United States — Federal
Which Federal Agency Regulates Your AI Use Case? A Decision Guide
There's no single US AI regulator. Jurisdiction runs through what your system does, not through the fact that it's AI — here's how to find the agency that actually has authority over yours.
There is no AI regulator in the US. Ask "who regulates AI" and you'll spend weeks looking for an agency that doesn't exist. Ask "who already regulates what my AI system does" and the answer is usually findable in minutes, because every federal agency below had jurisdiction over the underlying conduct — a hiring decision, a credit decision, a marketing claim — long before AI was part of the picture. The mapping runs through function, not technology, and this guide is that mapping.
Jurisdiction follows the function, not the technology
Six federal lanes cover most of what an AI system actually does in a regulated business context: the EEOC if it touches employment decisions, the CFPB if it touches credit decisions, the FTC if it touches marketing or consumer-facing claims, the SEC if it touches investment advice or public-company disclosures, the FDA if it touches medical devices or clinical decisions, and the FCC if it touches calls, texts, or synthetic voice. None of these agencies wrote AI-specific rules to get jurisdiction — they applied statutes that already existed, some by decades, to a new kind of tool performing an old kind of decision. A system that doesn't touch any of those six functions isn't automatically unregulated; it just means the mapping takes a closer look, which the last section here covers.
Does your AI make or influence a hiring, promotion, or termination decision?
That's EEOC territory. Title VII and the Americans with Disabilities Act apply to an algorithmic hiring, ranking, or termination tool exactly as they apply to a human manager making the same call — the statute doesn't have a carve-out for "the software decided." The EEOC's 2022 and 2023 guidance walking through how adverse-impact analysis applies to AI hiring tools was pulled from eeoc.gov in January 2025 following an executive order, but that withdrawal changed a technical-assistance document, not Title VII or the ADA themselves. It also doesn't matter whether the employer built the scoring model or licensed it from a vendor: liability for the hiring outcome stays with the employer making the decision. Our deeper breakdown of the EEOC's guidance covers the vendor-liability point and the enforcement record behind it.
Does it decide, or materially shape, a credit or lending outcome?
That's CFPB territory, running through the Equal Credit Opportunity Act and Regulation B. If an AI-driven underwriting model declines an application, the applicant is entitled to a specific, accurate reason tied to factors the model actually weighed — a bare low score or "the algorithm decided" doesn't satisfy a requirement that's been on the books since 1974. That requirement runs to the lender making the decision regardless of whether it built the underwriting model in-house or bought it from a third party; licensing the risk of an opaque scoring model doesn't license away the disclosure obligation that comes with it. The CFPB spent 2022 and 2023 explaining exactly how this applies to complex, less-interpretable models before withdrawing that explanation, not the underlying rule, in 2025. See our full breakdown of what adverse-action notices require for what "specific" actually means in practice.
Does it make a claim about what your product or company does?
That's FTC territory, and it's the broadest lane here because it isn't about what the AI does internally — it's about what you say about it externally, and it applies to any company, not just AI vendors. FTC Act Section 5 bans unfair or deceptive practices, and the agency has extracted settlements, including forced deletion of models trained on improperly obtained data, from companies that overstated AI capabilities in marketing. A company with no AI product at all can still land in this lane the moment its marketing describes one inaccurately. Our breakdown of the FTC's "algorithmic deception" theory covers the real case record.
Is it investment advice, or part of a public company's disclosure?
That's SEC territory — narrower than the FTC lane because it's specifically about claims made to investors or prospective investors, but with its own real case record. The SEC has charged investment advisers under the Advisers Act and the Marketing Rule, and at least one public company under securities-fraud and disclosure provisions, for describing AI capabilities that didn't match what the underlying system actually did. None of it required new legislation; it's ordinary securities law applied to an AI-shaped fact pattern. Our AI-washing breakdown walks through the specific settlements.
Is it a medical device, or does it support a clinical decision?
That's FDA territory. AI/ML-enabled software as a medical device goes through the same 510(k), De Novo, or premarket-approval pathways as any other device — there's no separate "AI track." The one AI-specific addition is the Predetermined Change Control Plan, built for models that keep learning after clearance rather than shipping as a fixed, static product. The part teams most often get wrong isn't the pathway itself but the threshold question of whether their software counts as a regulated device at all — some clinical decision support tools are carved out, and getting that classification wrong in either direction creates real exposure. Our full walkthrough of the FDA's device pathways covers where that line sits.
Does it call, text, or use a synthetic voice?
That's FCC territory, and the narrowest lane by function — but an easy one to miss if you're building an AI-voice or outbound-calling product rather than a hiring or lending tool. The FCC confirmed in a February 2024 declaratory ruling that an AI-generated or cloned voice counts as an "artificial voice" under the Telephone Consumer Protection Act, so the TCPA's decades-old consent requirements for robocalls apply to AI-voice calls exactly as they apply to any other prerecorded call. Our breakdown of that ruling covers what's settled and what's still only proposed.
What happens when one product hits more than one lane at once
Consider Cascade Talent Systems, a fictional HR-tech vendor that sells an AI resume-screening tool to employers and, separately, markets that tool directly to hiring teams with specific claims about how much it reduces bias in shortlisting. Cascade's general counsel, tracking only one lane, would reasonably start with the EEOC — the tool influences real hiring decisions at every company that licenses it, so Title VII and ADA exposure runs to Cascade's customers and arguably to Cascade itself as the vendor shaping the process. That's correct, but incomplete. The moment Cascade's own marketing describes a specific, checkable outcome — a bias-reduction figure, a claim about what the model actually measures — the FTC's Section 5 authority reaches that claim directly, independent of anything the EEOC does with the hiring side. Two agencies, two different theories of liability, one product. Cascade didn't do anything unusually aggressive to land in both lanes; it just performed two regulated functions — an employment decision and a marketing claim — inside a single feature set, which is closer to normal than exceptional for a company selling AI into a functional area like hiring, lending, or healthcare. Mapping a product to "the one agency that regulates us" is the mistake; mapping it to every function it actually performs is the fix.
When none of the six lanes fits cleanly
Workplace surveillance and algorithmic management sit in a genuine gray zone, and it's worth naming honestly rather than forcing it into one of the six lanes above. In October 2022, then-NLRB General Counsel Jennifer Abruzzo issued a memorandum arguing that employers' use of electronic monitoring and algorithmic-management tools could interfere with workers' Section 7 rights under the National Labor Relations Act, and urged the Board to adopt a framework treating pervasive surveillance as a presumptive violation. That memo was itself rescinded in February 2025 by the Acting General Counsel who succeeded her, along with roughly thirty other Abruzzo-era memos. The underlying statute, the NLRA, didn't change — but unlike the EEOC and CFPB withdrawals above, where decades-settled anti-discrimination and lending law sat untouched beneath a withdrawn explanation, the NLRB's own theory of how Section 7 applies to algorithmic management was never settled Board law to begin with, only a General Counsel's enforcement position that's now off the table. A use case that lands here is real, but currently less certain than the six lanes above — worth tracking rather than treating as either clearly regulated or clearly exempt. For the broader picture of why federal AI jurisdiction is scattered across agencies like this instead of centralized in one statute, see our overview of what federal AI regulation actually looks like today and our explanation of why Congress hasn't passed one.
Frequently asked questions
- Is there one federal agency that regulates AI in the United States?
- No. There is no single federal AI regulator. Jurisdiction runs through the underlying conduct the AI performs — a hiring decision, a credit decision, a marketing claim, a medical claim, a robocall — and each of those already had a federal regulator (the EEOC, CFPB, FTC, SEC, FDA, and FCC, respectively) before AI was part of the picture.
- Can more than one federal agency have jurisdiction over the same AI system?
- Yes, and it's common rather than exceptional. A single AI product that performs more than one regulated function — for example, a hiring tool that also markets specific claims about removing bias — can trigger both the EEOC (for the hiring decision) and the FTC (for the claim) at the same time. Treating jurisdiction as a single-agency question is itself a common gap.
- My AI use case doesn't fit hiring, lending, marketing, investing, medical, or calling — does that mean it's unregulated?
- Not necessarily. The FTC's general unfair-or-deceptive-practices authority under Section 5 is broad enough to reach conduct outside the other five lanes, and some areas, like workplace algorithmic monitoring under the National Labor Relations Act, remain genuinely unsettled at the guidance level even though the underlying statute exists. A use case that doesn't map cleanly is exactly when it's worth checking more than one lane rather than concluding none apply.
- Does a company avoid EEOC or CFPB jurisdiction by using a third-party AI vendor's tool instead of building its own?
- No. In both the EEOC and CFPB lanes, the agencies have made clear that using a vendor's algorithm doesn't shift legal responsibility away from the company making the underlying decision — an employer or lender stays responsible for a hiring or credit outcome regardless of whether it built the tool that produced it or licensed it from someone else.
- If an agency withdrew its AI guidance, does that mean the agency lost jurisdiction?
- No. The EEOC and CFPB both withdrew specific AI-related guidance documents in 2025, but withdrawing a technical-assistance document doesn't repeal the statute it was explaining. Title VII, the ADA, and ECOA didn't change; only the agencies' own plain-language explanations of how those laws apply did.
Sources & references
- Official source
- FTC — Aiming for truth, fairness, and equity in your company's use of AI
- EEOC — Select Issues: Assessing Adverse Impact in Software, Algorithms, and AI Used in Employment
- CFPB Circular 2022-03 — Adverse action notification requirements in connection with credit decisions based on complex algorithms
- NLRB — General Counsel Issues Memo on Unlawful Electronic Surveillance and Automated Management Practices (GC 23-02, Oct. 31, 2022)
- NLRB — GC 25-05, Rescission of Certain General Counsel Memoranda (Feb. 14, 2025)
Suggested next reading
regulations us
US Federal AI Regulation: What Actually Exists Today
regulations us
EEOC Guidance on AI in Employment Decisions, Explained
regulations us
SEC AI-Washing Enforcement: What Counts as a Violation
regulations us
FDA's Regulatory Pathway for AI/ML-Based Medical Devices
regulations us