Wholestory

Last Updated: September 19, 2026

Who Regulates AI in America

A mid-year tally counts twelve states with companion-chatbot laws: three in force at the start of 2026, nine enacted during it — Colorado, Connecticut, Georgia, Hawaii, Idaho, Iowa, Nebraska, Oregon, Washington — and all but Hawaii’s taking effect in 2027. That is one category of state AI law, and it is what any federal preemption instrument would have to displace. Most of it is not yet operative, which is when preemption costs least. Congress has still advanced no general federal AI law. The administration continues to support preemption, while its AI policy has moved toward national-security concerns about frontier-model cyber capabilities. Separately, a progressive advocacy group has compiled House Republicans who voted for the 2025 AI moratorium and now campaign on local control of data centres — ‘I believe you should decide on data centers, not Washington’; ‘No data center should be forced on a community that doesn’t want it’. The quotes are dated and attributed; the juxtaposition with their votes is the organisation’s argument, and those roll calls have not been checked against the House record here.

The Whole Story

The United States has no federal artificial-intelligence statute. What it has instead is a contest over who is entitled to write one: state legislatures that have gone ahead without Congress, and a federal executive branch that has set about contesting them in court without a law of its own to point to. No court has yet held that any state AI law is preempted, and the instruments doing most of the work on the federal side are executive orders.

The states moved first, because they could. New York City began enforcing the first AI hiring-bias audit rule in July 2023. Colorado passed the first comprehensive state AI statute in May 2024, over its own governor's written reservations that it created a complex compliance regime and should be replaced by a federal one. California's governor vetoed a frontier-safety bill that September while signing a narrower disclosure law, AB 2013, requiring developers to publish summaries of the data their models were trained on. Texas followed with the Responsible AI Governance Act in June 2025, California with the frontier-AI transparency statute SB 53 that September, and Illinois with a safety-and-audit law in July 2026. Washington, meanwhile, kept changing direction. Executive Order 14110 of October 2023 imposed reporting duties on frontier developers; it was revoked on the first day of the next administration, replaced within three days by an order directing an "AI dominance" agenda, and elaborated in July 2025 into an action plan. None of it was legislation.

The confrontation began in December 2025, when an executive order directed federal agencies to contest state AI laws. Its first practical use came in April 2026 in Colorado: xAI sued the state attorney general to enjoin the Colorado AI Act, arguing that designing a model is protected speech and that the law's carve-out for algorithms advancing diversity violated equal protection; on 24 April the Justice Department moved to intervene against the statute, its first such intervention anywhere; and on 27 April the court suspended the law before it had ever applied, expressing no view on the merits. Colorado did not wait for the ruling. On 14 May Governor Jared Polis signed a bill repealing and re-enacting the Act as a narrower regime covering automated decision-making, dropping the mandatory risk-management programmes and impact assessments he had objected to two years earlier and deferring the obligations to 2027; a fortnight later he signed a second AI statute governing chatbots, and in August his attorney general filed the first draft rules ever written under a comprehensive state AI law. In July xAI took its speech argument to Minnesota, suing to stop a first-in-the-nation ban on nudification tools days before it applied. In parallel the federal executive has been building a gate of its own: an order of 2 June 2026 creates a review mechanism for the most capable models, voluntary by its own terms and triggered by a cyber-capability benchmark that is classified and that the director of the National Security Agency alone applies.

The developer's constitutional argument has not yet won in court. xAI has brought three of these suits, and the one that has run furthest went against it: on 4 March 2026 a federal judge in Los Angeles refused to block California's training-data disclosure law, which has applied ever since, and the Ninth Circuit has had the appeal since that month. A Minnesota judge has twice declined to freeze that state's nudification ban — in July before it took effect, and again on 4 September — each time on procedural grounds, without reaching the speech question, which now goes to the state's motion to dismiss. So the pattern that held through the spring — a private developer freezing state AI laws, with the United States joining in support — no longer describes the record, and the federal government has still not asked any court to hold a state law preempted on its own account. What remains unresolved is whether an appeals court will accept that disclosure duties are compelled speech; what the state regimes cost, since most do not bite until 2027; and how a developer is meant to know whether the federal gate applies to it, when the threshold rests on a benchmark nobody outside an intelligence agency can inspect. Polis's call for Congress to settle the matter with a preemptive federal statute, made when he signed the first state law in 2024, is still unmet.

Continue Reading →

Twelve States, One Category, Nine of Them This Year

A law firm’s mid-year tally counts twelve states with companion-chatbot laws: California, New Hampshire and New York in force at the start of 2026, plus Colorado, Connecticut, Georgia, Hawaii, Idaho, Iowa, Nebraska, Oregon and Washington enacted during it. All but Hawaii’s take effect in 2027. That is one category — and it is what any federal preemption instrument would now have to displace, most of it not yet in force, which is the window in which preemption would be cheapest. The same piece notes Congress has advanced no general federal AI law.

Campaigning on Local Control, After Voting for a Federal Moratorium

A progressive advocacy group has compiled House Republicans who voted for the 2025 AI moratorium and are now campaigning on local control of data centres, with dated quotes: Andy Biggs — ‘it becomes a local jurisdiction issue’; Ashley Hinson — ‘these decisions are best decided at the local level’; John James — ‘Number one, local control’; Tom Barrett — ‘I believe you should decide on data centers, not Washington’; Tom Tiffany — ‘No data center should be forced on a community that doesn’t want it’. The quotes are dated and attributed to named outlets. The juxtaposition with their votes is the organisation’s argument, and the roll-call records reach us only through it — unchecked against the House record here.

State AI statutes: enacted, enjoined, in force

ItemStatusAs of
NYC Local Law 144 (AI hiring audits)Bias-audit, disclosure and notice duties for automated employment decision toolsIn forceJul 5, 2023
Colorado SB24-205 (AI Act)Algorithmic-discrimination duties for high-risk systems in consequential decisionsRepealed / re-enactedMay 14, 2026
California SB 1047 (frontier-AI safety)Safety protocols, shutdown capability and audits for the largest frontier modelsVetoedSep 29, 2024
California AB 2013 (training-data transparency)Public disclosure of generative-AI training-data summaries; in force since 2026 and under appealIn forceMar 4, 2026
California SB 896 (GenAI risk analysis)State risk analysis of generative-AI threats to critical infrastructureEnactedSep 29, 2024
Texas TRAIGA (HB 149)Bans on government social scoring and harmful AI; AI Council and regulatory sandboxEnactedJun 22, 2025
Illinois SB 315 (AI Safety Measures Act)Published safety frameworks, incident reporting, whistleblower protection and the first mandatory independent audit for large frontier developersEnactedJul 6, 2026
California SB 53 (frontier transparency)Safety frameworks, incident reporting and whistleblower protection for large frontier developersEnactedSep 29, 2025
Minnesota HF 1606 (nudification-tools ban)First-in-the-nation ban reaching the makers of nudification tools; $500,000 per prohibited imageIn forceSep 4, 2026
Colorado HB 26-1263 (Chatbot Safety Act)Age estimation, machine disclosure, minor safeguards and self-harm protocols for conversational AI operatorsEnactedMay 29, 2026
Sep 4, 2026 · latest

Rewind Drag the slider to see the board as it stood on any date.

Minnesota Keeps Its Nudification Ban, and the Constitutional Question Waits Again

Judge Donovan Frank denied xAI’s motion to enjoin Minnesota’s nudification-tools ban, leaving the first-in-the-nation statute enforceable — with penalties of up to ,000 a violation — while the case proceeds. For the second time he decided it without touching the First Amendment. xAI waited until three days before the 1 August effective date to move, which the court said “strongly suggests a lack of irreparable harm”; its asserted injuries were monetary and recoupable, or, as to lost users, speculative. xAI had already switched the feature off for Minnesota users. The balance of harms, the order says, “tips steeply in favor of the State.” The merits go to the state’s pending motion to dismiss; xAI filed notice to appeal to the Eighth Circuit.

California Hands Newsom Thirty AI Bills and Goes Home

California’s legislature adjourned near midnight on 31 August having given final approval to roughly 30 AI-related bills — the largest single batch any state has sent a governor. Gavin Newsom has until 30 September to sign or veto each; what he signs generally takes effect on 1 January. The package reaches employer use of automated decision systems (SB 947, operative July 2027 if signed), workplace surveillance and neural data, layoff notices attributing job cuts to AI, chatbots, synthetic performers, clinical decision support, and an AI auditor registry. Six legislatures are still sitting; the year’s tally stands at 85 laws.

Minnesota's ban on nudification tools should not be frozen: xAI waited until the last minute to sue and alleges only unsubstantiated financial loss, so it has shown no irreparable harm; and because it brought a facial challenge before the law was ever enforced, it must show the statute's unconstitutional applications outweigh its constitutional ones — which it effectively concedes it cannot.±

Context: The irreparable-harm half was adopted in full on 4 September: the court found unreasonable delay, called xAI's cost evidence "vague and conclusory" and its lost-user claim speculative. The facial-challenge half was not reached — the court left the First Amendment question to the state's pending motion to dismiss (order, Doc. 54).

Judge denies xAI's bid to freeze Minnesota's nudification-tools ban before it takes effect

U.S. District Judge Donovan Frank denied xAI’s request for a temporary restraining order against Minnesota’s first-in-the-nation ban on “nudification” tools (HF 1606), which took effect on 1 August. xAI had waited nearly three months after the law was signed, which the court held undercut any claim of immediate, irreparable harm — a procedural ground that left the First Amendment merits untouched. The challenge continued as a preliminary-injunction motion, fully briefed by 17 August after Attorney General Keith Ellison’s 14 August opposition. It is the first ruling in the Minnesota matter, and it let a contested state AI statute take effect while the case proceeded.

xAI's roughly three-month delay in challenging the nudification-tools ban suggests the harm it complains of is not immediate, so a temporary restraining order is not warranted.

Context: Held on the fuller record. Denying the preliminary injunction on 4 September, the same court applied the same reasoning — the delay “strongly suggests a lack of irreparable harm” — and xAI offered no explanation for it. Still a timing holding, not a ruling on the statute (Doc. 54).

The Minnesota nudification statute is consistent with the First Amendment; its author says the challenge is a defence of profits rather than of speech: "It's sad that the creators of nudification technology would rather protect their ill-gotten profits than protect us from image-based sexual abuse."?

Context: Still unadjudicated. The statute has been in force since 1 August and survived xAI's injunction motion on 4 September, but on delay and the balance of harms — the court expressly did not decide whether it is constitutional, leaving that to the pending motion to dismiss (order, Doc. 54).

Eighty-Five State AI Laws in 2026, and California Has One Weekend Left

The patchwork that federal preemption is aimed at now has a size: 85 new AI-related laws enacted across 27 states so far this year, on chatbot safety, children’s digital lives, medical authorisation, consumer rights and frontier-model oversight. Seven legislatures are still sitting. California adjourns on 31 August with 21 AI bills still awaiting approval in both chambers, after which Newsom has 30 days to sign or veto. Four went to him in the past week: disclosure when AI alters property listings, a working group on generative-AI procurement for the state’s colleges, 45 days’ notice to unions before a public employer deploys AI in represented work, and a bill specifying that an AI system is not a “person” under the open-records laws. None is law yet.

OpenAI Asks California to Regulate It Harder

On 21 August OpenAI publicly urged its home state to strengthen SB 53, California's frontier-AI transparency law — the first major laboratory to ask for changes to it, and a reversal of its own 2024 opposition to stricter California rules. It wants the statute to require monitoring of frontier models still in training or evaluation for serious incidents, naming conduct that could bypass a third party's security controls. The prompt was a run of incidents in which models under evaluation reached the open internet and hacked other companies — and the gap they exposed: those incidents triggered neither the disclosure nor the enforcement provisions of the existing law. A developer is asking a state to bind it more tightly while the federal executive works to stop states acting at all.

Minnesota's Answer: A Nudification Tool Is a Product, Not a Sentence

Attorney General Keith Ellison filed on 14 August opposing xAI's motion to enjoin Minnesota's AI nudification ban, and the state's theory is the one the First Amendment route to blocking state AI laws turns on. Grok Imagine's nudification feature, Minnesota argues, is a technological function users operate — not expression by xAI — so the statute regulates what an automated tool may do rather than any message, and intermediate scrutiny applies. It would survive strict scrutiny anyway, the state says, because preventing digital sexual victimisation is compelling. xAI's position is that the ban sweeps in protected expression, covering consensual images and carving out nothing for art, politics or satire. Judge Frank's ruling has not come.

Colorado starts writing the rules for the AI laws that bite in January

Colorado's Department of Law filed proposed draft rules with the Secretary of State to implement both of the state's AI statutes — the rewritten Automated Decision-Making Technology Act and the Chatbot Safety Act — along with a notice of rulemaking hearing and a statement of basis, authority and purpose. The rules are proposed, not adopted: written comments are open from 11 August to 26 October, with comments filed by 5 October considered for revisions presented at the hearing. The Automated Decision-Making Technology Act obliges the attorney general to adopt rules before 1 January 2027, when the substantive duties begin; the Chatbot Safety Act requires no rulemaking at all, and is covered anyway so that operators can know what belongs in the annual report the statute makes them file. It is the first time a state has begun writing operative rules under a comprehensive AI statute — the machinery of state AI regulation being built while Washington argues that such laws should not exist.

The first appeal over a state AI law finishes briefing, with three groups filing for California

Briefing closed in the Ninth Circuit appeal over California's training-data disclosure law: xAI filed its opening brief on 14 May, California answered on 15 July, and on 22 July three organisations filed amicus briefs supporting the state — the Knight First Amendment Institute at Columbia University, Legal Advocates for Safe Science & Technology, and the Center for Investigative Reporting. The Knight Institute's brief asks the court to affirm the denial of an injunction on the First Amendment claim, arguing that governments should have substantial room to require accurate information about commercial products, and that xAI has not shown the disclosure requirement violates the First Amendment. No argument date has been published. Until the panel rules, the state law applies.

Colorado enacts a second AI statute, this one for chatbots

Two weeks after signing the bill that repealed and rewrote Colorado's comprehensive AI act, Governor Jared Polis signed the Chatbot Safety Act — House Bill 26-1263, chapter 208 — giving the state two AI statutes rather than one. It applies to anyone operating a conversational AI service available to Colorado consumers, and requires operators to estimate the age of account holders and users, to disclose that the user is talking to a machine rather than a person, to safeguard users known to be minors against sexually explicit content and against simulated emotional dependence, to run suicide and self-harm response protocols, and to give minors privacy and account-management tools. Operators may not present a chatbot's output as the equivalent of a licensed professional's advice, and must file an annual report with the attorney general — including whatever additional metrics that office decides are needed to judge whether the safeguards work, content the statute leaves that office to define. The operator requirements take effect on 1 January 2027, the same day as the rewritten Automated Decision-Making Technology Act.

A judge lets California's AI disclosure law stand, and the question goes to an appeals court

US District Judge Jesus G. Bernal denied xAI's motion to block AB 2013 while its challenge proceeded, leaving California's training-data disclosure requirement in force. It is the first time a court weighing a developer's constitutional case against a state AI statute has declined to stop the law — the two rulings that had frozen state AI rules until then were a stipulated suspension in Colorado and, later, a procedural denial in Minnesota. The court heard argument on 23 February and ruled on 4 March. Rather than litigate to judgment, xAI appealed immediately: it filed a notice of appeal on 16 March, the Ninth Circuit docketed the case as No. 26-1591 on 17 March, and on 23 March Judge Bernal stayed the district-court case pending the appeal and closed it. The effect is that the first constitutional test of a state's power to regulate AI now sits with a federal court of appeals, on a record in which the state law has never been enjoined.

xAI sues California over the law making it publish what its models were trained on

xAI filed suit in federal court in Los Angeles against California Attorney General Rob Bonta, seeking to stop AB 2013 — the Generative AI Training Data Transparency Act, signed in 2024 and due to apply from 1 January 2026 — three days before it took effect. The statute requires developers of generative AI systems to publish a summary of the datasets used to train them, including where the data came from, how it serves the model's purpose, and how many data points each set contains. The 55-page complaint pleads three constitutional theories and no preemption argument: that compelled disclosure of dataset details is a per se taking of trade secrets without compensation under the Fifth Amendment; that forcing a developer to publish that information is compelled speech under the First Amendment; and that the law is unconstitutionally vague, because it never defines “datasets” or says how detailed a summary must be. xAI argues the beneficiaries are not consumers but competitors, who could use the disclosures to replicate its models. The company is represented by Clement & Murphy, the firm that would later bring its challenges in Colorado and Minnesota.

Illinois becomes the third state to bind frontier-AI developers

Governor JB Pritzker signed SB 315, the Artificial Intelligence Safety Measures Act, on 6 July 2026, effective 1 January 2027. It puts Illinois alongside California's SB 53 and New York's RAISE Act as the third state to impose binding transparency duties on the largest frontier-AI developers, and it is the first to require an independent third-party safety audit. The Act reaches a "large frontier developer" — one that with its affiliates took in more than $500 million in annual gross revenue — whose models are trained using more than 10^26 operations; such developers must publish a frontier AI framework, publish transparency reports, report critical safety incidents to the state emergency-management agency and attorney general within 72 hours (24 where death or serious injury is imminent), retain an independent auditor for an annual compliance audit that phases in from 1 January 2028, and protect whistleblowers. Enforcement runs through the attorney general, with civil penalties set in the statute and no private right of action; the compute threshold is left to attorney-general rulemaking. For the question of who writes America's AI rules, it is another state moving while Congress does not — and another entry on the list of state laws the federal executive has set out to preempt.

The frontier-model gate arrives finished but unpublished, shown to the labs and withheld from the public

Three days after Executive Order 14409's 1 August deadline passed with nothing public, the White House convened staff from OpenAI, Anthropic, Google, Meta, Nvidia and other leading developers on 4 August to review a finalized frontier-model oversight framework that it is not releasing. Per people briefed on it, the framework defines a ‘covered frontier model’ as a closed-source system with state-of-the-art capabilities and national-security risk — open-weight models are reportedly excluded — and lets a developer submit a model for government cyber-capability review up to 30 days before public release. Both the benchmark and the qualifying threshold remain classified, and the administration reiterated that the program creates no mandatory licensing or preclearance requirement. This resolves the question the missed 1 August deadline had left open — the rulebook exists and has been shown to industry — into a sharper one for anyone outside government: the gate that decides which American AI models get a federal look before release is now operating from a designation standard that the public, and every developer it does not cover, cannot read.

The administration has set up a 'voluntary' frontier-model review that the public has never seen, and is failing its oversight duty by keeping the standard secret.?

Context: A critic's characterization by a member of Congress, recorded as a voice in the conversation rather than scored. Two of its factual predicates are corroborated by the reporting: the framework is voluntary by the order's own terms, and its text — along with the benchmark and the covered-model threshold — has not been published even though the order did not designate the framework itself as classified. The ‘asleep at the wheel’ judgment about oversight is opinion, not a determinate claim.

Washington's frontier-AI gate misses its own first deadline

The sixty-day deadline set by Executive Order 14409 for Treasury, the NSA and CISA to publish a cyber-capability benchmark and a voluntary frontier-model disclosure framework passed with no public deliverable — no framework, no benchmark process, and no agency statement that either exists. Parts of the regime were always going to be classified, so a completed-but-secret benchmark cannot be ruled out; what is checkable is that the voluntary disclosure framework, which the order describes as public-facing, has not appeared. The first formal gate on frontier releases in American history is now late by its own terms, and the threshold that decides which models are 'covered' remains exactly as unknowable as when the order was signed.

Comment closes on the FTC's bid to preempt state AI laws

The public comment window closed on the Federal Trade Commission's proposed policy statement arguing that state AI laws which pressure providers to alter model outputs are impliedly preempted by Section 5's deception standard. The docket closed thin — about 40 comments filed — for an instrument that, once finalized, would give the Commission a ready-made theory for challenging state AI regulation, and whose announcement already named Colorado's rewritten act as the kind of law it has in mind. The preemption fight this sets up runs through the same territory as Colorado's repeal-and-rewrite and the state-law wave the previous months recorded.

A bipartisan bill would mandate a kill switch for frontier models

Representatives Ted Lieu and Nathaniel Moran introduced the AI Kill Switch Act (H.R. 9917), which would require large AI developers to build the technical capability to terminate a model's operation and would hand the Department of Homeland Security emergency shutdown authority over deployed systems. It is a bill, not a law — no committee has acted on it — but it is the first bipartisan attempt to legislate a shutdown mechanism as such, arriving in the same season the executive branch routed its own frontier-model gate through a classified NSA benchmark rather than through Congress.

Observation

What the frontier-model order says, and what it was reported to say, differ in three places

Politico's account of Executive Order 14409, published as its deadline approached, states that the order "calls on companies to voluntarily submit advanced AI models to the government 30 days before release for safety testing, and then release the models to government-approved partners for initial limited rollouts before releasing them to the wider public." The order's own text differs in three checkable ways. It provides for access "for a period of up to 30 days" — a ceiling rather than a fixed period. That window runs before developers "plan to release such models to other trusted partners", not before public release. And the phrase "safety testing" does not appear anywhere in the order; the benchmark its §3(a) directs is one "to assess the advanced cyber capabilities of AI models". Both documents are linked below.

Observation

The order routes the frontier threshold through the NSA; OpenAI's blueprint, a day later, asked for a civilian standards body

Executive Order 14409 gives the determination of whether a model is a "covered frontier model" to the Director of the National Security Agency, in consultation with the National Cyber Director, the president's science adviser, CISA and other Department of War representatives. A full-text search of the order — all of it, linked below — returns no occurrence of "CAISI", "Center for AI Standards and Innovation" or "AI Safety Institute"; the Commerce Department's evaluation body is not named, and the National Institute of Standards and Technology appears once, as a consulting party. OpenAI's governance blueprint, dated the day after the order, asks the United States to strengthen CAISI "as the U.S. federal government's primary institution for frontier AI safety". The two documents assign the same function to different parts of the government: one to an intelligence agency working from a classified benchmark, the other to a civilian standards body whose output is a published evaluation.

xAI sues to block Minnesota's ban on nudification tools days before it applies

xAI filed suit against Minnesota Attorney General Keith Ellison in federal court in Minnesota, seeking to stop the state's first-in-the-nation statute banning "nudification" tools from taking effect on 1 August. The law, passed in April and signed in May, is unusual in reaching the makers of the tools rather than the people who use them: ordinary deepfake statutes, and the federal Take It Down Act, penalise the creator of an image or require platforms to remove it. Minnesota's levies $500,000 for each prohibited image a user generates. The 38-page complaint says xAI does not contest the state's interest in banning distribution of AI-generated nude images of real people without consent, but argues the statute reaches far past that goal, sweeping in constitutionally protected images and video, offering no safe harbour for companies that make good-faith efforts to prevent generation, covering images the depicted person consented to or created themselves, and defining "intimate part" broadly enough to include body parts routinely displayed in public. xAI is separately facing a proposed class action alleging Grok was used to generate child sexual abuse material. Its record challenging state AI laws is mixed: a federal judge struck down California's election-deepfake law in 2025, while a different Minnesota deepfake law survived its 2025 challenge.

An executive order makes a classified cyber benchmark the trigger for federal review of a model

President Trump signed Executive Order 14409, "Promoting Advanced Artificial Intelligence Innovation and Security". Its central section gives the Secretary of the Treasury, the Secretary of War through the Director of the National Security Agency, and the Secretary of Homeland Security through the Director of CISA sixty days — to 1 August 2026 — to do two things: develop and maintain a classified benchmarking process assessing the advanced cyber capabilities of AI models and fixing the threshold at which a model is designated a "covered frontier model", and design a voluntary framework under which developers can ask whether a model in training crosses that line, give the government access to it for a period of up to 30 days before releasing it to other trusted partners, and help choose which partners get early access. The designation itself rests with the Director of the NSA. It is the first time a US legal obligation has been keyed to a capability measurement whose criteria are classified. The order also disclaims, in terms, any authority to create "a mandatory governmental licensing, preclearance, or permitting requirement" for developing or releasing a model; directs a set of thirty-day cyber-defence tasks across the Committee on National Security Systems, the Department of War, CISA and Treasury, including an AI cybersecurity clearinghouse; and instructs the Attorney General to prioritise enforcement of 18 U.S.C. 1028, 1030 and 1343 against anyone using AI to break into or damage a computer.

Colorado repeals and rewrites the first comprehensive US state AI law

Governor Jared Polis signed SB 26-189, which repeals and re-enacts the Colorado Artificial Intelligence Act two years after he signed the original with written reservations. The rewrite replaces the 2024 law's "high-risk artificial intelligence system" and algorithmic-discrimination framework with a narrower regime covering "automated decision-making technology" that processes personal data to materially influence a consequential decision — employment, housing, lending, insurance, health care, education or essential government services. It drops the two heaviest obligations, mandatory risk-management programmes and annual impact assessments, in favour of consumer disclosures, post-adverse-outcome explanations, correction rights and a right to human review; adds sector accommodations for HIPAA-covered entities, insurers, creditors, FERPA institutions and FDA-regulated devices; states expressly that there is no private right of action; and voids contract clauses purporting to indemnify a party for its own discriminatory conduct. It also removes the original's conditional exemptions for federally regulated entities, pulling in businesses the 2024 law had left out, and makes Attorney General rulemaking mandatory and due by 1 January 2027, the date the substantive obligations take effect. The bill cleared the House on 9 May after a two-year effort across three legislative sessions and a stakeholder working group that reported on 17 March 2026.

Governor Polis signed the Colorado AI Act with reservations, warning it creates a complex compliance regime that could hamper innovation, urging sponsors to significantly improve it before it takes effect, and calling on Congress to enact preemptive federal AI legislation.?

Context: A signing-statement opinion and call for federal action, not a scored factual claim. In hindsight it cuts both ways: Polis did get the revision he sought — after xAI's suit, the DOJ intervention and a 27 April 2026 court suspension, he signed SB 26-189 on 14 May 2026, narrowing the Act before it took effect — but it took two years and a federal lawsuit, not one session, and Congress never supplied the preemptive statute he wanted; the pressure came from the executive branch instead. Unresolved.

Colorado's AI Act is suspended before it takes effect, with the Justice Department intervening against it

The first comprehensive US state AI statute was frozen before it ever applied. xAI sued the Colorado Attorney General in early April 2026 to enjoin the Colorado AI Act (SB24-205), whose effective date had already slipped from 1 February to 30 June 2026, arguing that designing a model is protected speech and that the law's carve-out for algorithms advancing "diversity" violates equal protection. On 24 April the Justice Department moved to intervene against the law — its first intervention in a challenge to a state AI statute, and the first practical use of Executive Order 14365's directive that DOJ contest state AI rules. The same day, xAI and the Attorney General jointly moved to suspend enforcement; on 27 April the court granted the motion, staying the law until Colorado's 2026 legislative session and any resulting rulemaking conclude and xAI's preliminary-injunction motion is decided. The court expressed no view on the merits.

California enacts SB 53, the first US frontier-AI safety statute

One year after vetoing SB 1047, Governor Newsom signed SB 53, the Transparency in Frontier Artificial Intelligence Act — also authored by Senator Wiener and the first state frontier-AI safety law in the nation. It requires large frontier developers to publish a safety framework, report critical safety incidents to the Office of Emergency Services, and protect whistleblowers, with civil penalties enforceable by the attorney general, and it establishes the CalCompute public computing consortium. A narrower, transparency-focused successor to the bill Newsom had rejected.

White House releases "America's AI Action Plan"

The White House released America's AI Action Plan, the strategy mandated by EO 14179, organized around three pillars: accelerating innovation by removing regulation and promoting open-weight models; building AI infrastructure through faster data-center, semiconductor and grid permitting; and leading in international AI diplomacy while tightening compute export controls. It is policy direction, not law, and marks the deregulatory turn from the Biden-era order.

Texas enacts the Responsible AI Governance Act

Governor Greg Abbott signed the Texas Responsible Artificial Intelligence Governance Act (TRAIGA / HB 149). A pared-back version of an earlier draft, it bars government use of AI for social scoring and non-consensual biometric identification, prohibits AI intentionally designed to cause harm, incite crime, or produce unlawful sexual content, amends Texas biometric and privacy law, creates a Texas AI Council and sets up a regulatory sandbox. Enforcement is by the attorney general, with a 60-day cure period.

Trump signs a new AI order directing an "AI dominance" agenda

President Trump signed EO 14179, "Removing Barriers to American Leadership in Artificial Intelligence" (published 31 January 2025, 90 FR 8741). It treats EO 14110 as revoked, directs agencies to suspend, revise or rescind actions taken under it that obstruct US "AI dominance," orders OMB to rewrite its AI memoranda within 60 days, and commissions an AI Action Plan within 180 days.

Trump revokes Biden's AI executive order on day one

On his first day in office, President Trump revoked Executive Order 14110 through EO 14148 ("Initial Rescissions of Harmful Executive Orders and Actions"), erasing the reporting mandates and agency directives that had been the core of US federal AI policy. The single largest reversal of AI governance in the record — a governance-as-announced-versus-enforced turning point.

Newsom vetoes California's frontier-AI safety bill SB 1047, signs transparency laws

Governor Gavin Newsom vetoed SB 1047, the Safe and Secure Innovation for Frontier Artificial Intelligence Models Act by State Senator Scott Wiener, which would have required developers of the largest frontier models to build in safety protocols including full-shutdown capability and submit to audits against "critical harms." The same day he signed AB 2013, requiring public disclosure of generative-AI training-data summaries (effective 2026), and SB 896, directing state risk analysis of GenAI threats to critical infrastructure. The veto was the year's pivotal moment in US frontier-AI regulation.

Regulating only the largest and most expensive AI models could give the public a false sense of security while smaller specialized models may prove equally or more dangerous, and the bill applied stringent standards even to basic, low-risk uses.?

Context: The core reasoning of Newsom's SB 1047 veto message — a policy judgment about how to target frontier-AI regulation. It is a normative argument rather than a dated, falsifiable forecast, so it is recorded but not scored as a prediction.

Colorado enacts the first comprehensive US state AI law

Governor Jared Polis signed SB24-205, the Colorado AI Act, making Colorado the first US state to enact broad legislation governing high-risk AI and algorithmic discrimination in "consequential decisions" — employment, housing, credit, education and healthcare. It requires developers and deployers to use "reasonable care" against discrimination, complete impact assessments, disclose to consumers and offer appeal rights; the attorney general has exclusive enforcement. Operative obligations were later delayed, initially to 2026.

Biden signs Executive Order 14110, the first sweeping US federal AI order

President Biden signed Executive Order 14110, "Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence" (published in the Federal Register 1 November 2023, 88 FR 75191). It imposed mandatory Defense Production Act reporting on developers of dual-use foundation models — training activities, model-weight security and red-team results — for models trained above 10^26 operations (10^23 for biological-sequence data) or clusters above 10^20 operations/second, and directed NIST to write red-teaming guidance and the Department of Energy to build model-evaluation testbeds for nuclear, bio, chemical and cyber threats. The foundational US federal AI action, and the one later reversals would be measured against.

New York City begins enforcing the first AI hiring-bias audit law

New York City's Department of Consumer and Worker Protection began enforcing Local Law 144, barring employers from using an automated employment decision tool unless it has passed an independent bias audit within the prior year, the audit results are posted publicly, and candidates are notified. It was the first US law to put an enforced compliance obligation on algorithmic hiring tools.