What an operator in the United States must know first: There is no federal AI Act, and the federal executive is now actively working against state AI laws rather than adding to them. Executive Order 14365 of 11 December 2025 directed the Attorney General to establish an AI Litigation Task Force whose sole responsibility is to challenge state AI laws, and named Colorado's statute in terms. Operator liability meanwhile rests where it always did: FTC Act Section 5, sector regulators, state statutes led by the Colorado AI Act (SB 24-205, in force 30 June 2026 after SB 25B-004 postponed it from 1 February 2026) and Texas TRAIGA (HB 149, effective 1 January 2026), and common law negligence. There is no single compliance path, no pre-deployment conformity assessment and no designated national AI authority. US operators with European-market exposure must separately assess EU AI Act deployer duties.

Key takeaways

  • No comprehensive federal AI statute exists. The one AI-specific federal statute enacted in the 119th Congress is the TAKE IT DOWN Act, Public Law 119-12 of 19 May 2025, which is narrow and concerns non-consensual intimate imagery and deepfakes.
  • Executive Order 14110 is revoked and should not be relied on. Executive Order 14148 of 20 January 2025 rescinded it, and EO 14179 of 23 January 2025 replaced it. OMB Memorandum M-24-10 is likewise rescinded and replaced by M-25-21 of 3 April 2025. The operative federal posture is EO 14179, the America's AI Action Plan of 23 July 2025, and EO 14365 of 11 December 2025 on a national policy framework for AI.
  • The Colorado AI Act (Colorado Revised Statutes section 6-1-1701 et seq., SB 24-205) entered force on 30 June 2026 (postponed from the original 1 February 2026 date by SB 25B-004) and is the most significant US state AI statute. It imposes a duty of care, risk management, impact assessment, consumer notice, and incident reporting obligations on deployers of high-risk AI systems in Colorado.
  • Federal sector regulators remain the primary operative layer, but their AI-specific guidance has thinned. The CFPB withdrew Circulars 2022-03, 2023-03 and 2024-06 with effect from 12 May 2025, and the EEOC's AI technical assistance documents are no longer published at eeoc.gov. The underlying statutes, ECOA, Regulation B, the FCRA, Title VII and the ADA, are unchanged and still apply.
  • FTC Act Section 5 operates as a horizontal backstop: AI outputs that are unfair or deceptive expose operators to Federal Trade Commission enforcement regardless of sector.
  • US operators with EU exposure face EU AI Act Article 26 deployer obligations in parallel. The EU Act applies to operators established outside the EU when their system's output is used in the EU (Article 2(1)(c)).
  • Existing case law, including Mata v. Avianca (S.D.N.Y. 2023) and Moffatt v. Air Canada (British Columbia Civil Resolution Tribunal, 2024, a Canadian decision cited by analogy), supports the position that operators are liable under existing law for foreseeable harm caused by AI agent outputs.
  • AI liability insurance products are more developed in the US than in any other market. Standalone products from HSB, Armilla, and Munich Re aiSure are available; policy review for AI-related exclusions is a material operational step.

The federal vacuum: what exists and what does not

The United States federal government has not enacted a comprehensive AI statute. The policy instruments that exist at the federal level apply primarily to federal agencies and to a narrow class of AI developers working on the most powerful models, not to the broad population of businesses deploying AI agents in commercial contexts.

The instruments most often cited as the federal AI framework are no longer in effect. Executive Order 14110, Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence, signed 30 October 2023, was revoked by Executive Order 14148 of 20 January 2025, Initial Rescissions of Harmful Executive Orders and Actions, which lists it expressly. Executive Order 14179 of 23 January 2025, Removing Barriers to American Leadership in Artificial Intelligence, refers to it in terms as the revoked Executive Order 14110. OMB Memorandum M-24-10 of 26 March 2024 was rescinded and replaced by OMB Memorandum M-25-21 of 3 April 2025, Accelerating Federal Use of AI through Innovation, Governance, and Public Trust, which says so in its opening line.

What is operative is a different set. EO 14179 sets the current policy direction. The America's AI Action Plan, published as Winning the AI Race on 23 July 2025, accompanied by Executive Orders 14318, 14319 and 14320, sets the programme. Executive Order 14409 of 2 June 2026 addresses advanced AI innovation and security.

The instrument that most directly affects a private operator's state-law exposure is Executive Order 14365 of 11 December 2025, Ensuring a National Policy Framework for Artificial Intelligence. It directs the Attorney General to establish, within thirty days, an AI Litigation Task Force whose sole responsibility is to challenge state AI laws. It directs Commerce to publish an evaluation of onerous state AI laws within ninety days. It conditions BEAD broadband funding on states not having such laws. And it names Colorado, stating that a new Colorado law banning algorithmic discrimination may even force AI models to produce false results. Any assessment of how durable the Colorado AI Act is has to account for it.

Congress has not enacted a comprehensive federal AI statute. A search of enacted public laws of the 119th Congress returns three touching AI, and only one is AI-specific: the TAKE IT DOWN Act, Public Law 119-12 of 19 May 2025, on non-consensual intimate imagery and deepfakes. A proposed moratorium on state AI enforcement was stripped before enactment: the text of Public Law 119-21 of 4 July 2025 contains no AI moratorium and no preemption provision, and neither does Public Law 119-75 of 3 February 2026. The federal baseline for private-sector AI operators therefore remains the FTC Act, sector-specific statutes, and state law.

The Colorado AI Act: the first comprehensive US state statute

Colorado's Senate Bill 24-205, the Consumer Protections for Artificial Intelligence Act, was signed by Governor Polis on 17 May 2024 and entered force on 30 June 2026 (postponed from the original 1 February 2026 date by SB 25B-004). It is the first US state statute to impose a comprehensive, risk-based set of obligations on AI developers and deployers. Operators doing business in Colorado whose AI systems meet the high-risk definition must comply.

Who the statute covers

The Act applies to developers and deployers of high-risk AI systems. A developer is a person doing business in Colorado that develops, or substantially modifies, a high-risk AI system. A deployer is a person doing business in Colorado that deploys a high-risk AI system. The doing business in Colorado standard follows the Colorado Consumer Protection Act's established interpretation and reaches out-of-state operators whose systems have effects on Colorado consumers.

A high-risk AI system under CRS section 6-1-1701 is an AI system that makes, or is a substantial factor in making, a consequential decision about a consumer. Consequential decisions are decisions that have a material legal or similarly significant effect on a consumer's access to, or the cost or terms of, services or opportunities in these domains: education enrolment and opportunity, employment or employment opportunity, a financial or lending service, an essential government service, a healthcare service, housing or a housing opportunity, an insurance underwriting or claim assessment, a legal service, a service of important public interest, or any other domain that the Colorado Attorney General designates by rule.

Small businesses are not fully exempt, and there are sector carve-outs that matter more. The statute provides that an insurer or fraternal benefit society subject to the insurance commissioner's rules, or a developer of an AI system used by such an insurer, is in full compliance with the Act, and that a bank, credit union or affiliate subject to prudential examination under qualifying published guidance is likewise in full compliance. An operator inside either perimeter should establish that before building a parallel Colorado programme.

Sourcing note, 17 August 2026: the operative statutory text could not be read at source in this pass. leg.colorado.gov returns HTTP 403 to the signed, final and enrolled PDFs, and the codified statutes are delegated to a commercial publisher. The scope, carve-out, enforcement and reporting statements above are taken from the official bill summary as enacted at leg.colorado.gov. The following specific figures come from the same secondary summary rather than from the statutory text and are not confirmed against it: the count of ten consequential-decision categories, the fewer than fifty full-time equivalents small-deployer threshold, and the USD 20,000 per violation civil penalty. Treat them as indicative and read the enrolled text before relying on any of them.

Core obligations for deployers

The Act imposes four primary obligations on deployers. First, the duty of care: deployers must use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination. Algorithmic discrimination means any condition in which the use of an AI system results in an unlawful differential treatment or impact that disfavours an individual or group of individuals on the basis of a protected class characteristic under Colorado law, including race, color, national origin, sex, disability, age, religion, or sexual orientation.

Second, the risk management programme: deployers must implement and maintain a risk management programme for each high-risk AI system. Two distinct mechanisms sit around it and an earlier version of this guide collapsed them into one. The rebuttable presumption of reasonable care arises from complying with the enumerated statutory duties: the risk management policy and programme, the impact assessment, the annual review, the consumer notice, the correction right, the human-review appeal, the public statement and the Attorney General disclosure. Separately, there is an affirmative defense for compliance with a nationally or internationally recognised AI risk management framework that the Act or the Attorney General designates. Framework alignment is a defense, not the source of the presumption, and describing it as a safe harbour against algorithmic discrimination claims overstates it.

Third, the impact assessment: deployers must complete an impact assessment for each high-risk AI system before deployment and at least annually thereafter. The impact assessment must include a description of the AI system and its intended purpose, the categories of personal data processed, the reasonably foreseeable risks of algorithmic discrimination, and the mitigations in place. Impact assessments must be retained for at least three years.

Fourth, consumer notice, correction and appeal: before or at the time of a consequential decision, deployers must disclose that a high-risk AI system was used, describe the type of system and the categories of data it processed, and give the consumer a route to correct inaccurate personal data the system relied on. The statute also requires an opportunity to appeal an adverse consequential decision, via human review where technically feasible. The appeal right is a distinct obligation and not merely part of the notice.

Incident reporting: if a deployer discovers that its high-risk AI system has caused algorithmic discrimination, it must report that fact to the Colorado Attorney General within ninety days. Enforcement of the Act is through the Attorney General under the Colorado Consumer Protection Act; there is no private right of action under the statute itself, though common law claims remain available.

Enforcement and penalties

The Colorado Attorney General enforces the AI Act through the same mechanisms as the Colorado Consumer Protection Act. Violations constitute unfair or deceptive trade practices. Civil penalties of up to USD 20,000 per violation are available. The Attorney General may also seek injunctive relief and may require corrective action. The statute does not create a private right of action, though it does not displace common law claims in tort or under other consumer protection statutes.

Federal sector regulators: the primary operative layer

For most US operators, the binding AI governance obligations they encounter in practice come from sector regulators rather than from a horizontal AI statute. The sector framework is comprehensive in regulated industries and largely absent in unregulated ones.

Financial services: OCC, Federal Reserve, and CFPB

Banks and other federally regulated financial institutions are subject to model risk management guidance issued jointly by the Office of the Comptroller of the Currency (OCC Bulletin 2011-12) and the Federal Reserve (Supervisory Letter SR 11-7). While issued before the current generation of AI systems, both agencies have confirmed through examination guidance and supervisory letters that the model risk management framework applies to AI models used in credit decisions, fraud detection, anti-money laundering screening, and market risk. The framework requires model validation, ongoing monitoring, documentation of model logic and assumptions, and senior management accountability for model risk. Banks failing to maintain adequate model governance face supervisory action including Matters Requiring Attention and formal enforcement orders.

The Consumer Financial Protection Bureau enforces the Equal Credit Opportunity Act and the Fair Credit Reporting Act. Under ECOA and Regulation B, lenders must provide adverse action notices stating the specific reasons for an adverse credit decision, and a lender that cannot explain why its model denied an application faces exposure. That statutory position is unchanged.

What has changed is the guidance layer. The CFPB withdrew a large set of interpretive rules, policy statements and advisory opinions with effect from 12 May 2025. The withdrawal list expressly includes Circular 2022-03 on adverse action notification requirements in connection with credit decisions based on complex algorithms, Circular 2023-03 on adverse action notification requirements and the proper use of the sample forms in Regulation B, and Circular 2024-06 on algorithmic scores in hiring and promotion decisions. An earlier version of this guide cited Circular 2022-03 as current in four places. A lender should now reason from ECOA and Regulation B themselves rather than from withdrawn CFPB circulars.

Employment: EEOC and ADA

Title VII of the Civil Rights Act and the Americans with Disabilities Act apply to AI-assisted hiring, promotion and performance management decisions, and that is a matter of statute rather than guidance. An employer using a screening tool that produces a statistically significant disparate impact on a protected class faces Title VII disparate impact exposure regardless of design intent, and the ADA reasonable accommodation obligation is not discharged by pointing at a model's output.

The EEOC's own AI technical assistance documents, on the ADA and on assessing adverse impact in software, algorithms and artificial intelligence, are no longer published at eeoc.gov. Both canonical URLs return a 404, verified on 17 August 2026. The only AI material now on the site concerns the agency's own AI use under OMB memoranda. An earlier version of this guide treated those documents as current and described the resulting expectations as binding. The statutes are unchanged; the agency's AI-specific interpretive material is not there to rely on. Operators using AI in HR decisions should still conduct pre-deployment disparate impact analysis, document business necessity for any practice with identified disparate impact, and keep records sufficient to answer an investigation, because Title VII requires that whether or not the EEOC restates it.

Healthcare: FDA and AI/ML software

The Food and Drug Administration regulates AI-based software as a medical device under 21 U.S.C. 321(h) when the software is intended to diagnose, cure, mitigate, treat, or prevent a disease or condition, or when it significantly affects the structure or function of the body. The FDA's 2021 AI/ML-Based Software as a Medical Device Action Plan established a lifecycle approach to AI regulation, requiring pre-market authorisation or clearance for Class II and Class III devices (510(k) or PMA pathway), post-market performance monitoring, real world performance reporting, and the proposed Predetermined Change Control Plan framework that allows approved modification pathways without full re-authorisation.

An operator that deploys an AI system for clinical decision support that crosses the SaMD boundary, including AI diagnostic tools, AI-assisted image interpretation, and AI-driven treatment recommendation systems, is subject to FDA regulation as a medical device manufacturer or distributor. Unauthorised commercial distribution of an uncleared or unapproved AI medical device is a prohibited act under 21 U.S.C. 331.

FTC Act Section 5: the horizontal backstop

Section 5 of the Federal Trade Commission Act prohibits unfair or deceptive acts or practices in or affecting commerce. The Federal Trade Commission has confirmed through enforcement actions, policy statements, and guidance that Section 5 applies to AI-generated outputs deployed in commercial contexts.

Deception under Section 5 covers any representation, omission, or practice that is likely to mislead consumers acting reasonably under the circumstances, in a way that is material to the consumer. An AI agent that makes false or misleading factual statements to consumers, fails to disclose material information such as its non-human identity when that fact is material, or generates outputs that could reasonably be understood as factual representations when they are not, creates Section 5 exposure for the operator that deploys it.

Unfairness under Section 5 covers acts or practices that cause or are likely to cause substantial injury to consumers that is not reasonably avoidable and not outweighed by countervailing benefits to consumers or competition. An earlier version of this guide attributed the FTC's position on biased automated decisions, hidden AI identity and AI-facilitated fraud to a 2023 report titled Protecting Consumers in the Era of Generative AI. No such report could be located at ftc.gov, and both the report and the propositions resting on it have been removed.

The FTC's actual AI enforcement record is a better guide to its position, and it is documented. Operation AI Comply, announced on 25 September 2024, brought actions including against DoNotPay, which settled for USD 193,000 over claims about a world's first robot lawyer, and against Rytr over AI-generated fake reviews, alongside Ascend Ecom, Ecommerce Empire Builders and FBA Machine. The announcement also references earlier matters including Rite Aid, NGL Labs, Career Step, Automators and CRI Genetics. That is what the FTC has done, and it is the more reliable signal of what it will do.

The FTC does not require pre-deployment registration. Its enforcement model is post-harm and conduct-based. Consent decrees and civil penalty actions by the FTC in adjacent technology-deception cases provide guidance on the expected standard: operators must have a reasonable basis for any factual claim their AI system makes, must disclose AI identity when material, and must have in place reasonable procedures to detect and correct AI outputs that are false or misleading.

The EU AI Act and US operators: extraterritorial reach

US operators with European market exposure face EU AI Act obligations that are independent of US federal and state law. Article 2(1)(c) of Regulation (EU) 2024/1689 brings within scope providers established outside the EU where the output of their AI system is used in the EU, and deployers established outside the EU where the affected persons are located in the EU.

The practical effect: a US company whose AI agent is accessible to EU users, whose AI system outputs decisions about EU residents, or which is deployed in the supply chain of an EU-based business, is within the EU AI Act's scope for the EU-facing portion of its operation. The applicable obligations are those of a deployer under Article 26 of the Regulation for high-risk systems, and the transparency obligations of Article 50 for AI systems that interact with natural persons, in force from 2 August 2026 and not deferred by the Digital Omnibus.

The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force on 27 July 2026. It moved the Annex III stand-alone high-risk compliance deadline from 2 August 2026 to 2 December 2027, and the Annex I deadline to 2 August 2028. It is adopted and in force, and US operators should plan against the new dates. The Article 50 transparency obligations were not deferred and have applied since 2 August 2026.

For a full analysis of EU AI Act deployer duties see the Article 26 deployer obligations guide on agentliability.eu. For the EU transparency obligations applicable from 2 August 2026 see the Article 50 guide.

The state patchwork: beyond Colorado

Colorado is the most comprehensive example, but it is not alone. The US state AI regulation landscape in 2026 is an emerging patchwork of narrower targeted statutes, with meaningful implications for operators doing business nationally.

Illinois enacted the Artificial Intelligence Video Interview Act (P.A. 101-0260) in 2020, requiring employers using AI to analyse video interviews to disclose AI use to candidates before the interview, obtain consent, provide candidates with a summary of the AI features assessed, and destroy video and analysis data within thirty days of request. The Act applies to any employer that solicits applications from Illinois residents, regardless of where the employer is incorporated.

Texas enacted the Texas Responsible Artificial Intelligence Governance Act, HB 149, signed on 22 June 2025 and effective 1 January 2026. An earlier version of this guide described it inaccurately in four respects and the corrections change the analysis. There is no USD 25 million revenue threshold: the Act reaches any person who promotes, advertises or conducts business in Texas, produces products or services used by Texas residents, or develops or deploys AI systems in Texas. It does not mandate a risk management programme, bias testing, transparency disclosures or an AI governance officer; section 552.105(e) instead offers a liability defense for substantial compliance with the NIST AI Risk Management Framework, which is the opposite structure.

What TRAIGA actually prohibits is intent-based. Section 552.056 bars developing or deploying AI with the intent to unlawfully discriminate against a protected class, and states expressly that a disparate impact is not sufficient by itself to demonstrate an intent to discriminate. That is a materially lighter standard than Colorado's algorithmic discrimination duty of care, and an operator that has built a disparate-impact testing programme for Colorado is doing more than Texas asks. Enforcement is exclusively by the Attorney General, with a sixty day cure period and no private right of action.

California is the state most often described incorrectly. SB 1047 was vetoed by the Governor on 29 September 2024 and is not law; an earlier version of this guide said three times that California had enacted it. The California frontier-model statute that does exist is SB 53, the Transparency in Frontier Artificial Intelligence Act, chaptered on 29 September 2025 as Chapter 138, Statutes of 2025, which adds obligations for large frontier developers to the Business and Professions Code.

Three further California instruments matter to a deployer. AB 2013, on training data transparency for generative AI, was chaptered on 28 September 2024 as Chapter 817. SB 942, the California AI Transparency Act, was chaptered on 19 September 2024 as Chapter 291, and its operative date was moved from 1 January 2026 to 2 August 2026 by AB 853, Chapter 674, Statutes of 2025; it is in force now, and AB 853 adds duties for large online platforms and generative AI hosting platforms from 1 January 2027 and for capture-device manufacturers from 1 January 2028. And the California Privacy Protection Agency's automated decision-making technology regulations, adopted by the Board on 24 July 2025 and filed with the Secretary of State on 22 September 2025, require compliance with the ADMT requirements for significant decisions from 1 January 2027, with risk-assessment compliance beginning 1 January 2026 and the first attestation and summary due to the CPPA by 1 April 2028. For a business making significant automated decisions about Californians, the CPPA regulations are the most operationally demanding item on this list.

Illinois HB 3773, amending the Illinois Human Rights Act to address AI in employment decisions, and New York City Local Law 144 on automated employment decision tools, are the two employment-side instruments a national employer should check. Neither could be verified at its own official source in this verification pass, because ilga.gov was unreachable, so their commencement dates are not stated here and should be confirmed directly.

Virginia, Connecticut, Indiana and a number of other states have advanced or enacted AI governance bills covering automated decision-making in employment, consumer finance and healthcare. Operators doing business nationally need a monitoring process, and now also need to track the federal challenge to state AI laws under Executive Order 14365.

Common law liability: what case law already confirms

US courts have not applied any AI-specific statute to a claim for AI agent error. They have, however, applied existing common law and professional liability frameworks to AI-related conduct in ways that define the operative standard of care for operators.

In Mata v. Avianca, Inc. (S.D.N.Y. 2023), a federal district court imposed Rule 11 sanctions on attorneys who submitted court filings citing cases fabricated by an AI system. The court found that the duty to verify the accuracy of factual representations before filing on behalf of a client applied with full force to AI-generated content. The attorney's reliance on an AI system's output without independent verification was not a mitigating factor; it was the conduct sanctioned. The implications for operators who deploy AI systems in legal or advisory contexts are direct: professional obligations of care are not suspended by the presence of an AI intermediary.

In Moffatt v. Air Canada (BC Civil Resolution Tribunal, 2024), the tribunal held Air Canada liable for its customer service chatbot's materially incorrect representation about the airline's bereavement fare policy. Air Canada argued that the chatbot was a separate entity and that the airline was not bound by its statements. The tribunal rejected this argument: a business operating an AI agent is responsible for the statements that agent makes to consumers, on the same basis as it is responsible for statements made by human employees. The case is a Canadian decision, but its negligent misrepresentation reasoning is directly applicable under analogous US state law frameworks, and it has been cited in US academic and practitioner analysis as the controlling analogy for AI chatbot liability.

The negligence frame that emerges from these and analogous cases is consistent: an operator that deploys an AI agent in a context where its outputs could cause foreseeable harm to a consumer, a contracting party, or a professional obligation owes a duty of care. Failure to implement reasonable verification, oversight, or correction mechanisms is a breach of that duty. Damages recoverable include economic loss, the cost of corrective action, and in appropriate cases professional discipline or sanctions.

AI insurance for US operators

The United States is the most developed market for AI-specific liability insurance. Unlike the EU, where purpose-built AI agent insurance is nascent, US operators can access both standard policy adaptations and standalone AI products.

Technology errors and omissions policies are the baseline coverage vehicle for most technology companies deploying AI systems. Standard technology E and O policies cover claims arising from errors, omissions, or failures in technology services, which can include AI agent errors depending on policy wording. Operators must review whether their policy's definition of technology services covers AI-generated outputs and whether any AI exclusion endorsements have been added. ISO endorsements in the CG 40 47 series on commercial general liability policies are reported to exclude AI-triggered losses from standard CGL coverage. Sourcing note, 17 August 2026: this form number rests on broker and law-firm reporting and has not been read from a specimen or confirmed against the filed forms at ISO, Verisk or a state filing portal; its siblings CG 40 48 01 26 and CG 35 08 01 26 have been read from specimen facsimiles. A search engine confirming the number may be drawing on our own pages. It is kept here because it is how a reader finds the endorsement on their own schedule, not because it is verified.

HSB (Hartford Steam Boiler, Munich Re group) introduced AI Liability Insurance for small and medium-sized US businesses on 18 March 2026. HSB describes it as filling a gap created by general liability exclusions, covering liability for bodily injury caused by the insured's use of AI, liability for property damage caused by the insured's use of AI, and personal and advertising injury liability for claims that the insured's AI tools breached privacy, defamed a person, or infringed copyright. Standard limits are USD 25,000 or USD 50,000 with a USD 500 deductible, and higher limits are available. Limits and exclusions should be confirmed with the carrier directly as product terms evolve.

Armilla operates as a Lloyd's of London coverholder and offers affirmative AI liability insurance with limits up to USD 25 million per organisation, underwritten by certain underwriters at Lloyd's. Armilla states that coverage may not be available in all jurisdictions and is offered only through properly licensed surplus lines brokers. Where framework alignment is priced in explicitly, the clearest published example is AIUC-1, the AI agent standard published by the Artificial Intelligence Underwriting Company, which states that it operationalises ISO/IEC 42001, the NIST AI RMF, MITRE ATLAS and the OWASP Top 10 for LLMs.

Munich Re's aiSure product offers AI performance insurance that settles on measurable AI system performance data rather than requiring a fault finding. This structure is particularly relevant for operators in sectors where quantifying AI output accuracy is feasible, such as financial services AI systems with measurable prediction accuracy requirements.

The ElevenLabs AIUC-1 policy, announced on 12 February 2026, represents the leading edge of AI agent-specific insurance structured around the AIUC-1 certification standard. The AIUC-1 framework assesses agents across data and privacy, safety, security, reliability, accountability, and societal impact dimensions through adversarial simulation. US operators deploying voice or text AI agents may find this product line relevant as the market matures. For an analysis of the European market for AI insurance see agentinsured.eu.

The contrast with the EU deployer model

The structural difference between US and EU AI governance is the deployment framework it creates for operators. The EU AI Act's Article 26 is a single statutory provision that applies to all deployers of high-risk AI systems across all sectors, regardless of whether a sector-specific regulation also applies. It creates a unified compliance obligation: document the system, implement human oversight, conduct a fundamental rights impact assessment in certain public contexts, report serious incidents to the national supervisory authority, register the system in the EU database where required, and cooperate with market surveillance. National competent authorities can impose penalties up to EUR 15 million or 3 percent of global annual turnover for deployer violations.

No equivalent unified instrument exists in the United States. A US financial services company deploying an AI credit-scoring system must comply with the OCC's model risk management expectations (a supervisory examination standard), the CFPB's ECOA adverse action notice requirements (a statutory obligation), the Colorado AI Act if it serves Colorado consumers (a state statute), and FTC Act Section 5 (a federal enforcement standard). These four frameworks overlap in coverage but differ in their procedural requirements, documentation expectations, and penalty mechanisms. A single compliance document does not satisfy all four. The transaction cost of US AI compliance is therefore higher in structural complexity, even if the formal penalty ceiling for any single framework is lower than under the EU Act.

For global operators operating in both the US and EU markets, the EU AI Act's requirements are generally the more demanding procedural baseline. An operator that has built a compliance programme to meet EU AI Act Article 26 will typically exceed the specific documentation and oversight requirements of Colorado SB 24-205 and will have established the audit trail and impact assessment processes required for OCC model risk management. The reverse is not true: a US compliance programme designed only for the domestic market will not satisfy the EU Act's requirements.

What operators should do now

The practical compliance priorities for a business deploying AI agents in the United States in 2026 are the following.

First, determine whether your AI system is a high-risk AI system under the Colorado AI Act. If it makes or substantially contributes to consequential decisions for Colorado consumers in any of the ten covered domains, the obligations under CRS section 6-1-1703 apply from 30 June 2026 (postponed from the original 1 February 2026 date by SB 25B-004). Conduct an impact assessment, document your risk management programme against NIST AI RMF 1.0 or ISO/IEC 42001, and implement the required consumer notice and correction mechanism. If you have not done so, assess whether the Colorado Attorney General's ninety-day algorithmic discrimination incident reporting obligation has been triggered.

Second, identify your federal sector regulator and its AI governance expectations. For banks and credit unions: confirm model validation and documentation consistent with OCC Bulletin 2011-12 and SR 11-7. For consumer lenders: confirm adverse action notice capability under ECOA, including the ability to explain AI-driven adverse decisions in specific factor terms. For employers using AI hiring tools: conduct a disparate impact analysis and document business necessity. For healthcare AI: confirm FDA SaMD classification and obtain any required clearance or authorisation before commercial deployment.

Third, review your current insurance policies for AI-related exclusions and assess whether standalone AI liability coverage is appropriate. Review your technology errors and omissions, cyber and commercial general liability policies. Ask your broker for the actual endorsement document rather than a form number, model the uncovered exposure, and assess supplemental products from HSB, Armilla or Munich Re aiSure as applicable to your sector and scale.

Fourth, monitor the state pipeline in both directions. Texas TRAIGA has been in force since 1 January 2026. California's SB 942 has been operative since 2 August 2026 and the CPPA's ADMT requirements bite on 1 January 2027. At the same time, Executive Order 14365 has put a Department of Justice task force behind challenges to state AI laws, so a state obligation you build to today may be litigated. Assign tracking responsibility for both the legislation and the litigation.

Fifth, if you have any EU market exposure, assess your EU AI Act obligations independently of your US compliance programme. Article 50 transparency obligations have applied to any AI system interacting with EU natural persons since 2 August 2026. Annex III high-risk deployer obligations under Article 26 now apply from 2 December 2027 and Annex I obligations from 2 August 2028, under Regulation (EU) 2026/1744. Treat the EU programme as a parallel workstream, not a derivative of your US posture.

Frequently asked questions

Is there a federal AI Act in the United States?

No. The only AI-specific federal statute enacted in the 119th Congress is the TAKE IT DOWN Act, Public Law 119-12 of 19 May 2025, on non-consensual intimate imagery and deepfakes. Executive Order 14110 was revoked by EO 14148 on 20 January 2025 and replaced by EO 14179, and OMB Memorandum M-24-10 was rescinded and replaced by M-25-21 on 3 April 2025. AI operator liability derives from the FTC Act, sector-specific statutes, state law and common law negligence.

What is the Colorado AI Act and does it apply to my business?

The Colorado Consumer Protections for Artificial Intelligence Act (SB 24-205, CRS section 6-1-1701 et seq.) entered force on 30 June 2026 (postponed from the original 1 February 2026 date by SB 25B-004). It applies to any person doing business in Colorado that deploys an AI system making or substantially affecting consequential decisions in ten specified domains including employment, financial services, housing, healthcare, and insurance. If your system makes consequential decisions about Colorado consumers in those domains, the statute applies to you regardless of where you are incorporated.

Which federal agencies enforce AI-related obligations on private operators?

The Federal Trade Commission enforces Section 5 unfairness and deception standards across sectors. The Consumer Financial Protection Bureau enforces ECOA and FCRA in consumer finance. The Equal Employment Opportunity Commission enforces Title VII and the ADA in employment. The Office of the Comptroller of the Currency and the Federal Reserve enforce model risk management standards for federally regulated banks. The Food and Drug Administration regulates AI-based software as a medical device. There is no single federal AI regulator analogous to the EU's national competent authorities under the EU AI Act.

Does the EU AI Act apply to a US company?

Yes, if the company's AI system output is used in the EU or affects EU residents. Article 2(1)(c) of Regulation (EU) 2024/1689 extends the Act to providers and deployers established outside the EU when the system's output is used in the EU. A US company with EU-facing AI operations must assess its EU deployer obligations under Article 26 independently of its US compliance programme. The Article 50 transparency obligations apply from 2 August 2026 and are not deferred by the proposed Digital Omnibus.

Is the NIST AI RMF mandatory?

No. NIST published AI RMF 1.0 as NIST AI 100-1 on 26 January 2023 and states that it is intended for voluntary use. The Generative AI Profile, NIST AI 600-1, followed on 26 July 2024. Voluntary does not mean irrelevant: the Colorado AI Act provides an affirmative defense for compliance with a nationally or internationally recognised AI risk management framework that the Act or the Attorney General designates, and Texas TRAIGA section 552.105(e) offers a liability defense for substantial compliance with the NIST AI RMF. AIUC-1, the AI agent standard published by the Artificial Intelligence Underwriting Company, states that it operationalises ISO/IEC 42001, the NIST AI RMF, MITRE ATLAS and the OWASP Top 10 for LLMs, so framework alignment carries into certification and the insurance built on it.

What AI liability insurance options exist for US operators?

Technology errors and omissions policies are the standard baseline. HSB introduced AI Liability Insurance for US small and medium-sized businesses on 18 March 2026, with standard limits of USD 25,000 or USD 50,000. Armilla offers affirmative AI liability insurance as a Lloyd's of London coverholder, with limits up to USD 25 million per organisation. Munich Re aiSure provides performance-based AI insurance, written with Mosaic Insurance at an initial capacity of EUR, USD or CAD 15 million. The ElevenLabs policy of 12 February 2026, written on AIUC-1 certification, represents purpose-built AI agent insurance. Operators should review existing policy AI exclusions before assuming coverage.

What do the Mata v. Avianca and Moffatt v. Air Canada cases mean for US operators?

Mata v. Avianca (S.D.N.Y. 2023) established that professional duties of verification apply with full force to AI-generated outputs: attorneys who filed briefs containing AI-fabricated citations without verification faced court sanctions. Moffatt v. Air Canada (BC Civil Resolution Tribunal, 2024) established that a business is liable for materially false statements made by its AI chatbot, on the same basis as statements by its human employees. Together, these cases confirm that under existing law, operators are liable for foreseeable harm caused by AI agent outputs, and the absence of a specific AI statute does not provide a defence.

How does the US approach compare to the EU for a global operator?

The EU AI Act creates a single horizontal deployer obligation under Article 26, enforced by national competent authorities with penalties up to EUR 15 million or 3 percent of global turnover. The US has no equivalent. US AI compliance is assembled from multiple overlapping frameworks: FTC, sector regulators, state statutes, and common law. The EU framework is procedurally more demanding for high-risk systems. A compliance programme designed for EU AI Act Article 26 will generally satisfy Colorado SB 24-205 requirements and establish the audit trail expected under US sector guidance. The reverse does not hold: a US-only compliance programme will not satisfy EU obligations.

What other US states have AI statutes?

Texas enacted TRAIGA, HB 149, signed 22 June 2025 and effective 1 January 2026. It has no revenue threshold and mandates no risk management programme; it prohibits developing or deploying AI with intent to unlawfully discriminate, and states expressly that disparate impact alone is not sufficient to show intent. Illinois has had the AI Video Interview Act in force since 1 January 2020. In California, SB 1047 was vetoed on 29 September 2024 and is not law; SB 53 was chaptered on 29 September 2025, AB 2013 on 28 September 2024, and SB 942 became operative on 2 August 2026 via AB 853. The CPPA's automated decision-making technology regulations require compliance for significant decisions from 1 January 2027. Executive Order 14365 has established a Department of Justice task force to challenge state AI laws, so this landscape is contested as well as growing.

References

  1. Colorado Consumer Protections for Artificial Intelligence Act, Colorado Senate Bill 24-205, codified at Colorado Revised Statutes section 6-1-1701 et seq., in force 30 June 2026 (postponed from the original 1 February 2026 date by SB 25B-004).
  2. Executive Order 14110, Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence, 30 October 2023. Revoked by Executive Order 14148, Initial Rescissions of Harmful Executive Orders and Actions, 20 January 2025, 90 Fed. Reg. 8237. federalregister.gov.
  3. Executive Order 14179, Removing Barriers to American Leadership in Artificial Intelligence, 23 January 2025, 90 Fed. Reg. 8741. Executive Orders 14318, 14319 and 14320, 23 July 2025. Executive Order 14365, Ensuring a National Policy Framework for Artificial Intelligence, 11 December 2025, 90 Fed. Reg. 58499. Executive Order 14409, Promoting Advanced Artificial Intelligence Innovation and Security, 2 June 2026, 91 Fed. Reg. 34565. federalregister.gov.
  4. The White House. Winning the AI Race: America's AI Action Plan, 23 July 2025. whitehouse.gov.
  5. TAKE IT DOWN Act, Public Law 119-12, 19 May 2025. Public Law 119-21 of 4 July 2025 and Public Law 119-75 of 3 February 2026 contain no AI moratorium and no preemption provision. govinfo.gov.
  6. OMB Memorandum M-25-21, Accelerating Federal Use of AI through Innovation, Governance, and Public Trust, 3 April 2025, which rescinds and replaces OMB Memorandum M-24-10 of 26 March 2024. whitehouse.gov.
  7. Federal Trade Commission Act, 15 U.S.C. 45(a) (Section 5 unfair or deceptive acts or practices).
  8. Federal Trade Commission, Operation AI Comply, announced 25 September 2024, including actions against DoNotPay, Rytr, Ascend Ecom, Ecommerce Empire Builders and FBA Machine. ftc.gov. A report titled Protecting Consumers in the Era of Generative AI, cited in an earlier version of this guide, could not be located at ftc.gov and is not relied on.
  9. OCC Bulletin 2011-12, Sound Practices for Model Risk Management; Federal Reserve SR 11-7, Supervisory Guidance on Model Risk Management, April 2011.
  10. Equal Credit Opportunity Act, 15 U.S.C. 1691 et seq., and Regulation B. Note that CFPB Circulars 2022-03, 2023-03 and 2024-06 were withdrawn with effect from 12 May 2025 by the CFPB rule Interpretive Rules, Policy Statements, and Advisory Opinions; Withdrawal, 90 Fed. Reg. 20084. federalregister.gov.
  11. Equal Employment Opportunity Commission AI technical assistance documents on the ADA and on assessing adverse impact in software, algorithms and artificial intelligence are no longer published at eeoc.gov; both canonical URLs returned 404 on 17 August 2026. Title VII and the ADA are unaffected.
  12. Title VII of the Civil Rights Act of 1964, 42 U.S.C. 2000e et seq. (disparate impact, Section 703(k)).
  13. Food and Drug Administration, Artificial Intelligence and Machine Learning (AI/ML)-Based Software as a Medical Device Action Plan, January 2021.
  14. Texas Responsible Artificial Intelligence Governance Act, H.B. 149 (89R), signed 22 June 2025, effective 1 January 2026. Section 552.056 (intent standard, disparate impact insufficient), section 552.105(e) (NIST AI RMF liability defense). capitol.texas.gov.
  15. Illinois Artificial Intelligence Video Interview Act, P.A. 101-0260, in force 1 January 2020.
  16. California SB 1047, Safe and Secure Innovation for Frontier Artificial Intelligence Models Act, vetoed by the Governor on 29 September 2024 and not law. California SB 53, Transparency in Frontier Artificial Intelligence Act, chaptered 29 September 2025, Chapter 138, Statutes of 2025. AB 2013, training data transparency, chaptered 28 September 2024, Chapter 817. SB 942, California AI Transparency Act, chaptered 19 September 2024, Chapter 291, operative 2 August 2026 under AB 853, Chapter 674, Statutes of 2025. leginfo.legislature.ca.gov.
  17. California Privacy Protection Agency, automated decision-making technology regulations, adopted 24 July 2025, filed with the Secretary of State 22 September 2025. ADMT compliance for significant decisions from 1 January 2027; risk assessment compliance from 1 January 2026, first attestation and summary due 1 April 2028. cppa.ca.gov.
  18. Mata v. Avianca, Inc., No. 22-cv-1461 (S.D.N.Y.), order issued 22 June 2023.
  19. Moffatt v. Air Canada, BC Civil Resolution Tribunal, 2024 BCCRT 149 (21 February 2024).
  20. NIST AI Risk Management Framework 1.0, NIST AI 100-1, 26 January 2023, intended for voluntary use. nist.gov.
  21. NIST AI 600-1, Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, 26 July 2024. nist.gov.
  22. ISO/IEC 42001:2023, Information Technology: Artificial Intelligence: Management System.
  23. Regulation (EU) 2024/1689 (EU AI Act), Official Journal L 2024/1689, 12 July 2024, Article 2(1)(c) (extraterritorial scope), Article 26 (deployer obligations), Article 50 (transparency). Regulation (EU) 2026/1744, the Digital Omnibus on AI, in force 27 July 2026, deferring Annex III to 2 December 2027 and Annex I to 2 August 2028.
  24. ElevenLabs AIUC-1 AI agent insurance, announced 12 February 2026. Sources: ElevenLabs blog and PR Newswire, February 2026.