AI for Government
Visionary · M15 · lesson 15 of 47 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
AI Regulatory Design
📖
now learning

AI Regulatory Design

15 min

Learning Objectives

After completing this lecture, policy leaders will be able to design or advise on AI regulation in the U.S. federal context, understand the authorities and constraints that shape federal rulemaking, and apply comparative insights from the European Union AI Act and the OECD AI Principles. The course treats regulation as a design exercise requiring clear problem definition, statutory authority, administrative process, and accountability architecture.

Specifically, you will be able to:

  1. Describe the federal rulemaking process under the Administrative Procedure Act (5 U.S.C. 551 et seq.), including notice-and-comment rulemaking under 553, the reasoned-decision-making standard of Motor Vehicle Manufacturers Ass'n v. State Farm, Executive Order 12866 centralized review via OIRA, the Unified Agenda and Regulatory Plan, the Regulatory Flexibility Act, the Paperwork Reduction Act, and the Congressional Review Act's joint-resolution mechanism.
  2. Describe OMB Memorandum M-24-10 and Executive Order 14110 as executive-branch policy instruments that direct agency practice without formal rulemaking, and their limits.
  3. Describe the sector-regulator approach of the U.S. system, including the Food and Drug Administration's software-as-a-medical-device and Good Machine Learning Practice guidance; the Securities and Exchange Commission's oversight of AI in market surveillance, investment advisers, and broker-dealers; the Consumer Financial Protection Bureau's adverse-action notice requirements under the Equal Credit Opportunity Act; the Federal Trade Commission's unfair and deceptive practices authority; the Federal Aviation Administration's airworthiness framework; the National Highway Traffic Safety Administration's automated-driving authorities; the Equal Employment Opportunity Commission and Department of Labor for employment AI; and the Department of Health and Human Services' civil rights obligations under Section 1557 and Section 504.
  4. Describe the European Union AI Act's risk-based classification (unacceptable risk, high risk, limited risk, minimal risk) and compare to U.S. M-24-10 risk tiers; describe the Council of Europe Framework Convention on AI and the OECD AI Principles.
  5. Describe state-level approaches: Illinois AI Video Interview Act; Colorado AI Act (Senate Bill 24-205); New York City Local Law 144; California and Washington proposals; state attorneys general enforcement using existing consumer-protection authorities.
  6. Apply the rulemaking design test: identify market failure or public-interest rationale; locate statutory authority; design proportionate obligation; craft clear scope; anticipate costs and benefits; design enforcement mechanism; provide for periodic review and sunset.
  7. Communicate regulatory options to leadership, members of Congress, stakeholders, and affected industries, in a way that produces durable regulatory outcomes rather than reactive or counterproductive rules.

Key Topics Covered

Topics covered in this lecture include:

Federal rulemaking. The Administrative Procedure Act's rulemaking process including notice-and-comment under 5 U.S.C. 553; reasoned decision-making under State Farm; EO 12866 centralized review by OIRA; significant and economically significant rule categorization; Unified Agenda and Regulatory Plan; Regulatory Flexibility Act small-entity analyses; Paperwork Reduction Act review; Congressional Review Act joint-resolution mechanism with specific look-back and fast-track procedures. How rulemaking differs from executive-branch policy like OMB M-24-10.

Executive branch coordination. OMB Office of Information and Regulatory Affairs (OIRA) significant-rule review; Office of Science and Technology Policy (OSTP) policy development; the White House AI Council; National Science and Technology Council; Subcabinet coordination.

Sector regulators and their AI activities. FDA Digital Health Center of Excellence and SaMD guidance including Predetermined Change Control Plans; SEC Staff Statements on AI model use in markets; CFPB Circular series on AI-related adverse actions; FTC enforcement actions and blog guidance on AI claims; FAA certification framework for AI-enabled avionics; NHTSA voluntary guidance and standing general order for automated vehicles; EEOC guidance on AI in employment selection decisions; DOL guidance on AI in workforce contexts; HHS Office of Civil Rights Section 1557 and Section 504 obligations.

Comparative international frameworks. The European Union AI Act's risk-based architecture and conformity assessment; General Data Protection Regulation interactions; Council of Europe Framework Convention on AI; OECD AI Principles; G7 Hiroshima AI process; Bletchley Declaration and subsequent summits.

State approaches. Illinois AIVIA; Colorado AI Act; NYC Local Law 144; pending state proposals; state AG enforcement using UDAP statutes and civil-rights law.

The rulemaking design test. A practical checklist for evaluating whether a proposed rule is well-designed: market-failure or public-interest rationale; statutory authority; proportionate obligation; clear scope; anticipated costs and benefits; enforcement mechanism; periodic review and sunset.

Worked examples. FDA SaMD adaptation for ML models with Predetermined Change Control Plans. SEC's Staff approach to AI in broker-dealer supervision. CFPB Circular 2023-03 on adverse-action notices. EEOC guidance on algorithmic selection procedures. FTC enforcement on AI claims and privacy.

Risks of poor design. Over-broad rules that chill legitimate use; under-inclusive rules that fail to address harm; fragmented state-federal regimes; lack of enforcement capacity; regulatory capture; and chilling effects on federal AI adoption itself.

Practical communication. How to brief members and staff; how to engage the regulated community; how to coordinate across agencies; how to respect Congressional prerogatives on major rules; how to use the Congressional Review Act framework to anticipate joint-resolution risk.

Why This Matters for Government

The United States has chosen a sector-based, delegated-rulemaking approach to AI rather than a single comprehensive AI statute. This reflects the constitutional architecture and long practice: Congress enacts authorizing statutes that delegate detailed rulemaking to executive-branch agencies with expertise; agencies promulgate rules under the Administrative Procedure Act; OMB reviews significant rules; courts review for arbitrary-and-capricious error; Congress retains the Congressional Review Act and appropriations leverage; states operate under their own authorities in parallel. This architecture has trade-offs. It produces uneven coverage, with some sectors (finance, health, employment, transportation, communications) better covered than others. It moves more slowly than a single statute. It also has the virtue of expertise-driven rulemaking in mature sector regulators who understand the technology's role in their sector.

For L5 policy leaders in federal government, regulatory design is the primary lever. Even where agencies operate under Executive Order 14110 and OMB Memorandum M-24-10, ultimate durable change comes through rulemaking by sector regulators or through legislation that Congress enacts. Policy leaders therefore must be fluent in the mechanics of rulemaking, the specific authorities of each relevant sector regulator, and the comparative context provided by the European Union AI Act, the Council of Europe Framework Convention on AI, the OECD AI Principles, the G7 Hiroshima AI process, and the state-level experiments.

The EU AI Act, entered into force in 2024 with phased application, adopts a risk-based architecture: unacceptable risk (prohibited), high risk (conformity assessment and ongoing obligations), limited risk (transparency), and minimal risk (largely unregulated). Providers and deployers of high-risk systems are subject to obligations on risk management, data governance, transparency, human oversight, accuracy, robustness, and cybersecurity. Conformity assessment mechanisms tie to notified bodies and technical documentation. For U.S. federal regulators, the EU Act is not a template to copy but a reference to understand. Many U.S. sector regulators are converging on similar substantive requirements (risk management, data governance, transparency, oversight, accuracy, security) without the centralized classification architecture.

U.S. sector regulators have been active. The Food and Drug Administration has issued guidance on software as a medical device and on predetermined change control plans that address the challenge of learning medical devices. The Securities and Exchange Commission has issued Staff statements on AI in investment adviser and broker-dealer contexts. The Consumer Financial Protection Bureau has issued circulars clarifying that adverse-action notices under the Equal Credit Opportunity Act must be specific enough to be useful when complex algorithms are used. The Federal Trade Commission has emphasized that unfair and deceptive acts and practices law applies fully to AI claims and practices. The Equal Employment Opportunity Commission has issued guidance on algorithmic selection procedures. The Department of Labor has addressed AI in workplace contexts. The Department of Transportation, via FAA and NHTSA, has addressed AI in aviation and automotive. The Department of Health and Human Services has applied Section 1557 and Section 504 obligations to AI-informed health decisions. Each of these agencies acts under its authorizing statute and develops specific requirements.

At the state level, Illinois's Artificial Intelligence Video Interview Act imposes notice and retention requirements for employers using AI video analysis; Colorado's AI Act of 2024 addresses consequential decisions by developers and deployers; New York City's Local Law 144 requires bias audits for automated employment decision tools. State attorneys general have used long-standing unfair-and-deceptive-practices statutes and civil-rights laws to reach AI conduct. The interaction between federal and state authority is one of the active questions L5 leaders must navigate.

This lecture gives policy leaders the conceptual tools to evaluate, design, advise on, and defend AI regulation in the U.S. federal context. It is deliberately comparative because the U.S. approach cannot be understood in isolation. It is also deliberately practical because the difference between good and bad regulatory design is typically visible within months of adoption.

WHY THIS MATTERS FOR GOVERNMENT

Regulatory design in the U.S. federal system has distinctive features that shape every choice.

DELEGATION UNDER THE APA

Congress enacts authorizing statutes that delegate to agencies the authority to issue rules. Agencies use 5 U.S.C. 553 notice-and-comment rulemaking for most binding rules. State Farm requires reasoned decision-making: consider relevant factors, avoid clear errors of judgment, explain the rule, and respond to significant comments. EO 12866 requires OIRA review for significant regulatory actions.

THE CRA CONSTRAINT

The Congressional Review Act allows Congress to disapprove recently-promulgated rules by joint resolution with fast-track procedures. This is not a threat for most rules but imposes a design discipline: rules that exceed statutory authority or lack political support risk CRA disapproval.

THE SECTOR APPROACH

The U.S. distributes AI regulation across sector regulators with authorizing statutes. Finance to SEC, CFPB, FTC, OCC, prudential regulators; health to FDA, HHS OCR, CMS; employment to EEOC, DOL; transportation to FAA, NHTSA; communications to FCC; education to ED; privacy enforcement to FTC and HHS OCR; civil rights enforcement across. Each regulator operates under its authorizing statute with established rulemaking and enforcement authorities.

COMPARATIVE FRAMEWORKS

The EU AI Act risk classification (unacceptable, high, limited, minimal) is a formal risk-based architecture. U.S. M-24-10 uses a parallel vocabulary (general, rights-impacting, safety-impacting) but without a centralized enforcement body. Both converge on substantive requirements: risk management, data governance, transparency, oversight, accuracy, robustness, security.

STATE APPROACHES

Illinois AIVIA, Colorado AI Act, NYC Local Law 144. States move faster than the federal system on specific harms. Fragmentation creates compliance complexity for interstate actors and pressure for federal preemption or harmonization.

THE DESIGN TEST

For any proposed rule, ask:

  1. Is there a market failure or clear public-interest rationale? Without one, regulation is likely unjustified.
  2. Is there statutory authority? Rules without authority are vulnerable on APA review.
  3. Is the obligation proportionate to the harm? Over-broad rules chill legitimate use; under-inclusive rules fail.
  4. Is the scope clear? Ambiguous scope invites litigation and inconsistent application.
  5. What are the costs and benefits? Significant rules are subject to OIRA review under EO 12866.
  6. How will the rule be enforced? Paper obligations without enforcement produce paper compliance.
  7. How will the rule be reviewed? Sunsets and review provisions prevent obsolescence.

COMMUNICATION

Leaders brief members and staff; engage regulated communities early; coordinate across agencies; respect Congressional prerogatives on major rules; and use the CRA framework to anticipate risk. Bad-faith engagement is costly; good-faith engagement improves rules.

THE OUTPUT

The output of good regulatory design is a rule that is lawful, proportionate, enforceable, and durable. The output of bad regulatory design is a rule that is litigated, disapproved, or ignored. The difference is usually in the design, not in the underlying policy aim.

The rest of this lecture walks the sector regulators, the comparative frameworks, and worked examples.

L5 5.1.1 -- National AI Policy Landscape

L5 5.1.3 -- International AI Governance Coordination

L5 5.2.x -- Legislative and Regulatory Strategy

L5 5.3.x -- Rulemaking Workshop

L4 4.3.2 -- Accountability Frameworks for AI Failures

L4 4.3.3 -- Transparency: Citizens' Right to Know

L3 3.8.x -- Cross-Agency AI Collaboration

L2 2.3.x -- Sector Regulator Overviews

L4 4.4.x -- Sector Deep Dives

L5 5.4.x -- AI Standards and Certification