Congress has not passed comprehensive federal AI legislation. That gap is not stopping the states.
In 2025 and into 2026, legislatures across the country introduced and in several cases enacted laws governing artificial intelligence in employment, healthcare, consumer transactions, and high-stakes automated decision-making. For businesses operating across state lines, the result is a compliance environment that increasingly resembles what emerged after the early wave of state data privacy laws — complex, inconsistent, and fast-moving.
The Landscape by Category
Employment and Hiring
Several states have enacted or are advancing laws that restrict the use of AI in employment decisions — particularly screening, promotion, and termination. Key requirements typically include:
- Bias audits conducted by independent third parties before deployment
- Disclosure obligations notifying applicants or employees when AI is used
- Opt-out rights or rights to human review of automated decisions
Colorado's AI Act (SB 205, signed 2024) is the broadest enacted state law to date, applying to "high-risk" AI systems used in employment, education, housing, and financial services. It requires developers and deployers to use reasonable care to protect consumers from algorithmic discrimination and to conduct annual impact assessments.
Healthcare
AI used in clinical decision support, prior authorization, and patient triage is drawing regulatory attention from both state legislatures and state insurance commissioners. The common thread: requirements for human oversight, transparency about when AI is involved, and liability clarity when AI recommendations contribute to adverse outcomes.
Consumer-Facing AI
Several states are moving on requirements for disclosure when consumers are interacting with AI rather than humans — particularly in customer service contexts. Others are targeting generative AI output, requiring watermarking or disclosure of synthetic content.
The Federal Wildcard
The absence of a federal framework leaves two scenarios in play:
- The patchwork continues to grow, with each state adding its own requirements, and businesses managing a growing matrix of state-by-state compliance obligations.
- Federal preemption arrives, either through legislation or through aggressive use of existing federal authority (FTC, EEOC, CFPB) to establish de facto national standards that supersede state laws.
Both scenarios have precedent. Both are worth planning for.
What Businesses Should Do Now
- Map your AI use cases against the states where you operate and the categories of law (employment, healthcare, consumer) that are most active.
- Review your vendor contracts — many AI compliance obligations fall on the deployer, not the developer, but liability can shift depending on how contracts are written.
- Engage in state comment processes while laws are still being drafted. State legislative staff are more accessible than federal regulators, and early input shapes outcomes.
Evergreen Policy Lab tracks state and federal AI legislation as part of our Technology coverage. We'll continue updating this tracker as new laws are enacted or amended. Contact us if you need a state-specific analysis for your operations.
