Governments around the world are moving from broad aspirations about “trustworthy AI” to concrete regulatory proposals that would shape how advanced models are trained, evaluated, deployed, and monitored. That shift is accelerating litigation risk. AI governance is no longer just an internal compliance conversation about model cards and red-team exercises; it is becoming a public-law battleground where constitutional protections, statutory limits, and administrative procedure will determine what rules can survive. In the United States in particular, two bodies of doctrine are poised to do outsized work in the next wave of disputes: First Amendment law, which limits how government can regulate speech and speech-adjacent activity, and administrative law, which limits what agencies can do without clear congressional authorization and how courts review agency action. The result is an emerging reality that many AI regulatory efforts will be tested not only for policy wisdom, but for legal durability.
What makes AI governance uniquely litigious is that the object of regulation often looks like “speech” from at least one angle. Models generate text, images, and code, and they do so at scale, in response to user prompts, in ways that can influence public discourse. Meanwhile, the mechanisms regulators want to use content labeling, disclosure mandates, safety testing, distribution limits, liability rules, and restrictions on training or deployment can resemble familiar forms of speech regulation, including compelled speech, content-based restrictions, and constraints on editorial discretion. As these laws and rules mature, legal challenges will increasingly ask threshold questions: Is a model’s output protected expression? Is code expressive? Are platform-level ranking and moderation decisions constitutionally protected editorial judgment? What procedural burdens can government impose on private intermediaries before they have crossed into unconstitutional coercion?
At the same time, the administrative-law backdrop has shifted dramatically. The modern regulatory state has long depended on agency interpretations of ambiguous statutes, but the Supreme Court has tightened the screws on expansive readings of authority in “major” policy areas and has reshaped the doctrine of deference in ways that will reverberate across AI rulemaking. The Court’s emphasis on clear congressional authorization in major questions cases underscores that the more transformative an AI rule is, the more likely a court will demand unmistakable statutory grounding.[2] And the demise of Chevron-style deference means agencies may find it harder to defend creative interpretations of older statutes as they try to apply legacy mandates to novel AI systems.[1]
This article explores how those constitutional and administrative-law constraints are likely to frame the next generation of AI governance fights, and how organizations building or deploying AI systems can better understand though not eliminate the litigation risk that follows.
AI governance is often described in managerial terms policies, controls, testing, monitoring, and oversight structures that reduce the chance models will cause harm. But once governance becomes law, it takes on a different character. It becomes a set of enforceable obligations backed by penalties, licensing consequences, procurement restrictions, or private rights of action. That move from “best practice” to “mandate” triggers constitutional scrutiny because law is coercive. Even disclosure requirements and reporting duties seemingly modest governance tools can raise First Amendment concerns if they compel speech or chill protected expression, and they can raise administrative-law concerns if an agency lacks statutory authority or fails to explain its choices through reasoned decision-making.
In practice, the most politically attractive AI governance measures are also the most likely to be litigated. Requirements that force firms to explain model decisions, label certain outputs, publish safety testing results, limit the distribution of model weights, or restrict training on certain categories of data may be framed as consumer protection, civil rights enforcement, or national security. Yet each of these tools can be reframed in court as a restriction on expression, a compelled statement, a burden on editorial discretion, or an ultra vires action by an agency stretching beyond its delegated powers.
A further accelerant is jurisdictional fragmentation. In the United States, federal initiatives may be layered on top of state laws, attorney general actions, and sector regulators asserting authority through existing statutes. That multiplication increases both compliance cost and the likelihood that someone will sue because the incentives to test the boundaries are high, the regulated stakes are enormous, and the doctrinal environment is unusually favorable to challengers in some respects.
Many AI governance disputes will not turn on whether courts think AI is “good” or “dangerous,” but on how they categorize what is being regulated. In First Amendment law, categorization is often destiny. A rule that targets content certain ideas, viewpoints, or subjects tends to face far more severe scrutiny than a rule that regulates conduct without reference to expression. The difficulty for regulators is that AI sits at the intersection of both. Training and deployment are engineering activities, but the output is communicative; content moderation is operational, but it is also expressive judgment.
A central theme in future litigation will be whether and when AI-related decisions resemble editorial discretion. The Supreme Court’s recent treatment of state laws targeting social media platforms is a key signal. In Moody v. NetChoice, the Court addressed challenges to Florida and Texas statutes that sought to constrain platforms’ content moderation and require individualized explanations for certain moderation actions. The Court emphasized the need to analyze how such laws apply to particular functions and whether they intrude on protected editorial discretion, while also evaluating whether disclosure mandates unduly burden expression.[3] Even though that case was not about AI, the logic maps easily onto AI systems that rank, filter, recommend, summarize, refuse, or transform user speech. A generative AI assistant that declines certain prompts, prioritizes certain sources, or formats answers in a particular way can be framed as engaging in a form of content curation. If courts view those choices as editorial, attempts to force different choices may be seen as compelled hosting or compelled speech.
The hardest questions will come where governance rules are framed as “neutral” safety obligations but have speech-like effects. Consider output labeling mandates. If a law requires clear disclosure that a user is interacting with an AI system or that a piece of content was generated by AI, challengers may argue the law compels speech. Courts have sometimes tolerated certain disclosure regimes, but the analysis becomes more complex when the mandated disclosure is burdensome, controversial, or tied to contested policy narratives. Moody is instructive because it recognizes that individualized explanation requirements can themselves burden expression and require careful tailoring analysis rather than reflexive approval.[3] An AI governance regime that demands detailed explanations for refusals, filtering, or ranking may be attacked as forcing a system to “speak” in a government-prescribed way now of expressive judgment.
A related line of argument will focus on vagueness and overbreadth. If AI laws prohibit “harmful misinformation,” “biased content,” or “manipulative outputs” without clear definitions and safe harbors, challengers will argue that the uncertainty chills lawful speech and invites arbitrary enforcement. Those claims are not just technical pleading points; they are particularly potent in areas where the regulated entity must make rapid, high-volume decisions. Generative AI is exactly such a domain. If ambiguity forces developers to over-filter to avoid liability, courts may see chilling effects that weigh against the law’s constitutionality.
Another recurring issue will be whether AI-related regulation is truly content-neutral. Many governance proposals are framed in terms of “risk management,” but if the triggers for compliance depend on categories of content political speech, health advice, hate speech, election-related content then content neutrality becomes difficult to maintain. Once a law is seen as targeting particular subject matter, the government’s burden to justify it increases substantially. That is why AI governance drafters increasingly try to ground obligations in operational practices (testing, documentation, incident reporting) rather than output categories. Yet even operational mandates can become speech issues when they require publication of results, compelled explanations, or disclosures to users at the moment of interaction.
Transparency is the most widely endorsed theme in AI policy. Regulators want visibility into training data provenance, model limitations, performance disparities, and safety testing. Consumers want to know whether they are dealing with a human or a machine. Businesses want clarity on expectations. But transparency mandates are also the place where First Amendment challenges may land hardest, because a transparency rule is, by definition, a requirement to say something.
In litigation, opponents of AI disclosure regimes will often argue that some transparency mandates are not merely factual notices but ideological scripts. If a rule forces an AI developer to adopt the government’s framing of contested issues for example, to declare a system “unsafe” under criteria the developer disputes, or to deliver warnings in language that implies moral fault courts may treat that as compelled speech in the most suspect form. Even where the disclosure is purely factual, challengers can argue that the burden is excessive, that the disclosure crowds out other messages, or that it operates as a de facto penalty by stigmatizing lawful activity.
Moody highlights another subtlety: not all disclosure is the same. A high-level policy statement about moderation practices is different from individualized, transaction-by-transaction explanations that must be generated at scale.[3] In AI systems, the pressure for individualized explanations is intense. Legislators and regulators want a user who receives a refusal, a reduced-ranking decision, or an “unsafe” classification to receive a reason. But as soon as explanations become mandatory, the regulator has effectively inserted itself into how the system communicates about its own decision-making. That raises not only compelled speech concerns but also practical risks: explanations can be inaccurate, can reveal security details that facilitate evasion, can expose trade secrets, and can create new litigation hooks when users allege the explanation was false or misleading.
Transparency also interacts with trade secret and security concerns in ways that can deepen constitutional disputes. While trade secret protection is not itself a First Amendment doctrine, compelled disclosure regimes that require revealing sensitive information can strengthen arguments that the law is unduly burdensome and poorly tailored. The more a rule forces detailed disclosures about model weights, training pipelines, or safety mitigations, the more challengers will argue that government is imposing a penalty on lawful expression and innovation.
Generative AI products are increasingly judged by how they refuse. Refusals are governance in action: they are the point where the system enforces policy, prevents harm, and tries to comply with law. Yet refusals are also the point where constitutional disputes arise, because refusal is a form of selection. Selection can be framed as editorial judgment, and editorial judgment is a core First Amendment concept.
Moody underscores that when a law intrudes on a private actor’s control over “whether and how” third-party content is presented, the analysis can implicate protected editorial discretion.[3] In an AI setting, prompts and user-provided inputs are often third-party speech, and outputs can be understood as a transformation or presentation of that speech combined with the model’s own generated content. Rules that attempt to force a model to answer certain prompts, to remain “neutral,” or to carry categories of content it would otherwise reject can be challenged as compelled hosting or compelled speech.
This theory becomes especially salient when governments regulate AI systems used for news, politics, or public debate. If a state mandates that an AI assistant must not “discriminate” against particular viewpoints in how it answers political questions, the state may argue it is preventing censorship. The developer will argue the state is imposing compelling neutrality and intruding on how the system communicates. Courts will then have to decide whether the system’s curation and generation functions are more like a utility service or more like a publisher’s editorial process. Moody suggests courts will not assume away those complexities; they will want a function-by-function analysis and will be sensitive to burdens on expressive judgment.[3]
If the First Amendment is the constitutional front line, administrative law is the structural one. Many AI governance initiatives will be executed not through new statutes but through agency rulemaking, guidance, enforcement actions, procurement rules, and interpretations of existing authority. That approach is tempting because legislature moves slowly, while AI moves quickly. But speed comes with legal risk, because courts have grown more skeptical of agencies asserting sweeping power over major policy domains.
The major questions doctrine is the clearest warning label. In West Virginia v. EPA, the Supreme Court rejected an expansive agency approach to a significant policy problem, emphasizing the need for clear congressional authorization when an agency claims broad power with major economic and political significance.[2] AI governance is almost tailor-made for that scrutiny. Rules that would reshape the AI industry through licensing requirements, mandatory pre-deployment approvals, or expansive safety regimes will be defended as necessary to manage catastrophic risk. Challengers will respond that such rules are economically and politically enormous and therefore require explicit statutory permission rather than creative inference from old statutes drafted for other technologies.
Even where an agency has some plausible hook consumer protection, civil rights enforcement, workplace safety, or financial regulation, the more the agency’s AI program looks like a new, comprehensive regulatory framework, the more it invites major questions challenges. Regulators can attempt to mitigate this by tailoring rules to specific sectors or by emphasizing incremental measures. Yet the pressure to “do something big” after a high-profile AI incident will remain, and that is exactly the pattern that has produced major questions conflicts in other domains.
At the same time, the doctrine of judicial difference to agency statutory interpretation has changed. In Loper Bright Enterprises v. Raimondo, the Supreme Court overruled Chevron, reshaping how courts approach agency interpretations of ambiguous statutes.[1] The practical consequence for AI governance is that agencies may find it harder to rely on ambiguity as a shield. Courts will more readily say, in effect, “Show us the statute, and show us where Congress actually authorized this.” Agencies can still bring expertise to bear, and their reasoning can still matter under traditional administrative-law principles, but the decisive interpretive authority lies more squarely with judges.
This shift alters litigation strategy for both sides. Agencies must draft AI rules with an even greater emphasis on statutory text, historical practice, and careful tailoring to the delegated mission. Challengers, meanwhile, have a clearer path to argue that an agency is operating outside its lane even if the agency can point to broad, general statutory language. In a world where AI is pervasive, almost any statute can be framed as relevant; Loper Bright makes it more likely courts will reject that kind of maximalism when it is not anchored in clear congressional intent.[1]
Because comprehensive federal AI legislation remains difficult, executive action has played a central role in shaping the U.S. governance environment. Executive Order 14110 is an example of how presidents attempt to coordinate and accelerate agency activity around AI safety, security, and trust. Executive orders can be powerful within the executive branch, particularly when they direct agencies to use existing authority, prioritize enforcement, set procurement standards, or coordinate standards development.[5] But an executive order cannot itself expand an agency’s statutory powers. The legal vulnerability comes when agencies, spurred by executive direction, adopt binding rules or enforcement theories that push beyond what statutes permit.
This is where administrative-law challenges become particularly likely. When agencies rely on guidance documents, frameworks, or informal “best practices” to influence industry behavior, regulated entities may still face coercive pressure even if the document is not formally binding. Litigation may then focus on whether the agency has effectively created a rule without proper procedure or exceeded its legal authority. Conversely, if agencies do proceed through formal rulemaking, they face the full weight of procedural requirements and the risk of being vacated for inadequate justification, poor cost-benefit reasoning, insufficient consideration of alternatives, or failure to respond to significant comments. In a fast-moving technical domain like AI, building a robust administrative record is hard, but it is essential especially when major questions and post-Chevron interpretive skepticism loom.[2][1]
Executive-driven governance also creates a timing problem. Executive branch initiatives can change dramatically across administrations. That volatility affects business planning, but it also affects litigation posture. Parties may sue to block an aggressive AI program, betting that either a court will intervene or a future administration will reverse course. Meanwhile, agencies may rush to finalize rules before political windows close, increasing the risk of procedural mistakes and thin records that courts can later use to invalidate the rule.
While the U.S. system is shaped by constitutional limits and decentralized authority, the European Union has pursued a more comprehensive legislative approach through the EU AI Act. [4] The Act establishes a harmonized framework designed to shape development, market placement, and use of AI systems across the Union, with a structure that reflects the EU’s regulatory style and its emphasis on fundamental rights, safety, and market governance.[4] For global firms, this matters even when U.S. law is the primary risk driver, because cross-border compliance strategies often become de facto global standards. When the EU requires certain risk management steps, documentation, or obligations for high-risk systems, multinational developers may adopt similar governance processes everywhere to avoid operating two completely different systems.
But the EU approach also highlights why U.S. litigation risk may be higher. A comprehensive statute passed through a legislative process can still be challenged, but it typically rests on clearer democratic authorization than an agency program built from older statutory fragments. In the U.S., where agencies must often retrofit AI governance onto existing mandates, challengers can more plausibly argue “Congress never authorized this.” In Europe, the argument is more likely to be about proportionality, scope, or interpretation within the EU legal order rather than about whether the regulator has any authority at all.[4] That contrast will continue to shape where governance rules are most likely to “stick” and where they are most likely to be tied up in court.
Cross-border friction also creates practical litigation issues. U.S. plaintiffs challenging AI rules may point to the burdens of complying with multiple regimes, arguing that additional U.S. mandates are duplicative, overly burdensome, or destabilizing. Regulators may respond that foreign laws are irrelevant to domestic authority. Nonetheless, courts assessing burdens and tailoring in First Amendment cases may be influenced by real-world compliance impacts, and agencies defending rules under administrative-law standards must consider whether their approach is rational in light of the broader landscape.
AI governance litigation will often be brought as pre-enforcement challenges, because waiting for penalties can be too risky. Plaintiffs may seek injunctions that prevent enforcement while courts evaluate constitutional claims and statutory authority. In First Amendment cases, courts have historically been more open to pre-enforcement review because chilled speech is itself harm. In administrative-law cases, plaintiffs often argue that a rule is unlawful on its face or that the agency failed to follow required procedure.
Moody provides a useful template for how courts may insist on specificity about what a law covers before deciding whether it is unconstitutional.[3] That insistence on scope will likely appear in AI cases too, especially where laws are drafted broadly to cover many systems and functions. Judges will ask whether the law applies to a narrow class of high-impact models or sweeps in ordinary software features; whether it applies to direct messaging-style tools, search, ranking, or summarization; and whether it burdens expressive functions differently across those categories. Laws that are overinclusive risk being struck down or narrowed, while laws that are underinclusive risk being seen as politically selective.
On the administrative-law side, West Virginia and Loper Bright suggest that courts will demand statutory clarity and careful reasoning.[2][1] The more novel and transformative the regulation, the more an agency will need to show that Congress actually gave it the authority to do what it is doing, and the more the agency will need to explain why its chosen path is reasonable relative to alternatives. AI rules grounded in broad language like “unfair practices” or “public interest” will not automatically fail, but they will be litigated aggressively, and agencies will not be able to rely on the same level of interpretive deference that once insulated ambitious programs.[1]
For companies, universities, and public-sector entities, the lesson is not that AI governance is impossible; it is that governance has to be designed with legal durability in mind. That begins with recognizing that many of the most common governance tools, disclosure, explanations, content restrictions, and safety attestations have constitutional dimensions in the U.S. context. It also means appreciating that agency-led governance can be both powerful and fragile, especially when it is built on contested interpretations of older statutes in a post-Chevron world.[1]
Organizations can reduce exposure by treating governance artifacts as dual-purpose: they should improve safety and accountability, but they should also be defensible in court. That begins with building governance in ways that avoid viewpoint-based triggers, minimize ambiguity, and maintain clear rationales tied to demonstrable harms rather than contested ideologies. It also means creating documentation that accurately reflects what systems can and cannot do, because overpromising in public-facing disclosures can become a litigation problem even apart from regulatory scrutiny. The practical approach is to track how executive policy is operationalized, distinguish aspirational guidance from binding obligations, and anticipate where authority questions might later surface.
The direction of travel is clear: governments will regulate AI more, not less. Some of those regulations will be narrow and sector-specific, and it will likely survive. Some will be ambitious and sweeping, and it will become litigation magnets. The most durable frameworks will be those that respect the structural limits of the U.S. constitutional order by focusing on demonstrable harms, avoiding viewpoint-based triggers, tailoring disclosure obligations to avoid undue burdens, and grounding agency action in clear statutory text and reasoned explanations.[3][2][1]
For lawyers and compliance leaders, the near-term challenge is to integrate these constraints into governance planning. AI risk is not only a technical and reputational problem; it is a constitutional and administrative law problem. Organizations that treat AI governance as a purely operational matter will be surprised when rules are enjoined, when enforcement theories shift, or when litigation turns internal safety decisions into constitutional controversies. Organizations that anticipate those dynamics can make governance more resilient, reduce disruption, and be better positioned whether they end up defending a system, challenging a rule, or adapting quickly when courts reshape the landscape yet again.
Contact Tishkoff:
Tishkoff PLC specializes in business law and litigation. For inquiries, contact us at www.tish.law/contact/. & check out Tishkoff PLC’s Website (www.Tish.Law/), eBooks (www.Tish.Law/e-books), Blogs (www.Tish.Law/blog) and References (www.Tish.Law/resources).
Foot-noted Sources:
- Loper Bright Enterprises et al. v. Raimondo, Secretary of Commerce, et al., No. 22–451, Supreme Court of the United States (June 28, 2024). www.supremecourt.gov/opinions/23pdf/22-451_7m58.pdf
- Moody v. NetChoice, LLC, No. 22–277, Supreme Court of the United States (July 1, 2024). www.supremecourt.gov/opinions/23pdf/22-277_d18f.pdf
- Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonized rules on artificial intelligence (Artificial Intelligence Act), Official Journal of the European Union, L series, 2024/1689 (published July 12, 2024).
https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng - Executive Order 14110 of October 30, 2023, “Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence,” 88 Federal Register 75191 (published November 1, 2023). https://en.wikipedia.org/wiki/Executive_Order_14110
