United States (Federal) — data protection and AI governance
HIPAA, GLBA, COPPA, FCRA, FERPA (Lois sectorielles), in force since Varies. Supervisory authority: FTC + Régulateurs sectoriels.
Data protection
- Instrument
- HIPAA, GLBA, COPPA, FCRA, FERPA (Lois sectorielles)
- In force since
- Varies
- Authority
- FTC + Régulateurs sectoriels
- Penalties
- Varie (millions $)
- Key obligations
- HIPAA: santé
- GLBA: finance
- COPPA: enfants
- FCRA: crédit
What the engine decides here
These three attributes are what an agent decision depends on in this jurisdiction. They are modelled, sourced and dated.
- Transfer regime
- Open
No general transfer regime applies: moving data out is not conditioned by this framework.
- Localisation mandate
- Not modelled
- Automated decision rights
- Not modelled
- Verified on
- 2026-08-14
Three decisions, computed just now
Same actions, this jurisdiction's context. These answers come out of the engine as the page renders — the same function the API calls.
- ALLOW
Read an internal contract
Low-risk operation
- ALLOW
Send a customer record to FR
Low-risk operation
- DENY
Decide on a job application
Decision reserved for a human
Advisory decisions. StructureClerk decides; your infrastructure enforces.
AI governance
- Framework
- NIST AI RMF (volontaire)
- Status
- guidance
- Key points
- EO 14110 révoqué (jan. 2025)
- NIST AI RMF 1.0 volontaire
- Application sectorielle (FTC, EEOC)
Cybersecurity
- Framework
- NIST CSF 2.0
- Key points
- Govern, Identify, Protect, Detect, Respond, Recover
Do your agents operate in United States (Federal)?
The authority API makes these attributes executable: an ALLOW, APPROVE, DENY or ESCALATE decision before the agent acts, with signed evidence any third party can verify.