web analytics
AI Governance

State Privacy Laws

The Profiling Right That Governs AI Without Using the Word

The one-paragraph answer

State privacy laws are the sleeper AI regime in the US. As of mid-2026, roughly twenty states have enacted comprehensive consumer privacy laws: California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Iowa, Indiana, Tennessee, Montana, Oregon, Texas (TDPSA), Delaware, New Hampshire, New Jersey, Kentucky, Rhode Island, Minnesota, Maryland (MODPA), Nebraska, and a handful of others in the pipeline. Nearly every one of them creates a right to opt out of "profiling in furtherance of solely automated decisions that produce legal or similarly significant effects" concerning a consumer. That language does not use the word AI, and it does not need to. It reaches automated hiring decisions, credit and lending decisions, insurance underwriting, housing decisions, and any consequential automated decision that touches a resident of one of these states. When Colorado repealed the Colorado AI Act on May 14, 2026, the Colorado Privacy Act was untouched. Its profiling opt-out, its right to a data protection assessment, and its notice obligations all survived. The correction the field is confidently getting wrong here is treating state privacy laws as if they are about cookie banners. The profiling right is the AI regime, hiding inside a privacy statute.

The pain state privacy laws are causing AI operators

A national employer deploys an AI resume screener. Its counsel tells the board that federal law is unsettled and the EEOC's enforcement posture on AI is stalled, so exposure is manageable. Six months later, a Colorado applicant exercises her right under the Colorado Privacy Act to opt out of profiling in furtherance of solely automated decisions that produce legal or similarly significant effects. The employer's HR system has no mechanism to honour that request. The AG sends a notice. Damages start accruing. The exact same request from a Virginia applicant, a Connecticut applicant, or a Texas applicant would produce the same result under the equivalent state statute. This is what "state privacy laws are the AI regime" means in practice: the enforcement is not federal, it is state-by-state, and the trigger is a consumer request the employer's stack cannot answer.

The current landscape: twenty states, one family, several dialects

The state comprehensive privacy laws share a family resemblance. Almost every one carries consumer rights of access, correction, deletion, portability, and opt-out (from sale, from targeted advertising, and from profiling that produces legal or similarly significant effects). Almost every one imposes business obligations of transparency, purpose limitation, security, and (in the newer statutes) data minimisation. They diverge on: (a) applicability thresholds (revenue, volume of records), (b) sensitive-data treatment (consent vs opt-out), (c) whether a data protection assessment is required, (d) enforcement (AG only, or AG plus limited private right of action), and (e) universal opt-out mechanisms (whether Global Privacy Control signals must be honoured).

The data protection assessment obligation is the piece that AI operators keep tripping on. States that mandate a DPIA (Virginia, Colorado, Connecticut, Texas, Minnesota, Oregon, Delaware, New Hampshire, New Jersey, Montana, Indiana, Tennessee, Rhode Island, Maryland, and others) require one for high-risk processing, and profiling that produces legal or similarly significant effects is expressly named as high-risk in every one. That means the AI system doing the profiling triggers a mandatory documented assessment before deployment, kept for AG inspection.

The profiling right, in plain language

The consumer rights language is nearly identical across the CPA-family statutes. Here is the operative sentence, in Colorado's version: a consumer may opt out of the processing of personal data for purposes of "profiling in furtherance of decisions that produce legal or similarly significant effects concerning a consumer." "Legal or similarly significant effects" is defined to include decisions that result in the provision or denial of financial or lending services, housing, insurance, education enrollment or opportunity, criminal justice, employment opportunities, health-care services, or access to essential goods or services.

That is, in effect, an AI decision-rights regime. If an automated system contributes materially to a decision in any of those domains, the consumer has a state-law right to opt out, and the operator must have a mechanism to honour it. "Materially contributes" is the interpretive battleground: some statutes say "solely automated," some say "solely or predominantly automated," and Maryland's MODPA reaches further. What is not in dispute is that the right exists and that most AI operators have not built the plumbing to honour it.

Why the Colorado repeal changed almost nothing about state privacy laws and AI

This is the correction the field keeps missing. The Colorado AI Act (SB 24-205) was repealed by SB 26-189, signed May 14, 2026, and never took effect. That was a significant repeal for AI-specific regulation. But the Colorado Privacy Act is a completely separate statute, and it was not touched. Its profiling opt-out, its DPA requirement, its sensitive-data consent, and its notice obligations all remain in force exactly as they were before the AI Act was signed. The rebuttable presumption for NIST AI RMF alignment that lived inside the AI Act was lost. The privacy-law right to opt out of AI-driven profiling was not.

The practical effect is that a Colorado-focused compliance program that leaned on the AI Act still has all its privacy-law obligations intact, and the AI systems inside that program still trigger DPAs, opt-out mechanisms, and consumer notice. The regime moved from AI-specific back to privacy-general. It did not move from regulated to unregulated.

MODPA and Minnesota: the strictest branches

Two statutes are worth naming because they push the family further. Maryland's MODPA (effective October 1, 2025) is the strictest US comprehensive privacy law to date. It prohibits the sale of sensitive personal data outright (not merely on opt-out), mandates data minimisation as a substantive requirement, prohibits targeted advertising to consumers under 18, and reaches more broadly into biometric and precise-location data. Minnesota's Consumer Data Privacy Act (effective July 31, 2025 for most controllers) introduces the strongest DPA requirement, requiring assessments prior to processing that presents heightened risk, and creating rights around the profiling that resemble the CPA family but with tighter definitions. Both statutes point to where the family is heading: substantive data minimisation, universal opt-out honoring, and stronger profiling protections. AI operators building for the CCPA/CPRA baseline are increasingly building for MODPA and Minnesota instead.

What the research says about state privacy laws and AI

Between June 2018 and June 2024, nineteen US states enacted comprehensive consumer privacy laws, and lawmakers have continued to evolve existing laws, with California, Colorado, Connecticut, Kentucky, Montana, Oregon, Texas, Utah, and Virginia all amending their respective laws in 2025.

The evolution has moved consistently toward stronger profiling protection and substantive data minimisation. Kentucky and Montana quietly added DPA requirements. Texas closed the SPRS-adjacent loophole around service-provider status. Every amendment closed a lane that AI operators had been using.

Ninety-four percent of participants would turn on Global Privacy Control, indicating a need for an efficient opt-out mechanism, and eighty-one percent have a correct understanding of what GPC does, but only 12 percent of sites with a US Privacy String opt out users after receiving a GPC signal.

How to comply with state privacy laws for AI systems: a 5-step path

  1. Inventory every automated decision that could produce legal or similarly significant effects. Employment, credit, insurance, housing, education, healthcare, essential goods, criminal justice. The AI system does not have to make the decision alone; if it materially contributes, the profiling right attaches.
  2. Complete a data protection assessment before deployment for any high-risk processing. Multiple states require it. The assessment must weigh benefits against risks, document mitigations, and be available to state AGs on request. Not optional; not "we did a risk memo." A specific document with specific contents.
  3. Build the opt-out mechanism for profiling. Not a checkbox in a privacy policy. A working workflow that, when a consumer opts out, either removes them from automated processing or provides a human-decision alternative. Retain evidence of the request and the response.
  4. Honour Global Privacy Control signals where the state requires it. Colorado, Connecticut, California, and others require GPC honouring. If the site sends the signal, the site is opted out of sale and targeted advertising. Ignoring the signal is a per se violation.
  5. Track the amendments. The state privacy landscape amended nine statutes in 2025 alone. Every amendment tightens some lane. A compliance program frozen at the 2023 baseline is out of date by 2026 in half the states.

Frequently asked questions about state privacy laws and AI

If Colorado repealed its AI Act, do we still have to worry about Colorado?

Yes. The Colorado Privacy Act (a different statute) is fully in force. The right to opt out of profiling with legal or similarly significant effects, the DPA requirement, and the sensitive-data consent all continue exactly as before. The AI Act's specific hooks were removed; the privacy-law hooks were not.

Does a state comprehensive privacy law reach a business that does not operate in that state?

It reaches any business that targets residents of that state and meets the applicability threshold. "Targets residents" is broad. A national employer, a national lender, or a national insurer that has employees, borrowers, or policyholders in the state is generally in scope.

Is Global Privacy Control mandatory?

Yes in California, Colorado, Connecticut, and several other states. The technical requirement is that the site honour the signal as an opt-out from sale and targeted advertising. Universal opt-out mechanism honouring is the direction the whole family is moving.

Where do state privacy laws fit in SRJ's work?

The Volume II AI Readiness & Performance Assessment produces exactly the profiling-right documentation the DPAs require: which AI systems participate in which decisions, what proportion of the outcome they contribute, whether a human alternative exists, and what the opt-out plumbing looks like end-to-end. See Volume II.

Primary sources on state privacy laws

Ready to see where you stand?

The AI Business Enablement Audit™ measures your organization against every framework in this library, including State Privacy Laws, and delivers a defensible governance dossier. Start or finish your audit below.

Start or finish your AI Audit →
Schedule a Free AI Consultation