There is still no comprehensive federal AI statute. Instead, teams face executive orders, a preemption push against state laws, and sector regulators — here is the map.
This article is educational guidance, not legal advice. AI law in the United States is changing quickly and varies by state and sector. Confirm current statutory text, effective dates, and rulemaking with primary sources and qualified counsel before making compliance decisions.As of mid-2026, the United States still has no comprehensive federal AI statute. Federal AI policy runs through executive orders, agency guidance, standards bodies, and sector regulators — and, increasingly, through an active effort to preempt or challenge state AI laws. For teams operating nationwide, the practical result is a two-front problem: comply with a growing set of state laws while tracking a federal posture aimed at overriding some of them. This article maps the moving parts and what to monitor.
The executive-branch posture
The current administration's AI strategy emphasizes accelerating innovation and reducing regulatory friction. Key instruments:
- EO 14179 (January 2025), “Removing Barriers to American Leadership in Artificial Intelligence,” which rescinded the prior administration's 2023 AI executive order and reoriented policy toward deregulation and competitiveness.
- “Winning the Race: America's AI Action Plan” (July 2025), a blueprint of 90+ federal actions across three pillars — accelerating innovation, building AI infrastructure, and leading in international AI diplomacy and security.
- A December 2025 executive order challenging state AI laws (discussed below).
- A June 2026 executive order shifting emphasis toward national-security uses and oversight of advanced AI in the national-security enterprise.
The federal-preemption push
The most consequential 2025–26 development for compliance teams is the federal effort to constrain state AI regulation. It has two chapters.
The failed legislative moratorium
In 2025, Congress considered a 10-year moratorium that would have barred states from enforcing many AI laws, tied to federal broadband (BEAD) funding. On July 1, 2025, the Senate stripped the moratorium from the budget reconciliation bill in a 99–1 vote. The bill (the One Big Beautiful Bill Act) passed without it and was signed July 4, 2025. States retained their authority to regulate AI.
The executive-order route
Having lost the legislative moratorium, the administration pursued preemption through executive action. An executive order signed December 11, 2025 (“Ensuring a National Policy Framework for Artificial Intelligence”) directs several steps:
- A DOJ AI Litigation Task Force (standing up from January 10, 2026) to challenge state AI laws in federal court, largely on dormant Commerce Clause and preemption theories;
- A Commerce Department review of state AI laws (due around March 11, 2026) identifying those deemed burdensome or conflicting with federal policy;
- An FTC policy statement direction addressing whether certain state-mandated bias-mitigation requirements amount to deceptive practices;
- Conditioning of certain federal broadband (BEAD) funding on the absence of “onerous” state AI laws;
- Direction for the FCC to consider federal AI reporting/disclosure standards.
An executive order cannot by itself repeal a state statute. State AI laws (Colorado, California, Texas, Illinois, and others) remain in effect and enforceable unless a court or Congress says otherwise. Continue complying with applicable state law while tracking the litigation.Standards and NIST
NIST remains the center of gravity for practical US AI governance guidance, even without a binding federal law:
- The NIST AI Risk Management Framework (AI RMF) and its Generative AI Profile remain the de facto reference for structuring AI risk programs, and are frequently cited in state laws and contracts.
- NIST's AI work now runs largely through the Center for AI Standards and Innovation (CAISI), the successor to the US AI Safety Institute, with a focus on evaluations, standards, and security.
- Federal procurement and agency-use guidance (via OMB memoranda) shapes how AI is bought and deployed inside the government and, indirectly, by its vendors.
Even where no statute forces it, aligning to the NIST AI RMF is a low-regret move: it maps onto state ADMT duties, EU AI Act expectations, and ISO/IEC 42001, so one control set serves multiple regimes.Sector regulators still apply
Existing federal agencies continue to apply their authorities to AI use in their domains, regardless of any general AI statute:
| Regulator | AI-relevant focus |
|---|---|
| FTC | Unfair/deceptive practices — false AI claims, biased or harmful automated decisions, data practices. |
| EEOC / DOL | Employment discrimination and the ADA as applied to hiring and HR algorithms. |
| CFPB / banking regulators | Fair lending (ECOA), adverse-action notices, and model risk in credit. |
| FDA | AI/ML in medical devices and clinical decision support. |
| SEC / FINRA | AI in trading, advice, disclosures, and “AI-washing” in investor communications. |
| Copyright Office / courts | Training-data and output copyright questions (ongoing litigation). |
Federal legislation to watch
Comprehensive federal AI legislation remains unlikely in the near term, but narrower bills recur — covering deepfakes and non-consensual intimate imagery, AI in elections, transparency/provenance, child safety, and national-security controls on compute and model exports. Any renewed federal preemption proposal is the single most important item for multi-state teams to watch, because it would reshape the state-law calculus overnight.
What US-operating teams should track
- State laws first: Colorado (SB 26-189, eff. Jan 1, 2027), California (SB 53, AB 2013, SB 942, CPPA ADMT), Texas (TRAIGA, eff. Jan 1, 2026), plus Illinois, Utah, and others. These are enforceable now or soon.
- The preemption litigation: outcomes from the DOJ AI Litigation Task Force and the Commerce/FTC actions could pause or narrow specific state provisions.
- NIST/CAISI outputs: updated AI RMF profiles and evaluation standards that will shape contracts and audits.
- Sector guidance: FTC, EEOC, CFPB, FDA, and SEC statements applicable to your use cases.
- Any revived federal moratorium or omnibus AI bill in Congress.
Operating principle for 2026: build to the strictest applicable state standard using the NIST AI RMF as your backbone. That posture is defensible under state law today and adapts quickly if a federal framework or preemption ruling changes the map.