AI regulation for in-house counsel in 2026 is a state-led patchwork, not a federal one. As of July 2026, the US has no comprehensive federal AI statute. The live obligations come from state laws (Illinois, Texas, California, NYC, Connecticut, and soon Colorado), with the EU AI Act reaching any company that sells into Europe. The White House wants Congress to preempt the states, but no preemption bill has passed, so every state law below still applies.
Picture the operational pain. A US GC at a Series C SaaS company with employees in Illinois and NYC, customers in Colorado, an EU sales motion, and SEC filings is answering four AI regulatory regimes at once, three of which carry per-violation civil penalties, each routing a different artifact through a different team (HR, product, finance, legal).
That stack did not exist in June 2025. The moving pieces this year: Colorado repealed and replaced its AI Act weeks before it was due to bite (new version live January 1, 2027), the EU AI Act high-risk deadline moved from August 2, 2026 to December 2, 2027 (and that delay is now final law, not a proposal), and Connecticut SB 5 phases in starting October 1, 2026.
"AI compliance" stopped being a thought-leadership topic and started being an enforcement topic. The Biden AI executive order was rescinded. The Trump administration replaced it with Executive Order 14365 on December 11, 2025 and a March 2026 National Policy Framework that asks Congress to preempt state laws outright.
Until Congress acts, the state regime governs: live statutes in Illinois, Texas, California, and NYC, with Connecticut and Colorado arriving. Every M&A diligence questionnaire I have reviewed this quarter has an AI-governance section that was not there twelve months ago. Every vendor MSA now has an AI rider or a request for one.
A useful frame: three compliance tracks. Business-use AI (Colorado, Connecticut, state consumer-protection layers). Employment AI (Illinois, NYC, Colorado high-risk, CT SB 5 employment provisions). Frontier model governance (California SB 53, EU AI Act, GPAI).
Press attention concentrates on frontier; actual enforcement risk for a non-AI-company concentrates on employment AI. That asymmetry changes where the budget should land.
TL;DR
- Four regulatory trajectories matter in 2026. The White House Executive Order 14365 and its March 2026 National Policy Framework (a preemption push, not binding law), the EU AI Act phased enforcement (high-risk obligations now moved from August 2, 2026 to December 2, 2027), state laws in CO, IL, TX, CT, CA, and NYC, and ABA Formal Opinion 512 as the bar guidance.
- The state patchwork is enforceable now. Illinois HB 3773 has been live since January 1, 2026. Texas TRAIGA (HB 149) and California SB 53 took effect the same date. NYC Local Law 144 has been enforced since 2023. Connecticut SB 5 starts phasing in October 1, 2026.
- Colorado hit reset. The original Colorado AI Act (SB 24-205) was repealed and replaced by SB 26-189 on May 14, 2026, weeks before it would have taken effect. The replacement swaps the old risk-based regime for a lighter disclosure model and is effective January 1, 2027.
- The EU high-risk delay is now final. The Parliament endorsed the Digital Omnibus on June 16, 2026 and the Council gave final green light on June 29, 2026. Standalone high-risk moves to December 2, 2027, but AI-content transparency (watermarking) is due December 2, 2026.
- The federal "moratorium" on state AI laws failed twice. The Senate stripped a proposed 10-year ban from the 2025 budget bill 99-1, and Congress omitted a second version from the 2026 defense bill. Preemption is now a litigation and legislative ask, not law.
- By Q3 2026 every law department needs five things in place. An AI inventory, a vendor diligence template, an employment-AI notice posture, an EU AI Act gap analysis if you sell into the EU, and a written governance program tied to Formal Opinion 512.
Part of our in-house counsel resource hub. For the buyer's view of the tooling, see legal AI for in-house counsel. For the program itself, see our AI governance policy template.
What happened to the original Colorado AI Act (SB 24-205)?
The federal picture: a framework, not a statute
On December 11, 2025 the president signed Executive Order 14365, "Ensuring a National Policy Framework for Artificial Intelligence." On March 20, 2026 the White House released the National Policy Framework for Artificial Intelligence, a set of legislative recommendations to Congress.
The reading across firm analyses (Holland & Knight, Sullivan & Cromwell, K&L Gates) is consistent: a request for Congress to enact preemption of state AI laws, paired with a "light-touch" approach that relies on existing sector regulators (FTC, CFPB, EEOC, FDA) instead of a new federal AI agency.
The framework is not binding law. It is political signaling about the direction Congress is being asked to legislate in. It also follows two failed attempts. In 2025 Congress tried to put a 10-year moratorium on state AI enforcement into the One Big Beautiful Bill Act, and the Senate stripped it out 99-1 (only Senator Thom Tillis voted to keep it). Congress then declined to add a similar moratorium to the 2026 National Defense Authorization Act. Preemption is now being pursued through the framework and the courts. Three pieces matter today.
First, the direction of travel is preemption of broad state AI laws while preserving "laws of general applicability" (consumer protection, civil rights, fraud). That carve-out is load-bearing: FTC Section 5, EEOC Title VII guidance, and state AG consumer-protection actions keep applying to AI-driven harms even if a preemption bill passes.
Second, EO 14365 directs the Attorney General to stand up an AI litigation task force to challenge "burdensome" state AI laws in court, and the Secretary of Commerce to publish by March 11, 2026 an evaluation of state laws that conflict with federal policy. Treat that evaluation as the canonical target list; the legislative and litigation push hangs from it.
Third, SEC enforcement on AI-washing remains active and disconnected from the framework. The January 2025 action against Presto Automation, the first AI-washing case against a public company, was followed by a 2025 exam cycle that flagged registrant AI claims as a review priority.
The pattern: companies update the "use of AI" slide in the investor deck six months before the 10-K catches up. Fix the 10-K first.
The state map: live laws, not future bills
The legislative-tracker view exaggerates the bill count. The operative 2026 reality is a smaller set of statutes already in force or arriving within six months. The ones that did not pass are noise. The ones below are the law.
Here is the 2026 state and federal AI regulation map at a glance, with the dates and enforcers that actually drive a compliance calendar.
| Law | What it covers | Effective date | Enforcer |
|---|---|---|---|
| Illinois HB 3773 | AI bias and notice in employment decisions | Live (January 1, 2026) | IL Dept. of Human Rights |
| Texas HB 149 (TRAIGA) | State-agency AI use, banned uses, AI-interaction notice | Live (January 1, 2026) | Texas Attorney General |
| California SB 53 (TFAIA) | Frontier-model transparency, incident reporting | Live (January 1, 2026) | CA Attorney General |
| California AB 853 (CAITA) | AI-content provenance and detection tools | Delayed to August 2, 2026 | CA Attorney General |
| NYC Local Law 144 | Bias audits for automated employment decision tools | Live (since July 2023) | NYC DCWP |
| Connecticut SB 5 | AI-layoff notice, chatbots, employment-AI disclosure | Phases in from October 1, 2026 | CT agencies / AG |
| Colorado SB 26-189 | Disclosure for automated decision-making technology | January 1, 2027 (replaced SB 24-205) | Colorado Attorney General |
| EU AI Act (Reg. 2024/1689) | High-risk obligations for EU-market AI systems | December 2, 2027 (moved from August 2, 2026) | EU member-state authorities |
| US federal | EO 14365, National Policy Framework, failed moratorium | No binding statute as of July 2026 | Sector regulators (FTC, EEOC, etc.) |

Each state AI regime carries its own effective date, scope, and enforcer, all live until Congress or a court acts.
Colorado: SB 24-205 repealed, SB 26-189 replaces it (effective January 1, 2027)
The Colorado story changed twice in twelve months, so the date you may have written down is wrong. The original Colorado AI Act, SB 24-205, was first scheduled for February 1, 2026, then postponed to June 30, 2026 when Governor Polis signed SB 25B-004 in August 2025.
Then, weeks before that June 30 date, Polis signed SB 26-189 ("Automated Decision-Making Technology") on May 14, 2026, which repeals the original Act and replaces it. The new law takes effect January 1, 2027, so for most of 2026 there is no operative Colorado AI obligation.
The shift in approach is the headline. The old SB 24-205 was a risk-based, EU-style regime built around "high-risk" systems and a duty of reasonable care against algorithmic discrimination. SB 26-189 is disclosure-based: deployers of automated decision-making technology that "materially influences" a consequential decision (employment, housing, lending, insurance, education, healthcare, government services) owe point-of-interaction notice and, per Morrison Foerster's and Norton Rose Fulbright's readings, a post-adverse-outcome disclosure to the consumer within 30 days. Gone are the duty of care, the impact assessments, and the risk-management program that made the 2024 version the most burdensome AI law in the country. The Colorado AG keeps enforcement authority and will write the disclosure rules by January 1, 2027.
What this means in practice: do not build a Colorado high-risk impact-assessment program in 2026. Build the lighter disclosure posture, and aim it at the January 1, 2027 effective date.
Illinois HB 3773 (effective January 1, 2026)
Illinois HB 3773 amends the Illinois Human Rights Act to prohibit employers from using AI that has a discriminatory effect on protected characteristics in recruitment, hiring, promotion, training, discharge, discipline, tenure, or terms of employment.
It also requires notice when AI is used to influence an employment decision, whether or not the use triggers liability. The Illinois Department of Human Rights is finalizing implementing rules; draft notice rules circulated in early 2026.
HB 3773 applies to "use" of AI, so a Workday or Greenhouse module that scores candidates falls inside the statute even if the employer did not build it. Vendor diligence is the load-bearing compliance step. The notice is easy; establishing that the upstream tool was audited and documented is harder.
Texas HB 149 / TRAIGA (effective January 1, 2026)
The Texas Responsible Artificial Intelligence Governance Act, signed June 22, 2025, took effect January 1, 2026. The enacted version is materially narrower than the 2024 draft.
Obligations concentrate on state-agency use of AI, prohibitions on AI for social scoring, biometric identification, and political deepfakes, and consumer notice when interacting with an AI system. Prohibited use cases carry per-violation civil penalties. If your product touches any, the diligence question is binary.
California AI laws (SB 53 live, AB 853 delayed to August 2, 2026)
Governor Newsom signed more than 20 AI bills in 2025. SB 53, the Transparency in Frontier Artificial Intelligence Act, took effect January 1, 2026. It applies to "frontier developers" of large AI models and requires a published risk framework, incident reporting, and whistleblower protections.
The one people misdate is AB 853, the California AI Transparency Act. It was pushed from January 1, 2026 to August 2, 2026. It requires generative-AI systems with over 1,000,000 monthly users to offer a free AI-detection tool, and it layers a provenance-detection duty on "large online platforms" (over two million monthly users) starting January 1, 2027. Enforcement runs through the California AG at $5,000 per violation. California reads as a transparency-and-disclosure regime rather than a Colorado-style risk-management mandate.
NYC Local Law 144 (in force since July 2023)
NYC Local Law 144 has been enforced since July 5, 2023. Employers using an "automated employment decision tool" (AEDT) on candidates or employees residing in NYC must conduct an independent bias audit within one year of use, publish the results, and notify candidates.
The New York State Comptroller's December 2025 audit found the DCWP enforcement program "ineffective," which raised the political temperature, not lowered it. Treat the bias audit as a recurring annual workflow.
Connecticut SB 5 (phasing in from October 1, 2026)
Connecticut's SB 5 (a successor to the 2025 SB 2, which died after a veto threat) passed the Senate on April 21, 2026 and the House on May 1, 2026. Governor Lamont signed the 39-section bill into law in late May 2026.
It does not take effect all at once. AI-related layoff notice and frontier-model whistleblower protections start October 1, 2026; companion-chatbot and frontier-developer reporting from January 1, 2027; broader employment-AI disclosure from October 1, 2027; social-media safeguards from January 1, 2028.
The employment piece is the one most companies will touch first. Employers issuing plant-closing or mass-layoff notices have to disclose to the state Labor Department whether the layoffs relate to the employer's use of AI. Add that to the same HR-AI file you keep for Illinois and NYC.
The EU AI Act: extraterritorial reach, and a high-risk deadline that finally moved
Regulation (EU) 2024/1689 phases in across several dates. Article 5 (prohibited practices) has applied since February 2, 2025. Chapter V (general-purpose AI models) since August 2, 2025. Most of the rest, including standalone high-risk obligations, was set for August 2, 2026.
That date moved, and this time it is final, not a rumor. The Council and Parliament reached political agreement on May 7, 2026 on a "Digital Omnibus" package. The Parliament endorsed it on June 16, 2026, and the Council gave final green light on June 29, 2026. Standalone (Annex III) high-risk obligations now apply from December 2, 2027, and product-embedded (Annex I) obligations from August 2, 2028, per the same package analyzed by Gibson Dunn and Morgan Lewis.
The omnibus also added a new Article 5 prohibition on AI "nudifier" tools and non-consensual intimate imagery, so the prohibited-practices list is now longer, not shorter.
The undercounted piece: GDPR-style extraterritorial reach. The act applies to providers placing AI systems on the EU market regardless of where the provider is established, and to deployers whose output is used in the EU. Fines top out at 35 million euros or 7% of global turnover for prohibited-practice violations, and 15 million euros or 3% for high-risk non-compliance.
If your company sells a SaaS product into the EU with an AI feature, the exposure is real even without a European office. The near-term Q3 work is unglamorous: confirm no feature falls under Article 5, and map any AI-generated output to the December 2, 2026 transparency duty. The heavier high-risk gap analysis against Articles 9-15 (risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy) can now sequence toward the 2027 date. US companies typically satisfy these obligations through an authorized representative in the EU.
Across the three tracks: business-use AI is the hardest to evidence in diligence (the artifact crosses three departments); employment AI is the easiest to evidence and the highest enforcement probability; frontier-model governance is the highest theoretical fine and the lowest probability for a non-developer.
The ABA Formal Opinion 512 baseline
For the lawyers in your department, the regulatory question is narrower. ABA Formal Opinion 512, issued July 29, 2024, remains the only national bar guidance on lawyer use of generative AI. California, New York, Florida, and DC have layered on with their own opinions, none of which contradict the ABA framework.
The five obligations are the spine of any law-department AI program:
- Competence (Rule 1.1): understand the capabilities and limitations of the AI tools you use.
- Confidentiality (Rule 1.6): evaluate the data-handling posture of any tool before inputting client information. If you have never checked, start with whether ChatGPT is confidential for legal work.
- Communication (Rule 1.4): inform clients of material uses of AI, especially where the use bears on the work product or fee.
- Candor toward the tribunal (Rule 3.3): verify AI-generated citations and content before filing. The cost of getting this wrong is the Mata v. Avianca sanctions order from 2023.
- Reasonable fees (Rule 1.5): no billing for time learning a general AI tool, pass through tool costs only with informed consent, adjust billing where AI compresses the work.
The conflation I keep seeing: a single "AI policy" memo that purports to cover both the lawyers' use of AI (Opinion 512) and the company's use of AI for business decisions (the state regimes above). Those are two policies, with different owners, scopes, and audit trails.
What AI regulation for in-house counsel actually requires by Q3 2026
Start by answering one question: which regimes even touch you? Most lean teams over-scope, then freeze. The decision is simpler than the tracker makes it look.
Once you know the map, five things, in priority order.
1. An AI inventory. Every AI-enabled tool deployed or being procured, tagged by business unit, vendor, data flows, and consequential-decision exposure. One document, owned by a named compliance officer, refreshed quarterly. It surfaces the Colorado disclosure classification, the Illinois employment-notice question, and the EU AI Act gap analysis at the same time. Most law departments do not have one; the ones that do can answer a regulator's first three questions in five minutes.
2. A vendor diligence template with AI-specific clauses. Bias-audit deliverables for AEDTs, training-data provenance reps for generative-AI vendors, EU AI Act conformity-assessment reps for high-risk providers, and a Formal Opinion 512 information-security baseline for vendors handling client-confidential data. Negotiate it once at the contract level; the alternative is chasing it tool-by-tool after an enforcement letter.

A standing vendor questionnaire turns AI due diligence into a repeatable procurement step instead of a fire drill.
3. An employment-AI notice and audit posture. The real trap. Notice rules look procedural and get deprioritized for that reason. Overlapping statutes (Illinois HB 3773, NYC Local Law 144, Connecticut SB 5, and Colorado SB 26-189 from 2027) hit the same surface: every HR-tech vendor that scores, ranks, or filters candidates. The artifact to produce on demand is a per-tool file: the vendor's most recent bias audit, the notice text shown to candidates in each jurisdiction, deployment dates by jurisdiction, and sign-off from the HR business partner. If you cannot produce that file inside 48 hours of a regulator's letter, you are exposed.
4. An EU AI Act gap analysis (if applicable). First screen for Article 5 prohibited uses and the December 2, 2026 transparency duty, which are the near-term items. Then classify each AI feature shipping into the EU under Annex III and gap-analyze against Articles 9-15 toward the December 2, 2027 high-risk date. The framework is straightforward; the documentation is the work, and the documentation is what an EU authorized representative will ask for.
5. A written AI governance program tied to Formal Opinion 512. Not a memo, a program. Named owner, quarterly review cadence, approved-tools list, prohibited-inputs list, incident-reporting channel, training requirement, annual sign-off from each practice-group lead. The regulator's first question is not "do you have a policy" but "produce the artifacts the policy says you produce."
One more thing on the federal fight: preemption is politically loud and operationally irrelevant to your 2026 program. The 2025 moratorium died 99-1, a second version was left out of the 2026 defense bill, no preemption vehicle has cleared committee as of July 2026, and any bill that does pass will almost certainly preserve "laws of general applicability," so EEOC, FTC, and state AG enforcement tools survive regardless.
Pausing AI governance work to wait for preemption trades unmanaged enforcement exposure for a hypothetical statute you will still have to comply with under the surviving carve-outs. Build the program now.
FAQ
Is there a federal AI law in the United States in 2026? No. As of July 2026 there is no comprehensive federal AI statute. Federal oversight runs through existing agencies (FTC, EEOC, CFPB, FDA), Executive Order 14365, and a March 2026 National Policy Framework, which is a set of legislative recommendations, not binding law.
Did the federal moratorium on state AI laws pass? No, twice. The Senate stripped a proposed 10-year moratorium from the 2025 budget bill 99-1, and Congress omitted a similar provision from the 2026 defense bill. Preemption is now pursued through the White House framework and an AG litigation task force, but no preemption statute has become law.
What happened to the Colorado AI Act? Colorado repealed and replaced the original AI Act (SB 24-205) before it ever took effect. Governor Polis signed SB 26-189 on May 14, 2026. The replacement drops the risk-based duty of care for a disclosure model, effective January 1, 2027.
Which state AI laws are in effect right now? Illinois HB 3773, Texas HB 149 (TRAIGA), and California SB 53 all took effect January 1, 2026. NYC Local Law 144 has been enforced since 2023. California AB 853 was delayed to August 2, 2026, Connecticut SB 5 begins phasing in October 1, 2026, and Colorado's new law arrives January 1, 2027.
When does the EU AI Act apply to high-risk systems? The high-risk obligations moved from August 2, 2026 to December 2, 2027 for standalone systems, and to August 2, 2028 for product-embedded systems. That delay was finalized when the Council gave final green light on June 29, 2026. Prohibited-use rules already apply, and AI-content transparency is due December 2, 2026.
Does the EU AI Act apply to US companies? Yes, if you place an AI system on the EU market or your AI output is used in the EU, regardless of where you are established. Fines reach up to 35 million euros or 7% of global turnover for prohibited-practice violations.
What is the difference between the state AI laws and ABA Formal Opinion 512? They govern different things. The state laws regulate a company's use of AI in business decisions (hiring, lending, consequential decisions). ABA Formal Opinion 512 governs a lawyer's professional use of generative AI under the Rules of Professional Conduct. They need two separate policies.
What should an in-house legal team have in place by Q3 2026? Five things: an AI inventory, a vendor diligence template with AI clauses, an employment-AI notice and audit posture, an EU AI Act gap analysis if you sell into the EU, and a written governance program tied to Formal Opinion 512.
Build the AI governance program now
The 2026 takeaway is unglamorous: the state patchwork is the law you comply with today, and waiting on a federal preemption bill that may never pass only grows your exposure. Stand up the AI inventory, the vendor template, and the governance program, and keep a dated source next to every effective date because these dates keep moving.
We build Vaquill AI, a legal AI suite for in-house teams, and the compliance-check workflow maps the five Q3 items above to specific artifacts and review cadences. See how the compliance check works, or start with our AI governance policy template and the ABA Formal Opinion 512 guide.
This post is general information, not legal advice. Confirm every effective date against the primary source before you build to it.
New legal AI guides, weekly.
Further Reading
AI Governance Policy for In-House Legal Teams: A 2026 Template
Read postUS State Privacy Laws in 2026: The In-House Compliance Baseline
Read postAI in Legal Practice: State-by-State Regulation and Bar Guidance (2026)
Read postAI Compliance Check: CCPA, GDPR, and SOX for In-House Teams (2026)
Read postGenerative AI for Legal: An In-House Counsel's Guide (2026)
Read postDamien Charlotin's Hallucination Tracker, Read Like a Risk Manager
Read post
Co-Founder & CEO · Attorney
Arshita leads product and strategy at Vaquill, building the legal AI suite that solo, small-firm, and in-house US lawyers use to run a matter end to end.