← All briefings
Briefing 17 · U.S. Federal AI Posture

The federal AI floor receded. State law is what binds now.

If you’re waiting for a federal AI law to tell you what to do, the signal in 2026 is unambiguous: don’t. Over the last eighteen months the federal government has pulled back — rescinding guidance, narrowing enforcement theories, and actively trying to preempt the state laws that moved into the vacuum. Here is the honest map of what changed, what still binds, and why your compliance center of gravity is now the states.

What the agencies pulled back

The retreat is broad. The EEOC removed its 2022 (ADA) and 2023 (Title VII) technical-assistance documents on AI in hiring in January 2025, and an April 2025 executive order directed agencies to deprioritize disparate-impact enforcement. The FTC, under Chair Andrew Ferguson, shifted to a lighter touch, took down Khan-era AI blog posts, and wound down “Operation AI Comply.” The CFPB’s April 2026 final rule eliminated disparate-impact theory under ECOA/Regulation B for federal enforcement and narrowed related liability. The federal agencies that a year ago looked like AI’s enforcers have stepped back.

What still binds federally

The statutes didn’t disappear. Title VII, the ADA, the ADEA, the Fair Housing Act, and ECOA remain on the books and continue to bind employers and lenders using AI — guidance was withdrawn, not the underlying law. FTC Act §5’s prohibition on deceptive and unfair practices is very much alive and reaches false or unsubstantiated AI claims — deception is the one clearly live federal theory today. And what one administration deprioritizes, another can reactivate; the exposure is dormant, not deleted.

The preemption offensive

This is the part most companies miss. A December 11, 2025 executive order stood up a DOJ AI Litigation Task Force (launched January 10, 2026) to challenge state AI laws, directed Commerce to flag “onerous” state measures, and singled out Colorado’s AI Act by name. Congress had already defeated a proposed ten-year moratorium on state AI laws in 2025. So the federal government isn’t writing an AI rulebook — it’s trying to stop the states from having one. That makes the state-law layer both more important (it’s what binds) and less certain (some of it may be litigated).

What this means for you

Three conclusions follow. First, state and local law is now the binding layer — which is why our register tracks more than twenty U.S. instruments across eight-plus states plus New York City. Second, don’t build only to a single rule that could be enjoined; anchor to a framework-based governance posture — NIST AI RMF, ISO/IEC 42001 — that survives whichever way federal policy swings. Third, watch the preemption docket: a state law you’re relying on could be challenged, and one you’re ignoring could turn out to be all that binds.

Do these three things now

1. Stop waiting for a federal AI law — comply to state and local law today. 2. Anchor to a framework (NIST AI RMF / ISO 42001) that is administration-proof. 3. Monitor the DOJ task force and the preemption litigation so you know which state rules are contested.

The federal floor receded; the anti-discrimination statutes survived but their AI-specific enforcement did not, and the federal government is now actively trying to preempt the states. The companies that stay defensible are the ones that build to a durable framework and treat the state register — not a hoped-for federal law — as the thing that binds.

This briefing is general information from Sentinel Assurance Group, not legal advice. Regulatory dates and requirements change — we maintain these briefings, but verify against primary sources and counsel before acting. Last reviewed July 22, 2026.

See how a Gap Assessment maps your exposure →

Not sure which of these reach you?
Find out in 30 minutes.

The free AI Risk Exposure call maps your AI footprint to the obligations that actually apply — and the ones that don’t.

Book the call →