Mayhem Shield
Insight

State AI law and the obligations that land on the buyer.

Published

Much of US AI legislation regulates model developers or specific consumer products. A smaller set of state and local rules reaches the business that selects and deploys a system. Those rules carry dates and require evidence about the buyer's actual use, not only the product as shipped.

The test we apply.

A law belongs on this page if it places a dated obligation on the deployer and meeting that obligation requires evidence about the system or the workflow in which it is used.

That excludes many developer thresholds, model-training disclosures, provenance rules, and product-specific requirements. Those laws matter, but they do not answer the narrower question: what must an enterprise buyer do before or while using the system?

What binds now, and what starts next.

Texas, HB 149 (TRAIGA), effective January 1, 2026. The law prohibits specified intentional uses of AI. The Attorney General has exclusive enforcement authority, and the statute does not create a private right of action. Substantial compliance with the NIST AI Risk Management Framework, its Generative AI Profile, or another recognized framework can support an affirmative defense when used as part of an internal review process. See AI deployment review in Texas.

Illinois, HB 3773, effective January 1, 2026. The amended Human Rights Act prohibits an employer from using AI for listed employment purposes in a way that has a discriminatory effect, or from using ZIP codes as a proxy for protected classes. It also requires notice to an employee when the employer uses AI for those purposes. See AI deployment review in Illinois.

Connecticut, Public Act 26-15, first employer duties October 1, 2026. An employer filing a federal WARN notice with the Connecticut Labor Department must disclose whether the layoffs relate to AI or another technological change. The act also provides that use of an automated employment-related decision technology is not a defense to an employment discrimination claim. The interaction disclosure and pre-decision notice duties apply to covered technologies deployed on or after October 1, 2027. See AI deployment review in Connecticut.

California, CCPA regulations, ADMT compliance January 1, 2027. Covered businesses using automated decisionmaking technology for significant decisions face pre-use notice, opt-out or exception, access, and plain-language explanation duties. Related risk assessments must be documented, with the first summary submission for 2026 and 2027 assessments due April 1, 2028. See AI deployment review in California.

New York City, Local Law 144, in force. An employer or employment agency may not use a covered automated employment decision tool unless it has undergone an independent bias audit within the prior year, a summary is publicly available, and required notices have been provided. See what a bias audit does not tell you.

Colorado, SB 26-189, effective January 1, 2027. The replacement statute centers deployer duties on consumer notice, a plain-language description after an adverse outcome, access and correction of personal data, and meaningful human review and reconsideration. The enacted bill summary describes the final framework.

Why Colorado is the cautionary tale.

Colorado's 2024 law paired deployer impact assessments with a duty of reasonable care. In April 2026, xAI challenged the statute and the Department of Justice moved to intervene. The legislature then repealed and reenacted the framework in May through SB 26-189. The replacement removed the former general deployer impact assessment and substituted a different set of documentation, notice, data, and human-review duties.

The litigation did not itself produce the enacted replacement. The relevant operational fact is that the legislature changed the statutory framework before its duties took effect. A governance program built around one jurisdiction's current checklist therefore needs a controlled way to absorb legal change.

The federal picture.

A December 2025 executive order directed the Attorney General to establish an AI Litigation Task Force to challenge state laws that the administration considers unlawful. The Department of Justice established that task force on January 9, 2026. The order does not by itself repeal state statutes.

Congress also considered a ten-year state AI enforcement moratorium in the 2025 reconciliation bill. The Senate adopted an amendment striking that section by a 99 to 1 vote. Businesses should plan for the enacted obligations while counsel monitors litigation and later federal legislation.

What this means for a deployment program.

The common thread is that the deploying organization needs evidence about a system it did not build: what data it processes, what it can reach, how its output enters a decision, who is accountable for that decision, and who can stop the workflow. Vendor documentation is an input, but it does not describe the buyer's configuration and use.

We produce a findings register against named controls, mapped to NIST AI RMF 1.0 and the OWASP Top 10 for LLM Applications, with gate conditions for proof of concept, pilot, and production. We are paid by buyers and do not resell, implement, or take fees from the vendors whose tools we review.

Discovery calls take twenty minutes.

If you have a deployment with a date attached to it, a short call can establish which review fits.

See the Rapid Readiness Review or book a scoping call.

This is not legal advice. Current as of September 2026. State AI law is moving quickly, and at least one statute on this page has already been rewritten. Confirm the statute text, current agency guidance, and advice from your own counsel before relying on any requirement or date.

Ready to start?

Discovery calls take twenty minutes.

We confirm deployment fit, outline review scope, and match you to the right packaged offer. No engagement starts until you decide to proceed.