Mary Jane Wilson-Bilik
Partner

Mary Jane (MJ) Wilson-Bilik is a technology, privacy and insurance regulatory law partner at Eversheds Sutherland (US) in Washington, DC. She serves as head of the firm’s US artificial intelligence (AI) practice in financial services, and co-chair of its Global AI in financial services practice. For more than 25 years, MJ has advised her financial services and technology clients on privacy and innovation issues. Her recent focus has been to assist clients in performing AI impact assessments and developing robust risk management, governance and vendor management policies for their AI efforts, including generative AI. She counsels clients on assessing AI risks on a cross-sector basis, monitoring for bias, privacy, cybersecurity, intellectual property and specialized regulatory risks, and implementing effective governance measures and guardrails. MJ is a frequent speaker at conferences and client meetings on privacy, risk management and artificial intelligence, including generative AI. MJ received her PhD in quantitative political science from Columbia University and her J.D., magna cum laude, from the Georgetown University Law Center.

KEY AI DEVELOPMENTS AND TRENDS IN THE US FROM A LEGAL PERSPECTIVE

Since the start of the second Trump Administration in January 2025, there has been a dramatic shift in Artificial Intelligence (AI) policy in the United States (US or America) away from risk mitigation principles focused on AI’s potential social and physical harms to promoting America’s AI domination on the world’s stage, advancing innovation, accelerating AI infrastructure, and removing regulatory barriers. The July 23, 2025 release of the White House’s “Winning the Race: America’s AI Action Plan” (AIAP or Plan), bolstered by three Executive Orders,1“Accelerating Federal Permitting of Data Center Infrastructure,” Executive Order, July 23, 2025 (Executive Order #1); “Promoting the Export of the American AI Technology Stack,” Executive Order, July 23, 2025 (Executive Order #2); and “Preventing Woke AI in the Federal Government,” Executive Order, July 23, 2025 (Executive Order #3). is a resounding call for new US federal agency priorities and partnership with the private sector, rollbacks and reinterpretations of legal precedents, and new challenges to the states’ legal authority, all intended to ensure that the US prevails in the global AI race.

BACKGROUND

While the US has no laws at the federal level that set out parameters for the lawful development and deployment of AI, US Presidents have issued a number of Executive Orders that set out US AI policy priorities that direct federal executive agencies to undertake certain tasks to fulfill those policy goals.

The Biden Executive Order.2“Safe, Secure and Trustworthy Development and Use of Artificial Intelligence,” Executive Order 14110, October 30, 2023. In October 2023, President Biden issued an Executive Order (the Biden Order) that went beyond prior Administrations’ actions regarding AI in numerous respects. The broad ranging Biden Order urged the development of AI for justice, security and opportunity for all, similar to the principles for responsible AI set out by the Organization for Economic Cooperation and Development (OECD) in 2018. The Biden Order made clear that while AI holds extraordinary potential for good, it can also cause physical and social harms, including damage to national security, critical infrastructure and privacy and can exacerbate discrimination, bias, disinformation and workforce displacement.

The Biden Order promoted the responsible use of safe and secure AI, directing dozens of agencies to perform specific tasks. For instance, the National Institute of Standards and Technology (NIST) at the US Department of Commerce (DOC), together with the Department of Energy (DOE), were ordered to develop standards, recommendations and best practices for AI development and use. All federal agencies were directed to build AI standards into current and new regulations. And the Office of Management and Budget (OMB) was directed to require every executive agency to hire a Chief AI Officer, complete AI inventories and develop risk management controls.

The Biden Order included provisions to mitigate the privacy risks exacerbated by AI and to protect against the misuse of personal information and data. Actions designed to alleviate the potential disruption and displacement of workers by AI were ordered, as were actions advancing equity and civil rights. Noting that the irresponsible use of AI can lead to unlawful discrimination and other harms, the Biden Order required a range of agencies to use their regulatory powers to abate discrimination in the use of AI in areas from housing and employment to health care. Further, the Department of Justice (DOJ) was ordered to propose safeguards and appropriate limits on the use of AI in prison management, sentencing and police surveillance.

The Biden Order also called for strengthening US leadership of global efforts to meet AI’s challenges and potential by advancing responsible global technical standards and encouraging America’s international allies and partners to support voluntary commitments from the largest technology companies to engage in responsible AI practices.

Among the dozens of actions Federal agencies took in response to the Biden Executive Order were those of the Federal Trade Commission (FTC) that cracked down against companies using AI in ways that deceived or harmed consumers. In 2023, four major federal agencies, the Consumer Financial Protection Bureau (CFPB), the FTC, DOJ and the Equal Employment Opportunity Commission (EEOC) issued a joint statement3“Joint Statement on Enforcement Efforts Against Discrimination and Bias in Automated Systems,” 2023. pledging to use their enforcement powers to protect individuals’ civil rights, including fair and equal access to jobs, housing, credit opportunities and other goods and services and to monitor for discrimination in the use of automated technologies, such as AI. It is worth noting that the enforcement divisions of the CFPB and the EEOC were mostly dismantled in the first six months of the Trump Administration due to workforce cuts mandated by the Department of Government Efficiency (DOGE).

STATE LAWS START TO FILL THE VACUUM

In the absence of federal law governing the responsible use of AI, a number of states passed laws to regulate the development and use of AI, especially in the areas of algorithmic discrimination and frontier model safety.

Colorado. Among the most notable laws governing algorithmic discrimination is the Colorado AI Act of 2024 (SB 24-205). Enacted on May 17, 2024, and effective February 1, 2026, the Colorado AI Act is the first law in the US that places significant reporting, accountability and transparency obligations on companies that either develop or deploy high-risk AI systems. High-risk AI systems are AI systems that are a substantial factor in the making of consequential decisions, which are decisions in lending, employment, housing, healthcare and other areas that impact consumers. Both developers and deployers have a duty to exercise “reasonable care” to protect consumers from any known or reasonably foreseeable risks of “algorithmic discrimination” arising from the use of a high-risk AI system. “Algorithmic discrimination” occurs when an AI system results in the “unlawful differential treatment or impact that disfavors an individual or group” in a protected status under state law, including gender, race and religion.

The law requires developers to take several steps, including disclosing to the public how the developers manage the risks of algorithmic discrimination that may arise from its high-risk AI systems and reporting to the Attorney General of the state of Colorado any reasonably foreseeable risks of algorithmic discrimination. Deployers must implement a risk management policy and program to govern their use of high-risk AI systems, and they must conduct impact assessments at least annually that meet specified requirements, including describing data inputs and outputs, metrics for evaluating the system and post-deployment monitoring. Consumers must be provided with notice in plain language about how the high-risk AI system works and their right to opt out of the processing of their data.

Various technology and other lobbying groups have exerted pressure on the Colorado legislature to either revise or rescind the law before the February 2026 implementation deadline. It is expected that hearings will be held on this matter. Similar bills were introduced in several other states in 2025, but have not been passed into law.

Specific to the financial services sector, Colorado also passed a pioneering AI law, SB21-169, which prohibits insurers from using external consumer data, algorithms and AI models that result in unfair discrimination based on race, color, national origin, religion and other protected characteristics. The law applies to life, health, and auto insurers and requires insurers to implement a governance framework, conduct outcome-based testing, and file compliance reports with the Colorado Division of Insurance.

New York. In June 2025, the New York State legislature passed the Responsible AI Safety & Education (RAISE) Act, a frontier model public safety bill that would establish safeguards, reporting, disclosure and other requirements for large developers of frontier AI models, if signed into law by Governor Hochul. The RAISE Act would make New York the first state in the nation to enact public safety requirements for large frontier model developers, with accompanying substantial fines for noncompliance.

The RAISE Act is similar in purpose to California’s Safe & Secure Innovation for Frontier Models Act (SB 1047) that was vetoed by Governor Newsom in September 2024. Entities subject to the RAISE Act would be required to adopt safety and security protocols before a model is released and make the protocols available to relevant authorities. The Act would also compel developers to conduct annual safety reviews and disclose safety incidents. Industry advocates argue that the bill would hinder AI innovation.

Specific to the financial services sector, on July 11, 2024, the New York Department of Financial Services (NYDFS) adopted Insurance Circular Letter 7 on the use of AI in insurance underwriting and pricing. The Circular Letter outlines the NYDFS’ expectation that insurers adopt oversight, policies, procedures and internal controls to ensure that AI systems do not disproportionately impact protected groups. The themes in the Circular Letter are similar to those in Colorado’s SB21-169.

California. California has passed a number of AI laws that regulate a wide range of topics, from prohibiting the use of AI to produce deep-fake pornography to requiring the watermarking of certain AI medium, disclosure of AI training data and providing notice to consumers of certain uses of AI.

THE TRUMP ADMINISTRATION’S APPROACH TO AI POLICY

On the first day of his second administration, President Trump signaled a major change in US policy on AI when he rescinded the Biden Order, stating that the Biden Order hindered AI innovation and imposed onerous and unnecessary government control over AI development. On day three, President Trump issued his own Executive Order on AI4“Removing Barriers to American Leadership in Artificial Intelligence,” Executive Order, January 23, 2025. (Trump Order) that stated that the US must act decisively to retain leadership in AI and enhance America’s dominance in AI that is free from ideological bias and an engineered social agenda. The Trump Order directed the development of an AI Action Plan to further articulate this policy.

President Trump has issued other Executive Orders that will impact how the financial services sector implements AI systems.

Disparate Impact. On April 23, 2025, President Trump issued an Executive Order titled “Restoring Equality of Opportunity and Meritocracy,” (April Order), which declared disparate impact theory for assessing discrimination to be “wholly inconsistent with the Constitution,” and asserted a policy to eliminate disparate impact liability in all contexts to the maximum degree possible. The April Order repealed or amended certain regulations under Title VI of the federal Civil Rights Act and directed federal agencies to deprioritize enforcement of statutes and regulations that include disparate impact liability, among other impacts. Disparate impact framework is currently the principal test used by courts in evaluating whether a policy or practice is discriminatory and it is often used by private litigants to challenge practices in the financial services sector. Disparate impact discrimination is defined as unintentional discrimination resulting from a practice that is facially neutral but has a disproportionate adverse impact on a protected class. Many state laws, regulations and guidance impacting the financial services sector’s development and use of AI systems, including Colorado’s two AI Acts and the NYDFS Circular Letter 7, employ a disparate impact framework to assess the discriminatory impact of AI. The enforceability of these state laws is not altered by the April Order that applies only to federal government agencies. However, the April Order could affect litigation strategy and/or be cited in future constitutional challenges brought by private parties or industry groups against various state AI laws that employ a disparate impact framework.

Trump’s AI Action Plan (AIAP or Plan). The AIAP that was issued on July 23, 2025 has three pillars: accelerate AI innovation, build American AI infrastructure and lead in International AI diplomacy and security, all of which could have impacts on the financial services sector.

The AIAP envisions the federal government’s role as creating the conditions that will allow private-sector-led AI innovation to thrive. So that the private sector can innovate with fewer regulatory constraints, the OMB will ask business and the public to identify federal regulations that hinder AI innovation and will take appropriate actions. OMB will also work with all federal agencies to identify, modify or repeal burdensome regulations, interpretations, orders and guidance that hinder AI innovation.

The AIAP encourages the adoption of open-source and open-weight AI and the adoption of AI throughout the federal government. The Plan envisions a new frontier in AI-enabled science and directs key agencies to work on investing in automated cloud-enabled AI labs for a variety of hard sciences, and on building high-quality AI-ready scientific databases, as well as encouraging scientific breakthroughs through targeted investments in theoretical, computational and experimental research in AI. And the Plan positions NIST as a central architect of AI governance, evaluation and assurance frameworks. The Plan also calls on NIST to revise its well-known AI Risk Management Framework to remove references to perceived misinformation, climate change and diversity, equity and inclusion (DEI).

On the need for new infrastructure, the AIAP notes that America’s AI dominance will depend on building out its AI infrastructure, including data centers, related components and the electric grid. To this end, the AIAP and Executive Order #1 call for opening up Federal laws and military installations to new infrastructure projects, to establishing categorical exclusions under the National Environmental Protection Agency (NEPA) to cover data center-related actions that normally do not have a significant effect on the environment, and to expedite environmental permitting by streamlining or reducing regulations promulgated under the Clean Air Act, the Clean Water Act, the Comprehensive Environmental Response, Compensation and Liability Act, the Toxic Substance Control Act, and the Endangered Species Act, among others. It also encourages the use of old and new energy sources, including natural gas, coal, nuclear fusion, nuclear fission and geothermal to construct and supply new AI infrastructure.

On national security, the AIAP includes several provisions that address cybersecurity threats to AI systems as well as cybersecurity threats from adversary uses of AI systems. Those provisions reflect the need both to protect American AI innovation and to protect against—and recover from—AI-fueled cyber attacks. The AIAP also advocates for the advancement of AI-related national security interests through multinational diplomacy; measures to guard against the risk that adversaries could use AI to advance chemical, biological, radiological, and nuclear weapons programs; and provisions to advance the secure use of AI by the Department of Defense and the Intelligence Community.

On the promotion of the export of US AI equipment, the Plan and Executive Order #2 call for the promotion of “full AI technology stack” export packages. At the same time, the AIAP calls for using “creative approaches” to limit adversaries’ access to advanced AI compute and for developing greater consensus around US export control priorities among allies and partners.

The Plan also seeks to cut back the authority of the States to regulate AI by calling on the OMB, working with other federal agencies with discretionary AI-related funding, to consider the States’ AI regulatory climate when making funding decisions and to limit funding if the regulatory climate would hinder the effectiveness of federal funding. Finally, Executive Order #3 argues that when ideological biases and social agendas are built into AI models, it can distort AI outputs. As a result, federal agencies are ordered to procure only Large Language Models (LLMs) that are developed in accordance with two principles: “Truth-seeking” (LLMs must be truthful in responding to user prompts) and “Ideological Neutrality” (LLMs must be neutral, nonpartisan tools that do not manipulate responses in favor of ideological dogmas such as DEI.)

Finally, the AIAP supports a “worker-first” AI agenda focused on AI-upskilling and training, while de-emphasizing regulation. It envisions AI accelerating productivity and creating entirely new industries, while recognizing it will also transform how work gets done across all industries and occupations. The Administration stresses that AI will demand a serious workforce response to help workers navigate that transition. Key federal agencies are directed to take specific actions to ensure that AI creates economic opportunity for American workers by prioritizing AI skill development and training as a core objective of relevant education and workforce funding streams.

The dramatic change in the US AI policy under the second Trump Administration will have significant impacts both domestically and internationally. Financial services companies should pay careful attention to how the federal AI policy initiatives evolve and the effects of the new policies on both international and state law and regulation so that companies stay in compliance. It remains to be seen whether the new policies will open up new and more areas for private and interest group litigants to challenge how financial services companies interpret their obligations under the new evolving AI policies.