The most consequential AI policy story in the United States right now is not a single new law β€” it is a constitutional tug-of-war over who has the authority to regulate artificial intelligence at all. As of late July 2026, the federal government is actively trying to clear away state AI rules through litigation and funding pressure, while a bipartisan bloc of state attorneys general digs in to defend them. The outcome will shape the compliance landscape for every company deploying AI in America.

No Federal Statute, a Patchwork Below

The backdrop is a vacuum at the federal level. The US still has no comprehensive federal AI statute. Instead, binding obligations on the private sector sit almost entirely in state law, layered over voluntary federal frameworks like the NIST AI Risk Management Framework and ISO/IEC 42001. That patchwork β€” California, Texas, Illinois, Utah and others each writing their own rules β€” is precisely what the current administration wants to dismantle.

The instrument is a December 11, 2025 executive order, "Eliminating State Law Obstruction of National AI Policy," which stood up a Department of Justice AI Litigation Task Force to challenge state AI laws in court. The order also leans on funding levers to pressure states into line. It is an aggressive assertion of federal primacy over a domain Congress has not actually legislated.

The States Push Back

The pushback has been swift and, notably, bipartisan. A coalition of 36 state attorneys general has opposed broad preemption, defending their authority to protect residents from AI harms in the absence of federal rules. Their argument is straightforward: with Congress gridlocked and no federal statute on the books, states are the only bodies actually imposing enforceable duties on AI developers and deployers.

Crucially, the effort to override state law has so far produced no result. No federal statute or court has preempted or paused any state AI law β€” every state requirement remains valid and enforceable. The federal campaign is applying pressure, but it has not, to date, invalidated a single rule. For companies, that means the state obligations they face today have not gone away, whatever the political rhetoric suggests.

The State Frameworks in Motion

Even as the preemption fight plays out, the state landscape keeps shifting β€” sometimes toward narrower rules, sometimes toward later deadlines:

  • Texas has the broadest comprehensive law now in force, the Responsible AI Governance Act, which takes an intent-based approach with a safe harbor for organizations that substantially comply with the NIST framework, plus a regulatory sandbox for testing.
  • Colorado repealed its original AI Act and replaced it in May 2026 with a narrower automated-decision-making statute, pushing core duties to January 1, 2027.
  • New York's frontier-model safety law β€” requiring published safety protocols and 72-hour critical-incident reporting to the Department of Financial Services β€” takes effect January 1, 2027, with penalties up to $3 million for repeat violations.

The net effect is a moving target: obligations that vary by state, shift with amendments, and now sit under the shadow of a federal challenge to their very legitimacy.

Why It Matters

For any organization building or deploying AI, this is the defining governance uncertainty of 2026. The prudent posture is counterintuitive but clear: do not treat the federal preemption push as permission to ignore state law. Because no state rule has actually been struck down, compliance obligations remain fully in force β€” and betting on preemption that has not materialized is a legal gamble with real penalties attached.

The deeper significance is structural. The clash pits a federal government pursuing deregulation-by-preemption against states writing enforceable, risk-based rules β€” and because a handful of large states account for an outsized share of the US AI market, their standards function as a de facto national floor regardless of Washington's preferences. If the DOJ task force ultimately prevails, the country could swing toward a lighter-touch federal regime; if the states hold, the patchwork hardens into the operative reality.

Either way, the resolution will not come from a tidy new statute but from litigation, funding fights, and the slow grind of court decisions. Companies should watch the task force's cases closely, maintain compliance with the state rules that bind them now, and build governance flexible enough to survive whichever way the constitutional question breaks. In American AI policy, the biggest story is no longer any single law β€” it is the unsettled question of who gets to make the rules.

Sources