The state-law layer

Why states moved first

With no comprehensive federal AI statute, US state legislatures filled the gap the way they did with privacy — unevenly, quickly, and with penalty regimes that make the question practical rather than academic. The result is a compliance map where deployment geography matters: the same hiring screen or biometric feature can be lightly regulated in one state and an enforcement target in another. Tracking every bill is a losing game for an operating company; understanding the recurring structure is not, and one statute makes a good structural tour.

The worked example: Texas's TRAIGA

Facts below read from aitexas.org's statute guide on 2026-08-02; verify against HB 149 itself before relying on them.

The Texas Responsible AI Governance Act — signed June 22, 2025, effective January 1, 2026 — shows the anatomy most state acts share. Intent-based prohibitions: AI designed to manipulate behavior into harm, intentional discrimination, and for government entities, social scoring and biometric identification without consent. Concentrated enforcement: exclusively the state attorney general — no private right of action — with penalties up to $200,000 per uncurable violation and $40,000 per day for continuing ones. Compliance ramps: a 60-day cure window that rewards self-correction, a 36-month regulatory sandbox for innovators, and — the clause that travels — a safe harbor for substantial compliance with a recognized framework such as the NIST AI RMF. Texas-specific depth, including the government-entity rules, lives in aitexas.org's TRAIGA compliance guide.

The pattern worth building on

Read as a category, state acts converge on a deal: legislatures name the uses they will not tolerate, and in return offer predictability to companies that can evidence a real governance program. The safe-harbor clause is the hinge — it makes the NIST AI RMF not just a best practice but legal cover, and it quietly standardizes what "a real program" means: inventory, risk mapping, measurement on a schedule, named ownership, artifacts a regulator could read. That is the same evidence pile theEU AI Act demands for high-risk systems and enterprise procurement teams request in security reviews. Build it once, answer everyone — the software category exists to make that pile producible at scale, and the ethics page covers what the pile is for.

State-law questions

Do US states really have their own AI laws?

Yes, and the layer is growing: comprehensive state acts with penalty regimes, plus narrower statutes on biometrics, automated employment decisions, and synthetic media. The practical consequence for any company operating nationally is that "where are we deployed?" became a governance question — the same system can be unregulated in one state and carry six-figure exposure in another. The durable response is not tracking fifty legislatures reactively; it is running one governance program strong enough to satisfy the strictest applicable regime, which is why framework alignment keeps appearing in state laws as a safe harbor.

What is TRAIGA in plain terms?

The Texas Responsible AI Governance Act (House Bill 149) — signed June 22, 2025, effective January 1, 2026, per aitexas.org's guide to the statute. It prohibits AI designed to manipulate behavior into harm, intentional discrimination, and certain government uses (social scoring, non-consensual biometric identification); enforcement runs exclusively through the state attorney general with penalties up to $200,000 per uncurable violation and $40,000 per day for continuing ones, a 60-day cure window, and a safe harbor for substantial compliance with a recognized framework such as the NIST AI RMF. That last clause is the part with national significance.

Why does the NIST safe harbor matter beyond Texas?

Because it converts a voluntary framework into legal protection, and it is a pattern other legislatures can copy cheaply. A company that genuinely operationalizes the NIST AI RMF — inventory, risk mapping, measurement, management, with evidence — is simultaneously building its best defense under safe-harbor-style state laws, its answer to enterprise procurement questionnaires, and most of its EU AI Act homework. One program, several regimes. That convergence is the strongest practical argument for doing governance properly instead of jurisdiction-by-jurisdiction firefighting.

How should a company handle multi-state AI compliance?

Three moves cover most of it. Inventory first: you cannot assess exposure for systems you have not listed, and every regime starts there. Align to one recognized framework (in the US, NIST's AI RMF is the convergence point) and keep the artifacts — safe harbors and procurement reviews both run on evidence. Then track the deltas: the narrow places where a specific state adds something your baseline does not cover, which is a legal-counsel conversation, not a software purchase. Governance tooling helps with the first two; no tool substitutes for counsel on the third.