The Current AI Legal Landscape in the United States in 2025
The Current AI Legal Landscape in the United States in 2025
Updated as of February 2025
Currently, AI is governed by direct
state legislation targeting AI, existing federal and state legislation that apply
to AI, Presidential Executive Orders, Judicial Rulings, and local laws.
Importantly, there is no comprehensive federal legislation or regulations in
the US that directly regulate the development of AI or specifically prohibit or
restrict their use.
That said, there are more than 120 AI
bills being considered by the US Congress, covering a wide range of issues such
as AI education, copyright disclosure, AI robocalls, biological risks, and AI's
role in national security, including prohibiting AI from launching nuclear
weapons autonomously.
· https://www.technologyreview.com/2024/09/18/1104015/here-are-all-the-ai-bills-in-congress-right-now/
The below is an outline of the current
regulatory framework in the US governing AI use.
1.
Laws Directly Governing AI
Legislation
Directly Governing AI
As stated above, there are currently to
federal laws that directly regulate AI - however, several states have enacted
legislation that does and that is currently in effects, or scheduled to come
into force. An un-exhaustive list of state legislation specifically directed at
AI that is in force is listed below:
- Utah Artificial Intelligence Policy Act - In
May 2024, the Utah Artificial Intelligence Policy Act went into
effect. The Act requires individuals and entities to disclose the use of
GenAI in communications with consumers.
- https://le.utah.gov/~2024/bills/static/SB0149.html
- For
individuals and entities that engage in “regulated occupations” (i.e.,
those who must obtain a license or state certification to practice the
occupation, such as lawyers or health care providers), the disclosure
must be made “prominently” at the beginning of any communication with the
consumer, regardless of whether the consumer asks whether they are
dealing with a GenAI system (i.e., a proactive disclosure obligation).
- For
individuals and entities that do not engage in “regulated occupations,”
the disclosure must be made “clearly and conspicuously” only if the
consumer asks whether they are dealing with a GenAI system (i.e., a
reactive disclosure obligation).
- Non-compliant
individuals and entities may be fined up to US$2,500 per violation by the
Utah Division of Consumer Protection.
- Tennessee’s The Ensuring Likeness Image and Voice
Security (ELVIS) Act - became effective on July 1, 2024.
- https://www.capitol.tn.gov/Bills/113/Bill/HB2091.pdf
- https://www.armstrongteasdale.com/thought-leadership/artificial-intelligence-and-copyrights-tennessees-elvis-act-becomes-law/
- This
law addresses unauthorized AI-generated reproductions of individuals'
voices and likenesses, particularly protecting artists from unapproved
use of their identities through technologies like deepfakes and voice cloning.
· California’s Defending
Democracy from Deepfake Deception Act - requires large online platforms to
identify and block the publication of materially deceptive content related to
elections in California during specified time periods before and after an
election. Additionally, under this Act, large online platforms must label –
within 72 hours of notice – certain content as inauthentic, fake, or false
during specified time periods before and after an election in California.
- California’s Use of Likeness: Digital
Replica Act - establishes a cause of action for beneficiaries of
deceased celebrities to recover damages for the unauthorized use of an
AI-created digital replica of the celebrity in audiovisual works or sound
recordings. This Act requires deployers of AI systems to obtain the
consent of a deceased personality's estate before producing, distributing,
or making available the digital replica of a deceased personality's voice
or likeness in an expressive audiovisual work or sound recording.
- California’s Contracts against Public
Policy: Personal or Professional Services: Digital Replica Act -
limits the enforceability of contract provisions that allow the use of an
individual’s digital replica (a highly realistic AI-generated likeness or
voice) to replace their work. Such provisions are unenforceable unless
they include a clear description of intended uses and the individual was
represented by legal counsel or a labor union addressing digital replicas
in a collective bargaining agreement. The law aims to protect performers,
artists, and professionals from vague or exploitative contract terms while
ensuring transparency in licensing agreements for AI-generated likenesses.
- California’s Health Care Services:
Artificial Intelligence Act - requires health care providers that
use GenAI to generate patient communications to (i) disclaim that the
communication was generated by a GenAI system, and (ii) provide clear
instructions for how the patient can contact a human health care provider
for assistance. Where the GenAI communication has been reviewed by a human
health care provider, the disclaimer requirements do not apply.
- California’s Generative Artificial Intelligence
Accountability Act - Set to go
in effect on January 1, 2026.
- https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202320240AB2013
- The
Generative Artificial Intelligence Accountability Act mandates that the
California Office of Emergency Services conduct a risk analysis of
potential threats that “generative artificial intelligence” (an
artificial intelligence system that can generate derived synthetic
content, including text, images, video, and audio that emulates the
structure and characteristics of the system’s training data) poses to the
state’s critical infrastructure, including scenarios that could result in
mass casualty events. The office is required to provide a high-level
summary of this analysis to the California legislature. Additionally, any
state agency or department that uses generative AI to communicate with
individuals about government services and benefits must ensure that such
communications include a notice indicating that the message was generated
by AI and information on how to contact a human employee of the
department.
- New York’s Local Law 144 of 2021 - issued by the City of New York enacted that
"prohibits employers and employment agencies [in the city] from using
an automated employment decision tool unless the tool has been subject to
a bias audit within one year of the use of the tool, information about the
bias audit is publicly available, and certain notices have been provided
to employees or job candidates"
- Multi-State DeepSeek and Other Chinese Apps Ban
- Multiple
States (New York, Texas, and Virginia), have issued banns on Chine AI
apps and other apps, such as DeepSeek, across all government networks and
devices. Click here for more information
- https://www.jdsupra.com/legalnews/three-states-ban-deepseek-use-on-state-1633720/
In addition, the following is a
non-exhaustive list of State AI acts have been enacted, and will be coming into
force in the near future:
- The Colorado AI Act - Consumer Protections for Artificial
Intelligence - On May 17, 2024, Colorado enacted the first comprehensive
US AI legislation, the Colorado AI Act. The Act will go into effect on
February 1, 2026.
- https://leg.colorado.gov/bills/sb24-205
- https://advance.lexis.com/container/?pdmfid=1000516&crid=6a2f3aae-0174-4dd6-9673-c1c9e27c132c&func=LN.Advance.ContentView.getFullToc&nodeid=AAGAABAABAAS&typeofentry=Breadcrumb&config=0345494EJAA5ZjE0MDIyYy1kNzZkLTRkNzktYTkxMS04YmJhNjBlNWUwYzYKAFBvZENhdGFsb2e4CaPI4cak6laXLCWyLBO9&action=publictoc&pddocfullpath=%2Fshared%2Fdocument%2Fstatutes-legislation%2Furn%3AcontentItem%3A6C70-KFJ3-RSXR-S4CT-00008-00&pdtocfullpath=%2Fshared%2Ftableofcontents%2Furn%3AcontentItem%3A62D6-BVG3-CH1B-T3RY-00008-00&ecomp=h2vckkk&prid=7fc17746-9c49-48bd-8327-37eeacee11bb
- The
Act creates duties for developers and for those that deploy AI. Unlike
certain state privacy laws, there is no revenue threshold for
applicability – the Act applies to all developers and deployers of
high-risk AI systems in Colorado.
- The
Act focuses on automated decision-making systems and defines a covered
high-risk AI system as one that "when deployed, makes, or is a
substantial factor in making a consequential decision" that has a
material legal or similarly significant effect on the provision or denial
to any consumer of, or the cost or terms of: education, employment,
essential government services, healthcare, housing, insurance, and legal
services. There is a specific focus on bias and discrimination, and
developer and deployers must use reasonable care to avoid discrimination
via AI systems that make, or are a substantial factor in making a
consequential decision in the above enumerated fields.
o
The Colorado
Attorney General has rule-making authority to implement, and exclusive authority
to enforce, the requirements of the Act. A developer or deployer who
violates the Act is deemed to engage in unfair or deceptive trade practices.
- California AI Transparency Act – Set to go in effect on January 1, 2026. It mandates
that "Covered Providers" (AI systems that are publicly
accessible within California with more than one million monthly visitors
or users) implement comprehensive measures to disclose when content has
been generated or modified by AI. This Act outlines requirements for AI
detection tools and content disclosures, and establishes licensing
practices to ensure that only compliant AI systems are permitted for
public use. Covered Providers that violate the Act are liable for a
penalty of US$5,000 per violation per day.
- https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202320240SB942
- The
CA AI Transparency Act mandates that “Covered Providers” (AI systems that
are publicly accessible within California with more than one million
monthly visitors or users) implement comprehensive measures to disclose
when content has been generated or modified by AI. This Act outlines
requirements for AI detection tools and content disclosures and
establishes licensing practices to ensure that only compliant AI systems
are permitted for public use.
- Key
Obligations:
- AI
Detection Tool: Providers must offer a free, publicly accessible tool
for users to verify whether AI has generated or modified the content
(including text, images, video, and audio), including system provenance
data. While the detection tool must be publicly accessible, providers
may impose reasonable limitations to prevent or respond to demonstrable
risks to the security or integrity of their generative AI systems.
Further, providers must collect user feedback related to the tool’s
efficacy and incorporate relevant feedback into improvements.
- Manifest
and Latent Disclosures: Providers are required to disclose AI-generated
content clearly, conspicuously, and appropriately based on the medium of
communication and in such a way that a reasonable person would
understand. It should identify the content as AI-generated and be
permanent or extraordinarily difficult to remove, to the extent
technically feasible. Embedded disclosures must include the provider’s
name, the generative AI system’s name and version number, the creation
or alteration date, and a unique identifier. It should be detectable by
the AI detection tool, consistent with industry standards, and permanent
or extraordinarily difficult to remove.
- License
Revocation: Providers of generative AI systems must contractually
require licensees to maintain the system’s capability to include the
mandated disclosures. If a provider discovers that a licensee has
modified the system to remove required disclosures, the license must be
revoked within 96 hours and the licensee must cease using the system
immediately.
- Enforcement
and Penalties: Covered providers that violate the Act are liable for a
penalty of $5,000 per violation per day, enforceable through civil
action by the CA Attorney General, city attorneys, or county counsel.
- Generative AI: Training Data Transparency Act - Set to go in effect on January 1, 2026. It mandates
that developers of generative AI systems (GenAI) publish a
"high-level summary" of the datasets used to develop and train
GenAI systems. For example, developers of GenAI systems would need to
publish a summary of the following information, which is non-exhaustive:
- Sources
and owners of the datasets
- Description
of how the datasets further the intended purpose of the GenAI system
- Whether
the datasets include any information protected by IP law
- Whether
the datasets include personal information as defined in the CCPA
o
Whether the
datasets were purchased or licensed by the developer
o
https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202320240AB2013
- Unified Definition of Artificial Intelligence - Set
to go in effect on January 1, 2026.
- California
Assembly Bill 2885 ("AB 2885") aims to unify the definition of
"Artificial Intelligence" across various California laws. This
standardization is crucial, as varying definitions can lead to
inconsistencies in regulation and oversight in the rapidly evolving field
of AI. Specifically, AB 2885 defines Artificial Intelligence "an
engineered or machine-based system that varies in its level of autonomy and
that can, for explicit or implicit objectives, infer from the input it
receives how to generate outputs that can influence physical or virtual
environments".
- https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240AB2885
Proposed
and Upcoming Legislation
More than 40 state AI bills were introduced
in 2023, with Connecticut and Texas actually adopting statutes. Both
of those enacted statutes establish state working groups to assess state
agencies’ use of AI systems to ensure they do not result in unlawful
discrimination.
- (Vetoed)
Senate Bill 1047: Safe and Secure Innovation for Frontier Artificial
Intelligence Models Act.
- summary
2.
Existing Legislation that Applies to AI
Existing legislation has been the
primary way in which the US regulates AI as established law, including privacy
and intellectual property laws, which are generally applicable to AI technologies.
Notably, in April 2023, the Federal Trade Commission, Equal Employment
Opportunity Commission, Consumer Financial Protection Bureau, and Department of
Justice issued a joint statement noting that "existing legal authorities
apply to the use of automated systems and innovative new technologies."
-
https://www.ftc.gov/system/files/ftc_gov/pdf/EEOC-CRT-FTC-CFPB-AI-Joint-Statement%28final%29.pdf
Accordingly, developers, users,
operators and deployers of AI systems should anticipate that existing law will
apply to any regulated activity that uses AI, and consult legal counsel about
the potential liabilities that may arise. While potentially novel, the use of
AI does not per se provide a shield from the application of existing law.
Similarly, state regulators that
regulate privacy legislation likely also have the authority to regulate AI
vis-à-vis existing privacy provisions.
The following is a non-exhaustive list
of legislation that have been held to apply to AI:
- Federal:
- Federal Aviation Administration
Reauthorization Act - which
includes language requiring review of AI in aviation.
- National Defense Authorization Act
for Fiscal Year 2019 - which
directed the Department of Defense to undertake various AI-related
activities, including appointing a coordinator to oversee AI activities.
o
Telephone Consumer Protection Act - The
Federal Communications Commission issued a declaratory ruling stating that the
restrictions on the use of "artificial or pre-recorded voice"
messages in the 1990s era Telephone Consumer Protection Act include AI technologies
that generate human voices, demonstrating that regulatory agencies will apply
existing law to AI.8
§ https://docs.fcc.gov/public/attachments/FCC-24-17A1.pdf
- State:
o
Privacy Laws
- Several states have enacted comprehensive privacy legislation that can also
regulate AI. A non-exhaustive list of notable state legislation includes:
§ The
California Privacy Protection Act (CPPA),
contains provisions on the use of automated decision-making tools.
- Additionally, the California Privacy Protection Agency released
draft rules on these provisions governing consumer notice,
access and opt-out rights with respect to automated decision-making
technology, which the rules define broadly. The regulations are still
being finalized but will likely cover expanded uses of AI. The draft
rules, which are still being formalized, would require significant
disclosure about businesses’ implementation and use of ADMT.
- California Consumer
Privacy Act
· Draft Automated
Decision-making Technology Regulations
§ The
Biometric Information Privacy Act in Illinois, which is very broad and allows for extremely high damages for
violations. There is currently pending litigation in the AI context.
·
link
o
IP Laws – see
RiteAid discussion below.
·
Other:
o
The National Association of Insurance Commissioners - issued a model bulletin that
focuses on governance frameworks, risk management protocols and testing
methodologies that insurers should have in place to govern their use of AI
systems that impact insurance consumers.
§ As of February 1, 2025, several states have adopted this
model bulletin, including Alaska, Connecticut, Illinois, Kentucky, Maryland,
Nevada, New Hampshire, Pennsylvania, Rhode Island, Vermont, and Washington.
§ In these states, the principles outlined in the NAIC
Model Bulletin are in effect, requiring insurers to develop, implement, and
maintain a written program for the responsible use of AI systems. This includes
establishing governance frameworks, risk management protocols, and internal
controls to mitigate the risk of adverse consumer outcomes.
§ However, the adoption of the model bulletin varies by
state. Some states have implemented the bulletin with modifications, while
others have developed their own AI-related regulations or guidance. For
instance, Colorado established governance and risk management framework
requirements for life insurers regarding the use of external consumer data,
algorithms, predictive models, and similar systems, aiming to prevent unfair
discrimination.
§ Therefore, whether the NAIC Model Bulletin is
considered law depends on the specific regulations and guidance adopted by each
state. Insurers should consult the relevant regulatory authorities in the
states where they operate to understand the applicable requirements concerning
the use of AI systems.
o link
3.
Rulings
AI is also governed by court decisions
and regulatory body enforcement and rulings. For example, in relation to
Intellectual Property Law, Existing intellectual property laws also apply to
AI, both with respect to the data AI technologies are trained upon and the outputs
of such technologies. For example, with respect to outputs, the US District
Court has held that human authorship is an essential part of a valid copyright
claim, and the Copyright Office will refuse to register a work unless it was
created by a human being." There are also numerous cases before the courts
in the US alleging copyright infringement, among other things, with respect to
training data.
In addition, the Federal Trade
Commission has evoked an interest in and focus on regulating AI through
enforcement. On December 19, 2023, the FTC settled a significant action focused
on artificial intelligence bias and discrimination against Rite Aid regarding
the company’s use of facial recognition technology for retail theft deterrence.
Rite Aid faced allegations that the company improperly used artificial
intelligence-based facial recognition technology in its retail stores. The FTC
charged that Rite Aid deployed this technology without adequate safeguards,
leading to numerous false identifications of customers as potential
shoplifters, disproportionately affecting women and people of color. As part of
the settlement, Rite Aid:
· is prohibited from using facial recognition technology
for surveillance purposes for five years
· must delete all photos and videos of consumers used in
its AI facial recognition
- after Rite
Aid’s ban on using AI facial recognition expires, if Rite Aid operates AI
facial recognition technology for surveillance, it must maintain a
comprehensive automated biometric security or surveillance system
monitoring program that identifies and addresses the risks of such
operation and notifies consumers of its use of AI facial recognition.
- must also
provide a means for consumers to lodge complaints, and investigate and
respond to all complaints received, among other requirements.
This illustrative case provides guidance
on the FTC’s enforcement on AI systems.
4.
Proposed Legislation
Proposed Legislation (non-exhaustive
list):
- The REAL Political Advertisements Act - which aims to regulate generative AI in
political advertisements.
- The Stop Spying Bosses Act, which aims to regulate employers
surveilling employees with machine learning and AI techniques.
- The Draft No FAKES Act, which would protect voice and visual
likenesses of individuals from unauthorized recreations from Generative
AI.
- The AI Research Innovation and Accountability Act, which calls for greater transparency,
accountability and security in AI, while establishing a framework for AI
innovation. It would create an enforceable testing and evaluation standard
for high-risk AI systems and require companies that use high-risk AI
systems to produce transparency reports. It also empowers the National
Institute of Standards and Technology to issue sector-specific recommendations
to regulate them.
- The American Privacy Rights Act, which would create a comprehensive consumer
privacy framework. The draft bill includes provisions on algorithms,
including a right to opt-out of covered algorithms used to make or
facilitate consequential decisions.
5.
Executive Orders:
There are no current Presidential Executive orders that governs
AI.
President Trump’s January 23, 2025 Executive Order, titled “Removing Barriers to American Leadership in Artificial Intelligence
Executive Order”, revoked Biden’s Executive Order 14110 of October 30, 2023, titled “Safe, Secure, and
Trustworthy Development and Use of Artificial Intelligence”, among other things.
For a discussion of the prior order click here.
President Trump’s Executive Order sets out
that a plan to achieve the policy set out in the executive order, shall be
delivered to the president in 180 days of the order being signed, which is July
22, 2025. The Policy is:
Sec. 2. Policy. It is the policy of the
United States to sustain and enhance America’s global AI dominance in order to
promote human flourishing, economic competitiveness, and national security.
Biden’s Executive Order listed the following eight key principles
and priorities to encourage the responsible development of AI technologies and
safeguard against potential harms:
- AI must be safe and secure
- To lead in AI, the US must
promote responsible innovation, competition and collaboration
- Responsible development and use
of AI requires a commitment to supporting American workers
- AI policies must advance equity
and civil rights
- The interests of Americans who
increasingly use, interact with, or purchase AI and AI-enabled products in
their daily lives must be protected
- Privacy and civil liberties must
be protected
- The federal government must
manage the risks of its own use of AI
- The federal government should
exercise global leadership in societal, economic and technological
progress
Biden’s The Executive Order also called on the Department of
Commerce to issue guidance for content authentication and watermarking to label
AI-generated content. Lastly, The order required developers of artificial
intelligence models to notify the federal government if their models were
trained using computing power exceeding certain thresholds. Specifically, any
AI model trained with more than 10²⁶ floating-point operations (FLOPs), or
models trained primarily on biological sequence data using over 10²³ FLOPs,
fell under this mandate. Additionally, computing clusters with a theoretical
maximum capacity exceeding 10²⁰ FLOPs per second were also subject to reporting
requirements.
6.
International Commitments
Council
of Europe's Framework Convention on Artificial Intelligence
As for international commitments, on
September 5, 2024, the United States joined Andorra, Georgia, Iceland, Norway,
the Republic of Moldova, San Marino, the United Kingdom, Israel, and the
European Union to sign the Council of Europe’s Framework Convention on AI.
The treaty will enter into force on the first day of the month following three
months after five signatories, including at least three Council of Europe
Member States, have ratified it. Countries from all over the world will be
eligible to join and commit to its provisions.
· https://rm.coe.int/1680afae3c
The Council of Europe's Framework
Convention on Artificial Intelligence is the first legally binding
international treaty designed to ensure that AI development and deployment
uphold human rights, democracy, and the rule of law. The Convention requires
signatory states to implement measures that ensure AI activities comply with
fundamental principles, including human dignity, individual autonomy, equality,
non-discrimination, privacy, data protection, transparency, oversight,
accountability, responsibility, reliability, and safe innovation. Signatories
are obligated to establish risk and impact assessment frameworks throughout the
AI system lifecycle, provide accessible remedies for individuals adversely
affected by AI systems, and maintain effective oversight mechanisms. The
Convention also emphasizes the importance of public awareness and education
regarding AI technologies.
The
European Union's Artificial Intelligence Act’s Extra-Territorial Scope
The European Union's Artificial
Intelligence Act (AI Act), adopted in March 2024, establishes a comprehensive
regulatory framework for AI systems, aiming to ensure they align with
fundamental rights and European values. The Act classifies AI applications
based on risk levels—unacceptable, high, limited, and minimal—and imposes
corresponding obligations, including prohibitions and compliance requirements.
It came into force on August 1, 2024, with various provisions becoming
applicable over the following 6 to 36 months.
-
https://artificialintelligenceact.eu/ai-act-explorer/
Notably, the AI Act may have an
extraterritorial reach, applying to providers and deployers outside the EU if
their AI systems' outputs are used within the EU, thereby potentially affecting
U.S. entities whose AI technologies impact individuals or markets in the EU.
The EU AI Act applies not only to AI
systems developed or deployed within the EU but also to those placed on the EU
market or whose outputs are used in the EU, regardless of where the provider or
deployer is based. This means that even companies operating outside the EU,
such as in the U.S., could be subject to the Act if their AI systems influence
EU users or businesses. For example, a U.S.-based company offering an AI-powered
resume screening tool that EU companies use for hiring decisions may need to
comply with the Act's transparency and risk management requirements.
7.
Other
- National AI Initiative Act of 2020 - focused on expanding AI research and
development and created the National Artificial Intelligence Initiative
Office that is responsible for "overseeing and implementing the US
national AI strategy."
- The White House Blueprint for an AI Bill
of Rights - was introduced by the Biden Administration through the
White House Office of Science and Technology Policy (OSTP) on October 4,
2022. It asserts guidance around equitable access and use of AI
systems. The AI Bill of Rights provides five principles and associated
practices to help guide the design, use and deployment of "automated
systems" including safe and effective systems; algorithmic
discrimination and protection; data privacy; notice and explanation; and
human alternatives, consideration and fallbacks. Although not legally
binding, the Blueprint has influenced federal AI policy discussions and
regulatory efforts. It was later supplemented by Executive Order 14110,
signed by President Biden in October 2023, which established more concrete
AI governance policies. However, this executive order was rescinded by
President Trump in January 2025, potentially diminishing the Blueprint’s
impact on future AI regulations.
- link
- The Federal Trade Commission (FTC) - has also signaled an aggressive approach to
use its existing authority to regulate AI. The FTC recently issued a
warning to market participants that it may violate the FTC Act to use AI
tools that have discriminatory impacts, make claims about AI that are not
substantiated, or to deploy AI before taking steps to assess and mitigate
risks. The FTC has already taken enforcement action against various
companies that have deceived or otherwise harmed consumers through AI. As
discussed above, the FTC has notably banned Rite Aid from using AI facial
recognition technology without reasonable safeguards.
· US Senate - On September 12, 2023, the US Senate held public
hearings regarding AI, which laid out potential forthcoming AI regulations.
Possible legislation could include requiring licensing and creating a new
federal regulatory agency.
·
The SAFE Innovation AI Framework, which is a bipartisan set of guidelines for AI
developers, companies and policymakers. This is not a law, but rather a set of
principles to encourage federal law-making on AI.
o
SAFE Innovation AI
Framework
[chatgpt – include a disclaimer saying
nothing herein is legal advice].
