Research · AI Governance, Risk & Compliance
AI Regulations: EU AI Act and US State Laws
AI regulation is arriving unevenly. The EU has a comprehensive law with shifting deadlines, while the United States has a patchwork of state laws and a federal push toward preemption. This page summarizes where things stand as of September 2026.
The EU AI Act
The EU AI Act entered into force on 1 August 2024 and applies in stages. It takes a risk-based approach: certain practices are prohibited outright, high-risk AI systems face detailed requirements, some systems carry transparency obligations, and general-purpose AI model providers have their own duties. Prohibitions began applying in February 2025 and obligations for general-purpose AI models in August 2025.
In 2026 the EU adopted the “AI Omnibus,” which entered into force on 27 July 2026. According to the European Commission, it moves the start of the high-risk rules to 2 December 2027 for high-risk systems listed in Annex III (such as uses in employment, credit and essential services) and to 2 August 2028 for high-risk AI embedded in regulated products. The obligations were deferred, not removed.
United States: federal level
There is no comprehensive federal AI statute. On 11 December 2025, the President signed an executive order titled “Ensuring a National Policy Framework for Artificial Intelligence.” It aims to establish a uniform federal approach that preempts state AI laws considered inconsistent with federal policy, and it directs an AI litigation task force to challenge such laws. Existing federal laws on consumer protection, discrimination, privacy and sector regulation continue to apply to AI.
United States: state laws
- Colorado: the Colorado AI Act (SB 24-205) was delayed and then, in 2026, repealed and replaced by a narrower law focused on transparency for automated decision-making (S.B. 189). As reported by legal analysts, the new law takes effect 1 January 2027, contingent on attorney general rulemaking.
- Texas: the Texas Responsible Artificial Intelligence Governance Act (TRAIGA) took effect 1 January 2026.
- California: several AI laws took effect 1 January 2026, including the Transparency in Frontier Artificial Intelligence Act and a law on training data transparency for generative AI (AB 2013).
- Illinois: amendments to the Illinois Human Rights Act addressing discriminatory use of AI in employment took effect 1 January 2026.
- New York City: Local Law 144 requires bias audits and notices for automated employment decision tools.
What this means in practice
Deadlines and requirements are still moving, and state laws may face federal challenges. Organizations that wait for certainty risk falling behind. A practical approach is to build a governance program around an AI inventory, risk classification, documentation and testing, then map specific legal requirements onto it as they settle. This page reflects publicly reported information and is not legal advice; confirm obligations with counsel.
Questions leaders should ask
- Which jurisdictions’ AI laws apply to us based on where we operate and whom we serve?
- Which of our AI systems would be high-risk under the EU AI Act?
- Do we use AI in hiring, lending, housing, insurance or health decisions?
- Who in our organization tracks changes to AI law?