Not legal advice. This guide is for general informational purposes only. AI regulations are evolving rapidly. Always consult a qualified attorney for guidance specific to your situation.

Compliance guide · AI regulation

AI Regulation in the US: State-by-State Requirements for 2026

Colorado's landmark AI Act took effect February 1, 2026, the first comprehensive state AI law in the country. California, Illinois, New York and NYC have enacted their own AI-specific laws, and more proposals are advancing. This guide tracks where things stand and what businesses need to know.

6
States with AI laws
10
Enacted
Feb 2026
Colorado AI Act in force

State AI regulations PlainRegWatch tracks

The most recent state-level AI laws, newest first, each links to the full regulation detail.

State StatusEffective
California Transparency in Frontier AI Act Enacted 2025-09-01
Texas Texas Responsible AI Governance Act Enacted 2026-01-01
California Generative AI Training Data Transparency Act Enacted 2026-01-01
California California AI Transparency Act Enacted 2026-08-02
Illinois Illinois Human Rights Act — AI Amendment Enacted 2026-01-01
Colorado Colorado AI Act Enacted 2026-06-30
Utah Utah Artificial Intelligence Policy Act Enacted 2024-05-01
New York NYC Automated Employment Decision Tools Law Enacted 2023-07-05

Colorado AI Act, Senate Bill 205 (Effective February 1, 2026)

Colorado Senate Bill 205 is the most comprehensive US state AI law to date. It applies to developers and deployers of high-risk artificial intelligence systems - defined as AI systems that make, or substantially assist humans in making, consequential decisions in specific domains.

What Qualifies as a High-Risk AI System Under Colorado's Law?

A "high-risk AI system" under Colorado SB 205 is one used to make consequential decisions in:

  • Employment, hiring, firing, pay, promotion, performance evaluation
  • Education, admission, financial aid, academic evaluation
  • Financial services, credit, insurance underwriting, lending decisions
  • Healthcare, diagnosis support, treatment recommendations, triage
  • Housing, rental applications, mortgage qualification
  • Government services, benefits eligibility, criminal justice applications

Systems that merely assist or recommend, not just those that make fully automated decisions, are included if the AI output has a "material effect" on the decision. This is a notably broad scope.

What Developers Must Do

  • Provide deployers with documentation of the system's intended uses, known risks, and limitations.
  • Disclose what data was used to train the system and any known algorithmic discrimination risks.
  • Notify deployers of updates that materially change the system's risk profile.

What Deployers Must Do

  • Conduct annual algorithmic impact assessments evaluating the system's risks, potential for discrimination, and mitigation steps.
  • Implement a risk management policy covering the AI system's lifecycle.
  • Notify consumers when a high-risk AI system will be used to make a consequential decision about them.
  • Provide a consumer with a means to appeal or seek human review of an AI-driven consequential decision.
  • Disclose the general types of data used as input for the AI system.

Enforcement is by the Colorado Attorney General. The law does not create a private right of action. Violations are treated as deceptive trade practices under Colorado law. Businesses have a 60-day cure period upon notice of violation.

California, AB 2013: AI Training Data Transparency

California Assembly Bill 2013, effective January 1, 2026, requires developers of generative AI systems offered to California users to publish a data transparency disclosure. The disclosure must describe:

  • The data used to train the AI system, including categories of data and whether any synthetic data was used.
  • Whether the training data included personal information or data scraped from the internet.
  • Dates or timeframes of training data collection.
  • Whether consent was obtained for any personal information used in training.

The disclosure must be published on the developer's website and updated whenever training data changes materially. AB 2013 is specifically targeted at generative AI (large language models, image generators, etc.) and does not require the disclosure to include proprietary details about model architecture or weights.

California also has additional AI-related legislation pending for 2026, including bills addressing deepfakes, AI in political advertising, and automated decision-making in the workplace.

Illinois, BIPA and AI Hiring Laws

Biometric Information Privacy Act (BIPA)

Illinois BIPA, enacted in 2008 but still heavily litigated, requires written informed consent before any private entity collects, uses, stores, or transfers biometric identifiers, including fingerprints, voiceprints, face geometry, retina/iris scans, and hand geometry. AI systems using facial recognition, voice analysis, or other biometric inputs trigger BIPA obligations.

BIPA has a private right of action with statutory damages of $1,000–$5,000 per violation, making it one of the most litigated biometric privacy laws in the world. Illinois courts have held that each scan or collection of biometric data is a separate violation, potentially creating enormous class-action exposure.

Businesses using AI systems that process any biometric data about Illinois residents must: obtain written consent, establish a publicly available retention schedule, and never sell or profit from biometric data.

Artificial Intelligence Video Interview Act (HB 2557)

Illinois also enacted the Artificial Intelligence Video Interview Act, which requires employers using AI to analyze video interviews of job applicants to:

  • Notify applicants before the interview that AI will be used to analyze their facial expressions, word choice, or other characteristics.
  • Explain how the AI works and what characteristics it measures.
  • Obtain consent from the applicant before using AI analysis.
  • Limit who can view the videos and delete them within 30 days of a request.

New York City, Local Law 144: Automated Employment Decisions

New York City Local Law 144, effective July 5, 2023, is the most targeted US law addressing AI in hiring. It applies to NYC employers and employment agencies using automated employment decision tools (AEDTs) - defined as computational processes derived from machine learning, statistical modeling, or AI that substantially assist or replace discretionary employment decisions.

What NYC LL 144 Requires

  • Annual fairness audits - Conducted by an independent third-party auditor. The audit must evaluate the AEDT's impact rate across race/ethnicity and gender categories.
  • Public posting of audit results - A summary of the fairness audit, including the date, the auditor's name, and the impact rates found, must be published on the employer's website.
  • Candidate notification - Job candidates must be notified at least ten business days before an AEDT is used, informed of what data the AEDT will use, and given a way to request an alternative selection process.
  • Fines - $375 per violation per day for the first violation, $1,500 per day for subsequent violations.

LL 144 does not prohibit using AEDTs, it creates a transparency and accountability framework around them. Employers who conduct fairness audits and notify candidates are in compliance regardless of what the audit shows.

What's Coming Next

State Legislation Pipeline

Following Colorado's lead, multiple states introduced AI bills in 2025–2026 legislative sessions. States actively advancing AI legislation include Virginia, Texas, Connecticut, Massachusetts, and Washington. Most pending bills focus on high-risk AI in consequential decisions, algorithmic transparency, and consumer disclosure, following the Colorado model.

Several states are also advancing deepfake disclosure laws, AI in political advertising restrictions, and sector-specific AI rules for healthcare and insurance. PlainRegWatch tracks all enacted and pending AI regulations across states.

Federal Proposals

At the federal level, Congress has introduced multiple AI-focused bills, including the Algorithmic Accountability Act and various sector-specific proposals for healthcare AI and financial AI. As of early 2026, no comprehensive federal AI law has been enacted. The Biden administration's Executive Order on AI (October 2023) directed agency-level guidance, and the Trump administration has taken a different regulatory approach emphasizing AI development over regulation.

EU AI Act, Global Reach

The EU AI Act is fully in effect from August 2026 and applies extraterritorially, any business whose AI systems are deployed or whose AI outputs affect EU residents must comply, regardless of where the company is based. US companies serving EU customers with AI-powered products are in scope.

The EU AI Act categorizes AI applications by risk: unacceptable risk (prohibited), high risk (strict conformity requirements), limited risk (transparency obligations), and minimal risk (no specific requirements). High-risk categories closely mirror Colorado SB 205: employment, education, healthcare, critical infrastructure, law enforcement, and migration.

Many US businesses are treating EU AI Act compliance as their baseline, since it is the most demanding framework, meeting its requirements generally satisfies or exceeds US state requirements as well.

Where to Go Next on PlainRegWatch

Track AI regulations and related rules by state:

Frequently Asked Questions

Which US state has the most comprehensive AI law?

Colorado SB 205, effective February 1, 2026, is the most comprehensive US state AI law. It applies to developers and deployers of high-risk AI systems used in consequential decisions across employment, education, financial services, healthcare, housing, and government services.

What does the Colorado AI Act require?

Colorado SB 205 requires developers to provide risk documentation to deployers. Deployers must conduct annual algorithmic impact assessments, notify consumers when AI makes consequential decisions about them, and provide a process for appealing those decisions. Enforcement is by the Colorado Attorney General with a 60-day cure period.

Does Illinois BIPA apply to AI?

Yes, indirectly. Illinois BIPA requires written consent before collecting biometric data. AI systems using facial recognition, voice analysis, or biometric inputs trigger BIPA. Illinois also has a separate law (HB 2557) requiring disclosure and consent when AI analyzes video job interviews.

What is NYC Local Law 144?

NYC Local Law 144, effective July 2023, requires NYC employers using automated employment decision tools (AEDTs) to conduct annual independent fairness audits, publish audit summaries publicly, and notify job candidates at least 10 business days before an AEDT is used in their evaluation. Violations carry fines of $375–$1,500 per day.

Does the EU AI Act affect US businesses?

Yes, if your AI systems are deployed or affect EU residents. The EU AI Act applies extraterritorially, US companies serving EU customers with AI-powered products must comply with its risk categorization, conformity assessment, and transparency requirements, which are fully in effect from August 2026.

Key takeaways

If you build or deploy AI that touches consequential decisions, state law, not just federal policy, now sets your obligations.

  • Colorado SB 205 is the broadest state AI law in force (Feb 2026) - risk assessments, fairness audits and consumer disclosure for high-risk systems. Colorado regulations
  • PlainRegWatch tracks AI laws across 6 states; compare requirements before you deploy in a new jurisdiction. Compare AI laws
  • NYC Local Law 144 already requires annual bias audits for automated hiring tools, audit obligations are live now, not future.

This guide is general information, not legal advice; AI regulation is moving quickly, confirm current obligations with counsel.

Every figure on PlainRegWatch is rendered directly from state source data, no number is typed in by an editor. This page draws directly on federal and state source data, no figure is typed in by an editor. See our editorial standards & corrections policy, the methodology behind these numbers, or report a data error.