Which State AI Laws Apply to My Company in 2026?

The direct answer: as of August 27, 2026, four state AI laws already apply and one is pending. Texas TRAIGA has been in force since January 1, 2026, and reaches any company whose AI touches Texas residents. Illinois HB 3773, also live since January 1, 2026, covers every employer using AI in hiring or promotion decisions for Illinois workers. California SB 53 took effect the same day but only regulates frontier model developers, so most mid-market companies are out of scope as developers. Utah's narrowed UAIPA disclosure rules have applied since May 7, 2025. Colorado, the law everyone prepared for first, is not in effect: it was delayed twice and scaled back, and now starts January 1, 2027. The single highest-leverage move across all five states is documenting NIST AI RMF compliance, because Texas made it a statutory defense.
Status verified August 27, 2026. This page is updated when the regulatory status changes.
The state-by-state table
The map inverted expectations this year. Colorado passed the first comprehensive state AI law and then delayed and rewrote it, while Texas and Illinois quietly went live. Most content indexed before mid-2026 has this backwards. Here is the current state of play.
| State | Law | Status (Aug 27, 2026) | Who is in scope |
|---|---|---|---|
| Texas | TRAIGA | Live since Jan 1, 2026 | Any business using AI in Texas or serving Texas residents |
| Illinois | HB 3773 | Live since Jan 1, 2026 | Employers using AI in hiring, promotion, or discipline for Illinois workers |
| California | SB 53 + CPPA ADMT rules | SB 53 live since Jan 1, 2026; ADMT phasing in | SB 53: frontier developers only. ADMT: companies running automated decision tools on Californians |
| Colorado | Colorado AI Act | Delayed to Jan 1, 2027, scaled back | Developers and deployers of high-risk AI in consequential decisions |
| Utah | UAIPA (as amended) | Live since May 7, 2025 | Consumer-facing generative AI in health, financial, or legal advice contexts |
Texas: TRAIGA is live, and it comes with a safe harbor
The Texas Responsible AI Governance Act was signed June 22, 2025 and took effect January 1, 2026. It is an intent-based regime: liability attaches to misusing AI for discrimination, unlawful deepfakes, harm, or impairing constitutional rights, not to merely operating an AI system. Enforcement belongs exclusively to the Texas Attorney General. There is no private right of action, civil penalties run up to $200,000 per violation, and businesses get a 60-day cure period before penalties attach. The law also creates a regulatory sandbox and an AI Advisory Council.
The reach is the first thing to understand: TRAIGA covers any business operating in Texas that uses AI systems there, plus companies whose products or services are used by Texas residents. For a mid-market SaaS, healthcare, or financial services company, that effectively means you are in scope.
The safe harbor is the second thing, and it is the most commercially important sentence in any 2026 state AI law. TRAIGA provides a statutory defense for businesses that document compliance with the NIST AI Risk Management Framework, conduct adversarial testing, and keep audit trails. Documented AI governance is no longer just good practice. In Texas, it is a legal defense you can put on the table. Our practitioner's guide to implementing the NIST AI RMF walks through what that documentation actually looks like.
Illinois: HB 3773 is the one employers keep missing
HB 3773 amended the Illinois Human Rights Act effective January 1, 2026, and it is the sleeper of the group. If you use AI in hiring, promotion, or discipline decisions affecting Illinois employees or applicants, you must notify them, you are liable for discriminatory effects regardless of intent, and you cannot use zip codes as a proxy for protected classes. No small-business exemption has been noted, and the law reaches any employer with Illinois workers, not just companies headquartered there.
Most mid-market employers using AI-assisted recruiting tools do not know this law exists, and many are relying on their HR software vendor's assurances rather than their own review. One caution on the mechanics: the Illinois Department of Human Rights temporarily withdrew its proposed implementing rules, so the exact notice requirements are still in flux. The liability standard is not. Discriminatory effect is enough.
California: SB 53 is narrow, the ADMT rules are the real exposure
California SB 53, the Transparency in Frontier AI Act, was signed September 29, 2025 and took effect January 1, 2026. It regulates frontier developers training models above 10^26 FLOPs. Unless you are training frontier models, you are out of scope as a developer. What you inherit instead is vendor diligence: your AI vendors' compliance posture now flows down to you in procurement and security reviews.
The California exposure that actually reaches mid-market companies is the CPPA's ADMT regulations, which require risk assessments for significant-risk processing, including automated decision-making in employment. That obligation phases in over time, with the first CPPA reporting deadline arriving as early as April 1, 2028. The assessments themselves take time to build, so the 2028 date is closer than it sounds.
Not sure which of these laws reach your company?
An advisor can walk your AI inventory against each state's scope and show you what a TRAIGA-defensible NIST AI RMF file looks like.
Colorado: delayed twice, scaled back, now January 2027
The Colorado AI Act was supposed to be the American answer to the EU's risk-based model, and most 2025 compliance content was written on that assumption. It has not survived contact with implementation. SB25B-004, signed August 28, 2025, moved the original February 1, 2026 effective date to June 30, 2026. Then SB 189, signed May 14, 2026, delayed it again to January 1, 2027 and substantially scaled back the original duty-of-care and algorithmic-discrimination requirements, pivoting away from the EU-style approach.
Two practical consequences. First, anything you read citing February 2026 or June 2026 dates is stale. Second, the final shape of the law is still settling, so do not build a compliance program against the original 2024 text. If you deploy AI in consequential decisions in employment, lending, housing, healthcare, or insurance and do business in Colorado, put January 1, 2027 on the calendar and re-verify the requirements closer to the date.
Utah: narrow disclosure duties for regulated advice
Utah's Artificial Intelligence Policy Act was amended by SB 226 and SB 332, effective May 7, 2025. The amendments narrowed the original generative AI disclosure duty to high-risk interactions, meaning health, financial, and legal advice contexts, plus disclosure on request, and added a safe harbor. The law's repeal date was extended to July 2027. If you run consumer-facing generative AI in telehealth, fintech, or legal services and serve Utah residents, the disclosure duty applies to you. Everyone else can note it and move on.
The common thread: document NIST AI RMF compliance now
Five different laws, one convergent answer. TRAIGA gives NIST AI RMF documentation direct statutory defense value in Texas. The same governance file answers Illinois, where you need to demonstrate you evaluated your hiring tools for discriminatory effects. It is the natural preparation for Colorado's 2027 regime and California's ADMT risk assessments. And it is what your enterprise customers' vendor diligence questionnaires are already starting to ask for. The framework is free, it maps onto the CSF-based programs most mid-market security teams already run, and Texas just converted it from best practice into a legal position.
This is a governance decision, not just a security one, and your board will ask about it. Our guide to presenting AI risk to the board covers how to frame the state patchwork at that level. And if you sell into Europe, the state map is only half the picture: the EU AI Act's deadlines moved this summer too, which we cover in what the Digital Omnibus means for US companies.
What to watch next
Four dates and one open question. Colorado's scaled-back law takes effect January 1, 2027. Utah's UAIPA currently sunsets in July 2027, and the legislature will decide whether to extend it again. California's first CPPA ADMT reporting deadline arrives as early as April 1, 2028. Illinois rulemaking is the open question: the IDHR withdrew its proposed rules and has not yet reissued them, so notice mechanics could firm up on short notice. And watch the Texas Attorney General's office for the first TRAIGA enforcement actions, which will show how the intent standard and the safe harbor work in practice. This page will be updated as each of those lands.
Frequently Asked Questions
Which state AI laws are in effect in 2026?
As of August 2026, the live state AI laws are Texas TRAIGA (effective January 1, 2026), Illinois HB 3773 (effective January 1, 2026, covering AI in employment decisions), California SB 53 (effective January 1, 2026, but limited to frontier model developers), and Utah's narrowed UAIPA disclosure rules (effective May 7, 2025). The Colorado AI Act is not in effect: it has been delayed twice and is now scheduled for January 1, 2027, in a scaled-back form.
Does the Texas AI law TRAIGA apply to my company?
Probably, if you have Texas customers. TRAIGA reaches any business that operates in Texas and uses AI systems there, plus companies whose AI-powered products or services are used by Texas residents. It is an intent-based law: liability attaches to misusing AI for discrimination, harmful deepfakes, or impairing constitutional rights. Enforcement belongs exclusively to the Texas Attorney General, with no private right of action, civil penalties up to $200,000 per violation, and a 60-day cure period.
What is the TRAIGA NIST AI RMF safe harbor?
TRAIGA contains a statutory safe harbor for businesses that document compliance with the NIST AI Risk Management Framework, conduct adversarial testing of their AI systems, and maintain audit trails. If your company can produce that documentation, it functions as a defense against TRAIGA enforcement. This is the first US state law to give NIST AI RMF adoption direct legal defense value, which changes the business case for documenting AI governance now rather than waiting.
When does the Colorado AI Act take effect?
January 1, 2027, after two delays. The original February 1, 2026 date was moved to June 30, 2026 by SB25B-004 (signed August 28, 2025), then delayed again to January 1, 2027 by SB 189 (signed May 14, 2026). SB 189 also substantially scaled back the original duty-of-care and algorithmic-discrimination requirements. Most content indexed before mid-2026 cites dates and obligations that are no longer accurate.
Does Illinois HB 3773 apply to my company's hiring tools?
If you use AI in hiring, promotion, or discipline decisions for Illinois employees or applicants, yes. HB 3773 amended the Illinois Human Rights Act effective January 1, 2026. Employers must notify applicants and employees when AI is used in these decisions, are liable for discriminatory effects regardless of intent, and cannot use zip codes as a proxy for protected classes. No small-business exemption has been noted, so mid-market employers with any Illinois footprint are in scope.
Subscribe for Updates
Get cybersecurity insights delivered to your inbox.


