Written by a human
State AI regulations 2026: A compliance guide for financial firms
Without a consolidated federal AI rulebook, states across the U.S. have established their own governance laws. How can firms prepare their compliance programs to navigate these requirements while scaling innovative technologies?
In brief:
- States across the U.S. have established AI-specific laws to regulate its use
- This leaves firms to determine how best to navigate complex overlapping guidelines to remain compliant
- Firms must implement future-proof governance that can manage evolving technologies and evolving risks
Calls for clarity on AI expectations from governments and regulators are increasing, with 41% in financial services saying we need more regulatory clarity. Legislators and institutions are finding that they must both react to how AI is currently being used, and anticipate the path AI development may continue to take.
Without a comprehensive federal rulebook, states across the U.S. have established their own standards to anticipate and manage potential AI risks. AI technologies are becoming more ubiquitous in financial operations, and rule setting is growing at a similar pace to adoption — in 2026 alone, 341 laws were proposed across 45 states.
However, with hundreds of guidelines and more in development, how can financial institutions position their compliance programs ahead of an evermoving AI innovation target?
What AI risks are state laws targeting?
AI has allowed firms to optimize complex functions such as guiding consumer interactions, drafting and generating content, and conducting sentiment analysis for risk monitoring.
These use cases are valuable to resource-restricted teams. However, they can present substantial risks without the right guardrails and governance in place. Some states have established new legislation sitting outside of existing frameworks to address high-risk AI functions, especially where they influence human decision making, provide misleading content to consumers, or involve the handling of sensitive data.
Colorado is one of the first states to create a legislative framework that specifically focuses on AI use and data, State Bill (SB) 26-189. This Bill relates to the use of automated decision-making technology (ADMT) for making consequential decisions and promotes transparency and consumer protection.
SB 26-189 imposes disclosure obligations to let consumers know an AI system is involved in decision-making, rights allowing consumers to view data variables that influenced a decision, and human review alternatives to override a decision. It also states that organizations leveraging ADMT must retain records necessary to demonstrate compliance for three years.
These obligations make explainability and model governance especially crucial. Firms should ensure their compliance infrastructure can test and verify model accuracy, using methods like chain-of-thought prompting, validation loops, or evaluation sets to ensure they can evidence how and why their models reach decisions. Below are frameworks or guidelines that have been specifically created to manage risks related to AI:
| LAW | STATE | PURPOSE |
| State Bill 29-189 (replaced the AI Act) | Colorado | Transparency standards that require businesses to issue disclosures, provide consumer rights to review decisions, and set out obligations for human review when using ADMT. |
| Business and Commerce Code Chapter 551-554 | Texas | Transparency standards that require state agencies to notify consumers when they are interacting with AI in consumer-facing communications |
| GenAI Disclosure Law | Utah | Transparency standards that require businesses using GenAI to disclose it to consumers when asked |
Same governance, new obligations
While some states have established AI-specific laws, others are updating existing governance to reflect the increased use of emerging technologies. These updates are meant to manage the increasingly volatile risk landscape as well as protect consumers and markets from unprecedented — and unanticipated — threats.
The New York Department of Financial Services (NYDFS) updated its Cybersecurity Regulation Part 500 Guidance to account for AI-related risks. The rule already mandates that financial companies in NY maintain risk-based systems and audit trails of material transactions and cybersecurity events.
However, firms using ADMTs must also maintain an inventory of data and AI deployment paths handling sensitive information and conduct regular risk assessments of internal and external AI tools, among other requirements.
Below are existing rules that have had additional AI-specific guidance added:
| LAW | STATE | PURPOSE |
| Unfair Competition Law | California | Prohibits any unlawful, unfair, or fraudulent business practice and deceptive or misleading advertising over the internet. |
| California Consumer Privacy Act | California | Transparency standards that require firms to provide pre-use notices as well as rights to access and opt out when ADMT is being used. |
| Cybersecurity Regulation 23, New York Codes, Rules, and Regulations Part 500 | New York | Requires organizations to maintain robust cybersecurity programs accounting for AI-related risks, including recording AI-generated customer services responses and managing data exposure. |
| 940 Code of Massachusetts Regulations 3.00 and 201 17.03 | Massachusetts | Mandates that AI systems used for advertising cannot produce false or misleading content and must comply with MA data security standards if handling personal information. |
| NJ State 56:18-2; Attorney General Guidance | New Jersey | Prohibits online bots from communicating with NJ residents for advertising without identifying whether communication is AI-generated. |
| Unlawful Trade Practices Act; Consumer Privacy Act; Equality Act | Oregon | Requires businesses using AI to comply with consumer protection, data security, and anti-discrimination laws, such as safeguarding consumer data. |
How will state-level AI governance affect financial compliance?
With evolving AI rules seemingly coming from every direction, one of the first question firms are bound to ask is: “what can we do now to be ready?” It’s important firms and their compliance teams stay on the front foot, and the best way to do that is by predicting where AI risks may manifest, understanding where emerging regulation may require action, and ensuring existing governance measures are already adapting to the AI era.
Get data governance down before digital innovation
As the saying goes: good data in, good data out. If you don’t have a centralized system to consolidate and structure data, it will be fragmented. In that case, applying AI tools will likely lead to inaccurate results. Review your data stewardship and architecture to understand exactly where your data lives and how it’s managed.
Data privacy frameworks should be a core focus so that firms have oversight of how their AI is collecting, analyzing, and using personal information. Firms should implement data mapping tools to understand how information flows across systems, elevate encryption standards to withstand advancing attacks, and centralize compliance across privacy management platforms.
Keeping matters private
Cybersecurity is a top concern, especially as cybercriminals use novel AI models to exploit critical systems and access sensitive information. Firms need to continually test and evaluate their system soundness and resilience, now more than ever.
This means performing stress tests on systems to understand how they work under pressure, building out business continuity and external communication plans if systems were to be breached, enforcing multi-factor authentication standards, and implementing tools that can detect and respond to AI threats rapidly.
Defining the circle of trust
As several state laws highlight, third-party providers are a significant part of the compliance equation. With more firms reliant on AI providers, vendors, and third-party services, it’s crucial to conduct third-party risk management tests regularly and to ask partners the right questions.
Regulators like the Financial Industry Regulatory Authority (FINRA) have recognized this reliance and suggest that firms evaluate how their vendors use AI, how they can supervise it on an enterprise level, and how they can identify and mitigate associated risks like accuracy or bias.
Firms may consider building their own AI systems, though, if outsourcing AI tools, it’s important to consider the risks of having too many “links in the chain.” These links can increase the number of data transmission paths and create a gap that requires increased oversight, whereas a single solution, private cloud system can eliminate unnecessary ingress points.
As state-level laws coalesce and with federal-level guidance feeling increasingly inevitable, firms are finding themselves needing to learn — and re-learn — rules as they are being written. Compliance teams are used to having to stay light on their feet and keep one eye on the horizon, but, as with all things AI, the scale has increased. Those that build a flexible, future-looking strategy on a firm foundation of good governance and the right data and solutions will be best placed to navigate the evolving legislative landscape.
As compliance teams prepare for change, having a solution that is adaptable and future proof enough to evolve alongside laws across jurisdictions is essential. From centralized archiving systems to rapid search and retrieval to role-based access controls, the fundamentals are just as important now as ever before to setting up for success.