Federal vs State AI Law — How They Interact
Last verified: 2026-06-11 - supplemental refresh of federal-layer sources against NIST, the White House December 2025 state-AI-law order, the EEOC/DOJ/CFPB/FTC joint statement, CFPB Circular 2022-03, and FDA AI/ML SaMD guidance. Colorado SB 26-189 status was previously refreshed against the official Colorado General Assembly bill page on 2026-06-02; other state-law rows retain their own source dates.
Federal vs state AI law in the United States is a layered compliance problem, not a single preemption answer. A compliance program should separate three layers: voluntary federal frameworks that define controls, federal sector regulators that enforce existing statutes when AI is used, and state or municipal AI laws that add AI-specific triggers, notices, audits, records, or penalties.
Quick answer
As of June 11, 2026, U.S. AI compliance has three active layers: voluntary federal frameworks set the control vocabulary, federal agencies enforce existing laws against automated systems, and state or municipal AI laws add binding AI-specific obligations. The practical workflow is to map each AI system once, then attach evidence for the strictest triggered rule in each layer.
| Layer | What it does | Primary source anchor | Evidence artifact |
|---|---|---|---|
| Federal framework baseline | Defines reusable risk-management controls, but does not itself create state-law compliance | NIST says AI RMF 1.0 is intended for voluntary use and points to the AI RMF Playbook and GenAI Profile. Source: NIST AI Risk Management Framework, retrieved 2026-06-11 | Control library mapped to GOVERN / MAP / MEASURE / MANAGE and ISO/IEC 42001 where certification is needed |
| Federal enforcement under existing statutes | Applies civil-rights, consumer-protection, credit, employment, competition, and product-safety law when AI or automated systems are used | EEOC, DOJ, CFPB, and FTC jointly stated that automated systems must be consistent with federal laws. Source: EEOC joint statement release, retrieved 2026-06-11 | Sector checklist: adverse-action reasons, accommodation process, bias-testing file, AI-claims substantiation, product submission pathway |
| Federal preemption and policy pressure | Creates monitoring and litigation risk for state AI laws; it is not the same thing as a complete replacement statute | The December 11, 2025 White House order directs a Commerce evaluation of state AI laws and an AI Litigation Task Force. Source: White House order, retrieved 2026-06-11 | Preemption watch item per law: policy signal, litigation/agency action, binding court/statutory change |
| State and municipal AI laws | Create AI-specific duties for defined roles, sectors, or technologies | State-law sources are maintained on the linked Atlas law pages and the state AI regulation overview | Jurisdiction obligation row: trigger, role, due date, citation, evidence owner, refresh date |
The federal layer
Voluntary frameworks
- NIST AI Risk Management Framework (AI RMF 1.0 + Generative AI Profile NIST AI 600-1) — voluntary risk-management framework. Adopting it does not directly satisfy state-law obligations but substantially supports them. Operational guidance lives in the NIST AI RMF Playbook — NIST's companion resource of suggested actions per subcategory. Source: NIST AI Risk Management Framework, retrieved 2026-06-11.
- ISO/IEC 42001 — international AI management system standard, certifiable through accredited bodies.
Federal enforcement under existing statutes
Federal AI compliance does not wait for a single comprehensive AI statute. Agencies already apply existing law to automated systems:
| Domain | Federal source | Practical compliance implication |
|---|---|---|
| Cross-agency automated-system enforcement | EEOC, DOJ, CFPB, and FTC jointly committed to enforce their respective laws for automated systems. Source: EEOC joint statement release, retrieved 2026-06-11 | Keep an AI-system inventory tied to civil-rights, consumer-protection, credit, competition, and employment-law reviews |
| Credit and lending | CFPB Circular 2022-03 says ECOA and Regulation B adverse-action reasons apply to credit decisions using complex algorithms. Source: CFPB Circular 2022-03, retrieved 2026-06-11 | A model that cannot produce specific adverse-action reasons is a compliance blocker, not only a model-explainability concern |
| Employment and disability access | EEOC AI-and-ADA resources link to technical assistance on software, algorithms, and AI used to assess job applicants and employees. Source: EEOC Artificial Intelligence and the ADA, retrieved 2026-06-11 | Hiring-AI governance should include accommodation workflows and disparate-impact testing alongside state AEDT rules |
| Medical-device software | FDA states that many changes to AI/ML-driven device software may need premarket review and points to lifecycle guidance for AI-enabled device software functions. Source: FDA Artificial Intelligence in Software as a Medical Device, retrieved 2026-06-11 | Healthcare AI that functions as device software needs product-regulatory review before relying only on privacy or state-AI controls |
| AI claims and consumer deception | FTC AI enforcement resources and Operation AI Comply show that AI marketing claims and AI-enabled deception remain Section 5 issues. Source: FTC Artificial Intelligence page, retrieved 2026-06-11 | Substantiate claims that a tool uses AI, replaces professional judgment, improves outcomes, or automates regulated work |
Executive actions and federal policy
- EO 14110 (Biden, October 2023) — broad federal AI policy direction, NIST guidance commissioning, agency reporting obligations. Status uncertain post-2025 administration changes.
- December 11, 2025 Executive Order "Ensuring a National Policy Framework for Artificial Intelligence" — directs federal agencies to identify state AI laws that may conflict with the federal AI policy framework, including laws that may trigger constitutional or preemption challenges. Source: White House order, retrieved 2026-06-11.
The state layer
See the US State AI Regulation Overview for the full list. Currently effective or scheduled: Texas, NYC LL 144, Illinois, Utah, California AI laws, Washington Task Force, and Colorado's SB 26-189 ADMT regime scheduled around January 1, 2027. Source for Colorado status: Colorado SB 26-189, retrieved 2026-06-02.
Defeated and pending bills also matter for compliance planning. Virginia HB 2094 — a Colorado-modeled comprehensive AI bill — was vetoed by Governor Youngkin on March 24, 2025, and the 2026 General Assembly tabled comprehensive successors to the 2027 session, leaving Virginia organizations on a VCDPA-plus-federal-frameworks footing. Florida regulates AI through narrow topic-specific statutes (HB 919 political deepfakes, HB 757 sexual deepfakes) rather than a single comprehensive act, illustrating an alternative state model that some southern legislatures may follow if Colorado-style bills continue to face vetoes.
Preemption — current state of play
No Atlas-tracked federal statute currently replaces the state-law layer. The December 2025 EO is a monitoring and litigation signal: it directs federal officials to evaluate state AI laws and sets up an AI Litigation Task Force, but the Atlas keeps state-law rows active until a binding source changes a specific law's enforceability.
Existing federal law preempts state law in narrow areas:
- Federal communications and broadcasting: limits state authority over certain digital communications
- Federal trade secret law: complementary to state law, generally not preemptive
- Federal banking law: national-bank charters can preempt some state consumer-protection rules in lending
When a federal and state requirement appears to conflict, the Atlas marks the row for legal review instead of collapsing it into a generic answer; the enforceable result depends on the specific statute, agency action, or court order.
How to handle federal preemption risk in the compliance register
Treat preemption as a status field, not as a reason to delete state controls before a binding change occurs.
| Status | What it means | Register action |
|---|---|---|
| Policy signal | A federal order, framework, or legislative proposal criticizes state AI laws or calls for a national framework | Keep the state-law row active; add a monitoring note and source date |
| Litigation or agency action | DOJ, Commerce, a court, or a regulated party challenges a specific state law or provision | Mark the affected obligation as contested; keep evidence unless counsel approves a pause |
| Binding change | A court order, enacted federal statute, final agency action, or state amendment changes enforceability | Update the law page, obligation row, sitemap freshness date, and affected tools |
This three-status model is the operating difference between legal monitoring and compliance execution. It keeps the Atlas from overstating either side: federal policy pressure is real, but it is not the same as universal state-law preemption.
Operational implications
Adopt a federal framework as your control baseline
NIST AI RMF and ISO/IEC 42001 are voluntary at the federal level but are widely referenced as the substantive control framework satisfying due-care expectations. Most state-law obligations map to specific framework controls — for example:
- Colorado SB 26-189 covered ADMT documentation, notice, records, correction, and human-review workflows ↔ NIST AI RMF MAP/GOVERN functions + ISO 42001 Annex A.5
- NYC LL 144 bias audit ↔ NIST AI RMF MEASURE 2.11 + ISO 42001 Annex A.5
- California SB 53 frontier AI safety framework ↔ NIST AI RMF GOVERN function + GenAI Profile
See the framework × law mappings for the full matrix, then translate those mappings into an AI compliance framework register and assign ownership through the AI governance operating model.
Build for the most stringent jurisdiction
If you operate in multiple states, build your compliance program for the most demanding applicable law. Practically:
- Colorado SB 26-189 remains a scheduled U.S. benchmark for consequential-decision ADMT documentation, notice, records, correction, and human-review evidence; designing to that evidence level typically supports Texas, Illinois, Utah, and most California requirements even though SB 26-189 is narrower than the original SB 24-205 framework
- NYC LL 144 sets the floor for hiring AI bias audits — if an employer hires in NYC, annual AEDT bias-audit workflows apply
- California SB 53 sets the floor for frontier AI safety frameworks — if a developer trains at scale, it publishes the framework
Use a four-column evidence model
A multi-state AI register should keep federal and state evidence together without flattening the legal sources.
| AI system question | Federal framework evidence | Federal sector-law evidence | State or municipal AI evidence | Owner |
|---|---|---|---|---|
| What is the system and who owns it? | NIST MAP context row; ISO scope row | Vendor/procurement record where a regulated product or service is involved | Jurisdiction applicability row | System owner |
| What decision domain does it affect? | Risk-tier classification | ECOA, employment, medical-device, consumer-protection, or civil-rights screen | Colorado covered ADMT, NYC AEDT, Illinois employment, California GenAI/frontier, Texas TRAIGA, Utah disclosure, or other triggered law | Legal / compliance |
| What is the required notice or explanation? | Transparency control | CFPB adverse-action reasons, EEOC accommodation notice, FTC claim substantiation, FDA labeling/submission record where applicable | State AI notices, public bias-audit summaries, synthetic-content disclosures | Legal + product |
| What testing proves the control works? | NIST MEASURE / ISO impact-assessment evidence | Sector-specific testing or submission file | Bias audit, impact assessment, disclosure test, incident record | Risk + engineering |
| When does the evidence refresh? | Annual framework review | Sector cadence or model-change trigger | State-law due date and last-verified date | Compliance operations |
What if federal preemption succeeds
If state AI laws are partially or fully preempted in the future:
- Federal frameworks (NIST, ISO) remain unaffected — these are voluntary standards, not state laws
- Sector-specific federal guidance remains — CFPB, EEOC, FDA, HHS OCR, and other agencies continue to enforce their domains; healthcare workflows should keep a separate HIPAA AI compliance analysis
- State consumer-protection law (UDAP) remains — even if AI-specific laws are preempted, broad state UDAP and civil rights statutes still apply to AI-driven harms
The Atlas's pivot toward federal frameworks as primary tier (alongside state laws) reflects this risk: federal-framework adoption is preemption-proof.
Frequently asked questions
Is there one federal AI law in the United States?
The Atlas does not currently track an enacted federal AI statute that replaces the state AI law layer. The federal layer is currently a combination of voluntary frameworks, agency enforcement under existing laws, executive-branch policy, and sector-specific rules. State and municipal AI laws still need separate applicability checks.
Does NIST AI RMF preempt state AI laws?
No. NIST AI RMF is voluntary guidance. It is useful because it supplies a control vocabulary for governance, mapping, measurement, and risk management, but it does not replace binding state-law duties such as NYC LL 144 bias audits, California AI transparency duties, or Colorado SB 26-189 records and notice obligations.
Can federal agencies enforce AI systems without a new AI statute?
Yes. The EEOC, DOJ, CFPB, and FTC have said automated systems must comply with the laws those agencies already enforce. CFPB Circular 2022-03 is a concrete example: creditors using complex algorithms still need specific adverse-action reasons under ECOA and Regulation B.
What happens if a state AI law conflicts with federal AI policy?
The compliance team should mark the state-law obligation as contested only when there is a concrete federal action, lawsuit, court order, statute, or state amendment affecting that law. A policy statement or executive order is a monitoring trigger; it is not automatically the same as repeal of a state-law obligation.
Should a company follow federal frameworks or state AI laws first?
Build both into one register. Use NIST AI RMF or ISO/IEC 42001 as the baseline control library, then add state-law rows for the exact jurisdictions and roles triggered by each AI system. The strictest triggered obligation should drive the evidence artifact and refresh cadence.
Cross-references
- NIST AI RMF detail
- ISO/IEC 42001 detail
- State law overview
- AI governance guide
- AI compliance framework
- News log
- Verify primary sources with CiteCanon — citation-backed legal research to confirm the operative statute text before relying on any summary.