Tag: AI regulation

  • 109 Laws Later: The States Are Writing America’s AI Rulebook

    109 Laws Later: The States Are Writing America’s AI Rulebook

    With 109 state AI laws on the books at midyear and three big states setting a de facto national standard, the AI rulebook is being written in statehouses — and it reaches your organization through your vendors.


    The Center of Gravity Is the Statehouse

    Half a year into 2026, U.S. states have enacted 109 AI laws (plus 28 more governing data centers), according to TechPolicy.Press’s midyear review. And it’s not just volume — it’s weight. With Illinois signing its AI Safety Measures Act last week, three states — Illinois, California, and New York — now have frontier AI safety laws on the books, and together they represent roughly 40% of the U.S. AI market. Lawmakers are explicit about the strategy: in the absence of federal legislation, a handful of big states can set a de facto national standard, because no AI company builds a separate product for Illinois.

    The contrast with the rest of the world makes the moment sharper. In June, the EU actually delayed its AI Act’s toughest requirements to late 2027 and 2028, while Washington’s newest executive order focuses on federal capability and a cybersecurity clearinghouse rather than broad rules for the market. The center of gravity for AI regulation in America, at least for now, is the statehouse.


    The Patchwork Reaches You Through Three Doors

    You’re not an AI developer, so none of these laws regulate you directly — but the patchwork reaches you anyway. First, your vendors: as safety documentation, bias testing, and independent audits become legal requirements in big states, they become standard practice everywhere — which means you can (and should) start asking vendors for that documentation as a routine part of procurement. Second, your funders: as states normalize AI accountability, expect grant applications and board questions about how you govern AI internally. Third, your own footprint: if your nonprofit or business operates across state lines — remote staff, online programs, multi-state services — employment and automated-decision rules now genuinely differ by state, and it’s worth knowing which ones touch you.

    The strategic move isn’t to master 109 laws. It’s to build the one artifact every version of this future asks for: a simple, current inventory of the AI systems your organization uses and what decisions they touch. Every compliance regime, funder questionnaire, and board conversation starts from that list.


    If your state passed an AI transparency law tomorrow, could you list every AI tool your organization uses — and name the decisions each one touches?


    Where State AI Legislation Stands Half Way Into 2026 — TechPolicy.Press
    A clear-eyed midyear map of the state AI legislative landscape: what’s passed, what stalled, and where the momentum is heading for the second half of the year. Twenty minutes well spent if you want to understand the ground your vendors — and your organization — will be standing on in 2027.


    Follow Warren on LinkedIn for daily AI insights, nonprofit tech commentary, and strategy threads. If these weekly newsletters resonate, you’ll find more in the daily feed.

    Curated by Warren Wiggins · Created by Cousin Claude · Cousin’s AI Circulation, July 2026

  • The Rulebook Keeps Changing Before Anyone Has to Follow It


    The Rulebook Keeps Changing Before Anyone Has to Follow It

    Colorado repealed its toughest AI law before it ever took effect, and Congress floated preempting other states’ AI rules nationwide — proof that waiting for a stable rulebook is not a strategy.


    § The Trend

    The Rulebook Keeps Changing Before Anyone Has to Follow It

    Six weeks ago, Colorado’s AI Act (CAIA) was on track to become the country’s toughest state AI law, taking effect June 30, 2026 with mandatory risk-management policies, annual impact assessments, and consumer disclosures for “high-risk” AI systems. Then, on May 14, 2026, Governor Polis signed SB 26-189, repealing CAIA before it ever took effect and replacing it with the lighter CADMA — which drops the algorithmic-discrimination framework entirely and pushes its effective date to January 1, 2027 (Byte Back; Norton Rose Fulbright).

    While that was happening, Reps. Jay Obernolte (R-CA) and Lori Trahan (D-MA) released a 269-page bipartisan discussion draft of the Great American AI Act on June 4 — a federal framework that would preempt state laws “specifically regulating the development” of AI models for three years (Roll Call; TechPolicy.Press). Two different governments, two different directions, in the same six weeks: one state quietly stepped back from its own toughest AI law, while Congress floated wiping out other states’ versions of the same thing nationwide.


    § What It Means for Mission-Driven Orgs

    If you’ve been waiting for a stable AI compliance target before writing your own policy, this week is the proof that waiting doesn’t work. The rule that was supposed to bind Colorado deployers on June 30 doesn’t exist anymore — replaced by something weaker, effective six months later than planned. The federal proposal that might someday override other states’ rules is still a discussion draft, not law, and carries a sunset clause even if it passes. Nothing in this picture is settled, and nothing in this picture is going to settle soon.

    Meanwhile, the actors who aren’t waiting are the ones closest to the people they serve: Monday’s edition covered NYC Public Schools finalizing its own bias-and-equity review playbook for AI tools, regardless of what Colorado or Congress decide. That’s the model worth copying — not “wait for the law,” but “write the policy you’d want even if no law required it.” Your board, your funders, and your clients will ask about your AI practices long before any of this litigation settles, and “we’re tracking the legislation” is not an answer that holds up in a grant application.


    § Strategic Question of the Week

    If every state AI law you’re currently tracking could be repealed, replaced, or preempted within the next 12 months — as Colorado’s just was — what AI practices does your organization control internally, regardless of what regulators decide?

    If your honest answer is “none, we’re waiting to see what happens,” spend 30 minutes this weekend drafting the three rules you’d want followed even if no law existed: what data you’ll never feed into a model, what decisions a human must always make, and what you’ll disclose to the people affected.


    § Weekend Read

    “Unpacking the Great American Artificial Intelligence Act of 2026” — TechPolicy.Press’s plain-language breakdown of the GAAIA discussion draft’s four titles (Frontier AI Governance, Workforce, Cybersecurity, R&D) and the preemption fight at its center.

    It won’t tell you what the law will eventually say — nobody knows that yet. It will tell you which fights to watch for as the draft moves toward formal introduction.


    If your organization’s AI policy is currently “we’re watching what the states and Congress do” — that’s the most common answer I hear, and it’s the most exposed position to be in. If you want help drafting the three or four rules that are true regardless of how this legislative back-and-forth ends, I’m still running free 20-minute strategy sessions this month for nonprofit, school, and small-business leaders.


    Curated by Warren Wiggins · Created by Cousin Claude · Cousin’s AI Circulation, June 2026