AccuroAI
Products
What We Do
Solutions
Company
Resources
Book a demo
← Blog·AI Compliance6 min read

US State AI Laws: Which Ones Actually Fall on You

Four state AI laws took effect on 1 January 2026 and a fifth arrives in 2027. For most enterprises three of the five impose no direct obligation, and the question that sorts them is whether you develop AI or deploy it. Colorado is also the law most published guidance still describes incorrectly.

S
Sofia Reyes
Head of Compliance
Oct 6, 2026

Four state AI laws took effect on 1 January 2026. A fifth arrives on 1 January 2027. For most enterprises, three of those five impose no direct obligation at all, and working out which three is the entire exercise.

The question that sorts them is not which state you operate in. It is whether you develop AI systems or deploy them. Almost every piece of state AI law written so far picks one of those two parties and ignores the other, and the coverage that lists these statutes side by side rarely says which is which.

This tracker is organized around that split. We maintain it the way we maintain the EU AI Act enforcement tracker, which means the dates are checked against primary sources and the page changes when the law does.

What is in force right now

LawStateIn forceFalls onEnforced by
TRAIGA (HB 149)Texas1 Jan 2026Developers and deployers, intent-basedAttorney General, no private right of action
SB 53, Transparency in Frontier AI ActCalifornia1 Jan 2026Frontier model developers onlyAttorney General
AB 2013, training data transparencyCalifornia1 Jan 2026Generative AI developers onlyAttorney General
HB 3773, AI in employmentIllinois1 Jan 2026Employers using AI in employment decisionsIllinois Department of Human Rights
SB 26-189, automated decision-makingColorado1 Jan 2027Developers and deployers of consequential ADMTAttorney General, no private right of action

Read the fourth column. Two of the five are developer-only, and if you buy AI rather than train it, they are somebody else's problem.

California SB 53 and AB 2013: not about you, probably

SB 53 covers frontier developers, defined by compute: models trained using more than 10 to the 26th floating-point operations. That threshold is deliberately set at the frontier. Developers must publish risk frameworks, report safety incidents within 15 days, and protect whistleblowers, and those above $500 million in annual revenue carry enhanced duties with penalties reaching $1 million per violation.

The number of organizations training models at that scale is small and you know whether you are one of them. Fine-tuning an existing model does not put you there.

AB 2013 is broader but still developer-facing. Anyone who develops or substantially modifies a generative AI system made publicly available in California must post a disclosure about the training data: sources, whether copyrighted material was included, whether personal information was included. The disclosure goes up before the system is released and gets updated on substantial modification.

The words that catch enterprises are "substantially modifies" and "publicly available." A company that fine-tunes an open-weights model and ships it in a customer-facing product has a defensible argument that it is a developer under AB 2013. A company that uses a vendor's API does not become one. If you are anywhere near that line, it is a question for counsel rather than for a blog table.

Where both laws do touch ordinary enterprises is procurement. These disclosures are now public artifacts for a lot of models you buy, which means your vendor assessment can cite a published training-data disclosure instead of asking the vendor to answer a questionnaire about it. That is a small upgrade to diligence and it is free.

Illinois HB 3773: the one most enterprises actually owe

This is the quiet one, and it is the one with the broadest reach.

HB 3773 amends the Illinois Human Rights Act so that AI use in employment decisions falls inside existing civil rights enforcement. Employers may not use AI in a way that has a discriminatory effect on protected classes, and must give notice when AI is used in employment decisions.

Three features make this different from the others. It covers deployers, not developers. It carries no intent requirement, so discriminatory effect is enough. And it runs through an established enforcement body with existing procedures and an existing complaint pipeline, rather than a new AI regulator still writing its guidance.

Any company with Illinois employees that uses AI anywhere in hiring, promotion, discipline or termination owes this one. Resume screening, interview scoring, performance analytics and scheduling tools all plausibly qualify, including tools your HR team adopted without telling security. The notice requirement alone means you need to know which tools are in that path, which is an inventory problem before it is a compliance problem.

Texas TRAIGA: narrow prohibitions, useful safe harbor

TRAIGA's prohibitions are intent-based, which puts most ordinary commercial deployment outside them. Penalties run to $200,000 for uncurable violations with a 60-day cure period, the Attorney General has exclusive enforcement, and there is no private right of action.

The provision worth reading is Section 552.105(e), which shields a defendant who discovers a violation through feedback, testing, state agency guidelines, or an internal review process run under substantial compliance with a recognized AI risk framework. The statute names NIST's Generative AI Profile specifically. The trigger is self-discovery rather than mere compliance, which has consequences for what you need to be able to detect and prove.

We pulled that provision apart in the TRAIGA safe harbor piece, including the drafting ambiguity in subparagraph (D) and why reasonable readings differ.

Colorado: the law everyone still describes incorrectly

Colorado SB 24-205, passed in 2024, was the first broad US state AI law and the model everyone expected other states to copy. It imposed a duty of reasonable care, annual algorithmic impact assessments, and risk management program obligations on developers and deployers of high-risk AI.

It never took effect.

Governor Polis signed SB 26-189 on 14 May 2026, which repeals SB 24-205 and replaces its text in the Colorado Revised Statutes. The replacement is narrower and differently shaped. Gone are the duty of care, the annual impact assessments and the risk management program requirement. What remains is a transparency and consumer-rights regime around consequential automated decision-making: notice before use, an explanation within 30 days of an adverse outcome, meaningful human review, and developer documentation. It takes effect 1 January 2027, with the Attorney General as sole enforcer and no private right of action.

A good deal of published guidance still describes Colorado obligations that no longer exist. If your compliance plan contains a line item for Colorado algorithmic impact assessments, delete it and replace it with notice, explanation and human review.

The human review requirement is the one to start on, because meaningful review is a staffing and workflow commitment rather than a document. A review that rubber-stamps is not meaningful, and showing it was meaningful means showing what the reviewer saw and what they changed.

What the pattern tells you

Colorado's retreat from the impact-assessment model, Texas passing a cut-down version of the same model, and the two California laws aiming at developers rather than deployers all point the same way. US states are converging on transparency, notice and explanation, and away from mandated risk-management paperwork.

That is close to the opposite of the EU approach, and it changes what you build. EU AI Act conformity work is document-heavy and front-loaded. The emerging US pattern is disclosure-heavy and continuous: you have to tell people AI was involved, explain adverse outcomes within a deadline, and show a human was genuinely in the loop.

Four capabilities cover the current US surface:

  • An inventory that includes tools nobody procured, because the Illinois notice duty and the Colorado explanation duty both attach to systems in a decision path, and HR adopts software without a purchase order.
  • A record of human review that shows what the reviewer was shown and what they did, not merely that an approval field was set.
  • Adverse-outcome traceability, so a Colorado explanation can be produced in 30 days rather than reconstructed.
  • Self-discovery with a timestamped trail, which is the Texas safe harbor and is useful everywhere else.

None of those are state-specific. Build them once.

What we are watching

Federal preemption is the open question. Proposals to restrict state AI regulation have been active through 2026 and none has settled the matter, so the working assumption is that the state patchwork persists and grows. We will update this page as statutes take effect or change rather than adding a new post each time, which is how the EU tracker has worked.

Two housekeeping notes. Dates and section numbers here are checked against primary sources, and where published summaries disagree with the statutory text we follow the text. This is not legal advice, and the developer-versus-deployer line in particular is a fact-specific question for counsel when you are near it.

For the policy document most of these laws assume you already maintain, our AI acceptable use policy template is a starting point, and the AI compliance hub collects the framework-level material.

See AccuroAI in action.
30-minute demo tailored to your top AI risk.
Book a demo
More from the blog
See AccuroAI in action.

Book a 30-minute demo and see how security teams use AccuroAI to discover, govern, and protect every AI asset across their organization.

Book a demoRun the free assessment

15 enterprises secured · under 38ms p99 · live on your own estate in 72 hours