Legal obligations when building or deploying AI systems
AI regulation is shifting from theory to enforcement. Depending on the impact AI has in your decision making and user experience, these regulations may apply to your company. In the United States, more than a thousand AI related bills were introduced into state legislatures in 2025 with about 10% of them passing and being enacted into law. Federally, the FTC has issued guidance on AI and deceptive practices and NIST published its AI Risk Management Framework.
The central organizing concept in most AI regulation is risk classification. Laws distinguish between AI systems that pose higher risk (because they make consequential decisions about employment, credit, housing, healthcare, or critical infrastructure) and systems that pose lower risk. Higher-risk systems face more demanding obligations: impact assessments, human oversight requirements, transparency disclosures, bias auditing. Understanding where your AI system falls on the risk spectrum is the first compliance question to answer.