There Is No AI Law in the United States. There Are 109.
By Jean-Hugues Migeon
We often hear that the United States "has no AI law". It is meant as a contrast and driven by FOMO ("Fear of Missing Out"): Europe regulates, America innovates. It is the most common thing I hear from European boards about US AI governance, and it is wrong by about 109 regulations.
That is the number of AI laws US states enacted in the first half of this year, as of 1 July, according to Tech Policy Press, plus 28 more governing data centres. Twenty-nine states passed something. Last year the states finished on 159. The contrast between Europe and America is not presence against absence. It is one instrument against many, and the many are considerably harder to keep track of.
What 109 laws actually look like
The mental picture most European teams carry is a Colorado-style omnibus repeated across fifty states. That is not what happened. The bulk of the 2026 corpus is narrow, aimed at one harm at a time, and written by legislators who were not trying to build a governance framework.
Companion chatbots are the clearest cluster. California's SB 243 requires operators to disclose that the system is not human, run crisis protocols and treat minors differently. Oregon's SB 1546 added suicide ideation detection and crisis referral. Washington's HB 2225 lands in January 2027, Nebraska's Conversational AI Safety Act in July 2027. Elsewhere the targets are synthetic media and digital likeness, AI in hiring, and AI in clinical settings: Tennessee now bars a system from presenting itself as a licensed mental health professional.
Above that sits a smaller tier aimed at frontier developers, where California and New York went first and Illinois went furthest. The Artificial Intelligence Safety Measures Act, signed on 6 July, requires annual independent third-party audits of safety practices, with a redacted report published and filed with the state Attorney General inside 30 days. No European instrument currently compels an external safety audit of a model developer. On that one point, Illinois is stricter than the AI Act; maybe a lesson to learn for the Digital Omnibus.
One rulebook against many: where the difference actually sits
The useful comparison is not volume. It is four structural differences, and each one changes what a compliance team has to do.
What puts you in scope. The AI Act keys off your role and the market: you are a provider or a deployer, and the system is placed on the EU market or its output is used in the EU. US state laws overwhelmingly key off the location of the affected person, or the location of the job. A Belgian lender with no US entity can sit inside Colorado or Illinois obligations because a resident of that state was on the receiving end of a decision. There is no establishment threshold to hide behind and no single "US market" to be in or out of.
Who comes asking. In Europe it will be market surveillance authorities and the AI Office, working from a text everyone has read. In the US it is state Attorneys General, and mostly not under AI statutes at all. A late-July analysis found AGs probing automated underwriting, claims handling and customer communications using consumer protection, licensing and civil rights law that predates AI entirely. Insurers are the current focus. Waiting for an AI-specific statute in your state is not a defence when the theory of liability is deceptive practices.
What counts as evidence. The EU asks for a system: risk management, technical documentation, logging, quality management, with the first harmonised standard (EN 18286 on quality management systems) published on 22 July. US state laws usually ask a narrower question, but they ask it on a civil investigative demand timetable. Narrow and fast is not easier than broad and scheduled. It is a different failure mode, and it punishes teams whose evidence lives in slide decks.
How stable the ground is. This is the difference European teams underestimate most, and it deserves its own section.
Washington is trying to shrink the patchwork and has not managed it
Executive Order 14365, signed on 11 December 2025, set out to build a "minimally burdensome" national framework and reduce divergence between state regimes. The Department of Justice stood up an AI Litigation Task Force on 9 January to challenge state AI laws on Commerce Clause, preemption and other grounds, and Commerce was directed to name the laws it considered onerous, with federal broadband money as leverage.
It has produced one visible win. xAI sued Colorado in April on First Amendment, Commerce Clause, vagueness and equal protection theories. DOJ moved to intervene on 24 April, the first federal intervention in a challenge to a state AI law, and the court suspended enforcement of the Colorado AI Act on 27 April, two months before it was due to apply.
One law, in one state, paused. That is litigation, not preemption. No statute has passed, and an executive order cannot displace state law on its own: preemption runs through Congress. So the federal strategy means each law gets contested separately, on its own facts, in its own court, over years. Commentators have flagged the obvious limits, including Tenth Amendment problems and the legality of conditioning federal funding on a state's legislative choices.
The fair counter-argument is that the chill is working even without a court win. State AI lawmaking is behind last year's pace, 29 states against 39 by the same date, and the Task Force is plausibly part of the reason. I think that is true and also beside the point. Behind pace still produced 109 laws in six months, and a deterred legislature does not repeal what it already enacted. The realistic planning assumption through 2027 is fewer of the most aggressive state laws and no reduction whatsoever in the number of jurisdictions you have to watch.
The verdict
Europe is harder to satisfy once. The United States is harder to satisfy continuously.
AI Act obligations arrive on published dates you can put in a plan, which is why the 2 August milestone has been visible for two years. US obligations arrive when a legislature adjourns, when a court lifts a stay, or when an Attorney General opens a file. For a European company selling into the US, EU compliance work is a floor rather than a passport. Conformity with the AI Act does not answer a California chatbot disclosure question, an Illinois audit filing, or a Colorado notice requirement, and none of those three resemble each other.
The inventory decides whether any of this is manageable
The standard advice is to design controls to the strictest applicable regime. As a principle it is right, and on its own it does nothing, because "applicable" is the part nobody can answer. Very few organisations can say which of their AI systems produce outputs that reach people in Colorado, which ones talk to minors in California, or which ones feed a decision that Illinois would classify as consequential. That is a register problem rather than a legal one, and it is where these programmes actually break. A model card and a data protection impact assessment will not tell you where the output landed.
Three questions worth answering this quarter, before the next state law arrives:
- For each AI system in use, which US states do its outputs actually reach, and who confirmed that?
- Which systems would meet a state definition of consequential or high-risk decision-making, using the state's wording rather than the AI Act's?
- If an Attorney General asked next week how a specific automated decision was reached, what document would you send, and does it exist today?
This is the dimension we built insAIght to hold. Every AI system is recorded with the jurisdictions its outputs reach and the obligations that attach as a result, with the supporting evidence sitting on the system rather than inside a project folder. When a thirtieth state passes a chatbot law, the work becomes a filter over a register that already exists instead of a fresh discovery exercise across the business.
Which may explain something we wrote about earlier this month: US bankers have started asking for the AI rules Europe already has. Not because they enjoy regulation, but because 109 of them is worse than one.
Learn more
- insAIght: continuous AI governance, with each system mapped to the jurisdictions and obligations that apply to it and the evidence kept current.
- ExplAIn: a quick and free way to see how an AI system you already use would be classified and what disclosure it would owe.
- Why US Bankers Are Asking for the AI Rules Europe Already Has: the same fragmentation problem, seen from inside a US bank.
If your AI register cannot yet tell you which US states your systems touch, that is the gap to close before the next legislative session. Book a demo and we will walk through how insAIght maps a live inventory to multi-jurisdiction obligations.