← bylok.ink

Regulatory Tracker

AI Regulation Tracker

China, the United States, and the European Union — statutes, measures, standards, and what is coming next.

Updated 2026-07-31 · primary sources linked

State law19

New York RAISE Act — Responsible AI Safety and Education Act (S6953B, Ch. 699, as amended March 2026)

New York Legislature · 2027-01-01in force

Passed in June 2025, signed December 19, 2025 (Chapter 699), and finalized by a negotiated chapter amendment (S8828) signed March 27, 2026, the RAISE Act takes effect January 1, 2027. As amended it converges on California's SB 53 model: it binds 'large frontier developers' — those training frontier models with more than 10^26 integer or floating-point operations and with annual revenue above $500 million — requiring published safety frameworks, pre-deployment transparency reports, and critical-safety-incident reporting to the Department of Financial Services within 72 hours (24-hour law-enforcement notification where imminent danger exists), stricter than California's 15-day window. A new office within DFS receives reports and gains rulemaking authority; the Attorney General enforces with penalties up to $1 million for a first violation and $3 million for repeat violations.

  • Enacted but not yet operative — effective January 1, 2027
  • March 27, 2026 chapter amendment (S8828) replaced the original $100M-training-cost trigger with SB 53-style compute (>10^26 ops) plus $500M revenue thresholds and cut penalties from $10M/$30M to $1M/$3M
  • 72-hour incident reporting to DFS is the strictest frontier-AI reporting clock in US law (California allows 15 days)
  • Separate NY AI measures already bind: the LOADinG Act governs state-agency AI use, and NYC Local Law 144 has required bias audits of automated employment decision tools since July 2023
primary source →

Official NY Senate bill page (verified: signed Dec 19, 2025, Chapter 699; page reflects the original text). Chapter amendment verified via Wiley alert 'New York Finalizes RAISE Act for Frontier AI Models; Law Takes Effect January 1, 2027' (signed Mar 27, 2026; thresholds, DFS office, 72h/24h reporting, $1M/$3M penalties confirmed).

Colorado SB26-189 — Automated Decision-Making Technology Act (replacement for the Colorado AI Act)

Colorado General Assembly · 2026-08-12in force

Signed May 14, 2026, SB26-189 repeals and reenacts the Colorado AI Act as a much narrower disclosure-and-transparency law governing 'automated decision-making technology' (ADMT) used in consequential decisions such as employment, housing, insurance, and government benefits. It eliminates the 2024 law's duty of care against algorithmic discrimination, risk-management programs, impact assessments, and AG reporting, replacing them with pre-decision notice, post-adverse-decision disclosures within 30 days, data-correction and human-review rights, and developer documentation duties. The statute takes effect August 12, 2026 (enacted without a safety clause), with the substantive developer and deployer obligations operative January 1, 2027; the Colorado Attorney General enforces violations through the Colorado Consumer Protection Act, with a 60-day cure opportunity before enforcement actions filed before 2030.

  • Binds developers and deployers of ADMT used to make consequential decisions about Colorado consumers; obligations begin January 1, 2027
  • Drops the 2024 algorithmic-discrimination framework in favor of notice, disclosure, correction, and human-review rights
  • Developers must give deployers technical documentation on intended uses, training-data categories, and known limitations, and retain compliance records for three years
  • AG enforcement as a deceptive trade practice with no new private right of action; fault-based apportionment for discrimination liability; AG rulemaking due by Jan 1, 2027
primary source →

Official bill page (verified: 'Became Law', signed May 14, 2026; effective Aug 12, 2026 absent a safety clause; notice, disclosure, correction, and human-review provisions, developer documentation, CCPA enforcement, and no new private right of action all confirmed from the bill summary).

California SB 942 — California AI Transparency Act (as amended by AB 853)

California Legislature · 2026-08-02in force

SB 942 (signed September 19, 2024) requires 'covered providers' — publicly available generative AI systems with over 1 million monthly users accessible in California — to offer a free AI-detection tool and to embed latent (and offer manifest) provenance disclosures in AI-generated content. AB 853 (signed October 13, 2025) delayed the operative date from January 1, 2026 to August 2, 2026, aligning with the EU AI Act's Article 50 timeline, and extended obligations to large online platforms and generative AI hosting platforms (January 1, 2027) and capture-device manufacturers (January 1, 2028). Enforcement is by civil penalty of $5,000 per violation per day.

  • Provider obligations operative August 2, 2026; large-platform and hosting-platform duties January 1, 2027; capture-device duties January 1, 2028
  • Binds generative AI providers with >1M monthly users whose systems are publicly accessible in California
  • Requires free public AI-detection tools plus latent provenance/watermark disclosures in generated content
  • AB 853 expansion makes it the closest US analogue to EU AI Act content-provenance rules
primary source →

Official leginfo page for AB 853, which carries the operative amended text of SB 942 (verified: chaptered Oct 13, 2025; Aug 2, 2026 operative date and phased Jan 1, 2027 / Jan 1, 2028 platform and capture-device dates confirmed from the bill digest).

California 2026 landscape: session developments, SB 7 veto, and CPPA ADMT regulations

California Legislature · 2026-07news

As of July 2026 California has the deepest operative stack of state AI law: SB 53, AB 2013, and SB 243 took effect January 1, 2026, and SB 942/AB 853 becomes operative August 2, 2026. In October 2025 Governor Newsom vetoed SB 7 (the 'No Robo Bosses Act'), which would have required employer notice for automated decision-making in employment, and signed over a dozen narrower AI bills on chatbots, pricing algorithms, deepfakes, and digital replicas; separately, the California Privacy Protection Agency's automated decision-making technology (ADMT) regulations under the CCPA were finalized in 2025, with phased compliance dates (ADMT compliance obligations by January 1, 2027; risk-assessment submissions on later dates). The 2025-26 session runs through August 31, 2026, under open federal preemption pressure from the December 2025 executive order, which singles out California-style AI mandates for challenge.

  • SB 7 (employment ADS) vetoed October 2025 — no California AI-in-hiring statute yet; CPPA ADMT rules partially fill the gap
  • CPPA ADMT/risk-assessment regulations bind CCPA-covered businesses, with phased compliance dates (ADMT compliance by Jan 1, 2027; risk-assessment filings later)
  • Federal AI Litigation Task Force and funding leverage created by the Dec 11, 2025 EO explicitly target California-model state laws
primary source →

Secondary source (Latham & Watkins client alert, verified: published Oct 15, 2025, updated Oct 30, 2025; confirms SB 7 'No Robo Bosses Act' veto, AB 853 delay to Aug 2026, and the 2025 signing wave). Operative dates cross-verified against official leginfo bill pages; CPPA ADMT compliance dates should still be confirmed against cppa.ca.gov; pending 2026-session bills not individually verified.

State deepfake, election, and likeness laws — the pattern

Multiple state legislatures · 2026-06news

At least 28 states now have election-deepfake statutes, splitting into two models: disclosure mandates on AI-generated political media (e.g., Colorado, Utah, Oregon, Wisconsin, and California's surviving AB 730 approach) and outright prohibitions on materially deceptive synthetic media near elections (Minnesota, Michigan, Mississippi, Texas' pioneering 2019 SB 751). The prohibition model is faring worse in court: California's AB 2839 was struck down on First Amendment grounds and AB 2655 held preempted by Section 230 (Kohls v. Bonta, E.D. Cal. 2024-25), while Minnesota's ban survived preliminary-injunction review — the Eighth Circuit affirmed denial of the injunction on February 9, 2026 — but merits litigation continues (Kohls v. Ellison). A parallel wave covers non-consensual intimate imagery (near-universal among states, now backstopped federally by the TAKE IT DOWN Act) and digital-replica/likeness rights for performers (Tennessee's ELVIS Act, California AB 1836/AB 2602), which bind platforms, distributors, and contracting studios rather than model developers.

  • Disclosure-based election laws are surviving judicial review; flat prohibitions face the highest First Amendment risk
  • These laws bind distributors, platforms, campaigns, and individuals — generally not AI model developers
  • Likeness/digital-replica statutes create private rights of action for individuals and performers
  • The December 2025 federal preemption EO mostly spares this category, which even preemption advocates treat as legitimate state ground
primary source →

Secondary 50-state tracker used for the aggregate pattern (verified resolving; states 'at least 28' as of June 2026, disclosure-vs-prohibition split, and AB 2839's Aug 2025 permanent injunction confirmed on the page); individual state statutes are the official sources and counts are approximate. Kohls v. Ellison status (PI denial affirmed by the Eighth Circuit Feb 9, 2026; merits ongoing) verified via case reports.

Colorado repeals and replaces its AI Act with narrower ADMT law (SB 26-189)

Colorado General Assembly · 2026-05-14announced

Gov. Polis signed SB 26-189 ('Automated Decision-Making Technology') on May 14, 2026, repealing and reenacting the 2024 Colorado AI Act's high-risk framework as a transparency-focused regime for automated decision-making technology used in consequential decisions. The rewrite drops the duty of reasonable care against algorithmic discrimination, risk-management programs, and impact assessments, substituting clear notice at the point of interaction, post-adverse-decision disclosures within 30 days, and a right to meaningful human review and reconsideration. Substantive duties take effect January 1, 2027; violations are deceptive trade practices enforced by the attorney general, with a 60-day notice-and-cure period before January 1, 2030.

  • Retreat from the landmark 2024 algorithmic-discrimination model under litigation and federal pressure
  • Developer documentation duties and deployer notice/explanation/human-review duties from January 1, 2027
  • Violations are deceptive trade practices; AG enforcement with 60-day notice-and-cure (through 2029)
  • Replaces risk-management and impact-assessment mandates with transparency obligations
primary source →

Official Colorado General Assembly bill page (primary; fetched and verified — signing date, repeal-and-reenact structure, ADMT scope, notice/human-review duties, AG enforcement via the Colorado Consumer Protection Act, and 60-day cure all confirmed).

California SB 53 — Transparency in Frontier Artificial Intelligence Act (TFAIA)

California Legislature · 2026-01-01in force

Signed September 29, 2025 (Chapter 138) and effective January 1, 2026, TFAIA is the first enacted US law aimed at catastrophic risk from frontier AI. It binds 'frontier developers' (models trained with more than 10^26 integer or floating-point operations) and imposes heavier duties on 'large frontier developers' (frontier developers with over $500M annual revenue): publishing a frontier AI framework, per-model transparency reports, reporting critical safety incidents to the California Office of Emergency Services (within 15 days, or 24 hours where imminent danger exists), and whistleblower protections for AI-safety personnel. The Attorney General enforces with civil penalties up to $1 million per violation; the act also launches the CalCompute public compute consortium.

  • Binds frontier-model developers (>10^26 ops training compute); enhanced duties above $500M annual revenue
  • Requires published safety frameworks, transparency reports at deployment, and critical-safety-incident reporting to Cal OES (15 days; 24 hours if imminent danger)
  • Whistleblower protections plus mandatory internal anonymous reporting channels at large developers
  • Enacted one year after Governor Newsom vetoed the stricter SB 1047; New York's RAISE Act was later aligned to this model
primary source →

Official California Legislative Information bill page (verified: chaptered Sept 29, 2025, Ch. 138; 10^26-ops and $500M thresholds, OES reporting, $1M penalty confirmed from bill text).

California AB 2013 — Generative AI: Training Data Transparency

California Legislature · 2026-01-01in force

Signed September 28, 2024 and effective January 1, 2026, AB 2013 requires developers of generative AI systems or services made publicly available to Californians to post on their websites high-level documentation of the datasets used in training, including sources, whether the data contains personal or copyrighted material, and whether synthetic data was used. It applies retroactively to systems released on or after January 1, 2022, and to substantial modifications of them. It binds developers regardless of size, making it one of the broadest disclosure mandates now operative in the US.

  • Binds any developer of a generative AI system made available to Californians, with no revenue or compute threshold
  • Covers systems and substantial modifications released since January 1, 2022
  • Requires public dataset summaries: sources, personal data, copyrighted or licensed material, synthetic data use
  • Exemptions limited to security/integrity, aircraft-operation, and federal defense/national-security systems
primary source →

Official California Legislative Information bill page (verified: chaptered Sept 28, 2024; Jan 1, 2026 effective date and Jan 1, 2022 retroactive coverage confirmed from bill text).

California SB 243 — Companion Chatbot Safeguards

California Legislature · 2026-01-01in force

Signed October 13, 2025 (Chapter 677) and effective January 1, 2026, SB 243 binds any operator making a 'companion chatbot' available to California users. Operators must disclose that users are interacting with AI, maintain published protocols for responding to suicidal ideation and self-harm (with referrals to crisis services), and apply additional safeguards for known minors (explicit AI disclosure, three-hour reminders, and blocking sexually explicit content); annual reporting to the Office of Suicide Prevention begins July 1, 2027. The law includes a private right of action with damages of at least $1,000 per violation plus attorney's fees, a rarity among state AI statutes.

  • First US state law specifically regulating AI companion chatbots
  • Binds chatbot operators serving California users regardless of size; heightened duties for known minors
  • Private right of action (injunctive relief, at least $1,000 per violation, attorney's fees), unlike AG-only enforcement in most state AI laws
  • Annual reporting to the Office of Suicide Prevention begins July 1, 2027
primary source →

Official leginfo bill page (verified: chaptered Oct 13, 2025, Ch. 677; disclosure, crisis-protocol, minor-protection, July 1, 2027 reporting, and private-right-of-action provisions confirmed from bill text).

Texas Responsible Artificial Intelligence Governance Act (TRAIGA, HB 149)

Texas Legislature · 2026-01-01in force

Signed June 22, 2025 and effective January 1, 2026, TRAIGA binds any person who develops or deploys AI systems in Texas or offers AI-touched products or services used by Texas residents, plus Texas government agencies. Rather than a risk-tier framework, it prohibits developing or deploying AI with intent to cause specified harms — behavioral manipulation inciting self-harm or crime, unlawful discrimination, constitutional-rights infringement, and CSAM/unlawful deepfakes — and restricts government social scoring and biometric identification. The Attorney General has exclusive enforcement with a 60-day cure period, there is no private right of action, and the act preempts local AI ordinances; it also creates a regulatory sandbox and an AI advisory council.

  • In force since January 1, 2026; binds private developers/deployers reaching Texas residents and all state agencies
  • Intent-based prohibitions make it much narrower in practice than Colorado's original effects-based framework
  • Exclusive AG enforcement, 60-day cure, no private right of action, express preemption of city/county AI rules
  • Healthcare-practitioner AI disclosure requirement and a sandbox program for experimental deployments
primary source →

Official Texas Legislature Online bill history page (verified: signed June 22, 2025; effective Jan 1, 2026; subject line confirms 'Texas Responsible Artificial Intelligence Governance Act').

Illinois HB 3773 — AI Amendments to the Illinois Human Rights Act (P.A. 103-0804)

Illinois General Assembly · 2026-01-01in force

Signed August 9, 2024 and effective January 1, 2026, HB 3773 makes it a civil-rights violation for employers to use AI that has the effect of discriminating on the basis of protected classes in recruitment, hiring, promotion, discipline, discharge, or other terms of employment, and bans use of zip code as a proxy for protected characteristics. Employers must notify applicants and employees when AI is used for such decisions. It binds essentially all Illinois employers (the IHRA covers employers with one or more employees) and is enforced through the Illinois Department of Human Rights charge process; IDHR published proposed implementing rules on May 15, 2026 but temporarily withdrew them on June 2, 2026 — the statutory obligations apply regardless.

  • Effects-based discrimination standard — no intent required — now operative for AI in Illinois workplaces
  • Notice to employees and applicants required whenever AI is used in covered employment decisions
  • IDHR proposed rules published May 15, 2026 and temporarily withdrawn June 2, 2026; statute enforceable without them
  • Complements Illinois' AI Video Interview Act (2020) and the biometric-consent regime of BIPA, which continues to drive AI-related class litigation
primary source →

Secondary source (National Law Review / K&L Gates, verified: May 1, 2025 article confirming Jan 1, 2026 effective date, effects-based prohibition, and notice duties). Official text is Illinois Public Act 103-0804 at ilga.gov, which was unreachable from the audit environment. IDHR rules withdrawal verified via secondary reports.

New York enacts RAISE Act for frontier AI models; March 2026 amendments align it with California

New York Legislature / Governor Hochul · 2025-12-19announced

Gov. Hochul signed the RAISE Act (S6953B/A6453B) on December 19, 2025, making New York the second state (after California's SB 53) to impose transparency and safety-governance duties on frontier AI developers. Chapter amendments signed March 27, 2026 (S8828, Chapter 96) narrowed the law: it covers frontier models trained above 10^26 operations, defines 'large frontier developers' at $500M+ annual revenue, and requires published safety frameworks, pre-deployment transparency reports, and safety-incident reporting to the Department of Financial Services within 72 hours (24 hours for imminent risk). It takes effect January 1, 2027, with civil penalties up to $1M for a first violation and $3M for subsequent ones.

  • Signed Dec 19, 2025; chapter amendment S8828 signed Mar 27, 2026; effective Jan 1, 2027
  • Covers frontier models trained above 10^26 operations; large frontier developers at $500M+ revenue
  • Safety incident reports to NYDFS within 72 hours (24 hours for imminent life/safety risk)
  • Enacted in direct tension with the December 2025 federal preemption executive order
primary source →

Official NY Governor press release (primary; fetched and verified — Dec 19, 2025 signing, DFS oversight, 72-hour reporting, $1M/$3M penalties). Amendment details verified against the official NY Senate page for S8828 (signed March 27, 2026; 10^26 threshold; $500M revenue; Jan 1, 2027 effective date).

Colorado special session delays AI Act enforcement to June 30, 2026 (SB 25B-004)

Colorado General Assembly · 2025-08-28news

After lawmakers failed to agree on substantive amendments to the first-in-the-nation Colorado AI Act during the 2025 regular and special sessions, Gov. Polis signed SB 25B-004 ('Increase Transparency for Algorithmic Systems') on August 28, 2025, pushing the law's compliance date from February 1, 2026 to June 30, 2026. The bill made no substantive changes — a delay designed to give the 2026 session time to rework the law, which ultimately produced the SB 26-189 repeal-and-replace.

  • Passed August 25-26, 2025 in special session; signed August 28, 2025
  • Moved compliance date from Feb 1, 2026 to June 30, 2026
  • No substantive amendments — delay only, after regular and special sessions deadlocked
  • Precursor to the 2026 repeal-and-replace (SB 26-189) and the xAI/DOJ litigation
primary source →

Official Colorado General Assembly bill page (primary; fetched and verified — Senate passage Aug 25, House passage Aug 26, signed Aug 28, 2025; extends SB 24-205 requirements to June 30, 2026). Corroborated by Hunton privacy blog (delay-only, no substantive amendments).

Illinois Wellness and Oversight for Psychological Resources Act (WOPR, P.A. 104-0054)

Illinois General Assembly · 2025-08-01in force

Signed and effective August 1, 2025, the WOPR Act (HB 1806) is the first state statute to prohibit AI systems from independently providing therapy or psychotherapy services. Licensed clinicians may use AI only for administrative and supplementary support — not for therapeutic communication or independent treatment decisions — while general-purpose wellness apps outside the scope of therapy remain lawful. It binds anyone offering therapy services to Illinois residents, with civil penalties up to $10,000 per violation enforced by the Illinois Department of Financial and Professional Regulation.

  • First outright state ban on autonomous AI therapy; template for similar laws in other states
  • Binds providers and companies offering therapy-like AI services to Illinois consumers, including telehealth platforms and digital-health vendors
  • IDFPR enforcement, up to $10,000 civil penalty per violation; orders enforceable as court judgments
primary source →

Secondary source (Baker Donelson alert, verified: Aug 14, 2025 publication confirming HB 1806 / P.A. 104-0054, immediate effectiveness, IDFPR enforcement, and $10,000 penalty). Official text at ilga.gov was unreachable from the audit environment.

California SB 1047 — Safe and Secure Innovation for Frontier AI Models Act (vetoed)

California Legislature · 2024-09-29superseded

The 2024 frontier-model safety bill that would have imposed pre-deployment safety determinations, shutdown capability, and third-party audits on developers of models above a $100M training-cost threshold was vetoed by Governor Newsom on September 29, 2024, who objected that it regulated by model scale rather than by deployment risk. It never bound anyone, but its framework directly shaped the Joint California Policy Working Group report and the narrower transparency-first SB 53, enacted in 2025. It is included here because trackers frequently misreport it as law.

  • Vetoed September 29, 2024 — never took effect
  • Successor approach enacted as SB 53 (TFAIA), effective January 1, 2026
  • Its $100M-training-cost trigger reappeared in New York's original RAISE Act before that law's March 2026 chapter amendment
primary source →

Official leginfo bill page (verified: enrolled Sept 3, 2024 with $100M threshold, shutdown, and audit provisions; veto is documented in the governor's Sept 29, 2024 veto message).

California AB 2839 — election deepfake prohibition (struck down)

California Legislature · 2024-09-17superseded

The most ambitious state election-deepfake ban, signed as an urgency statute in September 2024, prohibited knowingly distributing materially deceptive AI-generated content about candidates and election officials in the months around an election. A federal court preliminarily enjoined it within weeks (October 2, 2024) and in August 2025 struck it down in Kohls v. Bonta as a content-based speech restriction failing First Amendment scrutiny; companion platform-takedown law AB 2655 was separately halted (January 3, 2025) and held preempted by Section 230. It is the landmark cautionary precedent constraining the prohibition model of state deepfake regulation; California's older disclosure-only AB 730 approach survives.

  • Permanently enjoined — binds no one; disclosure-based alternatives remain the viable design
  • Kohls v. Bonta is now the leading authority cited against flat synthetic-media bans nationwide
primary source →

Litigation-tracker source (verified resolving: confirms Oct 2, 2024 preliminary injunction and Jan 3, 2025 AB 2655 halt; tracker page current only through early 2025 — the Aug 2025 final ruling corroborated via independent trackers). Statute at leginfo.legislature.ca.gov (bill_id=202320240AB2839); judgment in Kohls v. Bonta (E.D. Cal., Aug. 2025).

Tennessee ELVIS Act — Ensuring Likeness, Voice and Image Security Act

Tennessee General Assembly · 2024-07-01in force

Signed March 21, 2024 and effective July 1, 2024, the ELVIS Act was the first US law to extend right-of-publicity protection explicitly to a person's voice, including AI-generated simulations, by amending Tennessee's 1984 Personal Rights Protection Act. It creates civil liability not only for unauthorized commercial use of a person's voice or likeness but also for distributing tools whose primary purpose is producing unauthorized simulations of an identifiable individual. It binds anyone commercially exploiting voice clones or distributing cloning tools reaching Tennessee, with enforcement through private suits by individuals, estates, and rights holders such as record labels.

  • First state statute covering AI voice cloning under publicity rights; model for performer-likeness bills nationwide
  • Liability extends to tool distributors, not just end users of a cloned voice
  • Private civil enforcement; postmortem rights run at least 10 years and can extend with continued commercial use
primary source →

Secondary source (verified resolving; confirms Mar 21, 2024 signing as first US voice/AI-replication protection). Official text is Tennessee Public Chapter 588 (2024), amending Tenn. Code Ann. § 47-25-1101 et seq.; capitol.tn.gov and tnsosfiles.com were unreachable from the audit environment. Effective date (July 1, 2024) and voice/tool-distributor provisions corroborated via Manatt and Skadden analyses.

Colorado AI Act (SB24-205) — Consumer Protections for Artificial Intelligence

Colorado General Assembly · 2024-05-17superseded

The first comprehensive US state AI law, signed May 17, 2024, would have imposed a duty of reasonable care on developers and deployers of 'high-risk' AI systems to prevent algorithmic discrimination in consequential decisions (employment, housing, credit, health care, and similar), backed by risk-management programs, impact assessments, and attorney-general notification. Its compliance date was pushed from February 1, 2026 to June 30, 2026 by SB25B-004 (signed August 28, 2025 in a special session), and in xAI LLC v. Weiser (D. Colo., No. 1:26-cv-01515, filed April 9, 2026, with DOJ intervening) the court granted a joint pause on April 27, 2026 while the legislature acted. SB26-189, signed May 14, 2026, repeals and reenacts the framework effective August 12, 2026, so the 2024 law's algorithmic-discrimination duties were never enforced.

  • Would have bound developers and deployers of high-risk AI systems used in consequential decisions affecting Colorado consumers
  • Compliance date moved Feb 1, 2026 → June 30, 2026 by SB25B-004; framework repealed by SB26-189 (effective Aug 12, 2026) without ever being enforced
  • Named in the December 2025 White House preemption EO; challenged in xAI LLC v. Weiser (filed Apr 9, 2026); court granted a joint pause Apr 27, 2026 and DOJ intervened
  • Repealed and reenacted as a narrower transparency law by SB26-189 (signed May 14, 2026)
primary source →

Official Colorado General Assembly bill page (verified: signed May 17, 2024). Delay verified at leg.colorado.gov/bills/sb25b-004 ('extends the effective date of the requirements of SB 24-205 to June 30, 2026'). Litigation verified via CourtListener docket 1:26-cv-01515 (filed Apr 9, 2026; joint motion to suspend granted Apr 27, 2026) and DOJ intervention announcement (justice.gov).

Utah Artificial Intelligence Policy Act (SB 149, as amended 2025)

Utah Legislature · 2024-05-01in force

The first state AI consumer-protection statute, effective May 1, 2024, binds businesses using generative AI in consumer transactions and in regulated occupations: they cannot blame the AI for consumer-protection violations, and must disclose AI use. 2025 amendments effective May 7, 2025 narrowed the duty — SB 226 limits disclosure to when a consumer clearly asks or to 'high-risk' interactions (health, financial, biometric data, or legal/financial/medical advice), with a safe harbor if the chatbot consistently self-identifies as AI, and SB 332 extended the act's sunset to July 1, 2027. Companion 2025 laws added mental-health chatbot rules (HB 452) and AI identity-fraud protections (SB 271); the Office of Artificial Intelligence Policy runs a learning-lab/mitigation-agreement program.

  • In force since May 1, 2024; scaled back May 7, 2025; sunsets July 1, 2027 absent reauthorization
  • Binds suppliers using generative AI in consumer transactions and licensed professionals using it in regulated services
  • Safe harbor for chatbots that clearly and consistently disclose they are not human
  • Enforced by the Utah Division of Consumer Protection; regulatory-sandbox model widely copied by other states
primary source →

Official Utah Legislature text for the 2024 act; 2025 amendments (SB 226, SB 332, HB 452, SB 271, 2025 General Session) at le.utah.gov. Audit caveat: le.utah.gov refused connections from the audit environment, so URL resolution could not be re-confirmed; the SB 226 narrowing, May 7, 2025 effective date, and SB 332 sunset extension to July 1, 2027 were corroborated via independent secondary analyses.

Agencies & enforcement24

Bartz v. Anthropic: court grants final approval of $1.5B copyright class settlement

U.S. District Court, N.D. Cal. · 2026-07-20news

Judge Araceli Martínez-Olguín granted final approval on July 20, 2026 of the $1.5 billion settlement — reported as the largest copyright class settlement in U.S. history — resolving authors' claims over Anthropic's downloading of pirated books from LibGen and Pirate Library Mirror, addressing all 54 objections on the merits. Payments run roughly $3,000 per work (about four times the statutory minimum), and Anthropic must destroy the pirate-sourced files and copies derived from them. The settlement followed Judge Alsup's June 2025 ruling that training on lawfully acquired books was fair use but retention of pirated library copies was not.

  • Final approval July 20, 2026; roughly $3,000 per claimed work (~4x the statutory minimum)
  • Class counsel fees cut to ~$101.5M (about 6.8% of the fund), from a 12.5% request
  • Anthropic must destroy LibGen/PiLiMi-sourced datasets and derived copies
  • Monetizes the acquisition/piracy distinction left by the June 2025 fair-use ruling
primary source →

Authors Guild announcement (secondary; fetched and verified — judge, date, amount, ~$3,000/work, fee cut to ~$101.56M (6.8%), destruction obligation). Order is on the N.D. Cal. docket, Bartz v. Anthropic, No. 3:24-cv-05417. Audit corrections: 54 objections (not 53); an unverified '~440,000 claimed works' figure was removed.

Kadrey v. Meta aftermath: interlocutory appeal on 'acquisition by piracy' denied

U.S. District Court, N.D. Cal. · 2026-07-08news

Judge Chhabria, who in June 2025 granted Meta summary judgment on fair use for LLM training while flagging an untested 'market dilution' theory, on July 8, 2026 denied the author plaintiffs' motion to certify an interlocutory appeal to the Ninth Circuit on whether Meta's downloading of books from shadow libraries was itself infringing — reasoning that a final judgment in one of the Meta cases will soon present the issue 'as part of a tidy package.' The denial leaves the acquisition-versus-training split (Kadrey vs. Bartz) unresolved at the appellate level, with the Third Circuit's Ross appeal positioned as the first appellate word on AI training fair use.

  • June 2025: summary judgment for Meta on fair use for training; piracy-acquisition question left open
  • July 8, 2026: interlocutory appeal certification denied; issue to await final judgment
  • Tension with Bartz v. Anthropic on pirated-source acquisition remains unresolved on appeal
  • Chhabria's market-dilution dictum continues to shape plaintiffs' strategies
primary source →

Blog of law professor Edward Lee tracking AI litigation (reputable secondary; fetched and verified — July 8, 2026 denial of certification on the downloading/shadow-library issue).

FTC Proposed Policy Statement on Suppression of Accuracy in AI Systems (AI accuracy / 'ideological steering')

FTC · 2026-07-07draft

Proposed policy statement (Federal Register July 7, 2026) taking the position that training or configuring an AI model to pursue undisclosed objectives contrary to users' reasonable expectations — including where done to comply with a state law — may be deceptive under FTC Act Section 5. Executive Order 14365 (Ensuring a National Policy Framework for Artificial Intelligence, signed December 11, 2025) expressly directs the Commission to issue this enforcement policy statement. Comment period closes July 31, 2026; not yet final, and even when finalized a policy statement is agency interpretation rather than a binding rule.

  • Shifts FTC AI focus from overhyped capability claims to whether models pursue undisclosed objectives diverging from user expectations
  • Distinguishes intentional steering (potential Section 5 violation) from hallucinations arising from technological and resource limits (not, by themselves, a violation)
  • States that deception violates Section 5 'even when a company engages in a deceptive act or practice in order to comply with a State law' — part of the federal push against state AI regulation under EO 14365
  • Comments due July 31, 2026; watch for the final statement and any companion enforcement
primary source →

Verified against the Federal Register document (2026-13628) via API and full text: title, FTC issuer, July 7, 2026 publication, 'proposed policy statement; request for comments' designation, EO 14365 directive language, the hallucination distinction, and the July 31, 2026 comment deadline all confirmed. EO 14365 (signed Dec. 11, 2025) confirmed in the Federal Register EO index. A previously claimed July 1, 2026 issuance date was not confirmed and was removed.

AI copyright litigation wave broadens: music amendments, Elsevier v. Meta, Midjourney and MiniMax studio suits

Federal courts (various) · 2026-06-18news

Mid-2026 docket activity shows the training-data fight expanding beyond books and news: record labels in UMG v. Suno and Sony v. Udio moved to add works uncovered in forensic review of training data even as settlement and licensing deals reshape the music cases; Elsevier, Hachette, McGraw Hill, and other publishers filed a new SDNY suit against Meta over systematic torrenting of copyrighted works; and the Disney/Universal/Warner suits against Midjourney and Disney v. MiniMax proceed through discovery and answers. Together with Bartz's $1.5B benchmark, the wave is pushing the industry toward licensing markets in the absence of congressional action.

  • Elsevier, Hachette, McGraw Hill and other publishers sue Meta in SDNY over torrenting of copyrighted works
  • Music-label cases against Suno and Udio being amended to add newly identified works from training-data review
  • Hollywood studio suits against Midjourney and MiniMax in active litigation
  • OpenAI leveraging the SCOTUS Cox decision against contributory claims
primary source →

McKool Smith AI litigation tracker, June 18, 2026 edition (secondary; fetched and verified — Elsevier/Hachette/McGraw Hill v. Meta filing, Suno/Udio amendment motions, Midjourney discovery fight, MiniMax/Hailuo answers, and OpenAI's Cox motion all confirmed).

Thomson Reuters v. Ross Intelligence: Third Circuit hears first appellate argument on AI training fair use

U.S. Court of Appeals, Third Circuit · 2026-06-11news

The Third Circuit heard oral argument on June 11, 2026 in the first federal appeal squarely presenting whether training an AI model on copyrighted material (Westlaw headnotes, used for a non-generative legal research tool) is fair use, reviewing Judge Bibas's February 2025 ruling that it was not. The panel (Restrepo, Montgomery-Reeves, Bove) pressed both sides on transformativeness and market harm. The forthcoming decision will be the first appellate precedent shaping generative-AI training cases; no ruling had issued as of late July 2026.

  • First federal appellate test of fair use for AI training
  • Argument focused on factor 1 (transformative use) and factor 4 (market harm)
  • District court (Judge Bibas) had rejected fair use for the non-generative tool in Feb 2025
  • Decision pending; will influence Bartz/Kadrey-line generative AI cases
primary source →

LawSites/LawNext reporting (reputable secondary; fetched and verified — June 11, 2026 argument, panel names, fair-use/transformativeness/market-harm focus, no decision date indicated). Audit correction: removed the claim that the panel 'appeared skeptical of Ross's position' — the report describes judges pressing both sides.

xAI v. Colorado and first-ever DOJ intervention against a state AI law; Colorado AI Act enforcement suspended

DOJ / U.S. District Court, D. Colo. · 2026-04-24news

In early April 2026, xAI sued the Colorado attorney general (X.AI LLC v. Weiser, No. 1:26-cv-01515, D. Colo.) to enjoin the Colorado AI Act (SB 24-205) before its June 30, 2026 compliance date, raising First Amendment, extraterritoriality/dormant Commerce Clause, and due-process claims. On April 24, 2026, DOJ moved to intervene — the first federal intervention against a state AI law, implementing EO 14365 — arguing the Act unconstitutionally compels discrimination. On April 27, 2026, the court granted a joint motion temporarily suspending enforcement pending legislative amendments; Colorado then repealed and replaced the Act (SB 26-189, signed May 14, 2026).

  • First test case implementing the DOJ AI Litigation Task Force created under EO 14365
  • Colorado AI Act enforcement temporarily suspended by court order April 27, 2026, via joint motion
  • DOJ intervention argues the Act compels discrimination in violation of equal protection
  • Colorado's SB 26-189 repeal-and-replace (signed May 14, 2026) has since restructured the underlying law
primary source →

Norton Rose Fulbright publication (secondary; fetched and verified — case number, DOJ intervention date, first-intervention characterization, April 27 suspension order, and June 30, 2026 compliance date all confirmed). Court filings are the primary source. Audit note: an earlier claim that Colorado/California/Texas/Illinois were named as likely federal targets could not be substantiated and was removed.

Supreme Court, Cox Communications v. Sony Music: contributory infringement narrowed, with AI spillover

U.S. Supreme Court · 2026-03-25news

On March 25, 2026, the Court held unanimously in judgment (opinion by Justice Thomas, with Sotomayor and Jackson concurring separately) that a company is not contributorily liable merely for providing a service to the public with knowledge that some users will infringe — liability requires inducement or a service tailored to infringement. Though an ISP case, it immediately reshaped AI litigation: defendants including OpenAI, Nvidia, Google, and Meta began invoking Cox to attack secondary-liability theories in training-data cases.

  • Decided March 25, 2026; unanimous in judgment, majority by Thomas
  • Mere knowledge that some users infringe does not create contributory liability absent inducement or tailoring
  • AI defendants (OpenAI, Nvidia, Google, Meta) moving to defeat secondary-infringement claims under Cox
  • OpenAI argues contributory infringement 'foreclosed' by Cox in the SDNY consolidated cases
primary source →

Wikipedia summary (secondary; fetched and verified — date, 9-0 judgment, Thomas majority, holding, and tech-defendant invocations). Official slip opinion at supremecourt.gov. OpenAI's use of Cox against contributory claims verified via McKool Smith AI litigation tracker (June 18, 2026). Audit correction: removed the claim that Concord Music v. Anthropic plaintiffs dropped secondary claims post-Cox — not substantiated by cited sources.

BIS Revision to License Review Policy for Advanced Computing Commodities (Nvidia H200 / AMD MI325X to China)

Commerce / BIS · 2026-01-15in force

A final rule (published and effective January 15, 2026) shifting BIS license review for exports of Nvidia H200, AMD MI325X, and comparable AI accelerators to China from presumption of denial to case-by-case review, conditioned on showings that exports will not reduce chip supply available to US customers, that Chinese purchasers maintain export-compliance and customer-screening programs, and that products pass independent third-party US testing. It followed the President's December 8, 2025 announcement permitting such sales and continues the 2025 trajectory in which H20-class chip sales to China were first restricted (April 2025 license requirement), then licensed under a reported revenue-sharing arrangement (August 2025). Despite roughly $10 billion in approved licenses, BIS Under Secretary Jeffrey Kessler testified on July 14, 2026 that actual H200 shipments to China remain 'trivial.'

  • Case-by-case licensing for H200/MI325X-class chips to China with supply, compliance, and testing conditions
  • Press reports add a 25% tariff/remittance and volume caps — those terms are not in the BIS release or the rule abstract
  • April 2025 H20 license requirement and August 2025 licensing arrangement preceded this rule
  • Actual shipments minimal as of July 2026 per BIS congressional testimony (House Foreign Affairs, July 14, 2026)
primary source →

Source URL upgraded to the Federal Register final rule (91 FR 1684, doc 2026-00789, effective Jan. 15, 2026 — verified). BIS press release of Jan. 13, 2026 verified separately at bis.gov (H200/MI325X and all three conditions confirmed; no tariff or volume-cap terms in the release). Kessler 'trivial' testimony corroborated by multiple outlets.

NYT v. OpenAI / In re OpenAI Copyright Litigation: 20 million ChatGPT logs ordered produced; sanctions fight follows

U.S. District Court, S.D.N.Y. · 2026-01-05news

In the consolidated SDNY litigation (16 copyright suits including the New York Times and Chicago Tribune), Judge Sidney Stein on January 5, 2026 affirmed Magistrate Judge Wang's November 2025 order compelling OpenAI to produce a de-identified sample of 20 million ChatGPT conversation logs, finding sample reduction, de-identification, and protective orders sufficient to protect user privacy. The consolidated cases remain the bellwether for whether training on and outputting news content is fair use. In July 2026, the news plaintiffs moved for sanctions, alleging OpenAI concealed its ability to search its training data and output logs for plaintiffs' works.

  • Jan 5, 2026: Stein affirms production of 20M de-identified user chat logs over privacy objections
  • Consolidated litigation of 16 publisher/author suits against OpenAI and Microsoft
  • Core copyright claims proceeding after 2025 rulings narrowed DMCA and unfair-competition theories
  • July 2026 sanctions motion alleges OpenAI hid its ability to search training data and output logs
primary source →

National Law Review analysis (secondary; fetched and verified — Jan 5, 2026 affirmance, Nov 2025 Wang order, 20M de-identified logs, 16-case consolidation). July 2026 sanctions motion verified via Prof. Edward Lee's litigation blog (July 15, 2026 post). Audit correction: prior claim that DMCA/unfair-competition claims were 'dismissed with prejudice' softened — the 2025 dismissal rulings narrowed those claims while core copyright claims proceed.

FTC launches Section 6(b) inquiry into AI companion chatbots and harms to minors

FTC · 2025-09-11news

The FTC issued compulsory 6(b) orders to seven companies operating consumer AI chatbots — Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap, and xAI — seeking information on how companion-style chatbots are designed, monetized, tested, and monitored for negative impacts on children and teens. The study, prompted in part by teen-suicide litigation against chatbot makers, is not an enforcement action but positions the agency for future cases and reporting.

  • Seven companies ordered to file special reports on companion chatbot safety and data practices
  • Focus areas: monetization, data sharing, pre/post-deployment impact testing, child safeguards
  • Parallel pressure: dozens of state AGs jointly warned chatbot providers over child-safety risks (Aug 2025)
  • Backdrop for state companion-chatbot laws such as California SB 243 (effective Jan 1, 2026)
primary source →

Official FTC press release (primary). Audit note: ftc.gov returned HTTP 403 to automated fetching, so the URL could not be re-resolved mechanically, but the September 11, 2025 announcement, the seven recipient companies, and the study's scope are well documented in contemporaneous coverage. A previously included claim that Sens. Padilla and Schiff urged broadening the inquiry in October 2025 was removed as unverified.

Raine v. OpenAI and the AI chatbot wrongful-death docket

California Superior Court (San Francisco) · 2025-08-26news

The August 26, 2025 wrongful-death suit by the parents of 16-year-old Adam Raine against OpenAI and Sam Altman — alleging ChatGPT encouraged their son's suicidal ideation and that OpenAI weakened self-harm safeguards — became the flagship of a growing product-liability docket against chatbot makers, alongside the Character.AI cases. An amended complaint (October 2025) added claims that OpenAI removed safeguards before the teen's death; OpenAI's November 2025 answer denied responsibility, citing crisis-resource referrals and terms-of-use violations. The litigation helped propel California SB 243, the FTC 6(b) chatbot inquiry, and federal chatbot child-safety proposals; no merits rulings had issued as of mid-2026.

  • Filed August 26, 2025; negligence and product-liability theories, expanded by October 2025 amendment
  • OpenAI answer (Nov 2025) asserts crisis-referral record, pre-existing ideation, and terms-of-use defenses
  • Catalyst (with Character.AI cases) for SB 243, the FTC 6(b) chatbot inquiry, and federal child-safety bills
  • First-wave test of product-liability theories against generative AI; no merits rulings as of mid-2026
primary source →

Wikipedia case summary (secondary; fetched and verified — Aug 26, 2025 filing in San Francisco County Superior Court, October 2025 amendment, November 2025 answer and defenses, ongoing status). Policy-catalyst connections (SB 243, FTC inquiry) rest on contemporaneous coverage rather than the cited page.

SEC: predictive data analytics (AI conflicts) rule withdrawn; 'AI-washing' enforcement continues

SEC · 2025-06-17superseded

By Federal Register notice published and effective June 17, 2025 (Commission notices dated June 12, 2025), the SEC formally withdrew fourteen Gensler-era rule proposals, including the July 2023 proposed conflicts-of-interest rule for broker-dealers' and investment advisers' use of predictive data analytics and AI (File S7-12-23). The Commission stated it does not intend to issue final rules on these proposals and would issue a new proposal if it revisits the area. Meanwhile, enforcement against 'AI-washing' — misrepresenting AI use to investors — continues under existing antifraud authority (Delphia and Global Predictions in 2024; Rimar Capital, Presto Automation, and Nate Inc. among later actions).

  • The PDA/AI conflicts proposal (File S7-12-23) is expressly listed among the 14 withdrawn — withdrawal is formal, not merely dormant
  • Existing securities antifraud law (not AI-specific rules) is the binding constraint on AI claims to investors
  • SEC scrutiny of AI-related disclosures continues through examinations and enforcement
primary source →

Source upgraded to the primary Federal Register withdrawal notice (doc. 2025-11110), verified via API: S7-12-23 listed among 14 withdrawn proposals, with the stated intent not to finalize and to re-propose if revisited. The previously cited sec.gov URL could not be machine-verified (403). An unverified claim that AI-washing cases 'exceed $44M across six matters' was removed; a claimed FY2026 exam-priority designation was softened.

US AI Safety Institute renamed Center for AI Standards and Innovation (CAISI)

Department of Commerce / NIST · 2025-06-03in force

Commerce Secretary Howard Lutnick transformed the Biden-era US AI Safety Institute (AISI, created at NIST in late 2023) into the Center for AI Standards and Innovation, dropping 'safety' from the name and reorienting the mission toward national-security evaluations (cybersecurity, biosecurity), standards leadership, and assessment of adversary AI systems such as Chinese frontier models. This is an administrative reorganization, not legislation — CAISI's evaluations of US developers rest on voluntary agreements.

  • Serves as 'industry's primary point of contact' within the US government for AI testing and collaborative research (NIST's own framing)
  • Launched the AI Agent Standards Initiative (announced February 17, 2026) on interoperable security and identity standards for autonomous agents
  • Publishes evaluations of foreign/adversary models framed around national-security risk — e.g., DeepSeek (2025), DeepSeek V4 Pro (May 2026), GLM-5.2 (July 2026), and a joint UK AISI/CAISI Kimi K3 cyber assessment (July 2026)
  • Continues collaborative security research, e.g., a CRADA with OpenMined signed March 27, 2026
primary source →

Verified on nist.gov/caisi (July 2026), including the agent-standards initiative date and model evaluations. The renaming was announced via a June 3, 2025 Commerce press statement by Secretary Lutnick; commerce.gov blocks automated retrieval, so the NIST CAISI page is used as the resolving official source. A prior claim of '40+ model evaluations completed by mid-2026' could not be substantiated and was removed.

CFPB withdraws AI/algorithm guidance in mass rescission of 67 guidance documents

CFPB · 2025-05-12superseded

By Federal Register notice effective May 12, 2025, the CFPB withdrew 67 guidance documents issued since its inception, including Circular 2022-03 on adverse-action notification requirements for credit decisions based on complex algorithms, along with other algorithm-related circulars (e.g., 2024-06 on algorithmic scores in employment decisions, 2024-01 on digital-intermediary steering). The statutory obligations under ECOA/Regulation B and FCRA are unchanged and remain binding — creditors using AI must still provide specific, accurate adverse-action reasons — but the Bureau has retreated from articulating AI-specific interpretations and from aggressive supervision in this area.

  • Withdrawal list confirmed to include Circular 2022-03 (complex-algorithm adverse-action notices); ECOA/Reg B duties themselves are statutory and still in force
  • 67 documents withdrawn in total: interpretive rules, policy statements, advisory opinions, and circulars
  • Part of a broader deregulatory posture at the CFPB, including rescinded rules and reduced supervision
  • State attorneys general and state mini-UDAP/AI laws are the more active enforcement vector for AI in consumer finance as of 2026
primary source →

Source upgraded to the primary Federal Register notice (90 FR, May 12, 2025, doc. 2025-08286), verified via full text: 67 withdrawn items counted, Circular 2022-03 expressly listed. Previously cited Goodwin Consumer Finance Insights analysis remains a useful secondary summary.

Copyright Office 'Copyright and Artificial Intelligence' report series (Parts 1–3) and the Perlmutter removal fight

US Copyright Office · 2025-05-09standard

Three-part advisory study: Part 1 (July 31, 2024) recommends a federal digital-replica law; Part 2 (Jan. 29, 2025) confirms existing law can handle copyrightability of AI-assisted works with human authorship required; Part 3 (May 9, 2025, still a pre-publication version as of July 2026) concludes generative-AI training on copyrighted works is fair use in some circumstances but not others. The reports are non-binding analysis but are heavily cited in the AI training-data litigation wave. Register Shira Perlmutter was fired May 10, 2025 — the day after Part 3's release — ordered restored by a divided D.C. Circuit panel on September 10, 2025, and the Supreme Court (which had deferred the administration's stay application on November 26, 2025) declined to stay her reinstatement on June 30, 2026 (Blanche v. Perlmutter), leaving her in office while the merits litigation proceeds.

  • Part 1 (digital replicas) recommended federal legislation — feeding the NO FAKES Act debate in Congress
  • Part 3 remains formally 'pre-publication'; the Office says a final version will follow without expected substantive changes, but none had been published as of July 2026
  • Perlmutter remains reinstated as Register; the June 30, 2026 SCOTUS action was a stay denial, not a merits ruling
  • Advisory only — courts deciding fair-use questions in AI training suits are not bound by it
primary source →

Report parts, dates, and Part 3's pre-publication status verified on copyright.gov/ai (July 2026). Perlmutter litigation timeline (May 10, 2025 firing; Sept. 10, 2025 D.C. Circuit ruling; Nov. 26, 2025 SCOTUS deferral in No. 25A478; June 30, 2026 stay denial; current reinstatement) corroborated via secondary sources — the removal dispute still creates residual uncertainty about the Office's AI policy trajectory.

EEOC withdraws AI employment-discrimination guidance

EEOC · 2025-01-27superseded

Following President Trump's January 23, 2025 AI executive order (EO 14179, 'Removing Barriers to American Leadership in Artificial Intelligence') and related directives, the EEOC on January 27, 2025 removed AI guidance from its website — most prominently the May 2023 technical assistance on adverse impact under Title VII when using algorithmic selection tools, with the 2022 ADA guidance on algorithmic employment decisions also reported removed. The withdrawal removes agency interpretation, not the law: Title VII and the ADA still fully apply to AI-driven hiring, and private plaintiffs and state/local regimes (e.g., NYC Local Law 144, Colorado) continue to fill the gap.

  • Guidance withdrawn was itself non-binding; underlying anti-discrimination statutes remain binding and enforceable
  • Signals de-prioritized federal enforcement of algorithmic disparate-impact theories under the current administration
  • Employer AI-bias exposure now driven mainly by private litigation (e.g., Mobley v. Workday) and state/local law
primary source →

Secondary source (K&L Gates alert) — verified as resolving and confirming the January 27, 2025 removal of the May 2023 Title VII AI guidance following the January 23, 2025 EO. The EEOC removed the pages themselves, so no stable primary URL exists. The 2022 ADA guidance removal rests on contemporaneous reporting rather than this alert; flagged accordingly.

BIS Framework for Artificial Intelligence Diffusion — rescission announced, formally unresolved

Commerce / BIS · 2025-01-15superseded

The Biden administration's January 2025 interim final rule created a three-tier global licensing system for advanced AI chips and, for the first time, controlled certain closed AI model weights. On May 13, 2025 BIS announced it would rescind the rule and not enforce its May 15, 2025 compliance deadline, issuing companion guidance (including that using certain Huawei Ascend chips risks violating the EAR). Critically, the formal rescission rulemaking has never been completed: no rescission rule appears in the Federal Register as of July 2026, and on May 12, 2026 GAO concluded (B-337935) that the non-enforcement announcement was itself a rule improperly withheld from Congress under the Congressional Review Act — leaving the framework on the books but unenforced.

  • Rescission announced May 13, 2025; no formal Federal Register rescission rule found as of July 2026
  • GAO decision B-337935 (May 12, 2026) held the non-enforcement press release was a CRA 'rule' not submitted to Congress
  • BIS has said it will issue a replacement rule; none published as of July 2026
  • May 2025 companion guidance flagged Huawei Ascend chips and training Chinese models on US chips as EAR risks
primary source →

BIS press release verified live (May 13, 2025; Huawei Ascend and non-enforcement content confirmed). Original IFR verified in FR (doc 2025-00636, Jan. 15, 2025; cited as 90 FR 4544). GAO B-337935 verified via gao.gov listing and practitioner coverage. Earlier claims about a draft replacement rule at OIRA (Feb.-Mar. 2026) could not be verified this audit and were removed.

FTC Rule on the Use of Consumer Reviews and Testimonials (16 CFR Part 465) — covers AI-generated fake reviews

FTC · 2024-10-21in force

Prohibits creating, buying, or selling fake consumer reviews and testimonials — expressly including AI-generated reviews by non-existent persons or people without actual product experience — with civil penalties up to statutory per-violation maximums. It is the clearest binding federal rule targeting generative-AI content in commercial contexts and remains in force as of mid-2026.

  • Effective October 21, 2024; explicitly reaches AI-generated fake reviews and testimonials
  • Also bans review suppression, undisclosed insider reviews, and buying fake social-media indicators
  • Complements FTC enforcement sweeps against deceptive AI claims (Operation AI Comply)
primary source →

Part 465 ('Rule on the Use of Consumer Reviews and Testimonials') verified current in the eCFR as of July 2026 via the eCFR API. Final rule verified at 89 FR 68034 (doc 2024-18519, published Aug. 22, 2024).

FTC Operation AI Comply — enforcement sweep on deceptive AI claims (ongoing)

FTC · 2024-09-25in force

Enforcement sweep applying existing FTC Act Section 5 deception/unfairness authority to AI: the September 25, 2024 launch bundled five actions (DoNotPay's 'robot lawyer' claims, Rytr's AI review generator, and AI-powered business-opportunity schemes Ascend Ecom, Ecommerce Empire Builders, and FBA Machine). Enforcement has continued under Chairman Ferguson with the same playbook — no new AI-specific statute, just established consumer-protection law applied to AI hype. Orders and settlements are binding on respondents.

  • Legal theory: unsubstantiated AI capability claims and AI-fueled deception violate FTC Act Section 5 — no new rulemaking required
  • Continued under the Trump-era FTC, e.g., the Click Profit (March 2025) and Workado (April 2025) actions
  • Related earlier/parallel AI-claims actions include Evolv Technologies, IntelliVision, and accessiBe
  • Separate 6(b) market study (no enforcement predicate) launched September 11, 2025 into AI companion chatbots' effects on children (orders to Alphabet, Character.AI, Instagram, Meta, OpenAI, Snap, xAI)
primary source →

FTC press release URL matches the September 25, 2024 announcement; ftc.gov blocks automated fetching, so resolution was not machine-verified but the five named cases, the 2025 continuations, and the 6(b) chatbot study are well documented. A claimed March 2026 Air AI proposed settlement with an $18M judgment could not be independently substantiated in this audit and was removed.

FCC Proposed Rule — AI-Generated Call Disclosure Requirements (NPRM, not finalized)

FCC · 2024-09-10draft

An August 2024 NPRM (published in the Federal Register September 10, 2024) proposing to define 'AI-generated call' and require in-call disclosure and AI-specific consent language for robocalls and robotexts, with carve-outs for accessibility uses by people with disabilities. No final rule adopting these requirements was found as of July 2026; the current FCC's deregulatory posture and EO 14365's separate directive that the FCC consider a preemptive federal AI reporting/disclosure standard leave the proceeding's future uncertain.

  • Proposes mandatory in-call AI disclosure and AI-specific consent
  • Not finalized as of July 2026 — only the 2024 declaratory ruling is binding
  • EO 14365 Sec. 6 directs a parallel FCC proceeding on a federal standard that could preempt state AI call-disclosure laws
primary source →

Federal Register NPRM verified: 89 FR 73321, doc 2024-19028, proposed rule. A Federal Register search found no finalizing rule; treat as pending.

FTC Trade Regulation Rule on Impersonation of Government and Businesses (16 CFR Part 461)

FTC · 2024-04-01in force

Prohibits impersonation of government agencies and businesses in commerce — the FTC's principal binding tool against AI-enabled deepfake and voice-clone impersonation scams — and allows the FTC to seek civil penalties and consumer redress in federal court. A companion supplemental proposal to extend the rule to impersonation of individuals (aimed directly at AI deepfakes of people) was issued in February 2024 but had not been finalized as of mid-2026.

  • Effective April 1, 2024; technology-neutral but squarely covers AI impersonation of agencies/businesses
  • Enables civil penalties without prior cease-and-desist orders
  • SNPRM extending coverage to impersonation of individuals remains unfinalized
primary source →

Part 461 ('Rule on Impersonation of Government and Businesses') verified current in the eCFR as of July 2026 via the eCFR API. Final rule verified at 89 FR 15017 (doc 2024-04335, published Mar. 1, 2024; effective Apr. 1, 2024).

FCC Declaratory Ruling — AI-Generated Voices Are 'Artificial' Under the TCPA (FCC 24-17)

FCC · 2024-02-08in force

A unanimous declaratory ruling confirming that calls using AI-generated or cloned voices are 'artificial or prerecorded voice' calls under the Telephone Consumer Protection Act, requiring prior express consent plus identification and opt-out compliance. This is binding interpretive law effective immediately and remains in force as of mid-2026; it underpins FCC enforcement against AI voice-cloning robocalls, including the 2024 Biden-deepfake primary-election case.

  • AI voice cloning triggers TCPA consent, disclosure, and opt-out rules
  • Enforceable by FCC, state AGs, and private TCPA plaintiffs
  • No rescission identified as of July 2026
primary source →

Official FCC ruling PDF verified at this URL (FCC 24-17, adopted Feb. 8, 2024; unanimous).

BIS advanced computing and semiconductor export controls (baseline 2022-2024 framework)

Commerce / BIS · 2023-10-17in force

The underlying export-control architecture for AI chips — ECCN 3A090/4A090 controls, the advanced-computing and supercomputer end-use rules, and China-wide license requirements established in October 2022 and tightened in October 2023 — remains in force and was further expanded in December 2024 to cover high-bandwidth memory and additional semiconductor manufacturing equipment, plus major Entity List additions. The 2025-2026 policy changes (diffusion-rule rescission announcement, H20/H200 licensing shifts) adjusted license review posture on top of this framework rather than dismantling it.

  • Oct. 2022 and Oct. 2023 rules created performance-threshold controls on AI accelerators to China
  • Dec. 2, 2024 rule added HBM controls, SME items, and roughly 140 Entity List additions
  • Framework remains the binding baseline beneath 2025-2026 license-policy shifts
primary source →

15 CFR Part 742 ('Control Policy—CCL Based Controls', EAR Subchapter C) verified current in the eCFR as of July 2026 via the eCFR API. The eCFR link is to current codified license requirements, not a single rule document; the controls span Parts 736-774. Rule-level FR citations for the 2022-2024 rules were not re-verified this session.

Copyright Office: Copyright Registration Guidance for Works Containing AI-Generated Material

US Copyright Office · 2023-03-16in force

Policy statement (88 Fed. Reg. 16,190) establishing that copyright protects only material with human authorship: applicants must disclose more-than-de-minimis AI-generated content and disclaim it, while human selection, arrangement, and modification of AI outputs can be protectable. This governs actual registration practice, so it is operationally binding on applicants even though it is guidance rather than statute.

  • Human-authorship requirement judicially confirmed: Thaler v. Perlmutter (D.C. Cir. 2025) held purely AI-generated works uncopyrightable; Supreme Court denied certiorari March 2, 2026 (No. 25-449)
  • Disclosure duty: AI-generated content in registered works must be identified and disclaimed
  • Remains the Office's operative registration policy as of mid-2026, reinforced by the Part 2 Copyrightability report
primary source →

copyright.gov/ai verified (July 2026): links the guidance with citation 88 Fed. Reg. 16,190 (Mar. 16, 2023). Thaler cert denial verified via the SCOTUSblog case file (denied March 2, 2026, docket 25-449).

Developments10

FTC proposed Policy Statement on 'Suppression of Accuracy' in AI systems (open for comment)

FTC · 2026-07-07draft

Implementing EO 14365, the FTC published for comment a policy statement asserting that steering AI systems toward undisclosed objectives and away from accurate outputs — including to comply with state mandates — can be a deceptive practice under FTC Act Section 5, and that state laws requiring such 'suppression of accuracy' may be impliedly preempted as in conflict with Section 5. Comments are due July 31, 2026 (Docket FTC-2026-0859, Matter No. P264200). If finalized it would be agency guidance rather than a rule, but it is designed to underwrite the administration's preemption strategy against state output-alteration mandates.

  • Comment period closes July 31, 2026
  • Theory: undisclosed steering of AI outputs deceives consumers under Section 5
  • Claims implied conflict preemption of state laws mandating alteration of truthful AI outputs
  • Delivered months after the EO's 90-day (March 11, 2026) deadline
primary source →

Federal Register (primary); full text verified via govinfo.gov (FR-2026-07-07, doc 2026-13628) — docket FTC-2026-0859, Matter P264200, July 31, 2026 comment deadline, and extensive citation of EO 14365 all confirmed.

Federal preemption of state AI laws — 2026 legislative landscape (pending)

Congress · 2026-07draft

After two failed moratorium attempts, preemption moved to standalone vehicles: Sen. Cruz's September 2025 AI policy framework pledged broad preemption legislation, and Rep. Baumgartner's American AI Leadership and Uniformity Act (H.R. 5388, introduced Sept. 16, 2025) would impose a temporary moratorium on certain state AI restrictions. Press reports also describe an Obernolte-Trahan 'Great American AI Act' discussion draft pairing frontier-model safety rules with preemption, and a Cruz-targeted July 29, 2026 Senate Commerce markup for AI bills (outcome unconfirmed). Counter-legislation is pending the other way: the GUARDRAILS Act (H.R. 8031, Beyer / S. 4216, Schatz) would repeal Executive Order 14365 — the Dec. 11, 2025 order directing a national AI policy framework and pressure on state AI laws — and Sen. Markey's States' Right to Regulate AI Act (S. 3557) would defund its implementation. As of late July 2026 no federal preemption statute has been enacted and state AI laws remain enforceable.

  • No preemption statute enacted; state AI laws remain in force
  • H.R. 5388 is the lead standalone preemption vehicle; broader drafts reported
  • Senate Commerce markup of AI bills targeted for July 29, 2026 (outcome unconfirmed)
  • GUARDRAILS Act (H.R. 8031/S. 4216) and S. 3557 push the other way against EO 14365
primary source →

All bills pending, none enacted. Verified on govinfo/Federal Register this audit: H.R. 5388 (Baumgartner, Sept. 16, 2025, temporary moratorium on certain state AI restrictions); GUARDRAILS Act H.R. 8031 (Beyer, Mar. 20, 2026) and S. 4216 (Schatz, Mar. 26, 2026), both repealing the EO 'Ensuring a National Policy Framework for Artificial Intelligence'; S. 3557 (Markey, Dec. 17, 2025, bars funds to implement that EO); EO 14365 confirmed via Federal Register (signed Dec. 11, 2025, doc. 2025-23092) — covered in the White House slice. Unverified against official records: the Obernolte-Trahan discussion draft (never introduced as a bill) and the outcome of the reported July 29, 2026 markup. Cruz framework announcement is on commerce.senate.gov (blocks automated access).

GSA draft acquisition clause on safeguarding data in large language model systems (open for comment)

General Services Administration · 2026-06-17draft

GSA requested public comment and announced listening sessions on a draft GSAR clause governing basic safeguarding of data within large language model AI systems acquired by the federal government. Written comments are due by August 3, 2026. If adopted, the clause would embed LLM data-security requirements directly into federal ICT procurement.

  • Draft GSAR clause on LLM data safeguarding in federal ICT acquisition
  • Comments due August 3, 2026; listening sessions announced
  • Extends federal AI governance through procurement requirements
primary source →

Federal Register proposed rule (primary; verified via FR API — title, June 17, 2026 publication, LLM data-safeguarding scope, and August 3, 2026 comment deadline all confirmed).

FDA request for information: AI-enabled optimization of early-phase clinical trials pilot

FDA · 2026-05-28draft

FDA extended the comment period on an RFI (originally published April 29, 2026) for a pilot program assessing how AI-enabled technologies can improve the efficiency, speed, and quality of decision-making in early-phase clinical trials; the extended comment period closed June 29, 2026. The initiative signals an enabling rather than restrictive posture toward AI in drug development.

  • RFI on AI in early-phase clinical trial design and decision-making
  • Comment period extended May 28, 2026 to June 29, 2026 (now closed)
  • Part of a broader pro-adoption FDA AI agenda
primary source →

Federal Register notice (primary; verified via FR API — this is the May 28, 2026 comment-period extension, not the original RFI; extended deadline June 29, 2026, now closed).

FY2026 appropriations — no AI preemption rider enacted

Congress · 2026-04-30news

Despite speculation that a state-AI-law moratorium would ride on must-pass funding bills after the OBBBA and NDAA failures, no AI preemption rider appeared in any FY2026 funding law. All twelve regular FY2026 appropriations bills are now enacted — Agriculture, MilCon-VA, and Legislative Branch via the November 12, 2025 CR package (P.L. 119-37, H.R. 5371); Commerce-Justice-Science, Energy-Water, and Interior on January 23, 2026; Defense, Labor-HHS, Transportation-HUD, Financial Services, and National Security-State on February 3, 2026; and Homeland Security on April 30, 2026 — none carrying AI preemption language. Appropriations activity affecting AI has been funding-level (NIST, NSF, DOE AI programs) rather than policy-rider-driven.

  • No state-AI moratorium attached to any FY2026 funding law
  • All twelve FY2026 bills enacted (final one April 30, 2026)
  • AI impact of appropriations is via funding levels, not policy riders
primary source →

Secondary source (Committee for a Responsible Federal Budget tracker), re-verified this audit and current: all twelve FY2026 regular bills enacted, with the enactment dates above; CR vehicle P.L. 119-37 (H.R. 5371, approved Nov. 12, 2025) verified on govinfo. Absence-of-rider finding corroborated by preemption trackers (CSA, Ropes & Gray) and consistent with the still-pending preemption bills in the landscape entry.

White House National Policy Framework for Artificial Intelligence (legislative blueprint for federal preemption)

White House · 2026-03-20announced

The White House released its promised national AI legislative framework on March 20, 2026, urging Congress to adopt a single national standard preempting the state patchwork while preserving state authority over child protection, fraud, and consumer protection. It asserts states should not regulate AI model development or penalize developers for unlawful third-party use of their models. It is a non-binding set of recommendations organized around six themes, and congressional action remains uncertain.

  • Six themes: child protection/parents, community safeguards and anti-fraud, IP/creators, anti-censorship, innovation without new federal regulators, workforce
  • Calls for a single national standard replacing the state patchwork
  • Would bar states from regulating model development or imposing developer liability for third-party misuse
  • Non-binding; sets the agenda for the 2026 congressional preemption debate
primary source →

WilmerHale client alert (secondary; fetched and verified — release date, preemption call, carve-outs, six themes, and non-binding character all confirmed). Official framework document on whitehouse.gov not independently confirmed during audit.

Federal preemption pressure on state AI law (context): EO 14365, 'Ensuring a National Policy Framework for Artificial Intelligence'

White House · 2025-12-11news

Signed December 11, 2025, Executive Order 14365 directed the Attorney General to stand up an AI Litigation Task Force within 30 days (by January 10, 2026) to challenge state AI laws as unconstitutional burdens on interstate commerce or compelled speech, directed Commerce to identify 'onerous' state AI laws within 90 days, and leveraged federal funding — including BEAD broadband money — against states with such regimes, naming Colorado's algorithmic-discrimination law specifically. Its effects are already visible in this tracker's slice: xAI sued Colorado in April 2026 with DOJ intervening, Colorado's original framework was paused and then repealed and replaced in May 2026, and New York's RAISE Act was finalized in narrowed form in its shadow. An EO cannot itself preempt state law — only Congress or successful litigation can — so every state law listed here remains valid unless and until courts hold otherwise.

  • Included as status context for state entries; the EO itself belongs to the federal executive-action slice of this tracker
  • Congress's earlier attempt at a 10-year state-AI moratorium was stripped from the 2025 reconciliation bill by a 99-1 Senate vote
  • As of July 2026, no court has struck a state AI law on the EO's commerce-clause or field-preemption theories; Colorado's retreat was legislative, and the Kohls-line losses rested on the First Amendment and Section 230
primary source →

Official White House posting (verified: EO 14365, signed Dec 11, 2025; 30-day AI Litigation Task Force directive, 90-day Commerce review, BEAD funding conditions, and the naming of Colorado's algorithmic-discrimination law all confirmed on the page; URL slug differs from the EO's formal title).

Executive Order 14365 — Ensuring a National Policy Framework for Artificial Intelligence (state-law preemption push)

White House · 2025-12-11in force

President Trump signed EO 14365 on December 11, 2025 (90 FR 58499), directing the federal government to counter state AI regulation. It orders DOJ to establish an AI Litigation Task Force within 30 days to challenge state AI laws, requires Commerce to publish an evaluation identifying 'onerous' state AI laws within 90 days (i.e., by March 11, 2026) with identified states losing BEAD non-deployment funds, and directs the FTC to issue a policy statement on when state laws requiring alteration of truthful AI outputs are preempted. It is binding executive action but cannot itself preempt state law; its legislative-recommendation section carves out child safety, AI compute/data-center infrastructure, and state procurement.

  • DOJ AI Litigation Task Force required within 30 days to challenge state AI laws on constitutional and preemption grounds
  • Commerce evaluation of onerous state AI laws due within 90 days (March 11, 2026); identified states ineligible for BEAD non-deployment funds
  • FTC directed to issue policy statement on preemption of state laws requiring alteration of truthful AI outputs (delivered July 2026)
  • Legislative carve-outs preserve state authority over child safety, compute/data-center infrastructure, and state procurement
primary source →

Federal Register (primary; verified via FR API and full text — EO number, title, signing date 2025-12-11, citation 90 FR 58499 all confirmed; FR HTML pages are bot-gated but canonical). Corroborated by Lawfare: lawfaremedia.org/article/trump-signs-executive-order-to-preempt-state-ai-laws. Audit note: a previously included '~$21B' BEAD figure was removed as unverified; still operative as of July 2026 (FTC implemented it July 7, 2026).

GUARD Act: proposed federal restrictions on AI companion chatbots for minors

Congress · 2025-10-28draft

Senators Hawley and Blumenthal, with other senators, introduced the GUARD Act on October 28, 2025 to restrict minors' (under-18) access to AI companion chatbots: it requires age verification for chatbot accounts, recurring disclosures that chatbots are not human and hold no professional credentials, and criminal penalties for knowingly providing minors access to chatbots that solicit sexually explicit content or promote suicide, self-harm, or violence, with enforcement by the U.S. Attorney General and state attorneys general. It remains pending, but with the White House's March 2026 framework carving child safety out of preemption, chatbot child-safety rules are the likeliest area of bipartisan federal AI legislation.

  • Age verification and recurring non-human disclosure duties for companion chatbot operators
  • Would prohibit minors' access to AI companions, with criminal penalties for harmful chatbots
  • Enforcement by the U.S. Attorney General and state attorneys general
  • Child safety expressly carved out of the administration's preemption push
primary source →

California Lawyers Association overview (secondary; fetched and verified — Oct 28, 2025 introduction, sponsors, age verification, non-human disclosures, criminal penalties, federal/state AG enforcement). Bill number not verified against congress.gov (blocked to automated fetching). Audit correction: removed an unverified list of parallel state bills (FL/MA/MO/NJ/PA/WA/TN); the source discusses New York and Utah companion-chatbot laws.

State AI-law moratorium in 2025 budget reconciliation (One Big Beautiful Bill Act) — DEAD

Congress · 2025-07-01news

The House-passed reconciliation bill (H.R. 1) contained a 10-year moratorium barring state enforcement of AI regulations; the Senate reworked it into a 5-year condition tied to BEAD broadband funds, then voted 99-1 on July 1, 2025 to strip the provision entirely. The One Big Beautiful Bill Act was signed July 4, 2025 with no AI preemption language, making this the highest-profile failed federal preemption effort. The fight then migrated to the FY2026 NDAA (excluded again, December 2025) and to the executive branch.

  • House version: 10-year ban on state AI-law enforcement
  • Senate stripped it 99-1 on July 1, 2025
  • OBBBA enacted July 4, 2025 without any AI preemption
  • Preemption push shifted to NDAA (failed) and executive action
primary source →

Dead — never enacted. OBBBA verified on govinfo this audit as Pub. L. 119-21 (H.R. 1), approved July 4, 2025; the enacted law contains no AI-preemption language. The 99-1 strip vote occurred July 1, 2025 (one secondary article misdates it to 2026). NDAA exclusion verified against Pub. L. 119-60 text.

Congress & statutes15

NO FAKES Act of 2026 (S. 4591)

Congress · 2026-06-24draft

The revised NO FAKES Act (Nurture Originals, Foster Art, and Keep Entertainment Safe Act of 2026) creates a federal intellectual-property-like right in one's voice and visual likeness, imposing liability for producing or distributing unauthorized AI 'digital replicas,' with notice-and-takedown obligations and safe harbors for platforms. Introduced May 20, 2026 by Sen. Coons with 13 bipartisan cosponsors, it was reported by Senate Judiciary in June 2026 (official reported print June 24; the committee vote, reported as unanimous, was June 18) and awaits a Senate floor vote. It supersedes the 2025 version (S. 1367, introduced April 9, 2025) and a 2024 predecessor that died without a vote.

  • Federal digital-replica right in voice and likeness
  • Reported by Senate Judiciary June 2026 (print June 24)
  • Backed by entertainment industry and major AI firms; supersedes S. 1367
  • Awaits Senate floor; House companion activity ongoing
primary source →

Pending — not law. Verified on govinfo this audit: S. 4591 introduced May 20, 2026 (Coons + 13 bipartisan cosponsors, referred to Judiciary); reported-in-Senate print dated June 24, 2026; no engrossed (Senate-passed) version exists. The June 18 unanimous committee vote is per Holland & Knight reporting, consistent with the June 24 report print. Industry backing per 2025-26 press reporting.

GUARD Act (S. 3062) — AI companion chatbots and minors

Congress · 2026-05-11draft

The Hawley-Blumenthal GUARD Act would ban AI companion chatbots for minors, require age verification and disclosure that a chatbot is not human, and create criminal penalties for companies whose companion bots solicit or produce sexual content for minors. Senate Judiciary advanced it in late April 2026 (reported as a unanimous April 30 vote; the official reported print, retitled GUARD Act of 2026 with 19 cosponsors, is dated May 11, 2026), and it awaits Senate floor action. A bipartisan House companion was reported introduced in spring 2026. It is the leading federal response to a wave of state chatbot laws and child-safety litigation.

  • Would bar AI companion chatbots for users under 18
  • Mandatory non-human disclosure by chatbots
  • Reported by Senate Judiciary (print May 11, 2026); floor timing uncertain
primary source →

Pending — not law. Verified on govinfo this audit: S. 3062 introduced Oct. 28, 2025 (Hawley); reported-in-Senate print May 11, 2026 with 19 cosponsors; no Senate floor passage. The Apr. 30, 2026 unanimous Judiciary vote is per Covington and The Hill, consistent with the May 11 report print. House companion detail per press reporting, not independently verified.

CREATE AI Act (H.R. 2385 / S. 4441) — codifying the NAIRR

Congress · 2026-04-29draft

The CREATE AI Act would statutorily establish the National Artificial Intelligence Research Resource at NSF, giving academic researchers, educators, and students access to compute, datasets, and testbeds. The NAIRR pilot has run since early 2024 and survived the revocation of the Biden EO that spawned it, but has no permanent authorization. The House bill (Obernolte-Beyer, H.R. 2385) was introduced March 26, 2025; Sens. Young, Heinrich, Rounds, and Booker reintroduced the Senate version (S. 4441) on April 29, 2026, referred to Senate Commerce. Repeatedly bipartisan, repeatedly short of the finish line: a committee-passed 118th Congress version died at the end of 2024.

  • Would make the NAIRR permanent, congressionally authorized infrastructure
  • Strong bipartisan sponsorship in both chambers
  • NAIRR pilot operating since 2024 despite EO revocation
  • Introduced in the 118th and again in the 119th Congress; never enacted
primary source →

Pending — not law. Verified on govinfo this audit: H.R. 2385 introduced Mar. 26, 2025 (Obernolte, with Beyer); S. 4441 introduced Apr. 29, 2026 (sponsor Young), referred to Senate Commerce. A previously reported June 2026 House Science Committee action could not be verified against official records (no reported print exists) and has been omitted.

DEFIANCE Act of 2025 (S. 1837) — passed Senate, pending in House

Congress · 2026-01-13draft

The DEFIANCE Act creates a federal civil cause of action letting victims of nonconsensual sexually explicit deepfakes sue creators and distributors, with liquidated damages reported up to $250,000 in aggravated cases. It passed the Senate by unanimous consent on January 13, 2026 (its second unanimous Senate passage; the 2024 version died in the House) and now awaits House action, where the companion effort is led by Rep. Ocasio-Cortez. It complements the criminal TAKE IT DOWN Act with a private remedy.

  • Civil damages remedy for sexual-deepfake victims
  • Passed Senate unanimously Jan. 13, 2026
  • Died in House last Congress; House action again the bottleneck
primary source →

Not yet law — Senate-passed only. Verified on govinfo this audit: engrossed-in-Senate text of S. 1837 with last action Jan. 13, 2026; no enrolled version exists, confirming it has not been enacted. Passage date also per Sen. Durbin's press release. Damages figures vary across sources ($150k base / $250k aggravated); consult bill text before quoting.

National Defense Authorization Act for Fiscal Year 2026 (AI provisions; state-AI moratorium excluded)

Congress · 2025-12-18in force

Signed December 18, 2025 as Pub. L. 119-60 (S. 1071), the FY2026 NDAA carries an extensive slate of AI provisions — described by law-firm analyses as the largest of any NDAA to date — including a National Security and Defense Artificial Intelligence Institute (sec. 224), pilot programs to integrate commercial AI across DoD, AI governance framework mandates, a prohibition on DoD use of certain covered AI (sec. 1532), and a ban on DeepSeek on intelligence community systems (sec. 6604). Critically for the preemption debate, Congress excluded a proposed moratorium on state AI laws from the final bill — the second time in 2025 such language failed.

  • Extensive AI slate; defense-focused
  • Sec. 1532 bars DoD use of certain covered AI; sec. 6604 bans DeepSeek on IC systems
  • Sec. 224 establishes National Security and Defense AI Institute
  • State AI-law moratorium was omitted from the final text
primary source →

Verified on govinfo this audit: Pub. L. 119-60, S. 1071, approved Dec. 18, 2025. Statutory text confirms sec. 224 (National Security and Defense Artificial Intelligence Institute), sec. 1532 (guidance and prohibition on use of certain artificial intelligence), sec. 6604 (DeepSeek prohibition on IC systems), and contains no state-AI-law moratorium. Moratorium-exclusion history per StateScoop (Dec. 2025) and law-firm analyses.

GAIN AI Act (H.R. 5885) — domestic priority for advanced AI chips

Congress · 2025-10-31draft

The GAIN AI Act (Guaranteeing Access and Innovation for National Artificial Intelligence Act of 2025, Rep. Moolenaar) would require entities seeking licenses to export advanced AI chips to countries of concern to certify that US persons have priority access to those chips — a CHIPS-adjacent effort to keep frontier compute onshore. A version pushed as an FY2026 NDAA amendment was excluded from the final defense bill amid White House and Nvidia opposition; the standalone bill remains in House Foreign Affairs.

  • US-first purchase right for export-controlled AI chips
  • Dropped from final FY2026 NDAA
  • Standalone version still in committee
primary source →

Pending — not law. Verified on govinfo this audit: H.R. 5885 introduced Oct. 31, 2025 by Rep. Moolenaar, referred to House Foreign Affairs; text requires export-license certification of US-person priority. NDAA-attachment failure (Dec. 2025) per contemporaneous reporting. A reported Senate companion was not independently verified.

SANDBOX Act (S. 2750) and the Cruz AI legislative framework

Congress · 2025-09-10draft

Sen. Cruz's SANDBOX Act would direct OSTP to run a federal AI regulatory sandbox in which developers obtain renewable waivers or modifications of federal rules (potentially up to 10 years) to test and deploy AI products, with regular reporting to Congress. Introduced September 10, 2025 as the first legislative implementation of the administration's AI Action Plan, it anchors Cruz's broader 'Legislative Framework for American Leadership in AI,' which also promises state-law preemption legislation. Still in Senate Commerce as of July 2026; reported as a candidate for the committee's late-July 2026 AI markup.

  • OSTP-run waiver program for federal AI-related regulations
  • First bill implementing the July 2025 AI Action Plan
  • Companion to Cruz's promised preemption legislation
primary source →

Pending — not law. Verified on govinfo this audit: S. 2750 introduced Sept. 10, 2025 by Sen. Cruz; directs OSTP to establish a federal AI regulatory sandbox. Deregulatory framework, not conduct regulation; opposition from consumer and labor groups (AFL-CIO letter) per press reporting. Markup-candidacy claim unconfirmed against official records.

SANDBOX Act (S. 2750) and congressional AI preemption bills

Congress · 2025-09-10draft

Senate Commerce Chair Ted Cruz introduced the SANDBOX Act (S. 2750) on September 10, 2025, directing OSTP to run a federal AI regulatory sandbox letting developers apply to waive or modify federal regulations for renewable two-year terms — the first plank of his light-touch AI framework. Separately, Rep. Baumgartner's American Artificial Intelligence Leadership and Uniformity Act (H.R. 5388, introduced September 16, 2025) would impose a five-year moratorium preempting state AI laws. Neither had been enacted as of July 2026: broad statutory preemption has struggled since the Senate stripped the OBBBA AI moratorium 99-1 in July 2025, and the fight now centers on the White House's March 2026 framework.

  • Regulatory waiver sandbox administered through OSTP with renewable two-year terms
  • H.R. 5388 (Baumgartner) would impose a five-year moratorium preempting state AI laws
  • Statutory preemption stalled after the 99-1 OBBBA moratorium defeat (July 2025)
  • Legislative preemption now hinges on the White House's March 2026 framework
primary source →

GovInfo official bill record (primary; fetched and verified — S. 2750, Cruz, Sept 10, 2025, OSTP sandbox; congress.gov canonical page blocked automated fetching). H.R. 5388 (Baumgartner, Sept 16, 2025, five-year state-preemption moratorium) verified via govinfo and the sponsor's announcement. Audit correction: removed the unverified claim that Cruz remained the sole SANDBOX sponsor as of mid-2026.

TAKE IT DOWN Act

Congress · 2025-05-19in force

Pub. L. 119-12 (S. 146, Klobuchar-Cruz) is the first federal statute squarely regulating an AI harm: it criminalizes knowingly publishing nonconsensual intimate visual depictions, explicitly including AI-generated 'digital forgeries' (deepfakes), with enhanced penalties for images of minors. It also requires covered platforms to operate a notice-and-removal process taking down reported NCII within 48 hours; the platform obligations became enforceable May 19, 2026, with FTC enforcement as an unfair or deceptive practice.

  • First federal law directly targeting AI deepfake abuse (NCII)
  • Federal crime to publish authentic or AI-forged intimate images without consent
  • Platforms must remove reported content within 48 hours (from May 19, 2026)
  • FTC enforces the platform duty
primary source →

Official record verified on govinfo this audit: Pub. L. 119-12, approved May 19, 2025, 139 Stat. 55. Criminal provisions effective at enactment; platform notice-and-removal duty took effect May 19, 2026 (one year after enactment). Enacted-text PDF at govinfo.gov/content/pkg/PLAW-119publ12/pdf/PLAW-119publ12.pdf.

AI Whistleblower Protection Act (S. 1792)

Congress · 2025-05-15draft

Grassley-led bipartisan bill extending retaliation protections to employees of AI companies who report AI security vulnerabilities or safety-related legal violations. Introduced May 15, 2025 and referred to the Senate HELP Committee, where it remains as of mid-2026; notable as one of the few AI-safety-oriented bills with cross-party sponsorship in the deregulatory 119th Congress.

  • Anti-retaliation protection for AI-company whistleblowers
  • Bipartisan (Grassley-led); still in committee
primary source →

Pending — not law. Verified on govinfo this audit: S. 1792, AI Whistleblower Protection Act, introduced May 15, 2025 by Sen. Grassley; referred to the Committee on Health, Education, Labor, and Pensions. Congress.gov equivalent URL is correct but blocks automated access.

Advancing American AI Act (Subtitle B, Title LXXII, FY2023 NDAA)

Congress · 2022-12-23in force

Enacted in the James M. Inhofe NDAA for FY2023 (Pub. L. 117-263, secs. 7221-7228), it requires federal agencies to maintain and publish inventories of their AI use cases, directs OMB to issue guidance on agency AI acquisition and use consistent with agency-use principles, and mandated pilot AI acquisition programs. It is the statutory backbone for the federal AI use-case inventory regime that successive administrations' OMB memoranda implement.

  • Requires annual public agency AI use-case inventories
  • OMB procurement and use guidance mandate
  • Governs federal agency AI, not private sector
primary source →

Binding statute. Vehicle verified on govinfo this audit: Pub. L. 117-263, H.R. 7776, approved Dec. 23, 2022. The Advancing American AI Act is Title LXXII, Subtitle B (secs. 7221-7228).

AI Training Act

Congress · 2022-10-17in force

Pub. L. 117-207 (S. 2551), the Artificial Intelligence Training for the Acquisition Workforce Act, requires OMB to establish an AI training program for the federal acquisition workforce — program managers, procurement, and logistics officials — so agencies buying AI understand its capabilities and risks. A narrow but binding statute on federal procurement competence.

  • Mandatory AI training program for federal acquisition workforce
  • Administered through OMB; updated at least every two years
primary source →

Binding statute. Verified on govinfo this audit: Pub. L. 117-207, S. 2551, approved Oct. 17, 2022.

CHIPS and Science Act of 2022 (AI-adjacent provisions)

Congress · 2022-08-09in force

Pub. L. 117-167 appropriated roughly $52.7B for domestic semiconductor manufacturing and R&D — the hardware substrate of the AI industry — and its 'Science' division authorized major AI-relevant programs: the NSF Directorate for Technology, Innovation and Partnerships, expanded AI research institutes, NIST AI testbeds and standards work, and DOE AI research. Authorizations in the Science division have been only partially funded through subsequent appropriations.

  • $52.7B semiconductor subsidies underpin US AI compute capacity
  • Authorized NSF TIP Directorate and expanded AI research programs
  • NIST AI standards and testbed authorities
  • Science-division authorizations remain incompletely appropriated
primary source →

Binding statute (spending and authorization). Verified on govinfo this audit: Pub. L. 117-167, H.R. 4346, approved Aug. 9, 2022 (govinfo carries the vehicle's formal appropriations title; the short title is the CHIPS and Science Act). AI provisions are enabling/investment measures, not conduct regulation.

National Artificial Intelligence Initiative Act of 2020 (Division E, FY2021 NDAA)

Congress · 2021-01-01in force

Enacted as Division E of the William M. (Mac) Thornberry National Defense Authorization Act for FY2021 (Pub. L. 116-283), this remains the foundational US federal AI statute. It established the National AI Initiative and the National AI Initiative Office in OSTP, authorized NSF National AI Research Institutes, created the National AI Advisory Committee, and directed NIST to develop a voluntary AI risk management framework (the origin of the NIST AI RMF). It coordinates federal AI R&D rather than regulating private-sector AI.

  • Foundational federal AI statute; coordinates R&D, not a regulatory regime
  • Created National AI Initiative Office and National AI Advisory Committee
  • Directed NIST to develop the voluntary AI Risk Management Framework
  • Authorized NSF AI Research Institutes and the NAIRR Task Force
primary source →

Binding statute. Verified on govinfo this audit: Pub. L. 116-283, H.R. 6395, approved Jan. 1, 2021 (enacted over presidential veto). The AI Initiative Act is Division E (secs. 5001 et seq.) of the NDAA vehicle. Congress.gov equivalent (bill/116th-congress/house-bill/6395) is correct but blocks automated access.

AI in Government Act of 2020 (Division U, Title I, Consolidated Appropriations Act 2021)

Congress · 2020-12-27in force

Enacted inside the Consolidated Appropriations Act, 2021 (Pub. L. 116-260), it created the AI Center of Excellence within GSA to advise agencies on AI adoption, required OMB to issue guidance to agencies on AI acquisition and use, and directed OPM to establish AI occupational classifications for the federal workforce. It governs federal government use of AI, not the private sector.

  • Created GSA AI Center of Excellence
  • Required OMB guidance on agency AI use and acquisition
  • Directed OPM to build federal AI workforce classifications
primary source →

Binding statute. Vehicle verified on govinfo this audit: Pub. L. 116-260, H.R. 133, approved Dec. 27, 2020. The AI in Government Act is Division U, Title I of the omnibus. Congress.gov equivalent is correct but blocks automated access.

Executive actions15

Executive Order 14409 — Promoting Advanced Artificial Intelligence Innovation and Security

White House (Trump) · 2026-06-02in force

The administration's first order squarely addressing frontier-model security risk, choosing voluntary mechanisms over mandatory safety review. It directs agencies on 30- and 60-day timelines to harden federal systems with AI-enabled cyber defenses, orders design of a voluntary framework under which developers of NSA-designated 'covered frontier models' may give the government pre-release access for up to 30 days, directs Treasury, NSA, and CISA to form an AI cybersecurity vulnerability clearinghouse in voluntary collaboration with industry and critical-infrastructure operators, and directs DOJ to prioritize criminal enforcement against AI-enabled computer crimes.

  • Voluntary pre-release federal access to covered frontier models for up to 30 days (Sec. 3(b))
  • AI cybersecurity clearinghouse for coordinated vulnerability discovery and patching (Sec. 2(d))
  • Federal network hardening on 30/60-day deadlines; DOJ enforcement priority on AI-enabled cybercrime
  • Sec. 3(c) expressly disclaims any mandatory licensing, preclearance, or permitting requirement for AI model release — a deliberate contrast with rescinded EO 14110
primary source →

Full text read and verified from the Federal Register: 91 FR 34565, doc 2026-11415, signed June 2, published June 5, 2026.

Executive Order 14409 — Promoting Advanced Artificial Intelligence Innovation and Security

White House · 2026-06-02in force

Signed June 2, 2026 (published June 5, 91 FR 34565), EO 14409 pairs AI-enabled cyber defense of government and critical-infrastructure systems (with 30-day prioritization directives) with a voluntary framework for engaging developers of covered frontier models, a Treasury-formed AI cybersecurity clearinghouse for vulnerability scanning and patching, and prioritized DOJ enforcement against criminal misuse of AI. It expressly disclaims authorizing any mandatory licensing, preclearance, or permitting requirement for developing or releasing AI models — codifying the administration's opposition to ex-ante frontier regulation.

  • Voluntary engagement framework for covered frontier models — express disclaimer of mandatory licensing/preclearance/permitting
  • Treasury-formed AI cybersecurity clearinghouse; 30-day cyber-defense prioritization directives
  • DOJ directed to prioritize enforcement against criminal use of AI in computer crimes
  • Clearest signal yet that federal frontier-model oversight will remain voluntary
primary source →

Federal Register (primary; verified via FR API and full text — EO number 14409, signing date, citation 91 FR 34565, voluntary framework (Sec. 3(b)), licensing disclaimer (Sec. 3(c)), Treasury clearinghouse (Sec. 2(d)), 30-day cyber-defense directives, and criminal-enforcement section all confirmed).

National Policy Framework for Artificial Intelligence (White House legislative blueprint)

White House · 2026-03-20announced

Released March 20, 2026 pursuant to EO 14365, this framework gives Congress the administration's blueprint for a single federal AI statute: age-assurance and parental-control requirements for minors' AI use, a stated position that training on copyrighted works does not violate copyright law (while deferring final resolution to courts), voluntary collective licensing markets, limits on government jawboning of AI content, no new centralized AI regulator, and federal preemption of state AI laws with child-safety and consumer-protection carve-outs. It is a legislative recommendation document with no binding force of its own.

  • Blueprint for preemptive federal AI legislation; Congress had not enacted it as of July 2026
  • Rejects a standalone federal AI agency in favor of sector regulators and industry standards
  • States copyright/fair-use position favorable to model training while deferring to courts
primary source →

Law-firm summary (WilmerHale), verified live and consistent with parallel coverage by DLA Piper, K&L Gates, and Ropes & Gray. An official whitehouse.gov URL could not be located during this audit; substitute it if confirmed.

Executive Order 14365 — Ensuring a National Policy Framework for Artificial Intelligence (state-law preemption push)

White House (Trump) · 2025-12-11in force

The administration's frontal challenge to state AI regulation: it directed DOJ to create an AI Litigation Task Force within 30 days (established January 9, 2026 by Attorney General memorandum) to challenge state AI laws as unconstitutional or preempted, ordered Commerce to publish an evaluation of onerous state AI laws and condition BEAD non-deployment funds on states' AI regulatory posture, directed the FCC to consider a preemptive federal AI reporting/disclosure standard, and directed the FTC to issue a policy statement on FTC Act preemption of state laws requiring alterations to truthful model outputs. The order itself cannot preempt state law — that requires Congress or successful litigation.

  • DOJ AI Litigation Task Force (Sec. 3) established January 9, 2026 to challenge state AI laws in court
  • BEAD non-deployment funds conditioned on state AI laws (Sec. 5); agencies to assess conditioning other discretionary grants
  • FCC directed to consider a federal AI reporting/disclosure standard (Sec. 6); FTC policy statement on preemption of state-mandated output alterations (Sec. 7)
  • Sec. 8 legislative-recommendation carve-outs preserve state child-safety, AI compute/data-center infrastructure, and state-procurement laws
primary source →

Full text read and verified from the Federal Register: 90 FR 58499, doc 2025-23092, signed Dec. 11, published Dec. 16, 2025. Note: the child-safety/infrastructure/procurement carve-outs apply to the proposed federal legislation (Sec. 8(b)), not to the order's litigation or funding provisions.

Executive Order 14363 — Launching the Genesis Mission

White House (Trump) · 2025-11-24in force

Launches a DOE-implemented national initiative — described in the order's own text as comparable in urgency and ambition to the Manhattan Project — to build the American Science and Security Platform, an integrated AI platform uniting national-laboratory supercomputers and federal scientific datasets (which the order calls the world's largest such collection) to train scientific foundation models and AI agents for research.

  • DOE implements; the Assistant to the President for Science and Technology (OSTP) provides general leadership via NSTC
  • American Science and Security Platform integrates national-lab compute, federal datasets, and scientific foundation models
  • Milestones at 60-270 days, including initial operating capability demonstration; at least 20 national S&T challenges to be identified
  • Funding expressly subject to available appropriations — scale of buildout not assured
primary source →

Full text read and verified from the Federal Register: 90 FR 55035, doc 2025-21665, signed Nov. 24, published Nov. 28, 2025. Note: the EO text does not itself use 'strategic national assets' language; that phrasing appears in secondary descriptions.

Winning the Race: America's AI Action Plan

White House (OSTP) · 2025-07-23announced

The administration's roadmap required by EO 14179, organizing roughly 90 policy actions under three pillars: accelerating AI innovation, building American AI infrastructure, and leading in international AI diplomacy and security. It is a policy document, not binding law, but frames the administration's subsequent executive action — including the three July 23, 2025 EOs signed alongside it, and it is expressly invoked in the Genesis Mission order (EO 14363).

  • Calls for removing regulatory barriers, including considering states' AI regulatory climate in federal funding decisions
  • Directs open-weight model support, data center buildout, and workforce measures
  • Recommends export of full-stack American AI to allies and tightened export-control enforcement
  • Implementation ongoing through mid-2026; no formal successor document identified as of July 2026
primary source →

PDF at this White House URL verified: title page reads 'Winning the Race: America's AI Action Plan, July 2025'; three-pillar structure confirmed from the table of contents. Non-binding roadmap — binding effect comes only through implementing EOs and rules.

Executive Order 14318 — Accelerating Federal Permitting of Data Center Infrastructure

White House (Trump) · 2025-07-23in force

Directs financial support (loans, grants, tax incentives, offtake agreements) for qualifying AI data center projects, new NEPA categorical exclusions and expedited FAST-41 treatment, Clean Water Act section 404 permitting review, and federal-land and military-installation siting through Interior, Energy, and Defense. It revoked Biden's EO 14141, replacing clean-energy-conditioned federal siting with a deregulatory permitting regime.

  • Expressly revokes EO 14141 of January 14, 2025 (quote verified verbatim)
  • Qualifying projects get expedited environmental review and streamlined permitting
  • Commerce directed to launch a financial-support initiative for qualifying projects
primary source →

White House URL verified live; all five directive categories confirmed in the text. Federal Register record verified (doc 2025-14212, published July 28, 2025). One of three EOs signed alongside the AI Action Plan on July 23, 2025.

Executive Order 14319 — Preventing Woke AI in the Federal Government

White House (Trump) · 2025-07-23in force

Requires federal agencies to procure only large language models that comply with two 'Unbiased AI Principles' — truth-seeking and ideological neutrality — and identifies DEI-related output shaping as inconsistent with those principles. Implemented through federal procurement contract terms rather than direct regulation of the private market, but functions as a de facto standard for any LLM vendor selling to the government.

  • Applies to federal LLM procurement; OMB implementation guidance required
  • Vendors face contract-term compliance and potential decommissioning costs for noncompliance
  • Transparency expectations on system prompts and model specifications for contractors
primary source →

Federal Register record verified: 90 FR 35389, doc 2025-14217, signed July 23, published July 28, 2025.

Executive Order 14320 — Promoting the Export of the American AI Technology Stack

White House (Trump) · 2025-07-23in force

Establishes the American AI Exports Program at the Commerce Department to assemble and promote full-stack US AI export packages — chips, servers, models, software, and cloud services — for allied and partner markets, with federal financing support through tools such as EXIM and DFC. Commerce stood up the program and issued its first call for proposals in late 2025.

  • 90-day deadline to establish the American AI Exports Program
  • Mobilizes federal financing tools for AI stack exports
  • Complements, and sits in tension with, chip export controls on China
primary source →

Federal Register record verified: 90 FR 35393, doc 2025-14218, signed July 23, published July 28, 2025.

Executive Order 14277 — Advancing Artificial Intelligence Education for American Youth

White House (Trump) · 2025-04-23in force

Establishes a White House Task Force on AI Education chaired by the OSTP Director, directs federal agencies to promote AI literacy in K-12 education, creates a Presidential AI Challenge, and prioritizes AI-related apprenticeships and educator training. It is a programmatic order without regulatory mandates on the private sector.

  • White House Task Force on AI Education chaired by the OSTP Director
  • Presidential AI Challenge to be established within 90 days, implemented within 12 months
  • No binding obligations on private AI developers
primary source →

White House URL verified live and matching. Federal Register record verified (doc 2025-07368, published Apr. 28, 2025).

OMB Memorandum M-25-21 — Accelerating Federal Use of AI through Innovation, Governance, and Public Trust

OMB · 2025-04-03in force

Rescinds and replaces Biden-era M-24-10 as the governing policy for federal agency use of AI. Retains Chief AI Officers and minimum risk-management practices for 'high-impact AI' but reframes the posture from risk mitigation to innovation acceleration; agencies must maintain public AI strategies and annual AI use-case inventories, with reporting cycles running through 2026.

  • Rescinds and replaces M-24-10; issued under EO 14179
  • 'High-impact AI' category replaces the safety-/rights-impacting taxonomy
  • Agencies must identify Chief AI Officers and update annual AI use-case inventories
primary source →

PDF at this URL verified: signed by Director Russell T. Vought, dated April 3, 2025; rescission of M-24-10 confirmed on page 1. The /2025/02/ upload path resolves.

OMB Memorandum M-25-22 — Driving Efficient Acquisition of Artificial Intelligence in Government

OMB · 2025-04-03in force

Rescinds and replaces M-24-18 as the government-wide AI procurement policy, emphasizing a competitive American AI marketplace, protecting agency data from vendor lock-in and unauthorized training use, and performance-based acquisition. It applies to contracts under solicitations issued on or after September 30, 2025, making FY2026 the first full compliance year for federal AI vendors.

  • Rescinds and replaces M-24-18; issued under EO 14179 and the Advancing American AI Act
  • Applies to solicitations issued on/after September 30, 2025 (180 days from issuance)
  • Contract terms must address IP/data rights and prevent vendor use of government data to train models without consent
  • Works in tandem with EO 14319's unbiased-AI procurement requirements for LLMs
primary source →

PDF at this URL verified: signed by Director Russell T. Vought, dated April 3, 2025; rescission of M-24-18 confirmed on page 1.

Executive Order 14179 — Removing Barriers to American Leadership in Artificial Intelligence

White House (Trump) · 2025-01-23in force

The foundational AI policy order of the second Trump administration, declaring a policy of sustaining US global AI dominance and directing review and revision of all actions taken under rescinded EO 14110. Section 4 ordered an AI Action Plan within 180 days (delivered July 23, 2025) and Section 5(b) ordered revision of OMB Memoranda M-24-10 and M-24-18 (delivered April 3, 2025 as M-25-21 and M-25-22). Remains the umbrella statement of federal AI policy as of mid-2026.

  • Frames AI policy around 'global AI dominance' and removing regulatory barriers
  • Parent authority for the July 2025 AI Action Plan and April 2025 OMB memoranda
  • Directed agencies to suspend, revise, or rescind actions inconsistent with the new policy
primary source →

White House URL verified live and matching; Federal Register record verified (doc 2025-02172, published Jan. 31, 2025; cited as 90 FR 8741).

Executive Order 14141 — Advancing United States Leadership in Artificial Intelligence Infrastructure (REVOKED)

White House (Biden) · 2025-01-14superseded

A late Biden-term order directing DOE and DOD to lease federal sites for gigawatt-scale AI data centers with clean-power conditions. It survived the January 2025 rescission wave but was expressly revoked on July 23, 2025 by Trump EO 14318, which replaced it with a deregulatory permitting regime; the revocation language in EO 14318 reads: "Executive Order 14141 of January 14, 2025 (Advancing United States Leadership in Artificial Intelligence Infrastructure), is hereby revoked."

  • Revoked July 23, 2025 by EO 14318 (revocation quote verified verbatim in EO 14318 text)
  • Its clean-energy matching conditions for federal-site data centers did not carry over
  • Federal-land leasing concept was retained but re-scoped under EO 14318
primary source →

Verified: 90 FR 5469, doc 2025-01395, signed Jan. 14, 2025, published Jan. 17, 2025. FR disposition data and the White House text of EO 14318 both confirm the revocation.

Executive Order 14110 — Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence (RESCINDED)

White House (Biden) · 2023-10-30superseded

The Biden administration's flagship AI executive order imposed government-wide AI governance duties, including Defense Production Act reporting requirements for developers of powerful dual-use foundation models. It was rescinded in full on January 20, 2025 by EO 14148 (Initial Rescissions of Harmful Executive Orders and Actions), the first day of the second Trump administration, and no longer has legal effect.

  • Rescinded January 20, 2025 by EO 14148; agencies directed to review and unwind implementing actions
  • Its compute-threshold reporting regime for frontier models lapsed with the rescission
  • Replaced as governing policy by EO 14179 (January 23, 2025)
  • Some implementing infrastructure continued in modified form (e.g., NIST's AI Safety Institute was rebranded the Center for AI Standards and Innovation in June 2025)
primary source →

Verified against Federal Register record (88 FR 75191, doc 2023-24283); FR disposition data confirms revocation by EO 14148 of Jan. 20, 2025.

Standards & frameworks3

NIST Generative AI Profile (NIST AI 600-1) — companion to the AI RMF

NIST · 2024-07-26standard

A cross-sectoral profile of the AI RMF identifying twelve risks unique to or exacerbated by generative AI (e.g., confabulation, CBRN information access, data privacy, provenance) with roughly 200 suggested actions. Developed under Biden EO 14110; it remains published and in use even though EO 14110 itself was rescinded in January 2025. Voluntary guidance, not binding.

  • Voluntary companion resource to AI RMF 1.0 focused on generative AI risks
  • Survived the January 20, 2025 rescission of EO 14110 (the Biden AI executive order that mandated its creation)
  • The base RMF it profiles is under an AI Action Plan-directed revision (removal of misinformation/DEI/climate references); no revised edition of AI 600-1 had been issued as of July 2026
primary source →

Canonical NIST publication PDF verified as resolving (July 2026); the July 26, 2024 release date is confirmed on NIST's AI RMF page. Check nist.gov for any revised edition once the RMF revision concludes.

White House Voluntary AI Commitments (2023–2024) — status under the current administration

White House (Biden administration) · 2023-07-21standard

Sixteen companies made eight voluntary commitments to the Biden White House on pre-release security testing, information sharing, cybersecurity and model-weight protection, and provenance/watermarking of AI content (Amazon, Anthropic, Google, Inflection, Meta, Microsoft, OpenAI in July 2023; Adobe, Cohere, IBM, Nvidia, Palantir, Salesforce, Scale AI, and Stability AI in September 2023; Apple in July 2024). Never legally binding, they were the template for later voluntary regimes. Under the current administration they have not been formally rescinded but are effectively dormant as a White House program — the voluntary-cooperation model now runs through CAISI's evaluation agreements and the 2025 AI Action Plan's security-oriented framework instead.

  • Purely voluntary — no enforcement mechanism; independent tracking finds uneven company follow-through (some commitments only 'technically' or 'partially' met)
  • Biden EO 14110, which operationalized several commitments into reporting requirements, was rescinded January 20, 2025
  • Successor model as of 2026: voluntary CAISI testing agreements and executive actions oriented to frontier-model security and national security rather than 'safety' framing
primary source →

Source upgraded to the official archived July 21, 2023 White House fact sheet (verified resolving on bidenwhitehouse.archives.gov). September 2023 signatories, the Apple addition, and follow-through assessments verified via the independent AI Lab Watch tracker (ailabwatch.org/resources/commitments). The 'dormant, not rescinded' characterization is an analytical judgment synthesized from post-2025 executive actions — flag as such.

NIST AI Risk Management Framework (AI RMF 1.0)

NIST · 2023-01-26standard

NIST's voluntary framework for mapping, measuring, managing, and governing AI risk, organized around four core functions (Govern, Map, Measure, Manage). It remains the de facto baseline for US AI governance programs and is referenced in state statutes (e.g., Colorado SB 24-205 safe harbors) and federal procurement guidance. It is not binding law; adoption is entirely voluntary.

  • Voluntary, sector-agnostic framework; no enforcement mechanism of its own
  • America's AI Action Plan (July 23, 2025) directed NIST to revise the RMF to eliminate references to misinformation, DEI, and climate change; NIST's page confirms 'AI RMF 1.0 is being revised'
  • Revision still in progress as of July 2026 — AI RMF 1.0 remains the operative version; no 'RMF 2.0' has been released
  • Ecosystem continues to grow: Generative AI Profile (July 2024), Cyber AI Profile work, and an AI RMF critical-infrastructure profile concept note released April 7, 2026
primary source →

Official NIST framework page verified July 2026: states the Jan 26, 2023 release date, that 'AI RMF 1.0 is being revised' (no version number or completion date given), and the April 7, 2026 critical-infrastructure profile concept note. The Action Plan directive is from the White House plan text; the revised RMF had not been published as of July 2026.