The United States has no comprehensive federal AI law. Binding AI rules instead come from a fast-moving patchwork of state statutes, from existing federal law applied to AI, and from sector regulators, over the top of the voluntary NIST AI Risk Management Framework. In late 2025 the federal government began trying to override that patchwork, setting up a genuine state-versus-federal contest. This page sets out the instruments, the dates, and what is binding versus voluntary versus merely proposed, with links to the sources for each, and points to our live tracker for the row-by-row detail.
Last reviewed: 21 July 2026 · The US landscape moves fast; confirm against the primary sources and the live tracker linked below
There is no single US AI Act. The binding rules that actually apply to an organisation come from the states: Texas, California, Colorado, Illinois and New York have all enacted AI statutes, and New York City regulates automated hiring tools, so compliance in the US is a jurisdiction-by-jurisdiction exercise rather than a single national one. Over the top sits existing federal law, applied to AI by regulators like the FTC and EEOC, and the voluntary NIST AI Risk Management Framework.
What is new in 2026 is the federal effort to replace that patchwork with a uniform standard. A statutory ten-year moratorium on state AI enforcement failed in mid-2025 when the Senate stripped it 99 to 1, but a December 2025 executive order then created a Department of Justice task force to challenge state AI laws in court. For now the state laws remain fully enforceable, so organisations must comply with them while watching a federal-versus-state contest that could reshape the map. For the dated, sourced detail on each law, see our live US AI Laws Tracker.
The National Institute of Standards and Technology published the AI Risk Management Framework, a voluntary, widely referenced framework for managing AI risk. It is guidance, not law, and remains the main federal reference point.
Colorado passed the first broad US state AI statute, aimed at high-risk AI and algorithmic discrimination, setting the template that other states debated through 2025 and 2026.
A provision in the budget reconciliation package would have barred states from enforcing AI regulation for ten years. The Senate voted 99 to 1 to strip it, and the bill was signed without any AI preemption language, leaving the state laws intact.
An executive order titled Ensuring a National Policy Framework for Artificial Intelligence established an AI Litigation Task Force in the Department of Justice, tasked from 10 January 2026 with challenging state AI laws in federal court, while carving out child-safety, data-centre, and state-government-use laws.
Multiple state statutes commenced, including the Texas Responsible AI Governance Act (TRAIGA) and obligations in Illinois and elsewhere, alongside standing rules such as New York City Local Law 144 on automated employment decision tools.
Colorado repealed its original AI Act and replaced it (SB 26-189), a reminder that the state patchwork is not only broad but unstable, changing materially within a single year.
The distinction that matters most for compliance is whether an instrument carries legal force, is voluntary guidance, or is a proposal still being fought over. The table below sorts the main instruments accordingly.
| Instrument | Status | Applies to / owner |
|---|---|---|
| State AI laws (Texas TRAIGA, California SB 53 / AB 2013 / SB 942, Illinois HB 3773, New York RAISE Act, NYC Local Law 144) | Binding | Organisations operating in or serving those states; the binding layer of US AI law |
| Colorado SB 26-189 (2026 repeal-and-replace of the 2024 Colorado AI Act) | Binding | Organisations in scope in Colorado; illustrates how fast the patchwork changes |
| Existing federal law and sector regulators (FTC, EEOC and others applied to AI) | Binding | Applied to AI the same way as to any other technology, via consumer protection, civil rights and sector rules |
| NIST AI Risk Management Framework | Voluntary framework | All organisations; the main federal reference, guidance rather than law |
| Federal preemption / uniform national standard (Dec 2025 executive order, DOJ task force, draft federal bill) | Contested, not enacted | A federal push to override the state patchwork; the July 2025 statutory moratorium failed, so it is now litigation and proposals, not law |
| EU AI Act (Regulation (EU) 2024/1689) | Binding on US exporters | US organisations that provide or deploy AI in the EU market |
For each state law with its dates and sources, and the EU AI Act deadlines that reach US exporters, see the US AI Laws Tracker, which is updated as statutes commence, get repealed or are amended.
Two practical points follow. First, US AI compliance is a map problem: what applies depends on which states an organisation operates in and which sectors it touches, so the same AI system can carry different obligations in Texas, California and New York. A single national checklist does not exist. Second, the ground is moving: Colorado rewrote its law inside a year, new statutes commence on rolling dates, and a federal task force is now challenging state laws in court, so a US AI position needs to be maintained, not set once.
Because the baseline is a shifting patchwork rather than one clear statute, the weight of day-to-day AI governance sits with each organisation’s own framework and controls, anchored to a recognised model such as the NIST AI RMF. Our AI GRC guide covers how those pieces fit together, a short governance assessment benchmarks where an organisation stands, and the US AI Laws Tracker keeps the obligations current.
No comprehensive federal AI law governs general AI use as of mid-2026. A discussion draft has circulated but has not been enacted. In practice, binding AI rules come from a growing patchwork of state laws, from existing federal law applied to AI (such as consumer protection and civil rights), and from sector regulators, supplemented by the voluntary NIST AI Risk Management Framework.
No. A proposal to bar states from enforcing AI regulation for ten years was included in a 2025 budget bill, but the Senate voted 99 to 1 to remove it, and the bill was signed without it. State AI laws remain fully in effect and enforceable. Separately, a December 2025 executive order created a Department of Justice task force to challenge state AI laws in federal court, so the federal-versus-state question is now being fought through litigation and proposals rather than settled by statute.
Several, and the list changes quickly. As of 2026 they include Texas (the Responsible AI Governance Act), California (a set of statutes including SB 53, AB 2013 and SB 942), Colorado (which repealed and replaced its 2024 AI Act in 2026), Illinois (HB 3773), and New York (the RAISE Act), alongside New York City Local Law 144. Our live US AI Laws Tracker keeps the dated, sourced detail current.
No. The NIST AI RMF is a voluntary framework. It is influential and widely adopted as good practice, and some contracts or agencies reference it, but it is guidance rather than a binding federal law in itself.
Yes, where a US organisation provides or deploys AI systems in the European Union market, the EU AI Act can apply to it regardless of where it is based. For many US firms it is the most concrete AI statute they face, which is why it sits on this page and in the tracker.
Per-statute sources for each state law are cited in the US AI Laws Tracker.
A short, free assessment benchmarks where your organisation stands against a structured AI governance model, useful precisely because US obligations vary by state and keep moving.
This page is general information describing the state of United States AI policy as at 21 July 2026, not legal or compliance advice. The US landscape is fast-moving and litigated; always confirm the current position against the primary sources and the live tracker linked above, and obtain advice from your own qualified counsel before relying on it.