Essex Junction, VT802-335-2662dkoran@davidkoran.com
DK
David Koran& Associates
AI Governance / State AI Laws

State AI laws in 2026: what is in force, what is coming, and why the boundaries follow people rather than companies.

With no comprehensive federal statute, the operative AI law of the United States is a patchwork of state measures, enacted on different legal theories, effective on different dates, and revised while organizations are still reading them. This page is the maintained reference for that patchwork: what is in force today, what takes effect next, and how a system falls inside a state's reach. Last reviewed August 2026.

The Patchwork at a Glance

Where state AI law stands, mid 2026

  • Texas TRAIGA: the comprehensive statute in force since January 1, 2026
  • Colorado: 2024 AI Act repealed; successor transparency law effective 2027
  • California: SB 53 and AB 2013 in effect; ADMT regulations phasing in
  • Utah, Illinois, and New York City measures in force
  • New York RAISE Act signed, effective January 1, 2027
  • Federal preemption pursued by executive order; none enacted
The Landscape

A patchwork built on different theories, revised in real time.

In 2025, every US state introduced AI legislation for the first time, and the results diverge on the most basic design question: what the law should regulate. Texas built an intent-based statute targeting deliberate misuse. Colorado built an impact-based regime for high-risk systems, then repealed it in 2026 before it ever operated and replaced it with a narrower transparency law. California legislated at the frontier developer and training data layers. Illinois amended its civil rights statute. New York City regulates one tool category through bias audits. Overlaying all of it, a December 2025 federal executive order directed agencies to pursue preemption of state AI laws; litigation and legislative maneuvering continue, and no preemption has been enacted.

This page tracks the field at the level an executive needs: what binds now, what binds next, and how a system comes within a state's reach. It is reviewed quarterly, and its companion page covers Texas TRAIGA, the one comprehensive statute in force, in full depth.

In Force Today

The measures binding as of mid 2026.

JurisdictionInstrumentEffectiveWhat It Regulates
TexasTRAIGA (HB 149)January 1, 2026Intent-based prohibitions on AI deployed to harm, manipulate, or discriminate; AI-generated CSAM and nonconsensual deepfakes; government social scoring; state agency disclosure. Attorney General enforcement with a 60 day cure period. Substantial compliance with the NIST AI RMF recognized as a defense.
CaliforniaSB 53 and AB 2013January 1, 2026SB 53 imposes transparency and safety framework obligations on large frontier AI developers; AB 2013 requires generative AI training data disclosure. Separate CPPA automated decisionmaking regulations phase in from 2027.
IllinoisHB 3773January 1, 2026Amends the Illinois Human Rights Act to prohibit employer AI use that discriminates against protected classes, with employee notice requirements.
UtahAI Policy Act (SB 149, 2024)May 1, 2024Disclosure that a consumer is interacting with generative AI, on request generally and affirmatively in regulated occupations.
New York CityLocal Law 1442023Annual independent bias audits and candidate notice for automated employment decision tools used for New York City roles.

Beyond these, more than 38 states have enacted narrower AI measures, principally deepfake, nonconsensual intimate imagery, and election-related statutes. Those laws are real exposure for organizations generating or distributing synthetic media, but they regulate content categories rather than AI governance generally.

The Watch List

What takes effect next.

Four developments define the near horizon. Each one is a scheduled change to the table above, which is why this page carries a review date.

2027

Colorado SB 26-189

Colorado repealed its landmark 2024 AI Act in May 2026 and replaced it with an automated decisionmaking transparency regime whose substantive obligations begin January 1, 2027. Notably, the framework-based defense the original law contained did not survive into the successor.

2027

New York RAISE Act

New York's RAISE Act, aimed at large frontier AI developers, is signed with a chapter amendment finalized in March 2026 and takes effect January 1, 2027, adding a second state to the frontier developer regulation California began with SB 53.

2027 to 2030

California ADMT regulations

The California Privacy Protection Agency's automated decisionmaking technology regulations are in force with a phased compliance cascade, with significant-decision obligations beginning in 2027 and further phases following. Organizations processing California consumers' data through automated decisions inherit these on schedule.

Pending

Federal preemption

The December 2025 executive order pressing preemption of state AI laws continues to generate litigation, agency activity, and legislative proposals. Until preemption is actually enacted, the state patchwork remains the operative law, and planning against its disappearance is speculation rather than strategy.

Reading the churn correctly matters more than predicting it. Colorado enacting, amending, pausing, repealing, and replacing its statute inside two years is not evidence that state AI law is going away; it is evidence that governing to any single statute is building on sand, while the inventory, policy, and framework records underneath survive every revision.
The Boundary Problem

Reach follows the residents a system affects.

State AI statutes generally attach to the people a system touches rather than to the location of the company deploying it. An AI system does not need to be developed, hosted, or operated in a regulated state to fall within that state's reach: a hiring tool that screens an applicant living in Illinois, a chatbot that serves Texas consumers, an automated decision affecting a Colorado resident once SB 26-189 operates, or a job posting drawing New York City candidates places the system inside the corresponding regime, wherever the organization and its infrastructure sit. The crossing is silent. Nothing in a system's operation announces that it has begun processing residents of a state whose statute now applies; a remote hire, a new customer, or an expanded applicant pool carries the system across the boundary without any technology change.

The governance consequence is specific: the AI use inventory has to record not only what each system does but whose residents it can reach, because jurisdictional exposure is a property of the user population rather than the server location. An inventory that answers that question turns the patchwork from an unknowable liability into a mapped one.

The Approach That Holds

Framework-based governance against a moving patchwork.

Fifty parallel statutory analyses is not a compliance program a midsize organization can run, and the patchwork's own behavior points at the alternative. Texas wrote the NIST AI Risk Management Framework into its statute as a defense, the framework's crosswalks connect it to ISO/IEC 42001 and the EU AI Act, and the records a framework-aligned program produces, the inventory, the use policy and its acknowledgment logs, intended use documentation, and risk decisions, are the same records nearly every state instrument asks about in its own vocabulary. Statute-specific work still exists, the Illinois employer notices and the New York City bias audits are concrete obligations with their own mechanics, but it sits as a thin layer on a stable base rather than as fifty separate programs. That is the architecture this practice builds, and the AI governance overview describes it end to end.

Common Questions

State AI law, answered briefly.

Which state AI laws are in force right now?

Texas TRAIGA, California SB 53 and AB 2013, and Illinois HB 3773, all effective January 1, 2026, plus Utah's 2024 AI Policy Act and New York City's Local Law 144 from 2023. Colorado's replacement statute, New York's RAISE Act, and California's phased ADMT obligations arrive from 2027.

Does a state law apply if we are not located there?

Generally yes, if your systems affect that state's residents. Reach attaches through consumers, applicants, and data subjects, not through the deployer's address, and the crossing happens silently through ordinary business growth.

How should a multi-state company approach this?

Govern to a stable framework, hold the records, and layer statute-specific work on top. The inventory that maps whose residents each system reaches, plus NIST AI RMF alignment, answers most of the patchwork from one body of evidence, with Texas making the framework a formal defense.

How often does this page change?

It is reviewed quarterly, and sooner when a statute is enacted, amended, or enjoined. The watch list above is the schedule of known changes; the preemption litigation is the principal source of unscheduled ones.

Get In Touch

Discuss Your Multi-State AI Exposure

Inquiries may involve mapping which state regimes your systems actually reach, building the inventory that records resident exposure, or structuring framework-based governance so the patchwork is answered from one set of records. Call, email, or send a note. I respond personally to every inquiry, usually within one business day.

Address
Essex Junction, VT
Travel
I travel to client sites nationally.

Discuss an Assessment

Whether the question is which of these statutes reach your organization today, what the 2027 arrivals will require of you, or how to build once for a patchwork that keeps moving, the first conversation carries no commitment and no pitch.

Discuss an Assessment →