US AI Policy September 2026: Federal Updates and What's Next
US AI Policy September 2026: Federal Updates and What's Next
US AI policy in September 2026 reflects an administration and Congress that are more aligned on AI's strategic importance than they are on how to regulate it. The federal government has significantly increased AI investment and formalized AI procurement standards, while comprehensive AI legislation continues to stall in Congress. The regulatory picture is built primarily from executive actions, agency guidance, and sector-specific rules rather than a unified AI statute.
The Executive Order Framework and What's Actually Been Implemented
The 2023 executive order on AI established reporting requirements and safety standards for frontier AI models. In the years since, the implementing mechanisms have taken shape — some more substantially than others.
The dual-use foundation model reporting requirements are now active. AI developers training models above a compute threshold must share safety test results with the federal government, and the process for those disclosures has been formalized through the AI Safety Institute (now operating under NIST).
The immigration pathways for AI talent have been implemented and expanded, with visa categories for AI researchers and engineers streamlined. This piece of the original EO has had the most direct positive industry response.
Federal agency guidance for AI use in government procurement has been issued and is now applied in new contract vehicles. Agencies acquiring AI systems must document safety and performance standards, and contractors providing AI tools to the federal government face disclosure requirements about model architecture and training.
The full current text of the executive framework is publicly available at the White House briefing page.
Congressional AI Activity: Still Fragmented
Congress in 2026 has not passed comprehensive federal AI legislation despite multiple competing frameworks. What has advanced reflects the existing committee structure more than a unified policy vision:
Financial services AI. The Senate Banking Committee has approved guidance on AI use in consumer financial products, building on existing fair lending authorities rather than creating new AI-specific rules. This is consistent with the sector-specific approach regulators have taken.
AI in healthcare. Legislation strengthening FDA oversight of AI-based medical devices has advanced with bipartisan support. The narrow scope — medical device AI specifically — has made it easier to build consensus than broader AI regulation.
National security AI. Defense AI procurement and oversight rules have moved through the Armed Services committees and are now part of the NDAA framework.
Transparency and disclosure requirements. Multiple bills requiring disclosure of AI use in specific contexts — news content, government decisions, political advertising — have introduced but not yet passed. The AI-generated election content disclosure requirements are the most advanced of this category.
What hasn't advanced despite years of hearings:
- Comprehensive AI liability frameworks
- Federal AI safety standards for non-government AI systems
- Data privacy and training data legislation (blocked by broader tech privacy stalemate)
- National AI authority that would consolidate regulatory responsibility
The NIST AI Risk Management Framework as Practical Governance
In the absence of binding federal AI legislation, the NIST AI Risk Management Framework has become the de facto standard against which organizations calibrate their AI governance programs. Federal procurement requirements increasingly reference the NIST AI RMF, which has driven adoption beyond just government contractors.
The framework is voluntary for non-regulated entities, but it has substantial practical influence:
- Major enterprises reference it in AI governance disclosures
- It's cited in state legislation and sector-specific federal guidance
- International alignment (the EU AI Act and UK approaches reference similar risk-tiering concepts)
The current framework version is available at airc.nist.gov, and NIST has been releasing sector-specific profiles for healthcare, financial services, and critical infrastructure.
State-Level AI Activity Filling the Federal Gap
The absence of federal AI legislation has created space for state-level activity that is reshaping the compliance landscape for companies operating across the US:
California AI legislation. California has been the most active state on AI regulation, passing legislation on deepfakes in elections (enacted), automated employment decisions (disclosure and impact assessment requirements), AI transparency in consumer products, and AI liability for high-risk consumer applications.
Other state developments. Colorado's AI Act (enacted 2024) imposes obligations on high-risk AI systems including employment, financial, and housing applications. Illinois, Texas, and New York have enacted or are advancing similar legislation. The result is a fragmented state-by-state compliance landscape for companies without federal preemption.
For companies operating nationally, state-level AI compliance now requires tracking legislation in multiple jurisdictions — a compliance overhead that industry groups are lobbying to reduce through federal preemption.
For broader context on the international regulatory picture, see the US AI regulation in 2026 overview and the EU AI Act compliance requirements covered separately.
Federal AI Investment and the National AI Initiative
While regulation has moved slowly, federal AI investment has accelerated. The National AI Initiative's funding has increased substantially, with priority given to:
- AI research through NSF and DARPA programs
- AI safety and alignment research through the National AI Safety Institute
- AI for scientific discovery through DOE national laboratories
- Defense and intelligence community AI applications
The government AI talent pipeline remains a challenge. Federal pay scales and procurement timelines make it difficult for government to compete with private sector salaries for top AI researchers. The workforce development programs funded through recent legislation are early-stage.
What Industry Is Watching Most Closely
The federal AI policy developments that industry is tracking most carefully in the fall of 2026:
NIST AI RMF updates. Any revision to the framework or new sector-specific profile releases will have cascading effects on enterprise AI governance programs.
AI Safety Institute activities. The AI Safety Institute's ongoing evaluations of frontier AI models and its developing standards for safety testing are closely watched. Its findings influence export control decisions and procurement requirements.
Export controls on AI. AI chip export controls have become one of the most active areas of AI policy, with ongoing adjustments to the restricted country list and compute thresholds. Companies involved in international AI supply chains face a dynamic compliance environment.
Congressional AI hearings. Multiple Senate and House committees have scheduled AI-focused hearings for the fall, covering deepfakes, AI in elections, and AI in financial markets. Whether these produce legislative action or remain oversight theater is uncertain.
What's Missing in US AI Policy
Critics from both sides of the regulatory debate have consistent complaints about the current US AI policy landscape:
From those advocating stronger oversight: The absence of binding liability standards means AI developers face limited accountability for harmful deployments. The sector-specific approach creates gaps for AI applications that don't fit neatly into existing regulatory buckets. Agency guidance without legislative backing is fragile.
From those advocating lighter oversight: State-level fragmentation creates compliance costs without unified standards. Voluntary frameworks don't create level playing fields. The US regulatory approach is less clear than the EU's, creating planning uncertainty for companies that need to build to a standard.
The most likely near-term development is continued sector-specific rulemaking at the federal agency level — FDA on medical AI, CFPB on lending AI, EEOC on employment AI — without the comprehensive federal framework that would create a unified standard.
For organizations building AI products for US deployment in 2026, the practical implication is to monitor sector-specific agency guidance carefully, build to the NIST AI RMF as a baseline, track state-level legislation in key jurisdictions, and plan for a comprehensive federal framework that may be years away.
Comments
Loading comments...