Back to Insights
FRAMEWORKAUGUST 27, 202614 min read

The Patchwork Has a Pattern: US State AI Laws in 2026, Mapped

Sigilith Research

Institutional AI governance & accountability

A note on dates. Every status below was checked against primary or authoritative sources on August 27, 2026, and in this subject that discipline is not optional: nearly every statute on this map has been amended, delayed, replaced, or stayed at least once since enactment. Colorado's law alone has had three effective dates. Any account of US state AI law that does not state its as-of date is a stale claim waiting to be repeated.

Which states have AI laws in 2026?

There is no federal statute governing AI-assisted decisions about people, and 2025 settled that there will not be one soon. In July 2025, the Senate voted 99 to 1 to strip a proposed ten-year moratorium on state AI enforcement out of the budget reconciliation bill; the bill was signed days later without it. The executive branch then took the opposite road: an executive order of December 11, 2025 directed the Attorney General to stand up a Department of Justice AI Litigation Task Force with the sole job of challenging state AI laws in court, ordered the Commerce Department to catalog them, and tied broadband funding to states' restraint.

So the current condition is neither preemption nor peace. States legislate; the federal government litigates; and companies deploying automated decisions comply with what is actually in force while the two fight over what will be. As of this writing, six state regimes matter most for automated decisions about individuals, with a seventh arriving:

  • Colorado: the first comprehensive state AI act, now repealed and reenacted in narrower form, effective January 1, 2027
  • New York City: bias audits and candidate notice for automated employment decision tools, in force since 2023
  • Illinois: employment AI discrimination amendments in force since January 1, 2026, on top of a video-interview law dating to 2020
  • California: civil-rights regulations for automated-decision systems in employment, in force since October 1, 2025
  • Utah: generative-AI disclosure duties, in force since May 2024 and narrowed in 2025
  • Texas: an intent-based prohibition statute, in force since January 1, 2026
  • Connecticut: an omnibus AI act signed June 2, 2026, phasing in from October 2026
Figure 1Seven jurisdictions, and the dates that held
In forceDate struckScheduled

ColoradoSB 24-205 → SB 26-189

Three effective dates. The original February 1, 2026 date was moved to June 30, 2026 by an August 2025 special session; a federal magistrate stayed enforcement on April 27, 2026 after xAI sued and the DOJ intervened; and SB 26-189, signed May 14, 2026, replaced the act outright. The rewrite, a notice-and-records regime without the original's impact assessments and risk program, takes effect January 1, 2027.

Positions are drawn on a 2020 to 2028 axis; the vertical rule marks August 27, 2026, the date every status in this article was verified. Colorado is the row to study: both struck markers were once real compliance dates that organizations planned against.

The figure is worth a slow read, because its instability is the finding. Between August 2025 and May 2026, the most demanding law on the map was delayed once, stayed by a federal court, and then replaced outright. Anyone whose compliance program was frozen against a 2024 memo about the Colorado AI Act is now planning against a statute that no longer exists.

What does the Colorado AI Act require now?

Colorado is the map's cautionary tale about stale claims, so the chronology deserves precision.

Senate Bill 24-205, signed May 17, 2024, was the first comprehensive AI statute in the country: a duty of reasonable care to protect consumers from algorithmic discrimination, a risk-management program for deployers, annual impact assessments, and reporting to the attorney general, all keyed to "high-risk" systems making consequential decisions in employment, education, lending, housing, insurance, and health care. It was to take effect February 1, 2026.

Then it moved. Three times.

  • August 28, 2025: after a contentious special session, SB 25B-004 pushed the compliance date to June 30, 2026 without changing the substance.
  • April 2026: xAI sued to block the law on April 9; the Justice Department's new AI Litigation Task Force intervened on April 24; and on April 27 a federal magistrate judge stayed enforcement, with the state agreeing to the stay while the legislature acted.
  • May 14, 2026: Governor Polis signed SB 26-189, which repeals and reenacts the law. The June 30, 2026 compliance date that our Mobley v. Workday analysis documented in its two-calendars section never arrived. The replacement takes effect January 1, 2027, and applies to decisions made on or after that date.

What survived the rewrite is instructive. The duty of care is gone. The risk-management program is gone. The impact assessments are gone. The attorney-general reporting is gone. What remains is a disclosure-and-records regime built around "covered ADMT": automated decision-making technology used to materially influence a consequential decision. Developers must hand deployers documentation covering intended and known harmful uses, the categories of training data, known limitations and risks, and instructions for conducting meaningful human review. Deployers must give clear and conspicuous notice that ADMT is in use; must designate a trained human reviewer with authority to override; and, within 30 days of an adverse decision, must give the individual an easily understandable description of the ADMT's role, along with rights to access the data used, correct inaccuracies, and request human review where commercially reasonable. Enforcement belongs exclusively to the attorney general, who must adopt implementing disclosure rules by January 1, 2027.

Read that list again as an engineering requirement rather than a legal one. A deployer cannot write an accurate 30-day description of what an ADMT did in one specific decision unless a record of that decision, its inputs, and its role exists to write from. Without one, the description is testimony without an exhibit.

What does NYC Local Law 144 actually require?

New York City's Local Law 144 of 2021 is the veteran on the map: in force since January 1, 2023, enforced since July 5, 2023, and still the only US regime that mandates an audit. Employers and employment agencies using an automated employment decision tool to substantially assist hiring or promotion decisions about NYC candidates must have the tool bias-audited by an independent auditor within one year before use, publish a summary of the results (selection or scoring rates and impact ratios by sex and race/ethnicity) with the tool's distribution date, and notify candidates at least 10 business days before the tool is used, and separately publish, or provide on written request, the type and source of data collected and the employer's retention policy. Penalties run from $500 for a first violation to $1,500 for each subsequent one, with each day of noncompliant use a separate violation.

The 2026 development is about enforcement. On December 2, 2025, the New York State Comptroller published an audit of the city agency responsible, covering July 2023 through June 2025, and concluded its enforcement was "ineffective": three-quarters of test complaints placed through 311 were misrouted, and where the agency's review of 32 published bias audits had found a single compliance issue, the Comptroller's re-review of the same audits flagged at least 17 potential ones. The agency agreed to implement most of the recommendations, which practitioners read as a signal of stricter review ahead.

The tempting conclusion, that a weakly enforced law is a small obligation, misreads what the law produces. A published bias audit is a permanent public exhibit about your selection rates, discoverable and quotable whether or not a regulator ever calls. We have written before about the difference between producing numbers and producing evidence; a bias-audit summary posted to your own website is both.

What does Illinois require of employers using AI?

Illinois legislated early and twice. The Artificial Intelligence Video Interview Act has required notice, an explanation of how the AI works, and consent before AI analysis of recorded job interviews since January 1, 2020. The broader change is HB 3773, signed August 9, 2024 and effective January 1, 2026, which amends the Illinois Human Rights Act. It is now a civil rights violation for an employer to use AI that has the effect of subjecting employees or applicants to discrimination on a protected basis in recruitment, hiring, promotion, renewal, selection for training or apprenticeship, discharge, discipline, tenure, or terms of employment; to use ZIP codes as a proxy for protected classes; or to fail to provide notice that AI is being used in those decisions.

Two features distinguish it. First, the standard is effect, not intent: an employer's good faith is not the question. Second, the mechanics of the notice duty are still unsettled: the Department of Human Rights published proposed implementing rules on May 15, 2026, then withdrew them on June 2, 2026 to coordinate with other agencies, with no revised timeline. As of August 27, 2026, the statutory duty is in force while the rules that specify its timing and form are pending, an uncomfortable posture Illinois employers currently manage by giving notice on the strictest plausible reading.

California's ADS rules are already in force

California regulated through rulemaking rather than a new statute. The Civil Rights Council's regulations on automated-decision systems in employment took effect October 1, 2025, folding ADS use into the Fair Employment and Housing Act for employers with five or more employees. Three provisions carry most of the weight. Using an ADS that discriminates on a protected basis violates FEHA, and the definition of ADS is broad: a computational process that makes a decision or facilitates human decision-making about an employment benefit. Employment records, expressly including automated-decision system data, must be retained for at least four years. And evidence of anti-bias testing, including its quality, efficacy, recency, and scope, is relevant to defending a discrimination claim.

That last pair is the shape of things. California does not order you to test, notify, or explain. It makes the records you kept, and the testing you can document, the difference between a defensible position and an indefensible one when the claim arrives. The four-year clock is also the only named retention period on this map, a point we return to below.

Utah and Texas: disclosure and intent

Utah enacted the first state statute aimed squarely at generative AI. The Artificial Intelligence Policy Act (SB 149), effective May 1, 2024, required businesses in state-regulated occupations to disclose prominently when a person is interacting with generative AI, and everyone else to disclose when asked. Amendments in 2025 narrowed it: disclosure is now triggered by a clear and unambiguous request, or by "high-risk" interactions involving health, financial, or biometric information or advice on legal, financial, or medical matters, and a safe harbor protects suppliers whose AI discloses itself clearly and conspicuously at the start of an interaction. A companion bill extended the act's sunset to July 2027, a reminder that this map can shrink as well as grow.

Texas passed the most philosophically distinct law of the group. The Texas Responsible Artificial Intelligence Governance Act (HB 149), signed June 22, 2025 and effective January 1, 2026, prohibits developing or deploying AI systems with the intent to manipulate people into self-harm, harm, or crime; to discriminate against protected classes; or to produce certain unlawful sexual content, with the statute stating expressly that disparate impact alone does not establish discriminatory intent. Disclosure duties fall mainly on government agencies and certain healthcare uses. The attorney general enforces exclusively, with a 60-day cure period and civil penalties from $10,000–12,000 per curable violation to $80,000–200,000 per uncurable one.

An intent statute might look like the end of the documentation story. It is the opposite. TRAIGA gives a safe harbor to organizations that discover potential violations through internal review, testing, or red-teaming while substantially complying with a recognized AI risk-management framework, NIST's AI RMF named among them. In practice, the defense Texas offers is a documented governance program and the records proving it operated.

Connecticut is the map's next entry: the Artificial Intelligence Responsibility and Transparency Act (Public Act 26-15), signed June 2, 2026, phases in from October 1, 2026, with its employment-decision notice obligations taking effect October 1, 2027.

The compliance denominator is documentation

Set the six regimes side by side and the divergence is real: Illinois condemns effect, Texas condemns intent, Colorado after its rewrite condemns neither and mandates transparency, New York City audits, California waits for the lawsuit. There is no single national standard of conduct, and firms hoping one state's program covers the rest will be disappointed on the details.

But look at what each law obliges you to produce, and the patchwork resolves into a pattern.

Figure 2Six regimes, five kinds of paper
RequiredConditional or limitedRewarded as a defenseNot required
Notice of useAdverse-decision explanationAudit or testing evidenceMulti-year retention clockRisk program as defense

Colorado · SB 26-189 (from Jan 1, 2027)

Clear and conspicuous notice that covered ADMT is in use; within 30 days of an adverse decision, an understandable description of the system's role, with rights to access the data used, correct it, and request human review. Developers owe deployers documentation on training data, limitations, and human review. The impact assessments and risk-management program of SB 24-205 were removed by the rewrite, and no retention period is named.

Statuses as of August 27, 2026; Colorado's row describes SB 26-189 as it takes effect January 1, 2027. Read down a column and the states disagree about conduct. Read across the rows and every regime converges on the same demand: documents that prove what the system did.

Five artifacts recur. A notice that an automated system is in use, before or at the decision. An explanation of an adverse decision, after it. Audit or testing evidence, mandated in New York City, rewarded as a defense in California and Texas. Retained records on a multi-year clock. And a documented risk program, no longer commanded anywhere since Colorado's rewrite, but functioning as the affirmative defense in the one state with real penalties attached. Every regime on the map is, at the compliance layer, a documentation regime. The legislatures disagree about what AI must not do. They agree, almost perfectly, about what you must be able to show.

And each artifact quietly depends on the same underlying object. A 30-day Colorado explanation, an Illinois notice defended as accurate, a California record that survives four years, a Texas safe-harbor showing: each is only as good as a record of what the system actually did in a specific decision, created when the decision was made. The anatomy of that record, what it must contain and why operational logs fail as a substitute, is its own piece; the point here is that state law has converged on demanding its outputs, whether or not any statute names the record itself.

Two cautions from adjacent work belong in any state-law program. First, a bias audit and the ability to reconstruct one individual's decision are different capabilities, and regulators ask for the first while litigants ask for the second; the Mobley discovery record is the demonstration of what happens when only the first exists. Second, statutory calendars and evidentiary calendars move independently. Colorado's obligations receded twice in twelve months; the discovery window in active AI litigation still opens in September 2020. California's four-year retention floor is the longest named on this map, and it is still shorter than the limitation periods your decisions can be examined under.

What should compliance teams do before 2027?

Six moves cover most of the map, and none requires guessing how the federal litigation ends:

  1. Inventory against the broadest definitions. Colorado's "covered ADMT," California's "automated-decision system," and NYC's "AEDT" overlap but do not match. A system exempt in one frame is covered in another; the inventory should record which definitions each system trips.
  2. Build notice once, to the strictest standard. A notice designed for NYC's 10 business days and Colorado's clear-and-conspicuous requirement will satisfy the lighter regimes, and will be close to whatever Illinois's rules finally require.
  3. Make the adverse-decision explanation producible, not writable. If your systems cannot generate Colorado's 30-day description from retained records today, the gap is in the records, not the drafting.
  4. Keep testing evidence in a producible tier. California and Texas both reward documented testing; testing that lives entirely under legal privilege defends nothing.
  5. Retain on the exposure clock. Four years satisfies California. It does not cover the window a 2031 lawsuit will examine.
  6. Watch the three open rulemakings: Illinois's withdrawn notice rules, Colorado's attorney-general rules due by January 1, 2027, and Connecticut's phase-in.

Our own interest in this map is not neutral, and it is narrow: the Sigilith Platform exists to write the object these regimes keep demanding evidence of, a policy-checked, sealed record of each consequential decision at the moment it issues, exportable when someone asks. But the map stands on its own. Whatever a legislature bans next, the safe prediction, on the evidence of six states and counting, is that it will ask you to prove what your system did. The organizations that can answer will have started writing the record before the statute told them to.

Sources

Statutes and regulations

Litigation and enforcement

Federal actions

Related Sigilith analysis

Also Applicable To

Public Sector
Critical Infrastructure
Telecommunications
Sigilith

Evidence infrastructure for consequential AI decisions: records built to outlive the systems that made them.

Est. in the decision path

{ CORRESPONDENCE }

syed@sigilith.com

Vendor-risk questionnaires and security reviews are welcome with a first message.

LinkedIn

© 2026 Sigilith, Inc. · A Delaware corporation. All rights reserved.

Set in Instrument Serif · Inter · IBM Plex Mono