U.S. Government AI Policies: Latest Regulatory Updates
Between January 2025 and early 2026, the federal government issued multiple executive orders on AI and put forward a national legislative framework, while sector regulators in finance, healthcare, and insurance advanced their own enforcement priorities. For enterprises deploying AI in production, two compliance tracks now run simultaneously, evolving federal standards and sector-specific rules, and neither is waiting for the other.
Key takeaways
- Federal AI policy shifted decisively toward innovation, with a unified framework designed to override conflicting state laws
- Key actions: Executive Order 14179 (January 2025), the "Winning the Race" AI Action Plan (July 2025), and the National AI Legislative Framework (March 2026)
- The March 2026 framework sets seven objectives covering child safety, intellectual property, free speech, workforce, and federal preemption
- Compliance is two-layered: federal standards plus sector rules from HHS, OCC, and state insurance regulators
- Building governance infrastructure now beats playing catch-up under pressure once final rules land
How did the federal policy arc unfold?
Executive Order 14179 (January 23, 2025), "Removing Barriers to American Leadership in Artificial Intelligence," revoked the prior administration's AI executive order and directed agencies to eliminate regulatory barriers to AI adoption. The July 2025 "Winning the Race: America's AI Action Plan" framed AI as a national competitiveness issue, emphasizing innovation infrastructure, international engagement, and accelerated deployment. The March 2026 National AI Legislative Framework then proposed a unified federal approach intended to supersede the growing patchwork of state AI laws.
What do the framework's seven objectives cover?
The legislative framework organizes federal priorities across child safety protections, intellectual property treatment of AI training and outputs, free speech considerations in AI moderation, workforce and economic measures, innovation and infrastructure investment, national security, and, most consequentially for enterprises, federal preemption of conflicting state AI laws.
What's the state of the federal vs. state preemption battle?
Unresolved, and that's the operational point. States have continued legislating (over 1,500 AI bills introduced across 45 states by March 2026), insurance regulators continue applying the NAIC framework, and California's ADMT rules approach enforceability, while federal preemption remains proposed rather than enacted. Until it resolves, enterprises must comply with the strictest applicable layer.
What does this mean for enterprises in regulated industries?
Sector obligations didn't pause: HHS expectations for AI in HIPAA risk analyses, OCC and Fed model-risk supervision, and state insurance AI bulletins all remain in force and actively enforced. The practical strategy is regulatory-change-resilient infrastructure: policy-driven runtime governance where new rules become policy updates rather than re-architectures, with per-decision audit evidence that satisfies whichever layer asks. That is the design point of Trussed AI's control plane, framework-mapped policies, runtime enforcement, automatic evidence, so compliance posture survives the policy churn.
How do you stay compliant as policy evolves?
Track both layers (federal direction and binding sector/state rules); inventory AI systems against current obligations; enforce policies at runtime so changes deploy in days; and keep evidence continuous so any regulator's question is answerable from records.
Frequently Asked Questions
Should we wait for federal preemption before investing in compliance? No, sector and state rules bind today, and the infrastructure (inventory, enforcement, evidence) is identical under any final framework.
Does the innovation-first federal posture reduce our obligations? It shapes future rule-making; it doesn't repeal HIPAA, fair lending law, NAIC expectations, or state privacy statutes that already govern AI use.
What's the lowest-regret move right now? Runtime governance with policy-driven controls, every plausible regulatory outcome requires the same foundation.
Related resources
Ready to govern your AI in production?