The state-level regulatory landscape for artificial intelligence has expanded dramatically in 2026. To date, 85 new AI-related laws have been enacted across 27 states , with…
The state-level regulatory landscape for artificial intelligence has expanded dramatically in 2026. To date, 85 new AI-related laws have been enacted across 27 states, with additional legislation actively pending in California, Michigan, Pennsylvania, Massachusetts, Ohio, New Jersey, and North Carolina. For U.S. businesses that develop, deploy, or rely on AI systems, the practical result is an increasingly fragmented compliance environment in which obligations turn on where customers reside, where data is processed, and which industry a company operates within.
Sector-specific mandates are moving from proposal to enforcement. The New York Department of Financial Services' binding AI model risk management guidance for insurers took effect on July 1, requiring covered entities to formalize governance, validation, and monitoring practices around AI models used in underwriting, pricing, and claims. In Illinois, the AI Video Interview Act has been expanded to cover AI-generated avatar interviewers, extending disclosure and consent obligations to a rapidly growing category of automated hiring tools. These developments signal that regulators are no longer content with general principles and are instead prescribing concrete controls tied to specific business functions.
At the same time, some jurisdictions are recalibrating implementation timelines. Colorado has shifted the effective date of its general AI framework to January 1, 2027, giving covered businesses additional runway to align governance, risk assessment, and documentation practices before enforcement begins. Companies should treat that extension as an opportunity rather than a reprieve, using the additional time to inventory AI use cases, map data flows, formalize impact assessments, and build the internal accountability structures that most emerging state frameworks require.
For multi-state operators, the near-term priority is a coherent compliance program that can absorb overlapping and sometimes inconsistent obligations. That includes maintaining a centralized AI system inventory, standardizing vendor diligence and contractual protections, implementing model risk management aligned with the strictest applicable regime, and monitoring pending bills in the states listed above. Employment, insurance, financial services, and consumer-facing technology sectors warrant particularly close attention given the volume of targeted activity.
This article is provided for general informational purposes only and does not constitute legal advice. Clients should consult qualified counsel for guidance tailored to their specific circumstances, industry, and jurisdictions of operation.