United States:Federal Direction Meets State Enforcement
Federal instruments issued from December 2025 onwards are reshaping the landscape, California’s transparency law has been operative since January 2026, and Illinois’s first-in-nation AI safety-audit law lands January 2027. The companies that thrive will be those with governance infrastructure that satisfies every track.
The Dual-Track Reality
Federal AI Policy: Three Coordinated Instruments
Between December 2025 and March 2026, the federal government issued three instruments that collectively reshape AI governance. The Administration’s unified national approach creates new dynamics for businesses operating across jurisdictions.
DOJ AI Litigation Task Force
Established to pursue a unified national framework by addressing state laws that may create barriers to interstate commerce. Signals federal intent to shape — not just observe — the AI regulatory landscape.
Commerce Dept. Evaluation
Comprehensive review of state AI laws, identifying approaches that align with or diverge from federal policy objectives. Creates a roadmap for potential federal preemption or harmonization.
FTC Proposed Policy Statement
A proposed FTC policy statement dated 30 June 2026 addresses the suppression of accuracy in AI systems. It is a proposal and is not final. Separately, Section 5 of the FTC Act already applies to deceptive or unfair AI-related conduct, with civil penalties of up to $50,120 per violation per day.
NIST AI Risk Management Framework: The Federal Standard
The Administration’s preferred voluntary standard provides a roadmap that aligns with federal objectives
Colorado’s AI Act explicitly recognizes NIST AI RMF compliance as an affirmative defense. Companies that align their governance infrastructure with this framework are better positioned for both federal reviews and state enforcement actions.
Existing Federal Law Already Reaches AI Conduct
Section 5 of the FTC Act applies to deceptive and unfair conduct today, including conduct involving AI systems. Governance infrastructure matters not only because states mandate it, but because federal consumer-protection law already reaches how AI systems are described and how they behave.
Where Section 5 Exposure Arises in AI Systems
What This Means for Businesses
AI accountability is reachable under existing federal law, not only under state mandates. Section 5 applies to AI-related claims and conduct today.
Companies with documented AI governance records are better positioned for FTC reviews, state enforcement actions, and EU conformity assessments.
The NIST AI Risk Management Framework — the Administration’s preferred voluntary standard — provides a roadmap that aligns with federal objectives.
Jurisdiction-neutral governance records serve as business insurance that holds up under any regulatory framework — federal, state, or international.
Illinois: The First-in-Nation AI Safety-Audit Law
Illinois SB 315 — the Artificial Intelligence Safety Measures Act — is the first US statute to mandate annual, independent, third-party safety audits of frontier AI developers. It moves audit-based accountability from voluntary practice to enforceable law.
What SB 315 Requires
- Independent Third-Party Audits: Annual audits by conflict-free auditors with frontier-model safety expertise — the first such US mandate
- Frontier AI Frameworks: Published, annually updated plans to identify, disclose and mitigate “catastrophic risks”
- Incident Reporting: Critical safety incidents reported to the state within 72 hours (24 hours if imminent risk of death or serious injury)
- Whistleblower Protections: Confidential internal channels and legal protection for employees raising safety concerns
Who Is Covered & When
- Frontier Developers: Companies with more than $500M annual gross revenue that train models above defined compute thresholds
- “Catastrophic Risk” Defined: Foreseeable harm contributing to death or serious injury of 50+ people, or over $1B in property damage
- Effective Jan 1, 2027: Core obligations begin, with independent third-party audit requirements phasing in through 2028
- Federal Interoperability: Illinois may recognize future federal standards deemed “substantially equivalent”
Why SB 315 Validates Regitech’s Approach
SB 315 turns independent audit and continuous evidence into a legal baseline — exactly the assurance layer Regitech was built to provide. Annual audits are only credible when the underlying monitoring and evidence exist year-round, not reconstructed after the fact.
Continuous monitoring and tamper-evident, provenance-backed trails give auditors verifiable evidence of safety controls operating.
A neutral, conflict-free assurance layer aligns with the statute’s demand for structurally independent audits.
As other states and regulators follow Illinois, one SB 315-aligned methodology extends across the wider compliance map.
State Enforcement: Active Regardless of Federal Developments
While the federal government pursues a unified national approach, California’s transparency law is on schedule and Colorado has reset its framework. Companies need governance infrastructure that satisfies every track.
Colorado: SB 24-205 → SB 26-189
- Original Act Repealed: SB 24-205 was repealed before taking effect and replaced by SB 26-189, signed May 14, 2026
- New Model: Shifts from “high-risk” impact assessments to transparency and consumer-rights rules for automated decision-making technology
- Consumer Rights: Developer documentation, consumer notice, and a right to human review of consequential decisions
- Effective Jan 1, 2027: Enforced by the Colorado AG under the Consumer Protection Act, with a 60-day right to cure
California CAITA (SB 942)
- Content Provenance: AI-generated content must carry machine-readable provenance metadata
- Watermarking: Covered providers must embed persistent, tamper-resistant watermarks in AI outputs
- Detection Tools: Must provide free tools enabling users to determine if content is AI-generated
- 18+ Covered Providers: OpenAI, Google, Meta, Microsoft, Anthropic, Adobe, and growing
The Updated Enforcement Timeline: Phased, Not Delayed
Federal direction, state enforcement, and EU obligations are now operating on parallel tracks. Every quarter from now through 2028 brings a new enforcement milestone.

Federal Direction
State Enforcement
EU (For US Companies)
Key Sectors: Where Federal and State Requirements Converge
Each sector faces overlapping compliance obligations from federal enforcement, state mandates, and international requirements. Effective governance infrastructure addresses all simultaneously.
Employment & HR Tech
Colorado ADMT + FTC fairness + EEOC oversight
- • Colorado: Notice & human-review rights for AI hiring/promotion decisions (SB 26-189)
- • FTC: Algorithmic discrimination enforcement under Section 5
- • EEOC: AI guidance on Title VII compliance for employment decisions
- • EU: Annex III high-risk classification for employment AI (Dec 2027)
Financial Services & Insurance
Colorado Act + FTC + OCC/Fed/FDIC + fair lending
- • Colorado: Consequential decisions in credit, insurance, investment
- • FTC: Consumer protection enforcement for AI lending decisions
- • Federal regulators: OCC, Fed, FDIC issuing AI model risk guidance
- • Fair lending: ECOA/FCRA intersect with state AI requirements
Healthcare & Life Sciences
Colorado Act + FDA + HHS + state regulations
- • Colorado: AI affecting healthcare access and coverage decisions
- • FDA: AI/ML medical device guidance and pre-market requirements
- • HHS: AI in Medicaid/Medicare decision-making oversight
- • Telemedicine: AI triage, diagnostic support, and clinical decision tools
Legal & Government
Federal procurement + state requirements + transparency
- • Federal contractors: NIST AI RMF creates procurement advantage
- • Colorado DORA: 10 regulatory divisions using AI for licensing
- • California: Government agency AI transparency requirements
- • Legal tech: 180% AI adoption increase creating compliance need
Cross-Jurisdictional Penalty Exposure
For companies operating across multiple jurisdictions, penalty exposure is cumulative. A single AI governance failure can trigger enforcement actions under federal, state, and international frameworks simultaneously.
The Business Certainty Argument
AI governance isn’t a regulatory burden — it’s business insurance. Whether regulation comes from federal enforcement, state mandates, or international requirements, companies with defensible AI governance records are better positioned. Jurisdiction-neutral governance infrastructure produces defensible evidence of responsible AI practice regardless of which regulatory framework prevails.
Federal Direction + State Enforcement = Governance Now
Existing federal law already reaches AI conduct, and the state enforcement dates are now fixed. Companies that build governance infrastructure today — aligned with NIST AI RMF, defensible under FTC Section 5, and compliant with the state mandates that apply to them — will be ready when scope widens.
