Overview
The Algorithmic Accountability Act is proposed U.S. federal legislation that would require large companies to conduct and document impact assessments of automated decision systems and of augmented critical decision processes — the software and workflows that increasingly decide who gets a job interview, an apartment, a loan, a diagnosis, or a benefit.
First introduced in 2019 and reintroduced in updated form in 2022 and again in 2023, the Act would empower the Federal Trade Commission (FTC) to issue regulations, receive summary reports of impact assessments, and maintain a public repository of covered systems. Even as the bill continues to move through Congress, its structure has become a de facto template for state laws, procurement standards, and enterprise governance programs.
This guide translates the Act's core mechanics into plain English and outlines what operators of AI systems can do now to be ready — regardless of whether the federal bill becomes law this session.
Who is covered
The Act applies to covered entities — generally organizations that meet at least one of the following thresholds during the previous three years:
- Revenue: more than $50 million in average annual gross receipts.
- Consumer data: possess, control, or process identifying information on more than 1 million consumers, 1 million consumer devices, or 1 million unique users.
- Data brokers: substantially derive revenue from collecting, processing, or selling consumer data.
Covered entities are responsible for any automated decision system they deploy, contract for, or license from a vendor. Buying an AI tool from a third party does not transfer accountability — the deploying organization is still on the hook for how it is used.
Critical decisions
The Act focuses on augmented critical decision processes: uses of automation to make, or materially contribute to, decisions that have a legal or similarly significant effect on a person's life. The bill enumerates domains including:
- Employment, worker management, and self-employment
- Credit, financial services, and insurance
- Housing and utilities
- Education and vocational training
- Healthcare and access to essential health resources
- Public accommodations, legal services, and government benefits
- Family planning and reproductive health
If your model, rules engine, or scoring system influences an outcome in one of these domains — even as an "advisory" signal to a human decision-maker — it is likely in scope.
Impact assessment: what it must include
At the heart of the Act is a required algorithmic impact assessment. The FTC would be authorized to prescribe the exact form, but the statute specifies that assessments must, at minimum, document:
- System description — intended purpose, deployment context, and the decisions influenced.
- Data — sources, collection method, retention, and known limitations of training and evaluation data.
- Performance — tested accuracy, error rates, and outcomes disaggregated by demographic groups where lawfully possible.
- Risks — foreseeable harms including bias, privacy violations, safety failures, and downstream misuse.
- Mitigations — technical controls, human oversight, appeal processes, and monitoring in production.
- Consultation — engagement with affected stakeholders, workers, or communities.
- Alternatives considered — less-invasive or non-automated options that were evaluated.
Assessments must be updated when the system changes materially and re-verified on a regular cadence. Organizations should expect at least an annual review for high-impact systems.
FTC reporting & public repository
Covered entities would submit summary reports of their impact assessments to the FTC. The FTC, in turn, would maintain a public repository so that journalists, researchers, and the public can see which organizations use automated decision systems in critical domains and — at a high level — how those systems perform.
The full underlying assessment is generally treated as confidential business information; the public artifact is the summary. This design mirrors how environmental impact reports or SEC filings work: detailed internal work, standardized public disclosure.
The Ethos AI Registry is a civic-society analog to that repository. Organizations that publish here today build the muscle — and the public trust — needed to comply the day a statutory registry goes live.
Penalties & enforcement
Violations of the Act would be treated as unfair or deceptive practices under Section 5 of the FTC Act. Consequences can include:
- Civil penalties per violation
- State attorney general enforcement actions on behalf of residents
- Consent decrees and mandated remediation programs
- Reputational harm from a public FTC action or repository entry
Notably, the Act does not create a private right of action. Enforcement flows through the FTC and state AGs — but civil-rights, employment, and consumer-protection statutes already provide private remedies for the underlying harms.
Timeline & current status
As of July 2026, the Algorithmic Accountability Act has not been enacted. Its legislative history illustrates a steady maturation:
- 2019 — first introduction by Senators Wyden and Booker and Representative Clarke.
- 2022 — revised bill expanding scope to augmented critical decision processes.
- 2023 — reintroduction with strengthened FTC authority and clearer thresholds.
- 2024–2026 — parallel state action (Colorado, California, New York City) and FTC guidance push accountability expectations into practice ahead of federal enactment.
Even without federal passage, the compliance floor is rising. Colorado's AI Act, the EU AI Act, and NIST AI RMF adoption among federal contractors mean most large operators already face something that looks a lot like the Algorithmic Accountability Act.
How to prepare in 90 days
A pragmatic 90-day program to get ahead of the Act:
- Inventory — list every automated or AI-assisted system that influences a critical decision. Do not exclude vendor tools, spreadsheets with embedded logic, or human-in-the-loop workflows.
- Classify by impact — flag high-impact systems (employment, credit, housing, healthcare, benefits) for full assessments; lower-impact systems for lighter review.
- Adopt a framework — align each system to the NIST AI Risk Management Framework. The Ethos Registry rubric maps directly to NIST Govern and Map functions.
- Run bias & performance testing — measure outcomes across demographic groups where lawful. Document what you tested, what you found, and what you changed.
- Assign accountable owners — every system needs a named executive owner and a named technical owner. No orphans.
- Publish transparency documentation — post a public entry (registry, model card, or system card) covering purpose, data, oversight, and known limits.
- Set a review cadence — quarterly monitoring, annual reassessment, and change-triggered re-review.
Organizations that complete these seven steps will be substantially ready for the Act and materially better positioned under existing law.
Roles & responsibilities
- Board / CEO — sign-off on the AI governance policy and on high-impact deployments.
- General Counsel — regulatory tracking, assessment sufficiency, and FTC / AG readiness.
- Chief Risk / Compliance Officer — assessment cadence, exception management, third-party diligence.
- Chief Data / AI Officer — inventory, framework mapping, bias and performance testing.
- Product & Engineering leads — monitoring, human-oversight controls, incident response.
- Affected employees & community reviewers — consultation input and channels for reporting concerns.
Common pitfalls
- "It's just a vendor tool" — accountability follows the decision, not the code base.
- Assessments as marketing — an impact assessment that only lists strengths is not an assessment.
- Shadow AI — pilots, prototypes, and spreadsheet models that never make it into the inventory are a top source of enforcement risk.
- One-and-done — a system re-trained on new data is a new system. Update the assessment.
- No appeal path — regulators, courts, and the public consistently penalize systems with no human recourse.
Frequently asked questions
Does the Act apply to small businesses?
Generally no. The revenue, consumer-data, and data-broker thresholds are designed to exempt small businesses. However, small firms that provide AI tooling to covered entities will face pass-through requirements through contracts and procurement standards.
What if my AI is only advisory to a human?
Advisory or "augmented" decisions are explicitly in scope when they materially influence a critical outcome. A recommendation a manager rubber-stamps is, for legal purposes, a decision.
How does this relate to the EU AI Act?
The EU AI Act is a comprehensive risk-based product-safety regime. The Algorithmic Accountability Act is a narrower transparency-and-assessment regime scoped to critical decisions. Organizations operating in both jurisdictions can largely reuse the same evidence base.
Where can I read the actual bill text?
Search "Algorithmic Accountability Act" on Congress.gov for the most recent version. Bill numbers change between sessions, so always confirm you are reading the current draft.
Get ready in public
The Ethos AI Registry is the fastest way for operators to document automated decision systems, publish transparency scores, and demonstrate accountability to regulators, funders, and the communities they serve.