Skip to main content
State & Local

State AI policy and what it means for vendors

Most of what circulates about state AI law describes bills. A bill that passed is not a duty you owe. The distance between the two is measured in years, and in at least one state the headline statute was rewritten before a single obligation under it ever attached to anyone.

Passed, in force, and enforceable are three different words

The National Conference of State Legislatures counted roughly 100 artificial intelligence measures enacted or adopted across 38 states in the 2025 session alone. Almost none of that volume changes what a software vendor has to do this quarter. Some of it regulates state agencies rather than their suppliers. Some sets duties that begin in 2027 or 2028. Some was replaced by a later act before the first compliance date arrived. A vendor who reads a summary of what "passed" and starts building controls is often building against text that no longer governs.

What follows reads the primary sources: enrolled bill text, session-law effective dates, and the pages of the offices that will enforce these laws. Every date comes off a legislature's own record, and anyone selling a product that touches hiring, lending, housing, benefits, insurance, health care, or education can check the same documents.

Colorado is the case study, and it is not the one people cite

Colorado is quoted more than any other state, because Senate Bill 24-205 was the first broad American AI statute: developer duties, deployer duties, impact assessments, consumer notice, an appeal with human review. Governor Polis signed it May 17, 2024, with obligations set to begin February 1, 2026.

They did not begin. In an August 2025 special session the legislature passed SB 25B-004, approved August 28, 2025 and effective November 25, 2025, which pushed the start to June 30, 2026. Then, in the 2026 regular session, Senate Bill 26-189 repealed and reenacted the whole thing. It was signed May 14, 2026 and recorded as chapter 131 with an effective date of the same day, six weeks before the June 30 obligations would have first attached. The new duties begin January 1, 2027.

So the version of Colorado law that most vendor briefings summarize is a version no company ever had to comply with. The operative text is now framed around automated decision-making technology, defined as technology that processes personal data and uses computation to generate output including predictions, recommendations, classifications, rankings, or scores used to make, guide, or assist a decision about an individual. A consequential decision is one relating to access to, eligibility for, or compensation related to education, employment, housing, financial or lending services, insurance, health-care services, or essential government services and public benefits.

Starting January 1, 2027, a developer of a covered technology must give each deployer technical documentation describing intended uses, categories of training data, known limitations, and instructions for appropriate use and human review, and must notify deployers of material updates. Both sides keep compliance records for at least three years. Deployers give consumers clear and conspicuous notice at the point of interaction, and after an adverse outcome must supply a plain-language description of the system's role within 30 days. Consumers may request their personal data, correct factually incorrect data, and ask for meaningful human review and reconsideration. The attorney general enforces through the Colorado Consumer Protection Act, a violation counts as a deceptive trade practice, and before January 1, 2030 the office must give 60 days' notice and an opportunity to cure where a cure is possible. There is no new private right of action, though the act does allocate fault between developers and deployers in discrimination suits brought under existing law.

Colorado also passed HB 26-1263, the conversational AI service operator requirements, signed in May 2026 as chapter 208. Its operator duties also begin January 1, 2027: age estimation, disclosure that the service is AI, protocols for prompts involving self-harm, restrictions on engagement mechanics and simulated emotional dependence for known minors, an annual report to the attorney general, and a bar on claiming output is equivalent to a licensed professional's services.

The Colorado attorney general filed proposed rules for both acts on August 11, 2026, with a public comment period running to October 26, 2026 and early submissions requested by October 5. That is the signal worth watching. A state opens rulemaking when it expects a law to operate.

What is actually in force

Strip out the pending and the superseded and the map gets small enough to act on. These are the regimes with duties a vendor can violate today, plus the deadlines already on the calendar.

JurisdictionInstrumentStatus as of August 2026What it asks of a vendor
UtahUtah Code 13-75-101 to 13-75-106 (SB 226, 2025)In force since May 7, 2025Tell a person they are talking to generative AI when they ask. Disclose up front in licensed-profession settings.
TexasHB 149, Texas Responsible Artificial Intelligence Governance ActIn force since January 1, 2026Avoid the enumerated intentional harms. Government-facing systems carry extra rules.
IllinoisPublic Act 103-0804, amending 775 ILCS 5/2-102In force since January 1, 2026No AI in employment decisions that discriminates in effect, no zip code as proxy, notice to employees.
CaliforniaAB 2013 training-data transparencyPosting duty began January 1, 2026Publish documentation of training data for public generative systems.
CaliforniaSB 942 as amended by AB 853Core duties operative August 2, 2026Provenance in outputs and a free public detection tool, above a user threshold.
New YorkLOADinG Act, State Technology Law art. 4Signed December 21, 2024State agencies may not procure your system for covered functions without real human review.
ColoradoSB 26-189 and HB 26-1263Enacted May 2026, duties begin January 1, 2027Developer documentation package, consumer notice, adverse-outcome explanation, human review.

Utah wrote the rule that is easiest to break by accident

Utah's is the shortest of these statutes and the one most likely to catch a product team off guard, because it turns on a user's question rather than on a risk category. Under Utah Code 13-75-103, a supplier using generative AI to interact with an individual in a consumer transaction must disclose that the individual is interacting with generative AI and not a human, if the individual asks or otherwise prompts the supplier about whether AI is being used. The statute requires the question be a clear and unambiguous request. A support chatbot that deflects "am I talking to a person?" is the violation, and it is the kind of behavior a model can produce without anyone intending it.

The second duty is heavier. Someone providing services in a regulated occupation, meaning one licensed or state-certified by the Utah Department of Commerce, must prominently disclose generative AI use when the interaction is high-risk. High-risk covers collection of health, financial or biometric data, and personalized advice a person could reasonably rely on for significant decisions, with financial, legal, medical and mental-health advice named. Disclosure goes verbally at the start of a verbal interaction and in writing before a written one.

Section 13-75-104 is the part product teams should read first, because it is a design instruction rather than a legal one. A person is not subject to enforcement if the generative AI itself clearly and conspicuously discloses, at the outset and throughout the interaction, that it is generative AI, is not human, or is an AI assistant. Persistent labeling in the interface discharges the duty and removes the dependence on correct model behavior under an ambiguous prompt.

Utah's Division of Consumer Protection enforces, with administrative fines up to $2,500 per violation and up to $5,000 per violation of a resulting order. Utah also runs an Office of Artificial Intelligence Policy inside the Department of Commerce and an AI regulatory sandbox at Utah Code 13-72-401, where a company can test under state observation. The broader Artificial Intelligence Policy Act that created that office carries a repeal date of July 1, 2027, which is worth a calendar entry rather than an assumption.

A support chatbot that deflects "am I talking to a person?" is the violation, and it is the kind of behavior a model can produce without anyone intending it.

Texas made intent the test, and named a framework as the defense

The Texas Responsible Artificial Intelligence Governance Act was signed June 22, 2025 and took effect January 1, 2026. It went a different direction from Colorado's first draft. Rather than imposing process duties on anyone deploying a high-risk system, it prohibits specific intentional conduct: developing or deploying a system intentionally aimed at inciting self-harm, harm to others, or criminal activity; developing a system with intent to unlawfully discriminate against a protected class; producing child sexual abuse material or sexualized deepfakes of minors; and developing a system with the sole intent to infringe constitutional rights.

The discrimination provision states plainly that disparate impact alone is not sufficient to show intent. That single sentence separates Texas from every other regime on this page and is the reason a model that shows an outcome gap in Texas is a different legal problem than the same model in Illinois.

Governmental entities carry rules private firms do not. A government entity may not deploy a system that assigns social scores leading to detrimental treatment, and may not use AI with biometric identifiers to uniquely identify an individual without consent where doing so infringes rights. Government agencies offering consumer-facing AI must disclose clearly and conspicuously before or at the time of interaction, and health-care providers using AI in treatment must disclose no later than the start of service. If you sell into a Texas agency, those obligations land in your product and your statement of work, not just in the buyer's policy binder.

Enforcement sits with the attorney general alone, and there is no private right of action. A complaint portal feeds civil investigative demands, and a 60-day cure period follows a notice of violation. Uncured penalties run $10,000 to $12,000 for curable violations, $80,000 to $200,000 for uncurable ones, and $2,000 to $40,000 per day for continuing violations.

The defensive structure matters more than the penalty schedule. Developers and deployers get a rebuttable presumption of reasonable care, and are shielded where a violation is found through feedback channels, testing, red-team exercises, compliance with state guidelines, or adherence to the NIST AI Risk Management Framework. Texas also created a Department of Information Resources sandbox allowing tests for up to 36 months, and a seven-member Texas Artificial Intelligence Council. A vendor who runs adversarial testing and documents it against a named framework is buying something concrete in Texas, not signaling diligence.

California is not one clock. It is four.

California legislates in narrow instruments with staggered dates, and treating it as a single deadline is how teams miss one.

Training-data transparency. AB 2013 was chaptered September 28, 2024, and its posting duty began January 1, 2026. A developer of a generative system made publicly available in California must post documentation of the data used to train it, covering sources, dataset description, counts, copyright and license status, whether personal information was included, and whether synthetic data was used. It reaches back to systems released on or after January 1, 2022, and applies again before each substantial modification. Carve-outs exist for systems built solely for security and integrity purposes, for aircraft operation, and for those developed exclusively for federal national security or defense use.

Content provenance. SB 942, the California AI Transparency Act, applies to a covered provider whose publicly accessible generative system has over one million monthly visitors or users in California. It requires latent disclosure embedded in generated content carrying provider name, version, time of creation, and a unique identifier, a manifest disclosure option the user can apply, and a free public detection tool. Penalties are $5,000 per violation with each day counted separately, enforced by the attorney general, city attorneys, and county counsels. AB 853, chaptered October 13, 2025, moved the operative date from January 1, 2026 to August 2, 2026, added duties for large online platforms starting January 1, 2027, and added latent disclosure requirements for capture device manufacturers starting January 1, 2028.

Frontier model transparency. SB 53, the Transparency in Frontier Artificial Intelligence Act, was signed September 29, 2025. Large frontier developers publish a framework covering risk management, cybersecurity and catastrophic risk assessment, publish transparency reports before deploying new frontier models, send quarterly risk summaries to the Office of Emergency Services, report critical safety incidents within 15 days or 24 hours where danger is imminent, and maintain anonymous internal reporting channels. This one reaches a short list of companies, and quoting it as though it binds every AI vendor is a common error.

Privacy regulations. The California Privacy Protection Agency's rules on automated decisionmaking technology, risk assessments, and cybersecurity audits cleared the Office of Administrative Law on September 22, 2025 and took effect January 1, 2026. The compliance dates are later and staggered. Businesses using such technology for significant decisions must comply with the ADMT requirements beginning January 1, 2027. Risk assessment obligations began January 1, 2026, with attestations and summaries due April 1, 2028. Cybersecurity audit submissions are due April 1, 2028 for businesses above $100 million in revenue, April 1, 2029 between $50 and $100 million, and April 1, 2030 below $50 million.

For state agency customers there is a fifth thread. SB 896, the Generative Artificial Intelligence Accountability Act, was chaptered September 29, 2024. It directs risk analysis of generative AI threats to critical infrastructure and requires that when a state agency uses generative AI to communicate directly with a person about government services or benefits, the communication carry a prominent disclaimer that it was generated by generative AI, with placement rules that vary by medium, plus information on how to reach a human employee. If you are building an agency-facing assistant in California, those disclaimers are a product requirement.

Illinois regulates the outcome. New York regulates the purchase.

Illinois Public Act 103-0804 took effect January 1, 2026 and amended the Illinois Human Rights Act rather than creating a standalone AI statute. Under 775 ILCS 5/2-102, it is a civil rights violation for an employer to use artificial intelligence that has the effect of subjecting employees to discrimination on the basis of protected classes, or to use zip codes as a proxy for protected classes, in recruitment, hiring, promotion, renewal, selection for training or apprenticeship, discharge, discipline, tenure, or terms and conditions of employment. It is a separate violation to fail to give notice that AI is being used for those purposes. The Act defines both artificial intelligence and generative artificial intelligence, and directs the Illinois Department of Human Rights to adopt rules on when notice is required, the time period for giving it, and the means.

Read the operative words. "Has the effect of" is an effects test sitting inside a civil rights statute that already has enforcement machinery and a body of law about proof. It is the mirror image of the Texas intent standard, and a hiring product sold nationally has to satisfy both at once.

New York went at the problem from the buyer's side. The Legislative Oversight of Automated Decision-making in Government Act, signed December 21, 2024, adds article 4 to the State Technology Law. Section 402(1) bars a state agency from using an automated decision-making system for functions related to public assistance benefits, functions with material impact on rights, civil liberties, safety or welfare, or functions affecting a statutory or constitutional right, unless the system is subject to continued and operational meaningful human review. Section 402(2) applies the same condition to procurement: no state agency shall authorize the procurement, purchase, or acquisition of any service or system using or relying on such a system for those functions unless that human review is in place.

"Meaningful human review" is defined, and the definition is demanding. It means review, oversight, and control by individuals who understand the risks, limitations, and functionality of the system, who are trained to use it, and who have authority to intervene or alter the decision, including the ability to approve, deny, or modify any decision the system recommends or makes. A reviewer who can only rubber-stamp does not satisfy it. Agencies also owe the legislature a disclosure of the systems they use that includes a list of software vendors. Your company name goes in a public document.

The four artifacts that travel

Different statutes, converging asks. The same small set of artifacts keeps discharging obligations across these regimes, and building them once beats building them state by state. The ranking below is a judgement about breadth of coverage.

How far one artifact carries across the in-force regimes

System documentation: intended use, training-data categories, known limits
92%
Point-of-interaction disclosure, persistent and on by default
90%
A human-review path where the reviewer can change the outcome
86%
Adverse-outcome explanation produced inside a fixed window
78%
Retention of compliance records for three years
75%
Testing program mapped to a named risk framework
68%

Editorial ranking of how many in-force state obligations each artifact helps satisfy at once, drawn from the statutes cited above. A comparative judgement, not a measured statistic.

The framework question deserves a straight answer. The NIST AI Risk Management Framework 1.0 was released January 26, 2023, is organized around Govern, Map, Measure and Manage, and was joined July 26, 2024 by the Generative AI Profile, NIST AI 600-1. NIST has said it is under revision. Texas names the framework in statute as a basis for its safe harbor, and Colorado's 2024 text named both it and ISO/IEC 42001 before that text was replaced. No state certifies conformance, so it buys a defensible answer to "what standard did you follow," not a compliance stamp. That is still the cheapest evidence a vendor can produce.

Getting a product to a defensible position

1
List every state where the product runs and every decision it touches; drop the states with no in-force duty
1 week
2
Classify each use against the named decision categories: employment, lending, housing, insurance, health, benefits, education
1–2 weeks
3
Turn on persistent AI disclosure in every conversational surface, then check it survives an adversarial prompt
2–4 weeks
4
Write the documentation package a deployer will need: intended use, training-data categories, limits, human-review instructions
3–6 weeks
5
Build the human-review path and the adverse-outcome explanation, and time how long producing one takes
4–8 weeks
6
Run and record testing against a named framework; keep the artifacts on the three-year retention clock
Ongoing

What shows up in the contract

Public buyers move faster than legislatures here. Long before a statute reaches your product, its language turns up in a solicitation attachment. Expect these.

  • A human-review representation, tracking New York's definition: a trained reviewer with authority to approve, deny, or modify what the system recommends.
  • A documentation deliverable naming intended uses, training-data categories, and known limitations, due at delivery rather than on request.
  • Disclosure obligations pushed into the interface, including the disclaimer and route-to-a-human pattern California requires of its own agencies.
  • Records retention long enough to answer a regulator years later, with three years now the reference point in Colorado's 2027 framework.
  • A named risk framework in the technical response, since Texas ties its safe harbor to one and evaluators increasingly ask which one you used.
  • Cloud security verification through GovRAMP, formerly StateRAMP, a nonprofit running NIST-based verification with 70-plus government organizations engaged and an AI task force of its own.
  • Notice and cure mechanics, since Texas and Colorado both build a cure period into enforcement and buyers copy it.

Where this is genuinely unsettled

Two things are moving and should be described that way. The first is federal preemption of state AI law, proposed in more than one form and not resolved into a settled answer. Nothing above has been withdrawn on that basis, and Colorado opening rulemaking in August 2026 is a state proceeding as though its law will operate. Planning against the state map as it stands is the conservative choice.

The second is the definitional layer. Colorado's 2026 act, the Illinois amendments and the Utah chapter each define artificial intelligence differently, and Colorado moved from "artificial intelligence system" to "automated decision-making technology" between drafts. That is not cosmetic. A scoring model with no learned component can fall inside an automated decision-making definition while sitting outside a narrower AI definition. When a customer asks whether your product is covered, the honest answer starts with which definition they are reading.

Bottom line

Read the session law, not the summary. Check the effective date and the applicability date separately, because they differ often and the gap is where the real answer lives. Then build the four artifacts that satisfy most of these regimes at once: documentation a deployer can use, disclosure that does not depend on a model behaving well, a human-review path with real authority behind it, and an explanation you can produce quickly after an adverse outcome. A vendor holding those answers a buyer's diligence questionnaire in a day and sells into Texas, Illinois, California and New York without maintaining four products. A vendor holding none of them hears about it from a procurement officer, which is the expensive way to find out.

Frequently asked questions

Does the Colorado AI Act apply to my product today?

No. The 2024 statute was delayed to June 30, 2026 and then repealed and reenacted by SB 26-189, signed May 14, 2026, before those obligations attached. The replacement framework governs automated decision-making technology used in consequential decisions and its duties begin January 1, 2027. Colorado's attorney general filed proposed rules on August 11, 2026 with comments open to October 26, 2026.

Which state duty is a vendor most likely to be violating right now?

Utah's disclosure rule. It has been in force since May 7, 2025 and triggers when a user asks whether they are talking to a human. Any conversational product deployed into a consumer transaction can fail it. The statutory safe harbor rewards a persistent interface label that identifies the assistant as AI at the outset and throughout, which removes the dependence on model behavior.

Does adopting the NIST AI Risk Management Framework make a company compliant?

No state certifies conformance to it. Texas names adherence to it among the grounds that shield a developer or deployer from liability, and it gives a documented answer to what standard you followed. Treat it as evidence and as an organizing structure, not as a compliance certificate. NIST released version 1.0 on January 26, 2023 and the Generative AI Profile in July 2024, and has said the framework is being revised.

We only sell to government agencies. Do private-sector AI statutes still matter?

Yes, in two ways. Some laws bind government buyers directly, which pushes requirements into your product: New York conditions agency procurement on meaningful human review, Texas restricts government use of biometric identification and social scoring and requires disclosure on consumer-facing agency systems, and California requires disclaimers on agency generative AI communications. Separately, buyers copy private-sector statutory language into contract terms well before those statutes would reach you.

How do the Texas and Illinois standards differ for a hiring product?

They point opposite directions. Texas requires intent to discriminate and states that disparate impact alone is not sufficient to establish it. Illinois makes it a civil rights violation to use AI that has the effect of subjecting employees to discrimination, and separately bars using zip codes as a proxy for protected classes, with notice required. A product sold in both states has to hold to the effects test, because it is the stricter of the two.

1 business day response

Need the documentation package a state buyer will ask for?

We build models, decision systems and the evidence that goes with them: intended-use documentation, human-review workflows, adverse-outcome explanations, and testing records mapped to a named framework. Prime or subcontract.

CapabilitiesMore insights →Start a conversation
UEI Y2JVCZXT9HP5CAGE 1AYQ0NAICS 541512SAM.GOV ACTIVE