Texas bans specific AI uses, California regulates frontier model developers, and Colorado rewrote its flagship AI law under litigation pressure — here's what each actually requires, and why Trump's preemption executive order hasn't changed any of it yet.
On January 1, 2026, two new state AI laws took effect in the United States on the same day, built on almost entirely different theories of what needs regulating. Ten days before that, President Trump signed an executive order whose stated goal is to make both of them go away. And the state whose AI law came first — Colorado — spent the first half of 2026 delaying its effective date, watching a federal court block it, and then rewriting it from scratch.
None of this is settled. But the mechanics of what's actually required, by whom, and starting when are concrete enough to map — and the map matters more than the politics, because businesses have to comply with the laws sitting on the books right now, regardless of what a future federal statute might eventually preempt.
The three most significant state AI laws in effect in 2026 don't regulate the same thing. Texas targets how AI is used. California targets how the largest models are built and disclosed. Colorado, after its rewrite, targets automated decisions that affect people in specific high-stakes categories. Conflating them is the single most common mistake in compliance planning right now.
| Texas TRAIGA | California SB 53 (TFAIA) | Colorado SB 189 (replacing SB 205) | |
|---|---|---|---|
| Effective date | January 1, 2026 | January 1, 2026 | June 30, 2026 (as amended May 2026) |
| Who's regulated | Any entity developing or deploying AI in Texas, plus government agencies | "Frontier developers" — companies training models above a compute threshold, with extra duties for "large" frontier developers | Developers and deployers of "covered automated decision-making technology" (ADMT) |
| What triggers coverage | Specific prohibited uses (see below) or government AI use | Releasing or materially modifying a frontier model | ADMT that "materially influences" a consequential decision |
| Covered domains | Broad — any AI use, with government-specific rules | Frontier model development only, not use-case specific | Employment, housing, lending, insurance, healthcare, education, essential government services |
| Core obligation | Don't use AI for specific prohibited purposes (below); state agencies must disclose AI use | Publish a safety framework (large developers) and a transparency report before deployment; report critical safety incidents | Disclose ADMT use, explain adverse decisions, allow correction and human review, retain records 3 years |
| Liability standard | Intent-based for most prohibitions — the state must show the AI was used for the prohibited purpose | Framework and reporting failures are the violation, not model outputs themselves | Fault allocated between developer and deployer; contractual indemnification for one's own discrimination is void |
| Enforcement | Texas Attorney General only; 60-day cure period | California Attorney General; civil penalties per violation | Colorado Attorney General; mandatory rulemaking due by January 1, 2027 |
| Private right of action | No | No | No |
TRAIGA reads less like the EU AI Act and more like a targeted list of things you're not allowed to do with AI in Texas. It bars using AI to manipulate human behavior toward self-harm, to socially score individuals in ways that cause unjustified harm, to infer protected characteristics from biometric data without consent for identification, or to produce child sexual abuse material or unlawful deepfakes. Government agencies get an additional layer: disclosure requirements when AI is used in decisions affecting the public, and restrictions on facial-recognition surveillance without a warrant.
The load-bearing detail is the state of mind requirement. For most of the prohibited-use provisions, the Attorney General has to show the AI system was used with the intent to bring about the prohibited outcome — not merely that a biased or harmful outcome occurred as a side effect of an otherwise legitimate system. That's a meaningfully lower compliance burden than a strict-liability or reasonable-care standard, and it's a large part of why Texas describes TRAIGA as light-touch relative to the laws it competes with for describing itself as "AI friendly." There's also a 60-day cure period before the AG can pursue civil penalties, and no private right of action — enforcement runs through one office, not through class-action plaintiffs' bars.
SB 53 does something structurally different: it doesn't touch how AI is used inside a business at all. It regulates the companies training the largest foundation models. If you're not training frontier-scale models, SB 53 mostly doesn't apply to you as a deployer — which is the opposite emphasis from Texas and Colorado.
"Frontier developers" — a definition tied to training compute thresholds that California's Department of Technology is required to reassess annually as the state of the art moves — have to publish a transparency report before deploying a new or materially modified frontier model, describing capabilities, intended uses, limitations, and the results of risk assessments, including whether third-party evaluators were involved. "Large" frontier developers (the biggest labs, roughly) carry heavier duties on top: publishing a frontier AI safety and security framework describing how they assess and mitigate catastrophic risk, reporting critical safety incidents to state authorities within specified windows, and honoring whistleblower protections for employees who raise safety concerns internally.
This is why SB 53 gets described as putting California in the position of de facto national AI safety regulator — not because it reaches the most companies, but because nearly every major frontier lab either is headquartered in California or does business there, and the law doesn't carve out an exemption for developers based elsewhere. A transparency-report regime aimed at a few dozen companies has outsized reach precisely because those companies' models get embedded in everyone else's products.
Colorado's story is the most instructive one, because it shows what actually happens when a broad, EU-style AI law meets both political pushback and litigation risk in real time.
The original SB 205, passed in 2024, would have required developers of "high-risk AI systems" to use reasonable care to prevent algorithmic discrimination, and required deployers to run annual impact assessments and maintain formal risk-management programs — obligations closer in spirit to the EU AI Act's high-risk-system regime than to anything else on the US books. It was originally set to take effect February 1, 2026. Lawmakers pushed that to June 30, 2026 when they couldn't agree on amendments in time. Then a federal court blocked enforcement of the predecessor provisions before that date arrived, and with a White House increasingly hostile to state AI rules in the background, Colorado's legislature did something unusual: it repealed and reenacted its own flagship AI law in a matter of weeks.
SB 189, signed May 14, 2026, is narrower in three specific ways. First, it replaces "high-risk AI system" with "automated decision-making technology" (ADMT) and swaps the vague "significant factor" trigger for a more precise "materially influence" standard. Second, it eliminates the reasonable-care duty to prevent algorithmic discrimination outright, along with the mandatory risk-management programs and annual impact assessments — the three provisions industry lobbied hardest against. Third, it adds sector carve-outs SB 205 never had: HIPAA-covered entities are largely exempt outside employment uses, insurers already subject to Colorado's existing algorithmic-discrimination rules are deemed compliant, ECOA/FCRA-compliant creditors don't need duplicate disclosures, and FDA-regulated medical devices are excluded entirely.
What survives is a disclosure-and-correction regime: deployers of covered ADMT in employment, housing, lending, insurance, healthcare, education, and essential government services have to tell people when ADMT materially influenced a decision about them, explain the principal reasons, and give them a path to correct data and request human review. Three-year record retention still applies. And unlike the original law's permissive rulemaking, SB 189 requires the Colorado Attorney General to finalize rules by January 1, 2027 — meaning the current text is not the final word on how this gets enforced.
On December 11, 2025, President Trump signed Executive Order 14365, "Ensuring a National Policy Framework for Artificial Intelligence." It directs the Department of Justice to stand up an AI Litigation Task Force whose sole job is suing states over AI laws the administration considers unconstitutional burdens on interstate commerce or otherwise preempted; it directs the FTC to issue a policy statement on when state laws that force AI systems to alter "truthful outputs" are preempted by the FTC Act's unfair-and-deceptive-practices authority; and it threatens to cut off certain federal broadband funding (BEAD) to states judged to have "onerous" AI laws.
The order followed two failed legislative attempts at the same goal. A ten-year moratorium on state AI enforcement was stripped from the 2025 reconciliation bill by a 99-1 Senate vote after bipartisan backlash. A similar provision considered for the 2026 National Defense Authorization Act didn't survive either. Congress, in other words, has twice declined to do by statute what the executive order now tries to do by administrative pressure.
That distinction matters legally. An executive order is not a statute passed by Congress, and federal preemption of state law ordinarily requires either a congressional enactment or a federal regulation issued under authority Congress actually delegated. The order itself acknowledges there is no existing federal AI regulatory framework for state laws to conflict with — which undercuts its own conflict-preemption theory before a single lawsuit is filed. Legal analysts tracking the order broadly agree it signals an aggressive posture rather than an immediately binding one: expect DOJ lawsuits, an FTC policy statement, and funding threats, not automatic nullification of Colorado, California, or Texas's statutes. States have continued enforcing what's on their books.
The practical mechanics, stripped of the politics:
The throughline across all three states is that "AI regulation" in the US isn't converging toward the EU's single risk-tiered framework — it's fragmenting into at least three distinct regulatory postures (ban specific uses, regulate model developers, regulate consequential automated decisions), each shaped by a different state's politics and each still being rewritten in response to litigation and lobbying in real time. The patchwork isn't a temporary phase before a federal law arrives. As of late 2026, it's the actual operating environment.