State AI Transparency Laws in 2026: Which Disclosure Rules Actually Apply to Companies That Deploy AI

State AI Transparency Laws in 2026: Which Disclosure Rules Actually Apply to Companies That Deploy AI

Most 2026 state AI transparency laws regulate frontier developers, not businesses deploying AI. Here's which disclosure duties actually apply to you.

Most of These Laws Are Not About You — But Four of Them Are

If you run operations or compliance at a manufacturer or a consulting firm and you’ve been reading headlines about state AI transparency laws, you’ve probably absorbed two things: California passed something big, and the penalties run into the millions. Both are true. Neither tells you what your company has to do.

Here is the distinction the coverage keeps blurring. The headline laws — California’s SB 53 and New York’s RAISE Act — regulate companies that build frontier AI models. SB 53 applies to developers training models at more than 10^26 floating-point operations, with the heaviest duties reserved for developers whose annual gross revenue exceeds $500 million (CA SB 53, Gov. Code, signed September 29, 2025). That is a handful of companies on the planet. If your AI footprint is ChatGPT or Claude licenses, an AI-enabled EHS platform, a chatbot on your website, and a resume-screening tool inside your applicant tracking system, you are a deployer — and SB 53 and the RAISE Act impose exactly zero obligations on you.

The laws that do reach deployers are quieter, and three of them took effect on January 1, 2026. As of today, a company deploying AI tools needs to answer for the Texas Responsible Artificial Intelligence Governance Act, Illinois’ amendment to its Human Rights Act, Utah’s AI Policy Act, and — in one specific fine-tuning scenario — California’s training data disclosure law. That’s the working list. Everything else is either a frontier-developer law, a law that hasn’t taken effect, or a law that a state legislature is actively shrinking.

This post sorts the 2026 state AI disclosure landscape into those buckets, with effective dates and penalty figures from primary sources — and covers the federal preemption campaign that may redraw the whole map.

What Do the Frontier Laws Require — and Why Don’t They Apply to Deployers?

California’s SB 53, the Transparency in Frontier Artificial Intelligence Act, took effect January 1, 2026. It requires frontier developers to publish a frontier AI framework, issue transparency reports when releasing new models, and report critical safety incidents to the California Office of Emergency Services, with whistleblower protections layered on top. Civil penalties run up to $1 million per violation, enforced by the Attorney General (SB 53, 2025–26 Reg. Sess.; Governor’s signing announcement, September 29, 2025).

New York’s RAISE Act follows the same architecture. Governor Hochul signed S6953-B on December 19, 2025, and a chapter amendment finalized on March 27, 2026 brought it largely in line with California’s framework — with a notably tighter 72-hour critical-incident reporting window versus California’s 15 days. Penalties were cut in the amendment process from $10 million/$30 million down to $1 million for a first violation and $3 million for repeats, and the law takes effect in 2027 (S6953-B/A6453-B; chapter amendment, March 27, 2026).

Both statutes define their covered universe by training compute and developer revenue. Buying, licensing, integrating, or even white-labeling AI does not put you in it. The practical takeaway for an ops leader: when your board asks “are we exposed under the California AI law?”, the precise answer is “not under SB 53 — our exposure is in Texas, Illinois, and Utah, and here’s what we’ve done about it.” That answer signals you’ve actually read the statutes.

Which State AI Laws Apply to Businesses Deploying AI in 2026?

Texas — TRAIGA (HB 149), effective January 1, 2026. This is the one with no size floor. TRAIGA applies to every developer and deployer doing business in Texas (HB 149, 89th Leg., signed June 2025). Its core is a set of prohibited purposes — AI developed or deployed to intentionally discriminate, manipulate users toward self-harm or criminal conduct, or infringe constitutional rights — plus disclosure duties when consumers interact with AI in government and healthcare contexts. Enforcement sits exclusively with the Attorney General: a 60-day cure period after written notice, then penalties of $10,000–$12,000 per curable violation, $80,000–$200,000 per uncurable violation, and $2,000–$40,000 per day for continuing violations. Two features matter operationally. First, the AG can issue a civil investigative demand on the basis of a single complaint — your documentation needs to be producible, not theoretical. Second, TRAIGA makes alignment with the NIST AI Risk Management Framework an affirmative defense. That turns a voluntary federal framework into the cheapest insurance available under the statute: a documented NIST AI RMF-aligned governance program is the difference between a cure letter and a penalty action.

Illinois — HB 3773, effective January 1, 2026. Illinois amended its Human Rights Act to prohibit employers from using AI that has the effect of discriminating against protected classes in recruitment, hiring, promotion, discharge, discipline, training selection, or terms and conditions of employment — and to require notice to employees and applicants when AI is used in those decisions (HB 3773, 103rd Gen. Assem., 2024). Using zip codes as a proxy for protected classes is expressly banned. The trap here is vendor software: IDHR’s proposed rules read notice as required when AI is used “to influence or facilitate” an employment decision — which captures the AI ranking features inside your ATS whether or not anyone at your company thinks of them as “using AI.” Note the procedural wrinkle: IDHR temporarily withdrew those proposed rules on June 2, 2026 for interagency collaboration, with no revised timeline — but the statutory notice obligation took effect January 1 and applies regardless. If you have Illinois employees or applicants and you have not asked your HR-tech vendors what AI sits inside their products, you have a live notice obligation with no agency guidance to lean on.

Utah — AI Policy Act (SB 149, 2024, as amended 2025). Utah’s law has been in effect since May 1, 2024, making it the oldest deployer-disclosure statute on the books. As narrowed by SB 226 and SB 332 in 2025, the rule is: any business using generative AI in consumer interactions must disclose it when a consumer clearly and unambiguously asks; licensed professionals — healthcare, legal, financial — must disclose prominently and proactively in high-risk interactions involving sensitive data or consequential advice (SB 149, 2024 Gen. Sess.; SB 226, 2025 Gen. Sess.). Penalties are modest by comparison — up to $2,500 per violation administratively, $5,000 per violation in court actions — but the compliance lift is also modest: script the chatbot to answer the question honestly, and train regulated staff to disclose up front.

California — AB 2013, the fine-tuning trap, effective January 1, 2026. AB 2013 requires developers of generative AI systems made publicly available in California to post a high-level summary of training data across 12 enumerated categories (AB 2013, 2023–24 Reg. Sess.). A pure deployer is out of scope — but the statute pulls in anyone who “substantially modifies” a system, including retraining or fine-tuning that materially changes functionality. A company that fine-tunes a model on its own data and offers the result publicly can become a “developer” with disclosure duties it never planned for. A federal district court has already upheld the law against constitutional challenge, so it is not going away on its own. If your roadmap includes fine-tuned customer-facing models, this belongs in the build review.

What Changed in Colorado — and Why You Shouldn’t Build to a Repealed Law

Colorado is the cautionary tale for over-building. The Colorado AI Act (SB 24-205) was the first comprehensive state framework, originally requiring deployers of high-risk AI systems to run risk management programs, conduct impact assessments, and report to the Attorney General — effective February 1, 2026. Then the schedule and the substance both collapsed. A special-session bill (SB 25B-004, signed August 28, 2025) pushed the effective date to June 30, 2026. Then SB 26-189, signed May 14, 2026, pushed it again to January 1, 2027 — and eliminated the algorithmic-discrimination duty of care, the deployer risk management program requirement, the impact assessments, and the AG reporting obligations, leaving a narrower disclosure framework for automated decision-making technologies (SB 24-205; SB 25B-004; SB 26-189, leg.colorado.gov).

Any company that spent late 2025 building Colorado impact-assessment machinery bought obligations that never arrived. That is the operational lesson of this whole landscape: comply with what is in effect, build durable basics for what is coming, and do not construct programs around statutes that are still moving.

The Counter-Signal: Washington Is Suing the States

There is a credible case that some of this map gets redrawn, and you should hear it straight.

On December 11, 2025, the White House issued an executive order — “Ensuring a National Policy Framework for Artificial Intelligence” — directing a coordinated federal campaign against state AI laws (whitehouse.gov, December 11, 2025). The order instructed the Attorney General to stand up an AI Litigation Task Force, which the Department of Justice established on January 9, 2026, with the sole mission of challenging state AI laws as unconstitutional burdens on interstate commerce or as federally preempted (DOJ AG memorandum, January 9, 2026). The order also set in motion an FCC proceeding on a federal AI disclosure standard that could preempt state regimes, an FTC policy statement, and a review of federal funding conditions for states with “onerous” AI laws — with carve-outs preserving state authority over children’s safety, compute infrastructure, and state procurement.

The campaign is past the memo stage. On April 9, 2026, xAI sued the Colorado Attorney General to block the Colorado AI Act, and DOJ intervened with its own complaint arguing the law violates the Equal Protection Clause (xAI v. Weiser, D. Colo.; DOJ intervention April 2026). An April 24, 2026 stipulation temporarily stays enforcement of the Colorado AI Act while the case proceeds. The outcome will shape every state algorithmic-discrimination framework in the country.

So why comply at all? Three reasons. First, the laws in effect today — TRAIGA, Illinois HB 3773, Utah’s AI Policy Act, AB 2013 — are enforceable today, and no court has enjoined any of them. Second, the litigation targets the contested frameworks first; a notice posted to Illinois job applicants or a chatbot disclosure in Utah is not the kind of obligation a preemption ruling rescues you from retroactively. Third, even where AI-specific statutes fall, general law reaches AI conduct anyway: on May 5, 2026, Pennsylvania sued Character.AI over AI bots making false medical claims — the first state enforcement action of its kind, built on unlicensed-practice and consumer-protection theories, not an AI statute (pa.gov, May 2026). Forty-two state attorneys general have already signed a joint letter demanding AI safeguards. “Our state has no AI law” is not a safe harbor, and neither is “the EO will sort it out.”

What Should a Deployer Actually Do Before Year-End?

The durable program — the one that survives both the enforcement wave and the preemption wave — is short:

  1. Inventory every AI touchpoint. Customer-facing, employee-facing, and embedded in vendor tools. Every state obligation starts with knowing where AI influences a consumer interaction, an employment decision, or a consequential outcome. Vendor AI counts.
  2. Screen against TRAIGA if you touch Texas. Document the intent and design of each AI use case against the prohibited purposes, and align governance with the NIST AI RMF to hold the affirmative defense.
  3. Fix the Illinois HR gap. Get written answers from HR-tech vendors on AI components, then issue the required notice to employees and applicants. Comply with the statute’s own text — IDHR withdrew its proposed rules on June 2, 2026 with no revised timeline, so there are no agency rules to wait for.
  4. Script the disclosures. Utah-style answer-when-asked language for consumer-facing AI; proactive disclosure for any licensed-professional interaction.
  5. Check the AB 2013 trap before any fine-tuned model goes public.
  6. Document everything. The AG enforcement model in Texas, California, and Colorado runs on what you can produce within a cure window — 60 days in Texas. A program that exists only in practice, not on paper, does not exist for enforcement purposes.

None of this requires slowing down AI adoption. It requires knowing which of a dozen loud statutes actually name you — four do — and being able to prove the basics when an AG inquiry letter shows up.

iSi’s AI compliance services cover exactly this scope for EHS firms, manufacturers, and producers: AI compliance setup mapped to the state laws that actually apply to your footprint, independent audits of your AI use inventory and disclosure practices, and periodic spot checks as the statutes — and the litigation — keep moving. If your AI tool list has grown faster than your documentation of it, that gap is closable in weeks, not quarters. Talk to us about where your state exposure actually sits.


Sources