AI regulation explained poorly sounds like a morality play: either the government is about to “stifle innovation,” or it is about to “rein in Big Tech.” Neither sentence tells a procurement officer, a founder, or a congressional staffer what the text would actually do. U.S. AI policy news is full of bills, executive actions, agency requests for comment, and state statutes that use the same five words—safety, transparency, bias, security, accountability—while pointing at different targets.
I cover this beat the way I covered enterprise software: start with the operative clauses. Who is covered? What must they disclose or refrain from? Who enforces? Who pays when the rule is fuzzy? Those four questions do more work than any adjective in the title of the bill.
Question 1: Who Is Actually Covered?
Many proposals talk about “AI systems” as if that were a single object. It is not. A rule that covers a general-purpose model provider, a company that fine-tunes, a company that embeds an API, and a hospital that uses the output for triage is a rule with four different compliance departments.
Scope fights are not academic. A definition that turns on “high-risk use” will pull in credit, employment, housing, health, and some public benefits. A definition that turns on “frontier model training compute” will pull in a handful of labs and their cloud partners. A definition that turns on “automated decision-making” may already overlap with existing state privacy and employment laws.
Scope tells you the politics
Broad consumer-facing scope tends to mobilize civil-rights and consumer groups.
Compute or model-size thresholds tend to mobilize labs and cloud providers.
Sector-specific rules tend to mobilize banks, hospitals, insurers, and their regulators.
Procurement rules for federal or state agencies can move markets without a new private right of action.
If a summary of U.S. AI policy news does not tell you who is in and who is out, it is not yet a summary.

Question 2: What Must They Do, Specifically?
“Be transparent” is not a requirement. A requirement is: disclose that a consumer is interacting with a machine; disclose training-data categories; disclose evaluation results against a named standard; keep logs for a defined period; obtain consent before using a biometric; or refrain from using specified data.
I read proposals the way I used to read vendor contracts. Vague duties create later fights about meaning. Specific duties create implementation calendars, vendors, and costs. Both can be legitimate policy. Only one can be budgeted.
Common duty types, without the slogans
Duty type | Example of an operative ask | Who feels it first |
|---|---|---|
Notice | Tell a user a system is automated | Product and legal teams |
Evaluation | Test for specified harms before deployment | Model providers and large deployers |
Recordkeeping | Keep prompts, outputs, or decision logs | IT and compliance |
Human review | Require a person before a specified decision | Operations and labor |
Restriction | Ban a use (e.g., certain biometric scraping) | Specific product lines |
The announcement says “AI safety.” The incentives suggest a fight over which row in that table will survive markup.

Question 3: Who Enforces, and With What Tools?
A rule enforced by a federal agency with examination authority looks different from a rule enforced by state attorneys general, private litigants, or procurement officers who can simply refuse to buy. The same sentence in a bill can be mild or severe depending on the remedy: civil penalty, injunction, disgorgement, exclusion from contracts, or a private right of action with fee shifting.
Preemption is part of this question. Companies want one federal floor. States have already moved on privacy, employment decision tools, and, in some cases, AI-specific disclosure. Courts will eventually sort conflicts. Until then, multi-state operators live in the overlap.
Read the announcement. Then read the incentives. Agencies seek jurisdiction and budget. Advocates seek a hook that works even if Congress never finishes a comprehensive statute. Companies seek a single checklist. Local governments seek tools that do not require a new technical staff they cannot hire.
Question 4: Who Pays When the Rule Is Unclear?
Compliance costs do not land on “the industry.” They land on the firms that cannot spread legal spend across a giant product surface, and on the workers who become the human review layer. A rule that requires documentation can be a full-time job at a small deployer and a template at a large lab.
This is the question I write on the last page of the notebook: who really benefits, and who really pays? A disclosure regime can help a sophisticated buyer and confuse an ordinary customer. A compute threshold can spare small developers and still miss harmful uses of smaller systems. A private right of action can deter sloppy deployments and also deter useful ones that cannot afford the first lawsuit.
I am not arguing for or against any single bill in this piece. I am arguing that AI regulation explained without these four questions is just mood. Policy Desk will keep returning to the text, the enforcer, and the invoice.
Here is what changed, and what did not. The United States still lacks a single comprehensive federal AI statute comparable to a full-stack sector law, while agencies, states, and courts have not waited. The need to read operative language did not change. If you only remember one method from this essay, remember the four questions. They travel well from hearing room to hearing room.
No notes on this sheet yet.