The plan for US AI rules this year was the same everywhere. Wait.
Wait for Congress. Wait for the executive order that flattens the states. Wait for one federal standard you write once and ship in fifty places.
It is August 2026. Nobody preempted anything.
There were 109 AI laws across 29 states by 1 July 2026. Not proposals. Laws. And the thing that catches operators out is not the count, it is the trigger. These duties follow the resident, not your head office. Your entity is in Delaware, your engineers in Austin, your servers in Virginia. None of that decides which rulebook applies. The person on the other end does. Enter a new state, inherit a new rulebook.
Here is the map, with the part every summary gets wrong: who each rule binds.
Texas put a deadline on the disclosure
HB 149, the Texas Responsible AI Governance Act, signed 22 June 2025, in force since 1 January 2026, codified at Tex. Bus. & Com. Code s 552.051(f).
A provider using an AI system in relation to a health care service or treatment must disclose that use to the recipient or their personal representative, no later than the date the service is first provided. Emergencies get an exception, with disclosure to follow as soon as reasonably possible. Clear and conspicuous, plain language, no dark patterns.
Read the timing again. Not eventually, not on request. By the date of first service. That is a dated record, or it is nothing.
California is three laws binding three different parties
This is where most guidance turns to mush. All three get filed under "California AI rules" and handed to the wrong team.
AB 3030 (Ch. 848, 2024), effective 1 January 2025, binds health facilities, clinics, physician offices and group practices. Communications containing patient clinical information need a GenAI disclaimer plus clear instructions for reaching a human health care provider. There is an exemption: if a licensed human provider reads and reviews the output, the duty falls away.
That exemption is the whole design. Human review buys you out, so it is worth exactly what your evidence of review is worth.
SB 1120, also effective 1 January 2025, binds payors: health care service plans and disability insurers. It bars AI, algorithms or software from being the sole basis for a medical necessity denial, delay or modification. If you are a provider, this one is not yours.
AB 489 (Ch. 615, 2025), effective 1 January 2026, is the one that reaches an ordinary operator. It bars AI systems, and their developers and deployers, from using terms implying a health care licence. Any deployer. Which makes what you named your assistant, and how it introduces itself, a legal question, not a branding one.
Illinois drew a line, not a disclosure duty
HB 1806, the Wellness and Oversight for Psychological Resources Act, PA 104-0054, codified at 225 ILCS 155, signed and in force 1 August 2025.
A licensed professional may not let an AI system make independent therapeutic decisions, generate treatment plans without licensed review, or detect emotions. IDFPR enforces it, with civil penalties up to $10,000 per violation.
No disclaimer cures this one. Either the licensed human was in the loop or they were not, and only your evidence stands between you and the penalty.
Utah is the state almost everyone describes wrong
Utah Code Title 13 Chapter 77, enacted by SB 226 in 2025, in force 7 May 2025.
Section 13-77-103(1): a supplier using generative AI in a consumer transaction must disclose only when the individual makes a clear and unambiguous request. Asked and answered.
Section 13-77-103(2): proactive disclosure is required only at the intersection of two conditions. First, an individual providing services in an occupation regulated by the Utah Department of Commerce requiring a licence or state certification. Second, a high risk artificial intelligence interaction. Both, or neither. And the duty attaches to the licensed individual, not the facility that employs them.
The wide version you have probably read, blanket proactive disclosure across every regulated occupation, was s 13-2-12 under SB 149. Repealed. Plenty of commentary still runs it as current, so check the section number your Utah policy cites.
Colorado is a moving object
SB 24-205 was delayed to 30 June 2026 by SB 25B-004, then enforcement was suspended by court order on 27 April 2026 in xAI v. Weiser, D. Colo. 1:26-cv-01515.
SB 26-189, the Automated Decision-Making Technology Act, was signed 14 May 2026, repealing and reenacting a narrower disclosure regime with duties from 1 January 2027. AG rulemaking is open, proposed rules filed 11 August 2026, comment to 26 October 2026, and the stay reaches SB 26-189 too. Nothing to comply with today, then a hard date.
The denial side is converging
Maryland HB 820 (Ch. 747), approved 20 May 2025, effective 1 October 2025, bars AI from being the sole basis to deny, delay or modify care. Determinations must rest on the enrollee's individual clinical history. Final adverse medical necessity decisions stay with a qualified human clinician.
Comparable laws now cover Arizona (HB 2175, operative 1 July 2026), Connecticut (PA 25-94, 1 October 2025), Nebraska (LB 77, 1 January 2026) and Texas (SB 815, 1 September 2025).
Different drafters, same shape. A human owns the decision, and the record has to show what it rested on.
The federal section, short because it has to be
EO 14365, 11 December 2025, "Ensuring a National Policy Framework for Artificial Intelligence", is the order everyone points at. It created a DOJ AI Litigation Task Force, made states with onerous AI laws ineligible for BEAD non-deployment funds, and asked Congress for preemption legislation. Asking is not preempting. It does not displace state law.
EO 14409, 2 June 2026, covers frontier model security and cyber defence. It is silent on state law. It keeps getting cited as though it settled the question.
The Obernolte-Trahan "Great American Artificial Intelligence Act" was released as a discussion draft on 4 June 2026 and has never been formally introduced.
No federal statute or executive order has preempted these state regimes as at August 2026. Fragmentation is the base case, not the risk case. Build for it.
Why all of it collapses into one problem
Litigation is ahead of the statutes here.
The Senate Permanent Subcommittee on Investigations released "Refusal of Recovery" on 17 October 2024, under Chairman Richard Blumenthal. It found UnitedHealthcare's post-acute prior authorization denial rate rose from 10.9% in 2020, to 16.3% in 2021, to 22.7% in 2022. Its skilled nursing facility denial rate rose ninefold between 2019 and 2022, from 1.4% to 12.6%, across the period automated review under naviHealth's nH Predict was expanded.
In Estate of Gene B. Lokken et al. v. UnitedHealth Group, D. Minn. 0:23-cv-03514, filed 14 November 2023, plaintiffs plead that over 90% of denials are reversed on internal appeal or in ALJ proceedings, and that roughly 0.2% of policyholders appeal at all. Those are allegations, attributed as such.
On 9 March 2026 a federal magistrate judge granted broad discovery, ordering production across most categories plaintiffs sought, including material going to whether the tool was designed to override the clinical judgement of treating physicians. The insurer disputes that characterisation and maintains the tool does not make coverage determinations.
Strip the dispute away and one narrow point is left standing. How an automated decision was reached is discoverable, and courts will compel it.
You cannot comply with a disclosure duty you cannot evidence
Look back at the map. Texas is a timestamp. AB 3030's exemption is a review record. Illinois is a review record with a licensed name on it. Maryland is one tied to an individual clinical history. Colorado is the same question, dated 2027.
They all resolve to three facts: what the system did, who reviewed it, when. Get those wrong and the statute barely matters, because you will be arguing about a log file you cannot stand behind.
That is the problem I have been building against. APIR issues cryptographically signed credentials to agents, Ed25519, W3C Verifiable Credentials, with hash-chained audit records and independent behavioural scoring, so an organisation can evidence what an autonomous system did when a regulator, an insurer or a court asks. The check is free and public at apir.ai/check-agent, no account, and it stays that way.
We don't promise results. We prove whatever happens.
The federal standard may still arrive. It will not retroactively produce the records you did not keep.