Introduction
The regulatory environment for artificial intelligence (AI) in the United States is characterized by a fragmented patchwork of state statutes, federal agency guidance, professional standards, and varying enforcement philosophies. This heterogeneity creates significant challenges for commercial organizations seeking to deploy AI responsibly while remaining compliant across jurisdictions. A connected, adaptive governance approach is essential to manage risk, build trust, and ensure alignment with evolving regulatory expectations (Source: Deloitte, https://deloitte.wsj.com/cio/how-ai-governance-can-adapt-to-a-fragmented-regulatory-landscape-2671f597).
Federal Framework
Existing Federal Laws and Guidance
As of June 2025, no comprehensive federal AI legislation has been enacted (CRS Report R48555). Instead, the current federal framework relies on existing statutes—such as the Federal Trade Commission Act, the Securities Act, and sector‑specific regulations—and on guidance issued by agencies such as the National Institute of Standards and Technology (NIST). NIST’s AI Risk Management Framework (AI RMF) provides a voluntary, risk‑based methodology that many organizations adopt to structure their AI governance (NIST, 2023).
Role of Federal Agencies
Federal agencies continue to issue sector‑specific guidance, often interpreting existing laws in the context of AI. For example, the Federal Trade Commission (FTC) has warned companies about deceptive AI practices, while the Securities and Exchange Commission (SEC) has emphasized disclosure requirements for AI‑driven investment tools. These agency actions illustrate a pragmatic, incremental approach to AI regulation, but they also contribute to a disjointed landscape for businesses operating across multiple sectors.
State‑Level Patchwork
Emerging State Legislation
State legislatures have responded swiftly to the federal absence, passing a growing number of AI‑related bills. As of mid‑2025, at least 15 states have enacted AI‑specific statutes, covering areas such as consumer privacy, algorithmic transparency, and high‑risk AI applications. Notable examples include:
- California: The California AI Accountability Act requires impact assessments for high‑risk AI systems and imposes penalties for non‑compliance.
- Illinois: The Artificial Intelligence Video Interview Act mandates disclosure to job candidates when AI is used in hiring decisions.
- Texas: The Texas AI Regulation establishes a framework for the certification of AI systems used in critical infrastructure.
These state laws differ markedly in scope, definition of “AI,” and enforcement mechanisms, reinforcing the patchwork nature of the regulatory environment.
Professional and Industry Frameworks
Standards and Best Practices
Beyond statutory regimes, professional bodies and industry consortia have developed voluntary frameworks to support AI governance. The NIST AI RMF, ISO/IEC 42001 (AI management), and sector‑specific guidelines from the Institute of Electrical and Electronics Engineers (IEEE) provide structured approaches for risk assessment, model documentation, and continuous monitoring. While not legally binding, these standards serve as reference points for organizations seeking to align their internal policies with recognized best practices.
Connected Risk Approach
Rationale
Effective AI governance requires a “connected risk” perspective that integrates disparate regulatory requirements into a cohesive risk management program. Deloitte’s research emphasizes that organizations must move beyond siloed compliance checks and adopt a holistic view that accounts for cross‑jurisdictional obligations, risk tolerance, and business objectives (Deloitte, https://deloitte.wsj.com/cio/how-ai-governance-can-adapt-to-a-fragmented-regulatory-landscape-2671f597).
Implementation
A connected risk approach involves:
- Centralized Policy Repository – maintaining a single source of truth for AI policies that can be mapped to each applicable jurisdiction.
- Dynamic Risk Assessment – continuously evaluating AI system risk as regulations evolve and as the system’s lifecycle changes.
- Cross‑Functional Governance Committee – bringing together legal, compliance, technology, and business leaders to oversee AI initiatives and ensure alignment with both internal policies and external requirements.
Enforcement and Compliance Challenges
Divergent Enforcement Philosophies
Enforcement agencies adopt differing philosophies, ranging from proactive inspection regimes to reactive, complaint‑driven models. This variance can create uncertainty for firms operating in multiple states, as compliance programs must be flexible enough to satisfy divergent enforcement expectations.
Practical Steps for Organizations
- Conduct regular audits against the most stringent applicable standards to establish a baseline compliance posture.
- Maintain documentation of decision‑making processes, data provenance, and model documentation to satisfy potential regulator inquiries.
- Engage in ongoing dialogue with regulators and industry groups to stay informed about emerging guidance and legislative changes.
Recommendations for Commercial Organizations
- Adopt an Adaptive Governance Model – design policies that can be quickly modified in response to new state or federal mandates.
- Leverage Technology Tools – employ AI‑governance platforms that provide real‑time monitoring, automated compliance checks, and policy versioning.
- Invest in Talent Development – equip staff with knowledge of both regulatory requirements and industry standards to foster a culture of responsible AI use.
- Participate in Industry Coalitions – collaborate with peers and standard‑setting bodies to shape forthcoming regulations and share best practices.
Conclusion
The United States’ AI regulatory landscape remains a mosaic of state enactments, federal guidance, and voluntary standards. For commercial organizations, navigating this patchwork demands an adaptive, risk‑centric governance strategy that can evolve alongside the regulatory tide. By integrating federal and state requirements, leveraging professional frameworks, and embracing connected risk management, firms can mitigate legal exposure while unlocking the full value of AI technologies.
All sources referenced are publicly available; the primary source for the connected risk concept is Deloitte’s analysis (https://deloitte.wsj.com/cio/how-ai-governance-can-adapt-to-a-fragmented-regulatory-landscape-2671f597).