A Fragmented Compliance Landscape
Enterprise AI governance teams are currently tracking four state-level frameworks that share a common concern, oversight of high-impact AI systems, but differ substantially in scope, obligated parties, and timing. Colorado's SB 24-205 established broad duties of reasonable care for developers and deployers of high-risk AI systems, but the state legislature has since taken up a repeal-and-replace amendment process that has already pushed back the original February 2026 effective date. Texas took a narrower path with TRAIGA, focusing primarily on government use of AI and intentional discriminatory practices rather than a general private-sector duty of care. New York's RAISE Act and California's SB 53 represent a third model entirely, regulating frontier-scale foundation model developers rather than downstream enterprise deployers.
Because these four laws use different definitions of covered systems, different obligated roles, and different effective dates, a single compliance calendar or risk classification will not work across all four jurisdictions.
Legislative Status at a Glance
| State / Law | Legislative Status | Primary Scope | Effective Date | Enforcement |
|---|---|---|---|---|
| Colorado (SB 24-205) | Enacted; repeal-and-replace amendment active | High-risk AI in consequential decisions; broad private sector | Delayed from original Feb 2026; confirm current date | State Attorney General |
| Texas (TRAIGA, HB 149) | Enacted 2025 | Government use of AI; intentional discriminatory practices | January 1, 2026 | State Attorney General |
| New York (RAISE Act) | Passed legislature 2025; enactment status requires confirmation | Frontier and foundation model developers | TBD pending enactment confirmation | State Attorney General (expected) |
| California (SB 53) | Enacted 2025 | Transparency and incident reporting for frontier model developers | Enacted; confirm operative date in statute | State Attorney General |
A note on effective dates
Colorado's effective date has already shifted once. Governance teams should verify the current operative date for all four laws directly against state legislative sources before finalizing compliance timelines.
Two Distinct Regulatory Models
The four laws split into two distinct approaches. Colorado and, to a more limited extent, Texas focus on consequential decision-making systems: AI used as a substantial factor in decisions about employment, credit, housing, education, healthcare, or insurance. This model requires impact assessments and consumer-facing disclosures rather than technical testing of the underlying model.
California SB 53 and New York's RAISE Act instead target frontier or foundation models directly, using capability or scale thresholds rather than use-case categories to determine coverage. This distinction matters operationally: an enterprise deploying a narrow, task-specific model in a hiring workflow may trigger Colorado-style obligations without coming anywhere near the frontier-model thresholds in SB 53 or the RAISE Act, and vice versa.
Texas TRAIGA's narrower scope means fewer enterprise deployers of task-specific systems face direct statutory obligations compared to Colorado's broader consequential-decision framework. This increases the importance of mapping each AI system against each state's specific definition rather than applying one internal risk label across all jurisdictions.
Documentation and Disclosure Obligations
None of the four frameworks currently mandate a single certified technical standard or third-party benchmark. Obligations are instead documentation, disclosure, and risk-assessment based.
- Colorado's framework centers on impact assessments and consumer notices for high-risk systems.
- California SB 53 and New York's RAISE Act emphasize safety-protocol disclosure and structured incident reporting for frontier developers.
- Across all four states, obligations are assigned by role: developers who build or train models carry different duties than deployers who put those models into production.
- An organization acting in both capacities for the same system needs to track both sets of obligations separately.
- Enforcement in the three confirmed statutes rests with state Attorneys General, pointing toward investigatory and civil-penalty exposure rather than individual litigation risk under current statutory text.
Operational Implications for Governance Programs
Multistate enterprises face a practical sequencing problem. Colorado's obligations remain the broadest in current scope even as its effective date shifts, while Texas TRAIGA becomes operative January 1, 2026 with a materially narrower footprint. Many governance programs choose to architect controls to the most stringent applicable requirement (currently Colorado's consequential-decision framework) while separately tracking frontier-model thresholds relevant to California and New York.
This requires an AI system inventory that distinguishes consequential-decision systems from frontier-scale models, and that records which organizational role (developer or deployer) applies to each system under each statute. Runtime logging and decision-trace capture support the impact-assessment and disclosure obligations common to the consequential-decision laws. Structured incident logging, distinct from general security incident response, supports the safety-reporting obligations under SB 53 and the RAISE Act.
Trussed AI's runtime governance and audit logging capabilities are built around role-based, decision-level visibility. This is relevant context for teams evaluating tooling, but does not substitute for direct legal review of each statute's current text.
Practical Next Steps for Compliance Teams
- Confirm current effective dates for each law directly against state legislative sources. Colorado's date has already shifted once.
- Map each AI system in the enterprise inventory to the specific "high-risk" or "frontier model" definition of each applicable state, rather than applying one uniform risk label.
- Determine whether the organization is acting as developer, deployer, or both under each statute for a given system, since each role carries distinct obligations.
- Establish recordkeeping for impact assessments, consumer disclosures, and safety-incident reports. All four regimes emphasize documentation over technical certification.
- Monitor Colorado's repeal-and-replace process and New York's enactment status on a recurring basis, since both remain subject to change before becoming operative.