Regulation
US State AI Laws: What UK and EU Compliance Teams Must Do
American AI rules are arriving through state legislatures and federal enforcement, not one statute. A practical guide to when UK and EU organisations are caught, and what to build.
A UK insurer licenses a CV-screening tool from a Californian vendor. A Dublin SaaS firm sells a customer-scoring feature to a business in Denver. A London agency fills vacancies for a client's New York office. None of the three has a US legal entity, and none of them budgeted for American AI compliance. All three are within reach of it, because most of the state AI laws now in force attach to where the affected person sits, not where the company is registered.
That is the practical shape of what people mean when they say the US is advancing AI safety through state and federal action. There is no single American equivalent of the EU AI Act to read once and file. There are two engines running at different speeds, producing overlapping duties in different vocabularies. For a compliance officer, risk lead or DPO in the UK or EU, the useful question is not the abstract one about jurisdiction. It is narrower: which of our systems touch US individuals, which of our vendors are subject to these rules, and what evidence would we produce if a customer, a regulator or a plaintiff's lawyer asked us tomorrow.
Two engines, not one regime
The first engine is state legislation. Colorado enacted an AI statute built around algorithmic discrimination in consequential decisions — credit, employment, housing, insurance, education, healthcare, legal services — placing distinct duties on developers and on deployers, including impact assessments, notice to affected individuals and a duty of reasonable care. Its commencement has already been revisited by the legislature, so check the current position before relying on any timetable. California has legislated on generative AI training-data disclosure, on labelling AI-generated content, and on frontier model safety reporting, while its privacy regulator has adopted rules on automated decision-making technology carrying notice, access and opt-out rights. Illinois has amended its civil rights law to restrict employment uses of AI that produce discriminatory effects, including proxy variables. Utah imposes disclosure duties when generative AI interacts with consumers, tightened for regulated occupations. Texas has taken an intent-based prohibition approach paired with a regulatory sandbox. New York City — a city, not a state, which is precisely the point about granularity — requires an annual independent bias audit of automated employment decision tools, publication of a summary of the results, and advance notice to candidates.
The second engine is federal enforcement of existing law. The Federal Trade Commission treats deceptive AI performance claims and unfair AI-driven practices under its general consumer protection powers. The Equal Employment Opportunity Commission applies established anti-discrimination law to selection tools. The Food and Drug Administration regulates AI-enabled medical devices. Securities regulators have pursued overstated AI capabilities in investor disclosures. Alongside enforcement, NIST publishes voluntary standards — the AI Risk Management Framework, organised around Govern, Map, Measure and Manage, and its generative AI profile. Voluntary is not the same as optional in practice: those functions increasingly appear as contractual warranties in US enterprise procurement.
The direction of travel is not linear. Executive orders on AI have been issued, revoked and replaced as administrations change. Proposals to pre-empt state AI laws have been floated and contested. Planning around any single political outcome is a poor bet. Plan around the floor that has already been laid: discrimination law, consumer protection law, and sectoral regulation, all of which apply to AI whatever happens next.
Why a UK or EU organisation is already in scope
Three routes bring these rules to your desk, and they are worth checking separately because they fail in different ways.
The individual route. State duties typically bite on decisions about residents of that state. If your system helps decide something consequential about a person in Colorado, Illinois or New York City, your location is largely irrelevant. Recruitment, insurance underwriting, credit and tenant screening are the common exposures.
The vendor route. Your model or tooling supplier is probably American. As their obligations change, so do their documentation, contract terms, retention practices and model behaviour. You need their artefacts anyway — technical documentation, training-data statements, evaluation results — because your own EU AI Act and UK GDPR positions depend on them. A supplier who cannot produce those in the US will not produce them for you either.
The contract route. This one usually arrives first. US enterprise buyers push AI warranties, audit rights, incident notification windows and NIST-aligned attestations into supplier agreements well ahead of statutory deadlines. Many UK and EU teams first encounter American AI regulation as a clause in a renewal they have three weeks to sign.
The overlap is larger than the gap
The strategic error is running a separate US programme. The underlying control set is substantially the same as the one you need for the EU AI Act and UK GDPR; what differs is terminology, thresholds and who receives the paperwork. Build once, map many.
| Control | Typical US expression | Nearest UK/EU anchor | Shared evidence |
|---|---|---|---|
| Inventory and classification | Deployer duties triggered by "consequential decisions" | AI Act risk tiers; records of processing under Article 30 | One AI register: purpose, decision type, jurisdictions of affected people |
| Impact assessment | Deployer impact assessments for high-risk systems | DPIA; fundamental rights impact assessment where required | Single assessment template with jurisdiction annexes |
| Discrimination testing | Independent bias audit of employment tools | Equality Act 2010; AI Act data governance duties | Subgroup performance metrics, methodology, remediation log |
| Notice to individuals | Pre-use notice and opt-out for automated decisions | Articles 13, 14 and 22 UK/EU GDPR; AI Act transparency | Versioned notice library tied to each system |
| Provider transparency | Training-data and content-provenance disclosure | AI Act provider technical documentation | Model cards, provenance statements, version history |
| Incident handling | Safety incident reporting to a state authority | AI Act serious-incident reporting; personal data breach rules | One incident taxonomy, one log, one clock |
A working checklist
- Every AI-assisted system that influences a decision about a person is on a register with a named owner — not a team, a person.
- The register records the jurisdictions of the people affected, not just where the system is hosted.
- Each entry states whether a human can realistically override the output, and whether anyone ever has.
- Discrimination testing exists for selection, scoring and eligibility uses, with the method written down and results retained.
- Individual-facing notices are current, versioned, and match what the system actually does.
- Supplier contracts contain documentation rights, change notification and incident notification with a defined window.
- You hold, rather than merely trust, your suppliers' model documentation and evaluation summaries.
- Logs are retained long enough to reconstruct a contested decision after a complaint arrives, not merely for operational debugging.
- Someone owns horizon scanning for state-level change, with a named review cadence.
- Prohibited and restricted uses are written into an internal policy staff have actually read.
Where this stops, and when to get advice
This guide is an orientation, not a legal opinion, and it has real limits. State AI law is moving quickly, effective dates have shifted, and pre-emption remains contested — anything time-sensitive must be verified against the current text rather than a summary. Enforcement thresholds, cure periods and private rights of action vary by state and are not treated here. Nor does this cover the sectoral layers that may dominate your position: financial services, medical devices, defence, or public-sector procurement each bring their own regime.
For proportionality of penalties, the anchor most UK and EU boards already understand is their own: under the EU AI Act, up to 7% of global annual turnover for prohibited practices and up to 3% for most other obligations, with fixed-sum alternatives where higher; under UK and EU GDPR, up to 4%. US exposure is structured differently — state attorney general enforcement, sectoral regulators, and private litigation — and does not map neatly onto a percentage.
Take specialist advice where you have a US entity or employees, where you make consequential decisions about US residents at scale, where you develop rather than merely deploy models, where a contract asks you to warrant compliance with named US laws, or where a complaint or enforcement contact has already arrived. In practice, most teams need less legal input than they fear and more evidence discipline than they expect. The register, the testing records and the decision logs are what you will be judged on — in any jurisdiction.
- US AI regulation
- State law
- EU AI Act
- Vendor management
- Compliance operations
- Automated decisions