The Profiling Right That Governs AI Without Using the Word
The one-paragraph answer
State privacy laws are the sleeper AI regime in the US. As of mid-2026, roughly twenty states have enacted comprehensive consumer privacy laws: California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Iowa, Indiana, Tennessee, Montana, Oregon, Texas (TDPSA), Delaware, New Hampshire, New Jersey, Kentucky, Rhode Island, Minnesota, Maryland (MODPA), Nebraska, and a handful of others in the pipeline. Nearly every one of them creates a right to opt out of "profiling in furtherance of solely automated decisions that produce legal or similarly significant effects" concerning a consumer. That language does not use the word AI, and it does not need to. It reaches automated hiring decisions, credit and lending decisions, insurance underwriting, housing decisions, and any consequential automated decision that touches a resident of one of these states. When Colorado repealed the Colorado AI Act on May 14, 2026, the Colorado Privacy Act was untouched. Its profiling opt-out, its right to a data protection assessment, and its notice obligations all survived. The correction the field is confidently getting wrong here is treating state privacy laws as if they are about cookie banners. The profiling right is the AI regime, hiding inside a privacy statute.
A national employer deploys an AI resume screener. Its counsel tells the board that federal law is unsettled and the EEOC's enforcement posture on AI is stalled, so exposure is manageable. Six months later, a Colorado applicant exercises her right under the Colorado Privacy Act to opt out of profiling in furtherance of solely automated decisions that produce legal or similarly significant effects. The employer's HR system has no mechanism to honour that request. The AG sends a notice. Damages start accruing. The exact same request from a Virginia applicant, a Connecticut applicant, or a Texas applicant would produce the same result under the equivalent state statute. This is what "state privacy laws are the AI regime" means in practice: the enforcement is not federal, it is state-by-state, and the trigger is a consumer request the employer's stack cannot answer.
The state comprehensive privacy laws share a family resemblance. Almost every one carries consumer rights of access, correction, deletion, portability, and opt-out (from sale, from targeted advertising, and from profiling that produces legal or similarly significant effects). Almost every one imposes business obligations of transparency, purpose limitation, security, and (in the newer statutes) data minimisation. They diverge on: (a) applicability thresholds (revenue, volume of records), (b) sensitive-data treatment (consent vs opt-out), (c) whether a data protection assessment is required, (d) enforcement (AG only, or AG plus limited private right of action), and (e) universal opt-out mechanisms (whether Global Privacy Control signals must be honoured).
The data protection assessment obligation is the piece that AI operators keep tripping on. States that mandate a DPIA (Virginia, Colorado, Connecticut, Texas, Minnesota, Oregon, Delaware, New Hampshire, New Jersey, Montana, Indiana, Tennessee, Rhode Island, Maryland, and others) require one for high-risk processing, and profiling that produces legal or similarly significant effects is expressly named as high-risk in every one. That means the AI system doing the profiling triggers a mandatory documented assessment before deployment, kept for AG inspection.
The consumer rights language is nearly identical across the CPA-family statutes. Here is the operative sentence, in Colorado's version: a consumer may opt out of the processing of personal data for purposes of "profiling in furtherance of decisions that produce legal or similarly significant effects concerning a consumer." "Legal or similarly significant effects" is defined to include decisions that result in the provision or denial of financial or lending services, housing, insurance, education enrollment or opportunity, criminal justice, employment opportunities, health-care services, or access to essential goods or services.
That is, in effect, an AI decision-rights regime. If an automated system contributes materially to a decision in any of those domains, the consumer has a state-law right to opt out, and the operator must have a mechanism to honour it. "Materially contributes" is the interpretive battleground: some statutes say "solely automated," some say "solely or predominantly automated," and Maryland's MODPA reaches further. What is not in dispute is that the right exists and that most AI operators have not built the plumbing to honour it.
This is the correction the field keeps missing. The Colorado AI Act (SB 24-205) was repealed by SB 26-189, signed May 14, 2026, and never took effect. That was a significant repeal for AI-specific regulation. But the Colorado Privacy Act is a completely separate statute, and it was not touched. Its profiling opt-out, its DPA requirement, its sensitive-data consent, and its notice obligations all remain in force exactly as they were before the AI Act was signed. The rebuttable presumption for NIST AI RMF alignment that lived inside the AI Act was lost. The privacy-law right to opt out of AI-driven profiling was not.
The practical effect is that a Colorado-focused compliance program that leaned on the AI Act still has all its privacy-law obligations intact, and the AI systems inside that program still trigger DPAs, opt-out mechanisms, and consumer notice. The regime moved from AI-specific back to privacy-general. It did not move from regulated to unregulated.
Two statutes are worth naming because they push the family further. Maryland's MODPA (effective October 1, 2025) is the strictest US comprehensive privacy law to date. It prohibits the sale of sensitive personal data outright (not merely on opt-out), mandates data minimisation as a substantive requirement, prohibits targeted advertising to consumers under 18, and reaches more broadly into biometric and precise-location data. Minnesota's Consumer Data Privacy Act (effective July 31, 2025 for most controllers) introduces the strongest DPA requirement, requiring assessments prior to processing that presents heightened risk, and creating rights around the profiling that resemble the CPA family but with tighter definitions. Both statutes point to where the family is heading: substantive data minimisation, universal opt-out honoring, and stronger profiling protections. AI operators building for the CCPA/CPRA baseline are increasingly building for MODPA and Minnesota instead.
Between June 2018 and June 2024, nineteen US states enacted comprehensive consumer privacy laws, and lawmakers have continued to evolve existing laws, with California, Colorado, Connecticut, Kentucky, Montana, Oregon, Texas, Utah, and Virginia all amending their respective laws in 2025.
The evolution has moved consistently toward stronger profiling protection and substantive data minimisation. Kentucky and Montana quietly added DPA requirements. Texas closed the SPRS-adjacent loophole around service-provider status. Every amendment closed a lane that AI operators had been using.
Ninety-four percent of participants would turn on Global Privacy Control, indicating a need for an efficient opt-out mechanism, and eighty-one percent have a correct understanding of what GPC does, but only 12 percent of sites with a US Privacy String opt out users after receiving a GPC signal.
Yes. The Colorado Privacy Act (a different statute) is fully in force. The right to opt out of profiling with legal or similarly significant effects, the DPA requirement, and the sensitive-data consent all continue exactly as before. The AI Act's specific hooks were removed; the privacy-law hooks were not.
It reaches any business that targets residents of that state and meets the applicability threshold. "Targets residents" is broad. A national employer, a national lender, or a national insurer that has employees, borrowers, or policyholders in the state is generally in scope.
Yes in California, Colorado, Connecticut, and several other states. The technical requirement is that the site honour the signal as an opt-out from sale and targeted advertising. Universal opt-out mechanism honouring is the direction the whole family is moving.
The Volume II AI Readiness & Performance Assessment produces exactly the profiling-right documentation the DPAs require: which AI systems participate in which decisions, what proportion of the outcome they contribute, whether a human alternative exists, and what the opt-out plumbing looks like end-to-end. See Volume II.
The AI Business Enablement Audit™ measures your organization against every framework in this library, including State Privacy Laws, and delivers a defensible governance dossier. Start or finish your audit below.
Start or finish your AI Audit →