AI Regulation: 38 States Create Chaos for 2024

Listen to this article · 7 min listen

A striking 82% of U.S. states have either enacted or introduced legislation concerning artificial intelligence governance since 2023, reflecting a dramatic acceleration in regulatory efforts. This rapid proliferation of state-level AI regulation creates a complex and often contradictory compliance environment for businesses operating nationwide. How can organizations effectively chart a course through this intricate web of evolving AI laws?

Key Takeaways

  • Prioritize compliance with the California AI Accountability Act, as its broad scope and enforcement mechanisms set a de facto national standard for AI system audits and impact assessments.
  • Implement an AI governance framework that includes a dedicated AI ethics committee and a clear process for data provenance and model transparency to address varying state requirements.
  • Establish a strong data privacy infrastructure, focusing on consent management and data minimization, given that 70% of state AI bills include provisions related to personal data use.
  • Conduct regular, at least quarterly, legal reviews of AI deployments against emerging state statutes, particularly those in states where your organization has significant user bases or data processing operations.

38 States Introduced AI-Related Bills in 2024

The sheer volume of legislative activity is staggering. According to data compiled by the Future of Privacy Forum (FPF), 38 states saw AI-related bills introduced in the 2024 legislative session alone, with several of these already signed into law. This figure shows a fundamental shift from a purely federal AI policy discussion to a decentralized, state-by-state approach. My professional experience suggests that this distributed legislative effort, while intended to be responsive to local concerns, often leads to significant compliance headaches for multi-state operators. Consider a company deploying an AI-powered hiring tool. What is permissible in Arizona might be scrutinized differently under Illinois’s Artificial Intelligence Video Interview Act, which requires explicit consent and disclosure for AI analysis of applicant videos. The fragmentation means that a one-size-fits-all compliance strategy simply won’t work.

70% of State AI Bills Address Data Privacy and Bias

A deeper look into the content of these bills reveals a common thread: 70% of proposed state AI legislation includes provisions related to data privacy, algorithmic bias, or both. This emphasis reflects growing public and legislative concern over how AI systems collect, process, and potentially discriminate based on personal data. For instance, the Colorado Artificial Intelligence Act, signed into law in May 2024, imposes duties on developers and deployers of high-risk AI systems to make reasonable efforts to avoid algorithmic discrimination and disclose certain information to consumers. This law defines “high-risk artificial intelligence system” broadly, encompassing areas like employment, housing, and healthcare. Companies must now conduct impact assessments to identify and mitigate risks of algorithmic discrimination, a significant undertaking that demands clear internal policies and technical safeguards. The focus here isn’t just on data protection, but on the downstream societal impacts of AI decisions, forcing organizations to think beyond mere legal checkboxes to genuine ethical considerations.

California’s AI Accountability Act: A Bellwether for Broader Adoption

While many states are legislating, California often sets the pace for tech policy. The proposed California AI Accountability Act, currently making its way through the legislature, mandates independent audits for high-risk AI systems and requires developers to provide documentation on data sources, model architecture, and risk mitigation strategies. If passed, this legislation will likely serve as a template for other states, much like the California Consumer Privacy Act (CCPA) did for data privacy laws. This isn’t just about California. It’s about anticipating the next wave of national regulation. The independent audit requirement alone represents a substantial new cost and operational challenge for AI developers and deployers. It forces a level of transparency and external validation that few organizations are currently prepared for, demanding a proactive approach to AI system design and documentation from the outset. I’ve seen firsthand how companies that adopted CCPA readiness early were far better positioned for subsequent state privacy laws. The same will hold true for California’s AI regulations.

Only 5 States Have Dedicated AI Task Forces or Advisory Bodies

Despite the flurry of legislative activity, only 5 states have established dedicated AI task forces or advisory bodies to systematically study AI and recommend policy. This disparity is a critical observation. It suggests that much of the legislative output is reactive, driven by immediate concerns rather than complete, long-term strategic planning. While some might argue that this allows for agile policy responses, I find it creates an environment of regulatory uncertainty. Without a dedicated body to provide consistent guidance and engage with industry experts, laws can be passed that are technically unfeasible or create unintended consequences. For example, a state might pass a law requiring real-time, explainable AI decisions without fully understanding the current technical limitations of such systems. This lack of coordinated expertise can lead to poorly drafted legislation that is difficult, if not impossible, to comply with in practice. Companies must engage with legislative processes early, offering technical expertise to help shape practical and effective regulations. Ignoring this engagement means risking compliance with laws that simply don’t make sense.

Conventional Wisdom Misses the Interoperability Challenge

The conventional wisdom often suggests that a patchwork of state laws will eventually lead to a federal standard, as businesses demand uniformity. I disagree. The reality is that we are witnessing the emergence of distinct regional variations in AI policy, not merely precursors to a single national framework. For example, states like New York and Illinois have focused heavily on specific applications like AI in hiring, while others, like Utah, have leaned into more general consumer protection around AI-generated content. These aren’t just different facets of the same problem. They reflect different legislative priorities and philosophical approaches to AI governance. The idea that a federal law will simply “harmonize” these divergent paths overlooks the deeply entrenched political and economic differences that drive state-level policymaking. Businesses must therefore prepare for ongoing compliance with multiple, potentially conflicting, state regimes. This means developing internal AI governance frameworks that are flexible enough to adapt to these regional nuances, rather than waiting for an elusive federal silver bullet. Implementing granular controls over AI system deployment based on jurisdictional requirements, perhaps using geo-fencing for certain AI applications, becomes not just a best practice, but a necessity.

The rapidly evolving field of state AI regulation demands a proactive and adaptable compliance strategy. Organizations that prioritize understanding specific state mandates, particularly those from influential states like California, and establish strong internal governance structures will be best positioned to navigate this complex environment.

Which states are leading in AI regulation?

California, Colorado, and Utah are among the states with the most complete AI legislation enacted or proposed, focusing on areas like algorithmic discrimination, data privacy, and transparency in AI systems.

What is a “high-risk AI system” under state laws?

Definitions vary, but generally, a high-risk AI system is one that makes or is a substantial factor in making consequential decisions affecting individuals, such as in employment, housing, credit, education, healthcare, or insurance.

Do I need a separate compliance strategy for each state?

While a foundational AI governance framework can be universal, specific compliance measures, such as consent requirements, disclosure obligations, and impact assessment scopes, often need to be tailored to the exact statutes of each state where an AI system operates or impacts residents.

What role do AI ethics committees play in compliance?

An internal AI ethics committee can help interpret regulatory requirements, guide the development of ethical AI principles, oversee impact assessments for bias and discrimination, and ensure that AI systems align with both legal mandates and organizational values.

How can businesses track the fast-changing state AI laws?

Businesses often use legal counsel specializing in technology law, subscribe to legislative tracking services, and participate in industry working groups to stay informed about new AI bills, amendments, and enacted laws at the state level.

Nadia Kamara

Tech Policy Strategist M.S., Technology Policy, Carnegie Mellon University

Nadia Kamara is a leading Tech Policy Strategist with over 15 years of experience at the intersection of technology and governance. Currently a Senior Fellow at the Global Digital Governance Institute, her work primarily focuses on the ethical deployment of artificial intelligence and its societal impact. She previously served as a policy advisor for the Silicon Valley Policy Coalition, where she spearheaded initiatives on data privacy regulations. Her seminal paper, "Algorithmic Accountability: Designing for Fairness in the Digital Age," is widely cited as a foundational text in responsible AI development