top of page

The landscape has changed dramatically’: States defy the tech lobby on AI rules

  • Writer: Gammatek ISPL
    Gammatek ISPL
  • 4 hours ago
  • 8 min read

Author: Gammatek ISPL, Published: 2nd SEP 2026

If you've been waiting for one national AI law to tell you what's required before you build a compliance plan, stop waiting. Congress has now rejected the tech industry's push to override state AI rules twice in a single year, most recently by refusing to attach preemption language to the National Defense Authorization Act. That means the patchwork of state laws already in force, in California, New York, Texas, and Colorado, isn't a placeholder until Washington acts. It is the law, it's enforceable now or within months, and the industry group that spent 2025 and 2026 lobbying to make it disappear has lost.

In this article

  • What just happened in Congress, and why it matters

  • The four state laws actually in force or about to be

  • Comparison: what each state law actually requires

  • Why the industry's "one national law" argument keeps losing

  • Implementation considerations for a four-state compliance reality

  • FAQ

US map illustration highlighting California, New York, Texas, and Colorado in distinct colors, each labeled with its AI law's effective date, showing a patchwork rather than a single national standard
Four states, four different AI laws, four different effective dates, and no federal law overriding any of them. This is the compliance map businesses are actually working with in 2026.

What just happened in Congress, and why it matters

Tech industry lobbying on AI shifted dramatically over the past year. Long-running fights over social media content and privacy have been largely eclipsed by AI-specific battles, and the biggest, richest tech companies have poured resources into shaping how AI gets regulated at exactly the moment states started moving faster than Washington. Executives from Meta, OpenAI, Google, and venture firm Andreessen Horowitz pushed hard for a single federal AI law that would supersede state rules, arguing that a fragmented, state-by-state legal landscape creates compliance headaches and risks ceding ground to international competitors.


Congress said no. Lawmakers rejected an attempt to use the National Defense Authorization Act, a defense-focused bill, as a vehicle for AI preemption language, with House Majority Leader Steve Scalise himself saying the defense bill wasn't the right place for it. That followed an earlier Senate vote of 99-1 against a similar preemption measure. White House AI czar David Sacks spent days working congressional leadership and tech executives to change the outcome and still came up short. This is now the second major defeat for the industry's preemption push in a single year, and both sides in Congress say the underlying debate isn't over, just that it didn't happen through this particular bill.

Meanwhile, tech lobbyists haven't stopped, they've redirected. Rather than only pushing Congress, they're fanning out to state capitals: helping shape California's main AI bill directly, staying in frequent contact with the Connecticut senator prepping a major AI push, and engaging early with legislators in New York, Massachusetts, and Illinois before bills are even introduced. The strategy mirrors what the industry learned from the earlier wave of state privacy laws: get to the table with proposed solutions before legislators write rules without you at all. Consumer advocates see the same states, California and New York especially, as the places where model AI policy gets set for the rest of the country, which is exactly why the lobbying pressure there is so intense.

The four state laws actually in force or about to be

While Washington and the lobbyists argue about preemption, four states have moved from proposal to enforceable law. None of them waited for a federal framework, and none of them are going away because a defense bill amendment failed.

California's SB 53 (Transparency in Frontier Artificial Intelligence Act) took effect January 1, 2026, becoming the first US frontier AI law. It requires large frontier model developers, those with revenue over $500 million, to publish transparency reports covering model capabilities and safety testing, report critical safety incidents to state authorities within 15 days, and implement whistleblower protections for AI safety researchers. Penalties run up to $1 million per violation. Governor Newsom explicitly described the law as a blueprint for other states in his signing statement.


New York's RAISE Act was signed in December 2025 and takes effect January 1, 2027. It follows the same "trust but verify" framework as California's law, in many places directly borrowing SB 53's text and definitions, and applies to the same tier of company: models trained on more than 10^26 FLOPS, developed by companies with over $500 million in prior-year revenue. It requires published safety protocols and 72-hour incident reporting to the state attorney general and a new state oversight office, with penalties up to $1 million for a first violation and $3 million for repeat violations.


Texas's TRAIGA has been in force since January 2026, with a different enforcement structure entirely: penalties ranging from $10,000 to $200,000 depending on the violation, targeting a broader set of AI use cases and harms rather than only frontier-model developers.


Colorado's AI Act has had the rockiest path, delayed twice, first to mid-2026 and then to January 2027, with its scope narrowed along the way to remove some deployer risk-management and impact-assessment duties. Even narrowed, Colorado's Attorney General released proposed rules in August 2026 that would convert the law's disclosure, correction, and human-review rights into detailed process requirements spanning developers, deployers, and the intermediaries sitting between them in the AI supply chain.

Comparison: what each state law actually requires

The differences between these laws matter more than the headlines suggest, because "AI regulation" isn't one thing legally. Some laws are conduct-based (banning specific uses regardless of company size), others are disclosure-based (requiring published safety frameworks or user notification), and a few do both. Reading a headline like "California passes AI law" without checking which axis it sits on is how compliance teams either over-invest in work that doesn't apply to them or miss an obligation that does.

Law

Who it targets

Core requirement

Effective date

Max penalty

California SB 53

Frontier developers, $500M+ revenue

Transparency reports, 15-day incident reporting, whistleblower protections

January 1, 2026 (live)

$1M per violation

New York RAISE Act

Frontier developers, same thresholds as SB 53

Published safety protocols, 72-hour incident reporting

January 1, 2027

$1M first / $3M repeat

Texas TRAIGA

Broader set of AI deployers, not just frontier

Prohibited-use and disclosure rules across use cases

January 2026 (live)

$10K–$200K

Colorado AI Act (revised)

Developers and deployers, narrowed scope

Disclosure, correction, and human-review rights

January 1, 2027

Rules still being finalized

Two things stand out. First, most companies building or deploying AI agents on top of third-party models, rather than training frontier models themselves, won't meet SB 53 or RAISE's compute and revenue thresholds. If you're a mid-sized business using AI tools rather than building foundation models, the frontier laws likely don't apply to you directly, but Texas's TRAIGA and Colorado's deployer-facing rules might, and that distinction is exactly where compliance teams get it wrong. Second, a company operating across all four states isn't choosing one law to comply with. It's layering four different trigger conditions, definitions, and enforcement regimes on top of whatever EU AI Act exposure it may also carry, since the EU law reaches any company whose AI touches EU residents regardless of headquarters location.


Why the industry's "one national law" argument keeps losing

The tech industry's core argument, that a single federal law prevents a confusing state-by-state patchwork, isn't wrong on the merits. It's losing anyway, for reasons worth understanding if you're planning compliance spend past this year.


First, states have historically moved faster than Washington on tech regulation, and lawmakers know it. The same dynamic played out with data privacy laws before AI: California and a wave of other states acted first, and industry eventually had to build compliance programs around a patchwork it had spent years trying to prevent. AI is following the identical pattern, just faster.


Second, California and New York's frontier AI laws turned out to converge rather than conflict. New York's RAISE Act borrows heavily from California's SB 53, including core definitions for catastrophic risk and critical safety incident, and both apply the same revenue and compute thresholds. That convergence undercuts the industry's strongest argument, that state laws would fragment into fifty incompatible standards, at least for the frontier-model tier. The worst-case scenario preemption advocates warned about hasn't materialized for the biggest AI developers, even without a federal law forcing alignment.


Third, and most practically for a business reading this rather than lobbying on it: SB 53 includes a federal-deference clause, meaning demonstrated compliance with a comparable federal or equivalent safety framework can satisfy the state obligation. States aren't necessarily trying to create pure duplication, they're filling a vacuum, and they've signaled willingness to defer to federal standards if and when those standards actually exist. Right now, they mostly don't, so the state requirement is the operative one.

Implementation considerations for a four-state compliance reality

Whether or not your company trains frontier models, if you deploy AI tools that touch customers, employees, or applicants in these states, the patchwork is your operating environment now, not a temporary condition to wait out.

  1. Map your AI exposure against thresholds, not headlines. Determine whether your AI use falls under a frontier-developer law (SB 53, RAISE) or a broader deployer law (TRAIGA, Colorado's revised AI Act) before assuming either applies or doesn't. The compute and revenue thresholds in the frontier laws exclude most mid-sized companies; the deployer-facing laws often don't.

  2. Track effective dates separately from enforcement dates. SB 53 and TRAIGA are already live. RAISE and Colorado's law aren't enforceable until 2027, but rulemaking and disclosure prep typically needs to start well before an effective date, not the week of it.

  3. Build one compliance framework, not four. Given how closely RAISE mirrors SB 53, and given SB 53's federal-deference clause, a single well-documented AI governance framework, covering transparency, incident reporting, and human oversight, can likely satisfy multiple state requirements with state-specific addenda rather than four separate programs.

  4. Assign accountability before a regulator asks who's responsible. Every one of these laws expects a named point of responsibility inside the organization, whether for incident reporting, human review, or correction rights. A working group formed after an incident is a worse position than one formed now.

  5. Watch Illinois, Massachusetts, Connecticut, and Washington next. These are the states tech lobbyists are already engaging early, which is itself a signal of where the next binding law is likely to land, often before it's formally introduced.


Frequently asked questions

Does the failure to add AI preemption to the defense bill mean state AI laws are permanent? It means they're not currently at risk of federal override, and it's the second time in 2026 that a preemption effort has failed. Congress hasn't ruled out a future federal AI framework working alongside state laws, but as of now, state laws are the enforceable standard and businesses should treat them that way rather than waiting for a federal law to arrive.

My company doesn't build AI models, we just use AI tools. Do these laws apply to me? Possibly, but not necessarily the frontier laws. SB 53 and the RAISE Act target frontier model developers above specific compute and revenue thresholds, which excludes most companies that deploy third-party AI tools. Texas's TRAIGA and Colorado's revised AI Act reach a broader set of deployers, so the right question is which law's trigger conditions your actual AI use meets, not whether "an AI law" exists in your state.

Which state's AI law should a multi-state business use as its compliance baseline? California's SB 53 is a reasonable baseline for frontier-model-adjacent obligations, since New York's RAISE Act was deliberately written to closely mirror it. For deployer-level obligations (human review rights, disclosure to affected individuals), Colorado's finalized rules and Texas's TRAIGA are worth building toward separately, since they follow a different structure.

Is a national AI law still possible? Yes, and both sides of the preemption fight say the conversation continues. But two failed attempts in one year suggest it won't happen quickly, and even SB 53's federal-deference clause assumes a comparable federal framework doesn't yet exist. Building compliance around current state law, with room to adjust if a federal law arrives, is the more defensible position than waiting.

What happens if my business operates in a state without a specific AI law yet? Existing enforcement by federal regulators like the FTC and EEOC still applies to AI-specific harms under decades-old statutes covering discrimination and unfair practices, even absent a state AI law. And given how quickly states are moving, the safer assumption is "not yet" rather than "never."

Not sure which of these state AI laws actually apply to your business, or what your current AI tools might already be exposing you to?

Our AI compliance and governance review maps your AI systems against California, New York, Texas, and Colorado's current requirements, flags which thresholds you do and don't meet, and builds a single framework instead of four separate scrambles.


 
 
 

Comments


bottom of page