Evidence Library · Jurisdictions

United States context note

Instruments a US risk team may ask about,their status, and the limits of what AAES records establish.

Last reviewed:

A narrow, dated note on US instruments relevant to AI-agent oversight. The US has no comprehensive federal AI statute; AI-specific duties today come mainly from state and municipal laws, while federal executive action is actively contesting some of them, and existing federal civil-rights, consumer-protection, credit and privacy laws apply to AI use regardless. Each entry names the instrument's exact status. Executive orders, contested state laws and voluntary frameworks are different things, and this note keeps them apart.

These pages describe the product and cite public instruments. They are not legal advice, not a certification, and not a statement that any instrument applies to your organisation. The official source is authoritative; applicability questions belong to your advisers.

Instruments, by status

US instruments relevant to agent oversight (verified September 17, 2026)
InstrumentStatusWhat it addresses
Executive Order 14365 and the DOJ AI Litigation Task Force · FederalExecutive action, not legislation. EO 14365 (11 December 2025) seeks a national policy framework and directs challenges to state AI laws; the DOJ task force was announced 9 January 2026; a nonbinding National Policy Framework followed on 20 March 2026. An executive order does not itself invalidate a state law. Outcomes depend on litigation and courts; treat preemption claims as unsettled.The federal–state balance for AI regulation. No federal compliance duty for enterprises results from these instruments by themselves; existing federal civil-rights, consumer-protection, credit and privacy laws continue to apply to AI use.
Texas Responsible Artificial Intelligence Governance Act (TRAIGA, HB 149)Binding state law, effective 1 January 2026. Exclusive Attorney General enforcement, a 60-day cure period, and an affirmative defense linked to NIST AI RMF–aligned risk-management practices, subject to the statute's conditions.Persons doing business in Texas who develop or deploy AI systems. Intent-based prohibitions (manipulation toward self-harm or crime, intentional unlawful discrimination, certain biometric and synthetic-content uses) and disclosure duties for government AI interactions.
California SB 53 (Transparency in Frontier AI Act) and AB 2013Binding state law. SB 53 signed 29 September 2025, effective 1 January 2026; AB 2013 training-data transparency effective 1 January 2026.SB 53 addresses frontier-model developers above defined compute thresholds (safety frameworks, incident reporting), mostly upstream of enterprise deployers. AB 2013 requires training-data disclosures from developers.
Utah AI Policy Act · Illinois HB 3773Binding state laws. Utah (2024): disclosure duties when generative AI interacts with consumers in regulated occupations. Illinois: AI employment amendments to the Human Rights Act, effective 1 January 2026.Consumer disclosure and employment-decision duties respectively.
NYC Local Law 144Binding municipal law; enforcement began 5 July 2023.Automated employment decision tools as defined by the law, not every hiring tool: annual independent bias audits and candidate notices.
New York RAISE Act · Colorado automated decision-making transparency lawFuture-effective and unsettled. New York's RAISE Act (frontier-model safety) was signed 19 December 2025, amended by a chapter amendment signed 27 March 2026, and takes effect 1 January 2027. It brings Department of Financial Services oversight and 72-hour incident reporting for large frontier developers above a $500 million revenue threshold. Colorado's original AI Act (SB 24-205) never took effect: delayed to 30 June 2026, its enforcement stayed in the xAI v. Weiser litigation, it was repealed and replaced by SB 26-189 (signed 14 May 2026), a narrower automated decision-making transparency law effective 1 January 2027, with Attorney General implementing rules due by then and the litigation ongoing.Frontier-model safety duties (NY) and automated decision-making transparency duties (CO), respectively.
NIST AI Risk Management Framework 1.0Voluntary technical guidance. Not a law, but TRAIGA references NIST AI RMF–aligned practices in its affirmative defense. See the NIST AI RMF framework note.Enterprise AI risk management structure; the action-layer records a reviewer can inspect are described in the framework note.

What AAES records may contribute

Selected contributions; capability status per the dated capability matrix
ExpectationAAES contributionCapability status
Named accountability for AI-driven work (state disclosure and oversight duties; internal governance)Every registered agent has a named accountable manager, a configured association rather than a statutory appointment; approvals are attributable to a named person; agent identities cannot act as approvers through the supported AAES approval path.Implemented.
Human control over consequential actions (internal governance; state and municipal oversight scrutiny)Actions the operator registers as irreversible (a registration classification, not an independent assessment of effects) require approval by an authorized person, bound to one intent and the exact payload, with expiry. An approval record does not by itself show the approver had adequate information, time or practical power to intervene.Implemented.
Documented risk management (records potentially relevant to a NIST AI RMF review; TRAIGA's NIST-linked affirmative defense)Sealed, hash-chained decision records with offline integrity verification by the client's own reviewer.Implemented. An independently controlled witness can be configured separately; that is not an external assessment, and the default deployment has none.

AAES decision records may support review of access and approval controls. They do not establish lawful processing, model fairness, suitability, or compliance with any instrument as a whole, and no AAES feature satisfies a state bias-audit or impact-assessment requirement by itself.

Within the configured trust model, integrity verification checks the exported records; it does not establish that every action was recorded, that an external action succeeded, or that recorded assertions are true. Approval records do not by themselves establish meaningful human oversight. Enforcement depends on control of the credential path, and actions bypassing AAES are not recorded.

Residual responsibility and explicit gaps

  • The client remains the regulated entity. Which state laws reach your organisation (and whether federal preemption changes that) is your adviser's question, not this page's.
  • Work outside AAES is invisible to AAES. Records cover actions routed through AAES; they say nothing about actions on bypass paths.
  • No independent certification or assessment of AAES exists. No SOC 2 report, no penetration test.
  • Status changes. State legislation and federal–state litigation were both moving when this note was reviewed. Re-check the primary source before relying on the status shown here.

Bring the instruments your risk team cites to a scoped evaluation.

Scope an evaluation