Quick Answer
US state AI laws 2026 are the state rules that govern AI in hiring, chatbots, healthcare, credit, privacy, deepfakes, and frontier models. There is still no single US AI Act that replaces them. By mid-2026, trackers counted about 109 new AI-related laws across roughly 29 states, and the focus has shifted from “study bills” to implementation and enforcement.
If you need a practical US state AI laws 2026 list and update, prioritize California, Colorado, Connecticut, Texas, New York (NYC + RAISE Act), Illinois, and Utah. Your baseline should be: inventory AI tools, identify consequential decisions, disclose AI interactions, enable human review, and lock down vendor oversight.
This page is built for founders, marketers, HR, product, and compliance teams who need scannable answers not statute dumps.
Why 2026 Feels Different
Earlier years were heavy on task forces and pilot bills. US state AI laws 2026 feel different because:
- More laws are in force or phased in, not just proposed
- Attorneys general and private plaintiffs are watching real deployments
- Employment, healthcare, kids/AI companions, elections/deepfakes, and frontier models are the hot zones
- Federal preemption talk continues, but states still set the daily compliance calendar
In short: 2026 is the year AI governance becomes an operating system, not a PDF.
What US State AI Laws 2026 Cover
People search “AI rules USA,” “laws on AI in USA,” and “AI laws US states” for one plain answer. Here it is:
US state AI laws 2026 are use-case laws. Regulators care less about which model you bought and more about whether AI changes a person’s opportunities and whether you can explain, document, and correct that process.
Core themes:
- Consequential / significant decisions (jobs, education, housing, health, credit, insurance, essential services)
- Notice when people interact with AI or face automated outcomes
- Human review and adverse-outcome disclosures
- Bias audits or assessments (especially hiring tools)
- Privacy, biometrics, children’s data, and AI companions
- Generative AI provenance, training-data transparency, deepfakes, and synthetic ads
- Frontier-model safety duties for the largest developers
Threshold language matters. Colorado and similar regimes often key off systems that “materially influence” a consequential decision not every AI suggestion in a slide deck.

Key 2026 Changes at a Glance
| Change | Why it matters |
| Colorado SB 26-189 | Repealed/replaced the original 2024 Colorado AI Act. Narrows to covered ADMT that materially influences consequential decisions. Emphasizes notices, human review, and adverse disclosures. Major obligations start Jan 1, 2027. |
| Connecticut SB 5 / CART Act | Broad package: employment AEDT notices, AI companion/self-harm rules, generative provenance/watermarking themes, frontier whistleblower protections. Phased from Oct 1, 2026 into 2027–2028. |
| Texas TRAIGA | Effective Jan 1, 2026. Targets harmful/deceptive AI uses, government AI limits, and consumer-protection enforcement. |
| Illinois BIPA + SB 315 | BIPA remains the biometric powerhouse. SB 315 adds frontier AI safety with third-party audit expectations for large developers. |
| California AB 2013 + ADMT/employment rules | GenAI training-data transparency (2026) plus phased ADMT notices/assessments for significant decisions, including employment contexts. |
| New York | NYC Local Law 144 remains the hiring-audit benchmark. Statewide RAISE Act adds frontier-model safety duties (implementation toward Jan 1, 2027). |
| Federal overlap | No clean nationwide override. FTC deception rules, sector laws (health/finance/employment), and executive national-framework efforts still matter but state dates still drive ops. |
US State AI Laws 2026 List: Comparison Table
| State | Priority | Enforcement risk | Core instrument | What to do | Key timing |
| California (CA) | High | High (AG + privacy exposure) | CCPA/CPRA + CPPA ADMT; AB 2013; employment ADS rules | Notices/assessments for significant decisions; GenAI training-data disclosures for public systems | AB 2013: Jan 1, 2026; ADMT phased |
| Colorado (CO) | High | High (AG-focused ADMT duties) | SB 26-189 (ADMT rewrite) | Map ADMT that materially influences consequential decisions; notices, human review, adverse disclosures | Key duties: Jan 1, 2027 |
| Connecticut (CT) | High | High (broad 2026 package) | SB 5 / CART Act | Employment AI notices; companion safeguards; provenance readiness | Starts Oct 1, 2026; more in 2027–2028 |
| Texas (TX) | High | Medium–High (AG consumer protection) | TRAIGA | Block harmful/deceptive uses; document governance for consumer-facing AI | Effective Jan 1, 2026 |
| New York / NYC (NY) | High | High (NYC audits + frontier duties) | NYC LL 144 + RAISE Act | Bias audits + candidate notices for covered hiring AEDTs; frontier developers track RAISE | LL 144 ongoing; RAISE ~Jan 1, 2027 |
| Illinois (IL) | High | Very high (BIPA private suits) | BIPA + employment AI notices + SB 315 | Biometric consent; employment AI notices; frontier audits for large labs | 2026 cycle |
| Utah (UT) | Medium–High | Medium (disclosure-led) | AI Policy Act (2024 base, still active) | Disclose GenAI interactions, especially regulated/consumer settings | In force (earlier base law) |
| Virginia (VA) | Medium / Watch | Medium (privacy/deepfakes) | Privacy + narrow AI activity | Do not treat as a full high-risk AI act state; still monitor privacy/deepfakes | No broad high-risk act in force |
Other notable states
Washington, Florida, Tennessee, and others have passed narrower AI rules (deepfakes, government AI, kids, specific disclosures). Washington, for example, has drawn attention for companion/chatbot and consumer-protection style AI rules that matter if you run high-engagement assistants there. These states may not top a national program, but they matter if you have concentrated users, political ads, or companion products in-market.
GEO tip: Rank by where your users, candidates, patients, and employees live, not where your HQ sits.
High-Risk AI: Plain Examples
Treat these as priority under US state AI laws 2026:
- Resume screening, interview scoring, promotion, discipline, termination recommendations
- Credit approvals, loan pricing, insurance underwriting, claims triage, fraud scoring
- Healthcare access, prior-auth support, clinical decision support used in care/coverage pathways
- Housing, education admissions, essential government benefits
- Workplace monitoring that affects pay, schedules, discipline, or status
Lower immediate legal heat (still not free): internal writing copilots, grammar tools, non-decision analytics unless they feed a consequential system, handle sensitive data, or create deceptive content.
Remember Colorado-style wording: many duties attach when AI materially influences the decision, not only when it is the sole decision-maker.
Developer vs Deployer
| Role | Typical duties |
| Developer / provider | Intended-use docs, limits, evals, training-data transparency (e.g., CA AB 2013), frontier safety/audits (e.g., IL SB 315, NY RAISE) |
| Deployer / business user | Inventory, notices, human review, adverse explanations, bias audits (NYC AEDTs), lawful use, vendor oversight |
| Both | Contracts allocate work but usually cannot erase duties a state places directly on you |
Off-label use is a classic trap: buying an “assistive” tool and using it as an automated gatekeeper can still create deployer risk.
Generative AI, Provenance, Deepfakes, and Elections
Generative AI is not broadly banned. Risk rises when GenAI powers:
- Undisclosed chatbots or AI companions
- Misleading health, finance, legal, or job claims
- Cloned voices, fake endorsements, synthetic spokespeople
- Political/election deepfakes and deceptive campaign content
- Unsafe companion experiences involving minors or self-harm content

Election note for political and performance-marketing teams: Multiple states now have election-specific deepfake or synthetic-media disclosure/ban rules around candidates, ballots, and campaign ads. Pair state law checks with platform policies before running political or issue ads that use AI-generated audio, video, or likenesses.
Practical controls:
- Label bots early and clearly
- Use provenance/watermarking where required or expected (CT and others)
- Expert-review regulated claims before publish
- Block undisclosed impersonation creatives
- Align political/ad workflows with state deepfake rules and platform policies
Industry Snapshot
Healthcare
Patient chat, triage, prior auth, and clinical support need human oversight, clear AI labels, and tight PHI handling. State AI rules stack on HIPAA, they do not replace it.
Employment / HR
NYC LL 144 remains the vendor benchmark (audit + notice). CA and CT expand notices/assessments. Illinois adds biometric and employment-notice pressure.
Finance & insurance
Fair testing + understandable adverse reasons. Avoid sole automated denials.
Marketing & growth
Chatbots, personalization, synthetic ads, and AI-written health/finance copy sit at the consumer-protection edge. Disclosure + substantiation protect both compliance and SEO/AEO trust.
Small businesses
Size is not a free pass. If you hire with AI, run multi-state bots, or automate decisions that affect residents in regulated states, risk and residency not headcount usually decide whether US state AI laws 2026 apply. A 12-person company using AI resume screening on California and New York candidates can face more exposure than a larger firm using only internal writing tools.
Enforcement Trends (Why Documentation Matters)
- Attorney general offices are shifting from education to implementation questions
- Private rights of action remain a major Illinois biometric risk: BIPA allows roughly up to $1,000 per negligent violation and up to $5,000 per intentional or reckless violation (plus fees). Damages can multiply per scan or instance, so repeated face/voice collection without compliant notice and consent gets expensive fast
- NYC EDT enforcement continues to influence vendor questionnaires nationwide
- Expect more scrutiny of chatbots, hiring tools, healthcare AI, deepfakes, elections content, and kids/companion products after 2026 legislative sessions
If you cannot show inventory, notices, vendor diligence, and human-review logs, you are underprepared.
Federal Overlap (No Clean Override)
US AI Act summary: There is still no EU-style comprehensive federal AI Act that wipes out state power.
What still matters federally:
- FTC deception / unfair practices (including AI claims and chatbots)
- Sector rules (health privacy, fair lending, employment discrimination doctrines)
- Executive “national framework” efforts and preemption debates
Until Congress passes clear preemption, run a multi-state program and treat federal rules as a floor not a replacement for US state AI laws 2026.
30-Day Action Plan
- Inventory everything — tools, vendors, models, data types, owners, states touched, including shadow AI.
- Tier risk — low / limited / consequential (“materially influences” decisions).
- Disclose chatbots, companions, and synthetic media on public surfaces.
- Stop sole automated adverse decisions without a trained human override path.
- Collect vendor packets — intended use, limits, evals, bias/security docs, training-data statements, incident SLAs.
- Localize for CA, CO, CT, TX, NY/NYC, IL, UT based on real traffic and workforce maps.
- Schedule quarterly reviews tied to legislative sessions, AG guidance, vendor changes, and new launches.
Bias Audit & Assessment Checklist
NYC LL 144-style (hiring AEDTs):
- Is the tool a covered AEDT?
- Independent bias audit completed on required cadence?
- Public summary posted?
- Candidates notified before use?
- Alternative process / accommodation path documented?
Other-state variation:
Many states emphasize notices, impact assessments, anti-discrimination compliance, and human review rather than an identical independent audit. Use NYC as the vendor baseline, then map CA/CT/CO assessment and notice duties on top.
Vendor Contract Clauses Worth Demanding
- Audit and regulatory-cooperation rights
- Data-use limits (no training on your confidential/customer data without written OK)
- Security + defined breach timelines
- Intended-use and prohibited-use schedule
- Allocation of IP, biometric, and deceptive-output risk where negotiable
- No clause pretending statutory deployer duties can be waived away
Sample Notice Language (Adapt with Counsel)
Chatbot notice:
“You’re chatting with an AI assistant, not a human. It can make mistakes. For account, medical, legal, or urgent issues, ask for a person.”
Adverse-outcome themes (CO-style thinking):
Plain-language decision summary · role of the automated system · how to request more info · how to seek human review when available · how to correct inaccurate personal data.
FAQ: US State AI Laws 2026
Is there one federal US AI law that replaces state AI rules?
No. The U.S. still has no single EU-style AI Act that removes state power. Federal agencies set baselines, but US state AI laws 2026 remain the day-to-day layer for hiring, privacy, chatbots, and consequential decisions.
Which states matter most right now?
California, Colorado, Connecticut, Texas, New York (NYC LL 144 + RAISE Act), Illinois, and Utah. Virginia is a watch state for privacy/deepfakes, not a top comprehensive high-risk driver.
What happened to the original Colorado AI Act?
It was repealed and replaced by SB 26-189 (signed May 2026). The new ADMT framework is narrower, focuses more on notices/human review/adverse disclosures, and pushes key obligations to January 1, 2027.
When do Connecticut’s new AI rules start?
The CART Act / SB 5 uses staggered dates beginning October 1, 2026, with additional duties in 2027 and into 2028. Map each use case to the exact phase that applies.
Do I have to disclose AI chatbots and companions?
Often yes. Utah has generative AI disclosure rules; Connecticut adds companion disclosure and safety protocols on a phased timeline. Clear labeling also reduces FTC-style deception risk.
What counts as high-risk or consequential AI?
Systems that materially influence jobs, school, housing, health access, credit, insurance, or essential services. If the tool can help approve, deny, rank, or limit someone, treat it as priority under US state AI laws 2026.
Who is liable the vendor or my company?
Often both. Developers owe design/documentation/frontier duties; deployers owe notices, oversight, and lawful use. Contracts help allocate work but rarely erase statutory duties.
Are bias audits required for hiring AI?
For covered NYC AEDTs, yes (independent audit, public summary, notices). Other states may require assessments/notices instead of the same audit model—still treat LL 144 as the practical vendor baseline.
Do small businesses need to comply?
Yes when AI touches hiring, multi-state support, companions, or material automated decisions affecting regulated-state residents. Risk and residency usually matter more than headcount.
What is the fastest way to reduce enforcement risk?
Inventory systems (including shadow AI), disclose bots, stop sole automated adverse decisions, collect vendor compliance packets, and document human review. Those five steps cover most practical exposure under US state AI laws 2026.
Final Takeaway
US state AI laws 2026 reward teams that treat AI governance like a product requirement: know your states, label your bots, document systems that materially influence people, and refresh quarterly. Build one national core, then localize notices and assessments for the states that actually touch your users.
