What AI Regulation Is Actually Coming Next?
July 15, 2026Quick answer: There's no comprehensive federal AI-and-identity framework on the horizon. The most active areas right now are state-level biometric privacy law, evolving contract standards for AI rights, and the unresolved question of whether Section 230 covers a platform's own AI-generated content.
Ask people close to this space what's coming next, and the honest answer is usually some version of "we don't fully know yet," but there are clear areas of active movement worth watching.
The pace problem
The technology is moving faster than policy, which is how it almost always goes. Regulation, by nature, responds to established behavior rather than anticipating it, which means meaningful frameworks tend to lag well behind the technology they're meant to govern. By the time a law addressing a specific AI capability passes, the technology it was written to regulate has often already evolved past the assumptions baked into the statute.
Where the real activity is
Biometric privacy law is the area to watch most closely, particularly whether more states follow Illinois and Texas toward stronger protections, or move in the opposite direction as surveillance technology, license plate readers, public cameras, home security devices, continues expanding largely unchecked. The direction individual states take here over the next few years will likely set the practical floor for biometric protection nationally, in the continued absence of federal legislation.
Contract standards are also shifting
Separately from formal regulation, industry practice itself is evolving. AI-specific rights language is increasingly expected in creator and talent deals, similar to how digital rights became standard during the streaming transition, even in the absence of new law requiring it. In many ways, private contract standards are moving faster than public law, filling gaps that legislatures haven't yet addressed.
The platform liability question
Whether Section 230 protections extend to a platform's own AI-generated content remains a live, unresolved legal question, with early signals from cases like the recent German Google ruling suggesting courts may treat that differently than ordinary user-generated content. How this question gets resolved, in the U.S. and internationally, will shape how much responsibility platforms bear for AI-generated harm to real people going forward.
What this means for individuals in the meantime
Until federal regulation catches up, the most reliable protection available to creators and public figures comes from a combination of careful contract review, proactive registration of likeness rights, and active monitoring for unauthorized use, rather than waiting for a law that fully addresses AI and identity to arrive.
FAQ
Is federal AI regulation coming soon in the U.S.? There's no comprehensive federal framework currently addressing AI and identity specifically. Most meaningful activity is happening at the state level.
What area of regulation is most active right now? Biometric privacy law, particularly in states like Illinois and Texas, is where the most concrete legal activity currently exists.
Will contracts change even without new regulation? Yes. Industry practice is shifting independently, with AI-specific rights language becoming more standard in creator and talent deals regardless of formal legal requirements.
onwards,
The Royall team