# AI rules in United States (federal)

No comprehensive federal AI statute: Washington governs AI through executive orders, OMB rules for federal agencies, export controls and sector regulators, while the White House and DOJ try to preempt or litigate against state AI laws.

- **Approach:** Patchwork
- **Key bodies:** White House OSTP, Office of Management and Budget (OMB), Department of Commerce (BIS, NIST/CAISI, NTIA), Department of Justice (AI Litigation Task Force), Federal Trade Commission (FTC), Food and Drug Administration (FDA), Federal Communications Commission (FCC)
- **Strategy:** [America's AI Action Plan (Winning the Race)](https://www.whitehouse.gov/wp-content/uploads/2025/07/Americas-AI-Action-Plan.pdf) (2025)
- **Last reviewed:** 4 Oct 2026

## Rules (15)
- [EO 14179](https://wheresthe.ai/rule/us-eo-14179-removing-barriers-ai-2025/index.md): In force, Executive order, effective 23 Jan 2025. Revokes the Biden-era EO 14110 on safe, secure and trustworthy AI and directs agencies to review and rescind actions taken under it. Sets federal policy to 'sustain and enhance America's global AI dominance' and ordered the AI Action Plan delivered in July 2025.
- [AI Action Plan](https://wheresthe.ai/rule/us-ai-action-plan-2025/index.md): In force, Strategy, effective 23 Jul 2025. Federal AI strategy built on three pillars (accelerate innovation, build AI infrastructure, lead in international AI diplomacy and security) that directs agencies to remove regulatory barriers, revise the NIST AI RMF, expand CAISI model evaluations, speed data-center permitting and promote exports of the US 'AI stack'. It also tells agencies to weigh a state's AI regulatory climate when awarding AI-related funding.
- [State AI law preemption EO](https://wheresthe.ai/rule/us-eo-14365-national-ai-policy-framework-2025/index.md): In force, Executive order, effective 11 Dec 2025. Orders the Attorney General to set up an AI Litigation Task Force to challenge state AI laws, tells Commerce to publish a list of 'onerous' state AI laws within 90 days and to bar those states from remaining BEAD broadband non-deployment funds, and asks the FTC (policy statement) and FCC (possible preemptive disclosure standard) to act. It also orders a legislative proposal for a preemptive federal framework that would spare state child-safety, data-center and state-procurement laws.
- [White House AI legislative framework](https://wheresthe.ai/rule/us-wh-national-ai-legislative-framework-2026/index.md): Proposed, Strategy. Non-binding recommendations asking Congress to pass a uniform federal AI framework that preempts 'unduly burdensome' state AI laws while preserving state police powers, generally applicable child-protection laws and zoning. It also proposes age-assurance and anti-self-harm features for AI services used by minors, a federal digital-replica right, regulatory sandboxes, and no new federal AI regulator.
- [Great American AI Act](https://wheresthe.ai/rule/us-great-american-ai-act-draft-2026/index.md): Proposed, Bill. Bipartisan discussion draft that would require large frontier AI developers to publish safety frameworks and transparency reports, report critical safety incidents to NIST's Center for AI Standards and Innovation, and undergo periodic independent audits. It would preempt state laws that specifically regulate AI model development for three years, while leaving state laws on AI use and deployment in place.
- [EO 14409 (covered frontier models)](https://wheresthe.ai/rule/us-eo-14409-advanced-ai-innovation-security-2026/index.md): In force, Executive order, effective 2 Jun 2026. Directs NSA, CISA, Treasury and NIST to build a classified benchmark for the cyber capabilities of AI models and a threshold for designating 'covered frontier models', plus a voluntary framework under which developers give the government up to 30 days' pre-release access to such models. It also orders CISA directives on AI-enabled cyber defence, a Treasury-led AI vulnerability clearinghouse, and DOJ prioritisation of prosecutions for AI-enabled hacking.
- [EO 14434 ('Super Intelligence' terminology)](https://wheresthe.ai/rule/us-eo-14434-super-intelligence-terminology-2026/index.md): In force, Executive order, effective 29 Sep 2026. Requires executive-branch agencies, to the extent permitted by law, to use 'Super Intelligence' and 'SI' instead of 'Artificial Intelligence' and 'AI' in correspondence, websites, reports and policy documents, defining SI by reference to the existing statutory definition of AI (15 U.S.C. 9401(3)). It asks OSTP to propose legislation within 60 days on whether a statutory 'Super Intelligence' definition should supersede 'artificial intelligence'.
- [OMB M-25-21](https://wheresthe.ai/rule/us-omb-m-25-21-federal-ai-use-2025/index.md): In force, Guideline, effective 3 Apr 2025. Binding guidance for all federal agencies (including independent regulators) that replaces M-24-10: agencies must appoint Chief AI Officers, publish AI strategies and use-case inventories, and apply minimum risk-management practices (pre-deployment testing, impact assessments, human oversight) to 'high-impact AI'. Agencies had 365 days (to 3 Apr 2026) to document those practices and must stop using non-compliant high-impact AI.
- [OMB M-25-22](https://wheresthe.ai/rule/us-omb-m-25-22-ai-acquisition-2025/index.md): In force, Guideline, effective 30 Sep 2025. Replaces M-24-18 and sets rules for how agencies buy AI: preference for American AI, protections against vendor lock-in, limits on vendors' use of government data, and performance-based contracting. It applies to contracts awarded under solicitations issued 180 days or more after issuance and to options exercised after that date.
- [OMB M-26-04 ('Woke AI' procurement rules)](https://wheresthe.ai/rule/us-omb-m-26-04-unbiased-ai-principles-2025/index.md): In force, Guideline, effective 11 Dec 2025. Implements EO 14319 (Preventing Woke AI in the Federal Government) by requiring agencies to buy only large language models that meet two 'Unbiased AI Principles' — truth-seeking and ideological neutrality — and to write compliance terms and vendor disclosure requirements into LLM contracts. Agencies had to update procurement policies by 11 Mar 2026 and should amend existing LLM contracts before exercising options.
- [BIS H200 case-by-case rule](https://wheresthe.ai/rule/us-bis-advanced-computing-license-policy-2026/index.md): In force, Regulation, effective 15 Jan 2026. Changes BIS licence review for exports to China and Macau of Nvidia H200-class and less advanced AI chips from a presumption of denial to case-by-case review, if the exporter certifies sufficient US supply, no diversion of foundry capacity, adequate recipient security, and independent US third-party performance testing. More advanced chips remain under the existing controls.
- [TAKE IT DOWN Act](https://wheresthe.ai/rule/us-take-it-down-act-2025/index.md): In force, Law, effective 19 May 2025. Makes it a federal crime to knowingly publish non-consensual intimate images, including AI-generated 'digital forgeries', and threats to do so. Since 19 May 2026 'covered platforms' must run a notice-and-removal process and take down reported images and known identical copies within 48 hours, enforced by the FTC.
- [FDA PCCP guidance](https://wheresthe.ai/rule/us-fda-pccp-ai-device-guidance/index.md): In force, Guideline, effective 4 Dec 2024. Final FDA guidance explaining how makers of AI-enabled medical devices can include a Predetermined Change Control Plan in 510(k), De Novo or PMA submissions describing planned model modifications, the protocol for developing and validating them, and an impact assessment. Changes made within an authorised PCCP do not need a new marketing submission.
- [FTC AI accuracy policy statement](https://wheresthe.ai/rule/us-ftc-ai-accuracy-policy-statement-2026/index.md): In consultation, Guideline. Proposed FTC policy statement on how Section 5's ban on deceptive practices applies to companies marketing AI systems, focusing on undisclosed steering or distortion of AI outputs. It takes the position that complying with a state law does not excuse undisclosed distortion of outputs and that state laws requiring such conduct may be preempted.
- [NIST AI RMF](https://wheresthe.ai/rule/us-nist-ai-rmf/index.md): In force, Standard, effective 26 Jan 2023. Voluntary framework (Govern, Map, Measure, Manage) for managing AI risks across the lifecycle, with a Generative AI Profile and, since 7 Apr 2026, a concept note for a critical-infrastructure profile. NIST states the AI RMF 1.0 'is being revised as part of the White House AI Action Plan', which calls for removing references to misinformation, DEI and climate change.

## Upcoming deadlines
- 28 Nov 2026: OSTP to propose statutory definition of 'Super Intelligence' and conforming amendments ([EO 14434 ('Super Intelligence' terminology)](https://wheresthe.ai/rule/us-eo-14434-super-intelligence-terminology-2026/index.md))

## Programmes and facts
- Genesis Mission (EO 14363, 24 Nov 2025): DOE-run national effort and 'American Science and Security Platform' applying AI to scientific discovery
- FDA list of AI-enabled medical devices: 1,614 authorised devices (final decisions through 29 Jun 2026)
- NIST Center for AI Standards and Innovation (shown as 'CAISSI' on NIST's site after EO 14434) runs voluntary pre-deployment testing and published evaluations of PRC open-weight models (e.g. DeepSeek V4 Pro, May 2026; Z.ai GLM-5.3, Sep 2026)
- FTC TAKE IT DOWN complaint portal (TakeItDown.ftc.gov) live since 19 May 2026; warning letters sent to 12 'nudify' services on 20 May 2026
- DOJ AI Litigation Task Force created 9 Jan 2026 to challenge state AI laws

---
Canonical page: https://wheresthe.ai/j/us/ · Not legal advice.
