AAI Compliance Atlas
FrameworksState lawsIndustriesToolsNews
GuidesMap my obligations →
AAI Compliance Atlas

Structured, continuously verified reference for US AI compliance — federal frameworks, state laws, and the obligations that connect them.

Atlas

  • Frameworks
  • State laws
  • Industries
  • By role
  • Comparisons

Tools

  • Compliance Checker
  • Penalty Calculator
  • Impact Assessment
  • Vendor Questionnaire

Resources

  • Guides
  • News
  • Blog
  • Methodology

Company

  • About
  • Contact
  • Privacy
  • Terms
© 2026 AI Compliance Atlas. Informational only — not legal advice. Consult qualified counsel before making compliance decisions.Verified Jul 28, 2026
  1. Home/
  2. Guides/
  3. Federal vs State AI Law: Preemption & How They Interact

Federal vs State AI Law — How They Interact

Last verified: 2026-06-11 - supplemental refresh of federal-layer sources against NIST, the White House December 2025 state-AI-law order, the EEOC/DOJ/CFPB/FTC joint statement, CFPB Circular 2022-03, and FDA AI/ML SaMD guidance. Colorado SB 26-189 status was previously refreshed against the official Colorado General Assembly bill page on 2026-06-02; other state-law rows retain their own source dates.

Federal vs state AI law in the United States is a layered compliance problem, not a single preemption answer. A compliance program should separate three layers: voluntary federal frameworks that define controls, federal sector regulators that enforce existing statutes when AI is used, and state or municipal AI laws that add AI-specific triggers, notices, audits, records, or penalties.

Quick answer

As of June 11, 2026, U.S. AI compliance has three active layers: voluntary federal frameworks set the control vocabulary, federal agencies enforce existing laws against automated systems, and state or municipal AI laws add binding AI-specific obligations. The practical workflow is to map each AI system once, then attach evidence for the strictest triggered rule in each layer.

LayerWhat it doesPrimary source anchorEvidence artifact
Federal framework baselineDefines reusable risk-management controls, but does not itself create state-law complianceNIST says AI RMF 1.0 is intended for voluntary use and points to the AI RMF Playbook and GenAI Profile. Source: NIST AI Risk Management Framework, retrieved 2026-06-11Control library mapped to GOVERN / MAP / MEASURE / MANAGE and ISO/IEC 42001 where certification is needed
Federal enforcement under existing statutesApplies civil-rights, consumer-protection, credit, employment, competition, and product-safety law when AI or automated systems are usedEEOC, DOJ, CFPB, and FTC jointly stated that automated systems must be consistent with federal laws. Source: EEOC joint statement release, retrieved 2026-06-11Sector checklist: adverse-action reasons, accommodation process, bias-testing file, AI-claims substantiation, product submission pathway
Federal preemption and policy pressureCreates monitoring and litigation risk for state AI laws; it is not the same thing as a complete replacement statuteThe December 11, 2025 White House order directs a Commerce evaluation of state AI laws and an AI Litigation Task Force. Source: White House order, retrieved 2026-06-11Preemption watch item per law: policy signal, litigation/agency action, binding court/statutory change
State and municipal AI lawsCreate AI-specific duties for defined roles, sectors, or technologiesState-law sources are maintained on the linked Atlas law pages and the state AI regulation overviewJurisdiction obligation row: trigger, role, due date, citation, evidence owner, refresh date

The federal layer

Voluntary frameworks

  • NIST AI Risk Management Framework (AI RMF 1.0 + Generative AI Profile NIST AI 600-1) — voluntary risk-management framework. Adopting it does not directly satisfy state-law obligations but substantially supports them. Operational guidance lives in the NIST AI RMF Playbook — NIST's companion resource of suggested actions per subcategory. Source: NIST AI Risk Management Framework, retrieved 2026-06-11.
  • ISO/IEC 42001 — international AI management system standard, certifiable through accredited bodies.

Federal enforcement under existing statutes

Federal AI compliance does not wait for a single comprehensive AI statute. Agencies already apply existing law to automated systems:

DomainFederal sourcePractical compliance implication
Cross-agency automated-system enforcementEEOC, DOJ, CFPB, and FTC jointly committed to enforce their respective laws for automated systems. Source: EEOC joint statement release, retrieved 2026-06-11Keep an AI-system inventory tied to civil-rights, consumer-protection, credit, competition, and employment-law reviews
Credit and lendingCFPB Circular 2022-03 says ECOA and Regulation B adverse-action reasons apply to credit decisions using complex algorithms. Source: CFPB Circular 2022-03, retrieved 2026-06-11A model that cannot produce specific adverse-action reasons is a compliance blocker, not only a model-explainability concern
Employment and disability accessEEOC AI-and-ADA resources link to technical assistance on software, algorithms, and AI used to assess job applicants and employees. Source: EEOC Artificial Intelligence and the ADA, retrieved 2026-06-11Hiring-AI governance should include accommodation workflows and disparate-impact testing alongside state AEDT rules
Medical-device softwareFDA states that many changes to AI/ML-driven device software may need premarket review and points to lifecycle guidance for AI-enabled device software functions. Source: FDA Artificial Intelligence in Software as a Medical Device, retrieved 2026-06-11Healthcare AI that functions as device software needs product-regulatory review before relying only on privacy or state-AI controls
AI claims and consumer deceptionFTC AI enforcement resources and Operation AI Comply show that AI marketing claims and AI-enabled deception remain Section 5 issues. Source: FTC Artificial Intelligence page, retrieved 2026-06-11Substantiate claims that a tool uses AI, replaces professional judgment, improves outcomes, or automates regulated work

Executive actions and federal policy

  • EO 14110 (Biden, October 2023) — broad federal AI policy direction, NIST guidance commissioning, agency reporting obligations. Status uncertain post-2025 administration changes.
  • December 11, 2025 Executive Order "Ensuring a National Policy Framework for Artificial Intelligence" — directs federal agencies to identify state AI laws that may conflict with the federal AI policy framework, including laws that may trigger constitutional or preemption challenges. Source: White House order, retrieved 2026-06-11.

The state layer

See the US State AI Regulation Overview for the full list. Currently effective or scheduled: Texas, NYC LL 144, Illinois, Utah, California AI laws, Washington Task Force, and Colorado's SB 26-189 ADMT regime scheduled around January 1, 2027. Source for Colorado status: Colorado SB 26-189, retrieved 2026-06-02.

Defeated and pending bills also matter for compliance planning. Virginia HB 2094 — a Colorado-modeled comprehensive AI bill — was vetoed by Governor Youngkin on March 24, 2025, and the 2026 General Assembly tabled comprehensive successors to the 2027 session, leaving Virginia organizations on a VCDPA-plus-federal-frameworks footing. Florida regulates AI through narrow topic-specific statutes (HB 919 political deepfakes, HB 757 sexual deepfakes) rather than a single comprehensive act, illustrating an alternative state model that some southern legislatures may follow if Colorado-style bills continue to face vetoes.

Preemption — current state of play

No Atlas-tracked federal statute currently replaces the state-law layer. The December 2025 EO is a monitoring and litigation signal: it directs federal officials to evaluate state AI laws and sets up an AI Litigation Task Force, but the Atlas keeps state-law rows active until a binding source changes a specific law's enforceability.

Existing federal law preempts state law in narrow areas:

  • Federal communications and broadcasting: limits state authority over certain digital communications
  • Federal trade secret law: complementary to state law, generally not preemptive
  • Federal banking law: national-bank charters can preempt some state consumer-protection rules in lending

When a federal and state requirement appears to conflict, the Atlas marks the row for legal review instead of collapsing it into a generic answer; the enforceable result depends on the specific statute, agency action, or court order.

How to handle federal preemption risk in the compliance register

Treat preemption as a status field, not as a reason to delete state controls before a binding change occurs.

StatusWhat it meansRegister action
Policy signalA federal order, framework, or legislative proposal criticizes state AI laws or calls for a national frameworkKeep the state-law row active; add a monitoring note and source date
Litigation or agency actionDOJ, Commerce, a court, or a regulated party challenges a specific state law or provisionMark the affected obligation as contested; keep evidence unless counsel approves a pause
Binding changeA court order, enacted federal statute, final agency action, or state amendment changes enforceabilityUpdate the law page, obligation row, sitemap freshness date, and affected tools

This three-status model is the operating difference between legal monitoring and compliance execution. It keeps the Atlas from overstating either side: federal policy pressure is real, but it is not the same as universal state-law preemption.

Operational implications

Adopt a federal framework as your control baseline

NIST AI RMF and ISO/IEC 42001 are voluntary at the federal level but are widely referenced as the substantive control framework satisfying due-care expectations. Most state-law obligations map to specific framework controls — for example:

  • Colorado SB 26-189 covered ADMT documentation, notice, records, correction, and human-review workflows ↔ NIST AI RMF MAP/GOVERN functions + ISO 42001 Annex A.5
  • NYC LL 144 bias audit ↔ NIST AI RMF MEASURE 2.11 + ISO 42001 Annex A.5
  • California SB 53 frontier AI safety framework ↔ NIST AI RMF GOVERN function + GenAI Profile

See the framework × law mappings for the full matrix, then translate those mappings into an AI compliance framework register and assign ownership through the AI governance operating model.

Build for the most stringent jurisdiction

If you operate in multiple states, build your compliance program for the most demanding applicable law. Practically:

  • Colorado SB 26-189 remains a scheduled U.S. benchmark for consequential-decision ADMT documentation, notice, records, correction, and human-review evidence; designing to that evidence level typically supports Texas, Illinois, Utah, and most California requirements even though SB 26-189 is narrower than the original SB 24-205 framework
  • NYC LL 144 sets the floor for hiring AI bias audits — if an employer hires in NYC, annual AEDT bias-audit workflows apply
  • California SB 53 sets the floor for frontier AI safety frameworks — if a developer trains at scale, it publishes the framework

Use a four-column evidence model

A multi-state AI register should keep federal and state evidence together without flattening the legal sources.

AI system questionFederal framework evidenceFederal sector-law evidenceState or municipal AI evidenceOwner
What is the system and who owns it?NIST MAP context row; ISO scope rowVendor/procurement record where a regulated product or service is involvedJurisdiction applicability rowSystem owner
What decision domain does it affect?Risk-tier classificationECOA, employment, medical-device, consumer-protection, or civil-rights screenColorado covered ADMT, NYC AEDT, Illinois employment, California GenAI/frontier, Texas TRAIGA, Utah disclosure, or other triggered lawLegal / compliance
What is the required notice or explanation?Transparency controlCFPB adverse-action reasons, EEOC accommodation notice, FTC claim substantiation, FDA labeling/submission record where applicableState AI notices, public bias-audit summaries, synthetic-content disclosuresLegal + product
What testing proves the control works?NIST MEASURE / ISO impact-assessment evidenceSector-specific testing or submission fileBias audit, impact assessment, disclosure test, incident recordRisk + engineering
When does the evidence refresh?Annual framework reviewSector cadence or model-change triggerState-law due date and last-verified dateCompliance operations

What if federal preemption succeeds

If state AI laws are partially or fully preempted in the future:

  • Federal frameworks (NIST, ISO) remain unaffected — these are voluntary standards, not state laws
  • Sector-specific federal guidance remains — CFPB, EEOC, FDA, HHS OCR, and other agencies continue to enforce their domains; healthcare workflows should keep a separate HIPAA AI compliance analysis
  • State consumer-protection law (UDAP) remains — even if AI-specific laws are preempted, broad state UDAP and civil rights statutes still apply to AI-driven harms

The Atlas's pivot toward federal frameworks as primary tier (alongside state laws) reflects this risk: federal-framework adoption is preemption-proof.

Frequently asked questions

Is there one federal AI law in the United States?

The Atlas does not currently track an enacted federal AI statute that replaces the state AI law layer. The federal layer is currently a combination of voluntary frameworks, agency enforcement under existing laws, executive-branch policy, and sector-specific rules. State and municipal AI laws still need separate applicability checks.

Does NIST AI RMF preempt state AI laws?

No. NIST AI RMF is voluntary guidance. It is useful because it supplies a control vocabulary for governance, mapping, measurement, and risk management, but it does not replace binding state-law duties such as NYC LL 144 bias audits, California AI transparency duties, or Colorado SB 26-189 records and notice obligations.

Can federal agencies enforce AI systems without a new AI statute?

Yes. The EEOC, DOJ, CFPB, and FTC have said automated systems must comply with the laws those agencies already enforce. CFPB Circular 2022-03 is a concrete example: creditors using complex algorithms still need specific adverse-action reasons under ECOA and Regulation B.

What happens if a state AI law conflicts with federal AI policy?

The compliance team should mark the state-law obligation as contested only when there is a concrete federal action, lawsuit, court order, statute, or state amendment affecting that law. A policy statement or executive order is a monitoring trigger; it is not automatically the same as repeal of a state-law obligation.

Should a company follow federal frameworks or state AI laws first?

Build both into one register. Use NIST AI RMF or ISO/IEC 42001 as the baseline control library, then add state-law rows for the exact jurisdictions and roles triggered by each AI system. The strictest triggered obligation should drive the evidence artifact and refresh cadence.

Cross-references

  • NIST AI RMF detail
  • ISO/IEC 42001 detail
  • State law overview
  • AI governance guide
  • AI compliance framework
  • News log
  • Verify primary sources with CiteCanon — citation-backed legal research to confirm the operative statute text before relying on any summary.

Related reading

Continue with the frameworks, laws, and companion guides most relevant to this topic.

  • NIST AI Risk Management Framework — the federal anchor most state regimes build on.
  • NIST AI RMF Playbook — the companion action library for translating federal controls.
  • Colorado AI Act — the leading state statute in the federal–state interaction.
  • US state AI regulation overview — the full map of enacted and pending state AI laws.
  • ISO/IEC 42001 — the international standard organizations use across jurisdictions.

Last reviewed July 18, 2026. Reviewed by the AI Compliance Atlas editorial process against primary sources. Source selection, retrieval dates, and update rules are documented in the Atlas methodology.

Legal disclaimer

This content is informational only and does not constitute legal advice. Laws change frequently and vary by jurisdiction. Consult qualified legal counsel before making compliance decisions. Information accuracy not guaranteed as of any specific date.