Skip to content

AI Safety Laws in The United States: 2026 Update

As of September 2026, the U.S. still has no federal AI Act. This update maps EO 14365/14409, California SB 53, Texas TRAIGA, Colorado's ADMT rewrite, and New York RAISE plus Illinois SB 315 for 2027.

Share
AI Safety Laws in the United States: 2026 Update

As of September 2026, the United States still has no comprehensive federal AI Act. What operators actually face is a live state patchwork: California SB 53 already in force, Texas TRAIGA live since January, Colorado rewritten before it ever applied, and New York plus Illinois frontier laws queued for 2027.

This update is the U.S.-only map for labs, deployers, and deep-tech investors. It covers federal executive orders and the March 2026 National Policy Framework, the frontier-developer cluster (California, New York, Illinois), deployer and ADMT statutes (Colorado, Texas, Utah), and the honest limits of what Congress and the AI Litigation Task Force have not done yet. For the global GPAI / AGI jurisdiction map, see Inside Deep Tech's companion September update.

Key Takeaways

  • No federal AI Act exists; EO 14365 preemption remains nonbinding.
  • California SB 53 frontier transparency has applied since 1 Jan 2026.
  • New York RAISE and Illinois SB 315 take effect 1 Jan 2027.
  • Colorado's 2024 AI Act was repealed; narrower ADMT law starts 2027.
  • Texas TRAIGA and Utah disclosure rules already bind deployers in 2026.
📌
Scope note: this is a United States safety-and-governance map for frontier model developers and high-stakes deployers, not a glossary of AI definitions and not a global AGI comparison. Claims are date-stamped as of 11 September 2026.

U.S. snapshot (as of September 2026)

Start with the table. The practical split is frontier developer duties (compute + revenue thresholds) versus deployer / consequential-decision duties (employment, lending, housing, health, government services).

InstrumentWho it bitesStatus as of Sep 2026Hard obligation?
Federal EO 14365 (11 Dec 2025)State AI laws targeted for challenge / preemption askTask Force stood up Jan 2026; no filed suits reported as of mid-2026No (policy + litigation posture)
National Policy Framework (20 Mar 2026)Congress (legislative recommendations)Nonbinding White House ask for uniform federal standardNo
Federal EO 14409 (2 Jun 2026)Covered frontier model developers (voluntary)Voluntary pre-release access / cyber benchmarking; not a licenseNo federal license
California SB 53 (TFAIA)Frontier / large frontier developers (>10^26 FLOPs; $500M+ revenue tier)In force since 1 Jan 2026Yes (civil penalties up to $1M / violation)
California AB 2013 (TDTA)Generative AI developers posting training-data summariesIn force since 1 Jan 2026Yes (training-data transparency)
Texas TRAIGADevelopers and deployers of AI systems in TexasIn force since 1 Jan 2026Yes (AG enforcement; cure period)
Utah AI Policy Act (SB 149)Regulated professions + consumer AI interactionsIn force since 1 May 2024Yes (disclosure duties)
Colorado SB 26-189 (ADMT rewrite)Developers / deployers of ADMT in consequential decisionsSigned 14 May 2026; applies from 1 Jan 2027Yes from 2027 (narrower than 2024 Act)
New York RAISE ActFrontier / large frontier developers operating in NYSigned / amended 2025-2026; effective 1 Jan 2027Yes from 2027 (72-hour incidents)
Illinois SB 315Large frontier developers operating in IllinoisSigned 6 Jul 2026; effective 1 Jan 2027; audits from 1 Jan 2028Yes from 2027/2028
NIST AI RMFVoluntary adopters (often cited in TRAIGA safe harbors)Voluntary Govern / Map / Measure / Manage frameworkNo (voluntary)

Federal layer: executive orders without an AI Act

Congress has not enacted a cross-sector frontier AI statute. The one notable standalone federal statute in this lane is the TAKE IT DOWN Act, which targets non-consensual intimate imagery (including AI deepfakes) on platforms rather than model training itself.

EO 14365 and the March 2026 National Policy Framework

On 11 December 2025, the White House issued Executive Order 14365 (Ensuring a National Policy Framework for Artificial Intelligence). It directs a Department of Justice AI Litigation Task Force to challenge state AI laws viewed as inconsistent with a "minimally burdensome" national policy, and it asks for legislative recommendations that would preempt conflicting state rules.

On 20 March 2026, the White House released a National Policy Framework for Artificial Intelligence: nonbinding recommendations to Congress, not a statute. As of this writing, no federal preemption bill implementing that framework has become law. Courts do not wipe state statutes because an executive order exists.

Here's why that matters. As of mid-2026 reporting, the Task Force had not yet filed suits against the major state AI laws. Treat LinkedIn claims that "federal preemption killed SB 53" as unverified.

EO 14409: voluntary covered-frontier access

On 2 June 2026, Executive Order 14409 (Promoting Advanced Artificial Intelligence Innovation and Security) set up a voluntary framework around "covered frontier models": agency cyber benchmarking and limited pre-release model access for trusted partners. The order expressly says it does not authorize mandatory licensing, preclearance, or permitting for developing or releasing AI models.

That means Washington's frontier posture in September 2026 is still voluntary evaluation access, not an FAA-style deployment license. NIST's AI Risk Management Framework remains the soft standard many state statutes point to for recognized practice.

Frontier developer laws: California live, New York and Illinois next

California SB 53 (Transparency in Frontier Artificial Intelligence Act)

California filled the federal gap first. SB 53, signed 29 September 2025, took effect 1 January 2026. It sits in Business and Professions Code Chapter 25.1 and defines a frontier model by training compute above 10²⁶ FLOPs (including subsequent fine-tuning and material modifications).

"Large frontier developers" (prior-year gross revenue above $500 million) must publish a frontier AI framework covering catastrophic-risk assessment, third-party engagement, and model-weight security, then publish transparency reports when deploying new or substantially modified frontier models. Critical safety incidents go to the California Office of Emergency Services (generally 15 days, or 24 hours for imminent death/serious injury risk). Civil penalties can reach $1 million per violation.

Important correction for older decks: SB 1047 was vetoed in 2024 and is not law. SB 53 is the frontier statute that applies in 2026. Companion California rules also matter: AB 2013 (training-data transparency for generative systems) likewise took effect 1 January 2026.

New York RAISE Act

New York's Responsible AI Safety and Education (RAISE) Act aligns closely with SB 53 after chapter amendments: same 10²⁶ FLOPs frontier threshold and $500 million large-developer revenue tier. It applies to frontier models developed, deployed, or operated in whole or in part in New York, with an academic-research carve-out.

RAISE takes effect 1 January 2027. Relative to California, the operational differences labs feel first are 72-hour critical-incident reporting (versus SB 53's 15-day default) and a more detailed published framework, with oversight routed through the Department of Financial Services.

Illinois SB 315

On 6 July 2026, Illinois enacted SB 315, another SB 53-style frontier statute. Baseline effective date: 1 January 2027. The distinctive add-on is an annual independent third-party audit of procedural compliance with the frontier AI framework and transparency duties, starting 1 January 2028. Large developers must also keep a disclosure statement on file to operate a frontier model in Illinois.

💡
Inside Deep Tech's take: the U.S. frontier compliance map for a large lab in September 2026 is California disclosures now, New York and Illinois calendars for 2027-2028, plus voluntary federal evaluation access under EO 14409. Budget release engineering for SB 53 before you budget for a fictional federal license.

Deployer and ADMT laws: Colorado rewrite, Texas, Utah

Colorado: 2024 Act repealed, narrower ADMT law for 2027

Colorado's original 2024 algorithmic-discrimination AI Act never took effect. On 14 May 2026, Governor Polis signed SB 26-189, which repeals and replaces that framework with a narrower Automated Decision-Making Technology (ADMT) statute effective 1 January 2027.

Covered ADMT is technology that materially influences consequential decisions in education, employment, housing, lending, insurance, health care, or essential government services. Developers must give deployers documentation on intended uses, training-data categories, known limitations, and human-review instructions. Deployers owe consumer notice and, after an adverse outcome, a plain-language explanation within 30 days. The Attorney General enforces via the Colorado Consumer Protection Act, with a 60-day cure window before 2030 when a cure is possible.

What disappeared relative to the 2024 text: the broad duty of care against algorithmic discrimination, mandatory risk-management programs, and deployer impact assessments. If your 2025 compliance deck still cites those, update it.

Texas TRAIGA

The Texas Responsible AI Governance Act (TRAIGA), enacted 22 June 2025 and effective 1 January 2026, binds developers and deployers operating in Texas. It prohibits intentional misuse for certain harmful uses (including unlawful discrimination and specified deepfake harms), requires clear consumer disclosure that a person is interacting with AI, and creates AG enforcement with a cure period. Following NIST AI RMF-aligned practice is treated as a recognized safe-harbor path in the statute's design.

Utah disclosure duties

Utah's AI Policy Act (SB 149), effective 1 May 2024, remains one of the earliest live disclosure regimes: regulated professions must disclose generative-AI use in specified high-risk consumer interactions, and consumers who ask whether they are talking to AI must get a straight answer.

Timeline that actually moved U.S. obligations

DateWhat happenedWhy labs / deployers care
1 May 2024Utah AI Policy Act effectiveEarly disclosure duties for generative AI in regulated professions
Sep 2024California SB 1047 vetoedNot law; do not cite as active frontier statute
22 Jun 2025Texas TRAIGA enactedStarts the Texas developer/deployer clock
29 Sep 2025California SB 53 signedFrontier transparency path locked in
11 Dec 2025Federal EO 14365 signedPreemption + litigation posture, not a statute
1 Jan 2026SB 53, AB 2013, TRAIGA applyFirst hard U.S. frontier + Texas deployer day
9 Jan 2026DOJ AI Litigation Task Force establishedChallenge vehicle exists; suits still the open question
20 Mar 2026National Policy Framework releasedNonbinding ask to Congress
14 May 2026Colorado SB 26-189 signed2024 AI Act repealed; ADMT law set for 2027
2 Jun 2026Federal EO 14409 signedVoluntary covered-frontier access framework
6 Jul 2026Illinois SB 315 signedThird state frontier statute; audits from 2028
1 Jan 2027RAISE, SB 315, Colorado ADMT applyMulti-state frontier + ADMT calendar goes live
1 Jan 2028Illinois independent audits beginProcedural compliance audits for large frontier developers

Why this matters for AI infrastructure buyers

U.S. safety law now tracks the same bottlenecks Inside Deep Tech already covers on the hardware side: training compute above 10²⁶ FLOPs, model-weight security, and release process. That couples legal risk to packaging, memory, rack power, and interconnect choices long before a chatbot UX ships.

If your diligence pack already includes Global AGI Regulations in 2026 and The State of Data Centers 2026, add a one-page U.S. matrix that separates frontier developer duties from deployer/ADMT duties. Capital allocators watching where deep-tech funding went in 2026 should treat SB 53 disclosures and the 2027 RAISE / Illinois calendar as underwriting inputs, not footnotes.

Global AGI Regulations in 2026 (September 2026 Update)
Companion map: EU GPAI, China CAC filing, UK sectoral oversight, and OECD soft law.

Named downside: what this map does not give you

This update will not tell you whether any lab has "achieved AGI." U.S. regulators are not waiting for that finish line. They are regulating compute proxies, catastrophic-risk process duties, and consequential automated decisions.

It also will not replace counsel. Extraterritorial reach, open-source carve-outs, knowledge-distillation definitions, and how New York defines "operating in whole or in part" turn on facts a blog cannot litigate. Connecticut's 2026 online-safety package and other narrow state bills keep moving. Federal preemption can change with a single enacted statute.

Who this is not for: teams shipping narrow classical ML with no public generative interface, training compute far below frontier thresholds, and no consequential automated decisions in employment, lending, housing, or health. Your risk is still privacy, product liability, and sector rules.

⚠️
Honest limit: if a thread claims a "federal AI license" or that EO 14365 already voided California SB 53, ask for the statute number or the court order. As of 11 September 2026, Inside Deep Tech cannot verify either from primary sources.

FAQ

Is there a federal AI safety law in the United States in 2026?

No comprehensive federal AI Act exists as of September 2026. Policy runs through executive orders (EO 14365, EO 14409), agency guidance such as the NIST AI RMF, and narrow statutes like the TAKE IT DOWN Act for intimate deepfake imagery.

Does Executive Order 14365 preempt California SB 53?

No. An executive order is not a preemption statute. EO 14365 directs litigation strategy and asks Congress for a framework. State laws remain enforceable until a court invalidates them or Congress preempts them.

What California frontier AI law actually applies in 2026?

SB 53's Transparency in Frontier Artificial Intelligence Act, effective 1 January 2026. SB 1047 was vetoed in 2024 and is not law. AB 2013 separately requires generative training-data transparency.

When do New York RAISE and Illinois SB 315 take effect?

Both take effect 1 January 2027. Illinois' independent third-party audit duty for large frontier developers begins 1 January 2028.

What happened to Colorado's 2024 AI Act?

SB 26-189, signed 14 May 2026, repealed and replaced it with a narrower ADMT disclosure statute that applies from 1 January 2027. The original algorithmic-discrimination framework never took effect.

Does Texas TRAIGA regulate frontier training compute?

TRAIGA is primarily a developer/deployer misuse, discrimination, deepfake, and disclosure statute effective 1 January 2026. It is not a California-style 10^26 FLOP frontier transparency law.

Do U.S. labs need a federal license before releasing a frontier model?

Not under EO 14409. That June 2026 order creates a voluntary covered-frontier access framework and states it does not authorize mandatory licensing or preclearance.

How does this differ from Inside Deep Tech's global AGI regulations update?

The global update maps EU GPAI, China filing, UK sectoral oversight, and soft law. This piece is the U.S.-only deep dive on federal EOs and the state frontier plus deployer patchwork.


What happens next

The next twelve months will not produce a single U.S. AI constitution. They will produce enforcement samples: first California SB 53 penalty patterns, first Texas TRAIGA AG actions, whatever voluntary covered-frontier evaluations federal agencies actually run, and the 1 January 2027 go-live for RAISE, Illinois SB 315, and Colorado's ADMT rewrite.

For operators, Monday looks like this: classify every model by training compute and public release path, map large-developer revenue against California duties now and New York / Illinois calendars for 2027, then separately inventory consequential ADMT deployments for Colorado, Texas, and Utah. The labs that treat U.S. safety law as a release-engineering problem will outrun the ones still waiting for Congress.

The State of Data Centers 2026
Where AI capex is going, why the grid became the bottleneck, and who pays.