Photo by Signature Pro on Unsplash
The Question a General Counsel Actually Gets Asked
Ask who regulates artificial intelligence in the United States and most people point to Washington. Ask a company's lawyers which document actually changed how their engineering team trains a model, and the answer is almost never a statute. It's a complaint, a discovery order, or a settlement.
That gap is the whole story, and as of August 22, 2026 it has not closed. According to refresh, the publisher whose reporting prompted this analysis, AI governance now runs on two tracks that barely speak to each other: courts interpreting old laws in real time, and legislatures drafting new ones that arrive late. In plain terms, the rules that bind you today were written for photocopiers and job applications, not for a model that ingested the open internet.
One transparency note before the numbers, because it matters for how much weight you should give them. The underlying research for this piece could not reach live sources — the search layer returned errors and fell back on material current through January 2025. Every figure below carries that date stamp. Anyone telling you the AI litigation landscape looks exactly the same in August 2026 as it did in January 2025 is guessing, and so would we be if we didn't say so.
The Docket Produced More Binding Rules Than Congress Did
Here is the arithmetic that surface coverage tends to skip. As of the 2024 data available in this research, more than 50 AI-related bills were introduced in the US Congress. Comprehensive laws passed: none. That is a conversion rate of zero. In the same period, over 30 AI copyright lawsuits were filed against major AI companies including OpenAI, Meta, Stability AI, and Midjourney — and legal analytics firms measured an increase of roughly 300% in AI-related US litigation between 2022 and 2024.
Fifty proposals that bind nobody. Thirty-plus cases that each bind somebody.
Measured by enforceable outcomes produced per year, the courthouse outran the Capitol — not because judges wanted the job, but because a plaintiff with standing does not need 218 votes.
Chart: Counts drawn from research current as of January 2025. Bills proposed and lawsuits filed are 2024 figures; federal comprehensive AI laws in the US stood at zero as of January 2025.
The case that anchors all of this is The New York Times v. OpenAI and Microsoft, filed in December 2023. It is not asking whether AI should be allowed. It asks a narrower and far more consequential question: does training a model on copyrighted material fall inside fair use? A court answering that question sets a boundary no bill has managed to set. Meanwhile the FTC has skipped the waiting game entirely, bringing enforcement actions against AI companies for deceptive practices under existing consumer protection law — the same authority it uses against a mattress company that fakes reviews.
Two Governance Systems, and Who Wins Under Which
The tempting read is that Europe got it right and America is drifting. The honest read is that each system buys something the other cannot.
The EU AI Act became the world's first comprehensive AI regulation when it landed in May 2024, with enforcement phasing in through 2026. It sorts AI systems into four risk categories with different compliance duties, and the research estimates it reaches 500-plus companies. One instrument, one classification exercise, and a very large number of firms suddenly know what box they are in. That is breadth, delivered on a schedule.
Litigation delivers something else: depth, aimed at a defendant list you could count on one hand. A ruling in a training-data case can settle an issue with a precision no regulator drafting in advance could manage — because the court has the actual contract, the actual dataset, the actual harm in front of it. The statute reads in generalities; the docket reads in specifics.
So who wins under which condition? If you are a mid-size company that needs to know what compliance costs before you build, regulation wins — you can budget against four risk tiers. If you are a rights-holder whose work was scraped and no statute names your situation, litigation wins, because you do not have to wait for a legislature to notice you exist. And if you are a US company operating in both markets, you get the worst of both: a predictable EU framework you must engineer for, plus an unpredictable domestic environment where, as legal scholars have noted, courts are effectively writing AI policy in real time to fill the regulatory vacuum.
The fair pushback, and it deserves an answer: judicial governance is reactive and jurisdictionally inconsistent. A fair-use holding in one circuit does not bind another. That is a real defect. But the counter-counter-argument is stronger than critics allow — regulation moves too slowly for the pace of AI development, and a slow, uniform rule that arrives after the harm is not obviously better than a fast, messy one that arrives during it. On balance, the inconsistency is the price of speed, not evidence that the courts have overstepped.
States are not waiting either. California signed AB 2013 in 2024, requiring disclosure of AI training data, and Colorado passed its own AI bill the same year. That is a third track — and it is the one most likely to reach an ordinary business first.
Where You Are Actually Exposed
Most readers are not defendants in a training-data case. The exposure is quieter and closer.
If you use AI output commercially, the unresolved fair-use question is not the AI vendor's problem alone. Check whether your provider's terms include an IP indemnity — meaning the vendor agrees to cover you if the output triggers an infringement claim. Some do. Some cap it at a number that would not cover a week of litigation. Before you sign, read that clause specifically, not the marketing page.
If you deploy AI in hiring, lending, or tenant screening, the governing law already exists and it is not AI law. It is employment and civil rights law, and a court would likely look at disparate outcomes first and your vendor's technical explanation second. The legal technology sector has grown quickly around this gap — AI legal tools for contract review and bias auditing now sit inside a lot of law firm automation stacks — but adopting legal software does not transfer your liability to the software company.
If you built on someone else's model, map which jurisdictions you touch. A company selling into the EU inherits the AI Act's risk classification regardless of where its servers sit. This is the same accountability question that surfaces whenever an autonomous system acts on its own — a problem our sister publication examined in Binance AI Agent Trading: Who Is Liable When a Bot Loses?, where the liability chain runs through the deployer, not the algorithm.
The first defensive step in all three cases is the same and it is dull: write down, in one page, which AI systems your organization uses, what data went in, and which jurisdiction's rules you are betting on. Nearly every company that has been surprised by an AI claim was surprised because nobody had that page.
Frequently Asked Questions
What is the difference between AI litigation and AI regulation?
Regulation is a rule written in advance by a legislature or agency that applies broadly — the EU AI Act's four risk categories are the clearest example. Litigation is a dispute decided after the fact, where a court applies existing law (copyright, privacy, employment) to a specific set of facts. Regulation is predictable but slow. Litigation is fast but binds only the parties, and can point in different directions in different jurisdictions.
Has the US passed any AI laws as of 2026?
As of January 2025 — the most recent point this research can verify — there was no comprehensive federal AI law in the United States, despite more than 50 congressional proposals in 2024. States moved first: California's AB 2013 on training-data transparency and a Colorado AI bill were both signed in 2024. Federal status should be re-checked against current sources before you rely on it.
What is the EU AI Act and when does it take effect?
It is the world's first comprehensive AI regulation, adopted in May 2024, and it sorts AI systems into four risk categories carrying different compliance obligations. Enforcement arrives in phases running through 2026, and the research estimates it affects 500-plus companies. Reach is based on where you sell, not where you are incorporated.
Can companies be sued for AI copyright infringement?
They already are. Over 30 AI-related copyright suits had been filed as of late 2024 against companies including OpenAI, Meta, Stability AI, and Midjourney. The landmark test is the December 2023 New York Times action against OpenAI and Microsoft, which asks whether training on copyrighted material is fair use. Until courts answer that, both model builders and commercial users of AI output carry unresolved risk.
Why is AI regulation taking so long in the United States?
Volume is not the bottleneck — over 50 bills appeared in 2024 alone. Passage is. Comprehensive AI legislation requires agreement on definitions, liability, and enforcement authority across committees with competing priorities, while the technology changes faster than the drafting cycle. The practical result is that agencies like the FTC use existing consumer protection powers, and courts fill the rest.
- In 2024, US Congress produced 50+ AI bills and zero comprehensive laws, while 30+ AI copyright suits and a roughly 300% rise in AI litigation from 2022 to 2024 produced actual binding outcomes.
- The EU AI Act (May 2024, phasing through 2026) buys breadth — four risk tiers reaching an estimated 500+ companies. US litigation buys depth and speed at the cost of consistency across jurisdictions.
- Our analysis: the most likely path from here is not a grand federal statute but a patchwork — court rulings on fair use, FTC enforcement under existing consumer protection law, and state rules like California's AB 2013 setting the practical floor for everyone else.
- Your first defensive step is not hiring counsel. It is documenting which AI systems you use, what data trained them, and whose law applies.
Explore Our Network
No comments:
Post a Comment