Rättskällor med officiella primärkällor

Utskrivet ·

Skip to main content
Skip to the answer

What must a US company document when it deploys an AI system?

No general federal statute sets the list. In practice the record is built on the four NIST functions, on the consumer protection rule that governs claims and uses, and on state statutes such as Colorado's, which requires impact assessments for high risk systems.

The answer differs between the federal level and the states, see the rows below.

The answer by level

  • Federal level

    There is no general federal AI statute. The framework is voluntary and organises the work in four functions: govern, map, measure and manage.

    NIST AI 100-1
  • Enforcement

    Claims about what an AI system does, and unfair uses of it, are treated as deception or unfairness under the general consumer protection rule.

    15 U.S.C. § 45
  • State level

    Colorado requires developers and deployers of high risk systems to use reasonable care against algorithmic discrimination, with documentation and impact assessments.

    Colorado SB24-205, Consumer Protections for Artificial Intelligence
  • European comparison

    The European regulation is binding and classifies systems by risk, with documentation, logging and human oversight duties for high risk systems.

    Regulation (EU) 2024/1689, the AI Act

Source lines

  • The NIST framework describes govern, map, measure and manage, and is explicitly voluntary.
  • Section 5 of the FTC Act prohibits unfair or deceptive acts or practices, which covers unsubstantiated claims about model performance.
  • Colorado SB24-205 imposes a duty of reasonable care on developers and deployers of high risk artificial intelligence systems.

What it means for the company

A buyer or regulator asks for the same four artefacts: what the system decides, what data it uses, how it was tested, and who can override it. Producing them later is far more expensive than recording them at deployment.

Comparison across levels and states
LevelRequirementSource
Federal levelThere is no general federal AI statute. The framework is voluntary and organises the work in four functions: govern, map, measure and manage.NIST AI 100-1
EnforcementClaims about what an AI system does, and unfair uses of it, are treated as deception or unfairness under the general consumer protection rule.15 U.S.C. § 45
State levelColorado requires developers and deployers of high risk systems to use reasonable care against algorithmic discrimination, with documentation and impact assessments.Colorado SB24-205, Consumer Protections for Artificial Intelligence
European comparisonThe European regulation is binding and classifies systems by risk, with documentation, logging and human oversight duties for high risk systems.Regulation (EU) 2024/1689, the AI Act

What it means for the individual

Where a system decides on employment, credit, housing or insurance, state law increasingly gives the individual notice and a route to contest the decision.

Source lines

  • NIST AI Risk Management Framework 1.0
    NIST AI 100-1 · read 2026-08-25 · proof fcd3414643260807
  • FTC Act Section 5, unfair or deceptive practices in AI and data
    15 U.S.C. § 45 · read 2026-08-25 · proof fcd3414643260807
  • Colorado General Assembly
    Colorado SB24-205, Consumer Protections for Artificial Intelligence · read 2026-08-25 · proof fcd3414643260807
    Official source
  • EUR-Lex, Publications Office of the European Union
    Regulation (EU) 2024/1689, the AI Act · read 2026-08-25 · proof fcd3414643260807
    Official source

Next step

Write one system card per deployed model that names the decision, the data, the test results and the named human who can override it.

All US questions

This page reports what the sources say, with the identifier and address of the publisher. It is not legal advice and does not decide an individual matter.

Next step

Three ways to put the register to work in your own practice.

Start with your task