A-LIGN
Audit and certification firm offering ISO 42001, SOC 2, ISO 27001, FedRAMP, HITRUST and PCI DSS assessments across 45+ standards.
Jurisdictions · United States · reviewed 2026-09-21
This hub covers the state laws on the tracker: Texas, California, Colorado, Utah and New York. Federal rules are not tracked here. The state laws differ in who they target: Texas bans a short list of uses, Utah requires disclosure of generative AI, California and New York mostly regulate developers of large or frontier models, and Colorado and California regulate automated decisions about consumers from 1 January 2027.
For a company that uses AI rather than builds models, the practical duties are disclosure (Utah), banned uses in the acceptable-use policy (Texas), and notices, explanations and human review for automated decisions in Colorado and California from 2027.
Next date: Colorado ADMT duties begin, 1 Jan 2027 (in 101 days, upcoming).
| Date | Obligation | Status | Who | What and evidence |
|---|---|---|---|---|
| 1 May 2024 874 days ago | AI disclosure duties in Utah US, Utah · Utah AI Policy Act (SB 149, narrowed 2025) | In force | Businesses using generative AI with Utah consumers, with stricter duties in regulated professions | Disclose the use of generative AI on request in consumer interactions and proactively in regulated professions. Evidence: Disclosure texts, script for staff answering 'am I talking to AI?'. |
| 1 January 2026 264 days ago | TRAIGA in force US, Texas · Texas Responsible AI Governance Act (HB 149) | In force | Developers and deployers of AI in Texas; state agencies | Bans intentional development or deployment of AI that incites self-harm or crime, AI-generated child sexual abuse material, non-consensual deepfake pornography and government social scoring. Rules for state-government AI. Evidence: Acceptable-use policy prohibiting the banned uses. |
| 1 January 2026 264 days ago | Generative AI training-data documentation US, California · AB 2013 (training data transparency) | In force | Developers of generative AI systems made available to Californians | Developers must publish documentation about the datasets used to train their generative AI. Evidence: Published training-data summary (developers only). |
| 27 March 2026 179 days ago | Frontier-model developer duties US, New York · RAISE Act (as amended 27 March 2026) | In force | Developers of frontier AI models only | Transparency and reporting on training, deployment, safety protocols and incidents for frontier developers. Not relevant to companies that only use AI. Evidence: Not applicable to deployers. |
| 2 August 2026 51 days ago | Provenance and detection tools for large generative AI providers US, California · SB 942 (AI Transparency Act) | In force | Providers of generative image, video or audio tools with more than 1 million monthly users | Offer AI detection tools, watermark options and disclosures for AI-generated content. Delayed from 1 January 2026 to 2 August 2026. Evidence: Provenance features and disclosure options (large providers only). |
| 1 January 2027 in 101 days | Colorado ADMT duties begin US, Colorado · SB 26-189 (Automated Decision-Making Technology) | Upcoming | Developers and deployers of automated decision-making technology affecting Colorado consumers | Replaces the 2024 Colorado AI Act. Requires pre-use consumer notices, an explanation within 30 days of an adverse outcome, meaningful human review rights and developer documentation. The earlier risk-management-programme and impact-assessment duties were removed. Evidence: Pre-use notice texts, adverse-outcome explanation procedure, human review process. |
| 1 January 2027 in 101 days | ADMT significant-decision obligations US, California · CPPA automated decision-making regulations | Upcoming | Businesses under the CCPA using automated decision-making for significant decisions about consumers | Notices, opt-out and access rights around automated decisions with significant effects. Evidence: ADMT notice, opt-out process, risk assessment where required. |
| 1 January 2027 in 101 days | Provenance duties extend to large online platforms US, California · AB 853 | Upcoming | Large online platforms (2027) and capture-device manufacturers (2028) | Extends SB 942 obligations to platforms from 1 January 2027 and to capture devices from 1 January 2028. Evidence: Platform provenance handling (platforms only). |
11 verified listings from the directory, each checked against the company's own website. Listing is free; paid placements are labelled.
Audit and certification firm offering ISO 42001, SOC 2, ISO 27001, FedRAMP, HITRUST and PCI DSS assessments across 45+ standards.
Trust management platform automating compliance evidence, risk management and monitoring across frameworks including ISO 42001, with an AI agent governance product in limited availability.
Runtime governance layer recording each AI action against declared controls and emitting cryptographically signed OVERT records verifiable by auditors and customers.
Pre-written editable Word and Excel documentation toolkits for 80+ standards including ISO 42001 and the EU AI Act, with policies, registers and audit checklists.
Editable DOCX and XLSX ISO/IEC 42001 documentation pack covering mandatory AIMS documents, all Annex A controls, gap analysis workbooks and crosswalks.
AI compliance proxy for regulated firms that enforces policies inline on model traffic and maintains a tamper-evident audit trail for examiners.
AI governance module that discovers, assesses, monitors and controls first- and third-party AI systems, with runtime monitoring and audit evidence generation.
GRC platform module that inventories AI and agentic systems, maps them to 25+ frameworks including the EU AI Act and ISO 42001, and monitors risk.
ANAB-accredited certification body providing ISO 42001 certification audits, plus SOC 2, ISO 27001, AI red teaming and HITRUST AI assessments.
AI governance platform covering AI intake, risk assessment, compliance mapping and continuous monitoring across the AI lifecycle.
Compliance automation module that maps AI agents across an organization's technology stack, enforces usage guardrails and generates compliance evidence.