> ## Content Index
> Fetch the complete content index at: https://www.insidedeeptech.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# AI Safety Laws in The United States: 2026 Update
- URL: https://www.insidedeeptech.com/ai-safety-laws-united-states-2026-update/
- Published: 2026-09-11T06:06:55.000Z
- Updated: 2026-09-11T06:06:54.000Z
- Description: As of September 2026, the U.S. still has no federal AI Act. This update maps EO 14365/14409, California SB 53, Texas TRAIGA, Colorado's ADMT rewrite, and New York RAISE plus Illinois SB 315 for 2027.
- Author: Austin Heaton
- Tags: AI, Policy

As of September 2026, the United States still has **no comprehensive federal AI Act**. What operators actually face is a live state patchwork: California SB 53 already in force, Texas TRAIGA live since January, Colorado rewritten before it ever applied, and New York plus Illinois frontier laws queued for 2027.

This update is the U.S.-only map for labs, deployers, and deep-tech investors. It covers federal executive orders and the March 2026 National Policy Framework, the frontier-developer cluster (California, New York, Illinois), deployer and ADMT statutes (Colorado, Texas, Utah), and the honest limits of what Congress and the AI Litigation Task Force have **not** done yet. For the global GPAI / AGI jurisdiction map, see Inside Deep Tech's companion September update.

## Key Takeaways

- No federal AI Act exists; EO 14365 preemption remains nonbinding.
- California SB 53 frontier transparency has applied since 1 Jan 2026.
- New York RAISE and Illinois SB 315 take effect 1 Jan 2027.
- Colorado's 2024 AI Act was repealed; narrower ADMT law starts 2027.
- Texas TRAIGA and Utah disclosure rules already bind deployers in 2026.

📌

Scope note: this is a United States safety-and-governance map for frontier model developers and high-stakes deployers, not a glossary of AI definitions and not a global AGI comparison. Claims are date-stamped as of 11 September 2026.

## U.S. snapshot (as of September 2026)

Start with the table. The practical split is **frontier developer duties** (compute + revenue thresholds) versus **deployer / consequential-decision duties** (employment, lending, housing, health, government services).

| Instrument                              | Who it bites                                                             | Status as of Sep 2026                                                | Hard obligation?                            |
| --------------------------------------- | ------------------------------------------------------------------------ | -------------------------------------------------------------------- | ------------------------------------------- |
| Federal EO 14365 (11 Dec 2025)          | State AI laws targeted for challenge / preemption ask                    | Task Force stood up Jan 2026; no filed suits reported as of mid-2026 | No (policy + litigation posture)            |
| National Policy Framework (20 Mar 2026) | Congress (legislative recommendations)                                   | Nonbinding White House ask for uniform federal standard              | No                                          |
| Federal EO 14409 (2 Jun 2026)           | Covered frontier model developers (voluntary)                            | Voluntary pre-release access / cyber benchmarking; not a license     | No federal license                          |
| California SB 53 (TFAIA)                | Frontier / large frontier developers (>10^26 FLOPs; $500M+ revenue tier) | In force since 1 Jan 2026                                            | Yes (civil penalties up to $1M / violation) |
| California AB 2013 (TDTA)               | Generative AI developers posting training-data summaries                 | In force since 1 Jan 2026                                            | Yes (training-data transparency)            |
| Texas TRAIGA                            | Developers and deployers of AI systems in Texas                          | In force since 1 Jan 2026                                            | Yes (AG enforcement; cure period)           |
| Utah AI Policy Act (SB 149)             | Regulated professions + consumer AI interactions                         | In force since 1 May 2024                                            | Yes (disclosure duties)                     |
| Colorado SB 26-189 (ADMT rewrite)       | Developers / deployers of ADMT in consequential decisions                | Signed 14 May 2026; applies from 1 Jan 2027                          | Yes from 2027 (narrower than 2024 Act)      |
| New York RAISE Act                      | Frontier / large frontier developers operating in NY                     | Signed / amended 2025-2026; effective 1 Jan 2027                     | Yes from 2027 (72-hour incidents)           |
| Illinois SB 315                         | Large frontier developers operating in Illinois                          | Signed 6 Jul 2026; effective 1 Jan 2027; audits from 1 Jan 2028      | Yes from 2027/2028                          |
| NIST AI RMF                             | Voluntary adopters (often cited in TRAIGA safe harbors)                  | Voluntary Govern / Map / Measure / Manage framework                  | No (voluntary)                              |

## Federal layer: executive orders without an AI Act

Congress has not enacted a cross-sector frontier AI statute. The one notable standalone federal statute in this lane is the **TAKE IT DOWN Act**, which targets non-consensual intimate imagery (including AI deepfakes) on platforms rather than model training itself.

### EO 14365 and the March 2026 National Policy Framework

On **11 December 2025**, the White House issued [Executive Order 14365](https://www.whitehouse.gov/wp-content/uploads/2025/12/eo-14365.pdf?ref=insidedeeptech.com) (Ensuring a National Policy Framework for Artificial Intelligence). It directs a Department of Justice **AI Litigation Task Force** to challenge state AI laws viewed as inconsistent with a "minimally burdensome" national policy, and it asks for legislative recommendations that would preempt conflicting state rules.

On **20 March 2026**, the White House released a **National Policy Framework for Artificial Intelligence**: nonbinding recommendations to Congress, not a statute. As of this writing, no federal preemption bill implementing that framework has become law. Courts do not wipe state statutes because an executive order exists.

Here's why that matters. As of mid-2026 reporting, the Task Force had **not yet filed suits** against the major state AI laws. Treat LinkedIn claims that "federal preemption killed SB 53" as unverified.

### EO 14409: voluntary covered-frontier access

On **2 June 2026**, **Executive Order 14409** (Promoting Advanced Artificial Intelligence Innovation and Security) set up a voluntary framework around "covered frontier models": agency cyber benchmarking and limited pre-release model access for trusted partners. The order expressly says it does **not** authorize mandatory licensing, preclearance, or permitting for developing or releasing AI models.

That means Washington's frontier posture in September 2026 is still **voluntary evaluation access**, not an FAA-style deployment license. NIST's **AI Risk Management Framework** remains the soft standard many state statutes point to for recognized practice.

## Frontier developer laws: California live, New York and Illinois next

### California SB 53 (Transparency in Frontier Artificial Intelligence Act)

California filled the federal gap first. **SB 53**, signed **29 September 2025**, took effect **1 January 2026**. It sits in Business and Professions Code Chapter 25.1 and defines a frontier model by training compute above **10²⁶ FLOPs** (including subsequent fine-tuning and material modifications).

"Large frontier developers" (prior-year gross revenue above **$500 million**) must publish a **frontier AI framework** covering catastrophic-risk assessment, third-party engagement, and model-weight security, then publish transparency reports when deploying new or substantially modified frontier models. Critical safety incidents go to the California Office of Emergency Services (generally **15 days**, or **24 hours** for imminent death/serious injury risk). Civil penalties can reach **$1 million per violation**.

Important correction for older decks: **SB 1047 was vetoed in 2024 and is not law**. SB 53 is the frontier statute that applies in 2026\. Companion California rules also matter: **AB 2013** (training-data transparency for generative systems) likewise took effect 1 January 2026.

### New York RAISE Act

New York's **Responsible AI Safety and Education (RAISE) Act** aligns closely with SB 53 after chapter amendments: same **10²⁶ FLOPs** frontier threshold and **$500 million** large-developer revenue tier. It applies to frontier models developed, deployed, or operated in whole or in part in New York, with an academic-research carve-out.

RAISE takes effect **1 January 2027**. Relative to California, the operational differences labs feel first are **72-hour** critical-incident reporting (versus SB 53's 15-day default) and a more detailed published framework, with oversight routed through the Department of Financial Services.

### Illinois SB 315

On **6 July 2026**, Illinois enacted **SB 315**, another SB 53-style frontier statute. Baseline effective date: **1 January 2027**. The distinctive add-on is an **annual independent third-party audit** of procedural compliance with the frontier AI framework and transparency duties, starting **1 January 2028**. Large developers must also keep a disclosure statement on file to operate a frontier model in Illinois.

💡

Inside Deep Tech's take: the U.S. frontier compliance map for a large lab in September 2026 is California disclosures now, New York and Illinois calendars for 2027-2028, plus voluntary federal evaluation access under EO 14409\. Budget release engineering for SB 53 before you budget for a fictional federal license.

## Deployer and ADMT laws: Colorado rewrite, Texas, Utah

### Colorado: 2024 Act repealed, narrower ADMT law for 2027

Colorado's original 2024 algorithmic-discrimination AI Act never took effect. On **14 May 2026**, Governor Polis signed **SB 26-189**, which **repeals and replaces** that framework with a narrower Automated Decision-Making Technology (ADMT) statute effective **1 January 2027**.

Covered ADMT is technology that materially influences consequential decisions in education, employment, housing, lending, insurance, health care, or essential government services. Developers must give deployers documentation on intended uses, training-data categories, known limitations, and human-review instructions. Deployers owe consumer notice and, after an adverse outcome, a plain-language explanation within **30 days**. The Attorney General enforces via the Colorado Consumer Protection Act, with a **60-day cure** window before 2030 when a cure is possible.

What disappeared relative to the 2024 text: the broad duty of care against algorithmic discrimination, mandatory risk-management programs, and deployer impact assessments. If your 2025 compliance deck still cites those, update it.

### Texas TRAIGA

The **Texas Responsible AI Governance Act (TRAIGA)**, enacted **22 June 2025** and effective **1 January 2026**, binds developers and deployers operating in Texas. It prohibits intentional misuse for certain harmful uses (including unlawful discrimination and specified deepfake harms), requires clear consumer disclosure that a person is interacting with AI, and creates AG enforcement with a cure period. Following **NIST AI RMF**\-aligned practice is treated as a recognized safe-harbor path in the statute's design.

### Utah disclosure duties

Utah's **AI Policy Act (SB 149)**, effective **1 May 2024**, remains one of the earliest live disclosure regimes: regulated professions must disclose generative-AI use in specified high-risk consumer interactions, and consumers who ask whether they are talking to AI must get a straight answer.

## Timeline that actually moved U.S. obligations

| Date        | What happened                            | Why labs / deployers care                                          |
| ----------- | ---------------------------------------- | ------------------------------------------------------------------ |
| 1 May 2024  | Utah AI Policy Act effective             | Early disclosure duties for generative AI in regulated professions |
| Sep 2024    | California SB 1047 vetoed                | Not law; do not cite as active frontier statute                    |
| 22 Jun 2025 | Texas TRAIGA enacted                     | Starts the Texas developer/deployer clock                          |
| 29 Sep 2025 | California SB 53 signed                  | Frontier transparency path locked in                               |
| 11 Dec 2025 | Federal EO 14365 signed                  | Preemption + litigation posture, not a statute                     |
| 1 Jan 2026  | SB 53, AB 2013, TRAIGA apply             | First hard U.S. frontier + Texas deployer day                      |
| 9 Jan 2026  | DOJ AI Litigation Task Force established | Challenge vehicle exists; suits still the open question            |
| 20 Mar 2026 | National Policy Framework released       | Nonbinding ask to Congress                                         |
| 14 May 2026 | Colorado SB 26-189 signed                | 2024 AI Act repealed; ADMT law set for 2027                        |
| 2 Jun 2026  | Federal EO 14409 signed                  | Voluntary covered-frontier access framework                        |
| 6 Jul 2026  | Illinois SB 315 signed                   | Third state frontier statute; audits from 2028                     |
| 1 Jan 2027  | RAISE, SB 315, Colorado ADMT apply       | Multi-state frontier + ADMT calendar goes live                     |
| 1 Jan 2028  | Illinois independent audits begin        | Procedural compliance audits for large frontier developers         |

## Why this matters for AI infrastructure buyers

U.S. safety law now tracks the same bottlenecks Inside Deep Tech already covers on the hardware side: training compute above **10²⁶ FLOPs**, model-weight security, and release process. That couples legal risk to packaging, memory, rack power, and interconnect choices long before a chatbot UX ships.

If your diligence pack already includes [Global AGI Regulations in 2026](https://www.insidedeeptech.com/global-agi-regulations-2026-september-update/) and [The State of Data Centers 2026](https://www.insidedeeptech.com/the-state-of-data-centers-2026/), add a one-page U.S. matrix that separates frontier developer duties from deployer/ADMT duties. Capital allocators watching [where deep-tech funding went in 2026](https://www.insidedeeptech.com/deep-tech-funding-hit-records-in-2026-heres-where-it-went/) should treat SB 53 disclosures and the 2027 RAISE / Illinois calendar as underwriting inputs, not footnotes.

[Global AGI Regulations in 2026 (September 2026 Update)Companion map: EU GPAI, China CAC filing, UK sectoral oversight, and OECD soft law.![](https://www.insidedeeptech.com/favicon.ico)Inside Deep Tech](https://www.insidedeeptech.com/global-agi-regulations-2026-september-update/)

[Read the global AGI regulations update](https://www.insidedeeptech.com/global-agi-regulations-2026-september-update/)

## Named downside: what this map does not give you

This update will not tell you whether any lab has "achieved AGI." U.S. regulators are not waiting for that finish line. They are regulating compute proxies, catastrophic-risk process duties, and consequential automated decisions.

It also will not replace counsel. Extraterritorial reach, open-source carve-outs, knowledge-distillation definitions, and how New York defines "operating in whole or in part" turn on facts a blog cannot litigate. Connecticut's 2026 online-safety package and other narrow state bills keep moving. Federal preemption can change with a single enacted statute.

Who this is not for: teams shipping narrow classical ML with no public generative interface, training compute far below frontier thresholds, and no consequential automated decisions in employment, lending, housing, or health. Your risk is still privacy, product liability, and sector rules.

⚠️

Honest limit: if a thread claims a "federal AI license" or that EO 14365 already voided California SB 53, ask for the statute number or the court order. As of 11 September 2026, Inside Deep Tech cannot verify either from primary sources.

---

## FAQ

#### Is there a federal AI safety law in the United States in 2026?

No comprehensive federal AI Act exists as of September 2026\. Policy runs through executive orders (EO 14365, EO 14409), agency guidance such as the NIST AI RMF, and narrow statutes like the TAKE IT DOWN Act for intimate deepfake imagery.

#### Does Executive Order 14365 preempt California SB 53?

No. An executive order is not a preemption statute. EO 14365 directs litigation strategy and asks Congress for a framework. State laws remain enforceable until a court invalidates them or Congress preempts them.

#### What California frontier AI law actually applies in 2026?

SB 53's Transparency in Frontier Artificial Intelligence Act, effective 1 January 2026\. SB 1047 was vetoed in 2024 and is not law. AB 2013 separately requires generative training-data transparency.

#### When do New York RAISE and Illinois SB 315 take effect?

Both take effect 1 January 2027\. Illinois' independent third-party audit duty for large frontier developers begins 1 January 2028.

#### What happened to Colorado's 2024 AI Act?

SB 26-189, signed 14 May 2026, repealed and replaced it with a narrower ADMT disclosure statute that applies from 1 January 2027\. The original algorithmic-discrimination framework never took effect.

#### Does Texas TRAIGA regulate frontier training compute?

TRAIGA is primarily a developer/deployer misuse, discrimination, deepfake, and disclosure statute effective 1 January 2026\. It is not a California-style 10^26 FLOP frontier transparency law.

#### Do U.S. labs need a federal license before releasing a frontier model?

Not under EO 14409\. That June 2026 order creates a voluntary covered-frontier access framework and states it does not authorize mandatory licensing or preclearance.

#### How does this differ from Inside Deep Tech's global AGI regulations update?

The global update maps EU GPAI, China filing, UK sectoral oversight, and soft law. This piece is the U.S.-only deep dive on federal EOs and the state frontier plus deployer patchwork.

---

## What happens next

The next twelve months will not produce a single U.S. AI constitution. They will produce enforcement samples: first California SB 53 penalty patterns, first Texas TRAIGA AG actions, whatever voluntary covered-frontier evaluations federal agencies actually run, and the 1 January 2027 go-live for RAISE, Illinois SB 315, and Colorado's ADMT rewrite.

For operators, Monday looks like this: classify every model by training compute and public release path, map large-developer revenue against California duties now and New York / Illinois calendars for 2027, then separately inventory consequential ADMT deployments for Colorado, Texas, and Utah. The labs that treat U.S. safety law as a release-engineering problem will outrun the ones still waiting for Congress.

[The State of Data Centers 2026Where AI capex is going, why the grid became the bottleneck, and who pays.![](https://www.insidedeeptech.com/favicon.ico)Inside Deep Tech](https://www.insidedeeptech.com/the-state-of-data-centers-2026/)

[Read the State of Data Centers 2026 report](https://www.insidedeeptech.com/the-state-of-data-centers-2026/)