State-level AI regulation is the body of US AI law and rulemaking enacted or proposed by individual states. As of May 2026 it was the principal field of US AI regulation, given the unresolved federal-preemption fight (EO — Trump Federal Preemption of State AI Laws (Dec 11, 2025), Techno-Federalism). Individual instruments are tracked in legislation/; this page is the cross-cutting index. Aggregate counts of how many states have acted, and what those counts include, are treated separately at Counting state AI legislation; the National Conference of State Legislatures reported that 38 states adopted or enacted around 100 AI measures in the 2025 session, a figure whose unit is measures including resolutions rather than obligation-imposing statutes (Source: ncsl.org).
State landscape (May 2026)
Most-active states
Regulatory modes used by states
| Mode | Examples |
|---|---|
| Frontier-lab transparency | CA SB 53, NY RAISE Act |
| Sector-specific high-risk regulation | Colorado AI Act (hiring, lending, housing, education, healthcare) |
| Chatbot disclosure / mental-health regulation | CA SB 243 + multi-state wave |
| Training-data documentation | CA AB 2013 |
| Procurement attestation | CA EO N-5-26 |
| AI-content disclosure | Multiple states (election deepfakes, etc.) |
| State-AG enforcement of existing law | Massachusetts, NY, California AGs applying consumer-protection + anti-discrimination to AI |
Multistate AG action against a frontier developer
On August 3, 2026 the attorneys general of fifteen states — Iowa, Alabama, Arkansas, Florida, Idaho, Indiana, Kansas, Missouri, Montana, Nebraska, Oklahoma, Pennsylvania, South Carolina, Texas and Utah, led by Iowa's Brenna Bird — wrote to OpenAI chief executive Sam Altman stating that the company "may have violated State and federal law, including consumer-protection and data-privacy statutes that many Attorneys General are charged with enforcing" over the July 2026 Hugging Face intrusion (Letter from fifteen State Attorneys General to Sam Altman on the July 2026 Hugging Face intrusion (August 2026)). The letter demands preservation of eleven enumerated categories of materials with an express spoliation warning, assurance that no personnel face adverse action for protected whistleblowing, and that OpenAI "immediately cease and desist" from internal evaluations prompting its models "to pursue advanced exploitation using complex attack paths."
The instrument extends the state-AG enforcement mode in the table above from applying consumer-protection law to AI products to demanding changes in a developer's internal research practice. No case has been filed, and every factual assertion in the letter is prefaced "based on public reporting."
Federal preemption of state law
The xAI v. Colorado case (filed May 6, 2026, with the DOJ intervening on 14th Amendment grounds) and the Trump preemption EO are the live legal tests of whether state AI laws survive federal action. Their outcomes will shape the state-versus-federal balance through 2026–2027. A parallel constitutional front is SpaceXAI v. Bonta (AB 2013 challenge), SpaceXAI's First Amendment challenge to California AB 2013's training-data disclosure mandate: an appeals ruling adopting strict scrutiny could bear on the transparency provisions of SB 53, Illinois SB 315, and New York's RAISE Act (Source: transformernews.ai).
The preemption question was live in the Senate Commerce Committee as of late July 2026. Reporting published July 28, 2026 said Senate Democrats planned to offer amendments during the committee's AI markup to weaken proposed preemption of state AI laws, and to raise alleged conflicts of interest in the Trump administration's AI and technology deals. Only the lede of that account was retrievable; the markup date and the bill number were not recovered (Source: washingtonpost.com).
California-sized markets can create universal-compliance economics that resist preemption in practice, a propagation dynamic tracked on California Effect. California EO N-5-26 illustrates a separate route: state procurement, which is described as preemption-resistant under Section 8 of the Trump EO, an approach other states may follow. State AG enforcement of existing consumer-protection and anti-discrimination law operates independently of state AI statutes, and may be harder to preempt.
State preemption of local AI rules
A second preemption front opened in May 2026. The Local Solutions Support Center reported on 2026-05-11 that 9 states were considering 12 bills to preempt local AI regulation, including "Right to Compute" bills in New Hampshire, Ohio, South Carolina, and Virginia based on an American Legislative Exchange Council (ALEC) model; Montana enacted a Right to Compute Act in 2025 as the prototype. The center characterized the pattern as state legislatures invoking preemption against local governments while resisting federal preemption against themselves (Source: route-fifty.com).
The "Right to Compute" framing casts AI deployment as a commerce-clause-style protected economic activity, the same theory the DOJ may invoke against state AI regulations, and positions ALEC-model legislation as a convergence vehicle for the substantive-preemption Republican position (compare the Blackburn TRUMP AMERICA AI Act). If municipalities lose footing for local AI rules, such as San Francisco surveillance ordinances and New York City bias-audit ordinances, regulatory authority would shift up to the state level.
2026 legislative sessions
As state legislatures moved to close their 2026 sessions, a May 29, 2026 legislative update found AI bills remaining in play in several states. Louisiana lawmakers were set to adjourn June 1, with three AI-related bills sent to Gov. Jeff Landry and two awaiting final votes. Illinois headed toward Sunday adjournment with nine AI bills still alive, spanning chatbots, children's online safety, and privacy, including Illinois SB 315 (frontier safety framework with mandatory third-party audits), Illinois SB 317 — Consumer Artificial Intelligence Notice Act, and Illinois SB 3444 — Artificial Intelligence Safety Act (Source: transparencycoalition.ai).
In Colorado, Gov. Jared Polis vetoed the state's algorithmic-pricing bill on June 5, 2026, amid what one report described as "dueling stakeholder narratives" over whether the measure protected consumers or chilled legitimate pricing software, continuing the contested course of Colorado AI legislating seen in the much-amended Colorado AI Act (SB 24-205) (Source: insideaipolicy.com). In California, State Sen. Jerry McNerney withdrew his bill regulating utilities' use of AI on June 5, 2026, after a fiscal panel made "unwanted changes" that weakened it (Source: insideaipolicy.com).
California lawmakers approved a set of AI regulation bills on August 13, 2026, ahead of an August 14 deadline for fiscal committees to act. The measures reported include establishing a state-specific auditing and standards system, call-center oversight, and restrictions on AI-aided employment decisions. Technology firms and industry groups oppose the measures, and Governor Gavin Newsom's position on them was not clear at the time of reporting (Source: insideaipolicy.com). Only the article lede was retrievable and the bill numbers were not recovered, so the measures are recorded by subject rather than by designation; the auditing-and-standards item is consistent with the California SB 813 (AI Standards and Safety Commission) and AB 1405 track described under Independent Verification Organizations (IVOs), but no source confirms that identification.
State action in this period also extended to AI's physical footprint. Illinois Gov. JB Pritzker will pause data-center tax-incentive processing from July 1, 2026, and New York's one-year data-center moratorium awaits Gov. Hochul's signature; both are covered on AI Data Centers and Data Center Siting / AI Power Politics.
Professional-licensure regulation emerged as a further state vehicle: Pennsylvania Rep. Brenda Pugh introduced HB 2678 on June 29, 2026, amending Title 63 of the state's consolidated statutes governing licensed professions to address artificial intelligence; the bill was referred to the House Professional Licensure Committee (Source: palegis.us).
Tracking infrastructure has followed the activity: on July 12, 2026, technology lawyer Ray Sun expanded his Global AI Regulation Tracker to cover all 50 US states in both website and API form, citing state-level activity on algorithmic discrimination, chatbot disclosure, deepfakes, children's safety, and health AI as where most binding US AI regulation now sits (Source: techieray.substack.com).
Frontier-lab positioning on state legislation sharpened in mid-July. In a Wired interview published July 16, 2026, Anthropic said the transparency-based state AI laws it endorsed in 2025 "may already be outdated," and backed an Illinois measure requiring third-party model audits and a Massachusetts proposal empowering the state attorney general to seek injunctive relief — a state-by-state strategy that contrasts with OpenAI's push for federal preemption. David Sacks called the effort "a sophisticated regulatory capture strategy based on fear-mongering" (Source: wired.com; transformernews.ai).
Criminal-law measures on synthetic imagery also continued to advance: Pennsylvania SB 1413, introduced July 8, 2026 by Sen. Tracy Pennycuick and referred to the Senate Judiciary Committee, would criminalize AI-generated intimate depictions of a person without consent under the state's invasion-of-privacy statute (Source: palegis.us). In the same chamber's workforce lane, Pennsylvania HB 2705, directing a state report on AI in the workforce, was introduced and referred to the House Labor & Industry Committee on July 16, 2026 (Source: palegis.us).
Rent-pricing algorithms became the subject of a fourth state law on July 20, 2026, when New Jersey Gov. Mikie Sherrill signed the Forbidding the Algorithmic Inflation of Rent (FAIR) Act, barring rent-setting software from pooling nonpublic pricing data (Source: nj.gov). See Algorithmic Pricing and Antitrust. Sherrill had earlier signed A-5328 on June 30, 2026 — two days after its introduction — creating a data broker and "data collector" registration regime with annual fees scaling to $1.5 million by data volume and prohibiting sales of sensitive data; privacy practitioners have questioned both the compressed timeline and the breadth of the covered-entity definition (Source: wilmerhale.com; iapp.org).
By August 2026 the activity had shifted from enactment toward implementation and enforcement machinery. New York Gov. Kathy Hochul and Attorney General Letitia James announced final implementing rules for the state's SAFE for Kids Act on July 28, 2026: where an operator lacks actual knowledge that a user is a minor, it must apply an age assurance method meeting the certification standards of Section 700.4, covering documentation, accuracy, data processing, security and testing. Three further bills awaited Hochul's action — S 9051 on companion chatbots, S 9408 on chatbots in toys, and S 9269 on consumer health. Vermont Attorney General Charity Clark separately proposed rules under the state's Age Appropriate Design Code (S 69) requiring a graduated-escalation approach to age assurance tied to method intrusiveness, with comments closing October 2 (Source: thealgorithmicupdate.substack.com).
California opened the first formal compliance audit under this wave. The California Privacy Protection Agency targeted whether gig economy platforms let consumers and workers — including the independent contractors who make up most gig platform workers — exercise CCPA access rights within the required 45-day window. A new Audits Division under chief auditor Sabrina Ross runs it, separate from enforcement though findings may be referred; under 11 CCR § 7304 the agency may examine business practices without a prior complaint or settlement. The announcement followed by one month Illinois's enactment of the first compliance-audit requirement under its frontier model law (Illinois SB 315 (frontier safety framework with mandatory third-party audits)) (Source: thealgorithmicupdate.substack.com). The audit power is a distinct regulatory mode from the disclosure and prohibition instruments catalogued above: it reaches practice rather than published policy, without requiring a complaint.
Federal activity ran alongside rather than displacing this. The Senate Committee on Commerce, Science, and Transportation was set to mark up five bills on August 5, 2026 — S. 737 (SCREEN Act), S. 1748 (KOSA), S. 4199 (Youth AI Privacy Act), S. 4407 (CHATBOT Act) and S. 5171 (Children's AI Toy Safety Act) — without COPPA 2.0 or the federal data broker registry carried in the House-passed KIDS Act (Source: thealgorithmicupdate.substack.com). See Kids Internet and Digital Safety Act (KIDS Act, H.R. 7757).
Congressional testimony arguing the preemption case against this activity — and the competing reverse-federalism reading of the same evidence — is summarized at AI at a Crossroads: A Nationwide Strategy or Californication? — Testimony of Kevin Frazier (September 2025).
Relationships
- related: Techno-Federalism (the cross-cutting federalism concept), California Effect (the propagation dynamic).
- related: Procurement-Driven AI Governance (the state-procurement-seam alternative).
- related: EO — Trump Federal Preemption of State AI Laws (Dec 11, 2025), America's AI Action Plan (federal-preemption instruments).
- related: all
legislation/*state pages.
Sources
Stub created 2026-05-11.