US State and Local AI Laws
How New York City's bias-audit law, Colorado's rewritten AI Act and California's frontier-model and automated-decision rules create a moving patchwork, and why federal preemption pressure makes the effective dates less stable than the statutes suggest.
A hiring tool advances 40 of 100 applicants in one demographic category and 24 of 80 in another. The selection rates are 0.40 and 0.30, and New York City's rules define the impact ratio as a category's selection rate divided by the rate of the most selected category: \(0.30/0.40 = 0.75\). Under the federal four-fifths rule of thumb it would draw attention. Under NYC Local Law 144 it has to be published, and nothing else follows automatically. That gap between measuring and acting runs through US subnational AI law, which as of September 2026 is a patchwork whose dates keep moving.
This concept covers the US layer that sectoral rules and overlapping regimes only touches on.
New York City: disclosure without a threshold
Local Law 144 has been enforced since 5 July 2023. An employer or employment agency may not use an automated employment decision tool (AEDT) unless an independent auditor has run a bias audit within the past year, the results summary is public, and candidates got notice. The implementing rule defines both measures (NYC DCWP rule). For tools that classify, the selection rate is the share of a category moved forward. For tools that score, the scoring rate is the share of a category scoring above the sample median. Impact ratios must be reported by sex, by race/ethnicity and intersectionally. Auditors may leave out categories below 2% of the data, and an auditor who helped develop, distribute or use the tool is not independent.
The law sets no pass mark, requires no mitigation, and leaves the employer to decide what "in scope" means. That last point is where most of the criticism has landed: an employer who says a human makes the final call can argue the tool does not "substantially assist" the decision. Enforcement has been thin too. A December 2025 New York State Comptroller audit called it ineffective: the city agency reviewed 32 published bias audits and found one compliance issue, where the Comptroller's reviewers found at least 17 (DLA Piper summary of the audit).
Colorado: a comprehensive law, rewritten before it bit
Colorado's SB 24-205 (2024) was the first broad US state law on high-risk AI: developer and deployer duties of reasonable care against algorithmic discrimination, impact assessments, and notices for consequential decisions. It was due to take effect on 1 February 2026. In August 2025, SB 25B-004 pushed that to 30 June 2026 after a special session failed to agree amendments (Colorado General Assembly, SB 24-205).
xAI sued in federal court on 9 April 2026, the US Department of Justice joined on 24 April arguing compelled speech and impermissible race- and sex-conscious obligations, and on 27 April a stipulated court order paused state enforcement until after a ruling on xAI's motion for a preliminary injunction (McDermott Will & Schulte analysis). On 14 May 2026 the governor signed SB 26-189, which repeals and re-enacts the law around "automated decision-making technology" that materially influences a consequential decision, effective 1 January 2027 (Norton Rose Fulbright analysis). The replacement drops impact assessments and the affirmative anti-discrimination duty. In their place: developer documentation to deployers, consumer notice, a plain-language explanation of an adverse outcome within 30 days, correction of inaccurate data, and, on request after an adverse outcome, meaningful human review by someone with authority to override the system. The Attorney General enforces it, with no private right of action.
California: frontier models and automated decisions
California regulates at both ends. SB 53, the Transparency in Frontier Artificial Intelligence Act, was signed on 29 September 2025 and has applied since 1 January 2026. It covers frontier models trained with more than \(10^{26}\) operations, ten times the EU's systemic-risk presumption, and puts most duties on "large frontier developers" with more than $500 million in annual revenue: publish a frontier AI framework, publish transparency reports at deployment, report critical safety incidents to the Office of Emergency Services within 15 days, and protect whistleblowers, with civil penalties of up to $1 million per violation (SB 53 bill text).
At the other end, the California Privacy Protection Agency's regulations, approved on 22 September 2025 and effective 1 January 2026, give consumers rights to pre-use notice, opt-out and access for automated decision-making technology used in a "significant decision": financial or lending services, housing, education, employment or healthcare. Businesses already using such technology must comply by 1 January 2027 (CPPA, CCPA updates, cybersecurity audits, risk assessments and ADMT).
When it breaks
Federal preemption pressure makes every date provisional. Executive Order 14365 of 11 December 2025 directed the Attorney General to set up an AI Litigation Task Force to challenge state AI laws, tied some federal broadband funding to state AI policy, and named Colorado's law as an example (The White House, EO 14365). Colorado shows the effect: litigation reshaped a statute before it applied. Supporters of preemption argue a 50-state patchwork taxes every deployment; state officials and civil-rights groups argue that without federal rules, preemption means no rules.
Definitions do not line up. Colorado's "materially influences", California's "significant decision" and NYC's "substantially assist" draw different boundaries around the same product. Map obligations to controls, not labels.
Disclosure regimes can measure without improving. An impact ratio of 0.75 published on a careers page satisfies LL144. Whether anyone acts on it depends on employment-discrimination law, which applies anyway and does have teeth.
Building to the rewritten law is a bet. Teams that built impact-assessment programmes for SB 24-205 found them not required by its successor. The durable investments are the ones every regime asks for in some form: inventory, notice, explanation of adverse decisions, human review with real authority, and outcome testing by group.
7 flashcards for this concept
Click a card to reveal the answer.