Guides

    AI in US Market Access: What Binds You Today, and What Is Coming

    The honest answer is that no American regulator cares yet. That is not the same as having no exposure, and the pressure is now on one pain point.

    By Gabriel Tremblay, DBA, Founder & CEO, Untraceable

    Published 2026-09-25 · Last reviewed 2026-09-25

    The short answer

    No US federal or state law requires the author of a regulatory, health economics or market access document to disclose that AI helped write it. The FDA's draft guidance expressly excludes drafting a submission; ICER, AMCP's current Format, state law and commercial payers require nothing. The binding constraint is contractual: your client NDA currently in place and your engagement terms are what applies today. Federal activity in 2026, up to now, is aimed at preventing the expansion of state AI laws.

    The sentence that gets people into trouble

    "There's no AI regulation yet." It is true, and it is one of the more expensive true sentences in our field, because it answers a question nobody should be asking. Whether a regulator has written a rule about AI-assisted writing has very little to do with whether you are exposed. You signed a contract, and the contract does not need a statute behind it to end a client relationship. You also have a duty to protect employees, individual clients, patient data, and many other data points that are common in regulated fields, if not on every page.

    In this page, I am trying to present the US picture in two halves: what actually constrains you today, and where the pressure is growing. It does not restate which agencies and journals require a declaration, that is a separate guide, and most of the bodies with a real duty are not American.

    What binds a US regulated expert today

    One item on this list is enforceable against you this week. It is not the regulatory one.

    Source of obligationDoes it bind you today?What it actually reaches
    Your client NDAYes, immediatelyWho may receive confidential information. Sending it to a third-party AI service is capable of being a disclosure to a third party, whether or not the agreement mentions AI.
    Your engagement terms and BAAsYesPermitted processing, subcontracting, and often a notification duty. Read the subcontractor clause before assuming a tool is permitted.
    The AI vendor's termsYes, but they bind the vendor to youThey do not bind you to your client. A vendor promising not to train on your inputs does not discharge your obligation to your client or the patients (with the risk of sounding overdramatic, we do this job to help patients).
    FDANo duty to disclose authorshipThe 2025 draft guidance on AI supporting regulatory decision-making names drafting a submission in its own scope exclusion. It is also still a draft, and non-binding.
    ICER, AMCP Format, US state law, commercial payersNoTo our knowledge, nothing requires an author to declare AI assistance. State AI statutes overwhelmingly govern AI used to make a coverage or employment decision, a duty on the payer or employer, not the writer.
    Why the state-law headlines do not apply to you
    Two different duties get conflated constantly. The first is: AI makes or informs a coverage or medical decision, which creates duties on the payer. The second is: disclosure that AI produced a document, which would create a duty on the author. Nearly every US measure reported as an "AI disclosure law" is the first kind. If you are writing dossiers rather than adjudicating claims, those laws are about someone else.

    Where the government is acting

    The most common assumption about 2026 is that American AI policy is a blank page waiting to be filled with rules. It is not blank, and certainly not empty.

    The executive order of 11 December 2025, "Ensuring a National Policy Framework for Artificial Intelligence", points in the opposite direction from the one most people expect. Rather than adding federal duties, it takes aim at state ones: it established a litigation task force within the Department of Justice to challenge state AI laws in federal court, and directed the Federal Trade Commission to act on state-mandated bias mitigation. Reported carve-outs include child safety, compute and data-centre infrastructure, and state procurement.

    How we read this order, and what we have not read
    Our account of the order comes from legal analyses of it, not from the Federal Register text. We therefore describe its mechanism and decline to quote it. The distinction matters on a page whose whole value is that its claims are checkable.

    The practical consequence for a consultant is worth stating plainly: the US is not there yet, or should I say, the discussions are not currently impacting disclosure of AI at this point. Federal legislation to attempt to block state law has been discussed rather than enacted. Nothing in the federal or state programmes proposes a duty on an expert who wrote a submission.

    What happened at the United Nations in September 2026

    This is the part worth understanding properly, because it is the clearest available signal about the shape of any future regime, and because it is routinely reported as something it was not.

    On 23 September 2026 the UN Security Council held a session on artificial intelligence and international security. It heard from Yoshua Bengio, co-chair of the UN's Independent International Scientific Panel on AI, and from the chief executives of OpenAI, Anthropic and Hugging Face. Two days earlier, 22 countries had adopted a declaration, "A Call for Control of Frontier AI Models", asking the members to explore a new international institution. It should be able to set standards and verify compliance, in addition to testing before frontier models are deployed.

    22 countries signed. The United States and China did not.

    Source: “A Call for Control of Frontier AI Models”, adopted on the margins of the UN General Assembly, 21 September 2026. The US and China are both absent from the signatories; sources differ on the rest of the list, so we state only what is uncontested.

    The industry asked for records, not restraint

    The reporting compressed this into "AI bosses call for a slowdown". Read what was actually asked for. Sam Altman, to the Council:

    • "We need a mechanism for complementary national and international frontier AI standards: standards for measuring capabilities, assessing risks, determining whether safeguards are sufficient, and preserving meaningful human oversight."
    • "We need common standards so countries can compare evidence, verify compliance, and have a shared language and understanding about what is happening."
    • "We need accurate and speedy incident reporting, classification and reporting protocols, so the world can learn from failures before they become catastrophes."

    Every one of those is a paperwork obligation. Measurement, comparable evidence, verification, incident reports. The firms with the most to lose from heavy-handed regulation went to the Security Council and asked for a documentation regime. That is the most informative thing in the whole episode, and it is the reason the advice at the end of this page is what it is.

    On the word “slowdown”
    Altman did say "We have unilaterally slowed down in the past. We will do so in the future." That is a statement about OpenAI's own release decisions, not a call for an industry moratorium, and the two get reported interchangeably. Anthropic's chief executive also addressed the Council and pressed for common global standards for testing; his remarks were delivered by video and we have not seen an authoritative transcript, so we do not quote him.

    The United States said no, in the same room, the same afternoon

    Michael Kratsios, Director of the White House Office of Science and Technology Policy, delivered the US intervention. He delivered "The frontier of intelligence is advancing rapidly. That is not a reason to pause its further development or to constrain it with new global governance structures.", and then added "international dialogue, in this forum and in others, cannot be allowed to drift toward global governance.". To close the argument, he added "The American people's representatives will legislate and regulate on the American people's behalf. You should do the same for your people.".

    He cited a G20 innovation ministers' consensus that countries should "preserve national sovereignty in the governance of emerging technologies", and urged states to "prepare your institutions and regulators" domestically. For anyone working across borders, that last quotation is a risky one. The stated American position is that each country should regulate for itself. I don't know any consultant that likes to spend all their day doing translation between one country and another, or being allowed to do something in one country and not the other. Divergence is not a temporary lag, if we follow his intent. In my opinion, it might lead some countries to have severe laws and others much more linear ones, and trans-national consulting does not like to be told "not in this country". In sum, a consultant filing into the United States, Canada and Europe should expect the duties to keep diverging, which means you need to be prepared to adapt to the most severe laws in a flexible infrastructure.

    What this means for the way you work

    Put the two halves together. Today, your only binding constraint is a contract. Tomorrow, it will likely get to a point where the constraint is a record: what the system did, on what, and who checked it, and, for our sakes, what secrets came out of the bottle. Maybe we should try to get prepared. Here are some ideas.

    Do this nowWhy it survives whatever comes
    Keep confidential values out of the modelDischarges the contractual duty that binds you today, and gets you ready for whatever a future rule could ask about your data. A vendor's promise is a promise; an architecture where the value never leaves is a factual accuracy (a little wink to our NICE friends).
    Disclose AI assistance where a venue asks, and to clientsNo venue penalises disclosure. Several penalise its absence, including withdrawal of a submitted abstract.
    Keep a complete record of tool, document, and reviewer, and any data riskThis is the unit every proposal on the table is built around: measurement, comparable evidence, verification, incident reporting. Built later, it is reconstruction; built now, it is a stone that killed two birds.
    Write the policy down before you need itA short permissioned policy is what turns all of the above from individual judgement into something you can show a client.

    The reason to do this while nothing compels it is that the cost is almost entirely front-loaded and the benefit is not. A record kept as you go is a by-product of working with you, while its absence suggests something shadowy is happening. A record reconstructed after a client asks, or after a rule lands, is a really big project, and one whose reputational cost only grows the longer it is left.

    What could change this page

    • Federal legislation. Codifying the December 2025 order in statute would settle whether the state patchwork survives.
    • The Global Call for AI Red Lines deadline. Its signatories asked governments to reach an international agreement on red lines "by the end of 2026". That deadline is now closing, and the US position above seems unlikely to change drastically.
    • An AMCP Format update. Format 5.0 is silent on AI. AMCP's own commentary frames new AI text as answering questions raised since 5.0.
    • Anything that regulates authorship. That is the line this page turns on. If any US body crosses it, this page changes.

    And maybe a little counter-argument to change the air, this time again by the Canadians. Canada took the opposite turn in the same period: it abandoned its AI act, and then opened a consultation on the transparency of AI-generated content. Same months, opposite directions.

    Related reading

    Frequently asked questions

    Is there a US law requiring me to disclose that AI helped write a submission?

    No. As of September 2026 no US federal or state law requires the author of a health economics, market access or regulatory document to declare that AI assisted in writing it. The FDA's draft guidance on AI in regulatory decision-making expressly excludes drafting a submission from its scope. What does bind you is contracts and client NDAs, your engagement terms, and the terms of the AI tool you used. This is an orientation, not legal advice, please consult your corporate counsel before relying on it.

    If nothing requires disclosure, what is the actual risk of not disclosing?

    Contract, not regulation. An NDA restricts who may receive confidential information, and sending it to a third-party AI service can be a disclosure to a third party regardless of whether any law mentions AI. That exposure exists today and we do not really need any statute, since it is enforced by your client rather than by a regulator.

    What did the Trump administration's executive order on AI actually do?

    The executive order of 11 December 2025, "Ensuring a National Policy Framework for Artificial Intelligence", is directed at state AI laws. It established a litigation task force in the Department of Justice to challenge state AI statutes in federal court, and directed the Federal Trade Commission to address state-mandated bias mitigation. It creates no disclosure duty for anyone writing a submission. This is an orientation, not legal advice, please consult your corporate counsel before relying on it.

    The AI companies asked the UN to regulate them. Should I expect new rules?

    We should probably expect paperwork duties rather than more severe forms of limitation. At the UN Security Council on 23 September 2026, OpenAI and Anthropic asked for common standards for testing AI systems and for incident reporting between states, which is really just a records-and-evidence requirement, something we are used to in regulated industries. Expectedly, the United States rejected international governance at the same meeting. Any regime that emerges from that pressure is likely to ask what a system did and who checked it, and most specifically what sensitive data left the building, which is something you should probably start keeping track of by now.

    What should a US consultant do while the rules are unsettled?

    Three things that cost little and hold up under any future rule, and in my experience of implementing new guidelines over many years, the transition is predictably painful when you are not ready. First, keep confidential values out of the model rather than relying on a vendor's promise not to train on them. Second, disclose AI assistance to clients and in submissions where a venue asks, because no venue penalises disclosure and several penalise the absence of transparency. Third, keep a deep record of which tool did what, on which document, reviewed by whom, and what could potentially be exposed as a sensitive value. That record, the Untraceable protocol, as we like to call it here, is the unit every proposed regime is built around.

    About the author

    Gabriel Tremblay, DBA, Founder & CEO, Untraceable. Gabriel holds a doctorate in business administration (DBA) specialising in decision-making, and has published health economics and outcomes research on de-identification, cloaking methods and AI writing quality. Publications and DOIs are listed on the publications page.

    This guide is general information about how AI tools interact with confidentiality obligations. It is not legal advice, and it does not create any professional relationship. Confidentiality agreements vary, so review your own agreements with qualified counsel before relying on any framework described here.

    Work with AI on data you can't share with it.

    Untraceable cloaks confidential values on your computer before any AI model sees the text. The model never receives the secret at all.