AAgentProof

Framework lens

US AI governance — documentation support

A documentation and evidence coverage lens for the layered US model — coverage of expectations across federal, sectoral, and state directions, never a legal verdict.

Framework lensNever one US AI lawLegal review recommendedCoverage-not-compliance

A documentation and evidence coverage lens for the layered US model — NIST RMF, FTC practice, sectoral rules, federal direction, and a state-law watch; never one US AI law.

Why it matters

There is never one US AI law. US AI governance is a layered model: the voluntary NIST AI Risk Management Framework for structure, established FTC practice on unfair or deceptive practices, sector-specific rules (for example in health, finance, and employment), evolving federal direction, and a fast-moving patchwork of state law that a team has to watch rather than read once. A documentation lens organises what an agent can already show against those layers and, just as importantly, keeps the open questions visible — so a team going to market in the US knows where legal review is recommended before a stakeholder asks.

What good looks like

The same evidence, controls, and tests you have already captured, viewed by layer — a NIST RMF function view, an FTC-practice-flavoured view of claims and fairness, a sectoral pointer where a finance or employment context applies (a health context raises a legal-review flag), and an explicit state-law-watch note rather than a false 'covered'. Each layer reuses the same underlying record instead of a parallel checklist. State law is treated as a watch item that stays open and dated, never silently resolved. Where a high-impact use is present, the lens raises a legal-review-recommended pointer framed as a direction to review, not a determination.

What can go wrong

A tool implies there is a single US AI law an agent has satisfied. The state-law patchwork is flattened into one 'covered' flag that goes stale the moment a state moves. A sectoral rule that clearly applies is missed because the model only looked at the federal layer. Coverage is mistaken for a legal conclusion, and the recommendation to get legal review is dropped.

What AgentProof checks

AgentProof maps documentation and evidence coverage across the US layers via the one lens engine, pinned to a named framework version, and keeps the state-law-watch layer as an explicit open item rather than a fabricated pass. It reports documentation and evidence coverage plus an applicability read and legal-review-recommended pointers on higher-impact domains — never a conformance score, never a claim that an agent has satisfied US AI law, and never legal advice. Your legal and risk teams remain responsible; legal review is recommended for any US go-to-market decision.

Key terms

The exact vocabulary this part of the record uses — grounded in the shipped product model.

Layered model
NIST RMF, FTC practice, sectoral rules, federal direction, state-law watch — not one law.
State-law watch
An explicit open, dated watch item — never flattened into a single 'covered' flag.
Legal-review-recommended
A direction to review raised on higher-impact domains, not a determination.
Applicability
may_apply, likely_relevant, not_enough_information, not_currently_relevant.
Framework version
The US AI governance seed is pinned to a named framework version.

Keep reading

Build this record for your own agents

AgentProof turns each part of this into one documented, evidence-backed record — before your compliance review.

Ready to build a compliance-readiness record for your own agent?

Request a compliance readiness pilot to apply this guidance to a real agent.

AgentProof builds a compliance-readiness record, not an official audit, and it does not speak on behalf of any vendor.