Jan 15, 2026 · View original article
New US State AI Laws Take Effect as Federal Order Targets Them for Preemption
California's frontier-AI transparency law and Texas's AI governance act took effect on 1 January 2026, even as Executive Order 14365 set 90-day deadlines for federal action against 'onerous' state rules.
The start of 2026 delivered a contradictory picture of AI regulation in the United States. On 1 January, several significant state laws took effect. California's Transparency in Frontier Artificial Intelligence Act requires developers above a revenue threshold of roughly 500 million dollars to publish a frontier AI framework covering catastrophic risks and to maintain critical safety-incident procedures. Texas's Responsible Artificial Intelligence Governance Act prohibits building or deploying AI for a set of restricted purposes, including unlawful discrimination and certain deepfakes, and offers an affirmative defence to organisations that follow recognised risk-management frameworks. California also brought in rules on training-data disclosure, healthcare AI disclosures and companion-chatbot safety, while Illinois amended its employment law to address discriminatory AI use. Colorado's broader algorithmic-discrimination statute was pushed to 30 June 2026.
At the same time, a presidential executive order signed on 11 December 2025, numbered 14365 and titled "Ensuring a National Policy Framework for Artificial Intelligence," set the federal government on a course to challenge those very laws. Law-firm analyses published in mid-January 2026 summarised its mechanics: the Attorney General must establish an AI litigation task force within 30 days; within 90 days the Commerce Secretary must identify "onerous" state laws for referral, the FTC must issue a policy statement on how consumer-protection law applies to AI models, and the FCC must open proceedings on a federal reporting standard. Agencies may condition federal funding on states' alignment with the federal framework, and officials are directed to propose preemptive legislation. Child safety, AI infrastructure and state procurement are carved out.
The result is legal uncertainty rather than deregulation. An executive order cannot itself preempt state statutes; only Congress or the courts can do that, and no federal AI law exists. Until litigation or legislation resolves the conflict, the state laws are in force and enforceable. Companies operating in California or Texas therefore face binding obligations today, with a possibility, not a certainty, that some will be struck down later.
This mirrors a pattern seen in privacy law, where a patchwork of state statutes persisted for years while federal preemption was debated. The practical difference is that the affirmative-defence structure in Texas explicitly rewards adoption of frameworks such as the NIST AI RMF, giving governance programmes a concrete legal payoff.
What it means for leaders
- Comply with state law as written. Executive-branch intent does not suspend statutory duties; build to the strictest applicable state standard and adjust if courts rule otherwise.
- Use recognised frameworks as legal shields. Texas offers an affirmative defence for organisations following the NIST AI RMF or comparable standards; ISO/IEC 42001 certification strengthens that position.
- Frontier developers should formalise incident management. California's requirement for critical safety-incident procedures overlaps with EU AI Act serious-incident reporting; design one process that satisfies both.
- Track the 90-day federal milestones. Commerce, FTC and FCC actions due by mid-March 2026 will indicate which state provisions are most at risk of challenge.
- Brief the board on jurisdictional divergence. Multi-state and transatlantic operations need a single control set mapped to several regimes, not separate compliance silos.
