Guide to AI Laws and Regulations in the U.S.

Guide to Laws and Regulations about AI (Artificial Intelligence) in the United States
As artificial intelligence (AI) continues to shape our world, policymakers and regulators are grappling with how to govern this transformative technology. While the U.S. lacks comprehensive federal AI regulations, several key developments have taken place at both the federal and state levels.
These regulations are aimed at generative AI (gen AI), such as OpenAI’s ChatGPT or Google Gemini, as well as other forms of AI which use algorithms and machine learning for facial recognition or predict individual behavior.
The regulatory landscape in the United States includes several laws and policies governing AI use, primarily addressing national security, privacy, and misuse (such as deepfakes).
How is artificial intelligence (AI) defined in the law?
The National Artificial Intelligence Initiative Act defines artificial intelligence as “a machine-based system that can, for a given set of human-defined objectives, make predictions, recommendations, or decisions influencing real or virtual environments.”115 U.S.C. § 9411 (2021)
What are the federal regulations on AI?
Congress passed the National Initiative on Artificial Intelligence (NIAI) as part of the National Defense Authorization Act of 2021. The NIAI does not impose specific regulations on AI, but seeks to coordinate the use of AI across federal agencies.
1. Executive Order 14179 (2025)
Signed on January 23, 2025, Executive Order 14179 is titled Removing Barriers to American Leadership in Artificial Intelligence. It revoked earlier Biden-era AI directives and policies. The order directs all federal agencies to develop an AI Action Plan within 180 days, focusing on promoting innovation, reducing regulatory burdens, and advancing U.S. global competitiveness in AI. Agencies are instructed to identify and repeal any policies that may hinder AI development or deployment. The order also emphasizes risk-based regulation and encourages partnerships with the private sector.
2. TAKE IT DOWN Act (Effective May 2025)
This bipartisan law criminalizes the distribution of non-consensual, AI-generated intimate imagery (commonly referred to as “deepfake porn”). It requires platforms to remove such content within 48 hours of receiving notice. The law provides civil and criminal penalties for those who create or knowingly distribute such content, and it gives individuals the right to seek removal and money damages.
3. Federal Export Controls and AI-Related Standards
The U.S. Department of Commerce, through the Bureau of Industry and Security (BIS), continues to enforce export restrictions on advanced semiconductors and AI-related technologies. These controls limit the export of AI chips and related tools to certain countries, primarily to protect national security interests.
The National Institute of Standards and Technology (NIST) has also been tasked with developing and maintaining voluntary AI risk management frameworks. The NIST AI Risk Management Framework 1.0, released in January 2023, remains active and is widely adopted by federal agencies and private sector actors for managing AI risks.
4. Center for AI Standards and Innovation (CAISI)
Previously called the AI Safety Institute, the CAISI operates within NIST. It is responsible for coordinating standards for AI development, deployment, safety testing, and reporting across federal agencies. While not a rulemaking body, CAISI plays a key role in shaping how agencies use and oversee AI tools. Its standards are often adopted by reference in federal contracts and guidelines.
Are there any state regulations on AI?
Despite attempts to restrict state regulation, several state-level laws on AI are in effect as of June 2025:
Montana (HB 178): Enacted in May 2025, this law limits the use of AI by state agencies. It prohibits the use of automated systems for surveillance or decision-making without human review, requires disclosure when AI is used in public services, and mandates impact assessments for high-risk AI systems used by the government.
Tennessee (ELVIS Act): Enacted in 2024, this law prohibits the unauthorized use of an individual’s voice or likeness through AI. It extends existing rights of publicity to cover generative AI technologies. The law is enforceable by both civil suits and state action.
Illinois
- In 2019, Illinois passed the Artificial Intelligence Video Interview Act (AIVIA) aimed at regulating the use of AI by employers who conduct video interviews of applicants for positions based in Illinois.
- Biometric Information Privacy Act (BIPA): While not AI-specific, BIPA has been increasingly applied to AI systems that use biometric data such as facial recognition or voice analysis. It requires companies to obtain informed consent before collecting or using biometric identifiers and allows for private lawsuits.
California
- California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA): These laws impose obligations on companies that use personal data in AI systems, including transparency, opt-out rights, and data minimization. Enforcement is overseen by the California Privacy Protection Agency, which has issued guidance on automated decision-making.
- Requires chatbots to disclose that they are not human.
Colorado
S.B. 169 restricts insurers from using consumer data or predictive models in a way that unfairly discriminates against individuals based on protected grounds, such as race, gender, or sexual orientation.
Is it considered copyright infringement for a gen AI to train on data or content without the consent of the owner of that data or content?
It may be considered fair use, and thus not infringing on copyrights of owners of content used by generative AI. However, this is currently being decided by the courts. See updates at our page What is Fair Use.
Can an AI receive a patent, or can a human inventor get a patent for an invention developed with assistance from AI?
See our Guide to Patent Law.
Are deepfakes illegal?
Deepfakes involve creating fake or altered videos, images, or recordings of people, often through the use of artificial intelligence. The TAKE IT DOWN Act (2025) criminalizes the distribution of non-consensual, AI-generated intimate imagery (commonly referred to as “deepfake porn”). Other than this, there are no federal laws in the US related to deepfakes.
The use or distribution of deepfakes may be illegal based on existing laws. It could be found as copyright infringement if someone else’s copyrighted material was used. It may be considered illegal defamation to create, post, or share deepfakes, if it portrays someone in a false light and harms their reputation.
However, it could also be considered legal “parody” protected under the 1st amendment, especially if it is done to a public official. This is a very new thing that the law has not yet resolved.
It is also illegal to use a deepfake for fraudulent purposes.
Further Resources
See our Guide to Laws About Technology
See our Guide to Laws for Consumers
Photo credit: Image by vector_corp on Freepik
References
