Texas TRAIGA, Colorado's AI Law Reset, and Federal Preemption: Navigating AI Regulation in 2026

Quick answer: Texas's TRAIGA (effective January 1, 2026) is in force, and Colorado has already replaced its original AI law with a narrower, notice-based statute (SB 26-189) after a federal court blocked the original version — that law now takes effect January 1, 2027. A December 2025 federal executive order seeking to preempt conflicting state AI laws has not taken effect. Until it does, companies operating across state lines should comply with the strictest applicable state standard rather than wait for federal clarity.

Companies deploying AI systems in 2026 are navigating one of the most fragmented and fast-moving regulatory environments in recent memory — and the fragmentation is coming from multiple directions at once: individual states enacting their own AI laws, a federal executive order attempting to preempt those laws, and state attorneys general actively enforcing existing consumer protection statutes against AI-related harms in the meantime.

Texas's Responsible Artificial Intelligence Governance Act (TRAIGA) took effect January 1, 2026, and is directly relevant to any company doing business in the state. TRAIGA restricts specific uses of AI systems the state considers high-risk — including certain applications in hiring, healthcare, and government services — and imposes civil penalties ranging from $10,000 to $200,000 per violation, enforced by the Texas Attorney General. Unlike some other state frameworks, Texas's law relies on AG enforcement rather than a private right of action, but the penalty range alone makes non-compliance a material financial risk for companies operating at scale.

Colorado's approach to AI regulation has already been through one major reset. The original algorithmic discrimination law, SB 24-205, would have required developers and deployers of high-risk AI systems to exercise reasonable care to protect consumers from algorithmic discrimination. After its effective date was delayed once already (from February 1 to June 30, 2026), a federal court blocked SB 24-205's enforcement in April 2026 following a constitutional challenge. Colorado responded with a replacement measure, SB 26-189, signed May 14, 2026, which repeals and reenacts the state's AI consumer-protection framework on narrower terms: instead of the detailed impact-assessment and algorithmic-discrimination duties in the original law, SB 189 requires AI developers to give deployers technical documentation and requires deployers to notify consumers when an AI system makes a consequential decision — in areas like education, employment, finance, healthcare, housing, or insurance — and to provide an explanation and human review after an adverse outcome. SB 189 takes effect January 1, 2027. California's Transparency in Frontier Artificial Intelligence Act (TFAIA) similarly took effect January 1 and imposes its own disclosure and governance obligations on developers of the most capable AI models.

Layered on top of this state-by-state patchwork is a significant federal development. In December 2025, the President signed an executive order proposing a uniform federal policy framework for AI that would preempt state AI laws found to conflict with it. The order directed the Secretary of Commerce to publish, by March 11, 2026, an evaluation identifying which state AI laws should be considered unduly burdensome under the new federal framework. This sets up a genuine and unresolved conflict between federal preemption ambitions and the growing body of state AI legislation — a conflict that will likely take years, and possibly Supreme Court review, to fully resolve.

What matters most for companies right now is that until any such conflict is resolved through litigation or legislation, state AI laws remain fully enforceable. State attorneys general retain broad authority to pursue investigations and enforcement actions under both AI-specific statutes and general consumer protection laws covering deceptive, discriminatory, or unfair practices — authority they are actively using. Some state AI laws, including proposals in states like South Carolina, go further and include a private right of action, meaning individual consumers, not just government regulators, can bring suit for violations, including for algorithmic discrimination or failures to provide required disclosures.

Practical Guidance for Companies Deploying AI

Given this landscape, companies should not wait for federal preemption to resolve before building compliance programs. A practical approach starts with mapping where the company operates and which state AI laws apply based on where the company does business, where its customers are located, and where any AI-driven decisions (hiring, lending, healthcare, etc.) take effect — since AI laws often apply based on the location of the affected individual, not just the company's headquarters. From there, companies should identify which of their AI systems would likely be classified "high-risk" under frameworks like Texas's, or which systems make "consequential decisions" that trigger notice and explanation duties under newer frameworks like Colorado's revised law, since these systems carry the most significant compliance obligations and enforcement exposure. Documentation is critical: maintaining records of algorithmic impact assessments, bias testing, and disclosures to affected individuals creates a defensible record if a regulator or plaintiff later challenges a specific AI-driven decision. Finally, companies should build compliance programs designed around the strictest applicable state standard rather than a patchwork of minimum requirements, since operating across state lines means the most stringent law in any state where the company has customers or employees will effectively set the floor.

The regulatory landscape for AI will continue to shift throughout 2026 as the federal preemption question plays out and additional states consider their own legislation. Companies that build flexible, well-documented compliance programs now will be far better positioned to adapt as the rules continue to evolve — and far less exposed to the civil penalties and private lawsuits already available to regulators and plaintiffs today.

Wittliff Cutter Saba advises companies on AI governance, regulatory compliance, and litigation defense across this rapidly changing landscape. If your company deploys AI in hiring, customer service, healthcare, or other high-risk contexts, we can help you assess your compliance posture.

Frequently Asked Questions

Is Texas's AI law (TRAIGA) already in effect?

Yes. The Texas Responsible Artificial Intelligence Governance Act (TRAIGA) took effect January 1, 2026, and authorizes the Texas Attorney General to seek civil penalties of $10,000 to $200,000 per violation for restricted high-risk uses of AI, including certain applications in hiring, healthcare, and government services. There is no private right of action under TRAIGA.

What happened to Colorado's AI law?

Colorado's original algorithmic discrimination law, SB 24-205, was blocked by a federal court in April 2026 after a constitutional challenge. The state replaced it with SB 26-189, signed May 14, 2026, which takes a narrower, notice-based approach — requiring disclosure and an explanation-and-human-review right when AI makes a consequential decision — and takes effect January 1, 2027.

Does federal law preempt state AI regulations?

Not yet. A December 2025 executive order directed the Secretary of Commerce to identify state AI laws that conflict with a proposed national framework, but no preemption has taken legal effect. State attorneys general retain full enforcement authority in the meantime, and several state laws include a private right of action.

What should a company deploying AI do right now, given the regulatory uncertainty?

Map where the company operates and which state AI laws apply based on where decisions affecting customers or employees take effect; identify which AI systems would likely be classified "high-risk" or trigger consequential-decision notice duties; document algorithmic impact assessments and bias testing; and build compliance programs around the strictest applicable state standard rather than the average.

Sources: Texas Responsible Artificial Intelligence Governance Act (TRAIGA), eff. Jan. 1, 2026; Colorado SB 24-205 (blocked April 2026) and SB 26-189 (signed May 14, 2026, eff. Jan. 1, 2027); California Transparency in Frontier Artificial Intelligence Act (TFAIA); White House executive order on AI policy (Dec. 2025).
Visuable

Award-winning Top Squarespace Expert agency creating high-end Squarespace 7.1 websites with Fluid Engine. We deliver branding, copywriting, SEO and AIO strategies, membership, course, subscription, scheduling and ecommerce platforms (Squarespace and Shopify). Since 2015, we’ve helped 1,500+ brands across B2B, Food & Drink, Technology, Creative, Health & Wellness, personal brands and non-profits grow online. Meet us: visuable.co.

http://www.visuable.co
Next
Next

Record Trade Secret Filings in 2025: What's Driving the Surge and How to Protect Your Company