Written by a human

How compliance teams can prepare for state-level AI governance laws

Capturing voice communications has evolved from a regulatory checkbox into a critical must have for firms looking to weed out market abuse and misconduct.

7 mins read 27 July 2026

The regulatory ground beneath AI is shifting, and nowhere faster than at the state level. In 2025 alone, legislators introduced 1,208 AI-related bills across all 50 states, enacting 145 into law. By early 2026, 45 states had introduced 1,561 more. With no consolidated U.S. rulebook on the horizon, healthcare and life sciences compliance leaders must anticipate risks that haven’t yet taken statutory form.

But regulatory uncertainty is not a reason to wait. The organizations best positioned for what comes next are building governance programs now that hold up regardless of which framework prevails.

What regulatory pressures already exist?

Several key regulations already set standards for data regulation, privacy, and recordkeeping, whether AI is involved or not. Typically, the same compliance principles can be applied to all types of data, from static, manual entry to AI-powered analysis.

Constant, messy updates often leave organizations implementing reactive measures, rather than strategic proactivity. This usually leads to a patchwork effect, with compliance managers forced to retrofit new tech capabilities as each update arrives. Not only does this put teams on the regulatory backfoot, but it also burns through resources.

The following table provides an overview of the pressures coming from each regulation:

RegulationCore focusData logging and
audit retention
Management and access controlRegulatory pressure
HIPAA & HITECH ActSecure and restrict access to Protected Health Information (PHI) at rest and in transit.Access logs must track who viewed or modified PHI, and records must be kept for 6 years.Strict role-based access controls. Only personnel with a documented need to know can access decryption keys.Perfect data encryption does not satisfy AI transparency laws. HIPAA ensures data is locked away safely, but it does not police what an algorithm says to a patient or how a model routes a clinical file.
EU AI ActEnforces strict risk-based practices to promote product safety and fundamental rights.High-risk systems must automatically generate and retain logs tracking their entire operational lifetime to ensure traceability.Access keys to model settings and operational logs must be strictly gated.If a digital clinic touches cross-border care, triage systems trigger strict European documentation mandates, multi-year logging requirements, and mandatory registry enrollment.
State privacy lawsProtect all consumer and sensitive data, expanding past traditional boundaries.Requires data minimization documentation. Data maps must actively trace exactly where sensitive data is shared or sold.Expands access controls to include the right for a consumer to limit the use or processing of their sensitive data.Data risks if passed through patient-facing channels or used in decision-making pathways without explicit, compliant disclosures.

What new obligations will increased AI governance bring?

Increased AI governance won’t just bring new laws, it will also increase the obligations for regulations already governing the market. And these changes are already playing out in healthcare and life sciences industries.

For example, in EU-facing organizations, substantive risk management is now required. This has transformed the risk assessment process from a static checklist to a tiered engineering system. Businesses that use AI must now systematically vet training datasets for demographic bias and maintain continuous post-market audit logs across high-risk algorithms.

Adding State-level AI governance laws into the mix

State-level AI governance laws place another layer of risk and obligation for compliance teams. Colorado SB 26-189 is one of the first examples of this new regulation type; it involves a state-level framework focused specifically on AI usage and data. Passed in May 2026, it is set to be officially enacted in January 2027.

Colorado SB 26-189 homes in on automated decision-making technology (ADMT). The rules cover data usage in healthcare services, insurance, employment, education, financial services, and housing.

For healthcare and life sciences operations, this law applies when a treatment decision is made by a computer rather than a human doctor. When that happens, the following apply:

Disclosure obligations: pre-use notices let the patient know an AI system will be involved in the decision making, and active, real-time notifications must then inform patients at the exact moment an automated system is interacting with them.

Consumer rights: patients are legally entitled to view the exact data variables driving their automated care path and can demand an override in case of inaccuracies.

Meaningful human review: organizations must offer a commercially reasonable path for reconsideration when requested by the patient. This requires a trained human reviewer who has the explicit authority to examine primary evidence and override the algorithm’s output.

These new obligations mean that compliance teams can’t just log everything into a central dashboard and call it a day. They have to build conditional logic and explainability—often through deterministic grounding—into their infrastructure to be truly governance-ready.

How will AI governance affect specific industries?

Depending on the type of industry you work in, some regulatory pressures will be more relevant than others. We’ve broken down the exact demands you might face, which risks are most relevant, and how this all translates into your governance planning.

Risks and pressures: pharmaceuticals and life sciences

State-level AI governance laws are specifically targeting AI usage that overlaps with patient data. This puts several types of communications at risk, including hub services, field reimbursement, manager outreach, patient assistance program calls, and medical affairs communications.

It’s only natural for compliance leaders in the pharma industry to be most concerned about:

  • FDA 21 CFR Part 11: data in electronic records can be filtered out to help AI algorithms make high-throughput decisions, but this can contradict integrity and record-keeping requirements.
  • AI Act exposure through patient support program AI tools: potentially classified as high-risk, requiring a much higher grade of risk management and subsequent resources.
  • BAA obligations as manufacturers work through hub operators: the subcontractor chain of liability creates auditing obligations and requires contractual protection for PHI.

Risks and pressures: payers and managed care

Because the U.S. operates in a highly fragmented multi-payer system, payers sit between patients, providers, and third parties. This creates distinct pressure in communications systems between all the parties.

With incoming AI regulations, compliance teams in the payer market are likely to be thinking about:

  • CMS regulations on prior authorization documentation: new electronic PA rules force tight deadlines on communications and decision validation.
  • AI Act exposure through utilization management and claims adjudication tools: while systems may be categorized as limited risk, modern tools that flag outliers and fraudulent claims sit outside of that in the high-risk category, bringing the burden of greater compliance requirements.
  • State insurance commissioner oversight: as they hold the licensing power, this is the immediate, localized regulatory pressure for continuing operations.

Risk and pressures: healthcare providers

For providers, patient-related clinical communications are most exposed to AI-related compliance pressures. Often using a combination of PHI, care co-ordination, telehealth records and EHR-adjacent communications, providers will have to continuously review best practices for storage and usage when using AI tools.

Incoming governance changes are most likely to affect:

  • Joint Commission and CMS Conditions of Participation: responsible AI usage is likely to be assessed and directly impact funding eligibility.
  • State medical board requirements: protecting licensing and ensuring the human professional is completely responsible for patient outcomes.
  • AI Act exposure through clinical decision support tools placing providers into the high-risk category, requiring a much higher grade of risk management and subsequent resources.
  • Interoperability requirements under the 21st Century Cures Act: challenges to information blocking and AI decision explainability mean compliance managers will have to carefully navigate flows of information.

How to evolve your compliance program to account for AI governance laws

As compliance leaders prepare for yet more change, finding a solution that holds up regardless of evolving laws and various jurisdictions is key. Features like complete channel capture, immutable storage, granular search and retrieval, and role-based access controls were all necessary before AI was introduced and will be even more important going forward.

The organizations best positioned for compliant AI adoption are the ones that have already built the infrastructure necessary to adapt to evolving regulatory guidelines. Global Relay’s suite of compliant communications solutions helps companies capture, monitor, and retrieve business communications and collaboration data, including logs of generative AI use. Learn more about Global Relay for Healthcare & Life Sciences.

7 mins read 27 July 2026