With no comprehensive federal AI statute, US state legislatures filled the gap the way they did with privacy. That means unevenly, quickly, and with penalty regimes that make the question practical rather than academic. The result is a compliance map where deployment geography matters. The same hiring screen or biometric feature can be lightly regulated in one state and an enforcement target in another. Tracking every bill is a losing game for an operating company. Understanding the recurring structure is not, and one statute makes a good structural tour.
The worked example: Texas's TRAIGA
Facts below read from aitexas.org's statute guide on August 2026; verify against HB 149 itself before relying on them.
The Texas Responsible AI Governance Act was signed June 22, 2025 and takes effect January 1, 2026. It shows the anatomy most state acts share. Intent-based prohibitions: AI designed to manipulate behavior into harm, and intentional discrimination. For government entities, add social scoring and biometric identification without consent.
Concentrated enforcement: exclusively the state attorney general, with no private right of action. Penalties run up to $200,000 per uncurable violation and $40,000 per day for continuing ones. Compliance ramps: a 60-day cure window that rewards self-correction, and a 36-month regulatory sandbox for innovators. Then the clause that travels — a safe harbor for substantial compliance with a recognized framework such as the NIST AI RMF. Texas-specific depth, including the government-entity rules, lives in aitexas.org's TRAIGA compliance guide.
The pattern worth building on
Read as a category, state acts converge on a deal. Legislatures name the uses they will not tolerate. In return they offer predictability to companies that can evidence a real governance program. The safe-harbor clause is the hinge: it makes the NIST AI RMF not just a best practice but legal cover. It also standardizes what "a real program" means — inventory, risk mapping, measurement on a schedule, named ownership, and artifacts a regulator could read.
That is the same evidence pile the EU AI Act demands for high-risk systems, and the one enterprise procurement teams request in security reviews. Build it once, answer everyone. The software category exists to make that pile producible at scale, and the ethics page covers what the pile is for.
State-law questions
Do US states really have their own AI laws?
Yes, and the layer is growing: comprehensive state acts with penalty regimes, plus narrower statutes on biometrics, automated employment decisions, and synthetic media. For any company operating nationally, "where are we deployed?" became a governance question. The same system can be unregulated in one state and carry six-figure exposure in another. The durable response is not tracking fifty legislatures reactively. It is running one governance program strong enough to satisfy the strictest applicable regime, which is why framework alignment keeps appearing in state laws as a safe harbor.
What is TRAIGA in plain terms?
The Texas Responsible AI Governance Act (House Bill 149) was signed June 22, 2025 and takes effect January 1, 2026, per aitexas.org's guide to the statute. It prohibits AI designed to manipulate behavior into harm, intentional discrimination, and certain government uses such as social scoring and non-consensual biometric identification. Enforcement runs exclusively through the state attorney general. Penalties reach up to $200,000 per uncurable violation and $40,000 per day for continuing ones, with a 60-day cure window. There is also a safe harbor for substantial compliance with a recognized framework such as the NIST AI RMF. That last clause is the part with national significance.
Why does the NIST safe harbor matter beyond Texas?
Because it converts a voluntary framework into legal protection. It is also a pattern other legislatures can copy cheaply. Consider a company that genuinely operationalizes the NIST AI RMF: inventory, risk mapping, measurement, management, with evidence. It is building its best defense under safe-harbor-style state laws, its answer to enterprise procurement questionnaires, and most of its EU AI Act homework at the same time. One program, several regimes. That convergence is the strongest practical argument for doing governance properly instead of jurisdiction-by-jurisdiction firefighting.
How should a company handle multi-state AI compliance?
Three moves cover most of it. Inventory first: you cannot assess exposure for systems you have not listed, and every regime starts there. Second, align to one recognized framework — in the US, NIST's AI RMF is the convergence point — and keep the artifacts. Safe harbors and procurement reviews both run on evidence. Third, track the deltas: the narrow places where a specific state adds something your baseline does not cover. That is a legal-counsel conversation, not a software purchase. Governance tooling helps with the first two; no tool substitutes for counsel on the third.