The United States finds itself in a unique position: the federal government has yet to produce a comprehensive AI regulatory bill, but the states are not waiting.
As of March 2026, 45 state legislatures have introduced 1,561 AI-related bills—and that is just for this year. The scope ranges from algorithmic discrimination to deepfakes to healthcare claims processing.
What the Federal Side Is Doing
No new laws, but federal agencies are using existing legal frameworks to address AI issues:
The FTC is using Section 5 (unfair competition law) to target advertisements that exaggerate AI capabilities and products that fail to disclose AI use. False claims about AI features or passing off AI-generated content as human-made—these are all on the FTC's radar.
The SEC is specifically going after "AI washing." Public companies that claim extensive AI use in earnings reports or investor presentations, when that is not the case or the results fall far short of what was claimed—the SEC has begun seriously pursuing such cases this year.
The DOJ is using the False Claims Act to target inflated AI-related statements in government procurement contracts, particularly sensitive in federal healthcare programs and defense contracts.
Antitrust authorities are watching algorithmic pricing and data sharing, especially a model known as "hub-and-spoke conspiracy": an AI supplier acts as the hub, and multiple competitors exchange pricing information through it to achieve tacit coordination.
The White House issued an AI action plan last July with a tone of "promote innovation, light regulation." In December 2025, President Trump signed an executive order to establish a unified federal AI policy framework and specifically created the DOJ AI Litigation Task Force (operational since January 10, 2026), aiming to challenge state laws in court that are deemed to conflict with federal policy.
But an executive order itself has no legislative force—to truly override state laws, either Congress must pass new legislation or a court must rule. Until then, existing state laws remain in effect, and businesses still face multi-jurisdictional compliance.
State-Level Actions
California, Colorado, New York, and Texas are the leading players.
California's TFAIA (Transparency in Frontier AI Act) and Texas's RAIGA (Responsible AI Governance Act) both took effect on January 1 this year, targeting transparency disclosures for frontier models and governance frameworks for high-risk AI systems, respectively. Colorado's AI Act is currently the most comprehensive among the states, with full enforcement beginning in 2026.
New York has enacted algorithmic pricing disclosure requirements: if you use algorithms to set prices, you must inform consumers.
Indiana, Utah, and Washington State have all passed laws this year regulating AI use in healthcare claims processing: insurers cannot use AI systems as the "sole basis" for denying or modifying claims—a human review step is required.
State attorneys general also have a powerful tool at their disposal: UDAP statutes (Unfair and Deceptive Acts and Practices laws). These laws levy fines per violation without requiring proof of individual harm, making the enforcement threshold much lower than federal tools, and the cumulative fines can be substantial.
A Comparison with the EU
The contrast is clearer when compared side by side. The EU AI Act enters full enforcement in 2026, with the European AI Office beginning audits and issuing fines, which can reach up to 7% of annual global revenue. There is a unified framework, a clear enforcement body, and a well-defined risk classification.
The US currently lacks a unified mechanism of this scale. While the cumulative UDAP fines across 50 states can add up significantly, the consistency and predictability of enforcement are vastly different. What is a violation in California might be fine in Texas, and a different logic applies at the federal level.
Compliance Challenges for Businesses
For AI companies operating in multiple US states, the current situation is:
- No single set of federal rules to follow
- 50 states each with their own bills, some with directly conflicting provisions
- Legal battles between federal and state authorities are ongoing, with the final landscape uncertain
- The DOJ Litigation Task Force has begun operations, but the outcome may need to be settled by the Supreme Court
A report published in April by legal consultancy Morgan Lewis identified four main risk areas for businesses: data privacy governance gaps, securities disclosure vulnerabilities, false claims risks in government contracts, and cross-state coordinated enforcement.
Their advice is pragmatic: build cross-functional compliance teams, make transparency disclosures, avoid sharing competitively sensitive pricing data with AI vendors, and continuously track state legislative developments.
How Long Will This Landscape Last?
If Congress does pass a federal AI bill, it could consolidate the current fragmented landscape. But federal legislative efficiency in the US is well understood—it took the EU over three years from discussion to enforcement, and the US has not even formally advanced a draft bill.
What is more likely is that the DOJ's AI Litigation Task Force will pursue a few landmark cases, a specific conflict will reach the Supreme Court, and a court ruling will ultimately clarify the boundaries between federal and state authority. Until then, US AI regulation will remain as it is—decentralized, fragmented, and still being fought out in courtrooms.
For companies entering the US market, the practical implication of this situation is: you must consider the specific regulations of your target states, not just the federal level. California's requirements and Texas's requirements can differ significantly, and both are evolving.
Sources: AI Enforcement Accelerates as Federal Policy Stalls and States Step In (Morgan Lewis); U.S. Tech Legislative & Regulatory Update – First Quarter 2026 (Global Policy Watch); Proposed State AI Law Update: April 6, CocoLoop, 2026 (JDSupra)