Skip to main content
Laminin Briefings

7 min read

State-Level AI Regulation: What Compliance Officers Are Actually Building for Colorado, NYC 144, and California SB 942

The US state-level AI regulatory patchwork is now real. What compliance officers are actually building for the Colorado AI Act, NYC Local Law 144, and California SB 942.

The federal AI regulatory posture has, through 2025 and into 2026, remained principally a framework and guidance posture rather than a binding-rules posture. The state-level regulatory posture, by contrast, has moved from proposed to operative in a specific set of jurisdictions that together cover a meaningful share of the US employment and consumer market. The Colorado Artificial Intelligence Act, New York City's Local Law 144, and California's SB 942 on generative AI transparency are the three that have driven the most concrete compliance work inside affected organizations, and the specific builds that compliance officers have shipped are worth naming because they contradict the assumption that state-level regulation would produce only paperwork.

The Colorado AI Act, effective February 2026, imposes a duty of reasonable care on developers and deployers of high-risk AI systems that make consequential decisions in employment, education, financial services, government services, healthcare, housing, insurance, and legal services. The specific compliance builds it has driven are more substantive than the initial industry reaction predicted. Deployer organizations have had to inventory their in-scope systems, produce impact assessments against a specific methodology, establish a consumer-facing notification and appeal process, and file the specific incident-reporting notices the statute requires when algorithmic discrimination is detected. The organizations that treated the requirement as an assessment exercise, rather than as an operational build, are the ones now trying to retrofit the appeal mechanism against systems that were not designed for it.

New York City's Local Law 144, which took effect in 2023 and has now had multiple full annual bias-audit cycles applied to it, has produced a more disciplined understanding of what a defensible bias audit actually looks like. The specific practice that has stabilized around the law is a joint scoping conversation between the employer, the vendor of any automated employment decision tool used, and an independent auditor, run against a documented data-input and outcome-metric methodology, with the summary results published on the employer's careers site as the statute requires. The specific audit failures that have produced enforcement attention have generally been on the specificity of the disclosure rather than on the underlying bias measurement, which suggests the enforcement posture will tighten around disclosure quality in the next cycle.

California's SB 942, the California AI Transparency Act, requires large generative-AI providers to make AI-detection tooling available and to embed provenance information in generated content, with compliance dates in 2026. The specific builds that have shipped in response are technical rather than administrative. Providers have implemented content-credentials embedding at generation time, have exposed public detection endpoints against their own model outputs, and have documented the specific limitations of those detection capabilities against evolving evasion techniques. The specific compliance question that has emerged, which the statute did not fully anticipate, is the treatment of content generated by non-covered smaller providers or by open-source models running on user infrastructure. The disclosure obligations do not cover that content, and the enforcement practice on the gap is not yet settled.

The pattern across the three, and across the broader wave of state-level AI legislation that will arrive over the next two legislative sessions, is that the compliance function is being asked to produce operational capabilities rather than only documentation. That shift is what separates the organizations handling this well from the ones producing paperwork against requirements they have not operationalized. Compliance officers who have staffed and tooled for an operational program are, in current conditions, absorbing new state-level requirements as they arrive with relatively contained marginal cost. Compliance officers who are running each new state-level requirement as a standalone paperwork exercise are, at some point in the next two years, going to have to rebuild the function against the operational standard the affected regulators are converging on.

For a chief compliance officer, the working question is whether the current AI compliance program has been designed against the specific state-level operational standard the leading jurisdictions have established, or against a more general framework posture. Programs designed against the general posture will meet the letter of individual state requirements but will not, without rebuild, meet the operational bar that Colorado in particular has now made concrete.

For a general counsel, the parallel question is whether the exposure the organization carries under the current state-level patchwork has been mapped clearly enough to distinguish between the jurisdictions where the operational build is required and the jurisdictions where a lighter documentation posture is defensible. Enterprises with material employee or consumer footprint in Colorado, New York, and California are, in most cases, effectively subject to the full operational standard whether or not the internal program has been sized to that reality.

  • AI Regulation
  • Compliance
  • State Law
  • General Counsel
  • Governance

Bring us a decision, not a brief.

If this piece maps to something on your plate, we'd like to hear it.

Talk to Laminin