What Changed
In 2026, state AI legislation took an unexpected turn. Instead of focusing on automated decision system (ADS) regulation, states shifted their attention to chatbot safety. A total of 146 chatbot-related bills moved through 19 state legislatures, while comprehensive ADS bills stalled in New York and California. Colorado replaced its landmark regulation with a transparency-focused alternative, removing risk management requirements.
For your model risk team, this creates a fragmented compliance landscape. Your chatbot interfaces now face more scrutiny than your decision models, and Connecticut's requirements differ fundamentally from Colorado's approach.
Key Findings
Connecticut enacted the most comprehensive private-sector AI law. CT SB 5 requires developers to disclose information needed for deployers to comply with the law, mandates disclosure of adverse employment decisions to affected individuals, and prohibits discriminatory automated decision systems. It also launched a study of independent verification organizations and created a regulatory sandbox. Labor groups found these protections insufficient compared to their preferred bill, which included stronger privacy rights and decision review mechanisms.
Colorado walked back its ADS regulation under legal pressure. The state replaced SB 24-205 with SB 26-189, removing duty of care obligations, risk management requirements, and impact assessments. The new law focuses on transparency disclosures from developers to deployers and from deployers to affected individuals. This change occurred as xAI, joined by the Department of Justice, sued to block the original law's implementation. SB 26-189 remains the strongest ADS-style law currently in effect, but it represents a significant scaling back from the original framework.
Chatbot regulation dominated state activity, creating new compliance obligations. The 146 chatbot bills share four patterns: age verification requirements that raise privacy concerns, prohibitions on simulating emotional connections (especially for minors), mandatory protocols for suicidal ideation and self-harm, and liability structures that shield foundation model providers while targeting chatbot deployers. Only five states required internal or third-party audits of these protocols, meaning you must document your approach but rarely prove its effectiveness.
Federal frontier model legislation remained stalled. Despite focus on frontier model risks at the federal level, no bills passed in the current session. This leaves your organization navigating state-by-state requirements without federal preemption or harmonization.
What This Means for Your Team
You're managing compliance across fundamentally different regulatory philosophies. Connecticut wants transparency plus non-discrimination controls. Colorado wants transparency without risk management obligations. Chatbot-focused states want content moderation protocols without validation requirements.
This creates three immediate challenges:
Your audit scope must account for interface-specific rules. If your model powers a conversational interface accessible to consumers, you face chatbot regulations even if the underlying system wouldn't qualify as an ADS. Your validation evidence must now cover self-harm detection protocols, age verification mechanisms, and emotional manipulation safeguards that weren't in your original threat model.
Your vendor contracts need jurisdiction-specific disclosure obligations. If you're a developer, Connecticut requires you to provide deployers with compliance-relevant information. If you're a deployer, you must disclose adverse decisions to affected individuals. Your vendor due diligence checklist must now map which party holds disclosure responsibility in each state where you operate.
Your risk tiering framework must handle regulatory rollback. Colorado's shift from duty of care to transparency-only means your risk classification can't assume stable regulatory requirements. You need version control for compliance obligations, not just model versions.
Action Items by Priority
Immediate (next 30 days):
Map your chatbot footprint against the 19 states with passed legislation. Identify which systems qualify as "conversational AI" under state definitions that reference natural language interfaces, session memory, and responses beyond direct prompts. Don't assume your customer service bot escapes regulation because it serves a business function rather than consumer interaction.
Inventory your self-harm and suicidal ideation protocols. Even without audit requirements in most states, you must document and publish these protocols or report them to attorneys general. If you don't have protocols, you're non-compliant in multiple jurisdictions.
Short-term (60-90 days):
Revise your developer-deployer contracts to specify disclosure obligations by state. Connecticut's transparency requirements flow from developer to deployer. Your standard vendor agreement likely doesn't account for jurisdiction-specific information sharing that's legally mandated rather than commercially negotiated.
Build a regulatory change tracking process. Colorado's replacement of SB 24-205 with SB 26-189 happened mid-cycle under litigation pressure. You can't rely on annual compliance reviews when fundamental obligations shift within months.
Ongoing:
Evaluate independent third-party audit readiness, even though only five states currently require it. Connecticut is studying certified auditor programs. When certification frameworks emerge, you'll need validation evidence that an external party can review. Start documenting model limitations and use restrictions, data lineage, and bias mitigation approaches in auditor-ready formats now.
Monitor chatbot liability structures. Current laws shield foundation model providers while targeting deployers. If you're fine-tuning or hosting someone else's model in a conversational interface, you own the compliance risk. Your vendor risk management must account for this asymmetry.



