This is Part Two of a two-part series. Part One is available here.
U.S. law in the area of artificial intelligence is fragmented, consisting of state laws, local regulations, and existing laws regarding privacy and discrimination. Even as the regulatory environment is becoming more hospitable for businesses, the legal risk remains significant, particularly in high-impact and rights use cases.
Transparency is a common denominator. Across jurisdictions, AI regulation appears to be focusing on (1) disclosure of AI use, (2) the ability to explain consequential decisions, and (3) consumer notice and appeal rights.
This trend is evident in both Colorado’s revised law (discussed in Part One), as well as regulation in the European Union.
Even as comprehensive AI regulations retreat from stringent prohibitions on discrimination, U.S. states are enacting highly-focused AI laws, especially in areas that affect individual rights, including hiring, lending, and health care. Although there is no omnibus federal legislation, federal agencies -- including the Equal Employment Opportunity Commission, the Federal Trade Commission, and the Department of Health and Human Services -- have released AI guidance.
In the employment context, we expect regulators and agencies to continue to focus on algorithmic discrimination, bias auditing and testing, and fairness with or without prescriptive governance requirements.
Recommended steps for businesses
Organizations using AI should adopt compliance strategies that include the following:
No. 1: Inventory AI systems. Companies should begin by conducting a comprehensive inventory of all AI and automated decision-making systems used across the organization. This includes not only internally developed tools, but also third-party systems embedded in Human Resources, customer service, marketing, fraud detection, and analytics platforms. Particular attention should be paid to systems used in making “consequential decisions” (for example, hiring, lending, pricing, or access to services), because these uses are most likely to trigger regulatory obligations. The inventory should identify the purpose, inputs and outputs, and data sources of the system, and whether human oversight is involved.
No. 2: Adopt internal governance programs. Organizations should establish internal AI governance programs that define roles, responsibilities, and escalation procedures for AI-related risks. Many companies are aligning with recognized programs such as the AI Risk Management Framework of the National Institute of Standards and Technology, which provides guidance on risk identification, measurement, and mitigation. At a minimum, governance programs should include policies for acceptable AI use, procedures for approving new AI deployments, and documentation standards to demonstrate accountability.
No. 3: Conduct risk and bias assessments. Even if not required by an AI law to do so, companies should evaluate their AI systems for risks related to bias, discrimination, accuracy, and unintended outcomes. For example, employers using AI in hiring should assess whether the system has a disparate impact on protected classes. These assessments may include statistical testing, validation studies, and periodic re-evaluation as systems evolve. Documenting these efforts can be critical in defending against regulatory inquiries or litigation.
No. 4: Ensure transparency. Businesses should put into place clear and consistent disclosure practices regarding their use of AI, particularly where systems influence decisions affecting individuals. This may include providing advance notice that AI is being used, explaining in general terms how the system operates, and offering explanations for adverse decisions where feasible. Internally, companies should also maintain documentation that explains how key decisions are made and what role AI plays in those processes.
No. 5: Monitor regulatory developments. Given the rate of change, companies should establish a process for ongoing monitoring of legal developments at the state, federal, and international levels. This includes keeping up with developments in jurisdictions such as Colorado, California, and New York, as well as in the European Union. Assigning responsibility to legal or compliance personnel -- or engaging outside counsel -- can help to ensure that the organization remains current and avoids being caught off guard by new obligations.
No. 6: Review vendor contracts. Because many AI systems are provided by third-party vendors, companies should carefully review and, where necessary, renegotiate contracts to address compliance responsibilities. Agreements should clearly allocate responsibility for issues such as bias audits, data protection, and regulatory compliance. They should also contain clear provisions addressing indemnification.
The Constangy Cyber Team assists businesses of all sizes and industries with compliance needs. If you would like additional information about state or federal data privacy laws, please contact us at cyber@constangy.com.
- Senior Counsel
Amanda has substantial experience advising clients on compliance with data privacy and information security laws and regulations. She serves as co-chair of Constangy's Artificial Intelligence Practice, where she helps ...
- Associate Attorney
Kimberly leads clients through high‑impact cyber events, including ransomware attacks, business email compromises, network intrusions, and insider‑driven data theft, overseeing forensic investigations, remediation ...
The Constangy Cyber Advisor posts regular updates on legislative developments, data privacy, and information security trends. Our blog posts are informed through the Constangy Cyber Team's experience managing thousands of data breaches, providing robust compliance advisory services, and consultation on complex data privacy and security litigation.



