US State AI Laws, Mapped
12 min read · updated August 4, 2026
There is no United States AI statute. What exists is a small number of states with binding AI-specific obligations, a much larger number of states with comprehensive privacy laws that reach profiling, and a federal position that has repeatedly tried and failed to preempt any of it.
There is no federal AI statute
No general federal AI law has been enacted. Federal activity has been executive and sectoral: Executive Order 14110 of October 2023 was revoked in January 2025 by a successor order taking a deregulatory direction, and federal agencies apply existing statutes — the FTC Act, the Fair Credit Reporting Act, the Equal Credit Opportunity Act, Title VII, the FD&C Act — to AI as to anything else.
Preemption of state AI law has been attempted more than once. A proposed moratorium on state AI regulation was stripped out of a federal budget bill by a near-unanimous Senate vote in July 2025, and further executive attempts to press against state laws followed. As at this review date, no federal preemption of state AI law is in effect. Treat any claim that state laws have been superseded with suspicion and check the source.
Colorado: the one comprehensive state act
The Colorado Artificial Intelligence Act (SB 24-205, signed May 2024, codified in the Colorado Revised Statutes at title 6, article 1, part 17) is the only enacted US state law with the shape of the EU AI Act: risk-based, covering developers and deployers, aimed at algorithmic discrimination in consequential decisions.
- Scope. “High-risk artificial intelligence systems” that make, or are a substantial factor in making, a consequential decision — education, employment, financial or lending services, essential government services, healthcare, housing, insurance, or legal services.
- Core duty. Reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination. Compliance with specified steps creates a rebuttable presumption that reasonable care was used.
- Developer duties. Documentation to deployers on intended uses, known harmful uses, training data summaries, evaluation, mitigation, and how the system should be used and monitored; a public statement of the high-risk systems developed; disclosure of discovered algorithmic discrimination to the Attorney General and to known deployers.
- Deployer duties. A risk management programme; impact assessments, including on any intentional and substantial modification; notice to consumers before a consequential decision; on an adverse decision, a statement of the principal reasons and an opportunity to correct data and to appeal for human review.
- Enforcement. Exclusively by the Attorney General. There is no private right of action. A rebuttable presumption arises from compliance with a recognised risk management framework, with the NIST AI Risk Management Framework named as one.
The date has already moved. The Act was originally to take effect on 1 February 2026. In a special session in August 2025 the legislature postponed it to 30 June 2026. Further amendment has been under active discussion since. If you are planning against this statute, check the current effective date and the current text together, because the amendments have changed both.
California: several narrow acts, not one
California has legislated repeatedly and narrowly. There is no single California AI act; there are half a dozen obligations pointed at specific problems.
| Instrument | Description |
|---|---|
| AB 2013 (training data transparency) | Developers of generative AI systems made available to Californians must post documentation about the datasets used to train them, including sources, whether they include personal information or copyrighted material, and the time period of collection. Effective 1 January 2026, and it reaches systems released since 2022 rather than only new ones. |
| SB 942 (California AI Transparency Act) | Provenance obligations on covered generative AI providers — latent disclosures in generated content and a free public detection tool. Its commencement was amended in 2025 by follow-on legislation that pushed the date back and extended the regime toward capture devices and large platforms. Treat the original 1 January 2026 date as superseded and check the current one. |
| SB 53 (frontier AI transparency) | Signed September 2025. Requires large frontier developers to publish a safety framework, report critical safety incidents to state emergency services, and protects employees who raise catastrophic-risk concerns. Aimed at a small number of developers by compute and revenue thresholds, not at ordinary deployers. |
| SB 1001 (bot disclosure, 2018) | Predates the current wave. Unlawful to use a bot to communicate with a Californian to incentivise a sale or influence a vote without disclosing it is a bot. Still in force and still forgotten. |
| CCPA regulations on automated decisionmaking technology | The California Privacy Protection Agency adopted regulations covering pre-use notice, opt-out and access rights for automated decisionmaking in significant decisions. Compliance is phased; the principal compliance date falls in 2027. Confirm the exact date against the CPPA's own rulemaking record. |
Texas
The Texas Responsible Artificial Intelligence Governance Act (HB 149, signed June 2025, effective 1 January 2026) took a different route from Colorado’s. It is built on intent rather than on outcomes: it prohibits developing or deploying AI with the intent to incite self-harm or crime, to infringe constitutional rights, or to unlawfully discriminate, and it makes clear that a disparate impact alone is not sufficient to show intent to discriminate.
It also restricts government use — biometric identification of individuals from publicly available sources without consent, and social scoring by state agencies — requires disclosure when a state agency interacts with a person through AI, creates a regulatory sandbox and an advisory council, and gives enforcement to the Attorney General with a cure period before action. There is no private right of action.
The practical difference from Colorado is large. A Colorado deployer owes documented risk management whether or not anyone intended harm. A Texas deployer, on the face of the statute, does not.
Illinois
- HB 3773 (2024), effective 1 January 2026, amends the Illinois Human Rights Act to make it a civil rights violation for an employer to use AI that has the effect of discriminating on a protected class in recruitment, hiring, promotion, discipline or discharge, or to use ZIP code as a proxy for a protected class. It also requires notice to employees and applicants when AI is used for those purposes.
- The Artificial Intelligence Video Interview Act (820 ILCS 42), in force since 2020, requires notice, an explanation of how the AI works and what characteristics it uses, consent before an AI-analysed video interview, limits on sharing, and destruction of the video within 30 days of a request.
- The Biometric Information Privacy Act (740 ILCS 14) is not an AI law and is the most litigated of the three. It requires informed written consent before collecting biometric identifiers and provides a private right of action with statutory damages, which is why it produces class actions where the other two do not.
Utah
Utah’s Artificial Intelligence Policy Act (SB 149, 2024, in force since May 2024) was the first state generative AI disclosure law. Its core is narrow: a person in a regulated occupation must disclose prominently, at the outset, when a consumer is interacting with generative AI rather than a human; others must disclose when asked. It also makes clear that “the AI said it” is not a defence to a consumer protection claim, and it created an office of AI policy with a learning-lab mechanism for tailored regulatory relief.
It was amended in 2025, narrowing the general disclosure trigger and extending the framework. The amendments are the reason to read the current code rather than the 2024 press coverage.
New York City, and state-level activity
New York City Local Law 144 of 2021, enforced since July 2023, remains the most-cited US AI rule and is a city ordinance rather than a state law. It requires an annual independent bias audit of automated employment decision tools used to screen candidates for jobs in the city, publication of a summary of the results, and notice to candidates at least ten business days before use. Enforcement is by the Department of Consumer and Worker Protection. What it does and does not achieve is worth reading before you treat it as a model.
At state level, New York passed the RAISE Act in 2025, directed at frontier model developers and requiring safety protocols and incident disclosure. The version signed differed from the version passed by the legislature, and this page does not state a commencement date for it: check the chaptered text. New York also legislated on state agency use of automated decision-making, and passed a law on AI companion models with safeguards around self-harm.
Tennessee’s ELVIS Act (2024) extended the state’s right of publicity to cover voice, aimed squarely at synthesised performances, and several states have passed election deepfake disclosure laws and non-consensual intimate imagery laws that reach synthetic media.
What is not covered anywhere
Marking the gaps is as useful as mapping the coverage, and it is what the usual survey article leaves out.
- Most states have no AI-specific statute at all. The majority of US states have enacted nothing binding on private-sector AI use beyond deepfake and election provisions. Their residents are covered by general law: unfair and deceptive practices statutes, civil rights law, and a comprehensive privacy law in around twenty states.
- No general training data or copyright rule. Beyond California’s disclosure requirement, no state regulates what may be trained on. That question is being decided in federal courts under fair use, not in legislatures.
- No general liability rule for model output. Product liability doctrine has not settled whether a model is a product. Claims proceed under negligence, misrepresentation and consumer protection theories instead.
- No interoperability. Colorado’s risk-based duties, Texas’s intent-based prohibitions and California’s disclosure obligations do not compose into a single compliance programme. A multi-state deployer either builds to the strictest or maintains separate treatments per state, and most build to Colorado plus the EU.