Rules that already reach AI tools
There is no single federal AI statute in the United States, but existing law applies to AI the same way it applies to any other business tool. Anti-discrimination laws cover hiring and lending decisions whether a person or an algorithm makes them, consumer protection agencies have treated exaggerated claims about AI capabilities as deceptive marketing, and privacy laws apply to the data used to train and run models. New York City requires a bias audit and notice to candidates before employers use certain automated tools in hiring and promotion decisions. Several states have passed AI laws of their own, and the European Union's AI Act reaches companies that sell or deploy systems in the EU market.
What to inventory and document
Begin with a list of where AI is actually in use, including features buried in vendor platforms that employees may have switched on without review. For each use, note what decisions it influences, what data goes in, and who checks the output. Vendor contracts deserve a close read, since they determine who is responsible for audits, data handling, and errors, and many standard terms push that responsibility back onto the customer. Keep records of testing, human review, and any complaints about results. Those records are what a regulator, a plaintiff, or a business partner will ask for first.
Deciding what comes first
Federal policy on AI has shifted with each administration, and state legislatures are still adding requirements, so a compliance plan has to be revisited rather than written once. We sort your uses by risk: tools that affect employment, credit, housing, health care, or insurance tend to draw the closest scrutiny, while internal drafting aids usually raise more modest issues around confidentiality and accuracy. We also look at which jurisdictions you operate in and what your customers are demanding in their contracts. The goal is a program sized to how you actually use these tools, not a policy copied from a much larger company.