AI regulation in the United States

There is no comprehensive federal AI statute in the United States. Federal policy comes from executive orders (Executive Order 14179 of January 2025), OMB memoranda that bind federal agencies, the voluntary NIST AI Risk Management Framework, and enforcement of existing consumer-protection, civil-rights and financial laws. Binding AI-specific rules for businesses come mainly from states, including Colorado's algorithmic-discrimination law and California's frontier-model transparency act.

Source-linked Source-linked Source-linked
Voluntary standard Framework

NIST AI Risk Management Framework (AI RMF 1.0) and Generative AI Profile

The NIST AI Risk Management Framework is a voluntary framework for managing risks to individuals, organisations and society from AI. It organises practices into four functions: Govern, Map, Measure and Manage, and describes characteristics of trustworthy AI such as validity, safety, security, accountability, explainability, privacy and fairness. The July 2024 Generative AI Profile (NIST AI 600-1) adds risks and suggested actions specific to generative AI. Many US procurement requirements and state laws reference the framework as a recognised approach.

Full record: obligations, sources and change history

Federal layer

Executive orders set policy direction for agencies and shape procurement; OMB memoranda M-25-21 and M-25-22 require agency governance, inventories, high-impact AI practices and acquisition rules; NIST provides the AI RMF and its Generative AI Profile as the shared vocabulary. Agencies such as the FTC, EEOC and CFPB apply existing law to AI.

State layer

States create most binding duties for private organisations. Colorado imposes reasonable-care duties on developers and deployers of high-risk AI; California requires frontier-model safety frameworks and regulates automated decision-making under the CCPA; Texas, Utah and others have targeted statutes. Effective dates have moved after enactment, so verify each record's official source.

What to do

Map where your users and employees are; adopt the NIST AI RMF as your governance backbone (state laws and federal buyers recognise it); and treat anti-discrimination, consumer-protection and privacy law as applying to AI today.

Recorded policy instruments

United States Framework Voluntary standard

NIST AI RMF

NIST AI Risk Management Framework (AI RMF 1.0) and Generative AI Profile

The NIST AI Risk Management Framework is a voluntary framework for managing risks to individuals, organisations and society from AI. It organises practices into four functions: Govern, Map, Measure and Manage, and describes characteristics of trustworthy AI such as validity, safety, security, accountability, explainability, privacy and fairness. The July 2024 Generative AI Profile (NIST AI 600-1) adds risks and suggested actions specific to generative AI. Many US procurement requirements and state laws reference the framework as a recognised approach.

Adopted 26 Jan 2023 Source-linked Official source
California (United States) Act / statute In force Binding

California SB 53

California SB 53: Transparency in Frontier Artificial Intelligence Act

SB 53 requires "large frontier developers" (developers of the most compute-intensive models above statutory thresholds) to publish a frontier AI framework describing how they assess and mitigate catastrophic risks, publish transparency reports when deploying new frontier models, report critical safety incidents to the California Office of Emergency Services, and protect employees who report safety concerns. It also directs creation of a public computing cluster ("CalCompute").

Applies from 1 Jan 2026 Source-linked Official source
Colorado (United States) Act / statute Adopted Binding

Colorado AI Act

Colorado Senate Bill 24-205: Consumer Protections for Artificial Intelligence (Colorado AI Act)

The Colorado AI Act requires developers and deployers of high-risk AI systems to use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination. High-risk systems are those that make, or are a substantial factor in making, consequential decisions about education, employment, financial or lending services, essential government services, healthcare, housing, insurance or legal services. Deployers must run risk-management programmes and impact assessments, notify consumers, and explain adverse decisions; developers must document systems and disclose known risks.

Applies from 30 Jun 2026 Source-linked Official source
United States Executive order In force Binding

EO 14179

Executive Order 14179: Removing Barriers to American Leadership in Artificial Intelligence

Executive Order 14179, signed 23 January 2025, sets US federal policy to sustain and enhance American AI dominance, directs the development of an AI Action Plan within 180 days, and orders agencies to review and revise or rescind actions taken under the revoked Executive Order 14110 that are inconsistent with the new policy. It also called for revision of the OMB memoranda governing federal agency use and procurement of AI, which OMB replaced in April 2025 with M-25-21 and M-25-22.

In force 23 Jan 2025 Source-linked Official source
United States Guidance In force Binding

OMB M-25-21

OMB Memorandum M-25-21: Accelerating Federal Use of AI through Innovation, Governance, and Public Trust

M-25-21 directs US federal agencies on how to govern and use AI. It requires agencies to designate Chief AI Officers, maintain AI governance boards, publish AI use-case inventories, and apply minimum risk-management practices to "high-impact" AI, including pre-deployment testing, AI impact assessments, ongoing monitoring, human oversight and training, and remedies for affected individuals. It replaced the 2024 memoranda with a greater emphasis on adoption and innovation while retaining core risk practices.

In force 3 Apr 2025 Source-linked Official source
United States National strategy Adopted

Winning the Race: America's AI Action Plan

America's AI Action Plan is the federal AI strategy mandated by Executive Order 14179. It lists more than 90 policy actions grouped under three pillars: accelerating innovation (including removing regulatory barriers), building AI infrastructure such as data centres and chip fabrication with streamlined permitting, and leading internationally through AI exports and security measures. It was released with accompanying executive orders on federal procurement, data-centre permitting and AI exports.

Adopted 23 Jul 2025 Source-linked · checked 11 Sep 2026 Official source

Key obligations

Latest changes

Frequently asked questions

Is the NIST AI RMF mandatory in the US?
No, it is voluntary, but state laws and federal procurement reference it as a recognised framework.

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.