The Rise of State-Level AI Regulations in the U.S.
Just as the General Data Protection Regulation (GDPR) ignited a wave of state privacy laws across the United States, the recently enacted EU AI Act is pushing state-level AI regulations to the forefront in America. Kevin M. Alvero, the Chief Compliance Officer at Integral Ad Science, emphasizes the need for organizations to develop comprehensive governance frameworks that satisfy both regulatory compliance and stakeholder expectations in this rapidly evolving landscape.
As GDPR spurred a flurry of legislative activity, corporate leaders should brace themselves for similar developments following the EU AI Act, which came into effect in August. The momentum is already evident, with over 20 U.S. states proposing AI laws affecting private companies.
State AI Laws: Early Movers
Many states have begun enacting or discussing AI regulations, with some focus areas emerging in the legislative landscape. For instance, Utah’s “Artificial Intelligence Policy Act,” effective May 1, 2024, applies consumer protection laws to generative AI in the same way as other business operations. This act defines generative AI as an artificial system that interacts with users via various media and creates outputs similar to human-generated content, often with limited oversight.
Notably, Utah became the first state to mandate disclosure requirements for private companies using generative AI in consumer interactions, emphasizing transparency and accountability as key regulatory themes.
Colorado’s AI Framework
Following closely, Colorado has introduced its “Artificial Intelligence Act,” which targets high-risk AI systems. It obliges AI developers to protect consumers from algorithmic discrimination, a concept encapsulated in its definition of high-risk AI systems. These are systems that can significantly impact crucial life decisions, such as those related to education, employment, or healthcare.
Colorado also mirrors the EU’s focus on high-risk AI systems but employs specific criteria for determining risk levels. Compliance leaders must familiarize themselves with these definitions to navigate the regulatory landscape effectively.
California’s Multifaceted Approach
California has emerged as a frontrunner in enacting AI-related legislation. A notable law requires generative AI systems to disclose their AI-generated content. This includes providing information on data sources as well as usage characteristics related to the AI training process. California’s laws extend protection to output generated from AI applications, addressing issues like robocalls and deepfake content.
Common Threads in State AI Laws
As states implement AI legislation, several key themes have surfaced:
- Disclosure of AI-Generated Content: Transparency is paramount. Many laws require organizations to notify users when they are interacting with AI-generated outputs.
- Use-Case Transparency: Businesses must disclose the specific applications of AI systems, allowing consumers to understand how AI influences their interactions.
- Data Source Transparency: Organizations are obligated to clarify the origin and characteristics of data used in AI training processes.
- Focus on High-Risk Applications: Many laws differentiate between low and high-risk AI applications, imposing stricter guidelines on the latter.
- Controls Against Bias: There is a strong emphasis on mitigating bias and unfair treatment in AI systems, necessitating adherence to data privacy laws where applicable.
These themes reflect broader concerns mirrored in the EU AI Act, thus signaling a growing consensus on the importance of ethical AI use.
The Regulatory Landscape Ahead
With early movers like California, Colorado, and Utah leading the charge, more than two dozen other states are now exploring or drafting AI legislation. This burgeoning regulatory environment is compelling organizations to adapt swiftly to new compliance demands. Here are some emerging requirements organizations should consider:
Governance Programs
Companies are increasingly required to establish comprehensive governance frameworks that outline the policies and procedures for AI use. This includes risk assessments, training staff on governance practices, and appointing a responsible individual for overseeing AI programs.
Risk Assessments
Regular risk assessments are vital for identifying the potential legal and regulatory impacts of AI systems. Organizations must evaluate how their AI applications affect users and society at large.
Documentation and Transparency
Maintaining detailed documentation of AI systems is essential for compliance. This includes having an inventory of tools and techniques used in AI development, deployment protocols, and monitoring outputs.
Ethical Guidelines
Establishing clear ethical guidelines is invaluable for ensuring responsible AI use. Companies should define accountability and include ethical practices regarding fairness and bias in their operational frameworks.
Disclosures
Organizations must be transparent about AI usage, including the nature and purpose of their AI applications. Affected parties, such as users or individuals whose data is processed, should be informed about how AI impacts their interactions.
Third-Party Relations
Fostering compliance among third-party vendors is crucial. As organizations face reputational risks by association, ensuring that partners align with emerging laws is a practical necessity.
Looking Forward
The implications of emerging state-level AI regulations are significant for organizations operating in the U.S. The laws not only represent a growing regulatory risk but also underscore the importance of adopting ethical practices in AI development and deployment.
To navigate this complex landscape, organizations should remain proactive in aligning with governmental guidelines while concurrently addressing stakeholder expectations. Whether pursuing formal certifications or basic compliance, the road ahead requires authentic engagement with AI ethics and governance.

