US State AI Law Tracker: What Compliance Teams Must Know Now

Share Article

Table of Contents

State lawmakers introduced 1,561 AI-related bills across 45 states in the first quarter of 2026 alone, already surpassing every bill introduced in all of 2024, according to MultiState‘s legislative tracker. For a compliance team building a program around Colorado’s Automated Decision-Making Technology (ADMT) Act, Texas’s TRAIGA, or California’s stacked privacy and employment rules, that pace is the whole problem. A control built for one statute’s language can be obsolete before the ink dries, as Colorado proved in May 2026 when it repealed its own landmark AI law months before that law’s delayed effective date. This tracker sets out where each major state law actually stands today, and how to map one governance program across all of them without rebuilding it every legislative session.

The Patchwork Is the Point, Not a Side Effect

Congress has not passed comprehensive AI legislation. The closest it has come is the TAKE IT DOWN Act, which addresses non-consensual intimate imagery, including AI-generated deepfakes, and stops well short of a general AI governance statute. Into that vacuum, states have moved fast: in 2025, all 50 states introduced at least one AI-related bill for the first time, and 145 of those bills became law, according to MultiState. Some states are legislating comprehensive risk-based regimes. Others are amending existing employment, privacy, or consumer protection statutes to reach AI use cases. A handful are doing both at once.

This matters operationally because a single AI system, say a resume-screening tool used by a national employer, can trigger obligations under Illinois’s amended Human Rights Act, New York City’s Local Law 144, California’s Fair Employment and Housing Act rules, and eventually Colorado’s ADMT Act, each with its own notice language, recordkeeping period, and review process. Treating each as a one-off compliance project multiplies work that a single AI systems inventory, tagged by jurisdiction and use case, can absorb once.

Colorado: The Law That Was Rewritten Before It Took Effect

Colorado’s original AI Act, SB 24-205, was signed in May 2024 as the first comprehensive US state law targeting “high-risk artificial intelligence systems.” It built an EU-style architecture: classify a system as high risk, then require a risk management program, annual impact assessments, and a duty of care to prevent algorithmic discrimination. Its effective date slipped twice, first to February 2026 and then, via SB 25B-004, to June 30, 2026.

It never reached that date intact. In April 2026, Elon Musk’s xAI sued Colorado’s attorney general challenging the law’s constitutionality, and the US Department of Justice intervened on xAI’s side on April 24, 2026, the first time the federal government sought to invalidate a state AI law. A federal court stayed enforcement on April 27, 2026, and Colorado’s legislature responded by rewriting the statute in a matter of weeks. Governor Polis signed the replacement, SB 26-189, on May 14, 2026, repealing SB 24-205 in its entirety.

The replacement, the Automated Decision-Making Technology Act, drops the “high-risk AI system” classification and the algorithmic discrimination duty of care that defined the original law. Gone with it: mandatory risk management programs aligned to NIST AI RMF or ISO 42001, annual impact assessments, and self-reporting of harms to the attorney general, according to Buchalter’s analysis. In their place, SB 26-189 regulates “covered ADMT,” any technology that processes personal data and materially influences a consequential decision about employment, housing, credit, insurance, health care, education, or essential government services. Deployers must give consumers pre-use notice, explain adverse outcomes within 30 days, and offer meaningful human review; developers must hand deployers technical documentation describing intended use, training data categories, and known limitations.

None of it is enforced yet. The court-ordered stay explicitly covers legislation “replacing or amending” SB 24-205, which includes SB 26-189, and Colorado’s attorney general has said he will not enforce either law until interpretive rulemaking concludes. The AG’s office opened a pre-rulemaking comment period on the ADMT Act and a companion Chatbot Safety Act running through July 13, 2026. For compliance teams, the practical read is that Colorado’s substantive January 1, 2027 deadline is real enough to plan for, but the enforcement timeline underneath it is still moving.

Organizations operating in Colorado should prepare for Automated Decision Making Technology requirements with the Colorado AI Act compliance checklist

Texas TRAIGA: A Narrower Model Built Around Banned Uses

Texas took a different path. TRAIGA, signed by Governor Abbott in June 2025 and effective January 1, 2026, was originally drafted with a broader high-risk AI impact assessment regime similar to Colorado’s, but that piece was cut from the final bill. What remains is a short, specific list of prohibited uses: developing or deploying AI intended to incite self-harm or criminal activity, AI that generates child sexual abuse material or non-consensual deepfake pornography, AI that impersonates a minor in explicit conversation, and government social-scoring systems. Texas state agencies also have to disclose their AI use to consumers.

This is a meaningfully lighter compliance lift than Colorado’s original framework, and it is enforced exclusively by the Texas Attorney General through civil penalties, with no private right of action. A GRC team that already screens for prohibited-use categories under an internal AI acceptable-use policy is largely covering TRAIGA’s substance already. The gap most teams miss is the state-agency disclosure requirement, which applies even to routine chatbot or automation deployments inside Texas government contracts.

California’s Three-Law Stack: TFAIA, FEHA and CPPA’s ADMT Rules

No state has more moving parts than California, because California is regulating AI through three separate legal channels at once rather than a single AI-specific statute.

The Transparency in Frontier Artificial Intelligence Act (TFAIA, SB 53), enacted September 29, 2025 and effective January 1, 2026, targets developers of frontier foundation models deemed to pose a critical risk, requiring published safety and security protocols and catastrophic-risk testing. This is a model-developer obligation, relevant mainly to organizations building or fine-tuning large foundation models rather than typical enterprise deployers.

Separately, amendments to the Fair Employment and Housing Act (FEHA) took effect in October 2025, prohibiting discriminatory use of automated decision systems in hiring and employment and requiring covered employers to retain input data, output scores, and bias-testing results for at least four years.

The California Privacy Protection Agency’s ADMT regulations, approved September 23, 2025, add a third layer under the CCPA: businesses meeting CCPA thresholds must give pre-use notice and honor opt-out and access rights when ADMT is used to make a “significant decision” about a consumer, such as denial of housing, credit, employment, healthcare, or education. Risk assessment obligations under these rules began January 1, 2026, with ADMT-specific significant-decision duties phasing in by January 1, 2027. A business can be squarely inside FEHA’s employment rules and the CPPA’s consumer-facing ADMT rules simultaneously for the same hiring tool.

The Employment-AI Front: Illinois and NYC Local Law 144

Illinois HB 3773 took effect January 1, 2026, amending the Illinois Human Rights Act to reach AI use in employment decisions, including hiring, promotion, and termination, and to make discriminatory outcomes from AI tools actionable under existing state civil rights enforcement.

New York City’s Local Law 144, in force since July 2023, requires employers using automated employment decision tools on NYC-based candidates to complete an independent bias audit within the prior year and publish a summary of the results. It is the oldest law in this tracker, and also the one whose enforcement gap is best documented: the New York State Comptroller’s December 2, 2025 audit found the city’s Department of Consumer and Worker Protection had done little proactive enforcement since the law took effect, which pushed DCWP to shift toward proactive investigations during 2026. For any employer that concluded Local Law 144 was low-risk because enforcement had been quiet, that conclusion no longer holds.

Utah, New York’s RAISE Act and the Next States to Watch

Utah’s AI Policy Act (SB 149) was the first US law specifically regulating generative AI when it took effect in May 2024, requiring disclosure when consumers interact with generative AI instead of a human. A 2025 amendment narrowed the law’s reach to higher-risk generative AI interactions and introduced a safe harbor, a lighter-touch outcome than Colorado’s trajectory and a reminder that state AI laws move in both directions, not only toward stricter obligations.

New York’s RAISE Act took a similar softening turn. Governor Hochul signed amendments on March 27, 2026 that shifted the law from restricting deployment of models posing an “unreasonable risk of critical harm” toward a transparency and incident-reporting model for frontier model developers, aligning more closely with California’s TFAIA framework, but with a shorter 72-hour incident reporting window and higher civil penalties of up to $1 million for a first violation, according to Cooley.

Washington enacted three narrower laws in 2026: HB 1170 on AI content disclosure, HB 2225 on companion chatbots, and SSB 5886 expanding digital-likeness rights to cover AI-generated likenesses, effective between June 2026 and February 2027. Oregon followed with its own companion-chatbot bill, SB 1546. Beyond these named states, 38 or more states now have at least one narrower AI law on the books, most commonly targeting deepfakes or AI use in elections, per layer3labs’ tracker. None of these rise to Colorado, Texas, or California’s level of obligation, but each adds a jurisdiction-specific disclosure line item worth a single row in an inventory rather than a standalone project.

The Federal Backdrop: A Preemption Push That Hasn’t Landed Yet

Executive Order 14110, the Biden administration’s foundational AI policy order, was rescinded in January 2025 and should not be cited as active federal policy. Since then, federal AI policy has moved in a deregulatory direction: a January 2025 order removing what the administration characterized as innovation barriers, a July 2025 AI Action Plan, a December 2025 AI National Policy Framework, and a March 2026 National AI Legislative Framework that explicitly urges Congress to adopt a “minimally burdensome national standard” preempting state AI laws it considers unduly restrictive, per White & Case’s regulatory tracker.

A June 2026 executive order went further, creating a Department of Justice AI Litigation Task Force specifically to challenge state AI laws in court, an approach already visible in the DOJ’s intervention in the Colorado xAI litigation. None of this amounts to preemption today. Colorado’s ADMT Act, Texas’s TRAIGA, and California’s three-law stack all remain enacted, enforceable state law on their own timelines. The federal posture is a live risk factor for a board-level AI risk report, but it is not yet a reason to stand down on any state-level control.

Mapping State Obligations to ISO/IEC 42001 and NIST AI RMF

The fastest way to stop rebuilding compliance work every legislative session is to stop mapping controls to individual statutes and start mapping them to a framework, then mapping the framework to each statute once. Colorado’s original SB 24-205 made this easy by naming NIST AI RMF and ISO 42001 alignment as an affirmative defense; that specific safe harbor was repealed along with the rest of the law in May 2026, and no enacted state law currently offers an equivalent. That makes the mapping a matter of operational efficiency rather than legal shortcut, but the efficiency case is still strong: most of what these state laws require, an inventory, pre-use notice, human review, developer documentation, and multi-year recordkeeping, already exists as named controls inside ISO/IEC 42001 and NIST AI RMF.

State AI Law Obligations Mapped to ISO/IEC 42001 and NIST AI RMF: State AI Law Obligations Mapped to ISO/IEC 42001 and NIST AI RMF

Common ObligationWhere It Shows UpISO/IEC 42001:2023NIST AI RMF 1.0
AI systems inventoryColorado ADMT Act, California ADMT Regs, Illinois HB 3773Clause 8.1 operational planning and controlMAP 1.1–1.2 (context and categorization)
Pre-use consumer noticeColorado ADMT Act, Utah AI Policy Act, California ADMT RegsClause 7.4 communicationGOVERN 4.1 (transparency policies)
Adverse-outcome explanationColorado ADMT Act (30-day rule), Illinois HB 3773Annex A control on impact communication [VERIFY]MEASURE 2.9 (explainability)
Human review of automated decisionsColorado ADMT Act, California FEHA ADS rulesClause 8.1 human oversight controlsGOVERN 3.2, MANAGE 2.2
Developer-to-deployer documentationColorado ADMT Act, California ADMT RegsClause 8.3 (supplier/third-party requirements)MAP 4.1 (third-party risk mapping)
Bias or discrimination mitigationIllinois HB 3773, NYC Local Law 144, California FEHA ADSAnnex A control on fairness testing [VERIFY]MEASURE 2.11 (fairness and bias)
Recordkeeping (typically 3+ years)Colorado ADMT Act, California ADMT RegsClause 7.5 documented informationGOVERN 1.5 (accountability structures)

The practical payoff shows up when a new state adds a requirement. An ADMT platform that already tags every AI system against NIST AI RMF’s MAP function and ISO 42001’s Clause 8.1 operational controls can typically demonstrate Illinois HB 3773 or Local Law 144 coverage by adding a jurisdiction flag to an existing record, rather than opening a new compliance workstream. Govern365.ai’s AI model registry is built around exactly that structure: each system in the registry carries its ISO 42001 and NIST AI RMF control mappings alongside the specific state and city obligations it triggers, so a Colorado rulemaking change or a new Illinois amendment updates one record instead of a spreadsheet per statute.

Build a consistent AI governance program across every state by implementing the NIST AI Risk Management Framework

Building an AI Systems Inventory That Survives the Next Rewrite

Colorado’s repeal-and-replace sequence is the clearest possible argument for building compliance infrastructure around systems and controls rather than statutory language. A team that spent 2025 building impact assessments keyed precisely to SB 24-205’s defined terms lost most of that work when SB 26-189 replaced the underlying framework. A team that instead maintained a system-level inventory, tagged by use case, jurisdiction, and control family, only had to update the jurisdiction tags.

  1. Inventory every AI and automated decision system in use, including vendor and embedded tools, not just internally built models.
  2. Tag each system by the covered domains it touches: employment, housing, credit, insurance, healthcare, education, or government services.
  3. Map each system’s existing controls to ISO 42001 and NIST AI RMF function areas, so state-specific obligations become jurisdiction tags on top of controls that already exist.
  4. Flag systems that materially influence a decision about a person, since that threshold, not mere AI use, is what triggers most state laws’ substantive duties.
  5. Set a recurring legislative review, quarterly at minimum, given that state AI bill volume is now outpacing every prior year on record.

For board and C-suite reporting, the inventory also answers the question that actually gets asked in the boardroom: not “are we compliant with X statute,” but “do we know where our AI systems create legal exposure, and can we prove it.” Govern365.ai‘s compliance dashboards translate that system-level inventory directly into board-ready reporting, showing which systems carry open obligations under which state law and which are fully mapped to an underlying framework control.

Frequently Asked Questions

Is the Colorado AI Act still in effect?

No. The original Colorado AI Act, SB 24-205, was repealed before its delayed effective date ever arrived. Governor Polis signed its replacement, SB 26-189, on May 14, 2026, creating a narrower Automated Decision-Making Technology Act that takes effect January 1, 2027. Enforcement of both the old and new frameworks is currently stayed pending federal litigation, so treat this as an active compliance target, not a closed matter.

Does Texas TRAIGA require AI impact assessments like Colorado’s original law did?

No. TRAIGA is built around a short list of banned uses, such as AI systems designed to incite self-harm or generate child sexual abuse material, plus disclosure duties for state agencies. It does not impose a broad high-risk-system impact-assessment regime, which makes it meaningfully lighter than Colorado’s original 2024 approach.

What is the difference between California’s ADMT regulations and its FEHA automated decision system rules?

The CPPA’s ADMT regulations amend the California Consumer Privacy Act and apply to businesses meeting CCPA revenue or data-volume thresholds, covering significant decisions about any consumer. California’s amended Fair Employment and Housing Act rules apply specifically to employment decisions and took effect earlier, in October 2025. Many employers are subject to both.

Do any state AI laws still offer a NIST AI RMF or ISO 42001 safe harbor?

Colorado’s original SB 24-205 included an affirmative defense tied to NIST AI RMF or ISO 42001 alignment, but that provision was repealed along with the rest of the statute in May 2026. As of mid-2026, no enacted state AI law provides a comparable framework-based safe harbor, though framework alignment remains the most practical way to operationalize the documentation and human-oversight duties that most states still require.

Has the federal government preempted state AI laws?

Not yet. The Trump administration’s March 2026 National AI Legislative Framework urges Congress to pass a national standard preempting state laws it considers unduly burdensome, and a June 2026 executive order created a DOJ AI Litigation Task Force to challenge state laws in court. Neither action has actually preempted Colorado’s, Texas’s, or California’s AI statutes, which remain in force or on their scheduled timelines.

Which state AI law should a multi-state employer prioritize first?

Start with whichever state law covers your highest-volume automated employment use case today. For most national employers, that means California’s FEHA automated decision system rules and CPPA ADMT regulations plus Illinois HB 3773, since hiring and performance tools are already in force in those states, while Colorado’s ADMT Act still has more than a year before its effective date.

How many AI-related bills have US states introduced in 2026?

State lawmakers introduced 1,561 AI-related bills across 45 states in the first quarter of the 2026 legislative session alone, according to MultiState, already surpassing the 635 bills introduced across all of 2024. That volume is why a status check, not a one-time compliance review, is the right operating model for this area.

Does NYC Local Law 144 still apply if my company is not headquartered in New York?

Yes. Local Law 144 applies based on where the employment decision affects a candidate or employee, not where the employer is headquartered, so any company using an automated employment decision tool to evaluate New York City-based candidates is in scope, and enforcement scrutiny increased in 2026 after a Comptroller audit criticized weak follow-through.

The Bottom Line for Compliance Teams

Colorado’s reversal is the clearest signal yet that state AI law is a moving target, not a settled compliance checklist, and the pace of new bill introductions in 2026 suggests more states will follow with amendments of their own. The organizations handling this well are not the ones racing to comply with each statute’s specific language. They are the ones that built an AI systems inventory mapped to ISO 42001 and NIST AI RMF once, so that a Colorado rulemaking update or a new Illinois amendment becomes a jurisdiction tag rather than a new project. Start by inventorying every system that touches employment, housing, credit, insurance, healthcare, education, or government services, and map it to a framework before the next legislative session adds another state to track.

Start your 14-day free trial of Govern365.ai, by the Global AI Certification Council, to see your AI systems mapped across state law and ISO 42001 or NIST AI RMF controls in one place.

Stay ahead of the curve

Join 5,000+ industry leaders who receive our weekly briefing on AI governance and secure enterprise collaboration.

About the Author

Dr Faiz Rasool

Director at the Global AI Certification Council (GAICC) and PM Training School

Globally certified instructor in ISO/IEC, PMI®, TOGAF®, and Scrum.org disciplines with hands-on experience in ISO/IEC 42001 AI governance across the US, EU, and Asia-Pacific.

Summarize with AI

AI-Powered Data Governance Platform

Secure, Govern, and Collaborate on Sensitive Data—All Within Microsoft 365

Further Reading

Related Insights

eu-ai-act-us-companies-applicability-records-controls

EU AI Act for US Companies: Applicability, Records and Controls

Spending on AI governance platforms is projected to reach $492 million in 2026 and surpass

Read More →
ai-governance-roadmap-mid-market-risk-teams

US AI Governance Roadmap for Mid-Market Risk Teams

Forty-five state legislatures introduced more than 1,561 AI-related bills by March 2026 alone, according to

Read More →
employee-ai-use-policy-template

Employee AI Use Policy Template for ChatGPT, Copilot and Workplace AI Tools

According to a Gartner survey of 2,986 employees, 62% say generative AI has already saved

Read More →

Summarize with AI

Transforming AI Risks into Strategic Assets.

Request a Personalized Demo

Our governance experts will walk you through the platform and help you map out your ISO 42001 or EU AI Act roadmap.