← Back to blog
AI Policy·September 26, 2026·9 min read

Colorado, California, Texas: Mapping the 2026 US State AI Law Patchwork

Texas bans specific AI uses, California regulates frontier model developers, and Colorado rewrote its flagship AI law under litigation pressure — here's what each actually requires, and why Trump's preemption executive order hasn't changed any of it yet.

Three states, three different laws, one Executive Order trying to erase all of them

On January 1, 2026, two new state AI laws took effect in the United States on the same day, built on almost entirely different theories of what needs regulating. Ten days before that, President Trump signed an executive order whose stated goal is to make both of them go away. And the state whose AI law came first — Colorado — spent the first half of 2026 delaying its effective date, watching a federal court block it, and then rewriting it from scratch.

None of this is settled. But the mechanics of what's actually required, by whom, and starting when are concrete enough to map — and the map matters more than the politics, because businesses have to comply with the laws sitting on the books right now, regardless of what a future federal statute might eventually preempt.

The three laws, side by side

The three most significant state AI laws in effect in 2026 don't regulate the same thing. Texas targets how AI is used. California targets how the largest models are built and disclosed. Colorado, after its rewrite, targets automated decisions that affect people in specific high-stakes categories. Conflating them is the single most common mistake in compliance planning right now.

Texas TRAIGACalifornia SB 53 (TFAIA)Colorado SB 189 (replacing SB 205)
Effective dateJanuary 1, 2026January 1, 2026June 30, 2026 (as amended May 2026)
Who's regulatedAny entity developing or deploying AI in Texas, plus government agencies"Frontier developers" — companies training models above a compute threshold, with extra duties for "large" frontier developersDevelopers and deployers of "covered automated decision-making technology" (ADMT)
What triggers coverageSpecific prohibited uses (see below) or government AI useReleasing or materially modifying a frontier modelADMT that "materially influences" a consequential decision
Covered domainsBroad — any AI use, with government-specific rulesFrontier model development only, not use-case specificEmployment, housing, lending, insurance, healthcare, education, essential government services
Core obligationDon't use AI for specific prohibited purposes (below); state agencies must disclose AI usePublish a safety framework (large developers) and a transparency report before deployment; report critical safety incidentsDisclose ADMT use, explain adverse decisions, allow correction and human review, retain records 3 years
Liability standardIntent-based for most prohibitions — the state must show the AI was used for the prohibited purposeFramework and reporting failures are the violation, not model outputs themselvesFault allocated between developer and deployer; contractual indemnification for one's own discrimination is void
EnforcementTexas Attorney General only; 60-day cure periodCalifornia Attorney General; civil penalties per violationColorado Attorney General; mandatory rulemaking due by January 1, 2027
Private right of actionNoNoNo

Texas: an intent-based ban list, not a risk framework

TRAIGA reads less like the EU AI Act and more like a targeted list of things you're not allowed to do with AI in Texas. It bars using AI to manipulate human behavior toward self-harm, to socially score individuals in ways that cause unjustified harm, to infer protected characteristics from biometric data without consent for identification, or to produce child sexual abuse material or unlawful deepfakes. Government agencies get an additional layer: disclosure requirements when AI is used in decisions affecting the public, and restrictions on facial-recognition surveillance without a warrant.

The load-bearing detail is the state of mind requirement. For most of the prohibited-use provisions, the Attorney General has to show the AI system was used with the intent to bring about the prohibited outcome — not merely that a biased or harmful outcome occurred as a side effect of an otherwise legitimate system. That's a meaningfully lower compliance burden than a strict-liability or reasonable-care standard, and it's a large part of why Texas describes TRAIGA as light-touch relative to the laws it competes with for describing itself as "AI friendly." There's also a 60-day cure period before the AG can pursue civil penalties, and no private right of action — enforcement runs through one office, not through class-action plaintiffs' bars.

California: regulating the model, not the use case

SB 53 does something structurally different: it doesn't touch how AI is used inside a business at all. It regulates the companies training the largest foundation models. If you're not training frontier-scale models, SB 53 mostly doesn't apply to you as a deployer — which is the opposite emphasis from Texas and Colorado.

"Frontier developers" — a definition tied to training compute thresholds that California's Department of Technology is required to reassess annually as the state of the art moves — have to publish a transparency report before deploying a new or materially modified frontier model, describing capabilities, intended uses, limitations, and the results of risk assessments, including whether third-party evaluators were involved. "Large" frontier developers (the biggest labs, roughly) carry heavier duties on top: publishing a frontier AI safety and security framework describing how they assess and mitigate catastrophic risk, reporting critical safety incidents to state authorities within specified windows, and honoring whistleblower protections for employees who raise safety concerns internally.

This is why SB 53 gets described as putting California in the position of de facto national AI safety regulator — not because it reaches the most companies, but because nearly every major frontier lab either is headquartered in California or does business there, and the law doesn't carve out an exemption for developers based elsewhere. A transparency-report regime aimed at a few dozen companies has outsized reach precisely because those companies' models get embedded in everyone else's products.

Colorado: the law that got rewritten under fire

Colorado's story is the most instructive one, because it shows what actually happens when a broad, EU-style AI law meets both political pushback and litigation risk in real time.

The original SB 205, passed in 2024, would have required developers of "high-risk AI systems" to use reasonable care to prevent algorithmic discrimination, and required deployers to run annual impact assessments and maintain formal risk-management programs — obligations closer in spirit to the EU AI Act's high-risk-system regime than to anything else on the US books. It was originally set to take effect February 1, 2026. Lawmakers pushed that to June 30, 2026 when they couldn't agree on amendments in time. Then a federal court blocked enforcement of the predecessor provisions before that date arrived, and with a White House increasingly hostile to state AI rules in the background, Colorado's legislature did something unusual: it repealed and reenacted its own flagship AI law in a matter of weeks.

SB 189, signed May 14, 2026, is narrower in three specific ways. First, it replaces "high-risk AI system" with "automated decision-making technology" (ADMT) and swaps the vague "significant factor" trigger for a more precise "materially influence" standard. Second, it eliminates the reasonable-care duty to prevent algorithmic discrimination outright, along with the mandatory risk-management programs and annual impact assessments — the three provisions industry lobbied hardest against. Third, it adds sector carve-outs SB 205 never had: HIPAA-covered entities are largely exempt outside employment uses, insurers already subject to Colorado's existing algorithmic-discrimination rules are deemed compliant, ECOA/FCRA-compliant creditors don't need duplicate disclosures, and FDA-regulated medical devices are excluded entirely.

What survives is a disclosure-and-correction regime: deployers of covered ADMT in employment, housing, lending, insurance, healthcare, education, and essential government services have to tell people when ADMT materially influenced a decision about them, explain the principal reasons, and give them a path to correct data and request human review. Three-year record retention still applies. And unlike the original law's permissive rulemaking, SB 189 requires the Colorado Attorney General to finalize rules by January 1, 2027 — meaning the current text is not the final word on how this gets enforced.

The preemption fight sitting on top of all three

On December 11, 2025, President Trump signed Executive Order 14365, "Ensuring a National Policy Framework for Artificial Intelligence." It directs the Department of Justice to stand up an AI Litigation Task Force whose sole job is suing states over AI laws the administration considers unconstitutional burdens on interstate commerce or otherwise preempted; it directs the FTC to issue a policy statement on when state laws that force AI systems to alter "truthful outputs" are preempted by the FTC Act's unfair-and-deceptive-practices authority; and it threatens to cut off certain federal broadband funding (BEAD) to states judged to have "onerous" AI laws.

The order followed two failed legislative attempts at the same goal. A ten-year moratorium on state AI enforcement was stripped from the 2025 reconciliation bill by a 99-1 Senate vote after bipartisan backlash. A similar provision considered for the 2026 National Defense Authorization Act didn't survive either. Congress, in other words, has twice declined to do by statute what the executive order now tries to do by administrative pressure.

That distinction matters legally. An executive order is not a statute passed by Congress, and federal preemption of state law ordinarily requires either a congressional enactment or a federal regulation issued under authority Congress actually delegated. The order itself acknowledges there is no existing federal AI regulatory framework for state laws to conflict with — which undercuts its own conflict-preemption theory before a single lawsuit is filed. Legal analysts tracking the order broadly agree it signals an aggressive posture rather than an immediately binding one: expect DOJ lawsuits, an FTC policy statement, and funding threats, not automatic nullification of Colorado, California, or Texas's statutes. States have continued enforcing what's on their books.

What this actually means if you're building or deploying AI

The practical mechanics, stripped of the politics:

The throughline across all three states is that "AI regulation" in the US isn't converging toward the EU's single risk-tiered framework — it's fragmenting into at least three distinct regulatory postures (ban specific uses, regulate model developers, regulate consequential automated decisions), each shaped by a different state's politics and each still being rewritten in response to litigation and lobbying in real time. The patchwork isn't a temporary phase before a federal law arrives. As of late 2026, it's the actual operating environment.

#ai-policy#ai-regulation#colorado-ai-act#california-sb-53#texas-traiga#state-preemption

Related reading

AI Policy
AI Copyright Litigation, Mapped: Where Fair Use Actually Stands After the Anthropic Settlement
AI Policy
The EU AI Act's High-Risk Rules Land in August 2026 — What Actually Changes for Builders
AI in HR
Where AI Actually Works in Hiring: Resume Screening, Interview Scoring, and the Bias Audit Laws Catching Up to It