Home/Digital Rights/Platform Algorithm Harm
Digital & Technology Rights

Platform Algorithm Harm: Enacted Law vs. Proposals — Know the Difference

Headlines about "AI regulation" often blur together binding law, bills that never passed, and rules that were delayed or replaced before taking effect. This page separates what is actually enforceable today — in the EU, in specific US states and cities, and via existing US regulators — from what remains proposed or has already been superseded.

At a Glance

Aug 2024
EU AI Act entered into force (Regulation (EU) 2024/1689)
Dec 2027 / Aug 2028
Delayed EU AI Act high-risk-system compliance deadlines (Annex III / Annex I)
$500–$1,500/day
NYC Local Law 144 penalties for uncorrected AEDT bias-audit violations
0
Comprehensive US federal algorithmic accountability laws actually enacted, as of July 2026

The US Has No Comprehensive Federal Algorithm Law — Existing Rights Come From Elsewhere

There is currently no comprehensive US federal statute regulating algorithmic decision-making generally. The Algorithmic Accountability Act has been reintroduced in Congress repeatedly since 2019 — including versions in 2022, 2023, and again in the current 119th Congress (2025–2026) — and has never been enacted. If you see it referenced as if it were current law, that reference is wrong; it remains a proposal.

What DOES exist federally is enforcement under existing law by existing regulators, applied to algorithmic conduct. The clearest example: in December 2023, the FTC settled with Rite Aid over its use of facial recognition surveillance, alleging the company deployed the technology without assessing accuracy or bias, disproportionately in stores in neighborhoods with more residents of color, generating many false "shoplifter" matches. The consent order required Rite Aid to delete the images and any algorithms/models built from them (a remedy commentators call "algorithmic disgorgement"), banned facial recognition use for five years except in narrow circumstances with affirmative consent, and imposed ongoing monitoring — all under the FTC's existing Section 5 authority over "unfair or deceptive" practices, not a new AI-specific statute.

At the state and city level, a small number of genuinely enacted (not proposed) algorithm-specific laws exist. NYC Local Law 144 (enacted, effective January 1, 2023, actively enforced by the Department of Consumer and Worker Protection since July 2023) requires employers using "automated employment decision tools" to evaluate NYC candidates or employees to commission an independent annual bias audit, publish a summary, and give candidates 10 business days' notice — with penalties from $500 for a first violation up to $1,500 per day for continued non-compliance. Illinois' Biometric Information Privacy Act (BIPA, enacted 2008) separately gives individuals a private right of action over unconsented collection of biometric identifiers, which has been used in disputes over facial-recognition and similar algorithmic systems.

What a Remedy Actually Looks Like

Rarely a direct cash payment to an individual — more often a regulatory order affecting the platform's conduct

FTC/state AG enforcement action

Can require deletion of unlawfully obtained data/algorithms, injunctions on future use, and sometimes consumer redress funds — but is regulator-initiated, not something you personally sue for.

NYC Local Law 144 / BIPA-style claims

Statutory penalties (Local Law 144, paid to the city) or, under BIPA, a private right of action with statutory damages per violation.

EU DSA/AI Act rights

Practical rights like a non-profiling recommender option (DSA Art. 38 today) or future transparency/high-risk protections (AI Act, phased through 2027–2028) — enforced by EU/national regulators, with growing but still-developing individual complaint routes.

Colorado's AI Law: A Cautionary Example of "Enacted but Never Took Effect"

Colorado's SB 24-205 (the "Colorado AI Act") is a genuinely useful case study in reading algorithm-law headlines carefully. It was enacted in 2024 with an original effective date of February 1, 2026. In August 2025, Colorado postponed it to June 30, 2026. Then, on May 14, 2026, Colorado's governor signed SB 26-189, which REPLACES the original law before it ever took effect — stripping out its duty-of-care, risk-management, and impact-assessment provisions and substituting a narrower framework focused on disclosure and transparency for automated decision-making, with a new effective date of January 1, 2027. In short: as of mid-2026, the original, more protective Colorado AI Act never actually governed anyone, and a different, narrower law is what will eventually apply. verify the current status directly, since this is an unusually fast-moving example and may have changed again by the time you read this

The EU AI Act (Regulation (EU) 2024/1689) is genuinely enacted, but its obligations are phased in over several years and some deadlines have themselves been pushed back. Prohibited AI practices (for example, certain biometric categorization, manipulative or exploitative AI, and specified social-scoring uses) have applied since February 2, 2025, with the highest penalty tier (up to €35 million or 7% of global turnover). Transparency obligations (for example, disclosing that you're interacting with an AI system) apply from August 2, 2026. But the compliance deadlines for high-risk AI systems — the category most relevant to algorithmic decisions about employment, credit, insurance, and similar consequential areas — were pushed back under a 2026 simplification package to December 2, 2027 for standalone high-risk systems and August 2, 2028 for AI embedded in products covered by other EU safety law. If a source tells you high-risk AI Act obligations are already in force in 2026, check the date again.

The EU Digital Services Act (Regulation (EU) 2022/2065) is separate from the AI Act and already fully in force for designated Very Large Online Platforms and Search Engines (VLOPs/VLOSEs — platforms with more than 45 million monthly active EU users). Article 38 requires these platforms to offer at least one recommender-system option that is not based on profiling — meaning you have an enforceable right today to opt out of a personalized algorithmic feed on a qualifying platform (several major platforms, including TikTok, have implemented a non-personalized feed option in the EU specifically to comply with this rule).

What This Area Does NOT Currently Guarantee

There is no general US federal right to an explanation of, or to opt out of, an algorithmic decision outside the specific contexts covered by existing law (e.g., certain credit decisions under the Fair Credit Reporting Act / Equal Credit Opportunity Act, which are older, non-AI-specific statutes that happen to apply when the underlying process involves an algorithm).

A law being "enacted" does not mean its obligations are in effect yet — as the EU AI Act's phased timeline and Colorado's replaced law both illustrate, always check the specific applicability date of the specific provision you're relying on, not just whether the underlying law exists.

Employer or platform-side AI disclosure/audit laws (like NYC Local Law 144) generally create obligations enforced by a city/state agency; they don't necessarily give the affected individual a direct right to sue for a specific outcome, though enforcement can indirectly benefit you by forcing a compliant audit or process change.

How to Pursue a Platform Algorithm Harm Concern, Step by Step

Given how much of this area is still developing, identifying the RIGHT enacted law for your situation matters more than usual

1

Identify the specific harm and context

Employment decision (hiring/promotion), credit/insurance decision, content moderation/feed personalization, or biometric identification — each maps to a different (and possibly nonexistent) legal framework.

2

Check whether an EXISTING, non-AI-specific law already applies

Credit and employment decisions are often already covered by older laws (FCRA, ECOA, Title VII, state anti-discrimination statutes) regardless of whether the process involved an algorithm — these can be a more solid footing than emerging AI-specific rules.

3

Check for a genuinely enacted, currently-effective algorithm-specific law

NYC Local Law 144 (if the employer/tool touches NYC-based candidates), Illinois BIPA (biometric collection), or EU DSA Article 38 (recommender-system opt-out on a qualifying VLOP/VLOSE) are examples of law that is both enacted and already in effect.

4

File with the right regulator or use the right platform mechanism

US: FTC complaint (reportfraud.ftc.gov) for unfair/deceptive algorithmic practices, or your state attorney general's consumer protection division. NYC: DCWP for a Local Law 144 compliance concern. EU: use the platform's required non-profiling feed option directly, or file with your national Digital Services Coordinator for a DSA compliance concern.

5

Document the specific algorithmic output and context

Screenshots of the decision/output, dates, the platform's stated policy or disclosure (if any), and any human response you received — this matters regardless of which legal framework ultimately applies.

Documents to gather

  • Screenshots or exports of the algorithmic output/decision and its date
  • Any notice, disclosure, or bias-audit summary the platform/employer published
  • Correspondence with the platform, employer, or a human reviewer
  • Evidence of pattern or disparate impact, if you have access to it (e.g., outcomes for similarly situated people)
  • Any prior complaint you filed and its reference number

Timelines and Deadlines

Vary enormously by which underlying law actually applies to your situation

Because so much of this area is either brand-new, phased in, or still proposed, there is no single "algorithmic harm" limitation period — the deadline is whatever applies to the underlying enacted law you're actually using (e.g., an employment-discrimination charge deadline, an FTC complaint with no fixed deadline, or a DSA regulator complaint).

JurisdictionLimitation Period
EU AI Act — prohibited practicesApplicable since February 2, 2025 (already enforceable)
EU AI Act — high-risk system obligationsDecember 2, 2027 (Annex III) / August 2, 2028 (Annex I) — not yet in effect verify current status
EU DSA — Article 38 non-profiling recommender optionAlready in effect for designated VLOPs/VLOSEs
NYC Local Law 144 — AEDT bias auditAlready in effect since January 1, 2023
Colorado algorithmic-decision lawOriginal SB 24-205 replaced before taking effect; new SB 26-189 framework effective January 1, 2027 verify current status
US federal Algorithmic Accountability ActNot enacted — proposed only, as of July 2026

Realistic Outcomes and Caveats

Complaints grounded in an existing, well-established law (FCRA/ECOA for credit, Title VII/state law for employment discrimination, BIPA for biometric collection) tend to have clearer, more predictable outcomes than complaints framed purely as "the algorithm was unfair" without tying to a specific enacted legal right.

Regulatory enforcement actions (FTC, state AGs, NYC DCWP, EU Digital Services Coordinators) can produce real changes to a platform's practices, but individual complainants usually do not receive a direct personal payout from these actions — the primary benefit is often systemic (a practice stops or an audit is required) rather than individual compensation.

This page can help you distinguish enacted, currently-effective law from proposals and superseded bills so you pursue the right framework, but it cannot predict whether a specific regulator will act on your complaint, and it is not a guarantee of any particular remedy.

Common Pitfalls

Citing a proposed federal bill as if it were current law

The Algorithmic Accountability Act and similar federal proposals have been reintroduced repeatedly but never enacted — check congress.gov for a bill's actual status before relying on it.

Assuming a law is in effect just because it was "passed" or "signed"

The EU AI Act's high-risk provisions and Colorado's algorithm law both show that enactment and actual effective/applicability dates can be years apart — and can change again before taking effect.

Overlooking that older, non-AI-specific laws often already apply

An algorithmic credit or hiring decision is frequently still covered by FCRA, ECOA, Title VII, or state anti-discrimination law regardless of whether "AI" was involved — these can be a stronger, more established footing than newer AI-specific proposals.

Not checking whether the platform already offers a non-profiling option

On a VLOP/VLOSE covered by the EU DSA, a non-personalized feed option is already a legal requirement (Article 38) — check the platform's settings before assuming you have no recourse.

Expecting a personal payout from a regulatory enforcement action

FTC, state AG, and most EU regulator actions typically produce systemic remedies (deletion orders, audits, injunctions) rather than direct payments to individual complainants.

Organize Your Platform Algorithm Concern

Use the workspace to identify which enacted law (if any) applies to your situation and organize the evidence before you file a complaint.

Organize Your Platform Algorithm Concern

Use the workspace to identify which enacted law (if any) applies to your situation and organize the evidence before you file a complaint.

This stays in your private workspace until you choose a next step.

This stays in your private workspace until you choose a next step. It does not submit a claim on your behalf on its own.

Official and Legal References

EU vs. US Approach to Algorithmic Harm

The EU has enacted, cross-cutting frameworks (the AI Act and the Digital Services Act) with phased-in obligations — some provisions already binding, others delayed years out. The US has no comprehensive federal algorithm law; protection instead comes from existing regulators (FTC) applying general unfair-practice authority, a handful of enacted state/city laws (NYC Local Law 144, Illinois BIPA), and older non-AI-specific statutes (FCRA, ECOA, Title VII) that happen to apply when an algorithm is part of the process. Always confirm the CURRENT status and applicability date of any specific law before relying on it — this is one of the fastest-changing areas of law covered on this site.

Frequently Asked Questions

Real edge cases, answered in plain language

Is there a US federal law against algorithmic discrimination?

Is the Colorado AI Act in effect?

Can I opt out of a platform's personalized recommendation algorithm?

This page provides general information about platform algorithm harm as of July 2026. It is not legal advice. This is one of the fastest-moving areas of law covered on this site — laws described as "enacted" may not yet be in effect, and pending bills may never become law. Confirm the current status of any specific law directly (e.g., via congress.gov, EUR-Lex, or your relevant state/city regulator) before relying on it.

Organize Your Platform Algorithm Concern

Use the workspace to identify which enacted law (if any) applies to your situation and organize the evidence before you file a complaint.

Organize My Case