U.S. AI Regulatory Patchwork: Preemption Showdown, Colorado Repeal, and State-Level ADMT Regs
As state legislatures and administrative agencies grapple with the absence of a unified federal AI framework, a highly complex state-level regulatory patchwork has emerged in 2026.1 This landscape is characterized by a shift toward accountability-based requirements borrowing heavily from privacy law, specifically in California and Colorado.
California's "AI Governance by Design" Model
California is leading the transition toward embedding AI risk management directly into business operations through two major regulatory pillars:
1. Transparency in Frontier AI (SB 53)
Signed into law on September 29, 2025, Senate Bill 53 (the "Transparency in Frontier Artificial Intelligence Act") mandates that large developers of advanced foundation models (specifically those with over $500 million in annual gross revenue) implement comprehensive internal governance systems. These systems must cover safety oversight, cybersecurity, risk assessment, and incident response. SB 53 reflects a regulatory shift that targets upstream developers to manage risk before deployment.
2. Automated Decision-Making Technology (ADMT) Regulations
The California Privacy Protection Agency (CPPA) has advanced groundbreaking regulations targeting automated decision-making technology (ADMT). Starting January 1, 2027, businesses using ADMT will be legally required to provide consumers with:
- Pre-use notices explaining how the technology is used.
- Rights to access information about how the system evaluated them.
- The right to opt-out of ADMT processing in high-stakes contexts (such as employment, housing, lending, healthcare, and education).
The CPPA defines ADMT broadly as any technology that processes personal data and uses computation to "replace" or "substantially replace" human decision-making. To avoid these requirements, a business cannot merely rely on a nominal "human-in-the-loop." Instead, human reviewers must understand the system's output, evaluate it alongside other information, and possess the authority to override the algorithm's decision.
Colorado's Legislative Pivot (SB 26-189)
The regulatory patchwork was further reshaped on May 14, 2026, when Colorado Governor Jared Polis signed SB 26-189, which repealed and replaced the state's landmark 2024 Colorado Artificial Intelligence Act (CAIA). Driven by federal preemption concerns and industry pressure, the new law replaced the rigid risk-based developer/deployer liability split with a disclosure-and-rights ADMT framework, significantly reducing compliance burdens for employers while focusing on consumer rights.
Enterprise Compliance Considerations
For enterprise legal and risk teams, these state-level frameworks demand a shift from reactive risk mitigation to proactive "governance by design." Key operational requirements include:
- Layered Disclosures: Providing detailed, stage-specific notices to individuals when automated tools are used to screen, score, or rank them.
- Active Human Review: Ensuring that human oversight of AI outputs is meaningful, trained, and legally empowered to override automated decisions.
- Vendor Contract Allocations: Drafting robust vendor agreements that guarantee access to model training data, audit rights, and cooperation in responding to individual access, correction, or opt-out requests.
-
An instance of The absence of a centralized AI statute fragments corporate compliance across legacy regulatory frameworks. — The vacuum of federal oversight has forced individual states to build highly disparate regulatory guidelines. ↩︎