intelligence Act and AI Transparency Act (effective January 2026), and Texas's Responsible Artificial Intelligence Governance Act (effective January 2026) (Source: White & Case). Many states have also enacted deepfake and AI-in-hiring rules.
It is the first broad US state AI law. It requires developers and deployers of high-risk AI systems, such as those used in hiring and lending, to use reasonable care to protect consumers from algorithmic discrimination, and after amendment it takes effect on June 30, 2026 (Source: Colorado Public Radio). It is the only state law named directly in the December 2025 federal executive order.
Yes. Even without a dedicated AI law, the FTC Act's ban on deceptive practices, civil rights laws like Title VII, and privacy and intellectual property laws all apply to how AI is built and used. Organizations remain accountable for AI outputs, a principle reinforced when a company was held liable for its chatbot's false information (Source: American Bar Association).
The EU has a single, binding, risk-based AI law with obligations tied to risk levels, including transparency requirements (Source: EU Artificial Intelligence Act). The US has no such law, relying instead on a deregulatory federal posture and a state patchwork. The US model is more flexible and innovation-focused but far less uniform, and firms operating in both markets usually face the EU's stricter rules.
Identify and comply with the state AI laws that apply to you, since they remain enforceable, and follow existing federal laws on deception, discrimination, and privacy. Use the NIST AI Risk Management Framework as a voluntary baseline (Source: NIST), keep humans accountable for AI decisions, and maintain a flexible compliance program that can adapt as federal policy, court rulings, and legislation evolve. If you also operate in the EU, plan for the stricter EU AI Act.
AI inference is the process where a trained AI model generates new outputs by reasoning and making predictions on new...
In August 2026, a story out of Anhui province, China started making the rounds on tech news sites for a...
AI is no longer a side project running in a lab. It is embedded in hiring decisions, credit approvals, medical...