United States:Federal Direction Meets State Enforcement
Three federal instruments issued between December 2025 and March 2026 are reshaping the landscape, California’s transparency law takes effect in August 2026, and Illinois’s first-in-nation AI safety-audit law lands January 2027. The companies that thrive will be those with governance infrastructure that satisfies every track.
The Dual-Track Reality
Federal AI Policy: Three Coordinated Instruments
Between December 2025 and March 2026, the federal government issued three instruments that collectively reshape AI governance. The Administration’s unified national approach creates new dynamics for businesses operating across jurisdictions.
DOJ AI Litigation Task Force
Established to pursue a unified national framework by addressing state laws that may create barriers to interstate commerce. Signals federal intent to shape — not just observe — the AI regulatory landscape.
Commerce Dept. Evaluation
Comprehensive review of state AI laws, identifying approaches that align with or diverge from federal policy objectives. Creates a roadmap for potential federal preemption or harmonization.
FTC Policy Statement on AI
Confirms existing consumer protection law under Section 5 already applies to AI. Enforcement priorities include algorithmic fairness, deceptive AI claims, data privacy, and automated decision transparency. Penalties up to $50,120 per violation per day.
NIST AI Risk Management Framework: The Federal Standard
The Administration’s preferred voluntary standard provides a roadmap that aligns with federal objectives
Colorado’s AI Act explicitly recognizes NIST AI RMF compliance as an affirmative defense. Companies that align their governance infrastructure with this framework are better positioned for both federal reviews and state enforcement actions.
Federal Enforcement Confirms the Need for AI Governance
The FTC’s March 2026 Policy Statement makes clear: existing federal law already requires AI accountability. Companies need governance infrastructure not because states mandate it, but because the federal government itself recognizes these risks.
FTC Section 5 Enforcement Priorities
What This Means for Businesses
AI governance is a federal priority, not just a state-level requirement. The FTC’s enforcement agenda validates the need for accountability infrastructure.
Companies with documented AI governance records are better positioned for FTC reviews, state enforcement actions, and EU conformity assessments.
The NIST AI Risk Management Framework — the Administration’s preferred voluntary standard — provides a roadmap that aligns with federal objectives.
Jurisdiction-neutral governance records serve as business insurance that holds up under any regulatory framework — federal, state, or international.
Illinois: The First-in-Nation AI Safety-Audit Law
Illinois SB 315 — the Artificial Intelligence Safety Measures Act — is the first US statute to mandate annual, independent, third-party safety audits of frontier AI developers. It moves audit-based accountability from voluntary practice to enforceable law.
What SB 315 Requires
- Independent Third-Party Audits: Annual audits by conflict-free auditors with frontier-model safety expertise — the first such US mandate
- Frontier AI Frameworks: Published, annually updated plans to identify, disclose and mitigate “catastrophic risks”
- Incident Reporting: Critical safety incidents reported to the state within 72 hours (24 hours if imminent risk of death or serious injury)
- Whistleblower Protections: Confidential internal channels and legal protection for employees raising safety concerns
Who Is Covered & When
- Frontier Developers: Companies with more than $500M annual gross revenue that train models above defined compute thresholds
- “Catastrophic Risk” Defined: Foreseeable harm contributing to death or serious injury of 50+ people, or over $1B in property damage
- Effective Jan 1, 2027: Core obligations begin, with independent third-party audit requirements phasing in through 2028
- Federal Interoperability: Illinois may recognize future federal standards deemed “substantially equivalent”
Why SB 315 Validates Regitech’s Approach
SB 315 turns independent audit and continuous evidence into a legal baseline — exactly the assurance layer Regitech was built to provide. Annual audits are only credible when the underlying monitoring and evidence exist year-round, not reconstructed after the fact.
Real-time monitoring and immutable, provenance-backed trails give auditors verifiable evidence of safety controls operating.
A neutral, conflict-free assurance layer aligns with the statute’s demand for structurally independent audits.
As other states and regulators follow Illinois, one SB 315-aligned methodology extends across the wider compliance map.
State Enforcement: Active Regardless of Federal Developments
While the federal government pursues a unified national approach, California’s transparency law is on schedule and Colorado has reset its framework. Companies need governance infrastructure that satisfies every track.
Colorado: SB 24-205 → SB 26-189
- Original Act Repealed: SB 24-205 was repealed before taking effect and replaced by SB 26-189, signed May 14, 2026
- New Model: Shifts from “high-risk” impact assessments to transparency and consumer-rights rules for automated decision-making technology
- Consumer Rights: Developer documentation, consumer notice, and a right to human review of consequential decisions
- Effective Jan 1, 2027: Enforced by the Colorado AG under the Consumer Protection Act, with a 60-day right to cure
California CAITA (SB 942)
- Content Provenance: AI-generated content must carry machine-readable provenance metadata
- Watermarking: Covered providers must embed persistent, tamper-resistant watermarks in AI outputs
- Detection Tools: Must provide free tools enabling users to determine if content is AI-generated
- 18+ Covered Providers: OpenAI, Google, Meta, Microsoft, Anthropic, Adobe, and growing
The Updated Enforcement Timeline: Phased, Not Delayed
Federal direction, state enforcement, and EU obligations are now operating on parallel tracks. Every quarter from now through 2028 brings a new enforcement milestone.

Federal Direction
State Enforcement
EU (For US Companies)
Key Sectors: Where Federal and State Requirements Converge
Each sector faces overlapping compliance obligations from federal enforcement, state mandates, and international requirements. Effective governance infrastructure addresses all simultaneously.
Employment & HR Tech
Colorado ADMT + FTC fairness + EEOC oversight
- • Colorado: Notice & human-review rights for AI hiring/promotion decisions (SB 26-189)
- • FTC: Algorithmic discrimination enforcement under Section 5
- • EEOC: AI guidance on Title VII compliance for employment decisions
- • EU: Annex III high-risk classification for employment AI (Dec 2027)
Financial Services & Insurance
Colorado Act + FTC + OCC/Fed/FDIC + fair lending
- • Colorado: Consequential decisions in credit, insurance, investment
- • FTC: Consumer protection enforcement for AI lending decisions
- • Federal regulators: OCC, Fed, FDIC issuing AI model risk guidance
- • Fair lending: ECOA/FCRA intersect with state AI requirements
Healthcare & Life Sciences
Colorado Act + FDA + HHS + state regulations
- • Colorado: AI affecting healthcare access and coverage decisions
- • FDA: AI/ML medical device guidance and pre-market requirements
- • HHS: AI in Medicaid/Medicare decision-making oversight
- • Telemedicine: AI triage, diagnostic support, and clinical decision tools
Legal & Government
Federal procurement + state requirements + transparency
- • Federal contractors: NIST AI RMF creates procurement advantage
- • Colorado DORA: 10 regulatory divisions using AI for licensing
- • California: Government agency AI transparency requirements
- • Legal tech: 180% AI adoption increase creating compliance need
Cross-Jurisdictional Penalty Exposure
For companies operating across multiple jurisdictions, penalty exposure is cumulative. A single AI governance failure can trigger enforcement actions under federal, state, and international frameworks simultaneously.
The Business Certainty Argument
AI governance isn’t a regulatory burden — it’s business insurance. Whether regulation comes from federal enforcement, state mandates, or international requirements, companies with defensible AI governance records are better positioned. Jurisdiction-neutral governance infrastructure produces defensible evidence of responsible AI practice regardless of which regulatory framework prevails.
Federal Direction + State Enforcement = Governance Now
The federal government has confirmed AI accountability is a national priority. State enforcement begins in months. Companies that build governance infrastructure today — aligned with NIST AI RMF, defensible under FTC Section 5, and compliant with state mandates — will define the standard that laggards must eventually meet.
