For companies building or deploying artificial intelligence in the United States, the regulatory question is no longer whether AI rules are coming. It is which rules apply in which state.
Congress has yet to establish a comprehensive national framework governing artificial intelligence, but state legislatures have moved ahead with their own approaches. The result is an increasingly complicated patchwork covering everything from automated hiring decisions and algorithmic discrimination to training-data disclosures, deepfakes, chatbots and frontier-model safety.
The National Conference of State Legislatures maintains an AI legislation database tracking bills across all 50 states, territories and Washington, D.C. Its categories now span private-sector AI, health care, employment, elections, cybersecurity, discrimination, provenance and other uses.
For businesses operating nationally, compliance may soon depend as much on geography as technology.

Colorado Changes Course
Colorado illustrates how quickly the rules can change.
The state initially passed one of America’s first comprehensive AI laws, targeting so-called high-risk systems involved in consequential decisions such as employment, lending, housing and health care.
But before that framework fully took effect, lawmakers reconsidered it.
Colorado ultimately replaced the original system with a new framework under SB 26-189. The revised law, scheduled to take effect January 1, 2027, focuses on automated decision-making technology that materially influences consequential decisions.
Among its provisions are requirements involving consumer notifications, information following adverse decisions and opportunities in some circumstances for human review.
The reversal itself is significant. Businesses aren’t simply preparing for AI regulation; they may have to prepare for regulations that change substantially before implementation.
California Goes Its Own Way
California is moving on several different fronts.
Governor Gavin Newsom signed the Transparency in Frontier Artificial Intelligence Act in 2025, establishing state-level requirements aimed at developers of powerful frontier AI systems.
The law includes transparency and safety provisions as well as mechanisms for reporting critical AI safety incidents. Newsom said when signing the legislation that California was acting partly because of the absence of comprehensive federal AI policy.
California also has separate requirements addressing training-data transparency and AI-generated content.
That illustrates the larger compliance challenge: a company may face multiple AI-related laws within the same state.
Texas Takes a Different Approach
Texas enacted its own framework through the Texas Responsible Artificial Intelligence Governance Act.
The law, which took effect January 1, 2026, addresses prohibited uses of AI, government deployment, biometric information and enforcement, while also creating an AI regulatory sandbox intended to allow companies to test emerging systems under specified conditions.
Texas therefore isn’t simply duplicating California or Colorado.
It is creating another regulatory model.
One AI System, Multiple Rulebooks
That is where the problem becomes operational.
Imagine an employer using the same AI-powered recruiting system nationwide. The underlying software may be identical, but disclosure, documentation, discrimination, assessment and consumer-rights requirements can differ depending on where applicants live or work.
The same problem can affect AI developers selling products to customers across multiple states. Companies must determine which laws apply, which systems are covered, what records must be maintained, what users must be told and which regulator has enforcement authority. And the target continues moving.
The AI Compliance Stack Is Growing
Businesses already navigate federal privacy, discrimination, employment and consumer-protection laws that can apply to AI. Now they are adding state-specific AI requirements on top.
For large enterprises, that may mean building compliance programs capable of tracking regulatory obligations by jurisdiction and adjusting AI deployment accordingly. For smaller companies, the burden may be considerably harder to absorb.
The U.S. may eventually adopt broader federal rules that create greater uniformity. Until then, businesses deploying AI nationally are increasingly facing something familiar from American privacy regulation: One technology. Fifty potential rulebooks.


