No single US law governs AI agents. A dozen sector statutes already apply depending on what the agent does: FCRA for one that screens people, ECOA for one touching a credit decision, GLBA for one reading a dealership's customer data, TCPA for one calling a lead. Most checklists stop at HIPAA, GDPR, and SOC 2, missing the law that actually applies.
That gap shows up because most compliance checklists are written for enterprise buyers evaluating vendor platforms, not for an owner deciding whether the agent they just deployed needs a consent form. The law that governs an AI agent depends on what the agent touches, not on the fact that it is AI.
Is there one federal law that governs AI agents?
No. The United States has no general-purpose federal AI statute. What exists instead is a patchwork: older statutes written for human decision-makers and human phone calls, now being applied to software that screens, scores, calls, and stores data on a business's behalf. Regulators have been explicit that using AI does not create an exemption. The CFPB's Circular 2024-06 stated plainly that a score generated by an algorithm is a consumer report under the Fair Credit Reporting Act the same as a human-compiled file, once it draws on data beyond a single employer's own dealings with that person. The Bureau withdrew that circular in May 2025 with dozens of others, but withdrawing guidance does not change the underlying statute, only what the agency actively cites in an enforcement action.
The EU AI Act gets cited constantly in vendor marketing, but it only matters to a business serving EU residents. A local HVAC company running a voice agent to book jobs is not an EU AI Act problem. It is a Telephone Consumer Protection Act problem, and that law has applied to automated calls since 1991, long before anyone called it an "AI agent."
What law applies when an AI agent screens or scores a person?
The Fair Credit Reporting Act, if the score draws on more than that one employer's own records. A staffing agency that reuses one AI-generated candidate score across multiple client placements is arguably furnishing a fresh consumer report each time, which triggers a disclosure, a signed consent, and a two-step adverse-action notice under 15 U.S.C. Section 1681b(b)(3) before the agency can reject someone based on that score. Most agencies only associate that process with third-party background check vendors, not with their own AI screening tool.
State law adds a second layer. Illinois requires notice, an explanation of how the AI evaluates a candidate, written consent, and destruction of a video interview within 30 days of a request, under the Artificial Intelligence Video Interview Act (820 ILCS 42). New York City requires an independent bias audit of any automated employment decision tool before it screens candidates in the city.
What law applies when an AI agent influences a credit decision?
The Equal Credit Opportunity Act and its implementing rule, Regulation B. 12 CFR 1002.9(b)(2) requires a lender to give the actual, specific reasons a credit decision went against an applicant, and it explicitly rejects generic reasons like "internal standards" or "failed to achieve a qualifying score." An AI agent that denies or downgrades a loan application has to produce a real, individualized reason, not a confidence score.
ECOA carries a private right of action: actual damages plus punitive damages up to $10,000 for an individual claim, or the lesser of $500,000 or 1% of the lender's net worth for a class action, plus attorney's fees. The CFPB withdrew two AI-specific interpretive circulars on this question in May 2025, which changes what a lender cites, but the underlying regulation and its penalty structure did not move.
What law applies when an AI agent handles a dealership or advisor's customer data?
The Gramm-Leach-Bliley Act's Safeguards Rule, administered by the FTC, treats a car dealership as a financial institution because it arranges financing. Under 16 CFR 314, any AI vendor reading a dealership's customer data becomes a "service provider" subject to vendor due-diligence, a written contract, and periodic monitoring duties. The FTC's own Safeguards Rule FAQ for auto dealers contains no AI-specific carve-out; the obligations apply exactly as written. FTC civil penalties currently run $53,088 per violation per day.
Financial advisors face a narrower but sharper duty. SEC Rule 204-2 requires advisors to retain records of client communications, which extends to an AI agent's prompts and the data it accessed on a client's behalf. The SEC's March 2024 enforcement actions against Delphia and Global Predictions over AI-related misrepresentations resulted in $225,000 and $175,000 penalties, the agency's first AI-specific enforcement actions.
What law applies when an AI agent calls or texts someone?
The TCPA, and the bar is higher for an AI voice agent than most businesses assume. The FCC's February 2024 ruling, FCC 24-17, holds that an AI-generated voice counts as an "artificial voice" under the statute. That means an automated callback from a voice agent needs prior express written consent under 47 CFR 64.1200(a)(1) and (f)(9), a materially higher bar than the "prior express consent" a human employee dialing the same lead would need. Switching a lead-response workflow from a human callback to an AI voice callback raises the compliance bar even when nothing else about the process changes. TCPA violations carry statutory damages of $500 to $1,500 per call, per 47 U.S.C. 227(b)(3).
Debt collection agents face an added wrinkle under Regulation F. The limited-content voicemail safe harbor at 12 CFR 1006.2(j) requires excluding any mention of the debt or the word "collector," which conflicts with the mini-Miranda disclosure the FDCPA requires on a live call. An agent's voicemail branch needs a different script from its live-call branch, or it loses the safe harbor and counts against the seven-calls-in-seven-days cap.
What law applies when an AI agent touches student, health, or donor data?
FERPA governs any AI agent a school district gives access to student records. 34 CFR 99.31 allows disclosure without consent only under the "school official" exception, which requires the vendor to perform an institutional function, be under the district's direct control, and use the data only for its authorized purpose. FERPA has no private right of action; a district's real exposure is state law layered on top, such as New York's Education Law 2-d, which carries penalties up to $10,000 per violation for a third-party contractor.
Nonprofits commonly assume a blanket charitable exemption from privacy law, and that is wrong in a growing number of states. Colorado's Privacy Act and Oregon's Consumer Privacy Act both reach nonprofits directly, with no carve-out, and both states' notice-and-cure grace periods have expired. Colorado's penalty structure runs up to $20,000 per violation, capped at $500,000 for a single action.
What law applies when an AI agent takes a payment by phone?
PCI DSS, if the agent records the call or otherwise stores a spoken card number. A voice agent that lets a caller read a card number aloud and keeps the recording has captured cardholder data in scope, and pause-and-resume recording, the fallback most vendors use, is a weaker control than DTMF masking, which strips the tones from the recording entirely. Non-compliance fines from the card networks run $5,000 to $100,000 per month until the gap is fixed.
A quotable reference table
| Industry | AI agent trigger | Governing law |
|---|---|---|
| Staffing / recruiting | Scoring or screening a candidate | FCRA, CFPB Circular 2024-06 |
| Mortgage lending | Approving, denying, or pricing credit | ECOA / Regulation B |
| Car dealerships | Reading dealership customer data | GLBA Safeguards Rule (FTC) |
| Financial advisors | Storing client communications | SEC Rule 204-2 |
| Real estate / any outbound caller | Auto-calling or texting a lead | TCPA, FCC 24-17 |
| Debt collection | Live call or voicemail | Regulation F |
| School districts | Accessing student records | FERPA, 34 CFR 99.31 |
| Nonprofits (CO, OR) | Storing donor personal data | State privacy law (CPA, OCPA) |
| Restaurants | Taking a card number by phone | PCI DSS |
| Accounting firms | Processing tax return data | IRC Section 7216 |
| Funeral homes | Answering a price question by phone | FTC Funeral Rule |
| Hotels | Taking a phone reservation | ADA, 28 CFR 36.302(e) |
What does getting this wrong actually cost?
The penalties above are not theoretical. Air Canada was held liable for a chatbot's fabricated refund policy; the ruling established that a company answers for what its bot tells a customer the same as an employee. iTutorGroup's hiring software rejected older applicants for months before anyone noticed, and the EEOC settled that case for $365,000. Neither company set out to break a law; both deployed an agent without checking which one applied first. A fuller rundown of eight comparable incidents, with the fix that would have prevented each one, is in Suvysoft's AI agent incident tracker.
The fix is not a generic compliance framework bolted on after launch. It is scoping the agent's permissions and consent flow against the law that governs its specific function, before the agent goes live. Suvysoft's custom AI agent builds start every engagement by mapping exactly what an agent will touch and which statute governs that function, the same question that would have caught every example above. Two verticals with especially sharp, underdiscussed compliance gaps are covered in more depth in AI agents for staffing agencies and AI agents for mortgage lenders.
If none of the categories above match your business exactly, that is the point of a patchwork system: the law follows the function, not the industry label. Talk to Suvysoft about what your specific agent will touch, and which statute actually governs it, before it goes live rather than after.
Frequently asked questions
Does a small business have to comply with any AI-specific law?
Usually not a law written specifically for AI. What applies instead is whatever statute already governed that function before AI existed: a credit decision is still governed by ECOA, a debt collection call is still governed by the FDCPA and Regulation F, a student record is still governed by FERPA. Company size does not create an exemption from any of these; a two-person staffing agency using an AI screening tool owes the same FCRA disclosure as a national firm.
Which federal law applies to an AI agent that screens or scores job applicants?
The Fair Credit Reporting Act, once the score draws on data beyond that one employer's own records with the candidate. The CFPB's 2024 guidance treats an AI-generated candidate score the same as a traditional background check report, which means a disclosure, signed consent, and a two-step adverse-action notice before rejecting someone based on the score. Some states, including Illinois and New York City, layer additional notice or audit requirements on top.
Is an AI voice agent's outbound call covered by the TCPA?
Yes. The FCC ruled in February 2024 that an AI-generated voice counts as an "artificial voice" under the TCPA, which means an automated callback needs prior express written consent, a higher bar than the consent a human employee dialing the same number would need. A consent form written before that ruling, covering "phone calls" in general terms, may not cover an AI voice agent specifically.
Does HIPAA apply to an AI agent used in a medical practice?
Yes, if the agent touches protected health information, but HIPAA is not the only rule in play. A voice or chat agent doing prior authorization or eligibility work also runs into CMS's own interoperability requirements, including the FHIR API deadline taking effect January 1, 2027, which affects whether an agent should be built around portal automation now or built to switch to a payer's API once that payer turns it on.
What is the actual penalty for using an AI agent that violates one of these laws?
It varies by statute, and the range is wide. TCPA violations run $500 to $1,500 per call. ECOA carries actual and punitive damages up to $10,000 for an individual claim. FTC Safeguards Rule violations run up to $53,088 per violation per day. IRC Section 7216 violations for mishandling tax return data can mean a $1,000 fine, up to $100,000 under a related provision, and up to a year in prison per violation. None of these are AI-specific penalties; they are the same penalties that applied before AI entered the workflow.
How do you find out which law applies to your specific AI agent?
Start with what the agent actually does, not what industry you are in. An agent that screens people triggers different rules than one that calls people, which differs again from one that stores payment or health data. Map the agent's functions against the table above, then check whether your state adds a second layer, since state privacy, cancellation, and consumer-protection statutes frequently go further than the federal floor.
