Sectoral enforcers: FTC · FDA · EEOC · CFPB
Issuer: Federal agencies under existing statutes
Date: ONGOING
Status: IN FORCE in United States, as of 29 JUL 2026
FTC (Operation AI Comply; Growth Cave $48.6M), FDA (1,247+ AI devices; PCCP), EEOC (guidance pulled, statutes intact), CFPB (ECOA/Reg B; Apr 2026 rule narrows disparate impact ⚠).
The most binding federal AI rules come from agencies enforcing pre-existing statutes. FTC: 'Operation AI Comply' sweep against AI-washing (DoNotPay $193k; Growth Cave $48.6M, Jan 2026) plus TAKE IT DOWN takedowns. FDA: 1,247+ AI-enabled devices authorized (~76 to 80% radiology), PCCP lifecycle updates. EEOC: guidance pulled from its site after EO 14179, but Title VII/ADA/ADEA fully apply. CFPB: circulars withdrawn May 2025, yet ECOA/Reg B still demand specific, accurate denial reasons, while the Apr 2026 Reg B final rule removes disparate-impact liability.
The 2026 Reg B final rule removing ECOA disparate-impact liability and the SR 26-2 model-risk guidance are cited from compliance trackers quoting Federal Register notices; consider a direct federalregister.gov check before publication.
What it actually requires (4 provisions)
- FTC: Operation AI Comply (from Sep 2024): DoNotPay $193k, Workado, Air AI, Growth Cave $48.6M; TAKE IT DOWN takedowns since 19 May 2026
- FDA: 1,247+ AI-enabled medical devices authorized (~76 to 80% radiology); PCCP final guidance (Dec 2024)
- EEOC: AI guidance pulled Jan 2025; Title VII/ADA/ADEA statutes fully intact (Mobley v. Workday proceeds)
- CFPB: Circulars 2022-03/2023-03 withdrawn May 2025; ECOA/Reg B specific-reason duty still binds; Apr 2026 rule removes disparate impact ⚠
How its status moved
- SWEEPOperation AI Comply, 25 Sep 2024
- SHIFTReg B disparate-impact rule, 22 Apr 2026 (eff. 21 Jul 2026) ⚠
- CURRENTThe operative federal enforcement layer
Sources (2)
FDA: FDA AI-Enabled Medical Devices
1,247+ AI-enabled devices authorized (~76 to 80% in radiology): the most concrete algorithmic oversight in America.
CFPB Reg B: ECOA / Regulation B: 2026 final rule
Reg B final rule (22 Apr 2026; effective 21 Jul 2026) eliminates disparate-impact ('effects test') liability under ECOA, narrowing federal fair-lending exposure for AI credit models.
The 2026 Reg B final rule removing ECOA disparate-impact liability and the SR 26-2 model-risk guidance are cited from compliance trackers quoting Federal Register notices; consider a direct federalregister.gov check before publication.
The rest of the United States stack
15 more instruments in this jurisdiction, each with its own status, provisions and sources.
- EO 14110 “Safe, Secure, Trustworthy AI”REVOKEDBiden safety EO; reporting mandates died with it.
- EO 14179 “Removing Barriers…”IN FORCEPro-innovation directive; ordered the AI Action Plan.
- America's AI Action Plan (“Winning the Race”)IN FORCE90+ actions, three pillars; policy, not law.
- EO 14365 “National Policy Framework”CONTESTEDDOJ AI Litigation Task Force (est. 9 Jan 2026) + BEAD funding leverage against state AI laws; intervened against Colorado Apr 2026.
- State-law moratoriumFAILEDStripped 1 Jul 2025, Senate 99 to 1.
- NIST AI RMF 1.0 + GenAI ProfileVOLUNTARY / SOFT LAWGovern/Map/Measure/Manage; safe harbor in TX TRAIGA; embedded in procurement.
- OMB M-25-21 & M-25-22IN FORCEAgency AI use & acquisition rules; bind federal agencies only.
- TAKE IT DOWN Act (Pub. L. 119-12)IN FORCEFirst federal AI-content law; FTC 48-hr takedown enforcement since 19 May 2026; up to $53,088/violation.
- Colorado SB 24-205 (Colorado AI Act)REPEALEDFirst comprehensive state AI law; stayed 27 Apr 2026 after xAI suit + DOJ intervention; never took effect.
- Texas TRAIGA (HB 149)IN FORCEProhibited-practices model; AG enforcement; $10k to $200k/violation; NIST safe harbor; sandbox.
- California cluster: SB 53 · AB 2013 · SB 243 · SB 942IN FORCESB 53 frontier transparency (>10²⁶ FLOPs + $500M revenue; OES incident reporting), AB 2013 training-data summaries, SB 243 companion chatbots (PRA ≥$1,000), SB 942 watermarking (UPCOMING 2 Aug 2026).
- Utah AI Policy ActIN FORCEDisclosure-on-request; no 'AI did it' defense; Learning Laboratory; ≤$2,500/violation.
- Illinois HB 3773 + AIVIA (2020)IN FORCEAI employment discrimination = civil-rights violation; first US AI-hiring law for video interviews.
- NYC Local Law 144IN FORCEFirst US bias-audit mandate; $500 to $1,500/day; Dec 2025 Comptroller audit found enforcement 'ineffective'.
- CAISI frontier-model evaluationsVOLUNTARY / SOFT LAWVoluntary pre-deployment testing agreements (Anthropic, OpenAI, Google DeepMind, Microsoft, xAI); EO 14409 cybersecurity testing ⚠ single-source.
Where this sits in the wider picture
- The United States regime dossier gives the doctrine this instrument belongs to, next to the other two jurisdictions.
- The Framework Explorer, filtered to US lists every instrument in this jurisdiction in one filterable index.
- The governance simulator shows what these rules do to a real AI system, next to what the other two jurisdictions do to the same one.
- The timeline places this date beside what the other capitals were doing that month.
Knowing the instrument is step one. Complying with it is the job.
The programs teach the work that follows a rule like this one: classification calls, conformity assessment, filings, documentation, and the judgment to defend every decision.
VERIFIED 29 JUL 2026. Every fact on this page is drawn from the sources listed above and dated to the day it was checked. Study aid, not legal advice: the official texts are always authoritative.