Blog

US states bring in AI laws despite tech industry lobbying

Politico reports that several US states are bringing in AI laws despite industry lobbying. What this patchwork means for organisations handling sensitive data.

· By

Paper map of the United States on a wooden table, with a few states marked by coloured paper tabs and a yellow highlighter, beside a stack of documents.
A growing number of individual US states are enacting their own AI laws, creating a patchwork of obligations rather than a single federal standard.Image: IamVera.ai — original editorial illustration

Politico reported on 2 September 2026 that several US states have brought in AI laws despite lobbying by national tech industry groups that would prefer a single light-touch federal standard. According to TechPolicy.Press, by the middle of 2026 as many as 29 states had already passed AI legislation, on topics such as automated decision-making, synthetic media and consumer protection. Concrete examples include Texas HB 149 (TRAIGA, in force since 1 January 2026), Californian transparency and frontier-model laws, and the New York RAISE Act, which according to Orrick requires developers of frontier models to publish safety frameworks and report serious incidents within 72 hours.

For organisations this means US AI compliance is no longer a future federal debate but a patchwork of state obligations that must be mapped per workflow: which state applies, which duties apply and where the burden of evidence sits.

What exactly did Politico report and why is it relevant?

The core of the Politico reporting is the clash between two movements. On the one hand, national tech industry groups and trade associations are pushing for a single, lighter federal standard; on the other, individual states have brought in their own AI rules. Politico described earlier, in May 2024, in the piece on tech industry lobbying against state AI bills how a coalition of tech advocates — including TechNet and BSA — opposed early state AI bills. Yet those bills went ahead in Colorado and other jurisdictions.

The pattern is thereby confirmed: organised industry opposition has not halted the rise of state regimes. In our assessment, that is the practically relevant signal for anyone working with sensitive information: US AI governance is increasingly operating as a collection of state duties rather than a single overarching federal framework. That contrasts with broader arguments for light-touch AI regulation at the G20 innovation summit, which point in a different direction from the state laws now being enacted in practice.

Which AI laws have individual states passed?

The verification tracker from Glacis and the legislation summary from the National Conference of State Legislatures (NCSL) provide concrete, checkable examples. According to the US State AI Laws Tracker from Glacis, several state AI laws came into force in 2026. A few laws that illustrate the current picture:

  • Texas HB 149 (TRAIGA): according to Glacis in force on 1 January 2026, with civil enforcement by the attorney general. NCSL lists this law as "Enacted".
  • California: Glacis describes that several Californian AI laws and transparency rules came into force in 2026, including transparency obligations and other state AI requirements.
  • New York (RAISE Act): Orrick describes that this law requires developers of "AI frontier models" to publish safety frameworks and to report incidents involving serious harm within 72 hours.
  • Colorado: one of the states that, according to Politico, moved ahead with AI bill proposals despite industry lobbying.

TechPolicy.Press places these individual laws in a wider context: with 29 states having passed AI legislation by the middle of 2026, these are not isolated experiments but a widespread pattern. Topics range from automated decision-making to synthetic media and consumer protection.

What does this state patchwork mean in practice for organisations handling sensitive data?

The practical shift is that, in our view, generic "AI compliance" no longer suffices. In practice, an organisation may need to know per workflow which state rules an AI application falls under and where activities across multiple states create stacked obligations. The New York RAISE Act, as described by Orrick, imposes concrete duties for developers of frontier models at the level of safety frameworks and incident reporting, not only at the level of end results.

Analysis: for sectors that work with confidential information — legal, financial, healthcare — this means AI governance slots in underneath existing privacy, security and sector duties rather than replacing them. The New York 72-hour deadline for incident reporting suggests that verification is needed not only at the setup stage but also when something goes wrong. This ties in with the broader shift we described earlier, in which AI governance moves from principles to concrete control duties. One pragmatic line is not to manage privacy, cyber and AI in separate silos but to bundle them, as in our discussion of integrated governance for privacy, cyber and AI.

How do you map which state obligations apply per workflow?

A verifiable approach begins by making visible which AI systems and data flows run through which jurisdictions. A workable sequence:

  1. Inventory per workflow which AI models are used and whether they involve frontier models or high-risk automated decisions.
  2. Determine which states apply based on where users, data and decisions are located.
  3. Link the concrete duties per state: safety frameworks, transparency about training data, consumer disclosures and incident reporting.
  4. Record which logs, reports and evidence each state expects, including deadlines such as the 72-hour report from the RAISE Act.
  5. Test where the verification gaps are and how this relates to broader privacy and sector rules.

Our topic hub on AI governance and control duties gathers the broader context around this kind of control duty. For legal teams operationalising AI under mounting pressure, the execution gap between firms is also relevant, because compliance and operationalisation come together here.

In this landscape a verification layer such as Vera can help to make visible, per sensitive workflow, which AI systems and data flows run through which jurisdictions and which control steps have been carried out. Vera is not a chatbot and not its own language model, but makes verification steps, corrections and sources inspectable. The Semantic Privacy Shield can replace sensitive document values before processing with synthetic, session-only equivalents on EU infrastructure; the workflow is designed to send onward only anonymised content and is fail-closed, so that when a privacy check fails nothing is sent. That gives more insight into the control steps carried out, but the professional final judgement — which state rules apply and whether they have been met — remains with the user.

Sources and references

  1. Two unlikely states are leading the charge on regulating AIPolitico · 2024-05-15
  2. Where State AI Legislation Stands Half Way Into 2026TechPolicy.Press · 2026-07-06
  3. US State AI Laws Tracker: What Changed in 2026Glacis · 2025-12-20
  4. Orrick State Attorney General Update | January 2026Orrick · 2026-01-15
  5. Summary of Artificial Intelligence 2025 LegislationNational Conference of State Legislatures (NCSL) · 2025-07-10

Sources: The article draws on reporting by Politico and TechPolicy.Press, the laws tracker from Glacis, the legislation summary from NCSL and the State Attorney General Update from Orrick.

← All articles in this topic ← All articles