Skip to content
The US Has No Federal AI Law: Inside the 2026 State vs. White House Preemption Fight
AI & Automation48 min read

The US Has No Federal AI Law: Inside the 2026 State vs. White House Preemption Fight

Scult Team
48 min read

The US has no federal AI law, so the White House is trying to preempt state rules by executive order while 109 state AI laws already govern businesses.

The US Has No Federal AI Law: Inside the 2026 State vs. White House Preemption Fight

Direct answer: The United States has no comprehensive federal AI statute, so since December 2025 the White House has been trying to override the growing body of state AI laws through an executive order and a nonbinding "National Policy Framework," while a dedicated DOJ AI Litigation Task Force challenges state laws directly in court. That preemption push hasn't succeeded through actual legislation, so by 1 July 2026 states had still enacted 109 AI laws and 28 data-center laws — meaning any US-facing AI business is navigating a fragmented, actively contested regulatory map rather than one settled rulebook, and that fragmentation is the real operating environment for the foreseeable future, not a temporary gap waiting to be resolved.

There Is No Federal AI Law. That's the Starting Point for Everything Else.

It's worth stating plainly before getting into the fight over what should replace the vacuum: as of mid-2026, the United States does not have a comprehensive federal AI law comparable to the EU's AI Act. There's no single statute setting out risk tiers, provider obligations, or a dedicated federal AI regulator with cross-sectoral enforcement power. What exists instead is a voluntary framework — the NIST AI Risk Management Framework — plus a rapidly growing patchwork of state-level laws that have moved in to fill a space Congress hasn't legislated.

This isn't a new pattern for American technology regulation. Data breach notification is the clearest earlier example: nearly every state passed its own notification statute over roughly two decades, each with different triggers and timelines, while a comprehensive federal statute to unify them kept getting proposed and never quite arriving. AI regulation is tracking a similar rhythm, just compressed into a far shorter timeframe, because the technology itself is moving faster and the stakes businesses perceive are higher. Recognizing that pattern is useful for calibrating expectations: betting on an imminent, comprehensive federal AI law to sweep in and simplify everything is betting against how nearly every other wave of US technology regulation has actually played out.

That patchwork is not small or theoretical. By 1 July 2026, states had enacted 109 AI-specific laws and 28 laws specifically addressing data centers (the physical infrastructure increasingly tied to AI's power and water demands), according to tracking cited in Cloud Security Alliance research. That pace is described as running slightly behind 2025's, which tells you something useful on its own: state legislative activity on AI isn't slowing to a trickle while everyone waits for Washington to act — it's continuing at a substantial clip, just marginally less frantic than the prior year's initial wave.

This is the baseline every other part of this story sits on top of. The preemption fight described below isn't a dispute over how to amend an existing federal law — there isn't one to amend. It's a fight over whether the federal government can use executive authority to override a body of state law that exists precisely because Congress hasn't passed anything for that authority to build on.

The White House's Opening Move: An Executive Order With a Litigation Arm

The current phase of this fight traces back to a December 2025 executive order — EO 14365 — that declared a national policy favoring "minimally burdensome" AI regulatory standards. That phrase is doing real work: it's not a neutral description, it's a policy stance, and it set the tone for everything that followed. Alongside that declaration, the order created a DOJ AI Litigation Task Force with a specific mandate: challenge state AI laws directly in court, largely on the theory that certain state AI regulations improperly burden interstate commerce in a way the Dormant Commerce Clause doesn't permit.

The Dormant Commerce Clause is a constitutional doctrine that restricts states from passing laws that excessively burden interstate commerce, even where Congress hasn't explicitly legislated in that area. It's a real, established legal doctrine — but using it as the primary weapon against a broad category of state AI laws is a genuinely contested legal theory, not a settled one. State AI laws vary enormously in scope and mechanism, from algorithmic-discrimination rules to chatbot disclosure requirements to data-center permitting conditions, and whether a Dormant Commerce Clause challenge succeeds tends to depend heavily on the specific mechanics of each individual law, not on AI regulation as a category. A task force built around this theory is making a bet that it can win enough of these individual fights to functionally shrink the state regulatory map one lawsuit at a time, rather than through a single sweeping ruling.

The March 2026 National Policy Framework: A Plan, Not Yet a Law

Three months later, in March 2026, the administration went further with a National Policy Framework that proposed federal preemption of state AI laws considered "undue burdens" on AI development and deployment. This is the document that got the most attention from law firms tracking AI regulation — Morgan Lewis was explicit that it puts federal preemption "at the center of the debate" — because it's the clearest articulation yet of what the administration actually wants Congress to do, even though the Framework itself doesn't have the legal force to do it directly.

That distinction matters more than it might seem. A National Policy Framework of this kind functions as a set of nonbinding legislative recommendations — a strong signal of executive-branch preference and a starting point for possible legislation, but not itself a law that changes what any business is required to do. Congress would still have to pass an actual preemption statute for the Framework's proposal to take binding effect, and as of this writing, that hasn't happened. The gap between "the White House wants this" and "this is now the law" is exactly where the current uncertainty lives, and it's a gap that's proven durable rather than transitional so far in 2026.

The Framework also wasn't a blanket preemption proposal, which is worth being specific about. It carved out explicit exemptions: state child-safety laws, state regulation of AI compute and data-center infrastructure, and state procurement rules were all excluded from the proposed preemption. That's a meaningful signal about where the political limits of this push actually sit — even an administration explicitly trying to shrink the state AI regulatory map wasn't willing to touch child-safety rules or state authority over data-center siting and permitting, both of which carry their own separate, highly motivated political constituencies.

Why the Preemption Campaign Hasn't Actually Won

Here's the part that's easy to miss if you only read the headlines about executive orders and policy frameworks: none of this has actually preempted a single state AI law through legislation. An executive order can direct federal agencies and set litigation priorities; it cannot, on its own, override a validly enacted state statute the way an actual act of Congress could. The DOJ AI Litigation Task Force's court challenges are a real mechanism with real teeth if they succeed, but "succeed" here means winning individual cases against individual state laws under a genuinely contested constitutional theory — a slower, more uncertain path than a single federal preemption statute would be, and one where outcomes could easily vary by state, by law, and by court.

That's precisely why the state legislative pace hasn't collapsed. If businesses and state legislatures believed federal preemption were imminent and comprehensive, you'd expect state AI lawmaking activity to slow sharply while everyone waited to see what survived. Instead, the pace through mid-2026 was only slightly behind 2025's — consistent with a landscape where state lawmakers are still treating their own laws as the operative rules for now, not as placeholders about to be wiped away. For any business trying to plan a compliance roadmap, that's the single most important practical fact in this entire story: the patchwork is not a temporary inconvenience on its way to resolution. It is, for now, the actual regulatory environment, and treating it as anything else is planning around a hope rather than a fact.

Winning this fight in any durable sense would require the kind of bipartisan, cross-industry consensus that has proven difficult to build around nearly every other digital-era policy question over the past decade, from data privacy to platform liability. A litigation campaign can chip away at individual state laws over time, but it can't manufacture the political agreement needed for a comprehensive replacement, which is the piece still missing regardless of how the current court challenges eventually resolve.

This isn't the first time Washington has tried and failed to cleanly preempt a body of state technology law that grew up in the absence of federal action. Data privacy went through a strikingly similar arc: states passed their own comprehensive privacy statutes — California's first among them — precisely because Congress spent years unable to agree on a single federal privacy law, and repeated attempts at a federal statute that would preempt the state laws have stalled for the same underlying reason the AI preemption push is stalling now, a lack of consensus on what should replace the patchwork rather than just a desire to remove it. AI regulation is following that same script on a compressed timeline, which is a useful pattern to recognize: a federal government publicly committed to preemption and a patchwork of state laws that keeps growing anyway aren't necessarily in contradiction — they're often just two stages of the same unresolved fight running in parallel for years at a time.

The State Side of the Ledger: What's Actually in Force

With 109 state AI laws in place by the middle of 2026, no business operating nationally can treat "US AI regulation" as a single question with a single answer. The specifics vary by state, but a few have become reference points precisely because other states' laws borrow from or react to them. Colorado's AI Act is widely treated as the first comprehensive state law targeting algorithmic discrimination specifically — establishing obligations around risk assessment and disclosure for AI systems used in consequential decisions like employment, lending, or housing. Texas took its own approach with the Texas Responsible AI Governance Act (TRAIGA), which builds a risk-oriented framework covering developers and deployers of AI systems, including restrictions on certain uses the state considers manipulative or discriminatory and disclosure requirements tied to government use of AI. Illinois and New York have each moved on narrower fronts, particularly around AI's use in employment decisions — requiring employee-facing disclosure and, in various forms, guarding against discriminatory automated outcomes in hiring and workplace management.

These obligations rarely arrive in isolation, either. A company running an AI-driven hiring tool nationally can find itself subject to Illinois' and New York's employment-specific disclosure rules, Colorado's broader algorithmic-discrimination framework if the same tool factors into other consequential decisions, and a state privacy law's separate rules about the underlying candidate data — all at once, for one single product. Treating each of those as a standalone compliance project rather than recognizing the overlap is how compliance costs multiply faster than the number of states actually involved would suggest: the same AI system, the same underlying data flow, and the same basic user-facing behavior often trigger three or four separate legal analyses rather than one unified review.

The states themselves aren't coordinating this complexity deliberately — each legislature is responding to its own constituents' concerns about AI in employment, lending, or consumer protection, largely independent of what neighboring states are doing. That's a meaningfully different dynamic than a single regulator designing one coherent framework, and it's precisely why treating the patchwork as a coordination problem to be solved, rather than a permanent feature of how state legislatures work, tends to lead to more realistic compliance planning.

Enforcement mechanisms differ meaningfully across these laws too, which is a detail that gets lost when they're all lumped together as "state AI laws." Most rely on state attorney general enforcement rather than letting private individuals sue directly. Oregon is a notable exception: SB 1546 includes a private right of action, giving affected individuals a direct legal route that most other state AI statutes don't provide. That distinction changes the practical risk calculus considerably — a law enforced only by an under-resourced state AG's office carries different real-world exposure than one where any affected individual can bring their own claim.

Underneath all of this sits the NIST AI Risk Management Framework, which remains voluntary rather than legally binding anywhere. It doesn't carry the force of law in the way a state statute does, but it functions as a widely referenced baseline for what "reasonable AI governance" looks like — courts and regulators evaluating whether a company acted responsibly often look to whether recognized frameworks like NIST's were followed, even without a legal requirement to do so. Treating a voluntary framework as optional in every sense, including as evidence of due diligence, is a common and avoidable misreading of how much it actually matters in practice.

It's also worth being clear that "no federal AI statute" doesn't mean "no federal AI enforcement at all." Federal agencies with existing, non-AI-specific authority have continued applying it to AI use cases in the absence of a dedicated AI law: the Federal Trade Commission's general authority over unfair or deceptive practices reaches misleading claims about what an AI product actually does, financial regulators' existing authority reaches AI-driven credit and trading decisions, and employment-discrimination law reaches AI-assisted hiring decisions regardless of whether an AI-specific hiring statute exists in the relevant state. None of this amounts to a comprehensive federal AI framework, and none of it moves at the pace or with the specificity of a dedicated statute — but it means a business can't treat the absence of a federal AI law as the absence of any federal exposure whatsoever. The realistic picture is a federal layer built from existing, general-purpose authority sitting underneath the state-level AI-specific statutes, rather than an empty federal layer beneath a state patchwork.

A Second Executive Order Raised the Stakes Again in June 2026

The preemption fight wasn't the administration's only AI-related move this year. A separate executive order issued in June 2026 shifted focus toward frontier AI models and national security, and reporting from firms including Skadden and McDermott Will & Emery has described it as establishing a "covered frontier model" category — generally understood in this context to mean the most capable, largest-scale models rather than AI systems generally — subject to distinct obligations. Coverage has specifically flagged provisions around early government access to these frontier models and a classified benchmarking process aimed at evaluating AI systems' cyber capabilities, reflecting a national-security framing that's distinct from the consumer-protection and anti-discrimination framing driving most state AI laws.

It's worth being direct about the limits of public detail here: the granular legal text defining exactly which models qualify as "covered," and the precise mechanics of the government-access and benchmarking provisions, are the kind of specifics that continue to get clarified through agency guidance and law-firm analysis as implementation proceeds, rather than being fully settled the moment the order was signed. What's clear directionally is that this order runs on a different track from the December 2025 preemption order and March 2026 Framework — one is about which government, federal or state, gets to set the rules for AI generally, the other is about the federal government's own access to and oversight of the most powerful models specifically, largely for national-security reasons that sit outside the preemption debate entirely.

That split isn't unusual for how the federal government has historically approached powerful new technology: national-security-driven oversight of the most capable systems tends to move on its own track, often through executive action and sometimes through classified process, while the broader question of how the technology gets regulated for ordinary commercial and consumer use plays out through a slower, more public legislative and regulatory fight. Export-control regimes over sensitive technologies have followed a similar pattern for decades — tight federal control at the frontier of capability, layered on top of a much more contested and fragmented picture for the technology's ordinary commercial applications. Frontier AI models appear to be settling into the same two-track structure, and a company's practical obligations depend heavily on which track its own systems actually fall into.

What This Actually Looks Like for a Business Operating in 20-Plus States

None of this abstraction changes the concrete problem in front of a compliance or legal team at a company deploying AI across a meaningful footprint of US states: the rules are genuinely different state to state, none of it is likely to resolve into one clean federal standard soon, and the safest planning assumption is that the patchwork persists rather than collapses into simplicity.

The practical response that tends to work is building to the most stringent applicable state requirement as a baseline rather than maintaining fifty different compliance postures — the same logic many companies already apply to state privacy law compliance, where building to something like California's or Colorado's standard as a floor tends to cover a large share of other states' requirements with less complexity than a fully bespoke fifty-state matrix. That's not a legal guarantee of coverage everywhere, but it's a far more manageable operating model than treating each new state law as its own from-scratch project. Layering the NIST AI RMF underneath that as a documented governance baseline gives a business a defensible answer to "what framework did you follow" even in states without their own specific statute yet, and even if a regulator or plaintiff's attorney is evaluating the company's conduct under a law that didn't exist when the AI system was first built.

This is also where technical architecture and legal exposure genuinely intersect rather than staying in separate lanes. A system built with clear audit trails, documented decision logic, and human review points at the junctures that matter is materially easier to defend under any of these state frameworks — Colorado's, Texas's, or whatever comes next — than a system that was never designed with any of this in mind and now needs it bolted on after a law already applies to it. That's the same principle behind good custom software development generally: building governance and auditability into a system's architecture from the start costs a fraction of what retrofitting it onto something already in production does, regardless of which specific regulation eventually asks for it.

Procurement and vendor contracts deserve the same scrutiny as internal builds, and this is a step a surprising number of companies skip. Any AI tool or platform brought in from a third party should come with clear answers about which states' obligations the vendor itself is helping you meet, what happens contractually if a state law changes and the vendor's product falls out of alignment with it, and who bears responsibility if a regulator or plaintiff's attorney comes asking questions about a decision the tool helped make. A vendor that can't answer those questions clearly is effectively asking you to absorb legal uncertainty on their behalf, and that's a cost worth pricing into the vendor selection decision itself rather than discovering later during an actual dispute.

The View From Outside the US

This particular fight — a federal government trying to preempt its own states over AI regulation — doesn't have a close parallel in most of the other major markets watching AI regulation closely in 2026, and it's worth being honest about that rather than manufacturing a false equivalence.

The UK isn't having a federal-versus-state fight because it doesn't have US-style federated AI lawmaking in the first place; its live debate is a different question entirely — whether to pass any dedicated, comprehensive AI statute at all, rather than which level of government should hold that authority once one exists. Germany's AI regulation story in 2026 is also structurally different from a preemption fight, even though it involves questions of authority: because the EU AI Act is already supreme law across the bloc, Germany's live question has been which national regulator enforces it domestically, a question it answered directly by naming its federal network agency as the market surveillance authority, rather than a contest over which level of government gets to legislate in the first place. France, Australia, the UAE and Dubai, and China don't have distinct public reporting connecting them to this specific federal-versus-state preemption dynamic, which makes sense once you consider that the underlying structural condition driving it — a large federated country with individually empowered state legislatures actively regulating in a policy area ahead of its own national government — is fairly unusual outside the US to begin with, rather than a story every jurisdiction happens to be quietly having a version of.

That's a useful thing to hold onto when comparing US AI regulation to anywhere else: the interesting comparison isn't "which country has stricter AI rules," it's "which countries even have this particular kind of internal jurisdictional fight to begin with," and right now that's a fairly distinctly American story.

The variable driving all of this is federalism itself, not AI specifically. Any country with strong, independently elected sub-national governments that already regulate business activity — health, employment, consumer protection — has the underlying structural potential for exactly this kind of fight whenever a new technology arrives faster than national consensus can form around it. The US has that structure in an unusually pronounced form, with fifty states each capable of passing binding law and a federal government that can't simply overrule them by decree. Countries organized more centrally, where national government holds the AI-relevant regulatory authority by default, don't generate this particular dynamic no matter how contested their AI policy debate gets internally — which is exactly why this is a genuinely American story rather than a universal stage every country eventually passes through.

Where This Goes Next, and How to Build for a Moving Target

Congress could still pass a federal AI preemption law — nothing about the current stalemate forecloses that permanently, and the political pressure pushing toward some kind of federal standard, from industry groups tired of fifty-state compliance work, isn't going away. But betting a compliance strategy on that happening on any particular timeline would be planning around a hope rather than the facts on the ground as they exist right now. The more durable approach treats the current fragmented landscape as the actual operating environment for the foreseeable future: build governance practices that would hold up under the most demanding state law you're currently subject to, document decisions and data flows well enough to answer a regulator's or plaintiff's questions regardless of which state's law is asking, and revisit that baseline as new state laws land rather than trying to freeze a compliance program in place.

For businesses building or buying AI-powered systems during this period of genuine legal uncertainty, that argues for picking implementation partners and internal architectures that treat compliance-readiness as a design property rather than a feature bolted on after a law changes. Our methodology page covers how we scope that kind of build — mapping the regulatory exposure a system actually has before writing the first line of code, rather than treating governance as a checklist applied at the end. And if the honest state of play inside your own organization is "we're not fully sure which of the 109-plus state AI laws actually touch what we've already shipped," a full compliance review that maps your actual AI footprint against the laws that apply to it is a considerably better starting point than waiting to find out through a regulator's inquiry or a plaintiff's complaint instead.

The Practical Takeaway

The United States isn't moving toward a single federal AI law in 2026 — it's living through a genuine contest over whether one level of government can even displace the other's authority to regulate AI at all, fought through executive orders, a policy framework with no binding force yet, and a slower, case-by-case court campaign built on a contested constitutional theory. State AI law isn't a placeholder waiting to be overwritten; as of mid-2026 it's 109 laws deep and still the operative rulebook for most businesses. Planning around the patchwork as the real environment, rather than around the preemption campaign as an imminent resolution, is the reading of this moment that actually holds up.

Questions Companies Keep Asking About the US AI Regulation Patchwork

Is AI regulated in the US?

Yes, but not through one comprehensive federal law — that's the detail that trips people up. There's no single US AI statute comparable to the EU's AI Act, no dedicated federal AI regulator with cross-sectoral authority, and no federal risk-tiering system. What exists instead is a rapidly growing body of state law — 109 state AI laws enacted by 1 July 2026 — plus the voluntary NIST AI Risk Management Framework and various sector-specific rules (financial services, healthcare, employment) that already applied before AI became a distinct policy topic and now get applied to AI use within those sectors. So "is AI regulated" is really several separate questions: regulated federally (mostly not, beyond sectoral rules), regulated at the state level (extensively, and unevenly), and regulated through existing non-AI-specific law (yes, wherever AI touches an already-regulated activity like lending or hiring).

Why isn't there a federal AI law?

Partly because Congress hasn't reached agreement on what a federal AI law should actually contain, and partly because the current administration has pursued a different strategy entirely — trying to use executive authority and litigation to limit state AI laws rather than proposing its own comprehensive federal replacement for Congress to pass. The December 2025 executive order and March 2026 National Policy Framework are both explicitly about constraining what states can do, not about establishing a federal alternative regulatory regime with its own substantive AI rules. That's a meaningfully different approach than, say, the EU's, which built a binding statute first. Without a federal bill actually moving through Congress, and with the executive branch's tools limited to litigation and policy statements rather than legislation, the vacuum that states have been filling since roughly 2023 has had no federal counterpart to displace it.

Which states have AI laws I need to follow?

This depends entirely on where your business operates and where your users or customers are located, since state AI laws generally apply based on where the affected individuals are rather than where your company is headquartered — similar to how state privacy laws work. With 109 state AI laws in place by mid-2026, a business with any meaningful national footprint should assume multiple states' laws apply simultaneously rather than picking one state to comply with. Colorado's AI Act and Texas's TRAIGA are two of the most frequently referenced comprehensive state frameworks, but narrower laws in states like Illinois and New York covering AI in employment decisions can apply even to a business that's never heard of the state's broader AI framework. The realistic approach is a current inventory of every state where you have users, customers, or employees, checked against that state's specific AI-related statutes rather than relying on a general sense of "the big states."

What is NIST AI RMF and why does it matter?

The NIST AI Risk Management Framework is a voluntary set of guidelines from the National Institute of Standards and Technology for identifying, assessing, and managing risk across an AI system's lifecycle. It doesn't carry the force of law anywhere in the US, and no company is legally required to adopt it. It matters anyway because it's become the de facto reference point for what "reasonable AI governance" looks like in the absence of binding federal rules — regulators, courts, and business partners evaluating whether a company acted responsibly with an AI system often look to whether a recognized framework like NIST's was actually followed. Treating it as optional in every practical sense, not just the legal one, is a common mistake: a documented NIST-aligned governance process is frequently the strongest evidence a company has that it approached AI risk seriously, especially in a state without its own specific statute yet.

Will federal law override state AI regulations?

Not automatically, and not yet through any legislation that's actually passed. The administration has used an executive order and a policy framework to signal a clear preference for federal preemption, and a DOJ task force is actively litigating against specific state laws on constitutional grounds — but none of that is the same as Congress passing a federal preemption statute, which is the mechanism that would actually and comprehensively override state AI law. Until that happens, if it happens, existing state AI laws remain the operative rules for businesses in those states. Even if some future federal law does preempt parts of the state landscape, some of the current proposals explicitly exempt categories like child-safety laws and data-center regulation from preemption, meaning "federal law override" is unlikely to mean a single clean wipe of every state AI statute even in the most aggressive preemption scenario currently on the table.

What are the practical compliance steps for US AI governance in 2026?

Start with an inventory of every AI system your business provides or deploys, and map it against the states where your users, customers, and employees are located, since state AI law generally follows the people affected rather than your company's home base. From there, build to the most demanding applicable state standard as a working baseline — usually something modeled on Colorado's or Texas's frameworks — rather than trying to maintain a genuinely different compliance posture per state. Layer the NIST AI RMF underneath as a documented governance baseline that gives you a defensible answer to "what framework did you follow" regardless of which state's law eventually gets tested against your practices. Finally, treat this as a standing process rather than a one-time project: with state AI law still being enacted at a substantial pace, a compliance program that isn't revisited regularly will fall behind the actual legal landscape within a single year.

What areas are exempt from the White House's proposed federal preemption of state AI law?

The March 2026 National Policy Framework explicitly excluded three categories from its proposed preemption of state AI laws: state child-safety laws, state regulation of AI compute and data-center infrastructure, and state procurement rules. That's a meaningful signal about where the practical political limits of this push sit — even an administration actively trying to shrink the state AI regulatory map wasn't willing to propose preempting child-safety protections or state authority over data-center siting and permitting, both of which have their own separate, highly motivated constituencies pushing back against federal override. For a business, this means that even in the most aggressive preemption scenario currently on the table, certain categories of state law — particularly anything framed around protecting minors from AI-related harm — would very likely remain enforceable regardless of what happens to broader state AI statutes.

What is the DOJ AI Litigation Task Force and what legal theory is it using to challenge state AI laws?

The DOJ AI Litigation Task Force was created under the December 2025 executive order (EO 14365) with a specific mandate to challenge state AI laws directly in court, primarily using a Dormant Commerce Clause theory — the constitutional doctrine that restricts states from passing laws that excessively burden interstate commerce, even in areas Congress hasn't explicitly legislated. This is a genuinely contested legal strategy rather than a settled one: state AI laws vary enormously in scope and mechanism, and whether a Dormant Commerce Clause challenge succeeds tends to depend heavily on the specific structure of each individual law rather than on AI regulation as a category. The Task Force's approach amounts to a case-by-case litigation campaign rather than a single sweeping mechanism, which is inherently slower and less certain than a federal preemption statute would be, and results could plausibly vary significantly by state and by law.

How many state AI and data center laws have been enacted in 2026 so far?

By 1 July 2026, states had enacted 109 AI-specific laws and 28 laws specifically addressing data centers, according to tracking cited in Cloud Security Alliance research. That pace was described as running slightly behind 2025's — a meaningful data point in its own right, since it shows state legislative activity continuing at a substantial clip rather than slowing to a trickle while waiting on federal action. The two figures are worth keeping distinct: the 109 count covers AI regulation generally (algorithmic discrimination, transparency, employment-related AI use, and similar), while the 28 data-center laws address the physical infrastructure increasingly tied to AI's power and water demands — a related but separate policy concern that's generated its own distinct wave of state legislation as AI infrastructure buildout has accelerated.

Does Colorado's AI Act still apply if Congress eventually passes a federal preemption law?

That depends entirely on what a future federal preemption law actually says, which is precisely why the answer is currently unknowable rather than simply unclear. If Congress passes a preemption statute closely modeled on the March 2026 National Policy Framework's proposal, Colorado's AI Act could be substantially affected unless it falls into one of the framework's carved-out categories, none of which obviously cover Colorado's general algorithmic-discrimination framework. But no such federal statute currently exists — the Framework is a nonbinding recommendation, not a law — and Colorado's AI Act remains fully enforceable today regardless of what Washington eventually decides. Businesses should treat current state law as fully binding now and revisit that assessment if and when actual federal legislation passes, rather than discounting Colorado's law today based on a preemption campaign that hasn't yet succeeded through legislation.

What does the Texas Responsible AI Governance Act (TRAIGA) require and when does it take effect?

TRAIGA establishes a risk-oriented framework covering developers and deployers of AI systems in Texas, including restrictions on AI uses the state considers manipulative or unlawfully discriminatory, along with disclosure requirements tied specifically to government use of AI systems. It reflects the broader pattern many comprehensive state AI laws follow — distinguishing obligations by role (developer versus deployer) and by risk level, rather than applying one uniform rule to every AI system regardless of context. TRAIGA is one of the most frequently cited state frameworks precisely because Texas is a large enough market that compliance with it functions as a meaningful baseline for many multi-state businesses, similar to the role Colorado's AI Act plays for algorithmic-discrimination-specific obligations. For the current, precise effective-date and compliance-deadline details, checking Texas's own legislative text and current legal guidance is worthwhile, since implementing specifics continue to be clarified as the law takes effect.

How does California's AI regulatory approach differ from Colorado's?

Colorado's AI Act is best known as a comprehensive, single-statute approach to algorithmic discrimination specifically — establishing risk-assessment and disclosure obligations tied to AI use in consequential decisions like employment, lending, and housing under one unified framework. California has generally taken a more piecemeal approach, building AI-related obligations into multiple separate, narrower laws rather than one comprehensive statute, including specific rules addressing AI chatbot disclosure and child-safety contexts, such as the kind of law referenced in discussions of California's SB 243. The practical difference for a business is architectural as much as substantive: complying with Colorado often means satisfying one integrated framework, while complying with California can mean tracking several distinct, narrower statutes that each address a specific AI use case rather than AI risk as a single unified category.

What does Executive Order 14365, 'Ensuring a National Policy Framework for AI,' actually require?

EO 14365, signed in December 2025, declared a national policy favoring "minimally burdensome" AI regulatory standards and established a DOJ AI Litigation Task Force tasked with challenging state AI laws in court, largely on Dormant Commerce Clause and preemption grounds. As an executive order, it directs federal agencies and sets enforcement and litigation priorities within the executive branch — it doesn't and can't, on its own, repeal or override a validly enacted state law the way an act of Congress could. Its practical effect so far has been to set the policy tone that led to the March 2026 National Policy Framework's more detailed preemption proposal, and to stand up the litigation mechanism actively being used against specific state laws, rather than to directly change what any business is legally required to do under existing state statutes.

Can the federal government sue a state directly for enacting an AI law under EO 14365?

The DOJ AI Litigation Task Force created under EO 14365 is specifically built to bring legal challenges against state AI laws, generally arguing that particular statutes violate the Dormant Commerce Clause by unduly burdening interstate commerce. That's a real litigation mechanism with genuine legal consequences if a challenge succeeds, but it's meaningfully different from a clean, categorical power to void any state AI law by executive fiat — each challenge has to be brought against a specific law and succeed on its own legal merits in court, under a constitutional theory that remains genuinely contested rather than settled. Outcomes are likely to vary by state and by the specific mechanics of each law being challenged, meaning this is realistically a slow, case-by-case campaign rather than a single decisive legal action that resolves the broader preemption question all at once.

What does 'minimally burdensome' AI regulation mean under the White House's March 2026 framework?

It's the framing language the administration has used to describe its preferred regulatory philosophy — favoring lighter-touch, less prescriptive AI governance over the kind of binding, risk-tiered compliance regime the EU AI Act represents. In practice, within the March 2026 National Policy Framework, it translates into a proposal to preempt state AI laws viewed as imposing "undue burdens" on AI development and deployment, while explicitly carving out child-safety laws, data-center regulation, and state procurement rules from that preemption. It's worth treating "minimally burdensome" as a policy stance rather than a neutral technical description — it reflects a specific position in an active political debate about how much AI regulation is appropriate, and law firms tracking this, including Morgan Lewis, have been explicit that it puts federal preemption of state authority at the center of that debate rather than treating it as a settled premise.

Is the National Policy Framework for AI legally binding on Congress, or just a recommendation?

Just a recommendation — the National Policy Framework functions as a set of nonbinding legislative recommendations from the executive branch, not a law, and it has no power to bind Congress or force any legislative outcome. Congress would need to actually draft, pass, and have the President sign a genuine federal preemption statute for the Framework's proposals to take binding legal effect, and that hasn't happened as of this writing. The Framework's real function has been to signal the administration's preferred policy direction clearly enough that it shapes debate and potential future legislation, and to justify the DOJ Litigation Task Force's litigation strategy as consistent with a stated national policy — but as a document, it changes nothing about what any business is currently required to do under existing state AI law.

Why did the federal AI preemption campaign fail to pass through legislation in 2026?

"Failed" may overstate it, since the campaign was arguably never purely a legislative one to begin with — the administration's primary tools so far have been an executive order and a nonbinding policy framework rather than an actual bill introduced and voted on in Congress. Getting comprehensive federal preemption legislation passed requires building the kind of congressional consensus that AI regulation, as a topic, simply hasn't produced yet — lawmakers disagree not just on whether to preempt state law but on what should replace it, and industry itself isn't unified on the question, since some companies benefit from having settled state rules to build against while others prefer the current patchwork's absence of federal-level restrictions on some fronts. Without that consensus, the executive branch's litigation-and-framework approach has functioned as the available substitute, but it's a structurally slower and less certain path than legislation would be.

What's the difference between a state's 'AI law' count and its 'data center law' count in legislative trackers?

These track two related but distinct policy areas. A state's "AI law" count generally covers legislation addressing AI systems' use, outputs, and effects directly — things like algorithmic-discrimination rules, transparency and disclosure requirements, and AI use in employment or government decisions. A state's "data center law" count covers legislation addressing the physical infrastructure that increasingly underlies AI development and deployment — permitting, power and water usage, and tax incentives or restrictions tied to data-center construction, among other mechanisms. By 1 July 2026, trackers cited in Cloud Security Alliance research counted 109 laws in the first category and 28 in the second. A business evaluating its own compliance exposure should check both categories separately, since a state might have no direct AI-use law relevant to your product but still have a data-center law relevant if you're operating or planning to operate physical AI infrastructure there.

Which state was first to pass a comprehensive AI algorithmic-discrimination law?

Colorado is widely credited as the first state to pass a comprehensive law specifically targeting algorithmic discrimination — the Colorado AI Act, which established risk-assessment and disclosure obligations for AI systems used in consequential decisions like employment, lending, insurance, and housing under one unified framework rather than a collection of narrower, sector-specific rules. That "first comprehensive" framing matters because plenty of narrower AI-adjacent rules existed before it in various states, around specific technologies like facial recognition, for instance, but Colorado's law is generally treated as the first to build a single, cross-sector framework around algorithmic-discrimination risk specifically. Its early-mover status is part of why it's become a reference point other states' legislation gets compared against, even where those other states ultimately took a different structural approach.

Do NIST AI RMF voluntary standards carry legal weight in court?

Not directly as binding law — no court can require a company to follow the NIST AI Risk Management Framework simply because it exists, since it's explicitly voluntary and NIST has no enforcement authority over private companies' AI governance choices. Indirectly, though, it can carry real practical weight: in litigation or regulatory proceedings where a court or agency has to evaluate whether a company acted reasonably or with appropriate care in how it built and deployed an AI system, whether the company followed a recognized framework like NIST's is a natural reference point for that assessment, similar to how following industry-standard security practices can factor into a negligence analysis even without a specific law requiring those exact practices. Treating NIST alignment purely as a nice-to-have rather than as genuinely useful evidentiary groundwork undersells how it's actually likely to matter in a real dispute.

How should a company handle compliance if it operates in 20+ US states with different AI laws?

The realistic approach is building to the most stringent applicable state standard as an operating baseline, rather than trying to maintain 20-plus genuinely distinct compliance postures — the same strategy many companies already use for state privacy law compliance, where building to something like Colorado's or California's standard as a floor tends to cover a large share of other states' requirements with far less complexity than a fully bespoke, state-by-state matrix. That baseline should be layered on top of a documented NIST AI RMF-aligned governance process, giving a defensible answer to "what framework did you follow" regardless of which state's law eventually gets tested against your practices. This is also where sector matters — a company operating across healthcare, financial services, or employment-adjacent AI use cases faces compounding state and sectoral obligations at once, which is a big part of why our industries pages break out compliance priorities by sector rather than treating "AI compliance" as one undifferentiated topic.

Does the federal AI preemption push exempt child-safety chatbot laws like California's SB 243?

Based on the exemptions named in the March 2026 National Policy Framework, state child-safety laws were explicitly excluded from the proposed federal preemption of state AI law, meaning a chatbot-focused child-safety statute would very likely fall within that carved-out category rather than being subject to the preemption push, though the framework's language addresses child-safety laws as a category rather than naming every individual state statute it covers. That exemption is worth reading as a genuine political signal: even an administration explicitly trying to shrink the state AI regulatory footprint chose not to touch protections framed around children's safety, which tend to carry broad bipartisan support regardless of the broader AI-regulation debate. Businesses building AI products used by or accessible to minors should treat state child-safety-specific obligations as durable requirements unlikely to be preempted even if broader federal AI preemption legislation eventually passes in some form.

How does the June 2026 AI executive order differ from the December 2025 preemption order?

The two orders run on genuinely different tracks. The December 2025 order (EO 14365) is about domestic regulatory authority, asserting a "minimally burdensome" national policy and creating a DOJ task force to challenge state AI laws in court. The June 2026 order shifts focus toward frontier AI models and national security, reportedly establishing a "covered frontier model" category subject to distinct obligations, including provisions around early government access to these models and a classified benchmarking process for evaluating AI systems' cyber capabilities, according to reporting from firms including Skadden and McDermott Will & Emery. One order is fundamentally about which government, federal or state, gets to set AI rules generally; the other is about the federal government's own oversight of and access to the most powerful models specifically, driven by national-security concerns that sit largely outside the preemption debate.

What is a 'covered frontier model' under the June 2026 executive order?

Based on how law firms have described the June 2026 order's provisions, a "covered frontier model" is generally understood as a category capturing the most capable, largest-scale AI models, rather than AI systems broadly, reflecting a national-security framing that treats the very largest models as warranting distinct federal oversight separate from the AI-regulation-generally debate playing out through the preemption fight. The precise legal criteria used to determine which specific models qualify as "covered" are the kind of granular detail that continues to be clarified through agency guidance and legal analysis as implementation proceeds, rather than something fully settled the moment the order was signed. What's clear directionally is that this creates a distinct, narrower regulatory lane focused on frontier-capability AI and national security, running alongside rather than merging with the broader state-versus-federal preemption story.

Does the June 2026 executive order give the federal government early access to frontier AI models?

Reporting on the order, including coverage from Skadden, has specifically described provisions for early government access to frontier AI models as one of its notable features — a national-security-oriented measure allowing federal review of the most capable models before or as they reach wider deployment. This is a materially different kind of obligation than anything in the state-versus-federal preemption fight, since it's about the federal government's own oversight relationship with frontier model developers specifically, rather than about which level of government gets to set consumer-facing AI rules generally. Companies developing models that could plausibly fall into the "covered frontier model" category should treat this as a distinct compliance track worth following through current legal guidance as implementation details are clarified, separate from whatever else their state AI law compliance program is handling.

What is the classified benchmarking process for AI cyber capabilities mentioned in the June 2026 order?

Reporting from firms including McDermott Will & Emery has described the June 2026 order as establishing a classified process for benchmarking AI systems' cyber capabilities — evaluating frontier AI models for capabilities relevant to cybersecurity and national security, conducted under classified rather than public procedures. This reflects a genuine and separate policy concern from consumer AI regulation: the worry that increasingly capable AI models could meaningfully assist offensive cyber operations, which is a national-security question distinct from the algorithmic-discrimination and transparency concerns driving most state AI laws. The specific mechanics of how this benchmarking process operates and which developers it applies to are, by design, not fully public given the classified nature of the process, which limits how much detail even close legal and policy trackers of this order have been able to report.

Is state AI bill introduction in 2026 faster or slower than in 2025?

The clearest figure available describes enactment rather than introduction specifically: by 1 July 2026, states had enacted 109 AI laws and 28 data-center laws, a pace described as running slightly behind 2025's. Bill introduction volume — the number of AI-related bills filed, as opposed to the smaller number that actually become law — tends to run considerably higher than enactment in any given year, since most introduced bills don't pass, so the enactment-pace comparison is the more meaningful and reliably tracked figure here. What the "slightly behind 2025" framing does tell you is that state legislative appetite for AI regulation hasn't meaningfully cooled even as the federal preemption fight has escalated — states are still producing new AI law at a substantial clip rather than pausing to see how the federal preemption campaign resolves.

What is the Dormant Commerce Clause argument being used against state AI laws?

The Dormant Commerce Clause is a constitutional doctrine, inferred from the Constitution's grant of interstate commerce power to Congress, that restricts states from passing laws that unduly burden or discriminate against interstate commerce, even in policy areas where Congress itself hasn't passed legislation. Our glossary covers legal and technical terms like this one in plain language if you want the fuller definition alongside other jargon that comes up across AI compliance work. The DOJ AI Litigation Task Force is using this doctrine to argue that certain state AI laws impose exactly this kind of undue burden on companies operating across state lines, since a business that has to build different compliance systems for different states' AI rules could be seen as facing a discriminatory or excessive interstate commerce burden. It's a real, established doctrine, but applying it broadly against AI-specific state laws is a genuinely contested legal theory whose success will likely vary law by law and state by state rather than resolving as a single sweeping precedent.

Could Congress still pass a federal AI preemption law in 2027?

Nothing about the current stalemate forecloses that possibility — Congress retains full authority to pass a comprehensive federal AI preemption statute whenever it can build sufficient consensus to do so, and the political pressure pushing toward some kind of federal standard, especially from industry groups tired of fifty-state compliance complexity, hasn't gone away. But predicting a specific timeline would be speculation rather than analysis, since the same disagreements that have prevented legislation so far — not just whether to preempt, but what should replace the current patchwork, and how far any preemption should reach — don't resolve simply because a new calendar year begins. The more useful planning assumption for any business is that the current fragmented landscape persists until there's an actual bill moving through Congress with real momentum, rather than building a compliance strategy around an assumed 2027 resolution.

How should a multi-state business prioritize compliance given the current patchwork of state AI laws?

Prioritize by where your actual exposure is concentrated first — the states where you have the most users, customers, or employees, and the specific AI use cases (employment decisions, lending, consumer-facing chatbots) that tend to draw the most state legislative attention and enforcement interest. From there, build to the most demanding relevant state standard as a baseline rather than a bespoke posture per state, and treat the NIST AI RMF as the documented governance floor underneath that baseline regardless of which specific state law eventually gets tested against your practices. Revisit the whole assessment on a regular cadence rather than once — with state AI law still being enacted at a substantial pace, a program that isn't actively maintained will fall behind the actual legal landscape within a single year, turning what could be routine compliance maintenance into a larger catch-up project later.

What does Illinois' AI law require regarding automated employment decisions?

Illinois has moved specifically on AI's use in employment decisions, generally requiring that employers using AI tools in hiring or employment-related decisions provide disclosure to affected employees or applicants and take steps to guard against discriminatory outcomes from automated decision-making, consistent with a broader pattern across several states of treating employment as one of the highest-priority use cases for AI-specific disclosure and anti-discrimination obligations, alongside credit and lending decisions. This reflects a recognizable legislative pattern worth understanding at that level even before checking a specific state's exact statutory language: employment-related AI use draws disproportionate state legislative attention because it touches individual economic outcomes directly and visibly, which is also why New York and several other states have moved on similar ground around the same period.

What does New York's AI regulation require of employers or AI developers?

New York has, like Illinois, focused significant AI-related legislative attention on the employment context, generally pushing toward disclosure obligations for employers using automated decision tools in hiring and personnel decisions, along with mechanisms aimed at surfacing and addressing discriminatory outcomes from those tools. The exact scope and mechanism vary depending on which specific New York statute or local rule applies to a given employer, since AI employment regulation in New York has developed through more than one distinct legislative and regulatory track rather than a single unified statute. For any employer using AI in hiring or workforce management with New York-based employees or applicants, checking current state and any applicable local requirements specifically is worthwhile, since this is one of the more actively evolving areas of state AI law.

Is there a private right of action under any current US state AI law?

Yes — Oregon's SB 1546 is a notable example that includes a private right of action, giving individuals affected by a covered AI system a direct legal route to sue rather than relying solely on state attorney general enforcement. That's a meaningful exception rather than the norm: most current state AI laws, including comprehensive frameworks like Colorado's AI Act, rely on enforcement by the state attorney general's office rather than granting individuals their own standing to sue directly. The distinction changes the practical risk calculus considerably for a business — a law enforced only by an often under-resourced state AG's office carries a different real-world compliance risk profile than one where any affected individual can independently bring a claim, which is worth factoring specifically into how much compliance priority a given state's law gets relative to others without that mechanism.

What's the compliance risk for global companies facing both the EU AI Act and the US state-law patchwork at once?

The core risk is complexity compounding rather than any single rule being unusually hard to meet on its own: the EU AI Act is a binding, risk-tiered statute with a functioning enforcement body as of August 2026, while the US presents a fragmented, still-evolving patchwork of over a hundred state laws with no comprehensive federal equivalent and an active, unresolved preemption fight layered on top. A global company has to satisfy both simultaneously, and the two systems don't share a common structure to build one unified compliance approach against — the EU's risk-tiering doesn't map cleanly onto individual US states' varied approaches to algorithmic discrimination, disclosure, and employment-specific AI rules. The practical answer is usually building to the strictest applicable standard globally as an engineering baseline, then layering jurisdiction-specific documentation on top, rather than maintaining fully separate compliance architectures for each market.

Will the DOJ AI Litigation Task Force challenge chatbot child-safety laws even though they're exempted from preemption?

Based on what's been publicly reported about the March 2026 National Policy Framework's exemptions, child-safety laws were specifically carved out from the administration's proposed preemption approach, which suggests the DOJ AI Litigation Task Force is less likely to prioritize challenging those specific laws compared with other categories of state AI regulation. That said, an exemption from a policy framework's preemption proposal isn't necessarily an absolute guarantee against any future litigation on different legal grounds, since the Task Force's Dormant Commerce Clause theory could in principle be applied to a specific child-safety law's mechanics if it were structured in a way that genuinely burdened interstate commerce. Businesses building AI products for minors should treat state child-safety obligations as the current durable requirement, while watching for any shift in the Task Force's litigation targets as its case-by-case campaign continues to develop.

Want results like this?

Keep reading