38 US states enacted AI laws in 2025.
Most businesses don't know they apply.
There is no single federal AI law — which is why most businesses assume the state ones cannot reach them. California, Texas and Illinois laws are live right now.
Illinois follows your staff. Use AI in a hiring, promotion or performance decision about someone in Illinois and HB 3773 requires you to tell them — for any employer with even one Illinois employee, whichever state you are in.
California follows your customers. If your customers are in California, California law reaches the automated decisions you make about them, wherever your business sits.
Your own state passing nothing changes little. State privacy laws across twenty states already cover automated decision-making on personal data, and most AI tools qualify. Most businesses are non-compliant and do not know it.
Not sure where you stand? Answer 7 questions and get your free US AI compliance exposure report — instant, no sign-up.
Take the Free Check →"No federal AI law" does not mean "no obligation."
The most common mistake US businesses make is waiting for federal legislation before acting. State laws don't wait. They're enforced now. And most of them apply to you regardless of which state your business is registered in — it's about where your employees and customers are.
Illinois HB 3773 applies to any employer using AI in hiring, promotion, or performance review decisions about Illinois staff or applicants — regardless of which state the employer is based in. Notice is required.
Colorado SB 26-189 applies from 1 January 2027 and will require impact assessments and consumer disclosure rights for automated decision-making technology influencing decisions about employment, credit, housing, insurance, education, or healthcare. It replaced SB 24-205, which never took effect — so build against SB 26-189.
SB 942, the California AI Transparency Act, covers large generative AI providers: a free AI-detection tool and a hidden marker in AI-generated content (Already in force — since 2 August 2026). California's privacy law also reaches the automated decisions you make about California consumers, wherever you are based: its rules on automated decision-making are in force, and a business already using AI for a significant decision — a job, a loan, housing, education or healthcare — must give notice, an opt-out and access by 1 January 2027. They apply to businesses within the California Consumer Privacy Act.
Texas HB 149, the Responsible AI Governance Act, has applied since 1 January 2026. It prohibits certain uses of AI, including intentional discrimination, requires government bodies to disclose their AI use, and is enforced by the Attorney General.
Connecticut Public Act 26-15, passed in 2026, reaches any business doing business in Connecticut, whatever its size. From 1 October 2027, if AI helps decide who you hire, promote or discipline, you must tell the person and give them written notice before the decision is made.
New York City Local Law 144 has been enforced since 5 July 2023. An automated tool that screens or ranks candidates for a New York City job needs a bias audit from the past year, published results, and notice to every candidate.
Utah's Artificial Intelligence Policy Act has applied since 1 May 2024. If a customer asks whether they are dealing with AI, you must say so, and licensed professions must say it up front when the conversation matters.
Tennessee's ELVIS Act and Washington's forged digital likeness law protect a real person's voice and likeness from AI copies. An advert with an AI version of someone's voice or face, used without their permission, exposes the business that runs it to a claim — even if an agency in another state made it. And from 1 January 2027, California SB 1050 requires any advert shown in California that prominently features an AI-generated performer who looks or sounds human to say so clearly, in words like "this performance features a synthetic performer" — whatever the size of the business.
Washington's My Health My Data Act has applied since 31 March 2024 and covers small businesses too: consent before collecting or sharing a customer's health data, and a published health data privacy policy. A clinic or wellbeing business putting customer health information into AI tools is in it.
In 2025, state legislators introduced over 1,100 AI-related bills across all 50 states. 145 were enacted. More are coming.
US AI law moved faster than anyone expected.
Illinois amends its AI Video Interview Act. New York City Local Law 144 requires bias audits for AI hiring tools. The foundation is laid.
Colorado passes the most comprehensive US state AI law. California enacts multiple AI transparency measures. The patchwork accelerates.
38 states enacted AI legislation in 2025. Texas and Illinois are enforceable now. California's automated-decision rules came into force the same month, with businesses already using those tools due to comply by 1 January 2027. Colorado's SB 26-189 follows on 1 January 2027, and Connecticut's hiring rules on 1 October 2027.
Congress has not passed a federal AI law. Bills that would set one national standard and override the state rules have been introduced, and none has passed — the Senate has already voted down an attempt to freeze state enforcement. Nothing at federal level changes what your states require of you today.
Do the White House AI orders mean state laws no longer apply? No.
Two executive orders are behind the talk of federal pre-emption. Neither one switches a state law off.
Made removing barriers to US AI development federal policy, and ordered a review of everything done under the previous administration's AI order, which had already been revoked. It directs federal agencies. It says nothing about state law.
The one aimed at the states. It orders the Attorney General to set up a task force to challenge state AI laws in court, the Commerce Secretary to list the state laws it considers onerous, and conditions on federal broadband funding for states that keep them. It also asks for a proposal to Congress for one national standard that would override conflicting state laws — leaving out state laws on child safety, AI data-centre infrastructure, states' own use of AI, and other topics still to be decided.
An executive order directs the federal government. It cannot repeal a state law. A state AI law stops applying to you only when a court strikes it down, Congress passes a law that overrides it, or a federal rule validly pre-empts it — and until one of those happens to that law, it can be enforced against you. So build against the states that reach your staff and customers now.
28 dates that decide whether you are compliant.
14 of them have already passed.
United States is one line of 9. A business with US staff usually sits on more than one. Yours is marked. The others reach you through your customers, your staff and your suppliers, wherever you are incorporated.
Europe
- in force Obligations for general-purpose AI models.
- in force Article 50 transparency duties and enforcement powers for national regulators.
- coming New prohibitions, and Article 50(2) marking of synthetic content.
- coming Every Member State must have an AI regulatory sandbox running.
- coming High-risk obligations for Annex III systems — including AI used in recruitment, credit scoring, education and essential services.
- coming High-risk obligations for Annex I systems — AI embedded in products already covered by EU product safety law.
United Kingdom
- in force Most Part 5 data protection provisions of the Data (Use and Access) Act 2025, including the wider lawful bases for solely automated decisions and the safeguards that come with them.
- in force The duty on controllers to operate a complaints procedure and respond to data protection complaints within set time limits.
United States this page
- in force New York City Local Law 144 — an employer or agency using an automated employment decision tool for a New York City job needs a bias audit within the past year, published results, and notice to candidates.
- in force Washington My Health My Data Act (RCW 19.373) — consent before collecting or sharing consumer health data and a published health data privacy policy, for any business targeting Washington consumers; small businesses from 30 June 2024. A breach is an unfair practice under the Consumer Protection Act.
- in force Utah Artificial Intelligence Policy Act (SB 149, 2024) — a business using generative AI with a consumer must say so when the consumer clearly asks; licensed professions must disclose it up front in high-risk interactions. Narrowed by SB 226 from 7 May 2025, with a safe harbour for disclosing at the start.
- in force Texas HB 149, the Responsible Artificial Intelligence Governance Act — prohibited uses, government AI disclosure, and Attorney General enforcement.
- in force California SB 942, the AI Transparency Act — free AI detection tool and latent provenance disclosure for large generative AI providers. Delayed from 1 January 2026 by AB 853.
- coming Colorado SB 26-189 — developer and deployer duties for automated decision-making technology used in consequential decisions. It repealed and reenacted SB 24-205, which never took effect. California SB 1050 (Chapter 246, Statutes of 2026) — an advert shown in California that prominently features an AI-generated performer who looks or sounds human must say so clearly, in words like "this performance features a synthetic performer". Any size of business; enforced as false advertising. California CCPA regulations on automated decisionmaking technology (Cal. Code Regs. tit. 11, s. 7200) — a business using ADMT for a significant decision about a consumer must give pre-use notice, opt-out and access rights. In force 1 January 2026; businesses already using ADMT must comply by this date. Only businesses within the CCPA. Connecticut Public Act 26-15, sections 4 to 6 — duties on operators of AI companions, including detecting and responding to signs of self-harm. Washington HB 2225 (Chapter 168, Laws of 2026) — AI companion chatbots must disclose that they are not human, with safeguards for minors and a private right of action. A customer-service bot that does not sustain a relationship is excluded. Oregon SB 1546 (Chapter 85, Oregon Laws 2026) — operators of AI companions must tell users they are not talking to a person, keep a protocol for users who express thoughts of suicide or self-harm, and add safeguards for minors; a user who is harmed can sue. Software used solely for customer service, business operations or productivity is excluded.
- coming Idaho Conversational AI Safety Act (S 1297, Session Law Chapter 249 of 2026; Idaho Code Title 48, Chapter 21) — a conversational AI service open to the public must say it is AI where a person could be misled, answer prompts about suicide with a crisis referral, and protect account holders who are minors. Enforced by the Attorney General. A chatbot used only for customer service or a business's own operations is excluded.
- coming Connecticut Public Act 26-15 (Substitute SB 5, 2026), sections 7 to 12 — any business doing business in Connecticut that uses an automated employment-related decision technology for a hiring, promotion or discipline decision must disclose it and give written notice before the decision. No size threshold. A breach is an unfair trade practice.
- coming California CCPA regulations, s. 7157 — risk assessments conducted in 2026 and 2027 must be submitted to the California Privacy Protection Agency by this date.
Canada
- in force Ontario ESA / O. Reg. 476/24 — a publicly advertised job posting must disclose the use of AI to screen, assess or select applicants. Employers of 25 or more, including where a third party screens on their behalf.
Australia
- coming Privacy Act 1988 (Cth), APP 1.7 — a privacy policy must say what kinds of personal information a computer program uses to make decisions that could reasonably be expected to significantly affect a person, and what kinds of decisions those are — the automated decision-making (ADM) transparency obligations, regulated by the OAIC.
United Arab Emirates
- in force DIFC Data Protection Regulation 10 — a business deploying an autonomous or semi-autonomous system that processes personal data must tell users, on first use, what the system decides for itself, what it was built to do and what it does with the output.
Saudi Arabia
- in force The Saudi Data and AI Authority's grace period under the Personal Data Protection Law ends, and with it the undertaking not to apply penalties. The authority has said it may extend the grace period for a business that gives it good reason.
South Korea
- in force Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust in force. A business in the AI industry must tell users in advance where a product runs on generative or high-impact AI, and label what generative AI produces. It applies to conduct outside Korea that affects the Korean market or its users.
China
- in force Personal Information Protection Law in force. A business outside China that handles the personal information of people in China — to offer them products or services, or to analyse their behaviour — must have a lawful basis for it and must appoint a representative or a dedicated body inside the country. Nothing in the duty turns on how much data is held.
If any of these apply to your business, you have compliance obligations today.
- Using AI tools to screen CVs, rank candidates, or assist with any US hiring decision
- AI-assisted performance reviews, promotion decisions, or disciplinary actions for US employees
- AI chatbots or automated systems interacting with California, Colorado, or Texas customers
- Automated decision-making affecting consumer credit, insurance, or housing for US residents
- AI tools processing personal data of residents in any of the 20 states with active privacy laws
- Any business that wants to be ready for federal AI legislation when it passes
Read it before you buy it.
This is not a mock-up or a contents page. It is a genuine US AI Compliance pack — all 16 documents — produced by the same system that will produce yours, for a fictional marketing agency we invented to test it. They publish AI-written work for clients across four states, so the pack is written around that. Yours is written around whatever your business does.
26 September 2026 — added: Answers to the AI questions clients send their suppliers
The gap. Public bodies and large companies now send their suppliers questions about the AI they use. Our frameworks held most of the answers, but a client had to know where to look, usually with a renewal waiting.
What we added. The questions real buyers publish, each put in plain words, with the document in your framework that answers it and anything still yours to do.
24 September 2026 — added: ISO/IEC 42001 and NIST AI RMF alignment map
The gap. Bigger clients, insurers and tenders can ask a supplier whether its AI governance meets ISO/IEC 42001 or the NIST AI Risk Management Framework. Our frameworks held most of the evidence, but nothing in them showed it.
What we added. A map that names, clause by clause, which of your documents meets each standard and what is still yours to do. It shows alignment, not certification.
Every framework, in all seven markets, has these changes. The pages below were made before them, so they show 2 documents fewer than a framework bought today.
This framework also comes with a compliance dashboard you run all year: a dated to-do list, your AI tools and their risks, staff sign-off, an incident log, every document to download, the deadlines for your markets and a statement you can share. See a fictional example → · What the dashboard does →
The states disagree on the wording. They agree on what you have to be able to prove.
Chasing fifty statutes one at a time is how this gets expensive. Underneath the drafting, the live regimes ask for the same short list: tell people before an automated system decides something about them, assess the system before you deploy it, test whether its outputs fall unevenly on people, keep a human who can review a decision, and hold records that show all of it. Illinois asks for the notice. Colorado's regime asks the Attorney General's questions. The state privacy laws ask about the data.
So the durable move is to build to the list, not to a state line. Do that and one framework covers the states you already trade into — and if a federal framework does arrive, it tests something you already hold rather than something you write under deadline. That is what the annual renewal is for: as states add requirements, your framework absorbs them, and you are not paying to start again.
Not sure which states already reach you? Seven questions, no sign-up.
Take the free check →
Your customers decide which law
applies to you. Not your address.
Where your customers are, where your staff are and where your AI has effect — those decide, not where the business is registered. We write frameworks to four legal systems, and serve four more on request.
- United Kingdom UK GDPR, in force now. The Data (Use and Access) Act added automated-decision duties from 5 February 2026.
- European Union The EU AI Act. General-purpose AI obligations already apply; regulators have had enforcement powers since 2 August 2026.
- United States State by state, not federal. Texas from 1 January 2026, California from 2 August 2026, Colorado from 1 January 2027.
- Canada PIPEDA plus provincial law. Ontario's AI hiring disclosure rules applied from 1 January 2026.
US AI Compliance Packages.
Every package builds a documented compliance position for your business. Prices in GBP — approximate USD and EUR equivalents shown. Stripe accepts all major cards.
~$250 · ~€230
- AI Acceptable Use Policy
- Employee AI guidelines
- AI tool inventory template
- Plain-English summary of obligations by state
Best for: small businesses wanting a baseline policy that covers all 50 states before specific obligations kick in.
In your inbox by the end of the business day
Buy now — £197 →~$1,010 · ~€930 per year
- Everything in US AI Policy
- State obligations assessment (CA, CO, TX, IL)
- Employment AI disclosure notices
- Algorithmic discrimination prevention procedures
- Consumer-facing AI transparency disclosures
- Data processing documentation for AI tools
- ISO/IEC 42001 and NIST AI RMF alignment map
Best for: businesses operating in or serving customers in California, Colorado, Texas, Illinois, Connecticut, Utah, Washington or New York City — or any business using AI in US employment decisions.
In your inbox by the end of the business day · Covers you for 12 months, renews yearly
Buy now — £797/year → or book a scoping call first~$1,900 · ~€1,750 per year
- Everything in US AI Compliance Foundation
- Multi-state compliance matrix
- Full HR AI procedures and disclosure templates
- Impact assessment templates for high-risk AI use
- Incident response procedure
- Federal legislation readiness assessment
- ISO/IEC 42001 and NIST AI RMF alignment map
- Your AI compliance dashboard: a to-do list, your AI tools, staff sign-off, an incident log, every document and a shareable statement
Best for: multi-state businesses, businesses with 15+ employees, or any business wanting a comprehensive position ahead of federal legislation.
In your inbox by the end of the business day · Covers you for 12 months, renews yearly
Renews yearly — new state laws applied to your framework throughout your cover.
Buy now — £1,497/year → or book a scoping call firstEvery framework is annual — your fee covers 12 months of protection, with new state AI laws monitored and applied to your framework as they pass, and renews yearly so your cover never lapses.
The same work, done in-house.
11 documents to write, and 15 records a year to keep afterwards. Costed against what a member of staff on the median UK salary actually costs an hour:
£2,140+
Your own staff — 83 hours of their time
£797/year
US AI Compliance — in your inbox by the end of the business day
Marked + because the reading is not in that figure yet — we are still counting this market's statutes, so the real in-house cost is higher than shown, never lower.
Bought, built and delivered without a meeting.
Buy it
Buy it on this page. There is no call to book and no slot to wait for. If you would rather talk it through first, that option is there too.
Tell us about you
A dozen questions: your sector, your size, the states you operate in, the AI tools you use, what those tools decide, and what you are worried about.
It arrives
Your framework is written from your answers against the state laws that reach you — disclosures, HR notices, impact assessments and incident procedures — in your inbox by the end of the business day. PDF and Word, the full pack and every document on its own.
It stays current
For 12 months we watch new state laws and federal developments. When something moves, we confirm it against the legislature’s own record, rebuild your documents and email them to you. Renews yearly.
Straight answers.
Does US state law apply to a non-US business?
In many cases, yes. If you have US-based employees or customers in states with active AI laws, those laws can apply to you regardless of where your business is incorporated. California law applies based on where your customers are. Illinois employment AI law applies based on where your employees are. If you're a UK or European business with US operations or staff, you're likely in scope for at least some of these laws.
What does Illinois law actually require?
Illinois HB 3773 makes it a civil rights violation to use AI in a way that discriminates in hiring, firing, promotion, discipline or other employment decisions, and requires employers to tell employees and applicants when AI is used in those decisions. It covers any employer with one or more employees in Illinois for 20 weeks or more of the year, including employers based in other states. What the notice must contain is being set by rules the Illinois Department of Human Rights has proposed but not yet finalised. Complaints go to the Department of Human Rights.
My business is in a state that hasn't passed AI laws. Am I safe?
Not necessarily. Two things still apply to you: first, if you have customers or employees in California, Colorado, Texas, or Illinois, those states' laws apply. Second, state privacy laws (CCPA in California, VCDPA in Virginia, the Colorado Privacy Act, and others in 20 states) already cover automated decision-making systems that process personal data — and most AI tools qualify. A baseline AI policy protects you regardless of your state.
Is a federal AI law coming?
Congress has not passed a federal AI law, and there is no agreed timetable for one. Bills that would set a single national standard and override conflicting state laws have been introduced, and none has passed; the Senate has already voted down one attempt to freeze state enforcement. Nothing at federal level changes what your states require of you today. Whatever eventually arrives will be built on the same ideas as the Colorado and California rules — so a business that meets those now will be testing a framework it already holds, rather than writing one against a deadline.
What happens if I don't comply?
Penalties vary by state. California's AI transparency laws carry significant fines for non-compliance. Colorado's SB 26-189 will allow the Attorney General to enforce violations from 1 January 2027, with civil penalties per affected consumer. Illinois employment AI violations can be filed with the state Department of Human Rights. Beyond direct fines, non-compliance creates exposure in employment disputes and consumer litigation where your AI practices come under scrutiny.
Is this legal advice?
No. We produce compliance documentation frameworks and policy documents — we are not US attorneys. For businesses in regulated sectors or facing specific enforcement actions, we recommend reviewing your documentation with US-qualified legal counsel. For most businesses using standard AI tools, our frameworks provide a practical, well-documented compliance position that demonstrates good-faith effort.
Get compliant before more states add requirements.
145 AI bills were enacted in the US in 2025. That number will be higher in 2026. Building your compliance framework now means you adapt, not scramble, as new laws pass.
See the Packages →Or book a free 20-minute call to discuss your situation — hello@opsintel.io