Framework

US state AI laws

No federal AI statute, and a fast-growing patchwork of state ones. Colorado, Texas, Utah, Illinois, New York City and California each ask something different. US state framework content is available in Aicura on the Enterprise tier.

What it is

The United States has no comprehensive federal AI statute. What it has instead is a patchwork, made up of state legislatures moving at speed, city-level rules in the employment space and federal agencies applying existing consumer protection, credit and anti-discrimination law to AI-driven conduct. For any organisation serving US users, "US AI law" means working out which pieces of the patchwork its systems touch, and the pieces do not ask the same things.

The pieces that matter most

  • Colorado AI Act. The first comprehensive state statute on high-risk AI, aimed at algorithmic discrimination in consequential decisions such as employment, credit, housing and essential services. It places duties of reasonable care on both developers and deployers, with risk management programs, impact assessments and disclosures among the mechanics.
  • Texas Responsible AI Governance Act. Texas's entry, oriented around prohibited harmful uses and government AI duties, and notable for a regulatory sandbox and for how large a market it attaches the rules to.
  • Utah AI Policy Act. Narrower and earlier, imposing disclosure duties when consumers interact with generative AI, wired into consumer protection law.
  • Employment decision rules. New York City's Local Law 144 requires bias audits and notices for automated employment decision tools, and Illinois regulates AI in hiring including video interview analysis, on top of its long-standing biometric privacy statute.
  • California. A cluster rather than one act, covering generative AI transparency and training-data disclosure laws, privacy rules on automated decision-making through the CCPA/CPRA regime and frontier model safety legislation, with more passing most sessions.
  • Federal enforcement. Above the states, the FTC, EEOC and CFPB apply existing statutes to AI-driven conduct, so unfair, deceptive or discriminatory outcomes are actionable without any AI-specific law at all.

Why an Australian organisation might care

Reach into the US rarely waits for a US entity. Serving US consumers, hiring in New York, making credit-adjacent decisions about Colorado residents or shipping a generative product Utah's disclosure rules touch is enough, and the obligations attach to the conduct rather than the incorporation. The patchwork also makes a governance point the single-statute jurisdictions do not. Because the asks differ by state, the only economical response is one governance program whose register, assessments and records can be read through multiple lenses, rather than a compliance project per statute.

Common misreadings

"There's no US AI law, so the US market is unregulated." There is no single federal AI statute, which is a different claim. The states have legislated energetically, existing federal law applies to AI-driven conduct through agencies like the FTC and the EEOC, and an Australian organisation serving US users can be inside several state regimes at once without noticing.

"We'll wait for the patchwork to settle." The patchwork is the settlement, at least for the foreseeable future. Federal preemption has been debated for years without arriving, and the states keep legislating. Governance that waits for a single US answer is governance that never starts.

"State laws only bind companies incorporated there." State laws typically apply to doing business in the state or to decisions affecting the state's residents, not to incorporation. A Colorado consumer affected by your high-risk AI decision is what puts you in Colorado's frame, wherever your company lives.

How Aicura supports work against it

US state framework content is available in Aicura on the Enterprise tier, operating the way every Aicura framework does, as loaded content applied through the product. The register establishes which systems make the consequential decisions the state statutes care about, risk and impact assessments carry the duties of care and the multi-framework view reads the same systems through each applicable lens, US, Australian and otherwise, with the record in the Evidence Vault throughout.


A note on this page

This is Aicura's reading of a fast-moving landscape, written to help you understand what the product is wired into. It is not legal advice, the US patchwork changes by the legislative session and which statutes reach your organisation is squarely a question for US counsel.

For a more complete picture of what Aicura does and doesn't do for any framework, see the boundaries page.

Get started with Aicura.

Sign up and start the work. From your first session, you can catalogue your AI systems, run your privacy policy through Aicura's guidance and put your first risk assessments in place.