United States - AI Accountability Act (S. 2892)
Algorithmic Accountability Act (S. 2892, Senate version)
United States
RAI-US-NA-AAS2SXX-2023S.2892 (Algorithmic Accountability Act of 2023) would require certain companies under FTC jurisdiction that develop or deploy automated decision systems for high‑impact "critical decisions" to conduct ongoing impact assessments, maintain documentation, submit summary reports to the Federal Trade Commission, and register selected information in a publicly accessible FTC repository. The bill directs the FTC to promulgate implementing regulations and creates staffing and resource authorizations to support oversight and enforcement.
Summary
Read full text ↗Plain English
Overview
The Algorithmic Accountability Act of 2023 (S.2892) directs the Federal Trade Commission ("Commission" or "FTC") to promulgate rules requiring covered entities to perform and retain impact assessments for automated decision systems and "augmented critical decision processes"—systems that participate in making decisions with legal, material, or similarly significant effects on consumers. The bill (introduced Sept. 21, 2023) targets high‑impact uses such as education, employment, utilities, family planning, financial services, healthcare, housing, and legal services, and sets objective thresholds for "covered entity" status based on revenue, equity value, consumer data scale, or ownership relationships. The FTC is required to build a publicly accessible repository of summary report data to enable researchers, advocates, and consumers to study these systems while retaining mechanisms to protect sensitive information. For full statutory text and legislative status, see the official resources: Congress.gov - S.2892 text and the sponsor press release at Sen. Wyden press release. The bill also authorizes FTC staffing and coordination with federal standards bodies such as NIST and the Office of Science and Technology Policy (OSTP), reinforcing an evidence‑driven regulatory approach.
Definitions
S.2892 contains precise definitions to focus obligations: "automated decision system" (any computation‑based system used as basis for a decision, excluding passive infrastructure), "augmented critical decision process" (an automated decision system making a critical decision), "critical decision" (decisions affecting access, cost, terms, availability of services in specified categories), "covered entity" (entities under FTC jurisdiction that deploy augmented critical decision processes and meet financial or data scale thresholds), "impact assessment" (ongoing study of system impacts), "summary report" (machine‑readable subset of impact assessment data for submission), and "third‑party decision recipient" (any party beyond the consumer and covered entity that receives decision outputs). These definitions establish the statutory scope and the triggers for compliance obligations.
Governance and Institutional Framework
The Act centralizes regulatory authority at the Federal Trade Commission while mandating interagency consultation. Within two years of enactment the FTC must promulgate rules (per the Administrative Procedure Act) in consultation with the Director of NIST, the Director of the National AI Initiative (or equivalent office), OSTP, standards bodies, industry, academia, civil‑society advocates, and impacted communities. To operationalize oversight, S.2892 authorizes creation of a Bureau of Technology within the FTC and the appointment of at least 50 personnel dedicated to technical, standards, and research functions, plus 25 additional enforcement staff in the Bureau of Consumer Protection for civil enforcement. The FTC must also negotiate cooperation agreements with other Federal agencies and provide secure access to summary reports to NIST, OSTP, and agency heads for standards development. This structure pairs technical capacity building inside the FTC with cross‑agency alignment to support consistent rulemaking and enforcement. See the statutory text at Congress.gov - S.2892 text for governance provisions.
Key Focus Areas
S.2892’s substantive compliance regime concentrates on impact assessment, documentation, transparency, mitigation, and public reporting. Impact assessments must describe the decision purpose, datasets, data provenance and quality, training and labeling practices, technical and business performance metrics, benchmarking and test procedures, and evaluations of differential performance by race, sex, age, disability, religion, socioeconomic and other categories the FTC may specify. Assessments must also document stakeholder consultation, security and privacy protections, consumer rights pathways (contest, correct, appeal, opt‑out), and remediation plans for likely material negative impacts. Covered entities must keep full assessment documentation for three years beyond deployment, submit initial summary reports prior to a new system’s deployment, and submit annual summaries thereafter in a machine‑readable format defined by the FTC. The FTC will operate a searchable public repository containing a limited subset of summary report fields to promote research and public oversight while considering commercial risk. The bill recognizes tradeoffs between transparency and proprietary risk and explicitly allows the FTC to define repository content that balances those factors. The full bill text provides detailed lists of required elements for assessments and summary reports: Congress.gov - S.2892 text and the sponsor materials at Wyden press release provide context and supporting commentary.
Implementation Framework
The Commission has two years after enactment to adopt regulations under section 553 of title 5, U.S.C. The rulemaking must: define covered entity status and the calculation methods for consumer/data thresholds; set formats and machine‑readable standards for summary reports; prescribe impact assessment requirements and prioritization criteria for multiple systems; issue guidance and training to help entities determine covered status; and create the FTC public repository with search and accessibility features (consistent with the 21st Century Integrated Digital Experience Act). The FTC’s rulemaking must consider administrative burdens, the stage of system development, availability of data, existing privacy constraints, and feasibility. The Act authorizes appropriation of funds to hire specialized personnel, and allows the FTC to appoint certain staff without regard to civil service rules for rapid capability building. The FTC is tasked with producing guidance and training materials that will be periodically updated to reflect experience and stakeholder feedback. Key cross‑agency coordination is required with NIST, OSTP, and the National AI Initiative for standards alignment and technical guidance.
Monitoring and Evaluation
The Act requires ongoing monitoring through annual summary report submissions and retention of full impact assessment documentation for potential FTC inspection. The FTC must review regulations at least every five years and update them as appropriate. The public repository and machine‑readable reporting enable external researchers and civil society to study outcomes, enabling independent monitoring of compliance and system impacts. The bill also provides that the FTC make summary reports available in a private, secure manner to NIST and other Federal agencies to inform standards development. The combination of internal FTC oversight, periodic regulatory review, external researcher access, and interagency standardization is intended to create iterative evaluation loops to refine best practices and regulatory obligations over time.
Penalties, Liability, and Appeals
S.2892 treats violations of the Act and implementing regulations as violations of unfair or deceptive acts or practices under section 18(a)(1)(B) of the FTC Act, enabling the FTC to pursue civil enforcement actions including injunctive relief, civil monetary penalties (as authorized under the FTC Act and implementing statutes), disgorgement, and other remedies available under Federal law. The Act authorizes State attorneys general and other authorized state officials to bring civil actions consistent with the FTC’s powers. The Act also makes it unlawful to knowingly provide substantial assistance to a covered entity in violating the regulations. Civil venue and service provisions are specified, and the Act preserves entities’ rights to appeal administrative decisions under existing statutes. The bill does not create a private right of action in the federal statute but does not preclude state remedies; the FTC’s enforcement discretion and state AG litigation powers are the primary compliance incentives.
Relationship to Other Instruments
The statute is designed to complement existing laws and regulatory frameworks rather than preempt them. It requires coordination with existing privacy, consumer protection, civil rights, and sectoral regulations (for example, healthcare and financial rules), and explicitly states that it does not preempt State, tribal, city, or local laws. The Act references the FTC Act for enforcement mechanisms and directs secure sharing of summary reports with NIST and OSTP to inform standards and future regulation. It anticipates interplay with sectoral regulators where augmented critical decision processes overlap with domains already regulated by agencies such as HHS, CFPB, or state regulators, and requires cooperation agreements with relevant Federal agencies to clarify information‑sharing and enforcement responsibilities.
International Alignment
While focused on U.S. jurisdiction, S.2892 advances policy principles that align with international trends emphasizing risk‑based regulation, impact assessments, transparency, and technical standards (for example, the EU AI Act’s risk‑based approach and various OECD AI principles). The Act mandates consultation with technical standards bodies and NIST, which often coordinate with international standardization bodies, thereby encouraging harmonization of assessment methodologies, reporting formats, and testing practices. The public repository and machine‑readable reporting could facilitate cross‑jurisdictional research and comparability of enforcement approaches, though the bill leaves data export and international enforcement coordination to existing interagency mechanisms and bilateral/multilateral cooperation arrangements.
Implementation Timeline
| Milestone | Date/Period |
|---|---|
| Introduced in Senate | 2023-09-21 |
| Rulemaking deadline (promulgate regulations) | Within 2 years after enactment (statutory) |
| Effect of regulations | Effective 2 years after promulgation (statutory) |
| FTC Bureau staffing minimum appointment | Not later than 2 years after enactment (minimum 50 personnel) |
| Periodic regulatory review | At least every 5 years after promulgation |
Compliance Checklist
| Requirement | Action for Covered Entities |
|---|---|
| Determine covered status | Run revenue, equity, data scale, and ownership tests; document determination; follow FTC guidance |
| Perform impact assessments | Conduct pre‑deployment and ongoing testing/evaluation; document data, metrics, differential impacts |
| Maintain documentation | Retain full impact assessments for 3 years beyond deployment |
| Submit summary reports | File initial summary report prior to deployment and annual summaries in FTC format |
| Stakeholder consultation | Engage internal and external stakeholders; document consultations and outcomes |
| Mitigation and remediation | Implement timely mitigation for likely material negative impacts and document actions |
| Transparency measures | Provide consumer contest/correct/appeal/opt‑out mechanisms and document them in summary reports |
Sources and References
| Source | Type |
|---|---|
| S.2892 - Algorithmic Accountability Act of 2023 (full text) | Primary Source |
| S.2892 - PDF (introduced version) | Primary Source |
| Sen. Wyden press release (sponsor materials) | Primary Source |
The Algorithmic Accountability Act is a proposed U.S. Senate bill that would require certain companies using automated systems for significant decisions to assess their impact, document their operations, and report key information to the Federal Trade Commission.
This bill targets "covered entities" under FTC jurisdiction—companies that deploy automated decision systems in "critical decisions" affecting consumers, such as those related to education, employment, housing, healthcare, and financial services. To be in scope, companies must also meet specific thresholds for revenue, equity value, or the amount of consumer data they handle.
If passed, companies would face several key obligations: - Conduct ongoing impact assessments to study how their automated systems affect consumers, including potential differential impacts based on factors like race or sex. - Maintain detailed documentation of these assessments for three years after a system is deployed. - Submit summary reports to the FTC, with an initial report required before a new system goes live, followed by annual updates. - Register certain information from these reports in a new, publicly accessible FTC repository, balancing transparency with proprietary concerns. - Establish clear pathways for consumers to contest, correct, appeal, or opt-out of decisions made by these systems.
While currently a proposed bill, if enacted, the Federal Trade Commission would have two years to develop detailed rules, which would then take effect two years after their promulgation. This means compliance wouldn't be mandatory for at least four years after the bill becomes law. Violations would be treated as unfair or deceptive practices under the FTC Act, allowing the FTC to levy civil monetary penalties, seek injunctive relief, and demand disgorgement. State attorneys general could also bring enforcement actions. A practical pitfall for companies is the extensive, ongoing nature of the impact assessments and documentation, which will require significant internal resources and expertise, even for systems that seem straightforward.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 9 marked completePlain-English obligations under United States - AI Accountability Act (S. 2892). Not legal advice — verify against the official text before relying on it.
- #1Critical
Applies to: Entities potentially deploying automated decision systems.
“S.2892 contains precise definitions to focus obligations: ... 'covered entity' (entities under FTC jurisdiction that deploy augmented critical decision processes and meet financial or data scale thresholds)”
- #2Critical⏰ Before placing on market, then ongoing
Applies to: Covered entities deploying augmented critical decision processes.
“The Algorithmic Accountability Act of 2023 (S.2892) directs the Federal Trade Commission... to promulgate rules requiring covered entities to perform and retain impact assessments for automated decision systems...”
- #3Critical⏰ Before placing on market, then ongoing
Applies to: Covered entities performing impact assessments.
“Impact assessments must describe the decision purpose, datasets, data provenance and quality, training and labeling practices, technical and business performance metrics, benchmarking and test procedures, and evaluations of differential performance by race, sex, age, disability, religion, socioeconomic and other categories the FTC may specify.”
- #4Critical⏰ Before placing on market, then ongoing
Applies to: Covered entities performing impact assessments.
“Assessments must also document stakeholder consultation, security and privacy protections, consumer rights pathways (contest, correct, appeal, opt‑out), and remediation plans for likely material negative impacts.”
- #5Critical⏰ 3 years after deployment ends
Applies to: Covered entities deploying augmented critical decision processes.
“Covered entities must keep full assessment documentation for three years beyond deployment.”
- #6Critical⏰ Before placing on market
Applies to: Covered entities deploying new augmented critical decision processes.
“Covered entities must... submit initial summary reports prior to a new system’s deployment.”
- #7Critical⏰ Annually
Applies to: Covered entities deploying augmented critical decision processes.
“Covered entities must... submit initial summary reports prior to a new system’s deployment, and submit annual summaries thereafter in a machine‑readable format defined by the FTC.”
- #8Critical⏰ As needed
Applies to: Covered entities deploying augmented critical decision processes.
“Assessments must also document... remediation plans for likely material negative impacts.”
- #9Critical⏰ Before placing on market
Applies to: Covered entities deploying augmented critical decision processes.
“Assessments must also document... consumer rights pathways (contest, correct, appeal, opt‑out).”
Related Regulations
Algorithmic Accountability Act (H.R. 5628, House version)
United States97% similar
Preventing Algorithmic Collusion Act (S. 232, 2025)
United States91% similar
Federal A.I. Governance and Transparency Act (H.R. 7532)
United States90% similar
Concerning algorithmic discrimination
United States90% similar
An act to amend the civil rights law and the executive law, in relation to the use of artificial intelligence systems
New York, United States89% similar
© Regulations.AI — created on 13-Jun-2026