There is no shortage of state AI law round-ups. The problem is that almost all of them are alerts: written the week something passed, accurate that week, and never revisited. When Colorado repealed its 2024 AI Act in May 2026, a large body of confident, well-written guidance became wrong overnight — and none of it changed.
This page is intended to be maintained rather than published once. It carries a last-verified date, and it tells you which claims we checked against the statute and which rest on professional commentary. That distinction is doing real work: on one of the rows below, the commentary and the statute say materially different things.
What is in force right now
| Jurisdiction | Instrument | Duties from | Who it reaches | Verified against |
|---|---|---|---|---|
| Texas | TRAIGA (HB 149) | 1 Jan 2026 | Developers and deployers; prohibitions framed around intent | Statutory text |
| California | AB 2013 | 1 Jan 2026 | Any developer of a generative AI system offered in California | Commentary |
| California | SB 53 | 1 Jan 2026 | The largest developers only | Commentary |
| Illinois | HB 3773 | 1 Jan 2026 | Employers using AI in employment decisions | Commentary |
| Colorado | SB 26-189 (ADMTA) | 1 Jan 2027 (act effective 12 Aug 2026) |
Developers and deployers of automated decision-making technology | Bill record |
| New York | RAISE Act | 1 Jan 2027 | Large frontier developers | Commentary |
“Verified against: commentary” does not mean a row is doubtful. It means we have not read the statute ourselves, so you should read it before relying on the detail — and we would rather say that than let a table imply a uniform level of confidence it does not have.
The correction: what the Texas safe harbour actually says
This is the most repeated claim in the state AI law literature, and it is stated too broadly almost everywhere.
The common summary is that substantially complying with the NIST AI Risk Management Framework gives you an affirmative defence under TRAIGA. Read that way, it is close to a free compliance shield: adopt a voluntary federal framework, gain a statutory defence.
The statute is narrower. The provision sits at §552.105(e)(2)(D), and the defence is framed around how the violation came to light. It applies where the defendant discovers the violation through an internal review process that substantially complies with the most recent version of NIST's Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile — or another nationally or internationally recognised AI risk management framework.
Two differences matter, and both cut against the popular reading:
- The trigger is self-discovery, not general compliance. The defence is built around finding your own violation through a compliant review process. An organisation that adopted the framework but never ran the review that surfaced the problem is in a materially weaker position than the summaries imply.
- It names the Generative AI Profile specifically (NIST-AI-600-1), not the core AI RMF that most "NIST-aligned" programmes are built against.
If you have been told your NIST alignment is a codified legal shield in Texas, that is worth re-checking against the text before you rely on it. This is exactly why the verification column exists.
The pattern worth understanding
Scope follows your users
The single most important structural point: these statutes reach organisations by where their systems are offered, not where the organisation sits. California's AB 2013 is the clearest case — it applies to any developer of a generative AI system offered in California, which in practice means nearly everyone building generative products for a US market.
“We are not a California company” is not an answer to AB 2013.
The same state can run statutes with wildly different reach
California illustrates this well. SB 53 imposes publication and incident-reporting duties on the largest developers — a small population. AB 2013 requires a training-data summary from a vastly larger one. Being out of scope for the famous statute tells you nothing about the other.
Definitions decide everything
Colorado's replacement act regulates automated decision-making technology in consequential decisions — not "artificial intelligence systems". A scoring rule or threshold model can fall inside that regardless of whether your team calls it AI. Illinois is scoped by use (employment decisions) rather than by technology. New York's RAISE Act is scoped by developer size.
The practical consequence: you cannot answer "which laws apply to us?" from a list of technologies. You need a list of decisions, who they affect, and where those people are.
What to do with this
- Inventory decisions, not tools. Ask which automated systems participate in decisions that materially affect people — hiring, credit, housing, pricing, benefits, access to services.
- Map those to jurisdictions by user location, not by office location.
- Separate what you build from what you buy. Nearly every statute splits duties along that line, and for bought systems your compliance ceiling is whatever documentation your vendor provides.
- Read the definitions and exemptions for any statute you think applies. Scope is decided there, and thresholds may put you out of scope entirely.
- Re-check quarterly. Colorado is the proof that a settled answer can stop being true without anything on your side changing.
What this page does not cover
Sector regulators — in health, finance, insurance and employment — already reach AI use through existing law, often more immediately than any AI-specific statute. A hiring tool can be lawful under state AI law and still breach anti-discrimination law. Municipal rules, particularly on facial recognition and automated enforcement, are also outside this map.
And this is a map of what exists, not advice about your situation. Nothing here is legal advice; where a decision turns on scope or exposure, that is a question for a lawyer licensed in the relevant jurisdiction.
How this page is maintained
Government policy is reviewed on a 60–90 day cadence on this site, and this page carries a last-verified date so you can judge for yourself whether it is current. When a statute is superseded — as Colorado's was — we mark it superseded and say what replaced it rather than quietly deleting the page. People arrive from links and search results, and a page that vanishes tells them nothing.
If you find something here that is out of date or wrong, our corrections policy explains how to tell us and what happens next.