The headlines about AI regulation are everywhere, and they range from "the government is about to lock down everything" to "nothing is settled so don't worry about it." Neither of those is useful if you're running a 20-person company trying to figure out whether you need to actually do something.
Short answer: some of this affects you now, some of it will within a year or two, and a good chunk of it is genuinely not your problem yet. This piece helps you sort which is which — and gives you a few concrete steps that cost almost nothing but keep you clearly on the right side of what's coming.
This is not legal advice. If you have a specific compliance concern, talk to a lawyer. This is informed orientation for a business owner who needs to know where to pay attention.
Why Small Businesses Can't Completely Ignore This
Historically, when new regulations hit an industry, small businesses either get an exemption or get so far down the enforcement priority list that it doesn't matter for years. That's still partly true with AI. But a few things make this wave different:
The rules aren't coming from one place. AI regulation in the U.S. right now is a patchwork — federal agencies, state legislatures, and sector-specific rules are all moving at different speeds. You can be in full compliance with federal guidance and still have a problem under a state law that took effect last month.
Some of what's already active looks like existing law, applied to AI. The FTC's rules on deceptive marketing apply to AI-generated content. EEOC hiring guidance applies to AI-assisted screening. These aren't hypothetical future regulations — they're current enforcement frameworks being applied to AI behavior right now.
Being a small business isn't a shield if you're doing something that harms someone clearly. Enforcement tends to follow egregious cases, not company size. If you're using AI in a way that discriminates in hiring or misleads customers, size doesn't give you cover.
The Signal: Three Areas Worth Acting On Now
1. Marketing and Advertising Claims
This is probably the most immediately relevant area for most small businesses.
The FTC has been clear: if you use AI to generate marketing content — testimonials, reviews, product descriptions, endorsements — the same truth-in-advertising rules apply as if a human wrote it. AI-generated fake reviews are deceptive. AI-generated before-and-after images that misrepresent a product are deceptive. AI-written testimonials attributed to real customers who didn't say those things are deceptive.
This isn't a new law. It's the existing FTC Act, and the FTC has been explicit that AI doesn't create a carve-out.
What's worth acting on:
- Don't use AI to generate or fabricate customer reviews or testimonials — this was always against the rules, but the tooling now makes it easy to do at scale, which makes enforcement more likely.
- If you're using AI-generated imagery in advertising (especially health, beauty, fitness, financial results), be careful about what it implies. An AI-generated image of a "result" that's implausible or misleading is the same problem as a doctored photo.
- If you have affiliate relationships or sponsored content, AI doesn't change your disclosure obligations — they still apply.
Most small businesses using AI for copywriting, social posts, or email drafting are fine. The issue is AI-generated claims that aren't true, not AI-assisted writing that is.
2. Hiring and HR Decisions
Several states — Colorado, Illinois, New York City, and others — have passed or are passing laws that specifically regulate the use of AI in employment decisions. New York City's Local Law 144, which has been in effect since 2023, requires employers using automated employment decision tools (AEDTs) to conduct annual bias audits and notify candidates when such tools are used.
If you're using AI to screen resumes, rank candidates, or make any part of the hiring decision, you need to know whether you're in a jurisdiction with active requirements — and more are coming.
Even outside those jurisdictions, the EEOC has made clear that if an AI tool produces discriminatory outcomes in hiring, the employer is responsible. "The vendor told me the tool was unbiased" is not a defense.
What's worth acting on:
- If you're using an AI-powered applicant tracking system or any software that scores or ranks candidates, ask the vendor directly: has this tool been audited for bias? Do you help clients meet disclosure requirements in regulated jurisdictions?
- If you're in New York City specifically, or operating there, look at Local Law 144 requirements now — they apply to employers with NYC-based roles.
- Keep humans meaningfully in the loop for hiring decisions. "AI flagged these three candidates" plus a human review is a very different posture than "AI rejected 400 applications automatically."
3. Client Data and Privacy
If your use of AI involves putting customer or client data into an AI tool — a CRM connected to an AI assistant, customer service chatbots, document summarization tools — you need to know where that data goes and what the tool's vendor does with it — in other words, what happens to the data you paste into AI.
This matters for two reasons:
Existing privacy law may already require it. If you handle health information, you're subject to HIPAA. Financial data has its own frameworks. Several states (California, Colorado, Virginia, Connecticut, and others) have consumer data privacy laws that give residents rights over their personal data — and feeding that data into a third-party AI system may be a "sale" or "sharing" under those laws.
Contractual obligations. Many client service agreements — especially in professional services, healthcare, and finance — include data handling clauses. Sending client data through an external AI tool without checking whether that's permitted is a contract risk, not just a regulatory one.
What's worth acting on:
- For any AI tool that processes customer or client data, read the privacy policy and data processing terms. Specifically: does the vendor use your data to train their models? Where is it stored? Who can access it?
- If you're in a regulated industry (healthcare, finance, legal), this conversation probably needs to involve your attorney or compliance person before you deploy the tool.
- If you're using something like ChatGPT's free tier for work that involves client specifics, switch to a business-tier account that offers data processing agreements, or stop putting client details in the prompt.
The Noise: What You Can Probably Stop Worrying About (For Now)
The EU AI Act. This is sweeping, comprehensive regulation — and it's largely not your concern unless you're selling AI systems or AI-embedded products into the EU, or you're a company of significant scale. The compliance obligations for most SMBs operating domestically are minimal to nonexistent right now.
Federal AI legislation. Congress has introduced a lot of AI-related bills. Very few have passed. Federal comprehensive AI legislation in the U.S. is likely still years away from affecting your day-to-day operations. Watch it, but don't build your compliance strategy around a law that doesn't exist yet.
"AI disclosure" as a blanket requirement. Some people are asking whether you have to tell customers every time AI was involved in something. Right now, there's no general legal requirement to disclose AI use in the U.S. The disclosure requirements that exist are specific: disclosure in hiring (in some jurisdictions), disclosure when AI is impersonating a human in real-time conversation (some state laws address this), and disclosure in political advertising (several states). General AI-assisted drafting doesn't trigger a legal disclosure obligation.
That said, voluntary transparency — telling clients you use AI tools the same way you'd mention other software you use — is often good for trust and worth considering on its own merits.
A Short Checklist: Low-Effort, High-Value
You don't need a compliance program. You need to not be caught flat-footed. Often that starts with a simple written AI policy. Here's what a two-hour review looks like:
-
Audit your AI tools list. Write down every AI tool your business is actively using. Include anything your team uses informally (ChatGPT, Grammarly Business, an AI-powered CRM feature, etc.).
-
Flag anything that touches client data or hiring. Those get closer scrutiny on vendor terms.
-
Read the data processing terms for your top two or three tools. Look specifically for: model training on your data, data retention periods, and whether they offer a Data Processing Agreement (DPA) if you need one.
-
Check your jurisdiction for hiring tool rules. If you have employees or hire in New York City, Illinois, or Colorado, search for the specific AI hiring rules that apply there.
-
Review any marketing content that makes specific claims. If AI generated claims about results, testimonials, or endorsements, verify they're accurate and attributable.
That's it. Most small businesses can get to a defensible, reasonable posture in an afternoon.
The Bigger Picture
Regulation always lags technology. Right now, the AI regulatory landscape is genuinely fragmented and incomplete — but the direction of travel is clear. Disclosure requirements will expand. Bias audit requirements will spread beyond New York City. Data handling rules will get stricter. Companies that wait for final rules to take effect before thinking about any of this will be scrambling.
The businesses that handle this well aren't the ones with the biggest legal teams. They're the ones that treat it like any other operational risk: know what you're actually doing, make sure it's above-board, and don't wait for a problem to force the conversation.
This is exactly the kind of review we walk through with clients — mapping out their AI tool usage, flagging real exposure, and figuring out what's worth addressing and in what order. If you'd like that kind of structured thinking applied to your business, book a strategy call and we'll start there.
