Congress has not passed a federal AI law, and it does not look close to one. That vacuum is exactly why state attorneys general have become the most consequential AI regulators in the country right now, and why the pace of activity out of their offices has picked up sharply through 2025 and into 2026. If you run compliance, legal, or risk for a regulated company and you have been tracking the EU AI Act while treating state AG activity as background noise, I think you have the risk backwards. The EU AI Act takes years to bite. A state attorney general can open an investigation this quarter.
I want to walk through what is actually live right now: which AGs have enforcement authority written directly into new AI statutes, which are using their existing consumer protection powers against AI claims, and where the multistate coordination is heading. This is not speculative. Every example below is a statute, a settlement, or a public guidance document you can pull and read yourself.
Why Attorneys General, Not Federal Agencies
The FTC has authority under Section 5 of the FTC Act to police unfair or deceptive practices, and it has used that authority against AI companies through actions like Operation AI Comply. But the FTC is one agency with national jurisdiction and finite staff. State attorneys general are fifty-plus separate offices, each with its own consumer protection statute, its own civil investigative demand power, and its own political incentive to be seen acting on the issue voters are asking about.
That combination matters. An AG does not need a new AI-specific law to open an investigation. Every state has some version of a deceptive trade practices act, and "we used AI, so normal advertising rules don't apply to our accuracy claims" has never been a defense that has held up. Attorneys general have been quick to treat AI marketing claims as ordinary consumer protection matters, and several new state AI statutes now hand them enforcement authority explicitly, with no private right of action, meaning the AG is the only one who can bring the case.
The Case That Set the Pattern: Texas and Pieces Technologies
If you want one case study that shows where this is headed, look at the Texas Attorney General's September 2024 settlement with Pieces Technologies, a company that sold AI-generated clinical documentation summaries to hospitals. Texas Attorney General Ken Paxton's office alleged the company overstated the accuracy of its AI outputs to healthcare providers under the Texas Deceptive Trade Practices Act, without needing any AI-specific statute to bring the claim. The settlement, an Assurance of Voluntary Compliance, runs for five years, with Pieces eligible to request early rescission after the first year; it requires the company to submit to ongoing compliance monitoring, notify customers of known or potential harms, and stop making unsubstantiated accuracy and safety claims about its AI system.
No new law was required to bring that case. The lesson for any company selling AI into healthcare, financial services, or other regulated sectors is that your accuracy and validation claims are already enforceable under laws that have existed for decades, and an attorney general does not need to wait for AI-specific legislation to test them.
Texas Doubles Down With TRAIGA
Texas has now gone further. The Texas Responsible AI Governance Act, House Bill 149, took effect January 1, 2026, and it puts enforcement exclusively in the hands of the Texas Attorney General. There is no private right of action under TRAIGA — an individual harmed by a covered AI system cannot sue the developer or deployer directly. Only the AG can bring an enforcement action, and the statute builds in a cure period: the AG's office must give written notice of a violation and the company generally has an opportunity to fix it before penalties attach. Civil penalties under TRAIGA scale by violation type and whether the conduct was curable or involved intentional misuse, reaching into six figures per violation for the most serious conduct.
That structure, exclusive AG enforcement plus a cure period, is becoming the template other states are copying. It gives companies a real chance to correct course, but it also means the AG's office is the only audience whose judgment matters. There is no plaintiff's bar looking for a test case. There is one prosecutor's office deciding what "curable" means in practice.
Colorado's AI Act: Enforcement Delayed, Not Cancelled
Colorado's SB 24-205, the Colorado AI Act, was the first comprehensive state law targeting "high-risk" AI systems used in consequential decisions like employment, lending, housing, and healthcare. It gives the Colorado Attorney General exclusive enforcement authority, again with no private right of action, and it includes a rebuttable presumption of reasonable care for developers and deployers who maintain a documented risk management program aligned with a recognized framework such as NIST AI RMF or ISO/IEC 42001.
The original effective date was pushed back once already: lawmakers moved it from February 1, 2026 to June 30, 2026 to give businesses more runway and to let the legislature revisit some provisions.
That delay is worth sitting with for a second, because it tells you something about how these laws actually get enforced. A postponed effective date is not the same as a postponed risk.
Companies operating in Colorado now have a defined runway to build the documented risk management program that earns them the statute's affirmative defense, and June 30, 2026 is closer than the calendar makes it feel once you account for the time it takes to run a real AI risk assessment across every high-risk use case in your business. If you have not started, an outside AI risk assessment is the fastest way to find out where your gaps actually sit before the Colorado AG's office does.
California: Old Laws Applied to New Systems
California has taken a different path, at least at first. Rather than leading with a single comprehensive AI statute, Attorney General Rob Bonta's office published legal guidance in January 2025 that put businesses on notice that existing California law, the Unfair Competition Law, the California Consumer Privacy Act, and the state's civil rights statutes, already applies fully to AI systems. The guidance walked through specific scenarios: AI tools used in hiring that produce discriminatory outcomes, AI-driven pricing or lending decisions, and AI chatbots that mislead consumers about who or what they are talking to.
The message in that guidance is worth stating plainly: California is not waiting for a comprehensive AI law to start enforcing against AI-related harm. It is treating "the system is AI" as irrelevant to whether the underlying conduct is already illegal. California has also layered new AI-specific statutes on top of that baseline, including AB 2013's AI training data transparency requirements, which took effect January 1, 2026 and puts enforcement in the Attorney General's hands.
The Multistate Signal: AGs Are Coordinating
Individual state action is one thing. What should get a compliance officer's attention is coordination. In August 2025, a bipartisan coalition of attorneys general representing dozens of states sent a joint letter to major AI companies raising concerns about chatbot interactions with minors, following reporting on child safety incidents tied to AI companion products. That kind of joint letter is not a lawsuit, but it is a signal: when AGs across party lines are willing to sign the same letter, it usually means legislative and enforcement activity is not far behind, and it means no single state's regulatory posture is the whole picture.
The National Association of Attorneys General has also stood up AI-focused working groups that let offices share investigative techniques and coordinate on multistate settlements, the same infrastructure that produced multistate tobacco, opioid, and data-breach settlements in prior decades. If your AI governance program is built to satisfy only the state where you are headquartered, you are underbuilding it. A multistate AG coalition does not care where your headquarters sits; it cares where your product touches consumers.
Comparing the Major State AG Enforcement Regimes
| State | Statute / Authority | AG Enforcement Structure | Effective Date | Private Right of Action |
|---|---|---|---|---|
| Texas | TRAIGA (HB 149) | Exclusive AG enforcement, written notice + cure period, tiered civil penalties | January 1, 2026 | None |
| Texas | Deceptive Trade Practices Act (used against AI claims) | AG civil investigative demand + enforcement | Pre-existing law | Limited, consumer claims possible |
| Colorado | AI Act (SB 24-205) | Exclusive AG enforcement, rebuttable presumption for documented risk programs | June 30, 2026 (delayed from Feb 1, 2026) | None |
| California | UCL, CCPA, civil rights statutes (per AG guidance, Jan. 2025) | AG enforcement under existing consumer protection and privacy law | Pre-existing law | Varies by statute |
| California | AB 2013 (AI training data transparency) | AG enforcement | January 1, 2026 | None specified |
What This Means If You Operate in a Regulated Industry
I have said this to clients directly and I will say it here: the absence of a federal AI law is not a compliance gap you can rely on. It is a jurisdictional patchwork, and patchworks are harder to comply with than a single clear rule, not easier. A financial services company operating in Texas, Colorado, and California today is answering to three different enforcement postures:
- Texas — a cure-period statute with tiered civil penalties
- Colorado — a rebuttable presumption tied to a documented risk management program
- California — decades-old consumer protection law applied to a new technology
None of those three postures forgive a company that has no documentation of how its AI systems were evaluated, tested, or monitored.
The common thread across all three, and across the multistate letters, is documentation. Texas's cure period only protects you if you can show what you knew and when you fixed it. Colorado's rebuttable presumption only applies if your risk management program is actually documented against a recognized framework. California's AG guidance leans hard on whether a company can show it tested its AI system for discriminatory outcomes before deploying it, not after a complaint arrives. An AI governance program built around ISO/IEC 42001 or the NIST AI RMF is not a compliance nicety in this environment. It is the paper trail that determines whether you get a cure period or a consent decree.
Frequently Asked Questions
Do state attorneys general need an AI-specific law to bring an enforcement action against an AI company? No. Texas Attorney General Ken Paxton's September 2024 settlement with Pieces Technologies was brought entirely under the state's existing Deceptive Trade Practices Act, with no AI-specific statute involved. Any state consumer protection law that prohibits unfair or deceptive practices can reach misleading claims about an AI system's accuracy, safety, or capabilities.
Which states currently give their attorney general exclusive enforcement authority over AI? Texas, under TRAIGA (HB 149), effective January 1, 2026, and Colorado, under the Colorado AI Act (SB 24-205), effective June 30, 2026, both vest enforcement exclusively in the state attorney general and do not create a private right of action, meaning individuals cannot sue directly under these statutes.
Why was Colorado's AI Act effective date delayed? Colorado lawmakers pushed the Colorado AI Act's effective date from February 1, 2026 to June 30, 2026 to give businesses additional time to build compliance programs and to allow the legislature to revisit specific provisions before enforcement began. The delay changed the timeline, not the underlying enforcement structure or the Attorney General's exclusive authority.
Does having a documented AI risk management program actually reduce legal exposure? Under Colorado's AI Act, yes, directly: the statute creates a rebuttable presumption of reasonable care for developers and deployers that maintain a risk management program aligned with a recognized framework such as NIST AI RMF or ISO/IEC 42001. Other states' enforcement postures, including Texas's cure-period structure and California's guidance-based approach, both put significant weight on whether a company can document its pre-deployment testing and ongoing monitoring.
How does multistate AG coordination change the compliance picture for a national company? A joint letter or multistate investigation means a company cannot treat AI compliance as a single-state problem. Practically, that argues for one governance program mapped to a recognized framework like NIST AI RMF or ISO/IEC 42001 that satisfies the strictest applicable state's requirements, rather than maintaining separate compliance efforts state by state. The National Association of Attorneys General's AI working groups give offices a shared pipeline for investigative techniques and settlement templates, so a gap surfaced in one state's inquiry can reach another office before you hear about it.
If your AI governance program was built around a single jurisdiction, or built around nothing more formal than internal review, this is the year that gap gets expensive. For a closer look at how Colorado's law interacts with other state and local requirements like NYC Local Law 144, see our breakdown of the Colorado AI Act and NYC Local Law 144. And if you have not yet mapped which of your AI systems would count as "high-risk" under these statutes, an AI risk assessment is the place to start before an attorney general's office starts asking the same questions for you.
Last updated: 2026-09-03
Jared Clark
AI Governance Consultant, Regulated AI Consulting
Jared Clark is the founder of Regulated AI Consulting, advising organizations on AI governance frameworks, ISO 42001 compliance, and responsible AI deployment in regulated industries.