AI Regulation in Flux: U.S. and global shift toward “lighter touch”

Part One of a two-part series.

The regulation of artificial intelligence in the United States continues to be driven primarily by state-level initiatives in the absence of comprehensive federal legislation. Recently, there has been a measurable shift in this legislation toward more flexibility and transparency.

Many states -- including California, Texas, and New York -- have advanced targeted and sector-specific AI laws focusing on consumer protection, employment, and transparency. Meanwhile, Colorado recently repealed its landmark, comprehensive AI law targeting algorithmic discrimination, replacing it with less stringent requirements for developers and deployers.

Globally, we are seeing similar trends. The European Union’s “Digital Omnibus” initiative reflects growing pressure to delay and soften aspects of its AI Act, particularly for high-risk systems.

The United States: A patchwork of state laws

In the absence of a comprehensive federal AI statute, U.S. states have taken the lead in regulating AI. More than 1,000 AI-related bills were introduced in 2025. Numerous state AI laws took effect on January 1, 2026, including legislation in California and Texas. 

State laws generally focus on three key areas: Algorithmic discrimination and civil rights, transparency and disclosure obligations, and sector-specific regulation (such as employment, health care, financial services).

To date, 46 states have enacted laws regulating AI.

California, New York, and Texas

California has multiple effective and proposed laws addressing automated decision-making technology, consumer privacy, and frontier AI transparency obligations for large developers.

New York has taken both municipal and statewide approaches. New York City Local Law 144 (in force since July 5, 2023) regulates the use of automated employment decision tools, known as “AEDTs.” Local Law 144 requires annual third-party bias audits, public disclosure of audit results, and candidate notice requirements. Recent developments include increased enforcement activity, including initial fines issued in 2026 for noncompliance and a 2025 audit finding enforcement gaps, prompting commitments to strengthen oversight. At the state level, New York’s Responsible AI Safety and Education Act (RAISE Act) will take effect in 2027. 

The Texas Responsible Artificial Intelligence Governance Act took effect in 2026. It prohibits certain harmful uses of AI but generally avoids imposing extensive compliance requirements. 

Colorado’s AI Act is recalibrated

Colorado’s AI Act (SB 24-205) was the most comprehensive AI law in the United States, modeled in part on the risk framework of the European Union AI Act. The Colorado Act was enacted in 2024 with an initial effective date of February 1, 2026.

The law imposed significant obligations on developers and deployers of high-risk AI systems. The mandates included risk management programs, impact assessments, consumer disclosures, and preventing and reporting “algorithmic discrimination.”

In August 2025, Colorado enacted SB 25B-004, which delayed the law’s effective date to June 30, 2026. The delay was intended to allow further refinement of the law amid industry concerns regarding feasibility, scope, and innovation.

Then, in May 2026, Colorado enacted SB 26-189, which repealed and replaced the original AI Act. The revisions in the new, “softer” law include the following:

  • A shift from algorithmic discrimination governance toward a transparency-based framework.
  • Narrower system coverage.
  • An emphasis on consumer disclosure and rights (notice, explanation, appeal).
  • Alignment of enforcement with existing anti-discrimination laws rather than the creation of new AI-specific liability standards.

SB 26-189 also delays implementation of the AI Act to January 1, 2027. Details about the current version of the Colorado law are available here.

European Union AI Act and Digital Omnibus

The European Union’s AI Act, which took effect in August 2024, remains the most comprehensive AI regulatory framework in the world. The Act has different obligations based on the risks of the applicable systems, with strict obligations for “high-risk” systems.

However, even the EU law is softening. The European Commission has introduced the “Digital Omnibus” to simplify overlapping digital regulations. As part of this Omnibus, in May 2026, the European Parliament and Council reached a provisional agreement to modify the AI Act.

Key changes include the following:

  • Extended deadlines. Compliance deadlines have been delayed to December 2, 2027 (for standalone high-risk systems) and August 2, 2028 (for embedded high-risk systems).
  • Narrower scope and reduced overlap. Certain uses of industrial AI that were already governed by EU product safety laws are carved out. In addition, the definition of “high-risk systems” has been narrowed. Both changes reduce the number of systems subject to the most stringent requirements.
  • Reduced compliance burden and added flexibility. The amendments apply simplified compliance measures to mid-sized companies, streamline bias detection requirements, and provide additional implementation guidance.
  • Targeted adjustments (and limited expansions). Transparency obligations remain in place, but some deadlines have been pushed back and additional guidance has been provided. On the other hand, there are some new prohibitions, such as restrictions on non-consensual intimate content.

These changes have been widely characterized as a “watering down” of the original framework, driven by concerns regarding competitiveness, feasibility, and regulatory complexity.

But the core architecture of the AI Act remains intact. The following have been preserved:

  • Risk-based framework. The AI Act’s core structure, categorizing AI by risk level, remains unchanged.
  • Substantive obligations for high-risk systems. Requirements relating to risk management, data governance, documentation, human oversight, and system robustness continue to apply.
  • Transparency and prohibitions. Key disclosure requirements and existing prohibitions (such as prohibitions on social scoring and manipulative practices) remain in force, with only limited timing adjustments.

Penalties are also still significant despite the revisions. The Omnibus amendments do not materially reduce the AI Act’s penalties, which remain among the most stringent globally:

  • Up to €35 million or 7 percent of global annual turnover for violations involving prohibited AI practices.
  • Up to €15 million or 3 percent of global annual turnover for violations of core obligations, including transparency requirements.
  • Exposure to civil damages, including damages for violation of EU product liability provisions, particularly for harmful AI outputs.

The EU approach contrasts with Colorado’s more limited enforcement model, where authority rests with the Attorney General and there is no private right of action. However, both laws are moving away from highly prescriptive, front-loaded regulation toward more flexible, implementation-focused approaches.

In Part Two of this post, we’ll discuss what businesses should be doing to ensure compliance.

The Constangy Cyber Team assists businesses of all sizes and industries with compliance needs. If you would like additional information about state or federal data privacy laws, please contact us at cyber@constangy.com.

The Constangy Cyber Advisor posts regular updates on legislative developments, data privacy, and information security trends. Our blog posts are informed through the Constangy Cyber Team's experience managing thousands of data breaches, providing robust compliance advisory services, and consultation on complex data privacy and security litigation. 

Search

Get Updates By Email

Subscribe

Archives

Jump to Page

Constangy, Brooks, Smith & Prophete, LLP Cookie Preference Center

Your Privacy

When using this website, Constangy and certain third parties may collect and use cookies or similar technologies to enhance your experience. These technologies may collect information about your device, activity on our website, and preferences. Some cookies are essential to site functionality, while others help us analyze performance and usage trends to improve our content and features.

Please note that if you return to this website from a different browser or device, you may need to reselect your cookie preferences.

For more information about our privacy practices, including your rights and choices, please see our Privacy Policy. 

Strictly Necessary Cookies

Always Active

Strictly Necessary Cookies are essential for the website to function, and cannot be turned off. We use this type of cookie for purposes such as security, network management, and accessibility. You can set your browser to block or alert you about these cookies, but if you do so, some parts of the site will not work. 

Functionality Cookies

Always Active

Functionality Cookies are used to enhance the functionality and personalization of this website. These cookies support features like embedded content (such as video or audio), keyword search highlighting, and remembering your preferences across pages—for example, your cookie choices or form inputs during submission.

Some of these cookies are managed by third-party service providers whose features are embedded on our site. These cookies do not store personal information and are necessary for certain site features to work properly.

Performance Cookies

Performance cookies help us improve our website by collecting and reporting information on its usage. We access and process information from these cookies at an aggregate level.

Powered by Firmseek