AAI Compliance Atlas
FrameworksState lawsIndustriesToolsNews
GuidesMap my obligations →
AAI Compliance Atlas

Structured, continuously verified reference for US AI compliance — federal frameworks, state laws, and the obligations that connect them.

Atlas

  • Frameworks
  • State laws
  • Industries
  • By role
  • Comparisons

Tools

  • Compliance Checker
  • Penalty Calculator
  • Impact Assessment
  • Vendor Questionnaire

Resources

  • Guides
  • News
  • Blog
  • Methodology

Company

  • About
  • Contact
  • Privacy
  • Terms
© 2026 AI Compliance Atlas. Informational only — not legal advice. Consult qualified counsel before making compliance decisions.Verified Jul 28, 2026
  1. Home/
  2. Roles/
  3. Deployer

AI Deployer Obligations Under US Law

Deployers operate AI systems to make or substantially factor into decisions affecting consumers, employees, or other regulated parties. Most US state AI laws place the heaviest compliance burdens on deployers, including impact assessments, disclosures, and post-deployment monitoring.

Governance routing

Use the AI governance guide to assign decision rights, committees, lifecycle gates, and escalation paths before mapping role-specific duties into the AI compliance framework register.

Obligations under US laws

  • disclosureColorado Artificial Intelligence ActC.R.S. § 6-1-1704(1)–(2)

    Before using a covered ADMT to materially influence a consequential decision, provide a clear and conspicuous notice to the consumer that automated decision-making technology is or will be used in a consequential decision affecting them, with instructions for obtaining further information; a prominent public notice kept reasonably accessible at points of consumer interaction satisfies this requirement.

    Deadline: before_decision

  • disclosureColorado Artificial Intelligence ActC.R.S. § 6-1-1704(3)

    When a covered ADMT materially influences a consequential decision that results in an adverse outcome, provide the consumer, within 30 days of the decision, a plain-language description of the decision and the role the ADMT played, a simple process to request additional information (the system's name, version, developer, and the types, categories, and sources of personal data used), and an explanation of the consumer's correction and human-review rights under § 6-1-1705.

    Deadline: within_30_days_of_adverse_outcome

  • consumer rightColorado Artificial Intelligence ActC.R.S. § 6-1-1705(1)

    On request from a consumer who experiences an adverse outcome, provide instructions to access and correct factually incorrect or materially inaccurate personal data used in the consequential decision (consistent with C.R.S. § 6-1-1306) and an opportunity for meaningful human review and reconsideration of the decision to the extent commercially reasonable; correction is not required for opinions, predictions, scores, or protected evaluations.

    Deadline: on_consumer_request

  • governanceColorado Artificial Intelligence ActC.R.S. § 6-1-1703

    Retain, for at least three years after a consequential decision, the records reasonably necessary to demonstrate compliance with Part 17 of article 1 of title 6 — including covered-ADMT version identifiers, changelogs, and documentation of material mitigation changes.

    Deadline: retain_3_years

  • disclosureTexas Responsible Artificial Intelligence Governance Act (TRAIGA)Tex. Bus. & Com. Code § 552.051

    Provide clear and conspicuous disclosure to consumers when they are interacting with an AI system in a manner where a reasonable consumer might believe they are interacting with a human.

    Deadline: at_interaction

  • governanceTexas Responsible Artificial Intelligence Governance Act (TRAIGA)Tex. Bus. & Com. Code § 552.104, § 552.105

    On receipt of a written notice of alleged violation from the Texas Attorney General, cure the violation within the statutory cure window to avoid tier-1 civil penalties of $10,000–$12,000; uncurable violations and continuing violations escalate to $80,000–$200,000 per violation and $2,000–$40,000 per day under § 552.105.

    Deadline: on_ag_notice

  • governanceTexas Responsible Artificial Intelligence Governance Act (TRAIGA)Tex. Bus. & Com. Code § 552.106

    Licensed, registered, or certified persons remain separately subject to discipline by their Texas licensing authority, including sanctions of up to $100,000, in addition to civil penalties imposed by the Attorney General under § 552.105.

    Deadline: ongoing

  • bias auditNYC Local Law 144 (Automated Employment Decision Tools)N.Y.C. Admin. Code § 20-871

    Subject the Automated Employment Decision Tool to an annual independent bias audit calculating selection rates and impact ratios across race/ethnicity and sex categories prior to use, then on a yearly basis.

    Deadline: annually

  • transparencyNYC Local Law 144 (Automated Employment Decision Tools)N.Y.C. Admin. Code § 20-872

    Publicly post a summary of the most recent bias audit results on the employer's website, including the date the AEDT was first used and the source of the data.

    Deadline: ongoing

  • disclosureNYC Local Law 144 (Automated Employment Decision Tools)N.Y.C. Admin. Code § 20-871(b)

    Provide candidates and employees who reside in NYC with at least 10 business days advance notice of AEDT use, including job qualifications, characteristics assessed, and instructions for requesting an alternative selection process or reasonable accommodation.

    Deadline: 10_business_days_before_use

  • governanceIllinois HB 3773 (AI in Employment Decisions)775 ILCS 5/2-102(L)

    Refrain from using AI that has the effect of subjecting employees or applicants to discrimination on the basis of protected classes under the Illinois Human Rights Act in employment decisions.

    Deadline: ongoing

  • disclosureIllinois HB 3773 (AI in Employment Decisions)775 ILCS 5/2-102(L)

    Provide notice to employees and applicants when AI is being used to make employment-related decisions covered by the amended IHRA.

    Deadline: at_use

  • disclosureUtah Artificial Intelligence Policy ActUtah Code § 13-77-103

    A supplier using generative AI in a consumer transaction must disclose that the individual is interacting with generative AI and not a human when the individual makes a clear and unambiguous request about whether AI is being used; regulated-occupation providers must prominently disclose GenAI use for high-risk AI interactions, verbally at the start of verbal interactions or in writing before written interactions.

    Deadline: on_clear_request_or_before_regulated_service_interaction

  • governanceUtah Artificial Intelligence Policy ActUtah Code § 13-77-102

    Maintain accountability for consumer-protection compliance when generative AI makes a violative statement, undertakes a violative act, or is used in furtherance of a violation; Chapter 77 states that generative AI is not a defense to statutes administered and enforced by the Division of Consumer Protection.

    Deadline: ongoing

  • disclosureNew Jersey A 2726 Automated Employment Decision Tool BillA2726 § 2(c)-(e)

    If enacted, an employer or employment agency using an AEDT would have to notify each covered individual at least 10 business days before use through a website employment section, job posting, written policy, U.S. mail, or electronic mail, depending on whether the person is a candidate or employee.

    Deadline: proposed_10_business_days_before_use

  • disclosureNew Jersey A 2726 Automated Employment Decision Tool BillA2726 § 2(f)

    If enacted, an employer using an AEDT would have to provide covered individuals, within 30 days after use, notice that the tool was used, the job qualifications or characteristics assessed, data sources, retention policy, tool name, vendor, and enough adverse-outcome information to contest the employment decision.

    Deadline: proposed_within_30_days_after_use

  • transparencyNew Jersey A 2726 Automated Employment Decision Tool BillA2726 § 2(g)

    If enacted, an employer or employment agency would have to publish the most recent bias-audit date and results on its employment website in accessible, machine-readable, downloadable form, keep the summary posted for at least 10 years after the latest AEDT use, and issue a press release when the report is made publicly available.

    Deadline: proposed_post_for_10_years_after_latest_use

  • disclosureFlorida AI Legislation (Deepfake and AI Disclosure Laws)Fla. Stat. ch. 2024-126 (HB 919)

    Include a clear and conspicuous disclaimer on any political advertisement that uses generative AI to depict a real person performing an action that did not occur, where the advertisement is intended to injure a candidate or deceive a voter. Omission is a first-degree misdemeanor.

    Deadline: at_publication

  • data handlingFlorida AI Legislation (Deepfake and AI Disclosure Laws)Fla. Stat. § 836.13 (HB 757 / Brooke's Law)

    Do not willfully generate, solicit, promote, or possess with intent to promote an altered sexual depiction of an identifiable person without consent, including AI-generated deepfakes. Covered platforms must remove altered sexual depictions and known identical copies within 48 hours of a valid takedown request. Civil exposure includes $10,000 or actual damages for covered violations, plus FDUTPA penalties for takedown failures.

    Deadline: 48_hour_takedown

  • disclosureConnecticut Public Act 26-15 / SB 5 (Online Safety and AI Provisions)Public Act 26-15 (Sub. SB 5, An Act Concerning Online Safety)

    On and after October 1, 2026, an employer that conducts a layoff substantially caused or contributed to by an artificial intelligence system must provide the AI-related layoff notice required by Public Act 26-15. This is one of the earliest-effective private-sector duties in the Connecticut package and applies alongside the state's existing separation and mass-layoff notice obligations.

    Deadline: from_2026-10-01

  • consumer rightConnecticut Public Act 26-15 / SB 5 (Online Safety and AI Provisions)Public Act 26-15 (Sub. SB 5) — AI companion provisions

    On and after January 1, 2027, an operator of an AI companion (a system designed to simulate sustained human-like relationships with a user) must implement the Act's chatbot safety provisions, including protections for minors. These operator duties sit within the Act's broader youth online-safety framework and are enforced by the Attorney General as CUTPA violations.

    Deadline: from_2027-01-01

  • disclosureConnecticut Public Act 26-15 / SB 5 (Online Safety and AI Provisions)Public Act 26-15 (Sub. SB 5) — AEDT provisions

    For deployments of automated employment-related decision technology (AEDT) on or after October 1, 2027, a deployer must provide the Act's interactive disclosures and pre-decision written notice to affected individuals. The Attorney General may issue a 60-day cure notice for AEDT violations occurring through December 31, 2027, so the earliest AEDT-specific compliance work is a 2027 program task rather than a 2026 one.

    Deadline: from_2027-10-01

Framework controls

  • governanceNIST AI RMFGOVERN 1-6

    GOVERN function: establish policies, processes, structures, and accountability for AI risk management across the organization, including senior leadership oversight and a risk-based culture.

  • risk assessmentNIST AI RMFMAP 1-5

    MAP function: identify the context, intended uses, stakeholders, and risks of each AI system, including categorization of impacts on individuals, communities, and the organization.

  • risk assessmentNIST AI RMFMEASURE 1-4

    MEASURE function: assess, analyze, and monitor AI risks using both quantitative and qualitative methods, including bias evaluation, robustness testing, and explainability assessments.

  • governanceNIST AI RMFMANAGE 1-4

    MANAGE function: prioritize and treat identified risks, allocate resources, and implement risk response strategies including mitigation, transfer, acceptance, or avoidance.

  • governanceISO/IEC 42001Clauses 4-5

    Establish, implement, maintain, and continually improve an AI management system (AIMS) covering policies, leadership commitment, roles, and integration with other management systems.

  • risk assessmentISO/IEC 42001Clause 6 + Annex A.5

    Conduct AI system impact assessments and risk assessments addressing intended uses, deployment context, affected stakeholders, and mitigation of identified risks per Annex A.5 controls.

  • documentationISO/IEC 42001Clause 8 + Annex A.6

    Maintain documentation throughout the AI system lifecycle including data management, system development, verification and validation, and deployment per Annex A.6 controls.

  • transparencyISO/IEC 42001Clause 8 + Annex A.8

    Provide information to users and affected stakeholders about the AI system's intended use, capabilities, limitations, and how to interpret outputs per Annex A.8 controls.

Run AI risk and impact assessments faster with Credo AI

partner link

Specialized AI governance platform built around the NIST AI RMF and EU AI Act. Bias auditing, model registry, policy automation.

Get a Credo AI demo →
Legal disclaimer

This content is informational only and does not constitute legal advice. Laws change frequently and vary by jurisdiction. Consult qualified legal counsel before making compliance decisions. Information accuracy not guaranteed as of any specific date.

We may receive referral commissions from recommended compliance tools. Recommendations are based on product fit and not on commission size. Links marked “partner link” include a tracked redirect.