US AI Policy Explained: How the US Regulates AI in 2026

  • Aug 18, 2026
  • 11 min read
US AI regulation in 2026 showing federal oversight, state legislation and sector-specific artificial intelligence rules.

Here is the paradox at the heart of US AI policy: as of 2026, Congress has passed only one AI-specific federal law, yet state lawmakers have introduced well over a thousand AI-related bills and enacted more than a hundred, according to the White & Case US AI regulatory tracker. Where the European Union built a single, sweeping AI Act, the United States has done almost the opposite, producing a fast-shifting mix of light-touch federal policy, a growing patchwork of state laws, and an active fight over who gets to regulate at all.


For anyone building, deploying, or working with AI in America, that fragmentation is the whole story. Pew Research Center data on workplace AI adoption indicates that roughly one in five US workers now uses AI on the job, meaning the technology already shapes a fast-growing share of workplaces. This guide explains how US AI policy actually works: the federal government's deregulatory approach, the state laws where the real rules currently live, the preemption battle between them, and what is changing in 2026. It is written for tech and compliance professionals, and it is general information, not legal advice.


The single most important fact about US AI policy is that there is no single AI law. Instead of one rulebook, you face a moving target: federal policy pulling toward deregulation, states pulling toward their own rules, and courts left to sort out the conflict.

The Big Picture: No Single Federal AI Law

The United States has no broad federal statute governing artificial intelligence. As the White & Case overview of US AI regulation explains, AI is instead governed by a combination of existing federal laws, a patchwork of state laws, voluntary frameworks, and executive actions setting policy direction.
This is the mirror image of the European Union, whose AI Act is a single binding law that applies risk-based rules across the whole bloc, including Article 50 transparency obligations. The US approach is bottom-up and fragmented rather than top-down and unified, and in the current administration it leans firmly toward promoting innovation over imposing new rules. Understanding US AI policy means understanding three moving parts at once: what the federal government is doing, what the states are doing, and how the two are colliding.

The Federal Approach: Light-Touch and Pro-Innovation

At the federal level, the defining posture is deregulatory. The administration's stated goal is to sustain US leadership in AI through what it repeatedly calls a "minimally burdensome" national approach, and it has pursued this through executive action rather than sweeping new law.


The sequence is worth knowing. On his third day in office in January 2025, the President revoked the previous administration's 2023 AI safety executive order and directed agencies to remove barriers to AI. This was followed in July 2025 by "America's AI Action Plan," a strategy document aimed at reducing regulatory friction and promoting AI development, as detailed in the White & Case US regulatory timeline. In December 2025 came the most consequential action yet: the White House issued an executive order targeting state AI laws and setting out a national policy framework. In March 2026 the White House followed with legislative recommendations urging Congress to codify a uniform federal standard, and in June 2026 it issued a further order focused on the cybersecurity of advanced AI systems.

US federal AI policy timeline showing five key milestones from January 2025 to June 2026.


Two federal building blocks matter alongside these policy statements. The first is the one AI-specific law Congress has actually passed: the TAKE IT DOWN Act, signed in May 2025, which prohibits the nonconsensual publication of intimate images, including AI-generated deepfakes, and requires online platforms to remove such content within 48 hours of notice, with enforcement against platforms beginning in May 2026. The second is the voluntary NIST AI Risk Management Framework, which has become the main federal reference point for building AI responsibly, even though it carries no legal force.


The underlying philosophy tying these together is that existing federal laws are enough to handle AI's risks, so new, AI-specific regulation should be minimal and a fragmented state-by-state approach should be avoided.


Federal AI policy in 2026 is defined less by what Washington has enacted than by what it has chosen not to: no broad AI law, no new AI regulator, and an explicit preference for letting innovation run with light-touch oversight.

The State Patchwork: Where the Real Rules Are

Because the federal government has largely declined to regulate AI directly, states have rushed to fill the gap, and this is where the binding rules currently live. The White & Case state-by-state AI tracker reports that lawmakers introduced well over a thousand AI-related bills in 2025 and that dozens of states have enacted at least one AI law. A few laws stand out.


Colorado passed the first broad state AI law. The Colorado AI Act requires developers and deployers of "high-risk" AI systems, such as those used in hiring and lending, to use reasonable care to protect people from algorithmic discrimination. After amendment, it takes effect on June 30, 2026. Colorado Public Radio's coverage of the federal-state dispute notes that it is the only state law named directly in the federal executive order targeting state regulation.


California has moved on transparency, with its Transparency in Frontier Artificial Intelligence Act taking effect on January 1, 2026, alongside a separate AI Transparency Act addressing the labeling of AI-generated content. Both measures are covered in the White & Case review of state AI legislation.


Texas enacted its Responsible Artificial Intelligence Governance Act, also effective January 1, 2026. As outlined in the White & Case US AI regulatory tracker, lawmakers narrowed it substantially during passage, focusing most obligations on government use of AI while still prohibiting certain uses outright, such as behavioral manipulation, unlawful discrimination, and generating illegal deepfakes. It also offers an affirmative defense to companies that follow the NIST framework.

US state AI law patchwork map highlighting AI regulation in California, Colorado and Texas, with indicators for Illinois and New York.

Beyond these, Illinois has amended its civil rights law to bar employers from using AI in discriminatory ways, New York City requires bias audits of automated hiring tools, and many states have passed laws on deepfakes, covering both nonconsensual intimate imagery and election-related synthetic media. States are also applying existing consumer protection, civil rights, and deceptive-practices laws to AI conduct.The pattern is a growing, uneven patchwork, with the most activity in algorithmic accountability, AI in hiring, transparency, and deepfakes, and meaningful differences from one state to the next.
If you want to know what rules actually bind your AI system in the US today, look to the states, not Washington. That is where the enforceable obligations are, and where they differ depending on where you operate.

The Preemption Fight: Who Gets to Regulate AI?

The central drama of US AI policy right now is a jurisdictional one: the federal government wants to rein in state AI laws, and the states are resisting.
The federal push escalated sharply with the December 2025 executive order on state AI regulation. It directs the Department of Justice to establish an AI Litigation Task Force to challenge state AI laws in court, orders the Commerce Department to identify state laws deemed too burdensome, tasks the Federal Trade Commission with examining when state rules requiring changes to AI outputs might count as deceptive practices, and moves to condition federal funding, including billions in broadband money, on states not enforcing AI laws the administration considers onerous. The March 2026 legislative framework then asked Congress to pass a law preempting burdensome state rules outright.


But there is a hard legal limit to this strategy. As the White & Case legal analysis of AI preemption explains, an executive order cannot, by itself, override state law; only an act of Congress or a ruling by the courts can do that. Congress has repeatedly refused to supply that preemption. A proposed ten-year moratorium on state AI laws was stripped from a major budget bill when the Senate voted 99 to 1 against it, and a similar effort attached to defense legislation also failed. The federal push faces further questions over the Tenth Amendment, the Dormant Commerce Clause, the legality of conditioning funds on state cooperation, and the limits of FTC and FCC authority.


The upshot is clear and important: for now, state AI laws remain fully enforceable. The White & Case regulatory guidance reflects the consistent advice that businesses should continue complying with them until the courts or Congress change the picture.

US AI regulation diagram showing federal government, Congress, courts and state AI laws connected by opposing regulatory authority arrows.

The preemption fight is unresolved, and that uncertainty is itself the current state of US AI policy. Until a court strikes a state law down or Congress passes a preemption statute, the safe assumption is that state rules still bind you.

Existing Laws Already Apply to AI

A frequent misconception is that, without a dedicated AI law, AI is a regulatory free-for-all in the US. It is not. Existing federal laws already reach AI. The Federal Trade Commission Act's ban on unfair and deceptive practices applies to how companies market and deploy AI, civil rights laws such as Title VII apply when AI is used in hiring, and privacy and intellectual property laws apply to how AI systems handle data and content.


The accountability principle behind these laws has real force. Organizations are responsible for what their AI does, a point underscored by an American Bar Association analysis of a chatbot liability ruling in which a tribunal held a company liable for false information its chatbot gave a customer. Because AI can generate confident but incorrect information, as explained in IBM's guide to AI hallucinations, the burden of catching those errors falls on the people and companies deploying it. In other words, "the AI did it" is not a defense under laws that already exist.

US vs the EU and the Rest of the World

Seeing the US approach next to the EU's clarifies what makes it distinctive. The European Union has a single, binding, risk-based AI Act that imposes obligations according to how risky an AI use is, including Article 50 transparency duties for certain AI systems and AI-generated content. The United States has no such law, favoring a deregulatory federal posture layered over a state patchwork.


That makes the US a deliberate alternative to the EU model, offering other countries a lighter-touch template. Yet the US remains a signatory to the internationally recognized OECD AI Principles, even as its federal policy has leaned toward deregulation. The tradeoff in the US approach is real: it prioritizes innovation and flexibility at the cost of consistency, legal certainty, and the stronger guardrails a single national law could provide. At the same time, the World Economic Forum's Future of Jobs Report 2025 shows that demand for the human skills needed to work with AI responsibly continues to rise.

What This Means for You

If you build or use AI in the US, the fragmented picture translates into a few concrete priorities.
First, since there is no single federal rulebook, focus on the state laws that apply to you, based on where you operate and whose residents your systems affect, with Colorado, California, and Texas leading the way. Second, keep complying with those state laws despite the federal push to preempt them. The White & Case US AI regulatory tracker confirms that they remain enforceable for now. Third, remember that existing federal laws already bind you: do not deceive consumers about AI, and do not let AI produce discriminatory outcomes in areas like hiring.


Beyond compliance, treat the NIST AI Risk Management Framework as a sensible voluntary baseline, since it is widely referenced and even serves as an affirmative defense under some state laws. Build a flexible compliance program that can adapt as executive orders, court rulings, and possible federal legislation reshape the landscape. And if you also operate in the EU, plan for the stricter EU AI Act, since meeting the higher bar generally covers the lower one.

 

US AI policy in 2026 is best understood not as a settled framework but as a contest. The federal government is betting on light-touch, innovation-first policy and is actively trying to clear away the state rules it sees as obstacles, while states are legislating quickly to fill the vacuum and defending their authority to do so. For now, the states hold the enforceable rules, existing federal laws still apply, and the courts and Congress will decide how the conflict resolves. For businesses and professionals, the message is to comply with the state laws that bind you, lean on frameworks like NIST, keep humans accountable for AI, and stay nimble, because in the US, AI policy is still very much being written.

Frequently Asked Questions

Not a broad one. As of 2026, the only AI-specific federal statute Congress has enacted is the TAKE IT DOWN Act, which targets nonconsensual intimate imagery, including deepfakes. There is no single, cross-sector federal AI law; instead, the US relies on existing laws, state laws, voluntary frameworks, and executive actions.

The country uses a fragmented mix of existing federal laws, including consumer protection and civil rights law, a growing patchwork of state laws, the voluntary NIST AI Risk Management Framework, and executive orders setting policy direction. The White & Case overview of US AI regulation tracks how these different measures interact. Unlike the EU, the US has no single binding AI law, and federal policy currently leans deregulatory.

The TAKE IT DOWN Act is the first AI-specific federal law, signed in May 2025. It prohibits the nonconsensual online publication of intimate images, including AI-generated deepfakes, and requires online platforms to remove such content within 48 hours of a valid request, with platform enforcement beginning in May 2026. It passed with near-unanimous support in Congress.

The White House's December 2025 executive order on national AI policy seeks to limit state AI laws. It directs the Justice Department to challenge state laws in court, the Commerce Department to identify burdensome measures, and federal agencies to condition certain funding on states not enforcing them. It reflects the administration's pro-innovation, "minimally burdensome" approach.

Not through an executive order alone. The White & Case analysis of the preemption dispute explains that overriding state law generally requires an act of Congress or a court ruling, so the December 2025 order cannot invalidate state laws by itself. Congress has repeatedly declined to pass preemption, including a moratorium the Senate rejected 99 to 1, so state laws remain enforceable for now.

The most significant include Colorado's AI Act, California's Transparency in Frontier Artificial Intelligence Act and AI Transparency Act, and Texas's Responsible Artificial Intelligence Governance Act. The White & Case state AI law tracker covers their requirements and effective dates. Many states have also enacted deepfake and AI-in-hiring rules.

It is the first broad US state AI law. It requires developers and deployers of high-risk AI systems, such as those used in hiring and lending, to use reasonable care to protect consumers from algorithmic discrimination. Colorado Public Radio's reporting on the law and federal executive order notes that, after amendment, the Act takes effect on June 30, 2026 and is the only state law named directly in the December 2025 order.

Yes. Even without a dedicated AI law, the FTC Act's ban on deceptive practices, civil rights laws such as Title VII, and privacy and intellectual property laws all apply to how AI is built and used. Organizations remain accountable for AI outputs, a principle reinforced by anAmerican Bar Association analysis of a chatbot liability ruling.

The EU has a single, binding, risk-based AI law with obligations tied to risk levels, including Article 50 transparency requirements. The US has no such law, relying instead on a deregulatory federal posture and a state patchwork. The US model is more flexible and innovation-focused but far less uniform, and firms operating in both markets usually face the EU's stricter rules.

Identify and comply with the state AI laws that apply to you, since they remain enforceable, and follow existing federal laws on deception, discrimination, and privacy. Use the NIST AI Risk Management Framework as a voluntary baseline, keep humans accountable for AI decisions, and maintain a flexible compliance program that can adapt as federal policy, court rulings, and legislation evolve. If you also operate in the EU, plan for the stricter EU AI Act.