Home / Resources / Frameworks / US State AI Laws
US State AI Laws: a patchwork of obligations with no federal floor
With no comprehensive federal AI legislation in place, US states are writing the rules. Over 1,500 AI bills have been introduced across 45 states, and the laws already enacted in Colorado, Texas, California, Illinois, and Connecticut each carry distinct obligations, timelines, and penalty structures. Organizations deploying AI agents must comply with every state whose residents they touch.
Why state AI laws matter now
The United States has no comprehensive federal AI law. The only standalone federal AI statute, the TAKE IT DOWN Act signed in May 2025, addresses a narrow scope. President Trump revoked Biden's Executive Order 14110 on January 20, 2025, and subsequent executive orders, including EO 14365 (December 2025) and the March 2026 National Policy Framework, urge preemption of state AI regulation. However, executive orders cannot overturn existing state law, and no preemption legislation has passed. The practical result: state laws are the binding compliance baseline for any organization deploying AI in the United States.
1,561
AI bills introduced across 45 states by March 2026
MultiState Associates, March 2026
145
State AI bills enacted during the 2025 legislative cycle
National Conference of State Legislatures, 2025
5
States with comprehensive or targeted AI laws already signed into law (CO, TX, CA, IL, CT)
Legislative tracking, 2024 to 2026
Who must comply
AI developers and vendors
Companies that build or distribute AI systems serving users in any US state. Colorado requires developers to provide technical documentation to deployers. California imposes safety framework and transparency reporting obligations on frontier model developers.
Colorado SB 26-189 · California SB 53
Deployers using AI in consequential decisions
Organizations that use automated decision-making tools (ADMT) in areas such as credit, housing, insurance, employment, or education. Colorado requires clear notice before deployment, explanation of outcomes within 30 days, and designation of trained personnel for human review.
Colorado SB 26-189 · Connecticut SB 5
Employers using AI in hiring
Any employer using AI systems in employment decisions. Illinois HB 3773, which amends the Illinois Human Rights Act, requires notice when AI influences hiring and imposes strict liability for discriminatory outcomes. It also grants a private right of action, unlike most state AI laws.
Illinois HB 3773
Frontier model developers
Developers of large-scale AI models trained with computing power at or above 10^26 FLOPs. Those with $500M or more in annual revenue must publish annual safety frameworks. All frontier developers must file transparency reports before deployment.
California SB 53
Government agencies
Texas TRAIGA imposes disclosure requirements on government agencies using AI systems. Prohibited uses include government social scoring, systems designed for intentional discrimination, and manipulative AI deployments.
Texas HB 149 (TRAIGA)
Healthcare providers
Healthcare organizations using AI for clinical or operational decisions face disclosure obligations under Texas TRAIGA. These requirements sit alongside existing HIPAA and state health privacy mandates, creating layered compliance demands.
Texas HB 149 (TRAIGA)
State-by-state requirements
Colorado SB 26-189: disclosure, human review, and three-year record retention for automated consequential decisions
Colorado SB 26-189 (signed May 14, 2026, effective January 1, 2027) Replaces the original SB 24-205, removing the duty of care, impact assessments, and risk management programs. Deployers must provide clear and conspicuous notice before using automated decision-making technology (ADMT) in consequential decisions covering employment, housing, lending, healthcare, education, and government services. Within 30 days of an adverse outcome, deployers must supply understandable descriptions of the outcome and the role ADMT played. Trained individuals must be designated for human review and override of automated decisions. Developers must provide deployers with technical documentation covering intended uses, known risks, system limitations, and instructions for meaningful human review. Both developers and deployers must retain compliance records for at least three years. Consumer rights include data access, correction, and human review of adverse decisions. A 60-day cure period applies through January 1, 2028.
→ Nexovern's runtime evidence captures the full decision chain for every AI agent session, supporting Colorado's notice requirements, 30-day adverse outcome explanations, and the three-year record retention obligation with searchable, exportable records.
Texas TRAIGA (HB 149): intent-based prohibitions, government and healthcare disclosure, and a NIST AI RMF safe harbor defense
Texas HB 149 (signed June 22, 2025, effective January 1, 2026) Applies to any entity promoting or conducting business in Texas. Prohibits intentional discrimination against protected classes, systems designed to incite self-harm or criminal activity, government social scoring, CSAM generation, and unlawful deepfakes. Government agencies must disclose AI use before or during consumer interactions in plain English, without dark patterns. Healthcare providers must disclose AI use on the date of treatment. Companies that follow the NIST AI Risk Management Framework gain an affirmative defense against liability. A 36-month regulatory sandbox program allows controlled AI testing with quarterly reporting. Third-party misuse protections shield developers from liability when others misuse their systems. Cure period: 60 days after receiving notice of a violation.
→ Nexovern's evidence exports are structured to support NIST AI RMF alignment, enabling organizations to document the testing, monitoring, and governance practices that activate the Texas TRAIGA safe harbor defense.
California SB 53: safety frameworks, transparency reports, and incident disclosure for frontier AI models
California SB 53 (signed September 29, 2025, effective January 1, 2026) Applies to developers of frontier models trained with 10^26 or more FLOPs. Large frontier developers (annual revenue exceeding $500M) must publish annual safety frameworks covering catastrophic risk identification, mitigation, governance structures, and cybersecurity practices. All frontier developers must publish transparency reports before deployment, detailing model capabilities, intended uses, modalities, restrictions, and catastrophic risk assessments. Safety incidents must be reported to the California Office of Emergency Services within 15 days of discovery, or within 24 hours if imminent danger exists. Covered incidents include unauthorized tampering causing harm, materialized catastrophic risks, loss of control resulting in injury, and deliberate evasion of safeguards. Whistleblower protections prohibit retaliation against employees or contractors who report catastrophic risk activities. Large developers must maintain anonymous internal reporting channels.
→ Nexovern's incident detection and alerting supports the 15-day and 24-hour reporting windows by capturing the evidence needed for California's safety incident disclosure, and providing the continuous monitoring that transparency reports require.
Illinois HB 3773: strict liability for discriminatory AI in employment, with a private right of action
Illinois HB 3773 (signed August 9, 2024, effective January 1, 2026) Amends the Illinois Human Rights Act. Employers must provide notice when AI is used in employment decisions, including recruitment, hiring, promotion, training, discharge, discipline, and tenure. Strict liability attaches when AI produces a discriminatory effect on protected classes, regardless of whether the discrimination was intentional. ZIP codes may not be used as a proxy for protected classes in AI-driven employment processes. Individuals may bring civil rights complaints directly, making Illinois one of the few states with a private right of action for AI discrimination in employment. Penalties escalate based on prior violations.
→ Nexovern's automated AI inventory surfaces which agents are involved in employment decisions, enabling compliance teams to direct bias testing where the strict liability exposure is highest and build the evidence trail needed to respond to private complaints.
Connecticut SB 5: staggered AI governance covering employment decisions, frontier models, and content provenance
Connecticut SB 5 (signed May 27, 2026) Anti-discrimination amendments, the developer-deployer framework, and WARN Act disclosure requirements take effect October 1, 2026. Interactive disclosure and pre-decision notice obligations for automated employment decision tools follow on October 1, 2027. Pre-decision notice must identify the automated tool being used, its purpose, the trade name of the technology, categories and sources of personal data analyzed, how the data is assessed, and contact information. Using automated employment decision technology is not a defense to discrimination claims under the Connecticut Fair Employment Practices Act, though courts may consider anti-bias testing efforts as a mitigating factor.
→ Nexovern's jurisdiction-aware evidence mapping tracks which AI agents affect Connecticut residents and employees, ensuring that disclosure and anti-discrimination obligations are met in advance of each enforcement milestone.
Penalties for non-compliance
Colorado: up to $20,000 per violation
The Attorney General has exclusive enforcement authority. Penalties reach up to $20,000 per violation, with enhanced penalties for violations affecting elderly individuals. A 60-day cure period applies from the effective date through January 1, 2028, after which violations become immediately actionable.
Colorado SB 26-189 · AG enforcement
Texas: tiered penalty structure
Curable violations carry penalties of $10,000 to $12,000 each. Uncurable violations range from $80,000 to $200,000 per incident. Ongoing violations accrue $2,000 to $40,000 per day. A 60-day cure period applies. The Attorney General holds exclusive enforcement authority.
Texas HB 149 (TRAIGA) · AG enforcement
California: up to $1 million per violation
California SB 53 targets frontier model developers with penalties of up to $1 million per violation, scaled to severity. The Attorney General enforces. Whistleblower retaliation claims entitle successful plaintiffs to attorneys' fees.
California SB 53 · AG enforcement
Illinois: escalating per-person penalties with private right of action
First violations carry penalties of $16,000 per aggrieved party. With one prior violation within five years, penalties increase to $42,500. With two or more priors within seven years, penalties reach $70,000. Individuals can sue directly, and successful claims may include actual damages, attorneys' fees, and compliance reporting obligations.
Illinois HB 3773 · Illinois Human Rights Act
Connecticut: anti-discrimination enforcement with mitigation factors
Discrimination claims proceed through the Connecticut Fair Employment Practices Act. Using automated tools is not a defense. Courts may, however, consider an employer's documented anti-bias testing as a mitigating factor when evaluating liability.
Connecticut SB 5 · Fair Employment Practices Act
Key dates
01
August 2024: Illinois HB 3773 signed
Illinois becomes the first state to amend its Human Rights Act for AI, requiring notice when AI is used in employment decisions and imposing strict liability for discriminatory outcomes.
02
January 1, 2026: Texas, California, and Illinois laws take effect
Three major state AI laws become enforceable on the same day. Texas TRAIGA establishes intent-based prohibitions and a NIST AI RMF safe harbor. California SB 53 activates frontier model reporting requirements. Illinois HB 3773 begins enforcement of AI employment discrimination protections.
03
May 2026: Colorado SB 26-189 signed
Colorado replaces its original AI Act (SB 24-205) with a narrower, disclosure-focused law. The replacement removes the duty of care, impact assessments, and risk management requirements, retaining deployer notice obligations and human review provisions.
04
May 2026: Connecticut SB 5 signed
Connecticut enacts a staggered AI governance framework. Anti-discrimination provisions and a developer-deployer accountability framework activate in October 2026, with interactive disclosure and pre-decision notice requirements following in October 2027.
05
October 1, 2026: Connecticut anti-discrimination provisions effective
The first phase of Connecticut SB 5 takes effect, activating anti-discrimination amendments and the foundational developer-deployer framework for AI governance.
06
January 1, 2027: Colorado SB 26-189 effective
Colorado's replacement AI law becomes enforceable. Deployers must provide clear notice before using ADMT in consequential decisions, explain adverse outcomes within 30 days, and designate trained personnel for human review. The 60-day cure period runs until January 1, 2028.
How Nexovern helps
- Automated AI inventory: Discover and catalog every AI agent deployment across the enterprise, including shadow AI that was never formally provisioned, giving compliance teams a single source of truth for multi-state reporting.
- Jurisdiction-aware evidence mapping: Runtime evidence maps each agent's activity to the state laws that apply, based on where affected consumers or employees reside, so obligations are tracked per jurisdiction rather than treated as a single national standard.
- Multi-state record retention: Continuous monitoring and audit logs satisfy the strictest state retention requirements, maintaining three or more years of searchable, correlated records for every AI agent session.
- Human review and override support: Policy enforcement provides the decision context, execution records, and escalation controls that trained reviewers need to evaluate and, where required, override AI-driven outcomes under Colorado's deployer obligations.
- NIST AI RMF alignment: Evidence exports are structured to support the NIST AI Risk Management Framework, enabling organizations to assert the Texas TRAIGA safe harbor defense with documented, auditable proof of framework alignment.
- Incident detection and response: Real-time incident detection captures the evidence needed for California's safety incident reporting obligations, with timeline-aware alerting calibrated to the 15-day standard window and the 24-hour imminent danger window.
- Bias exposure visibility: Automated inventory surfaces which AI agents are making consequential decisions subject to Illinois or Connecticut anti-discrimination rules, enabling targeted bias testing where legal exposure is highest.
- Federal preemption readiness: Because federal preemption status remains unsettled, Nexovern builds to the strictest current standard, ensuring that organizations remain compliant regardless of how the federal landscape evolves.
Map your AI estate against every state that matters
Five states have already enacted AI laws, and more are advancing. A Nexovern demo inventories your current AI deployments, maps them to the jurisdictions where your users and employees reside, and identifies the compliance gaps before enforcement begins.