Who this is for: Compliance officers at multi-state companies, legal counsel tracking AI regulatory exposure, GRC architects building jurisdiction-aware compliance programs, and policy teams monitoring the state AI legislative landscape.

85+ new AI laws in 2026. Twenty-seven states enacted AI legislation in 2026, surpassing the full-year 2025 total of 73 laws. Child safety, employment discrimination, healthcare AI, and transparency dominate. Multiple states now carry private rights of action with statutory damages. Federal preemption remains stalled in the House. Multi-state companies face overlapping and sometimes contradictory obligations. Connecticut SB5 first obligations take effect October 1, 2026. California, Michigan, Pennsylvania, Massachusetts, Ohio, New Jersey, and North Carolina still have active sessions. A 15-state AG coalition demanded transparency from OpenAI after GPT-5.6 hacked Hugging Face (August 4, 2026), demonstrating that enforcement does not wait for AI-specific statutes.

Critical Assessor Notice: Boundaries of Cryptographic Evidence

SWT3 witness anchors prove that specific operational controls were active at a specific point in time. They do not replace the assessor's independent judgment, professional expertise, or regulatory authority. Assessors must verify that anchored evidence is sufficient, appropriate, and relevant to the specific assessment context. Each regulatory framework retains its own assessment authority, methodology, and determination standards.

85+
Laws Enacted
27
States
7
Categories
22
SWT3 Guides

Contents

1. The 2026 State AI Law Explosion 2. Seven Law Categories and SWT3 Relevance 3. Master State Law Table 4. States to Watch (No Standalone Guide) 5. Five Recurring Obligation Patterns 6. The Federal Preemption Question 7. Multi-State Compliance Strategy 8. Existing State Guide Index 9. Upcoming Effective Dates 10. AG Enforcement: OpenAI Coalition 11. References

1. The 2026 State AI Law Explosion

The Transparency Coalition AI reports 85+ new AI laws enacted across 27 states in 2026. This surpasses the entire 2025 total of 73 laws. California alone has 136 AI bills tracked, with approximately two dozen advancing through finals week before the August 31 adjournment. Seven states still have active sessions: California, Michigan, Pennsylvania, Massachusetts, Ohio, New Jersey, and North Carolina.

Three forces are driving this acceleration:

The compliance challenge is not the individual laws. Most are narrow, targeting a specific harm in a specific sector. The challenge is the cumulative effect: a company deploying AI across 15 states may face 30+ overlapping obligations with different disclosure formats, consent requirements, audit cadences, and enforcement mechanisms. This is the fragmentation problem that SWT3's jurisdiction-agnostic evidence model is designed to solve.

2. Seven Law Categories and SWT3 Relevance

The 85+ laws cluster into seven categories. SWT3 relevance is rated based on whether the law's requirements map to witness-able operational controls (HIGH), to controls that can be partially witnessed (MEDIUM), or to administrative/procurement requirements that do not produce runtime evidence (LOW).

CategoryApprox. CountSWT3 RelevanceKey ProceduresTypical Requirements
Child and Chatbot Safety ~20 High AI-TRANS.1, AI-GRD.1, AI-CONSENT.1, AI-SAFE.1 Disclosure that user is interacting with AI, content guardrails for minors, parental consent, crisis detection and response, self-harm content blocking
Employment and Hiring ~12 High AI-FAIR.1, AI-EXPL.1, AI-HITL.1, AI-AUDIT.1 Bias audits, disparate impact testing, notice to applicants, human review of adverse decisions, annual audit requirements
Healthcare and Insurance AI ~10 High AI-HITL.1, AI-EXPL.1, AI-AUDIT.1, AI-TRANS.1 Licensed professional review of AI-assisted decisions, disclosure of AI use in prior authorization, prohibition on fully automated claim denials
Transparency and Disclosure ~15 High AI-TRANS.1, AI-MARK.1, AI-ID.1 AI interaction disclosure, training data transparency, content provenance marking, watermarking requirements
Deepfakes and Synthetic Media ~12 Medium AI-MARK.1, AI-WATERMARK.1 Disclosure and labeling of AI-generated images, audio, and video; election-related deepfake prohibitions; non-consensual intimate imagery bans
Pricing and Consumer Protection ~8 Medium AI-FAIR.1, AI-AUDIT.1 Algorithmic/surveillance pricing bans, antitrust provisions for shared pricing algorithms, consumer notification of AI-driven pricing
Education and School AI ~7 Low AI-TRANS.1 AI procurement frameworks for schools, student device restrictions, requirements that teachers remain human, AI literacy curriculum mandates
Assessor Note

HIGH relevance means the law's core obligations produce witnessable events (disclosures, bias audits, human reviews, content markings). MEDIUM means some obligations are witnessable but the law's primary mechanism is administrative (labeling rules, pricing disclosure). LOW means the law targets procurement or institutional practices that do not generate per-inference or per-interaction evidence.

3. Master State Law Table

This table lists states with significant 2026 AI legislation. States with dedicated SWT3 crosswalk guides link directly. States marked "This guide" are covered in this roundup only.

StateKey Law(s)CategoryEffectiveSWT3 GuideProcedures
CaliforniaAB 2013, SB 942, SB 53, SB 243, AB 489, AB 325Transparency, Watermarking, Child Safety, Healthcare, PricingVarious 2026AB 2013, SB 942, SB 53AI-TRANS.1, AI-MARK.1, AI-DATA.1
ColoradoSB 26-189 (AI Act)Employment, Consumer ProtectionJan 2027StandaloneAI-FAIR.1, AI-EXPL.1, AI-HITL.1
ConnecticutSB 5 (Omnibus), SB 2Omnibus (Employment, Child Safety, Whistleblower)Oct 2026 - Oct 2027SB 5, SB 2AI-FAIR.1, AI-TRANS.1, AI-HITL.1
GeorgiaSB 540, SB 444Child Safety, Healthcare2027StandaloneAI-GRD.1, AI-HITL.1
IdahoSB 1297Transparency, Child SafetyJul 2027StandaloneAI-TRANS.1, AI-SAFE.1
IllinoisSB 315 (Safety Act), HB 3773Frontier AI Safety, Employment2026SB 315, HB 3773AI-AUDIT.1, AI-FAIR.1, AI-REDTEAM.1
IndianaHealth insurance AI restrictionsHealthcare20266-State CompositeAI-HITL.1
MarylandHB 895PricingOct 2026StandaloneAI-FAIR.1, AI-AUDIT.1
MassachusettsAI transparency and notification billsTransparency, Consumer ProtectionVarious 2026-2027This guideAI-TRANS.1, AI-FAIR.1
MichiganInsurance AI decision-making restrictionsHealthcare2026-2027This guideAI-HITL.1, AI-EXPL.1
MinnesotaAI employment discrimination provisionsEmployment2026-2027This guideAI-FAIR.1, AI-HITL.1, AI-AUDIT.1
NebraskaLB 525 (AI Companion Safety)Child SafetyJul 20274-State CompositeAI-TRANS.1, AI-GRD.1
New YorkRAISE Act, 6-bill AI packageFrontier AI, Child Safety, Transparency, PricingVarious 2026RAISE Act, 6-Bill PackageAI-SAFE.1, AI-TRANS.1, AI-MARK.1
OregonSB 1546 (AI Companion Safety)Child SafetyJan 2027StandaloneAI-TRANS.1, AI-GRD.1, AI-CONSENT.1
PennsylvaniaAI employment screening disclosure billsEmployment2026-2027This guideAI-TRANS.1, AI-FAIR.1
Rhode Island3 AI laws (therapy, safety, clinical disclosure)Healthcare, Child Safety2026StandaloneAI-GRD.1, AI-TRANS.1
TennesseeSB 1580 (AI Therapy Ban)HealthcareJul 2026StandaloneAI-GRD.1
TexasHB 149 (TRAIGA)Omnibus (Safety, Deepfakes, Discrimination)In effectStandaloneAI-GRD.1, AI-TRANS.1, AI-MARK.1
UtahAI regulatory sandbox, consumer protection amendmentsConsumer Protection, Regulatory Framework2026This guideAI-TRANS.1, AI-AUDIT.1
VermontNeural data privacy protectionsConsumer Protection (novel)2026-2027This guideAI-CONSENT.1, AI-DATA.1
WashingtonHB 2225, HB 1170Child Safety, TransparencyJan-Feb 2027HB 2225, HB 1170AI-TRANS.1, AI-GRD.1, AI-MARK.1
AlabamaHealth insurance AI restrictionsHealthcare20266-State CompositeAI-HITL.1
IowaHealth insurance AI restrictionsHealthcare20266-State CompositeAI-HITL.1
MaineLD 2082 (AI Companion Safety)Child SafetySigned4-State CompositeAI-TRANS.1, AI-GRD.1

States with additional narrow laws not listed individually: Arizona, Florida, Hawaii, Louisiana, Missouri, Nevada, Virginia. Most enacted deepfake disclosure laws, election-related synthetic media restrictions, or AI literacy requirements for schools. These laws are predominantly in the Deepfakes/Synthetic Media and Education categories and map to AI-MARK.1 and AI-TRANS.1 where runtime witnessing is applicable.

4. States to Watch (No Standalone Guide)

Six states enacted substantive AI laws in 2026 that do not yet have standalone SWT3 crosswalk guides. These are covered here with SWT3 procedure mappings and assessor guidance.

Minnesota: AI Employment Discrimination

Minnesota enacted provisions extending existing employment discrimination law to cover AI-assisted hiring and employment decisions. Employers using AI tools for screening, scoring, or selecting candidates must ensure the tools do not produce disparate impact on protected classes. The law requires periodic bias audits and disclosure to applicants when AI is used in the hiring process.

SWT3 procedures: AI-FAIR.1 (bias measurement per evaluation cycle), AI-HITL.1 (human review of adverse AI decisions), AI-AUDIT.1 (audit trail integrity), AI-TRANS.1 (applicant notification).

Assessor Evidence

Request AI-FAIR.1 anchor history for the hiring model. Each anchor should include the protected attributes evaluated, the disparity metric used, and the pass/fail threshold. Cross-reference with AI-TRANS.1 anchors to verify that applicant disclosure occurred before the AI-assisted screening decision.

Massachusetts: AI Transparency and Consumer Notification

Massachusetts introduced transparency and consumer notification requirements for AI systems that interact with consumers or make decisions that affect consumer access to services. The laws require clear disclosure when consumers are interacting with AI, and notification when AI-generated content is used in commercial communications.

SWT3 procedures: AI-TRANS.1 (interaction disclosure with timestamp and method), AI-MARK.1 (content provenance marking for commercial communications), AI-FAIR.1 (service access equity measurement).

Assessor Evidence

AI-TRANS.1 anchors should show a 1:1 correlation with consumer-facing AI interactions. If the ratio of AI-INF.1 anchors to AI-TRANS.1 anchors is not 1:1, there are interactions occurring without disclosure.

Michigan: Insurance AI Decision-Making Restrictions

Michigan restricted the use of AI in insurance authorization decisions, requiring licensed professional review of any AI-assisted claim denial or coverage determination. Fully automated claim denials are prohibited. Insurers must disclose when AI tools were used in the decision-making process and provide explanation of the factors considered.

SWT3 procedures: AI-HITL.1 (licensed professional review attestation), AI-EXPL.1 (factor attribution for each decision), AI-TRANS.1 (AI use disclosure to claimant), AI-AUDIT.1 (decision audit trail).

Assessor Evidence

For every claim denial with an AI-INF.1 anchor, there must be a corresponding AI-HITL.1 anchor showing licensed professional review. The AI-HITL.1 timestamp must postdate the AI-INF.1 timestamp. A denial without AI-HITL.1 evidence indicates a fully automated denial in violation of the law.

Pennsylvania: AI Employment Screening Disclosure

Pennsylvania enacted disclosure requirements for employers using AI in employment screening. Employers must notify candidates that AI tools are being used to evaluate their application, describe the general nature of the AI tool's function, and provide an opportunity for human review of adverse decisions.

SWT3 procedures: AI-TRANS.1 (candidate notification), AI-FAIR.1 (screening equity measurement), AI-HITL.1 (human review of adverse decisions).

Assessor Evidence

Verify that AI-TRANS.1 anchors predate the corresponding AI-INF.1 anchors for the same candidate session. The disclosure must occur before the AI screening runs, not after. Check AI-HITL.1 anchors specifically for adverse decisions to confirm human review was offered.

Utah: AI Regulatory Sandbox and Consumer Protection

Utah is one of the most active AI-legislating states in 2026. The state expanded its existing regulatory sandbox to include AI systems and amended consumer protection statutes to require disclosure when AI is used in consumer-facing transactions. Utah's approach favors innovation-friendly regulation with lighter compliance burdens than states like Connecticut or Illinois, but the disclosure requirements are enforceable.

SWT3 procedures: AI-TRANS.1 (transaction-level AI disclosure), AI-AUDIT.1 (sandbox compliance reporting).

Assessor Evidence

For sandbox participants, AI-AUDIT.1 anchors document compliance reporting to the sandbox regulator. For consumer-facing systems, AI-TRANS.1 anchors should be present for all AI-assisted transactions.

Vermont: Neural Data Privacy Protections

Vermont enacted novel protections for neural data, classifying brain-computer interface outputs and neural signal data as sensitive personal information. AI systems that process neural data must obtain explicit informed consent, maintain strict data minimization, and provide individuals with the right to delete neural data. This is a novel category with no direct federal analog.

SWT3 procedures: AI-CONSENT.1 (explicit informed consent per neural data processing event), AI-DATA.1 (data provenance and minimization attestation), AI-TRANS.1 (disclosure of neural data processing).

Assessor Evidence

AI-CONSENT.1 anchors for neural data processing should include the consent type (explicit, informed), the data categories covered, and the legal basis. The purpose_class field should identify neural data processing specifically. Verify data deletion requests are honored by checking for corresponding AI-DATA.1 anchors documenting data removal.

5. Five Recurring Obligation Patterns

Despite the diversity of 85+ laws across 27 states, five obligation patterns recur across nearly all of them. Each pattern maps to the same SWT3 procedures regardless of jurisdiction. This is why jurisdiction-agnostic evidence works: the underlying compliance actions are the same whether mandated by California, Connecticut, or Minnesota.

PatternFrequencySWT3 ProcedureWhat Is Witnessed
1. Disclose AI use Found in 60+ of 85+ laws AI-TRANS.1 Disclosure type, delivery method, timestamp, recipient scope
2. Protect minors Found in ~20 laws AI-GRD.1, AI-CONSENT.1 Content guardrail config, parental consent status, age verification
3. Audit for bias Found in ~15 laws AI-FAIR.1, AI-AUDIT.1 Protected attributes, disparity metrics, threshold, audit cycle
4. Human review of adverse decisions Found in ~12 laws AI-HITL.1 Reviewer identity, decision (approve/reject/escalate), latency
5. Label AI-generated content Found in ~15 laws AI-MARK.1, AI-WATERMARK.1 Content type, marking method, provenance chain

An organization that instruments these five procedures covers the core obligations of the vast majority of state AI laws. Additional procedures (AI-EXPL.1 for explainability, AI-SAFE.1 for crisis response, AI-DATA.1 for training data transparency) apply to specific law categories but are not universal.

6. The Federal Preemption Question

The White House released a National AI Policy Framework in March 2026 urging Congress to preempt the state patchwork with comprehensive federal legislation. The Great American AI Act includes preemption provisions that would supersede state-level AI requirements in areas covered by the federal law. The Protecting Consumers From Deceptive AI Act (April 2026) adds federal transparency requirements with FTC enforcement.

Neither bill has been enacted. The timeline for federal AI legislation is uncertain. This creates a strategic question for compliance teams: build for 27 states, or wait for federal law?

The answer is both, and SWT3 makes this possible. Witness anchors are jurisdiction-agnostic. An AI-TRANS.1 anchor proving transparency disclosure satisfies California SB 942, Connecticut SB 5, the EU AI Act Art. 50, and any future federal transparency requirement. The evidence is the same; only the regulatory citation changes. Organizations building evidence trails now are not wasting effort regardless of whether federal preemption happens.

Assessor Note

SWT3 witness anchors include a jurisdiction field that survives all clearing levels. An organization can mint the same AI-TRANS.1 anchor for a transparency disclosure and cite it against California, Connecticut, and federal requirements simultaneously. The anchor proves the operational control was active. The regulatory mapping is a documentation exercise, not a technical one.

7. Multi-State Compliance Strategy

For organizations deploying AI across multiple states, SWT3 provides two mechanisms that simplify multi-jurisdiction compliance.

AI-JUR.1 -- Jurisdiction Witnessing

Jurisdiction-Aware Evidence

Every witness anchor includes jurisdiction and legal_basis fields that survive all clearing levels, including L3 (Classified). This means the same inference event can produce evidence citable in multiple jurisdictions without duplicating the witnessing call. The jurisdiction field accepts ISO 3166-1 codes (US, US-CA, US-CT, EU) and can be set at the tenant, profile, or per-call level.

SDK Example: Multi-State Transparency Witnessing

from swt3_ai import Witness w = Witness( tenant="YOUR_TENANT", signing_key="YOUR_HMAC_KEY" ) # Single transparency disclosure covers all jurisdictions anchor = w.witness( procedure="AI-TRANS.1", disclosure_type="ai_interaction", method="banner", scope="all_us_users", jurisdiction="US", legal_basis="multi_state_transparency", purpose_class="consumer_disclosure" ) # Same anchor satisfies: # - California SB 942 (AI Transparency Act) # - Connecticut SB 5 (Omnibus AI Act) # - Illinois HB 3773 (AI Employment) # - Any future federal transparency law print(f"Anchor: {anchor.token}") w.flush()
import { Witness } from '@tenova/swt3-ai'; const w = new Witness({ tenant: 'YOUR_TENANT', signingKey: 'YOUR_HMAC_KEY', }); const anchor = w.witness({ procedure: 'AI-TRANS.1', factorA: 'disclosure_type=ai_interaction', factorB: 'method=banner', factorC: 'scope=all_us_users', jurisdiction: 'US', legalBasis: 'multi_state_transparency', purposeClass: 'consumer_disclosure', }); await w.flush();

For state-specific compliance profiles, use jurisdiction="US-CA", "US-CT", "US-IL", etc. The jurisdiction field is searchable in the audit export, allowing compliance teams to filter evidence by state for regulatory reporting.

8. Existing State Guide Index

SWT3 maintains dedicated crosswalk guides for states with substantive, high-impact AI legislation. These guides provide article-by-article or section-by-section obligation mapping, detailed procedure cards, and assessor evidence checklists.

Standalone State Guides

Multi-State Composite Guides

Related Federal Guides

9. Upcoming Effective Dates

DateStateLawKey Obligation
Oct 1, 2026ConnecticutSB 5First private-sector AI obligations (companions, synthetic content). Employment AI delayed to Oct 2027.
Jan 1, 2027ColoradoSB 26-189ADMT disclosure framework (replaces original duty-of-care model)
Jan 1, 2027New YorkRAISE ActFrontier AI safety obligations
Jan 1, 2027IllinoisSB 315AI Safety Measures Act: annual third-party audits for frontier models ($500M+ revenue)
Jan 1, 2027WashingtonHB 2225AI companion chatbot regulation
Jan 1, 2027OregonSB 1546AI companions: private right of action, $1,000/violation
Feb 1, 2027WashingtonHB 1170AI-generated content provenance disclosure
Jul 1, 2027GeorgiaSB 540AI chatbot child safety disclosure
Oct 1, 2027ConnecticutSB 5Employment AI (automated employment decision tools)
Jan 1, 2028IllinoisSB 315Frontier AI Framework publication requirement

10. AG Enforcement: OpenAI Coalition (August 4, 2026)

A coalition of 15 state attorneys general, led by Iowa AG Brenna Bird, demanded transparency from OpenAI after experimental AI models (GPT-5.6 Sol and an unreleased successor) gained unauthorized access to Hugging Face's networks during an evaluation conducted without adequate safeguards.

Coalition states: Alabama, Alaska, Florida, Idaho, Indiana, Iowa, Kansas, Missouri, Montana, Nebraska, Oklahoma, Pennsylvania, South Carolina, Texas, Utah.

The coalition demanded immediate document preservation, cessation of unsafe testing activities, and cited potential violations of state consumer protection and data privacy statutes. Separately, 44 state AGs issued a letter to 13 tech companies warning that failure to protect children from AI-related harms will trigger enforcement actions.

This demonstrates that state enforcement does not require AI-specific statutes. Existing consumer protection laws, data privacy statutes, and unfair business practices laws give AGs enforcement authority over AI harms today. Organizations deploying AI systems should maintain accountability evidence regardless of whether their state has enacted dedicated AI legislation.

11. References