Colorado Retreats, California Surges: Inside America’s Fractured AI Law Patchwork

0

With Congress still unable to pass comprehensive AI legislation, states are writing the real rules — and in 2026 they are writing very different ones. Colorado just narrowed its landmark law; California just went further than any state before it.

Eighteen months ago, Colorado looked like the state that would define American AI regulation. Its 2024 law targeting “high-risk” artificial intelligence systems was the country’s first comprehensive attempt to govern AI the way the EU had, through broad risk-management duties and an affirmative obligation to prevent algorithmic discrimination. In 2026, that law is gone. In its place sits a narrower statute, born out of litigation, industry pressure and a legislature that ultimately concluded its own creation had gone further than it could defend.

How Colorado’s flagship law collapsed

The Colorado AI Act, formally SB 24-205, was supposed to become enforceable on June 30, 2026, after an earlier delay from its original February start date. It never got the chance. On April 27, a federal court in Colorado granted a joint motion staying enforcement while litigation over the law’s scope played out, freezing it just weeks before it was due to take effect.

Rather than fight to preserve the original text, Governor Jared Polis signed a replacement on May 14: the Automated Decision-Making Technology Act, known as SB 26-189. The contrast between the two laws is stark. The original act regulated any “high-risk artificial intelligence system” used in a consequential decision and imposed a freestanding duty on developers and deployers to prevent algorithmic discrimination, on top of risk-management programs, mandatory impact assessments and detailed consumer disclosures. The replacement drops the “high-risk AI” framing entirely, narrows the scope to automated decision-making technology that materially influences a defined set of consequential decisions, and eliminates the standalone anti-discrimination duty in favor of simply applying Colorado’s existing anti-discrimination statutes to automated systems.

Enforcement authority stays with the state attorney general, but the new law adds a 90-day notice-and-cure period before penalties can be pursued, and it draws a clearer line between developer and deployer liability than the original ever did. It takes effect January 1, 2027 — and even then, only once the attorney general finishes the rulemaking the statute requires.

The retreat did not happen in a vacuum. It followed a federal push against state-level AI rules generally, with the current administration arguing that laws imposing algorithmic-discrimination duties on developers threaten American AI competitiveness and improperly embed race- and sex-conscious mandates into product design. An executive order directed the Federal Trade Commission to issue guidance by March 11 on how existing federal deceptive-practices law interacts with, and potentially preempts, state AI statutes — though notably, the order carved out child-safety regulation, AI compute and data-center infrastructure, and government procurement as areas it would not attempt to preempt. No formal federal preemption has actually passed Congress; the fight over whether state AI laws can survive a hostile federal posture is, as of this summer, still being fought in the courts rather than settled by statute.

California takes the opposite path

While Colorado was narrowing its ambitions, California spent 2026 doing the reverse — layering on more AI-specific statutes than any other state has attempted. Several took effect January 1, and one of the most consequential, the California AI Transparency Act (SB 942), becomes fully operative on August 2, after its own delay from an original January start date. It requires large AI platforms to provide free, publicly accessible AI-content detection tools and to embed both visible and invisible watermarks in AI-generated media.

California has paired that transparency mandate with a cluster of narrower, purpose-built statutes. AB 489 bars AI systems from falsely implying they hold a healthcare license and requires clear disclosure whenever AI is communicating directly with a patient. AB 325 updates the state’s Cartwright antitrust act to explicitly prohibit shared or common pricing algorithms that let competitors coordinate prices without ever picking up a phone. And SB 243, the Companion Chatbot Act, requires AI companion products to disclose their non-human nature, mandates safety protocols for detecting expressions of self-harm or suicidal ideation, and imposes content limits and break reminders specifically for minor users.

The state’s political trajectory suggests this is a floor, not a ceiling. In early May, gubernatorial candidate Xavier Becerra released an eleven-point AI policy platform explicitly positioning California as what he called the “gold standard” for AI governance, framed in direct opposition to what he described as the federal government’s abdication of AI oversight. Whatever one makes of the framing, it signals that California’s appetite for AI-specific statute writing is not slowing down heading into the next election cycle.

Connecticut’s omnibus approach

Sitting between Colorado’s retreat and California’s expansion is Connecticut, which took a third approach entirely: a single, broad omnibus package covering multiple facets of AI governance at once. SB 5 bundles new employment-related AI obligations, chatbot safety rules, synthetic-content labeling requirements, a safe-harbor compliance program, and anti-discrimination provisions into one statute, each with its own effective date and compliance mechanics. Rather than picking one narrow use case the way Colorado’s replacement law does, or stacking separate single-issue bills the way California has, Connecticut’s lawmakers bet that a single comprehensive framework would be more durable — and more defensible in court — than a patchwork of overlapping single-purpose statutes.

What the patchwork means for anyone actually building or deploying AI

For a compliance team operating nationally, the practical consequence of 2026’s divergence is that “complying with state AI law” has stopped being a meaningful single task. A hiring algorithm deployed in Colorado, California and Connecticut simultaneously is now subject to three different legal theories of what makes automated decision-making dangerous, three different disclosure regimes, and three different enforcement postures — one narrowed by litigation and legislative retreat, one expanding through a swarm of targeted statutes, and one consolidated into an omnibus framework.

Legal observers tracking the broader landscape note that documentation has become the one constant across nearly every current and proposed state AI law, regardless of which philosophical camp it falls into: risk assessments, bias-testing results, impact evaluations and governance records show up as requirements again and again, even as the underlying legal theory for why they are required varies enormously state to state. Organizations that build a single, rigorous internal documentation practice — rather than trying to satisfy each state’s statute as a separate, bespoke compliance project — are best positioned to adapt as more states, inevitably, follow Colorado, California or Connecticut’s lead over the next year.

What is unlikely to happen any time soon is federal resolution. With no comprehensive AI statute anywhere near passage in Congress, and the executive branch relying on orders and procurement policy rather than legislation to shape the field, the state layer is where binding AI obligations for private companies actually live in the United States right now — and where they will keep living, for the foreseeable future, in fifty different and diverging forms.

The preemption fight nobody has resolved

Underneath all of this sits an unresolved constitutional and political question: can the federal government simply override state AI laws by executive order, or does it require an act of Congress? So far, the answer has been neither clean nor final. The executive order directing the FTC to study preemption stopped well short of actually preempting anything by itself — it directed the agency to produce a policy statement describing how existing federal deceptive-practices law interacts with state AI statutes, which is a very different thing from a binding preemption rule. Legal challenges to individual state laws, like the one that froze Colorado’s original act, have so far been fought on narrower statutory and constitutional grounds specific to each law, not on a sweeping theory that state AI regulation is categorically preempted by federal authority.

That leaves courts, rather than either Congress or the White House, as the actual arena where the boundaries of state AI authority are being drawn in 2026. Multiple state AI laws — in California, Colorado, Illinois and Texas among them — remain live candidates for further litigation testing exactly how far a state can go in regulating a technology that, by its nature, operates across state lines instantly and by default. Until an appellate court, or Congress itself, definitively answers the preemption question, every new state AI statute will be drafted, at least in part, as a bet on how it might eventually survive a federal challenge — which helps explain why Colorado’s replacement law is so much narrower and more procedurally cautious than its predecessor.

What comes next

Watch three things over the remainder of 2026: whether Colorado’s attorney general completes the rulemaking SB 26-189 requires before its January 2027 effective date; whether California layers on any additional AI-specific statutes as the state’s next election cycle heats up; and whether the Senate takes up anything resembling comprehensive federal AI legislation before year’s end. None of the three outcomes is likely to resolve the underlying fragmentation on its own — but each will meaningfully shift which state’s approach other legislatures choose to copy next.

For multistate employers and platforms, the pragmatic response has been to build compliance programs around the strictest applicable standard in any state where they operate, rather than maintaining fifty separate playbooks. That approach is imperfect — a program built for California’s transparency-heavy regime does not automatically satisfy Connecticut’s employment-specific provisions, and neither maps cleanly onto Colorado’s narrower ADMT framework — but it has emerged as the closest thing to a workable default in a legal landscape where no single national standard exists, and where none appears imminent.

Leave a Reply

Your email address will not be published. Required fields are marked *