There is no comprehensive federal AI law in the US, but laws in Colorado, Texas, Illinois, New York, California and Utah, together with the EU AI Act for companies whose AI is used in Europe, impose duties whose breach can lead to enforcement and lawsuits. Most are enforced by attorneys general and other regulators rather than by private plaintiffs, but their duties can also become the standard of care that private claims cite. Companies should therefore map their AI systems to these laws and check how their insurance responds to both kinds of claim.
How Do AI Laws Create Liability for a Company?
AI laws create liability in three ways: regulators enforce them with fines and orders, some give individuals a private right of action, and they define a standard of care that plaintiffs cite in ordinary lawsuits.
Definition
Private right of action
A private right of action is a statutory right that lets an individual, rather than only a government agency, sue over a violation. Laws that carry one with fixed damages per violation are the most likely to produce class actions.
Most new AI statutes withhold that right, but older laws do not. Illinois's Biometric Information Privacy Act (BIPA) lets individuals recover $1,000 for each negligent violation and $5,000 for each intentional or reckless one,[1] which matters for any AI that processes face or voice data, and the Fair Credit Reporting Act (FCRA) allows statutory damages of $100 to $1,000 for willful violations.[2] A proposed class action filed on January 20th 2026 already alleges that Eightfold AI's candidate scores are consumer reports under the FCRA,[3] a theory that, if accepted, would expose AI screening vendors to those damages.
Even a law with no right to sue can shape private claims, because a plaintiff can point to its duties to give notice, test for bias or keep records as the benchmark in a discrimination or negligence claim. Whether a court accepts that benchmark depends on the claim and the state, so it is best to treat every AI law that touches the business as part of its liability assessment rather than as a compliance matter alone.
Is There a Federal AI Law in the US?
There is no comprehensive federal AI statute as of October 5th 2026, and federal policy is aimed at limiting state AI laws rather than adding duties. Federal exposure comes instead from existing laws on deception, securities fraud, discrimination and lending, which apply to AI as they do to any other tool.
Executive Order 14365, signed on December 11th 2025, directed federal agencies to act against state AI laws, although it does not itself preempt, or override, them,[4] and in March 2026 the White House issued non-binding recommendations asking Congress to preempt state AI laws it considers unduly burdensome.[5] Congress had not enacted a preemption statute as of this writing, so state AI laws remain in force unless a court rules otherwise.
The Federal Trade Commission (FTC) treats false claims about AI as deception: on August 27th 2026 it finalized orders requiring Cox Media Group and two other firms to pay a total of $930,000 over claims about an “AI-powered” ad-targeting service.[6] In July 2026 it also proposed a policy statement arguing that state laws requiring companies to alter the truthful outputs of their AI models are “impliedly preempted” to the extent they conflict with federal law, naming Colorado's AI Act; the statement had not been finalized as of this writing.[7]
Since March 18th 2024 the SEC has brought AI-washing cases, which allege that a company overstated what its AI does or how much it relies on it.[8] In April 2025 Executive Order 14281 deprioritized federal enforcement of disparate-impact liability, which applies where a practice disproportionately harms a protected group even without intent to discriminate.[9] Private suits continue regardless: in May 2025 a federal court in Mobley v. Workday, an age discrimination case over AI screening, preliminarily certified a nationwide collective of applicants aged 40 and over.[10]
In financial services, the Consumer Financial Protection Bureau (CFPB) withdrew its circulars on algorithmic credit decisions on May 12th 2025,[11] and SR 26-2, the banking agencies' model risk guidance of April 17th 2026, leaves generative AI and agentic AI (AI that takes actions on its own) outside its scope.[12] The federal retreat lowers agency risk without lowering litigation risk, so it is best not to delay state compliance in the hope of preemption.
When Does the Colorado AI Act Take Effect?
The Colorado AI Act passed in 2024 never took effect: after it was delayed to June 30th 2026,[13] Colorado replaced it on May 14th 2026 with SB 26-189, a narrower law on automated decision-making technology whose obligations begin on January 1st 2027 and which only the attorney general can enforce.[14]
The original Act, SB 24-205, drew a challenge from xAI in which the Justice Department moved to intervene on April 24th 2026.[15] Under an order of April 27th 2026 to which both sides consented, the attorney general agreed not to enforce SB 24-205 until 14 days after a ruling on xAI's motion for a preliminary injunction (a court order blocking a law while the case proceeds). The order lets xAI time that motion to rulemaking under any replacement law such as SB 26-189, but the enforcement pause names only SB 24-205, so whether it reaches the new law is not yet clear.[13]
Definition
Developer and deployer
A developer is the business that builds an AI or automated decision system, and a deployer is the business that uses it to make or support decisions about people. A company that buys an AI tool is usually a deployer with obligations of its own.
Definition
Consequential decision
A consequential decision is a decision about an individual's access to education, employment, housing, lending, insurance, health care or essential government services. Colorado's SB 26-189 regulates automated technology that materially influences such decisions.
SB 26-189 divides its duties between developers and deployers as follows, and it creates no new private right of action.[14]
| Party | Main duties under SB 26-189 |
|---|---|
| Developer | Give deployers documentation of the system's intended uses, known limitations and appropriate human review |
| Deployer | Give notice at the point of interaction, explain the technology's role in an adverse decision within 30 days, and let consumers correct their data and request meaningful human review |
| Both | Keep records for 3 years |
Before January 1st 2030 the attorney general must offer a 60-day cure period, a window in which a company can fix a violation before enforcement action is taken.[14] The law also dropped the earlier Act's safe harbor, the legal protection it gave companies aligned with recognized risk management frameworks.[16] Colorado deployers should assume the January 1st 2027 date will hold and build the notice, explanation and review process now, because obtaining vendor documentation alone can take months.
What Does the Texas Responsible AI Governance Act Require?
The Texas Responsible Artificial Intelligence Governance Act (TRAIGA) has applied since January 1st 2026 and prohibits developing or deploying AI with the intent to incite harm or crime, to discriminate unlawfully, to infringe constitutional rights or to produce sexual content involving minors. The Act states that disparate impact alone does not show an intent to discriminate,[17] so a discrimination claim under TRAIGA turns on what the company intended rather than on the system's outcomes alone.
The attorney general has exclusive authority to enforce TRAIGA after a 60-day cure period, although state licensing agencies can also sanction a licensee once the attorney general has found a violation and recommended that sanction. Individuals cannot sue, and the Act states that it is not a basis for a private action under any other law. Penalties run from $10,000 to $12,000 per curable violation and $80,000 to $200,000 per uncurable one, plus up to $40,000 a day for a continuing violation.
TRAIGA also protects companies that test and review their AI: a company is not liable for a violation it discovers through red-team testing (deliberate attempts to make the system misbehave), feedback from a developer or deployer, or an internal review process carried out while substantially complying with NIST's Generative AI Profile or another recognized AI risk management framework.[17] Documented governance is therefore a legal defense in Texas as well as an underwriting asset, and companies deploying AI in Texas should keep dated records of their testing and reviews.
Which AI Laws Apply in Illinois and New York City?
Illinois and New York City both regulate AI used in employment decisions, Illinois through its Human Rights Act and New York City through Local Law 144.
Since January 1st 2026, the Illinois Human Rights Act, as amended by HB 3773, has made it a civil rights violation for an employer to use AI that has a discriminatory effect on protected classes, or to fail to tell employees and applicants that AI is being used. The Department of Human Rights withdrew its proposed implementing rules on June 2nd 2026,[18] but the statute applies regardless, and remedies on an employee's charge of discrimination may include back pay, emotional distress damages and attorneys' fees.[19]
New York City's Local Law 144 bars employers and employment agencies from using an automated employment decision tool, such as software that scores or ranks candidates, without an independent bias audit in the past year, a public summary of the results and notice to candidates. Fines run up to $500 for a first violation and up to $1,500 for later ones, and the law preserves existing rights to sue.[20] The law also covers a fully remote job if the location associated with it is a New York City office.[21]
Enforcement has been light: a State Comptroller audit released on December 2nd 2025 found that the city had identified 1 compliance issue among 32 companies in which the auditors found at least 17 potential instances.[22] The larger exposure is therefore a discrimination suit, in which a missing notice or audit suggests the employer never checked its tool for bias, so employers hiring in Illinois or New York City should give the required notices and commission the bias audit however rarely the rules are enforced. The guide to AI in hiring covers both laws in detail, and AI-EPL is the Mayflower module written for the employment claims that follow.
Which California AI Laws Create Liability?
California regulates AI through several narrower laws, and the ones most businesses will meet cover employment and automated decision-making under the state privacy law.
Regulations under the Fair Employment and Housing Act (FEHA) have treated discriminatory automated-decision systems as potential violations since October 1st 2025,[23] and from July 1st 2027 SB 947 bars employers from relying solely on such a system to discipline or fire workers, with employees able to seek punitive damages and fees.[24] The California Privacy Protection Agency's rules give consumers rights to access information about, and opt out of, a business's use of automated decision-making technology,[25] with compliance required from January 1st 2027 for businesses that use it to make significant decisions.[26]
The California AI Transparency Act has imposed disclosure duties on generative AI providers since August 2nd 2026, with penalties of $5,000 per violation per day,[27] and SB 1000 extended it to smaller providers on September 30th 2026.[28] Two further laws fall on the companies that build AI: AB 2013 has required generative AI developers to publish training-data summaries since January 1st 2026,[29] and SB 53 requires the largest frontier developers, meaning large companies that train the most powerful AI models, to publish safety frameworks and report critical incidents, with penalties of up to $1 million per violation.[30] New York's RAISE Act will impose the same kind of duties from January 1st 2027.[31] For companies that use AI rather than build it, the 2027 employment and automated-decision dates are the ones to plan for first.
What Do Utah and Connecticut Require?
Utah requires businesses to disclose generative AI use in some situations, and Connecticut has passed a broader law whose obligations start between October 1st 2026 and January 1st 2028.
Utah's Artificial Intelligence Policy Act took effect on May 1st 2024 and, as amended in 2025, requires businesses to disclose generative AI use when a consumer clearly asks and, in regulated occupations, at the start of high-risk interactions. A business cannot avoid liability under Utah consumer protection law by blaming generative AI for a violating statement, and the Division of Consumer Protection can impose fines of $2,500 per violation.[32]
Connecticut's SB 5, signed on May 27th 2026, sets rules on AI content provenance (information showing that content was made by AI), companion chatbots and notices about AI hiring tools.[33] Companies that use customer-facing chatbots or AI hiring tools in either state should add these duties to the same map as their Colorado and California notices.
Does the EU AI Act Apply to US Companies?
The EU AI Act applies to a US company that places an AI system on the EU market, deploys AI through an establishment in the EU, or whose AI system produces output used in the EU, even if the company has no office there.[34]
Definition
High-risk AI system
A high-risk AI system, under the EU AI Act, is an AI system used in an area the Act lists as sensitive, such as recruitment, credit scoring and life and health insurance pricing, or as a safety component of a regulated product. Such systems carry the Act's heaviest duties, including risk management, documentation and human oversight.
The Act applies in stages, and the Digital Omnibus, an amending regulation in force since July 27th 2026, pushed back the main high-risk obligations.[35]
| Date | What applies |
|---|---|
| February 2nd 2025 | Prohibited AI practices |
| August 2nd 2026 | Transparency duties |
| December 2nd 2027 | Main high-risk obligations |
| August 2nd 2028 | High-risk obligations for AI in regulated products |
Fines reach €35 million or 7% of worldwide annual turnover for prohibited practices and €15 million or 3% for most other breaches, whichever is higher.[34] For small and medium-sized enterprises (SMEs) and startups the lower of the two figures applies instead, and since the Omnibus the same is true of small mid-cap companies for breaches other than prohibited practices.[35]
The revised Product Liability Directive treats software, including AI, as a product and applies no-fault liability, under which an injured person need not prove negligence, to defective products placed on the EU market from December 9th 2026,[36] while the Commission withdrew its proposed AI Liability Directive in October 2025.[37] A US company with EU customers, users or staff should identify its high-risk systems now, since December 2027 is the date by which documentation and oversight must be in place.
Which AI Rules Apply to Insurers?
Insurers also answer to their own regulators on AI: according to the National Association of Insurance Commissioners (NAIC), 24 states and the District of Columbia had adopted its Model Bulletin on insurers' use of AI as of April 1st 2026, and California, Colorado, New York and Texas had their own rules.[38]
Colorado's Regulation 10-1-1 has extended AI and data governance duties to auto and health insurers since October 15th 2025,[39] and New York's Circular Letter No. 7 of July 11th 2024 expects insurers to test AI for unfair discrimination and to answer for their vendors' tools.[40] Insurers and the vendors that supply their models should expect examiners to apply these standards and should keep their testing records ready.
What Are the Key AI Laws and Their Deadlines?
The table below summarizes the main laws in this guide as of October 5th 2026: what each requires, when it applies, who enforces it and whether individuals can sue.
| Law | Main duty | In force | Enforcement | Private suits | Related Mayflower module |
|---|---|---|---|---|---|
| Colorado SB 26-189 | Notice, explanation and human review | January 1st 2027 | Attorney general | No | AI-EPL, AI-E&O |
| Texas TRAIGA | No AI used with intent to discriminate or cause listed harms | January 1st 2026 | Attorney general, up to $200,000 per uncurable violation | No | AI-E&O, AI-EPL |
| Illinois Human Rights Act | No AI with a discriminatory effect in employment; notice | January 1st 2026 | Department of Human Rights | Through individual charges | AI-EPL |
| Illinois BIPA | Consent for biometric data | Already in force | Private suits | Yes, $1,000 or $5,000 per violation | AI-E&O |
| NYC Local Law 144 | Annual bias audit and candidate notice | Enforced since July 5th 2023 | City fines up to $1,500 per violation | Existing rights preserved | AI-EPL |
| California FEHA rules and SB 947 | No discriminatory or automated-only employment decisions | October 1st 2025; July 1st 2027 | State agencies | Yes | AI-EPL |
| EU AI Act | Prohibitions, transparency and high-risk duties | Staged to August 2nd 2028 | National authorities, up to 7% of turnover | No | AI-E&O, AI-D&O |
| EU Product Liability Directive | No-fault liability for defective software | December 9th 2026 | Courts | Yes | AI-E&O |
The module column shows the Mayflower policy under which a claim of that kind would most likely be presented rather than a promise of cover, because whether a policy responds, and whether a fine or statutory damages award is insurable, depends on its wording and the governing law. The table is best used as the starting list for the system-by-system map described in the last section.
Does Insurance Cover AI Regulatory Fines and Lawsuits?
Insurance responds more readily to the lawsuits that AI laws generate than to the fines. Directors and officers (D&O), employment practices (EPL) and professional liability (E&O) policies may pay defense costs and settlements, but many forms exclude fines and penalties from the definition of loss or cover them only where the governing law allows, and cover for regulatory investigations varies by form.
AI exclusions narrow cover further: by May 2025 W. R. Berkley had introduced one for D&O, E&O and fiduciary liability that removes cover for claims “based upon, arising out of, or attributable to” any actual or alleged use, deployment or development of AI.[41]
Mayflower Specialty writes affirmative AI coverage, meaning cover that addresses AI risk expressly rather than leaving it to argument after a loss, in four modules. AI Directors and Officers Liability (AI-D&O) is written for claims against directors and officers arising from the company's use, oversight or disclosure of AI; AI Employment Practices Liability (AI-EPL) for employment claims arising from AI used in workforce decisions; and AI Professional Liability (AI-E&O) for claims by clients and third parties harmed by AI-enabled products or services. The fourth module, AI DIC Excess, is a difference-in-conditions layer that sits over an existing program and is written for AI claims where that program is silent on AI or excludes it.
Mayflower writes on a claims made and reported form on A- (Excellent) AM Best rated paper backed by global reinsurers, places its policies through brokers and underwrites on the applicant's AI governance. Whether a particular investigation, fine or lawsuit is covered depends on the policy wording and the governing law, so a company subject to these laws should ask its broker to compare its current wordings with an affirmative AI form before its next renewal.
What Should Companies Do About AI Regulation?
The recommended course of action is to treat AI regulation as a liability exposure to be mapped, documented and insured, in five steps:
- Map systems to laws: List each AI system, the decisions it supports and where the affected people are, because these laws turn on where the applicant, consumer or user is located rather than where the company is based.
- Settle roles and contracts: Decide whether the company is the developer or the deployer of each system, and write into vendor contracts the documentation that Colorado and the EU will require.
- Adopt a recognized framework: Build governance on the voluntary NIST AI Risk Management Framework and its Generative AI Profile[42] or on ISO/IEC 42001, the AI management-system standard published on December 18th 2023.[43] Documented compliance is the evidence that regulators, plaintiffs and underwriters ask for, and in Texas it also supports the defense for violations found through internal review.
- Keep the records: Retain notices, bias audits, risk assessments and human-review logs for the required periods, such as 3 years in Colorado.
- Review the insurance: Ask the broker how each policy treats investigations, fines and AI, and whether any layer carries an AI exclusion. Under a claims made and reported form, which covers only claims made and reported during the policy period, also ask when a regulator's inquiry must be reported to the insurer. The guide to how underwriters assess AI risk explains the governance evidence an application will ask for.
It is a good idea to start with the January 1st 2027 deadlines in Colorado and California and to revisit the map each quarter as the preemption effort and court challenges develop.
Change Log
October 5th 2026: First published.
Frequently Asked Questions
Does the EU AI Act apply to US companies?
When does the Colorado AI Act take effect?
Is there a federal AI law in the US?
Does NYC Local Law 144 apply to remote jobs?
What does the Texas Responsible AI Governance Act require?
Does insurance cover AI regulatory fines?
Sources
- [1]Biometric Information Privacy Act, 740 ILCS 14/20 (right of action), FindLaw, Illinois Compiled Statutes
- [2]15 U.S.C. § 1681n, Civil liability for willful noncompliance (Fair Credit Reporting Act), Legal Information Institute, Cornell Law School
- [3]Job Applicants Sue AI Screening Company for FCRA Violations: 5 Key Takeaways for Employers, Fisher Phillips, January 26th 2026
- [4]Executive Order 14365, Ensuring a National Policy Framework for Artificial Intelligence, 90 FR 58499, Federal Register (govinfo.gov), December 16th 2025
- [5]White House AI Framework Puts Federal Preemption at the Center of the Debate, Morgan Lewis, March 25th 2026
- [6]FTC finalizes orders with Cox Media Group and two other firms over claims of an AI-powered “active listening” ad service, Federal Trade Commission, August 27th 2026
- [7]FTC Seeks Public Comment on Policy Statement Addressing AI Accuracy, Federal Trade Commission, July 1st 2026
- [8]SEC Charges Two Investment Advisers with Making False and Misleading Statements About Their Use of Artificial Intelligence (Release 2024-36), U.S. Securities and Exchange Commission, March 18th 2024
- [9]Executive Order 14281, Restoring Equality of Opportunity and Meritocracy, 90 FR 17537, Federal Register (govinfo.gov), April 28th 2025
- [10]Mobley v. Workday, Inc. (N.D. Cal.), case summary, Civil Rights Litigation Clearinghouse
- [11]Withdrawal of guidance documents, 90 FR 20084 (including Circulars 2022-03, 2023-03 and 2024-06), Consumer Financial Protection Bureau, Federal Register, May 12th 2025
- [12]SR 26-2 Attachment: Supervisory Guidance on Model Risk Management (footnote 3, scope), Board of Governors of the Federal Reserve System, FDIC and OCC, April 17th 2026
- [13]Colorado AI law in flux: Comprehensive replacement bill signed after federal court blocks predecessor's enforcement, McDermott Will & Schulte, May 27th 2026
- [14]SB26-189, Automated Decision-Making Technology, Colorado General Assembly, May 14th 2026
- [15]X.AI sues, DOJ intervenes, enforcement of Colorado's AI Act suspended, Norton Rose Fulbright
- [16]Colorado's AI Reset: Two Weeks, a White House Callout, and a Pivot Away from the EU Model, Carpe Datum Law, May 18th 2026
- [17]HB 149 (89R), Texas Responsible Artificial Intelligence Governance Act, enrolled text, Texas Legislature, June 22nd 2025
- [18]Illinois Department of Human Rights Withdraws Proposed AI in Employment Rules, Burke, Warren, MacKay & Serritella, June 16th 2026
- [19]Illinois Passes Artificial Intelligence (AI) Law Regulating Employment Use Cases, Mayer Brown, September 9th 2024
- [20]Local Law 144 of 2021, Automated employment decision tools, New York City Council, December 11th 2021
- [21]Automated Employment Decision Tools: Frequently Asked Questions, NYC Department of Consumer and Worker Protection, June 29th 2023
- [22]Enforcement of Local Law 144: Automated Employment Decision Tools, Office of the New York State Comptroller, December 2nd 2025
- [23]Workplace AI Regulation in 2026: How Employers Can Navigate the Changing Legal Landscape, Epstein Becker Green, September 1st 2026
- [24]SB 947 (2025-2026), bill text and status, California Legislative Information, September 30th 2026
- [25]CCPA updates, cybersecurity audit, risk assessment and automated decisionmaking technology regulations, California Privacy Protection Agency
- [26]CPPA announcement on approval of regulations on cybersecurity audits, risk assessments and automated decisionmaking technology, California Privacy Protection Agency, September 23rd 2025
- [27]AB 853 (2025-2026), California AI Transparency Act amendments, California Legislative Information, October 13th 2025
- [28]SB 1000 (2025-2026), California AI Transparency Act amendments, California Legislative Information, September 30th 2026
- [29]California District Court upholds transparency requirements for generative AI training data, Norton Rose Fulbright
- [30]SB 53 (2025-2026), Transparency in Frontier Artificial Intelligence Act, California Legislative Information, September 29th 2025
- [31]S8828 (2025-2026), amendments to the RAISE Act, New York State Senate, March 27th 2026
- [32]Utah scales back reach of generative AI consumer protection law, Davis Polk & Wardwell, April 4th 2025
- [33]Connecticut Enacts Sweeping AI Law, Morrison Foerster, June 8th 2026
- [34]Regulation (EU) 2024/1689 (Artificial Intelligence Act), Articles 2, 99 and 113 and Annex III, Official Journal of the European Union (EUR-Lex), July 12th 2024
- [35]Regulation (EU) 2026/1744 (Digital Omnibus on AI), Official Journal of the European Union (EUR-Lex), July 24th 2026
- [36]Directive (EU) 2024/2853 on liability for defective products, Official Journal of the European Union (EUR-Lex), November 18th 2024
- [37]Procedure 2022/0303/COD, proposed AI Liability Directive (withdrawn), EUR-Lex, October 6th 2025
- [38]Map of state adoption of the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers (status as of April 1st 2026), National Association of Insurance Commissioners, April 1st 2026
- [39]SB21-169: Protecting Consumers from Unfair Discrimination in Insurance Practices, Colorado Division of Insurance
- [40]Circular Letter No. 7 (2024): Use of Artificial Intelligence Systems and External Consumer Data and Information Sources in Insurance Underwriting and Pricing, New York State Department of Financial Services, July 11th 2024
- [41]The Continued Proliferation of AI Exclusions, Hunton Andrews Kurth, Hunton Insurance Recovery Blog, May 28th 2025
- [42]AI Risk Management Framework, National Institute of Standards and Technology
- [43]ISO/IEC 42001:2023, Information technology: Artificial intelligence: Management system, International Electrotechnical Commission webstore, December 18th 2023
