United States (Federal) — data protection and AI governance

HIPAA, GLBA, COPPA, FCRA, FERPA (Lois sectorielles), in force since Varies. Supervisory authority: FTC + Régulateurs sectoriels.

US_FEDPriority jurisdiction — re-verified every cycleVerified on Lire en français

Data protection

Instrument
HIPAA, GLBA, COPPA, FCRA, FERPA (Lois sectorielles)
In force since
Varies
Penalties
Varie (millions $)
Key obligations
  • HIPAA: santé
  • GLBA: finance
  • COPPA: enfants
  • FCRA: crédit

What the engine decides here

These three attributes are what an agent decision depends on in this jurisdiction. They are modelled, sourced and dated.

Transfer regime
Open

No general transfer regime applies: moving data out is not conditioned by this framework.

Localisation mandate
Not modelled
Automated decision rights
Not modelled
Verified on
2026-08-14

Three decisions, computed just now

Same actions, this jurisdiction's context. These answers come out of the engine as the page renders — the same function the API calls.

  • Read an internal contract

    Low-risk operation

    ALLOW
  • Send a customer record to FR

    Low-risk operation

    ALLOW
  • Decide on a job application

    Decision reserved for a human

    DENY

Advisory decisions. StructureClerk decides; your infrastructure enforces.

AI governance

Framework
NIST AI RMF (volontaire)
Status
guidance
Key points
  • EO 14110 révoqué (jan. 2025)
  • NIST AI RMF 1.0 volontaire
  • Application sectorielle (FTC, EEOC)

Cybersecurity

Framework
NIST CSF 2.0
Key points
  • Govern, Identify, Protect, Detect, Respond, Recover

Do your agents operate in United States (Federal)?

The authority API makes these attributes executable: an ALLOW, APPROVE, DENY or ESCALATE decision before the agent acts, with signed evidence any third party can verify.

Other jurisdictions — North America