US AI Regulation: 1,500+ State Bills Collide With Federal Orders
There is no single federal AI law in the United States, and there won’t be one in 2026. What exists instead is a fast-moving mix of executive orders, agency enforcement under old statutes, and a state legislative surge that has produced more than 1,500 AI-related bills nationwide. Businesses need to adopt the NIST AI Risk Management Framework now, track state disclosure and impact-assessment rules in every jurisdiction they touch, and watch for a federal preemption fight that could reshape all of it by year’s end.
TL;DR:
- Over 1,500 AI-related bills across all 50 states create a complex legal patchwork with inconsistent definitions, assessment requirements, and enforcement risks.
- Most federal enforcement relies on existing statutes applied to AI conduct, making sector-specific agencies the primary regulators for now.
- The NIST AI Risk Management Framework is the de facto standard for AI governance, with adoption seen as a baseline for reasonableness, despite remaining voluntary.
- States like Colorado and California impose impact assessments, transparency, and liability provisions that often mirror or extend the NIST approach, increasing compliance complexity.
- Companies should layer adherence to the NIST framework with detailed jurisdictional tracking, vendor due diligence, and impact assessment documentation to manage evolving risks.
Table of Contents
- Federal AI Regulation in the US: Executive Orders, NIST, and Agency Enforcement
- The State AI Law Patchwork: Colorado, California, New York, and Beyond
- How AI Rules Are Actually Being Enforced Right Now
- Pending Federal AI Legislation and Legislative Intent in 2026
- Building an AI Compliance Program: A Practical Checklist for US Businesses
- Key AI Laws, Effective Dates, and Enforcement Authorities
- What the Patchwork Means for Competitiveness and Risk
- Where to Go for Deeper AI Policy Analysis
- Primary Sources to Track for AI Regulation in the US
- Sources
Federal AI Regulation in the US: Executive Orders, NIST, and Agency Enforcement
The federal government has chosen executive action over legislation, and that choice defines how AI regulation in the US actually works right now. Two executive orders anchor the current posture. The earlier one set a deregulatory tone, prioritizing American AI competitiveness and directing agencies to remove rules seen as slowing innovation. The more consequential one, Executive Order 14365, goes further: it directs federal agencies to build a national AI policy framework, creates an AI Litigation Task Force, and instructs agencies to evaluate state AI laws for conflicts with federal interests, including the possibility of conditioning federal funding on state compliance.
That last piece matters more than most coverage gives it credit for. An executive order can’t override a state statute on its own, but a litigation task force paired with funding leverage is a real mechanism, not a symbolic gesture. States that pass aggressive AI rules should expect legal challenges and, potentially, pressure through federal grant conditions tied to infrastructure, research, or broadband dollars.
Why the NIST AI RMF matters more than its “voluntary” label suggests
Absent binding federal rules, the NIST AI Risk Management Framework has become the closest thing to a national standard. It organizes AI governance into four functions: Govern, Map, Measure, and Manage. Govern sets accountability structures across legal, product, and security teams. Map identifies context and risk exposure for a given AI use case. Measure quantifies and tracks those risks with testing and metrics. Manage covers response, mitigation, and ongoing monitoring.
NIST has kept building on that base. A generative AI profile addresses risks specific to large language models and content-generation tools, and a 2026 concept note extends RMF thinking to AI used in critical infrastructure. None of this is legally mandatory. But regulators, auditors, and plaintiffs’ attorneys increasingly treat RMF adoption as the baseline for “reasonable” AI governance, the same way NIST’s cybersecurity framework became a de facto legal benchmark long before any statute required it.
Pro Tip: Document your NIST RMF mapping and measurement steps as you go, not after an incident. Regulators and courts look for a paper trail showing active risk management, not a framework you can recite but never applied.
Several agencies aren’t waiting for new legislation. Each is applying existing statutory authority to AI-driven conduct:
- FTC — pursues AI claims under unfair and deceptive practices authority, targeting inflated capability claims and algorithmic pricing or discrimination.
- FCC — treats AI-generated robocalls and voice cloning as violations of existing telemarketing and consumer-protection rules.
- SEC — requires AI-related disclosures from public companies and scrutinizes “AI washing” in investor communications.
- DOJ — applies civil rights and antitrust statutes to algorithmic decision-making, including hiring and lending tools.
- FDA — regulates AI-enabled medical devices and diagnostic software under existing medical device frameworks.
- EEOC — applies employment discrimination law to AI hiring, screening, and performance-evaluation tools.
CRS analysis makes a point worth sitting with: sector-specific regulators are the most immediate source of binding AI rules for most companies, precisely because they don’t need new legislation to act. They’re applying statutes that predate generative AI by decades to conduct that didn’t exist when those statutes were written.
Procurement is the other quiet lever. Federal agencies can require NIST RMF compliance, specific documentation, or vendor certifications as a condition of winning federal contracts or grants. For any company that sells to the federal government, that’s not guidance. That’s a gate.
The State AI Law Patchwork: Colorado, California, New York, and Beyond
If federal policy sets the outer boundary, state law is where most AI compliance obligations actually live. State legislatures introduced AI-related bills at a pace few anticipated, with trackers counting well over 1,500 bills across all 50 states as of early 2026. That volume alone tells you something: no single state’s approach is going to become the national default anytime soon.
A few patterns recur across the states that have actually passed laws rather than just introducing bills:
- Transparency and watermarking requirements for AI-generated content, especially political and commercial media.
- Impact assessments for “high-risk” AI systems used in employment, housing, credit, or healthcare decisions.
- Companion chatbot disclosure rules requiring apps to identify themselves as AI, particularly to minors.
- Deepfake and nonconsensual imagery laws with takedown and removal mandates.
- Algorithmic discrimination provisions that create liability for biased automated decisions, sometimes with a private right of action attached.
Colorado moved first and furthest on comprehensive coverage. The Colorado AI Act targets “high-risk” AI systems, defined as those making or substantially influencing consequential decisions in employment, lending, housing, healthcare, and education. It requires developers and deployed to conduct impact assessments, disclose AI use to consumers, and implement risk management programs that closely mirror NIST RMF structure, which is not a coincidence.
California has moved on multiple fronts simultaneously, and legal trackers treat it as the most consequential state to watch. SB 53, the Transparency in Frontier AI Act, imposes safety and transparency reporting obligations on developers of the largest frontier AI models. SB 243 requires companion chatbot operators to disclose AI status clearly and build in safeguards for minors and vulnerable users. AB 2013 mandates disclosure of training data summaries for generative AI systems, and SB 942 requires detection tools and provenance disclosures for AI-generated content from major platforms.
New York’s RAISE Act (and subsequent amendments) focuses on frontier AI safety reporting for large model developers, echoing California’s approach but with its own thresholds and enforcement mechanics. Illinois has moved specifically on employment, restricting or conditioning AI use in hiring decisions and requiring notice to candidates. Texas has taken a narrower, more industry-friendly path, focused on government use of AI and specific harms like deepfakes in elections, rather than broad private-sector impact assessments.
| Law | Jurisdiction | Focus area | Key obligation |
|---|---|---|---|
| Colorado AI Act | Colorado | High-risk systems | Impact assessments, consumer disclosure |
| SB 53 | California | Frontier AI models | Safety and transparency reporting |
| SB 243 | California | Companion chatbots | AI disclosure, minor safeguards |
| AB 2013 | California | Generative AI training data | Public training data summaries |
| SB 942 | California | AI-generated content | Detection tools, provenance labels |
| RAISE Act | New York | Frontier AI safety | Safety incident reporting |
The practical problem isn’t any single law. It’s that a company operating in a dozen states now faces a dozen different definitions of “high-risk,” different assessment formats, different disclosure timelines, and in some states, a private right of action that lets individual consumers sue directly rather than waiting for a regulator to act. Research from Communications of the ACM finds that this fragmentation materially raises compliance costs and legal uncertainty, and it’s a major reason industry groups are lobbying hard for federal preemption.
How AI Rules Are Actually Being Enforced Right Now
Enforcement is already happening, and it doesn’t require a comprehensive AI statute to bite. Agencies are using existing tools against AI-specific conduct, and state actors are moving fast on their own laws.

The FTC has pursued unfair and deceptive practices claims against companies that overstated what their AI products could do or used algorithmic pricing in ways that harmed consumers. The FCC has acted against AI-generated robocalls and voice cloning under telemarketing law that predates generative AI entirely. The SEC has flagged public companies for “AI washing,” meaning disclosures that overstate AI capabilities to investors. The FDA continues to apply medical device regulation to AI diagnostic tools, and the EEOC has opened inquiries into AI hiring tools accused of screening out protected classes.
State attorneys general and private plaintiffs are moving in parallel, often faster than federal agencies. Categories showing up repeatedly include companion chatbot lawsuits alleging harm to minors, nonconsensual deepfake cases now backed by federal takedown authority, and algorithmic discrimination claims in lending and hiring.
- Nonconsensual deepfakes now trigger federal removal obligations under the Take It Down Act, which requires platforms to remove flagged intimate imagery, including AI-generated content, within set timeframes.
- Chatbot harm claims are testing state disclosure laws like California’s SB 243 in real litigation, not just regulatory guidance.
- Algorithmic discrimination suits increasingly cite state impact-assessment failures as evidence of negligence, even when the underlying harm claim is a traditional one like wrongful denial of credit.
The AI Litigation Task Force created under Executive Order 14365 adds a new wrinkle: a federal body specifically built to challenge state AI laws seen as conflicting with national policy. For companies operating across multiple states, that means the legal ground could shift mid-compliance-cycle if a state law gets successfully challenged or preempted.
Pro Tip: Keep a jurisdiction-by-jurisdiction log of every AI-related compliance action you take. If a state law changes or gets struck down, you need to show you were acting in good faith under the rules that existed at the time, not scrambling retroactively.
Typical enforcement outcomes so far include mandated content removal, civil penalties, consent decrees requiring ongoing audits, and injunctive relief barring specific AI deployments until compliance gaps are fixed. None of these require a jury to decide novel questions about “AI harm.” They’re built on existing legal theories applied to new technology.
Pending Federal AI Legislation and Legislative Intent in 2026
Congress has multiple AI bills in committee, and the White House has pushed its own legislative recommendations favoring a unified national standard over the state patchwork. The core policy fight is preemption: should a federal framework override state AI laws, and if so, how much room does it leave states to protect consumers?
CRS analysis suggests sector-specific agency action will remain the primary regulatory force for most of 2026, regardless of what happens with broader legislation. That’s a useful expectation-setter. Even optimistic timelines for a comprehensive federal AI statute run into the same wall every major tech legislation hits: disagreement over the scope of preemption, private right of action provisions, and which agency gets primary enforcement authority.
Watch these signals rather than the bill headlines themselves:
- Committee calendars in the House Energy and Commerce Committee and Senate Commerce Committee, where most AI framework bills currently sit.
- OMB and procurement guidance updates, since federal contracting requirements often move faster than statutes and quietly become de facto national rules.
- Agency rulemaking dockets at the FTC, FCC, and SEC, where formal rulemaking can lock in requirements without needing new legislation.
- AI Litigation Task Force filings, which will signal which state laws the federal government considers most vulnerable to preemption challenges.
If a national standard does pass, expect it to set a compliance floor rather than eliminate state activity entirely, particularly in areas states consider consumer protection rather than technology regulation, like biometric privacy or child safety. If it doesn’t pass, which is the more likely near-term outcome, the state patchwork keeps expanding and companies keep building compliance programs state by state.
Building an AI Compliance Program: A Practical Checklist for US Businesses
Waiting for regulatory clarity is not a strategy. The businesses managing this landscape best have already built compliance programs around the NIST framework and layered state-specific requirements on top. Here’s a prioritized approach:
- Adopt NIST AI RMF as your governance backbone. Assign Govern-function ownership across legal, HR, product, and security teams rather than treating AI risk as an IT problem. Enforcement patterns so far show regulators looking for documented mapping and measurement, not just a policy binder.
- Build modular impact assessments. Design a base assessment template that can be tuned by jurisdiction, since Colorado, California, and other states define “high-risk” differently. A single national template that gets patched state by state avoids costly rebuilds every time a new law passes.
- Maintain a centralized model inventory. Know exactly which AI systems you use, what they do, what data trains them, and which jurisdictions’ rules apply to each deployment. You cannot comply with a disclosure law for a system you haven’t inventoried.
- Tighten vendor due diligence and contracts. Require AI vendors to warrant NIST RMF alignment, disclose training data sources where relevant, and indemnify against known compliance gaps. Most AI liability exposure for mid-size companies comes through third-party tools, not in-house models.
- Build incident response processes specifically for AI failures. A biased hiring algorithm or a chatbot disclosure failure needs its own escalation path, distinct from general data breach response, because the remediation obligations differ.
- Document testing and decisions as you go. How AI bias shows up in financial models illustrates why after-the-fact justification rarely satisfies regulators. Contemporaneous documentation is what separates a defensible compliance program from a liability.
Pro Tip: Treat jurisdictional gating, meaning the ability to turn features on or off by state, as a core product requirement, not an afterthought. It’s far cheaper to build that flexibility now than to retrofit it after a state law forces an emergency rollback.
Sector add-ons matter here too. Financial services firms need to layer AI governance into existing model risk management frameworks, particularly around credit and lending algorithms subject to fair lending law. Healthcare organizations need AI compliance to intersect with HIPAA and FDA medical device rules, not sit as a separate track. Employers need hiring and performance-evaluation AI tools vetted against both EEOC guidance and specific state and local rules, including New York City’s automated employment decision tool law and Illinois’s AI hiring notice requirements.
Key AI Laws, Effective Dates, and Enforcement Authorities
| Law | Jurisdiction | Key date | Enforcement authority |
|---|---|---|---|
| EO 14365 (National Policy Framework) | Federal | Issued December 2025 | White House / federal agencies |
| NIST AI RMF (Generative AI profile) | Federal (voluntary) | Ongoing updates through 2026 | NIST (non-binding standard) |
| Colorado AI Act | Colorado | Phased implementation | Colorado Attorney General |
| SB 53 (Frontier AI) | California | 2026 reporting obligations begin | California Attorney General |
| SB 243 (Companion chatbots) | California | 2026 disclosure requirements | California Attorney General |
| Take It Down Act | Federal | Removal obligations active | FTC / platform enforcement |
Several rulemaking windows close through 2027, particularly around California’s frontier model reporting thresholds and Colorado’s phased high-risk system deadlines, so treat this table as a starting point for tracking, not a final answer.
What the Patchwork Means for Competitiveness and Risk
The federal government is betting that a lighter regulatory touch keeps American AI companies ahead of international competitors, while states are betting that consumer protection can’t wait for Washington to act. Both bets have real economic logic behind them, and that tension isn’t resolving in 2026. It’s escalating.

The businesses I’d worry about aren’t the ones facing the toughest state law. They’re the ones treating this as a wait-and-see situation, assuming a federal standard will eventually simplify everything and make current compliance work moot. That bet is backwards. Even if a national framework passes, it will likely set a floor, not a ceiling, meaning state consumer-protection provisions on biometric data, child safety, and algorithmic discrimination probably survive in some form regardless of what Congress does. Building for the strictest current state requirement is cheaper than reverse-engineering a program after the fact.
Policymakers reading this should recognize that fragmentation isn’t just a business complaint. It’s creating uneven protection for consumers depending on which state they live in, which is precisely the outcome federal preemption efforts claim to want to fix. Companies operating in multiple states should treat active engagement with state legislative sessions as a normal cost of doing business now, not an occasional lobbying expense reserved for crisis moments.
— Josh
Where to Go for Deeper AI Policy Analysis
Tracking AI regulation in the US means watching executive orders, state legislative sessions, and agency enforcement actions simultaneously, which is exactly the kind of interpretive work Joshthinks does across its AI & Tech coverage.

If you found the federal-state tension here useful, related pieces dig into how AI is reshaping the labor market and how algorithmic tools are already influencing political messaging in ways state disclosure laws are trying to catch up with. For readers thinking about how policy shifts like these ripple into markets, Joshthinks also breaks down how futures markets price in regulatory risk, which is a natural next read if you’re trying to connect AI policy to portfolio decisions rather than just compliance checklists. Subscribe to Joshthinks for ongoing analysis as the federal preemption fight and state legislative sessions develop through the rest of 2026.
Primary Sources to Track for AI Regulation in the US
Bookmark these directly rather than relying on secondhand summaries, since AI policy here moves fast enough that even quarterly recaps go stale:
- The White House for the full text of Executive Order 14365 and any follow-on orders.
- NIST’s AI Resource Center for the AI RMF and generative AI profile updates.
- CRS reports via Congress.gov for nonpartisan analysis of pending federal AI legislation.
- State legislation trackers like Multistate for real-time bill counts and status across all 50 states.
- Law firm regulatory trackers, such as Wilson Sonsini’s AI developments page, for plain-language breakdowns of new state statutes and effective dates.
Sources
- Executive Order 14365 (Presidential document)
- NIST AI Risk Management Framework (AI RMF)
- Multistate
- Recent AI Regulatory Developments in the United States — Wilson Sonsini
- CRS product on Congressional approaches to AI regulation
