AI Governance: EU AI Act, U.S. Enforcement, and State Laws

AI governance is the set of laws, regulatory actions, technical standards, and internal corporate practices that control how artificial intelligence systems are built, tested, deployed, and held accountable when they cause harm. The rules differ sharply by jurisdiction. The European Union began enforcing bans on certain AI practices on February 2, 2025, and its main obligations for high-risk systems become enforceable on August 2, 2026. The United States moved the opposite direction the same month, revoking its principal AI safety executive order and shifting toward voluntary standards and sector-by-sector enforcement. That divergence is now the central fact anyone working with AI has to plan around.

What AI Governance Actually Covers

Almost every framework in use today rests on three ideas: accountability, transparency, and human oversight. They appear in the EU AI Act, the NIST AI Risk Management Framework, the OECD AI Principles, and most corporate policies. The specific requirements differ, but the logic is consistent.

Accountability means that when an AI system produces a harmful or wrong result, a specific person or organization can be held answerable. That requires detailed records of how a system was trained, what data it used, and who approved its release. Without that chain, there is no realistic way to correct errors or compensate people harmed by them.

Transparency means people affected by an automated decision can understand, in general terms, why the system reached its outcome. If an algorithm denies a loan or filters out a job candidate, the person on the receiving end needs enough information to judge whether the decision was fair. The EU AI Act codifies this for certain AI categories, and the FTC has treated opaque algorithmic decision-making as a possible unfair practice under existing consumer protection law.

Human oversight preserves the ability of a person to intervene when an automated system goes wrong. For high-stakes decisions in health, criminal justice, or financial access, a human reviewer must be able to override the system. Algorithms optimize for whatever objective they were given, and that sometimes produces results a person would immediately recognize as absurd or dangerous.

The European Union AI Act

The EU AI Act is the most comprehensive AI-specific law in force anywhere in the world, and its provisions are being phased in over several years.1Shaping Europe’s digital future. AI Act The prohibitions on unacceptable AI practices and the requirement that organizations ensure staff have adequate AI literacy took effect on February 2, 2025. Rules for general-purpose AI models followed in August 2025. The bulk of the Act, including the requirements for high-risk systems and the transparency obligations for limited-risk systems, becomes enforceable on August 2, 2026.

Prohibited Practices

The Act bans eight categories of AI outright. These include systems that use manipulative techniques to distort behavior in ways likely to cause harm, tools that exploit vulnerabilities tied to age, disability, or economic circumstances, and social scoring systems that judge people by behavior or personality traits to impose disproportionate consequences. Also banned: scraping facial images from the internet or CCTV to build recognition databases, inferring emotions in workplaces or schools, and most real-time biometric identification in public spaces by law enforcement.2The EU Artificial Intelligence Act. Article 5 – Prohibited AI Practices

High-Risk and Limited-Risk Categories

AI systems used in education, employment, law enforcement, critical infrastructure, and immigration are classified as high-risk. Before entering the market, they must pass conformity assessments covering safety, accuracy, cybersecurity, and documentation. Deployers must run impact assessments. Those rules become enforceable in August 2026.

Limited-risk systems, such as chatbots and tools that generate deepfakes, carry transparency obligations. Users must know they are interacting with a machine, and AI-generated content, particularly deepfakes and synthetic text on matters of public interest, must be clearly labeled. Minimal-risk applications like spam filters face no new requirements and make up the vast majority of AI tools currently in use.

Penalties

Fines scale with the severity of the violation:

  • Prohibited practices: up to €35 million or 7% of global annual turnover, whichever is higher.
  • Other compliance failures affecting providers, deployers, importers, or notified bodies: up to €15 million or 3% of global annual turnover.
  • Providing incorrect information to regulators: up to €7.5 million or 1% of global annual turnover.

For small and medium-sized enterprises, including startups, the fine is capped at whichever figure is lower.3The EU Artificial Intelligence Act. Article 99 – Penalties Regulators can also order specific AI models permanently removed from the EU market when accuracy or bias problems cannot be corrected.

United States Federal Policy After January 2025

The federal approach changed sharply at the start of 2025. Executive Order 14110, signed in October 2023, had required developers of large-scale AI models to share safety test results with the government and invoked the Defense Production Act to compel reporting on systems that could contribute to biological or nuclear threats. That order was revoked on January 23, 2025, and replaced by Executive Order 14179, titled “Removing Barriers to American Leadership in Artificial Intelligence.”4Federal Register. Removing Barriers to American Leadership in Artificial Intelligence

EO 14179 treats the earlier safety requirements as obstacles to innovation. It directed agencies to review every action taken under EO 14110 and to suspend or rescind anything inconsistent with maintaining American dominance in AI. It also directed the Office of Management and Budget to revise its memoranda governing federal use of AI, including M-24-10, which had established Chief AI Officer appointments and public inventories of agency AI use cases.

In March 2026, the White House published a National Policy Framework for Artificial Intelligence that recommended Congress avoid creating any new federal rulemaking body for AI and instead rely on existing sector-specific regulators. The framework urged federal preemption of state AI laws the administration considers burdensome, while preserving states’ ability to enforce general consumer protection, anti-fraud, and child safety laws.5The White House. National Policy Framework for Artificial Intelligence – Legislative Recommendations

The National Institute of Standards and Technology’s AI Risk Management Framework (AI RMF 1.0) remains the most widely referenced voluntary standard in the United States, even after the administration change.6National Institute of Standards and Technology. AI Risk Management Framework It walks organizations through governing, mapping, measuring, and managing AI risks.7National Institute of Standards and Technology. NIST AI 100-1 Artificial Intelligence Risk Management Framework Federal agencies, private companies, and international bodies have adopted it as a baseline.

How U.S. Agencies Enforce AI Rules Today

Without a comprehensive federal AI statute, existing agencies apply existing authority.

The FTC

The Federal Trade Commission uses Section 5 of the FTC Act to police unfair or deceptive practices involving AI. In September 2024, it launched Operation AI Comply, a coordinated crackdown on businesses making false claims about their AI products and services using AI-generated fake reviews.8Federal Trade Commission. FTC Announces Crackdown on Deceptive AI Claims and Schemes The agency’s position is that there is no AI exemption from consumer protection law: a practice that would be deceptive or unfair without AI remains so with it.9Federal Trade Commission. Artificial Intelligence Enforcement actions have produced consent decrees and financial settlements against companies that misrepresented AI capabilities or harmed consumers with automated tools.

The EEOC and Hiring Tools

AI tools that screen resumes, score candidates, or monitor productivity face established discrimination law. The EEOC applies the Uniform Guidelines on Employee Selection Procedures to AI-based hiring tools. Under the four-fifths rule, if a tool selects members of a protected group at less than 80% of the rate for the most-selected group, that creates a preliminary finding of adverse impact. The employer must then show the tool is job-related and consistent with business necessity, or that the initial analysis was flawed.

Employers using a third-party vendor’s hiring tool are not shielded from liability. If the tool produces discriminatory outcomes, the employer is on the hook regardless of who designed it. The EEOC recommends ongoing self-audits and expects employers to ask vendors what steps they have taken to test their products for adverse impact.

The NLRB and Workplace Surveillance

The National Labor Relations Board has raised separate concerns about AI-powered workplace surveillance, including algorithmic management tools that track keystrokes, monitor communications, or score productivity. The agency’s general counsel has advocated treating electronic monitoring that tends to interfere with workers’ rights to organize as presumptively illegal under the National Labor Relations Act.

The Copyright Office

The U.S. Copyright Office has taken a clear position on AI-generated content: on its own, it is not eligible for copyright protection. Copyright requires human authorship, and when an AI system determines the expressive elements of an output, the result is not a copyrightable work. A human who selects, arranges, or substantially modifies AI-generated material can claim copyright over those human contributions, but the AI-generated portions must be disclaimed in the registration. Anyone submitting a work containing more than trivial AI-generated content has a duty to disclose it.10U.S. Copyright Office. Works Containing Material Generated by Artificial Intelligence

Whether using copyrighted works to train AI models is fair use remains unsettled. Two federal court decisions in June 2025 found that the specific uses at issue were “highly transformative and fair use,” but the judges cautioned that in most cases, training on copyrighted works without permission is likely infringing, particularly when plaintiffs can show the resulting models flood the market with substitutes for the original works. Those cases are early, and appellate review will shape the law further.

The Take It Down Act

The Take It Down Act, signed into law in 2025, adds a criminal enforcement mechanism for one specific type of AI harm: nonconsensual intimate images, including AI-generated deepfakes. The law requires covered platforms to establish notice-and-removal processes by May 19, 2026, and imposes criminal penalties, including imprisonment, for publishing such content.11Congress.gov. The TAKE IT DOWN Act – A Federal Law

State Laws and the Preemption Fight

As the federal government has stepped back from prescriptive AI regulation, states have moved in. Several now require developers and deployers of high-risk AI systems to take reasonable steps to protect consumers from algorithmic discrimination, complete impact assessments, and give consumers the right to appeal adverse automated decisions through human review. Other states have focused more narrowly on AI in elections, healthcare claims processing, or government procurement.

The March 2026 White House framework explicitly called on Congress to preempt state AI laws the administration considers overly burdensome.5The White House. National Policy Framework for Artificial Intelligence – Legislative Recommendations Conflicts between federal and state approaches are likely to intensify.

Civil Liability and Insurance Gaps

Traditional liability frameworks were not built with AI in mind. One open question is whether Section 230 of the Communications Decency Act, which shields platforms from liability for user-posted content, covers AI-generated content. The law assumes content comes from either a user or a platform, and AI output does not fit that split cleanly. When a chatbot generates harmful advice or defamatory statements, the speaker is arguably neither the user who typed the prompt nor the platform in its traditional hosting role. No court has definitively resolved this.

The proposed AI LEAD Act (S.2937), introduced in 2025, would classify AI systems as “products” under federal law, opening the door to traditional product liability claims including defective design, failure to warn, and strict liability.12Congress.gov. S.2937 – AI LEAD Act 119th Congress (2025-2026) As of late 2025, the bill was referred to the Senate Judiciary Committee and had not advanced further. Even without new legislation, companies face potential negligence claims if their AI systems cause harm and they cannot demonstrate reasonable testing and safeguards.

Insurance is another emerging gap. Major carriers have begun adding AI-specific exclusions to commercial general liability and management liability policies. These exclusions can disclaim coverage for claims arising from AI-generated content, chatbot statements, inadequate AI governance, or violations of AI regulations. A loss caused by an AI tool may not be covered under a standard business policy. Anyone deploying AI at scale should read their policies carefully before assuming coverage.

Internal Corporate Governance

Organizations using AI at any meaningful scale need internal structures to manage the risk. The specifics vary by size and industry, but a few elements have become standard.

AI ethics committees bring together legal, technical, and operational perspectives to review proposed AI projects before launch. Engineers may not see the legal exposure; lawyers may not grasp the technical constraints. These committees work best when they have real authority to delay or block projects rather than an advisory role that gets overridden under business pressure.

A growing number of organizations appoint a Chief AI Officer to centralize oversight. OMB Memorandum M-24-10 required federal agencies to designate this role, and private companies have followed suit. The CAIO typically maintains a registry of every AI tool in use across the organization, ensures each meets applicable safety and compliance standards, and connects technical teams with executive leadership.

Impact assessments evaluate how a proposed AI system could affect employees, customers, and the public before deployment. A useful assessment documents the intended benefits, the foreseeable risks, and the mitigation planned for each. It also creates a record that matters if regulators or courts later ask what the organization knew and when. Several state laws now require these assessments for high-risk AI, and the EU AI Act mandates them for deployers of high-risk systems starting in 2026.

Most organizations do not build models from scratch. They license them from vendors, use open-source models, or integrate third-party APIs. That creates supply chain risk: a model poisoned at its source, a vendor that cuts corners on testing, or an open-source weight file with a built-in backdoor. Managing it requires evaluating vendors’ own governance, verifying training data provenance, and monitoring third-party dependencies over time. The EEOC guidance on hiring tools makes the point concretely: the employer, not the vendor, bears liability for discriminatory outcomes.

The technical work behind these structures matters too. Representative training data is the first line of defense against discriminatory outputs, because a dataset that overrepresents certain demographics, regions, or time periods will bake those imbalances into the model. Algorithmic auditing tests how a system performs under adversarial and edge-case inputs. Documentation practices known as model cards record who developed a system, what data trained it, what tasks it was designed for, how it performs across demographic groups, and its known limitations. Statistical testing for disparate impact and robustness testing for degraded inputs should be ongoing rather than one-time events; systems drift as real-world data diverges from training data.

Global Alignment Through the OECD

The OECD AI Principles provide a shared foundation for countries trying to align their domestic AI policies. Adopted by more than 40 countries, they promote inclusive growth, sustainability, transparency, and human-centered values.13OECD.AI. OECD AI Principles Overview Countries use them as a starting point for national risk frameworks, and they create some interoperability so that developers working across borders face fewer directly conflicting rules. The practical effect remains uneven. The EU has moved toward binding regulation informed by these principles; the U.S. has moved toward voluntary, industry-led standards. That split is the defining tension in global AI governance right now, and the choice of which regime an organization treats as its baseline will shape its compliance costs for years.