Navigating the 2026 Wave of U.S. State AI Regulations

By Alex Magaard, Head of Public Policy at Eticas.ai

‍ ‍

Right now, in this pivotal year for the U.S. Midterm elections, artificial intelligence has emerged as one of the key bipartisan issues, and although there are several promising bills in Congress—the bipartisan FRONTIER Act to Senator Warner's recently released seven-bill legislative package—it is the states who are paving the way. In the first half of 2026 alone, 27 U.S. states enacted 84 new AI laws, and even more are currently being discussed for this year’s legislative slate. That’s a lot of regulations for companies to comply with and companies need someone to help them comply with this fast-changing regulatory landscape. That’s where independent evaluations (or third-party AI audits) come in.

‍ ‍

Independent evaluations of AI systems, like Eticas.ai’s, are emerging as a requirement across the board, with many of the new state regulations establishing the importance of third-party evaluation. California, Connecticut, Illinois, and New York have all passed new frameworks for governing AI systems, and Massachusetts currently has legislation in committee–the final stage before becoming a law–that would require developers of frontier models to publish safety frameworks for assessing their models and use independent evaluators to assess catastrophic risks, already publicly supported by OpenAI and Anthropic.

‍ ‍

California’s Transparency in Frontier Artificial Intelligence Act (SB 53) and New York’s Responsible AI Safety and Education Act (RAISE Act) require developers to publish transparency reports and disclose the extent of third-party involvement in their own catastrophic risk assessments before the models are deployed to the public — obligations best based on an evaluation, but not quite an official mandate for the audit itself. However, Illinois has set a new regulatory ceiling for companies after Governor JD Pritzker signed theArtificial Intelligence Safety Measures Act (SB 315)on July 6th, becoming the first state to require large frontier model developers to submit annual independent third-party audits of their systems, starting January 1, 2028.

‍ ‍

Within this growing and complex patchwork of state regulations, it is important to differentiate between the different types of harm each law attempts to prevent and what it means for companies. For example, Massachusetts’ new bill focuses on frontier models and the catastrophic risks these emerging technologies pose. Whereas new and existing regulations cover what matters most for organizations beyond billion dollar frontier labs: the automated decision system (the “ADS” system) your Human Resources office uses, the chatbot your Information Technology Team installed on your website, the claims processor your Finance department uses, and/or the system your Procurement Department purchased from a vendor already deployed and making decisions about employees, patients, and customers, and everyday operations. Illinois's new amendment to its Human Rights Act(HB 3773), in effect since January 1, 2026, holds employers accountable for AI-driven discrimination in hiring, and New York City's Local Law 144 has required independent bias audits of automated employment decision tools for years.

We’ve compiled a comprehensive table with all the current State initiatives and what they mean for companies, and we’ve attached it at the end of this piece to not interrupt the narrative. We hope it is useful!

‍ ‍

If you are a U.S. company facing this complex landscape, independent evaluations, such as those that Eticas.ai provides, are the most cost-effective way to minimize your regulatory risk. With one single exercise you can, not only “signal” compliance - what you do when you simply confirm that you are following a process - but also defend it with evidence – the objective metrics a technical evaluation of the system delivers showing how the system behaves in the real world. And as a bonus, a third-party audit often provides insights that actually improve your performance metrics.

‍ ‍

Beyond regulatory compliance, independent evaluation is already becoming good industry practice at every layer of the technology stack. Frontier AI companies are using third-party organizations to test their models before release: OpenAI has described routing certain safety-critical evaluations through outside organizations such as METR, Apollo Research, SecureBio, and Irregular, and in August 2025, OpenAI and Anthropic even evaluated the other's models and published their findings, in what both companies described as the first time two competing labs had opened their internal testing to a direct competitor. Even without a regulatory requirement, the developers of the largest and most cutting-edge AI technologies are demonstrating where the industry is heading: toward third-party audits as standard practice — not only at the model layer, but for the systems built on top of it, which are the ones impacting users and where Eticas.ai has always worked. 

‍ ‍

Now, here you have the summary for your reference.

Regulation that applies to frontier models

State Policy Date Passed Date Goes Into Force What It Means for Companies
California
Transparency in Frontier Artificial Intelligence Act (SB 53)
Sept 29, 2025 Jan 1, 2026 Large frontier developers publish and annually update:
  • Safety framework with specific catastrophic-risk thresholds they test for, their assessment methodology, and how they measure mitigation effectiveness
  • Transparency report with a summary of catastrophic-risk assessment results and disclose the extent of third-party evaluator involvement
New York
Responsible AI Safety and Education Act (RAISE Act)
Dec 19, 2025 Jan 1, 2027 Large frontier developers publish:
  • A "frontier AI framework," with risk thresholds, assessment methods, third-party evaluator use
  • Pre-deployment transparency report with a catastrophic-risk assessment summary
  • Quarterly reporting of risk assessments arising from internal, non-public model use
Illinois
Artificial Intelligence Safety Measures Act (SB 315)
July 6, 2026 Most provisions Jan 1, 2027; framework/audit provisions Jan 1, 2028 Large frontier developers publish:
  • Annual independent third-party audit checking whether a developer's actual practices match its published safety framework, with redacted audit summaries made public and full reports sent to state agencies
  • Pre-deployment transparency reports
Colorado (amended)
Automated Decision-Making Technology (SB26-189)
May 14, 2026 Jan 1, 2027 System developers give deployers information on intended/harmful uses and training-data categories.

Deployers give consumers pre-decision notice, a plain-language explanation after an adverse decision, and a right to human review

Relevant regulation that does not appy to frontier models

State Policy Date Passed Date Goes Into Force What It Means for Companies
Colorado
Use of Artificial Intelligence in Health Care (HB26-1139)
June 3, 2026 Jan 1, 2027 Health insurance companies (and related) that use AI:
  • Must make sure the AI system weighs an individual's actual medical history and clinical circumstances rather than group/generalized data in utilization review
  • Ensure every coverage denial on medical-necessity grounds needs a qualified human clinician's review
  • Ensure coverage reports verify an algorithm isn't defaulting to population-level generalizations for individual cases
Connecticut
An Act Concerning Online Safety (SB 5)
June 2, 2026 Oct 1, 2026 – Jan 1, 2028 Employers using automated employment decision tools must disclose that a tool was used, its purpose, trade name, and what personal-data categories it analyzes and how
Alabama
Health care plans; to regulate the use of artificial intelligence in determinations of coverage (SB 63)
April 17, 2026 Oct 1, 2026 Health insurance companies must annually certify to the Department of Insurance that their AI "does not rely on group datasets" and "does not discriminate" against subscriber groups, backed by periodic accuracy monitoring
Washington
Making improvements to transparency and accountability in the prior authorization determination process (SB 5395)
March 26, 2026 June 11, 2026 Health insurance companies:
  • Are prohibited from using AI as the sole basis for denying, delaying, or limiting care
  • Perform periodic performance reviews that require the system to account for individual clinical conditions
  • Must report AI-aided denied prior-authorization requests to the insurance commissioner
Utah
Health Insurance Preauthorization Amendments (SB 319)
March 19, 2026 Jan 1, 2027 Health insurance providers must publicly disclose when AI was used in the review and statistics on a health insurer's rate of denial-approval
Maryland
Emergency Room Services and Post-Acute Care – Coverage and Facility Studies (HB 1563)
April 28, 2026 June 1, 2026 Health insurance providers must provide quarterly reporting to the Insurance Commissioner on the number of adverse decisions, service type, and degree of AI involvement, with commissioner authority to investigate denial spikes
Georgia
A Bill To Be Entitled An Act (SB 544 / SB 444)
May 5, 2026 Jan 1, 2027 Health insurance providers must review all "adverse determinations" with a licensed provider (a "human in the loop")
Oregon
Relating to artificial intelligence companions (SB 1546)
April 6, 2026 Jan 1, 2027 Operators of artificial intelligence companions and AI companion platforms must provide "evidence-based protocols" to detect and respond to suicidal ideation/self-harm, heightened safeguards for minors, and incident reporting
Idaho
Conversational AI Safety Act (S 1297)
March 31, 2026 July 1, 2027 Operators of AI companions and AI companion platforms must:
  • Disclose that the conversational AI service is artificial intelligence clearly and conspicuously
  • Adopt a protocol for the service to respond to user prompts regarding suicidal ideation, including reasonable efforts to refer users to crisis service providers
  • Provide minors with a visible disclaimer at the start of the interaction and every 3 hours
Nebraska
Conversational Artificial Intelligence Safety Act (LB 525)
April 14, 2026 July 1, 2027 Operators of AI companions and AI companion platforms must:
  • Disclose that the conversational AI service is artificial intelligence clearly and conspicuously
  • Adopt a protocol for the service to respond to user prompts regarding suicidal ideation, including reasonable efforts to refer users to crisis service providers
  • Provide minors with a visible disclaimer at the start of the interaction and every 3 hours
Previous
Previous

Our CEO at UNESCO's 4th Global Forum on the Ethics of AI

Next
Next

Eticas.ai Joins PACT AI as Founding Member to Scale Trust in the AI Economy