TEXAS AI REPORT
policy

Texas, Colorado, and the EU Just Diverged on AI Law. Here's the New Map.

By ·

Last reviewed June 26, 2026

Colorado just redrew the AI compliance map. On May 14, 2026, Governor Polis signed SB 26-189, repealing the state’s original AI Act (SB 24-205) and replacing it with a narrower framework built around disclosure and consumer rights — no impact assessments, no duty of care. For anyone tracking AI regulation from Texas, that repeal moves the reference points. There are now three dominant regimes, and they no longer rhyme.

The new landscape at a glance

TRAIGA (Texas)Colorado SB 26-189EU AI Act
Effective dateJan 1, 2026Jan 1, 2027Phased: Feb 2025–Aug 2027+
FrameworkProhibition-based (intent required)Disclosure + consumer rightsRisk-based tiered
EnforcerTX AG exclusivelyCO AG exclusivelyNational authorities + EU AI Office
Disclosure dutiesGov agencies + healthcare providers onlyAll covered ADMT in 7 domainsVaries by risk tier
Impact assessmentsNoNo (eliminated)Yes (high-risk systems)
Max penalty$200,000/violation (uncurable)Not yet specifiedEUR 35M or 7% global revenue
NIST safe harborYes (explicit)NoNo

What changed, and why Colorado pivoted

The original SB 24-205 mirrored the EU’s risk-tiered model, with deployer impact assessments and a duty-of-care standard. It was delayed twice, then stayed by a federal court in April 2026 after xAI sued and the DOJ intervened — a challenge fed in part by a December 2025 White House executive order that singled out Colorado’s approach.

SB 26-189 passed 34–1 in the Colorado Senate and 57–6 in the House. What survives: consumer notice at the point of AI interaction, post-adverse-outcome notice within 30 days, consumer rights to access data and request human review, and AG enforcement with a 60-day cure period. What was dropped: impact assessments, deployer risk-management programs, and the algorithmic discrimination duty of care. Seven sectors remain in scope — education, employment, housing, financial services, insurance, healthcare, and government services — but the compliance burden is much lighter than before.

Where Texas stands

TRAIGA has been in effect since January 1, 2026, and its logic differs from both Colorado and the EU: it targets intent, not risk tiers. The core prohibitions — behavioral manipulation designed to incite self-harm, constitutional-rights infringement, intentional unlawful discrimination (disparate impact alone is not enough), and child sexual content — apply to any entity. Government agencies must disclose AI interactions to consumers before or at the time of contact. Healthcare providers must disclose AI use in treatment on the date of service. Private non-healthcare businesses face no disclosure requirement at all.

Penalties run in tiers: $10,000–$12,000 for curable violations, $80,000–$200,000 for uncurable ones, and $2,000–$40,000 per day for continuing ones. An explicit NIST AI RMF safe harbor is available. As of May 2026, no TRAIGA enforcement actions had been publicly reported.

The EU’s next deadline: August 2

Most high-risk obligations under the EU AI Act — Annex III systems, transparency rules — take effect August 2, 2026. That is six weeks out. Prohibited AI practices have been enforceable since February 2025; GPAI model rules since August 2025. A political agreement to streamline certain obligations was reached May 7, 2026, but formal EU Parliament and Council adoption had not been confirmed as of publication.

For Texas-based companies with EU operations or EU customers, August 2 is a live deadline, not a distant one.

Three regimes, three theories of harm

Strip away the detail and the divergence is clean. Texas prohibits bad intent. Colorado mandates disclosure and consumer rights in defined sectors. The EU imposes tiered conformity obligations by risk. None of the three creates a private right of action; all three rely on government enforcement with a cure window before penalties attach.

The practical problem is that a compliance posture built around any one of them leaves gaps in the other two. Which is why the starting point hasn’t changed since the day TRAIGA passed: know exactly which AI systems you run, and where they touch people.

Frequently asked questions

Why did Colorado repeal its original AI Act rather than simply amend it?

The original SB 24-205 faced compounding opposition: a December 2025 White House executive order criticized Colorado's risk-tiered approach, the DOJ stood up an AI Litigation Task Force in January 2026, xAI sued the state, and a federal magistrate stayed the law on April 27, 2026. The replacement, SB 26-189, then cleared the Colorado Senate 34-1 and the House 57-6 — margins that read less like a patch than a decision to start over.

Does Colorado's new SB 26-189 require impact assessments the way the original law did?

No. Impact assessments, deployer risk-management programs, and the algorithmic-discrimination duty of care were all dropped. SB 26-189, effective January 1, 2027, relies instead on consumer notice at the point of interaction, post-adverse-outcome notice within 30 days, and consumer rights to access data and request human review — a substantially lighter structure than its predecessor.

Get the Texas AI daily brief
Matthew Bertram
Founder & Editor · Certified AI Auditor · NIST Cyber-AI Profile contributor. matthewbertram.com →
TRAIGAAI regulationColorado AI ActEU AI Actcompliance

Analysis and commentary, not legal advice.