The US does not currently have a single federal AI law equivalent to the EU AI Act, but existing federal laws and regulators still apply to AI-related conduct and claims.
Executive Order 14110, an AI executive order, was revoked in January 2025 and replaced by Executive Order 14179, highlighting how federal AI policy can shift over time. In practice, organizations should focus on current agency guidance, enforcement activity, and sector-specific obligations.
The Federal Trade Commission (FTC) has taken action against deceptive AI claims and AI-enabled unfair or deceptive conduct. The Securities and Exchange Commission (SEC) has also brought enforcement actions against investment advisers for false and misleading AI claims.
State-level requirements are also developing. Colorado has revised its AI legislation, with updated obligations scheduled to take effect on January 1, 2027. Other states, including California and Texas, are also introducing AI-related requirements, although scope, effective dates, and obligations differ significantly.
In this environment, ISO 42001 does not replace laws or regulations. Instead, it can provide a structured, auditable approach to demonstrating governance and control. While this can help organizations meet compliance obligations more effectively, they will still be required to identify and address applicable legal, regulatory, and contractual obligations.
It is also widely viewed as complementary to the NIST AI Risk Management Framework, particularly in its focus on accountability, transparency, and risk management.