Market · Markets

Delivering in the USA: The Rules Are Moving Underneath You, So Build to a Capability Rather Than a Rulebook

No federal privacy or AI law, a state patchwork that changed again in May 2026, and a federal executive order directing agencies to litigate against state AI laws. Designing to any single rulebook is the risk.

United States Updated 2026-08-10 726 words · about 3 min read

Every other market on this list has a direction of travel you can design against. The United States currently does not, and pretending otherwise is the most expensive mistake available here.

What actually happened in the last twelve months#

The Colorado AI Act was rewritten and delayed. Governor Polis signed SB 189 on 14 May 2026, moving the effective date from 30 June 2026 to 1 January 2027. More significantly, the replacement removes the hallmarks of the original: the duty of care, the risk management programme requirement and the impact assessments, in favour of a disclosure-based framework with limited rights.

Organisations that spent 2025 building a Colorado compliance programme built most of it for obligations that no longer exist.

The federal government moved against the states. A White House executive order of 11 December 2025, "Ensuring a National Policy Framework for Artificial Intelligence", directs federal agencies to challenge conflicting state AI laws through litigation and coordinated federal action.

So the position is: no federal privacy law, no federal AI law, an active state patchwork, and a federal posture in open conflict with parts of it.

What that means for how you build#

Do not design to a single state's rulebook. The Colorado experience is the argument. A programme built to one state's specific requirements can be invalidated by that state, and there are more states behind it moving in different directions.

Build instead to the capabilities that every version of every proposal has asked for, because those survive whichever way it lands:

  • Disclosure. The ability to tell a person an automated system was involved. Every framework, including the scaled-back Colorado one, keeps this.
  • Human review. A defined route for a person to contest or escalate a consequential decision.
  • Logging. Inputs, outputs, model and prompt version, who was affected. This is what any investigation asks for, under any regime.
  • Explanation. The ability to say why a decision came out as it did, at a level a non-specialist can follow.

Every one of those is defensible engineering regardless of the legal outcome, and none of it is wasted if the rules change again.

The obligations that are not moving#

While AI law churns, the sectoral rules are stable and are usually what actually binds:

  • HIPAA for anything touching health data
  • GLBA for financial services
  • State privacy laws, with California the most demanding, applying regardless of AI
  • FedRAMP for federal government workloads, which is a programme rather than a checkbox

For most commercial projects, these bite long before any AI-specific requirement does. A team worried about the Colorado AI Act while unclear on its HIPAA position has the risks in the wrong order.

How buying works#

Procurement is faster and more decentralised than in the Gulf or the UK. Budget authority sits lower in the organisation and pilots start with less ceremony. The counterweight is security review: enterprise buyers run a vendor security assessment that is frequently more demanding than anything a regulator asks, and SOC 2 comes up early.

What we would do differently here#

Sequence the sectoral rules first. HIPAA or GLBA exposure determines the architecture. AI-specific rules are currently the smaller constraint and the less stable one.

Build the four capabilities above regardless. They are good engineering, they are what an incident investigation needs, and they are the intersection of every proposal on the table.

Track the state you operate in, not the state in the headlines. The patchwork means the relevant question is narrow and specific.

Where we are honest about our limits#

We have no US office and no US legal capability. On multi-state exposure, and on anything turning on the reading of a specific state statute, you need US counsel and we will say so rather than improvise. We are also not currently FedRAMP-authorised, which rules us out of federal workloads.

Where we are useful is the engineering: building the disclosure, logging, human-review and explanation capability that every version of these rules requires.

Start here#

AI Readiness Assessment to establish the position including the regulatory one. AI Agent Implementation if the use case is chosen, since the guardrail set we build is exactly the capability described above.

Sources#

What else is coming for United States

Market brief Ready

What is genuinely different here.