FISTA Solutions does not load Google Analytics until you accept. Rejecting keeps optional analytics off. Read the Cookie Policy.

All field notes

Governance · 5 minute read

AI Regulation in the United States: The Landscape Businesses Face

AI regulation in the United States is a patchwork rather than a single law: federal agencies apply existing consumer protection, civil rights, privacy, and sector statutes to AI, executive guidance shapes federal priorities, states enact statutes on automated decisions and transparency, and sector regulators set expectations in finance, healthcare, insurance, and employment. Businesses prepare by building the common controls.

By FISTA Solutions· AI-Native Engineering Team·
AI Regulation in the United States: The Landscape Businesses Face article cover

Businesses looking for the United States AI law find that there is not one, and conclude either that AI is unregulated or that compliance is impossible to plan. Both are wrong. AI is regulated through existing laws that agencies enforce against AI harms, a fast-growing body of state statutes, and sector rules that name AI explicitly. The layers share requirements, and a business that builds to those requirements is prepared for most of what any layer demands. This guide maps the landscape and the preparation strategy, drawing on FISTA Solutions' AI enablement practice. State specifics are in california ai regulations for businesses and colorado ai act explained. This article is general guidance, not legal advice; laws change frequently, and businesses should confirm current obligations with counsel.

What are the layers?

LayerWhat it doesExamples of coverage
Existing federal lawApplies to AI as to any technology; enforced by agenciesUnfair and deceptive practices; discrimination in employment, credit, housing; privacy; product safety
Federal executive guidanceShapes federal procurement, agency priorities, and standardsRisk management frameworks; agency AI use; standards development
Sector regulatorsSet expectations for AI within regulated activitiesModel risk in banking; fair lending; healthcare privacy and safety; insurance fairness; hiring
State statutesCreate new obligations, often for consequential decisionsAutomated decision-making; algorithmic discrimination; transparency; deepfakes; privacy rights
Common lawLiability for harms caused by AINegligence; product liability; defamation

Frameworks that agencies reference are in nist ai risk management framework explained.

How do existing federal laws apply?

Consumer protection agencies have stated that unfair, deceptive, or discriminatory uses of AI violate existing prohibitions, and have brought actions over unsubstantiated AI claims and harmful automated systems. Civil rights laws apply to AI-assisted decisions in employment, credit, and housing regardless of the technology. Privacy laws govern personal data in AI systems. Product liability and negligence apply to AI-caused harm. The message from agencies is that there is no AI exemption. Disclosure obligations that follow are in ai incident disclosure.

What do sector regulators expect?

Financial regulators expect model risk management extended to AI, fair lending testing, adverse action reasons, and consumer protection in AI-assisted servicing. Healthcare regulators expect privacy safeguards including business associate agreements, safety, and device rules where AI performs a medical function. Insurance regulators expect governance and fairness in AI-assisted underwriting and claims, with several states issuing specific guidance. Employment regulators expect non-discrimination in AI-assisted hiring and, in some jurisdictions, audits and notices. Sector practice is in ai in regulated industries and model risk in ai model risk management.

What are states enacting?

Statutes on automated decision-making and algorithmic discrimination requiring risk assessments, notices, and rights for consequential decisions; transparency and disclosure requirements for AI interactions and generated content; deepfake and synthetic media laws; AI-specific rules for employment screening and insurance; and privacy laws with rights over automated processing and profiling. Scope, definitions, and effective dates vary, and multi-state businesses must map each. The two most-watched frameworks are covered in california ai regulations for businesses and colorado ai act explained.

What requirements do the layers share?

Common requirementWhere it appears
Inventory and risk classificationState frameworks; sector guidance; federal frameworks
Impact and risk assessments for consequential usesState statutes; sector rules
Testing for accuracy, bias, and safetyCivil rights enforcement; state statutes; model risk
Transparency and disclosure to affected peopleConsumer protection; state statutes; sector rules
Human oversight and contestabilityState statutes; sector rules; agency guidance
Records and documentationAll layers
Vendor and developer obligationsState statutes; sector rules

Building these once satisfies most of what any layer asks. The program structure is in what is ai governance.

How should a business prepare?

Build the shared controls: an inventory with risk tiers; impact and risk assessments for consequential uses; evaluation and bias testing with evidence; transparency notices and disclosure; human oversight of consequential decisions; explainability suited to audiences; records; and vendor management. Then map jurisdiction and sector specifics on top, assign an owner to track legislative and regulatory change, and review quarterly with counsel. Organizations that wait for a single federal law will be unprepared for the state and sector obligations already in force. Transparency practice is in ai transparency notices and oversight in ai human oversight requirements.

How does the US landscape compare with the EU?

The EU has a comprehensive AI regulation with risk-based obligations; the US relies on existing law, sector regulators, and state statutes. Businesses operating in both find that the EU's high-risk obligations and the US common requirements overlap substantially, so one control program serves both with jurisdiction-specific additions. The EU obligations for US companies are in eu ai act compliance for us companies and certification in iso 42001 explained.

What mistakes leave businesses exposed?

Assuming no AI law means no AI obligations; ignoring state statutes because headquarters is elsewhere; treating vendor AI as the vendor's problem; deploying consequential automated decisions without assessments, notices, or oversight; and having no owner tracking change. Enforcement actions and state effective dates have caught each.

How FISTA Solutions helps businesses prepare

FISTA Solutions builds AI systems with the shared controls the US landscape demands, inventory, assessments, testing evidence, transparency, oversight, records, and vendor management, and helps clients map jurisdiction and sector specifics with their counsel. The AI enablement practice leads governance design, AI agents ship with the controls, and forward deployed engineers embed with client compliance teams. The record behind the approach is 150+ projects for 50+ companies.

To build once for the obligations that are already in force, message FISTA on WhatsApp, or read what is ai governance for the program that satisfies them.

Share-ready article cover

Download the generated social format.

Download cover

Clear answers

Questions raised by this field note.

Straightforward guidance for evaluating scope, fit, and the next step.

01Is there a federal AI law in the United States?

No comprehensive one as of this writing. Federal agencies apply existing laws on unfair and deceptive practices, discrimination, privacy, and sector conduct to AI, and executive guidance shapes federal procurement and agency priorities. Proposals surface regularly; businesses should track them but plan around existing law.

02Which existing laws apply to AI?

Consumer protection prohibitions on unfair and deceptive practices, civil rights laws on discrimination in employment, credit, and housing, privacy laws at federal and state level, sector statutes in finance, healthcare, and insurance, and product liability and tort law. Agencies have stated these apply to AI as to any other technology.

03What are states doing?

Enacting statutes on automated decision-making and algorithmic discrimination, transparency and disclosure of AI use, deepfakes and synthetic media, AI in employment and insurance, and privacy rights over automated processing, with varying scope and timelines. Several states have comprehensive frameworks; more are in progress.

04What do sector regulators expect?

Financial regulators expect model risk management, fair lending compliance, and consumer protection; healthcare regulators expect privacy safeguards, safety, and device rules where applicable; insurance regulators expect fairness and governance in underwriting and claims; employment regulators expect non-discrimination in AI-assisted hiring.

05How should a business prepare?

Build the controls the layers share: an inventory with risk tiers, impact and risk assessments, testing for accuracy and bias, transparency to affected people, human oversight of consequential decisions, records, and vendor management; then map jurisdiction and sector specifics on top and track changes with counsel.

Start with the hard problem

Need the outcome owned, not merely analyzed?

Tell us where delivery is constrained. We’ll map the fastest credible path from intent to verified production.

Start a project