AI regulatory jurisdiction splits across FDA, DOT, Treasury, SEC, and the states. That fragmentation is the central fact any company entering the US market needs to plan around.
The most common mistake companies make when entering the US AI market is looking for the agency. The one regulator with jurisdiction over their product. The single approval they need to operate.
That agency does not exist. And understanding why it does not exist is the first step toward building a regulatory strategy that actually works.
The United States does not have a dedicated AI regulatory agency. What it has is a collection of sector-specific agencies, each of which has claimed — or is in the process of claiming — jurisdiction over AI applications that touch their domain.
The result is a fragmented landscape where your regulatory exposure depends entirely on what your AI does, not on the fact that it is AI.
FDA has jurisdiction over AI used in clinical decision-making, diagnostic tools, and anything that qualifies as a medical device under the Federal Food, Drug, and Cosmetic Act. The agency has issued guidance on AI/ML-based software as a medical device and is actively developing a framework for continuous learning systems.
DOT and NHTSA govern AI in transportation — autonomous vehicles, advanced driver assistance systems, and AI-enabled logistics platforms. The regulatory picture here is complicated by the fact that NHTSA's authority is primarily safety-focused, while state governments retain significant authority over vehicle operation on public roads.
Treasury, OCC, and CFPB have overlapping jurisdiction over AI in financial services. The OCC has issued guidance on model risk management that applies to AI-driven underwriting and credit decisions. The CFPB has signaled aggressive interest in algorithmic fairness in consumer lending. Treasury is developing a broader AI risk framework for the financial sector.
SEC has jurisdiction over AI used in investment advice, trading systems, and financial disclosures. The agency has proposed rules on predictive data analytics that would significantly affect how AI-driven platforms interact with retail investors.
Federal agency jurisdiction is only part of the picture. State governments have moved aggressively on AI regulation in areas where federal law is silent or ambiguous.
Fourteen states have active AI-related statutes or regulations as of mid-2026. The areas of most activity: automated decision-making in employment, AI in healthcare settings, algorithmic transparency requirements, and data privacy frameworks that directly affect how AI systems can be trained and deployed.
The important point is that state AI statutes do not wait for federal preemption. A company that has navigated FDA clearance for a clinical AI tool still needs to assess whether the states where it operates have additional requirements around data use, algorithmic auditing, or patient notification.
The fragmentation of AI regulatory jurisdiction has a direct implication for how companies should sequence their US market entry.
Identify your primary federal regulator first. Every AI application has a dominant regulatory home, even if it also touches other agencies. A clinical AI tool is primarily an FDA matter, even if it also implicates HIPAA and state health data law. Identifying the primary regulator determines where your compliance investment needs to be deepest.
Map the secondary exposure. Most AI applications have secondary regulatory exposure that is easy to underestimate. A financial AI tool that also uses health data has both SEC/CFPB and HIPAA exposure. A transportation AI that collects biometric data has both NHTSA and state biometric privacy exposure. Secondary exposure does not always require the same depth of engagement as primary exposure, but it needs to be mapped.
Prioritize states by market importance and regulatory activity. Not all state AI statutes are equally consequential. A company entering the Northeast Corridor needs to understand New York's AI governance posture differently than it needs to understand Wyoming's. State prioritization should be driven by where your customers are, where your data flows, and where regulatory activity is most concentrated.
Build the federal-state picture before you build the compliance program. The most expensive compliance mistakes happen when companies build programs around a single regulator and then discover, after launch, that they have exposure they did not account for. The mapping work is cheaper than the remediation.
The absence of a single AI regulator is not a gap in the regulatory system. It is a structural feature of how the United States regulates technology — through existing sector-specific frameworks, extended to cover new applications as they emerge.
For companies entering the US market, that structure means the regulatory question is never simply "is this AI legal?" It is always "which agencies have jurisdiction over what this AI does, in which states, and what does each of them require?"
Answering that question accurately, before you build your compliance program, is the work that determines whether your US entry is orderly or reactive.
Next Step
Discuss how this affects your regulatory position