5 MCP servers live now What’s live ›
Real Biz Digital logo Real Biz Digital

United States

Automated decision-making compliance in the US: what actually applies in 2026

There is no federal AI law imposing compliance obligations on private companies, and federal policy is currently pointed at preempting state law rather than adding to it. What actually binds an enterprise deploying automated decision-making is a short list of state statutes and one set of regulations — California's ADMT rules — plus the sector regulators that already governed automated systems before anyone called them AI. This article maps what is in force today, what is not, and three widely repeated claims that are simply wrong.

How Barzel applies here Start free with BarzelVault

Three corrections first

These circulate constantly in vendor content and would embarrass you in front of a well-informed buyer.

The Colorado AI Act never took effect

SB 24-205 was signed in May 2024 with a February 2026 operative date. It was delayed twice, its enforcement was then suspended under a stipulation in litigation brought against the state, and it was repealed and reenacted by SB 26-189, signed 14 May 2026, effective 1 January 2027. Nobody ever complied with SB 24-205 because it never applied. Content describing its duty of care, algorithmic impact assessments or risk-management-program requirement is describing a law that was repealed before it operated.

The replacement is materially lighter: it drops the duty of care, the impact assessments and the risk-management programme, and pivots to disclosure — pre-use notice, adverse-outcome disclosure within 30 days, data correction and meaningful human review. Attorney-General enforcement only, no private right of action, 60-day cure sunsetting in 2030.

California SB 1047 was vetoed and never became law

It was vetoed in September 2024. Its successor is SB 53, the Transparency in Frontier Artificial Intelligence Act, signed 29 September 2025 and effective 1 January 2026 — and it applies only to frontier developers above a 10²⁶ training-FLOP threshold, with heavier duties above $500M revenue. It is not a general enterprise AI law.

The SEC's predictive data analytics proposal is dead

Proposed July 2023, formally withdrawn in June 2025 as one of fourteen rescinded proposals. The SEC stated it does not intend to issue final rules; any future action would require a new proposal. It is not pending.

Is there a federal US AI law?

EO 14110 was rescinded on 20 January 2025. EO 14179 ("Removing Barriers to American Leadership in Artificial Intelligence", January 2025) became the operative policy instrument, with America's AI Action Plan (July 2025) as the roadmap.

EO 14365 (December 2025) is the current centrepiece — and what it requires of private companies is nothing. It directs federal agencies: a DOJ AI Litigation Task Force to challenge state AI laws, Commerce to identify "onerous" state laws and condition broadband funding, an FTC policy statement on preemption, an FCC rulemaking on a federal AI reporting standard, and legislative recommendations for a preemptive federal standard.

No preemption statute has been enacted. Preemption is a policy push, not law. The practical consequence for compliance planning is that state obligations remain live, but their durability is genuinely uncertain — which argues for building controls that satisfy the strictest applicable regime rather than optimising to any one statute.

Which US AI rules are actually in force?

LawIn forceWhat it does
CPPA/CCPA regulations 1 Jan 2026 (framework)
1 Jan 2027 (ADMT duties)
The closest US analogue to GDPR Article 22. See below.
Texas TRAIGA (HB 149) 1 Jan 2026 Intent-based prohibitions. Disparate impact alone is not sufficient to prove intent. AG-only enforcement, 60-day cure.
Illinois HB 3773 1 Jan 2026 Amends the Human Rights Act. Bars discriminatory-effect AI in employment decisions; bars zip code as a proxy; requires notice.
California AB 2013 1 Jan 2026 Training-data transparency for generative AI, retroactive to systems released or updated from 1 Jan 2022.
California SB 53 1 Jan 2026 Frontier developers only. Incident reporting to Cal OES within 15 days, 24 hours if imminent danger.
NYC Local Law 144 July 2023 Bias audits and notice for automated employment decision tools.
Colorado SB 26-189 1 Jan 2027 Disclosure-based ADMT regime for consequential decisions.
NY RAISE Act 1 Jan 2027 Frontier developers. Incident reporting to NY DFS within 72 hours.

What do California's ADMT rules require?

Approved by the Office of Administrative Law in September 2025, effective 1 January 2026, with staged compliance. This is the closest thing the United States has to a general automated-decision regime.

The definition is narrower than most assume

ADMT is technology that processes personal information and replaces or substantially replaces human decision-making. That test — "substantially replaces" — is exactly the line agentic tooling sits on, and it is where the compliance analysis actually happens. A model that informs a human decision is not ADMT. A model whose output is adopted without genuine review probably is.

It bites on significant decisions: financial or lending services, housing, education, employment or independent contracting, and healthcare. Notably, behavioural advertising was dropped from the final rules.

What you owe where ADMT is used for a significant decision

  1. a risk assessment;
  2. a pre-use notice;
  3. an opt-out, subject to limited exceptions;
  4. access to the logic of the ADMT and how outputs are used;
  5. a right to appeal.

The staged dates

DateObligation
1 Jan 2026Risk assessment obligation begins
1 Jan 2027ADMT obligations apply
31 Dec 2027Assessments for pre-existing activities due
1 Apr 2028First risk-assessment summary filing to CPPA; retain 5 years
1 Apr 2028 / 2029 / 2030Cybersecurity audits, staged by 2026 revenue (>$100M / $50–100M / <$50M)

The item most often missed is the access to logic requirement. Explaining how an output was produced, for a specific individual, months later, requires that you captured the inputs and the model or rule version at the time. Re-running the case on a current model produces a new decision, not an explanation of the old one.

Financial services: FINRA is the most concrete source

No SEC AI rule exists and none is being written; the Chairman set a principles-based, technology-neutral posture in March 2026, anchored in materiality. AI remains an examination priority and "AI-washing" is pursued under existing antifraud provisions.

FINRA is where the specifics are. Regulatory Notice 24-09 (June 2024) confirmed existing rules apply to generative AI — Rule 3110 supervision, Rule 2210 communications, Rule 4511 books and records, Reg BI. More usefully, FINRA's 2026 Annual Regulatory Oversight Report addresses AI agents directly, naming:

  • autonomy without human validation;
  • scope creep beyond intended authority;
  • auditability of multi-step reasoning;
  • sensitive-data disclosure;
  • domain-knowledge gaps and misaligned reward structures.

Its recommendations are human-in-the-loop protocols, tracking mechanisms and behavioural guardrails — and it states that supervisory systems relying on AI must evaluate the integrity, reliability and accuracy of the model. A regulator naming scope creep and auditability as supervisory risks in an official 2026 report is the strongest citation available for agentic governance in US financial services.

Also already in force and frequently overlooked: Reg SCI, Rule 15c3-5 market access controls, and Rule 3110 generally. These governed automated decisioning long before AI-specific rules were contemplated.

Frameworks and assurance

NIST AI RMF 1.0 (January 2023) remains the current version — there is no 2.0 — and it is voluntary, not a regulation. The Generative AI Profile (NIST AI 600-1, July 2024) is final. The Control Overlays for Securing AI Systems project has produced a concept paper and an annotated outline but no public draft overlay; the one final publication under it is the adversarial machine learning taxonomy (NIST AI 100-2 E2025, March 2025).

One caution: a "NIST AI RMF Agentic Profile" circulates online. It is a Cloud Security Alliance work product, not a NIST publication.

There is no SOC 2 for AI. No AICPA attestation standard or criteria set specific to AI exists, the Trust Services Criteria have not been amended, and NIST AI RMF, ISO 42001 and the EU AI Act have not been incorporated into SOC 2. In practice, auditors expect AI controls mapped into the existing structure: AI governance policy in the control environment, AI in the risk assessment, and control activities covering model validation, bias testing, version control, audit trails and logging, vendor management, data lifecycle and continuous monitoring. ISO/IEC 42001 is currently the only certifiable AI management system standard.

E-invoicing: nothing to comply with

The United States has no federal e-invoicing mandate, B2B or otherwise, no clearance model and no real-time reporting to a tax authority. The DBNAlliance exchange framework — which grew out of the Business Payments Coalition pilot facilitated by the Federal Reserve — is a voluntary, industry-governed four-corner network. Some federal agencies require invoicing through the Treasury's Invoice Processing Platform, which is agency-specific.

For any organisation operating on both sides of the Atlantic, this is the sharpest possible contrast: the same invoice that must clear a government system in Poland or be reported within days in Slovakia has no filing obligation at all in the US.

What to actually build

Given a patchwork this unstable — one statute repealed before it operated, another under active constitutional challenge, and a federal effort aimed at preempting both — optimising controls to any single law is poor engineering. The controls that satisfy the strictest applicable regime and survive repeal are:

  1. An inventory of systems making significant decisions about people, including agentic workflows nobody classified as decision-making.
  2. A defensible human-review boundary — and evidence that review was substantive, not a queue confirmation.
  3. Version capture alongside every decision, so "access to the logic" and appeal operate on the original decision.
  4. Pre-execution thresholds enforced outside the model, so the agent cannot decide whether it needs supervision.
  5. Retention that outlives the incident — CPPA risk assessments carry a five-year retention, and application logs do not.

Frequently asked questions

Is there a federal AI law binding private companies?

No. EO 14179 and EO 14365 direct agencies, not companies, and no preemption statute has been enacted.

Did the Colorado AI Act take effect?

No. SB 24-205 was repealed and replaced by SB 26-189, effective 1 January 2027. The original never applied.

What triggers California's ADMT rules?

Use of technology that replaces or substantially replaces human decision-making, for a significant decision in financial services, housing, education, employment or healthcare.

Is there a SOC 2 for AI?

No. AI controls are mapped into the existing Trust Services Criteria. ISO/IEC 42001 is the only certifiable AI management system standard.

Is there a US e-invoicing mandate?

No. The US is post-audit. DBNAlliance is voluntary.

What is the best-sourced guidance on AI agents specifically?

FINRA's 2026 Annual Regulatory Oversight Report, which names scope creep and auditability of multi-step reasoning as supervisory risks.

Where this leads

Across every regime above — California's access-to-logic right, Colorado's meaningful human review, FINRA's auditability expectation — the same control keeps appearing under different names: the ability to show what a system did, on what basis, with whose authorisation, long after the fact.

BarzelVault enforces policy and approval thresholds in a layer the agent passes through and records each action with its inputs, policy version and approver before execution. FinOps Atlas measures what those automated workflows cost.

In practice

Permission before the action. Evidence after it.

The duties on this page attach to the moment an automated system acts: who permitted it, on which data, under which policy version, and what a person saw before approving. Barzel enforces that decision before execution and writes the record an auditor, a regulator or a data subject can be shown.

95 days leftColorado AI Act (SB 26-189) takes effect 1 January 2027

BarzelVault

The AI action firewall: decide what an agent may do before it does it.

  • Approval thresholds and policy checks enforced before execution; human approvals that expire and escalate.
  • Cryptographically signed audit receipts: trigger, inputs, policy version, approver, outcome.
  • Credential isolation, spend and action limits, and an emergency kill switch.

Free tier: 10,000 calls a monthPaid plans from $199 a monthLive on MCPize

Start free Ask by emailProduct pageDocumentation

Barzel FinOps Atlas

Intelligent financial operations for AI agents and automation.

  • Cost per action, workflow and business outcome, allocated as it happens.
  • Spend limits and anomaly detection before the bill, not after.
  • Financial evidence tracing and close-readiness for SOX, SOC 2 and external audit.

Free tier: 500 calls a monthPaid plans from $29 a monthLive on MCPize

Start free Ask by emailProduct pageDocumentation

Enterprise: written quote by email within two business days. No sales call.


Sources

  1. Executive Order 14179 (January 2025); Executive Order 14365 (December 2025); America's AI Action Plan (July 2025).
  2. CPPA, regulations approved 22 September 2025; CCPA rulemaking updates.
  3. Colorado SB 26-189 (signed 14 May 2026); Colorado SB 24-205 (repealed).
  4. Texas HB 149 (TRAIGA); Illinois HB 3773; California AB 2013; California SB 53.
  5. SEC, Notice of Withdrawal, Release 33-11377 (June 2025).
  6. FINRA Regulatory Notice 24-09; FINRA 2026 Annual Regulatory Oversight Report.
  7. NIST AI Risk Management Framework 1.0; NIST AI 600-1; NIST AI 100-2 E2025.
  8. Federal Reserve, Business Payments Coalition; DBNAlliance.

This article is for information and does not constitute legal advice. Position as at 2 September 2026.