United States - AI Bill of Rights
Blueprint for an AI Bill of Rights: Making Automated Systems Work for the American People (OSTP)
United States
RAI-US-NA-BARMAXX-2022The Blueprint for an AI Bill of Rights establishes five non-binding principles to guide developers and deployers in protecting civil rights and privacy in automated systems, published by the White House Office of Science and Technology Policy in 2022. With a status of Adopted, it sets advisory standards for impacts on public rights.
Summary
The Blueprint for an AI Bill of Rights: Making Automated Systems Work for the American People holds the status of Adopted as a non-binding federal guidance document. It was released on October 4, 2022, by the White House Office of Science and Technology Policy (OSTP). Subsequent federal policy initiatives, such as Office of Management and Budget (OMB) Memorandum M-24-10 issued on March 28, 2024, have operationalized its core recommendations to govern artificial intelligence deployment across federal executive agencies.
The Blueprint articulates five foundational principles designed to protect civil rights, data privacy, and democratic values in the technological design and deployment process: Safe and Effective Systems, Algorithmic Discrimination Protections, Data Privacy, Notice and Explanation, and Human Alternatives, Consideration, and Fallback. The principles apply whenever automated systems have the potential to meaningfully impact public rights, opportunities, or access to critical services such as healthcare, housing, employment, education, financial services, and criminal justice.
Because the Blueprint is an advisory framework and non-binding white paper, no federal regulatory or administrative body enforces it, and it does not establish independent statutory penalties, fines, or auditing mandates. Instead, oversight and enforcement rely on voluntary organizational compliance or existing statutory pathways enforced by executive agencies—including civil rights enforcement by the Department of Justice, consumer protection oversight by the Federal Trade Commission, and health privacy regulation by the Department of Health and Human Services.
The document includes a technical companion titled From Principles to Practice, offering actionable guidance, risk assessment steps, and governance templates for technologists, deployers, and policymakers. It functions alongside other rights-focused federal instruments, including the National Institute of Standards and Technology (NIST) Artificial Intelligence Risk Management Framework published on January 1, 2023.
Full article
Read full text ↗Overview
The "Blueprint for an AI Bill of Rights" (OSTP, Oct. 4, 2022) is a non‑binding rights-based framework that describes five principles intended to protect the public from harms caused by automated systems and to guide the design, use, and deployment of those systems. The Blueprint is accompanied by a technical companion that provides concrete steps and examples for implementation. OSTP frames the document around a two‑part scope test—automated systems that can meaningfully impact rights, opportunities, or access to critical resources—and recommends practices that range from pre‑deployment testing to public reporting, human alternatives, and fallbacks. The full text and PDF are available from OSTP and the White House archival pages; see the OSTP page and the official PDF for the full document and appendices. For the OSTP page see Blueprint for an AI Bill of Rights (OSTP) and for the PDF see Blueprint for an AI Bill of Rights (PDF).
Definitions
The Blueprint uses a practical, purpose-driven definition set. "Automated systems" encompass software, automated decision‑making, and algorithmic tools that process input data to produce outputs that inform, affect, or decide aspects of people’s lives. "Meaningfully impact" is a contextual threshold: systems that affect civil rights, equal opportunity, or access to critical services (healthcare, education, housing, credit, public benefits, safety) fall within scope. The Blueprint distinguishes between low‑impact automated conveniences and high‑impact systems requiring additional safeguards; it endorses risk‑based triage and lifecycle thinking (design, build, deploy, monitor, retire) to determine safeguards and governance needs.
Governance and Institutional Framework
The Blueprint recommends a layered governance approach involving developers, deployers, procurers, and overseers. For federal agencies, OSTP recommends coordination with Office of Management and Budget (OMB), National Institute of Standards and Technology (NIST), and sectoral regulators. For private actors, it recommends accountability measures such as documented risk assessments, pre‑deployment testing, human‑in‑the‑loop controls, and public reporting. OSTP situates the Blueprint in broader federal efforts: it aligns with and is intended to inform the work of NIST (e.g., the NIST AI Risk Management Framework), and federal policy instruments (including procurement guidance and subsequent executive actions). OSTP stresses meaningful stakeholder engagement—particularly with communities historically subject to harm—and a cross‑agency institutional approach to AI governance. Learn more.
Key Focus Areas
The Blueprint’s five principles capture overlapping protections. "Safe and Effective Systems" stresses pre‑deployment testing, domain‑specific standards, and ongoing monitoring to ensure systems meet intended performance and safety goals. "Algorithmic Discrimination Protections" focuses on preventing biased outcomes, recommended statistical and procedural mitigations, and civil rights review in high‑risk contexts. "Data Privacy" urges minimization, purpose limitation, transparency about data use, and user control. "Notice and Explanation" requires clear, plain‑language disclosure when automated systems are used and meaningful explanations about how decisions are made and can be contested. "Human Alternatives, Consideration, and Fallback" calls for opt‑outs where appropriate and accessible, effective processes for human review and remediation. Across these areas, OSTP recommends documentation, public reporting of summaries, and accessible redress options so that individuals can understand and challenge system impacts.
Implementation Framework
The technical companion included with the Blueprint offers lifecycle‑oriented practices: process and design controls during requirements and data collection phases; algorithmic and engineering safeguards during model training and evaluation; user‑facing notices and appeal mechanisms at deployment; and monitoring, logging, and incident response during operation. OSTP proposes a proportional approach—matching controls to the magnitude and likelihood of harms—and encourages the adoption of standards, benchmarks, and third‑party evaluation where appropriate. The document also recommends that procurement policies embed rights‑preserving clauses and that vendors provide documentation and test results to procurers. See OSTP’s companion materials and example checklists for concrete methods and templates in the Technical Companion and appendices (PDF).
Monitoring and Evaluation
OSTP urges continuous monitoring and post‑deployment evaluation including ongoing performance metrics, bias audits, anomaly detection, and incident reporting. It recommends public summaries of monitoring outcomes and encourages independent third‑party audits in higher‑risk systems. The Blueprint emphasizes accessible metrics and plain‑language explanations so that oversight bodies, affected communities, and the public can assess whether systems are meeting safety, fairness, and privacy objectives. For federal deployments, OSTP recommends alignment with agency reporting, OMB guidance, and NIST standards to ensure consistent monitoring frameworks.
Penalties, Liability, and Appeals
The Blueprint itself is non‑binding and does not create penalties; however, OSTP explicitly references existing enforcement pathways where harms arise. These pathways include consumer protection enforcement by the Federal Trade Commission (FTC) for unfair/deceptive practices, civil rights enforcement by the U.S. Department of Justice (DOJ) Civil Rights Division, sectoral enforcement (e.g., health privacy by the HHS Office for Civil Rights), and private liability under existing tort and anti‑discrimination laws. The Blueprint recommends that organizations implement internal redress, human review, and appeal mechanisms, and it advises agencies and lawmakers to consider statutory and regulatory mechanisms to address gaps where necessary.
Relationship to Other Instruments
The Blueprint complements—but does not supersede—other U.S. and international AI governance instruments. OSTP cross‑references the NIST AI Risk Management Framework, OMB guidance, federal procurement rules, sectoral statutes, and later executive orders addressing AI. It has been used to inform agency guidance, procurement standards, and legislative proposals, while remaining explicitly advisory. The Blueprint is thus best read as a rights‑focused policy primer that both draws on and feeds into more prescriptive regulatory efforts, standards work, and enforcement strategies in the U.S. and abroad.
International Alignment
The Blueprint shares common aims with international initiatives—such as the European Union’s regulatory approach to high‑risk AI, OECD AI Principles, and UNESCO’s recommendations—while reflecting U.S. legal traditions (sectoral regulation and civil rights enforcement). OSTP encourages international alignment on technical standards and measurement methods (for safety, bias testing, and documentation) while recognizing differences in legal systems and enforcement models. The Blueprint has informed multilateral dialogues and comparative policy studies and is often cited in discussions around interoperable governance mechanisms.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| OSTP Blueprint published | 2022-10-04 | OSTP publication |
| Distribution of Technical Companion | 2022-10-04 | Companion included in the OSTP materials (PDF) |
| Subsequent federal actions (e.g., NIST alignment, procurement guidance) | 2023–2024 | Follow‑on documents include the NIST AI RMF and agency memos |
Sources and References
| Source | Type |
|---|---|
| Blueprint for an AI Bill of Rights: Making Automated Systems Work for the American People (OSTP, Oct. 4, 2022, PDF) | Primary Source |
Requirements for a company
What an organisation has to do under United States - AI Bill of Rights, at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Not yet in force (Adopted). These requirements apply once the instrument takes effect and may change before then.
Must do
0Nothing in this category.
Must not do
0Nothing in this category.
Should do
6- Conduct pre-deployment testing and continuous monitoring to ensure automated systems are safe and effective.Developers and deployers of automated systems
- Implement data minimization, purpose limitation, and user controls to protect individuals from abusive data practices.Designers and deployers of automated systems
- Provide clear, plain-language notice and meaningful explanations about how automated systems are used and affect decisions.Deployers of automated systems
- Provide accessible opt-out options and human review mechanisms to contest automated decisions.Deployers of high-impact automated systems
- Perform post-deployment monitoring, bias audits, anomaly detection, and incident logging on operational systems.Deployers and operators of automated systems
- Publish plain-language summaries of system risk assessments, monitoring outcomes, and governance processes.Deployers of automated systems
Should not do
1- Do not deploy automated systems that produce algorithmically discriminatory or biased outcomes against protected groups.Developers and deployers of automated systems
Who must do what
The obligations under United States - AI Bill of Rights, most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Developers and deployers of automated systems | Conduct pre-deployment testing and continuous monitoring to ensure automated systems are safe and effective. “stresses pre‑deployment testing, domain‑specific standards, and ongoing monitoring to ensure systems meet intended performance and safety goals” | Before deployment | Key Focus Areas | Recommended |
| 2 | Developers and deployers of automated systems | Do not deploy automated systems that produce algorithmically discriminatory or biased outcomes against protected groups. “focuses on preventing biased outcomes, recommended statistical and procedural mitigations, and civil rights review in high‑risk contexts” | — | Key Focus Areas | Recommended |
| 3 | Designers and deployers of automated systems | Implement data minimization, purpose limitation, and user controls to protect individuals from abusive data practices. “urges minimization, purpose limitation, transparency about data use, and user control” | — | Key Focus Areas | Recommended |
| 4 | Deployers of automated systems | Provide clear, plain-language notice and meaningful explanations about how automated systems are used and affect decisions. “requires clear, plain‑language disclosure when automated systems are used and meaningful explanations about how decisions are made” | At or before deployment | Key Focus Areas | Recommended |
| 5 | Deployers of high-impact automated systems | Provide accessible opt-out options and human review mechanisms to contest automated decisions. “calls for opt‑outs where appropriate and accessible, effective processes for human review and remediation” | — | Key Focus Areas | Recommended |
| 6 | Deployers and operators of automated systems | Perform post-deployment monitoring, bias audits, anomaly detection, and incident logging on operational systems. “urges continuous monitoring and post‑deployment evaluation including ongoing performance metrics, bias audits, anomaly detection, and incident reporting” | — | Monitoring and Evaluation | Recommended |
| 7 | Deployers of automated systems | Publish plain-language summaries of system risk assessments, monitoring outcomes, and governance processes. “recommends public summaries of monitoring outcomes and encourages independent third‑party audits in higher‑risk systems” | — | Monitoring and Evaluation | Recommended |
Related Regulations
Artificial Intelligence Risk Management Framework (AI RMF 1.0)
United States91% similar
Principles for the Ethical Use of Artificial Intelligence in the United Nations System
United Nations91% similar
Executive Order: Ensuring National AI Policy Framework (December 2025)
United States91% similar
Recommendation of the Council on Artificial Intelligence
OECD90% similar
National Policy Framework for Artificial Intelligence (Legislative Recommendations)
United States90% similar
© Regulations.AI · reviewed against official sources on 07-Sep-2026 using Gemini 3.6 Flash