The Multistate Patchwork Problem
Enterprises operating across state lines face uneven and evolving obligations for AI systems that influence consequential decisions about individuals. Colorado and Texas have each enacted state-level statutes addressing AI use in decisionmaking, commonly referenced as the Colorado AI Act and the Texas Responsible AI Governance Act. Other states have introduced or advanced comparable legislation over the past year.
Because state legislatures amend, delay, and in some cases repeal these provisions on their own timelines, compliance teams cannot rely on secondary summaries as a substitute for verified statutory text. What can be said with confidence is structural: any organization operating in more than one state must maintain a current map of which statutes apply. Obligations are jurisdiction-specific and are not harmonized by any single federal standard.
At a Glance: Four Foundational Steps
Before conducting deeper legal review, most compliance programs benefit from working through the same four questions in sequence:
| Step | What to Do |
|---|---|
| Jurisdiction Mapping | Identify every state where your organization deploys or offers AI-driven decision systems to individuals or businesses. |
| Definition Review | Confirm how each applicable statute currently defines "automated decision system" or "high-risk AI system" from the enacted text, not summaries. |
| Agentic Use Case Fit | Assess, with counsel, whether autonomous multi-step AI agents fall within the existing statutory definitions in each jurisdiction. |
| Documentation Trail | Maintain verifiable records of risk assessments and decision logic tied to each applicable requirement. |
Agentic AI and the Limits of Existing Definitions
Most state AI statutes were drafted to address systems that produce a single output, such as a credit score, hiring recommendation, or risk rating, which a human then reviews before acting. Definitions of "automated decision system" or "high-risk AI system" in that context typically hinge on whether the system's output is a substantial factor in a consequential decision.
Autonomous AI agents complicate this framing. An agent may take a sequence of actions, call external tools, or coordinate with other agents before producing any output a human reviews. Whether a given statute's definition extends to that kind of multi-step, tool-using behavior is a legal interpretation question that depends on the specific language of each statute.
Key judgment: Do not assume that agentic systems are automatically in or out of scope under any given statute. Treat scope as an open question requiring jurisdiction-by-jurisdiction legal review.
Verification Steps Before Asserting Compliance
Before any compliance assertion can be made, a systematic verification process should be completed for each jurisdiction. The following sequence reflects the structural approach most commonly needed:
-
Confirm statute status Verify that the statute is currently enacted, effective, and unmodified since your last review. Check the state legislature's official publication for any recent amendments or delayed effective dates.
-
Read the definition section directly Pull the exact statutory definition of "high-risk AI system," "automated decision system," or equivalent term from the enacted text. Compare it to your system's technical architecture and decision role.
-
Identify the covered entity scope Determine whether the statute applies to developers, deployers, or both, and confirm whether your organization's role in the AI value chain triggers obligations in that jurisdiction.
-
Map documentation requirements Identify what records, risk assessments, or impact evaluations the statute requires, and at what frequency. Confirm that your documentation practices satisfy those requirements as written.
-
Review disclosure obligations Determine what, if anything, must be disclosed to individuals affected by the system's output, including whether automated processing is occurring and what recourse options exist.
-
Consult qualified legal counsel Treat every statutory interpretation question, particularly scope questions involving agentic systems, as requiring legal review rather than relying on general technical analysis.
Recurring Themes Across State AI Statutes
Even without citing specific provisions, a general pattern is visible across recent state legislative activity. Statutes addressing AI systems in decisionmaking tend to focus on three areas:
- Scope and definition: How the statute defines which systems and use cases are subject to its requirements, typically anchored to the concept of a "consequential" or "high-risk" decision.
- Documentation and assessment: What records a deploying organization must produce, often including risk assessments, impact evaluations, or impact reports tied to specific use cases or affected populations.
- Individual disclosure: What notice or explanation is owed to a person affected by the system's output, including whether an individual may request human review or contest an automated determination.
The mechanics of each area vary by state. There is no basis to claim that any two states have adopted identical requirements. Enterprises operating in multiple jurisdictions should expect to produce jurisdiction-specific documentation even when the underlying AI deployment is technically identical across states. A single control set does not guarantee simultaneous compliance with different statutory language.
Operational Practices That Hold Regardless of Which Statute Applies
Because requirements vary by jurisdiction and continue to evolve, compliance programs benefit from building operational foundations that satisfy recurring structural themes rather than optimizing narrowly for any one statute. These include:
- Maintaining a current inventory of AI systems and their decision roles, including agentic deployments, with enough technical detail to evaluate scope under new or amended definitions.
- Creating traceable documentation of risk assessments tied to specific systems and use cases, rather than generic program-level descriptions.
- Establishing a defined process for monitoring legislative changes in each operating jurisdiction and triggering re-review when statutes are amended or new statutes take effect.
- Building a log of agent actions and decision outputs that can be reconstructed to support regulatory inquiries or internal audits.
- Implementing pre-deployment review for new AI agent deployments that assesses scope under applicable statutes before go-live, rather than after.
Practical note: Documentation that is produced reactively, after a regulator or individual raises a concern, is significantly harder to defend than documentation that was systematically maintained before the question arose.
Where Runtime Governance Fits
The recurring themes above, scope assessment, documentation, and individual disclosure, point to an operational need that exists regardless of which specific statute applies. Enterprises need a reliable record of what their AI agents actually did, and a mechanism to enforce boundaries on agent behavior before problems occur rather than only after.
Trussed AI provides runtime governance and security for enterprise AI agents, including runtime policy enforcement, agent identity and permissions management, least-privilege controls, tool approval workflows, and audit logging. These capabilities do not determine which state statutes apply to a given deployment. That remains a legal and jurisdictional question. They do, however, support the documentation and control expectations that recur across the state AI statutes reviewed for this guide's structural analysis.
Frequently Asked Questions
Do the Colorado and Texas AI statutes apply to my organization?
This depends on your organization's operating jurisdictions, the nature of the AI systems you deploy, and how each statute defines covered entities and covered uses. Both statutes impose obligations on organizations that deploy AI systems in contexts involving consequential decisions about individuals, but the precise scope differs. You should review the enacted text of each statute with qualified legal counsel rather than relying on general summaries.
Are autonomous AI agents covered under existing state AI statutes?
Most state AI statutes were written before autonomous, multi-step AI agents were common deployment patterns. Whether a given agent falls within a statute's definition of "automated decision system" or "high-risk AI system" depends on the specific language of that statute and how it characterizes the role of AI in consequential decisions. This is an open legal interpretation question, not a general technical one, and requires jurisdiction-specific legal review.
What documentation do most state AI statutes require?
Common documentation expectations across state AI statutes include risk assessments, impact evaluations tied to specific use cases, records describing the system's decision role, and evidence of ongoing monitoring. The precise requirements, frequency, format, and retention obligations vary by statute. You should confirm the exact requirements from the current enacted text in each applicable jurisdiction rather than relying on general descriptions.
Can a single compliance program satisfy requirements across multiple states?
A unified program can establish shared operational foundations, such as system inventories, documentation practices, and monitoring processes, that apply consistently across jurisdictions. However, because state definitions and specific requirements differ, you will likely need jurisdiction-specific documentation artifacts rather than a single document that asserts compliance with all applicable statutes simultaneously. A single control set does not guarantee compliance with materially different statutory language.
How does runtime governance support state AI compliance?
Runtime governance capabilities, including policy enforcement, agent permission controls, audit logging, and tool approval workflows, support the documentation and oversight expectations that recur across state AI statutes. They do not determine which statutes apply to your deployment. However, they provide the operational record and control infrastructure that compliance programs need to respond to regulatory inquiries and demonstrate that AI agent behavior was monitored and bounded appropriately.