AI Deployer Obligations Under US Law
Deployers operate AI systems to make or substantially factor into decisions affecting consumers, employees, or other regulated parties. Most US state AI laws place the heaviest compliance burdens on deployers, including impact assessments, disclosures, and post-deployment monitoring.
Governance routing
Use the AI governance guide to assign decision rights, committees, lifecycle gates, and escalation paths before mapping role-specific duties into the AI compliance framework register.
Obligations under US laws
Before using a covered ADMT to materially influence a consequential decision, provide a clear and conspicuous notice to the consumer that automated decision-making technology is or will be used in a consequential decision affecting them, with instructions for obtaining further information; a prominent public notice kept reasonably accessible at points of consumer interaction satisfies this requirement.
Deadline: before_decision
When a covered ADMT materially influences a consequential decision that results in an adverse outcome, provide the consumer, within 30 days of the decision, a plain-language description of the decision and the role the ADMT played, a simple process to request additional information (the system's name, version, developer, and the types, categories, and sources of personal data used), and an explanation of the consumer's correction and human-review rights under § 6-1-1705.
Deadline: within_30_days_of_adverse_outcome
On request from a consumer who experiences an adverse outcome, provide instructions to access and correct factually incorrect or materially inaccurate personal data used in the consequential decision (consistent with C.R.S. § 6-1-1306) and an opportunity for meaningful human review and reconsideration of the decision to the extent commercially reasonable; correction is not required for opinions, predictions, scores, or protected evaluations.
Deadline: on_consumer_request
Retain, for at least three years after a consequential decision, the records reasonably necessary to demonstrate compliance with Part 17 of article 1 of title 6 — including covered-ADMT version identifiers, changelogs, and documentation of material mitigation changes.
Deadline: retain_3_years
- disclosureTexas Responsible Artificial Intelligence Governance Act (TRAIGA)Tex. Bus. & Com. Code § 552.051
Provide clear and conspicuous disclosure to consumers when they are interacting with an AI system in a manner where a reasonable consumer might believe they are interacting with a human.
Deadline: at_interaction
- governanceTexas Responsible Artificial Intelligence Governance Act (TRAIGA)Tex. Bus. & Com. Code § 552.104, § 552.105
On receipt of a written notice of alleged violation from the Texas Attorney General, cure the violation within the statutory cure window to avoid tier-1 civil penalties of $10,000–$12,000; uncurable violations and continuing violations escalate to $80,000–$200,000 per violation and $2,000–$40,000 per day under § 552.105.
Deadline: on_ag_notice
- governanceTexas Responsible Artificial Intelligence Governance Act (TRAIGA)Tex. Bus. & Com. Code § 552.106
Licensed, registered, or certified persons remain separately subject to discipline by their Texas licensing authority, including sanctions of up to $100,000, in addition to civil penalties imposed by the Attorney General under § 552.105.
Deadline: ongoing
Subject the Automated Employment Decision Tool to an annual independent bias audit calculating selection rates and impact ratios across race/ethnicity and sex categories prior to use, then on a yearly basis.
Deadline: annually
Publicly post a summary of the most recent bias audit results on the employer's website, including the date the AEDT was first used and the source of the data.
Deadline: ongoing
Provide candidates and employees who reside in NYC with at least 10 business days advance notice of AEDT use, including job qualifications, characteristics assessed, and instructions for requesting an alternative selection process or reasonable accommodation.
Deadline: 10_business_days_before_use
Refrain from using AI that has the effect of subjecting employees or applicants to discrimination on the basis of protected classes under the Illinois Human Rights Act in employment decisions.
Deadline: ongoing
Provide notice to employees and applicants when AI is being used to make employment-related decisions covered by the amended IHRA.
Deadline: at_use
A supplier using generative AI in a consumer transaction must disclose that the individual is interacting with generative AI and not a human when the individual makes a clear and unambiguous request about whether AI is being used; regulated-occupation providers must prominently disclose GenAI use for high-risk AI interactions, verbally at the start of verbal interactions or in writing before written interactions.
Deadline: on_clear_request_or_before_regulated_service_interaction
Maintain accountability for consumer-protection compliance when generative AI makes a violative statement, undertakes a violative act, or is used in furtherance of a violation; Chapter 77 states that generative AI is not a defense to statutes administered and enforced by the Division of Consumer Protection.
Deadline: ongoing
If enacted, an employer or employment agency using an AEDT would have to notify each covered individual at least 10 business days before use through a website employment section, job posting, written policy, U.S. mail, or electronic mail, depending on whether the person is a candidate or employee.
Deadline: proposed_10_business_days_before_use
If enacted, an employer using an AEDT would have to provide covered individuals, within 30 days after use, notice that the tool was used, the job qualifications or characteristics assessed, data sources, retention policy, tool name, vendor, and enough adverse-outcome information to contest the employment decision.
Deadline: proposed_within_30_days_after_use
If enacted, an employer or employment agency would have to publish the most recent bias-audit date and results on its employment website in accessible, machine-readable, downloadable form, keep the summary posted for at least 10 years after the latest AEDT use, and issue a press release when the report is made publicly available.
Deadline: proposed_post_for_10_years_after_latest_use
Include a clear and conspicuous disclaimer on any political advertisement that uses generative AI to depict a real person performing an action that did not occur, where the advertisement is intended to injure a candidate or deceive a voter. Omission is a first-degree misdemeanor.
Deadline: at_publication
- data handlingFlorida AI Legislation (Deepfake and AI Disclosure Laws)Fla. Stat. § 836.13 (HB 757 / Brooke's Law)
Do not willfully generate, solicit, promote, or possess with intent to promote an altered sexual depiction of an identifiable person without consent, including AI-generated deepfakes. Covered platforms must remove altered sexual depictions and known identical copies within 48 hours of a valid takedown request. Civil exposure includes $10,000 or actual damages for covered violations, plus FDUTPA penalties for takedown failures.
Deadline: 48_hour_takedown
- disclosureConnecticut Public Act 26-15 / SB 5 (Online Safety and AI Provisions)Public Act 26-15 (Sub. SB 5, An Act Concerning Online Safety)
On and after October 1, 2026, an employer that conducts a layoff substantially caused or contributed to by an artificial intelligence system must provide the AI-related layoff notice required by Public Act 26-15. This is one of the earliest-effective private-sector duties in the Connecticut package and applies alongside the state's existing separation and mass-layoff notice obligations.
Deadline: from_2026-10-01
- consumer rightConnecticut Public Act 26-15 / SB 5 (Online Safety and AI Provisions)Public Act 26-15 (Sub. SB 5) — AI companion provisions
On and after January 1, 2027, an operator of an AI companion (a system designed to simulate sustained human-like relationships with a user) must implement the Act's chatbot safety provisions, including protections for minors. These operator duties sit within the Act's broader youth online-safety framework and are enforced by the Attorney General as CUTPA violations.
Deadline: from_2027-01-01
- disclosureConnecticut Public Act 26-15 / SB 5 (Online Safety and AI Provisions)Public Act 26-15 (Sub. SB 5) — AEDT provisions
For deployments of automated employment-related decision technology (AEDT) on or after October 1, 2027, a deployer must provide the Act's interactive disclosures and pre-decision written notice to affected individuals. The Attorney General may issue a 60-day cure notice for AEDT violations occurring through December 31, 2027, so the earliest AEDT-specific compliance work is a 2027 program task rather than a 2026 one.
Deadline: from_2027-10-01
Framework controls
GOVERN function: establish policies, processes, structures, and accountability for AI risk management across the organization, including senior leadership oversight and a risk-based culture.
MAP function: identify the context, intended uses, stakeholders, and risks of each AI system, including categorization of impacts on individuals, communities, and the organization.
MEASURE function: assess, analyze, and monitor AI risks using both quantitative and qualitative methods, including bias evaluation, robustness testing, and explainability assessments.
MANAGE function: prioritize and treat identified risks, allocate resources, and implement risk response strategies including mitigation, transfer, acceptance, or avoidance.
Establish, implement, maintain, and continually improve an AI management system (AIMS) covering policies, leadership commitment, roles, and integration with other management systems.
Conduct AI system impact assessments and risk assessments addressing intended uses, deployment context, affected stakeholders, and mitigation of identified risks per Annex A.5 controls.
Maintain documentation throughout the AI system lifecycle including data management, system development, verification and validation, and deployment per Annex A.6 controls.
Provide information to users and affected stakeholders about the AI system's intended use, capabilities, limitations, and how to interpret outputs per Annex A.8 controls.
We may receive referral commissions from recommended compliance tools. Recommendations are based on product fit and not on commission size. Links marked “partner link” include a tracked redirect.