Passing an AI law turns out to be the easy part. In April 2026, the states that led on AI regulation are quietly revising the provisions companies found most burdensome, while hundreds more AI bills work their way through state legislatures.

A survey of the regulatory landscape by law firm Cooley, published April 24, found that Colorado, California, New York, and Utah have all substantially revised their original AI frameworks. The pattern is consistent across jurisdictions: formal risk assessment requirements are being scaled back, the definition of "high-risk AI" is being narrowed to exclude routine business processes, and annual compliance reviews are being eliminated or delayed.

Colorado's SB 205, initially one of the more ambitious state AI frameworks in the country, has been revised to narrow what counts as high-risk automated decision-making. New York's RAISE Act, signed in amended form by Governor Hochul in March 2026, moved away from direct liability toward a transparency and reporting framework, requiring companies to document their AI governance approaches rather than comply with specific outcome standards. Utah's AI Policy Act has been scaled back through subsequent legislative amendments.

This is not entirely a story of industry lobbying winning the day, though that played a role. States are also drawing lessons from the EU's experience with the AI Act, which ran into practical obstacles with compliance timelines and definitional ambiguities. Broad prescriptive frameworks are hard to enforce, and they can suppress innovation in ways regulators did not intend.

The pace of new AI legislation is not slowing, however. Advocacy organization Plural Policy tracked 19 AI bills signed into law in April 2026 alone, covering deepfake disclosures in Tennessee, AI companion platform rules in Oregon, chatbot transparency requirements in Washington state, and AI use restrictions in health insurance pre-authorization in Utah. Over 600 AI bills have been introduced across state legislatures in 2026 so far, according to tracking by Troutman Pepper.

The bigger threat to all of this is federal preemption. The Trump administration's National Policy Framework for AI, released in March, recommends that Congress preempt state AI laws that "impose undue burdens" on AI development. The Department of Justice established an AI Litigation Task Force in January with a mandate to challenge state laws the Attorney General deems unconstitutional or otherwise unlawful. That is an active enforcement posture, not a hypothetical one.

What this creates is a moving target for anyone building AI compliance programs. The laws are being revised faster than they can be implemented, under the shadow of potential federal preemption that could void large portions of them. The Cooley analysis notes that despite some laws already taking effect, actual enforcement activity is minimal.

The messy revision process might, in the end, produce better regulation. The first wave of state AI legislation was written before anyone had much experience governing AI in practice. The revised frameworks reflect what regulators actually learned. Whether Congress preempts most of it before it matures is the open question nobody can answer yet.

Sources

  1. i. www.cooley.com
  2. ii. pluralpolicy.com
  3. iii. www.troutmanprivacy.com
  4. iv. www.governor.ny.gov

Commentarii · 0

Add · a · Comment