
Blog Post
State AI Laws Change Faster Than Compliance Programs
August 26, 2026
Colorado passed the first comprehensive state AI law in May 2024, and organizations spent the following year building impact assessment processes against it. Those obligations never took effect. The statute was delayed twice, blocked by a federal court, then repealed and replaced by a narrower framework before its own effective date arrived.
Anyone who built a compliance program to that specific statute prepared for a regime that never existed. With more than fifteen hundred AI-related bills introduced across forty-five states in the first quarter of 2026 alone, exceeding the total for all of 2024, the lesson generalizes. Programs built to track statutes will be rebuilt every eighteen months.
What Happened in Colorado
The sequence is worth setting out because it demonstrates how quickly the ground moves.
The original act established duties for developers and deployers of high-risk AI systems to prevent algorithmic discrimination, borrowing its architecture from European law. Its effective date was pushed back more than once. In late April 2026 a federal court blocked enforcement following a constitutional challenge, with the Department of Justice intervening in support. A replacement bill was introduced days later and signed within two weeks.
The replacement drops the algorithmic discrimination duty and mandatory bias audits in favor of a narrower disclosure framework covering automated decision-making technology that materially influences a consequential decision. It takes effect on the first day of 2027, subject to rulemaking the state attorney general must complete first, and further legal challenge is anticipated.
The Laws Are Not Nested
A natural response to a patchwork is to identify the strictest regime and comply with that everywhere. It does not work here, because the statutes differ in kind rather than in severity.

Intent Versus Outcome
Texas targets intentional discrimination and behavioral manipulation, without disparate impact liability or mandatory audits, and provides a cure period. Frameworks in other states attach to outcomes produced by automated decision-making regardless of intent. A program designed to demonstrate absence of intent produces different evidence from one designed to demonstrate absence of disparate outcomes, and neither substitutes for the other.
Developer Versus Deployer
Obligations land on different parties depending on the statute. Some place the weight on those building models, others on enterprises using them for hiring, lending or healthcare decisions. An organization can hold developer duties in one state and deployer duties in another for the same system, and European rules add a further mechanism where changing a system's purpose moves the classification.
Build to Attributes, Not to Statutes
The durable approach records the properties every one of these laws asks about, rather than tracking the laws themselves. The statutes change constantly and the questions underneath them are remarkably stable.
- Decision Consequence: Whether the system materially influences employment, housing, lending, insurance, healthcare or education outcomes.
- Role Per System: Whether you built it, deployed it, substantially modified it or put your name on it.
- Affected Population: Which jurisdictions the individuals subject to the decision are in, which is rarely where the company is.
Three further attributes complete it. Whether a person makes the final determination and holds authority to depart from the output. Whether the basis for a decision can be explained to the individual affected. Documentation a regulator could examine completes the set. Every statute in this space, repealed or pending, asks some combination of those six.
Attributes Survive Repeal
An organization that recorded these against each system in early 2025 lost nothing when Colorado's framework was replaced, because the replacement asks about the same properties in a different arrangement. One that built impact assessment templates matched to the original statutory language rebuilt them. Recording intended purpose as the unit is what makes attribute-level tracking possible, since obligations attach to uses rather than to products.
Jurisdiction Follows the Individual
The most commonly missed attribute is the simplest. These laws generally apply based on where the person subject to the decision resides, not where the company operates or where the model runs.

A company headquartered in one state, running a model in a cloud region in another, screening applicants who live in a third, answers to the third. Employment screening and lending are where this bites hardest, because applicant pools are rarely confined to one state and nobody records applicant residence as a compliance attribute. Financial services carries the same pattern, where the use case determines the obligation.
Municipal Rules Sit Underneath
City-level requirements add a layer that state trackers miss entirely, with bias audit and notification obligations for automated employment tools in place in at least one major jurisdiction well before any state framework. Any organization hiring across multiple metropolitan areas should treat municipal obligations as a separate category rather than assuming state coverage subsumes them.
Federal Preemption Remains Unresolved
A separate uncertainty sits above all of this. The executive branch has pursued a national policy framework aimed at limiting state AI regulation, legislation establishing a unified federal standard has been under debate in Congress, and the Department of Justice has intervened in litigation challenging a state statute.
How that resolves is not knowable from here, and planning should not assume either outcome. The practical consequence is that building deeply to any single state's statutory language carries risk over and above ordinary amendment risk, since the statute may be superseded rather than revised. Attribute-level records are neutral to the outcome, which is a further argument for them.
What to Do This Quarter
Three actions hold value regardless of how the legal picture develops.
Record the six attributes against every AI system that touches a consequential decision, which is a scoping exercise rather than a legal one and can be completed without counsel. Capture applicant and customer jurisdiction where decisions affect individuals, since retrofitting that data later is considerably harder than collecting it now. Mapping existing framework work to the attributes completes it, because organizations already assessed against recognized standards will find much of the evidence exists, and mapping once to serve several obligations is the pattern that applies.
Voluntary Standards as a Working Baseline
Recognized frameworks are being used as a practical floor while the statutory picture settles, and at least one state framework references adherence to a recognized risk management framework in its safe harbor provisions. Aligning to one is worthwhile, and it does not discharge a statutory obligation. Choosing between the main frameworks matters less than picking one and being able to evidence it.
The Questions Outlast the Statutes
Colorado demonstrated that a state AI law can be delayed, blocked, repealed and replaced before it ever binds anyone, and the volume of legislative activity across other states makes that sequence likely to repeat. Programs organized around statutory text inherit that instability. Programs organized around what the system decides, who it affects, where those people live and whether a human holds the final call keep their value through repeal, replacement and preemption alike. Kovrr's AI compliance readiness scores each regime separately against the same underlying record, which is what allows one assessment to answer several.
To see which regimes reach your AI systems and where the obligations differ, book a demo mapped to your own estate.
State AI Law FAQs
Speak to an ExpertWhat happened to the Colorado AI Act?
It was repealed before it ever took effect. Passed in May 2024 as the first comprehensive state AI law, it established duties for developers and deployers of high-risk systems to prevent algorithmic discrimination. Its effective date was pushed back more than once, a federal court blocked enforcement in late April 2026 following a constitutional challenge with the Department of Justice intervening in support, and a replacement bill was introduced days later and signed within two weeks. The replacement drops the discrimination duty and mandatory bias audits in favor of a narrower disclosure framework taking effect at the start of 2027.
Can you comply by following the strictest state law?
No, because the statutes differ in kind rather than in severity. Texas targets intentional discrimination and behavioral manipulation without disparate impact liability or mandatory audits, while other frameworks attach to outcomes produced by automated decision-making regardless of intent. A program designed to demonstrate absence of intent produces different evidence from one designed to demonstrate absence of disparate outcomes. Obligations also land on different parties, so an organization can hold developer duties under one statute and deployer duties under another for the same system.
Which state's law applies to a given decision?
Generally the state where the person subject to the decision resides, rather than where the company operates or where the model runs. A company headquartered in one state, running a model in a cloud region in another, and screening applicants living in a third answers to the third. Employment screening and lending are where this bites hardest, because applicant pools are rarely confined to one state and few organizations record applicant residence as a compliance attribute. Municipal requirements add a further layer that state-level trackers miss.
What should be recorded instead of tracking statutes?
Six attributes that every one of these laws asks about in some combination. Whether the system materially influences a consequential decision such as employment, housing, lending, insurance, healthcare or education. Your role per system, covering whether you built it, deployed it, modified it or put your name on it. The jurisdictions where affected individuals live. Whether a person makes the final determination with authority to depart from the output. Whether the basis can be explained to the individual. Documentation a regulator could examine completes the set.
Will federal law preempt state AI regulation?
Unresolved, and planning should not assume either outcome. The executive branch has pursued a national policy framework aimed at limiting state AI regulation, legislation establishing a unified federal standard has been debated in Congress, and the Department of Justice has intervened in litigation challenging a state statute. The practical consequence is that building deeply to any single state's statutory language carries risk over and above ordinary amendment risk, since a statute may be superseded rather than revised. Attribute-level records are neutral to how this resolves.
Do voluntary frameworks help with state compliance?
They provide a practical baseline while the statutory picture settles, and at least one state framework references adherence to a recognized risk management framework in its safe harbor provisions. Aligning to one is worthwhile and does not discharge a statutory obligation. Organizations already assessed against a recognized standard will find much of the evidence the attribute questions require already exists, which makes mapping existing framework work to the attributes more efficient than starting a separate exercise.




