← Front Page
AI Daily
AI Policy • Friday, 07 August 2026

Fifty States, Fifty Rulebooks

By AI Daily Editorial • Friday, 07 August 2026

Somewhere in a compliance office this week, a lawyer is trying to draw a single map of American AI regulation and failing. In California, a new law took effect that forces large AI companies to stamp generated photos, audio and video with metadata that is hard to remove, so a viewer can run the file through a verifier and see whether it is real. State Senator Josh Becker calls it a nutrition label for the internet, the first transparency rule of its kind, with further stages arriving in 2027 and 2028. In Colorado, the direction of travel is the opposite. The state that in 2024 passed the country's first comprehensive AI law has just repealed it and replaced it with a slimmer version, trading proactive risk assessments for lighter disclosure duties before the original ever took effect.

Those two moves capture a country regulating AI in every direction at once. Illinois in July became the third state, after New York and California, to pass a frontier-model safety law, and the first anywhere to require independent third-party audits of AI safety practices, with penalties running from one to three million dollars. But the audit requirement does not bite until 2028, and it applies only to the largest developers, those with revenue above half a billion dollars training the most compute-intensive models. Connecticut, meanwhile, has taken a narrower path aimed at hiring tools and chatbots. Layer these together and the definitions conflict, the deadlines stagger across three years, and a mid-sized company can be a regulated "deployer" in one state and untouched in the next.

The genuinely hard part is that most firms think none of this applies to them, and most are wrong. Auditors describe walking into companies that build no AI of their own, then finding a resume-screening tool, a chatbot handling billing disputes, and a credit-scoring system already running, each one making decisions about employment or credit that several states now regulate. The obligation attaches to using AI, not just building it. Yet these organisations typically hold nothing but a vendor questionnaire and a contract, no real evidence of how the systems were validated. It echoes cloud computing around 2010, when buyers first asked suppliers "how do you know it is secure," and independent attestation slowly became a condition of doing business, driven by procurement rather than by any statute.

Then there is Washington, pulling hard the other way. The Trump administration has treated aggressive AI regulation as a threat to competitiveness, and a December executive order directed federal agencies to actively contest state AI laws. Colorado's original act was even enjoined by a federal court before the legislature rewrote it. Just weeks after Colorado's revision, the Federal Trade Commission floated a policy statement warning that some state AI laws, Colorado's included, could themselves create deception concerns under federal consumer-protection rules. The message to companies is contradictory: comply with a thickening patchwork of state mandates, while the federal government signals it may try to knock several of them down.

It is tempting to read the preemption fight as permission to wait. That is the trap. Court rulings can strike a regulation, but they cannot strike a customer's expectations, and the through-line across every one of these laws points the same way: disclosure first, then transparency, and eventually independent verification. A frontier developer facing audits in 2028 is only the leading edge. The recruiting tool quietly rejecting applicants is the part most companies have not noticed they already own. The regulatory map may stay a mess for years, but the direction it is drawing is not actually in doubt.

Sources