AI agent governance in the United States
The United States has no comprehensive federal AI statute. Agent governance is set by a state patchwork layered on long-standing federal sectoral supervision — and, unusually, at least one state offers an affirmative defence to organisations that follow a recognised risk framework.
Get an Agent Trust Gap BriefThe short answer
There is no single US answer, which is precisely the operational problem. A national deployment touches several state regimes at once, plus whichever federal regulator supervises your sector. The regimes disagree on definitions and thresholds but converge on three demands: disclose when a person is dealing with AI, manage risk against a documented framework, and be able to explain a consequential decision.
The affirmative-defence pattern is the one worth understanding. Texas TRAIGA provides a defence for organisations that comply with a recognised risk framework such as the NIST AI RMF. That converts a voluntary framework into something with litigation value — and it means your framework conformance evidence is not a compliance nicety, it is a legal asset.
The instruments that actually bind
Named, dated, and separated from the guidance that carries no force of law. Where an instrument does not mention agents directly, that is stated rather than implied away.
| Instrument | Scope | Bearing on agents |
|---|---|---|
| Texas TRAIGA | State AI statute with an affirmative defence tied to recognised risk frameworks. | Documented NIST AI RMF conformance becomes evidence you can rely on. Makes framework-mapping worth doing properly. |
| Colorado SB 26-189 | Consequential-decision duties for developers and deployers. | Impact assessment and notice duties where an agent influences consequential decisions — employment, lending, housing, healthcare, insurance. |
| California transparency measures | Disclosure and transparency obligations. | Where an agent interacts with a person or generates content, disclosure duties are the first thing to check. |
| NYDFS guidance | New York financial services cybersecurity supervision. | AI-specific risk expectations layered on existing cybersecurity rules for covered entities. |
| SR 11-7 | Federal Reserve model risk management guidance. | Predates AI entirely and still governs. Model inventory, validation, and ongoing monitoring — an agent making decisions is a model with an actuator. |
| NIST AI RMF | Voluntary framework: Govern, Map, Measure, Manage. | No certification exists. Its value is as the reference frameworks and statutes point back to — including TRAIGA's defence. |
Last verified 2026-08-07. This is a summary of published instruments for orientation, not legal advice. Obligations depend on your role, deployment and sector — confirm against the primary text and your counsel.
What this means for an agent deployment
Regulation in this region does not generally name "AI agents". It names outcomes: traceability, human oversight, accountability for automated decisions, incident reporting. An agent that acts — books, pays, sends, changes records — has to produce evidence of those properties on demand.
- Map to NIST AI RMF and keep the evidence. It is voluntary, uncertifiable, and the closest thing to a common denominator across state regimes and at least one affirmative defence.
- Inventory agents as models. In supervised financial institutions, SR 11-7 expectations attach whether or not anyone calls the system a model. An inventory you maintain beats one an examiner builds for you.
- Build consequential-decision notice into the flow. Where an agent influences employment, credit, housing, insurance or healthcare outcomes, notice and explanation duties surface fast.
- Disclose the machine. The cheapest compliance win across states is being unambiguous when a person is interacting with an agent rather than a human.
- Keep per-state applicability in one table. Deployments break when nobody owns the question of which state law applies to which workflow.
Common questions
Is there a federal AI law in the United States?
No comprehensive statute. Governance comes from state law plus federal sectoral supervision — banking, insurance, healthcare, employment — much of which predates AI and applies anyway.
What is the TRAIGA affirmative defence?
Texas TRAIGA provides a defence for organisations that comply with a recognised AI risk framework such as the NIST AI RMF. It gives documented framework conformance direct legal value, which is unusual for a voluntary framework.
Does SR 11-7 apply to AI agents?
If you are a supervised institution and the agent informs or makes decisions, examiners will treat it within model risk management expectations: inventory, validation, monitoring, and documented limitations.
Which state should we design for first?
Design for the strictest requirement in your actual deployment footprint, then document per-state applicability. Designing for the loosest and patching later is how organisations end up rebuilding.
Does NIST AI RMF certification exist?
No. There is no certification body and no certificate. Anyone offering NIST AI RMF certification is selling something that does not exist. What you can hold is documented conformance evidence.
What a regulator or plaintiff asks in the US
The control set barely changes across jurisdictions; the interrogation does. These are the instruments an examiner cites here, and the question each one turns into.
| Instrument | Status | What the examiner actually asks |
|---|---|---|
| Texas TRAIGA | Effective 2026; affirmative-defence structure | Do you operate a documented governance program? It is the affirmative defence, so the evidence is the shield. |
| Sectoral law (FTC, HIPAA, GLBA) | In force | No AI statute is needed to bind an automated effect; which sectoral duty does this action touch and how is it evidenced? |
| State automated-decision rules | Emerging (CO, CA, others) | Is there notice, an opt-out, or an impact assessment obligation for this decision class? |
Instruments and dates as verified 2026-08-12. Not legal advice.