US states bring in AI laws despite tech industry lobbying
Politico reports that several US states are bringing in AI laws despite industry lobbying. What this patchwork means for organisations handling sensitive data.
You must now map which US state AI laws apply to each workflow handling sensitive data, document the specific duties each imposes, and establish where your organisation carries the burden of proof for compliance. Generic AI governance frameworks no longer suffice.
An analysis of 4 September 2026 of state AI laws enacted despite industry opposition argues that organised tech industry lobbying for a single federal standard has not halted the rise of state-level AI regulation. By mid-2026, 29 states had passed AI legislation covering automated decision-making, synthetic media and consumer protection. In our assessment, this signals a fundamental shift: US AI governance now operates as a collection of state duties rather than a single overarching framework, and organisations handling sensitive information must treat it as such.
Which state rules actually apply to your workflows?
The first practical step is jurisdictional mapping. You need to identify which states your AI systems operate in, which data they process, and which state laws therefore bind you. This is not a one-time exercise. A workflow that touches customer data in New York, processes financial information in California and handles employment decisions in Texas may fall under three separate regimes simultaneously. Each state law defines its scope differently—some apply to all AI systems, others only to high-risk categories or frontier models. You cannot assume that compliance in one state satisfies another.
What specific duties do the laws impose?
State AI laws now carry concrete operational requirements, not merely principles. Texas HB 149 (TRAIGA), in force since 1 January 2026, imposes duties on automated decision-making. California's transparency and frontier-model laws require disclosure and safety documentation. The New York RAISE Act requires developers of frontier models to publish safety frameworks and report serious incidents within 72 hours. These are not aspirational standards. They create documented obligations with defined timelines and specified audiences. You must be able to demonstrate that you have met each one.
What controls must you be able to show?
Compliance verification requires a structured approach:
- Identify which AI systems and data flows operate in each state — document the jurisdictional footprint of every workflow that touches sensitive information.
- Map applicable state laws to each system — establish which state duties apply to which AI application, and record the legal basis for that mapping.
- Document safety frameworks and incident protocols — for systems subject to frontier-model rules, maintain written safety frameworks and establish incident reporting procedures with defined timelines.
- Establish verification steps before deployment — confirm that each system meets the specific requirements of the states it operates in before it processes live data.
- Create audit trails for control execution — record which verification steps were carried out, when, and by whom, so you can demonstrate compliance if challenged.
- Test incident response procedures — verify that your organisation can meet reporting deadlines when something goes wrong, not only when everything works as designed.
How does this fit with existing privacy and security duties?
For sectors handling confidential information—legal, financial, healthcare—state AI laws do not replace existing privacy, cyber and sector-specific obligations. They sit alongside them. The 72-hour incident reporting requirement in New York, for example, creates a verification need not only at setup but also when failures occur. This means AI governance, privacy compliance and security operations must be integrated, not managed in separate silos. A breach in an AI system is still a breach; a failure to report it within the state deadline is a separate violation.
What can tooling do, and what remains your responsibility?
Verification systems can make visible which AI systems and data flows run through which jurisdictions and which control steps have been executed. They can flag gaps and create inspectable records of compliance work. What they cannot do is substitute for professional judgment about which state rules apply to your specific business, whether you have interpreted them correctly, or whether your controls genuinely satisfy them. That remains your responsibility. The law, the state, and your customers will hold you accountable for that judgment, not the tool.
Sources: This article draws on reporting and guidance from Politico, Techpolicy, Glacis, Orrick and National Conference of State Legislatures (NCSL).
Written by
Marit Halversen
Covers AI governance and regulatory design, with a focus on how compliance obligations land on architecture rather than on paperwork.