The State of State AI: Legislative Approaches to AI in 2025 is a 21-page report published in October 2025 by the Future of Privacy Forum (FPF), authored by Justine Gluck (Policy Analyst, AI Policy and Legislation), Beth Do (Policy Fellow), and Tatiana Rice (Senior Director of U.S. Legislation). It surveys state-level AI legislation introduced during 2025, classifies bills by regulatory approach, and reports that state lawmakers moved away from sweeping, framework-style AI regulation toward narrower, transparency-driven, use-case-specific laws.
Summary of findings
FPF tracked 210 AI-related bills introduced across 42 US states; only 8 states introduced no qualifying bills. Of the tracked bills, approximately 9% were enrolled or enacted, and most of those enacted focused on government AI use or state investment rather than private-sector compliance obligations. Substantive compliance frameworks — particularly high-risk automated decision-making technology (ADMT) regulations modeled on the Colorado AI Act (SB 24-205) and SB 25B-004 (Date Amendment) — faced significant hurdles in 2025, and generally failed to pass or were diluted.
The report's central finding is the shift from comprehensive framework legislation toward targeted transparency requirements aimed at specific use cases.
Classification of approaches
FPF groups the tracked bills into four thematic approaches by share of bills tracked:
| Approach | Description | Share of tracked bills |
|---|---|---|
| Use/context-specific | Healthcare, employment, finance — targets high-risk applications | ~12% ADMT + ~9% healthcare + ~10% employment |
| Technology-specific | GenAI, frontier/foundation models, chatbots | ~11% GenAI + ~4% chatbots + ~3% frontier |
| Liability/accountability | Modifies existing liability regimes; clarifies tort application to AI | ~3% liability |
| Government/structural | Government AI use, task forces, investment | ~15% government use + ~8% task forces |
For private-sector regulation, FPF identifies three archetypes: use/context-specific bills targeting sensitive applications; technology-specific bills addressing GenAI, chatbots, and foundation models; and liability/accountability bills that apply or modify tort law.
Use/context-specific bills
FPF describes this as the most common category. Healthcare bills set disclosure requirements (for example California's AB 3030), clinical AI oversight, and ambient scribe liability. Employment bills cover AI-in-hiring disclosure and bias audit requirements, building on the New York City Local Law 144 model. Financial-services bills address algorithmic lending and credit-scoring AI disclosure. ADMT/high-risk bills sought Colorado-style comprehensive requirements; these advanced in 2025 but generally failed to pass or were diluted.
Technology-specific bills
Chatbot disclosure was a major category: California's SB 243 (see California SB 243 — Companion Chatbots) triggered similar bills in Oregon and Washington, a trend extended in the companion report (see The Rest of the West: Oregon and Washington Build on California Chatbot Law). Frontier and foundation model bills were California-focused, with SB 53 the leading enacted example. GenAI transparency bills addressed disclosure of AI-generated content through watermarking and labeling.
Liability/accountability bills
These bills modify tort law to clarify AI developer and deployer liability; FPF cites the federal AI LEAD Act as the analog. Some bills create safe harbors for standards-compliant AI as a complement to liability exposure.
Enacted laws and the innovation tilt
FPF reports that the most commonly enacted measures were healthcare AI laws (AB 3030-style disclaimers), chatbot disclosures (SB 243 successors), and innovation safeguards such as sandboxes and safe harbors, which FPF frames as legislatures balancing protection with growth. The report identifies sandboxes and liability defenses as signals of a pro-innovation tilt, citing the Texas TRAIGA sandbox (see Texas Responsible AI Governance Act (TRAIGA / HB 149) — Source Summary) as the most prominent example and Illinois SB 3444's conditional liability shield (see Illinois SB 3444 — Artificial Intelligence Safety Act) as another.
Structural observations
FPF attributes the surge in state activity to the absence of federal AI legislation: no major federal AI bill advanced in Congress, and states filled the gap. The report was written before EO 14365's preemption attempt. It characterizes the ~9% enactment rate as low, with a large gap between introduction and passage, especially for substantive private-sector compliance frameworks. The report notes that government use is easier to regulate than private-sector conduct — most enacted bills focused on government agency AI use, which FPF attributes to lower political resistance.
Outlook for 2026
The report identifies three trends emerging into 2026. FPF describes definitional uncertainty — what counts as "AI," "high-risk," or "frontier model" — as the most persistent challenge. It identifies agentic AI governance (autonomy, multi-step action, oversight requirements) as a distinct regulatory question. And it flags algorithmic pricing as an emerging consumer-protection focus, with 51 bills tracked in the first half of 2025 alone (see FPF — A Price to Pay: U.S. Lawmaker Efforts to Regulate Algorithmic Pricing).
Provenance and methodology
The report is a single source reflecting FPF's own bill tracking; FPF is a recognized nonprofit (see Future of Privacy Forum (FPF)). The methodology excludes election, housing, agriculture, and education bills. The reported 9% enactment rate is for FPF's curated 210-bill list, not the more than 1,000 AI-referencing bills introduced overall. Confidence is high for the qualitative trends; the exact counts reflect FPF-specific methodology.
The report supplies empirical counts referenced elsewhere: 42 states and 18 distinct bill types relevant to state regulatory fragmentation (see Techno-Federalism: How Regulatory Fragmentation Shapes the U.S.-China AI Race); the documented shift away from comprehensive frameworks (see US AI Regulatory Approaches Compared); the 51-bill algorithmic-pricing count (see FPF — A Price to Pay: U.S. Lawmaker Efforts to Regulate Algorithmic Pricing); and the chatbot-law expansion feeding The Rest of the West: Oregon and Washington Build on California Chatbot Law and California SB 243 — Companion Chatbots.
Relationships
- supports: Techno-Federalism: How Regulatory Fragmentation Shapes the U.S.-China AI Race — 42-state fragmentation confirms Wu's regulatory-fragmentation thesis
- supports: US AI Regulatory Approaches Compared — provides empirical backbone for "narrow approaches winning" narrative
- related: Incentives or Obligations? The U.S. Regulatory Approach to Voluntary AI Governance Standards — same FPF policy team; companion on voluntary standards
- related: The Rest of the West: Oregon and Washington Build on California Chatbot Law — chatbot law trend documented here is extended in the companion report
- related: FPF — A Price to Pay: U.S. Lawmaker Efforts to Regulate Algorithmic Pricing — algorithmic pricing section of this report directly connects to dedicated FPF pricing bill tracker
- related: Colorado AI Act (SB 24-205) and SB 25B-004 (Date Amendment) — the sweeping-framework approach that failed to replicate in 2025
- related: Texas Responsible AI Governance Act (TRAIGA / HB 149) — Source Summary — primary example of the sandbox/safe-harbor innovation approach
- related: Illinois SB 3444 — Artificial Intelligence Safety Act — primary example of the conditional liability shield approach
- related: AI Regulatory Sandbox — concept page covering the sandbox approach.
- related: Vetocracy — 9% enactment rate is empirical evidence of the dynamic at state level.
- related: Brussels Effect — US-state fragmentation as domestic counterweight to EU-originating uniformity.
- related: Future of Privacy Forum (FPF) — publisher.