→ Back to Home
AI Ethics

US States Forge Coherent AI Regulatory Framework, Converging with EU Act Amidst Federal Deregulation

On July 6, 2026, Illinois Governor JB Pritzker signed the Artificial Intelligence Safety Measures Act (SB 315) into law, mandating independent third-party audits for AI labs' safety practices. This legislation, unique in the US, is part of a coordinated effort by several states, including California's SB 53 (frontier-developer transparency) and New York's Responsible AI Safety and Education (RAISE) Act (incident reporting and oversight). Collectively, these state-level initiatives are creating a coherent AI compliance regime that surprisingly aligns with the legal constructs seen in the European Union's AI Act, particularly in their emphasis on pre-market safety checks and incident reporting. This development occurs despite ongoing federal attempts to deregulate AI and preempt state-level policies, as evidenced by Executive Order 14179 from January 2025, which aimed to remove barriers to AI innovation. The Senate's removal of preemption from a federal bill in July 2025 further empowered states, leading to a surge of AI-related legislation. This emergent state-led regulatory landscape significantly impacts any organization developing, deploying, or utilizing AI systems within the United States. For cloud providers, AI developers, and DevOps teams, the absence of a unified federal framework means navigating a complex, potentially divergent, set of state-specific requirements. The Illinois law, in particular, introduces a stringent third-party audit mandate, which raises the bar for demonstrating AI safety and trustworthiness. This shift affects not just AI labs but also enterprises integrating AI, as they become responsible for ensuring their AI supply chain adheres to these new standards. The convergence with EU-like regulations suggests a global trend towards more robust oversight, making "responsible AI" not just a best practice but an increasingly legal necessity. The fragmentation of AI regulation in the US, contrasted with the comprehensive approach of the EU AI Act, has been a long-standing point of discussion in the AI ethics and governance space. While the EU has pursued a risk-based, rights-centric framework, the US federal government has historically favored a more innovation-friendly, less prescriptive stance. However, the recent actions by states like Illinois, California, and New York indicate a growing recognition that self-regulation and voluntary guidelines are insufficient to address the societal risks posed by advanced AI. This trend mirrors the broader movement towards "shift-left" in security and compliance within DevOps, where ethical considerations and regulatory adherence are integrated early into the development lifecycle. The push for auditable safety practices and transparency aligns with the demand for explainable AI (XAI) and robust MLOps practices that ensure model accountability and governance throughout their lifecycle. Practitioners must proactively assess their AI systems against a potentially diverse set of state regulations, rather than solely relying on federal guidance. This includes establishing clear internal policies for AI development, deployment, and monitoring that can withstand external scrutiny. DevOps and MLOps teams should prioritize building robust logging, auditing, and explainability features into their AI pipelines to facilitate compliance with transparency and accountability requirements. The Illinois mandate for third-party audits means that organizations should begin evaluating potential independent auditors and preparing their documentation and processes for such assessments. Furthermore, companies operating across state lines or internationally will need to develop flexible compliance strategies that can adapt to both the emerging US state-level regimes and established international frameworks like the EU AI Act. The trade-off is increased overhead in compliance and auditing, but the benefit is reduced legal risk, enhanced public trust, and a more resilient AI ecosystem. Ignoring these state-level developments could lead to significant legal penalties, reputational damage, and operational disruptions.
#ai regulation#governance#compliance#state laws#third-party audit#responsible ai
Read original source