Data Science Talent Logo
Call Now

AI Regulation in the US: Understanding the Patchwork of Rules by James Tumbridge, Robert Peake and Ryan Abbott


Robert Peake

ROBERT PEAKE is an intellectual property lawyer with over 15 years’ experience. His practice covers the intersection of intellectual property, technology, and regulation. Robert has a particular interest in emerging issues at the intersection of law and technology. He completed his LLM at the London School of Economics, focussing on the liability of internet intermediaries for IP infringement, and returns regularly as a visiting practitioner.

James Tumbridge

JAMES TUMBRIDGE is an intellectual property lawyer, arbitrator and mediator. Through his engagement with policymakers he advises clients on how to prepare for legislative changes and regulation compliance. James chairs the Digital Services function for the City of London, and has been an advisor to various MPs and MEPs on a range of issues.
He took part in the AI Global Summit and gave advice to the government on the 2018 Data Protection Act, and Online Safety Act 2024, and helped design the first guidance for public sector use of GenAI, published in 2023.

Ryan Abbott

RYAN ABBOTT is a highly experienced commercial and intellectual property lawyer whose practice focuses on representing companies in the life science and information technology industries. Ryan is an experienced trial and appellate attorney, having appeared as an advocate and lead counsel in numerous litigations in the UK and US.
Ryan is a physician, attorney, and patent attorney in the United States. He is a CEDR-accredited mediator, and a Fellow of the Chartered Institute of Arbitrators (FCIArb).
In this post, our authors discuss the challenges of implementing AI regulation in the US. The country isn’t governed by a single piece of legislation; instead more than 1,500 AI-related bills have been introduced across all 50 states. What will be the impact of the proposed federal framework to prevent the emergence of this patchwork of AI state regulation?

Artificial intelligence regulation in the United States is not centred on a single comprehensive piece of legislation, such as the EU’s AI Act; it is more of a layered landscape. As a threshold matter, many technologically-neutral laws, or laws focused on broader areas of technology than just AI, effectively regulate AI, such as laws related to false advertising or labour/employment practices.

But even focusing on AI-specific activity, at the federal level, executive orders, agency enforcement, and technical standards play an important role.

There is also a rapidly expanding body of state and local laws that regulate AI. At present, more than 1,500 AI-related bills have been introduced across all 50 states, covering issues ranging from generative AI, to synthetic content, to algorithmic accountability.

Existing doctrines at both the federal and state level in areas such as consumer protection, civil rights, privacy, and securities regulation are also being used to apply where new technologies are introduced.

“At present, more than 1,500 AI-related bills have been introduced across all 50 states, covering issues ranging from generative AI, to synthetic content, to algorithmic accountability.”

The US approach is said to be innovation first, and in March 2026 [1], the Trump administration published what it called a comprehensive National Policy Framework with six key objectives:

Preventing Children and Empowering Parents

Parents are best equipped to manage their children’s digital environment and upbringing. The administration is calling on Congress to give parents tools to effectively do that, such as account controls to protect their children’s privacy and manage their device use. The administration also believes that AI platforms likely to be accessed by minors should implement features to reduce potential sexual exploitation of children or encouragement of self-harm.

Safeguarding and Strengthening American Communities

AI development should strengthen American communities and small businesses through economic growth and energy dominance. The administration believes that ratepayers should not foot the bill for data centres, and is calling on Congress to streamline permitting so that data centres can generate power on site, enhancing grid reliability. Congress should also augment federal government ability to combat AI-enabled scams and address AI national security concerns.

Respecting Intellectual Property Rights and Supporting Creators

The creative works and unique identities of American innovators, creators, and publishers must be respected in the age of AI. Yet, for AI to improve, it must be able to make fair use of what it learns from the world it inhabits. The administration is proposing an approach that achieves both of these objectives, enabling AI to thrive while ensuring Americans’ creativity continues propelling the country’s greatness.

Preventing Censorship and Protecting Free Speech

The federal government must defend free speech and First Amendment protections, while preventing AI systems from being used to silence or censor lawful political expression or dissent. AI cannot become a vehicle for government to dictate right and wrong-think. The administration is proposing guardrails to ensure that AI can pursue truth and accuracy without limitation.

Enabling Innovation and Ensuring American AI Dominance

The administration is calling on Congress to take steps to remove outdated or unnecessary barriers to innovation, accelerate the deployment of AI across industry sectors, and facilitate broad access to the testing environments needed to build and deploy world-class AI systems.

Educating Americans and Developing an AI-Ready Workforce

The administration wants American workers to participate in and reap the rewards of AI-driven growth, encouraging Congress to further workforce development and skills training programs, expanding opportunities across sectors and creating new jobs in an AI-powered economy.

In order to achieve those aims, the administration proposes that a federal framework must be established by the federal government to support innovation and prevent the emergence of a patchwork of state AI regulation; the latter would, it is said, hinder national competitiveness. Such a federal framework should be a ‘minimally burdensome national standard’ that respects existing principles of federalism; pre-emption of state laws should cover areas such as development of AI and liability for unlawful conduct by third party using a developer’s model.

EXECUTIVE ORDERS, SHIFTING FEDERAL POLICY, AND TARGETED LEGISLATION

At the federal level, there have been several key executive orders related to AI. In 2023 we had President Biden’s Executive Order 14110, “Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence”. That order directed federal agencies to address a wide range of issues, including safety testing, national security, consumer protection, civil rights, and responsible procurement. In particular, the Department of Commerce and the National Institute of Standards and Technology (NIST) were tasked with helping develop the technical and governance infrastructure for AI oversight.

Shortly after taking office, President Trump issued an executive order on January 23rd, 2025, “Removing Barriers to American Leadership in Artificial Intelligence”, which characterised earlier federal AI regulatory initiatives as potentially impeding innovation; it therefore directed agencies to revisit policies thought to constrain US competitiveness. That executive order signalled a change of direction for AI governance at the federal level. In the US system, executive orders can influence procurement rules, grant conditions, enforcement priorities, and the kinds of technical standards agencies elevate.

The interest in AI continued in December 2025, when President Trump issued an executive order entitled “Ensuring a National Policy Framework for Artificial Intelligence”, instructing the Secretary of Commerce to evaluate state AI laws in order to identify those which may conflict with national policy priorities.

On the legislative front, Congress passed a law in May 2025, called the TAKE IT DOWN Act, which addresses non-consensually published intimate imagery including AI-generated deepfakes. The Act requires certain online platforms to establish ‘notice and takedown’ processes for content within scope of the law.

Other federal legislative proposals have included:

  • The Algorithmic Accountability Act of 2025, which would require impact assessments for automated decision systems used in contexts such as employment, education, and credit; and
  • The NO FAKES Act, which would create a federal framework addressing unauthorised digital replicas of individuals’ voices or likenesses.

Federal agencies have been active in applying existing law to AI-related conduct. The Federal Trade Commission (FTC) has, for example, made clear that AI is not exempt from existing consumer protection rules; in 2024, it announced a crackdown on deceptive AI claims and AI-enabled fraud schemes. In essence, where an organisation overstates the capabilities of its AI, conceals material limitations of its AI, or uses AI tools in ways that facilitate deception or unfairness, existing authority allows the FTC to treat such conduct as unlawful.

In an employment law context, the Equal Employment Opportunity Commission (EEOC) launched an initiative in 2021 on artificial intelligence and algorithmic fairness. The EEOC noted that employers remain responsible under existing civil rights laws when AI tools are used in the hiring, promotion, or evaluation of employees; if those tools operate in a way that is discriminatory, the employer remains liable under existing laws in the same way as the fact that the decision was automated does not insulate the employer.

Consumer finance presents a similar story. In the CFPB Circular 2022-03, the Consumer Financial Protection Bureau made clear that creditors using complex algorithmic systems must still provide intelligible reasons for adverse action decisions. That requirement matters because it translates the abstract debate over explainability into a concrete regulatory obligation. It is not enough for a model to be predictive; its outputs must also be capable of being translated into legally adequate explanations when consumers are denied credit or offered worse terms.

The Securities and Exchange Commission has likewise shown interest in AI-related risks. In 2023, the SEC proposed rules addressing conflicts of interest associated with predictive data analytics. The concern is that financial firms could use algorithmic systems to optimise behaviour in ways that advantage a firm while disadvantaging investors. This is an example of how AI regulation in finance is emerging through familiar categories such as fiduciary conflict, disclosure, investor protection, rather than through AI-specific statutory language.

NIST AND ‘SOFT LAW’ STANDARDS FOR AI

Technical governance frameworks can play an important role in legislation, agency activities, and private sector regulation. For instance, the National Institute of Standards and Technology (NIST) released its NIST Artificial Intelligence Risk Management Framework (AI RMF) in 2023. The AI RMF is organised around four core functions: Govern, Map, Measure, and Manage. It covers central issues for AI systems, including bias, privacy, safety, transparency, robustness, and accountability; the nomenclature used in the framework serves as a common vocabulary for those working across AI governance, notably engineers, compliance teams, legal counsel, and indeed regulators. Adherence to the AI RMF is voluntary, but its wide commercial adoption has made it one of the main reference points for demonstrating responsible AI governance for US organisations.

NIST has also developed a more specific resource for generative systems: the Generative AI Profile. That profile adapts the general AI RMF to risks associated with large language models and other generative architectures, including hallucinations, synthetic content misuse, evaluation difficulty, data provenance concerns, and the challenge of aligning highly flexible systems with intended use.

IN THE ABSENCE OF COMPREHENSIVE FEDERAL LAW, STATES LIKE CALIFORNIA ARE MOVING FORWARD WITH AI-SPECIFIC LEGISLATION

Numerous US states have enacted AI-specific regulation, with California as one of the most active in this space. California now has the fourth largest GDP in the world, and its regulators shape the approach of other states. In addition, as it is home to many of the leading AI developers and technology firms, California’s legislative initiatives may function as de facto national standards. Notable is the Transparency in Frontier Artificial Intelligence Act (SB 243) (the Act), signed into law in October 2025, which seeks to regulate advanced AI systems.

Background and objectives

The Act was adopted against the backdrop of rapid advances in so-called ‘frontier AI’ consisting of large-scale models with capabilities that may pose a range of systemic risks including; malicious cyber activities, generation and dissemination of disinformation, or unintended autonomous behaviour. The Act therefore pursues three principal policy objectives:

  1. Transparency: Ensuring that developers of advanced AI systems disclose key information about their models, training processes, and risk profiles.
  2. Accountability: Requiring developers of frontier AI to assess and mitigate risks associated with their systems.
  3. Oversight: Enabling regulators to understand and evaluate the capabilities and limitations of frontier AI.

The Act does not attempt to ban or directly restrict the development of frontier AI systems; rather, it sets a governance model focused on disclosure of material information and risk management.

Defining ‘frontier AI’

A central feature of the Act is the definition of the category of AI systems subject to its rules. The Act relies on the concept of ‘frontier artificial intelligence models,’ generally understood to include highly capable systems trained using substantial computational resources and capable of performing a wide range of tasks across domains. The Act relies on technical thresholds such as:

  • The scale of computational resources used in training, measured in the number of floating point operations, or FLOPs (10^26), used;
  • Model size and the number of parameters in the model; and
  • General-purpose capabilities across multiple domains.

As the characteristics of true frontier models may evolve quickly, the Act allows for regulators to update or refine definitions over time.


Scope of application

The Act primarily applies to developers of frontier AI models, rather than to all downstream users or deployers. This design choice reflects the view that those who create foundational models are best positioned to assess systemic risks.

Entities subject to the Act typically include:

  • Companies training large-scale general-purpose models;
  • Organisations developing models with advanced generative, or autonomous capabilities; and
  • Entities operating at the cutting edge of AI research and deployment.

The Act may also extend, in certain circumstances, to entities that substantially modify or fine-tune frontier models in ways that materially affect their capabilities. Notably, smaller developers, academic researchers, and open-source contributors may fall outside the scope of the Act if they do not meet the defined thresholds. This reflects a deliberate effort to avoid stifling innovation at lower levels of the ecosystem.

Core transparency obligations

Developers of in-scope models must provide detailed disclosures regarding various aspects of their systems. These include:

  • Model Capabilities and Limitations; developers must document the capabilities of their models, including:
    • The range of tasks the model can perform;
    • Known limitations or failure modes;
    • Potential misuse scenarios.

This is intended to address concerns about ‘black box’ systems whose behaviour may not be fully understood, even by their developers.

  • Training Data and Methodology; the Act requires disclosure of information about a model’s training, including:
    • The general categories of data used;
    • Data sourcing practices;
    • High-level descriptions of training methodologies.

Importantly, the Act does not require full disclosure of proprietary datasets; it requires disclosure sufficient to enable meaningful oversight and accountability.

  • Risk Assessments; developers must conduct and disclose risk assessments evaluating the potential harms associated with their models, typically including:
    • Misuse risks such as the generation of harmful or deceptive content;
    • Systemic risks such as potential impacts on critical infrastructure;
    • Societal risks such as bias, discrimination, or economic disruption.

      Risk assessments

      Risk assessments require updating periodically in line with evolving capabilities of the relevant model.

      Safety and mitigation obligations

      Developers are expected to implement reasonable safeguards to reduce identified risks. These include:

      • Content filtering mechanisms;
      • Access controls and usage restrictions;
      • Monitoring systems to detect misuse;
      • Adversarial testing including ‘red teaming’.

      The Act does not prescribe specific technical solutions, instead allowing flexibility for developers to adopt measures they consider to be appropriate for a given context.

      Reporting and incident disclosure

      Developers must report certain types of incidents to regulators, including:

      • Significant safety failures;
      • Evidence of large-scale misuse;
      • Breaches of safeguards designed to prevent harmful outputs.

      These incident reporting obligations align with regulatory requirements in other high-risk contexts, such as in the aviation and pharmaceutical industries, where reporting plays a critical role for safety oversight.

      Enforcement mechanisms

      The Act provides for enforcement primarily through state regulatory authorities, with the California Attorney General playing a central role. Available enforcement tools include:

      • Civil penalties for non-compliance;
      • Injunctive relief requiring corrective actions to be taken;
      • Oversight mechanisms such as audits or compliance reviews.

      Lawmakers were conscious of the need to include enforcement provisions that could be used to compel compliance, but were also certainly conscious of the risk that measures seen as overly aggressive or punitive could deter innovation (and investment).

      INDUSTRY RESPONSE TO CALIFORNIA’S SB 243

      SB 243 has received a mixed reception from the AI industry. Some have welcomed the adoption of a relatively commercially friendly approach focussed on transparency and risk management, but leaving a significant degree of flexibility for AI developers as to how compliance is achieved. Detractors cite a lack of certainty around the systems that are caught by the law, compliance costs and non-alignment with other state laws on AI.

      WHAT THE FUTURE HOLDS

      As noted above, the US has no comprehensive federal AI legal framework, and so AI-specific legislation has largely been at the state level. That may change if Congress were to pre-empt state action in this area or enact federal AI-specific laws in the future. Other jurisdictions are also regulating AI, and those rules may impact AI development or travel for domestic rules; the EU’s AI Act, for example, is likely to remain on the radar of legislators, and has already been the subject of commentary by the current federal administration. The AI Act is in the process of being revised, possibly in part due to international pressure following its initial introduction.

Back to blogs
Share this:
© Data Science Talent Ltd, 2026. All Rights Reserved.