AI compliance frameworks in the US: requirements for responsible AI

July 29, 2026 14 min read 122 views

Learn which AI compliance frameworks apply in the U.S., what risks to watch for, and how to create a responsible approach to AI adoption.

Eight out of ten (78%) U.S. organizations plan to increase AI spending during the fiscal year 2025. As AI takes on complex decisions in areas such as lending, hiring, and healthcare, organizations face growing expectations around accountability, fairness, and responsible use.

A recent Illinois case illustrates the risks. An automated hiring tool screened candidates based on geographic data and excluded applicants from lower-income areas. Although the system was not designed to discriminate, it reflected biases in its training data. Cases like this show why thorough risk assessments and ongoing oversight are essential.

State governments, federal agencies, and industry regulators are becoming more assertive. Compliance is becoming essential to any AI strategy and is no longer merely a legal footnote. In this article, we will answer the questions you might have around AI compliance in the United States, regardless of whether you are developing AI applications or purchasing AI tools.

What is the current AI compliance landscape in the United States?

The AI compliance landscape in the United States is evolving rapidly, with federal initiatives, state-level regulations, and industry-specific requirements shaping how organizations develop and deploy AI systems. Unlike the EU, the U.S. does not currently have a single comprehensive AI law; instead, businesses must navigate a growing set of frameworks, executive actions, and sector-specific rules.

Federal AI policy has also shifted significantly in recent years. While Executive Order 14110 introduced the first broad federal framework for trustworthy AI in 2023, it was revoked in January 2025 and replaced by Executive Order 14179, which emphasizes U.S. leadership in AI innovation while directing federal agencies to develop governance policies that support responsible AI adoption. As a result, organizations increasingly rely on established frameworks such as the NIST AI Risk Management Framework to build consistent compliance and risk management practices amid a changing regulatory landscape.

Nonetheless, much of the regulatory momentum has come from the state level, including the Illinois 3773 case, which limits the use of ZIP codes in automated hiring, due to bias and systemic bias concerns. Another case adding to the propriety of compulsory AI compliance took place when Amazon-powered résumé screening was disbanded after reports showed the program was biased against women. Now, New York’s Local Law 144 requires companies to conduct bias audits before using AI for hiring. Last but not leat, in California, the California Privacy Rights Act (CPRA) encourages businesses to report any automated decision-making processes impacting consumers’ rights or access to services.

American businesses now understand that it is more than just penalties are at stake. Ignoring AI regulatory compliance equals the risk of losing the public’s trust and having your technology removed from the market.

Hence, what are the AI compliance frameworks a business must adhere to in the United States to stay on the safe side?

Learn how to achieve a 50% faster software delivery with Avenga’s AI-native engineering system.

Learn more
ISG Report on Advanced Analytics and AI Services

Key AI compliance frameworks and regulations in the U.S.

The U.S. approach to AI regulation continues to evolve through a combination of federal initiatives, state-level legislation, industry-specific requirements, and voluntary risk management frameworks. Unlike the European Union, the United States does not currently have a single comprehensive AI law. Instead, organizations must navigate a growing patchwork of regulations and standards that address areas such as transparency, fairness, privacy, security, and accountability.

Executive orders: EO 14110 and EO 14179

President Biden’s 2023 Executive Order 14110 on Safe, Secure, and Trustworthy Artificial Intelligence represented a pivotal moment in the federal approach to AI policy. The order established eight guiding principles for federal AI use, including requirements for safety testing of AI systems before public release, standards for detecting AI-generated content through watermarking, and protections against AI-enabled fraud. It also mandated that developers of the most powerful AI systems share safety test results with the federal government, particularly for systems that could pose risks to national security, economic security, or public health. The order directed the FTC and the Department of Commerce to devise regulations around fairness, safety, and transparency, with specific attention to preventing algorithmic discrimination in housing, education, and employment.

National Institute of Standards and Technology (NIST) AI Risk Management Framework

First released in January 2023 and updated in mid-2024, the NIST AI Risk Management Framework (AI RMF) has gained wider traction and adopted in the business world as an actionable framework for managing AI risks of all shapes and sizes. Its updated version has a specific profile for generative AI models with more specific guideposts for assessing and mitigating risks relating to hallucinations, misinformation, and lack of explainability. For instance, the framework addresses scenarios where AI models generate factually incorrect information presented as fact, produce biased outputs based on training data limitations, or make recommendations without providing traceable reasoning that users can verify.

Since it is purely voluntary guidance, the AI RMF was not intended to be a compliance standard; however, it is increasingly treated as such, especially among large enterprises and federal contractors.

New York City Local Law 144

New York City’s Local Law 144, which went into effect in July 2023, mandates that companies using automated employment decision technologies warn candidates and do impartial bias audits. The regulation applies to businesses that use algorithmic systems to screen applicants for employment or promotions, and non-compliance can result in hefty penalties. Due to the regulation, numerous big staffing platforms and HR tech companies have already seen changes in their AI governance policies.

Tennessee Ensuring Likeness Voice and Image Security (ELVIS) Act

The ELVIS Act was passed in March 2024 to amend Tennessee’s Personal Rights Protection Act. The ELVIS Act prohibits unauthorized commercial use of a person’s “voice” along with their name, image, and likeness. “Voice” is broadly identified in the ELVIS Act to include the actual recording of a voice, AI-generated voice approximations, and imitations by humans that performed identifiable impersonations.

Importantly, the Act also introduces secondary liability, meaning that the individual or company can be responsible even if they didn’t upload the infringing content themselves, but only enabled, facilitated, or distributed it. This presents new compliance requirements and risks for AI developers, content platforms, and advertising companies that use synthetic likenesses or voices without clear consent.

As of 2026, state AI regulation continues to accelerate, with more than 1,500 AI-related bills introduced across dozens of states and hundreds of proposals moving through legislative processes. These measures address areas such as consumer protection, transparency, privacy, and sector-specific AI use cases, including employment, healthcare, education, and law enforcement. Without a federal umbrella law, organizations must proactively monitor evolving requirements and utilize frameworks like the NIST AI RMF to build consistent, risk-based compliance processes.

Multiple trends are converging to make compliance not just pressing, but inevitable:

  • Presidential Executive Orders and agency guidance (FTC, Equal Employment Opportunity Commission (EEOC), Consumer Financial Protection Bureau (CFPB)) indicate a pivot from the AI algorithms that are neither transparent nor explainable.
  • Enactment of state-level legislation such as Illinois’ 3773 and the evolving landscape of California privacy laws.
  • Publicly visible failures of AI implementation, like biased hiring tools and flawed facial recognition.
  • Consumer backlash around the lack of transparency in automated decision-making.
  • Cross-border pressure from foreign legislation, especially around the EU AI Act, is impacting U.S. compliance frameworks.

Failed AI compliance in the US: first lawsuits already filed

The responsibility of AI technologies is determined by the compliance infrastructure we build around them. Two recent cases remind us how firms’ lack of AI risk management can lead to dire business and legal consequences.  

  • Mobley v. Workday (Feb 2024): Derek Mobley, an African American man over 40 with a disability, has filed suit against Workday’s automated résumé‑screening tool based on alleged age, race, and disability discrimination. The amended complaint contends that the tool systematically rejected applicants like Mobley, creating repeat-use issues across protected classes.
  • SafeRent Settlement in Massachusetts (Nov 2024): Mary Louis and others filed suit against SafeRent after a low AI-generated tenant-screening score caused housing applications to be denied, even with valid rental histories and housing-voucher status as part of their application. SafeRent settled for $2.2 million and turned off the feature for voucher holders for 5 years.

A stepwise guide to building AI compliance in the United States

Below are key steps a company can take to ensure AI compliance — both in the United States and more broadly — by adopting a responsible approach throughout the AI lifecycle:

PhaseCompliance actionsExamples/Tools
Data collectionVet sources for legality and bias; avoid collecting unnecessary attributes   Data minimization, anonymization, differential privacy
Model training   Test for bias across protected classes; make models explainableSHAP, LIME, IBM AI Fairness 360, Microsoft Azure Responsible AI Dashboard, AWS Clarify, and Google Cloud Explainable AI
Pre-deploymentConduct formal audits (internal or third-party) for discrimination risksNYC Local Law 144 (for hiring tools), custom audit protocols
DeploymentClearly document AI use case, limitations, and human fallback optionsModel cards, datasheets for datasets, use policies




MonitoringEstablish feedback loops, drift detection, security monitoring, and governance reviews (Data Ethics, Model Risk, Security). Track the 11 Responsible AI Framework pillars: Explainability, Transparency, Traceability, Reliability, Repeatability, Data Ethics, Accountability, Impact, Human-in-Loop, Bias Freedom, and Fairness.Responsible AI dashboards, drift detection tools, governance frameworks, bias alerts, A/B fairness testing
Table 1. Practical Steps to Build AI Compliance Standards

Robust compliance efforts start with an AI impact assessment to recognize who the systems may negatively affect and under what conditions, especially in sensitive areas like housing, credit, hiring, and healthcare. Teams should establish their definitions of accepted bias and identify thresholds that will indicate if a model may need retraining or adjustments during development or after deployment.

Avenga’s Responsible AI framework explained
Graph 1. Avenga’s Responsible AI framework explained

Due to the risks inherent in relying upon a single tool for explainability, teams should engage several styles of examinations and cross-validate interpretations to understand more about logical decisions. Creating a means for redress (allowing users to appeal or dispute an automated outcome) is just as critical. During the assessment process, developing and maintaining usable logs, audit trails, and other types of records ensures traceability — something regulators require to ensure compliance.

AI Project Timeline deconstructed
Graph 2. AI Project Timeline deconstructed

Key challenges in AI compliance

Despite increased awareness about responsible use of AI, compliance issues are still common, and here’s why.

Lack of explainability in AI models

Black box systems can generate outputs, but without transparency about how the system arrived at that outcome, the organization can’t explain or justify those outputs to third parties, particularly where the outputs may concern lives or large sums of money. IBM’s now-defunct Watson for Oncology project is a textbook example. Watson made treatment recommendations that were intentionally unsafe or inconsequential, and although Watson showed promise, it could not be trusted clinically. The result was a reported $62 million loss and court documents stating that the project was shut down. From a compliance perspective, a lack of explainability creates legal blind spots.

Bias embedded in training data

Data biases originating from poorly curated or unbalanced datasets are one of the leading sources of biased AI outcomes. Numerous medical imaging diagnostics and other systems were developed using AI practices during the COVID-19 pandemic, mostly from narrow sets of relatively non-representative datasets. Certain systems, for example, learned to identify patterns correlated with COVID-positive outcomes based on spurious factors like which imaging equipment manufacturer was used or which hospital facility captured the scan, rather than actual medical indicators in the images themselves rather than the medical signals in the image, resulting in dangerously flawed outcomes. In high-risk industries, biases in data are not only a technical problem; it is an inherent compliance one.

Fragmented regulatory landscape

Without a federal AI law, companies must comply with a patchwork of state-level laws that often have different requirements and timelines. For instance, New York requires bias audits of hiring algorithms to be conducted annually and mandates candidate notification, while Utah’s S.B. 149 focuses on disclosure requirements for generative AI in customer-facing roles but doesn’t require bias audits. Within this environment, compliance has turned into a real-time game of whack-a-mole (particularly companies doing business across multiple states).

Lack of internal ownership

AI compliance and risk management frequently exist within the complex intersection of departments (legal, data science, and engineering), where the roles are ill-defined based on the evidence. This disparity raises the possibility of mistakes being made when developing and implementing the model. Without clearly defined roles, compliance turns into a reactive process that is frequently initiated only after an issue arises.

Evolving models and legal standards

AI systems evolve through retraining, data drift, or architecture changes, and the legal landscape changes just as readily. Failing to identify these changes can expose organizations to substantial compliance and business risks. According to IBM’s Cost of a Data Breach Report, 13% of organizations had already experienced a breach involving AI models or applications, while 97% of those organizations lacked proper AI access controls. The report also found that AI-related security incidents frequently resulted in compromised data and operational disruption. The lesson is clear: AI compliance is not limited to launching a model—it requires continuous monitoring, governance, and risk management throughout the AI lifecycle.

FAQ

AI compliance refers to the process of ensuring AI systems adhere to legal, regulatory, ethical, and industry requirements, while AI governance defines the policies, roles, and processes used to manage AI responsibly. AI compliance focuses on meeting specific obligations, while governance provides the broader framework needed to embed compliance across the AI lifecycle. Together, they help organizations develop trustworthy AI and ensure AI systems operate within acceptable risk boundaries.

AI compliance tools help organizations identify, monitor, and manage compliance risks throughout the AI lifecycle. These AI compliance tools and technologies can automate compliance activities such as bias testing, model monitoring, documentation, explainability checks, and audit preparation. By improving transparency in AI and creating traceable compliance processes, they help teams demonstrate compliance and maintain responsible AI practices.

Data privacy is a key AI compliance requirement because many AI systems process personal information or rely on large datasets used in AI training. Organizations must ensure compliance with data privacy regulations and implement safeguards that protect sensitive information throughout the development and use of AI. Strong data governance practices help reduce compliance risk and support ethical AI use.

Organizations can prepare for an AI compliance audit by documenting their AI initiatives, assessing potential risks, and establishing clear compliance processes. This includes maintaining records of data sources, model decisions, testing procedures, and governance controls. Using frameworks such as the NIST AI Risk Management Framework can help teams structure their compliance efforts and demonstrate that their AI systems align with regulatory expectations.

Organizations should regularly review and update their AI compliance policies because AI technologies, regulations, and business use cases continue to evolve within the regulatory framework. Changes in AI systems, data used in AI training, or new AI regulatory requirements may introduce new compliance risks. A continuous approach to compliance helps organizations ensure AI systems operate within legal and ethical boundaries throughout their lifecycle.

AI compliance in 2026: the new standard, not an option

The evolution of AI regulation in the U.S. is increasingly being underpinned not solely by enforcement, but by expectations of trustworthiness, transparency, and responsible innovation in high-risk AI systems. Organizations will be expected to use ethical AI and create those capabilities based on legal and ethical compliance when using AI as part of sensitive transactions to maximize human experience (for example, hiring, lending, healthcare).

Signals of this inflection point have already been seen. From New York’s mandatory bias audits (Local Law 144) to Illinois’ ZIP code discrimination cases, state lawmakers are stepping in where federal regulation hasn’t yet unified. Even major players are learning the hard way: think Zillow’s $300M pricing model failure or Workday’s résumé screening lawsuit.

AI usage in high-stakes areas like hiring, lending, and healthcare now demands transparency, explainability, and a rock-solid AI governance framework.

Build AI systems that are both innovative and defensible. Start a conversation to design a compliance framework that moves at the pace of your market.

Rate this article!

Average 0.0 out of 5

Olena Domanska

AI Engineering Manager

Olena Domanska