-
What is the legal definition of “artificial intelligence” in your jurisdiction, if any? If no definition exists, how do regulators or courts typically describe artificial intelligence?
The National Artificial Intelligence Initiative Act of 2020, 15 U.S.C. § 9401(3), defines artificial intelligence (AI) as “a machine-based system that can, for a given set of human-defined objectives, make predictions, recommendations, or decisions influencing real or virtual environments. Artificial intelligence systems use machine and human-based inputs to (A) perceive real and virtual environments; (B) abstract such perceptions into models through analysis in an automated manner; and (C) use model inference to formulate options for information or action.” This definition has been used and referenced (sometimes with context-specific additions) in other proposals, laws, and executive orders since then. Executive Order 14179 (Jan. 23, 2025), titled “Removing Barriers to American Leadership in Artificial Intelligence,” expressly retains the same statutory definition, providing that “‘artificial intelligence’ or ‘AI’ has the meaning set forth in 15 U.S.C. 9401(3).” Apart from implementation of the National Artificial Intelligence Initiative Act (and other laws that expressly adopt this definition), the definition is not necessarily binding on courts or intellectual property offices like the U.S. Patent and Trademark Office.
The American Bar Association, in Formal Opinion 512 (July 29, 2024), titled “Generative Artificial Intelligence Tools,” states: “There is no single definition of artificial intelligence. At its essence, AI involves computer technology, software, and systems that perform tasks traditionally requiring human intelligence. The ability of a computer or computer-controlled robot to perform tasks commonly associated with intelligent beings is one definition. The term is frequently applied to the project of developing systems that appear to employ or replicate intellectual processes characteristic of humans, such as the ability to reason, discover meaning, generalize, or learn from past experience.”
At the state level, there has been a significant proliferation of AI legislation, with some state laws using definitions that differ from the federal statutory definition. For example, Colorado SB 24-205 (May 17, 2024), titled “Consumer Protections for Artificial Intelligence,” defines “artificial intelligence system” as “any machine-based system that, for any explicit or implicit objective, infers from the inputs the system receives how to generate outputs, including content, decisions, predictions, or recommendations, that can influence physical or virtual environments.” This definition notably adds “content” as an output type and replaces the perceive/abstract/infer structure with a simpler “infers from the input it receives” formulation.
-
Has your country developed a national strategy for artificial intelligence? If yes, what progress has been made in its implementation? Are there plans for updates or revisions?
The United States has developed several recent national strategies for AI, focusing on different aspects of the development, use, and regulation of AI. These are in active implementation by the Trump administration, which has issued a series of executive orders, signed legislation, and released legislative proposals since January 2025.
The Trump administration rescinded Executive Order 14110 (Oct. 30, 2023), titled “Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence,” on January 20, 2025, and issued Executive Order 14179 (Jan. 23, 2025), titled “Removing Barriers to American Leadership in Artificial Intelligence.” The administration later released its national AI strategy, “Winning the Race: America’s AI Action Plan” (July 23, 2025), together with three implementing executive orders on federal procurement of ideologically neutral AI, AI exports, and data-center infrastructure. The Plan identifies over 90 potential federal policy actions across three key pillars: Accelerate AI Innovation, Build American AI Infrastructure, and Lead in International AI Diplomacy and Security. Additionally, the One Big Beautiful Bill Act, signed July 4, 2025, includes over $1 billion in AI-related defense and national security appropriations, though a proposed 10-year moratorium on state AI regulation was stripped from the final law.
Since the Plan’s release, the administration has continued implementation through additional executive orders: the “Genesis Mission” (November 24, 2025), establishing a Manhattan Project-scale national effort to use AI to accelerate scientific discovery through DOE’s national laboratories; “Ensuring a National Policy Framework for Artificial Intelligence” (December 11, 2025), asserting federal authority to challenge state AI laws that create a regulatory patchwork; and “Promoting Advanced Artificial Intelligence Innovation and Security” (June 2, 2026), creating a voluntary framework for federal pre-release review of frontier AI models and directing AI-powered cybersecurity defense across government. On June 5, 2026, the President signed NSPM-11, directing the national security enterprise to accelerate AI adoption and directing updates to autonomous weapons policy.
Beyond executive orders, the White House released legislative recommendations in March 2026 for a national AI policy framework, proposing that Congress enact broad federal preemption of state AI laws while protecting children, preventing censorship, and respecting copyrights. On June 4, 2026, Reps. Jay Obernolte (R-CA) and Lori Trahan (D-MA) released a bipartisan discussion draft of the Great American Artificial Intelligence Act of 2026. It is designed to establish a comprehensive federal framework for AI governance, prioritizing frontier model transparency, workforce protections, cybersecurity, and research. The proposed legislation is still in its discussion draft phase, and gathering feedback from industry experts, civil society, and the public before being formally introduced into the House. As of June 2026, Congress has not enacted comprehensive federal AI legislation, and state AI laws remain in effect.
-
Has your jurisdiction adopted any AI-specific laws, regulations, voluntary standards, or ethical guidelines? If so, please provide a brief overview. If not, which existing laws could be/are applied to artificial intelligence and the use of artificial intelligence, what are the main interpretive challenges, and are there any pending artificial intelligence legislative initiatives?
As of June 2026, the United States has adopted several AI-specific measures, including executive orders and initiatives aimed at both regulating and promoting artificial intelligence. The relevant executive orders include: (1) Executive Order 14277 (Apr. 23, 2025), titled “Advancing Artificial Intelligence Education for American Youth,” which establishes a White House Task Force on Artificial Intelligence Education to promote AI literacy and proficiency among Americans; (2) Executive Order 14319 (July 23, 2025), titled “Preventing Woke AI in the Federal Government,” which directs federal AI procurement and use policy around “truth-seeking” and “ideological neutrality” principles; (3) Executive Order 14365 (Dec. 11, 2025), titled “Ensuring a National Policy Framework for Artificial Intelligence,” which seeks a minimally burdensome and unified federal AI policy and directs agencies to examine or challenge state AI laws viewed as obstructive; and (4) Executive Order 14409 (June 2, 2026), titled “Promoting Advanced Artificial Intelligence Innovation and Security,” which creates a national security-oriented framework for advanced AI. It is important to note that executive orders do not themselves preempt state law, as preemption ordinarily requires congressional action. These orders serve as a litigation and funding pressure campaign the ultimate legal force of which is unresolved.
The Tools to Address Known Exploitation by Immobilizing Technological Deepfakes on Websites and Networks Act (or TAKE IT DOWN Act) is a federal law that was signed into effect on May 19, 2025. It criminalizes the knowing publication of an “intimate visual depiction” or “digital forgery” (including AI deepfakes) of an identifiable individual and requires covered platforms to implement notice and removal procedures for such intimate imagery, including removing reported content and known identical copies within 48 hours of a valid request. The Act’s criminal prohibitions took effect immediately upon enactment, while covered platforms were given one year — until May 19, 2026 — to establish the required notice-and-removal process. The U.S. Federal Trade Commission, which enforces the platform obligations in Section 3 of the Act as unfair or deceptive acts or practices, began this enforcement work on May 19, 2026. Moreover, the Nurture Originals, Foster Art, and Keep Entertainment Safe Act (or NO FAKES Act) was formally introduced to the U.S. Congress in July 2024, and a revised version of the proposed Act was reintroduced in April 2025. The bill is intended to protect the voice and visual likeness of individuals from unauthorized computer-generated recreations using generative AI and other technologies. In short, it addresses the use of nonconsensual digital replications in certain audiovisual works, images, and sound recordings. As of June 2026, the bill has been referred to the U.S. Senate Committee on the Judiciary but has not been passed by Congress or signed into law. A further iteration, the NO FAKES Act of 2026 (H.R. 8915), has been introduced in the House, but it likewise remains pending.
-
Are there legal requirements for artificial intelligence transparency, explainability, or audits? Are there obligations to disclose the use of artificial intelligence to customers/clients?
There are limited federal requirements relating to transparency, explainability, or audits that are binding on private parties at this time.
The National AI Initiative Act (15 U.S.C. § 9401 et seq.) establishes federal AI research and coordination priorities, including directing the National Institute of Standards and Technology (NIST) to develop common definitions for trustworthiness characteristics — including explainability, transparency, interpretability, and related properties of AI systems — but the resulting NIST AI Risk Management Framework (AI RMF 1.0) is voluntary guidance for the private sector and not a binding legal obligation.
The Biden administration issued Executive Order 14110 (October 30, 2023), titled “Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence,” that addressed some of these issues, but it was rescinded by the Trump administration on January 20, 2025.
The U.S. Congress passed the Tools to Address Known Exploitation by Immobilizing Technological Deepfakes on Websites and Networks Act (or TAKE IT DOWN Act), which was signed into law on May 19, 2025. It concerns non-consensual intimate imagery (sometimes called “revenge porn”) posted to online sites and social media applications and includes provisions relating to so-called deepfake pornography that may be created using AI tools. However, the Act does not specifically concern transparency, explainability, or audits.
The U.S. Federal Trade Commission announced Operation AI Comply in 2024, a cross-agency initiative to ensure that AI products and marketing claims comply with existing consumer-protection, fair-credit, and truth-in-advertising laws. The FTC stated that companies deploying AI systems must “keep their AI claims in check” and warned that false or misleading representations about AI capabilities would be subject to enforcement under the FTC Act. This, however, is not a new or AI-specific law so much as a reminder to the business community that unfair trade practices enforcement will include a review of practices that involve the use of AI tools.
The Trump administration issued Executive Order 14365 (December 11, 2025), titled “Ensuring a National Policy Framework for Artificial Intelligence,” that purports to curtail state-level AI laws. Its enforceability will be challenged through the courts, including in a case filed by X.AI LLC in Colorado in which the U.S. government has sought to intervene.
Several states are considering and/or have implemented requirements. For example, on July 6, 2026, Illinois enacted the Artificial Intelligence Safety Measures Act (SB 315), which is the first U.S. state law requiring third-party audits for large, frontier AI developers. There is still some uncertainty as to how the law will be implemented, and lawmakers are expected to make clarifying revisions before the law takes effect on January 1, 2027. California, Hawaii, and New York, for example, have enacted “synthetic performer” laws that require public disclosure when a digitally created performer is used in commercial advertising. See, e.g., N.Y. Gen. Bus. Law § 396-b. California has also enacted the California AI Transparency Act (SB 942, as amended by AB 853), which includes requirements for latent and manifest disclosures in AI-generated content and creates obligations for large online platforms, generative AI system-hosting platforms, and capture device manufacturers. (A “capture device” is one that records images, video, and/or audio.) Colorado enacted the Colorado AI Act in 2024, which included transparency obligations, but it was repealed in 2026 and replaced with a new law that focused disclosure obligations only on certain topics, like decision-making relating to employment and housing. As a practical matter, companies that do business throughout the U.S. will need to consider and possibly take into account all of these developing laws.
-
Are there legal requirements or best practice expectations for human oversight and human-in-the-loop in artificial intelligence systems?
There are no federal legal requirements for human oversight or humans-in-the-loop in artificial intelligence systems at this time. However, businesses may not shift blame to AI or other computerized systems for decisions made by such systems. A hiring decision, for example, that was made by an AI system based on impermissible considerations (such as race or gender) will be as actionable as such a decision made by a human. Some states are working on legislation that will mandate human oversight. California, for example, is considering a law called “Critical infrastructure: artificial intelligence systems: human oversight” (SB 833) that would mandate human oversight of AI in critical infrastructure. It passed the California Senate but remains pending in the Assembly. As a result, it can probably be said that it is a best practice to have human involvement and oversight in many contexts.
-
Are there specific legal or regulatory requirements addressing algorithmic bias, discrimination, or fairness in AI systems (including gender bias)?
Several U.S. government agencies (the Consumer Financial Protection Bureau, the Civil Rights Division of the Department of Justice, the Equal Employment Opportunity Commission, and the Federal Trade Commission) issued a joint statement in 2023 that they viewed algorithmic bias or discrimination as actionable under existing laws. They have each issued reports regarding these issues, and while federal enforcement in this space may be less active at present, several states are also working on laws that may may impose specific requirements.
-
What legal frameworks apply to AI-related harm and defective artificial intelligence systems? Who can be held liable (developer, deployer, victim of the damage, others), how is liability allocated, and what burden of proof applies to victims?
It is unclear as of June 2026 how liability will be allocated between and among various parties. Although numerous class actions have been filed against companies building large language models and AI-related products, few if any have progressed to a point where courts have provided substantive guidance on the allocation of liability for harm caused by an AI system. However, the first wave of substantive AI rulings issued in Bartz v. Anthropic, 791 F. Supp. 3d 1038 (N.D. Cal. 2025), and Kadrey v. Meta Platforms, Inc., 788 F. Supp. 3d 1026 (N.D. Cal. 2025), provides important guidance regarding the potential exposure of model developers. In Bartz, Judge William Alsup held on summary judgment that Anthropic’s use of lawfully acquired copyrighted books to train its large language models was protected by fair use because the training use was “exceedingly transformative,” while separately holding that Anthropic’s acquisition and retention of millions of pirated books was not protected by fair use and gives rise to damages liability. In Kadrey, the court likewise concluded that Meta’s use of copyrighted books to train its AI Llama models was “highly transformative” and granted summary judgment against the plaintiffs on their copyright claims. These summary judgment rulings address a developer’s direct fair use defense and therefore provide guidance regarding potential copyright exposure for AI model developers. They do not, however, resolve the question of how liability should be allocated among the developer, deployer, user, and victim. That question remains largely unsettled under U.S. law. These cases, of course, concern copyright law, and there will undoubtedly be cases relating to defects and to non-copyright harms caused by AI systems, including AI agents.
A current test case involving AI agents is Amazon.com Services LLC v. Perplexity AI, Inc., No. 3:25-cv-09514 (N.D. Cal.), in which Amazon alleges that Perplexity’s Comet shopping agent accessed password-protected Amazon account areas without Amazon’s authorization (despite user permission to do so); the district court granted Amazon a preliminary injunction; the Ninth Circuit stayed the injunction pending appeal; and after June 11, 2026 oral argument, the case remains unresolved, underscoring that the law is unclear whether a platform user may instruct an AI agent (such as a shopping agent) to act on its behalf when the platform itself denies authorization under computer-access laws.
There is no indication yet that the burden of proof in cases arising from or related to the use of AI systems will be different from the burden of proof in other cases brought under the same substantive laws. Criminal prosecutions will always require proof of guilt beyond a reasonable doubt. Civil liability will usually follow where a preponderance of the evidence (i.e. proof that a thing is more likely than not) indicates the defendant performed or was responsible for the actions giving rise to liability. There are some frameworks in U.S. jurisprudence where liability may be premised upon “strict liability,” where liability follows from the mere fact of performing the act that caused the harm (even in the absence of fault or criminal intent). There are no statutes or cases yet that have applied strict liability in relation to the use of AI systems. Even in the absence of new statutes that impose strict liability in relation to AI systems, it is foreseeable that courts may apply strict liability to AI-related cases where that is the standard applied by the underlying substantive law (e.g. certain construction and products liability cases).
-
What cybersecurity obligations apply to AI systems?
There is no single federal statute in the U.S. that comprehensively governs AI cybersecurity. Obligations arise from a layered patchwork of executive actions, existing agency authority, and accelerating state legislation.
Federal Executive Action
Executive Order 14409 (June 2, 2026), titled “Promoting Advanced Artificial Intelligence Innovation and Security,” directs the Cybersecurity and Infrastructure Security Agency to release Binding Operational Directives enhancing cyber defense of federal systems, establishes a voluntary framework for “covered frontier model” security assessments with AI developers, and creates an AI cybersecurity clearinghouse coordinating vulnerability scanning and patching across government and critical infrastructure. The EO expressly disclaims any mandatory licensing or preclearance requirement for AI models, though the Trump administration’s June 2026 actions to restrict access to Anthropic’s Mythos and Fable models, as well as OpenAI’s ChatGPT-5.6 model, have raised questions about whether the preclearance security assessments envisioned in the EO are truly “voluntary.” This is a rapidly evolving area of U.S. law and policy.
The National Institute of Standards and Technology issued a draft Cyber AI Profile (IR 8596, December 2025) and an AI Risk Management Framework (AI RMF 1.0) that provide voluntary but influential guidance on securing AI system components. Several state laws reference these as safe harbors.
FTC Enforcement
The U.S. Federal Trade Commission applies its existing authority under 15 U.S.C. § 45 (commonly called FTC Act § 5) to regulate unfair or deceptive acts and practices in relation to AI data security. Its Biometric Information Policy Statement (May 18, 2023) extends data-security expectations to AI-powered biometric technologies, and the ongoing commercial surveillance rulemaking may yield binding data-security rules applicable to AI systems.
State Laws
Colorado’s original AI act, “Consumer Protections for Artificial Intelligence” (SB 24-205, May 17, 2024), which required risk-management programs referencing the NIST AI RMF, has been repealed and replaced by “Automated Decision-Making Technology” (SB 26-189, May 14, 2026). The new act is effective January 1, 2027 and narrows the scope of the original, removing mandatory impact assessments and explicitly carving out cybersecurity technologies. Texas has enacted a law called the “Texas Responsible Artificial Intelligence Governance Act” (often called TRAIGA) (HB 149, June 22, 2025), that became effective January 1, 2026 and provides a safe harbor for organizations aligned with the NIST AI Risk Management Framework. New York enacted a law called the “Responsible AI Safety and Education Act” (often called the RAISE Act) (S6953B/A6453B, Dec. 19, 2025) that will become effective January 1, 2027 and requires frontier AI developers to implement “safety and security protocols” with cybersecurity protections and 72-hour incident reporting. California is considering a law called “Critical infrastructure: artificial intelligence systems: human oversight” (SB 833) that would mandate human oversight of AI in critical infrastructure. It passed the California Senate but remains pending in the Assembly.
Organizations deploying AI in the U.S. should consider aligning with the NIST AI RMF as the emerging de facto standard, should continue to monitor state-specific requirements, and maintain robust incident response capabilities. The regulatory landscape remains fragmented, with federal preemption of state AI laws still unresolved.
-
Is the use of artificial intelligence insured and/or insurable in your jurisdiction, including with cyber policies? Are there market trends, or limitations?
Insurance in the United States is primarily state-regulated, under the framework established by the McCarran-Ferguson Act, 15 U.S.C. §§ 1011–1015, which generally reserves insurance regulation to the states. There is no federal statute specifically governing AI insurance coverage or mandating AI-specific policies. Risks arising from AI use may be covered under some policies.
Effective January 1, 2026, the Insurance Services Office, a private advisory and rating organization for the property/casualty insurance industry, introduced three endorsements for commercial general liability (CGL) policies, each excluding claims “arising out of” generative artificial intelligence (which it defines as “a machine-based learning system or model that is trained on data with the ability to create content or responses, including but not limited to text, images, audio, video or code”). The three endorsements are:
i. CG 40 47: The broadest, excluding both Coverage A (bodily injury and property damage) and Coverage B (personal and advertising injury)
ii. CG 40 48: Narrower, excluding only Coverage B (personal and advertising injury) and
iii. CG 35 08: Applying exclusively to the products/completed operations liability coverage part, excluding bodily injury and property damage
Some carriers have introduced purported “absolute” AI exclusions in D&O, E&O, and fiduciary liability policies, barring coverage for claims “based upon, arising out of, or attributable to” any actual or alleged use, deployment, or development of artificial intelligence, using a definition broad enough to encompass any machine-based system that infers how to generate outputs from input data. Other carriers have introduced more limited exclusions. There is a clear trend toward excluding these risks.
-
Can artificial intelligence be named as an inventor in a patent application filed in your jurisdiction? If not, what is the current legal position?
No, not at present. Both the U.S. Patent and Trademark Office and the courts have required that an inventor be a “natural person,” which excludes AI systems. Thaler v. Vidal, 43 F.4th 1207 (Fed. Cir. 2022). Use of an AI system by a natural person does not preclude patentability so long as a natural person contributed to the conception of the claimed invention. The USPTO issued Revised Inventorship Guidance for AI-Assisted Inventions (Docket No. PTO-P-2025-0014, Nov. 28, 2025), rescinding its prior guidance on this topic (89 Fed. Reg. 10043, Feb. 13, 2024). The guidance reaffirms the principle that only natural persons can be inventors under U.S. patent law. Additionally, it emphasizes that AI is to be treated as a tool; the traditional “conception” standard applies without AI-specific modifications; and the joint-inventorship factors set forth in Pannu v. Iolab Corp., 155 F.3d 1344 (Fed. Cir. 1998), are reserved for inventions involving multiple human inventors. This issue may not be finally decided, however, until it reaches the U.S. Supreme Court and/or U.S. Congress.
-
Do images or works generated by and/or with artificial intelligence benefit from copyright protection in your jurisdiction? If so, who is the authorship attributed to, and under what conditions?
No, not at present. Both the U.S. Copyright Office and the courts have agreed that an author must be a “natural person,” which excludes AI systems from being identified as authors. Thaler v. Perlmutter, 130 F.4th 1039 (D.C. Cir. Mar. 2025), cert. denied, 146 S. Ct. 1290 (2026). However, while AI systems cannot be identified as authors, the Copyright Office issued guidance in March 2023 indicating that use of such systems by natural persons does not preclude the possibility of those natural persons securing copyright protection, so long as the natural persons have contributed original subject matter to the work. In other words, AI-generated images can benefit from copyright protection only to the extent that a human contributes original, creative input to the work. Fully autonomous AI-created content is not protected under this standard. Authorship is attributed to the human who exercises creative control, whether through extensive prompt engineering, curation, selection, arrangement, or post-processing.
-
What are the main issues to consider when using artificial intelligence systems in the workplace? Have any new regulations, or guidelines, been introduced regarding AI-driven hiring, performance assessment, or employee monitoring?
There are many issues to consider when integrating AI systems into the workplace. While these issues span a range of areas, the following are some key ethical and legal considerations:
- Bias and Fairness: AI systems can perpetuate and amplify biases present in training data, leading to unfair treatment of employees or applicants. It is crucial to ensure that AI algorithms are developed and trained on diverse and representative data sets.
- Transparency and Explainability: Employees and stakeholders should understand how AI systems make decisions, especially in critical areas like hiring, performance evaluations, and promotions. AI systems should be explainable and transparent.
- Privacy and Data Protection: The use of AI systems often involves collecting and processing large amounts of data. It is essential to ensure compliance with data protection laws and regulations such as the General Data Protection Regulation in the European Union and the California Consumer Privacy Act and other similar laws in the U.S. These laws govern how personal data is collected and processed.
- Employment Laws: AI systems must comply with existing employment laws and regulations, such as non-discrimination laws and labor standards.
- Intellectual Property: Companies must consider the infringement exposure that may follow, in relation to both the technical operation of an AI system and a system’s outputs. Companies ought also to consider the protectability of their own inventions and works (and those of its contractors, service providers, and vendors).
The U.S. Equal Employment Opportunity Commission removed from its website “List of EEOC Disability-Related Technical Assistance Documents,” a 2023 Title VII AI technical-assistance document, and a 2022 ADA AI guidance document, and on June 4, 2025, it rescinded its 2024-2028 Strategic Enforcement Plan. The U.S. Department of Justice issued a rule in December 2025 eliminating Title VI disparate-impact provisions. However, the underlying statutes did not change. Title VII’s disparate impact theory and the Uniform Guidelines on Employee Selection Procedures validation expectations still apply to AI-driven selection tools regardless of whether the agencies publish guidance. And several states (including California, Colorado, Illinois, and New York) are actively filling the federal guidance vacuum. The practical risk has migrated but has not disappeared.
-
What are the main privacy/data protection issues arising from artificial intelligence development and use (including training data)? Have data protection authorities issued guidelines or rulings on artificial intelligence, and what are the key takeaways?
The U.S. has in place a range of guidelines and principles on artificial intelligence, but most applicable laws are not specific to artificial intelligence technologies. Agencies with AI-specific or AI-related guidelines are currently reevaluating these regulations based on a recent Office of Management and Budget memo outlining government rules for the use of AI. “Accelerating Federal Use of AI through Innovation, Governance, and Public Trust” (OMB Memorandum M-25-21, Apr. 3, 2025).
Prior to the current administration, several federal agencies had already issued AI-related guidelines. Many guidelines and rules released prior to 2025 are being reviewed under the new administration’s priorities.
- U.S. National Institute of Standards and Technology: NIST released its “AI Risk Management Framework” in January 2023, providing voluntary guidance to organizations on managing risks associated with AI systems. More recently, the Center for AI Standards and Innovation has focused on security and national security risks in both American and non-American AI systems.
- White House: The White House secured voluntary security commitments in 2023 from AI companies developing frontier models to ensure the safe, secure, and trustworthy development of AI systems by focusing on ensuring the safety of those systems, protecting against cybersecurity threats to AI, and developing watermarking systems to help detect AI-generated content. The commitments were part of the Biden administration’s initiative to “seize the tremendous promise and manage the risks” of AI, a novel technology with broad ramifications.
- U.S. Food and Drug Administration: The FDA published its “Artificial Intelligence and Machine Learning Software as a Medical Device Action Plan” in January 2021, which outlines the FDA’s approach to regulating adaptive AI and machine learning in medical devices as part of existing premarket submission processes. The approach emphasizes a “total product life cycle” regulatory approach, which includes clear expectations for quality systems and “good machine learning practices,” and focuses on the importance of real-world performance monitoring.
- U.S. Copyright Office: Since launching an initiative in early 2023, the Copyright Office has been examining the copyright law and policy issues raised by AI. The Copyright Office has been publishing its findings in a multi-part report, Copyright and Artificial Intelligence. Part 1 was published on July 31, 2024 and addresses the topic of digital replicas. Part 2 was published on January 29, 2025 and addresses the copyrightability of outputs created using generative AI. On May 9, 2025, the Office released a pre-publication version of Part 3 in response to Congressional inquiries and expressions of interest from stakeholders. The day after Part 3 was released, the Register of Copyrights, Shira Perlmutter, was removed by the Trump administration; she sued, and a panel of the Court of Appeals for the District of Columbia Circuit found her likely to prevail in her litigation. She was effectively reinstated and testified before the IP Subcommittee of the U.S. Senate Committee on the Judiciary in May 2026. Part 3 remains in pre-publication form as of June 2026, and a final version of Part 3 is expected to be published in the future without any substantive changes in the analysis or conclusions.
- U.S. Federal Trade Commission: The FTC has published guidance on using AI and algorithms fairly, emphasizing transparency, explainability, and accountability. More recently, it has undertaken a number of enforcement actions against deceptive claims related to AI.
- State Regulations: States such as California, Colorado, Illinois, New York, Tennessee, Texas, and Utah have implemented their own AI-related laws. For example, California enacted the “Transparency in Frontier Artificial Intelligence Act” (SB 53, Sept. 29, 2025), effective January 1, 2026, imposing risk-management and transparency obligations on large frontier model developers, and it finalized employment and automated decision-making regulations through its Civil Rights Council and Privacy Protection Agency (effective in late 2025). Colorado’s pioneering act, “Consumer Protections for Artificial Intelligence” (SB 24-205, May 17, 2024), was delayed and then repealed and replaced before ever taking effect: SB 25B-004 pushed the effective date to June 30, 2026, and a May 14, 2026 amendment (SB 26-189) scaled the law back to an automated decision-making transparency regime. Illinois amended the Illinois Human Rights Act (by means of HB 3773) to reach discriminatory employer use of AI, effective January 1, 2026. New York enacted a law called the “Responsible AI Safety and Education Act” (often called the RAISE Act) (S6953B/A6453B, Dec. 19, 2025) addressing frontier model safety, with a January 1, 2027 effective date. The “Texas Responsible Artificial Intelligence Governance Act” (often called TRAIGA) (HB 149, June 22, 2025) took effect January 1, 2026 and prohibits specified harmful or discriminatory AI uses and establishes that “the attorney general has authority to enforce” the Act but “may not institute an action for a civil penalty against a developer or deployer” for AI systems that are isolated from customer interaction “in a pre-deployment environment.” Monetary penalties are authorized “up to $100,000.” Earlier measures such as Tennessee’s “Ensuring Likeness, Voice, and Image Security Act” (often called the ELVIS Act) (HB 2091/SB 2096 Mar. 7, 2024) and Utah’s “Artificial Intelligence Policy Act” (SB 149, Mar. 13, 2024) established protections relating to name, image, likeness, and voice, which remain in force. These AI-specific laws supplement broader state consumer-privacy statutes that increasingly regulate profiling and automated decision-making. It is likely that additional states will follow. These AI-focused laws supplement state data protection laws that are broader in reach but may also impact AI, such as provisions related to automated decision-making.
Additionally, many relevant U.S. laws that are intended to be “technology neutral” and to apply to processes and outcomes (rather than to the methods used to achieve them) are likely to apply to business activities, without regard to whether AI is used. Some examples include:
- Financial: The Fair Credit Reporting Act and Fair and Accurate Credit Transactions Act, the Equal Credit Opportunity Act, the Dodd-Frank Wall Street Reform Act, and the Consumer Financial Protection Act impose well-established rules for eligibility decision-making, credit reporting, and eligibility explainability, all of which provide a lens through which to examine AI.
- Health: The U.S. Department of Health and Human Services regulates discriminatory outcomes under a number of laws, including the Civil Rights Act, the Rehabilitation Act, the Age Discrimination Act, and the Affordable Care Act.
- Insurance: Insurance is regulated primarily by states; however, anti-discrimination rules at the federal level came into force through the Civil Rights Act, and many states also have civil rights acts/laws.
- Housing: The Civil Rights Act and the Fair Housing Act both address discriminatory housing practices, including the use of background screening.
- Employment: The Equal Employment Opportunity Commission has rules that govern employment and hiring policies and practices and that prohibit discrimination throughout the hiring and employment life cycle. These rules are increasingly applied in relation to automated hiring and employment processes.
The U.S. Supreme Court issued a landmark decision in Loper Bright Enterprises v. Raimondo, 603 U.S. 369 (2024), that may greatly curtail the ability of federal government agencies to promulgate strategy and regulation relating to AI. It remains to be seen how Congress and agencies will respond to this development.
-
How is data scraping regulated in your jurisdiction from an IP, privacy and competition perspective? Are there recent precedents addressing the legality of data scraping for training of artificial intelligence systems?
There is no unified framework for regulation of data scraping in the U.S. However, several types of laws may apply. These include copyright, contract, and misappropriation law:
- Copyright. There is neither per se liability for copyright infringement nor a blanket “fair use” exception to copyright liability for copying and/or making derivative works of copyrightable works that are collected by means of data scraping. Operators of large language models are arguing in pending litigation in the U.S. that data scraping to train their models is a form of fair use. It will be some years before the courts reach a final determination of this issue under current copyright law, and it is possible the U.S. Congress will amend copyright law in the meantime or after such a final court determination. It bears mentioning that copyright law in the U.S. protects the expression of ideas, not ideas themselves or unarranged data. So, a threshold determination in a copyright claim brought in relation to data scraping is whether the scraped data is protectable under copyright in the first instance. Note that the Copyright Office recently addressed the issue of data scraping for AI training purposes in Part 3 of its Copyright and Artificial Intelligence report of May 9, 2025. This pre-publication report raised significant legal concerns surrounding some aspects of data scraping under current copyright law. Specifically, it highlights that unauthorized copying of copyrighted works, even if publicly accessible, may constitute infringement. The report advises caution and recommends that AI developers consider licensing agreements and other legal mechanisms to ensure compliance. Even more recently, two decisions have issued in cases evaluating the availability of a fair use defense to copyright infringement relating to the use of protected works to train large language models. Bartz v. Anthropic PBC, 791 F. Supp. 3d 1038 (N.D. Cal. 2025), and Kadrey v. Meta Platforms, Inc., 788 F. Supp. 3d 1026 (N.D. Cal. 2025). The decisions suggest that the defense may be available where the works used as training data were lawfully acquired, but it will be some time before the law settles in this area.
- Contract. Information made available pursuant to a contract is governed by the terms of the contract, and parties to a contract may agree that certain copying is not permitted, even if copyright law would otherwise allow it. There have been cases in the U.S. that found liability for data scraping on the basis of a trespass theory (specifically “trespass to chattels”). These cases generally have been premised on a website proprietor alerting visitors that scraping was prohibited and that that prohibition (coupled with proof of harm) made the scraping a trespass.
- Misappropriation. Some states in the U.S. have found liability for misappropriation of information, but this doctrine is quite limited because federal copyright law preempts inconsistent state laws. Put another way, the federal framework that authorizes or declines to authorize the “owner” or publisher of certain information to bring a copyright infringement claim is exclusive, and unless liability under state law includes an added element (beyond mere copying), the state law will not be permitted to prohibit what is authorized by federal copyright law.
- Computer Fraud and Abuse Act. Some website proprietors have argued over the years that data scraping is a violation of the 1986 federal Computer Fraud and Abuse Act, which provides for both criminal and civil liability, depending on the conduct and circumstances. In the present context, the Act generally prohibits actions that damage protected computers, that involve taking of certain financial information, and that involve committing fraud using a computer. Additional protections are available for government computers. Moreover, the holding in CDK Glob., LLC v. Tekion Corp., No. 25-cv-01394-JSC, 2025 U.S. Dist. LEXIS 134955 (N.D. Cal. July, 2025), indicates that CFAA liability may be upheld where the alleged scraping or data acquisition involves access to password-protected systems, the circumvention of technical access controls, or continued access after authorization has been revoked. Recent case law has significantly limited the applicability of the Act in cases of data scraping of private commercial websites on the open internet. It is currently unclear whether a cause of action under the Act remains for this conduct.
- Privacy. Depending on the nature of the information that is subject to scraping on the open internet, state consumer data privacy laws may apply.
- Competition. Competition law (known as antitrust law in the U.S.) does not have any particular applicability to data scraping. Acts that give rise to liability under antitrust law will do so regardless of the technical means involved to perform the acts.
-
To what extent is the prohibition of data scraping in the terms of use of a website enforceable?
The enforceability of website terms of use in the U.S. tracks general principles of contract law. A binding contract may be formed where terms are offered by one party and accepted by another party. The challenge in terms-of-use cases is that website visitors may be unaware of proposed contract terms and may not have accepted them, including whatever restrictions may be included in regard to data scraping. This challenge may be overcome by presenting contractual terms in a more prominent manner. For example, requiring a party to scroll through contractual terms and select an “I agree” checkbox will more likely result in an enforceable contract than terms of use under a link to “Legal Terms” in small text at the bottom of a web page. A prohibition on data scraping in an otherwise enforceable contract will be enforceable; it is not the case that such a prohibition would be prohibited by current law as, for example, contrary to public policy. Some websites use the Robots Exclusion Protocol by including the robots.txt filename on their sites. This is an electronic signal to web crawlers that they are not authorized to scrape a site. Compliance with the protocol is voluntary, and there is no enforcement mechanism. However, the operator of a web crawler that ignores this instruction may be on notice that data scraping is not authorized, and this may help support other legal claims, such as trespass to chattels (discussed above). The court in Bartz v. Anthropic PBC, 791 F. Supp. 3d 1038 (N.D. Cal. July 2025), held that training large language models using purchased copyrighted books is a fair use, while doing so with pirated books is not. This may lead parties to argue that using a licensed work in violation of license terms is not a fair use. It will take more time for case law to develop on this issue.
-
Does your country have a regulator or authority responsible for supervising the use and development of artificial intelligence? What are its powers and enforcement tools?
The U.S. does not have a single, dedicated regulator responsible for overseeing the use and development of artificial intelligence across all sectors. For now, the U.S. approach to AI governance remains largely sector-specific and decentralized, with various agencies adapting existing regulatory frameworks and pursuing new rules; the recently issued Office of Management and Budget Memorandum titled “Accelerating Federal Use of AI through Innovation, Governance, and Public Trust” (M-25-21, Apr. 3, 2025) directs agencies to adopt de-regulatory approaches for AI. For instance, the U.S. Federal Trade Commission has taken a leading role in addressing AI-related consumer protection and competition issues. The U.S. Equal Employment Opportunity Commission has begun to tackle AI’s impact on workplace discrimination. The U.S. Food and Drug Administration is developing frameworks for AI in medical devices, while the U.S. National Highway Traffic Safety Administration is addressing AI in autonomous vehicles. Additionally, the Center for AI Standards and Innovation at the National Institute of Standards and Technology has been tasked with developing guidelines and best practices to measure and improve the security of AI systems, which while not regulatory provides guidance for the development and protection of AI systems. Coordination of these efforts sits with the White House Office of Science and Technology Policy’s National AI Initiative Office and the Special Advisor for AI and Crypto, principally through “Winning the Race: America’s AI Action Plan” (July 23, 2025), none of which carries independent regulatory authority. The government’s posture under the Trump administration has tilted toward deregulation and enforcement discretion and has moved toward centralizing federal authority. Executive Order 14179 (Jan. 23, 2025), titled “Removing Barriers to American Leadership in Artificial Intelligence,” revoked the prior administration’s principal executive order relating to AI and directed agencies to remove barriers to AI adoption. OMB Memorandum M-25-21, noted above, directs agencies to accelerate their own adoption and use of AI while reducing bureaucratic burdens. Executive Order 14365 (Dec. 11, 2025), titled “Ensuring a National Policy Framework for Artificial Intelligence,” and the resulting U.S. Department of Justice AI Litigation Task Force — charged with challenging state AI laws viewed as inconsistent with the executive order’s policy — mark the clearest recent move toward centralizing federal authority, though the order seeks to create a national framework through litigation rather than creating a federal AI regulator.
-
How widespread is the adoption of artificial intelligence in businesses in your jurisdiction, and which sectors are leading?
The use of artificial intelligence by businesses in every industry within the U.S. is widespread and growing rapidly. Many business and legal software platforms, including email, word processing, and research services, have incorporated AI-enhanced functions into their products. Some of these functions include drafting short messages and editing/correcting text. It bears mentioning that the extent of use varies greatly, depending on the type of AI under consideration and the industry. The use of generative AI to create images, software, and completed documents may not be widespread yet across all industries, but use of autocorrect and voice-operated systems like Siri and Alexa, to the extent these are considered forms of AI, is pervasive. In contrast, many companies are embracing agentic AI and building AI agents that are autonomous programs capable of making decisions and interacting with their environment with minimal or no human intervention. Furthermore, several companies are actively researching and pursuing hypothetical advanced AI, such as artificial general intelligence.
-
How is artificial intelligence used in the legal sector, by lawyers and/or in-house counsels? Are AI-driven legal tools widely adopted, and what are the main regulatory concerns?
Lawyers in firms and at companies are exploring and making use of AI technologies in their practices. Many legal research and document and information management providers are integrating AI functions into their offerings. Many of these platforms have been cautiously trained on licensed or public domain information. After some well-publicized incidents of lawyers filing error-filed court papers created by ChatGPT, some lawyers are leery of adopting AI in their practices. Lawyers are also concerned about protection of confidentiality and attorney-client privilege and, as a result, may be slower to adopt these technologies than some other industries. That being said, even a casual observer of the legal field can see that AI tools are transforming the legal industry and impacting the way attorneys work, how back-office functions within law firms are managed, and the evidence and factors courts weigh in making decisions regarding AI. Here are some illustrative examples of how AI is being used in the legal sector:
- Due Diligence and Document Review: AI can quickly review vast amounts of data and documents, identify key points, and draw attention to relevant provisions. AI tools can process contracts and flag clauses responsive to diligence requests or disclosure requirements. This significantly reduces the time and effort needed for legal professionals to review documents.
- Legal Research and Predictive Analysis: Related to document review, AI can sift through many cases, regulations, and rules to identify relevant precedent and clauses. AI can also analyze prior decisions and judgments to predict possible outcomes of ongoing disputes to assist in devising legal strategy.
- Contract Generation: AI tools can be used to automate the creation of legal agreements based on set parameters or letters of intent, and they can flag non-standard clauses, check compliance with legal requirements, and highlight critical agreements that are due for renewal or require re-negotiation.
- Chatbots and Ideation: AI-powered chatbots can provide legal direction on simple matters, reducing the time lawyers need to spend on routine queries or producing general client communications.
- Administrative Matters: AI can automate administrative tasks such as billing and time-tracking, reducing errors and freeing up more time for legal professionals to produce higher-level, complex legal work.
Law firms and attorneys can be expected to adopt AI tools from commercial providers that are fine-tuned specifically for legal work. Even with the availability of “safer” AI tools, law firms and attorneys will still need to consider frameworks for ethical and responsible use of AI, training of individual attorneys, and careful review of outputs for relevancy, accuracy, truthfulness, and completeness. This is especially true, given that sanctions for AI-hallucinated citations in documents filed in courts have continued and broadened in the past year. For instance, in Noland v. Land of the Free, L.P., 336 Cal. Rptr. 3d 897 (Cal. Ct. App. 2025), the court sanctioned appellant’s counsel $10,000 for filing appellate briefs “replete” with fabricated quotations and citations generated by AI tools.
-
What are the 5 key challenges and the 5 key opportunities raised by artificial intelligence for lawyers in your jurisdiction?
Challenges
- Learning about and training on the many types of specialized AI systems that are available and being used by clients and other lawyers. This implicates legal ethics and even malpractice issues relating to competence, confidentiality, and other duties.
- Understanding the operational details of AI systems, including the corpus of original training data used in an AI system, how the training data is processed and used, whether prompts are used for further training, and whether and how confidentiality is preserved.
- Tracking the many laws promulgated by legislators and courts and case law at the federal and state levels (not to mention internationally) that are relevant to advising clients and to guiding lawyers’ own practices.
- Avoiding unintentional bias and lack of transparency by use of AI systems that may lead to unfair or discriminatory outcomes.
- Balancing cost and time with risk and benefit while keeping pace with peers and properly serving clients.
Opportunities
- There is great client demand for counseling, negotiation, and in some cases litigation related to AI issues, and this can be expected to continue for some years.
- AI tools will provide a wide variety of efficiencies in lawyers’ own practices, including review and drafting of documents, analysis of large collections of documents (e.g. in discovery in litigation), and evaluation of potential case outcomes. These efficiencies should enable lawyers to spend more time on strategic thinking and to handle a greater number of matters.
- AI tools may raise both the floor and the ceiling in terms of the quality of legal services lawyers are able to provide.
- AI tools may reduce the cost of some types of legal services, making legal counsel available to people who could not previously afford it.
- AI tools may help drive lawyer and client satisfaction, as certain routine tasks are automated and more time is available for attorneys to focus on “higher-level” tasks.
-
Where do you see the most significant legal developments in artificial intelligence in your jurisdiction in the next 12 months? Are there any ongoing initiatives that could reshape AI governance?
The most significant legal developments in the next 12 months are likely to come in the form of legal regulation, whether by executive orders, agency action, or legislation. Litigation is slow-moving, and the principles established in pending cases will not gel until appeals are exhausted, different states and circuits have their say, and (potentially) the U.S. Supreme Court weighs in on major issues. It can be expected that these rulings will address a wide range of topics, including intellectual property law, privacy, consumer protection, public safety, antidiscrimination, and employment practices.
United States: Artificial Intelligence
This country-specific Q&A provides an overview of Artificial Intelligence laws and regulations applicable in United States.
-
What is the legal definition of “artificial intelligence” in your jurisdiction, if any? If no definition exists, how do regulators or courts typically describe artificial intelligence?
-
Has your country developed a national strategy for artificial intelligence? If yes, what progress has been made in its implementation? Are there plans for updates or revisions?
-
Has your jurisdiction adopted any AI-specific laws, regulations, voluntary standards, or ethical guidelines? If so, please provide a brief overview. If not, which existing laws could be/are applied to artificial intelligence and the use of artificial intelligence, what are the main interpretive challenges, and are there any pending artificial intelligence legislative initiatives?
-
Are there legal requirements for artificial intelligence transparency, explainability, or audits? Are there obligations to disclose the use of artificial intelligence to customers/clients?
-
Are there legal requirements or best practice expectations for human oversight and human-in-the-loop in artificial intelligence systems?
-
Are there specific legal or regulatory requirements addressing algorithmic bias, discrimination, or fairness in AI systems (including gender bias)?
-
What legal frameworks apply to AI-related harm and defective artificial intelligence systems? Who can be held liable (developer, deployer, victim of the damage, others), how is liability allocated, and what burden of proof applies to victims?
-
What cybersecurity obligations apply to AI systems?
-
Is the use of artificial intelligence insured and/or insurable in your jurisdiction, including with cyber policies? Are there market trends, or limitations?
-
Can artificial intelligence be named as an inventor in a patent application filed in your jurisdiction? If not, what is the current legal position?
-
Do images or works generated by and/or with artificial intelligence benefit from copyright protection in your jurisdiction? If so, who is the authorship attributed to, and under what conditions?
-
What are the main issues to consider when using artificial intelligence systems in the workplace? Have any new regulations, or guidelines, been introduced regarding AI-driven hiring, performance assessment, or employee monitoring?
-
What are the main privacy/data protection issues arising from artificial intelligence development and use (including training data)? Have data protection authorities issued guidelines or rulings on artificial intelligence, and what are the key takeaways?
-
How is data scraping regulated in your jurisdiction from an IP, privacy and competition perspective? Are there recent precedents addressing the legality of data scraping for training of artificial intelligence systems?
-
To what extent is the prohibition of data scraping in the terms of use of a website enforceable?
-
Does your country have a regulator or authority responsible for supervising the use and development of artificial intelligence? What are its powers and enforcement tools?
-
How widespread is the adoption of artificial intelligence in businesses in your jurisdiction, and which sectors are leading?
-
How is artificial intelligence used in the legal sector, by lawyers and/or in-house counsels? Are AI-driven legal tools widely adopted, and what are the main regulatory concerns?
-
What are the 5 key challenges and the 5 key opportunities raised by artificial intelligence for lawyers in your jurisdiction?
-
Where do you see the most significant legal developments in artificial intelligence in your jurisdiction in the next 12 months? Are there any ongoing initiatives that could reshape AI governance?