Country · Americas

AI regulation in the United States

Source-linked 4 instruments · 2 binding

Overview

The United States has no comprehensive federal AI statute. Federal policy is set through executive orders, Office of Management and Budget (OMB) memoranda for federal agencies, agency enforcement under existing consumer-protection, civil-rights, employment and financial laws, and voluntary frameworks such as the NIST AI Risk Management Framework. States have moved faster: Colorado enacted the first cross-sector algorithmic-discrimination law in 2024, and California, Texas, Utah and others have adopted AI-specific statutes on transparency, frontier models, chatbots and government use. The result is a patchwork that organisations must map state by state and sector by sector.

What is the current regulatory status?

Federal: executive-branch policy (Executive Order 14179 of January 2025 and the July 2025 AI Action Plan) plus binding OMB requirements for federal agencies' use and procurement of AI; NIST AI RMF is voluntary. States: a growing number of binding statutes with 2025–2026 effective dates. A reviewer must confirm the status of federal efforts to pre-empt or discourage state AI laws announced in late 2025.

Binding rules versus guidance

Binding on the private sector: state statutes (for example Colorado SB 24-205, California SB 53, Texas HB 149), sector laws (FCRA, ECOA, Title VII, HIPAA, FTC Act Section 5) as applied to AI. Binding on federal agencies: OMB memoranda M-25-21 and M-25-22. Voluntary: NIST AI RMF and its Generative AI Profile.

Key policy instruments

United States Framework Voluntary standard

NIST AI RMF

NIST AI Risk Management Framework (AI RMF 1.0) and Generative AI Profile

The NIST AI Risk Management Framework is a voluntary framework for managing risks to individuals, organisations and society from AI. It organises practices into four functions: Govern, Map, Measure and Manage, and describes characteristics of trustworthy AI such as validity, safety, security, accountability, explainability, privacy and fairness. The July 2024 Generative AI Profile (NIST AI 600-1) adds risks and suggested actions specific to generative AI. Many US procurement requirements and state laws reference the framework as a recognised approach.

Adopted 26 Jan 2023 Source-linked Official source
United States Executive order In force Binding

EO 14179

Executive Order 14179: Removing Barriers to American Leadership in Artificial Intelligence

Executive Order 14179, signed 23 January 2025, sets US federal policy to sustain and enhance American AI dominance, directs the development of an AI Action Plan within 180 days, and orders agencies to review and revise or rescind actions taken under the revoked Executive Order 14110 that are inconsistent with the new policy. It also called for revision of the OMB memoranda governing federal agency use and procurement of AI, which OMB replaced in April 2025 with M-25-21 and M-25-22.

In force 23 Jan 2025 Source-linked Official source
United States Guidance In force Binding

OMB M-25-21

OMB Memorandum M-25-21: Accelerating Federal Use of AI through Innovation, Governance, and Public Trust

M-25-21 directs US federal agencies on how to govern and use AI. It requires agencies to designate Chief AI Officers, maintain AI governance boards, publish AI use-case inventories, and apply minimum risk-management practices to "high-impact" AI, including pre-deployment testing, AI impact assessments, ongoing monitoring, human oversight and training, and remedies for affected individuals. It replaced the 2024 memoranda with a greater emphasis on adoption and innovation while retaining core risk practices.

In force 3 Apr 2025 Source-linked Official source
United States National strategy Adopted

Winning the Race: America's AI Action Plan

America's AI Action Plan is the federal AI strategy mandated by Executive Order 14179. It lists more than 90 policy actions grouped under three pillars: accelerating innovation (including removing regulatory barriers), building AI infrastructure such as data centres and chip fabrication with streamlined permitting, and leading internationally through AI exports and security measures. It was released with accompanying executive orders on federal procurement, data-centre permitting and AI exports.

Adopted 23 Jul 2025 Source-linked · checked 11 Sep 2026 Official source
Filter all United States policies

Upcoming deadlines

No scheduled future dates recorded. Past milestones are listed on each policy page.

Current priorities

Federal deregulatory agenda and infrastructure build-out under the AI Action Plan, agency AI use-case inventories and procurement rules, state implementation of algorithmic-discrimination and frontier-model transparency laws, and litigation and enforcement by state attorneys general and the FTC on deceptive AI claims.

Latest changes

Applicable sectors, use cases and obligation areas

How to use this information

  1. Map the states where your users or employees are located; state law, not federal law, creates most binding AI duties.
  2. Treat NIST AI RMF as the common vocabulary for governance evidence that regulators and customers recognise.
  3. If you sell to the federal government, align with OMB M-25-21 and M-25-22 requirements for high-impact AI.
  4. Apply existing anti-discrimination, consumer-protection and privacy laws to AI decisions; they are enforced today.
  5. Check effective dates carefully; several state laws were delayed or amended after enactment.

Official government and regulator sources

  1. NIST AI Risk Management Framework (AI RMF 1.0)
    National Institute of Standards and Technology · 2023-01-26 · Tier 1 source
  2. Executive Order 14179: Removing Barriers to American Leadership in Artificial Intelligence
    The White House · 2025-01-23 · Tier 1 source
  3. America's AI Action Plan
    The White House / Office of Science and Technology Policy · 2025-07-23 · Tier 1 source

Frequently asked questions

Is there a federal AI law in the United States?
No comprehensive federal AI statute exists. Federal policy is set by executive orders, OMB memoranda binding on agencies, and enforcement of existing laws. Binding AI-specific rules for businesses come mainly from state legislation.
Which US states have AI laws?
Colorado (SB 24-205, algorithmic discrimination), California (including SB 53 on frontier-model transparency and privacy-agency rules on automated decision-making), Texas (HB 149), Utah and others. Effective dates and scope differ, and several have been amended; check each record's official source.

Follow by email

Get every dated, source-linked change to this jurisdiction in a weekly email.

Double opt-in; one-click unsubscribe in every email. Choose jurisdictions

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.