GLACIS·US state AI laws·Tracker·Updated August 2026
The US state AI laws tracker.
A US state AI law tracker is only worth the date on it, so this one leads with a change log and a single effective-date calendar. Where every comprehensive state AI statute now stands: Colorado repealed its 2024 AI Act and replaced it with SB 26-189’s ADMT transparency regime (compliance from January 1, 2027), California’s ADMT regulations live with a phased compliance cascade through 2030, Texas TRAIGA in force, New York’s RAISE Act finalised, and the Trump administration’s December 2025 preemption executive order pressing on all of it — though no federal preemption has yet been enacted. With the citations attorneys general expect.
By Joe Braidwood, CEO GLACIS·32 min read·Published 20 December 2025·Updated 13 August 2026
Jan 2026
CA AB 2013, SB 53, ADMT (risk-assessments), TX TRAIGA all in force
May 14 2026
Colorado signs SB 26-189, repealing & replacing the 2024 AI Act
Apr 1 2027
CA ADMT pre-use notices begin for significant decisions
Jan 1 2027
CO SB 26-189 compliance; NY RAISE Act, WA HB 2225, OR SB 1546 effective
Joe Braidwood
CEO, GLACIS
35 min read
Executive summary
The United States still lacks comprehensive federal AI legislation; what it has is a growing patchwork of state laws operating against the backdrop of an active federal preemption push. As of June 2026, Texas HB 149 (TRAIGA) is live (effective January 1, 2026), California’s CPPA ADMT regulations are in force with significant-decision obligations phasing in April 1, 2027, California’s SB 53 Frontier AI Transparency Act applies to large frontier developers, and Colorado repealed and replaced its 2024 AI Act (SB 24-205) with SB 26-189 (Automated Decision-Making Technology), signed May 14, 2026, whose substantive obligations commence January 1, 2027. New York’s RAISE Act is signed (chapter amendment March 27, 2026) and effective January 1, 2027.
State AI laws generally address three categories: (1) algorithmic discrimination in high-stakes decisions, (2) automated decision-making transparency and consumer rights, and (3) sector-specific AI use in employment, healthcare, insurance, and financial services. Many laws leverage existing consumer protection or privacy frameworks rather than creating entirely new regulatory structures.
The federal counter-current. President Trump’s December 11, 2025 executive order “Eliminating State Law Obstruction of National AI Policy” stood up a DOJ AI Litigation Task Force to challenge state AI laws. It applies pressure through litigation and funding levers, but no federal statute or court has actually preempted or paused any state AI law — state requirements remain valid and enforceable. A bipartisan coalition of 36 state attorneys general has opposed broad preemption. Until the courts and Congress sort this out, organisations operating nationally should still adopt a “highest common denominator” posture aligned to NIST AI RMF and ISO/IEC 42001 — sound practice for AI governance, even though Colorado’s SB 26-189 no longer codifies them as a legal safe harbor.
Q1 → Q2 2026 update brief
Colorado repealed and replaced its AI Act: SB 26-189 (Automated Decision-Making Technology) was signed May 14, 2026, repealing and reenacting the 2024 SB 24-205 before it took effect. Substantive obligations commence January 1, 2027. The old June 30, 2026 trigger never went live.[F1]
Trump executive order on state AI law preemption signed December 11, 2025; a DOJ AI Litigation Task Force was stood up to challenge state AI laws. As of June 2026 no federal statute or court has preempted or paused any state AI law.[F1]
California CPPA ADMT regulations approved by OAL on September 22, 2025 with the phasing finalised: risk-assessment compliance from January 1, 2026, ADMT pre-use notices for significant decisions from April 1, 2027, first attestation due April 1, 2028, cybersecurity audit certifications cascading 2028–2030.[F2]
California SB 53 (Frontier AI Transparency Act) in force January 1, 2026. ~5–8 frontier developers in scope; transparency reports, NIST AI RMF or ISO/IEC 42001 alignment, 15-day critical-incident reporting, $1M civil penalty per violation.[F3]
New York RAISE Act chapter amendment signed March 27, 2026; effective January 1, 2027 with DFS oversight and AG enforcement to $1M/$3M.[F4]
Washington enacted three AI laws in March 2026: HB 1170 (AI content disclosure, eff. February 1, 2027), HB 2225 (companion chatbots, eff. January 1, 2027), and SSB 5886 (digital-likeness rights, eff. June 10, 2026). Oregon followed with SB 1546 (companion chatbots).[F5]
NYC Local Law 144 enforcement reform: NY State Comptroller’s December 2, 2025 audit found DCWP enforcement “ineffective”; DCWP shifted to proactive investigations in 2026.[F6]
1
Comprehensive AI Law Enacted
30+
States with AI Bills
Jan 2027
Colorado SB 26-189 Compliance
$20K
Max Penalty per Violation
In This Guide
What changed in 2026
Every entry below is dated, and each links to the section of this tracker that carries the detail. The single most consequential change of the year is that the state everyone cited as the model for AI regulation repealed its own law before it took effect.
Date
Change
Status now
14 May 2026
Colorado signed SB 26-189, repealing and replacing the 2024 Colorado AI Act before it ever took effect. The reasonable-care and impact-assessment model is gone, replaced by a narrower transparency and disclosure regime for covered ADMT.
Enacted; obligations commence 1 Jan 2027
27 Mar 2026
New York signed the final chapter amendment to the RAISE Act, originally signed 19 Dec 2025. Second US state frontier-model law after California SB 53.
Enacted; takes effect 1 Jan 2027
Mar 2026
A bipartisan coalition of 36 state attorneys general publicly opposed broad federal preemption of state AI law.
Unresolved; no federal statute or court has preempted state AI law
1 Jan 2026
Texas HB 149 (TRAIGA) took effect, with Attorney General enforcement and civil penalties up to $200,000 per violation.
In force
1 Jan 2026
The California CPPA ADMT, risk assessment and cybersecurity audit regulations took effect, phasing in over 24 months.
In force; significant-decision duties from 1 Jan 2027
11 Dec 2025
Executive order “Eliminating State Law Obstruction of National AI Policy” created a DOJ AI Litigation Task Force and conditioned BEAD broadband funding on state repeal of burdensome AI rules.
Active political contest; no preemption enacted
Two patterns are worth naming because they change how a multi-state program should be planned. First, the direction of travel is no longer one-way: Colorado demonstrated that a comprehensive state AI law can be repealed and narrowed before it binds anyone, so building a compliance program against a single state statute now carries repeal risk as well as deadline risk. Second, the center of gravity has moved from broad algorithmic-discrimination statutes toward two narrower shapes — transparency and disclosure duties for automated decisions, and frontier-model safety obligations aimed at a handful of large developers. An organization that is neither a frontier developer nor a user of ADMT in significant decisions is touched by far less of this than the headlines suggest.
Effective-date calendar
The dates that bind, in order. Dates in the past are obligations already live; dates in the future are the planning horizon. Each entry is covered in more detail in the state section it belongs to.
Effective
Law
Applies to
1 Jan 2020
Illinois AI Video Interview Act
Employers using AI to analyze video interviews
1 Jan 2023
California CPRA amendments to the CCPA
Profiling opt-out and automated decision disclosure
5 Jul 2023
NYC Local Law 144
Automated employment decision tools used in NYC hiring and promotion
1 Oct 2024
Montana Consumer Data Privacy Act
Profiling opt-out and data protection assessments
1 Jan 2026
Texas HB 149 (TRAIGA)
Prohibited AI uses and consumer-facing AI disclosure
1 Jan 2026
California CPPA ADMT regulations, baseline duties
Businesses using automated decision-making technology
1 Jan 2027
Colorado SB 26-189
Covered ADMT; AG clarifying rules due the same date
1 Jan 2027
California ADMT significant-decision duties
ADMT used in significant decisions
1 Jan 2027
New York RAISE Act
Large frontier developers above compute and revenue thresholds
1 Apr 2028
California first ADMT risk-assessment attestation
Businesses filing with the CPPA; cybersecurity audit certifications cascade 2028–2030
1 Jan 2030
Colorado 60-day cure right sunsets
Entities relying on cure to avoid SB 26-189 enforcement
The US AI Regulatory Landscape
Unlike the European Union, which enacted a comprehensive AI Act covering all member states, the United States has taken a fragmented approach to AI regulation. In the absence of federal legislation, individual states have begun enacting their own AI laws—creating a complex compliance landscape for organizations operating across state lines.
Why States Are Acting
Several factors are driving state-level AI regulation:
Federal inaction: Despite multiple proposed bills, Congress has not passed comprehensive AI legislation, leaving a regulatory vacuum
Consumer protection concerns: High-profile cases of algorithmic discrimination in hiring, lending, and insurance have prompted state responses
Privacy law extension: States with existing privacy laws (California, Virginia, Connecticut, Colorado) are extending those frameworks to address AI
Economic competition: States like California and Colorado are positioning themselves as leaders in responsible AI governance
Types of State AI Laws
State AI legislation generally falls into several categories:
Categories of State AI Legislation
Category
Focus
Example States
Comprehensive AI Laws
Broad regulation of high-risk AI systems across multiple domains
Colorado (enacted), Texas (enacted, HB 149), California (pending)
Employment AI
AI in hiring, promotion, termination decisions
Illinois (AIPLA), New York (Local Law 144), Maryland
Biometric AI
Facial recognition, voice recognition, biometric data
Illinois (BIPA), Texas, Washington
Privacy + AI
Automated decision-making provisions in privacy laws
California (CCPA/CPRA), Virginia (VCDPA), Connecticut (CTDPA)
Healthcare AI
AI in clinical decisions, insurance, care management
California (pending), New York (proposed)
Government AI
AI use by state and local government agencies
California, Washington, multiple states
Colorado: From the 2024 AI Act to the SB 26-189 ADMT Regime
Colorado was the first state to enact a comprehensive AI law — and the first to walk it back. The 2024 Colorado AI Act (SB 24-205) was repealed and replaced before it ever took effect by SB 26-189, titled “Automated Decision-Making Technology,” which Governor Polis signed on May 14, 2026. The new law trades the old reasonable-care-and-impact-assessment model for a narrower transparency and disclosure regime built around “covered automated decision-making technology (ADMT).” Substantive obligations commence January 1, 2027, by which date the Attorney General must also adopt clarifying rules.
EnactedSB 26-189 — compliance January 1, 2027
Colorado SB 26-189 Key Points
Scope: Covered ADMT used to materially influence a consequential decision in education, employment, housing, financial or lending services, insurance, health-care services, and essential government services
Trigger: “Materially influence” — a non-de-minimis factor in the outcome; incidental or clerical uses are excluded
Model: Transparency and disclosure — the reasonable-care duty, impact assessments, and the NIST/ISO safe harbor are not part of the new law
Penalties: Up to $20,000 per violation under the Colorado Consumer Protection Act; a 60-day cure right that sunsets January 1, 2030
Enforcement: Colorado Attorney General only (no private right of action); not yet operative — obligations begin January 1, 2027
Developer Requirements
Under SB 26-189, developers of covered ADMT must provide each deployer documentation that includes:
Intended uses and known harmful or inappropriate uses
The categories of training data, to the extent known
Known limitations and risks, and circumstances where the ADMT should not be used
Instructions for appropriate use, monitoring, and meaningful human review
The information a deployer needs to meet its own obligations
Records are retained for at least three years. No disclosure of proprietary source code, model weights, or trade secrets is required.
Deployer Requirements
Deployers of covered ADMT owe four operational duties, with at least three-year recordkeeping:
Pre-use notice — clear-and-conspicuous notice before covered ADMT is used to materially influence a consequential decision
Post-adverse-outcome disclosure within 30 days — a plain-language description of the ADMT’s role plus the consumer’s rights and how to exercise them
Data correction — on request, access to and correction of factually inaccurate personal data used by the ADMT
Meaningful human review or reconsideration — on request, to the extent commercially reasonable
The earlier risk-management-program requirement, annual impact assessments, the 90-day Attorney General notification on discovering discrimination, and the standalone “you are interacting with an AI” chatbot disclosure did not survive the rewrite. Discrimination is now addressed under existing Colorado anti-discrimination law, and there is no longer a size-based small-business exemption.
California leads US states in data privacy regulation, and its frameworks increasingly address AI. While California hasn’t enacted a comprehensive AI law equivalent to Colorado’s, multiple overlapping regulations affect AI deployment:
California Consumer Privacy Act (CCPA/CPRA)
EnactedEffective January 1, 2023 (CPRA amendments)
CCPA/CPRA AI Provisions
Profiling opt-out: Consumers can opt out of automated decision-making
Access rights: Consumers can access information about automated decisions
Risk assessments: Required for processing posing significant risk (including profiling)
Penalties: $2,500-$7,500 per intentional violation
California Automated Decision-Making Technology (ADMT) Regulations
The California Privacy Protection Agency (CPPA) finalized its ADMT, risk assessment, and cybersecurity audit regulations, which took effect January 1, 2026. The rules phase in over the following 24 months, with the most consequential obligations for AI systems used in "significant decisions" beginning January 1, 2027. Key provisions:
Pre-use notice: Detailed disclosure before ADMT is used in significant decisions
Opt-out rights: Consumers may request human review or alternative processes
Access to logic: Businesses must explain how automated decisions are made
Risk assessments: Required for ADMT used in significant decisions and other high-risk processing
The regulations are now in force. Businesses already had to begin complying on January 1, 2026 for baseline obligations; significant-decision ADMT requirements, risk assessments, and the first cybersecurity audit cycle phase in through 2027 and 2028 depending on business size.
California Pending AI Legislation
California’s legislature has considered multiple AI bills, including proposals modeled on the EU AI Act:
SB 1047 (2024): "Safe and Secure Innovation for Frontier Artificial Intelligence Models Act" - Originally imposed significant requirements on large AI models; later amended significantly before passing
AB 2013 (2024): AI training data transparency for generative AI
AB 2885 (2024): AI watermarking for synthetic content
Healthcare AI bills: Multiple proposals addressing AI in clinical settings
Illinois: Biometrics and Employment AI Pioneer
Illinois has been at the forefront of regulating specific AI applications, particularly biometric data and employment decisions:
Illinois Biometric Information Privacy Act (BIPA)
EnactedEffective 2008
BIPA Requirements
Scope: Fingerprints, face geometry, iris scans, voice prints, hand geometry
Notice & consent: Written consent required before collection
Private right of action: Individuals can sue directly
Penalties: $1,000 per negligent violation; $5,000 per intentional violation
BIPA has generated significant litigation against AI companies using facial recognition technology, with settlements reaching hundreds of millions of dollars. The law effectively prohibits most commercial facial recognition uses without explicit consent.
Illinois Artificial Intelligence Video Interview Act (AIVIA)
EnactedEffective January 1, 2020
AIVIA Requirements
Employers using AI to analyze video interviews must: (1) notify applicants that AI will be used; (2) explain how the AI works and what characteristics it evaluates; (3) obtain applicant consent before the interview; (4) limit who can view the video; (5) delete videos upon applicant request.
Illinois Employment AI Legislation
Illinois continues to expand employment AI regulation:
HB 3773 (2024): Broader employment AI transparency and discrimination prevention requirements
Amendments to AIVIA: Expanded disclosure and consent requirements
Human Rights Act integration: AI discrimination treated as civil rights violation
Texas: TRAIGA Now in Force
Texas, with its large technology sector and business-friendly reputation, has moved from a measured stance to enacting one of the most consequential state AI laws. Texas HB 149, the Texas Responsible Artificial Intelligence Governance Act (TRAIGA), took effect January 1, 2026 and is now live. It prohibits certain AI uses (including intentional discrimination and unlawful manipulation), establishes disclosure obligations for consumer-facing AI, and creates Attorney General enforcement with civil penalties up to $200,000 per violation.
Texas HB 149 (TRAIGA)
EnactedEffective January 1, 2026
Texas Responsible AI Governance Act
Scope: Developers and deployers of AI systems doing business in Texas, producing AI products or services used by Texas residents, or whose AI affects Texas residents
Prohibited uses: AI intentionally developed or deployed for unlawful discrimination, unlawful behavioral manipulation, social scoring by government, or generation of unlawful visual content
Government disclosure: State agencies interacting with consumers via AI must disclose the interaction
Enforcement: Attorney General exclusive; civil penalties up to $200,000 per prohibited use and $40,000 per day for continuing violations; 60-day cure period
Regulatory sandbox: Establishes a sandbox program administered by the Texas Department of Information Resources for testing innovative AI systems
Texas Capture or Use of Biometric Identifier Act (CUBI)
EnactedEffective 2009
Texas CUBI
Requires notice and consent before capturing biometric identifiers for commercial purposes. Unlike Illinois BIPA, Texas does not provide a private right of action—enforcement is through the Attorney General. Penalties up to $25,000 per violation.
Texas Data Privacy and Security Act (TDPSA)
Effective July 1, 2024, the TDPSA includes provisions affecting AI:
Profiling opt-out: Consumers can opt out of profiling for decisions with legal or significant effects
Data protection assessments: Required for processing that presents heightened risk, including profiling
No private right of action: Attorney General enforcement only
Texas AI Advisory Council
Texas established an AI Advisory Council to study AI issues and recommend legislation. Areas under consideration include:
AI in government decision-making
AI in healthcare and insurance
AI workforce implications
AI safety and security standards
New York: Local and State AI Regulation
New York presents a complex regulatory landscape with both city-level and state-level AI requirements:
New York City Local Law 144 (Automated Employment Decision Tools)
EnactedEffective July 5, 2023
NYC Local Law 144
Scope: Automated employment decision tools (AEDTs) used in NYC hiring/promotion
Bias audit: Annual independent audit for disparate impact by race, ethnicity, sex
Publication: Audit summary must be publicly posted
Notice: Candidates must be notified at least 10 days before AEDT use
Penalties: $500 first violation; $500-$1,500 subsequent violations per day
April 2026 enforcement update. The New York State Comptroller’s December 2, 2025 audit found NYC DCWP enforcement of Local Law 144 “ineffective” — 75% of 311 calls about AEDTs were misrouted. DCWP committed to proactive investigations starting in 2026, increasing the likelihood of enforcement actions for employers and AEDT vendors operating in NYC.
New York RAISE Act (frontier AI)
The Responsible AI Safety and Education Act (S6953B / A6453B) was originally signed by Governor Hochul on December 19, 2025; the final chapter amendment was signed on March 27, 2026. It is the second US state frontier-model law (after California SB 53) and takes effect January 1, 2027.
Scope: Large frontier developers (training-compute and revenue thresholds aligned to SB 53).
Obligations: Publish safety protocols; report critical incidents to the Department of Financial Services within 72 hours.
Oversight: A new oversight office within DFS will assess large frontier developers.
Enforcement: Attorney General may bring civil actions; penalties up to $1 million for first violation, $3 million for subsequent.
Other New York AI legislation
NY SHIELD Act: data security requirements applicable to AI systems processing personal information.
NYDFS Insurance Circular Letter No. 7 (2024): AI underwriting and pricing guidance for licensed insurers.
Healthcare AI bills: requirements for AI in clinical decision-making (pending).
Other State AI Laws and Pending Legislation
Beyond the major states covered above, AI regulation is advancing across the country:
States with Privacy Laws Including AI Provisions
Virginia (VCDPA)
Enacted
Effective January 1, 2023
• Profiling opt-out rights
• Data protection assessments for profiling
• No private right of action
Connecticut (CTDPA)
Enacted
Effective July 1, 2023
• Profiling opt-out for legal/significant decisions
• Data protection assessments required
• 60-day cure period
Utah (UCPA)
Enacted
Effective December 31, 2023
• Consumer access to profiling information
• More limited than other state laws
• AG enforcement only
Montana (MCDPA)
Enacted
Effective October 1, 2024
• Profiling opt-out rights
• Data protection assessments
• 60-day cure period
Oregon (OCPA)
Enacted
Effective July 1, 2024
• Profiling opt-out for automated decisions
• Data protection assessments
• Cure period through 2026
Delaware (DPDPA)
Enacted
Effective January 1, 2025
• Profiling opt-out rights
• No revenue threshold
• Broad applicability
States with Biometric/Facial Recognition Laws
State
Law
Private Action
Key Requirements
Illinois
BIPA
Yes
Most stringent; written consent required
Texas
CUBI
No
Notice and consent; AG enforcement
Washington
HB 1493
No
Notice required; enrollment consent
Arkansas
PIPA
No
Notice and consent requirements
Maryland
SB 169
No
Facial recognition restrictions in employment
States with Government AI Restrictions
Several states have enacted or proposed restrictions on government use of AI:
California: Restrictions on law enforcement facial recognition
Massachusetts: Proposed moratorium on government facial recognition
Maine: Limits on law enforcement use of facial recognition
Vermont: Restrictions on government AI without human oversight
Washington: State agency AI accountability requirements
State AI Law Comparison Matrix
This matrix provides a high-level comparison of key AI regulatory requirements across major states:
Requirement
Colorado
California
Illinois
New York
Texas
Comprehensive AI Law
✓ Enacted
Partial
Partial
Pending
✓ HB 149
Employment AI
✓
CPRA
✓ AIVIA
✓ LL144
—
Biometric AI
—
CCPA
✓ BIPA
Pending
✓ CUBI
Impact Assessments
— (repealed)
✓ CPRA
—
✓ LL144
✓ TDPSA
Consumer Opt-Out
Correction / human review
✓
Limited
—
✓
Private Right of Action
No
Limited
Yes (BIPA)
No
No
Safe Harbor (Frameworks)
— (repealed)
—
—
—
—
Federal context and the preemption push
The federal landscape changed materially in late 2025 and now actively shapes how state AI law plays out.
The December 2025 executive order
On December 11, 2025, President Trump signed “Eliminating State Law Obstruction of National Artificial Intelligence Policy.” The order:
Establishes an AI Litigation Task Force within the Department of Justice to challenge state AI laws on commerce-clause and preemption grounds. (Colorado’s 2024 SB 24-205 had drawn early scrutiny, but the state has since repealed and replaced it with SB 26-189 — a state legislative change, not a federal preemption.)
Directs the FTC to articulate when state laws “requiring alterations to truthful AI outputs” are preempted by Section 5 of the FTC Act.
Conditions roughly $42 billion of BEAD broadband funding on state repeal of “burdensome” AI regulation.
Carves out child-safety, AI-compute and data-centre infrastructure, and state procurement from preemption.
A bipartisan coalition of 36 state attorneys general publicly opposed broad federal preemption in March 2026; the Senate previously voted 99–1 to strip a similar preemption provision from the budget reconciliation bill, and a rumored FY2026 NDAA moratorium was omitted from the final bill text. No federal statute or court has preempted or paused state AI law; the political contest remains unresolved as of June 2026.
Senate AI Working Group and proposed federal bills
Senator Marsha Blackburn’s TRUMP AMERICA AI Act would codify the executive order into statute and create comprehensive federal AI governance, but remains in committee. The Bipartisan Senate AI Working Group reports continue to be a roadmap document rather than enacted law.
NAAG state AG AI Task Force
In early 2026 Utah Attorney General Derek Brown (R) and North Carolina Attorney General Jeff Jackson (D) launched a bipartisan AI Task Force in partnership with OpenAI, Microsoft, and the Attorneys General Alliance. The task force coordinates state AG investigations and monitors emerging AI risks — especially child-safety and chatbot harms.
Why no comprehensive federal AI law yet
Despite bipartisan interest, federal AI legislation has stalled due to:
Partisan disagreement on the regulation-versus-innovation balance.
Preemption disagreement — many governors of both parties (CA, FL, CO) oppose stripping state authority.
Definitional challenges in scoping “AI” and “high-risk” applications.
Jurisdictional complexity across Senate and House committees.
Existing Federal AI-Related Laws
While no comprehensive AI law exists, several federal laws affect AI deployment:
Civil Rights Act (Title VII): Prohibits employment discrimination, including via AI
Fair Credit Reporting Act (FCRA): Governs AI used in credit and background checks
Federal agencies have issued AI guidance within their regulatory domains:
EEOC: Guidance on AI in employment decisions (May 2023)
FTC: Enforcement actions against deceptive AI practices
CFPB: Statements on AI in consumer financial services
FDA: Guidance on AI/ML medical devices
HHS OCR: AI guidance for HIPAA covered entities
NIST AI Risk Management Framework
The NIST AI RMF, released January 2023, provides a voluntary framework that multiple state laws reference. Colorado’s 2024 AI Act once offered a rebuttable-presumption safe harbor for following NIST AI RMF or ISO/IEC 42001, but SB 26-189 removed it and provided no replacement; the frameworks remain sound governance practice rather than a codified legal defense in Colorado. NIST 1.1 has not yet been released; through 2026 NIST is publishing addenda and profiles, including the Generative AI Profile (NIST AI 600-1, July 2024) and an AI RMF Profile on Trustworthy AI in Critical Infrastructure (concept note released April 7, 2026).
Multi-State Compliance Strategy
Organizations operating across multiple states need a strategic approach to managing divergent requirements:
Highest Common Denominator Approach
Rather than maintaining separate compliance programs for each state, implement controls satisfying the strictest applicable requirements:
GLACIS Framework
Multi-State AI Compliance
1
Adopt NIST AI RMF
Implement NIST AI Risk Management Framework as baseline. It maps to most state requirements and remains sound governance practice — though, following SB 26-189, it is no longer a codified safe harbor in Colorado. Document implementation across all four functions: Govern, Map, Measure, Manage.
2
Implement Comprehensive Impact Assessments
Create impact assessment templates that satisfy California CPRA, NYC LL144, and pending state requirements. (Colorado’s SB 26-189 no longer mandates impact assessments, but the same artifacts still support its disclosure duties.) Include bias testing, discrimination risk analysis, and consumer rights documentation.
3
Build Unified Consumer Rights Infrastructure
Implement consumer-facing capabilities: opt-out mechanisms, explanation rights, data correction, appeal processes with human review. Design once, deploy across all states.
4
Document for Multiple Regulators
Maintain documentation that can be adapted for any state regulator: risk management policies, bias testing results, training records, incident response procedures. Use standardized formats (model cards, dataset cards).
5
Monitor Regulatory Evolution
Establish processes to track new state legislation, regulatory guidance, and enforcement actions. Update compliance programs proactively rather than reactively. Subscribe to AG office updates and industry associations.
Sector-Specific Considerations
Certain industries face additional state-specific requirements:
Healthcare AI
HIPAA compliance remains primary federal requirement
State health privacy laws may impose additional AI restrictions
Insurance AI regulations vary significantly by state
Telehealth AI may trigger multiple state licensing requirements
Employment AI
NYC LL144 sets high bar for bias auditing
Illinois AIVIA requires video interview AI disclosure
Colorado SB 26-189 treats employment as a consequential-decision domain for covered ADMT
EEOC guidance applies nationally to Title VII compliance
Financial Services AI
FCRA and ECOA provide federal baseline
State fair lending laws may be more restrictive
Insurance AI regulations are state-by-state
Model risk management (SR 11-7) applies to banks
Frequently asked questions
Which US states have AI laws?
As of August 2026, Texas HB 149 (TRAIGA) is in force (effective January 1, 2026) and California’s CPPA ADMT regulations are in force (effective January 1, 2026, with significant-decision obligations phasing in 2027). Colorado repealed and replaced its 2024 AI Act with SB 26-189 (Automated Decision-Making Technology), signed May 14, 2026, whose substantive obligations commence January 1, 2027. California has additional AI-related provisions in CCPA/CPRA. Illinois has BIPA (biometrics) and pending AI-specific bills. Connecticut, Virginia, and other states have privacy laws with AI provisions. Over 30 states have introduced AI-related legislation.
What is the Colorado AI Act?
Colorado’s 2024 AI Act (SB 24-205) was repealed and replaced before it ever took effect by SB 26-189 (Automated Decision-Making Technology), signed by Governor Polis on May 14, 2026. SB 26-189 establishes a narrower transparency and disclosure regime for covered automated decision-making technology (ADMT) used to materially influence a consequential decision in seven domains: education, employment, housing, financial or lending services, insurance, health-care services, and essential government services. Developers must supply documentation to deployers; deployers owe pre-use notice, post-adverse-outcome disclosure within 30 days, data correction, and meaningful human review. Substantive obligations commence January 1, 2027. The earlier reasonable-care duty against algorithmic discrimination, impact assessments, and the NIST/ISO safe harbor are no longer part of Colorado law.
Does California have an AI law?
California has multiple AI-related regulations: CCPA/CPRA includes profiling opt-out rights and automated decision-making disclosure requirements. The CPPA’s Automated Decision-Making Technology (ADMT) regulations took effect January 1, 2026, with significant-decision obligations phasing in on January 1, 2027. California continues to consider comprehensive AI legislation, and various sector-specific AI bills are also in progress addressing employment, healthcare, and consumer protection.
How do state AI laws interact with federal law?
Currently, there is no comprehensive federal AI law in the US. State AI laws fill this gap but create a patchwork of requirements. Federal sector-specific regulations (HIPAA, FCRA, ECOA) still apply. Some state laws explicitly defer to federal frameworks like NIST AI RMF. Organizations operating nationally must comply with the strictest applicable state requirements.
What are the penalties for violating state AI laws?
Penalties vary by state. Colorado SB 26-189: up to $20,000 per violation under the Colorado Consumer Protection Act, enforced by the Attorney General with no private right of action, and a 60-day cure right that sunsets January 1, 2030. California CCPA: $2,500–$7,500 per violation. Illinois BIPA: $1,000–$5,000 per violation with a private right of action. Texas TRAIGA: civil penalties up to $200,000 per violation. Some states allow class action lawsuits while others limit enforcement to state attorneys general.
Which state has the strictest AI law?
Texas HB 149 is among the broadest enacted state AI laws. Colorado’s new SB 26-189 (which repealed and replaced the 2024 AI Act) is comparatively light — a transparency and disclosure regime for covered ADMT rather than a reasonable-care duty. Illinois BIPA remains the strictest for biometric AI due to its private right of action and significant damages. For employment AI, NYC Local Law 144 sets rigorous bias audit requirements. California’s ADMT regulations, now in force since January 1, 2026, add a substantial automated decision-making layer on top of CCPA/CPRA.
Do state AI laws apply to companies headquartered elsewhere?
Yes. State AI laws typically apply based on where consumers are located, not where companies are headquartered. If you serve Colorado residents, make decisions affecting Illinois employees, or deploy AI impacting NYC job candidates, you must comply with those jurisdictions’ laws regardless of your company’s location.
Will federal AI law preempt state laws?
Uncertain. If comprehensive federal AI legislation passes, it may or may not preempt state laws depending on the law’s language. Historically, federal privacy laws (like HIPAA and FCRA) have included limited preemption, allowing states to enact more protective requirements. Current state AI laws generally don’t conflict with federal requirements—they fill gaps in federal coverage.
How do I know which state laws apply to my AI system?
Consider: (1) Where are the people affected by your AI decisions located? (2) What type of AI application is it (employment, healthcare, credit, etc.)? (3) What data does it process (biometric, personal information)? (4) Who deploys the system (government, private sector)? Most organizations operating nationally should assume the strictest applicable requirements apply.
What is the difference between a developer and deployer under state AI laws?
Developers create or substantially modify AI systems (model providers, algorithm developers). Deployers use AI systems to make decisions affecting consumers (employers using hiring AI, lenders using credit scoring). An organization can be both if they build and use their own AI. Each role has distinct compliance obligations under laws like Colorado’s SB 26-189 ADMT regime, which assigns developers documentation duties and deployers notice, disclosure, correction, and human-review duties.
Do small businesses need to comply with state AI laws?
It depends on the law. Some states (like California and Virginia) have revenue or data volume thresholds. Colorado’s SB 26-189 applies to any developer or deployer of covered ADMT doing business in the state, with no size-based exemption (the old "fewer than 50 employees" carve-out is gone). NYC LL144 applies to any employer using AEDTs in NYC hiring. Illinois BIPA has no size exemption. Check specific law thresholds, but assume requirements apply if you’re using covered automated decision-making technology.
Key takeaways
Colorado reset: The 2024 AI Act was repealed and replaced by SB 26-189, an ADMT transparency regime with compliance from January 1, 2027 — no more reasonable-care duty
Patchwork is growing: 30+ states have AI bills; major states have enacted targeted laws
NIST AI RMF stays a strong baseline: still sound governance practice, though Colorado’s SB 26-189 no longer codifies it as a safe harbor
Illinois BIPA is highest risk: Private right of action creates significant litigation exposure
National companies need unified approach: Implement highest common denominator controls
More regulation coming: California ADMT significant-decision phase in January 2027, healthcare AI bills, and new state laws through 2026 and 2027
References
[F1] White House, “Eliminating State Law Obstruction of National AI Policy” (Dec 11, 2025) — whitehouse.gov; Paul Hastings client alert (Dec 2025); Gibson Dunn analysis (Jan 2026).
[F2] California Privacy Protection Agency, “California Finalizes Regulations to Strengthen Consumers’ Privacy” (Sept 23, 2025) — cppa.ca.gov; Skadden, Wiley, White & Case briefs (Sept–Oct 2025).
[F3] Office of Governor Newsom, SB 53 signing statement (Sept 29, 2025) — gov.ca.gov; Future of Privacy Forum “California’s SB 53: The First Frontier AI Law, Explained”; Brookings (2025).
[F5] Washington House Democrats, HB 1170 release (Feb 16, 2026); Cooley client alert (Apr 6, 2026); Mayer Brown “Oregon and Washington Join California in Enacting Companion Chatbot Laws” (Apr 2026).
[F6] NY State Comptroller, “Enforcement of Local Law 144 — Automated Employment Decision Tools” (Dec 2, 2025) — osc.ny.gov; DLA Piper GENIE (Jan 2026).
Multi-state AI compliance
Ready to make the receipts? See what GLACIS can attest in 5 minutes.
Our evidence pack demonstrates compliance across multiple state frameworks — Colorado AI Act, California ADMT, NIST AI RMF, ISO/IEC 42001 — with the cryptographic logs an AG would expect. One investment, multi-jurisdictional coverage.