Regulation · United States

The US does not have an AI Act. It has regulators.

There is no federal AI law. There is NIST's voluntary framework. There is a Colorado statute already rewritten twice. There are five sector regulators, an FTC, and an EU law reaching into firms with no office in Europe.

Ask a US chief risk officer to name the AI Act. There is no single answer, because there is no single act.

Europe wrote one law and gave it one clock. The United States built something else: a voluntary technical framework, a state statute already rewritten twice under political pressure, five sector regulators running independent programs, a federal trade regulator that treats an AI claim like any other claim, and a European law that reaches into firms that never opened an office in Brussels. None of these bodies coordinates with the others. Each expects to be satisfied on its own terms, on its own calendar.

A European compliance officer reads one statute, enforced by a single AI Office and the member state authorities beneath it, on one published calendar. A US counterpart reads eight, several of them capable of changing the deadline after the fact.

NIST is the reference framework, and no one has to follow it

The National Institute of Standards and Technology released the Artificial Intelligence Risk Management Framework, AI RMF 1.0, on January 26, 2023. It organizes AI risk work into four functions: govern, map, measure, manage (NIST, AI RMF 1.0). It is the closest thing US enterprises have to a common vocabulary for AI risk, and examiners, auditors, and vendor questionnaires now cite it by name.

It is also explicitly voluntary. NIST states the framework is "intended for voluntary use" (NIST, AI Risk Management Framework page). Nothing compels a bank, an insurer, or a hospital system to adopt it, and the framework carries no penalty of its own for skipping a function. NIST extended it on July 26, 2024, with a Generative AI Profile, NIST-AI-600-1, built specifically for large language model risks (NIST, AI Risk Management Framework page).

The reference document is not settled, either. America's AI Action Plan, released by the White House on July 23, 2025, directs the Department of Commerce to revise the AI RMF and strip references to misinformation, diversity, equity and inclusion, and climate change (The White House, Winning the Race: America's AI Action Plan). A framework enterprises cite in board decks and vendor contracts is being edited under a policy mandate while those citations sit in force. Build a governance program around this year's wording, and the wording under it can move again before the next audit cycle closes.

Colorado tried to write the AI Act, and Washington is suing to stop it

Colorado came closest to a broad state AI statute. Governor Jared Polis signed SB24-205, Consumer Protections for Artificial Intelligence, on May 17, 2024. It required developers and deployers of high-risk AI systems to use reasonable care against algorithmic discrimination, with disclosures, impact assessments, and a consumer right to appeal (Colorado General Assembly, SB24-205). The law was set to take effect February 1, 2026.

It never reached that date intact. After a special legislative session failed to produce a compromise, Polis signed SB25B-004 on August 28, 2025, pushing the requirements to June 30, 2026 (Colorado General Assembly, SB25B-004). On April 27, 2026, a federal court paused enforcement entirely: the Colorado Attorney General, the plaintiffs, and the US Department of Justice jointly asked the court to stay the case, and the Attorney General committed not to enforce SB24-205 "or any legislation replacing or amending" it until a rulemaking process concludes (Troutman Pepper, April 2026). Then, on May 14, 2026, Polis signed SB26-189, which repeals SB24-205 outright and replaces it with a narrower framework built around "automated decision-making technology," with developer documentation obligations beginning January 1, 2027 (Colorado General Assembly, SB26-189).

Two years, one governor, three bills, and the state's flagship AI statute has still never taken effect as originally written. Washington moved in the opposite direction at the same time. On December 11, 2025, the White House issued Executive Order 14365, Ensuring a National Policy Framework for Artificial Intelligence, directing the Attorney General to stand up an AI Litigation Task Force within 30 days to challenge state AI laws as unconstitutional burdens on interstate commerce or as preempted by federal authority. The same order directs the FTC and the FCC to develop federal standards meant to preempt state requirements, and it puts federal grant and broadband funding on the table against states that keep AI laws the administration considers "onerous" (The White House, Executive Order 14365).

A statute rewritten three times before its own effective date arrived is not a compliance delay. It is proof the target moves. Hikari Blue · operator note

Banking, insurance, and healthcare never waited for a statute

Financial regulators did not wait for Congress or Colorado. The Office of the Comptroller of the Currency, the Federal Reserve, and the FDIC jointly issued Interagency Guidance on Third-Party Relationships: Risk Management on June 6, 2023, requiring banks to manage AI vendors under the same lifecycle discipline as any other outsourced service, from due diligence through termination. The guidance replaced two earlier OCC bulletins from 2013 and 2020, neither of which anticipated the technology it now governs (OCC Bulletin 2023-17). FINRA followed on June 27, 2024, with Regulatory Notice 24-09, reminding broker-dealers that its rules are technology neutral and apply in full to generative AI and large language models, including supervision under Rule 3110 and communications standards under Rule 2210 (FINRA, Regulatory Notice 24-09). Neither document references the other. Both apply at once to a bank that also runs a broker-dealer arm.

Insurers answer to a third body. The National Association of Insurance Commissioners adopted its Model Bulletin on the Use of Artificial Intelligence Systems by Insurers in December 2023, requiring a written governance program, an "AIS Program," covering underwriting, rating, claims, fraud detection, marketing, and customer service across the full AI lifecycle (NAIC, Model Bulletin). More than twenty states and the District of Columbia had adopted the bulletin by mid-2026, each through its own insurance department, each free to vary the wording.

Health systems answer to a fourth and a fifth. HHS, through its Office of the National Coordinator for Health IT, finalized the HTI-1 rule, published in the Federal Register on January 8, 2024: the first federal requirement for algorithm transparency inside certified health IT decision support tools (HealthIT.gov, HTI-1 Final Rule). The FDA runs a parallel track for AI inside medical devices, with a final guidance on Predetermined Change Control Plans in December 2024 and a draft guidance on lifecycle management for AI-enabled device software published January 6, 2025 (Federal Register, Docket FDA-2024-D-4488). A hospital deploying a diagnostic model answers to ONC for the software and to the FDA for the device, on two different clocks, inside two different agencies of the same department.

Build one AI governance program to satisfy five regulators, and it will not survive contact with any of them. An agentic underwriting or claims workflow falls inside the NAIC bulletin's full lifecycle whether or not the carrier calls it artificial intelligence in its own documentation.

The FTC treats an AI claim like any other claim, which is the point

The Federal Trade Commission does not run an AI program. It runs Section 5 of the FTC Act, the prohibition on unfair or deceptive practices, and it has made clear that AI products get no exemption. On September 25, 2024, the FTC announced Operation AI Comply, five enforcement actions against companies that used AI hype to mislead consumers, including a $193,000 settlement over a service marketed as a "robot lawyer" (FTC, FTC Announces Crackdown on Deceptive AI Claims and Schemes). No new AI-specific rule was needed. An ordinary claim against an ordinary lie did the work.

On July 7, 2026, the FTC published a proposed policy statement, Concerning the Suppression of Accuracy in Artificial Intelligence Systems, open for public comment through July 31, 2026 (Federal Register, Docket FTC-2026-0859). It states that a company which steers its AI system's output to comply with a state law can still be found to deceive consumers under Section 5, even where the steering was a genuine attempt at state compliance. Read that carefully. A federal regulator is on record saying that satisfying a state AI statute does not, by itself, satisfy federal consumer protection law. One tile of the mosaic does not clear the board.

Brussels still has a claim on firms that never opened an EU office

The EU AI Act was written to reach outward. Article 2 applies to "providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union" (Regulation (EU) 2024/1689, Article 2). A US bank, insurer, or platform with no EU subsidiary can fall inside the regulation the moment an EU job applicant, an EU patient, or an EU customer sees an AI system's output.

The timeline itself keeps moving. Prohibited practices became binding February 2, 2025, and governance and general-purpose-model obligations followed on August 2, 2025 (European Commission, AI Act regulatory framework). The Digital Omnibus amendment, in force since July 27, 2026, pushed the deadline for stand-alone high-risk systems under Annex III, covering hiring, credit, education, and critical infrastructure, to December 2, 2027, and pushed high-risk systems embedded in already-regulated products to August 2, 2028 (European Commission, updated August 3, 2026). The deadline moved. The reach into companies outside the Union did not. A US firm whose AI output touches an EU employee, applicant, or customer still answers to a law it never voted on, on a schedule Brussels resets, not Washington. The general-purpose model providers that most US enterprises route through their own operating layer have carried GPAI obligations since that same August 2025 date, regardless of where their customers sit.

The board question: which tile did you satisfy, and can you prove it

Lay the regimes side by side. A voluntary NIST framework under revision by executive order. A Colorado statute repealed and rewritten, with its next real deadline on January 1, 2027. A federal Executive Order actively suing to invalidate state AI laws. Bank and broker-dealer guidance from three agencies that do not cite each other. An insurance bulletin adopted state by state, with variations. A health IT transparency rule and a medical device pathway running on separate clocks inside the same federal department. An FTC that treats state compliance as no defense to a federal deception claim. A European law that reaches in regardless of where a company is incorporated, on a schedule the European Commission alone controls. Eight regimes. Eight clocks. No shared checklist between any two of them.

None of this is easier than Brussels. It is harder. Satisfying the EU AI Act is one problem, argued in one room, against one text. Satisfying the eight regimes above is eight problems, each capable of changing without warning the other seven.

That is the case for an operating layer, not a policy binder. A policy binder answers one regulator on the day it is written and goes stale the day any one of the eight moves. An operating layer keeps a single architecture producing every regulator's evidence on demand: which model produced an output, under which control, reviewed by whom, logged where, and when. It does not pick one framework and hope the others align. It is built to answer NIST's four functions, Colorado's disclosure and appeal rights, the OCC's third-party lifecycle, the NAIC's AIS Program, HTI-1's transparency fields, the FTC's ordinary deception standard, and the EU AI Act's high-risk documentation from one system of record, because the eight were never going to converge on their own.

Of the regimes above, which one could you satisfy today, with a logged answer, before a regulator or a plaintiff's lawyer finishes asking?

NIST is being revised this year. Colorado rewrote itself twice in two years and is not finished. The task force built to challenge state AI laws launched in January 2026. Brussels moved its own deadline in July. None of that is a reason to wait for the mosaic to settle. It is the reason it will not.

The Hikari Blue team · Austin, August 2026

More from the Newsroom

See all articles in the Newsroom →

Own the audit trail before a regulator asks for it.

Thirty minutes with an operator. No slides.

Direct call with one of the partners. We map which of the US and EU regimes actually touch your AI programs, and what the operating layer would need to answer each one, for your specific stack and regulatory perimeter.