AI Regulation in 2026: State Laws, Governance Frameworks, and What Businesses Must Know
March 3, 2026
The Regulatory Landscape Has Shifted
For most of the 2010s, AI governance was a matter of voluntary guidelines, academic debate, and aspirational frameworks from international organizations. By 2026, that has fundamentally changed. State legislatures across the U.S. — and regulatory agencies at the federal level — are actively passing enforceable laws that impose specific obligations on businesses that develop or deploy artificial intelligence systems. For companies building AI products, integrating AI tools into their operations, or using algorithmic systems to make consequential decisions, the compliance imperative is now real and immediate.
This guide surveys the current AI regulatory landscape, with a focus on the state-level developments that are most immediately actionable for businesses.
Colorado: The First Comprehensive AI Act
Colorado's SB 205, signed into law in 2024 and effective February 1, 2026, is the first comprehensive AI legislation enacted in the United States. It applies to "deployers" (businesses that deploy high-risk AI systems to make or assist with consequential decisions) and "developers" (businesses that develop high-risk AI systems for commercial use).
What Is a "High-Risk AI System" Under Colorado Law?
A high-risk AI system is one that makes or substantially influences a consequential decision — defined as a decision that has a material legal or similarly significant effect on a Colorado resident's access to education, employment, financial services, essential government services, housing, insurance, or legal services.
Key Obligations for Deployers
- Use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination
- Complete an impact assessment documenting the AI system's purpose, intended use cases, known limitations, steps to mitigate bias, and post-deployment monitoring procedures
- Provide consumers with notice that a high-risk AI system is being used and a clear description of the types of consequential decisions the system assists with
- Disclose the principal reason for any adverse consequential decision and offer an opportunity to correct data errors
- Provide a meaningful opportunity to appeal consequential decisions and seek human review
Violations are enforced by the Colorado Attorney General. There is no private right of action under the Colorado AI Act.
Synthetic Media and Deepfake Laws
One of the fastest-growing areas of AI-specific legislation is the regulation of synthetic media — AI-generated or AI-manipulated audio, video, and images that depict real people saying or doing things they didn't say or do (commonly called "deepfakes").
As of 2026, more than 20 states have enacted laws addressing deepfakes in various contexts:
- Election interference: Laws in California, Texas, Minnesota, and other states prohibit the distribution of materially deceptive AI-generated content depicting candidates in the 90-120 days before an election.
- Pornographic deepfakes: Numerous states have enacted laws creating civil and/or criminal liability for the non-consensual distribution of AI-generated intimate images.
- Right of publicity: Several states have extended existing right of publicity laws to cover AI-generated content that depicts a person's likeness without consent.
For businesses creating marketing content, entertainment, or any media involving depictions of real people, these laws create significant compliance considerations.
AI in Employment
The use of AI in hiring decisions — including AI-powered resume screening, video interview analysis, and automated candidate ranking — is an area of intense regulatory attention. New York City's Local Law 144, which took effect in 2023, requires employers using automated employment decision tools (AEDTs) to conduct and publish annual bias audits and to notify candidates that an AEDT is being used.
The EEOC has issued guidance making clear that AI-powered employment tools are subject to Title VII's disparate impact analysis — meaning that an AI hiring tool that produces discriminatory outcomes can give rise to employment discrimination liability, regardless of intent. Employers deploying AI in hiring should conduct regular bias audits, review the assumptions built into any AI tool they use, and maintain meaningful human oversight of automated employment decisions.
Federal AI Governance
At the federal level, the FTC has used its Section 5 authority to challenge deceptive and unfair AI practices. The CFPB has issued guidance on the application of the Equal Credit Opportunity Act to AI-based lending decisions. The FDA is developing frameworks for AI/ML-based medical devices. And Congress has introduced (though not yet enacted) several comprehensive AI governance bills.
The Biden Administration's Executive Order on AI (October 2023) directed federal agencies to develop AI governance standards within their respective domains. The Trump Administration's approach to AI governance has been more deregulatory in emphasis, but individual agency enforcement in areas like financial services, consumer protection, and civil rights continues.
What Businesses Should Do Now
- Inventory your AI use: Identify every AI system your business uses, develops, or deploys — including third-party AI tools. Understand what decisions they assist with and whether those decisions are "consequential" under applicable law.
- Assess high-risk AI systems: For systems that make or assist with consequential decisions, conduct an impact assessment documenting the system's purpose, limitations, bias risks, and mitigation measures.
- Implement human oversight: Ensure that meaningful human review is available for consequential AI-assisted decisions, and that the review is genuine rather than pro forma.
- Review vendor agreements: If you use third-party AI tools that assist with consequential decisions, your vendor agreements should address bias auditing, data practices, and allocation of liability for AI errors.
- Update consumer notices: Where required by law, disclose to consumers when AI is being used in consequential decisions and explain their rights to explanation, correction, and appeal.
- Monitor legal developments: AI regulation is evolving extremely rapidly. What is sufficient today may be inadequate in 12 months. Build a process for tracking regulatory developments in the jurisdictions where you operate.