AI regulation in United States
No single federal AI law, and no federal preemption of state law. NIST's AI RMF is the voluntary national reference. Binding rules come from individual states, and that layer is unsettled rather than merely patchy — Colorado repealed and rewrote its AI Act in 2026, and a federal executive order now directs litigation against state AI laws.
NIST AI Risk Management Framework
Administered by U.S. National Institute of Standards and Technology.
- No binding federal AI statute. Congress has not preempted state AI law, and previous attempts to do so have failed.
- The NIST AI Risk Management Framework is voluntary. It is the de facto national reference and is what most US procurement language points at, but nothing makes it mandatory.
- Binding obligations come from states, and the state picture is actively unsettled rather than merely fragmented — the leading example was repealed and rewritten in 2026.
- Sector regulators (FTC, EEOC, financial and health regulators) apply existing law to AI, which is where most live enforcement risk actually sits.
State attorneys general for state AI statutes; federal sector regulators under existing authority. A federal executive order has directed the Justice Department to challenge state AI laws and threatened federal broadband funding over them, so the preemption question is live and unresolved.
This page is a general orientation guide built from public sources, not legal advice, and it does not establish that any organisation complies with United States's requirements. AIC certifies governance against its own published standard; that is a different question from legal compliance, and neither substitutes for the other. Back to the map.