Colorado, Texas, California, Illinois, Connecticut, Tennessee
The one-paragraph answer
State AI laws in the United States are a patchwork, not a single system, and the patchwork is actively shifting. Six states have binding AI laws that reach beyond their borders: Colorado, Texas, California, Illinois, Connecticut, and Tennessee. Each takes a different approach. Connecticut regulates broadly (SB 5, effective October 1, 2026). Texas adds a government-use track. California passes narrow, targeted laws. Illinois is where employment AI litigation starts, and now also regulates frontier developers. Tennessee protects voice and likeness. Colorado is the cautionary tale: its comprehensive high-risk AI law was repealed in May 2026 before it ever took effect, and replaced with a narrower disclosure regime. Any national business needs to track all six, and needs to build to durable practice rather than to any single statute.
Federal law is stalled. States are not. In the absence of comprehensive federal AI legislation, states have moved first. That has produced a patchwork of six comprehensive or semi-comprehensive laws with different structures, different definitions of "high-risk" or "consequential," different effective dates, and different enforcement mechanisms. Multi-state operators are trying to build one AI program that satisfies all six state laws plus the EU AI Act plus federal agency enforcement. That is not easy.
The state laws share a common core: consumer notice when AI materially influences a consequential decision, some right to explanation or human review, and documentation obligations on developers and deployers. Where they now diverge sharply is on architecture. The EU-style high-risk classification model, which Colorado adopted and then abandoned, is in retreat. Disclosure-and-rights regimes are ascendant.
Alignment to NIST AI RMF or ISO/IEC 42001 still serves as evidence of reasonable care, but note carefully: Colorado's explicit rebuttable presumption for framework alignment, which was the single largest driver of voluntary US adoption, was repealed with the rest of the statute. Framework alignment is now commercially and evidentially valuable rather than statutorily protective.
Click into each state below for detailed compliance guidance.
Because your AI touches residents of these states. Every state law has extraterritorial reach: if your AI system makes a decision about someone who lives in Colorado, Texas, California, Illinois, Connecticut, or Tennessee, that state's law applies to you regardless of where your company is based. Multi-state compliance requires a program designed for the highest common denominator, not the lowest.
The academic literature on state AI laws is ahead of most corporate practice, and it is unusually blunt. Two findings are worth putting in front of any executive who thinks this is a compliance formality.
“concerns about their impact on individual and societal wellbeing, particularly due to the lack of transparency and accountability”
That is the gap between having AI and governing it. The second finding is the one that tends to change the room.
“The promise of efficient, low-cost, or 'neutral' solutions harnessing the potential of big data has led public bodies to adopt algorithmic systems.”
Neither of these is a fringe position. Both come from peer-reviewed work, and both describe the condition most organisations are actually in when the question about state AI laws arrives from the board, the buyer, or the regulator.
This is the sequence that works, and it is not the sequence most organisations choose. They start with the framework and work backwards toward reality. Start with reality.
Done in this order, state AI laws becomes tractable. Done out of order, it becomes a document nobody uses and a control nobody exercises.
No statutory preemption exists today, but federal pressure is already reshaping state law in practice. A December 2025 executive order created an AI Litigation Task Force inside the Department of Justice to challenge state AI laws. The FTC has advanced an implied preemption argument. The Great American AI Act discussion draft contains a three-year preemption of state frontier-AI development laws. That combination contributed materially to Colorado repealing its own statute. Treat state AI laws as live obligations, but do not treat them as fixed points.
Depends on your industry and customer geography. Connecticut SB 5 is now the broadest in force, from October 1, 2026. California's stack has the most breadth in narrow slices. Illinois BIPA has the most litigation history and the largest settlements. The EU AI Act is broader than any US state law. Colorado, which used to be the answer to this question, repealed its comprehensive law in May 2026.
The AI Governance Reference Library maps each state law to specific SRJ operating artifacts. Volume III of The Operating Discipline for AI Library™ includes state-by-state applicability guidance and impact assessment templates designed for multi-state use.
The detail pages below each take one component of state AI laws and answer the same four questions: what it actually is, what it requires of you, why it matters commercially and legally, and what a defensible position looks like. Read the one that maps to your exposure first. The others become relevant as your AI footprint widens.
Executives ask, reasonably, where to start. The sequence that works is the same one every time, and it is not the sequence most organisations choose. Start with an inventory: you cannot govern AI you cannot list, and almost every organisation we assess is using more AI than its leadership believes. Then rank by consequence, not by volume, because the tool that makes one high-stakes decision a week carries more exposure than the one that drafts a thousand emails.
Only then assign an owner. Not a committee, an owner, named, with the authority to stop a deployment. Governance without a person who can say no is documentation, not control. With those three steps done, the specific requirements of state AI laws become tractable, because you now know what you have, what matters, and who answers for it.
The organisations that struggle are the ones that begin with the framework and work backwards toward reality. The frameworks are the map. The inventory is the territory. Start with the territory.
The authoritative texts and agency pages behind this summary. We keep this page current, but where a compliance decision turns on exact wording, read the source. Anything concerning state AI laws that carries legal consequence should be confirmed against the enrolled text or the issuing body, not against a secondary summary, including this one.
The AI Business Enablement Audit™ measures your organization against every framework in this library, including State AI Laws, and delivers a defensible governance dossier. Start or finish your audit below.
Start or finish your AI Audit →