The Current AI Legal Landscape in the United States in 2025



The Current AI Legal Landscape in the United States in 2025

Updated as of February 2025

 

Currently, AI is governed by direct state legislation targeting AI, existing federal and state legislation that apply to AI, Presidential Executive Orders, Judicial Rulings, and local laws. Importantly, there is no comprehensive federal legislation or regulations in the US that directly regulate the development of AI or specifically prohibit or restrict their use.

 

That said, there are more than 120 AI bills being considered by the US Congress, covering a wide range of issues such as AI education, copyright disclosure, AI robocalls, biological risks, and AI's role in national security, including prohibiting AI from launching nuclear weapons autonomously.

·       https://www.technologyreview.com/2024/09/18/1104015/here-are-all-the-ai-bills-in-congress-right-now/

 

The below is an outline of the current regulatory framework in the US governing AI use.

 

1. Laws Directly Governing AI

 

Legislation Directly Governing AI

 

As stated above, there are currently to federal laws that directly regulate AI - however, several states have enacted legislation that does and that is currently in effects, or scheduled to come into force. An un-exhaustive list of state legislation specifically directed at AI that is in force is listed below:

 

  • Utah Artificial Intelligence Policy Act - In May 2024, the Utah Artificial Intelligence Policy Act went into effect. The Act requires individuals and entities to disclose the use of GenAI in communications with consumers.
    • https://le.utah.gov/~2024/bills/static/SB0149.html
    • For individuals and entities that engage in “regulated occupations” (i.e., those who must obtain a license or state certification to practice the occupation, such as lawyers or health care providers), the disclosure must be made “prominently” at the beginning of any communication with the consumer, regardless of whether the consumer asks whether they are dealing with a GenAI system (i.e., a proactive disclosure obligation).
    • For individuals and entities that do not engage in “regulated occupations,” the disclosure must be made “clearly and conspicuously” only if the consumer asks whether they are dealing with a GenAI system (i.e., a reactive disclosure obligation).
    • Non-compliant individuals and entities may be fined up to US$2,500 per violation by the Utah Division of Consumer Protection.
  • Tennessee’s The Ensuring Likeness Image and Voice Security (ELVIS) Act - became effective on July 1, 2024.

·       California’s Defending Democracy from Deepfake Deception Act - requires large online platforms to identify and block the publication of materially deceptive content related to elections in California during specified time periods before and after an election. Additionally, under this Act, large online platforms must label – within 72 hours of notice – certain content as inauthentic, fake, or false during specified time periods before and after an election in California.

  • California’s Use of Likeness: Digital Replica Act - establishes a cause of action for beneficiaries of deceased celebrities to recover damages for the unauthorized use of an AI-created digital replica of the celebrity in audiovisual works or sound recordings. This Act requires deployers of AI systems to obtain the consent of a deceased personality's estate before producing, distributing, or making available the digital replica of a deceased personality's voice or likeness in an expressive audiovisual work or sound recording.
  • California’s Contracts against Public Policy: Personal or Professional Services: Digital Replica Act - limits the enforceability of contract provisions that allow the use of an individual’s digital replica (a highly realistic AI-generated likeness or voice) to replace their work. Such provisions are unenforceable unless they include a clear description of intended uses and the individual was represented by legal counsel or a labor union addressing digital replicas in a collective bargaining agreement. The law aims to protect performers, artists, and professionals from vague or exploitative contract terms while ensuring transparency in licensing agreements for AI-generated likenesses.
  • California’s Health Care Services: Artificial Intelligence Act - requires health care providers that use GenAI to generate patient communications to (i) disclaim that the communication was generated by a GenAI system, and (ii) provide clear instructions for how the patient can contact a human health care provider for assistance. Where the GenAI communication has been reviewed by a human health care provider, the disclaimer requirements do not apply.
  • California’s Generative Artificial Intelligence Accountability Act - Set to go in effect on January 1, 2026.  
    • https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202320240AB2013
    • The Generative Artificial Intelligence Accountability Act mandates that the California Office of Emergency Services conduct a risk analysis of potential threats that “generative artificial intelligence” (an artificial intelligence system that can generate derived synthetic content, including text, images, video, and audio that emulates the structure and characteristics of the system’s training data) poses to the state’s critical infrastructure, including scenarios that could result in mass casualty events. The office is required to provide a high-level summary of this analysis to the California legislature. Additionally, any state agency or department that uses generative AI to communicate with individuals about government services and benefits must ensure that such communications include a notice indicating that the message was generated by AI and information on how to contact a human employee of the department.
  • New York’s Local Law 144 of 2021 - issued by the City of New York enacted that "prohibits employers and employment agencies [in the city] from using an automated employment decision tool unless the tool has been subject to a bias audit within one year of the use of the tool, information about the bias audit is publicly available, and certain notices have been provided to employees or job candidates"
  • Multi-State DeepSeek and Other Chinese Apps Ban

 

In addition, the following is a non-exhaustive list of State AI acts have been enacted, and will be coming into force in the near future:

 

o   The Colorado Attorney General has rule-making authority to implement, and exclusive authority to enforce, the requirements of the Act. A developer or deployer who violates the Act is deemed to engage in unfair or deceptive trade practices.

  • California AI Transparency Act – Set to go in effect on January 1, 2026. It mandates that "Covered Providers" (AI systems that are publicly accessible within California with more than one million monthly visitors or users) implement comprehensive measures to disclose when content has been generated or modified by AI. This Act outlines requirements for AI detection tools and content disclosures, and establishes licensing practices to ensure that only compliant AI systems are permitted for public use. Covered Providers that violate the Act are liable for a penalty of US$5,000 per violation per day.
    • https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202320240SB942
    • The CA AI Transparency Act mandates that “Covered Providers” (AI systems that are publicly accessible within California with more than one million monthly visitors or users) implement comprehensive measures to disclose when content has been generated or modified by AI. This Act outlines requirements for AI detection tools and content disclosures and establishes licensing practices to ensure that only compliant AI systems are permitted for public use.
    • Key Obligations:
      • AI Detection Tool: Providers must offer a free, publicly accessible tool for users to verify whether AI has generated or modified the content (including text, images, video, and audio), including system provenance data. While the detection tool must be publicly accessible, providers may impose reasonable limitations to prevent or respond to demonstrable risks to the security or integrity of their generative AI systems. Further, providers must collect user feedback related to the tool’s efficacy and incorporate relevant feedback into improvements.
      • Manifest and Latent Disclosures: Providers are required to disclose AI-generated content clearly, conspicuously, and appropriately based on the medium of communication and in such a way that a reasonable person would understand. It should identify the content as AI-generated and be permanent or extraordinarily difficult to remove, to the extent technically feasible. Embedded disclosures must include the provider’s name, the generative AI system’s name and version number, the creation or alteration date, and a unique identifier. It should be detectable by the AI detection tool, consistent with industry standards, and permanent or extraordinarily difficult to remove.
      • License Revocation: Providers of generative AI systems must contractually require licensees to maintain the system’s capability to include the mandated disclosures. If a provider discovers that a licensee has modified the system to remove required disclosures, the license must be revoked within 96 hours and the licensee must cease using the system immediately.
      • Enforcement and Penalties: Covered providers that violate the Act are liable for a penalty of $5,000 per violation per day, enforceable through civil action by the CA Attorney General, city attorneys, or county counsel.
  • Generative AI: Training Data Transparency Act - Set to go in effect on January 1, 2026. It mandates that developers of generative AI systems (GenAI) publish a "high-level summary" of the datasets used to develop and train GenAI systems. For example, developers of GenAI systems would need to publish a summary of the following information, which is non-exhaustive:
    • Sources and owners of the datasets
    • Description of how the datasets further the intended purpose of the GenAI system
    • Whether the datasets include any information protected by IP law
    • Whether the datasets include personal information as defined in the CCPA

o   Whether the datasets were purchased or licensed by the developer

o   https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202320240AB2013

  • Unified Definition of Artificial Intelligence - Set to go in effect on January 1, 2026.
    • California Assembly Bill 2885 ("AB 2885") aims to unify the definition of "Artificial Intelligence" across various California laws. This standardization is crucial, as varying definitions can lead to inconsistencies in regulation and oversight in the rapidly evolving field of AI. Specifically, AB 2885 defines Artificial Intelligence "an engineered or machine-based system that varies in its level of autonomy and that can, for explicit or implicit objectives, infer from the input it receives how to generate outputs that can influence physical or virtual environments".
    • https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240AB2885

 

Proposed and Upcoming Legislation

 

More than 40 state AI bills were introduced in 2023, with Connecticut and Texas actually adopting statutes. Both of those enacted statutes establish state working groups to assess state agencies’ use of AI systems to ensure they do not result in unlawful discrimination.

 

 

 

2. Existing Legislation that Applies to AI

 

Existing legislation has been the primary way in which the US regulates AI as established law, including privacy and intellectual property laws, which are generally applicable to AI technologies. Notably, in April 2023, the Federal Trade Commission, Equal Employment Opportunity Commission, Consumer Financial Protection Bureau, and Department of Justice issued a joint statement noting that "existing legal authorities apply to the use of automated systems and innovative new technologies."

-          https://www.ftc.gov/system/files/ftc_gov/pdf/EEOC-CRT-FTC-CFPB-AI-Joint-Statement%28final%29.pdf

 

Accordingly, developers, users, operators and deployers of AI systems should anticipate that existing law will apply to any regulated activity that uses AI, and consult legal counsel about the potential liabilities that may arise. While potentially novel, the use of AI does not per se provide a shield from the application of existing law.

 

Similarly, state regulators that regulate privacy legislation likely also have the authority to regulate AI vis-à-vis existing privacy provisions.

 

The following is a non-exhaustive list of legislation that have been held to apply to AI:

o   Telephone Consumer Protection Act - The Federal Communications Commission issued a declaratory ruling stating that the restrictions on the use of "artificial or pre-recorded voice" messages in the 1990s era Telephone Consumer Protection Act include AI technologies that generate human voices, demonstrating that regulatory agencies will apply existing law to AI.8

§  https://www.congress.gov/bill/102nd-congress/senate-bill/1462#:~:text=Telephone%20Consumer%20Protection%20Act%20of%201991%20%2D%20Amends%20the%20Communications%20Act,a%20hospital%2C%20medical%20physician%20or

§  https://docs.fcc.gov/public/attachments/FCC-24-17A1.pdf

  • State:

o   Privacy Laws - Several states have enacted comprehensive privacy legislation that can also regulate AI. A non-exhaustive list of notable state legislation includes:

§  The California Privacy Protection Act (CPPA), contains provisions on the use of automated decision-making tools.

        • Additionally, the California Privacy Protection Agency released draft rules on these provisions governing consumer notice, access and opt-out rights with respect to automated decision-making technology, which the rules define broadly. The regulations are still being finalized but will likely cover expanded uses of AI. The draft rules, which are still being formalized, would require significant disclosure about businesses’ implementation and use of ADMT.
        • California Consumer Privacy Act

·       Draft Automated Decision-making Technology Regulations

§  The Biometric Information Privacy Act in Illinois, which is very broad and allows for extremely high damages for violations. There is currently pending litigation in the AI context.

·       link

o   IP Laws – see RiteAid discussion below.

·       Other:

o   The National Association of Insurance Commissioners - issued a model bulletin  that focuses on governance frameworks, risk management protocols and testing methodologies that insurers should have in place to govern their use of AI systems that impact insurance consumers.

§  As of February 1, 2025, several states have adopted this model bulletin, including Alaska, Connecticut, Illinois, Kentucky, Maryland, Nevada, New Hampshire, Pennsylvania, Rhode Island, Vermont, and Washington.

§  In these states, the principles outlined in the NAIC Model Bulletin are in effect, requiring insurers to develop, implement, and maintain a written program for the responsible use of AI systems. This includes establishing governance frameworks, risk management protocols, and internal controls to mitigate the risk of adverse consumer outcomes.

§  However, the adoption of the model bulletin varies by state. Some states have implemented the bulletin with modifications, while others have developed their own AI-related regulations or guidance. For instance, Colorado established governance and risk management framework requirements for life insurers regarding the use of external consumer data, algorithms, predictive models, and similar systems, aiming to prevent unfair discrimination.

§  Therefore, whether the NAIC Model Bulletin is considered law depends on the specific regulations and guidance adopted by each state. Insurers should consult the relevant regulatory authorities in the states where they operate to understand the applicable requirements concerning the use of AI systems.

o   link

 

3. Rulings

 

AI is also governed by court decisions and regulatory body enforcement and rulings. For example, in relation to Intellectual Property Law, Existing intellectual property laws also apply to AI, both with respect to the data AI technologies are trained upon and the outputs of such technologies. For example, with respect to outputs, the US District Court has held that human authorship is an essential part of a valid copyright claim, and the Copyright Office will refuse to register a work unless it was created by a human being." There are also numerous cases before the courts in the US alleging copyright infringement, among other things, with respect to training data.

-          https://cdn.patentlyo.com/media/2023/08/THALER-v.-PERLMUTTER-et-al-Docket-No.-1_22-cv-01564-D.D.C.-Jun-02-2022-Court-Docket-1.pdf

 

In addition, the Federal Trade Commission has evoked an interest in and focus on regulating AI through enforcement. On December 19, 2023, the FTC settled a significant action focused on artificial intelligence bias and discrimination against Rite Aid regarding the company’s use of facial recognition technology for retail theft deterrence. Rite Aid faced allegations that the company improperly used artificial intelligence-based facial recognition technology in its retail stores. The FTC charged that Rite Aid deployed this technology without adequate safeguards, leading to numerous false identifications of customers as potential shoplifters, disproportionately affecting women and people of color. As part of the settlement, Rite Aid:

·       is prohibited from using facial recognition technology for surveillance purposes for five years

·       must delete all photos and videos of consumers used in its AI facial recognition 

  • after Rite Aid’s ban on using AI facial recognition expires, if Rite Aid operates AI facial recognition technology for surveillance, it must maintain a comprehensive automated biometric security or surveillance system monitoring program that identifies and addresses the risks of such operation and notifies consumers of its use of AI facial recognition.
  • must also provide a means for consumers to lodge complaints, and investigate and respond to all complaints received, among other requirements.

 

This illustrative case provides guidance on the FTC’s enforcement on AI systems.

-          https://www.ftc.gov/news-events/news/press-releases/2023/12/rite-aid-banned-using-ai-facial-recognition-after-ftc-says-retailer-deployed-technology-without

 

 

4. Proposed Legislation

 

Proposed Legislation (non-exhaustive list):

  • The REAL Political Advertisements Act - which aims to regulate generative AI in political advertisements.
  • The Stop Spying Bosses Act, which aims to regulate employers surveilling employees with machine learning and AI techniques.
  • The Draft No FAKES Act, which would protect voice and visual likenesses of individuals from unauthorized recreations from Generative AI.
  • The AI Research Innovation and Accountability Act, which calls for greater transparency, accountability and security in AI, while establishing a framework for AI innovation. It would create an enforceable testing and evaluation standard for high-risk AI systems and require companies that use high-risk AI systems to produce transparency reports. It also empowers the National Institute of Standards and Technology to issue sector-specific recommendations to regulate them.
  • The American Privacy Rights Act, which would create a comprehensive consumer privacy framework. The draft bill includes provisions on algorithms, including a right to opt-out of covered algorithms used to make or facilitate consequential decisions.

 

 

 

5. Executive Orders:

 

There are no current Presidential Executive orders that governs AI.

 

President Trump’s January 23, 2025 Executive Order, titled “Removing Barriers to American Leadership in Artificial Intelligence Executive Order”, revoked Biden’s Executive Order 14110 of October 30, 2023, titled “Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence”, among other things. For a discussion of the prior order click here.

-          Trump’s – https://www.whitehouse.gov/presidential-actions/2025/01/removing-barriers-to-american-leadership-in-artificial-intelligence/

-          Biden’s - https://www.federalregister.gov/documents/2023/11/01/2023-24283/safe-secure-and-trustworthy-development-and-use-of-artificial-intelligence

 

President Trump’s Executive Order sets out that a plan to achieve the policy set out in the executive order, shall be delivered to the president in 180 days of the order being signed, which is July 22, 2025. The Policy is:

 

Sec. 2. Policy. It is the policy of the United States to sustain and enhance America’s global AI dominance in order to promote human flourishing, economic competitiveness, and national security.

 

Biden’s Executive Order listed the following eight key principles and priorities to encourage the responsible development of AI technologies and safeguard against potential harms:

  • AI must be safe and secure
  • To lead in AI, the US must promote responsible innovation, competition and collaboration
  • Responsible development and use of AI requires a commitment to supporting American workers
  • AI policies must advance equity and civil rights
  • The interests of Americans who increasingly use, interact with, or purchase AI and AI-enabled products in their daily lives must be protected
  • Privacy and civil liberties must be protected
  • The federal government must manage the risks of its own use of AI
  • The federal government should exercise global leadership in societal, economic and technological progress

 

Biden’s The Executive Order also called on the Department of Commerce to issue guidance for content authentication and watermarking to label AI-generated content. Lastly, The order required developers of artificial intelligence models to notify the federal government if their models were trained using computing power exceeding certain thresholds. Specifically, any AI model trained with more than 10²⁶ floating-point operations (FLOPs), or models trained primarily on biological sequence data using over 10²³ FLOPs, fell under this mandate. Additionally, computing clusters with a theoretical maximum capacity exceeding 10²⁰ FLOPs per second were also subject to reporting requirements.

 

 

6. International Commitments

 

Council of Europe's Framework Convention on Artificial Intelligence

As for international commitments, on September 5, 2024, the United States joined Andorra, Georgia, Iceland, Norway, the Republic of Moldova, San Marino, the United Kingdom, Israel, and the European Union to sign the Council of Europe’s Framework Convention on AI. The treaty will enter into force on the first day of the month following three months after five signatories, including at least three Council of Europe Member States, have ratified it. Countries from all over the world will be eligible to join and commit to its provisions.

·       https://rm.coe.int/1680afae3c

 

The Council of Europe's Framework Convention on Artificial Intelligence is the first legally binding international treaty designed to ensure that AI development and deployment uphold human rights, democracy, and the rule of law. The Convention requires signatory states to implement measures that ensure AI activities comply with fundamental principles, including human dignity, individual autonomy, equality, non-discrimination, privacy, data protection, transparency, oversight, accountability, responsibility, reliability, and safe innovation. Signatories are obligated to establish risk and impact assessment frameworks throughout the AI system lifecycle, provide accessible remedies for individuals adversely affected by AI systems, and maintain effective oversight mechanisms. The Convention also emphasizes the importance of public awareness and education regarding AI technologies.

 

The European Union's Artificial Intelligence Act’s Extra-Territorial Scope

The European Union's Artificial Intelligence Act (AI Act), adopted in March 2024, establishes a comprehensive regulatory framework for AI systems, aiming to ensure they align with fundamental rights and European values. The Act classifies AI applications based on risk levels—unacceptable, high, limited, and minimal—and imposes corresponding obligations, including prohibitions and compliance requirements. It came into force on August 1, 2024, with various provisions becoming applicable over the following 6 to 36 months.

-          https://artificialintelligenceact.eu/ai-act-explorer/

 

Notably, the AI Act may have an extraterritorial reach, applying to providers and deployers outside the EU if their AI systems' outputs are used within the EU, thereby potentially affecting U.S. entities whose AI technologies impact individuals or markets in the EU.

 

The EU AI Act applies not only to AI systems developed or deployed within the EU but also to those placed on the EU market or whose outputs are used in the EU, regardless of where the provider or deployer is based. This means that even companies operating outside the EU, such as in the U.S., could be subject to the Act if their AI systems influence EU users or businesses. For example, a U.S.-based company offering an AI-powered resume screening tool that EU companies use for hiring decisions may need to comply with the Act's transparency and risk management requirements.

 

 

7. Other

  • National AI Initiative Act of 2020 - focused on expanding AI research and development and created the National Artificial Intelligence Initiative Office that is responsible for "overseeing and implementing the US national AI strategy."
  • The White House Blueprint for an AI Bill of Rights - was introduced by the Biden Administration through the White House Office of Science and Technology Policy (OSTP) on October 4, 2022. It asserts guidance around equitable access and use of AI systems. The AI Bill of Rights provides five principles and associated practices to help guide the design, use and deployment of "automated systems" including safe and effective systems; algorithmic discrimination and protection; data privacy; notice and explanation; and human alternatives, consideration and fallbacks. Although not legally binding, the Blueprint has influenced federal AI policy discussions and regulatory efforts. It was later supplemented by Executive Order 14110, signed by President Biden in October 2023, which established more concrete AI governance policies. However, this executive order was rescinded by President Trump in January 2025, potentially diminishing the Blueprint’s impact on future AI regulations.
    • link
  • The Federal Trade Commission (FTC) - has also signaled an aggressive approach to use its existing authority to regulate AI. The FTC recently issued a warning to market participants that it may violate the FTC Act to use AI tools that have discriminatory impacts, make claims about AI that are not substantiated, or to deploy AI before taking steps to assess and mitigate risks. The FTC has already taken enforcement action against various companies that have deceived or otherwise harmed consumers through AI. As discussed above, the FTC has notably banned Rite Aid from using AI facial recognition technology without reasonable safeguards.

·       US Senate - On September 12, 2023, the US Senate held public hearings regarding AI, which laid out potential forthcoming AI regulations. Possible legislation could include requiring licensing and creating a new federal regulatory agency.

·       The SAFE Innovation AI Framework, which is a bipartisan set of guidelines for AI developers, companies and policymakers. This is not a law, but rather a set of principles to encourage federal law-making on AI.

o   SAFE Innovation AI Framework

 

 

[chatgpt – include a disclaimer saying nothing herein is legal advice].