Articles

Client Alert: AI Governance for Businesses

AI Governance in 2026: Why "Wait and See" Is No Longer a Safe Strategy

Date: October 1, 2026
Businesses have spent the last two years racing to adopt artificial intelligence. The law is now catching up unevenly, creating real exposure even for companies that assume the rules do not apply to them yet.

There is still no comprehensive federal AI statute, and no federal legislation preempting state AI regulation has been enacted. The Senate voted 99-1 to strip a proposed ten-year moratorium on state AI laws from the 2025 budget bill; a second attempt was left out of the 2026 defense bill.

In December 2025, the White House issued an executive order addressing state AI regulation. The order directs a Department of Justice task force to challenge state AI laws on constitutional grounds, requires the Commerce Department to review “onerous” state laws and conditions certain federal broadband funding. It does not itself preempt state law, and no federal court has enjoined enforcement of any of these statutes based on the order. State laws therefore remain in effect.
 

The state patchwork is live now.

Several laws are already enforceable, though their enforcement mechanisms, liability standards and jurisdictional triggers vary.
  • Texas’s Responsible Artificial Intelligence Governance Act (TRAIGA) took effect January 1, 2026. Rather than imposing a standard regulatory framework on all general business deployments, TRAIGA targets specific harmful practices. It is enforced exclusively by the state attorney general and prohibits the intentional deployment of AI for behavioral manipulation, deceptive deepfakes or unlawful biometric capture. The statute also references adherence to recognized governance frameworks, such as the NIST AI Risk Management Framework, as a factor that may be considered in evaluating compliance.
  • Illinois’s employment-AI law (HB 3773) also took effect January 1, 2026, with enforcement through the Illinois Department of Human Rights. It requires employers to provide notice when AI is used in employment decisions and broadly prohibits the use of AI that results in discriminatory effects—such as using geographic data as a proxy for race.
  • California’s Transparency in Frontier Artificial Intelligence Act (SB 53) targets developers of large-scale AI models rather than downstream business deployers. Taking effect January 1, 2026, it imposes safety and transparency frameworks but applies only to “frontier developers,” defined as those training models above a specified compute threshold, with the most extensive obligations reserved for “large frontier developers” that generate over $500 million in annual gross revenue.
  • NYC’s bias-audit requirement (Local Law 144) has been enforced by the New York City Department of Consumer and Worker Protection since 2023. It requires employers to conduct independent bias audits of automated employment decision tools and publish the results before use.
  • The Connecticut Artificial Intelligence Responsibility and Transparency Act (CART Act) takes effect October 1, 2026. It takes a targeted approach, imposing obligations on specified high-risk uses, including automated employment decision technology, AI companion chatbots (with heightened protections for minors), frontier-model developers, generative-AI content provenance and online platforms used by minors. The obligations take effect on staggered dates through January 2028. The Connecticut attorney general has exclusive enforcement authority under the statute, and the CART Act does not create a private right of action.
  • Colorado overhauled its framework. The state General Assembly repealed and reenacted its original algorithmic-discrimination law by passing SB 26-189, which was signed into law on May 14, 2026, and takes effect January 1, 2027. SB 26-189 shifts the state's regulatory focus to Automated Decision-Making Technology (ADMT). While it removed some of the original bill's annual impact assessment duties, it expands the definition of covered technology, and enforcement rests exclusively with the State Attorney General. Crucially for businesses, the new law voids contract terms that purport to shield software developers from liability for discriminatory outcomes attributable to their products. Businesses should build flexibility into their compliance programs as requirements continue to evolve.

Why mid-Atlantic businesses are already exposed. You do not need an office in Texas or California to be covered. Several of these laws reach businesses based on where their customers, employees or affected consumers are located. Because the specific jurisdictional triggers vary by statute, a Maryland, Virginia, D.C. or Delaware company serving a national market is often within scope. Multistate employers are especially exposed.

The AI-specific statutes are not the only risk. Existing anti-discrimination and consumer-protection laws already apply to AI-driven decisions. For example, Title VII’s disparate-impact prohibition, codified by statute and enforceable through private litigation, continues to apply to AI-driven hiring tools even after the EEOC withdrew its AI technical-assistance guidance in 2025. Multiple state attorneys general have also opened investigations into AI-powered consumer-facing tools. AI use additionally raises contract, intellectual property, data-privacy and trade-secret questions in every vendor agreement and internal deployment.


Steps to take now:

  • Inventory your AI systems, including tools embedded in software you already license and any use of public generative-AI tools by employees.
  • Map which state and sector-specific laws apply based on where your customers and employees are, and flag any "high-risk" or "consequential decision" uses (hiring, lending, healthcare, housing, insurance).
  • Adopt a written AI governance and acceptable-use policy, and train employees, particularly on not entering confidential or personal data into public tools.
  • Build AI terms into vendor contracts (representations, indemnities, data-use limits, audit rights) and conduct diligence on AI vendors.
  • Keep a human in the loop for consequential decisions. Document your governance and, where practicable, align it with a recognized framework such as the NIST AI Risk Management Framework, which Texas’s TRAIGA references as a compliance factor.

Whiteford's Corporate, Regulatory and Technology practices, working alongside our Labor & Employment attorneys, help businesses inventory AI use, assess multistate exposure and establish practical governance programs. To discuss how these developments affect your organization, please contact Clare Lewis at clewis@whitefordlaw.com or your Whiteford relationship attorney.
The information contained here is not intended to provide legal advice or opinion and should not be acted upon without consulting an attorney. Counsel should not be selected based on advertising materials, and we recommend that you conduct further investigation when seeking legal representation.