As artificial intelligence becomes more advanced, and more integrated into our daily lives, government entities are realizing the need to regulate its use for consumers’ and citizens’ safety. New government laws are continually being introduced, and organizations will soon find themselves trying to accommodate multiple laws that aren’t aligned with one another.
In both the United States and the European Union, AI laws and regulations have already been enacted that affect your business today — even if you aren’t located within their jurisdictions. Failure to comply with these regulations could result in millions of dollars of fines for your organization.
Let’s take a look at several of the most relevant laws you need to pay attention to.
Federal AI Regulations in the U.S.
The United States doesn’t have a federal-level law regulating artificial intelligence — yet. But two primary governing arms of AI regulation in the United States are the federal Executive Order and the Federal Trade Commission (FTC). These two entities are actively laying the foundation for eventual federal AI regulations — and the FTC in particular isn’t taking prisoners.
Executive Order: “Promoting Advanced Artificial Intelligence Innovation and Security”
The closest thing to a federal-level edict is the Executive Order, “Promoting Advanced Artificial Intelligence Innovation and Security.” Newly signed on June 2, 2026, key provisions within this directive include a frontier model framework that directs federal agencies, including the NSA and CISA, to put together classified benchmarks for advanced AI. It also establishes a voluntary process for developers to grant the government early access to covered frontier models for up to 30 days prior to public release.
An AI frontier model is a very large, general-purpose AI system that represents the bleeding edge or state-of-the-art in AI technology. These frontier models are trained on vast datasets, often costing tens to hundreds of millions of dollars. They possess advanced reasoning and planning capabilities for predictive work, multi-step workflows, debugging code, and solving complex novel problems. They can also act as digital agents that use external tools, call APIs, and trigger autonomous actions.
The Executive Order pushes for the creation of an AI cybersecurity clearinghouse. This is a voluntary collaboration with the AI industry and critical infrastructure operators to coordinate vulnerability scanning, patch distribution, and threat validation, creating a central repository fed by multiple organizations.
From a defense perspective, it requires immediate action from the Department of War and civilian agencies to prioritize AI cyber defenses for national security systems.
Finally, the executive order includes a criminal enforcement arm, directing the Attorney General to prioritize the enforcement of federal criminal statutes against actors using AI to breach or damage IT systems.
No AI Policy? Your Company Is Flirting with Disaster
Federal Trade Commission (FTC) Enforcement
The FTC aggressively monitors Section 5 of the FTC Act, which broadly prohibits unfair or deceptive acts or practices in or affecting commerce. This broad mandate is gaining focus in the AI space, specifically targeting deceptive practices — where organizations exaggerate or lie about their AI capabilities — and unfairness, where harmful algorithmic deployment occurs.
Under algorithmic discrimination and unfairness, the agency scrutinizes AI deployments that harm consumers financially or reputationally. For example, the FTC has taken action against retailers for flawed uses of AI facial surveillance, mandating comprehensive algorithmic fairness programs.
The FTC is also targeting developers and businesses that weaponize AI for fraud by creating neutral AI tools, like text generators, that are designed and marketed in ways that facilitate fraud, phishing, and consumer deception.
The enforcement arm of the FTC is substantial, aggressive, and highly capable of tacking an organization to the wall. They are not to be trifled with. When the FTC pulls the trigger, they wield a substantial, aggressive club designed to condition the entire industry’s behavior.
U.S. State Level Regulations
Several states have passed multiple regulations that likely impact your company, even if you aren’t located in those states. While a handful of states like Connecticut, New York, Texas, and Illinois have their own state-level rules, California has historically led the legislative charge, and the topic of AI is no different.
If your business hires remote workers, those state-level rules and regulations become directly applicable to your organization. Furthermore, if you serve people or organizations located within those states, you’re under their jurisdiction.
Automated Decision Systems Act (SB 947)
If passed, the pending “No Robo Bosses” legislation will prohibit employers from relying solely on an automated decision system (ADS) for the disciplinary termination, suspension, or deactivation of a worker. It mandates meaningful human oversight and transparency notices, requiring a real, live human being to independently investigate and corroborate data before taking adverse action.
This human review is a critical safeguard because AI systems are infamously not always accurate and can fabricate or even invent data.
The act also restricts predictive behavior profiling, banning the collection of personal data to profile future behavior as a basis for employment decisions. Furthermore, it establishes worker data access rights, allowing impacted workers to request a copy of their data used by the ADS from the preceding 12 months, and requires employers to provide timely, plain written language notices following any disciplinary or termination action.
Transparency in Frontier AI Act (SB 53)
The Transparency in Frontier AI Act requires developers of high-power frontier AI models to assess, mitigate, and report potential catastrophic risks. Requirements include a publicly posted annual framework detailing how the company manages and mitigates catastrophic risk, as well as transparency reports published before deployment detailing model capabilities, limitations, and risk assessments — including third-party evaluations.
A critical incident reporting component requires developers to notify the California Office of Emergency Services within 24 hours of any immediate safety risk. Built-in whistleblower protections mandate anonymous reporting channels and prohibit retaliation against staff reporting risks. The California Attorney General enforces the law with civil penalties for non-compliance up to $1 million per violation.
Your Company’s AI Adoption Is a Security Nightmare
AI Training Data Transparency Act (AB 2013)
This act requires developers of generative AI systems to post detailed documentation of their training datasets on their public websites to give consumers and creators greater visibility into how models are constructed.
Disclosures must include a high-level summary and specific categories of information about training, testing, and fine-tuning datasets, including the source owner, methods of acquiring or licensing data, dataset characteristics, volume, timelines for collection, and whether the datasets include personal information, copyrighted material, trademarks, or patents.
The act contains narrow exemptions for AI used exclusively for security and integrity detection, national airspace operations, or specific national security and defense purposes to protect critical infrastructure. Developers must update this documentation whenever substantial modifications or fine-tuning materially alter system performance.
Major developers like OpenAI, Anthropic, and Google have already begun publishing this documentation.
AI Transparency Act (SB 942)
Targeting AI-generated content and deep fakes, this act requires developers of large-scale generative AI platforms to embed hidden provenance watermarks (latent disclosure) using invisible, machine-readable metadata or watermarking to identify content as AI-generated. It also mandates a manifest disclosure element, requiring systems to offer options to attach visible labels or watermarks directly onto generated content. Developers must provide free, publicly accessible tools on their websites to allow anyone to upload content to determine if it was AI-generated.
The act creates platform and device obligations: hosting platforms and social media sites need to display or make this metadata easily accessible to users, and device manufacturers (such as camera makers) must include options for embedding that data directly into captured imagery.
This governing framework is designed to separate real content from fake content, protecting against devastating uses like deep fakes of political figures, human trafficking, or simulated atrocities.
Companion Chatbot Law (SB 243)
The Companion Chatbot Law regulates AI platforms designed to provide human-like social interaction. It requires explicit AI disclosures, crisis prevention protocols, and safeguards for the protection of minors.
Under the AI disclosure mandate, platforms must clearly notify users if a reasonable person could be misled into believing they are talking to a human. For known minors, platforms must issue conspicuous reminders every three hours stating that the chatbot is AI-generated, and encourage them to take a break.
Operators must publish and maintain safety protocols for the prevention of self-harm and suicidal ideation, providing immediate referrals to crisis resources. Age-appropriate guardrails must use reasonable measures to prevent minors from receiving sexually explicit content or inappropriate suggestions.
Additionally, starting in 2027, operators must submit annual reports detailing specific statistics, such as the number of crisis referrals made, to the California Department of Public Health to protect minors from dangerous or manipulative algorithmic interactions.
State AI Laws Apply to Your Organization
These state regulations apply across the board. They impact product manufacturers (such as makers of 360 cameras, GoPros, and doorbell cameras), businesses generating AI models, and any business integrating AI models or chatbot capabilities into their own SaaS platforms or products — even if the platform is integrating AI functionality through a third-party vendor.
While it may not directly impact a traditional local plumber writing invoices on paper, nearly anyone running a SaaS platform or integrating chatbot capabilities needs to pay attention to their responsibilities.
The European Union (EU) Frameworks
Just as you need to pay attention to every state AI regulation in the U.S., you may also need to comply with E.U. AI laws — especially if your organization has customers, employees, or partners within the E.U. Be sure you’re familiar with these regulatory requirements for artificial intelligence.
EU Artificial Intelligence Act
The EU Artificial Intelligence Act is the world’s first comprehensive legal framework for AI. It utilizes a risk-based approach designed to ensure AI is safe, transparent, and respectful of fundamental human rights. The law applies to any AI developer, deployer, or provider whose services or outputs are used within the EU.
Non-compliance penalties are substantial, reaching up to 35 million euro or 7% of the organizations’ annual global revenue.
This law establishes four distinct tiers of risk:
Unacceptable Risk: Systems that threaten human safety, livelihoods, or rights are strictly prohibited and banned. This includes cognitive manipulation, untargeted scraping of facial images from the internet or CCTV, social scoring, biometric categorization of sensitive traits, and emotion recognition within workplaces and educational institutions.
High Risk: Strictly regulated use cases in critical areas like healthcare, education, employment, law enforcement, and critical infrastructure. These require mandatory risk assessments, high-quality data governance, detailed documentation, human oversight, and continuous post-market monitoring.
Limited or Specific Risk: Subject to transparency obligations. AI systems interacting directly with people or generating synthetic media (such as deep fakes) must clearly label content and disclose to users that they are interacting with an AI.
Minimal Risk: The vast majority of AI systems in use, such as video games and spam filters, fall into this tier and remain largely unregulated to foster innovation.
AI-powered Cyberattacks Are Coming for Your Data. How Prepared Are You?
EU Cyber Resilience Act
This comprehensive framework mandates baseline cybersecurity and vulnerability handling for almost all hardware and software products with digital elements sold in the EU. This includes smart devices, operating systems, mobile apps, and industrial controllers.
The goal is to shift security responsibility to manufacturers and developers, requiring security by design across the product lifecycle to protect against unauthorized access, ensure data confidentiality and integrity, minimize attack surfaces, and for devices to ship with secure defaults.
Compliance is verified through conformity assessments. High-risk, important, or critical products require third-party assessments, while standard connected devices can rely on internal manufacturer checks.
There is an open-source exception to this regulation: to avoid stifling innovation, stewards and non-commercial developers of free and open-source software are largely exempted. However, commercial vendors utilizing open-source software in proprietary products remain fully responsible for the overall security of the hardware or software they generate. If you integrate open-source software into your proprietary platform, you take responsibility for its overall security.
Violations carry enforcement penalties up to 15 million euro or 2.5% of the organization’s annual global revenue, alongside highly impactful long-term market bans.
The Outlook for Governmental AI Regulation
These moves in government regulation are just the beginning, and they are critical for the protection of organizations and individuals. The EU has acted quicker and they have a more strategic approach to a unified government level without relying on a fragmented patchwork of individual state rules.
In the United States, the federal government needs to catch up and develop regulations with substantial teeth that can be actively modified, morphed, and enhanced as technology evolves.
It’s a massive risk to leave AI governance in the hands of individual organizations. We have seen similar frontiers before with the early internet, the dot-com bubbles, APIs, web services, and mobile applications — but AI poses a unique risk that demands serious oversight.
While the FTC’s enforcement capabilities and state-level laws are helpful, the federal Executive Order acts as a set of directives rather than an enforcement arm, and the FTC enforcement process runs painfully slow. Relying on states to continuously pop up their own individual regulations creates unnecessary operational complexity, so it’s critical to establish a unified federal framework with substantial consequences.

Get industry insider expertise delivered to your inbox
Subscribe to the TCT blog
