The Evolving Landscape of AI Governance in the U.S.
As artificial intelligence (AI) technologies become integral to various sectors, nearly half of U.S. states are stepping up efforts to formulate and implement AI governance laws. This burgeoning regulatory landscape carries important implications for compliance and risk management, as highlighted in a recent bulletin from Gallagher, a leading global insurance brokerage and risk management firm.
State-Level Legislative Initiatives
A significant number of states are currently developing or considering AI governance legislation. Among them, Colorado stands out with the introduction of the Colorado Artificial Intelligence Act, set to take effect on February 1, 2026. This pioneering legislation delineates specific responsibilities for AI developers and “deployers,” particularly concerning high-risk systems that impact critical areas like employment, finance, and healthcare.
Developers of AI systems are now required to be accountable for known risks and actively report instances of algorithmic discrimination. On the flip side, deployers utilizing high-risk AI systems must implement comprehensive risk management programs. Importantly, they must also establish avenues for individuals to contest AI-generated decisions, thereby safeguarding consumer rights.
Key Areas of Focus
At the state level, proposed regulations primarily concentrate on four essential areas:
- Consumer Protection: Safeguarding against algorithmic profiling that could lead to biased outcomes.
- Employment Practices: Ensuring ethical AI use in hiring and workforce management.
- Deceptive Media: Addressing the rise of deepfakes and their potential misuse.
- Impact Assessments: Establishing task forces to analyze the broader implications of AI deployment.
John Farley, managing director of Gallagher’s Cyber Liability Practice, predicts that the trajectory of AI regulation will likely follow a path similar to recent data privacy laws across the U.S., pointing to a trend toward increased oversight and consumer protection.
Federal Developments
On the federal stage, over 100 AI-related bills have been introduced in Congress. Most aim to enhance transparency and accountability while protecting consumers from the unintended consequences of AI deployment. Specific industry guidelines are emerging, with the Federal Trade Commission (FTC) focusing on AI transparency and the National Institute of Standards and Technology (NIST) crafting crucial governance frameworks.
Certain industries are seeing more targeted regulatory attention as well. The Health Insurance Portability and Accountability Act (HIPAA) has begun to incorporate AI-specific guidelines, while the Financial Industry Regulatory Authority (FINRA) is urging financial institutions to adopt robust risk management frameworks to deal with AI-related risks.
Cyber Insurance Landscape
The rise in AI regulations presents new challenges for organizations seeking comprehensive cyber insurance coverage. As companies increasingly integrate AI systems into their operations, insurers are re-evaluating coverage parameters to account for unique AI-related risks, such as algorithmic discrimination and the possibility of high-risk system failures.
The potential liabilities associated with AI systems transcend conventional cyber insurance policies, potentially extending into areas like employment practices liability, product liability, medical malpractice, and directors and officers liability. This evolving risk landscape necessitates that organizations reassess their entire insurance portfolios rather than concentrating solely on traditional cyber coverage.
Challenges in Policy and Coverage
Some cyber insurers are already modifying policy language to limit or exclude coverage for incidents linked to regulatory investigations, lawsuits, and settlements stemming from AI usage. As AI regulations tighten, it is anticipated that this trend will accelerate, adding further complexities to insurance landscapes.
An essential yet complicated area involves establishing liability between AI system developers and deployers. Under Colorado’s AI Act, distinct roles are defined for each party, raising questions about claims adjudication and coverage determinations as similar laws emerge across states. Insurance providers and policyholders will need clarity on responsibilities and coverage applications, especially when liability is shared among multiple parties.
Navigating New Regulations
As the landscape of AI governance continues to develop, organizations will find themselves navigating a maze of compliance requirements and insurance implications. Gallagher’s report emphasizes that many cyber insurance policies offer free or discounted risk consulting services. Insurers may adapt to cover some costs related to compliance with new AI regulations, including necessary AI risk assessments.
While this regulatory evolution brings challenges, it also presents opportunities for businesses to enhance their risk management strategies and ensure ethical AI use. With the regulatory environment becoming increasingly intricate, organizations must stay informed to adequately protect themselves and their stakeholders in this rapidly evolving digital age.
For further details on this topic, you can explore Gallagher’s full report here.

