Who regulates AI in America?
AI oversight in the United States is divided among Congress, the White House, federal agencies, courts, and state governments.
← All field notesAsk who regulates artificial intelligence in America and the honest answer is: many institutions, in different ways, with large gaps between them.
There is no single American AI regulator. There is no comprehensive federal AI law covering every model, company, government agency, and high-impact decision. Oversight comes from existing laws, executive orders, agency rules, procurement requirements, court decisions, and a growing collection of state laws.
The result is a system that can look active and incomplete at the same time.
Congress writes the broadest rules
Congress has the power to create national laws governing AI. It can establish rights, assign authority to agencies, regulate interstate commerce, set requirements for federal procurement, and decide when federal law overrides state law.
Congress has already passed laws that touch AI, including measures related to federal coordination and government use. GAO identified 94 government-wide AI requirements drawn from federal laws, executive orders, and guidance as of July 2025.
Those requirements do not form a complete national regulatory system. Many were designed for federal agencies. Existing civil-rights, consumer-protection, employment, credit, healthcare, and privacy laws can apply when AI is used in those areas, but coverage depends on the activity and the law.
Congress is also the institution that can settle one of the largest current fights: how much room states should have to regulate AI. A federal law could create a national minimum while allowing stronger state protections. It could also preempt state rules and replace them with a single federal standard.
That choice will shape American AI regulation for years.
The president directs the executive branch
The White House can move quickly through executive orders, national strategies, and instructions to federal agencies. These actions can set priorities for government use, procurement, national security, export controls, research, and enforcement.
In March 2026, the Trump administration released a national AI legislative framework. It asked Congress for a consistent national policy and argued that conflicting state laws could weaken American innovation and competition.
The president can shape how agencies operate under existing authority. Lasting rules across the private economy often require legislation from Congress or formal agency action grounded in a law Congress already passed.
Executive policy can also change between administrations. Companies, agencies, and the public may see priorities shift before Congress establishes a durable statutory framework.
Federal agencies regulate sectors and conduct
Several agencies can oversee uses of AI that fall within their existing missions.
The Federal Trade Commission can pursue unfair or deceptive business practices. Employment agencies can address discrimination in hiring and work. Financial regulators can oversee lending and credit. Health agencies can regulate medical products and protect covered health information. Sector regulators can apply existing law when an AI system performs a familiar activity through new technology.
This approach has a practical strength. A discriminatory hiring model remains part of employment. An unsafe medical tool remains part of healthcare. A misleading AI product remains a consumer-protection issue.
The gaps appear between sectors. America’s privacy laws are divided across specific activities and types of data. GAO found that federal law leaves gaps and inconsistent levels of privacy protection. The agency also found that federal guidance did not fully address major privacy challenges for government AI use.
Agency capacity matters too. Oversight requires technical expertise, reliable inventories, access to information, and enough staff to investigate complex systems. GAO’s review of the IRS found skills gaps and an incomplete inventory of AI uses, showing how governance can struggle inside a single agency.
States are building their own rules
State governments have become major AI regulators.
They are introducing and passing laws covering government use, healthcare, discrimination, private-sector systems, synthetic media, elections, employment, and studies of future regulation. The National Conference of State Legislatures maintains a database of introduced and enacted AI legislation from 2025 onward, updated monthly.
State action allows experimentation. A state can respond to a local concern while Congress remains divided. Successful rules can become models for other states or for a future federal law.
Different rules also create compliance work. Definitions, deadlines, covered systems, reporting duties, and enforcement can vary across state lines. Large companies may absorb that complexity. Smaller businesses can face a heavier relative burden.
The policy question involves both protection and capacity. A national standard can create consistency. State authority can preserve a path for stronger and faster action. The details determine whether people receive a reliable floor of rights.
Courts decide what the rules mean
Courts enter when governments, companies, workers, consumers, or civil-rights groups challenge a policy or an AI-assisted decision.
Judges can decide whether an agency exceeded its authority, whether a state law conflicts with federal law, whether automated conduct violates an existing statute, and whether a person has standing to sue. Courts also shape what evidence plaintiffs need when the important information sits inside a proprietary system.
Litigation moves case by case. It can clarify rights and stop unlawful practices. It can also take years, especially when technical evidence and trade-secret claims complicate discovery.
Companies regulate themselves until someone else does
AI developers publish safety policies, usage rules, model evaluations, and voluntary commitments. These can reduce harm and establish useful practices. They remain controlled by the company.
A private policy can change. Enforcement can vary. The public may receive limited information about failures. Voluntary governance works best alongside external rules that establish minimum duties and independent accountability.
Standards bodies also matter. The National Institute of Standards and Technology AI Risk Management Framework gives organizations a voluntary structure for governing, mapping, measuring, and managing AI risk. It helps define good practice, while legal enforceability comes from contracts, agency requirements, or laws that adopt those practices.
Regulation is a chain of responsibility
Congress writes national law. The president directs the executive branch. Agencies apply authority within their sectors. States create additional rules. Courts interpret and enforce legal boundaries. Standards bodies define practices. Companies make daily decisions about systems already in use.
Every link matters.
The harder question is who answers when an AI system causes harm. A clear regulatory system gives that question a clear path: notice, records, a responsible party, human review, an appeal, and an institution with the authority to act.
America has many pieces of that system. The next stage is making them work together.