"Incentives or Obligations? The U.S. Regulatory Approach to Voluntary AI Governance Standards" is an analysis written by Rafal Fryc, a legal intern at the Future of Privacy Forum (FPF), dated March 16, 2026 (inferred from the screenshot date). It argues that voluntary AI governance frameworks, chiefly the NIST AI Risk Management Framework and ISO/IEC 42001, are being incorporated into binding legal requirements across US states, so that compliance with nominally non-binding standards is becoming a baseline for reasonable conduct even in jurisdictions without AI-specific legislation.
Summary of argument
Fryc identifies three mechanisms through which voluntary standards (primarily NIST AI RMF and ISO 42001) acquire legal force:
- Statutory mandates — laws that require compliance with external frameworks as an obligation.
- Safe harbors — laws that offer legal protection as an incentive for framework adoption.
- Judicial reliance — courts using voluntary frameworks to define the standard of care in negligence and strict liability cases, regardless of whether a statute requires it.
The piece concludes that compliance with non-binding standards is effectively becoming a baseline for reasonable conduct even in jurisdictions without AI-specific legislation.
Enacted state laws
The analysis maps how enacted state laws assign a role to external frameworks:
| State | Law | Approach | Framework role |
|---|---|---|---|
| Colorado (original) | SB 24-205 (AI Act) | Mandate + affirmative defense | Required implementation; safe harbor from AG actions |
| Colorado (revised) | Working group revisions | Removed external standards | References removed in latest proposed revisions |
| Texas | TRAIGA (HB 149) | Incentive (safe harbor) | Compliance with NIST RMF = affirmative defense |
| California | SB 53 (TFAIA) | Transparency mandate | Must disclose approach to national/international standards |
| New York | RAISE Act | Transparency mandate | Must disclose how they "handle" incorporating standards |
| Montana | SB 212 | Mandate | Deployers in critical infrastructure must consider external standards |
Proposed legislation
Fryc groups pending bills into three families. Frontier model bills — Illinois SB 3312 and HB 4799; Illinois SB 3261; Utah HB 286; Tennessee SB 2171; and Nebraska LB 1083 — all require or encourage written policies incorporating NIST/ISO standards, and some mandate separate child protection plans. Liability bills — Illinois SB 3502/3590; Maryland HB 712; and Vermont H 792 — adopt a Texas-style safe harbor available if developers conduct testing, evaluation, and red-teaming "consistent with industry best practices" and submit a data sheet to the state attorney general. Automated decision-making technology (ADMT) bills include Washington HB 2157, which establishes a presumption of conformity for following NIST/ISO, and New York S 1169, which requires a risk management policy conforming to NIST or to an AG-designated standard. The New York S 1169 provision giving the attorney general power to name qualifying standards is described as unique among the surveyed bills; Fryc characterizes it as unusual and precedent-setting, noting that if adopted it would give the NY AG substantial regulatory authority over AI governance norms without a formal rulemaking process.
Judicial route
The analysis argues that even without statutory AI law, courts are using the NIST AI RMF to define the standard of care in negligence and strict liability cases. It situates this within established product-liability patterns, noting that courts have long admitted evidence of industry standards as "highly probative when defining a standard of care" and "admissible as bearing on the standard of care in determining negligence." Fryc's practical reading is that a company that ignores the NIST AI RMF may face greater negligence liability than one that adopted and documented it, regardless of whether its jurisdiction has passed AI-specific laws.
Key claims
The piece documents what it presents as a three-way fragmentation in how states tie standards to legal consequences: the Texas model is incentive-based (comply to obtain a safe harbor); the Colorado model is mandate-based (comply to reduce liability and ADA exposure); and the California model is transparency-based (disclose the approach taken, whatever it is). This adds an incentive/mandate/transparency dimension to the existing federal/state split described on AI Compliance Industry / Regulatory Fragmentation.
A second claim is that the NIST AI RMF and ISO/IEC 42001 increasingly function as quasi-legal requirements rather than optional frameworks. Fryc contends that treating these standards as merely voluntary, while technically correct, understates their practical legal weight as they are folded into statutory mandates, safe harbors, and judicial standards of care. The NIST AI Risk Management Framework 1.0 is presented as the de facto reference standard across US state AI legislation, with ISO/IEC 42001 — AI Management System cited alongside it as the second key reference.
Provenance
The analysis was published by the Future of Privacy Forum and authored by FPF legal intern Rafal Fryc. The raw source is a single article; the March 16, 2026 date is inferred from the screenshot date. It builds on FPF's earlier work, including FPF and Brookings — California SB 53 Compliance Analyses (Oct–Dec 2025).
Relationships
- supports: AI Compliance Industry / Regulatory Fragmentation — documents a new dimension of fragmentation along incentive/mandate/transparency lines
- supports: NIST AI Risk Management Framework 1.0 — confirms NIST RMF is the de facto reference standard across US state AI legislation
- supports: ISO/IEC 42001 — AI Management System — ISO 42001 cited alongside NIST RMF as the second key reference
- related: Colorado AI Act (SB 24-205) — the first law to require NIST RMF; referenced as the Colorado model
- related: Texas Responsible AI Governance Act (TRAIGA / HB 149) — the incentive-based Texas model
- related: California SB 53 — the disclosure-based California model
- related: New York RAISE Act — the RAISE Act's disclosure requirements
- related: FPF and Brookings — California SB 53 Compliance Analyses (Oct–Dec 2025) — earlier FPF analysis of SB 53