Four US state AI laws are now live or scheduled: Texas's TRAIGA (in force since January 2026), California's SB 53, New York's RAISE Act (effective January 2027), and Colorado's twice-delayed AI Act (now January 2027, with a narrowed scope). They do not regulate the same companies. TRAIGA is the broadest and already enforceable; SB 53 and the RAISE Act target frontier-model developers specifically; Colorado, after amendment, is now mostly a transparency law. This post compares who each law actually reaches.

None of this is legal advice — state AI law is moving fast and the specifics of your obligations depend on your jurisdiction, your role (developer vs. deployer), and counsel's read of your specific product. Treat this as a map of the terrain, not a compliance opinion.

Why "state AI law" is not one thing

Federal AI legislation in the US has not materialized, so states have filled the gap with laws that differ sharply in scope, trigger, and target. Two axes matter most when you are trying to work out if a law applies to you:

  • Who it regulates — some laws target only "frontier model" developers above a compute or revenue threshold; others regulate any business, of any size, that deploys AI touching the state's residents.
  • What triggers obligations — some laws are conduct-based (prohibited uses, regardless of company size); others are disclosure-based (you must publish a safety framework or notify users); a few impose both.

Reading a headline like "California passes AI safety law" without checking which axis it sits on is how teams either over-invest in compliance work that does not apply to them, or miss an obligation that does.

Texas TRAIGA: already in force, broadest reach

The Texas Responsible AI Governance Act (TRAIGA) was enacted 22 June 2025 and took effect 1 January 2026 — it is the only law in this comparison currently enforceable. Its scope is broad by design: it applies to any developer or deployer that advertises, conducts business, or develops AI products used by Texas residents, plus Texas state and local government entities. There is no compute or revenue threshold.

TRAIGA is conduct-based rather than disclosure-based. It prohibits AI systems designed for behavioral manipulation, unlawful discrimination, CSAM or unlawful deepfakes, and infringement of constitutional rights. Government entities using AI must disclose that interaction to consumers. Enforcement sits solely with the Texas Attorney General, who must give notice and a 60-day cure period before taking action — there is no private right of action. The law also creates a regulatory sandbox program and a Texas Artificial Intelligence Council.

For a team building AI agents that serve Texas users — even a small team — TRAIGA is the law most likely to actually apply, because its trigger is presence in the market, not company size.

California SB 53: frontier developers, not general deployers

California's Transparency in Frontier AI Act (SB 53) was signed by Governor Newsom on 29 September 2025 and is described as the first comprehensive US state frontier-AI transparency framework. Unlike TRAIGA, SB 53 targets developers of frontier models — the companies training and releasing the largest models — rather than every business that deploys AI.

The heavier obligations (standardized safety frameworks, incident reporting, internal governance structures, whistleblower protections) apply specifically to "large frontier developers," a narrower category still. If your team is building an agent on top of GPT, Claude, or Gemini rather than training a frontier model yourselves, SB 53's direct obligations are unlikely to reach you — you sit downstream of the regulated party.

One structural feature worth knowing regardless of whether SB 53 applies to you directly: the law includes a federal-deference mechanism, so a developer's demonstrated compliance with a comparable federal or equivalent safety standard can be accepted instead of a duplicate state filing. This is a pattern other states are likely to copy, and it matters if your organization operates across multiple state AI regimes.

New York's RAISE Act: a January 2027 deadline with hard thresholds

New York's RAISE Act reached its final form when Governor Hochul signed the chapter amendment on 27 March 2026, after an earlier version signed in December 2025 was revised through committee. The effective date is 1 January 2027.

Like SB 53, the RAISE Act is scoped to frontier-model developers, defined by explicit numeric thresholds: models trained using more than 10²⁶ FLOPs, with compute costs exceeding $100 million, developed by a company with annual revenue over $500 million. Those thresholds exclude nearly every company building on top of a third-party model API.

The RAISE Act requires covered developers to publish safety-protocol information and to report incidents to the state within 72 hours of determining an incident occurred. Rulemaking authority sits with a new office inside the New York Department of Financial Services, which is a signal that the state expects to keep refining scope and definitions after the effective date rather than treating the statute as final.

Colorado's AI Act: delayed twice, then narrowed

Colorado's AI Act has the most complicated timeline of the four, and it is the one most commonly misdescribed in older content. The original effective date was 1 February 2026. SB 25B-004, signed 28 August 2025, pushed that to 30 June 2026. SB 189, signed by Governor Polis on 14 May 2026, delayed it again — to 1 January 2027 — and made a substantive change beyond timing: it eliminated the original risk-based duty of care around algorithmic discrimination and removed the deployer risk-management-program and impact-assessment obligations, along with certain Attorney General reporting duties. What remains is narrower: primarily disclosure and transparency requirements around automated decision-making, not the fuller risk-management regime the original bill contemplated.

If you are working from an older summary of Colorado's law — including content published before mid-2026 — check the date on it. Our own explainer, Colorado AI Act compliance for engineers, covers the amended obligations and effective date in detail; treat any source that still cites a June 2026 enforcement date or the original impact-assessment duty as stale.

Side-by-side comparison

Law Status as of mid-2026 Who it targets Trigger type Enforcement
Texas TRAIGA In force since 1 Jan 2026 Any developer/deployer serving Texas residents; no size threshold Conduct-based (prohibited uses) + govt disclosure Texas AG, 60-day cure period, no private right of action
California SB 53 Signed 29 Sept 2025 Frontier-model developers; heaviest duties on "large frontier developers" Disclosure-based (safety framework, incident reporting) State enforcement; federal-deference clause available
New York RAISE Act Effective 1 Jan 2027 Frontier-model developers above FLOP/compute/revenue thresholds Disclosure-based (safety protocol publication, 72-hour incident reporting) New York DFS, new rulemaking office
Colorado AI Act (amended) Effective 1 Jan 2027 (narrowed by SB 189) Developers/deployers of high-risk AI in defined decisions Disclosure/transparency (post-SB 189 scope) Colorado AG

What this means for a team building AI agents

For most engineering teams building and deploying AI agents on commercial foundation models, the practical read is:

  1. Check TRAIGA first if you serve Texas users. It is the only one of the four already enforceable, it has no size threshold, and its prohibited-use categories (behavioral manipulation, discrimination, deepfakes) are exactly the kind of failure mode an ungoverned agent can produce.
  2. SB 53 and the RAISE Act probably do not apply to you directly unless you are training frontier-scale models. They matter to you indirectly — as a signal of what "responsible AI" documentation looks like to a regulator, and because your model vendor's compliance posture under these laws is now a reasonable question to ask in procurement.
  3. Re-check Colorado before you cite it. The scope narrowed materially in May 2026; do not build a compliance program against the original 2024 bill text.
  4. Multi-state operations compound quickly. A company serving customers in Texas, California, New York, and Colorado is not choosing one law — it is layering four different trigger conditions and enforcement regimes, on top of any EU AI Act exposure covered in the EU AI Act explained for engineering teams.

An AI agent compliance checklist for 2026 is a reasonable starting point for building the inventory this comparison implies you need: which AI systems you run, which state's residents they touch, and which of these four regimes — if any — actually reaches you. Financial-services teams should also see how this state-law layer interacts with sector-specific expectations in what FINRA and the SEC expect from AI agents, and organizations with EU ICT vendor exposure should read DORA and AI vendors for the parallel EU regime. The AI governance pillar guide covers the broader program these state-specific obligations feed into.

Praesidia is an AI agent security and governance control plane — agent identity and access, guardrails, audit evidence, and cost controls in one place — and the per-agent risk classification it supports can be mapped to whichever of these regimes actually applies to your deployment.

Common questions

Does my company need to comply with all four laws? Only if you meet each law's specific trigger. TRAIGA's trigger is market presence in Texas with no size threshold, so many companies meet it. SB 53 and the RAISE Act trigger on frontier-model development with explicit compute and revenue thresholds that exclude most companies building on third-party models. Colorado's amended law applies to developers and deployers of specific high-risk decision systems. Check each independently rather than assuming they move together.

Is Colorado's AI Act still a big compliance project? Less than the original bill implied. SB 189 removed the deployer risk-management-program and impact-assessment obligations that made the original law resource-intensive, leaving primarily disclosure and transparency duties around automated decision-making, effective 1 January 2027. See Colorado AI Act compliance for engineers for the current scope.

Do these laws only apply to companies headquartered in that state? No. All four are scoped to where the AI system's effects land — Texas residents, New York effects, California-based frontier developers regardless of where customers sit for SB 53's disclosure duties, and similarly for Colorado. Company headquarters location is not the determining factor; where your users or affected individuals are is.

Will more states pass similar laws? Given the pace since 2025 — Texas, California, Colorado (twice amended), and New York all moving within roughly eighteen months — more state activity is a reasonable expectation, but specific predictions are outside what this post can responsibly claim. Track each state's legislative session rather than assuming national convergence.

What should an engineering team actually do first? Build or update your AI system inventory with a column for "which US states does this system's output reach," then check that list against TRAIGA's broad trigger and the frontier-model thresholds in SB 53 and the RAISE Act. That inventory exercise is also the foundation for EU AI Act and ISO 42001 readiness, so it is not wasted work even if none of the four state laws currently apply to you.