State AI Laws of 2026: Legal Summary

Applications of AI


As the 2026 Legislature draws to a close, one theme dominates the policy landscape. That’s because artificial intelligence (AI) regulation is no longer a new frontier, but a mainstream compliance mandate.

Epstein Becker Greene AI Legislation Mapdeveloped by Eleanor Chung in collaboration with Jean-Claude Velasquez and Julia Thayer, tracks all state AI laws enacted across three policy areas: omnibus consumer transparency, healthcare and life sciences, and employment and workforce, and is continuously updated as new laws are signed into law. This roundup summarizes what the 2026 session brought and what it means for companies operating across state lines.

What you need to know

  • AI regulation is now a compliance requirement, not a new issue. With the 2026 legislative cycle complete, state AI laws are already in place in the areas of consumer transparency, health care, and employment. Companies operating in multiple states now face legally enforceable obligations that apply immediately. California, Colorado, Utah, Illinois, and New York remain the most active jurisdictions.
  • Your company, as well as your vendors, have compliance responsibilities. The national framework imposes obligations not only on technology developers but also on companies that deploy or use AI in their operations. Even when integrating third-party AI tools, most state laws place the organization in charge, and gaps in vendor contracts create significant compliance risks.
  • Healthcare providers are facing increased scrutiny of AI-driven decisions. Healthcare AI regulations dominated the 2026 legislative session, with states tightening rules around prior authorizations, clinical communications, and algorithmic decision-making. Providers must ensure that human review requirements are built into their workflows.
  • Employment obligations beyond disclosure. Early state laws focused on disclosure of the use of AI in employment decisions. The new law establishes auditing and reporting requirements and imposes affirmative non-discrimination obligations.
  • It is unlikely that compliance obligations will be simplified through federal preemptive action. Congress has not acted on a comprehensive federal AI bill, and preemption is unlikely in the near future. Until that happens, multi-state compliance will be the operational reality, and AI governance programs will need to consider 50 different regulatory frameworks.

introduction

Epstein Becker Green continues to track enacted state AI legislation, organizing legislation across three policy areas (omnibus, healthcare and life sciences, and employment) and making an interactive map available for free on its Trending Issues page.

As the 2026 Congress concludes across the United States, this roundup provides a comprehensive overview of what has been enacted, what patterns are emerging, and the compliance obligations that companies should prioritize heading into the second half of the year.

AI Legislative Landscape in 2026: Patchwork by Design

In the continued absence of comprehensive federal AI legislation, states have filled the void with laws that reflect disparate regulatory philosophies. Some states have instituted broad transparency frameworks for consumers that require disclosure whenever AI is used to make consequential decisions. Some companies are taking a targeted approach, focusing on health insurance coverage decisions and employment screening tools. Some states have adopted risk-based frameworks that impose stricter obligations on high-risk applications while allowing lighter treatment for lower-risk deployments.

The result is a patchwork of compliance obligations that vary by jurisdiction, sector, and use case. Companies that use AI to screen job candidates, generate communications for patients, and automatically determine coverage may face three different regulatory regimes simultaneously (sometimes from the same state). This complexity is exactly what the Epstein Becker Green AI Enacted Bills Map is designed to navigate.

Omnibus Consumer Law and Transparency Law

The Omnibus AI Act continued to expand in 2026. These laws impose broad transparency, disclosure, risk assessment, and accountability requirements that apply across industries and use cases, often requiring companies to notify consumers when AI or automated decision-making impacts them, document training data and model behavior, and establish liability frameworks for harm caused by AI. California, Colorado, and Utah remain the most active states in this area, and the new legislation refines and expands on the framework these states established in previous sessions.

A notable trend in 2026 is the emergence of requirements specifically targeting generative AI and large-scale language models. Several states have enacted or proposed disclosure requirements triggered by the deployment of generative AI systems that exceed specified size thresholds. This is a category of obligations that did not exist in most state frameworks two years ago. Companies using generated AI in consumer applications should evaluate whether these new requirements apply to their deployments.

Healthcare and life sciences

Healthcare remained the most active area for AI regulation in 2026 due to persistent concerns that automated systems are influencing clinical and coverage decisions without proper human oversight. The main focus of the laws enacted in this category was prior authorization. Several states have strengthened or clarified prohibitions on AI as the sole basis for denying coverage, requiring human review of AI-assisted determinations, and requiring documentation sufficient to support appeals.

The second wave of medical AI laws targeted AI-generated patient communications, requiring healthcare providers to disclose when a communication was generated or substantially created by an AI system and to ensure that patients have access to human alternatives. States active in this area include California, Colorado, and New York. Smaller states that have not previously enacted healthcare AI laws are also starting to move in this direction in 2026, suggesting that the sector-specific frameworks pioneered by leading states are now being adopted more broadly.

Employment, labor, labor force

National regulations regarding AI in the employment context matured significantly in 2026. Early generations of employment AI laws focused primarily on disclosure requirements, requiring employers to notify applicants and employees when automated decision-making tools were used in hiring or performance evaluations. The first wave is now almost in effect. In the 2026 session, states will move to second-generation requirements. Auditing, reporting, and affirmative nondiscrimination obligations require employers not only to disclose their use of AI, but also to demonstrate that their AI systems do not produce discriminatory outcomes.

Illinois, which enacted the nation’s first law regulating the use of AI in job interviews in 2019, continued to refine its framework in 2026. The state of Connecticut has enacted new mandates governing AI in the workplace and disclosure requirements for layoffs involving AI-assisted decision-making. Colorado’s Senate Bill 26-189, which sets out employer obligations for AI used in consequential employment decisions, has received attention throughout the session and is one of the most important pieces of employment AI legislation enacted this cycle.

What companies should pay attention to

Compliance deadlines approaching: Unlike earlier AI laws, which often had long lead times before going into effect, some of the 2026 laws had shorter implementation periods. Companies that have not yet mapped their AI deployments to the landscape of applicable state laws should do so now. The key questions for companies implementing AI are simple and straightforward. Which state laws apply to this system, what obligations are triggered, and when will they take effect?

Implementers as well as developers are responsible for compliance. Most state AI laws impose obligations not only on companies that develop the underlying technology, but also on companies that deploy or use AI in their operations. Companies that integrate third-party AI tools into recruitment workflows, clinical decision support systems, or consumer communications platforms are adopters under most state frameworks and bear compliance responsibilities accordingly. Contracts with AI vendors that do not address compliance obligations and risk allocation can leave significant gaps.

Federal preemption remains unlikely in the short term: Congress has not enacted comprehensive federal AI legislation, and the prospects for enacting legislation to preempt expanding state regulation remain uncertain. Companies cannot rely on federal preemptive action to simplify their compliance regimes. Until Congress takes action, a multi-state compliance framework will be a reality, and companies operating across state lines will need to manage their AI governance programs accordingly.

conclusion

The 2026 Congress will see AI regulation move from the periphery to the center of the national policy agenda. With nearly 80% of state legislatures recessed through June and a surge in AI-related legislation spanning consumer transparency, health care and employment, companies face a broader and more stringent compliance environment than a year ago. Organizations that have not yet taken inventory of their AI deployments in light of applicable state law frameworks should do so as a priority.

Epstein Becker Green will continue to update the AI ​​Legislation Map as additional legislation is signed and provide analysis of important new developments. insight, Blog posts and other publications.

Access the AI ​​Legislation Map

Do you have questions about your organization’s AI compliance obligations? Contact any of the attorneys listed on this page or the attorneys at Epstein Becker Green who regularly handle your legal matters.

Epstein Becker’s green resources

In case you missed it

‘Emily’ is not a psychiatrist: Pennsylvania Medical Board alleges illegal medical practice by AI chatbot, Health law advisor

One country, one privacy law: Republicans introduce federal privacy law, employee bulletin

Critical infrastructure at risk: project glasswing Calling attention to cyber risks caused by AI, employee bulletin

Quote by Eleanor Chan: Health leaders seek federal AI framework that preempts state laws internal medical policy

Managing the development and deployment of medical AI: Insights from HHS’ recently announced strategy to advance AI in healthcare, Health law advisor

Both this Executive Summary and the content of the AI ​​Legislation Map are for informational purposes only and are not intended to be a comprehensive description or overview of the relevant laws regarding this important topic. Always consult an attorney regarding specific legal and regulatory questions.



Source link