Why the United States Regulates AI State by State

Lesson concept diagram
Why the United States Regulates AI State by State

State-level AI regulation in the United States reflects a fragmented approach that contrasts with the EU’s unified framework. While the EU has adopted a single, broad AI Act applicable across member states, US AI governance remains decentralized. This lesson explains why US states have taken independent steps to regulate artificial intelligence, and how these efforts affect firms operating across multiple jurisdictions.

Why US States Regulate AI Separately

The United States does not have a federal AI law comparable to the EU AI Act. Instead, individual states have enacted or are considering legislation to address AI risks such as bias, transparency, and misuse. These laws often reflect local priorities, such as consumer protection, data privacy, or workforce impacts. For example, California’s AI Bill of Rights, passed in 2022, focuses on preventing discriminatory outcomes in AI systems used by government agencies. Meanwhile, Colorado’s AI legislation, enacted in 2023, introduces definitions and requirements for AI systems used in employment decisions. These state-specific laws create a complex regulatory environment for businesses that operate across multiple states.

  • State laws vary significantly in scope, definitions, and enforcement mechanisms
  • Each state may have different definitions of AI, high-risk systems, or transparency requirements
  • Legal frameworks often reflect local political and cultural values

Impact on Multi-State Firms

For firms operating in multiple US states, compliance with AI regulations presents practical challenges. A company using AI in hiring processes must ensure its systems meet both Colorado’s definitions of AI and California’s Bill of Rights. These frameworks may require different reporting, audit, or bias mitigation steps. For example, Colorado may require AI systems to undergo bias testing before deployment, while California may focus on public disclosure of AI usage. Firms must develop processes that accommodate these differences, often through internal governance structures or compliance teams.

This regulatory diversity compels businesses to adopt a multi-state compliance approach. Companies must identify which laws apply to their AI systems, map these requirements against existing processes, and adjust accordingly. The cost of compliance increases with each new state law, as firms must often re-evaluate or redesign AI systems to meet local standards. For example, a US-based firm using AI for clinical decision support must ensure its systems comply with both California’s data privacy laws and Colorado’s AI definitions, even if these laws do not directly overlap.

Alignment with EU AI Regulations

As US firms expand into international markets, they must also consider EU AI Act compliance. The EU framework, which applies to AI systems placed on the EU market, introduces obligations such as AI literacy, transparency, and high-risk system controls. The EU AI Act’s Article 5, prohibiting certain AI practices, became enforceable on 2 February 2025. Firms must ensure that AI systems used in EU markets meet these requirements, even if they are not yet required by US state laws. For example, a US company using generative AI must apply machine-readable marking by 2 December 2026, as required by EU AI Act Article 50, regardless of US state laws.

This dual compliance burden highlights the importance of understanding both US state laws and EU regulations. US firms must develop governance frameworks that accommodate these two distinct regulatory environments. The EU AI Act’s Article 4, which requires AI literacy, applies from 2 February 2025, and national supervision from 2 August 2026. Meanwhile, US firms must also consider the EU’s GPAI model obligations, which apply from August 2025, and Commission enforcement powers from 2 August 2026. These overlapping obligations complicate compliance planning, especially for firms using AI systems across multiple jurisdictions.

ISO/IEC 42001:2023 provides a framework for AI governance that aligns with these efforts. The standard, which became effective in 2023, offers guidance on establishing AI management systems. The first UKAS-accredited certification body, BSI, was granted certification on 15 January 2026. Firms using this standard must ensure their AI governance processes meet the requirements of both US state laws and EU regulations. The standard’s clause-based approach allows firms to map AI governance activities to specific regulatory obligations, such as those in the EU AI Act or US state laws.

In summary, US state AI laws reflect local priorities and regulatory approaches. Firms must develop strategies to comply with these laws, which often differ in scope and detail. The EU AI Act adds another layer of complexity, requiring firms to align with both US state frameworks and EU obligations. Adopting frameworks such as ISO/IEC 42001:2023 helps firms manage these diverse requirements through structured governance processes.