The comparison layer
The United States has no AI law either.
Executive orders, one voluntary framework, and old statutes doing new work.
84 NODES · 100 EDGES · 30 INSTRUMENTS · 12 AGENCIES · 22 BINDING · VERIFIED 2026-08-18
Why this is in a Singapore instrument
Because a Singapore or APAC company that ships into the United States has to answer one more question, and the answer has the same shape as Singapore's: there is no AI statute to comply with. The crosswalk in this Navigator already maps your controls to the NIST AI Risk Management Framework. This page is what sits behind that column, kept current on the same monthly pass.
Click the map to enable scroll zoom
Drag to pan. Click, then scroll to zoom. Double click to dive. Click a node to pin it, Escape to clear. Dashed amber edge means GAGE analysis, not an official mapping.
What actually binds a private company
Statutes of general application that predate AI, plus one narrow AI content statute. Not a single one of them was written for AI, and every one of them reaches it.
Federal Trade Commission Act, Section 5
Prohibits unfair or deceptive acts or practices affecting commerce. Technology neutral and already in force, it is the general purpose hook for AI claims, AI products and AI driven harm.
TAKE IT DOWN Act (Pub. L. 119-12)
Signed 19 May 2025. The only federal statute to date that regulates AI generated content directly. Criminal provisions plus a platform notice and removal duty enforced by the FTC.
Title VII of the Civil Rights Act of 1964
The binding floor under every AI hiring tool used in the United States. An employer is liable for a discriminatory selection procedure it uses, including one built and scored by a vendor.
Americans with Disabilities Act (1990)
Binding on employers using AI assessments. Two live exposures: screening out a qualified applicant with a disability, and failing to offer an alternative format on request.
Equal Credit Opportunity Act and Regulation B
The binding floor under AI credit decisioning. Adverse action notices must state the actual principal reasons, which is the requirement that makes an unexplainable model a legal problem rather than a technical one.
AI in Government Act of 2020 and the Advancing American AI Act
The statutory floor under federal AI use policy. M-25-21 is issued consistent with them, which is why a change of administration can rewrite the memorandum but not remove the duty to have one.
The trap: withdrawn guidance is not repealed law
Two US agencies removed their AI guidance in 2025. Neither withdrawal touched the statutes underneath. If your compliance programme was built against the guidance rather than the law, it now points at nothing while your exposure is unchanged.
- WithdrawnEEOC removes its AI guidance, January 2025
The EEOC's AI specific technical assistance documents on Title VII and the ADA were taken off its website on 27 January 2025. The statutes and the Uniform Guidelines were untouched. Withdrawn guidance is not repealed law.
- WithdrawnCFPB withdraws its two AI circulars, May 2025
Circulars 2022-03 and 2023-03, which told lenders how adverse action notices had to work for complex algorithms, were withdrawn in a bulk withdrawal of 67 guidance documents published 12 May 2025. Regulation B was not amended.
Who governs what
The White House (Executive Office of the President)
Issues the executive orders that carry current US federal AI policy. Executive orders direct the executive branch; they are not statutes and do not by themselves bind private companies, except where they flow through federal procurement.
Office of Management and Budget (OMB)
Turns AI executive orders into requirements every executive branch agency must follow, through numbered memoranda. M-25-21 governs federal use of AI; M-25-22 governs federal acquisition of it.
National Institute of Standards and Technology (NIST)
Publishes the voluntary AI Risk Management Framework and its profiles. NIST writes no binding rules for AI; its output becomes obligation only when a contract, a regulator or a state statute cites it.
Center for AI Standards and Innovation (CAISI), NIST
The federal government's frontier model evaluation body, housed at NIST. Runs voluntary model evaluations with frontier labs and, since February 2026, the AI Agent Standards Initiative.
Federal Trade Commission (FTC)
The closest thing the United States has to a general purpose AI regulator, using Section 5 of the FTC Act against deceptive or unfair AI conduct. No AI specific statute is required for an FTC case.
Equal Employment Opportunity Commission (EEOC)
Enforces Title VII, the ADA and the ADEA against discriminatory employment decisions, including decisions made by AI tools. Its AI specific guidance documents were removed from its website in January 2025; the statutes they interpreted did not change.
Consumer Financial Protection Bureau (CFPB)
Enforces ECOA and the Fair Credit Reporting Act against lenders, including where credit decisions are made by algorithms. Withdrew its two AI relevant circulars in May 2025; ECOA and Regulation B still bind.
Food and Drug Administration (FDA)
Regulates AI enabled medical devices through the existing device pathways. FDA guidance documents are expressly non binding; the underlying device requirements are not.
Department of Justice (DOJ)
Prosecutes federal crimes committed with AI, and since January 2026 runs the AI Litigation Task Force created to challenge state AI laws.
Cybersecurity and Infrastructure Security Agency (CISA), DHS
Owns the federal civilian cybersecurity directives that now carry AI specific obligations, and issues the joint guidance on securing AI systems.
United States Congress
Has enacted no comprehensive AI statute. One narrow AI content law is in force (the TAKE IT DOWN Act) and the White House asked Congress in March 2026 to pass a preemptive federal framework.
The states, and their attorneys general
The layer where most binding US AI obligation actually sits today. Covered in full by the 50-State AI Law Atlas, not restated here.
Every entry in the federal layer
Grouped by legal force, heaviest first. Executive orders and OMB memoranda are labelled binding sectoral because they bind the federal government and the vendors it buys from, not the general public.
Binding law. It applies to everyone in scope, whether or not anyone points at it.
22- Federal Trade Commission (FTC)
- Equal Employment Opportunity Commission (EEOC)
- Consumer Financial Protection Bureau (CFPB)
- Department of Justice (DOJ)
- United States Congress
- The states, and their attorneys general
- Federal Trade Commission Act, Section 5
- Do not overstate what your AI does
- Do not sell a tool whose foreseeable use is deception
- Operation AI Comply: the FTC's first AI enforcement sweep
- The Rite Aid order: what an FTC AI remedy looks like
- TAKE IT DOWN Act (Pub. L. 119-12)
- 48 hour removal duty for covered platforms
- Title VII of the Civil Rights Act of 1964
- The Uniform Guidelines on Employee Selection Procedures
- EEOC removes its AI guidance, January 2025Withdrawn
- Americans with Disabilities Act (1990)
- Equal Credit Opportunity Act and Regulation B
- CFPB withdraws its two AI circulars, May 2025Withdrawn
- AI in Government Act of 2020 and the Advancing American AI Act
- Where the binding AI obligations actually are: the states
- The United States has no comprehensive AI statute
Binding, but only for a defined population: one regulated sector, or the federal government and the vendors it buys from.
42- The White House (Executive Office of the President)
- Office of Management and Budget (OMB)
- Food and Drug Administration (FDA)
- Cybersecurity and Infrastructure Security Agency (CISA), DHS
- Executive Order 14110: Safe, Secure, and Trustworthy Development and Use of Artificial IntelligenceSuperseded
- Executive Order 14148: Initial Rescissions of Harmful Executive Orders and Actions
- Executive Order 14179: Removing Barriers to American Leadership in Artificial Intelligence
- Executive Order 14277: Advancing Artificial Intelligence Education for American Youth
- Executive Order 14318: Accelerating Federal Permitting of Data Center Infrastructure
- Executive Order 14319: Preventing Woke AI in the Federal Government
- Executive Order 14320: Promoting the Export of the American AI Technology Stack
- Executive Order 14355: Unlocking Cures for Pediatric Cancer With Artificial Intelligence
- Executive Order 14363: Launching the Genesis Mission
- Executive Order 14365: Ensuring a National Policy Framework for Artificial Intelligence
- Executive Order 14409: Promoting Advanced Artificial Intelligence Innovation and Security
- Section 2: the stated policy
- Revise the OMB AI memoranda
- The Unbiased AI Principles
- Write the principles into LLM contracts
- Section 3: the AI Litigation Task Force
- Section 4: Commerce names the onerous state laws
- Section 5: broadband money as leverage
- Section 6: an FCC reporting standard
- Section 7: the FTC deception theory
- Section 8: ask Congress for the real thing
- DOJ announces the AI Litigation Task Force, January 2026
- DOJ intervenes against the Colorado AI Act
- Section 2(d): the AI cybersecurity clearinghouse
- Section 3: covered frontier models
- Section 3: the explicit bar on licensing
- Section 4: criminal enforcement against AI enabled crime
- OMB M-25-21: Accelerating Federal Use of AI through Innovation, Governance, and Public Trust
- Every agency identifies a Chief AI Officer
- Each CFO Act agency publishes an AI strategy
- Annual public AI use case inventory
- Minimum risk management practices for high impact AI
- National Security Systems are out of scope
- OMB M-25-22: Driving Efficient Acquisition of Artificial Intelligence in Government
- Foster a competitive American AI marketplace
- Track performance and manage risk
- Buy AI with a cross functional team
- Executive Order 13960: Promoting the Use of Trustworthy AI in the Federal Government
Proposed, not final. Read it, plan for it, and do not treat it as settled.
4- National Policy Framework for Artificial Intelligence: Legislative RecommendationsConsultation
- AI RMF Profile for Trustworthy AI in Critical Infrastructure (concept note)Consultation
- FTC proposed policy statement on the suppression of accuracy in AI systemsConsultation
- FDA draft guidance: AI enabled device software functionsConsultation
Voluntary guidance. Best practice, not obligation, until a contract or a regulator cites it.
16- National Institute of Standards and Technology (NIST)
- Center for AI Standards and Innovation (CAISI), NIST
- America's AI Action Plan
- Pillar I: Accelerate AI innovation
- Pillar II: Build American AI infrastructure
- Pillar III: Lead in international AI diplomacy and security
- NIST AI Risk Management Framework 1.0
- Govern: an AI RMF core function
- Map: an AI RMF core function
- Measure: an AI RMF core function
- Manage: an AI RMF core function
- NIST AI 600-1: Generative AI Profile
- Center for AI Standards and Innovation (CAISI)
- The AI Agent Standards Initiative
- FDA guidance: Predetermined Change Control Plans for AI enabled devices
- CISA guidance on securing AI systems
Common questions
- Does the United States have a federal AI law?
- No comprehensive one. Congress has enacted a single narrow AI content statute, the TAKE IT DOWN Act. Federal AI policy otherwise runs through executive orders and OMB memoranda that bind federal agencies and their vendors, a voluntary NIST framework, and older statutes such as the FTC Act, Title VII and ECOA applied to AI systems.
- Do US AI executive orders bind my company?
- Only if you sell to the federal government. Executive orders direct the executive branch. They reach a private company through procurement, which is how Executive Order 14319 puts its Unbiased AI Principles into the contract for any large language model an agency buys.
- Is the NIST AI Risk Management Framework mandatory?
- No. It is voluntary. It carries weight anyway, because contracts, insurers and several state statutes cite it, which is how a voluntary framework becomes an obligation without ever being enacted.
Scope of this page
Federal layer only. Most binding AI specific obligation in the United States today sits in state law, and that lives in a separate instrument on its own verification cycle, so no state fact sits in two datasets waiting to drift apart.