Applied Oversight

AI Governance · US States + EU

Know exactly which AI laws reach you — and what they require.

In 2025, federal regulators pulled back their AI-enforcement guidance for private business. The exposure didn't disappear; it shifted to state law and the courts. A fast-growing patchwork of state AI laws and the EU AI Act (which reaches US companies whenever their AI's output is used in Europe) now governs the AI that mid-market companies already use in hiring, lending, healthcare, insurance, and customer service. Applied Oversight maps your exposure in plain language, with every obligation cited to the statute it comes from.

The deadlines are real

Enforcement moved to the states.
The clock is already running.

  • LIVE

    NYC bias audits

    Live now

    Local Law 144: annual bias audit plus candidate notice for automated employment decisions.

  • LIVE

    Illinois & Texas

    Live now

    Illinois AI-discrimination amendments and Texas TRAIGA are in force, alongside federal civil-rights and credit law.

  • LIVE

    California employment-AI rules

    Live now

    Automated-decision employment regulations now apply to hiring and personnel decisions.

  • LIVE

    EU AI Act baseline

    Live now

    Prohibited-practices bans and AI-literacy duties, in force since February 2025, for any US company with an EU connection.

  • AUG 2 2026

    EU AI Act transparency

    Upcoming

    Chatbot disclosure and AI-content labeling duties begin.

  • JAN 1 2027

    Colorado ADMT + chatbots, California CCPA

    Upcoming

    Colorado's ADMT duties (rules for software that helps decide things about people) and new chatbot-safety rules, plus California's CCPA/ADMT notices and opt-outs, take effect.

  • DEC 2 2027

    EU AI Act high-risk

    Ahead

    The heavy deployer obligations: oversight, logging, monitoring, notices. And yes, they can reach US companies.

View the full running calendar of AI compliance deadlines →

Methodology

One spine, many laws.

Most firms hand you a per-law checklist and let you reconcile the overlaps. We map every obligation from fifteen-plus legal regimes (seventy-plus obligations and counting) onto a single ISO/IEC 42001 control spine. One human-review control satisfies Colorado, California, and the EU at once; strictest requirement wins. You build each control once, not fifteen times.

15+
Legal regimes
70+
Obligations mapped
1
Control spine
2 days
Snapshot delivery

The discipline

Built on verification, not vibes.

Every obligation in our registry traces to the primary legal text: statutes and final regulations, never a blog summary. When laws change (they changed three times while we built this), the registry flags every affected deliverable. That discipline is the product.

Common questions

Questions we hear a lot.

Which AI laws does Applied Oversight cover?

Our registry currently maps 70+ obligations across 15+ legal regimes, and it grows as laws take effect. Today that includes the state AI laws of California (two regimes: CPPA automated-decision rules and FEHA employment rules), Colorado (the AI Act and the Chatbot Safety Act), Connecticut, Illinois, New Jersey, New York City, Texas, and Utah; the EU AI Act deployer track; long-standing US federal sectoral law (Title VII and the ADA, ECOA/Regulation B, the FCRA, HIPAA, the Fair Housing Act, and FTC Act §5); state insurance-regulator rules in Colorado and New York for regulated insurers; and the federal public-sector and procurement rules that reach agencies and government contractors. The full running list, with effective dates, lives on our compliance calendar.

Does the EU AI Act really reach a US company?

Often, yes. It applies if you have an establishment or staff in the EU, if you offer products or services to people in the EU, or if the output of your AI is used in the EU (the path most advisors miss), even when your company sits entirely in the US. If your screening scores, reports, or decisions travel to an EU office, client, or partner, the Act's baseline duties can already apply.

The AI is inside software we bought from a vendor. Are we still on the hook?

Usually, yes. Most of these laws reach the organization that uses an AI system to make or inform decisions (the deployer), including AI features embedded in vendor platforms like applicant-tracking, CRM scoring, or chat tools. Purchasing a tool keeps that obligation with you, and customizing or rebranding a vendor's system can quietly add heavier ones.

Do you work with government agencies and contractors?

Yes. Alongside private mid-market companies, we cover the AI rules that reach public-sector bodies and their contractors: federal agency AI-use governance, Section 508 accessibility for AI interfaces, the AI terms that now flow into federal contracts, and the state and local web-accessibility rules. If you sell AI to the government or run it inside an agency, those obligations are in scope.

Is the scan, or your work, legal advice?

No. We produce a structured analysis of which laws likely reach your AI and what they require, cited to the primary text and prepared for review with your counsel. It is informational, and no attorney-client relationship is formed. Where a question turns on legal interpretation, we package it clearly for your counsel to decide.

Ten minutes of questions.
A one-page map of your AI obligations.

Get your free exposure scan