There is no federal AI law in the United States. Instead, 2026 is the year state AI laws started biting — and if you run AI agents that serve customers in Texas or California, you already have obligations. Here's the landscape and what to do about it.
Texas: TRAIGA is in force¶
The Texas Responsible AI Governance Act (HB 149) was signed on June 22, 2025 and took effect January 1, 2026. It applies to anyone developing or deploying AI systems in Texas or offering AI products to Texas residents — which, for internet businesses, effectively means everyone.
What it prohibits: developing or deploying AI intended to incite self-harm, violence, or criminal activity; AI deployed with the intent to unlawfully discriminate against protected classes; AI-generated CSAM and certain sexually explicit content; and government social scoring. State agencies must disclose when consumers interact with AI.
Enforcement sits exclusively with the Texas Attorney General — no private right of action — with a 60-day cure period and civil penalties scaling up to $200,000 per incident depending on curability and intent. The law also creates a 36-month regulatory sandbox.
Deployer takeaway: document what your agents are for, build content guardrails against the prohibited uses, and keep records showing your intent and controls. The AG can issue investigative demands for system documentation.
California: transparency laws in force¶
California's AB 2013 (training-data transparency) took effect January 1, 2026: developers of generative AI systems must publicly document the datasets used for training. The AI Transparency Act (SB 942) requires provenance disclosures and a free AI-detection tool for content from large generative systems. And SB 53, the Transparency in Frontier AI Act signed in September 2025, requires frontier-model developers to publish safety frameworks addressing catastrophic risks.
Deployer takeaway: if your agents generate content for Californians, provenance and disclosure are your problem even if you didn't train the model — check what your providers give you and fill the gaps.
Utah: disclosure duties¶
Utah's AI Policy Act requires clear disclosure when consumers interact with generative AI — proactively in regulated occupations, on request otherwise. Simple, but it means every customer-facing agent needs an “you're talking to an AI” path.
Colorado: verify before you rely¶
Colorado: the old AI Act never took effect — a narrower replacement starts January 2027. Colorado's original AI Act (SB 24-205) was repealed and replaced by SB 26-189, signed May 14, 2026 and effective January 1, 2027. The replacement is a narrower, notice-based regime for automated decision-making technology: notify consumers when AI is used, disclose details within 30 days of an adverse consequential decision, correct inaccurate personal data on request, and offer meaningful human review. The old law's risk-management programs, impact assessments, and reasonable-care duties are gone. Do not rely on summaries (including this one) for Colorado; read the current statute text before making compliance decisions.
The deployer playbook for state laws¶
State laws differ in detail but converge on the same operational controls:
- Disclosure: every user-facing agent identifies itself as AI.
- Logging: you can reconstruct what the agent did and why — this is also your defense in any AG inquiry.
- Human appeal path: where agents influence consequential decisions, a human must be reachable.
- Documentation: intended purpose, guardrails, and testing, written down before anyone asks.
None of this requires a legal department. It requires the boring infrastructure: inventory, logs, approvals, disclosures. Our AI Agent Risk Audit Kit ($19) and Agent Incident Response Runbook ($19) cover the foundations; the Studio Edition ($29) is the complete system.
Practical guidance, not legal advice. State laws are moving quickly — verify current text and consult counsel.