The rapid adoption of artificial intelligence across industries, particularly in healthcare, is outpacing the development of unified regulatory frameworks in the United States. Legal and security experts highlight that AI use cases—ranging from clinical documentation to claims processing—introduce significant privacy, security, and legal risks. In the absence of comprehensive federal regulation, organizations are advised to rely on frameworks such as the NIST AI Risk Management Framework to guide governance and risk mitigation efforts, especially as AI becomes more deeply integrated into sensitive sectors like healthcare.
Simultaneously, the proliferation of state-level AI regulations has created a complex and inconsistent compliance landscape. In 2025, nearly every state introduced or enacted AI-related legislation, resulting in a patchwork of requirements that vary in definitions, compliance obligations, and enforcement. This fragmented approach complicates risk management for organizations operating across state lines, as they must navigate conflicting rules and adapt to a rapidly evolving regulatory environment without clear national standards.

See the reporting duties and controls this puts on the clock.
1 event from the most recent confirmed update back to the earliest known activity.
On 2025-12-29, published commentary and interviews highlighted growing AI adoption in healthcare for functions such as documentation, claims processing and decision support, while warning of privacy, security, legal and regulatory risks. The same day, advocates also argued that the fragmented state-by-state U.S. AI regulatory landscape requires a unified federal framework to improve security, trust and responsible innovation.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.