Where your AI rules actually come from
Stop waiting for one federal AI law and build the short list of things every version of every rule already asks a small business to do.
on this page · 0 / 0 checked
You are not going to read a state AI bill. You have work, and the question underneath the headlines is narrow: what am I actually required to do, when does it start, and who is going to tell me. The common plan is to wait for a federal law that settles it and comply with that. It is a sensible plan, and it has been the plan long enough that it is worth noticing the thing being waited for keeps not arriving.
The clearest evidence for that is not a poll or an op-ed. It is that the two labs with the most riding on a single clear national rule both say they want one, and both are arguing in state legislatures in the meantime [3][4]. This guide is for a business of 1 to about 20 people with AI touching customer-facing or money-touching work: a support bot, a saved drafting prompt, an intake form that scores leads, an automation that writes to a client before anyone reads it. It is not for anyone training frontier models, who sits squarely inside these laws and already has counsel. It is not legal advice, and where a person’s job, health or money turns on an output, the answer is a lawyer rather than a guide.
Two labs, opposite bets, one shared premise
Anthropic set out its position when it endorsed California’s SB 53 on 8 September 2025. The company said frontier AI safety “is best addressed at the federal level instead of a patchwork of state regulations”, and then endorsed the state bill anyway, on the reasoning that AI advances “won’t wait for consensus in Washington” and that without a mandatory disclosure floor, labs “could face growing incentives to dial back their own safety and disclosure programs in order to compete” [3].
OpenAI published its position on 15 July 2026 and used nearly the same words about the destination with a different route to it. “A federal framework remains essential,” the company wrote, warning against “a patchwork of state laws that are difficult for regulators to enforce, confusing for consumers to navigate, and divert developer resources” [4]. It then said California, New York and Illinois “have advanced frontier safety legislation that helps move the country toward a common baseline”, and set out the three elements those laws share: a documented safety framework with risk assessments and public disclosure of the results, reporting of serious safety incidents, and governance through independent, objective audits [4].
Put those two side by side and the disagreement is narrower than the coverage suggests. One company wants states to keep raising the bar until Washington catches up. The other wants states to converge on a shared baseline that Washington can then adopt. Both say a federal framework is the right end state. Both are making their case in state legislatures because that is where rules are actually being written. When the two best-informed parties in an argument are both routing around Congress, a small business planning around Congress is planning around the least likely input.
The federal effort is real, and it is not a law. Executive Order 14365, signed 11 December 2025, says that state-by-state regulation “creates a patchwork of 50 different regulatory regimes that makes compliance more challenging, particularly for start-ups”, and directs the machinery of government to do something about it [1]. The Attorney General was given 30 days to establish an AI Litigation Task Force. Commerce was given 90 days to publish an evaluation of existing state AI laws, and told to issue a policy notice providing that states with onerous AI laws “are ineligible for non-deployment funds, to the maximum extent allowed by Federal law” under the Broadband Equity, Access, and Deployment programme. The Federal Trade Commission was given 90 days to issue a policy statement explaining “the circumstances under which State laws that require alterations to the truthful outputs of AI models are preempted”. The Federal Communications Commission was told to open a proceeding on whether to adopt a federal reporting and disclosure standard for AI models that preempts conflicting state laws. Senior officials were told to prepare a legislative recommendation for a uniform federal policy framework [1].
Look at what that list contains: lawsuits, funding leverage, and a request to Congress. The recommendation itself is barred from proposing preemption of otherwise lawful state laws on child safety, AI compute and data center infrastructure, and state government procurement and use of AI [1]. It is a strategy for producing a federal standard, which is a different object from a federal standard.
The number that describes your position is 109
As of 1 July 2026, states had enacted 109 AI laws and 28 data center laws, against 121 AI laws and 27 data center laws by the same date in 2025. Twenty-nine states enacted AI legislation in 2026, and 14 of those laws govern companion chatbots, out of more than 100 such bills introduced [8].
That is the shape of the thing. Not one statute with a commencement date you can put in a calendar, but dozens of narrow rules, each aimed at a specific practice, arriving on their own schedules in jurisdictions you may not have thought about. Which means the question “does AI regulation apply to me” has no answer. The question with an answer is whether any of those rules describes something you already do, and the fastest way to find out is to list what you do first.
The frontier-model laws are aimed at your vendor
The laws that generate headlines are aimed at model developers, and the obligations reflect that. OpenAI’s own summary of the common ground between the California, New York and Illinois laws names a documented safety framework with risk assessments, reporting of serious safety incidents, and independent audits [4]. Illinois added a requirement that covered companies arrange yearly audits of frontier models by third parties [8]. None of those are tasks a four-person company performs, and no amount of reading the bill text will produce one you should be doing.
They still reach you, one step removed. When your vendor has to publish a safety framework, report incidents to a state agency and open itself to outside auditors, the model’s behaviour and the terms attached to it change, and your product inherits the change without anyone asking you. That is a vendor-management problem rather than a compliance one. The useful habit is knowing which model each of your automations names, and having somewhere to go when that model behaves differently on a Tuesday.
Colorado is the argument against building for a named statute
Colorado passed an AI law in 2024. On 14 May 2026 the governor signed SB26-189, which “repeals and reenacts those provisions with new requirements regarding the use of automated decision-making technology in consequential decisions” [2]. Developer duties to notify deployers of material updates begin on 1 January 2027, and the attorney general has until that same date to adopt rules clarifying the post-adverse-outcome disclosure requirements [2]. Any small business that spent a quarter of 2025 building a programme against the text of the 2024 statute built it against a text that no longer exists.
The replacement is still worth reading, not because it binds you today but because of what it asks for. It covers decisions concerning “an individual’s access to, eligibility for, or compensation related to education, employment, housing, financial or lending services, insurance, health-care services, or essential government services and public benefits” [2]. Deployers, which is the category most readers of this guide fall into, must give consumers clear and conspicuous notice at the point of interaction, provide a plain-language description of the technology’s role within 30 days after a decision that results in an adverse outcome, honour requests to correct factually incorrect personal data, allow requests for meaningful human review and reconsideration, and retain records demonstrating compliance for at least 3 years [2]. Developers owe deployers technical documentation covering intended uses, categories of training data, known limitations and instructions for appropriate use [2].
Notice, explanation, human review, records. Hold that list. It is going to keep showing up.
Your vendors already imposed most of it
Now read the usage policy of whichever model your work sits on.
Anthropic’s Usage Policy, effective 15 September 2025, says that when its products are used “to provide advice, recommendations, or in subjective decision-making directly affecting individuals or consumers”, “a qualified professional in that field must review the content or decision prior to dissemination or finalization” [5]. Where those outputs go to individuals, you must disclose that you are using AI to help produce them, “at a minimum at the beginning of each session”, and a consumer-facing chatbot “must disclose to users that they are interacting with AI rather than a human” [5].
OpenAI’s usage policies, effective 29 October 2025, forbid the “automation of high-stakes decisions in sensitive areas without human review”, listing education, housing, employment, financial activities and credit, insurance, legal, medical and essential government services among them [6]. They separately forbid the “provision of tailored advice that requires a license, such as legal or medical advice, without appropriate involvement by a licensed professional” [6].
Two competitors drafted those independently and landed on the same floor: a human in the loop where it matters, and a disclosure that the counterparty is a machine. Unlike a bill, these have no commencement date to wait for, no preemption fight to survive and no revenue threshold to clear. They applied to your account the day you opened it. Enforcement is not a regulator with a docket either. Anthropic says that if it learns you have violated the policy it may “throttle, suspend, or terminate your access to our products and services”, and OpenAI says breaking its rules “may mean you lose access to our systems or experience other penalties” [5][6].
Where your customers are decides more than where you are
Article 50 of the EU AI Act applies from 2 August 2026 under Article 113 [7]. It requires that AI systems intended to interact directly with people be designed so that those people “are informed that they are interacting with an AI system”, unless that is obvious to a person who is “reasonably well-informed, observant and circumspect” [7]. It also requires deployers of a system that generates or manipulates text “published with the purpose of informing the public on matters of public interest” to disclose that the text was artificially generated or manipulated, with an exemption where the content “has undergone a process of human review or editorial control” and a person “holds editorial responsibility for the publication of the content” [7].
You do not need a European office for that to matter, and the exemption in the last sentence is earned by doing the review rather than by intending to. The same logic runs domestically. Where your business is registered is close to irrelevant. Where the people receiving your output are sitting is the thing that decides which rules describe you, and for most small operators selling online, that answer is a list rather than a place.
Build four things, not a policy binder
Start with an inventory, because nothing else works on a system nobody has written down. One row for every place an AI output reaches a person, moves money, or feeds a decision about someone. Name the tool, the model, and the person who owns it. Expect to find rows nobody would have called a system.
Second, put a disclosure at the front of every customer-facing session. Anthropic already requires it of consumer-facing chatbots [5], the EU AI Act requires systems that interact directly with people to be built so those people know it [7], and Colorado will require clear and conspicuous notice at the point of interaction [2]. It costs one sentence and it is the single requirement most likely to be in whatever law lands next.
Third, name a reviewer for the consequential rows and give that person one specific thing to look for. OpenAI forbids automating high-stakes decisions without human review, Anthropic requires a qualified professional to review such content before it goes out [5][6], and Colorado will let consumers request meaningful human review and reconsideration [2]. A reviewer who cannot say what they would have caught is a signature rather than a check.
Fourth, keep records. What ran, on which model, who reviewed it, and enough of a trail that you could produce a plain-language explanation of a decision within 30 days of an adverse outcome [2]. Three years is the retention figure Colorado sets for records demonstrating compliance [2].
Touchpoints × minutes each. Computed in the page; nothing is sent anywhere.
If that number is under a day, the argument for waiting to see which way the regulation fight goes has nothing left in it.
What still goes wrong
Every date, quotation and figure above was read from its source on 5 September 2026, and this is the fastest-moving area covered on this site. Executive Order 14365 set 30 and 90 day clocks running in December 2025 [1], Colorado repealed and reenacted its AI law in May 2026 with attorney general rulemaking still due [2], and the two vendor policies quoted here carry effective dates of September and October 2025 [5][6]. Treat all of it as a snapshot to re-check rather than a standing fact.
The four things do not make you compliant with any particular statute, and it would be dishonest to suggest otherwise. They make the gap small and the catch-up cheap, which is a different claim and the only one available when the rules are being drafted in 50 places at once. If you make automated decisions about people at any real scale, in hiring, lending, insurance, housing or health, this is not enough and was never going to be. That is the category every one of these laws was written for, and it is the category where the fine is real.
The deeper problem is that none of this tells you whether the outputs are any good. Disclosure, review and records establish that somebody was supposed to be looking. They do not make a fluent, confident, wrong answer any less fluent, and a reviewer who agrees with the model is not oversight. The regulation fight will resolve one way or another and that limitation will survive it unchanged.
- 01Executive Order 14365 — Ensuring a National Policy Framework for Artificial Intelligencefederalregister.gov
- 02Colorado General Assembly — SB26-189, Automated Decision-Making Technologyleg.colorado.gov
- 03Anthropic — Anthropic is endorsing SB 53anthropic.com
- 04OpenAI — The US is advancing AI safety through state and federal actionopenai.com
- 05Anthropic — Usage Policyanthropic.com
- 06OpenAI — Usage policiesopenai.com
- 07EU AI Act, Article 50 — Transparency obligations (Regulation (EU) 2024/1689 text)artificialintelligenceact.eu
- 08Tech Policy Press — Where State AI Legislation Stands Half Way Into 2026techpolicy.press