The structured reference for US AI compliance.
NIST AI RMF, ISO/IEC 42001, and every consequential US state AI law in one continuously verified atlas — paired with interactive tools that map obligations to your operations.
Built for compliance officerslegal counselAI product teams
US state AI law status — at a glance
What's enforceable right now
Snapshot from the freshness monitor. Click any law for full obligations, penalties, and citations.
| Jurisdiction | Law | Status | Effective | Max penalty | Verified |
|---|---|---|---|---|---|
| Colorado | Colorado Artificial Intelligence ActC.R.S. § 6-1-1701 to § 6-1-1709 | StatusEffective soon | Effective dateJanuary 1, 2027 | Max penalty$20K | Last verifiedJuly 31, 2026 |
| California | California AI Transparency ActCal. Bus. & Prof. Code §§ 22757 et seq. | StatusIn effect | Effective dateAugust 2, 2026 | Max penalty$5K | Last verifiedAugust 13, 2026 |
| Connecticut | Connecticut Public Act 26-15 / SB 5 (Online Safety and AI Provisions)Public Act 26-15, 2026 Gen. Assemb. (Substitute S.B. 5, "An Act Concerning Online Safety"), as affected by Public Act 26-100 | StatusIn effect | Effective dateMay 27, 2026 | Max penaltyNot specified | Last verifiedAugust 10, 2026 |
| California | California Generative AI: Training Data TransparencyCal. Civ. Code §§ 3110–3111 | StatusIn effect | Effective dateJanuary 1, 2026 | Max penaltyNot specified | Last verifiedJuly 27, 2026 |
| Illinois | Illinois HB 3773 (AI in Employment Decisions)775 ILCS 5/2-102 (as amended) | StatusIn effect | Effective dateJanuary 1, 2026 | Max penaltyNot specified | Last verifiedAugust 8, 2026 |
| Texas | Texas Responsible Artificial Intelligence Governance Act (TRAIGA)Tex. Bus. & Com. Code Chs. 551-554 | StatusIn effect | Effective dateJanuary 1, 2026 | Max penalty$200K | Last verifiedAugust 8, 2026 |
| California | Transparency in Frontier Artificial Intelligence Act (TFAIA)Cal. Bus. & Prof. Code §§ 22757.10–22757.16; Cal. Lab. Code §§ 1107–1107.2; Cal. Gov. Code § 11546.8 (Stats. 2025, Ch. 138) | StatusIn effect | Effective dateJanuary 1, 2026 | Max penalty$1.0M | Last verifiedJuly 27, 2026 |
| Utah | Utah Artificial Intelligence Policy ActUtah Code Title 13, Chapters 77, 72, and 72a | StatusIn effect | Effective dateMay 7, 2025 | Max penalty$5K | Last verifiedJuly 27, 2026 |
For the complete source-linked calendar, watchlist, and law-by-law classification, read the 2026 US state AI laws overview.
Tools that turn law into action
Built on the same primary-source data that powers the atlas. Free, no account required.
Compliance Checker
Surface every framework and state law that applies to your AI deployments — including likely effective dates.
- Yes — directly affects outcomes
- Yes — but a human reviews each decision
- No — informational only
Penalty Calculator
Estimate worst-case civil penalties across applicable jurisdictions. Conservative methodology, fully cited.
Impact Assessment Generator
Produces a downloadable impact assessment template aligned with your jurisdiction's statutory requirements.
Four ways into the atlas
Same primary sources, different lenses. Pick the one that matches how you're scoping work this quarter.
By framework
Maturity & control programs you may already use.
By industry
Where AI use intersects existing sectoral law.
By role
Obligations differ for builders, buyers, and resellers.
By comparison
Side-by-side views for overlapping AI laws and frameworks.
Pillar guides
Long-form explainers behind the atlas — role obligations, high-risk classification, federal preemption, sectoral overlays, and framework mapping.
US State AI Laws: All 13 Tracked (2026 Overview)
2026 guide to US state AI regulation, refreshed for Colorado SB 26-189, Connecticut PA 26-15/26-100, California AI laws, and compliance strategy.
AI Deployer vs Developer Obligations — Role Framework
How US AI laws split obligations between developers and deployers, why the line matters, and how to map your operations to the right role.
High-Risk AI System Explained
High-risk AI defined under Colorado's AI Act (SB 24-205, now reenacted as the SB 26-189 ADMT regime) and parallel concepts in the EU AI Act, NIST AI RMF, ISO/IEC 42001, and other US state laws.
Federal vs State AI Law: Preemption & How They Interact
How federal AI frameworks, federal enforcement, White House preemption policy, and state AI laws interact in 2026 — with a compliance evidence matrix.
AI Impact Assessment Template (2026): NIST, ISO 42001, Colorado ADMT
Build an AI impact assessment evidence file mapped to NIST AI RMF, ISO/IEC 42001, Colorado SB 26-189 ADMT evidence, and state-law review workflows.
EU AI Act Compliance vs US State AI Laws — 2026 Comparison
EU AI Act compliance timeline for 2026-2028 compared with US state AI laws including Colorado, Texas, NYC LL 144, California, and Connecticut.
NIST AI RMF Playbook: Downloads, Actions & State-Law Map
NIST ships the AI RMF Playbook as PDF, Excel, CSV and JSON, updated twice a year. What its four functions cover, and how the actions map to US state AI laws.
HIPAA Compliance for AI in Healthcare (2026 Guide)
How HIPAA applies to healthcare AI: PHI use, business associate agreements, de-identification, Security Rule safeguards, breach response, and FDA overlap.
AI Compliance Framework: Regulatory Control Map (2026 Guide)
A 2026 AI compliance framework for mapping NIST AI RMF, ISO/IEC 42001, state AI laws, evidence artifacts, and AI regulatory compliance tooling.
AI Governance: Building an AI Compliance Program (2026 Guide)
How to build an AI governance program: operating model, decision rights, lifecycle gates, the NIST AI RMF GOVERN function, ISO/IEC 42001, and the US state-law overlay.
Recent updates
Every entry links to the primary source. We re-verify continuously and timestamp every page.
- August 2, 2026EffectiveCalifornia AI Transparency Act Becomes Operative After a Seven-Month DelayBusiness and Professions Code Chapter 25, the California AI Transparency Act, became operative on August 2, 2026 under Section 22757.6. The date is not the one SB 942 set: as enacted in 2024 the bill provided that "this chapter shall become operative on January 1, 2026," and AB 853 (Stats. 2025, Ch. 674) amended Section 22757.6 before that date arrived, moving the chapter-wide operative date to August 2, 2026. Covered providers with generative-AI systems exceeding 1,000,000 monthly visitors or users that are publicly accessible in California must now make a free AI detection tool available under Section 22757.2 and include manifest and latent disclosures in AI-generated image, video, and audio content under Section 22757.3, subject to a $5,000 civil penalty per violation under Section 22757.4 with each day treated as a discrete violation. Three duties AB 853 added start later: large online platform and GenAI system hosting platform duties on January 1, 2027 under Sections 22757.3.1 and 22757.3.2, and capture device manufacturer duties on January 1, 2028 under Section 22757.3.3. Codified chapter text and SB 942 bill text retrieved 2026-08-13.
- July 13, 2026GuidanceColorado Attorney General Closes ADMT Pre-Rulemaking Comment PeriodThe Colorado Attorney General's Office closed its pre-rulemaking comment period for the Automated Decision-Making Technology Act on July 13, 2026. Per coag.gov, the office collected informal public feedback through a comment form and published a considerations paper to guide that input ahead of formal rulemaking. SB 26-189 requires the Attorney General to adopt rules before January 1, 2027 clarifying the requirements for post-adverse-outcome notices and the definition of "materially influence," including presumptions and illustrative examples. As of August 9, 2026 the office had not published proposed rules or announced hearing dates, stating it will update its rulemaking page once the formal process begins. Source retrieved 2026-08-09.
- July 6, 2026EnactmentIllinois Enacts SB 315, the Artificial Intelligence Safety Measures ActIllinois Governor JB Pritzker signed Senate Bill 315, the Artificial Intelligence Safety Measures Act, on July 6, 2026. Per the Office of the Governor, the Act reaches developers of the largest advanced AI systems and requires them to publicly disclose safety practices, report significant safety incidents, maintain compliance processes, and undergo regular independent third-party safety audits — described by the state as the first such third-party audit mandate in the nation. The Act also establishes confidential reporting channels and whistleblower protections for employees who raise AI safety concerns, and takes effect January 1, 2027. SB 315 is a separate statute from Illinois HB 3773, the employment-discrimination amendment to the Illinois Human Rights Act that took effect January 1, 2026. Source retrieved 2026-08-09; the enacted text on ilga.gov was unreachable at retrieval, so covered-developer thresholds and penalty provisions are cited here only to the extent the Governor's announcement states them.
- July 1, 2026GuidanceWashington State AI Task Force Releases Final ReportThe Washington Attorney General's Office released the third and final report required by ESSB 5838 on July 1, 2026. Across its preliminary, interim, and final reports, the Task Force advanced 11 policy recommendations. The Attorney General's release says lawmakers introduced legislation addressing eight recommendations during the 2025-2026 biennium and enacted four in whole or in part. The report is a recommendation document and does not itself create private-sector AI compliance duties.
- June 2, 2026DelayIllinois IDHR Temporarily Postpones AI Employment Notice RulemakingThe Illinois Department of Human Rights announced on June 2, 2026 that the June 10 public hearing for proposed administrative rules implementing the Artificial Intelligence in Employment provisions of the Illinois Human Rights Act was temporarily postponed. IDHR said it is reviewing matters related to the proposed rulemaking and will provide updated next steps. The underlying Public Act 103-0804 requirements remain effective January 1, 2026; the detailed notice timing, means, and conditions rules remain pending.
The compliance digest, weekly.
New laws, rulemaking, enforcement actions, and framework updates — distilled to a 4-minute read every Tuesday.
Free · Unsubscribe anytime · No tracking pixels