Skip to main content

Techné AI · Free reference · Edition 3.0.0

US State Laws

Selected US AI laws in Colorado, Texas, California, New York, Illinois and other states, with dates and limits on who each provision covers.

Reviewed Download complete PDF Corrections
On this page
  1. Colorado — SB 26-189 (automated decision-making technology)
  2. Texas — HB 149 (Texas Responsible AI Governance Act, TRAIGA)
  3. California
  4. Utah — SB 226 (amending the Utah Artificial Intelligence Policy Act)
  5. Tennessee — ELVIS Act
  6. Illinois
  7. New York State — RAISE Act
  8. New York City — Local Law 144 (AEDT)
  9. Managing the differences

State and local AI requirements differ in their scope, operative dates, remedies, and enforcement arrangements. Some regulate a particular use, such as hiring or synthetic media; others impose duties on developers of frontier models. Enactment does not mean that every duty is already operative. Federal policy and litigation must also be checked for the particular provision at issue; an executive order is not a blanket repeal of state law. See US Federal.

This chapter covers selected state and local instruments, reviewed on 7 September 2026. It distinguishes enacted obligations from future operative dates and reported enforcement findings.

Colorado — SB 26-189 (automated decision-making technology)

SB 26-189, signed 14 May 2026, repealed and reenacted the framework created by SB 24-205. The replacement’s principal developer and deployer duties begin 1 January 2027. The earlier June 2026 deadline and its annual impact-assessment and risk-management-program requirements should not be used as the current compliance checklist.1

The replacement addresses automated decision-making technology (ADMT) used to materially influence consequential decisions about education, employment, housing, financial or lending services, insurance, healthcare, or essential government services and public benefits.

Core obligations:

  • Developers: provide technical documentation on intended uses, training-data categories, known limitations, appropriate use and human review; notify deployers of material updates.
  • Developers and deployers: retain records necessary to demonstrate compliance for at least three years.
  • Deployers: provide consumer notice, explain the ADMT’s role following an adverse outcome within the statutory period, and support rights to correct factually incorrect personal data and request meaningful human review and reconsideration.

Enforcement. The Attorney General enforces the act under the Colorado Consumer Protection Act. Before 1 January 2030, a 60-day notice and opportunity to cure applies where cure is possible. The act creates no new private right of action; it also addresses allocation of fault in discrimination actions under existing law.1

Texas — HB 149 (Texas Responsible AI Governance Act, TRAIGA)

Effective 1 January 2026, TRAIGA prohibits specified uses, including intentional incitement of self-harm, harm to others or criminal activity, certain government social scoring, and intentional unlawful discrimination. Disparate impact alone does not establish discriminatory intent under its discrimination provision. Disclosure duties cover government AI interactions with consumers and AI used in healthcare service or treatment, subject to the statute’s conditions. The act also establishes a regulatory sandbox.2

The Attorney General has principal enforcement authority. Penalties distinguish curable violations or breaches of a cure statement ($10,000–$12,000), uncurable violations ($80,000–$200,000), and continuing violations ($2,000–$40,000 per day). The 60-day cure protection requires correction plus a written statement, supporting documentation and preventive policy changes. State licensing agencies may impose additional sanctions in the circumstances specified by §552.106.2

California

The following California statutes address different actors and activities; their obligations should be assessed separately.

SB 53 — Transparency in Frontier Artificial Intelligence Act

Signed 29 September 2025, SB 53 distinguishes frontier developers from large frontier developers. Its requirements include:3

  • Large frontier developers: write, implement and publish a frontier AI framework addressing catastrophic risks.
  • Frontier developers: publish a transparency report before or concurrently with deployment of a new or substantially modified frontier model. Large developers include additional summaries of risk assessments, results and framework implementation.
  • Incident reporting: report critical safety incidents to the California Office of Emergency Services within 15 days of discovery. Qualifying imminent risks of death or serious physical injury require disclosure within 24 hours to an appropriate authority with jurisdiction.
  • Whistleblower protections: protect specified employee disclosures; large developers must also provide an internal reporting process.

Evidence used for other frontier-model frameworks may be relevant, but compliance with one jurisdiction does not establish compliance with another.

AB 2013 — Training Data Transparency

The initial documentation deadline was 1 January 2026. Covered developers must publish training-data documentation on their website for specified GenAI systems, services and substantial modifications released on or after 1 January 2022 and made publicly available to Californians. Publication is also required before subsequent covered releases. The documentation includes dataset sources, types, licensing, personal information, protected intellectual property and other listed characteristics, subject to statutory exceptions.4

SB 942 — California AI Transparency Act

AB 853 moved the principal operative date to 2 August 2026. Covered providers must offer a free detection tool and the option of a manifest disclosure for image, video and audio content. Specified latent provenance disclosures are required, with technical-feasibility qualifications. This is not a requirement to visibly label every output.5

AB 853 adds duties for large online platforms and GenAI hosting platforms from 1 January 2027, and specified capture-device duties from 1 January 2028. Its scope and technical requirements must be checked independently from EU transparency requirements.6

Other California laws

California also legislated on election-related synthetic media and digital replicas. Enforcement of particular election provisions has been litigated: the Attorney General’s advisory identifies court restrictions affecting AB 2655 and AB 2839. That historical advisory does not establish the present status of every provision or appeal; review current orders before relying on an election-law obligation.7

Utah — SB 226 (amending the Utah Artificial Intelligence Policy Act)

Effective 7 May 2025, SB 226 establishes distinct disclosure rules:8

  • Consumer transactions: a supplier using GenAI must identify it when the individual clearly asks whether the interaction is with AI or a human.
  • Regulated occupations: prominent disclosure is required for high-risk AI interactions, verbally at the start of a verbal interaction and in writing before a written interaction.
  • Disclosure safe harbour: conspicuous identification as AI, an AI assistant or not human at the outset and throughout the interaction can protect against enforcement of the disclosure provision.

The safe harbour is based on disclosure; it is not a general exemption for organisations overseen by a sector regulator.

Tennessee — ELVIS Act

The Ensuring Likeness, Voice, and Image Security Act (ELVIS Act), effective 1 July 2024, adds voice to the personal rights protected by Tennessee law. It addresses specified unauthorised uses and tools for reproducing an individual’s voice or likeness, subject to statutory conditions and exceptions. Voice licensing and consent deserve particular attention in entertainment and advertising.9

Illinois

  • HB 3773, effective 1 January 2026, prohibits discriminatory effects from AI used for specified employment purposes and the use of ZIP codes as proxies for protected classes. It requires notice of AI use for those purposes and assigns notice implementation details to Department of Human Rights rulemaking.10
  • The Artificial Intelligence Video Interview Act separately addresses notice, explanation and consent before AI analysis of applicant-submitted video interviews, along with restrictions on sharing, deletion on request and specified demographic reporting.11

New York State — RAISE Act

New York’s frontier-AI law was amended by S 8828 / A 9449, signed as Chapter 96 on 27 March 2026. The current provisions take effect 1 January 2027. A frontier model exceeds 10²⁶ training operations; a large frontier developer has more than $500 million in annual gross revenue together with affiliates.12

The law differentiates developer-wide obligations from large-developer framework and transparency duties. Critical-incident reporting to the designated office generally has a 72-hour trigger under §1422; qualifying imminent death or serious-injury risks require disclosure to an appropriate authority within 24 hours. Apply the statute’s knowledge and determination conditions rather than treating these clocks as interchangeable.13

New York City — Local Law 144 (AEDT)

Local Law 144 applies to covered AEDTs used by employers and employment agencies for hiring or promotion. The tool must have an independent bias audit within one year before use, with the required summary made public. Required notice to covered NYC-resident candidates and employees must precede use by at least ten business days. Enforcement began 5 July 2023.14

Reported enforcement findings: the Comptroller’s 2 December 2025 audit found weaknesses in complaint handling and review. Against DCWP’s identification of one issue, auditors identified at least 17 instances of potential noncompliance. These were audit findings, not 17 adjudicated violations. The report alone does not establish a current enforcement campaign or the status of employer investigations.15

Managing the differences

The statutes do not share a single Colorado/Texas template. A practical register should identify:

  1. The covered actor, technology, person and decision or output.
  2. The operative date, notice, records, reporting and review duties.
  3. The enforcing authority, available remedies, cure conditions and interaction with existing law.

Shared evidence can reduce duplicated work, but a review, disclosure or framework sufficient for one statute may leave another obligation unanswered.

Footnotes

  1. Colorado General Assembly. SB 26-189: enacted summary and signed act. 2

  2. Texas Legislature. HB 149 enacted text, Chapters 551–554. 2

  3. California Legislature. SB 53, Chapter 138.

  4. California Legislature. AB 2013, Civil Code §§3110–3111.

  5. California Legislature. SB 942, especially Business and Professions Code §22757.3.

  6. California Legislature. AB 853, Chapter 674.

  7. California Attorney General. Legal advisory on existing California laws and AI, including litigation notes.

  8. Utah Legislature. SB 226 enacted text.

  9. Tennessee General Assembly. 2024 legislative abstracts: Public Chapter 588, ELVIS Act.

  10. Illinois General Assembly. Public Act 103-0804, §2-102(L).

  11. Illinois General Assembly. Artificial Intelligence Video Interview Act, 820 ILCS 42.

  12. New York Senate. A 9449 / S 8828 amendment history; GBS §1420; GBS §1421.

  13. New York Senate. GBS §1422.

  14. New York City DCWP. Automated Employment Decision Tools requirements.

  15. New York State Comptroller. Report 2024-N-6, 2 December 2025.

This free handbook is a dated educational reference, not a determination of your organization's obligations. Check the source, jurisdiction and role before applying a requirement. For working documents, see TalentSight Intelligence and BoardSight Intelligence.