Two years ago, few states regulated AI. More than 30 people now do so. Companies with operations across multiple states often build to the most stringent requirements they face, but only if the requirements vary by degree. If the types are different, there is no single bar. Rules in some states could prompt companies to normalize bias in applicants. It can also force companies to track raw performance data. Compliance in one jurisdiction can put you at risk in the next, forcing companies to choose which laws to break.
CIOs must base their AI governance decisions on today’s patchwork of state legislative frameworks, rather than the federal framework they hope Congress will eventually adopt. The longer this gap persists, the more enterprise AI governance becomes less about technology adoption and more about legal micromanagement. This challenge falls on CIOs as AI runs not only one department’s technology stack, but also HR, marketing, customer data, cybersecurity, and regulatory compliance simultaneously.
Recruitment challenges
Employment most clearly illustrates the problem, as there is typically no other task or function that requires AI to perform this frequently on so many people. Just because you have a large volume doesn’t mean you’ll hire it in the places where problems occur first, but it does mean you’ll hire them in the places where problems are most likely to occur.
The tool that narrows down 100,000 resumes to a shortlist of 10 makes decisions about commute times, work experience, and career gaps. No one reflected that judgment in policy. No one reviewed the shortlist until it reached the recruiter. LinkedIn attracts candidates who have never applied before. Data providers scour the open internet to identify and recruit people who won’t come forward.
Tools trained on decades of history inherit the patterns of that history.
This requires no malice. Commute time filters can silently exclude applicants from underserved areas without decision makers choosing to discriminate. When applicant numbers are skewed 70% to 30% along gender lines, a difficult question arises: should companies normalize the ratio, leave it alone, or go with what the underlying performance data shows? The third option is the only one that seems neutral. This assumes unbiased historical performance data, the same assumption that is not true in the retail promotion context discussed below. Tools trained on decades of history inherit the patterns of that history.
There is no clear answer, and states that have tried to write down the answer not only set different standards. Some point in the opposite direction. The legal exposure that businesses face arises from a variety of consequences when neutral policies and practices unfairly harm members of protected groups. This exposure does not result from someone’s intentions or whether a company has disclosed its practices, but from how AI performs when deployed at scale against real humans.
Development and deployment: Where is the real danger?
Vendors build AI systems, but the companies that use them decide where to deploy them, what role they play in the resulting decisions, and whether their use complies with each state’s laws. The laws do not agree on legal hooks. Some will go to the developer. Some will go to the deployer. Some people reach both.
Assignments move from one framework to the next. But one fact remains the same. It means that the companies operating the tools against real people continue to exist in all jurisdictions at the same time. Deployment, rather than development, concentrates exposure, regardless of how a single statute allocates responsibilities. A vendor’s safety testing claims or federal review status do not take the risk off the adopter’s books.
This dynamic extends beyond employment. Retailers that provide camera disclosure and opt-outs can serve ads consistent with race, gender, and age tracking policies. Disclosure and opt-outs solve the notification problem. It does nothing about impact because the underlying model chooses engagement, not demographics chosen by someone. Even when retailers act transparently, they can produce biased results. That’s the important point. Consent mechanisms do not resolve disparate influences. Promotion decisions carry the same risks. Tools trained on decades of performance data inherit the patterns of that history and can produce results that no one in your company would have chosen.
Is a single federal standard the answer?
A federal framework with one set of standards, rather than 30 individual state standards, seems like the obvious solution. The White House tried twice last year. First, it created a task force to challenge state AI laws in court. We have also established a voluntary security review window for AI developers. Neither is a substitute for law. Executive orders cannot preempt state laws without Congressional action, and voluntary reviews do not impose compliance obligations on vendors who can opt in or out.
A single federal standard remains a better end state than 30 conflicting federal standards.
But even with a working mechanism, the law cannot answer the more difficult question of what level of algorithmic bias can be tolerated. The White House’s efforts have been procedurally unsuccessful. This policy issue remains unresolved for other reasons. Zero bias is not possible. No human being is unbiased, and neither is the data they generate.
There are no members of Congress on either the right or the left who are active in drawing that line. The problem is not prejudice itself. For decades, anti-discrimination laws have tolerated imperfect and biased human decision-making without requiring zero. Algorithms change politics by making residual bias more readable. You can measure, report, and audit that bias after the fact. Legislation will need to specify acceptable limits and defend them. It means acknowledging that the approved system is still biased, and saying exactly how biased it is. Doing that is politically more difficult than tolerating the same bias when it spreads across thousands of human managers and no one has to sign the numbers.
A single federal standard remains a better end state than 30 conflicting federal standards. But even if the conclusion remains the same, the other risk is worth recognizing. Technology advances so quickly that today’s most difficult questions, especially bias normalization, may have technical answers that no one has built yet. Federal standards created today can entrench today’s assumptions and impede tomorrow’s solutions. Considering this risk requires careful drafting. It does not justify the patchwork of state standards, the costs of which continue now and every day.
what shall we do today
None of this changes what companies can do today. CIOs need to map AI by use case and jurisdiction so they understand the laws that apply to each deployment. Next, governance needs to be built around practices that should exist regardless of the regulatory landscape, such as clear terms of use, reliable data provenance, and human review where results matter most.
Congress, courts, and future administrations will continue to shape AI regulations, but enterprise AI won’t wait for them. Companies already have systems in place based on laws that states can enforce today. CIOs need to govern within the legal framework that currently exists, not the federal framework they hope will eventually become a reality.
Jon Polenberg is a shareholder and vice chairman of Becker’s Business Litigation Practice. As a Florida business trial attorney, he is known for his advocacy and strategic acumen in complex commercial litigation. John has decades of experience representing companies in high-stakes litigation, handling complex legal disputes with precision, and striving for excellence. His practice spans a wide range of industries, helping companies resolve issues that impact their operations, reputation and financial interests.