Algorithmic Accountability Act

US FederalGeneral Cybersecurity2022
ByDecipherU Editorial

The Algorithmic Accountability Act is a proposed federal bill requiring large companies to assess the impacts of automated decision systems they use or sell. First introduced in 2019 and reintroduced in 2022, the bill would require impact assessments for automated systems that make critical decisions affecting housing, employment, education, lending, and criminal justice. It has not been enacted as of April 2026.

Quick Reference

EnactedNot enacted (reintroduced February 2022)
Enforcement BodyFederal Trade Commission (FTC)
PenaltiesFTC enforcement under Section 5 unfair or deceptive practices authority
Applicable ToCompanies with over $50 million in annual revenue or that possess data on more than 1 million people or devices

Key Requirements

Section 4 (Impact Assessments)

Covered entities must conduct impact assessments for automated decision systems that make critical decisions, evaluating effectiveness, bias, privacy impacts, and security vulnerabilities

Section 5 (Reporting)

Covered entities must submit summary impact assessment reports to the FTC and make summaries available to the public

Section 6 (Consultation)

Impact assessments must include consultation with relevant stakeholders including affected communities and independent auditors

How Does AAA Affect Cybersecurity Careers?

AI security engineers and data scientists need to understand algorithmic accountability requirements. GRC professionals at companies using AI for critical decisions should proactively build impact assessment frameworks. Even without passage, the bill signals regulatory direction that responsible organizations are already adopting.

Cybersecurity Roles That Work With AAA

Related Cybersecurity Certifications

Related Cybersecurity Laws

Read the full text of AAA at the official source: https://www.congress.gov/bill/117th-congress/senate-bill/3572

Frequently Asked Questions

The Algorithmic Accountability Act is a proposed federal bill requiring large companies to assess the impacts of automated decision systems they use or sell. First introduced in 2019 and reintroduced in 2022, the bill would require impact assessments for automated systems that make critical decisions affecting housing, employment, education, lending, and criminal justice. It has not been enacted as of April 2026.

AI security engineers and data scientists need to understand algorithmic accountability requirements. GRC professionals at companies using AI for critical decisions should proactively build impact assessment frameworks. Even without passage, the bill signals regulatory direction that responsible organizations are already adopting.

FTC enforcement under Section 5 unfair or deceptive practices authority

Last verified: April 2026?Report an inaccuracy

Explore Related Cybersecurity Resources

Was this page helpful?