AI Policy Wiki
Dashboard

Incentives or Obligations? The U.S. Regulatory Approach to Voluntary AI Governance Standards

medium confidence · updated 2026-06-06

FPF analysis of how voluntary AI governance frameworks (NIST AI RMF, ISO 42001) are being incorporated into binding legal requirements across US states, creating a new de facto compliance layer even in jurisdictions without AI-specific legislation

"Incentives or Obligations? The U.S. Regulatory Approach to Voluntary AI Governance Standards" is an analysis written by Rafal Fryc, a legal intern at the Future of Privacy Forum (FPF), dated March 16, 2026 (inferred from the screenshot date). It argues that voluntary AI governance frameworks, chiefly the NIST AI Risk Management Framework and ISO/IEC 42001, are being incorporated into binding legal requirements across US states, so that compliance with nominally non-binding standards is becoming a baseline for reasonable conduct even in jurisdictions without AI-specific legislation.

Summary of argument

Fryc identifies three mechanisms through which voluntary standards (primarily NIST AI RMF and ISO 42001) acquire legal force:

  1. Statutory mandates — laws that require compliance with external frameworks as an obligation.
  2. Safe harbors — laws that offer legal protection as an incentive for framework adoption.
  3. Judicial reliance — courts using voluntary frameworks to define the standard of care in negligence and strict liability cases, regardless of whether a statute requires it.

The piece concludes that compliance with non-binding standards is effectively becoming a baseline for reasonable conduct even in jurisdictions without AI-specific legislation.

Enacted state laws

The analysis maps how enacted state laws assign a role to external frameworks:

StateLawApproachFramework role
Colorado (original)SB 24-205 (AI Act)Mandate + affirmative defenseRequired implementation; safe harbor from AG actions
Colorado (revised)Working group revisionsRemoved external standardsReferences removed in latest proposed revisions
TexasTRAIGA (HB 149)Incentive (safe harbor)Compliance with NIST RMF = affirmative defense
CaliforniaSB 53 (TFAIA)Transparency mandateMust disclose approach to national/international standards
New YorkRAISE ActTransparency mandateMust disclose how they "handle" incorporating standards
MontanaSB 212MandateDeployers in critical infrastructure must consider external standards

Proposed legislation

Fryc groups pending bills into three families. Frontier model bills — Illinois SB 3312 and HB 4799; Illinois SB 3261; Utah HB 286; Tennessee SB 2171; and Nebraska LB 1083 — all require or encourage written policies incorporating NIST/ISO standards, and some mandate separate child protection plans. Liability bills — Illinois SB 3502/3590; Maryland HB 712; and Vermont H 792 — adopt a Texas-style safe harbor available if developers conduct testing, evaluation, and red-teaming "consistent with industry best practices" and submit a data sheet to the state attorney general. Automated decision-making technology (ADMT) bills include Washington HB 2157, which establishes a presumption of conformity for following NIST/ISO, and New York S 1169, which requires a risk management policy conforming to NIST or to an AG-designated standard. The New York S 1169 provision giving the attorney general power to name qualifying standards is described as unique among the surveyed bills; Fryc characterizes it as unusual and precedent-setting, noting that if adopted it would give the NY AG substantial regulatory authority over AI governance norms without a formal rulemaking process.

Judicial route

The analysis argues that even without statutory AI law, courts are using the NIST AI RMF to define the standard of care in negligence and strict liability cases. It situates this within established product-liability patterns, noting that courts have long admitted evidence of industry standards as "highly probative when defining a standard of care" and "admissible as bearing on the standard of care in determining negligence." Fryc's practical reading is that a company that ignores the NIST AI RMF may face greater negligence liability than one that adopted and documented it, regardless of whether its jurisdiction has passed AI-specific laws.

Key claims

The piece documents what it presents as a three-way fragmentation in how states tie standards to legal consequences: the Texas model is incentive-based (comply to obtain a safe harbor); the Colorado model is mandate-based (comply to reduce liability and ADA exposure); and the California model is transparency-based (disclose the approach taken, whatever it is). This adds an incentive/mandate/transparency dimension to the existing federal/state split described on AI Compliance Industry / Regulatory Fragmentation.

A second claim is that the NIST AI RMF and ISO/IEC 42001 increasingly function as quasi-legal requirements rather than optional frameworks. Fryc contends that treating these standards as merely voluntary, while technically correct, understates their practical legal weight as they are folded into statutory mandates, safe harbors, and judicial standards of care. The NIST AI Risk Management Framework 1.0 is presented as the de facto reference standard across US state AI legislation, with ISO/IEC 42001 — AI Management System cited alongside it as the second key reference.

Provenance

The analysis was published by the Future of Privacy Forum and authored by FPF legal intern Rafal Fryc. The raw source is a single article; the March 16, 2026 date is inferred from the screenshot date. It builds on FPF's earlier work, including FPF and Brookings — California SB 53 Compliance Analyses (Oct–Dec 2025).

Relationships