The United States has no single AI law. Instead, ten distinct regulatory approaches have emerged across the federal government and the states, each applying a different legal logic to overlapping technology. This page compares them along the dimensions of who is regulated, when regulation takes effect, what triggers enforcement, and how the approaches relate to one another, including the preemption conflict among federal instruments.
The ten approaches
| # | Approach | Key instrument | Level | ||
|---|---|---|---|---|---|
| 1 | Frontier transparency | [[california-sb-53 | CA SB 53]], [[new-york-raise-act | NY RAISE Act]] | State |
| 2 | Anti-discrimination (duty-of-care) | [[colorado-ai-act | Colorado AI Act]] | State | |
| 3 | Product liability | [[ai-lead-act | AI LEAD Act (S. 2937)]] | Federal (proposed) | |
| 4 | Federal preemption | [[eo-14365 | EO 14365]] | Federal | |
| 5 | Comprehensive strategy | [[americas-ai-action-plan | America's AI Action Plan]] | Federal | |
| 6 | Child safety | [[california-sb-243 | CA SB 243]] | State | |
| 7 | Voluntary standards | [[nist-ai-rmf | NIST AI RMF 1.0]] | Federal | |
| 8 | Enforcement guidance | [[state-ag-ai-guidances | State AG Guidances]] | State | |
| 9 | Intent-based prohibitions + sandbox | [[texas-traiga | Texas TRAIGA (HB 149)]] | State | |
| 10 | Developer immunity / safe-harbor | [[illinois-sb-3444 | Illinois SB 3444]] | State |
Antitrust case law (Algorithmic Pricing and Antitrust) operates as a further dimension through litigation rather than legislation.
Who bears responsibility
The approaches differ in which actor in the AI supply chain they regulate:
- Developers only. SB 53 and the RAISE Act target frontier model developers above a compute threshold; deployers are not regulated.
- Deployers only. The Colorado AI Act regulates decisions made with AI in consequential domains such as hiring, lending, and housing. Model developers are largely untouched.
- Both. The AI LEAD Act creates liability for both developers and deployers, with different standards for each: developers face strict liability and deployers face negligence.
- Regulators. EO 14365 acts on state regulators, using federal power to prevent state action.
- No binding obligation. The NIST AI RMF and state AG guidances are voluntary or interpretive rather than binding.
Because of this developer/deployer split, a single AI system can face transparency requirements on the developer (SB 53), anti-discrimination requirements on the deployer (Colorado), and product liability on both (AI LEAD Act), while the federal government simultaneously seeks to prevent the first two from existing (EO 14365).
When regulation takes effect
The approaches intervene at different points in the AI lifecycle:
| Timing | Approach | Logic |
|---|---|---|
| Pre-deployment | SB 53, RAISE Act | Measure and disclose before releasing |
| At deployment | Colorado AI Act, SB 243 | Impact assessments, consumer notice, opt-out rights |
| Post-harm | AI LEAD Act, antitrust | Litigation after damage occurs |
| Pre-regulation | EO 14365, AI Action Plan | Prevent states from acting |
| Ongoing | NIST AI RMF, AG guidances | Continuous risk management |
Taken together, these produce overlapping coverage across the lifecycle: transparency requirements before release, discrimination assessments at deployment, liability after harm, and voluntary risk management throughout.
What triggers enforcement
Each approach turns on a different trigger:
- Compute thresholds. SB 53 applies to models trained above a specified FLOP threshold. Managing Advanced Cyber Risks in Frontier AI Frameworks notes that compute is the simplest trigger but a weak risk signal, because compute does not directly measure danger.
- Consequential decisions. The Colorado AI Act triggers when AI is used in "high-risk" domains: employment, finance, housing, healthcare, legal, and government services.
- Harm occurrence. The AI LEAD Act triggers upon harm and includes "unexpected skills or behaviors" within its definition of "defective" AI, linking it to Emergent Misalignment.
- Market conduct. Antitrust triggers when algorithmic pricing produces effects resembling collusion.
- No trigger. The NIST AI RMF and AG guidances apply voluntarily or through existing law.
Preemption among federal instruments
The structural conflict among the federal approaches is between ceiling preemption and floor preemption:
- Floor preemption (AI LEAD Act): federal law sets a minimum standard and states may go further. This preserves state innovation, the Techno-Federalism: How Regulatory Fragmentation Shapes the U.S.-China AI Race model that Wu describes as productive.
- Ceiling preemption (EO 14365): federal executive power sets a maximum standard that states cannot exceed. It targets the Colorado AI Act by name and creates an AI Litigation Task Force to challenge state laws.
- Funding conditionality (AI Action Plan): a softer mechanism that does not legally preempt but conditions federal funding on states not having "burdensome" AI regulations.
The same administration pursuing ceiling preemption through EO 14365 also proposed floor preemption through the AI LEAD Act, and the AI Action Plan adds funding conditionality as a third mechanism. The three are in tension with one another.
Governance purpose by approach
Each approach reflects a different account of what AI governance is for:
| Approach | Core question |
|---|---|
| Frontier transparency | "Do we know what this AI can do?" |
| Anti-discrimination | "Is this AI fair?" |
| Product liability | "Who pays when this AI causes harm?" |
| Federal preemption | "Is state regulation hurting American competitiveness?" |
| Antitrust | "Is this AI reducing market competition?" |
| Child safety | "Is this AI safe for children?" |
| Voluntary standards | "How should organizations manage AI risk?" |
| Enforcement guidance | "Does existing law already cover this?" |
No single purpose dominates the landscape. Amodei's graduated-response approach, which starts with transparency and escalates as risks materialize, aligns most closely with the SB 53/RAISE Act paradigm. The AI LEAD Act represents a more aggressive posture, and EO 14365 rejects the premise that new regulation is needed.
State models: intent-based prohibitions and developer immunity
Two state approaches added in 2025–2026 sit outside the developer-transparency and deployer-duty-of-care models that preceded them.
Texas TRAIGA (HB 149)
Texas HB 149 was signed June 22, 2025, and takes effect January 1, 2026, the first comprehensive AI law enacted in a Republican-led state. It was originally drafted on the Colorado model but was scaled back into a distinct pattern. Rather than imposing a duty of care over "high-risk" systems, it defines a set of intent-based prohibited uses: behavioral manipulation, government social scoring, constitutional-rights infringement, intentional unlawful discrimination, and CSAM. Disparate impact alone is not sufficient to prove discriminatory intent, a narrower standard than Colorado's.
The law creates a regulatory sandbox of up to 36 months during which the attorney general cannot file charges for waived violations during testing, the first US state AI sandbox. It establishes a non-binding Texas AI Advisory Council that cannot adopt rules (§554.103(1)). Enforcement is exclusive to the attorney general, with a 60-day cure period and civil penalties of $10,000–$200,000 plus daily penalties. Its sponsors frame it around innovation-friendly guardrails rather than equity or anti-discrimination.
TRAIGA shares its enforcement architecture with the Colorado model (attorney-general-only enforcement, 60-day cure) while narrowing scope to intent-gated prohibitions and adding the sandbox.
Illinois SB 3444
Illinois SB 3444, filed February 4, 2026, by Sen. Cunningham, inverts the liability framing of the other approaches. Rather than imposing duties, it grants conditional immunity from liability for frontier AI developers against "critical harms," defined as 100 or more deaths or injuries, $1 billion or more in property damage, CBRN enablement, or autonomous criminal conduct, in exchange for publishing a safety protocol and transparency report. The threshold is $100 million in training spend or 10^26 FLOPs. Its logic is that disclosure unlocks a legal shield, the opposite of the AI LEAD Act's premise that tort liability forces safety investment (AI LEAD Act (S. 2937)).
The bill is publicly backed by OpenAI, the first state AI bill OpenAI has publicly supported and a departure from the industry posture during California SB 1047 — Safe and Secure Innovation for Frontier AI Models Act (enrolled + veto). Adherence to EU AI Act Article 56 satisfies its compliance requirements via EU General-Purpose AI Code of Practice (Final Version, 2025). It self-sunsets upon enactment of overlapping federal law, and a redaction provision for trade-secret and cybersecurity limits bounds what its transparency requirement discloses in practice. The pattern is developer immunity conditioned on disclosure, structurally opposite to the AI LEAD Act's strict-liability posture.
Same-state, opposite directions
Illinois illustrates the multi-level incoherence that techno-federalism describes: two Illinois legislators advance directly opposing AI liability frameworks at different levels of government. Sen. Richard Durbin (D-IL) is the lead Senate sponsor of the AI LEAD Act (S. 2937) at the federal level, which creates strict liability for defective AI, while Sen. Bill Cunningham (D-IL) sponsors SB 3444 at the state level, which shields frontier developers from liability for critical harms. The two represent the same party and state but opposite liability regimes at two levels of government.
Tensions across approaches
- Transparency versus liability. SB 53's logic is to disclose and let the market respond; the AI LEAD Act's logic is that developers pay for harm regardless of disclosure. The two create different incentive structures for the same developers.
- Developer versus deployer. A company building an AI model faces SB 53 requirements; a company using that model for hiring faces Colorado requirements. Neither set addresses the handoff between them.
- State innovation versus federal coherence. Techno-Federalism: How Regulatory Fragmentation Shapes the U.S.-China AI Race holds that the AI industry acts as a third regulatory force alongside state and federal governments. In the current landscape, states filled the federal vacuum, and the federal government is now attempting to roll that back while proposing its own overlapping federal law.
- Safety versus competition. The AI Action Plan frames regulation as a threat to American competitiveness, while safety frameworks frame the absence of regulation as a threat to safety. The Anthropic-DoW conflict is one instance of this tension.
- Existing law versus new law. State attorneys general argue that existing consumer-protection and anti-discrimination law already governs AI, a position harder to preempt because those laws predate AI and which counters the argument that AI-specific regulation is premature.
Sources
- California SB 53 — Transparency in Frontier AI Act, New York RAISE Act (S. 8828), Colorado AI Act (SB 24-205) and SB 25B-004 (Date Amendment), AI LEAD Act (S. 2937), Executive Order 14365 — Ensuring a National Policy Framework for AI, America's AI Action Plan, California SB 243 — Companion Chatbots, NIST AI Risk Management Framework (AI RMF 1.0), State AG AI Guidances (CA, NJ, MA, OR), Algorithmic Pricing and Antitrust, Texas Responsible AI Governance Act (TRAIGA / HB 149) — Source Summary, Illinois SB 3444 — Artificial Intelligence Safety Act
- Techno-Federalism: How Regulatory Fragmentation Shapes the U.S.-China AI Race — governance fragmentation framework
- Clawed — Anthropic-DoW conflict as case study
- Managing Advanced Cyber Risks in Frontier AI Frameworks — threshold design
- EU General-Purpose AI Code of Practice (Final Version, 2025) — referenced as a compliance alternative in SB 3444
- California SB 1047 — Safe and Secure Innovation for Frontier AI Models Act (enrolled + veto) — prior California frontier-model bill referenced for industry posture
- Emergent Misalignment — linked via the AI LEAD Act's "defective" definition
- Dario Amodei — graduated-response approach