Quick Takeaways
What you'll learn in this article
- 1
Implement pre-deployment safety protocols including red-teaming
- 2
Establish and publish safety incident reporting procedures
- 3
Maintain documentation of model capabilities and limitations
- 4
Report safety-relevant incidents to a state oversight body
- 5
Mandatory disclosure when AI systems make decisions affecting individuals
Keep reading for detailed implementation, code examples, and real-world results
The collision has been building since January 1, when a wave of state AI laws took effect across the country. California's Transparency in Frontier AI Act. Texas's Responsible AI Governance Act. Colorado's delayed but still pending AI Act. As I covered in my analysis of the state-by-state AI regulation patchwork, 38 states enacted AI legislation in 2025, creating a regulatory maze that takes effect this year.
Now the federal government is responding, and the response is not what the AI industry expected. President Trump's December 2025 executive order did not propose federal AI legislation. It directed the Commerce Department to identify "burdensome state AI laws" within 90 days. That 90-day deadline lands in early March 2026. When the Commerce Department delivers its report, the question shifts from academic to operational: will the federal government attempt to preempt state AI laws, and if so, on what constitutional basis?
This is not a hypothetical legal debate. It is a business planning crisis. Every major AI company, every enterprise deploying AI, and every startup building AI products needs to know which regulations apply. Right now, nobody knows. And the March deadline, rather than providing clarity, is likely to increase uncertainty before it decreases.
Leading States in AI Legislation (2025-2026)
| state | AI Laws Enacted | Effective Jan 2026 |
|---|---|---|
| California | 17 | 12 |
| Texas | 8 | 5 |
| Colorado | 6 | 3 |
| New York | 11 | 7 |
| Illinois | 5 | 4 |
| Virginia | 4 | 3 |
| Washington | 5 | 4 |
What the Executive Order Actually Says
The December 2025 executive order is worth reading carefully because its language is more aggressive than initial reporting suggested. The order does not simply request a review of state AI regulations. It frames state laws as potential obstacles to federal policy objectives and American competitiveness.
Three provisions matter most:
The 90-Day Review. The Commerce Department must compile a report identifying state AI laws that create "substantial burdens on interstate commerce, innovation, or the development and deployment of AI systems." The framing is deliberate. By tying state regulation to interstate commerce, the administration is laying the groundwork for a Commerce Clause preemption argument.
The Innovation Mandate. The order directs federal agencies to prioritize "American leadership in artificial intelligence" and characterizes regulatory barriers as threats to national competitiveness. This positions AI deregulation as a national security priority, which potentially invokes federal supremacy arguments beyond the Commerce Clause.
The Coordination Directive. Federal agencies are instructed to "coordinate with state and local governments to reduce regulatory fragmentation." This sounds collaborative but carries an implicit threat. Coordination that fails often becomes preemption in subsequent executive actions.
The administration has not publicly committed to preempting state laws. But the infrastructure for preemption, the legal framework, the economic analysis, the competitiveness argument, is being assembled within the 90-day review period.
State AI Legislation by Focus Area (2025-2026)
| Name | Value |
|---|---|
| Safety / Transparency | 35 |
| Deepfake / Content Auth | 20 |
| Employment / Hiring | 15 |
| Healthcare AI | 12 |
| Criminal Justice | 8 |
| Education | 5 |
| Financial Services | 5 |
The Three State Laws That Matter Most
While 38 states passed AI legislation, three laws are drawing the most federal attention because they impose substantive requirements on AI developers and deployers operating nationally.
California's Transparency in Frontier AI Act
Effective January 1, 2026, California's law requires developers of frontier AI systems to:
- Implement pre-deployment safety protocols including red-teaming
- Establish and publish safety incident reporting procedures
- Maintain documentation of model capabilities and limitations
- Report safety-relevant incidents to a state oversight body
California's law matters disproportionately because of where AI companies are headquartered. OpenAI, Anthropic, Google DeepMind, Meta AI, and most of the frontier model developers are California companies. Even if the law technically applies only to operations within California, the practical reality is that companies headquartered in the state will implement these requirements globally rather than maintain separate California-specific processes.
The AI industry's reaction has been mixed. Companies that already have safety practices in place, which includes most frontier developers, view the transparency requirements as manageable. Smaller companies and startups worry that the compliance burden will create barriers to entry that benefit incumbents.
Texas's Responsible AI Governance Act
Texas took a different approach from California, focusing on disclosure and risk management rather than prescriptive safety requirements:
- Mandatory disclosure when AI systems make decisions affecting individuals
- Risk management frameworks for high-impact AI deployments
- Consumer rights to know when AI is involved in consequential decisions
- Enforcement through the Texas Attorney General's office
Texas's law is notable because it comes from a state with a historically deregulatory posture. When Texas decides that AI needs governance guardrails, it signals that the political alignment on AI regulation does not follow traditional partisan lines. The law is pro-business in its structure, emphasizing risk management over prescriptive safety requirements, but it still imposes real obligations on AI deployers.
Colorado's AI Act (Delayed to June 30)
Colorado's AI Act was originally scheduled to take effect February 1, 2026. It was delayed to June 30, and the timing of that delay is suspicious. The postponement came after the federal executive order was issued, and Colorado officials cited a desire to "align with emerging federal guidance" as part of the reasoning.
This delay is potentially the first visible evidence of federal pressure working. If the Commerce Department's March report recommends preemption and Colorado had already deferred to federal signals before the report even published, other states may follow suit.
Colorado's law is important because it goes further than California or Texas in regulating algorithmic decision-making in employment, housing, and credit. It requires impact assessments for high-risk AI systems and gives consumers rights to contest AI-driven decisions. If it survives the federal preemption question, it becomes the model for states that want to protect consumers from AI harms.
Comparison of Major State AI Laws (Stringency 1-5)
| requirement | California | Texas | Colorado |
|---|---|---|---|
| Safety Protocols | 5 | 2 | 4 |
| Transparency | 5 | 4 | 4 |
| Consumer Rights | 3 | 3 | 5 |
| Risk Management | 4 | 4 | 5 |
| Enforcement | 4 | 3 | 4 |
The Constitutional Question
Federal preemption of state laws is not new. The federal government has preempted state regulations in areas ranging from food safety to financial services. But AI regulation presents unique constitutional challenges that make preemption less straightforward than the executive order implies.
The Commerce Clause Path
The strongest federal preemption argument runs through the Commerce Clause. AI systems operate across state lines by nature. A model trained in California, hosted in Virginia, and serving users in all 50 states cannot easily comply with different requirements in each jurisdiction. The federal government could argue that state AI laws create an undue burden on interstate commerce, similar to the argument used to preempt state truck weight limits and railroad safety standards.
The weakness of this argument is that state consumer protection laws have historically survived Commerce Clause challenges when they address local harms. California's privacy laws, for example, have withstood federal preemption attempts for decades. State AI laws that focus on protecting residents from AI harms, rather than regulating AI technology itself, may be similarly resilient.
The Supremacy Clause Path
If the federal government passes comprehensive AI legislation, the Supremacy Clause would give it clear preemptive authority over conflicting state laws. But Congress has not passed comprehensive AI legislation and shows no indication of doing so in the current session. An executive order alone does not have the same preemptive force as legislation.
The administration could attempt to argue that the executive order establishes federal policy with which state laws conflict, but this is a weaker argument that courts would likely scrutinize carefully. Executive orders direct federal agencies. They do not directly regulate state legislative authority.
The Practical Reality
Even if the federal government has constitutional authority to preempt state AI laws, exercising that authority through executive action rather than legislation would face immediate legal challenges. State attorneys general in California, New York, and other states with active AI legislation would likely file lawsuits challenging federal preemption. These cases could take years to resolve, creating exactly the kind of regulatory uncertainty that the executive order claims to prevent.
Projected Growth: State AI Laws vs Federal AI Actions (2026)
| month | State Laws Active | Federal Actions |
|---|---|---|
| Jan 2026 | 28 | 1 |
| Mar 2026 | 32 | 3 |
| Jun 2026 | 38 | 5 |
| Sep 2026 | 42 | 7 |
| Dec 2026 | 45 | 8 |
What the AI Industry Actually Wants
The AI industry's position on state regulation is more nuanced than "no regulation." In conversations with AI policy leaders at major companies, a consistent pattern emerges: the industry wants regulation, but it wants one set of regulations rather than 50.
Large AI companies prefer federal regulation because they can influence a single federal framework more effectively than 50 state legislatures. Anthropic, which just raised a massive new funding round that values the company at $350 billion, has publicly supported "thoughtful AI regulation." OpenAI has an entire policy team dedicated to engaging with regulators. Google and Microsoft have published detailed AI governance frameworks. These companies are not anti-regulation. They are anti-fragmentation.
Startups and smaller AI companies fear any regulation because compliance costs fall disproportionately on smaller organizations. A safety testing requirement that costs Anthropic 0.1% of its budget might cost a 10-person startup 20% of its runway. State regulation, with its varying requirements and compliance timelines, is particularly punishing for startups that lack dedicated legal and policy teams.
Enterprise AI deployers want clarity above all. Companies using AI in healthcare, finance, and critical infrastructure need to know which rules apply. The current regulatory uncertainty, where it is unclear whether California's safety requirements will be preempted by federal action before companies finish implementing them, creates a planning paralysis that slows AI adoption.
Stakeholder Preferences: Federal vs State AI Regulation (%)
| stakeholder | Federal Preference | State Tolerance |
|---|---|---|
| Frontier AI Labs | 85 | 40 |
| AI Startups | 70 | 25 |
| Enterprise Users | 90 | 30 |
| Civil Society | 50 | 80 |
| State AGs | 20 | 95 |
The Three Scenarios After March
The Commerce Department's March report will trigger one of three outcomes, each with dramatically different implications for the AI industry.
Scenario 1: Aggressive Federal Preemption (25% Probability)
In this scenario, the administration uses the Commerce Department report to justify immediate executive action preempting specific state AI laws. The administration argues that state regulations create an unconstitutional burden on interstate commerce and directs federal agencies to treat state AI laws as superseded by federal policy.
Implications: Immediate legal challenges from California and New York. Multi-year litigation uncertainty. Companies face impossible compliance decisions while cases are pending. The AI industry gets neither the regulation it wants nor the deregulation it claims to want, just chaos.
Who wins: No one in the short term. Large AI companies gain long-term if preemption survives judicial review, but the years of uncertainty are damaging.
Scenario 2: Cooperative Framework (45% Probability)
The Commerce Department report identifies areas of overlap and conflict among state laws, then proposes a voluntary federal framework that states can adopt. States that align with the federal framework receive incentives like federal AI funding, research grants, and regulatory sandboxes. States that do not align face no penalty but also receive no support.
Implications: Gradual harmonization as states voluntarily adopt federal standards. Some states, particularly California, maintain their own stricter requirements. The regulatory landscape simplifies over 2-3 years but remains fragmented in the interim.
Who wins: Everyone, gradually. This is the boring, effective outcome that policy experts recommend but political dynamics rarely produce.
Scenario 3: Report Without Action (30% Probability)
The Commerce Department delivers its report, the administration makes public statements about regulatory burden, but no concrete preemptive action follows. State laws remain in effect. The report becomes a talking point rather than a policy instrument.
Implications: State regulation continues to proliferate. Companies continue navigating the patchwork. The regulatory landscape becomes more complex over time, not less. Eventually, the fragmentation becomes severe enough that Congress acts, but that timeline extends into 2027 or 2028.
Who wins: State attorneys general and civil society organizations that prefer state-level accountability. AI companies lose because they must continue multi-state compliance without harmonization.
Probability Distribution: Post-March Federal Response Scenarios
| Name | Value |
|---|---|
| Aggressive Preemption | 25 |
| Cooperative Framework | 45 |
| Report Without Action | 30 |
The International Dimension
The federal-state collision does not exist in a vacuum. The global AI regulatory landscape is evolving simultaneously, and international dynamics are influencing domestic policy decisions.
The EU AI Act is the most comprehensive AI regulatory framework in the world. Its tiered risk-based approach has become the de facto template for AI regulation globally. California's Transparency in Frontier AI Act borrows heavily from the EU Act's safety assessment requirements. If federal preemption eliminates these state-level safety requirements, it creates a regulatory gap between US and EU standards that complicates international operations for American AI companies.
China's AI regulation has taken a different path, focusing on content control and algorithmic transparency. China requires AI-generated content to be labeled, mandates algorithmic audits, and maintains approval authority over new AI services. The existence of Chinese AI regulation undermines the American competitiveness argument for deregulation. If China can regulate AI while maintaining an active AI industry, as demonstrated by DeepSeek's continued innovation in open-weight models, the claim that regulation inherently harms competitiveness needs stronger evidence.
Japan, South Korea, and Brazil are all developing AI governance frameworks that draw elements from both the EU and US approaches. The regulatory choices the US makes in 2026 will influence whether these countries align with American or European standards, with significant implications for global AI interoperability.
Global AI Regulatory Stringency Comparison (1-5 Scale)
| jurisdiction | Safety Requirements | Transparency | Consumer Rights |
|---|---|---|---|
| EU | 5 | 5 | 5 |
| California | 4 | 4 | 3 |
| China | 3 | 4 | 2 |
| US Federal | 1 | 1 | 1 |
| Japan | 2 | 3 | 2 |
The Corporate Compliance Dilemma
For AI companies and enterprises deploying AI systems, the March deadline creates an immediate planning problem. Do you invest in state-level compliance now, or do you wait to see if federal preemption makes that investment unnecessary?
The answer depends on risk tolerance, and the calculus is different for different types of organizations.
Frontier AI developers should comply with California's law regardless of federal action. They are headquartered in California, they are already implementing most of the required safety practices, and non-compliance creates reputational risk that far exceeds compliance costs. OpenAI, Anthropic, and Google are already doing this.
Enterprise AI deployers in regulated industries should implement the strictest applicable requirements. A healthcare company using AI for diagnostic support cannot afford to gamble on federal preemption. If preemption fails and the company is found non-compliant with state law, the liability exposure is existential.
Startups and smaller AI companies face the hardest decision. Compliance costs are proportionally much higher, and the uncertainty about which requirements will survive federal review makes planning difficult. The pragmatic approach is to comply with the most stringent applicable state law, which de facto means California, since that compliance will likely satisfy requirements in every other jurisdiction.
The irony is that the executive order's attempt to reduce regulatory burden may actually increase compliance costs in the short term. Companies now need to track not only existing state laws but also potential federal preemption actions, ongoing litigation, and evolving federal frameworks. The regulatory landscape was complex before the executive order. Now it is complex and uncertain.
Projected AI Compliance Costs and Regulatory Uncertainty (Indexed, Q1 2026 = 100)
| quarter | Compliance Cost | Uncertainty Index |
|---|---|---|
| Q1 2026 | 100 | 60 |
| Q2 2026 | 130 | 85 |
| Q3 2026 | 145 | 75 |
| Q4 2026 | 155 | 65 |
| Q1 2027 | 140 | 50 |
What History Tells Us
Federal preemption of state technology regulation has a mixed track record, and the precedents are not encouraging for the current administration's approach.
The Internet Tax Freedom Act (1998) successfully preempted state taxation of internet access. But this was legislation passed by Congress, not an executive order. It had bipartisan support and addressed a clear interstate commerce concern. The AI regulation context is fundamentally different: there is no congressional consensus, the harms being regulated are more tangible than internet taxation, and state laws are already in effect rather than being preempted before implementation.
The National Childhood Vaccine Injury Act (1986) preempted state tort claims against vaccine manufacturers. This is sometimes cited as a precedent for AI liability preemption, but it included a federal compensation fund as a quid pro quo. The AI executive order proposes no equivalent federal framework to replace the protections that state laws provide.
The REAL ID Act (2005) established federal standards for state-issued identification. States resisted implementation for over a decade, with full compliance not achieved until 2023. If federal AI standards follow this timeline, the harmonization benefit does not arrive until the 2030s.
State privacy laws provide the most relevant precedent. The California Consumer Privacy Act (CCPA) has survived multiple federal preemption attempts. Federal privacy legislation has been proposed and failed repeatedly. State privacy laws continue to proliferate. There are now 15 state privacy laws in effect. AI regulation appears to be following exactly the same pattern.
The Parallel Trajectory: State Privacy Laws vs State AI Laws
| year | State Privacy Laws | State AI Laws |
|---|---|---|
| 2018 | 1 | 0 |
| 2020 | 3 | 2 |
| 2022 | 6 | 5 |
| 2024 | 12 | 15 |
| 2026 | 15 | 38 |
The March Deadline: What to Actually Watch
When the Commerce Department delivers its report, the details matter more than the headlines. Here is what to look for:
Specific laws named. If the report names California's Transparency in Frontier AI Act as burdensome, that signals aggressive preemption is on the table. If it speaks in generalities about regulatory fragmentation without naming specific laws, the report is likely a political document rather than a legal roadmap.
Constitutional arguments. The legal theories the report advances will determine the viability of preemption. Commerce Clause arguments are stronger than executive authority arguments. If the report relies on executive power alone, state challenges will likely succeed.
Industry reaction. Watch for statements from Anthropic, OpenAI, Google, and Microsoft. If frontier AI companies endorse the report, federal preemption gains momentum. If they distance themselves, emphasizing their support for safety standards, preemption becomes politically harder to pursue.
State AG responses. California Attorney General Rob Bonta and New York Attorney General Letitia James have both signaled willingness to defend state AI laws against federal preemption. Their immediate reactions will indicate whether litigation is imminent.
Congressional action. If the report is accompanied by a congressional AI bill, the dynamics change entirely. Legislation has much stronger preemptive force than executive action. But the current Congress has shown no ability to pass comprehensive AI legislation.
Signals to Watch: Indicators of Federal Preemption Likelihood (%)
| signal | Preemption Likelihood |
|---|---|
| Specific Laws Named | 85 |
| General Language Only | 30 |
| Commerce Clause Args | 65 |
| Executive Power Only | 20 |
| Congressional Bill | 90 |
| Industry Endorsement | 70 |
The Deeper Question
The federal-state AI regulation collision is ultimately about a question that America has been debating since the Constitution was ratified: who decides?
States argue that AI systems create local harms: discriminatory hiring algorithms affect local workers, biased lending models affect local communities, deepfakes target local elections. Local harms, the argument goes, require local accountability. A state attorney general can respond to AI harms affecting their constituents faster and more directly than a federal agency.
The federal government argues that AI is inherently national and global in scope. Fragmented regulation creates compliance costs that slow innovation, disadvantage American companies against international competitors, and produce inconsistent protections that confuse consumers rather than helping them.
Both arguments have merit. The honest answer is that America needs both federal standards for baseline protections and state flexibility for local conditions. The dishonest answer, which the current political dynamic may produce, is an all-or-nothing fight that leaves both levels of government weakened and the AI industry without the clarity it needs.
The March deadline will not resolve this tension. But it will determine whether the resolution comes through collaboration or litigation. As I explored in my prediction that AI agent governance frameworks will become enterprise requirements by Q4 2026, the market is not waiting for government to figure this out. Enterprises are building their own governance frameworks regardless of what Washington and Sacramento decide.
The companies that build those frameworks well will be ready regardless of which regulatory scenario unfolds. The companies that wait for regulatory certainty before acting on governance will be caught unprepared no matter what happens in March.
Sources
- New State AI Laws Effective January 1, 2026 - King & Spalding
- AI in February 2026: Three Critical Global Decisions - ETC Journal
- 2026 New Laws: States, Elections, AI - NBC News
- Colorado Delays AI Act to June 30 - Colorado General Assembly

