AAI Compliance Atlas
FrameworksState lawsIndustriesToolsNews
GuidesMap my obligations →
AAI Compliance Atlas

Structured, continuously verified reference for US AI compliance — federal frameworks, state laws, and the obligations that connect them.

Atlas

  • Frameworks
  • State laws
  • Industries
  • By role
  • Comparisons

Tools

  • Compliance Checker
  • Penalty Calculator
  • Impact Assessment
  • Vendor Questionnaire

Resources

  • Guides
  • News
  • Blog
  • Methodology

Company

  • About
  • Contact
  • Privacy
  • Terms
© 2026 AI Compliance Atlas. Informational only — not legal advice. Consult qualified counsel before making compliance decisions.Verified Jul 28, 2026
  1. Home/
  2. Roles/
  3. Developer

AI Developer Obligations Under US Law

Developers create, train, or substantially modify AI systems before they reach deployers and end users. The tracked US laws assign developer-specific documentation, transparency, incident-reporting, and prohibited-use duties that remain distinct from deployer obligations.

Governance routing

Use the AI governance guide to assign decision rights, committees, lifecycle gates, and escalation paths before mapping role-specific duties into the AI compliance framework register.

Last verified: 2026-07-23

AI developer duties: law-to-evidence handoff map

As of July 23, 2026, an AI developer compliance record is a versioned evidence package connecting each system to its legal role, intended use, data categories, known limitations, evaluation results, deployment handoff, material changes, and incident history. The four rows below distinguish mandatory state-law duties from the voluntary NIST AI RMF evidence baseline.

Primary sources: Colorado SB 26-189, California SB 53 chaptered text, Texas HB 149 enrolled text, and the NIST AI RMF Core; retrieved 2026-07-23.

TriggerDeveloper dutyEvidence packageRecipient / handoffPrimary source
Covered ADMT provided for consequential decisions in ColoradoBeginning January 1, 2027, provide deployers with intended-use, training-data-category, limitation, appropriate-use, monitoring, and human-review documentation; notify deployers of material updates; retain compliance records for at least three years.Versioned system card, training-data category register, known-limitations register, human-review instructions, deployer delivery receipt, material-change notice log, and retention schedule.Deployer; Colorado Attorney General if compliance is investigatedColorado SB 26-189 enacted summaryretrieved 2026-07-23
Frontier model above California SB 53 thresholdsPublish the required model transparency report and report critical safety incidents. A large frontier developer must also publish and maintain a frontier AI framework and submit required catastrophic-risk assessment summaries.Compute-threshold determination, deployment transparency report, incident triage and reporting log, current frontier AI framework, annual review record, and submitted assessment summaries.Public website, California Office of Emergency Services, and state enforcement authoritiesCalifornia SB 53 chaptered textretrieved 2026-07-23
AI system developed for provision in TexasClassify the developer role under Texas HB 149 and preserve investigation-ready records. In an Attorney General investigation, the requested material can include purpose, intended use, training and input data categories, outputs, performance metrics, known limitations, monitoring, and safeguards.Texas role memo, intended-use statement, data-category inventory, output description, evaluation report, limitations register, monitoring plan, safeguard record, and cure evidence.Texas Attorney General after a complaint and civil investigative demandTexas HB 149 enrolled text, §§ 552.001 and 552.103retrieved 2026-07-23
Voluntary risk-management baseline for a development lifecycleUse NIST AI RMF outcomes to document legal requirements, system context, risks and impacts, testing, incidents, and the decision to proceed, mitigate, monitor, or stop.Legal-requirements map, intended-use and context record, test plan and results, risk register, incident log, model-change decision, and release approval.Internal governance reviewers and deployers requesting assurance evidenceNIST AI RMF Coreretrieved 2026-07-23

Mandatory AI developer reporting is recipient-specific

The tracked laws do not use one interchangeable “developer report.” California SB 53 routes frontier-model transparency and incident material to public and state recipients. Colorado SB 26-189 routes technical documentation and update notices to deployers. Texas HB 149 identifies records the Attorney General may request after a complaint and civil investigative demand. The evidence map preserves the recipient, trigger, and delivery record for each path.

Obligations under US laws

  • documentationColorado Artificial Intelligence ActC.R.S. § 6-1-1702

    On and after January 1, 2027, make available to each deployer of a covered automated decision-making technology (ADMT), in a form understandable to the deployer and protective of trade secrets, a statement of the system's intended and known harmful or inappropriate uses, the categories of data (including personal data) used to train it, its known limitations and risks, instructions for appropriate use, monitoring, and meaningful human review, and the information the deployer needs to satisfy its disclosure duties under § 6-1-1704; developers must also notify deployers of material updates and retain compliance records for at least three years.

    Deadline: from_2027-01-01

  • governanceTexas Responsible Artificial Intelligence Governance Act (TRAIGA)Tex. Bus. & Com. Code § 552.056

    Refrain from developing or deploying AI systems with the intent to engage in unlawful discrimination against protected classes under Texas or federal law.

    Deadline: ongoing

  • governanceTexas Responsible Artificial Intelligence Governance Act (TRAIGA)Tex. Bus. & Com. Code § 552.104, § 552.105

    On receipt of a written notice of alleged violation from the Texas Attorney General, cure the violation within the statutory cure window to avoid tier-1 civil penalties of $10,000–$12,000; uncurable violations and continuing violations escalate to $80,000–$200,000 per violation and $2,000–$40,000 per day under § 552.105.

    Deadline: on_ag_notice

  • transparencyCalifornia AI Transparency ActCal. Bus. & Prof. Code § 22757.2

    Maintain a free AI detection tool allowing users to assess whether image, video, or audio content was created or altered by the covered provider's GenAI system.

    Deadline: from_2026-08-02

  • transparencyCalifornia AI Transparency ActCal. Bus. & Prof. Code § 22757.3

    Offer manifest disclosure options and apply latent provenance disclosures to AI-generated or AI-altered image, video, and audio content when technically feasible and reasonable.

    Deadline: from_2026-08-02

  • transparencyCalifornia Generative AI: Training Data TransparencyCal. Civ. Code § 3111

    Publicly post on the developer's website a high-level summary of training datasets used for any generative AI system or service made available to Californians on or after January 1, 2022.

    Deadline: by_2026-01-01

  • documentationCalifornia Generative AI: Training Data TransparencyCal. Civ. Code § 3111

    Address each statutory element in the dataset summary — sources or owners, how the data furthers the system's purpose, number and types of data points, copyright/trademark/patent or public-domain status, purchased-or-licensed status, presence of personal information or aggregate consumer information, any cleaning or modification, first-use dates, collection time period, and any use of synthetic data generation.

    Deadline: by_2026-01-01

  • transparencyCalifornia Generative AI: Training Data TransparencyCal. Civ. Code § 3110

    Refresh and re-post the public training-data summary before each subsequent public release or substantial modification of a covered generative AI system, so the disclosure stays current rather than ending at the initial January 1, 2026 deadline.

    Deadline: before_each_release

  • governanceTransparency in Frontier Artificial Intelligence Act (TFAIA)Cal. Bus. & Prof. Code § 22757.12

    Publish a written frontier AI safety framework describing how the developer assesses and mitigates catastrophic risks from frontier AI models, with periodic updates.

    Deadline: ongoing

  • transparencyTransparency in Frontier Artificial Intelligence Act (TFAIA)Cal. Bus. & Prof. Code § 22757.12(c)

    Publish a transparency report before or concurrently with deploying a new frontier model; large frontier developers must include summaries of catastrophic-risk assessments and mitigation steps.

    Deadline: before_deployment

  • documentationTransparency in Frontier Artificial Intelligence Act (TFAIA)Cal. Bus. & Prof. Code § 22757.13

    Report critical safety incidents to the California Office of Emergency Services within statutory timeframes.

    Deadline: within_statutory_timeframe

  • governanceTransparency in Frontier Artificial Intelligence Act (TFAIA)Cal. Lab. Code § 1107.1

    Preserve covered-employee whistleblower rights and maintain the required notice and anonymous internal disclosure process for catastrophic-risk reports.

    Deadline: ongoing

  • bias auditNew Jersey A 2726 Automated Employment Decision Tool BillA2726 § 2(a)

    If enacted, an AEDT could not be sold, developed, deployed, used, or offered for sale in New Jersey unless the tool was subject to a bias audit in the past year and the sale included an annual bias-audit service at no additional cost.

    Deadline: proposed_past_year_before_sale_or_use

  • transparencyNew Jersey A 2726 Automated Employment Decision Tool BillA2726 § 2(a)(4)

    If enacted, the AEDT developer would have to implement the recommendations from the most recent bias audit and issue a press release explaining how those recommendations were implemented.

    Deadline: proposed_before_sale_or_use

  • data handlingFlorida AI Legislation (Deepfake and AI Disclosure Laws)Fla. Stat. § 836.13 (HB 757 / Brooke's Law)

    Do not willfully generate, solicit, promote, or possess with intent to promote an altered sexual depiction of an identifiable person without consent, including AI-generated deepfakes. Covered platforms must remove altered sexual depictions and known identical copies within 48 hours of a valid takedown request. Civil exposure includes $10,000 or actual damages for covered violations, plus FDUTPA penalties for takedown failures.

    Deadline: 48_hour_takedown

  • transparencyConnecticut Public Act 26-15 / SB 5 (Online Safety and AI Provisions)Public Act 26-100 § 46 (revising Public Act 26-15 / Sub. SB 5)

    On and after October 1, 2026, a subscription-based provider that creates, codes, or otherwise produces a generative AI system with more than 1,000,000 monthly users and public accessibility to consumers for personal use must provide the generative-AI subscription disclosure required by Public Act 26-100 Section 46 (which replaced the original Public Act 26-15 subscription provisions). The duty is enforced solely by the Attorney General as a Connecticut Unfair Trade Practices Act (CUTPA) violation, with no private right of action.

    Deadline: from_2026-10-01

  • governanceConnecticut Public Act 26-15 / SB 5 (Online Safety and AI Provisions)Public Act 26-15 (Sub. SB 5) — frontier-developer provisions

    On and after January 1, 2027, a large frontier-model developer must establish an anonymous whistleblower reporting channel through which employees and contractors can report critical AI risks. Violations of the frontier-developer whistleblower provisions carry a civil penalty of up to $1,000 per violation plus injunctive and equitable remedies, distinct from the CUTPA/Attorney-General model that governs most other provisions of the Act.

    Deadline: from_2027-01-01

  • consumer rightConnecticut Public Act 26-15 / SB 5 (Online Safety and AI Provisions)Public Act 26-15 (Sub. SB 5) — AI companion provisions

    On and after January 1, 2027, an operator of an AI companion (a system designed to simulate sustained human-like relationships with a user) must implement the Act's chatbot safety provisions, including protections for minors. These operator duties sit within the Act's broader youth online-safety framework and are enforced by the Attorney General as CUTPA violations.

    Deadline: from_2027-01-01

Framework controls

  • governanceNIST AI RMFGOVERN 1-6

    GOVERN function: establish policies, processes, structures, and accountability for AI risk management across the organization, including senior leadership oversight and a risk-based culture.

  • risk assessmentNIST AI RMFMAP 1-5

    MAP function: identify the context, intended uses, stakeholders, and risks of each AI system, including categorization of impacts on individuals, communities, and the organization.

  • risk assessmentNIST AI RMFMEASURE 1-4

    MEASURE function: assess, analyze, and monitor AI risks using both quantitative and qualitative methods, including bias evaluation, robustness testing, and explainability assessments.

  • governanceNIST AI RMFMANAGE 1-4

    MANAGE function: prioritize and treat identified risks, allocate resources, and implement risk response strategies including mitigation, transfer, acceptance, or avoidance.

  • governanceISO/IEC 42001Clauses 4-5

    Establish, implement, maintain, and continually improve an AI management system (AIMS) covering policies, leadership commitment, roles, and integration with other management systems.

  • risk assessmentISO/IEC 42001Clause 6 + Annex A.5

    Conduct AI system impact assessments and risk assessments addressing intended uses, deployment context, affected stakeholders, and mitigation of identified risks per Annex A.5 controls.

  • documentationISO/IEC 42001Clause 8 + Annex A.6

    Maintain documentation throughout the AI system lifecycle including data management, system development, verification and validation, and deployment per Annex A.6 controls.

FAQ

AI developer responsibility and reporting FAQ

What are AI developers responsible for under tracked US AI laws?

Developer duties are law- and system-specific. Colorado SB 26-189 assigns technical-documentation, update-notice, and record-retention duties for covered ADMTs beginning January 1, 2027. California SB 53 assigns transparency, safety-framework, and incident-reporting duties to qualifying frontier developers. Texas HB 149 applies prohibited-use rules and exposes developers to specified Attorney General investigative requests.

Sources: Colorado SB 26-189 · California SB 53 · Texas HB 149; retrieved 2026-07-23.

Can AI developers be held liable under the tracked state laws?

The answer depends on the statute and conduct. Texas HB 149 gives the Attorney General exclusive enforcement authority, provides no private right of action under the chapter, and authorizes civil penalties after its cure process. Colorado SB 26-189 creates no new private right of action but addresses fault allocation in civil actions alleging unlawful discrimination under existing law. This page does not convert those provisions into a general liability rule.

Sources: Texas HB 149, §§ 552.101–552.105 · Colorado SB 26-189; retrieved 2026-07-23.

What mandatory AI developer reporting appears in the tracked laws?

The tracked duties use different reporting paths rather than one universal filing. California SB 53 requires qualifying frontier developers to publish transparency material and report critical safety incidents. Colorado SB 26-189 requires covered-ADMT documentation and material-update notices to deployers beginning January 1, 2027. Texas HB 149 permits specified documentation requests during an Attorney General investigation; that request process is not described as a routine developer filing.

Sources: California SB 53 · Colorado SB 26-189 · Texas HB 149, § 552.103; retrieved 2026-07-23.

Run AI risk and impact assessments faster with Credo AI

partner link

Specialized AI governance platform built around the NIST AI RMF and EU AI Act. Bias auditing, model registry, policy automation.

Get a Credo AI demo →
Legal disclaimer

This content is informational only and does not constitute legal advice. Laws change frequently and vary by jurisdiction. Consult qualified legal counsel before making compliance decisions. Information accuracy not guaranteed as of any specific date.

We may receive referral commissions from recommended compliance tools. Recommendations are based on product fit and not on commission size. Links marked “partner link” include a tracked redirect.