If your US state AI compliance framework treats California as one of fifty equivalently weighted compliance jurisdictions, the 2016-2025 legislative output data shows the framing understates California's structural role. California has enacted 62 AI-related bills since 2016: more than double Maryland's 28, Virginia's 25, and Utah's 24. In 2025 alone California passed 20 AI-related bills, double New York's 10 and two-thirds more than Texas's 12. The Californian AI policy is now functioning as a de facto federal framework. Organisations that comply with California requirements typically meet or exceed the requirements of other US states, while the inverse is rarely true.

The cumulative state totals show the concentration clearly. The top 15 states by AI legislation count over 2016-2025:

  • California 62
  • Maryland 28
  • Virginia 25
  • Utah 24
  • New York 17
  • Texas 12
  • Illinois 12
  • North Dakota 11
  • Washington 11
  • Colorado 11
  • Florida 11
  • Massachusetts 11
  • Alabama 9
  • Arizona 9
  • Michigan 9

The distribution has a long tail. Two states (Missouri and Rhode Island) have enacted zero AI bills. Many states are in single digits. The top three states (California, Maryland, Virginia) together account for nearly 35% of all state AI legislation since 2016.

California's 2025 bills span the substantive policy categories that define US state AI law:

  • Companion chatbot regulation: SB 243 (effective January 2026) requires companion chatbot operators to disclose their AI nature, implement safety protocols related to suicidal ideation, and provide additional safeguards for minors.
  • Generative AI provenance: AB 853 requires generative AI developers to ensure their tools' content includes provenance data.
  • Nonconsensual deepfakes: AB 621 extends existing state law on nonconsensual deepfakes.
  • AI safety and transparency: SB 53 (signed September 2025) requires large AI-model developers to disclose safety protocols and incident reports and to protect whistleblowers.
  • AI Transparency Act (SB 942) earlier mandated that large generative AI tools offer watermarking and detection tools at no cost.

Beyond 2025, California's earlier AI legislation includes provisions on algorithmic decision-making, AI in employment, AI-generated political content, AI bias auditing, and AI in healthcare. The cumulative effect is a relatively comprehensive AI compliance environment that few other states match.

Three prescriptive moves follow for organisations setting US state AI compliance strategy.

The first prescriptive move: treat California compliance as the baseline US AI compliance framework. The 62 California bills span enough policy categories that an organisation building genuine California compliance has substantially built the compliance posture needed in most other US states. The reverse is not true: building compliance for a state with single-digit bill counts produces a fraction of the controls needed in California. The strategic move is to architect AI compliance around California requirements and then add specific provisions for other states where their requirements diverge.

The second move: anticipate California legislative direction in compliance planning. California has shown consistent legislative activity year-over-year. The 2026-2027 California legislative calendar will continue producing AI bills, possibly at 15-25 per year given the 2025 pace. Compliance programmes that are reactive to enacted California law will be perpetually behind. The alternative: track California legislative committees, hearings, and bill movements as a leading indicator for compliance investments. Build compliance capability in advance of bill enactment based on visible legislative momentum.

The third move: engage proactively with California policy formation. California's AI legislative process is more open to industry input than the federal process and the processes in many other states. Trade associations, technology coalitions, and individual companies can engage with California legislative committees, propose bill amendments, and shape implementation regulations. The 62-bill compliance load is partly the consequence of organisations not engaging early enough in the legislative process. The cost of compliance engagement after enactment is structurally higher than the cost of policy engagement before enactment.

The Texas counter-example illustrates the dynamic. Texas's Responsible Artificial Intelligence Governance Act (HB 149) was originally proposed as the most all-encompassing state AI legislation. The final enacted version was significantly scaled back from the original proposal, removing most private-sector obligations and focusing on uses such as behavioural manipulation and child sexual abuse material. The scaling-back reflects active industry engagement during the legislative process. The California path could have included more such scaling, but industry engagement on California AI bills has historically been less coordinated, and the enacted requirements consequently more expansive.

The Colorado example illustrates the operationalisation challenge. Colorado's Artificial Intelligence Act, signed in May 2024, was among the first state laws targeting algorithmic discrimination in decisions like hiring, housing, and medical care. In 2025, Colorado attempted to enact amendments narrowing parts of the law but instead pushed key compliance dates back to mid-2026. The case study: even sweeping state AI laws face operationalisation difficulties post-enactment, which can produce post-passage modifications or delays. Compliance frameworks that account for this operational uncertainty by building flexibility into implementation timing handle the volatility better than frameworks that commit to fixed implementation tracks.

The Montana counter-example illustrates the deregulatory option. Montana's Right to Compute Act (SB 212), signed in April 2025, established the first state-level "right to compute" affirming individuals' and businesses' rights to own and use computational resources for lawful purposes. The law limits government restrictions to those that are "demonstrably necessary and narrowly tailored to fulfill a compelling government interest." Montana represents a different state policy position, pro-innovation and anti-restriction, that exists in tension with the California model.

The structural implication: US state AI policy is now a multi-track landscape with California producing the most expansive compliance requirements, Texas and Colorado producing complex frameworks with operationalisation challenges, Montana producing pro-innovation frameworks, and many other states producing single-issue bills (companion bots, deepfakes, child safety). Organisations need to engage with each track operationally rather than treat state AI law as a single category.

For multi-state organisations setting US AI compliance strategy in 2026, the recommendation: build California compliance as the baseline, track ongoing California legislative momentum as the leading indicator for future requirements, engage proactively with California policy formation through trade and coalition channels, and supplement California-baseline compliance with state-specific provisions for Texas, Colorado, Montana, and other states whose frameworks diverge in operationally consequential ways.

Sources

  • Primary: Stanford AI Index 2026, Chapter 8 (Policy and Governance) 8.4 — hai.stanford.edu/ai-index/2026
  • State legislation tracking: AI Index 2026 state legislation database — 50-state AI bill tracking, 2016–2025
  • Key California legislation: SB 243 (companion chatbots), AB 853 (GenAI provenance), AB 621 (deepfakes), SB 53 (AI safety and transparency), SB 942 (AI Transparency Act)
  • Comparative state legislation: Texas HB 149 (Responsible AI Governance Act); Colorado Artificial Intelligence Act (2024); Montana SB 212 (Right to Compute Act, April 2025); Utah HB 452 (Mental Health Chatbot Act)