Why states moved first
With no comprehensive federal AI statute, US state legislatures filled the gap the way they did with privacy — unevenly, quickly, and with penalty regimes that make the question practical rather than academic. The result is a compliance map where deployment geography matters: the same hiring screen or biometric feature can be lightly regulated in one state and an enforcement target in another. Tracking every bill is a losing game for an operating company; understanding the recurring structure is not, and one statute makes a good structural tour.
The worked example: Texas's TRAIGA
The Texas Responsible AI Governance Act — signed June 22, 2025, effective January 1, 2026 — shows the anatomy most state acts share. Intent-based prohibitions: AI designed to manipulate behavior into harm, intentional discrimination, and for government entities, social scoring and biometric identification without consent. Concentrated enforcement: exclusively the state attorney general — no private right of action — with penalties up to $200,000 per uncurable violation and $40,000 per day for continuing ones. Compliance ramps: a 60-day cure window that rewards self-correction, a 36-month regulatory sandbox for innovators, and — the clause that travels — a safe harbor for substantial compliance with a recognized framework such as the NIST AI RMF. Texas-specific depth, including the government-entity rules, lives in aitexas.org's TRAIGA compliance guide.
The pattern worth building on
Read as a category, state acts converge on a deal: legislatures name the uses they will not tolerate, and in return offer predictability to companies that can evidence a real governance program. The safe-harbor clause is the hinge — it makes the NIST AI RMF not just a best practice but legal cover, and it quietly standardizes what "a real program" means: inventory, risk mapping, measurement on a schedule, named ownership, artifacts a regulator could read. That is the same evidence pile theEU AI Act demands for high-risk systems and enterprise procurement teams request in security reviews. Build it once, answer everyone — the software category exists to make that pile producible at scale, and the ethics page covers what the pile is for.