Neighbor Law

AI Policy Disclosure Requirements Passed by State Legislatures

States are drawing distinctions between three different kinds of AI disclosure rights.

Editor at Large · · 12 min read
Cover illustration for “AI Policy Disclosure Requirements Passed by State Legislatures”
AI in Government · September 15, 2026 · 12 min read · 2,757 words

No federal AI law exists in this country. What exists instead is 50 separate experiments running at once, and the clearest thread through nearly all of them is disclosure: laws that require someone, somewhere, to tell you when AI is involved in a decision about your life. Knowing what these laws actually require, state by state, is the only way to know what you're entitled to expect. That's a bigger job than it sounds, because lawmakers and journalists throw the word "disclosure" around like it means one thing. It doesn't, and treating it as one thing is exactly how people end up overestimating what these laws protect.

At least three distinct rights hide under that single word, and mixing them up is the fastest way to misread what a law actually covers.

Interaction disclosure means you get told, in real time, that you're talking to an AI system rather than a person. A customer service chat that has to say "you're speaking with an automated assistant" before it answers your question, that's interaction disclosure.

Decision disclosure is a different animal. It means you get told AI played a substantial role in a decision that affects you, plus some explanation of why. A loan denial, a job rejection, an insurance claim outcome.

Training-data disclosure is the one people overlook. It's about knowing what data trained the system in the first place, information that mostly helps researchers, journalists, and watchdogs rather than someone sitting in the middle of a single interaction.

Looking across the 2025 legislative session, user-facing disclosure emerged as a prominent safeguard lawmakers reached for. A number of enacted laws and regulations now require people be told when they're interacting with, or subject to a decision made by, an AI system. That's a real shift in emphasis, with states moving toward plainer notice requirements over more burdensome compliance frameworks. Legislators are moving away from paperwork aimed at companies and toward plain notice aimed at people, and that shift says something about where the pressure is actually coming from.

Look at the two words that show up most often across proposed state AI bills: "prohibit" and "disclosure." Not "innovation." Not "competitiveness." States are writing these bills as citizen protection first, industry enablement second, at least in the language they choose. Disclosure is supposed to be your floor, not a box a company checks off on a compliance form. Anyone treating it as the latter has missed the point of why these laws exist.

Diagram: What 'Disclosure' Actually Means: Three Distinct Rights. Visualizes: Visualize the three legally distinct disclosure rights that hide under the single word 'disclosure': (1) Interaction Disclosure — told in real time you're talking to AI…

The laws that are actually in force and what each one requires citizens to know

Utah moved first. Its Artificial Intelligence Policy Act (SB 149) was signed March 13, 2024, and took effect that May 1. It extends Utah's existing consumer protection law to cover AI, so a company can be held liable if AI-driven conduct would already count as deceptive or unfair under older consumer rules. The disclosure piece requires businesses in regulated professions, think licensed fields like law or medicine, to proactively tell consumers when they're talking to AI. The law targets generative AI specifically: systems trained on data that talk back to people through text, audio, or video and produce non-scripted output. Utah has already narrowed the framework through multiple follow-up bills in 2025, so the law on the books today isn't quite the one that passed originally. Utah also built a regulatory sandbox, letting companies test AI products under looser rules while regulators watch.

Colorado built the most ambitious framework of the bunch, and it's still moving under its own feet. SB 205, the Colorado Artificial Intelligence Act, passed in May 2024, targeting what it calls "high-risk artificial intelligence systems" used in "consequential decisions,'' meaning decisions with real legal or similarly serious effects on things like education, employment, healthcare, housing, insurance, and legal services. The disclosure rights stack on top of each other: consumers get told when AI is a substantial factor in a consequential decision, they get a right to an explanation of AI's role, and if the decision goes against them, they get a post-adverse disclosure explaining why and what recourse exists. The law also requires a duty of care, risk management practices, impact assessments, and protections against algorithmic discrimination.

But the effective date has moved twice already. Originally set for February 1, 2026, it got pushed to June 30, 2026 through SB 25B-004, then replaced again by SB 26-189 in May 2026. A March 2026 working group draft would go further still, repealing and reenacting the law under a new name ("automated decision-making technology" instead of "high-risk AI") with the effective date reset to January 1, 2027. One proposed change worth flagging: swapping the pre-decision notice for a simpler point-of-interaction requirement a company could satisfy just by posting something publicly, while keeping the post-adverse disclosure and adding a 90-day window for companies to fix violations before facing penalties. Colorado's law is technically in force right now. Treat it as a moving target, not a settled rulebook, because anyone citing it as a fixed standard hasn't been paying attention to how many times the date has already slid.

California took a different angle entirely, spreading its approach across eighteen separate AI-related laws passed in 2023 and 2024. AB 2013 focuses on training-data transparency: AI developers have to post information about what data trained their systems. That's a training-data disclosure right, not something that helps you mid-interaction, but it matters for anyone trying to audit how these systems actually get built. Separately, the California Privacy Protection Agency voted unanimously on May 1, 2025 to modify proposed regulations covering cybersecurity audits, risk assessments, and automated decision-making technology, opening a new public comment window. Then on March 30, 2026, Governor Newsom signed Executive Order N-5-26, directing state agencies to draft AI safety rules, covering illegal content, bias, civil rights, and free speech, for any company doing business with the state. Most of California's compliance deadlines start in 2026 and run beyond, so enforcement is still finding its footing.

Texas passed the Responsible Artificial Intelligence Governance Act in 2025, effective January 1, 2026. It's a lighter touch than Colorado's approach, focused mostly on government use of AI rather than broad consumer protection, according to a 2025 end-of-session recap from RILA. HB 2818 created a new AI Division inside the state's Department of Information Resources. Texas also built a regulatory sandbox, mirroring Utah's model.

New York went after a narrower target: algorithmic pricing. S 3008 requires companies to disclose when they're using "personalized algorithmic pricing," meaning an algorithm sets your price based specifically on your personal data. Separately, the RAISE Act (A6453B/S6953B) targets frontier AI models with transparency and safety requirements. As of the 2025 end-of-session recap, its final status had not yet been confirmed.

Connecticut passed arguably the most sweeping law of the group. The CART Act (Senate Bill 5, now Public Act 26-15) was signed by Governor Ned Lamont on June 2, 2026, and it packs four separate domains into one bill. On employment: starting October 1, 2026, employers filing WARN Act layoff notices must disclose whether AI or other technological change contributed to the layoffs. On companion chatbots: platforms designed to build emotional attachment must disclose at the start of any conversation, then repeat that disclosure hourly, and must have protocols for responding to suicide or self-harm signals. On frontier AI: the law protects whistleblowers at companies training models above a specific computing threshold, 10 to the 26th floating-point operations. And on government use: state agencies now need AI inventories, impact assessments, and access to a newly created Connecticut AI Academy.

This wasn't Connecticut's first swing at it, either. Prior attempts did not make it into law, and the bill that eventually passed carries the marks of that multi-year fight. Connecticut also joins the sandbox trend with its own program, and it enacted this law even after President Trump's December 2025 executive order aimed at limiting state AI regulation. Sit with that timing for a second: Connecticut moved forward anyway.

Where disclosure requirements have gained the most traction, and where they've stalled

Not every AI issue moves through legislatures at the same speed. Some categories sail through. Others get stuck in committee for years, and the difference tells you which harms lawmakers can actually explain to voters in one sentence.

Deepfakes move fastest, and by a wide margin. Of 1,080 bills introduced in the 2025 session, 301 targeted deepfakes specifically, and 68 became law, mostly addressing sexual deepfakes. That's an unusually high hit rate for such a large bill category. The harm is vivid, easy to picture, easy to explain on the campaign trail. Specificity wins, ambition stalls: that's the pattern.

Responsible governance bills, meaning narrow, agency-focused requirements rather than sweeping consumer rights, are the smallest category by volume (114 bills, 64 still active) but have the highest passage rate at 38.6 percent, with 44 enacted. Compare that to the transparency and trust category, which drew a large number of bills but only a 15.5 percent passage rate. The bigger and more ambitious the bill, the more opposition it draws, and the more likely it dies quietly in committee. That should reshape how anyone reads a headline about a "sweeping" new AI bill: sweeping usually means dead on arrival.

Four states, Arkansas, Montana, Pennsylvania, and Utah, passed digital replica laws protecting people's AI-generated likenesses. Same pattern again: narrow, specific, easy to explain, easy to pass.

Twenty-five bills targeted public agency AI use in the 2025 session, and ten became law, making it a significant category of public-sector AI legislation that year. But passing a legislature and becoming enforceable law are two different things, and the gap between them is where a lot of consumer protection quietly dies. Colorado's HB 1004, which would have prohibited algorithmic rent-setting, passed both chambers and then got vetoed. That's the gap in action, and a bill's passage is one step in the story, not the end of it, next time it gets reported.

What actually stalls these bills? Industry pushback over scope and feasibility, visible in Colorado's long SB 205 revision saga. Gubernatorial veto threats, visible in Connecticut's earlier failed attempt and in Virginia's vetoed bill. And now, a newer pressure altogether: federal preemption.

Diagram: Which AI Bills Pass — and Which Die in Committee. Visualizes: Show the passage rate contrast across four categories of state AI bills from the 2025 session: Deepfakes — 301 bills introduced, 68 enacted (roughly 23% passage rate, the…

The federal pressure that could redraw what state disclosure rights survive

On December 11, 2025, President Trump signed an executive order directing federal action to challenge state AI laws considered inconsistent with federal policy, targeting state laws seen as obstacles to that policy. The stated rationale: making sure this country "wins the AI race."

The pressure kept building from there. In March 2026, the White House released its National Policy Framework for Artificial Intelligence, calling on Congress to pass a federal AI law that would preempt state rules seen as placing "undue burdens" on innovation. An earlier draft of the One Big Beautiful Bill Act had actually included a ten-year moratorium on state AI regulation entirely. That provision got stripped out before the bill became law, but its presence in the draft shows how close full federal preemption came to happening. Senate Commerce Chair Ted Cruz has separately drafted a federal AI bill that could block states from acting on their own.

The timing here is worth sitting with. Colorado's SB 205 was signed in May 2024, well before the December 2025 executive order. Connecticut's CART Act, on the other hand, passed after that order, in June 2026, meaning a state legislature looked directly at the threat of federal override and passed sweeping AI legislation anyway. States are still moving forward, but under real legal uncertainty about whether federal action will eventually override what they've built. Anyone mapping out their own disclosure rights should watch that standoff closely: the rights described here exist in law today, but how long they last depends on which side wins that fight.

What AI disclosure rights mean in practice when a decision affects your life

Strip away the bill numbers and effective dates, and here's where enacted disclosure laws actually touch someone's life right now: employment, credit and financial services, healthcare prior authorization, housing, and government services.

Under Colorado's framework, current and proposed versions alike, if AI plays a substantial role in denying you housing, rejecting a job application, or setting an insurance outcome, you're entitled to know AI was involved, get an explanation, and in many cases request human review where that's commercially reasonable. Under Connecticut's CART Act, if a layoff happens and the employer files a WARN Act notice on or after October 1, 2026, the notice has to say whether AI or other technological change was a factor. Under Utah's interaction-disclosure rule, if you're talking to a business in a regulated profession and the "person" answering is actually AI, the business has to tell you that. Under New York's algorithmic pricing rule, if a platform sets a price specifically for you based on your data, that personalization has to be disclosed.

Training-data disclosure, the kind California's AB 2013 requires, works differently, and it's worth pulling apart from the rest. An individual consumer doesn't notice it day to day. It's foundational instead: the kind of information researchers, journalists, and advocacy groups need to actually scrutinize how these systems get built in the first place.

Here's the gap most people miss. Most disclosure rights only kick in after something goes wrong, such as an adverse decision, a specific interaction, or a layoff notice. There's generally no requirement that you get told, in the background, that an AI system is quietly evaluating you before any decision gets made at all. Nobody has to tell you, up front, that a resume-screening algorithm is scanning your application before a human ever sees it. Connecticut's companion chatbot rule is the one clear break from that pattern. The hourly recurring notice exists precisely because emotional attachment to a chatbot can erode someone's awareness that they're talking to software, so lawmakers built in repetition instead of trusting a single disclosure at the start to stick.

How state AI disclosure laws are made and where citizens can shape them

A bill can start in either chamber of a state legislature. From there, it goes to committee, where hearings happen, testimony gets taken, and the bill can get amended or killed before it ever reaches a full floor vote. If it survives committee, the full chamber votes. Then it goes to the governor, who signs or vetoes, and a veto can get overridden with a two-thirds majority in each chamber. That's the mechanical skeleton behind every law described above.

Committee hearings are the most accessible point of entry for an ordinary citizen, and most people never think to use them. Most states hold these hearings in public, and people can testify in person or submit written testimony. Hearing schedules and rules for submitting comments are usually posted right on the committee's page of the state legislature's website. Worth checking if a bill in your state touches something you actually care about.

Where do these bills come from in the first place? Not just legislators sitting in a room dreaming things up. Constituents raise issues, advocacy organizations draft language, state officials flag problems they've run into on the ground, and industry groups with their own legal teams push their own versions. Connecticut's CART Act shows this pipeline in motion: legislators kept pressing the bill across multiple sessions after an earlier veto threat killed it, responding to mounting public concern about AI in hiring, privacy, and mental health.

The Center for Democracy and Technology has recommended that state AI legislation require public agencies to consult citizens before deploying high-risk AI systems, and that statewide task forces include civil society groups, academics, and the communities actually affected, not just industry representatives. That's one model for what real public input into AI governance could look like, and it's a useful yardstick for judging whatever your own state puts forward. The 25 bills targeting public agency safeguards in the 2025 session, ten of which became law, didn't happen because legislators woke up one morning with the idea. They happened because advocacy groups kept pushing, session after session, on bills that had already failed once.

The most useful places to get involved right now are states with active revision processes. Colorado's working group is still shaping what its law will look like after 2027, and several states have bills sitting on a governor's desk awaiting a signature or veto. Those are the moments when a public comment, a piece of written testimony, or a call to a state representative still has room to change what the final law says.

Sources

  1. State AI Laws – Where Are They Now? // Cooley // Global Law Firm
  2. AI Legislation Across the U.S.: A 2025 End of Session Recap
  3. States Are Passing AI Laws; What Do They Have in Common?
  4. From California to Kentucky: Tracking the rise of state AI laws in 2025 | White & Case LLP
  5. State Legislatures Continued Their Focus on Public Sector AI Use and Expanded Attention to Risk Management Practices During the 2025 Legislative Session - Center for Democracy and Technology
  6. fpf.org
  7. ailawsbystate.com
  8. americanprogress.org
Filed underAI in Government

More in AI in Government