US Federal AI Requirements carries 14 tracked obligations for companies in scope. This guide lists who is covered, the duty tiers, and every obligation with its deadline and statutory citation — all from Shieldra's versioned regulation pack, verified 2026-09-09.
What are the duty tiers under US Federal AI Requirements?
Statutory federal AI duties apply (TAKE IT DOWN Act (Pub. L. 119-12); COPPA Rule (16 CFR 312); Reg. B (12 CFR 1002.9); 45 CFR §92.210; FCC 24-17; OMB M-25-22; FY2026 NDAA §1532)
Citation: TAKE IT DOWN Act (Pub. L. 119-12); COPPA Rule (16 CFR 312); Reg. B (12 CFR 1002.9); 45 CFR §92.210; FCC 24-17; OMB M-25-22; FY2026 NDAA §1532 — https://www.ftc.gov/business-guidance/resources/complying-take-it-down-act
At least one federal rule with a specific, dated AI-relevant duty reaches you. These are enforced by their own agencies (FTC, CFPB and prudential regulators, HHS OCR, FCC, contracting agencies) and several carry private rights of action. The general duties in the next tier apply as well.
General federal law applies to your AI use (FTC Act §5 (15 U.S.C. 45); Title VII, ADA, ADEA; HIPAA; Securities Act and Exchange Act antifraud provisions)
Citation: FTC Act §5 (15 U.S.C. 45); Title VII, ADA, ADEA; HIPAA; Securities Act and Exchange Act antifraud provisions — https://www.ftc.gov/news-events/news/press-releases/2024/09/ftc-announces-crackdown-deceptive-ai-claims-schemes
No AI-specific statute is triggered, but existing federal law reaches how you describe, buy, and use AI. The FTC's 'Operation AI Comply' (since 25 September 2024) and its 2025–2026 follow-on cases target unsupported AI claims; employment and health statutes are unchanged by the withdrawal of agency guidance.
Baseline: no federal AI duty triggered beyond general law (FTC Act §5 (15 U.S.C. 45))
Citation: FTC Act §5 (15 U.S.C. 45) — https://www.ftc.gov/legal-library/browse/statutes/federal-trade-commission-act
Nothing you answered triggers a specific federal AI rule. The FTC Act still applies to any claim you make about AI, and a documented AI risk program is the expectation in any federal investigation (DOJ corporate compliance guidance, 23 September 2024). Re-screen if you add consumer-facing AI, start using AI in credit, hiring, or health decisions, host user content, or sell to government.
What should you do about each obligation?
Maintain a documented AI risk-management program (NIST AI RMF-aligned) (DOJ Evaluation of Corporate Compliance Programs (Sept. 2024); NIST AI RMF 1.0 and NIST AI 600-1 (Generative AI Profile))
Keep an inventory of every AI system you build or use with an owner, purpose, and data description; assess and document risks before deployment; monitor for misuse and drift; and align the program to the NIST AI Risk Management Framework. No federal statute mandates this, but DOJ prosecutors assess whether a company risk-assessed and monitors its AI use when evaluating any compliance program, federal buyers and enterprise questionnaires expect NIST alignment, Texas TRAIGA treats substantial NIST compliance as a defense, and the program is the evidence base every other duty in this pack draws on. NIST's revision of AI RMF 1.0 directed by the July 2025 AI Action Plan has not been published; the 2023 framework and the 2024 Generative AI Profile remain the reference.
Substantiate every AI capability, accuracy, and automation claim before making it (FTC Act §5, 15 U.S.C. 45; FTC Operation AI Comply (25 Sept. 2024) and follow-on orders (Workado, Aug. 2025; Air AI, Mar. 2026; Cox Media Group, Aug. 2026))
Hold competent and reliable evidence for every express or implied claim about what your AI does: accuracy or detection rates, degree of automation, earnings or productivity outcomes, and 'AI-powered' where humans do the work. Keep the test evidence with the claim. The FTC's posture under Chair Ferguson is anti-deception rather than anti-technology — it vacated the Rytr order on 22 December 2025 for targeting a tool rather than a harm — but it continues to bring AI-claim cases: Workado (unsupported AI-detector accuracy, final order 28 August 2025), Air AI ($18M judgment, March 2026), Growth Cave ($48.6M, January 2026), and Cox Media Group's 'active listening' marketing (final orders 27 August 2026). State attorneys general use the same theory under their unfair-practice statutes (Texas v. Pieces Technologies, September 2024).
No AI-generated or fake reviews and testimonials (FTC Consumer Reviews and Testimonials Rule, 16 CFR Part 465 (89 FR 68077))
Do not create, buy, sell, or publish reviews or testimonials that are AI-generated, from non-existent people, or from people without experience of the product (§465.2); do not pay for reviews conditioned on sentiment (§465.4); disclose insider reviews (§465.5); do not run company-controlled sites posing as independent (§465.6); do not suppress reviews (§465.7); do not buy fake social-media indicators (§465.8). Keep evidence that displayed reviews came from real customers. Civil penalties reach $53,088 per violation. The FTC sent warning letters to ten companies in December 2025 and filed its first litigated case under the rule with Illinois in May 2026. AI virtual endorsers count as endorsers under the 2023 Endorsement Guides: their claims are your claims.
Run a 48-hour notice-and-removal process for non-consensual intimate imagery, including AI forgeries (TAKE IT DOWN Act, Pub. L. 119-12 §3 (signed 19 May 2025))
Post a clear, conspicuous, plain-language notice of the removal process on your homepage and wherever intimate content may appear; accept requests from the depicted person or an authorized representative; remove the content and known identical copies within 48 hours of a valid request; make reasonable efforts to find identical copies; and keep records of requests and actions. The FTC enforces as a rule violation at up to $53,088 per violation, sent pre-deadline letters to fifteen major platforms and warning letters to twelve 'nudify' operators in May 2026, and runs a public complaint portal. No litigated case had been filed as of 8 September 2026. The criminal provisions applying to individuals who publish such imagery have been in force since 19 May 2025.
COPPA: separate parental consent before any AI training or third-party disclosure of children's data (COPPA Rule amendments, 90 FR 16977 (22 Apr. 2025), 16 CFR Part 312)
Obtain verifiable parental consent that is separate from consent to the service itself before disclosing a child's personal information to third parties or using it to train or develop AI — the FTC's preamble states such uses are never 'integral' to the service, so they always need the separate consent. Treat biometric identifiers (face templates, voiceprints) and government IDs as personal information; adopt a written retention policy and never retain indefinitely; run a written security program with an annual risk assessment and written assurances from vendors; use the new consent methods where helpful. Applies to child-directed services and to any operator with actual knowledge of under-13 users, including chatbots and ed-tech. 2025 enforcement: Disney ($10M), Apitor, Sendit. The FTC's September 2025 study of companion chatbots asks specifically about COPPA compliance.
Give specific, accurate principal reasons for AI-driven credit denials (Regulation B) (ECOA §701(d); 12 CFR 1002.9; CFPB Reg. B final rule, 91 FR (22 Apr. 2026), effective 21 July 2026)
Every adverse-action notice must state the specific principal reasons that actually drove the decision, which means you must be able to map model outputs to accurate reasons regardless of model complexity — an explainability requirement in all but name. The CFPB withdrew its two AI adverse-action circulars (2022-03, 2023-03) on 12 May 2025, and its Regulation B rule effective 21 July 2026 removed disparate-impact liability under ECOA, narrowed 'discouragement', and confirmed that facially neutral variables used as intentional proxies remain disparate treatment. That rule is under APA challenge in the D.D.C. (briefing into January 2027), Fair Housing Act disparate impact still applies to mortgage lending, and New Jersey (rules of 15 December 2025) and Illinois (credit standard from 1 January 2027) preserve or codify effects liability under state law. Keep disparate-treatment and proxy controls documented, and keep less-discriminatory-alternative testing where you lend in those states.
FCRA duties when AI decisions use consumer reports (FCRA §615, 15 U.S.C. 1681m; §604 permissible purpose)
Use consumer reports only for a permissible purpose, give the statutory adverse-action notice (including the report source and the consumer's rights) whenever a report contributes to a denial, and for employment screening follow the pre-adverse-action process. Watch the theory in Kistler v. Eightfold AI (N.D. Cal., filed 20 January 2026; motion to dismiss argued 4 August 2026, ruling pending) that an AI vendor's candidate 'likelihood of success' scores are themselves consumer reports — if it succeeds, scoring vendors become consumer reporting agencies and their customers become users with FCRA notice duties.
Validate AI hiring and workforce tools and provide accommodations (Title VII, ADA, ADEA) (Title VII (42 U.S.C. 2000e-2(k)); ADA; ADEA; Uniform Guidelines on Employee Selection Procedures, 29 CFR Part 1607; Mobley v. Workday, No. 3:23-cv-00770 (N.D. Cal.))
Treat every AI screening, ranking, assessment, or monitoring tool as a selection procedure: validate it for the job, run adverse-impact analysis, keep the analysis under counsel's direction to preserve privilege (held privileged in Mobley v. Workday, 28 May 2026, affirmed 24 June 2026), provide an accessible alternative and reasonable accommodation path, and never let a tool make disability-related or medical inquiries. The EEOC removed its AI technical assistance on 27 January 2025 and closed disparate-impact-only charges from September 2025, and a DOJ opinion of 9 June 2026 attacks the Uniform Guidelines — but the statutes are unchanged, the Guidelines remain codified, and the risk is private litigation: Mobley v. Workday has a certified nationwide ADEA collective of applicants aged 40+ (extended to HiredScore features), with rulings in 2026 that applicants are protected and that vendors can be liable as the employer's agent. Harper v. Sirius XM (Title VII, iCIMS screening) is proceeding. State duties (NYC, Illinois, California, Connecticut, Colorado, New Jersey) sit in the state packs.
Section 1557: identify and mitigate discrimination risk in patient-care decision-support tools (45 CFR §92.210 (89 FR 37522, 6 May 2024); HHS Notice of Vacatur, 91 FR (2 June 2026))
Make ongoing reasonable efforts to identify every patient-care decision-support tool — screening, risk prediction, diagnosis, prognosis, treatment planning, operations, resource allocation, automated or not — that uses race, color, national origin, sex, age, or disability as an input variable, and for each identified tool make reasonable efforts to mitigate the risk of discrimination: an inventory, a governance process, documentation of the developer's risk information, and staff training. OCR weighs entity size and resources, use as intended, customization, and the existence of an evaluation process. The gender-identity provisions of the 2024 rule were vacated in Tennessee v. Kennedy (S.D. Miss., 22 October 2025); HHS confirmed on 2 June 2026 that the other provisions, including §92.210, remain in force. Agency enforcement appetite is low; private litigants and state attorneys general can still rely on it.
HIPAA: business associate agreements and risk analysis for AI handling PHI (45 CFR Parts 160 and 164; HIPAA Security Rule NPRM, 90 FR 898 (6 Jan. 2025), not final)
Sign a business associate agreement with every AI vendor that creates, receives, maintains, or transmits PHI; apply the minimum-necessary standard to what the tool sees; add AI systems to the security risk analysis and asset inventory; do not permit vendors to train on PHI without patient authorization or proper de-identification under §164.514; and stop staff from using ungoverned consumer AI with PHI. There is no AI-specific HIPAA rule. The January 2025 Security Rule proposal (asset inventory and network map, mandatory MFA and encryption, 72-hour restoration, annual audits) has not been finalized; the Unified Agenda targets July 2027. Non-HIPAA health data is separately regulated by Washington's My Health My Data Act, Nevada SB 370, and the FTC Health Breach Notification Rule (see the state privacy pack).
Accurate AI disclosures to investors and clients (no 'AI-washing') (Securities Act §17(a); Exchange Act §10(b) and Rule 10b-5; Advisers Act §206 and Marketing Rule 206(4)-1; SEC FY2026 Examination Priorities (17 Nov. 2025))
Say only what is true about AI in filings, Form ADV, marketing, and client communications, and be able to show it: how AI is actually used, whether humans do the work, and what it does not do. The SEC charged Delphia and Global Predictions (March 2024), Presto Automation (January 2025, first public company), and Nate Inc. (April 2025, with parallel criminal charges). FY2026 examination priorities cover the accuracy of AI representations, policies for evaluating AI tools before deployment, monitoring outputs, and human oversight of material AI-driven decisions. The 2023 predictive-analytics conflicts proposal was withdrawn on 12 June 2025; the current Chair has said no AI-specific rules are planned and that existing antifraud law applies technology-neutrally.
TCPA: prior express consent, identification, and opt-out for AI-generated voice calls (47 U.S.C. 227; 47 CFR 64.1200; FCC Declaratory Ruling FCC 24-17 (CG Docket 23-362))
Treat any call or voice message using an AI-generated, synthetic, or cloned voice as an 'artificial or prerecorded voice' call: obtain prior express consent (prior express written consent for telemarketing), identify the caller at the start of the message and give a callback number, honor opt-outs and revocations by any reasonable means (revocation rule in force since 11 April 2025; the 'revoke-all' provision is waived to January 2027), and use properly attested caller ID under STIR/SHAKEN — the Lingo Telecom consent decree ($1M, August 2024) arose from the AI-cloned Biden calls. The FCC's 2024 proposal to require an AI disclosure on each call has not been adopted; the one-to-one consent rule was vacated by the Eleventh Circuit on 24 January 2025.
Federal procurement: AI contract terms and large-language-model disclosures (OMB M-25-22 (3 Apr. 2025); OMB M-25-21; OMB M-26-04 (11 Dec. 2025); EO 14319 (23 July 2025))
Expect and be ready to accept contract terms that: permanently bar using non-public agency inputs or outputs to train publicly or commercially available models without express consent; give the agency access and time for independent testing (quarterly or biannual) with agency-held test data, and require your testing procedures to be disclosed and reproducible; provide portability, knowledge transfer, and rights to code and models produced under the contract; require documentation supporting the agency's AI impact assessment where the use is 'high-impact'; and require notice before new AI features are integrated. For any large language model sold to an agency, supply an acceptable-use policy, model or system cards, end-user resources, and a feedback channel for outputs violating the 'Unbiased AI Principles', with enhanced disclosures (system prompts, bias evaluations, non-US training, third-party modifications) at agency discretion; agencies may make these material to payment and terminate for default, and the vendor bears decommissioning costs after a cure period. A GSA-wide AI clause (30-day disclosure of all AI systems, 7-day notice of guardrail changes, 72-hour incident reporting) is proposed and not final; there is no FAR or DFARS AI clause. Cloud AI services need FedRAMP authorization.
DoD contracts: no 'covered AI' from designated adversary-linked companies (FY2026 National Defense Authorization Act, Pub. L. 119-60, §1532)
Do not use AI models or services from companies designated under §1532 in the performance of Department of Defense contracts absent a waiver; keep an AI bill of materials for DoD deliverables so you can prove provenance. Separately, the January 2026 Department of War AI strategy directs contract language permitting 'any lawful use' of vendor AI and access to new model versions within 30 days of public release — the dispute over such terms produced the Anthropic supply-chain-risk designation and the injunction and merits ruling against it in 2026. Controlled unclassified information processed by AI systems remains subject to the CMMC rule.