Tracker · Verified against primary sources · September 2, 2026

State AI laws that apply to firms that use AI (September 2026)

Fewer states mandate AI audits than the headlines suggest, and more of them require something harder: that you can explain what your AI did, show who reviewed it, and produce the records. This table lists what is actually in force or enacted, what it asks of a firm that uses AI rather than builds it, and which AboveBoard controls evidence each obligation. Anything we could not verify against primary text is marked.

What changed in 2026

Two things. First, Colorado's mandate evaporated: SB 24-205 never took effect, a federal court paused enforcement on April 27, 2026, and the replacement law, SB 26-189, effective January 1, 2027, requires notice, explanation, human review and records rather than impact assessments (McDermott, May 2026; Seyfarth, May 2026). Second, Texas became the anchor: TRAIGA has been in force since January 1, 2026 and treats substantial compliance with the NIST AI RMF as an affirmative defense (Baker Botts, Jul 2025). Add California's records and automated-decision rules, Illinois and Connecticut notice laws, the NAIC bulletin in 24 states plus DC, and a federal government that is fighting the states without having preempted them, and the practical conclusion is one governance baseline that produces the same evidence everywhere.

The table, by jurisdiction

Control codes refer to the AboveBoard Standard v1.0: G = Governance, D = Data, O = Operations, W = Workforce, T = Transparency. The 40-point checklist spells each one out. "Evidence" means the control produces the document a regulator would ask for; it does not mean AboveBoard certifies compliance with any law.

JurisdictionLaw or ruleEffectiveWho it coversWhat it asks of a firm that uses AIAboveBoard controls that evidence it
TexasResponsible AI Governance Act (TRAIGA, HB 149)Jan 1, 2026Anyone who promotes, advertises or conducts business in Texas; developers and deployersIntent-based prohibitions (manipulation to self-harm or crime, intentional unlawful discrimination, certain deepfakes); government entities and healthcare providers must disclose AI interactions; AG enforcement with 60-day cure; $10,000–$12,000 per curable violation, $80,000–$200,000 per uncurable, $2,000–$40,000 per day continuing. Affirmative defense for substantial compliance with NIST AI RMF or other recognized standards (Baker Botts, Jul 2025).G4 (NIST-aligned risk method), G6 (obligations register), G8 (framework integration); the full verified evidence file organized by NIST function; T7 (healthcare disclosure)
CaliforniaCivil Rights Department regulations on automated decision systems in employmentOct 1, 2025All California employers using ADS in hiring, promotion, discipline or similar decisionsADS that discriminate violate FEHA; four-year retention of ADS records (dataset descriptors, scoring outputs, audit findings); anti-bias testing not mandatory but its quality, scope and recency count as evidence (Jackson Lewis; Mayer Brown, Aug 2025).G3 (inventory), G4 (risk rating), D5 (retention), O7 (traceability), T8 (use-case review)
CaliforniaCCPA regulations: automated decision-making technology, risk assessments, cybersecurity auditsJan 1, 2026; ADMT obligations for existing uses by Jan 1, 2027; first risk-assessment submissions Apr 1, 2028CCPA-covered businessesRisk assessments for high-risk processing; for ADMT used in significant decisions (employment, financial, housing, education, healthcare): pre-use notice, opt-out and access rights; cybersecurity audit certifications phased in 2028–2030 by revenue (Mayer Brown, Jan 2026).G4 (risk assessment), D6 (notice and consent), D8 (data-subject requests), T2 (public AI statement), T8
CaliforniaSB 53 (Transparency in Frontier AI Act); AB 2013 (training-data transparency)Jan 1, 2026Frontier and other AI developers onlyNothing for a firm that uses AI (MoFo, Oct 2025; Cooley, Apr 2026). Listed so you can tell clients why it does not apply.Not applicable
CaliforniaAB 3030 (generative AI in patient communications)Jan 1, 2025Health facilities, clinics and physician practices using generative AI to communicate clinical information to patientsDisclaimer that the communication was AI-generated and instructions for reaching a human. Healthcare-specific; see the healthcare page.T7 (required disclosure), T2, D6
IllinoisHB 3773 (Human Rights Act amendment)Jan 1, 2026Illinois employersNotify employees and applicants when AI is used in recruitment, hiring, promotion, discipline, discharge and similar decisions; discriminatory AI use is a civil-rights violation; zip codes may not be used as a proxy for protected class (Reinhart, Dec 2025). Unverified IDHR implementing rules (notice content, annual notice, four-year retention) were drafted, withdrawn and still not final as of Feb 26, 2026 (Hinshaw); status after that date not verified. Do not treat the draft retention period as law yet.T8 (use-case review), D6 (notice), G6 (obligations register), O7
ConnecticutSB 5 (signed May 29, 2026)Oct 1, 2026 (general); Jan 1, 2027 (AI companions); Oct 1, 2027 (employment provisions)AI users generally; Connecticut employers (no size threshold identified)Employment: pre-use notice when automated processes substantially factor into decisions (purpose, nature, data types and sources, role); high-level explanation of principal reasons after adverse decisions with a chance to correct data. No impact assessments. Voluntary safe harbor: AI users may apply to the Department of Consumer Protection for a presumption of compliance. AG-only enforcement; 60-day cure (Holland & Knight, Jun 2026; Ropes & Gray, Jun 2026).T8, D6, D8, G6; the verified evidence file as the basis for a safe-harbor application
ColoradoSB 26-189 (replaces SB 24-205, which never took effect: enforcement paused by federal court Apr 27, 2026; repealed and replaced May 14, 2026)Jan 1, 2027Deployers using automated decision-making for consequential decisions: employment, credit, housing, insurance, healthcare, education, legal servicesPre-use notice; within 30 days of an adverse outcome, a plain-language explanation, the ADMT's role, how to get system information, and rights to meaningful human review and data correction; records kept three years; accessible notices. Eliminated: impact assessments, AG risk-management disclosures, the affirmative anti-discrimination duty and the NIST AI RMF presumption. AG-exclusive enforcement; 60-day cure (sunsets 2030); no private right of action (Seyfarth, May 2026; Norton Rose Fulbright). Colorado does not require an AI audit.T8, D8 (requests), O1 (human review), O7 (traceability), D5 (three-year records)
New York CityLocal Law 144 (automated employment decision tools)Jul 5, 2023; enforcement tightening in 2026Employers and employment agencies using AEDTs for hiring or promotion of NYC residentsAnnual independent bias audit of the tool, published summary, candidate notice. A State Comptroller review (Jul 2023–Jun 2025) judged enforcement ineffective and the city committed to tightening it (DLA Piper, Jan 2026). The bias audit itself is a separate technical engagement outside AboveBoard's scope.G3, G4, D6, T8; plus a third-party bias audit
New York StateRAISE Act (chapter amendment Mar 27, 2026)Jan 1, 2027Frontier model developers onlyNothing for a firm that uses AI (Wiley, Apr 2026; MoFo, Apr 2026).Not applicable
UtahAI Policy Act (SB 149), as amended by SB 226 and SB 332 (2025)May 1, 2024; amendments 2025Businesses using generative AI with Utah consumers; licensed ("regulated occupation") professionalsDisclose generative AI on clear and unambiguous request and in high-risk interactions; licensed professionals must proactively disclose in high-risk interactions; Division of Consumer Protection enforcement, limited to date (Cooley, Apr 2026; Davis Polk).T2 (public statement), T6 (staff communications), T7 (required disclosure)
24 states + DCNAIC Model Bulletin on the Use of AI Systems by Insurers (adopted state by state); four more states with their own AI insurance rulesRolling; 24 + DC as of Spring 2026Insurers; flows down to agencies, MGAs and other third parties through vendor diligenceWritten AI systems program, governance, consumer notice, controls and third-party vendor due diligence; regulators may ask about the program in examinations (Quarles, Apr 2025; Mayer Brown, Apr 2026). See the insurance agencies page.G1 (policy), G2 (owner), D3 (vendor terms), O5 (vendor monitoring), T4 (questionnaire answer bank)
Washington, Oregon UnverifiedWA HB 1170 (AI-generated content disclosure); WA HB 2225 and OR SB 1546 (companion-chatbot self-identification)Feb 1, 2027 (HB 1170); Jan 1, 2027 (chatbot laws)Businesses communicating with consumers using AIReported by a vendor state-law tracker (GLACIS, Aug 2026); bill text not verified in our review. Treat as likely disclosure duties pending verification.T2, T6
EU (for US firms with EU clients or users)EU AI Act (Reg. 2024/1689) as amended by the Digital Omnibus on AI (Reg. 2026/1744, in force Jul 27, 2026)Art. 4 literacy since Feb 2, 2025, enforced from Aug 2, 2026; Art. 50 transparency Aug 2, 2026; Annex III high-risk Dec 2, 2027; Annex I Aug 2, 2028Deployers, including US firms serving EU clients or running EU-facing chatbotsTake measures to support staff AI literacy and keep records of them; disclose chatbots and label synthetic content; for high-risk uses from 2027, human oversight, monitoring and logs (White & Case, Aug 2026; Travers Smith, Jul 2025).W1, W2, W6 (training and records), T2, T6, O1

Federal status

Executive Order 14365 (Dec 11, 2025) directed the Department of Justice to form an AI Litigation Task Force (established January 2026), directed Commerce to list "onerous" state AI laws within 90 days (still stalled as of May 2026), and asked the FTC and FCC to act. The state-AI-law moratorium was dropped from the FY2026 defense bill, and no comprehensive preemption statute has passed; the bipartisan American Leadership in AI Act (H.R. 8516, Apr 2026) does not resolve preemption (K&L Gates, May 2026; StateScoop; Ropes & Gray, Mar 2026). Net: no federal preemption is in force.

The FTC's Policy Statement Concerning the Suppression of Accuracy in AI Systems (Federal Register, Jul 7, 2026) states that steering AI outputs toward undisclosed objectives while implying accuracy is deceptive under Section 5, that disclaimers must be prominent and persistent, and that compliance with a state law is no excuse. Combined with the SEC's AI-washing enforcement and its FY2026 exam priorities (Akin, Nov 2025), this makes claims about your own AI a federal exposure for every firm, in every state. Controls T3 (claims substantiation), T6 (communications guidance) and T2 (public statement) are the evidence.

Not laws, but they ask anyway

How to use this page

Put the rows that apply to you into control G6, your obligations register, with a review date. Then note that every row asks for some combination of the same things: a policy, an inventory, notice, human review, records and training. That is why one verified governance baseline works across the patchwork. This page is a research summary, not legal advice; confirm obligations with counsel for your jurisdictions.

Questions

Which states have AI laws that apply to businesses that use AI?

As of September 2026: Texas (TRAIGA, in force since Jan 1, 2026), California (employment automated-decision regulations since Oct 1, 2025 and CCPA automated decision-making rules phasing in through Jan 1, 2027), Illinois (AI-in-employment notice since Jan 1, 2026), Utah (generative-AI disclosure since 2024, narrowed in 2025), New York City (bias audits of hiring tools since 2023), Connecticut (general provisions from Oct 1, 2026, employment from Oct 1, 2027) and Colorado (a replacement notice-and-explanation law effective Jan 1, 2027). Insurance regulators in 24 states plus DC have adopted the NAIC AI bulletin.

Does Colorado require an AI audit?

No. Colorado's original AI Act, SB 24-205, never took effect: a federal court paused its enforcement on April 27, 2026 and the state repealed and replaced it with SB 26-189, signed May 14, 2026 and effective January 1, 2027 (McDermott, May 2026; Seyfarth, May 2026). The replacement is a notice-and-explanation law. It requires pre-use notice, a plain-language explanation within 30 days of an adverse outcome, a right to human review and data correction, and three years of records. It eliminated impact assessments and the NIST safe harbor. It does not require an audit.

What does the Texas AI law require?

TRAIGA, effective January 1, 2026, applies to anyone doing business in Texas. It prohibits intent-based harms such as manipulation toward self-harm, intentional unlawful discrimination and certain deepfakes, requires government entities and healthcare providers to disclose AI interactions, and is enforced by the attorney general with a 60-day cure period and penalties of $10,000 to $200,000 per violation. Substantial compliance with the NIST AI RMF or another recognized standard is an affirmative defense (Baker Botts, Jul 2025).

Is there a federal AI law that preempts state AI laws?

Not as of September 2026. Executive Order 14365 (Dec 11, 2025) created a DOJ AI Litigation Task Force and directed Commerce to list onerous state laws, but the list was late, the state-law moratorium was dropped from the defense bill, and no preemption statute has passed (K&L Gates, May 2026). The FTC's July 7, 2026 policy statement addresses deceptive AI accuracy claims under existing law. Plan for a state patchwork through at least 2027.

What does California require of employers that use AI?

Since October 1, 2025, California Civil Rights Department regulations make it unlawful for an automated decision system to discriminate in employment under FEHA and require employers to keep ADS records for four years (Jackson Lewis; Mayer Brown, Aug 2025). Separately, CCPA regulations effective January 1, 2026 require risk assessments for high-risk processing and, for existing deployments by January 1, 2027, pre-use notice, opt-out and access rights for automated decision-making technology used in significant decisions including employment (Mayer Brown, Jan 2026).