The AI Law Binding Your Product Isn't European. It's Texan, Coloradan and Californian.

European teams spent 2026 planning around one AI Act. The rules that already bind software sold into the United States arrived one state at a time, and almost all of them are build tickets with dates attached.

AI StrategyThe AI Law Binding Your Product Isn't European. It's Texan, Coloradan and Californian.

Why Does a European Compliance Plan Miss the American Deadlines Entirely?

If you run engineering for a European product company, your 2026 compliance calendar almost certainly has one entry on it. The EU AI Act's transparency obligations became applicable on 2 August 2026, the high-risk regime was deferred to December 2027, and somewhere in a planning document there is an epic named after it. That entry is correct, and it is roughly half of the picture if you sell anything into the United States.

The American half arrived without a single dramatic deadline, which is exactly why it did not make the calendar. There is no US AI Act. There are statutes, in separate states, with separate definitions, separate covered domains and separate enforcement bodies, arriving on separate dates. MultiState's legislative tracker recorded that lawmakers in 45 states had introduced 1,561 AI-related bills by March 2026, with sessions still running. Most of those bills will die. The ones that did not are already binding software that European teams shipped months ago.

There is a revealing asymmetry in how organisations respond to this. Schellman's 2026 governance survey, fielded between 13 April and 11 May 2026 across 525 US-based professionals at organisations with more than 500 employees and over $100 million in revenue, found that 89% had taken action for US regulations while only 29% had addressed EU AI Act requirements. American companies build for the rules in front of them. European vendors selling into the same market tend to do the mirror image, and the mirror image leaves the customer-facing jurisdiction uncovered.

The practical consequence is not a fine, at least not first. It is a procurement questionnaire. A US enterprise buyer whose own obligations under a state statute depend on documentation from its vendors will ask you for that documentation, and the request will arrive from a procurement team with a signature deadline rather than from a regulator with a cure period. Teams that cannot answer lose the deal quietly, and the loss never gets recorded as a compliance failure.

Key Takeaways

  • There is no single US AI law; obligations arrive per state with different definitions and dates
  • Lawmakers in 45 states introduced 1,561 AI-related bills by March 2026, with sessions still open
  • US organisations act on US rules far more than on the EU AI Act; European vendors do the reverse
  • The first consequence is usually a failed procurement questionnaire, not an enforcement action

Which American Deadlines Have Already Passed?

Start with the ones that are behind you, because the assumption that this is all future work is where most of the exposure sits. Texas has been operating under the Responsible AI Governance Act since 1 January 2026. It is a deliberately business-friendly statute, built on an intent standard rather than disparate impact, but it has real teeth: the Attorney General holds exclusive enforcement authority, must give a 60-day cure period, and can seek $10,000 to $12,000 per curable violation, $80,000 to $200,000 per uncurable one, and $2,000 to $40,000 per day for continuing violations. It applies to entities that conduct business in Texas or offer products to Texas residents, which includes a European SaaS company with a single Texan customer.

The same source records the most useful clause in any current AI statute for an engineering team: substantial compliance with the NIST AI Risk Management Framework, including its generative AI profile, is an explicit affirmative defence. That is a legislature naming a specific, published, implementable control framework and saying that following it helps you in court. There is also a 36-month regulatory sandbox administered by the Department of Information Resources for teams that want to test systems under reduced licensing requirements.

Illinois took a narrower and quieter route. Its amendment to the Human Rights Act took effect on 1 January 2026 and prohibits employers from using AI that discriminates on protected characteristics and requires notice when AI is used in employment decisions. The Illinois Department of Human Rights then temporarily withdrew its proposed implementing rules, which means the obligation is live while the detailed guidance is not. Engineering teams should read that as a reason to keep records, not as a reason to wait.

California got there first on employment. Its regulations on automated-decision systems under the Fair Employment and Housing Act took effect on 1 October 2025 and require four years of retention for automated-decision data, with employers responsible for discriminatory outcomes even when the tool came from a third-party vendor. Four-year retention of the inputs, outputs and configuration of a screening model is a storage schema and a lifecycle policy. Nobody writes that after receiving a subpoena.

New York City has had a bias-audit regime since 2023, and the interesting recent development is enforcement rather than the rule. The New York State Comptroller published an audit on 2 December 2025 concluding that the city's enforcement had been ineffective: of 32 employer and vendor disclosures the agency reviewed it identified one likely instance of non-compliance, while auditors reviewing the same 32 found at least 17 potential issues, and only two complaints had been received across a two-year window. A regulator publicly told it is not enforcing is a regulator about to start.

Two California statutes rounded out the live set this year. Companion chatbot rules took effect on 1 January 2026 requiring disclosure of non-human status, crisis protocols and protections for minors, part of a wave that now includes New York, Oregon, Washington, Nebraska and Tennessee with dates running through mid-2027. And the California AI Transparency Act became operative on 2 August 2026, three weeks ago.

Key Takeaways

  • Texas has been enforceable since 1 January 2026, with NIST AI RMF compliance as an affirmative defence
  • Illinois requires employment AI notice now, while its implementing rules sit withdrawn
  • California employment rules demand four-year retention of automated-decision data since October 2025
  • A state audit found New York City's bias-audit enforcement ineffective, which usually precedes tightening

What Do Colorado and California Make You Ship Before January?

Two obligations land on the same day, 1 January 2027, and between them they define most of what an AI compliance surface looks like in practice.

Colorado's story is worth telling because it explains why the roadmap keeps moving. Its original 2024 AI Act, a European-style high-risk framework with impact assessments and reasonable-care duties, never applied. It was repealed and replaced by SB 26-189, signed on 14 May 2026 and effective 1 January 2027, which drops the governance programme and impact assessment machinery in favour of four concrete duties. Deployers must give clear pre-use notice when covered automated decision-making technology is used in a consequential decision. They must provide, within 30 days of an adverse outcome, an explanation of the decision and the technology's role in it. They must offer access, correction and meaningful human review. Developers must hand deployers technical documentation covering intended uses, training data categories, limitations, risks and deployment instructions.

The covered domains are the familiar consequential ones: education, employment, financial services, insurance, healthcare and government services. Enforcement is exclusively the Attorney General's, as an unfair trade practice, with a 60-day cure period and no private right of action, and the Attorney General must adopt implementing rules before the effective date. Note the third duty in particular. Meaningful human review is defined to require a reviewer with authority to override the decision, who considers primary evidence, is trained, and does not simply defer to the automated output. That is a staffed workflow with a training record, not a checkbox.

California's automated decision-making rules under the CCPA arrive the same day and cover overlapping but differently drawn ground. Businesses using such technology for significant decisions must give advance notice, offer an opt-out subject to limited exceptions, and honour access rights, with businesses already using it required to comply by 1 January 2027. The same regulations bring risk assessments for high-risk processing, with information about assessments conducted in 2026 and 2027 due to the California Privacy Protection Agency by 1 April 2028, and cybersecurity audits phased in by revenue on 1 April 2028, 2029 and 2030.

The opt-out is the requirement engineering teams underestimate. A notice is a component. An opt-out is a second decision path: if a consumer declines automated processing of a significant decision, something else has to produce an outcome, at defensible latency, with its own audit trail. Teams that discover this in November will ship a queue that a human never actually clears.

The California AI Transparency Act, already operative, adds a different kind of build for anyone at scale in generative media. It covers providers whose systems have over one million monthly visitors or users and public accessibility in California, and requires latent provenance disclosures embedded in generated image, audio and video, manifest disclosure options, and a free public detection tool. The statute also requires a provider to revoke a licence within 96 hours of discovering that a licensee modified the system so it no longer includes the required disclosure, and sets a $5,000 civil penalty per violation with each day counted as a discrete violation. A 96-hour clock triggered by discovery is an incident response runbook with an on-call rotation attached, and daily-accruing penalties mean the cost of a slow response compounds rather than caps.

Key Takeaways

  • Colorado's replacement statute takes effect 1 January 2027: pre-use notice, 30-day adverse-outcome explanation, human review, developer documentation
  • CCPA automated decision-making rules land the same day with notice, opt-out and access rights
  • An opt-out is a second decision path with its own staffing, latency and audit trail
  • California's transparency act is already operative, with a 96-hour revocation clock and per-day penalties

Does the Federal Preemption Fight Buy You Any Time?

It buys uncertainty, which is not the same thing, and engineering leaders should be precise about the difference because the churn is genuinely dramatic.

On 11 December 2025 the White House issued an executive order titled Ensuring a National Policy Framework for Artificial Intelligence, aimed squarely at state AI regulation. It directed the creation of a Department of Justice litigation task force to challenge state AI laws as unconstitutional burdens on interstate commerce or as preempted, while expressly carving out categories including child safety, compute and data centre infrastructure, and state government procurement and use of AI. The Department of Justice announced the task force on 9 January 2026.

It has had effects. xAI sued Colorado over its original AI Act in early April 2026; the Department of Justice moved to intervene on 24 April 2026 and the court granted a joint motion suspending enforcement on 27 April. Weeks later Colorado repealed the statute and replaced it with the narrower one described above. So the preemption campaign did not remove Colorado's regime; it traded a broad governance framework for a tighter disclosure-and-review framework arriving six months later. Legal analysts also note the mechanism is multi-step: a state law has to be identified and referred, litigation has to be filed, and a court has to grant relief before anything changes for a deployer.

Meanwhile Texas, Illinois and the California statutes are all in force, unchallenged in any way that has stopped them, and the volume of state legislation has continued to climb. A rational reading is that the patchwork is unstable in its details and stable in its direction. Specific statutes will be struck, amended, repealed and replaced. The underlying demands, tell people when a machine decided, be able to explain the decision, let a human with authority look again, keep records that prove it, will not go away, because they are what both the litigation-driven American system and the regulation-driven European one converge on.

That is the argument for treating this as engineering rather than legal work. A compliance programme built around a specific statute has to be rebuilt every time the statute moves, and this year it moved twice in one state. A set of artefacts built around the underlying demands survives the churn and gets reused. You cannot schedule a roadmap against pending litigation, but you can build the things that every plausible outcome still requires.

Why Is This an Engineering Backlog Rather Than a Policy Memo?

Read the six live obligations side by side and they collapse into a short list of things somebody has to build, own and keep working. This is the list, and it is worth putting into a planning document verbatim.

First, an inventory. A registry of every AI or automated decision system in the product, with owner, purpose, model and version, jurisdictions it serves, and whether it touches a consequential decision. Almost every obligation begins with knowing which systems are in scope, and almost nobody can produce this on request. Second, decision logging: for each in-scope decision, the inputs, the model version, the output, the confidence or score, and the downstream action, retained long enough to satisfy the strictest applicable rule, which is currently four years for California employment data. Third, notice surfaces at the point of interaction, which is product work in every flow rather than one banner.

Fourth, a human review service: an intake path, a queue, a reviewer with genuine override authority, a record of that reviewer's training, and an outcome written back to the decision log within the statutory window. Fifth, opt-out routing, meaning a non-automated path capable of producing an outcome. Sixth, provenance: embedded metadata in generated media, a detection endpoint, and monitoring of how often embedding actually succeeds. Seventh, an evidence pipeline that can assemble all of the above into something a regulator, an auditor or a procurement team can read without an engineer narrating it.

The gap between believing you have this and having it is the most striking number in the current data. In Schellman's survey, 74% of respondents believed they could pass an AI compliance audit today, while only 27% described their governance programmes as fully mature. The same survey found 46% already running AI agents in production and 44% with AI-specific incident response procedures. Agents in production without incident response is the shape of the problem: capability shipped ahead of the machinery that makes it accountable.

None of these seven items is technically hard. All seven are cross-cutting, which is worse. They touch the model serving path, the product surface, the data platform, the retention policy, the support tooling and the contract with every customer, and they are owned by nobody in particular. That is precisely the category of work that a feature roadmap defers indefinitely, and precisely the category that a dedicated team with continuity is good at, which is the shape of engagement we build at Stepto: senior engineers who own a durable slice of the system rather than a rotating ticket queue, so the registry stays current and the evidence pipeline still runs in eighteen months.

What Does Meaningful Human Review Look Like When You Have to Ship It?

Of the seven, human review is the one most likely to be designed badly, because it looks like a policy commitment and behaves like a product with staffing costs.

The statutory definitions are unusually specific about what does not count. Colorado's replacement act requires a reviewer with authority to override the decision, who considers the primary evidence, is trained for the task, and does not simply defer to the automated output. California's privacy regulations describe human involvement in comparable terms, requiring that the reviewer understand the technology's output, analyse it alongside other relevant information, and hold authority to change the decision. Both are written to defeat the obvious implementation, which is a screen with an Approve button and a queue that empties at ten seconds an item.

Ship it properly and it has the characteristics of any other production service. It has a request rate you have to forecast, because review volume scales with adverse outcomes rather than with traffic. It has a service level, because an explanation owed within 30 days of an adverse outcome is a deadline that starts without anyone filing a ticket. It has an authorisation model, because a reviewer who cannot override is not a reviewer. It has an audit trail that must record who reviewed, when, on what evidence, and what changed. And it has a training record, because the statute names training as a condition and the only place that lives is a system somebody built.

There is a design decision hiding here that is worth making deliberately. If review is bolted onto the end of the pipeline, every adverse outcome becomes a manual escalation and cost scales linearly with volume. If the decision service is designed from the start to emit a structured explanation, a confidence band and a reversible action, then review becomes a lookup rather than a reconstruction, and the same explanation payload serves the pre-use notice, the adverse-outcome disclosure, the access request and the audit. One artefact, four obligations. Teams that build the explanation once tend to find the rest of the surface cheap; teams that treat each obligation as a separate feature build four systems that disagree with each other.

How Do You Build One Control Set Instead of Six?

The instinct when facing a patchwork is to build per jurisdiction. It is the wrong instinct almost every time, and the reason is arithmetic: six regimes built separately produce six review workflows, six notice components and six retention policies, and each new state adds another. Build to the superset instead, and each new statute becomes a mapping exercise rather than a project.

The superset is close to what the strictest of the current rules demands. Retain automated-decision data for four years, because California employment law requires it and nothing requires less. Give pre-use notice everywhere in a consequential domain, because Colorado and the CCPA both want it and the ones that do not require it are not harmed by it. Offer meaningful human review as a standing capability rather than a jurisdictional feature flag. Ship developer documentation, intended uses, training data categories, limitations, risks and deployment instructions, as a product artefact, because Colorado will require it of you as a developer and your US customers will ask for it as deployers regardless.

Anchor the whole thing to a named framework rather than to statutes. The NIST AI Risk Management Framework and its generative AI profile are the obvious spine, for the blunt reason that Texas made substantial compliance an affirmative defence and no other framework carries that endorsement in current US law. It also maps cleanly onto the technical documentation, logging and human oversight expectations that the EU regime asks for, which means one control set can serve both sides of the Atlantic with jurisdiction-specific mappings on top.

Be honest about where the superset breaks, because pretending otherwise produces a plan that fails quietly. Liability standards do not merge: Texas turns on intent while California employment law reaches disparate impact, and no amount of logging reconciles that difference. Opt-out rights are genuinely Californian and building them everywhere may be a product decision you do not want. Provenance obligations bind large generative providers, not every application that calls a model. And a few regimes impose duties that only a lawyer can discharge, such as filing and attestation. The superset covers the engineering surface, which is most of it, not the whole of it.

The last piece is evidence, and it is the part that decides how expensive every future audit is. If the registry, the logs, the review outcomes and the documentation live in one place with an export, responding to a regulator, an enterprise buyer or an insurer is a query. If they live in six places and three spreadsheets, every request is a two-week fire drill pulled from delivery. That difference is invisible until the first request arrives and permanent afterwards.

Key Takeaways

  • Build one superset control set and map statutes onto it, rather than one implementation per state
  • Use the strictest current requirement as the default: four-year retention, notice everywhere, standing human review
  • Anchor to the NIST AI Risk Management Framework, the only framework named as an affirmative defence in current US law
  • Accept that liability standards, opt-out rights and provenance duties do not fully merge

Who Owns This When It Competes With the Roadmap?

Every item on the list is unglamorous, cross-cutting, invisible in a demo, and deferrable without immediate consequence. It also competes for exactly the senior engineers who are the constraint on everything else you are trying to ship. That combination reliably produces the same outcome: the work is started late, under pressure, by whoever is available, and it is done as a documentation exercise rather than as a system.

It is also work with an unusual property. Almost none of it expires. A system registry, a decision log with lineage, an explanation payload, a review service and an evidence export remain useful when the statute that prompted them is repealed, amended or struck down, and they are the same artefacts that make an AI feature debuggable, an incident reconstructable and a due diligence process survivable. The Colorado sequence this year, a law repealed before it applied and replaced with a narrower one, is the clearest possible argument for building things that outlast the specific rule.

That is why this suits a dedicated team far better than a project engagement. The inventory is only worth having if it stays current, which means somebody defends it at code review for years. The review service is only meaningful if the people who designed the queue are still around when volume triples. The evidence pipeline is only credible if it has been run more than once. Continuity is the entire value, and a rotating set of contractors cannot supply it by construction.

This is the shape of engagement Stepto is built around. We put senior engineers in Serbia onto a product rather than a ticket queue, working Central European hours that overlap the full European day and the American morning, which matters when a 96-hour revocation clock or a 30-day explanation deadline needs somebody awake in the same window as your legal team and your US customer. Working inside the European regulatory perimeter means the AI Act, GDPR and data residency constraints are ours as well as yours, and the same engineers who build the control set for those obligations map it onto the American ones rather than starting again.

On timing, the useful window is the next two quarters and it is not elastic. The two January obligations are four months out, the transparency act is already accruing daily penalties for anyone in scope, and the procurement questionnaires do not wait for effective dates. The inventory is a matter of weeks. The explanation payload is a design decision that costs almost nothing if made before the next twenty features ship and a great deal afterwards. What you cannot do is start in December, because by then the deadline is not a planning input, it is an incident.

The Statutes Will Keep Moving. The Artefacts Will Not.

The American AI compliance surface is not coming; most of it arrived while European teams were reading about a single European deadline. Texas has been enforceable since January with tiered penalties and an explicit safe harbour for teams that follow the NIST framework. Illinois requires employment AI notice today while its implementing rules sit withdrawn. California has required four-year retention of automated-decision data since October 2025, made its transparency act operative on 2 August 2026 with a 96-hour revocation clock and penalties counted per day, and lands its automated decision-making rules on 1 January 2027 alongside Colorado's replacement statute, which was signed in May after the original was repealed under litigation pressure. That churn is the point rather than an excuse: a federal preemption campaign has already suspended one law and prompted the rewrite of another without removing a single obligation from an engineering backlog, and the direction, tell people when a machine decided, explain the decision, let a trained human with real authority look again, keep records that prove it, is what both regulatory systems converge on. Build the seven artefacts once, anchored to a named framework rather than to any statute, and the next state is a mapping exercise. Skip them, and you will meet the requirement for the first time in a procurement questionnaire with a signature deadline, which is the most expensive place to discover that your system inventory is a spreadsheet somebody stopped updating in March.

Building a team in Eastern Europe?

StepTo helps European and US companies build senior-led nearshore engineering teams in Serbia. Let's talk about what your next engagement could look like.

Start a conversation
I

Written by

Igor Gazivoda

Co-founder & CEO · StepTo

Igor has 15+ years in software engineering and business development. Former CTO at a Series A fintech startup, he specializes in scaling engineering teams, nearshore strategy, and AI-driven product development. He holds a Master's in Computer Science from the University of Belgrade and has published on distributed systems architecture.

LinkedIn →
Performance-led engineering

Want senior engineers who move work forward, not just tickets?

Work with accountable, English-fluent professionals who communicate clearly, protect quality, and deliver with a steady operating rhythm. Cost efficiency matters, but performance is why clients stay with us.

Delivery signals · senior engineering team
Senior ownership
Lead-level
Delivery rhythm
Weekly
Timezone overlap
CET
1 teamaccountable for outcomes, communication, and execution