
COMPLIANCE UNITED STATES
Enforced at runtime.
The US regulates AI through a fast-moving patchwork: state AI acts, federal enforcement and sector rules. What is compliant in one state may be a violation in another. EVEDY enforces the applicable rules per jurisdiction – at runtime.
FRAGMENTED AI REGULATION
The regulatory landscape for AI in the US
No comprehensive federal AI act – instead state statutes taking effect through 2026, active FTC enforcement, sector regulators and NIST's AI Risk Management Framework as the de-facto standard. This is an incomplete excerpt of the current compliance.
REGULATION
WHAT IT REQUIRES
HOW EVEDY ENFORCES IT
State AI laws
Colorado AI Act, Texas TRAIGA, California transparency laws and more – key duties effective in 2026
Duties for developers and deployers of high-risk AI: impact assessments, notice to consumers, protection against algorithmic discrimination, disclosure of AI use.
Jurisdiction-aware policy enforcement, automated consumer-notice controls, discrimination and accuracy monitoring, evidence per statute.
Federal enforcement & executive action
FTC enforcement; shifting executive orders; sector regulators (SEC, OCC)
No unfair or deceptive practices – including overstated AI claims and harmful outputs; sector-specific supervision of AI use.
Non-compliant outputs are detected, blocked or escalated in real time; complete, tamper-evident records for investigations.
NIST AI Risk Management Framework
De-facto standard for AI governance in the US
Govern, map, measure, manage: continuous risk identification and controls across the AI lifecycle.
The framework's controls become runtime policies: testing and evaluation of every version, continuous monitoring, measurable risk reporting.
State privacy laws
CCPA/CPRA and a growing set of comprehensive state privacy statutes
Consumer rights, limits on profiling and automated decision-making, data minimisation and security obligations.
Automatic PII redaction in prompts and responses, access control via your IAM, opt-out-aware processing, complete audit trails.
Sectoral rules & internal policies
HIPAA, GLBA, EEOC guidance, NYC Local Law 144 – plus your own directives
Sector-specific duties from health data to hiring: bias audits, confidentiality, human review of consequential decisions.
Enterprise and sector policies are stored as machine-enforceable rules and applied automatically to every AI interaction.
As of August 2026. This overview does not constitute legal advice.
