top of page
town of USA

COMPLIANCE UNITED STATES 

Enforced at runtime.

The US regulates AI through a fast-moving patchwork: state AI acts, federal enforcement and sector rules. What is compliant in one state may be a violation in another. EVEDY enforces the applicable rules per jurisdiction – at runtime.

FRAGMENTED AI REGULATION 

The regulatory landscape for AI in the US

No comprehensive federal AI act – instead state statutes taking effect through 2026, active FTC enforcement, sector regulators and NIST's AI Risk Management Framework as the de-facto standard. This is an incomplete excerpt of the current compliance.

REGULATION

WHAT IT REQUIRES 

HOW EVEDY ENFORCES IT

State AI laws

Colorado AI Act, Texas TRAIGA, California transparency laws and more – key duties effective in 2026

Duties for developers and deployers of high-risk AI: impact assessments, notice to consumers, protection against algorithmic discrimination, disclosure of AI use.

Jurisdiction-aware policy enforcement, automated consumer-notice controls, discrimination and accuracy monitoring, evidence per statute.

Federal enforcement & executive action

FTC enforcement; shifting executive orders; sector regulators (SEC, OCC)

No unfair or deceptive practices – including overstated AI claims and harmful outputs; sector-specific supervision of AI use.

Non-compliant outputs are detected, blocked or escalated in real time; complete, tamper-evident records for investigations.

NIST AI Risk Management Framework

De-facto standard for AI governance in the US

Govern, map, measure, manage: continuous risk identification and controls across the AI lifecycle.

The framework's controls become runtime policies: testing and evaluation of every version, continuous monitoring, measurable risk reporting.

State privacy laws

CCPA/CPRA and a growing set of comprehensive state privacy statutes

Consumer rights, limits on profiling and automated decision-making, data minimisation and security obligations.

Automatic PII redaction in prompts and responses, access control via your IAM, opt-out-aware processing, complete audit trails.

Sectoral rules & internal policies

HIPAA, GLBA, EEOC guidance, NYC Local Law 144 – plus your own directives

Sector-specific duties from health data to hiring: bias audits, confidentiality, human review of consequential decisions.

Enterprise and sector policies are stored as machine-enforceable rules and applied automatically to every AI interaction.

As of August 2026. This overview does not constitute legal advice.

THE DIFFERENCE

From written policy to runtime enforcement

Most enterprises have AI policies. Very few can prove they are followed. EVEDY closes exactly that gap.

1

Capture the rules

Legal requirements and internal policies are modelled as machine-readable policies – synchronised from your GRC platform if you wish.

2

Enforce at runtime

Every request to a model or agent passes through EVEDY. Violations are blocked, corrected or escalated – in real time, not after the fact.

3

Prove compliance

Audit trails per user, per agent and per regulation give internal audit, the board and regulators defensible evidence at any time.

bottom of page