United States - Algorithmic Accountability Act (H.R. 5628)

Algorithmic Accountability Act (H.R. 5628, House version)

United States

RAI-US-NA-AAH5HXX-2023
Proposed(Officially filed for action)
BillGovernance and OversightAccountability and DocumentationTransparency and Disclosure
Export PDF

The Algorithmic Accountability Act (H.R.5628) directs the Federal Trade Commission (FTC) to promulgate rules requiring covered entities that deploy automated decision systems used to make 'critical decisions' to perform and document ongoing impact assessments and to submit summary reports to the FTC. The bill creates a public repository, authorizes a Bureau of Technology within the FTC, and treats violations as unfair or deceptive acts enforceable under the FTC Act. (congress.gov)

Summary

The Algorithmic Accountability Act of 2023 (H.R.5628) is a federal legislative proposal that would require large and otherwise-specified entities that deploy automated decision systems (including systems using machine learning, statistics, or other AI/data-processing techniques) to conduct ongoing impact assessments and to report summary information to the Federal Trade Commission (FTC). The scope centers on so-called "augmented critical decision processes," defined as processes that employ automated decision systems to make decisions with legal, material, or similarly significant effects on an individual's life (including in areas such as education, employment, essential utilities, financial services, healthcare, housing, and legal services).

Key elements: the FTC must promulgate regulations (in consultation with NIST, OSTP, the National AI Initiative, standards bodies, civil-rights and consumer advocates, and other stakeholders) not later than two years after enactment to define categories of critical decisions, the content and format of impact assessments, and reporting requirements. Covered entities (defined by jurisdictional reach of the FTC and by thresholds tied to revenue, equity value, data holdings, and related company structures) would be required to perform detailed, documented impact assessments when developing, deploying, or materially changing automated decision systems used in critical decisions. Impact assessments must include reviews of baseline decision processes (for replacements or augmentations), description of decision logic, data sources, metrics used to evaluate performance (including differential performance by demographic groups), testing and validation procedures, monitoring plans, documentation of stakeholder consultation, attempts at remediation for identified harms, and records of items that could not be completed during assessment (with rationale).

The bill requires submission of a limited summary report (fields to be set by FTC rulemaking) to the FTC for qualifying systems and the establishment of a publicly accessible repository—the repository will contain a limited subset of information from summary reports to inform consumers, researchers, and advocates while balancing commercial risk and privacy constraints. The FTC must publish an annual anonymized aggregate report describing trends, lessons learned, and recommendations.

Enforcement mechanisms mirror the FTC's authorities under the FTC Act: violations of the Act or promulgated regulations would be treated as unfair or deceptive acts or practices, subject to the Commission's full investigatory and remedial powers. The Act further authorizes state attorneys general to bring parens patriae civil actions and preserves state, tribal, and local laws (no preemption). The bill authorizes establishment of a Bureau of Technology within the FTC, headed by a Chief Technologist, and authorizes the Chair to appoint technical and enforcement staff (minimum staffing levels are specified) to support rulemaking and enforcement, with appropriations authorized as necessary.

The Act includes provisions for guidance, training materials to help entities determine covered status, periodic regulatory review (at least every five years), interagency cooperation, and safeguards for privacy and intellectual property. It treats impact assessment obligations as ongoing and adaptive, allowing the FTC to design tailored requirements by category of critical decision and stage of system lifecycle. If enacted, the Act would create a structured federal compliance and oversight regime for high-impact automated decision systems, centered on mandatory impact assessment, public transparency via a repository, and FTC-led enforcement and technical capacity-building. ([congress.gov](https://www.congress.gov/bill/118th-congress/house-bill/5628/text))

Full article

Read full text ↗

Overview

The Algorithmic Accountability Act of 2023 (H.R.5628) is a proposed federal statute that would require covered entities to conduct and document ongoing impact assessments for automated decision systems used in "augmented critical decision processes"—that is, automated or AI-based systems that make decisions with legal, material, or similarly significant effects on individuals (e.g., in healthcare, housing, employment, finances, education). The Act directs the Federal Trade Commission (FTC) to promulgate implementing regulations (in consultation with NIST, the Office of Science and Technology Policy (OSTP), and the National AI Initiative) within a statutory period and to establish a public repository aggregating limited summary information for consumer and research use. The bill also establishes a Bureau of Technology within the FTC to provide technical expertise and authorizes staff appointments to support enforcement and oversight. The Act adopts enforcement mechanisms modeled on the FTC Act and empowers state attorneys general to bring parens patriae actions; it preserves state and local laws and explicitly prohibits private-contract clauses from overriding the Act's prohibitions. (Primary source: Congress.gov — H.R.5628 text, PDF at BILLS-118hr5628ih.pdf.)

Definitions

The Act defines core terms used throughout the bill, including "automated decision system" (any system, software, or process—excluding passive infrastructure—whose computational result serves as the basis for decisions), "augmented critical decision process" (a process using an automated decision system to make a critical decision), "critical decision" (decisions with legal, material, or similarly significant effects, with enumerated categories such as education, employment, essential utilities, family planning, financial services, healthcare, housing, and legal services), "covered entity" (entities under FTC jurisdiction meeting revenue, equity, or data-holding thresholds), "impact assessment" (ongoing study and evaluation of systems and their consumer impacts), and "summary report" (a limited subset of impact-assessment information to be submitted to the FTC). These definitions establish the legal scope and thresholds for compliance and enforcement under the Act.

Governance and Institutional Framework

The FTC is the primary regulator under the Act and is directed to promulgate regulations under the Administrative Procedure Act (5 U.S.C. 553) within two years of enactment (subject to consultation with NIST, OSTP, the National AI Initiative, standards bodies, academia, civil-rights and consumer advocates, and industry). The FTC must design the reporting and repository systems, adopt categories of critical decisions, and issue guidance and templates to assist covered entities. The Act creates within the FTC a Bureau of Technology led by a Chief Technologist (minimum staffing and authority to appoint technical experts outside civil service constraints are specified) and authorizes additional enforcement personnel for the Bureau of Consumer Protection. The Commission may negotiate information-sharing and enforcement-coordination agreements with other federal agencies and preserve other agency authorities; the Act also requires the FTC to share summary reports securely with NIST, OSTP, and appropriate federal agencies to inform standards and rulemaking. See H.R.5628 text for staff-authority and bureau provisions.

Key Focus Areas

The bill's regulatory focus includes the following areas: mandatory impact assessments and documentation (development, validation, deployment, monitoring, and remediation plans); standardized summary reporting to the FTC for qualifying systems; a public, searchable repository with limited, consumer-relevant fields to promote transparency while mitigating commercial risk and privacy harms; stakeholder consultation and documentation of outreach to affected communities; specific attention to differential performance and disparate impacts by demographic groups; data provenance and source documentation; evaluation metrics and testing protocols; monitoring and incident reporting; and documentation of infeasible assessment elements with rationale. The Act also contemplates tiered or category-specific requirements—allowing the FTC to craft tailored assessment obligations and summary-report fields by category of critical decision and stage of system lifecycle. Finally, the bill requires guidance materials, templates, and training from the FTC to support compliance and to assist entities in determining whether they are covered entities.

Implementation Framework

The FTC must promulgate regulations within two years after enactment and those regulations become effective two years after promulgation. Regulations will specify: the categories of critical decisions; the minimum content of impact assessments (e.g., baseline comparisons, data sources, technical design descriptions, testing/validation metrics, monitoring plans, stakeholder consultation records, mitigation/remediation actions); the format and fields for summary reports; conditions for public repository publication; and exemptions or adjustments where privacy or security concerns apply. The Commission is required to consider privacy limits and existing data-protection law when deciding what assessment material may be stored or published. The Act authorizes appropriations and staffing to operationalize these requirements and instructs the FTC to issue guidance and templates to simplify compliance and to train potential covered entities in evaluating their obligations.

Monitoring and Evaluation

Covered entities must maintain the full impact-assessment documentation and submit limited summary reports when required. The FTC will publish an annual anonymized, machine-readable report summarizing trends, aggregated statistics, and lessons learned from the submitted summaries to inform updates to guidance and recommendations to other agencies. The public repository will be updated quarterly; the FTC must ensure repository discoverability, searchability, accessibility, and downloadability consistent with applicable federal guidance (e.g., 21st Century Integrated Digital Experience Act and OMB guidance). The FTC is also required to review the regulations at least every five years to update requirements in light of new evidence, evolving technologies, and stakeholder input.

Penalties, Liability, and Appeals

Violations of the Act or of regulations promulgated under it are treated as violations of rules defining unfair or deceptive acts or practices under the FTC Act; enforcement will be by the FTC with the same jurisdiction, powers, and duties as under the FTC Act, including injunctive relief, civil penalties where authorized, and other remedies. The Act authorizes state attorneys general to bring parens patriae civil actions on behalf of residents; the FTC may intervene, be heard, or appeal decisions. The bill preserves other agency authorities and does not preclude enforcement under other federal or state laws. There is no express private right of action created by the bill, but state enforcement and FTC enforcement provide significant enforcement channels. See enforcement provisions at H.R.5628.

Relationship to Other Instruments

The Act is designed to operate within the FTC's consumer-protection authority and to coordinate with existing federal agencies and programs: the National Institute of Standards and Technology (NIST) for standards, OSTP for policy guidance, and other regulators with sectoral authority (e.g., HHS for health, CFPB for consumer finance) for consistent treatment across jurisdictions. It references the FTC Act and cross-references OMB and federal information-access statutes for repository design. The Act explicitly preserves state, tribal, and local law and forbids preemption of such laws; it also prohibits contractual clauses that would waive or limit obligations under the Act.

International Alignment

While the Act is a domestic U.S. regulatory proposal, its impact-assessment and transparency architecture echoes global approaches to high-risk AI systems (for example, the European Union's AI Act emphasis on high-risk system obligations and documentation). The requirement for detailed impact assessments, recordkeeping, and public transparency aligns with international trends and would allow interoperability with standards developed by NIST and other standards bodies. The bill's consultative rulemaking approach (including standards bodies and international stakeholders) aims to promote coherence with international norms and facilitate cross-border research and compliance where applicable.

Implementation Timeline

MilestoneTiming (per bill)
Congressional enactment— (requires passage)
FTC promulgation of implementing regulationsNot later than 2 years after date of enactment
Effective date of regulations2 years after promulgation of regulations
Repository developmentNot later than 180 days after FTC promulgates regulations; public by 180 days after regulations' effective date
Bureau staffing minimumsChair must appoint at least 50 personnel within 2 years after enactment; additional 25 enforcement personnel authorized
Annual FTC reportFirst report due within 1 year after regulations' effective date, then annually

Sources and References

SourceType
H.R.5628 — Algorithmic Accountability Act of 2023 (Congress.gov text)Primary Source
BILLS-118hr5628ih.pdf (House bill PDF)Primary Source
S.2892 — Algorithmic Accountability Act of 2023 (Senate text; identical)Primary Source
([congress.gov](https://www.congress.gov/bill/118th-congress/house-bill/5628/text))

Requirements for a company

What an organisation has to do under United States - Algorithmic Accountability Act (H.R. 5628), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Not yet in force (Proposed). These requirements apply once the instrument takes effect and may change before then.

Must do

12
  • Determine if your entity is covered by the Act using FTC guidance.Entities deploying automated decision systems in critical decision processes.
  • Conduct and document ongoing impact assessments for automated decision systems.Covered entities deploying automated decision systems in critical decision processes.
  • Document system design, data sources, testing, monitoring, and remediation plans.Covered entities performing impact assessments.
  • Pay specific attention to differential performance and disparate impacts by demographic groups.Covered entities performing impact assessments.
  • Document data provenance and all source data used in the automated decision system.Covered entities performing impact assessments.
  • Document evaluation metrics and testing protocols used for the automated decision system.Covered entities performing impact assessments.
  • +6 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under United States - Algorithmic Accountability Act (H.R. 5628), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Entities deploying automated decision systems in critical decision processes.Determine if your entity is covered by the Act using FTC guidance.
Use FTC guidance/templates to assess revenue, equity, and data thresholds; document determination
Before deploying an automated decision system for critical decisions.Critical
2Covered entities deploying automated decision systems in critical decision processes.Conduct and document ongoing impact assessments for automated decision systems.
require covered entities that deploy automated decision systems used to make 'critical decisions' to perform and document ongoing impact assessments
After regulations become effective and before deployment.Critical
3Covered entities performing impact assessments.Document system design, data sources, testing, monitoring, and remediation plans.
mandatory impact assessments and documentation (development, validation, deployment, monitoring, and remediation plans)
During impact assessment performance.Critical
4Covered entities performing impact assessments.Pay specific attention to differential performance and disparate impacts by demographic groups.
specific attention to differential performance and disparate impacts by demographic groups
During impact assessment performance.Critical
5Covered entities performing impact assessments.Document data provenance and all source data used in the automated decision system.
data provenance and source documentation
During impact assessment performance.Critical
6Covered entities performing impact assessments.Document evaluation metrics and testing protocols used for the automated decision system.
evaluation metrics and testing protocols
During impact assessment performance.Critical
7Covered entities deploying automated decision systems.Document monitoring procedures and incident reporting for the automated decision system.
monitoring and incident reporting
Continuously, after deployment.Critical
8Covered entities performing impact assessments.Conduct and document stakeholder consultation and outreach to affected communities.
stakeholder consultation and documentation of outreach to affected communities
During impact assessment performance.Critical
9Covered entities deploying automated decision systems.Prepare and submit standardized summary reports to the FTC as required by regulations.
standardized summary reporting to the FTC for qualifying systems
As specified by FTC regulations.Critical
10Covered entities deploying automated decision systems.Maintain full impact assessment documentation and make it available to the FTC upon request.
Covered entities must maintain the full impact-assessment documentation
Continuously, for the system's lifecycle.Critical
11Covered entities submitting summary reports.Coordinate summary report submissions with appropriate redaction for privacy or commercial risk.
Coordinate summary-report submissions with appropriate redaction for privacy/commercial risk; ensure accuracy
Before submitting summary reports.Important
12Covered entities performing impact assessments.Document any infeasible assessment elements along with a clear rationale.
documentation of infeasible assessment elements with rationale
During impact assessment performance.Important

© Regulations.AI · updated on 13-Jun-2026