The central U.S. dispute over AI regulation is not only about how to make artificial intelligence safer. It is also about which level of government gets to decide what safe, fair and lawful AI looks like. A failed federal proposal in 2025 to limit state and local AI rules brought that conflict into public view. Although the measure did not become law, its defeat did not resolve the underlying issue: whether Congress should eventually create a national framework that overrides some state requirements.
The answer could affect how companies design and deploy AI products, how employers use automated hiring tools and what remedies consumers have when AI systems cause harm.
The federal proposal that exposed the divide
In May 2025, the House of Representatives passed a budget reconciliation bill containing a provision that would have barred states and local governments from enforcing many laws regulating AI models, AI systems and automated decision systems for 10 years. The proposal was widely described as an AI moratorium.
Its scope drew opposition from state officials, consumer advocates and others who argued that it could interfere with state rules involving consumer protection, employment, privacy, biometric data and online safety. The Senate later removed a revised version of the provision during its consideration of the legislation in July. The final law, signed on July 4, 2025, did not include the state-law restriction.
That outcome preserved existing state and local laws. It also left open the larger question of federal preemption: when federal law should override conflicting state or local requirements.
Why federal and state officials approach AI governance differently
Supporters of a national federal AI policy argue that a state-by-state system can be difficult to manage. A company may offer the same hiring software, chatbot, fraud-detection tool or image-generation service in every state. Different rules for notices, audits, documentation and restricted uses can create legal uncertainty and require separate compliance programs.
Those concerns extend beyond major technology companies. A hospital using automated scheduling software, a retailer deploying fraud-detection tools or a small business relying on a recruiting platform may face obligations tied to the systems they buy and use.
States, however, are concerned that broad federal preemption could eliminate protections without replacing them. Congress has not enacted a comprehensive artificial intelligence regulation law. Federal agencies can apply existing authorities in areas such as consumer protection, civil rights and sector-specific oversight, but those powers do not create one general AI rulebook.
State governments also regulate many of the settings in which AI is used, including employment, insurance, education, health care and elections. State officials argue that they need room to address emerging harms when federal action is incomplete or delayed.
State AI laws companies are already watching
The United States does not have a single general AI statute. Instead, AI governance is developing through existing laws and targeted state and local measures.
- Colorado’s AI Act creates obligations for developers and deployers of certain high-risk AI systems used in consequential decisions, including decisions related to employment, housing, financial services and health care. Its effective date is June 30, 2026.
- New York City’s automated employment decision tool law requires bias audits and notices for covered automated tools used in hiring and promotion decisions.
- Illinois’ Biometric Information Privacy Act governs the collection and use of biometric identifiers, making it relevant to facial recognition and other AI-enabled identity systems.
- California measures address selected AI-related issues, including disclosures concerning certain AI-generated content and documentation about AI training data.
- Tennessee’s ELVIS Act expanded protections against unauthorized uses of a person’s voice and likeness, an issue made more prominent by synthetic audio and deepfakes.
These measures do not form a unified code. They apply to different technologies, impose different duties and use different enforcement mechanisms. Together, however, they demonstrate why the federal-state conflict matters: many immediate AI rules are being developed outside Washington.
What one national standard could mean for business
A carefully written federal law could reduce duplication. Common definitions for high-risk AI, shared documentation practices and interoperable disclosure requirements could help companies build compliance processes that work across state lines. This could be especially useful for software vendors and organizations that rely on third-party AI systems.
National uniformity, however, is not automatically simpler. A broad preemption rule using vague terms such as “AI system” or “automated decision system” could generate litigation over which state laws remain enforceable. Courts might need to decide whether general consumer-fraud, privacy or employment laws still apply when they affect AI development or deployment.
For companies, these questions can affect product design. Disclosure labels, human-review procedures, bias testing, recordkeeping, complaint processes and vendor contracts may all become compliance issues under federal, state or local law.
Why workers and consumers have a direct stake
Automated hiring illustrates the practical consequences. AI tools can rank applicants, recommend candidates or analyze recorded interviews. Employers may view those systems as efficiency tools, while applicants may have limited information about how the tool was used, what data informed a decision or how to challenge an error.
Similar concerns arise when AI is used to detect fraud, assess insurance risk, set prices, moderate content or create realistic synthetic media. Existing laws may provide remedies in some circumstances, but many were not written specifically for modern AI systems. State AI laws and related measures often seek to address those gaps through notices, impact assessments, audit requirements or rights to contest certain decisions.
A federal preemption policy without equivalent protections could limit some state-level remedies. At the same time, a fragmented system can produce uneven protections, with a person’s rights varying based on where they live, work or seek services.
What happens next in AI regulation
The defeat of the 2025 moratorium means states and local governments may continue to legislate and enforce laws within their authority. Congress could revisit the issue through a standalone bill, sector-specific legislation or a broader national AI framework. Federal agencies will also continue to apply their existing authorities where AI practices fall within their jurisdiction.
Courts may shape the boundaries as well. Companies can challenge particular state measures on constitutional or federal-law grounds even without an explicit AI preemption statute. Meanwhile, state legislatures are continuing to consider rules involving automated decision-making, deepfakes, biometric data and AI consumer protection.
The institutional question behind the technology debate
The lasting issue is institutional as much as technological. The United States must decide whether it can create national consistency without preventing state experimentation, and whether it can preserve local remedies without making compliance unworkable.
That balance will influence not only the legal obligations of technology companies, but also how quickly workers, consumers and other affected people can seek recourse when automated systems affect their jobs, privacy, finances or reputations.