The most common misconception about AI regulation in the United States is that there isn't any yet. In fact, most consequential automated decisions have been regulated for decades — by statutes written for the decision, not the technology. Credit denials trigger adverse-action notice duties whether a loan officer or a model said no. Hiring tools that screen out protected groups create disparate-impact exposure whether the screen is a manager's gut or an algorithm. Deceptive claims about what your AI does are ordinary FTC deception.
On top of that older base, a second layer of AI-specific law is arriving: New York City's bias-audit rule for hiring tools, Colorado's first-in-the-nation AI act, automated decision-making provisions inside state privacy laws, and disclosure statutes in several states. Governance means building one program that satisfies both layers.
Layer one: the law that already applies
Start with the statutes that never mention algorithms. In employment, Title VII, the ADEA, and the ADA apply fully to algorithmic screening: the EEOC's published guidance has warned that employers remain responsible for discriminatory outcomes of tools they buy, that disparate-impact analysis applies to selection algorithms, and that tools screening out disabled applicants who could perform with accommodation raise ADA problems — a reason to connect AI screening to your existing accommodation request process.
In credit, the Equal Credit Opportunity Act requires specific, accurate reasons in adverse-action notices — "the model said so" is not a lawful explanation — and the Fair Credit Reporting Act attaches duties whenever third-party data or scores about consumers feed decisions on credit, housing, insurance, or employment. Background-check and tenant-screening algorithms live inside the same FCRA framework that governs credit report accuracy and disputes. And across every sector, the FTC treats unsubstantiated AI claims, undisclosed synthetic content in commerce, and unfair automated practices as violations of its existing authority — its business guidance makes clear that "the algorithm did it" has never been a defense.
Watch out: Buying a tool does not outsource the liability. In nearly every regime — employment, credit, housing, insurance — the legal duty sits with the company making the decision, not the vendor that built the model. Vendor indemnities help with cost, not with compliance.
Layer two: the AI-specific statutes
New York City Local Law 144
Since enforcement began in July 2023, NYC's rule on automated employment decision tools (AEDTs) has required employers and employment agencies using such tools for NYC candidates to obtain an annual independent bias audit, publish a summary of the results, and give candidates advance notice that an automated tool will be used, with an alternative process available on request. The city's Department of Consumer and Worker Protection page hosts the rules and FAQs. Even outside New York, LL144's audit-plus-notice model has become the template other jurisdictions copy, which makes voluntary alignment a reasonable hedge.
The Colorado AI Act
Colorado's SB 24-205, signed in 2024, is the first U.S. state law regulating "high-risk" AI systems across sectors. It imposes a duty of reasonable care on both developers and deployers to protect consumers from algorithmic discrimination in consequential decisions, and it contemplates risk-management programs, impact assessments, consumer notices, and disclosure duties. The statute was amended in 2025 before its obligations took hold, with effective dates pushed into 2026 and details still being refined — so treat its final shape as evolving and check current Colorado guidance before building to a frozen summary. The direction of travel, though, is clear, and several other legislatures are working from similar drafts.
Automated decision-making inside privacy statutes
Most comprehensive state privacy laws give consumers an opt-out from profiling used for decisions with legal or similarly significant effects, and require data protection assessments for such profiling. California's privacy regulator has gone further, adopting regulations on automated decision-making technology, risk assessments, and cybersecurity audits under the CCPA/CPRA framework. If you have mapped your obligations under the state privacy patchwork, your AI governance program should reuse that inventory rather than duplicating it. A few narrower statutes round out the layer: Illinois has regulated AI analysis of video interviews since 2020, and Utah requires disclosure when consumers interact with generative AI in certain contexts.
Building the governance program
Regulators converge on the same architecture, and the voluntary NIST AI Risk Management Framework supplies neutral vocabulary for it: govern, map, measure, manage. In practice, a defensible program answers five questions in order.
- What automated decisions do we make? Inventory every system that decides or substantially influences outcomes for people — including "shadow AI" features switched on inside vendor software you already license. You cannot govern what you have not listed.
- Which are high-stakes? Classify by consequence: employment, credit, housing, insurance, healthcare, education, essential services. High-stakes systems get the full treatment below; low-stakes systems get lightweight review.
- Who owns each system? Assign a named business owner and a review cadence. Unowned models drift; regulators and plaintiffs both notice.
- How do we test them? Pre-deployment and periodic testing for accuracy and disparate impact across protected groups, documented with methodology and results — independent audits where law (or prudence) requires.
- What do affected people see? Notices before or at the decision point, meaningful adverse-action reasons where required, a channel for appeal or human review, and honored opt-outs where privacy law grants them.
Vendor management is the load-bearing wall of the program, because most companies deploy models they did not build. Contract for documentation of training data and testing, cooperation with audits and impact assessments, notice of material model changes, and allocation of costs when a tool draws regulatory attention — terms that belong in the same negotiation as the rest of your software contract's data and liability provisions.
Practical step: Write the impact assessment before deployment, not after a demand letter. A dated, honest pre-deployment assessment showing you looked for disparate impact and mitigated what you found is the single most valuable document in nearly every later dispute.
Documentation that holds up later
When an agency inquiry or lawsuit arrives, it arrives as a document request. Programs succeed or fail on whether these exist:
- The system inventory with risk classifications and named owners.
- Impact or risk assessments for each high-stakes system, versioned over time.
- Bias-testing methodology and results, plus remediation records where testing found problems.
- Copies of consumer- and candidate-facing notices, and logs proving they were delivered.
- Human-review procedures and records showing reviewers can and do overrule the system.
- Vendor contracts, audit reports, and model-change notifications.
- Board or leadership minutes showing governance oversight actually occurred.
Two cautions on human review. First, a human who rubber-stamps 400 machine recommendations a day is not meaningful review, and regulators increasingly say so. Second, employees who raise concerns about a system's fairness may be engaged in protected activity under anti-discrimination or whistleblower statutes — handle internal AI complaints with the same care as any other retaliation-sensitive report.
Quick answers
Does adding a human in the loop take us outside these laws?
It can change which specific provisions apply — some rules target decisions made without meaningful human involvement — but it never immunizes the outcome. Discrimination law judges results and processes, not org charts. If the human reviewer lacks the information, time, or authority to disagree with the model, expect regulators to treat the decision as automated regardless of the label.
We only use AI for first-round resume screening. Is that covered?
Very likely yes, where AI-specific rules exist, and yes under discrimination law everywhere. Screening tools that substantially assist or replace discretionary hiring decisions are the core target of NYC's Local Law 144, and disparate-impact analysis under federal employment law applies to any selection procedure, first-round or final. Early-funnel tools often carry the highest exposure because they touch the most candidates.
What penalties are actually on the table?
It depends on the hook: civil penalties per violation under city and state statutes, enforcement actions by the FTC or state attorneys general with orders that can include deleting models built on improperly obtained data, agency proceedings and private damages suits under employment and credit statutes, and contract claims between vendors and deployers. The per-violation math matters — a noncompliant tool that touched thousands of applicants multiplies quickly.
Is the EU AI Act something a U.S. company needs to track?
Only if you have EU exposure — offering systems in the EU market or affecting people there — in which case its risk-tier obligations phase in on their own timeline and deserve separate analysis. For purely domestic operations it does not apply, but it influences U.S. drafting: Colorado's act borrows recognizably from the EU's high-risk framing, so the EU text is a preview of vocabulary you may see in future state bills.
A sensible order of operations
Inventory first: list every system influencing consequential decisions, including vendor features. Classify by stakes, assign owners, and stand up testing and documentation for the high-stakes tier. Map jurisdiction-specific duties — NYC audits and notices, Colorado's act as its 2026 obligations settle, privacy-law opt-outs and assessments — onto that inventory. Fix vendor contracts at renewal. Then keep a standing watch on new statutes, because layer two is still being written, and programs built on the inventory-classify-test-document spine absorb each new law far more cheaply than programs improvised statute by statute.