web analytics
AI Governance

State AI Laws

Colorado, Texas, California, Illinois, Connecticut, Tennessee

The one-paragraph answer

State AI laws in the United States are a patchwork, not a single system, and the patchwork is actively shifting. Six states have binding AI laws that reach beyond their borders: Colorado, Texas, California, Illinois, Connecticut, and Tennessee. Each takes a different approach. Connecticut regulates broadly (SB 5, effective October 1, 2026). Texas adds a government-use track. California passes narrow, targeted laws. Illinois is where employment AI litigation starts, and now also regulates frontier developers. Tennessee protects voice and likeness. Colorado is the cautionary tale: its comprehensive high-risk AI law was repealed in May 2026 before it ever took effect, and replaced with a narrower disclosure regime. Any national business needs to track all six, and needs to build to durable practice rather than to any single statute.

The pain state AI laws are causing our customers

Federal law is stalled. States are not. In the absence of comprehensive federal AI legislation, states have moved first. That has produced a patchwork of six comprehensive or semi-comprehensive laws with different structures, different definitions of "high-risk" or "consequential," different effective dates, and different enforcement mechanisms. Multi-state operators are trying to build one AI program that satisfies all six state laws plus the EU AI Act plus federal agency enforcement. That is not easy.

The state AI laws currently in force or pending

The state laws share a common core: consumer notice when AI materially influences a consequential decision, some right to explanation or human review, and documentation obligations on developers and deployers. Where they now diverge sharply is on architecture. The EU-style high-risk classification model, which Colorado adopted and then abandoned, is in retreat. Disclosure-and-rights regimes are ascendant.

Alignment to NIST AI RMF or ISO/IEC 42001 still serves as evidence of reasonable care, but note carefully: Colorado's explicit rebuttable presumption for framework alignment, which was the single largest driver of voluntary US adoption, was repealed with the rest of the statute. Framework alignment is now commercially and evidentially valuable rather than statutorily protective.

Click into each state below for detailed compliance guidance.

Why state AI laws matter to you

Because your AI touches residents of these states. Every state law has extraterritorial reach: if your AI system makes a decision about someone who lives in Colorado, Texas, California, Illinois, Connecticut, or Tennessee, that state's law applies to you regardless of where your company is based. Multi-state compliance requires a program designed for the highest common denominator, not the lowest.

What the research says about state AI laws

The academic literature on state AI laws is ahead of most corporate practice, and it is unusually blunt. Two findings are worth putting in front of any executive who thinks this is a compliance formality.

“concerns about their impact on individual and societal wellbeing, particularly due to the lack of transparency and accountability”

That is the gap between having AI and governing it. The second finding is the one that tends to change the room.

“The promise of efficient, low-cost, or 'neutral' solutions harnessing the potential of big data has led public bodies to adopt algorithmic systems.”

Neither of these is a fringe position. Both come from peer-reviewed work, and both describe the condition most organisations are actually in when the question about state AI laws arrives from the board, the buyer, or the regulator.

How to get compliant with State AI Laws: a 5-step path

This is the sequence that works, and it is not the sequence most organisations choose. They start with the framework and work backwards toward reality. Start with reality.

  1. Inventory the AI in scope. List every AI system that could fall under state AI laws. Record what it does, what decision it influences, what data it touches, and who owns it. You cannot govern AI you cannot name, and almost every organisation we assess is running more AI than its leadership believes.
  2. Determine whether you are actually in scope. Work out precisely which of your AI systems and activities state AI laws reaches, and write the determination down with its reasoning. Do this in writing. A documented scope determination, right or wrong, is defensible. An undocumented assumption is not.
  3. Assign one accountable owner. Name a person, not a committee, with the authority to stop a deployment. Governance without someone who can say no is documentation, not control.
  4. Build the evidence file. Assemble the documentation state AI laws expects: the scope, the risk assessment, the controls, the testing evidence, and the incident record. Assemble it before anyone asks. Reconstructing it under a regulator's deadline costs several times more and looks exactly like what it is.
  5. Set a review cadence and hold it. Re-run the assessment on a schedule and after any material change to the model, the data, or the use case. Alignment decays. A control tested once is a snapshot, not a control.

Done in this order, state AI laws becomes tractable. Done out of order, it becomes a document nobody uses and a control nobody exercises.

Frequently asked questions about state AI laws

Will federal law preempt state AI laws?

No statutory preemption exists today, but federal pressure is already reshaping state law in practice. A December 2025 executive order created an AI Litigation Task Force inside the Department of Justice to challenge state AI laws. The FTC has advanced an implied preemption argument. The Great American AI Act discussion draft contains a three-year preemption of state frontier-AI development laws. That combination contributed materially to Colorado repealing its own statute. Treat state AI laws as live obligations, but do not treat them as fixed points.

Which of the state AI laws is most important?

Depends on your industry and customer geography. Connecticut SB 5 is now the broadest in force, from October 1, 2026. California's stack has the most breadth in narrow slices. Illinois BIPA has the most litigation history and the largest settlements. The EU AI Act is broader than any US state law. Colorado, which used to be the answer to this question, repealed its comprehensive law in May 2026.

Where do state AI laws fit in SRJ's work?

The AI Governance Reference Library maps each state law to specific SRJ operating artifacts. Volume III of The Operating Discipline for AI Library™ includes state-by-state applicability guidance and impact assessment templates designed for multi-state use.

What each area of state AI laws covers

The detail pages below each take one component of state AI laws and answer the same four questions: what it actually is, what it requires of you, why it matters commercially and legally, and what a defensible position looks like. Read the one that maps to your exposure first. The others become relevant as your AI footprint widens.

  • Colorado AI Act. Colorado's comprehensive AI law, effective February 2026. High-risk AI, impact assessments, consumer rights.
  • Texas Responsible AI Governance Act. Texas's AI governance framework, effective 2026. Impact assessments, developer duties, government use rules.
  • California AI Laws. California's stack of AI laws covering training data disclosure, AI content labeling, healthcare AI, and generative AI.
  • Illinois AI Laws. Illinois's AI video interview disclosure requirements and its employment AI restrictions under HB 3773.
  • Connecticut AI Act. Connecticut's comprehensive AI law, SB 5, enacted as Public Act 26-15 and signed May 27, 2026. Staggered effective dates from October 1, 2026 to January 1, 2028. Employment disclosure, frontier whistleblower protections, synthetic content watermarking, AI companion rules, anti-discrimination.
  • Tennessee ELVIS Act. Tennessee's voice-and-likeness rights law protecting artists and individuals from unauthorized AI imitation.

How to prioritise your work on state AI laws

Executives ask, reasonably, where to start. The sequence that works is the same one every time, and it is not the sequence most organisations choose. Start with an inventory: you cannot govern AI you cannot list, and almost every organisation we assess is using more AI than its leadership believes. Then rank by consequence, not by volume, because the tool that makes one high-stakes decision a week carries more exposure than the one that drafts a thousand emails.

Only then assign an owner. Not a committee, an owner, named, with the authority to stop a deployment. Governance without a person who can say no is documentation, not control. With those three steps done, the specific requirements of state AI laws become tractable, because you now know what you have, what matters, and who answers for it.

The organisations that struggle are the ones that begin with the framework and work backwards toward reality. The frameworks are the map. The inventory is the territory. Start with the territory.

Primary sources on state AI laws

The authoritative texts and agency pages behind this summary. We keep this page current, but where a compliance decision turns on exact wording, read the source. Anything concerning state AI laws that carries legal consequence should be confirmed against the enrolled text or the issuing body, not against a secondary summary, including this one.

Deep dives in this category

  • Colorado AI Act REPEALED before it ever took effect. What SB 26-189 replaced it with, and why the repeal is the most instructive event in US state AI law.
  • Texas Responsible AI Governance Act Texas's AI governance framework, effective 2026. Impact assessments, developer duties, government use rules.
  • California AI Laws California's stack of AI laws covering training data disclosure, AI content labeling, healthcare AI, and generative AI.
  • Illinois AI Laws Illinois's AI video interview disclosure requirements and its employment AI restrictions under HB 3773.
  • Connecticut AI Act Connecticut's comprehensive AI law, SB 5, enacted as Public Act 26-15 and signed May 27, 2026. Staggered effective dates from October 1, 2026 to January 1, 2028. Employment disclosure, frontier whistleblower protections, synthetic content watermarking, AI companion rules, anti-discrimination.
  • Tennessee ELVIS Act Tennessee's voice-and-likeness rights law protecting artists and individuals from unauthorized AI imitation.

Ready to see where you stand?

The AI Business Enablement Audit™ measures your organization against every framework in this library, including State AI Laws, and delivers a defensible governance dossier. Start or finish your audit below.

Start or finish your AI Audit →
Schedule a Free AI Consultation