As 2026 state legislative sessions draw to a close, one theme dominates the policy landscape: artificial intelligence (AI) regulation is no longer an emerging frontier but a mainstream compliance obligation.

Epstein Becker Green’s AI Enacted Bills Map, developed by Eleanor Chung, with Jean-Claude Velasquez and Julia Thayer, tracks every enacted state AI law across three policy domains—omnibus consumer transparency, health care and life sciences, and employment and workforce—and is updated continuously as new legislation is signed. This wrap-up summarizes what the 2026 sessions produced and what it means for businesses operating across state lines.

What You Need to Know

  • AI Regulation Is Now a Compliance Requirement, Not an Emerging Issue. With the 2026 legislative cycle complete, state AI laws are already in effect across consumer transparency, health care, and employment. Businesses operating in multiple states now face enforceable obligations that apply immediately. California, Colorado, Utah, Illinois, and New York remain the most active jurisdictions.
  • Your Company Bears Compliance Responsibility, Not Just Your Vendors. State frameworks impose obligations on businesses that deploy or use AI in operations—not only on the technology developers. Even if you’re integrating a third-party AI tool, your organization is the responsible party under most state laws, and gaps in vendor contracts create significant compliance risk.
  • Health Care Providers Face Intensified Scrutiny on AI-Driven Decisions. Health care AI regulation dominated the 2026 legislative session, with states tightening rules on prior authorization, clinical communications, and algorithmic decision-making. Providers must ensure human review requirements are built into workflows.
  • Employment Obligations Beyond Disclosure. Early state legislation focused on disclosure of the use of AI in employment decision-making. New laws prescribe requirements for auditing and reporting and impose affirmative anti-discrimination obligations.
  • Simplified Compliance Obligations through Federal Preemption Is Unlikely. Congress has not acted on comprehensive federal AI legislation, and preemption is unlikely in the near term. Until it does, multistate compliance is your operating reality, and your AI governance program needs to account for 50 different regulatory frameworks.

Introduction

Epstein Becker Green continuously tracks enacted state AI legislation, organizing laws across three policy domains (Omnibus (affecting every sector), Health Care and Life Sciences, and Employment) and makes its interactive map freely available on the firm’s Trending Issues page.

With 2026 legislative sessions now closing across the country, this wrap-up provides a comprehensive overview of what was enacted, what patterns emerged, and what compliance obligations businesses should prioritize heading into the second half of the year.

The 2026 AI Legislative Landscape: A Patchwork by Design

In the continued absence of a comprehensive federal AI statute, states have filled the void with laws reflecting sharply different regulatory philosophies. Some states have enacted broad consumer-facing transparency frameworks that require disclosure whenever AI is used in a consequential decision. Others have taken a targeted approach, focusing narrowly on health care coverage determinations or employment screening tools. A few states have adopted risk-based frameworks that impose more demanding obligations on higher-risk applications while permitting lighter-touch treatment of lower-stakes deployments.

The result is a patchwork of compliance obligations that vary by jurisdiction, sector, and use case. A business that uses AI to screen job applicants, generate patient-facing communications, and make automated coverage determinations may face three distinct regulatory regimes simultaneously—potentially from the same state. This complexity is precisely what the Epstein Becker Green AI Enacted Bills Map is designed to navigate.

Omnibus Consumer and Transparency Laws

Omnibus AI statutes continued to expand in 2026. These laws impose broad transparency, disclosure, risk assessment, and accountability requirements that apply across industries and use cases, often requiring businesses to notify consumers when AI or automated decision-making affects them, to document training data and model behavior, and to establish liability frameworks for AI-caused harm. California, Colorado, and Utah remain the most active states in this space, with new legislation refining and extending the frameworks those states established in prior sessions.

A notable trend in 2026 is the emergence of requirements specifically targeting generative AI and large language models. Several states enacted or proposed disclosure requirements that are triggered by the deployment of generative AI systems above specified scale thresholds, a category of obligation that did not exist in most state frameworks even two years ago. Businesses using generative AI in consumer-facing applications should evaluate whether these new requirements apply to their deployments.

Health Care and Life Sciences

Health care remained the most active arena for AI regulation in 2026, driven by persistent concerns that automated systems are influencing clinical and coverage decisions without adequate human oversight. The primary focus of enacted legislation in this category was prior authorization: multiple states strengthened or clarified prohibitions on AI serving as the sole basis for coverage denials, requiring human review of AI-assisted determinations and mandating documentation sufficient to support appeals.

A second wave of health care AI legislation targeted AI-generated patient communications, requiring health care organizations to disclose when a communication was generated or substantially drafted by an AI system and to ensure that patients can access a human alternative. States active in this area include California, Colorado, and New York. Smaller states that had not previously enacted health care AI legislation began moving in this direction in 2026 as well, suggesting that the sector-specific frameworks pioneered by early-mover states are now being adopted more broadly.

Employment, Labor, and Workforce

State regulation of AI in the employment context has matured significantly in 2026. The early generation of employment AI laws focused primarily on disclosure requirements—obligating employers to notify applicants and employees when automated decision-making tools were used in hiring or performance evaluation. That first wave is now largely enacted. The 2026 session has seen states move to a second generation of requirements: auditing, reporting, and affirmative anti-discrimination obligations that require employers not just to disclose AI use but to demonstrate that their AI systems do not produce discriminatory outcomes.

Illinois, which enacted the first U.S. law regulating the use of AI in job interviews in 2019, continued to refine its framework in 2026. Connecticut enacted new mandates governing workplace AI and disclosure requirements for reductions in force involving AI-assisted decision-making. Colorado’s Senate Bill 26-189, which addresses employer obligations for AI used in consequential employment decisions, was closely watched throughout the session and represents one of the most significant pieces of employment AI legislation enacted this cycle.

What Businesses Should Watch

Compliance Deadlines Are Arriving: Unlike early AI legislation, which often carried long lead times before taking effect, some 2026 enactments have shorter implementation windows. Businesses that have not yet mapped their AI deployments against the applicable state law landscape should do so now. The key questions for any business deploying AI are straightforward: which states’ laws apply to this system, what obligations are triggered, and when do they take effect?

Deployers, Not Just Developers, Bear Compliance Responsibility: Most state AI laws impose obligations on businesses that deploy or use AI in their operations, not just on the companies that develop the underlying technology. A business that integrates a third-party AI tool into its hiring workflow, clinical decision support system, or consumer-facing communications platform is a deployer under most state frameworks and bears compliance responsibility accordingly. Contracts with AI vendors that do not address compliance obligations and risk allocation may leave significant gaps.

Federal Preemption Remains Unlikely in the Near Term: Congress has not enacted a comprehensive federal AI law, and the prospect of legislation that would preempt the growing body of state regulation remains uncertain. Businesses cannot rely on federal preemption to simplify their compliance posture. Until Congress acts, the multistate compliance framework is the operative reality, and businesses operating across state lines must manage their AI governance programs accordingly.

Conclusions

The 2026 legislative sessions confirm that AI regulation has moved from the periphery to the center of state policy agendas. With nearly 80 percent of state legislatures adjourning by June and a surge of enacted AI legislation across consumer transparency, health care, and employment, businesses face a compliance landscape that is both broader and more demanding than it was a year ago. Organizations that have not yet inventoried their AI deployments against applicable state law frameworks should do so as a matter of priority.

Epstein Becker Green will continue to update the AI Enacted Bills Map as additional laws are signed and to provide analysis of significant new developments through Insights, blog posts, and other publications.

Visit the AI Enacted Bills Map

Questions about your organization’s AI compliance obligations? Contact the attorneys listed on this page or the Epstein Becker Green attorney who regularly handles your legal matters.

Related Epstein Becker Green Resources

In Case You Missed It

"Emilie" Is Not a Psychiatrist: Pennsylvania Board of Medicine Alleges Unlawful Practice of Medicine by an AI Chatbot, Health Law Advisor

One Nation, One Privacy Law: GOP Introduces Federal Privacy Legislation, Workforce Bulletin

Critical Infrastructure at Risk: Project Glasswing Urges Attention to AI-Driven Cyber-Risks, Workforce Bulletin

Eleanor Chung Quoted in “Health Execs Call for Federal AI Framework Preempting State Laws,” Inside Health Policy

Governing Health AI Development and Adoption: Insights from HHS’s Recently Announced Strategy to Promote AI in Healthcare, Health Law Advisor

Both this Executive Summary and the content in the AI Enacted Bills Map are for informational purposes only and are not intended as a comprehensive statement or summary of the relevant laws on this important topic. Always consult with counsel regarding your specific legal and regulatory questions.

Jump to Page
Advanced Search ›

Privacy Preference Center

When you visit any website, it may store or retrieve information on your browser, mostly in the form of cookies. This information might be about you, your preferences or your device and is mostly used to make the site work as you expect it to. The information does not usually directly identify you, but it can give you a more personalized web experience. Because we respect your right to privacy, you can choose not to allow some types of cookies. Click on the different category headings to find out more and change our default settings. However, blocking some types of cookies may impact your experience of the site and the services we are able to offer.

Strictly Necessary Cookies

These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the site will not then work. These cookies do not store any personally identifiable information.

Performance Cookies

These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site. All information these cookies collect is aggregated and therefore anonymous. If you do not allow these cookies we will not know when you have visited our site, and will not be able to monitor its performance.