Regulation
US AI Regulation: What UK and EU Compliance Teams Must Actually Do
The US has no single AI statute, but its patchwork of state laws and sector regulators still lands on UK and EU compliance teams through vendors, group operations and procurement. Here is what to do.
A UK insurer's HR team buys a CV-screening tool from a Delaware-registered vendor. The vendor's documentation pack is excellent — for a New York City bias audit and a Colorado impact assessment. It says almost nothing that helps the insurer meet its own deployer duties under the EU AI Act, and nothing at all about the lawful basis for the automated processing under UK GDPR. The procurement team files the pack as evidence. The DPO never sees it. Eighteen months later a rejected candidate asks how the decision was made, and the honest answer is that nobody in the organisation can say.
That gap is what "US AI regulation" means in practice for a mid-size UK or EU organisation. It is rarely a question of whether an American statute applies to you directly. It is that the AI supply chain is overwhelmingly US-built, US regulation shapes what your suppliers document and disclose, and the evidence you need for your own regulators is downstream of decisions made in Sacramento, Denver and Washington. Treating US developments as foreign news is how compliance teams end up holding a folder of the wrong paperwork.
There is no "US AI Act", and that is the difficulty
Anyone expecting an American analogue to the EU AI Act — one statute, one risk taxonomy, one set of dates — will be waiting a long time. What exists instead is three overlapping layers.
State legislatures have moved fastest, producing statutes that differ in scope, definitions and enforcement. Federal sector regulators apply laws that long predate generative AI: consumer protection, employment discrimination, credit, securities disclosure, medical devices. Federal executive direction has swung hard. An earlier executive order setting out safety, testing and reporting expectations was rescinded and replaced by a deregulatory, innovation-first posture, with agency guidance rewritten to match. Attempts to pre-empt state AI laws through federal legislation have not succeeded so far, and pre-emption remains genuinely contested.
The planning consequence matters more than the politics: plan for divergence, not convergence. A control set that only works if the US settles on a single national standard is a control set built on a hope.
Three routes by which US rules reach your desk
| Route | What triggers it | What it lands on you |
|---|---|---|
| Supply chain | Your AI vendor, model provider or embedded SaaS feature is US-domiciled | The documentation, model cards and contract terms you can obtain are shaped by US disclosure rules — which may not cover what the EU AI Act expects a deployer to hold |
| Own operations | US subsidiary, US-based staff, US customers, or processing about US residents | State statutes on employment screening, biometrics, insurance and automated decision-making apply to your own conduct, not your vendor's |
| Selling into the US | Bidding for US federal, state or large enterprise contracts | Procurement flows down NIST-shaped questionnaires, testing evidence and incident-reporting commitments into your contract, whatever the law says |
What is actually enforceable there today
The enforceable edge in the US is mostly not "AI law". It is existing doctrine applied to AI systems, which is precisely why it should feel familiar to a UK or EU practitioner.
The Federal Trade Commission uses its long-standing power over unfair and deceptive practices against overstated AI capability claims — so-called AI washing — and has, in past matters, required the deletion of models and algorithms built from improperly collected data. That remedy should concentrate minds more than any monetary penalty: it can destroy the asset. Employment regulators apply existing discrimination law to hiring tools regardless of who built them. Credit law requires a lender to give specific, accurate reasons for an adverse decision; the complexity of the model is not a defence, and that obligation sits in statute rather than depending on any one agency's current enthusiasm.
On top of that sits state legislation. Several themes recur: bias auditing and candidate notice for automated employment decision tools; consent requirements for biometric data, with Illinois notable for a private right of action that has driven substantial class litigation; duties of reasonable care on both developers and deployers of high-risk systems to guard against algorithmic discrimination, backed by impact assessments and consumer notice; training-data and provenance transparency for generative systems; and disclosure obligations when a consumer is interacting with a machine in a regulated occupation. Commencement dates in this area have been amended more than once, so verify the current position against the primary source before you build a plan around any single date.
The voluntary layer matters commercially. The NIST AI Risk Management Framework — organised around Govern, Map, Measure and Manage — carries no penalty for ignoring it, but it is the vocabulary US counterparties use in diligence questionnaires. If you want one management system that speaks to both audiences, ISO/IEC 42001 is certifiable and maps onto that vocabulary reasonably cleanly.
Where this overlaps with what you already owe
Most of the work is shared. The EU AI Act requires deployers of high-risk systems to use them in line with the provider's instructions, assign human oversight to competent people with the authority to act, ensure input data is relevant, retain logs, inform affected workers, and monitor operation. It also expects organisations to ensure a sufficient level of AI literacy among staff dealing with these systems. UK obligations run through UK GDPR — lawful basis, fairness, transparency, the restrictions on solely automated decisions with legal or similarly significant effects, and DPIAs — with sector regulators using existing powers rather than new ones.
Build the control set around evidence rather than around a named law and it will serve several regimes at once: a system inventory, a risk classification, an impact assessment, a named human owner, retained logs, a tested incident route, and a vendor evidence file. Only the paperwork wrapper changes per jurisdiction.
The exposure is asymmetric and worth stating plainly. Under the EU AI Act, penalties reach up to 7% of global turnover for prohibited practices and up to 3% for most other obligations; UK and EU GDPR reach up to 4%. US state regimes typically enforce through attorneys general or existing consumer protection law, with the biometric statutes as the notable private-litigation exception. In most mid-size organisations the realistic first cost is not a fine at all — it is a stalled deal, a failed enterprise diligence questionnaire, or a contract you cannot sign because you cannot answer question fourteen.
Checklist: the next quarter
- A single inventory of AI systems in use, including features switched on inside SaaS you already licence — the assistant bolted onto your CRM counts.
- For each system, the jurisdiction of the people it affects, not the jurisdiction of the vendor.
- A named accountable owner per system, at a grade that can order it switched off.
- The provider's instructions for use, retained and actually read, for anything you classify as high risk.
- Evidence of what testing the vendor performed, on which population, and when it was last repeated.
- Log retention that survives the vendor relationship ending.
- A defined human-review step for any decision with a legal or similarly significant effect on a person.
- Contract terms giving you disclosure on model changes, incidents and sub-processors — silence here is the most common gap.
- A tested route for an AI incident that reaches someone with authority within hours, not a mailbox.
- Training records for the staff who operate these systems, sufficient to evidence the AI literacy expectation.
- A watch item, owned by a named person, for US state commencement dates that affect your group operations.
Limits of this guide
This is orientation, not legal advice, and it is deliberately general where the law is moving. US state statutes are amended frequently and commencement dates have already shifted; check primary sources at the moment you act rather than relying on any secondary summary, including this one.
Several areas are out of scope here and need specialist input in their own right: US federal procurement obligations in detail; export controls affecting models and hardware; the copyright litigation over training data, which is unresolved and consequential; medical device regulation for clinical AI; prudential model risk management in financial services; the full automated-decision-making rules emerging under state privacy regimes; and the UK's own developing position.
Take specialist advice before deploying biometric processing in the US, before running a hiring tool across multiple states, and for anything in credit, insurance underwriting, health or services aimed at children. Take data protection advice specifically on transfers of personal data into US-hosted models — that is a transfer question and a purpose-limitation question before it is an AI question, and it is the one most often missed because the tool arrived as a feature rather than as a project.
- US AI regulation
- EU AI Act
- NIST AI RMF
- vendor due diligence
- AI governance
- DPO