AAI Compliance Atlas
FrameworksState lawsIndustriesToolsNews
GuidesMap my obligations →
AAI Compliance Atlas

Structured, continuously verified reference for US AI compliance — federal frameworks, state laws, and the obligations that connect them.

Atlas

  • Frameworks
  • State laws
  • Industries
  • By role
  • Comparisons

Tools

  • Compliance Checker
  • Penalty Calculator
  • Impact Assessment
  • Vendor Questionnaire

Resources

  • Guides
  • News
  • Blog
  • Methodology

Company

  • About
  • Contact
  • Privacy
  • Terms
© 2026 AI Compliance Atlas. Informational only — not legal advice. Consult qualified counsel before making compliance decisions.Verified Jul 28, 2026
  1. Home/
  2. Guides/
  3. US State AI Laws: All 13 Tracked (2026 Overview)

US State AI Regulation Overview

Last verified: 2026-07-01 - added a consolidated AI compliance-date calendar and a frequently-asked-questions section covering the most common US-state-AI-law questions; underlying jurisdiction rows retain their 2026-05-31 primary-source refresh dates. Prior note: 2026-06-02 targeted cleanup of residual Colorado SB 24-205/SB25B-004 wording after the 2026-05-31 refresh of Colorado SB 26-189, Connecticut Public Acts 26-15 and 26-100, and California Business and Professions Code Chapter 25.

As of May 31, 2026, the United States has no single comprehensive federal AI law. Instead, AI compliance for U.S. consumers is governed by a fast-emerging patchwork of state laws, municipal AI rules, federal voluntary frameworks, and sector-specific federal guidance.

As of July 1, 2026, the Atlas tracks 13 AI-law records across 11 US state and municipal jurisdictions; nine have enacted or scheduled AI-specific statutes, while Virginia (vetoed) and New Jersey (proposed) remain on the watchlist, and the United States still has no comprehensive federal AI law. The AI compliance calendar below consolidates every operative and scheduled state trigger date into a single view.

Which states have AI laws in 2026?

The Atlas tracks 13 law records across 11 state or municipal jurisdictions. They do not all do the same thing. A compliance team should separate binding direct duties from watchlist items and study bodies before building a control register.

Jurisdiction2026 statusPrimary compliance triggerPrimary source
ColoradoReenacted / scheduled; SB 26-189 became law on May 14, 2026 and replaces the prior SB 24-205 framework with a covered automated-decision-making-technology regime starting January 1, 2027Developers and deployers of covered ADMT used to materially influence consequential decisionsColorado SB 26-189, retrieved 2026-05-31
TexasEffective January 1, 2026Developers and deployers of AI systems offered, sold, leased, provided, or used in Texas; consumer disclosure, discrimination, social-scoring, biometric, and enforcement provisionsTexas HB 149 enrolled text, retrieved 2026-05-11
New York CityIn force; DCWP began enforcement July 5, 2023Employers and employment agencies using AEDTs for NYC hiring or promotionNYC DCWP AEDT page, retrieved 2026-05-11
IllinoisEffective January 1, 2026Employer use of AI in recruitment, hiring, promotion, renewal, selection, discharge, discipline, tenure, or employment terms where it discriminates or uses zip codes as protected-class proxiesIllinois Public Act 103-0804, retrieved 2026-05-11
UtahIn force, amended in 2025High-risk AI interactions, regulated-occupation disclosures, Office of AI Policy / learning-lab pathway, and mental-health-chatbot protectionsUtah SB 226 and Utah HB 452, retrieved 2026-05-11
CaliforniaSplit 2026 schedule: AB 2013 and SB 53 are effective January 1, 2026; SB 942 covered-provider duties are operative August 2, 2026, with AB 853 platform/hosting/capture-device duties phased into 2027-2028GenAI content provenance, training-data documentation, and large frontier developer safety frameworks / incident reportingBPC Chapter 25, AB 2013, SB 53, retrieved 2026-05-31
FloridaNarrow enacted statutes, not a comprehensive AI actAI-generated political-ad disclaimers and altered sexual-depiction / deepfake restrictionsFlorida HB 919 and Fla. Stat. § 836.13, retrieved 2026-05-11
WashingtonStudy / governance body, not a direct private-sector compliance regimeAI Task Force reporting and recommendationsWashington SB 5838, retrieved 2026-05-11
ConnecticutEnacted but phased; SB 5 is Public Act 26-15, and Public Act 26-100 later repeals PA 26-15 Sections 1 and 33 while adding a narrower generative-AI subscription disclosure ruleGenerative-AI subscription disclosures and AI-related layoff notices in 2026; AI companion, frontier-developer, AEDT, social-media-minor, state-AI, and workforce provisions phase in laterConnecticut PA 26-15, Connecticut PA 26-100, retrieved 2026-05-31
VirginiaDefeated / watchlist2025 Colorado-modeled bill vetoed; future comprehensive bill expected to be a 2027-session issueVirginia HB 2094 detail
New JerseyProposed / watchlistHiring AEDT bias-audit bill modeled on NYC LL 144New Jersey A 3854 detail

What changed in the May 2026 refresh?

ChangeCompliance meaningSource
Colorado moved from SB 24-205 delay tracking to SB 26-189 as the current enacted frameworkCompliance teams should no longer treat June 30, 2026 as the operative date for the old SB 24-205 framework. The current scheduled date is January 1, 2027, and the current law is framed around covered ADMT documentation, notice, records, correction, and human-review rights.Colorado SB 26-189, retrieved 2026-05-31
Connecticut moved from pending SB 5 tracking to enacted Public Act 26-15 plus Public Act 26-100 revisionsThe near-term private-sector trigger is narrower than the original SB 5 watchlist: generative-AI subscription disclosures and AI-related layoff notices begin October 1, 2026; AEDT duties apply to covered deployments on or after October 1, 2027.PA 26-15 and PA 26-100, retrieved 2026-05-31
California SB 942 is now shown as an August 2, 2026 covered-provider regime rather than a blanket January 1, 2026 lawCalifornia still has two January 1, 2026 AI laws in the Atlas - AB 2013 and SB 53 - but SB 942's Chapter 25 operative date is August 2, 2026, with later AB 853 duties.California BPC Chapter 25, retrieved 2026-05-31

AI compliance calendar: state trigger dates

The following consolidates every operative and scheduled compliance trigger tracked in the Atlas into a single chronological view. Each date reflects the primary-source retrieval cited in the jurisdiction table above.

Effective / trigger dateJurisdiction and trigger2026 status
July 5, 2023NYC Local Law 144 - AEDT bias-audit and candidate-notice enforcement (DCWP)In force
March 18, 2024Washington SB 5838 - AI Task Force study and reporting (not a direct private-sector duty)In force
Amended 2025Utah AI Policy Act (SB 149) - generative-AI disclosure and mental-health-chatbot rules, updated by SB 226 / HB 452In force
January 1, 2026Texas TRAIGA (HB 149); Illinois HB 3773; California AB 2013; California SB 53In force
August 2, 2026California SB 942 - AI Transparency Act covered-provider dutiesScheduled
October 1, 2026Connecticut PA 26-15 / PA 26-100 - generative-AI subscription disclosures and AI-related layoff noticesScheduled
January 1, 2027Colorado SB 26-189 - covered automated-decision-making-technology regimeScheduled
October 1, 2027Connecticut - AEDT duties for covered deploymentsScheduled
2027-2028California AB 853 - platform, hosting, and capture-device provenance duties phase-inScheduled

Florida's narrow deepfake and political-advertising statutes (HB 919 and Fla. Stat. § 836.13) are already in force but are triggered by specific conduct rather than a single statewide effective date.

State laws currently in force or scheduled

The Atlas tracks the following enacted, scheduled, or operative AI-specific laws and enactments:

  • Colorado Artificial Intelligence Act / SB 26-189 ADMT regime - Colorado's 2024 SB 24-205 framework has been repealed and reenacted by SB 26-189 as a narrower automated-decision-making-technology regime scheduled for January 1, 2027.
  • Texas Responsible Artificial Intelligence Governance Act (HB 149, TRAIGA) - broad disclosure and discrimination prohibitions, effective January 1, 2026, with tiered civil penalties under § 552.105.
  • NYC Local Law 144 - automated employment decision tools (AEDTs) bias audit + disclosure regime, in force since 2023.
  • Illinois HB 3773 - amends the Illinois Human Rights Act to make AI-driven employment discrimination a civil rights violation, effective January 1, 2026.
  • Utah AI Policy Act (SB 149, amended by 2025 SB 226/HB 452/SB 332) - generative-AI disclosure and mental-health-chatbot rules with several provisions updated in 2025.
  • California AB 2013 and SB 53 - January 1, 2026 laws covering GenAI training-data documentation and frontier-model safety / transparency; SB 942 becomes operative for covered providers on August 2, 2026.
  • Connecticut PA 26-15 / PA 26-100 - enacted but phased online-safety and AI package; October 1, 2026 is the first major private-sector AI trigger, with AEDT duties later in 2027.
  • Washington SB 5838 - Washington State AI Task Force enabling act, effective March 18, 2024; it creates study and reporting structures rather than direct private-sector compliance duties.
  • Florida AI laws - narrow enacted statutes covering AI in political advertising and altered sexual depictions, plus monitored 2026-session proposals.

Pending and defeated state laws

Compliance teams should also track:

  • Virginia HB 2094 - comprehensive AI law modeled on Colorado, vetoed by Governor Youngkin in 2025; expected to be reintroduced.
  • New Jersey A 3854 - hiring AI bias audit bill modeled on NYC LL 144.

Comprehensive AI laws vs narrow AI laws

Only a subset of state AI measures operate like broad AI governance statutes. Texas is currently the broadest in-force comprehensive state model in the Atlas. Colorado remains a major scheduled model, but SB 26-189 is narrower than the original SB 24-205 high-risk-AI framework and is centered on covered automated decision-making technology used for consequential decisions. California's 2026 AI laws are narrower but high-impact for GenAI and frontier-model developers. NYC and Illinois focus on employment decision tools. Florida focuses on specific deepfake contexts. Washington is a task-force law, not an operational compliance rule for private companies.

This distinction matters because an AI inventory should not apply a single checklist to every jurisdiction. A hiring model may need NYC LL 144 and Illinois controls but not California SB 53. A frontier-model developer may need California SB 53 and AB 2013 controls even when it has no Colorado deployer workflow. A political-advertising or non-consensual intimate-image workflow in Florida may trigger Florida-specific evidence and takedown controls without triggering a Colorado-style impact assessment.

Federal layer

Federal voluntary frameworks supplement state laws and often serve as the substantive control framework:

  • NIST AI Risk Management Framework (AI RMF 1.0 + GenAI Profile)
  • ISO/IEC 42001:2023 - certifiable AI management system standard
  • December 11, 2025 Executive Order "Ensuring a National Policy Framework for Artificial Intelligence" - see the news log for ongoing developments

How obligations differ

Broad AI laws tracked here often split obligations between developers and deployers:

  • Developers create or substantially modify AI systems; they typically owe documentation, disclosure to deployers, and bias-mitigation duties
  • Deployers put AI systems into use for consequential decisions; they typically owe consumer disclosure, post-deployment monitoring, records, and the bulk of penalty exposure where a state law assigns direct deployer duties

See the deployer-vs-developer pillar for a detailed walk-through.

Industries with the heaviest exposure

  • HR & hiring - covered by NYC LL 144, Illinois HB 3773, NJ A 3854 (proposed), and the employment scope of Colorado/Texas
  • Healthcare - covered by Colorado, Utah (regulated occupations and mental-health chatbots), and overlapping HIPAA/FDA AI guidance; use the HIPAA compliance for AI guide when PHI or ePHI enters an AI workflow
  • Financial services - covered by Colorado credit/lending applicability, Texas TRAIGA, and federal CFPB guidance
  • Insurance - covered by Colorado underwriting applicability, plus state insurance regulators

Multi-state compliance strategy

  1. Adopt a federal framework as the control baseline - NIST AI RMF or ISO/IEC 42001. Both substantially support every state-law obligation tracked here.
  2. Build a per-jurisdiction registry of obligations - use the Compliance Checker tool to scope.
  3. Classify each state AI law by legal shape before assigning controls - comprehensive AI governance statute, ADMT / consequential-decision law, employment AEDT law, GenAI provenance law, frontier-model law, sector-specific law, or watchlist item.
  4. Keep impact-assessment evidence for consequential-decision systems - even where current Colorado SB 26-189 is more documentation- and notice-centered than SB 24-205, the Impact Assessment Generator remains useful evidence for Colorado-style, NYC, Illinois, Utah, and framework-based reviews.
  5. Document obligations satisfied vs gaps in a single AI compliance framework register, refreshed annually, with ownership and escalation paths defined in the AI governance guide.
  6. Monitor news - federal preemption activity in late 2025 and 2026 may affect state-law enforceability.

Frequently asked questions

How many US states have AI laws in 2026?

The Atlas tracks 13 AI-law records across 11 state and municipal jurisdictions. Nine jurisdictions - Colorado, Texas, New York City, Illinois, Utah, California, Florida, Washington, and Connecticut - have enacted or scheduled AI-specific statutes, while Virginia (vetoed) and New Jersey (proposed) remain on the watchlist. There is no comprehensive federal AI law as of July 1, 2026.

Which states have comprehensive AI governance laws?

Texas is the broadest in-force comprehensive model under the Texas Responsible Artificial Intelligence Governance Act (HB 149), effective January 1, 2026. Colorado's SB 26-189 is a major scheduled model for January 1, 2027, but it is narrower than the repealed SB 24-205 high-risk-AI framework and is centered on covered automated decision-making technology. California's 2026 laws are narrower but high-impact for generative-AI and frontier-model developers.

When does the Colorado AI Act take effect?

Colorado's SB 24-205 framework was repealed and reenacted by SB 26-189, which became law on May 14, 2026. The covered automated-decision-making-technology regime is scheduled to take effect January 1, 2027, per Colorado SB 26-189 (retrieved 2026-05-31). Compliance teams should no longer treat June 30, 2026 as the operative date for the old framework.

Which states regulate AI in hiring?

Employment-focused AI rules apply in New York City (Local Law 144 AEDT bias audit and disclosure, in force since 2023) and Illinois (HB 3773, effective January 1, 2026, making AI-driven employment discrimination a civil-rights violation). New Jersey A 3854 is a proposed NYC-style bias-audit bill. Colorado and Texas also reach employment decisions within their broader AI statutes.

Is there a federal AI law in the United States?

No. As of July 1, 2026, the United States has no single comprehensive federal AI statute. AI compliance is governed by a patchwork of state and municipal laws plus voluntary federal frameworks - the NIST AI Risk Management Framework and ISO/IEC 42001. The December 11, 2025 Executive Order "Ensuring a National Policy Framework for Artificial Intelligence" may affect state-law enforceability; see the news log.

What's next

The state AI legislative pipeline shows continued activity. Track the news log for enactments, court rulings, enforcement actions, and guidance releases. Use the per-law detail pages for substantive obligations and the framework hubs for control mappings.

Related reading

Continue with the frameworks, laws, and companion guides most relevant to this topic.

  • Colorado AI Act — the first comprehensive US state AI law and its deployer duties.
  • Texas TRAIGA — Texas Responsible AI Governance Act obligations and scope.
  • NIST AI Risk Management Framework — the federal voluntary framework most state laws reference.
  • NIST AI RMF Playbook — turn the framework into suggested actions for state-law evidence files.
  • Federal vs state AI law — how the federal and state layers interact and where they conflict.

Last reviewed July 1, 2026. Reviewed by the AI Compliance Atlas editorial process against primary sources. Source selection, retrieval dates, and update rules are documented in the Atlas methodology.

Legal disclaimer

This content is informational only and does not constitute legal advice. Laws change frequently and vary by jurisdiction. Consult qualified legal counsel before making compliance decisions. Information accuracy not guaranteed as of any specific date.