GLACIS·US state AI laws·Tracker·Updated August 2026

The US state AI laws tracker.

A US state AI law tracker is only worth the date on it, so this one leads with a change log and a single effective-date calendar. Where every comprehensive state AI statute now stands: Colorado repealed its 2024 AI Act and replaced it with SB 26-189’s ADMT transparency regime (compliance from January 1, 2027), California’s ADMT regulations live with a phased compliance cascade through 2030, Texas TRAIGA in force, New York’s RAISE Act finalised, and the Trump administration’s December 2025 preemption executive order pressing on all of it, though no federal preemption has yet been enacted. Every claim below carries the citation an attorney general would ask for.

By Joe Braidwood, CEO GLACIS·32 min read·Published 20 December 2025·Updated 26 August 2026

Jan 2026
CA AB 2013, SB 53, ADMT (risk-assessments), TX TRAIGA all in force
May 14 2026
Colorado signs SB 26-189, repealing & replacing the 2024 AI Act
Apr 1 2027
CA ADMT pre-use notices begin for significant decisions
Jan 1 2027
CO SB 26-189 compliance; NY RAISE Act, WA HB 2225, OR SB 1546 effective
Joe Braidwood
Joe Braidwood
CEO, GLACIS
35 min read

Executive summary

The United States still lacks comprehensive federal AI legislation; what it has is a growing patchwork of state laws operating against the backdrop of an active federal preemption push. As of August 26, 2026, Texas HB 149 (TRAIGA) is live (effective January 1, 2026), California’s CPPA ADMT regulations are in force with significant-decision obligations beginning January 1, 2027, California’s SB 53 Frontier AI Transparency Act applies to large frontier developers, and Colorado repealed and replaced its 2024 AI Act (SB 24-205) with SB 26-189 (Automated Decision-Making Technology), signed May 14, 2026, whose substantive obligations commence January 1, 2027. New York’s RAISE Act is signed (chapter amendment March 27, 2026) and effective January 1, 2027.

State AI laws generally address three categories: (1) algorithmic discrimination in high-stakes decisions, (2) automated decision-making transparency and consumer rights, and (3) sector-specific AI use in employment, healthcare, insurance, and financial services. Many laws work through existing consumer protection or privacy frameworks rather than creating entirely new regulatory structures.

The federal counter-current. President Trump’s December 11, 2025 executive order “Eliminating State Law Obstruction of National AI Policy” stood up a DOJ AI Litigation Task Force to challenge state AI laws. It applies pressure through litigation and funding levers, but no federal statute or court has actually preempted or paused any state AI law. State requirements remain valid and enforceable. A bipartisan coalition of 36 state attorneys general has opposed broad preemption. Until the courts and Congress sort this out, organizations operating nationally should still adopt a “highest common denominator” posture aligned to NIST AI RMF and ISO/IEC 42001. Both remain sound practice for AI governance, even though Colorado’s SB 26-189 no longer codifies them as a legal safe harbor.

Q1 → Q2 2026 update brief

Colorado repealed and replaced its AI Act: SB 26-189 (Automated Decision-Making Technology) was signed May 14, 2026, repealing and reenacting the 2024 SB 24-205 before it took effect. Substantive obligations commence January 1, 2027. The old June 30, 2026 trigger never went live.[F1]

Trump executive order on state AI law preemption signed December 11, 2025; a DOJ AI Litigation Task Force was stood up to challenge state AI laws. As of August 26, 2026 no federal statute or court has preempted or paused any state AI law.[F1]

California CPPA ADMT regulations approved by OAL on September 22, 2025 with the phasing finalised: risk-assessment compliance from January 1, 2026, applicable ADMT significant-decision requirements from January 1, 2027, first risk-assessment attestation and summary due April 1, 2028, and cybersecurity-audit certifications cascading from 2028 to 2030.[F2]

California SB 53 (Frontier AI Transparency Act) took effect January 1, 2026. It applies through statutory developer and training-compute thresholds and includes public framework disclosures and critical-safety-incident reporting. It does not require a developer to adopt NIST AI RMF or ISO/IEC 42001 merely because those frameworks may inform a disclosure; check the current code for scope, deadlines, and enforcement.[F3]

New York RAISE Act chapter amendment signed March 27, 2026; effective January 1, 2027 with DFS oversight and AG enforcement to $1M/$3M.[F4]

Washington enacted three AI laws in March 2026: HB 1170 (AI content disclosure, eff. February 1, 2027), HB 2225 (companion chatbots, eff. January 1, 2027), and SSB 5886 (digital-likeness rights, eff. June 11, 2026). Oregon followed with SB 1546 (companion chatbots).[F5]

NYC Local Law 144 enforcement review: the New York State Comptroller’s December 2, 2025 audit criticized DCWP implementation and made recommendations. Verify DCWP’s current enforcement practices directly rather than treating a planned response as a completed operational change.[F6]

1
Comprehensive AI Law Enacted
30+
States with AI Bills
Jan 2027
Colorado SB 26-189 Compliance
Varies
Penalty by Law and Violation

In This Guide

What changed in 2026

Every entry below is dated, and each links to the section of this tracker that carries the detail. The single most consequential change of the year is that the state everyone cited as the model for AI regulation repealed its own law before it took effect.

Date Change Status now
14 May 2026 Colorado signed SB 26-189, repealing and replacing the 2024 Colorado AI Act before it ever took effect. The reasonable-care and impact-assessment model is gone, replaced by a narrower transparency and disclosure regime for covered ADMT. Enacted; obligations commence 1 Jan 2027
27 Mar 2026 New York signed the final chapter amendment to the RAISE Act, originally signed 19 Dec 2025. Second US state frontier-model law after California SB 53. Enacted; takes effect 1 Jan 2027
25 Nov 2025 A bipartisan coalition of 36 state attorneys general publicly opposed broad federal preemption of state AI law. Unresolved; no federal statute or court has preempted state AI law
1 Jan 2026 Texas HB 149 (TRAIGA) took effect, with Attorney General enforcement and civil penalties up to $200,000 per violation. In force
1 Jan 2026 The California CPPA ADMT, risk-assessment and cybersecurity-audit regulations took effect, with provision-specific compliance dates. In force; ADMT-specific business compliance from 1 Jan 2027, with separate later filing dates for specified risk assessments and audits
11 Dec 2025 Executive order “Eliminating State Law Obstruction of National AI Policy” created a DOJ AI Litigation Task Force and directed Commerce, to the maximum extent allowed by law, to withhold remaining non-deployment BEAD funds from states identified under the order. Active political contest; no preemption enacted

Two patterns are worth naming because they change how a multi-state program should be planned. First, the direction of travel is no longer one-way: Colorado demonstrated that a comprehensive state AI law can be repealed and narrowed before it binds anyone, so building a compliance program against a single state statute now carries repeal risk as well as deadline risk. Second, the center of gravity has moved from broad algorithmic-discrimination statutes toward two narrower shapes: transparency and disclosure duties for automated decisions, and frontier-model safety obligations aimed at a handful of large developers. An organization that is neither a frontier developer nor a user of ADMT in significant decisions is touched by far less of this than the headlines suggest.

Effective-date calendar

These are the dates that bind, in order. Anything already past is an obligation running now; anything ahead is the planning horizon. Each entry is covered in more detail in the state section it belongs to.

Effective Law Applies to
1 Jan 2020 Illinois AI Video Interview Act Employers using AI to analyze video interviews
1 Jan 2023 California CPRA amendments to the CCPA Profiling opt-out and automated decision disclosure
5 Jul 2023 NYC Local Law 144 Automated employment decision tools used in NYC hiring and promotion
1 Oct 2024 Montana Consumer Data Privacy Act Profiling opt-out and data protection assessments
1 Jan 2026 Texas HB 149 (TRAIGA) Prohibited AI uses and consumer-facing AI disclosure
1 Jan 2026 California CPPA ADMT regulations, baseline duties Businesses using automated decision-making technology
1 Jan 2027 Colorado SB 26-189 Covered ADMT; AG clarifying rules due the same date
1 Jan 2027 California ADMT significant-decision duties ADMT used in significant decisions
1 Jan 2027 New York RAISE Act Large frontier developers above compute and revenue thresholds
1 Apr 2028 California first ADMT risk-assessment attestation Businesses filing with the CPPA; cybersecurity audit certifications cascade from 2028 to 2030
1 Jan 2030 Colorado 60-day cure right sunsets Entities relying on cure to avoid SB 26-189 enforcement

The US AI Regulatory Landscape

Unlike the European Union, which enacted a comprehensive AI Act covering all member states, the United States has taken a fragmented approach to AI regulation. In the absence of federal legislation, individual states have begun enacting their own AI laws, and organizations working across state lines now face a different set of obligations in each one.

Why States Are Acting

The pressure comes from four directions at once:

Types of State AI Laws

Most of what has actually been enacted sorts into a few recognizable shapes. The table below groups them, with the states that have moved furthest in each:

Categories of State AI Legislation

Category Focus Example States
Comprehensive AI Laws Broad regulation of high-risk AI systems across multiple domains Colorado (enacted), Texas (enacted, HB 149), California (sector-specific enacted rules)
Employment AI AI in hiring, promotion, termination decisions Illinois (AIPLA), New York (Local Law 144), Maryland
Biometric AI Facial recognition, voice recognition, biometric data Illinois (BIPA), Texas, Washington
Privacy + AI Automated decision-making provisions in privacy laws California (CCPA/CPRA), Virginia (VCDPA), Connecticut (CTDPA)
Healthcare AI AI in clinical decisions, insurance, care management California (pending), New York (proposed)
Government AI AI use by state and local government agencies California, Washington, multiple states

Colorado: From the 2024 AI Act to the SB 26-189 ADMT Regime

Colorado was the first state to enact a comprehensive AI law, and the first to walk it back. The 2024 Colorado AI Act (SB 24-205) was repealed and replaced before it ever took effect by SB 26-189, titled “Automated Decision-Making Technology,” which Governor Polis signed on May 14, 2026. The new law trades the old reasonable-care-and-impact-assessment model for a narrower transparency and disclosure regime built around “covered automated decision-making technology (ADMT).” Substantive obligations commence January 1, 2027, by which date the Attorney General must also adopt clarifying rules.

Enacted SB 26-189, compliance January 1, 2027

Colorado SB 26-189 Key Points

  • Scope: Covered ADMT used to materially influence a consequential decision in education, employment, housing, financial or lending services, insurance, health-care services, and essential government services
  • Trigger: “Materially influence” means a non-de-minimis factor in the outcome; incidental or clerical uses are excluded
  • Model: Transparency and disclosure. The reasonable-care duty, impact assessments, and the NIST/ISO safe harbor are not part of the new law
  • Penalties: Up to $20,000 per violation under the Colorado Consumer Protection Act; a 60-day cure right that sunsets January 1, 2030
  • Enforcement: Colorado Attorney General only (no private right of action); not yet operative, since obligations begin January 1, 2027

Developer Requirements

Under SB 26-189, developers of covered ADMT must provide each deployer documentation that includes:

Records are retained for at least three years. No disclosure of proprietary source code, model weights, or trade secrets is required.

Deployer Requirements

Deployers of covered ADMT owe four operational duties, with at least three-year recordkeeping:

The earlier risk-management-program requirement, annual impact assessments, the 90-day Attorney General notification on discovering discrimination, and the standalone “you are interacting with an AI” chatbot disclosure did not survive the rewrite. Discrimination is now addressed under existing Colorado anti-discrimination law, and there is no longer a size-based small-business exemption.

For the full treatment, including the developer and deployer duties in detail, see our Colorado AI Act Complete Compliance Guide.

California: The Privacy Leader Expands to AI

California has no comprehensive AI law equivalent to Colorado’s. What it has instead is a deep stack of privacy rules that keep reaching further into AI, built up over the decade in which the state led the country on data regulation. Several of those rules now land on the same deployment at once:

California Consumer Privacy Act (CCPA/CPRA)

Enacted Effective January 1, 2023 (CPRA amendments)

CCPA/CPRA AI Provisions

  • Profiling opt-out: Consumers can opt out of automated decision-making
  • Access rights: Consumers can access information about automated decisions
  • Risk assessments: Required for processing posing significant risk (including profiling)
  • Penalties: $2,500-$7,500 per intentional violation

California Automated Decision-Making Technology (ADMT) Regulations

The California Privacy Protection Agency (CPPA) finalized its ADMT, risk-assessment, and cybersecurity-audit regulations, which took effect January 1, 2026. Businesses using ADMT for significant decisions must comply with the applicable ADMT requirements beginning January 1, 2027; later April deadlines apply to specified risk-assessment submissions and cybersecurity-audit certifications. Key provisions:

The regulations are in force, but their compliance dates differ. Significant-decision ADMT obligations begin January 1, 2027; specified risk-assessment submissions and cybersecurity-audit certifications follow the regulation’s separate phase-in dates. Confirm the schedule and whether the business and processing are in scope.

California enacted and historical AI bills

Status matters: a bill that passed the legislature is not necessarily law. These 2024 examples should not be grouped together as pending proposals:

Illinois: Biometrics and Employment AI Pioneer

Illinois never set out to regulate AI as such. It regulated biometric data in 2008 and AI-analyzed video interviews from 2020, well before the current wave of bills, and both statutes now sit squarely in the path of ordinary AI deployments:

Illinois Biometric Information Privacy Act (BIPA)

Enacted Effective 2008

BIPA Requirements

  • Scope: Fingerprints, face geometry, iris scans, voice prints, hand geometry
  • Notice & consent: Written consent required before collection
  • Private right of action: Individuals can sue directly
  • Penalties: $1,000 per negligent violation; $5,000 per intentional violation

BIPA has generated significant litigation involving facial-recognition and other biometric technologies. It imposes notice, written-release, retention and destruction, disclosure, and security duties on covered biometric identifiers and information; whether a use is lawful depends on the facts and statutory exceptions.

Illinois Artificial Intelligence Video Interview Act (AIVIA)

Enacted Effective January 1, 2020

AIVIA Requirements

Employers using AI to analyze video interviews must: (1) notify applicants that AI will be used; (2) explain how the AI works and what characteristics it evaluates; (3) obtain applicant consent before the interview; (4) limit who can view the video; (5) delete videos upon applicant request.

Illinois Employment AI Legislation

Three further measures build on that base, and each of them widens the disclosure the employer owes:

Texas: TRAIGA Now in Force

Texas, with its large technology sector and business-friendly reputation, has moved from a measured stance to enacting one of the most consequential state AI laws. Texas HB 149, the Texas Responsible Artificial Intelligence Governance Act (TRAIGA), took effect January 1, 2026 and is now live. It prohibits certain AI uses (including intentional discrimination and unlawful manipulation), establishes disclosure obligations for consumer-facing AI, and creates Attorney General enforcement with civil penalties up to $200,000 per violation.

Texas HB 149 (TRAIGA)

Enacted Effective January 1, 2026

Texas Responsible AI Governance Act

  • Scope: Developers and deployers of AI systems doing business in Texas, producing AI products or services used by Texas residents, or whose AI affects Texas residents
  • Prohibited uses: AI intentionally developed or deployed for unlawful discrimination, unlawful behavioral manipulation, social scoring by government, or generation of unlawful visual content
  • Government disclosure: State agencies interacting with consumers via AI must disclose the interaction
  • Enforcement: Attorney General exclusive; civil penalties up to $200,000 per prohibited use and $40,000 per day for continuing violations; 60-day cure period
  • Regulatory sandbox: Establishes a sandbox program administered by the Texas Department of Information Resources for testing innovative AI systems

Texas Capture or Use of Biometric Identifier Act (CUBI)

Enacted Effective 2009

Texas CUBI

Requires notice and consent before capturing biometric identifiers for commercial purposes. Unlike Illinois BIPA, Texas does not provide a private right of action; enforcement is through the Attorney General. Penalties up to $25,000 per violation.

Texas Data Privacy and Security Act (TDPSA)

Effective July 1, 2024, the TDPSA includes provisions affecting AI:

Texas AI Advisory Council

Texas established an AI Advisory Council to study AI issues and recommend legislation. Areas under consideration include:

New York: Local and State AI Regulation

New York regulates AI at two levels that do not line up. The city set rules for hiring tools that have been live since 2023. The state set rules for frontier model developers that begin in 2027. The two reach very different populations, and a company can easily be caught by one and untouched by the other:

New York City Local Law 144 (Automated Employment Decision Tools)

Enacted Effective July 5, 2023

NYC Local Law 144

  • Scope: Automated employment decision tools (AEDTs) used in NYC hiring/promotion
  • Bias audit: Annual independent audit for disparate impact by race, ethnicity, sex
  • Publication: Audit summary must be publicly posted
  • Notice: Candidates must be notified at least 10 days before AEDT use
  • Penalties: $500 first violation; $500-$1,500 subsequent violations per day

Enforcement review. The New York State Comptroller’s December 2, 2025 audit criticized NYC DCWP’s implementation of Local Law 144 and reported problems with complaint routing. The audit and agency response do not, by themselves, establish the volume or likelihood of future investigations; check current DCWP materials for enforcement practice.

New York RAISE Act (frontier AI)

The Responsible AI Safety and Education Act (S6953B / A6453B) was originally signed by Governor Hochul on December 19, 2025; the final chapter amendment was signed on March 27, 2026. It is the second US state frontier-model law (after California SB 53) and takes effect January 1, 2027.

Other New York AI legislation

Other State AI Laws and Pending Legislation

The five states above take most of the coverage. The rest of the country has not been idle. Profiling opt-outs sit inside general privacy statutes, several states run separate biometric rules, and a growing number limit what government agencies may deploy on their own account.

States with Privacy Laws Including AI Provisions

Virginia (VCDPA)

Enacted

Effective January 1, 2023

  • • Profiling opt-out rights
  • • Data protection assessments for profiling
  • • No private right of action

Connecticut (CTDPA)

Enacted

Effective July 1, 2023

  • • Profiling opt-out for legal/significant decisions
  • • Data protection assessments required
  • • Mandatory 60-day cure period ended Dec. 31, 2024; Attorney General has discretion afterward

Utah (UCPA)

Enacted

Effective December 31, 2023

  • • Consumer access to profiling information
  • • More limited than other state laws
  • • AG enforcement only

Montana (MCDPA)

Enacted

Effective October 1, 2024

  • • Profiling opt-out rights
  • • Data protection assessments
  • • No cure period in the current enforcement section; the former provision was removed effective Oct. 1, 2025

Oregon (OCPA)

Enacted

Effective July 1, 2024

  • • Profiling opt-out for automated decisions
  • • Data protection assessments
  • • General cure period ended Dec. 31, 2025; a narrow broadcaster rule was repealed July 1, 2026

Delaware (DPDPA)

Enacted

Effective January 1, 2025

  • • Profiling opt-out rights
  • • No revenue threshold
  • • Broad applicability

States with Biometric/Facial Recognition Laws

State Law Private Action Key Requirements
Illinois BIPA Yes Most stringent; written consent required
Texas CUBI No Notice and consent; AG enforcement
Washington HB 1493 No Notice required; enrollment consent
Arkansas PIPA No Notice and consent requirements
Maryland SB 169 No Facial recognition restrictions in employment

States with Government AI Restrictions

The list here is short, and most of it is about facial recognition rather than AI in general:

State AI Law Comparison Matrix

Read across the rows rather than down the columns. The same requirement carries different weight in each state, and “None” means the state has no law on that specific point, not that the activity is unregulated by anything else.

Requirement Colorado California Illinois New York Texas
Comprehensive AI Law ✓ Enacted Partial Partial ✓ RAISE Act ✓ HB 149
Employment AI CPRA ✓ AIVIA ✓ LL144 None
Biometric AI None CCPA ✓ BIPA Pending ✓ CUBI
Impact Assessments None (repealed) ✓ CPRA None ✓ LL144 ✓ TDPSA
Consumer Opt-Out Correction / human review Limited None
Private Right of Action No Limited Yes (BIPA) No No
Safe Harbor (Frameworks) None (repealed) None None None None

Federal context and the preemption push

Congress still has not passed a general AI law. The executive branch moved anyway in late 2025, and that move now shapes how much of the state patchwork survives and how a national program should be planned.

The December 2025 executive order

On December 11, 2025, President Trump signed “Eliminating State Law Obstruction of National Artificial Intelligence Policy.” The order:

A bipartisan coalition of 36 state attorneys general publicly opposed broad federal preemption on 25 November 2025; the Senate previously voted 99 to 1 to strip a similar preemption provision from the budget reconciliation bill, and a rumored FY2026 NDAA moratorium was omitted from the final bill text. No federal statute or court has categorically preempted or paused state AI law; claim-by-claim conflicts and the political contest remain unresolved as of August 26, 2026.

Senate AI Working Group and proposed federal bills

Senator Marsha Blackburn’s TRUMP AMERICA AI Act would codify the executive order into statute and create comprehensive federal AI governance, but remains in committee. The Bipartisan Senate AI Working Group reports continue to be a roadmap document rather than enacted law.

Attorney General Alliance bipartisan AI Task Force

On November 13, 2025, Utah Attorney General Derek Brown and North Carolina Attorney General Jeff Jackson announced a bipartisan AI Task Force through the Attorney General Alliance. The public announcement describes a standing forum to identify issues, share expertise, and develop safeguards; it should not be described as a NAAG body or as coordinating investigations unless a current primary source says so. North Carolina DOJ announcement.

Why no comprehensive federal AI law yet

Bills exist, and some of them have bipartisan sponsors. They stall on four things:

Existing Federal AI-Related Laws

While no comprehensive AI law exists, several federal laws affect AI deployment:

Federal Agency Guidance

Several agencies have set out how they read AI within the rules they already enforce:

NIST AI Risk Management Framework

The NIST AI RMF, released January 2023, provides a voluntary framework that multiple state laws reference. Colorado’s 2024 AI Act once offered a rebuttable-presumption safe harbor for following NIST AI RMF or ISO/IEC 42001, but SB 26-189 removed it and provided no replacement; the frameworks remain sound governance practice rather than a codified legal defense in Colorado. NIST 1.1 has not yet been released; through 2026 NIST is publishing addenda and profiles, including the Generative AI Profile (NIST AI 600-1, July 2024) and an AI RMF Profile on Trustworthy AI in Critical Infrastructure (concept note released April 7, 2026).

Multi-State Compliance Strategy

The failure mode here is familiar. A control built for one state gets reused in another, and only later does someone notice that the second state asked for something different. The rest of this section is about avoiding that.

Requirement-by-requirement approach

Shared controls can reduce duplicate work, but the “strictest” rule in one state does not automatically satisfy a differently framed duty elsewhere. Build a matrix by system, role, jurisdiction, decision type, effective date, and obligation, then reuse controls only where the legal and operational requirements actually overlap.

GLACIS logoGLACIS
Planning pattern

Multi-state AI requirement matrix

1

Organize voluntary risk work

Use NIST AI RMF or another suitable voluntary framework to organize risk work where useful. A framework mapping is not a finding that a state-law duty is satisfied, and SB 26-189 does not retain the former Colorado NIST/ISO safe harbor.

2

Separate assessment and audit duties

California privacy risk assessments, New York City Local Law 144 bias audits, and other assessment duties have different triggers, content, actors, timing, and publication rules. Reuse validated inputs where appropriate, but do not treat one template as satisfying all of them. SB 26-189 no longer mandates the prior Colorado impact assessment.

3

Build rights workflows with jurisdiction flags

Where applicable, support notice, opt-out, correction, explanation or disclosure, appeal, and human-review workflows. Route each request by the actual law, role, decision, consumer, deadline, and exception instead of assuming one national workflow fits every state.

4

Document for Multiple Regulators

Maintain reusable policies, testing results, training records, incident procedures, model or dataset documentation, and a jurisdiction-specific delta log. Adapt the package to the regulator and matter rather than presenting a generic bundle as universally sufficient.

5

Monitor Regulatory Evolution

Establish processes to track new state legislation, regulatory guidance, and enforcement actions. Update compliance programs proactively rather than reactively. Subscribe to AG office updates and industry associations.

Sector-Specific Considerations

Three sectors carry a second layer on top of everything above, and in each case the federal baseline arrived first:

Healthcare AI

Employment AI

Financial Services AI

Frequently asked questions

Which US states have AI laws?

As of August 2026, Texas HB 149 (TRAIGA) is in force (effective January 1, 2026) and California’s CPPA ADMT regulations are in force (effective January 1, 2026, with significant-decision obligations phasing in 2027). Colorado repealed and replaced its 2024 AI Act with SB 26-189 (Automated Decision-Making Technology), signed May 14, 2026, whose substantive obligations commence January 1, 2027. California has additional AI-related provisions in CCPA/CPRA. Illinois has BIPA (biometrics) and pending AI-specific bills. Connecticut, Virginia, and other states have privacy laws with AI provisions. Over 30 states have introduced AI-related legislation.

What is the Colorado AI Act?

Colorado’s 2024 AI Act (SB 24-205) was repealed and replaced before it ever took effect by SB 26-189 (Automated Decision-Making Technology), signed by Governor Polis on May 14, 2026. SB 26-189 establishes a narrower transparency and disclosure regime for covered automated decision-making technology (ADMT) used to materially influence a consequential decision in seven domains: education, employment, housing, financial or lending services, insurance, health-care services, and essential government services. Developers must supply documentation to deployers; deployers owe pre-use notice, post-adverse-outcome disclosure within 30 days, data correction, and meaningful human review. Substantive obligations commence January 1, 2027. The earlier reasonable-care duty against algorithmic discrimination, impact assessments, and the NIST/ISO safe harbor are no longer part of Colorado law.

Does California have an AI law?

California has multiple AI-related regulations: CCPA/CPRA includes profiling opt-out rights and automated decision-making disclosure requirements. The CPPA’s Automated Decision-Making Technology (ADMT) regulations took effect January 1, 2026, with significant-decision obligations phasing in on January 1, 2027. California continues to consider comprehensive AI legislation, and various sector-specific AI bills are also in progress addressing employment, healthcare, and consumer protection.

How do state AI laws interact with federal law?

Currently, there is no comprehensive federal AI law in the US. State AI laws create a patchwork alongside federal sector-specific requirements such as HIPAA, FCRA, and ECOA. Some state laws reference federal frameworks such as NIST AI RMF. Organizations operating nationally should identify and comply with each law that applies to the system, role, people, and jurisdiction at issue.

What are the penalties for violating state AI laws?

Penalties vary by state. Colorado SB 26-189: up to $20,000 per violation under the Colorado Consumer Protection Act, enforced by the Attorney General with no private right of action, and a 60-day cure right that sunsets January 1, 2030. California CCPA: $2,500 to $7,500 per violation. Illinois BIPA: $1,000 to $5,000 per violation with a private right of action. Texas TRAIGA: civil penalties up to $200,000 per violation. Some states allow class action lawsuits while others limit enforcement to state attorneys general.

Which state has the strictest AI law?

Texas HB 149 is among the broadest enacted state AI laws. Colorado’s new SB 26-189 (which repealed and replaced the 2024 AI Act) is comparatively light: a transparency and disclosure regime for covered ADMT rather than a reasonable-care duty. Illinois BIPA remains the strictest for biometric AI due to its private right of action and significant damages. For employment AI, NYC Local Law 144 sets rigorous bias audit requirements. California’s ADMT regulations, now in force since January 1, 2026, add a substantial automated decision-making layer on top of CCPA/CPRA.

Do state AI laws apply to companies headquartered elsewhere?

Potentially. Applicability depends on each law’s covered actors, territorial nexus, thresholds, activity, affected person, exemptions, and effective date. A company headquartered elsewhere may still be covered, but serving a resident or user does not by itself establish that every state AI law applies.

Will federal AI law preempt state laws?

Uncertain. If comprehensive federal AI legislation passes, it may or may not preempt state laws depending on the law’s language. Historically, federal privacy laws (like HIPAA and FCRA) have included limited preemption, allowing states to enact more protective requirements. Current state AI laws generally don’t conflict with federal requirements; they fill gaps in federal coverage.

How do I know which state laws apply to my AI system?

Consider: (1) Where are the people affected by your AI decisions located? (2) What type of AI application is it (employment, healthcare, credit, etc.)? (3) What data does it process (biometric, personal information)? (4) Who deploys the system (government, private sector)? Most organizations operating nationally should assume the strictest applicable requirements apply.

What is the difference between a developer and deployer under state AI laws?

Developers create or substantially modify AI systems (model providers, algorithm developers). Deployers use AI systems to make decisions affecting consumers (employers using hiring AI, lenders using credit scoring). An organization can be both if they build and use their own AI. Each role has distinct compliance obligations under laws like Colorado’s SB 26-189 ADMT regime, which assigns developers documentation duties and deployers notice, disclosure, correction, and human-review duties.

Do small businesses need to comply with state AI laws?

It depends on the law. Some states (like California and Virginia) have revenue or data volume thresholds. Colorado’s SB 26-189 applies to any developer or deployer of covered ADMT doing business in the state, with no size-based exemption (the old “fewer than 50 employees” carve-out is gone). NYC LL144 applies to any employer using AEDTs in NYC hiring. Illinois BIPA has no size exemption. Check specific law thresholds, but assume requirements apply if you’re using covered automated decision-making technology.

Key takeaways

  • Colorado reset: The 2024 AI Act was repealed and replaced by SB 26-189, an ADMT transparency regime with compliance from January 1, 2027, and the old reasonable-care duty is gone
  • Patchwork is growing: 30+ states have AI bills; major states have enacted targeted laws
  • NIST AI RMF stays a strong baseline: still sound governance practice, though Colorado’s SB 26-189 no longer codifies it as a safe harbor
  • Illinois BIPA is highest risk: Private right of action creates significant litigation exposure
  • National companies need one approach: build controls to the highest common denominator across the states you actually touch
  • More regulation coming: California ADMT significant-decision phase in January 2027, healthcare AI bills, and new state laws through 2026 and 2027

References

  1. [F1] White House, “Eliminating State Law Obstruction of National AI Policy” (Dec 11, 2025), whitehouse.gov; Paul Hastings client alert (Dec 2025); Gibson Dunn analysis (Jan 2026).
  2. [F2] California Privacy Protection Agency, “California Finalizes Regulations to Strengthen Consumers’ Privacy” (Sept 23, 2025), cppa.ca.gov; Skadden, Wiley, White & Case briefs (Sept and Oct 2025).
  3. [F3] Office of Governor Newsom, SB 53 signing statement (Sept 29, 2025), gov.ca.gov; Future of Privacy Forum “California’s SB 53: The First Frontier AI Law, Explained”; Brookings (2025).
  4. [F4] Office of Governor Hochul, RAISE Act chapter amendment release (Mar 27, 2026), governor.ny.gov; Wiley “New York Finalizes RAISE Act” (Mar 2026).
  5. [F5] Washington House Democrats, HB 1170 release (Feb 16, 2026); Washington State Legislature, SSB 5886 bill history; Cooley client alert (Apr 6, 2026); Mayer Brown “Oregon and Washington Join California in Enacting Companion Chatbot Laws” (Apr 2026).
  6. [F6] NY State Comptroller, “Enforcement of Local Law 144 — Automated Employment Decision Tools” (Dec 2, 2025), osc.ny.gov; DLA Piper GENIE (Jan 2026).
  7. [F7] Current privacy-law cure provisions checked Aug 26, 2026: Connecticut General Statutes § 42-525; Montana Code § 30-14-2817; and Oregon Revised Statutes § 646A.589 and 2025 chapter 417 notes.

Multi-state AI compliance

Supervision a regulator can review.

GLACIS can preserve signed records of what configured controls reported and map them to review questions from Colorado’s ADMT law, California’s ADMT regulations, NIST AI RMF, and ISO/IEC 42001. Mapping does not establish compliance, multi-jurisdictional coverage, or regulator acceptance.

Build the evidence pack

Related Guides