Ask a US chief risk officer to name the AI Act. There is no single answer, because there is no single act.
Europe wrote one law and gave it one clock. The United States built something else: a voluntary technical framework, a state statute already rewritten twice under political pressure, five sector regulators running independent programs, a federal trade regulator that treats an AI claim like any other claim, and a European law that reaches into firms that never opened an office in Brussels. None of these bodies coordinates with the others. Each expects to be satisfied on its own terms, on its own calendar.
A European compliance officer reads one statute, enforced by a single AI Office and the member state authorities beneath it, on one published calendar. A US counterpart reads eight, several of them capable of changing the deadline after the fact.
NIST is the reference framework, and no one has to follow it
The National Institute of Standards and Technology released the Artificial Intelligence Risk Management Framework, AI RMF 1.0, on January 26, 2023. It organizes AI risk work into four functions: govern, map, measure, manage (NIST, AI RMF 1.0). It is the closest thing US enterprises have to a common vocabulary for AI risk, and examiners, auditors, and vendor questionnaires now cite it by name.
It is also explicitly voluntary. NIST states the framework is "intended for voluntary use" (NIST, AI Risk Management Framework page). Nothing compels a bank, an insurer, or a hospital system to adopt it, and the framework carries no penalty of its own for skipping a function. NIST extended it on July 26, 2024, with a Generative AI Profile, NIST-AI-600-1, built specifically for large language model risks (NIST, AI Risk Management Framework page).
The reference document is not settled, either. America's AI Action Plan, released by the White House on July 23, 2025, directs the Department of Commerce to revise the AI RMF and strip references to misinformation, diversity, equity and inclusion, and climate change (The White House, Winning the Race: America's AI Action Plan). A framework enterprises cite in board decks and vendor contracts is being edited under a policy mandate while those citations sit in force. Build a governance program around this year's wording, and the wording under it can move again before the next audit cycle closes.
Colorado tried to write the AI Act, and Washington is suing to stop it
Colorado came closest to a broad state AI statute. Governor Jared Polis signed SB24-205, Consumer Protections for Artificial Intelligence, on May 17, 2024. It required developers and deployers of high-risk AI systems to use reasonable care against algorithmic discrimination, with disclosures, impact assessments, and a consumer right to appeal (Colorado General Assembly, SB24-205). The law was set to take effect February 1, 2026.
It never reached that date intact. After a special legislative session failed to produce a compromise, Polis signed SB25B-004 on August 28, 2025, pushing the requirements to June 30, 2026 (Colorado General Assembly, SB25B-004). On April 27, 2026, a federal court paused enforcement entirely: the Colorado Attorney General, the plaintiffs, and the US Department of Justice jointly asked the court to stay the case, and the Attorney General committed not to enforce SB24-205 "or any legislation replacing or amending" it until a rulemaking process concludes (Troutman Pepper, April 2026). Then, on May 14, 2026, Polis signed SB26-189, which repeals SB24-205 outright and replaces it with a narrower framework built around "automated decision-making technology," with developer documentation obligations beginning January 1, 2027 (Colorado General Assembly, SB26-189).
Two years, one governor, three bills, and the state's flagship AI statute has still never taken effect as originally written. Washington moved in the opposite direction at the same time. On December 11, 2025, the White House issued Executive Order 14365, Ensuring a National Policy Framework for Artificial Intelligence, directing the Attorney General to stand up an AI Litigation Task Force within 30 days to challenge state AI laws as unconstitutional burdens on interstate commerce or as preempted by federal authority. The same order directs the FTC and the FCC to develop federal standards meant to preempt state requirements, and it puts federal grant and broadband funding on the table against states that keep AI laws the administration considers "onerous" (The White House, Executive Order 14365).
A statute rewritten three times before its own effective date arrived is not a compliance delay. It is proof the target moves. Hikari Blue · operator note
Banking, insurance, and healthcare never waited for a statute
Financial regulators did not wait for Congress or Colorado. The Office of the Comptroller of the Currency, the Federal Reserve, and the FDIC jointly issued Interagency Guidance on Third-Party Relationships: Risk Management on June 6, 2023, requiring banks to manage AI vendors under the same lifecycle discipline as any other outsourced service, from due diligence through termination. The guidance replaced two earlier OCC bulletins from 2013 and 2020, neither of which anticipated the technology it now governs (OCC Bulletin 2023-17). FINRA followed on June 27, 2024, with Regulatory Notice 24-09, reminding broker-dealers that its rules are technology neutral and apply in full to generative AI and large language models, including supervision under Rule 3110 and communications standards under Rule 2210 (FINRA, Regulatory Notice 24-09). Neither document references the other. Both apply at once to a bank that also runs a broker-dealer arm.
Insurers answer to a third body. The National Association of Insurance Commissioners adopted its Model Bulletin on the Use of Artificial Intelligence Systems by Insurers in December 2023, requiring a written governance program, an "AIS Program," covering underwriting, rating, claims, fraud detection, marketing, and customer service across the full AI lifecycle (NAIC, Model Bulletin). More than twenty states and the District of Columbia had adopted the bulletin by mid-2026, each through its own insurance department, each free to vary the wording.
Health systems answer to a fourth and a fifth. HHS, through its Office of the National Coordinator for Health IT, finalized the HTI-1 rule, published in the Federal Register on January 8, 2024: the first federal requirement for algorithm transparency inside certified health IT decision support tools (HealthIT.gov, HTI-1 Final Rule). The FDA runs a parallel track for AI inside medical devices, with a final guidance on Predetermined Change Control Plans in December 2024 and a draft guidance on lifecycle management for AI-enabled device software published January 6, 2025 (Federal Register, Docket FDA-2024-D-4488). A hospital deploying a diagnostic model answers to ONC for the software and to the FDA for the device, on two different clocks, inside two different agencies of the same department.
Build one AI governance program to satisfy five regulators, and it will not survive contact with any of them. An agentic underwriting or claims workflow falls inside the NAIC bulletin's full lifecycle whether or not the carrier calls it artificial intelligence in its own documentation.
The FTC treats an AI claim like any other claim, which is the point
The Federal Trade Commission does not run an AI program. It runs Section 5 of the FTC Act, the prohibition on unfair or deceptive practices, and it has made clear that AI products get no exemption. On September 25, 2024, the FTC announced Operation AI Comply, five enforcement actions against companies that used AI hype to mislead consumers, including a $193,000 settlement over a service marketed as a "robot lawyer" (FTC, FTC Announces Crackdown on Deceptive AI Claims and Schemes). No new AI-specific rule was needed. An ordinary claim against an ordinary lie did the work.
On July 7, 2026, the FTC published a proposed policy statement, Concerning the Suppression of Accuracy in Artificial Intelligence Systems, open for public comment through July 31, 2026 (Federal Register, Docket FTC-2026-0859). It states that a company which steers its AI system's output to comply with a state law can still be found to deceive consumers under Section 5, even where the steering was a genuine attempt at state compliance. Read that carefully. A federal regulator is on record saying that satisfying a state AI statute does not, by itself, satisfy federal consumer protection law. One tile of the mosaic does not clear the board.
Brussels still has a claim on firms that never opened an EU office
The EU AI Act was written to reach outward. Article 2 applies to "providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union" (Regulation (EU) 2024/1689, Article 2). A US bank, insurer, or platform with no EU subsidiary can fall inside the regulation the moment an EU job applicant, an EU patient, or an EU customer sees an AI system's output.
The timeline itself keeps moving. Prohibited practices became binding February 2, 2025, and governance and general-purpose-model obligations followed on August 2, 2025 (European Commission, AI Act regulatory framework). The Digital Omnibus amendment, in force since July 27, 2026, pushed the deadline for stand-alone high-risk systems under Annex III, covering hiring, credit, education, and critical infrastructure, to December 2, 2027, and pushed high-risk systems embedded in already-regulated products to August 2, 2028 (European Commission, updated August 3, 2026). The deadline moved. The reach into companies outside the Union did not. A US firm whose AI output touches an EU employee, applicant, or customer still answers to a law it never voted on, on a schedule Brussels resets, not Washington. The general-purpose model providers that most US enterprises route through their own operating layer have carried GPAI obligations since that same August 2025 date, regardless of where their customers sit.
The board question: which tile did you satisfy, and can you prove it
Lay the regimes side by side. A voluntary NIST framework under revision by executive order. A Colorado statute repealed and rewritten, with its next real deadline on January 1, 2027. A federal Executive Order actively suing to invalidate state AI laws. Bank and broker-dealer guidance from three agencies that do not cite each other. An insurance bulletin adopted state by state, with variations. A health IT transparency rule and a medical device pathway running on separate clocks inside the same federal department. An FTC that treats state compliance as no defense to a federal deception claim. A European law that reaches in regardless of where a company is incorporated, on a schedule the European Commission alone controls. Eight regimes. Eight clocks. No shared checklist between any two of them.
None of this is easier than Brussels. It is harder. Satisfying the EU AI Act is one problem, argued in one room, against one text. Satisfying the eight regimes above is eight problems, each capable of changing without warning the other seven.
That is the case for an operating layer, not a policy binder. A policy binder answers one regulator on the day it is written and goes stale the day any one of the eight moves. An operating layer keeps a single architecture producing every regulator's evidence on demand: which model produced an output, under which control, reviewed by whom, logged where, and when. It does not pick one framework and hope the others align. It is built to answer NIST's four functions, Colorado's disclosure and appeal rights, the OCC's third-party lifecycle, the NAIC's AIS Program, HTI-1's transparency fields, the FTC's ordinary deception standard, and the EU AI Act's high-risk documentation from one system of record, because the eight were never going to converge on their own.
Of the regimes above, which one could you satisfy today, with a logged answer, before a regulator or a plaintiff's lawyer finishes asking?
NIST is being revised this year. Colorado rewrote itself twice in two years and is not finished. The task force built to challenge state AI laws launched in January 2026. Brussels moved its own deadline in July. None of that is a reason to wait for the mosaic to settle. It is the reason it will not.
- National Institute of Standards and Technology (2023, updated 2024). Artificial Intelligence Risk Management Framework (AI RMF 1.0), released January 26, 2023, voluntary and organized around Govern, Map, Measure, Manage; extended July 26, 2024 with the Generative Artificial Intelligence Profile (NIST-AI-600-1). nist.gov/itl/ai-risk-management-framework
- The White House (July 23, 2025). Winning the Race: America's AI Action Plan. Directs the Department of Commerce to revise the NIST AI RMF, including removal of references to misinformation, diversity, equity and inclusion, and climate change. whitehouse.gov/wp-content/uploads/2025/07/Americas-AI-Action-Plan.pdf
- Colorado General Assembly. SB24-205, Consumer Protections for Artificial Intelligence, signed May 17, 2024, original effective date February 1, 2026. leg.colorado.gov/bills/sb24-205
- Colorado General Assembly. SB25B-004, Increase Transparency for Algorithmic Systems, signed August 28, 2025, extending SB24-205's requirements to June 30, 2026. leg.colorado.gov/bills/sb25b-004
- Colorado General Assembly. SB26-189, Automated Decision-Making Technology, signed May 14, 2026, repealing and replacing SB24-205, with developer documentation obligations from January 1, 2027. leg.colorado.gov/bills/sb26-189
- Troutman Pepper, Privacy + Cyber + AI blog (April 2026). Colorado Attorney General Delays Enforcement of Colorado AI Act. Source for the April 27, 2026 federal court stay and the Attorney General's commitment not to enforce SB24-205 or any replacement pending rulemaking. troutmanprivacy.com/2026/04/colorado-attorney-general-delays-enforcement-of-colorado-ai-act
- The White House (December 11, 2025). Executive Order 14365, Ensuring a National Policy Framework for Artificial Intelligence. Directs an AI Litigation Task Force within 30 days to challenge state AI laws, and directs the FTC and FCC toward preemptive federal standards. whitehouse.gov/presidential-actions/2025/12/eliminating-state-law-obstruction-of-national-artificial-intelligence-policy
- Office of the Comptroller of the Currency, with the Federal Reserve and the FDIC (June 6, 2023). Bulletin 2023-17, Third-Party Relationships: Interagency Guidance on Risk Management. occ.gov/news-issuances/bulletins/2023/bulletin-2023-17.html
- FINRA (June 27, 2024). Regulatory Notice 24-09, reminding member firms of regulatory obligations when using generative AI and large language models. finra.org/rules-guidance/notices/24-09
- National Association of Insurance Commissioners (adopted December 2023). Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, requiring a written AIS governance program across the insurance lifecycle. content.naic.org, NAIC AI Model Bulletin
- US Department of Health and Human Services, Office of the National Coordinator for Health IT. HTI-1 Final Rule, published in the Federal Register January 8, 2024, establishing algorithm transparency requirements for decision support interventions in certified health IT. healthit.gov/regulations/hti-rules/hti-1-final-rule
- Food and Drug Administration, via the Federal Register (published January 7, 2025). Artificial Intelligence-Enabled Device Software Functions: Lifecycle Management and Marketing Submission Recommendations, draft guidance dated January 6, 2025, Docket FDA-2024-D-4488. federalregister.gov/documents/2025/01/07/2024-31543
- Federal Trade Commission (September 25, 2024). FTC Announces Crackdown on Deceptive AI Claims and Schemes, Operation AI Comply, including the $193,000 settlement over "robot lawyer" claims. ftc.gov/news-events/news/press-releases/2024/09/ftc-announces-crackdown-deceptive-ai-claims-schemes
- Federal Trade Commission, via the Federal Register (published July 7, 2026). Policy Statement Concerning the Suppression of Accuracy in Artificial Intelligence Systems (proposed), Docket FTC-2026-0859, comment period through July 31, 2026. federalregister.gov/documents/2026/07/07/2026-13628
- European Union. Regulation (EU) 2024/1689 (the AI Act), Article 2, on the scope covering providers and deployers outside the Union whose AI system output is used within it. eur-lex.europa.eu/eli/reg/2024/1689/oj/eng
- European Commission, Directorate-General for Communications Networks, Content and Technology (updated August 3, 2026). AI Act, regulatory framework page, for the prohibited-practices and GPAI obligation dates and for the Digital Omnibus deferral of high-risk obligations to December 2, 2027 and August 2, 2028. digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
The Hikari Blue team · Austin, August 2026