Chapter 9. World I: the US (federal vs states) and the UK
Story phase: expansion. Kompas leaves the EU and discovers a different type of regime. A broadening of the view, not a second spine.
The situation at Kompas
Kompas has passed the EU AI Act and is entering the US and the UK. The team's instinct is understandable: "Since we've beaten the strictest regime in the world, from here it's smooth sailing, checkboxes at most." Reality is harsher and subtler at once: the other regimes are not stricter, but built on a different logic, and the European dossier doesn't cover them automatically. Worse, hiring in the US is regulated not so much at the federal level as at the level of individual states and cities — and there they expect specific procedures that don't exist in the AI Act at all.
This chapter is a map of the horizon, not an operational guide. The task is to understand along which axes the regimes diverge, so that Kompas doesn't port EU artifacts blindly.
What the rule says
The US — fragmentation, not a single law.
- *The federal level* has taken a course toward deregulation / pro-innovation. The current executive order revoked the prior (Biden-era) approach and directly aims to limit the "patchwork" of state regulation: an AI Litigation Task Force was created at the DOJ, challenging state laws. An example as of September 2026 — xAI's lawsuit against the Colorado law, which the DOJ joined on the plaintiff's side. Whether a federal EO can preempt state laws without an act of Congress is being decided in the courts right now.
- *States and cities* — where the pressure actually lives, but the picture is fluid:
- Colorado AI Act (SB 24-205) — the most "European" law by design (a risk regime, a fight against algorithmic discrimination) — was cut back and shifted in 2026: SB 189 (May 2026) removed the duty of care, deployers' duties to run risk management and do impact assessments, narrowing the law to disclosure and transparency; entry into force moved to 01.01.2027. A telling turn of a state away from the EU model.
- NYC Local Law 144 — the most concrete one for hiring: since July 2023 an employer using an automated employment decision tool (AEDT) must annually run an independent bias audit, publish a summary of the results and notify candidates 10 business days in advance. Penalties — $375–$1500 per violation; the city comptroller's audit signals a move toward tougher enforcement.
- *California* — transparency, disclosure of training data, deepfakes, anti-discrimination regulations in hiring; *Illinois* — BIPA (biometrics) and a disclosure law.
- *Sector regulators* work on top: the FTC (unfair/deceptive practices), the EEOC (discrimination in hiring) — under existing law, without needing a new AI statute.
The UK — principles-based, deliberately without a separate law. Regulation runs through existing regulators (the ICO on data, the CMA on competition, the FCA on finance) on the basis of cross-sector principles (safety, transparency, fairness, accountability, contestability). There is an AI Safety Institute; a possible shift toward formal regulation of foundation models is under discussion, but there is no AI Act-like law.
A contrast of philosophies. The EU — an ex-ante risk regime (prove conformity before market); the US — ex-post + sectoral + a mosaic of states, with a federal rollback; the UK — principles on top of existing law.
How it lands on the product
For the US, Kompas runs first of all into hiring specifics, not a general AI regime: NYC LL144 requires precisely an annual bias audit, publication of a summary and notice to candidates 10 days in advance — procedures the European dossier doesn't contain. That is separate work, not a subset of the AI Act.
In the UK there are fewer formal gates, but UK GDPR (the ICO) and anti-discrimination law apply — Kompas leans on principles, not on a checklist.
The artifact is the first row of a cross-jurisdictional matrix: jurisdiction → what triggers → what is required → status. The full matrix is assembled in ch. 11.
Where it breaks
The political zone is fluid. Federal preemption versus states' rights is being decided in the courts; the balance could change within a quarter. Building a long strategy on the current federal rollback is risky — as is ignoring the states in the expectation that the feds will "cancel" them.
"Passed the EU → passed everything" is false. The NYC bias audit is a standalone procedure with an external auditor and publication, not a squeeze from the AI Act. EU conformity doesn't close it.
Patchwork and state drift. 50 trajectories, some — bills in flight, some — being cut back on the go (like Colorado). A snapshot ages fast; the matrix must be updated, not fixed once.
What to do as engineer/product
For each new market, check the hiring-specific rules separately from the general AI regime — it's precisely they, not "the AI law in general," that create concrete duties for an HR product.
Don't port EU artifacts one-to-one: build a matrix of "what triggers where" and keep it as a living document, because states change the rules on the go.
Provocation
"We passed the EU AI Act, the rest is a formality" is a dangerous symmetry. The US regulates AI not more softly, but differently: where the EU sets an ex-ante gate, the states wait ex-post — with a city law on a mandatory hiring audit that isn't in the European dossier by a single line, and with a lawsuit under existing anti-discrimination law. The strictness of a regime can't be measured on one scale: it's measured by what exactly is checked, and everywhere they check something different.
Read next
Shipping an AI product under regulatory risk?
A read of your product against the EU AI Act: risk class, role in the value chain, obligations and dossier — as a design constraint on the way in, not a lawyer's check at the end.
Email meThe transition engine
Next Move Engine — the system that takes a team to an autonomous delivery loop.
Next Move Engine →