AI, Automation & Algorithmic Systems

Legal obligations when building or deploying AI systems

Overview

AI regulation is shifting from theory to enforcement. Depending on the impact AI has in your decision making and user experience, these regulations may apply to your company. In the United States, more than a thousand AI related bills were introduced into state legislatures in 2025 with about 10% of them passing and being enacted into law. Federally, the FTC has issued guidance on AI and deceptive practices and NIST published its AI Risk Management Framework.

The central organizing concept in most AI regulation is risk classification. Laws distinguish between AI systems that pose higher risk (because they make consequential decisions about employment, credit, housing, healthcare, or critical infrastructure) and systems that pose lower risk. Higher-risk systems face more demanding obligations: impact assessments, human oversight requirements, transparency disclosures, bias auditing. Understanding where your AI system falls on the risk spectrum is the first compliance question to answer.

Federal Laws

Federal Laws

Statutes with broad authority over AI-related business practices
Federal
Communications Decency Act Section 230
Section 230 — 47 U.S.C. § 230
Section 230 provides significant immunity to online platforms for third-party content posted by users. It is particularly relevant to AI chat systems, social platforms, marketplaces, moderation systems, and products involving user-generated or AI-assisted content, although important limitations and ongoing legal challenges exist.
Last updated May 31, 2026
Federal
FTC Act Section 5
FTC Act — 15 U.S.C. § 45
Section 5 prohibits unfair or deceptive acts or practices in commerce and serves as the FTC's primary authority for regulating deceptive AI claims, unfair automated systems, and problematic data practices. It applies broadly to technology companies making representations about AI capabilities, automation, security, personalization, or algorithmic decision-making.
Last updated May 31, 2026

Federal Guidance & Frameworks

Agency guidance, executive directives, and risk frameworks shaping AI compliance expectations
NIST AI Risk Management Framework
NIST AI Risk Management Framework
NIST AI RMF
The NIST AI Risk Management Framework provides a widely used structure for identifying and managing AI-related risks, including bias, reliability, explainability, and governance concerns. Although voluntary, it is increasingly referenced in enterprise contracts, cybersecurity reviews, and government procurement — making it practically important for any company selling AI-powered products to larger organizations or government agencies.
View Guide

Other Federal Laws

Federal
TAKE IT DOWN Act
TAKE IT DOWN Act — Pub. L. 119-10
Federal law criminalizing the nonconsensual publication of intimate deepfake images and requiring platforms to remove such content within 48 hours of a victim's request. Applies to any platform hosting user-generated content.
Last updated June 28, 2026

Browse by State

Browse by Country

How Jurisdictions Differ

The EU AI Act is extraterritorial. If your AI system is used in the EU or its output is used there, the law may apply regardless of where you're located. US state laws are generally narrower in scope and focus on specific use cases (hiring, consumer decisions) rather than AI broadly. The key differences across state laws are: what qualifies as "high risk," what obligations attach (audit vs. disclosure vs. impact assessment), and whether there's a private right of action or only agency enforcement.

Related Articles

More articles coming soon.

Press Enter to go · ESC to close · Press / to open