Jurisdiction
United States
- Source
- Editorial review of primary sources — not yet re-anchored
- Verified
- Evidence not verified
- Confidence
- Low
Structured issue-spotting to support your own review — not legal advice. Verify against the cited primary sources and your counsel.
01Framework
The United States has no general federal privacy statute and no comprehensive federal AI statute. Federal AI policy is executive rather than legislative: EO 14179 revoked the 2023 AI order, and EO 14365 now directs the Justice Department to challenge state AI laws. Binding obligations come from sectoral statutes — FTC Act §5, HIPAA, GLBA, FCRA, COPPA — and, increasingly, from the states, whose rules diverge. Several 2022–24 federal AI guidance documents were withdrawn in 2025, so the federal guidance most teams remember no longer exists. For a private deployment the live questions are which state law reaches you, and whether 28 CFR Part 202 turns your vendor agreement into a restricted transaction.
- Region
- North America
- ISO code
- US
- Privacy framework
- Sectoral, not omnibus. FTC Act §5 (15 U.S.C. 45) is the general backstop for unfair or deceptive AI and data practices. HIPAA (45 CFR Part 164) covers protected health information; the GLBA Safeguards Rule (16 CFR Part 314) covers financial institutions; FCRA (15 U.S.C. 1681) governs consumer reports and adverse-action notices, which is the statute AI credit, tenant and employment screening most often engages; the COPPA Rule (16 CFR Part 312) covers under-13 data, and the 2025 amendments’ compliance deadline has passed. There is no federal cross-border transfer regime for ordinary personal data. State law supplies what the federal layer does not: California’s CCPA and the CPPA’s ADMT regulations, Colorado’s automated decision-making statute from 2027, Illinois BIPA and the Illinois Human Rights Act AI amendment, Texas TRAIGA, Connecticut Public Act 26-15 and New York City Local Law 144.
- AI-specific rules
- Executive-branch policy plus sectoral enforcement; no horizontal federal AI statute. EO 14179 (23 January 2025) revoked EO 14110. EO 14319 (23 July 2025) requires federal large-language-model procurement to meet Unbiased AI Principles, implemented by OMB M-26-04. OMB M-25-21 and M-25-22 (3 April 2025) govern federal agency AI use and acquisition. EO 14365 (11 December 2025) established a Justice Department AI Litigation Task Force to challenge state AI laws. EO 14409 (2 June 2026) adds a voluntary frontier-model evaluation pathway while expressly disclaiming any licensing requirement. The NIST AI Risk Management Framework and its Generative AI Profile remain the reference risk framework and are voluntary — they bind only where a contract or a state statute names them. Binding AI duties on a private deployer are state duties: bias audits, ADMT notices and opt-outs, biometric consent, and disclosure of generative AI use.
- Last reviewed
- 20 Aug 2026
- Status
- published
Cross-border transfer
There is no general US restriction on exporting personal data. The rule that actually bites an AI deployment is the Justice Department’s Data Security Program at 28 CFR Part 202, issued under EO 14117. It prohibits data-brokerage transactions with countries of concern and turns vendor, employment and investment agreements giving covered persons access to bulk US sensitive personal data into restricted transactions, carrying CISA security requirements, due diligence, recordkeeping and reporting. The recurring trap is that an AI vendor with engineering or support staff, or a subprocessor, in a country of concern makes an ordinary SaaS agreement a restricted transaction: the test is about people and ownership, not about which region the inference endpoint sits in. Ask where support engineers sit and who owns the vendor, not only where the model runs. Sectoral overlays add HIPAA business-associate agreements, GLBA service-provider oversight and FedRAMP for government workloads.
Regulators
Primary sources
- Legislation15 U.S.C. 45 — Federal Trade Commission Act Section 5
- Legislation15 U.S.C. 1681 — Fair Credit Reporting Act
- Legislation45 CFR Part 164 — Security and Privacy (HIPAA), reader-facing eCFR text
- Legislation16 CFR Part 314 — Standards for Safeguarding Customer Information
- Legislation16 CFR Part 312 — Children's Online Privacy Protection Rule
- Legislation28 CFR Part 202 — Access to U.S. Sensitive Personal Data by Countries of Concern
- Regulator pageExecutive Order 14365 — Ensuring a National Policy Framework for Artificial Intelligence
- Regulator pageExecutive Order 14409 — Promoting Advanced Artificial Intelligence Innovation and Security
- Regulator guidanceOMB memoranda index (M-25-21, M-25-22, M-26-04)
- StandardNIST AI Risk Management Framework
- Regulator guidanceCFPB — Interpretive Rules, Policy Statements, and Advisory Opinions; Withdrawal (90 FR 20084)
- Regulator guidanceCPPA — text of the approved CCPA updates, cybersecurity, risk assessment and ADMT regulations
- LegislationColorado General Assembly — SB26-189, Automated Decision-Making Technology
- Regulator pageNYC Department of Consumer and Worker Protection — Automated Employment Decision Tools
- Regulator pageTexas Governor — prohibited technologies list announcement
- Regulator pageVirginia IT Agency — artificial intelligence governance
02Regulations and guidance
| Instrument | Status |
|---|---|
| DOJ Data Security ProgramProhibits data-brokerage transactions with countries of concern and makes vendor, employment and investment agreements giving covered persons access to bulk US sensitive personal data restricted transactions, subject to CISA security requirements, due diligence and recordkeeping. | In force |
| CCPA/CPRACalifornia’s baseline privacy statute (Civil Code 1798.100 et seq.). Grants access, deletion, correction, opt-out of sale or sharing and sensitive-data limitation rights, and authorises the CPPA to make rules on profiling and automated decisionmaking. | In force |
| CPPA ADMT RegulationsAdds pre-use notice, opt-out and access rights for automated decisionmaking technology used in significant decisions, mandatory risk assessments with submissions to the Agency, and phased independent cybersecurity audits. | Partly in force |
| COPPA RuleRequires verifiable parental consent before collecting personal information from children under 13, with retention limits and separate consent for disclosure. The 2025 amendments’ compliance deadline has passed, so the amended rule is what applies now. | In force |
| Colorado ADMT ActRepeals and reenacts Colorado’s 2024 AI Act. Developers and deployers of automated decision-making technology used in consequential decisions owe documentation, consumer notice, data access and correction, and meaningful human review; the Attorney General enforces. | Partly in force |
| EO 14179Revokes Executive Order 14110 and directs agencies to identify and roll back AI policies seen as barriers to innovation. Established the mandate for America’s AI Action Plan. | In force |
| EO 14281Directs federal agencies to deprioritise enforcement of disparate-impact liability. It materially reduces federal enforcement risk for biased AI hiring tools without changing Title VII itself, so the liability remains while the enforcement priority does not. | In force |
| EO 14319Requires federal agencies to procure only large language models complying with Unbiased AI Principles of truth-seeking and ideological neutrality. Implemented by OMB memorandum M-26-04. A real procurement gate for anyone selling a model into the federal government. | In force |
| EO 14365Directs the Attorney General to establish an AI Litigation Task Force to challenge state AI laws, requires Commerce to identify conflicting state laws, and conditions certain federal broadband funding. It attacks state divergence rather than creating federal duties. | In force |
| EO 14409Creates a voluntary pathway for developers to have models designated covered frontier models with pre-release federal evaluation, and directs cybersecurity measures. It expressly disclaims any mandatory licensing requirement. | In force |
| FCRAGoverns consumer reports, permissible purposes and adverse-action notices. AI credit, tenant and employment screening tools frequently make their operator a consumer reporting agency or a user of consumer reports, which is the point at which the statute attaches. | In force |
| FTC Act §5Declares unfair or deceptive acts or practices in commerce unlawful. The general federal backstop for overstated AI capability claims, undisclosed AI use and inadequate data practices — it reaches an AI deployment through what the deployer says about it, not through a technology-specific duty. | In force |
| HIPAASets privacy and security standards for protected health information. Any clinical or health-adjacent AI deployment needs a business associate agreement covering the model vendor and its subcontractors, and a security risk analysis that actually includes the model. | In force |
| CFPB 2025 withdrawalWithdrew a long list of CFPB guidance documents, including Circular 2022-03 on adverse-action notices for credit decisions based on complex algorithms and Circular 2024-06 on algorithmic scores in employment decisions. FCRA and ECOA are unchanged; the interpretive gloss is gone. | In force |
| NYC LL144Employers and employment agencies using an automated employment decision tool for New York City candidates must commission an independent bias audit within a year of use, publish a summary of the results, and give candidates advance notice. | In force |
| NIST AI RMFVoluntary framework structured around Govern, Map, Measure and Manage. The de facto reference for US AI governance programmes, and frequently named in contracts and in state law — which is how a voluntary framework becomes a contractual obligation. | In force |
| M-25-21Governs federal agency use of AI, including high-impact AI risk management practices and Chief AI Officer roles. Replaced M-24-10. Binds the agency, not its vendor — but it is what the agency will push into the contract. | In force |
| M-25-22Sets federal AI acquisition policy including performance tracking, risk management and vendor-lock-in avoidance. Replaced M-24-18. The operative document for a vendor selling AI to a federal agency. | In force |
| M-26-04Implements EO 14319’s Unbiased AI Principles for federal large-language-model procurement. A vendor selling language models to federal agencies has to meet its truth-seeking and ideological-neutrality terms. | In force |
| GLBA Safeguards RuleRequires financial institutions to maintain a written information security programme with risk assessment, access controls, encryption, incident response and service-provider oversight. A model vendor handling customer financial information is a service provider under it. | In force |
| TAKE IT DOWN ActCriminalises nonconsensual publication of intimate visual depictions including computer-generated ones, and requires covered platforms to establish a notice-and-removal process. It reaches any product that can generate or host synthetic intimate imagery. | In force |
| Texas prohibited technologiesAdds a set of named applications, DeepSeek among them, to the state’s prohibited technologies list for state employees and contractors, covering state-owned devices and personal devices used for state work. A device and procurement rule, not a restriction on private use. | In force |
| TRAIGARegulates development and deployment of AI systems in Texas through intent-based prohibitions, government-use restrictions and an AI regulatory sandbox, with civil penalties enforced exclusively by the Attorney General. It also amended the state biometric statute. | In force |
| Virginia EO 46The Virginia IT Agency lists Executive Order 46 among the Commonwealth’s AI governance instruments. It prohibits the DeepSeek application on devices that access Commonwealth of Virginia networks or data, which reaches contractor equipment as well as state equipment. | In force |
03Common enterprise issues
Bias and fairness
The federal AI hiring guidance you remember is gone
The EEOC’s 2023 Title VII technical assistance on algorithmic decision-making tools and its AI fairness initiative page both now return 404, and EO 14281 directs agencies to deprioritise disparate-impact enforcement. Title VII itself is unchanged — the liability did not go away, only the guidance and the enforcement priority. The work runs through state law and private litigation.
Sector rules
The CFPB’s algorithmic-credit circulars were withdrawn
Circular 2022-03 on adverse-action notices for credit decisions based on complex algorithms and Circular 2024-06 on algorithmic scores in employment decisions were both withdrawn in May 2025. FCRA and ECOA still apply; the interpretive gloss that made the AI application explicit does not, so the reasoning has to be rebuilt from the statutes.
Cross-border transfers
28 CFR Part 202 is about vendor nationality, not data residency
The bulk sensitive data rule turns on whether a covered person can access the data, which means the location of support engineers, the ownership of the vendor and the identity of subprocessors. A US-region endpoint proves nothing about it, and most vendor questionnaires do not ask.
Automated decision-making
The binding AI duties are state duties, and they diverge
California’s ADMT regulations, Colorado’s 2027 automated decision-making statute, Illinois’s human rights amendment, New York City’s bias audit and Connecticut’s 2026 act do not agree with each other. Design to the strictest rule that reaches you, and watch the federal preemption litigation rather than assuming it will succeed.
Sensitive data
Biometric features created inside an AI pipeline
Illinois BIPA and the Texas biometric statute attach to face, voice and fingerprint identifiers, including ones a model derives rather than a form collects. Speaker diarisation, face matching in document processing and voice authentication all create them, usually without anyone deciding to.
Transparency
Federal AI transparency duties are essentially absent
The operative disclosure obligations for private-sector AI are state law — California’s training-data and provenance statutes, Utah’s generative AI disclosure, Colorado’s consumer notice. There is no federal duty to tell a person that AI was involved, so a national product ends up designing to the strictest state.
04Vendor restrictions
Restrictions we have written down and the page each one must be checked against. A restriction becomes a verified claim only once the sync job has fetched that page and found the phrase it declares; until then it is an editorial note with a link, and says so.
No vendor restriction has been recorded for this jurisdiction.
05Stacks with notes for this jurisdiction
No published stack carries a compliance note for this jurisdiction yet.
06Evidence
Every instrument above that we have fetched and anchored carries a footnote. The rest link to their primary source but have not been fetched and hashed yet, and are marked ASSESSMENT rather than FACT.
No sources were recorded for this answer. Nothing on this page should be treated as verified.
Improve this page
Sign in to contribute
From the field
0 deployments · 0 questions
Nobody has reported deploying this here yet, and no question has been opened against this page. Both appear once a reviewer accepts them.