State lawmakers introduced far more artificial intelligence legislation in 2025 than in the two prior years combined. State lawmakers in all 50 states introduced 1,208 AI-related bills that year, the first time every state had introduced at least one AI-related bill, and 145 of those bills were enacted into law. At the same time, the Federal Trade Commission (FTC) has kept prosecuting companies for overstating AI capabilities, and the European Union's AI Act already carries fines reaching into the tens of millions of euros for covered violations. No single comprehensive federal AI law exists yet in the United States, but the absence of one national statute does not mean AI use sits outside the reach of regulation.
AI compliance, in practical terms, means three connected things: an internal governance policy that defines how AI tools get evaluated and used, security controls that protect data flowing into and out of AI systems, and active tracking of the state, sector, and international rules that already apply. Corporate AI compliance today is less about a single checklist and more about a management discipline, similar to how privacy or security programs matured before a comprehensive federal law arrived. Businesses adopting AI tools ahead of formal national regulation face exposure now, through consumer protection law, state privacy statutes, and sector-specific rules, not just through hypothetical future legislation.
What Does AI Compliance Actually Mean Right Now?
AI compliance management, absent one binding federal framework, means voluntarily adopting recognized risk practices and layering them against a patchwork of state and international rules that already carry legal force. The most widely referenced voluntary reference point is the National Institute of Standards and Technology (NIST) AI Risk Management Framework (AI RMF). The Framework is intended for voluntary use and is designed to improve the ability to incorporate trustworthiness considerations into the design, development, use, and evaluation of AI products, services, and systems. It was released on January 26, 2023, developed through a consensus-driven, open, and collaborative process that included a public request for information, several draft versions, and multiple workshops.
The NIST AI RMF has no enforcement mechanism attached to it. Adopting it does not satisfy any specific law on its own. What it does provide is a structured vocabulary and process for organizing an AI governance and compliance program: identifying AI use cases, mapping risks, measuring outcomes, and assigning ongoing management responsibility. Regulators and auditors increasingly expect to see some version of this structure even where no statute mandates it by name.
The Regulatory Patchwork Already in Force
California's AI governance rules already involve several enacted state laws that took effect on staggered timelines through 2026, not a single future deadline. Three California statutes now govern generative AI directly. The Generative AI Training Data Transparency Act (AB 2013) requires developers of generative AI systems to publish high-level training data documentation, effective January 1, 2026. The Transparency in Frontier AI Act (SB 53) requires frontier model developers to publish safety protocols, report critical safety incidents, and maintain whistleblower protections, effective January 1, 2026, with penalties up to $1 million per violation. The California AI Transparency Act, originally set for January 2026, was pushed back; Chapter 25 became operative on August 2, 2026, requiring large generative AI providers to offer detection tools and content disclosures.
Separately, the California Privacy Protection Agency (CPPA) finalized rules on Automated Decision-Making Technology (ADMT) that reach far beyond generative AI chatbots. These regulations go into effect January 1, 2026, though businesses get additional time to comply with some requirements, including cybersecurity audits, risk assessments, and rules specific to automated decision-making technology. For employers specifically, related rules taking effect January 1, 2027 impose some of the most stringent requirements in the United States on how employers use artificial intelligence and automated tools in employment decisions. A business using AI to screen resumes, score creditworthiness, or evaluate performance reviews falls squarely inside this rule, regardless of whether it calls the tool "AI" internally.
State AI laws vary widely in scope and timeline, and Colorado's experience shows how volatile this landscape remains. The state passed the first comprehensive state AI law in 2024, then delayed it repeatedly amid industry pushback. On May 14, 2026, Colorado Governor Jared Polis signed SB 26-189, which replaces the state's previous AI law with a streamlined framework focused on transparency and disclosure. Companies operating in multiple states cannot assume a law announced today will look the same by the time it takes effect.
For businesses with any European exposure, the EU AI Act adds another layer. The Act entered into force on August 1, 2024 and became applicable in phases, with prohibited AI practices and AI literacy obligations entering into application on February 2, 2025, and governance rules for general-purpose AI models applying from August 2, 2025. Penalties for the most serious violations are steep: competent authorities may impose administrative fines up to EUR 35 million or 7 percent of global annual turnover for infringements relating to prohibited AI practices.
Regulatory Exposure Does Not Wait for New AI Laws
Existing consumer protection law already reaches deceptive AI marketing claims, without any AI-specific statute needed. The FTC has made this explicit through sustained enforcement. On September 25, 2024, the FTC announced a new enforcement sweep, Operation AI Comply, targeting companies that exaggerated or made deceptive claims about their use of AI. That effort has continued well past its launch, and the agency brought at least a dozen AI-washing cases in 2025 targeting companies that misrepresented the capabilities of AI-powered products or made misleading claims tied to artificial intelligence features. The agency's enforcement authority in these cases derives primarily from Section 5 of the FTC Act, which prohibits unfair or deceptive acts or practices, without requiring the passage of AI-specific legislation.
This matters for a healthcare technology company describing a clinical decision-support feature as AI-driven, or a software-as-a-service (SaaS) vendor marketing an AI-powered analytics dashboard. If the underlying technology cannot support the claim, or if performance data does not substantiate the marketing language, exposure exists under laws already on the books.
Building an AI Compliance Management Program
An effective AI compliance program starts with visibility into what AI tools are already running inside an organization, since most companies underestimate the count. A workable starting structure includes:
- An inventory of every AI tool in use, including embedded features inside existing software and tools adopted by individual teams without central review
- A risk tier for each use case, distinguishing low-risk uses like drafting internal documents from higher-risk uses like employment screening or medical documentation
- A written governance policy defining who approves new AI tools, what data can be shared with them, and how outputs get reviewed before reaching customers or regulators
- Vendor review procedures for AI providers, covering data handling, training data sources, and contractual liability
- A monitoring process for tracking applicable state, sector, and international rules as they change
Security controls belong inside this same program rather than as a separate afterthought. Data shared with AI tools, especially customer records, health information, or proprietary source code, needs the same access controls, encryption, and retention limits applied to any other sensitive system. Shadow AI use, where employees adopt consumer AI tools without approval, represents one of the more common gaps found during security assessments of small and mid-sized organizations.
AI compliance is not a future obligation waiting for a single federal law to arrive. It is a present-day discipline built from governance policy, data security controls, and ongoing attention to a regulatory landscape that continues shifting across states and internationally. Businesses that treat AI governance and compliance as an ongoing management function, rather than a one-time project, tend to adapt more easily as new rules take effect and old ones get rewritten.
Planet 9 is a Bay Area cybersecurity consulting firm providing AI risk governance for SMBs in healthcare, SaaS, and technology. Our vCISOs and compliance managers help organizations build AI governance policies, configure the right controls, and stay ahead of regulatory exposure.





