US State AI Laws: The 2026 Compliance Guide
US state AI laws are a patchwork of overlapping obligations that took effect throughout 2026. Texas's TRAIGA and California's SB 53 and AB 2013 became effective January 1, 2026, while Colorado repealed its original AI Act and replaced it with a narrower automated-decision law arriving in 2027. If you deploy AI that influences consequential decisions, you likely have obligations in at least one state today.
- Texas TRAIGA and California SB 53 / AB 2013 took effect January 1, 2026.
- Colorado repealed its 2024 AI Act and replaced it with SB 26-189, a narrower automated-decision law effective 2027.
- Substantial compliance with the NIST AI RMF earns enforcement safe harbor in Texas — one framework covers most state duties.
- 2,000+ state AI bills are in play; re-check the landscape quarterly.
Which state AI laws are in effect in 2026?
| State / Law | Status | Core obligations |
|---|---|---|
| Texas — TRAIGA (HB 149) | Effective Jan 1, 2026 | Intent-based prohibitions (manipulation, unlawful discrimination); NIST AI RMF safe harbor |
| California — SB 53 | Effective Jan 1, 2026 | Frontier-model developers: publish risk frameworks, report safety incidents, whistleblower protections |
| California — AB 2013 | Effective Jan 1, 2026 | Generative AI developers: publish training-data summaries |
| Colorado — SB 26-189 | Effective 2027 (replaced 2024 AI Act) | ADMT consumer notices, 30-day adverse-outcome explanations, human review rights |
| Illinois — HB 3773 | Effective Jan 1, 2026 | No AI-driven employment discrimination; notice when AI is used in employment decisions |
| Utah — AI Policy Act | In effect | Disclose generative AI interaction to consumers, strongest in regulated occupations |
| NYC — Local Law 144 | In effect since 2023 | Annual bias audits and candidate notices for automated hiring tools |
More than 2,000 AI-related bills have been introduced across the states, and a 2026 federal executive order signaled preemption pressure — treat this table as a floor, not a ceiling, and re-check it quarterly.
The three regulatory models states are using
1. Intent-based liability (Texas). TRAIGA prohibits developing or deploying AI with the intent to manipulate, discriminate unlawfully, or infringe rights — and grants organizations substantially complying with the NIST AI RMF protection against enforcement. Documented RMF alignment is now a legal defense in Texas, not just good practice.
2. Frontier-model transparency (California). SB 53 targets the largest developers with publication and incident-reporting duties; AB 2013 applies far more broadly — any developer of a generative AI system offered in California must publish a training-data summary. Most B2B software with embedded generative AI should assume AB 2013 relevance.
3. Consequential-decision protection (Colorado, Illinois, NYC). Colorado's SB 26-189 dropped the original act's risk-program mandates in favor of consumer rights: pre-use notice, an explanation within 30 days of an adverse outcome, and meaningful human review. Illinois and NYC focus on employment.
A five-step program that satisfies all of them
- Inventory every AI system — including third-party AI features inside SaaS tools — and classify by whether it influences consequential decisions.
- Map systems to jurisdictions. A hiring tool used for remote roles can trigger Illinois, NYC, and Colorado obligations simultaneously.
- Adopt NIST AI RMF as the backbone. Texas rewards it, Colorado's duties map to it, and it aligns with ISO/IEC 42001.
- Build the notice and explanation machinery once — pre-use notices, adverse-outcome explanations, human-review escalation — as reusable controls.
- Monitor legislative change quarterly. Colorado's repeal-and-replace shows how fast these laws mutate.
How Compyl helps
Compyl maps a single AI-governance control library to NIST AI RMF, ISO/IEC 42001, the EU AI Act, and state-law requirements — evidence collected once satisfies every framework. The platform's AI system inventory, policy management, and automated evidence collection turn state-law tracking into continuous compliance. See the AI Governance Implementation Guide for the full program blueprint.
Frequently asked questions
Does TRAIGA apply to companies outside Texas?
Is the original Colorado AI Act still law?
Do state AI laws apply to internal-only AI use?
What single framework covers the most state requirements?
Could federal law preempt state AI laws?
Operationalize state AI law compliance
Compyl unifies governance, risk, compliance and audit on one source of truth — built by CISOs, with a human approving every consequential decision.
About this guide. By Compyl Research. This is general information, not legal advice — consult counsel for your specific obligations. Compyl is an AI-powered, agentic GRC platform built by CISOs.