SkycrumbsSkycrumbs
AI News

US AI Policy News August 2026: New Rules and Guidance

August 14, 2026·9 min read

US AI Policy News August 2026: New Rules and Guidance

US AI policy in August 2026 is best characterized as a complex, multi-front, partially-coordinated effort across dozens of agencies and fifty state legislatures — without the overarching federal framework that would make compliance straightforward. Understanding what's actually changing, and what it means for organizations deploying AI, requires tracking more moving parts than at any previous point in US technology regulation.

Here's what's new and what matters.

Federal Agency Activity: The August 2026 Landscape

With no comprehensive federal AI statute enacted, federal agencies are using their existing authorities to address AI through guidance documents, enforcement actions, and interpretive rules. August 2026 has been unusually active.

The FTC has been the most aggressive federal actor on AI in 2026. This August, the Commission issued updated guidance on AI in advertising and marketing — specifically addressing undisclosed AI-generated testimonials, AI-synthesized endorsement content, and the use of AI to target advertising to vulnerable populations. The guidance is paired with new enforcement authority: the FTC has opened investigations into at least three companies for deceptive AI practices, with formal actions expected before year-end.

Key FTC AI guidance elements from August 2026:

  • Disclosure requirements when AI-generated content is used to simulate authentic testimonials or reviews
  • Standards for what "material AI involvement" in product creation means for disclosure purposes
  • Specific prohibitions on using AI to identify and target consumers showing signs of financial distress, health vulnerability, or behavioral manipulation susceptibility

The EEOC updated its technical assistance guidance on AI in employment this August, with more specific standards than the 2024 guidance. The new elements include:

  • A detailed framework for when AI-assisted screening tools constitute a "selection procedure" requiring adverse impact analysis
  • Specific guidance on AI resume screening, video interview analysis, and AI-scored assessments
  • Documentation requirements for employers using AI in hiring, promotion, or termination decisions

The EEOC guidance isn't a rule — it doesn't have force of law — but it signals enforcement priorities and will likely be cited in litigation. Employers using AI in any employment decision context should review their practices against it.

HHS and the FDA have been particularly active in healthcare AI. August brought:

  • Updated FDA guidance on AI/ML-based Software as a Medical Device (SaMD) post-market monitoring requirements
  • HHS Office for Civil Rights guidance on AI in healthcare billing and prior authorization
  • CMS (Centers for Medicare and Medicaid Services) finalized rules on disclosure requirements when AI is used in Medicare Advantage coverage determination

The NIST AI Risk Management Framework received its second major update this August. The update includes new profiles for high-risk deployment domains (healthcare, financial services, education, employment), expanded guidance on red-teaming AI systems before deployment, and new metrics for evaluating AI reliability and fairness. The RMF isn't mandatory, but it's being referenced increasingly in federal procurement requirements and in state laws that require AI risk management documentation.

For the regulatory landscape beyond US borders, AI regulation August 2026 has the global picture.

Congressional Activity

Congress has been slow to pass comprehensive AI legislation, but August 2026 has seen notable committee activity that signals where legislation is heading.

The AI Accountability Act remains in committee but received updated text this August following extensive stakeholder comment. The current draft includes:

  • Mandatory disclosure requirements for high-risk AI systems (defined to include AI used in employment, healthcare, housing, credit, and criminal justice)
  • A federal AI incident reporting requirement analogous to data breach notification
  • Limited private right of action for individuals harmed by high-risk AI systems that didn't comply with disclosure requirements

The bill faces significant opposition from technology industry groups on liability provisions. Progress before the end of the Congressional year is uncertain.

The AI Research and Development Act is further along in the legislative process, having cleared committee. This bill focuses on federal AI R&D funding priorities, national AI testbeds, and workforce development programs rather than on regulation. It has broader bipartisan support and is more likely to pass before year-end.

Congressional hearings scheduled for August 18 will address AI and national security, with testimony from DoD officials and AI lab executives. This is the most significant Congressional AI event of the month and is expected to address export controls, adversarial AI risks, and the balance between AI development speed and safety evaluation.

State Laws: The Patchwork Expands

The US state AI regulatory landscape has expanded significantly in 2026. August brings new laws taking effect and new legislation advancing.

States with active AI legislation in August 2026:

  • California: Multiple active rulemaking processes. The CPPA's automated decision-making rules are in final comment period; the AB 2013 AI training data disclosure requirements took effect this month; SB 1047-style safety requirements for large AI systems remain in ongoing litigation.

  • Colorado: The Colorado AI Act, focused on high-risk AI systems in consumer-facing contexts, has active implementing guidance being developed. Colorado's law is one of the more comprehensive state frameworks and is being watched as a potential model.

  • Texas: The Texas Responsible AI Governance Act finalized rules this August requiring disclosure when AI is used in employment decisions affecting Texas residents.

  • Illinois: Extended BIPA to AI systems using biometric data, with new guidance clarifying what "biometric data" means in AI contexts.

  • New York: The NYC Local Law 144 on automated employment decision tools is in enforcement, and state-level AI legislation is advancing in the legislature.

  • Multiple states: More than fifteen states have enacted or are advancing AI disclosure requirements of varying scope. The lack of federal preemption means multistate businesses face a growing compliance matrix.

The AI state laws 2026 article has the state-by-state breakdown.

National Security and AI: The August Picture

The national security dimension of US AI policy is increasingly prominent in August 2026.

Export controls on AI-related technology continue to be a major policy tool. The Commerce Department's Bureau of Industry and Security has expanded control lists covering advanced AI chips, specific model weights above certain capability thresholds, and AI development tools classified as having weapons applications potential. August 2026 brings new interim rules expanding the scope of controls on model weight exports to certain jurisdictions.

The NSCAI successor — the National AI Security Center, established within NSA — has released its first public report on AI security threats from foreign adversaries. The report documents AI-assisted cyber intrusion campaigns, AI-generated disinformation operations, and efforts to acquire controlled AI technology through front companies and academic partnerships.

DoD AI policy continues to evolve. The Department of Defense's AI and Data Office has published updated guidelines for AI in military decision-support systems, maintaining human-in-the-loop requirements for lethal force decisions while expanding autonomous operation permissions for surveillance and logistics applications.

Allies and export controls is a live tension. US allies have pushed back on export controls that restrict their access to AI technology while framing the controls as national security measures. The administration has been developing "trusted partner" frameworks that would provide easier access to allied nations while maintaining controls on adversary access.

What Businesses Need to Do Right Now

For organizations deploying or planning to deploy AI in the United States, August 2026 regulatory developments call for several practical actions:

If you use AI in employment decisions: Review your practices against the updated EEOC guidance immediately. Document your AI tools, their purpose, and any disparate impact analysis you've conducted. If you haven't conducted adverse impact analysis on AI screening tools, this is now a regulatory priority.

If you use AI in marketing or advertising: Review the FTC guidance on AI in advertising. Undisclosed AI testimonials and targeted marketing using manipulation-susceptibility signals are active enforcement priorities. Ensure your marketing AI practices include clear disclosure where AI-generated content simulates authentic human voices.

If you operate across multiple states: Assess which state AI laws apply to your operations. California, Colorado, Illinois, and New York all have AI requirements that may affect you regardless of where you're headquartered.

If you're in healthcare: Track the FDA SaMD guidance updates and the HHS/CMS rules on AI in coverage determinations. Healthcare AI faces the most active federal regulatory attention of any sector.

For all businesses: Align your AI risk management practices with the NIST AI RMF update. Federal procurement is increasingly requiring NIST RMF alignment, and state laws are beginning to reference it. Documentation of how AI risk is assessed and managed is becoming a compliance expectation.

The Regulatory Trajectory

The US AI policy trajectory in August 2026 is toward more regulation, not less — even without a comprehensive federal statute. The combination of agency guidance, state laws, and eventual federal legislation is creating a more demanding compliance environment than existed a year ago.

The EU AI Act continues to influence US regulatory thinking, even in a political environment skeptical of EU-style regulation. The practical pressure: US companies operating globally often find it more efficient to implement EU-compatible practices uniformly than to maintain separate US and EU compliance programs.

The one element of uncertainty: the US political environment can shift regulatory priorities quickly. The direction of travel over the past 18 months has been toward more AI regulation, but specific rules can be modified or reversed by changes in administration or Congressional priorities.

For ongoing tracking of US AI policy developments, the AI news week of August 14, 2026 weekly roundup includes regulatory highlights. Check back weekly for updates as the policy landscape continues to evolve through the end of 2026.

Key Dates and Deadlines to Track

  • August 18: Congressional hearings on AI and national security
  • September 30: California AB 2013 first-year reporting deadline
  • October 1: Multiple state AI disclosure requirements take effect
  • November 15: Colorado AI Act first enforcement action period begins
  • Year-end: FTC AI enforcement actions in current investigation pipeline expected

Organizations with AI deployments in any of the affected categories should have these dates on their compliance calendars.

For the broader global AI regulatory picture, global AI regulation 2026 provides the international context alongside the US developments.

Comments

Loading comments...

Leave a comment