On January 1, 2026, three US state AI laws took effect on the same day: California’s SB 53 (the Transparency in Frontier Artificial Intelligence Act), Texas’s HB 149 (the Responsible AI Governance Act, or TRAIGA), and Illinois’s HB 3773. Together they cover the full spread of the debate — model safety at the frontier labs, deployment limits on high-risk applications, and algorithmic discrimination in employment. With the federal level still missing in action, this is where American AI regulation actually lands, and it is the first compliance bill of 2026 to reach engineering and legal teams.
One piece of context matters up front: the White House’s December 11, 2025 executive order argues for preempting state AI laws that conflict with federal policy. An executive order cannot switch off state statutes. The consensus among legal commentators is blunt — until court challenges resolve, state laws stay enforceable, and none of the compliance work is optional.
California SB 53: Transparency Duties for Frontier Labs
SB 53 is the first US statute addressing catastrophic risks from frontier AI, signed by Governor Newsom on September 29, 2025. It applies to developers of large models trained with more than 10^26 FLOPS of compute, and its core duties are threefold: publish a safety framework describing how risk assessment and mitigation are built into development, report critical safety incidents to the state within 15 days, and put whistleblower protections in place. Penalties run up to $1 million per violation.
For labs at the Anthropic, OpenAI, or Google tier, this is not paper compliance. Safety frameworks become public documents, incident reporting carries a hard clock, and internal reporting channels have to actually work. California has also directed its Government Operations Agency to deliver a consortium report to the legislature by January 1, 2027 — which leaves the door open to further mandates and audits.
Texas TRAIGA: Tiered Penalties, AG-Only Enforcement
Texas HB 149 was signed on June 22, 2025 and governs any entity developing or deploying AI in the state. It starts from a list of “restricted purposes” — encouraging self-harm, unlawful discrimination, and generating CSAM — which are banned outright. Government agencies face separate disclosure and human-review duties when they use AI, and developers of high-risk systems must conduct impact assessments.
The enforcement design is deliberately conservative: penalties are tiered at $10,000–$12,000 for curable violations and $80,000–$200,000 for incurable ones, enforcement sits exclusively with the Texas Attorney General, and there is no private right of action. For companies, that means a fines-based regime rather than a class-action magnet — the risk is calculable, but calculable is not the same as negligible.
Illinois and What Comes Next on the Map
Illinois HB 3773 amends the state’s Human Rights Act and governs employers using AI in employment decisions: employees must be notified, and systems may not produce discriminatory outcomes against protected classes. In contrast to Texas, this route preserves a private right of action — so vendors and adopters of hiring AI (resume screening, interview analytics, performance scoring) carry genuine litigation exposure.
Two more timers are running. The Colorado AI Act — the first comprehensive US high-risk AI statute — takes effect June 30, 2026, requiring impact assessments, consumer disclosures, and reasonable care against algorithmic discrimination. New York’s RAISE Act was signed December 19, 2025. The state map only gets denser from here.
Federal Retreat, State Advance
The December executive order directed the Commerce Department to evaluate state AI laws, with a report due March 11, 2026, and named the Colorado AI Act as a preemption target. But actual preemption requires Congress or a courtroom, not a signature. Baker Botts’ January legal watch summarizes the situation in four words: federal retreat, state advance — and federal pullback should not be read as regulatory relief.
That matches the tone we noted in our 2026 opening outlook: terms and rules are tightening through 2026, and the only open question is whether the pressure arrives through service terms or through state-law penalties.
What Engineering Teams Actually Need to Do
Translated into engineering language, the to-do list is concrete. Audit whether any model you train or fine-tune crosses the 10^26 FLOPS threshold, including training provenance for third-party base models. Stand up a security and safety incident process that can complete a regulatory notification inside 15 days. Add disclosure flows for US users affected by AI in employment decisions. And write impact-assessment documentation for high-risk deployments in healthcare, credit, employment, or government services. Where multiple states’ duties overlap, implementing once to the strictest standard is far cheaper than state-by-state customization.
Sources
- AI Legal Watch: January 2026 — Baker Botts
- Governor Newsom Signs SB 53 — Office of Governor California
- New AI Regulations Come into Play with the Texas TRAIGA — Blank Rome
AI-assisted summary compiled from the sources above, reviewed by a human before publishing.
