Key Points
- With no comprehensive federal regulatory framework for AI, a growing number of states have enacted their own laws — some targeting developers, others focused on the way companies deploy AI, and some both.
- The Trump administration opposes state-specific laws and has threatened to challenge some, but states continue to legislate in the area, and it is unclear how the conflict will play out.
- In this unsettled environment, boards should be comfortable that their companies have processes in place to monitor developments, assess which laws apply to their businesses, and adjust their AI governance and compliance programs as the legal landscape changes.
__________
At present, there is no federal regulatory framework for artificial intelligence (AI), but a number of states have stepped into this void, adopting laws that govern different aspects of the development and use of AI. Other states also appear likely to adopt their own laws, making for a complex and potentially conflicting set of requirements for companies, and these remain in flux.
The Trump administration has said it will challenge some of these laws, which adds another layer of uncertainty to the legal landscape.
Below is a guide for boards about the current situation, with some questions they can address to management to ensure their companies comply with the applicable laws and position their companies for the evolution of the law.
The Current Federal Landscape
The Trump administration has generally favored a light-touch approach to AI regulation, emphasizing the need to promote innovation and avoid regulatory requirements that could slow the development and adoption of AI. The centerpiece of that approach is the administration’s July 2025 AI Action Plan, which called on the U.S. to “innovate faster and more comprehensively” and to “dismantle unnecessary regulatory barriers.”
For now, there appears to be little prospect of comprehensive federal AI legislation. Instead, the administration has relied largely on voluntary measures, including guidelines under which developers of advanced AI models are encouraged to share information about their more complex models with the federal government before public release.
Against that backdrop, a number of states have stepped in with their own AI laws. The administration, however, has made clear that it would prefer AI regulation to be addressed at the federal level and has pushed back against state regulation. In December 2025, President Trump issued an Executive Order directing the Department of Justice to establish an AI Litigation Task Force to challenge certain state AI laws, instructing the Commerce Department to identify particularly burdensome state laws, and directing federal agencies to consider a state’s AI regulatory climate when making certain discretionary funding decisions. In March 2026, the White House went a step further, issuing a National Policy Framework that urged Congress to adopt a “minimally burdensome national standard” that would displace state-by-state regulation.
How much practical effect the administration’s position will have on state AI regulation remains to be seen. There are already signs, however, that it may be influencing state policymakers. Colorado, for example, recently repealed and replaced its comprehensive AI law before it took effect, significantly reducing some of its requirements.
The broader point for boards is that the AI regulatory landscape remains unsettled. Although the federal government is currently taking a relatively permissive approach, states continue to legislate, and the interaction between federal and state regulation is evolving quickly. Boards should therefore be comfortable that their companies have processes in place to monitor these developments, assess which laws apply to their businesses, and adjust their AI governance and compliance programs as the legal landscape changes.
The State Landscape
A growing number of states have enacted, or are considering, laws regulating artificial intelligence (see table). These generally take one of two paths which track the broader debate on how AI should be regulated. Some focus on regulating the developers of frontier AI models, imposing transparency, disclosure and, in some cases, risk-management obligations, while other laws focus on the deployment of AI in areas such as decision-making or consumer-facing chatbots. Still other laws seek to regulate both developers and deployers. Which laws apply will depend on a company’s business, the AI systems it develops or uses, and how those systems are deployed.
New York’s Responsible AI Safety and Education (RAISE) Act is an example of a state law focused on regulating developers. The law, which takes effect January 1, 2027, applies to developers of large AI models, and requires them to publish safety protocols, report serious safety incidents within 72 hours and register with a new oversight office.
The Colorado Artificial Intelligence Act (CAIA), initially enacted in May 2024, is an example of a regulation seeking to regulate both developers and deployers of AI systems. Initially, the law covered “high-risk” AI systems that are a substantial factor in reaching a “consequential decision” about an individual (e.g., relating to education, employment, lending, health, etc.) and the potential of such systems to yield algorithmic discrimination. Likely in response to the administration’s opposition to laws that focus on algorithmic discrimination, the CAIA has since been repealed and replaced with the Automated Decision-Making Technology Act, a narrower framework focused on increased transparency about consequential decisions and disclosures about adverse outcomes affected by automated decision-making technology.
For many companies, the principal challenge will be developing a coherent AI compliance framework across an increasingly fragmented landscape of state laws. Rather than adopting policies that vary depending on the state in which a user or consumer resides, companies may conclude that it is more efficient, both to reduce compliance costs and to minimize the risk of non-compliance, to adopt a single, nationwide policy designed to satisfy the most stringent applicable state requirements. Even that approach, however, can be challenging where states impose materially different, or potentially inconsistent, requirements.
Boards should therefore ensure that management has established an appropriate governance process for identifying applicable state AI laws, assessing their impact on the company’s AI activities, updating the company’s policies and controls as those laws evolve, and ensuring AI implementation is being documented to the extent required by state laws.
This does not require boards to oversee compliance on a state-by-state basis, but they should understand the company’s overall approach to managing this regulatory complexity, including who within the organization is responsible for AI compliance, how potentially conflicting requirements are addressed, and whether the board is receiving periodic updates on material regulatory developments and associated compliance risks.
Questions to Ask
Given the current landscape, boards may want to ask management questions along these lines:
- Do we have a clear understanding of the company’s AI footprint and the regulatory regimes that apply to it?
- Has management identified the AI systems the company develops, deploys or relies upon, the jurisdictions in which those activities occur, and the different legal obligations that may arise depending on the company’s role?
- Is responsibility for AI compliance clearly assigned, and is the board receiving the right level of reporting?
- Who within management is accountable for monitoring legal developments, assessing compliance gaps and escalating material incidents? Is the board receiving regular, decision-useful updates on emerging risks rather than simply descriptions of new laws?
- Are the company’s compliance processes sufficiently robust to address both its own use of AI and foreseeable downstream uses?
- Do the company’s controls extend, where appropriate, to customer or third-party use of its AI systems? Are there effective processes for detecting, investigating and escalating incidents?
- Are the company’s public statements about AI accurate, supportable and consistent with its actual practices?
- Has management established a process to verify claims regarding AI safety, testing, risk management and compliance, and to ensure that disclosures made in different contexts are consistent with one another?
- How is management preparing for further changes in the federal-state regulatory landscape?
- Is the company tracking potential federal challenges to state AI laws, as well as congressional action that could preempt or displace state requirements? Has management considered how the company’s compliance framework would need to change if the current patchwork of state laws is narrowed, expanded or replaced?
More broadly, boards should understand whether the company has an effective framework for overseeing the core elements likely to remain relevant regardless of changes in the regulatory landscape, including AI inventories, safety and risk-management documentation, incident reporting and public disclosures.
Selected State AI Laws
| KEY LEGISLATION | SCOPE | STATUS |
|---|---|---|
| CALIFORNIA | ||
|
SB 53 AB 2013 SB 942 (provenance) SB 243 (companion chatbots) |
Laws include requirements for developers of frontier AI models relating to safety and incident reporting, transparency regarding AI training data, disclosures and tools relating to AI-generated content, and safeguards for companion chatbots, particularly where minors are involved. |
SB 53, AB 2013 and SB 243 in effect SB 942 effective |
| NEW YORK | ||
| S 6453-A (RAISE Act) |
Focuses on developers of large, advanced AI models that could present significant public safety risks. Requires covered developers to maintain safety and security protocols, report certain serious incidents within 72 hours, and comply with related oversight and documentation requirements. | Effective Jan. 1, 2027 |
| CONNECTICUT | ||
| PA 26-15 | Broad AI statute that regulates frontier AI, companion chatbots, AI used in employment decisions, AI-content provenance and disclosure, and certain AI systems and online services used by or directed toward minors. | Staggered: Oct. 1, 2026 - Mar. 1, 2028 |
| COLORADO | ||
| SB 189 (ADMT Act, replacing the 2024 AI Act) |
Regulates automated decision-making technologies that process personal data and are used to materially influence consequential decisions about individuals, (e.g., employment, education, housing, financial services, insurance and healthcare). Imposes documentation and disclosure obligations on both developers and deployers, and give individuals certain rights following adverse decisions. | Effective Jan. 1, 2027 |
| TEXAS | ||
| HB 149 (TRAIGA) | Prohibits specified uses of AI that are considered harmful or unlawful, including uses involving manipulation, discrimination, unlawful surveillance and other identified misconduct. Also imposes disclosure requirements in some contexts and establishes enforcement mechanisms for violations. | In effect (Jan. 1, 2026) |
| UTAH | ||
| SB 149 | Primarily regulates how businesses use generative AI in interactions with consumers. Requires certain disclosures when consumers are interacting with AI, imposes additional obligations in regulated professions, and includes safeguards applicable to certain chatbot and consumer-facing AI applications. | In effect (May 2024) |
View other articles from this issue of The Informed Board
- It’s Time to Start Preparing for Congressional Investigations
- SEC Forms Beefed Up Enforcement Unit to Focus on Public Companies
- The SEC’s ‘Hands-Off’ Policy Alters the Calculus for Excluding Shareholder Proposals
- Director Interview: Preparing for the Crisis You Inevitably Can’t Anticipate
- Activism Update: Fewer Proxy Contests, More AI-Focused Themes
- Podcast: State AGs Step In Where They Think Feds Aren’t Doing Enough
- Delaware Court Reaffirms Deference to Directors in Risk Management Cases
See all the editions of The Informed Board
This memorandum is provided by Skadden, Arps, Slate, Meagher & Flom LLP and its affiliates for educational and informational purposes only and is not intended and should not be construed as legal advice. This memorandum is considered advertising under applicable state laws.
