Photo by Dennis Zhang on Unsplash
What's on the Table
As of July 23, 2026, a CIO deploying a single hiring algorithm across all fifty states is effectively running two different compliance programs — one built for Colorado, one for everywhere else. That's not a hypothetical. According to TechTarget's reporting on how CIOs are navigating federal and state AI regulation uncertainty, enterprises are being forced to build governance programs against a moving target because Congress still hasn't passed comprehensive federal AI legislation. The closest thing to a federal baseline remains President Biden's October 2023 Executive Order 14110, which set AI safety standards but carries no enforcement teeth for private companies outside federal contractors.
Into that vacuum, states have rushed in. The National Conference of State Legislatures (NCSL) AI legislation tracker shows more than 25 states introduced AI-related bills in 2024 alone, with at least 7 states passing laws that require some form of transparency or impact assessment. California, Colorado, Utah, and Texas have moved the furthest, each with its own definitions of "high-risk" AI, its own disclosure triggers, and — critically — its own enforcement mechanism.
Side-by-Side: How State AI Laws Differ
Start with the rule everyone in enterprise compliance is watching: Colorado's SB 24-205, the Colorado AI Act, takes effect in February 2026 and requires algorithmic impact assessments for any high-risk AI system that affects consumers — think hiring tools, credit scoring, or insurance underwriting. California took a narrower but earlier path: AB 2013, enacted in 2024, mandates disclosure whenever an AI system makes a consequential decision about someone's employment, housing, credit, or education. In plain terms, Colorado wants companies to document and test the system before it's deployed; California wants companies to tell the affected person after a decision touches them.
The gap that matters most for a general counsel's risk memo isn't the paperwork — it's who can sue. Colorado's statute reads to create a private right of action, meaning a consumer harmed by algorithmic discrimination can bring their own lawsuit. Most other state AI laws, California's included, leave enforcement to the attorney general's office only. That's a meaningfully different liability exposure, and it's the kind of divergence that a court would likely weigh heavily when deciding where a company's compliance program actually needs to be strictest.
Chart: State AI legislative activity in 2024 — bills introduced vs. laws enacted with transparency or impact-assessment requirements. Source: NCSL AI Legislation Tracker, as of July 23, 2026.
Layered on top of the state patchwork are sector-specific federal rules that never went away: the EEOC and CFPB both increased enforcement actions against algorithmic discrimination in hiring and lending through 2024 and 2025, using existing civil rights and consumer-protection law rather than any new AI statute. Meanwhile, the EU AI Act entered into force in August 2024 with phased compliance deadlines running through 2026, which matters for any US company with European operations or European customers touched by the same model.
The AI Angle
The one document nearly everyone agrees on is voluntary: NIST's AI Risk Management Framework (AI RMF 1.0), published in January 2023, organizes AI risk into governance, mapping, measuring, and managing functions. It carries no legal force, but many enterprises are adopting it as the de facto internal standard because it maps cleanly onto what Colorado and California actually ask for on paper. This is also where legal technology is starting to earn its keep — legal software built to track shifting requirements across jurisdictions, and AI legal tools that flag when an internal system (a contract review model, a resume screener) crosses into "high-risk" territory under a given state's definition. It's worth noting this fight isn't confined to state legislatures — a divide Smart AI Trends explored in its look at how OpenAI, Meta, and Anthropic split on regulation shows the model builders themselves disagree on how much oversight AI deployment should carry, which only adds to a CIO's uncertainty about where the ground will settle.
Which Fits Your Situation
Legal experts interviewed on this pattern describe it as a repeat of privacy law in the 2010s: adopt Colorado's impact-assessment requirements and California's disclosure mandate as your company-wide baseline, even in states with no AI law at all. It's cheaper to over-comply once than to run 50 separate playbooks.
Before any AI system touching hiring, lending, housing, or education decisions goes live, have a written impact assessment, a bias-testing record, and a human-oversight checkpoint on file — not after a regulator or plaintiff's attorney asks for it.
EEOC and CFPB enforcement doesn't wait for state legislatures. If your AI touches hiring or credit decisions, existing federal civil rights and consumer-protection law already applies regardless of what your state has or hasn't passed.
Frequently Asked Questions
Do CIOs need an AI governance framework if there's no federal AI law yet?
Yes. Sector-specific federal law (EEOC, CFPB, FTC) still applies to AI-driven decisions, and at least 7 states had passed their own AI transparency or impact-assessment laws as of 2024, according to NCSL. Waiting for federal clarity leaves a company exposed on both fronts.
How does Colorado's AI Act differ from California's AI transparency law?
Colorado's SB 24-205, effective February 2026, requires proactive algorithmic impact assessments for high-risk AI systems and includes a private right of action for consumers. California's AB 2013 focuses on after-the-fact disclosure when AI makes consequential decisions about employment, housing, credit, or education, and is enforced through the attorney general rather than individual lawsuits.
Which states have passed AI transparency laws that affect enterprise AI systems?
NCSL's tracker identifies at least 7 states with laws requiring some form of AI transparency or impact assessment as of 2024, with California, Colorado, Utah, and Texas among the most active in enacting or advancing AI-specific legislation.
Bottom Line
On balance, the fragmented US approach to AI regulation looks less like a temporary gap and more like the new normal for the next several years — the Senate's AI Insight Forums produced roadmap recommendations through 2024 with no legislative action to show for it as of mid-2025, and nothing in the record since suggests Congress is close to preempting the states. The more likely outcome, in our analysis, is that Colorado's private-right-of-action model becomes the template other states copy rather than an outlier, which raises the stakes for any CIO still treating AI governance as optional.
Disclaimer: This article is for informational purposes only and does not constitute legal advice. Research based on publicly available sources current as of July 23, 2026.