AI Regulations Resource Hub
A practitioner reference to global AI regulation — US state laws, the EU AI Act, Singapore's IMDA framework for agentic AI, and NIST AI RMF — with applicability checklists, FAQs, and cross-framework control mappings.
Navigating the Fragmented Landscape of AI Regulation
AI regulation in 2026 is global, fragmented, and moving fast. The European Union has shipped the world’s first comprehensive binding AI law. The United States is operating under a patchwork of state statutes overlaid on the voluntary NIST AI Risk Management Framework. Singapore has just published the first government-issued governance framework dedicated specifically to agentic AI, and other Asia-Pacific regimes are following. The result is that any organisation deploying AI faces a stack of overlapping obligations rather than a single jurisdiction to satisfy.
For business and engineering leaders, the practical challenge is no longer "are we regulated?" — you almost certainly are, somewhere — but "which regimes apply to which of our AI systems, and how do we run one compliance programme that satisfies them all?" The risks are concrete: discrimination claims from algorithmic bias, prompt-injection breaches of agentic systems, undeclared AI use triggering consumer-protection enforcement, and — increasingly — vendor risk questionnaires that gate enterprise deals.
TrustEdge maintains this resource hub as a practitioner reference: state-by-state coverage of US AI legislation, plus the federal and international frameworks (NIST AI RMF, the Singapore Model AI Governance Framework for Agentic AI, the EU AI Act) that are converging into a shared global standard. Each framework page includes an applicability checklist, an FAQ, a control-mapping table, and quick-start steps so you can see at a glance how the framework intersects with your existing SOC 2, HIPAA, HITRUST, or ISO 42001 programme.
Whether you are a SaaS founder shipping LLM features, a healthcare administrator deploying clinical AI, or a compliance officer building an AI risk register, the goal is the same: move beyond compliance theater and operate AI systems that are transparent, accountable, and legally defensible across every regime that touches them.
Does federal action override any of this?
No. As of August 2, 2026, no federal statute preempts state AI law, and every obligation on this page remains operative.
Congress has twice declined to preempt. The ten-year moratorium on state AI enforcement written into the One Big Beautiful Bill Act was stripped by a 99–1 Senate vote, and a similar provision was left out of the annual defense authorization bill.
The pressure has moved to the executive branch instead.Executive Order 14365, signed December 11, 2025, directed the Attorney General to stand up an AI Litigation Task Force to challenge state AI laws in federal court. That task force was created on January 9, 2026, and has acted at least once — intervening in April 2026 in the industry challenge to Colorado’s AI Act. The Commerce Department evaluation of “onerous” state laws that the order required by March 11, 2026 has not been publicly released. The White House National Policy Framework for AI, published March 20, 2026, asks Congress to replace the state patchwork with a single federal standard; it is non-binding and creates no compliance obligation.
What this means for planning: preemption is being pursued through litigation and political pressure, not through enacted law. So far it has changed the position in exactly one state — Colorado, where a federal court stayed enforcement. A stay is not an invalidation, and it reaches no other jurisdiction. Build your compliance calendar against the statutes on this page, and treat federal preemption as a risk to monitor rather than a reason to wait.
Federal preemption status reviewed August 2, 2026. This section covers federal action only; each state entry carries its own review date.
State AI Regulations
States with enacted or proposed AI-specific legislation. Select a state to view detailed provisions, enforcement details, and compliance guidance.
California
California has more AI law in force than any other state. The rule most likely to reach you is not the frontier-AI headline act — it is an employment regulation that has bound every employer with five or more employees since October 1, 2025.
Colorado
The first-in-nation AI act was repealed and replaced before it ever took effect. Colorado now runs a narrower disclosure regime, and nothing is operative until 2027.
Connecticut
SB 2 never became law. Connecticut's AI statute is Public Act 26-15, signed May 27, 2026, and its first duties land October 1, 2026 — while amended privacy-law obligations on profiling are already in force.
Texas
TRAIGA has been in force since January 1, 2026, and it is intent-based. Liability turns on what you meant the system to do, not on what it did — the opposite of the Illinois standard.
New York
A frontier-model regime arriving January 1, 2027 under the Department of Financial Services, a state-agency AI statute already in force, and an NYC hiring-audit law that a State Comptroller audit found is barely being enforced.
Florida
Florida has no comprehensive AI statute. Two attempts at an AI Bill of Rights passed the Senate and died in the House. What exists is narrow: election deepfake disclaimers, a takedown duty for altered sexual imagery, and a privacy law that reaches almost nobody.
Illinois
The most demanding AI compliance regime in the United States — the only state requiring independent third-party audits of frontier AI, and an employment standard that turns on effect rather than intent.
Tennessee
No comprehensive AI statute. Instead a set of narrow, hard-edged laws — voice and likeness cloning, mental-health impersonation, political deepfakes — most of which carry a private right of action.
Utah
The first state AI law in the country, and narrower than almost every summary of it says. Utah amended its disclosure duty down in 2025 — most businesses now disclose only when a customer clearly asks.
Pennsylvania
No comprehensive AI statute. Two narrow criminal deepfake acts, an insurance notice, and a state-agency executive order — and an administration that is suing AI companies under laws written long before AI.
Virginia
Virginia has no comprehensive AI statute. HB 2094 was vetoed in 2025 and the veto was sustained. The real obligations run through the Consumer Data Protection Act, and its exemptions remove most healthcare and financial services entities outright.
Federal & International Frameworks
The voluntary and binding frameworks that, in combination, define the global AI governance baseline — NIST AI RMF (US federal voluntary), Singapore IMDA MGF for Agentic AI (voluntary, internationally influential), and the EU AI Act (binding law with extraterritorial reach).
NIST AI Risk Management Framework (AI RMF 1.0)
Voluntary federal framework for managing AI risks — increasingly referenced in state legislation.
Singapore Model AI Governance Framework for Agentic AI
The first government-issued framework specifically for autonomous AI agents — four dimensions for safe agentic deployment.
EU AI Act (Regulation 2024/1689)
The world's first comprehensive, binding AI law — now amended by the Digital Omnibus, which deferred the high-risk obligations to December 2027 and August 2028.
Other States
As of April 7, 2026, the following 37 states have not enacted AI-specific statutes, though many have introduced proposals or executive orders related to AI governance. We monitor these jurisdictions and will add coverage as legislation advances.
Enacted since this list was compiled — full coverage in progress
These states have AI statutes on the books but do not yet have a detail page here. We would rather name the gap than leave them in a list that says they have no statute.
- Washington — HB 2225 — companion chatbot disclosure, with a private right of action. Signed March 24, 2026 (Chapter 168, 2026 Laws). Effective January 1, 2027.
- New Jersey — A3497, the FAIR Act — ban on algorithmic rent-setting. Signed July 20, 2026 (P.L. 2026 c.43).
As of August 2, 2026. We are not lawyers and this is not legal advice. It is the responsibility of consumers of this data that they verify the applicability and current ratified statutes and legal precedence with a qualified attorney licensed in the state or country they are researching.
Need Help Navigating AI Compliance?
Our team helps organizations build compliance-first AI systems that meet current and emerging regulatory requirements.
