U.S. Constitution Logo
U.S. Constitution

Who Regulates AI in the U.S.?

September 14, 2026by Eleanor Stratton

Every few months, a familiar claim comes roaring back into American politics: AI is so consequential that it needs one thing above all else, a strong president to “keep it under control.”

The Constitution does not work that way. Not because the Founders predicted large language models, but because they were allergic to unchecked power as a general concept. In the U.S. system, regulation is not a personality trait. It is a set of legal authorities created by Congress, executed by the president, and reviewed by courts.

So when you see sweeping statements about the executive branch already having “tremendous criminal and regulatory power” over AI companies, the right question is not whether that sounds tough. The right question is: power from where?

The White House in Washington, D.C., photographed from the North Lawn in daylight.

Join the Discussion

The constitutional starting point

The Constitution assigns different jobs to different branches.

  • Congress writes the rules. Article I gives Congress the power to pass laws, fund programs, create agencies, and set the scope of federal regulation.
  • The president executes the rules. Article II requires the president to “take Care that the Laws be faithfully executed.” That is enormous power, but it is not the same thing as the power to invent new legal duties for private companies.
  • Courts police the boundaries. Article III courts ultimately review whether a regulation is authorized by statute, whether it violates constitutional rights, and whether an agency followed required procedures.

This matters for AI because most “guardrails” people talk about are not just moral preferences. They are legal obligations: what data can be collected, what claims can be made, what safety testing is required, what audits must be performed, what must be disclosed to consumers, and what penalties attach to violations.

Those obligations often require either (1) a statute passed by Congress, or (2) a regulation issued by an agency that Congress has authorized to regulate that subject. But they can also arise outside federal rulemaking, through state statutes, contracts and warranties, and common-law doctrines like negligence and product liability.

What a president can do

A president is not powerless. The executive branch can shape AI policy in real ways, but almost all of them fit into one of four buckets.

1) Direct agencies within existing law

The president can instruct executive agencies to prioritize enforcement, coordinate, issue guidance, and propose rules, but only within the authority Congress already gave those agencies.

That also has a practical wrinkle: some of the most important AI-facing regulators are independent agencies (like the FTC and SEC).

Presidents appoint leaders and can set broad priorities across government, but independent agencies are not meant to take day-to-day legal orders from the White House.

If an agency does not have a statutory hook, presidential enthusiasm does not create one. This is why major AI moves often show up as executive orders that tell agencies to study, coordinate, publish frameworks, and use procurement leverage, rather than imposing new nationwide obligations on every AI developer.

2) Control federal procurement and federal use

The federal government is one of the world’s largest customers. The president can push “AI guardrails” by conditioning federal contracts on safety practices, security standards, incident reporting, and testing. For example, an agency can require vendors to follow NIST-aligned security controls or report significant cyber incidents as a condition of doing business.

That can influence the market, but it is not the same as regulating everyone. It regulates sellers who want federal money.

Procurement is not a magic wand, though. It is constrained by procurement statutes and the Federal Acquisition Regulation, and many requirements must have a defensible connection to lawful procurement goals like economy and efficiency.

3) Use national security and emergency authorities, within limits

Presidents have special tools when AI touches export controls, sanctions, critical infrastructure, and defense. But those tools still come from statutes and they still face judicial review.

Calling something a “national security issue” can broaden executive discretion. It does not erase constitutional constraints, including due process and First Amendment limits. In some foreign-affairs contexts, courts may be more deferential or review may be narrower, but that variability is not the same thing as unlimited power.

4) Enforce criminal law, but only where Congress made something a crime

“Criminal power” is real, but it is not a free-floating authority to punish “bad things.” Federal prosecutors must point to specific criminal statutes: fraud, hacking, identity theft, illegal surveillance, obstruction, false statements, export violations, and so on.

AI can be the tool, the target, or the accelerant. A classic example is wire fraud schemes that use AI voice cloning to impersonate an executive and trick a victim into wiring funds.

But the crime still has to be in the U.S. Code.

The Robert F. Kennedy Department of Justice Building in Washington, D.C., photographed from the street.

Who regulates AI right now

There is no single, dedicated federal “AI regulator” analogous to a sector regulator like the FAA in aviation. In the U.S., AI regulation mostly happens through existing agencies applying old statutes to new technology.

That can feel unsatisfying, but it is also how American government often adapts: by forcing new inventions to fit inside preexisting legal boxes until Congress builds a new one.

Federal Trade Commission (FTC)

The FTC is one of the most important AI regulators because it can police deception and unfairness in commerce. If a company lies about what an AI system does, how accurate it is, how it uses data, or how “safe” it is, the FTC can often act. Think of deceptive “AI-powered” marketing claims, or promises that a model does not retain sensitive user data when it actually does.

The FTC also has leverage over privacy and data security practices when broken promises or unreasonable security creates consumer harm. That matters because AI systems are often trained on large datasets and deployed through products that collect sensitive information.

Equal Employment Opportunity Commission (EEOC)

AI tools used in hiring, scheduling, evaluation, or termination can trigger civil rights law. If an algorithm has a disparate impact on protected classes or is used as a vehicle for discrimination, the EEOC can investigate and enforce existing anti-discrimination statutes.

Department of Housing and Urban Development (HUD)

Tenant screening tools, automated underwriting, and other AI-driven systems can implicate the Fair Housing Act. These disputes are usually statutory. Constitutional due process issues tend to show up most clearly when the government is the decision-maker or is sufficiently involved to qualify as state action.

Consumer Financial Protection Bureau (CFPB) and bank regulators

AI used for credit decisions lives under longstanding financial statutes and supervision. Regulators can scrutinize unfair, deceptive, or discriminatory practices, and they can demand compliance with requirements like adverse action notices under ECOA and Regulation B. That is one place where “explainability” shows up in practice: lenders often must give specific reasons for denials, even when models are complex.

Food and Drug Administration (FDA)

When AI is embedded in medical devices or functions as software that can diagnose or guide treatment, FDA authority can apply. This is one of the clearest cases where “AI regulation” looks like classic safety regulation, because the harms are physical and immediate.

Department of Transportation (NHTSA and others)

Driver-assistance and autonomous vehicle systems can trigger transportation safety oversight. This is less about chatbots and more about AI as a control system in machines that can injure people.

Federal Communications Commission (FCC)

The FCC is not an “AI truth commission.” But when AI intersects with telecommunications networks, robocalls, and related rules, the FCC can have a role.

Securities and Exchange Commission (SEC)

If AI is used to mislead investors, manipulate markets, or if public companies make materially false statements about AI capabilities or risks, the SEC’s existing fraud and disclosure authorities can come into play.

Department of Commerce (including NIST) and export controls

NIST is influential not because it can arrest anyone, but because technical standards and frameworks often become the backbone of procurement rules and compliance programs. Commerce also intersects with export controls for advanced computing and related technologies where statutes authorize those controls.

The Federal Trade Commission headquarters building in Washington, D.C., photographed from outside.

What “guardrails” means in law

AI guardrails is a catchy phrase, but in law it typically cashes out as:

  • Product safety rules: testing, reporting, recalls, and liability.
  • Data rules: privacy, security, consent, and limits on collection or sharing.
  • Truth and fairness rules: anti-fraud, anti-discrimination, and transparency obligations.

The U.S. already has tools in each category. What it often lacks is a single, comprehensive statute designed specifically for modern AI systems across sectors, with clear definitions, baseline duties, and a designated lead regulator.

For contrast, other jurisdictions are more comfortable with a unified framework. The European Union’s AI Act is the most prominent example. The United States has leaned harder on sector regulators, state experimentation, and case-by-case enforcement.

The federal “hook” requirement

Even when Congress wants to regulate broadly, it cannot just pass a law titled “The Everything Is Now Regulated Act” and call it a day. Federal power must tie back to enumerated powers.

For AI, the most common constitutional hooks are:

States are not spectators. They have their own police powers over health, safety, and consumer protection. Unless federal law preempts them, states can regulate many AI uses directly. That is why the American future here may look less like one national rulebook and more like overlapping federal and state regimes, at least until Congress chooses to unify them.

The United States Capitol building in Washington, D.C., photographed from the West Front in clear weather.

Can the president regulate AI directly?

Not in the way people usually mean.

The president can:

  • set policy priorities for executive agencies
  • choose enforcement emphasis within lawful discretion
  • negotiate voluntary commitments from companies
  • shape federal contracting standards
  • invoke certain emergency or national security powers where Congress has authorized them

The president generally cannot:

  • create new nationwide duties for private AI companies without statutory authority
  • punish lawful speech because it is “bad” or “potentially bad”
  • order independent agencies to violate their statutory constraints

That last point is where constitutional reality collides with political rhetoric. The executive branch can be aggressive, but it has to be aggressive through law, not around it.

What courts watch for

If AI regulation ramps up, courts will not just ask whether a policy is wise. They will ask whether it is legal.

Did Congress authorize the agency action?

Agencies need a statute that fits what they are doing. Judges often frame this as the boundary between major policy choices for Congress and technical implementation for agencies. That debate shows up in modern doctrine too, including the major questions doctrine, which can require clear congressional authorization for rules of vast economic and political significance.

Did the agency follow required procedures?

Many regulations require notice-and-comment rulemaking and reasoned explanations. Skipping steps can doom a rule even if the underlying goal is popular.

Does the regulation violate constitutional rights?

AI regulation can collide with several constitutional protections:

  • First Amendment: restrictions that target speech content, compelled disclosures, or certain publication activities can trigger serious scrutiny.
  • Fourth Amendment: government use of AI for surveillance, searches, and data aggregation raises search and seizure issues, especially as tools become more comprehensive.
  • Due process: when AI systems are used by government to deny benefits, flag people, or make risk determinations, people often demand notice, explanation, and a meaningful chance to contest errors.
  • Equal protection: discriminatory outcomes in government deployment can become constitutional claims, not just policy disputes.

When people say “AI needs guardrails,” they are often arguing about private tech companies. But some of the hardest constitutional fights will be about government AI, because the Bill of Rights restricts government first. Public-sector procurement, benefits administration, and law enforcement uses often raise different questions than private-sector product regulation.

So who is in charge?

In the United States, AI regulation is not owned by one person or one agency. It is an ecosystem:

  • Congress can create a comprehensive AI statute, fund enforcement, and assign clear authority.
  • The president can coordinate the executive branch, set priorities, and enforce existing law.
  • Agencies can police AI through consumer protection, civil rights, finance, health, transportation, and security statutes.
  • States can regulate many AI uses unless federal law preempts them.
  • Courts referee the boundaries when any of the above oversteps.

If that sounds slower than a single decisive executive calling the shots, that is the point. The Constitution was designed to be frustrating to anyone who wants total control quickly. It assumes power is dangerous even when you agree with the person holding it.

And that is the durable takeaway: AI may be new. American governing authority is not. The real guardrails are the old ones, separation of powers, statutory limits, and judicial review. The question is whether Congress will build clearer lanes for a technology that currently keeps changing faster than our legal categories can keep up.

Quick answers

Is there a single federal agency that regulates all AI?

No. AI is regulated indirectly through multiple agencies applying existing laws, plus state laws.

Can a president ban or shut down an AI company?

Not by fiat. Any shutdown would need a lawful basis, such as enforcement of specific statutes, national security authorities authorized by Congress, or court orders.

Are there already criminal laws that apply to AI misuse?

Yes. Many AI-driven harms map onto existing crimes like fraud, hacking, identity theft, and illegal surveillance. The AI is usually the tool, not the statute.

Can AI rules be blocked by the Constitution?

Yes. Even valid statutes and regulations can be narrowed or struck down if they violate constitutional rights or exceed the powers Congress has under Article I.