State-by-State AI Security Legislation: Q2 2026 Tracker
Home / Intelligence / State-by-State AI Security Legislation: Q2 2026...
Standards & Compliance

State-by-State AI Security Legislation: Q2 2026 Tracker

How biometric privacy statutes, state AI governance laws, the 14-state Alyssa's Law expansion, and SB 553 are reshaping AI security procurement in Q2 2026.

Published April 2026
Read Time 16 min read
Stream Standards & Compliance
1,561
AI-related bills introduced across 45 state legislatures in Q1 2026 (NCSL AI Legislation Database)
14
States with Alyssa's Law silent panic alert mandates in effect or signed by Q2 2026 (Make Our Schools Safe)
$1k–$5k
Per-violation BIPA statutory damages available to private plaintiffs in Illinois (740 ILCS 14)

The state-by-state AI security legislation landscape changed faster between January 2025 and April 2026 than it had in the prior decade combined. Three pressure systems are converging at once: a wave of biometric privacy statutes that constrain how computer vision platforms can be deployed, a parallel wave of school safety mandates (Alyssa’s Law and its derivatives) that require schools to deploy them, and a third wave of cross-cutting AI governance laws — the Colorado AI Act, Texas TRAIGA, and follow-on bills in roughly a dozen more states — that impose disclosure, accountability, and consequential-decision rules on the platforms themselves. The state-by-state AI security legislation tracker that follows is built to give procurement teams a Q2 2026 snapshot of where each pressure system stands.

This Q2 2026 tracker is built for security directors, general counsel, school superintendents, hospital risk officers, and procurement leads who need to understand which statutes actually apply to a physical security AI deployment, where the enforcement risk sits, and how the procurement calculus changes by jurisdiction. It maps the four legislative categories that matter most, walks through the top ten state regimes by procurement impact, and ends with a buyer’s decision framework for evaluating vendors against the rules in force where the cameras will live.

Real IntelliSee weapon detection overlay on commercial CCTV footage with bounding box and confidence score on a drawn firearm
LIVE CAM-12 · INTERIOR CORRIDOR
Actual IntelliSee detection output. A drawn firearm flagged with bounding box and confidence score in real time on existing CCTV infrastructure. The detection layer infers an object, not an identity. No facial recognition. No stored video. No protected health information. That architectural choice is what keeps an installation viable under Illinois BIPA, the Washington biometric statute, the Colorado AI Act, and the next dozen state biometric bills working through committee in 2026.

Why state-level AI security legislation became the dominant compliance variable in 2026

State legislative volume on AI is now an order of magnitude greater than the federal rulemaking pipeline. The National Conference of State Legislatures reports that lawmakers in 45 states introduced 1,561 AI-related bills in the first quarter of the 2026 session, already surpassing the total volume of AI bills introduced in all of 2024. That is a velocity that any vendor — or buyer — selecting a physical security platform cannot afford to track informally.

The vacuum at the federal level explains the state activity. Congress has not passed comprehensive AI legislation, and federal regulators have chosen sector-specific rulemaking over a unified statute. State legislatures, watching the EU operationalize the AI Act, have moved to fill the gap on their own timelines — with the predictable result that the rules in Springfield differ from Sacramento, Austin, and Hartford.

For a physical security buyer, procurement now has a jurisdictional dimension it did not have in 2022. A multi-site healthcare system with hospitals in Illinois, Texas, and Washington is operating under three different biometric statutes. A multi-state school district consortium evaluating AI gun detection for K–12 campuses is doing so under a patchwork of Alyssa’s Law variants whose technology requirements are converging but not identical. Four legislative categories carry essentially all of the procurement-relevant pressure.

The four state-level legislative categories that matter for AI security procurement

Most of the state activity falls into one of four buckets. The categories are not always cleanly separated — a single bill can introduce both biometric privacy and school-safety obligations — but understanding the four lets a buyer build a defensible compliance map from the ground up.

Four Categories of State AI Security Legislation Driving 2026 Procurement

CategoryWhat It RegulatesAnchor Statutes
Biometric privacyCollection, retention, and use of facial geometry, voiceprints, fingerprints, and other biometric identifiers by private entitiesIllinois BIPA (740 ILCS 14), Texas CUBI, Washington RCW 19.375, plus comprehensive privacy laws in Colorado, Connecticut, Virginia, and others with biometric annexes
Cross-cutting AI governanceAlgorithmic accountability, disclosure, impact assessment, and prohibited use cases for AI systems generallyColorado AI Act (SB 24-205), Texas TRAIGA (HB 149), New York Algorithmic Pricing Disclosure Act, plus parallel bills in NJ, CA, IL, MA
School safety mandatesRequired deployment of silent panic alert technology, weapons detection capability, and threat-reporting infrastructure in K–12 environmentsAlyssa’s Law (now in 14 states), Florida MSDHS Public Safety Act (SB 7026), Tennessee SAVE Act and 2024 funded-pilot legislation, FortifyFL
Workplace violence preventionRequired WV prevention plans, incident reporting systems, and (increasingly) technology specifications, especially in healthcare and general industryCalifornia SB 553, Virginia HB 2269 / SB 1260, Missouri HB 3401, Massachusetts H.4767, Vermont H.259 / Act 9

The buyer’s mistake is to treat these as alternatives. A single deployment in a single facility can sit inside all four simultaneously: a Texas hospital evaluating drawn-firearm detection on a campus that also includes a behavioral health unit and a charter school is operating under CUBI (biometrics), TRAIGA (AI governance), and Texas’s Alyssa’s Law variant for the school portion of the property. The compliance map has to be drawn jurisdiction by jurisdiction and facility by facility.

Category 1: State biometric privacy laws and what they actually permit

Biometric privacy statutes are where most physical security AI deployments live or die. The category is older than the AI governance category — Illinois BIPA was enacted in 2008 — but the procurement implications have shifted as computer vision platforms have grown more capable.

The architectural distinction that matters is between platforms that compute biometric identifiers and those that perform object, posture, and motion-pattern detection. A platform that does facial recognition or computes a face template is regulated by every state biometric statute. A platform that performs object-level detection — identifying that a drawn firearm is present without identifying who is holding it — is generally outside the biometric-identifier scope, which is why it is the dominant architectural choice for healthcare, K–12, and behavioral health deployments.

Illinois BIPA (740 ILCS 14) is still the most consequential biometric statute in the country because it is the only one with a private right of action. Plaintiffs can recover $1,000 per negligent violation and $5,000 per intentional or reckless violation, plus attorneys’ fees and costs. On April 1, 2026, the Seventh Circuit ruled that the 2024 amendment capping damages at one recovery per person rather than one per scan applies retroactively to pending lawsuits — a major plaintiff-side change, but BIPA still anchors the U.S. biometric enforcement landscape.

Texas CUBI (Bus. & Com. Code Ch. 503) covers similar ground but lacks the private right of action. Enforcement is by the Texas Attorney General, with civil penalties up to $25,000 per violation. Consent does not have to be in writing, which is a meaningful operational difference for camera-based deployments where written consent at the point of capture is impractical.

Washington (RCW 19.375) covers commercial use of biometric identifiers and is enforced by the Washington Attorney General under the Consumer Protection Act. The statute is narrower than BIPA and CUBI in that it applies only to identifiers enrolled for commercial purposes, which has been litigated as a meaningful exclusion for security-only use cases.

Colorado, Connecticut, Virginia, and a growing number of comprehensive privacy laws include biometric annexes. Colorado HB 24-1130, effective July 2025, requires consent for biometric collection, prohibits sale of biometric data, and mandates deletion protocols. The downstream effect is that even states without standalone biometric statutes increasingly regulate biometrics through their broader privacy regimes.

The Architectural Decision That Determines Compliance

Why object-level detection sits outside most state biometric scope

State biometric statutes regulate biometric identifiers — data derived from a person’s physiological characteristics that can be used to identify that specific person. A platform that detects an object (a drawn firearm, a person in a restricted zone, a fall in progress) is not generating a biometric identifier in the statutory sense. The detection is based on what something is, not who it belongs to. This distinction is what allows a properly architected computer vision platform to be deployed in Illinois, Washington, or Texas without triggering BIPA, the Washington biometric statute, or CUBI’s consent and retention requirements. Buyers should confirm in writing during procurement that no facial geometry, no face templates, and no biometric identifiers are computed at any stage of the detection pipeline. That single line in the contract is the most important biometric-compliance control a buyer can secure.

Category 2: Cross-cutting AI governance laws and how they treat physical security systems

The AI governance category is the newest and the fastest-growing. It includes statutes that regulate AI generally rather than biometrics specifically: algorithmic accountability requirements, impact assessments for high-risk systems, prohibited use cases, and disclosure obligations.

Colorado AI Act (SB 24-205), signed in May 2024 and now scheduled to take effect June 30, 2026 after a 2025 special-session delay, is the most comprehensive state AI statute in force. It regulates “high-risk” AI systems — defined as AI used to make or substantially contribute to consequential decisions about education, employment, financial services, government services, healthcare, housing, insurance, or legal services. A physical security system used purely to detect threats and route alerts is not generally a “consequential decision” system in the statutory sense. But a system that filters access to housing, scores employee risk, or denies entry based on algorithmic judgment can fall within scope. The line is functional, not technological.

Texas TRAIGA (HB 149), signed in June 2025 and effective January 1, 2026, took a narrower path. The original draft mirrored the Colorado high-risk framework; the enacted version was pared back to prohibited use cases (behavioral manipulation, unlawful discrimination, deepfake creation, constitutional rights infringement). Government entities are prohibited from using AI for social scoring or biometric identification without consent. For private security buyers, TRAIGA is meaningful but not as procedurally heavy as Colorado’s law.

New York went a different direction with targeted disclosure statutes: the Synthetic Performer Disclosure law (effective June 9, 2026) and the Algorithmic Pricing Disclosure Act (GBL § 349-A, effective November 10, 2025). Neither directly regulates physical security platforms, but both signal the disclosure-first posture New York is likely to extend to other AI use cases.

The procurement implication of the AI governance category is more about process than product. Buyers in Colorado-style jurisdictions should expect to maintain impact assessments, document AI use, and demonstrate reasonable care — even where the deployment itself is below the “consequential decision” threshold — because the documentation burden is itself a defense against future enforcement.

Category 3: School safety mandates and the Alyssa’s Law expansion

School safety legislation is moving in the opposite direction from the privacy/governance categories. Where biometric and AI governance laws constrain deployment, school safety statutes increasingly require it — and the technology specifications inside those statutes are getting more prescriptive. The threat picture justifies the legislative posture: the FBI’s 2024 Active Shooter Incidents in the United States report documented 24 designated active-shooter incidents in 19 states across five location categories, with education accounting for 17% of incidents and the five-year cumulative count reaching 223 incidents nationwide between 2020 and 2024.

Alyssa’s Law is the anchor. Named for 14-year-old Alyssa Alhadeff, killed in the 2018 Marjory Stoneman Douglas High School shooting, the law requires public elementary and secondary schools to be equipped with silent panic alarms directly linked to law enforcement. As of Q2 2026, Alyssa’s Law has been signed in fourteen states: New Jersey (2019), Florida (2020), New York (2022), Texas (2023), Tennessee (2023), Utah (2024), Oklahoma (2024), Georgia (2025), Washington (2025), Oregon (2025), Virginia (2026), and West Virginia (2026), with active companion bills in roughly a dozen additional states.

Florida’s Marjory Stoneman Douglas High School Public Safety Act (SB 7026), enacted in 2018, remains the most prescriptive state-level school security statute. It established the Office of Safe Schools, required school security risk assessments, created the FortifyFL suspicious-activity reporting tool, and established the School Hardening Grant program. The state has subsequently appropriated more than half a billion dollars in school safety funding through that grant program, with successive legislative cycles expanding eligibility and increasing the budget line.

Tennessee’s SAVE Act and 2024 school safety legislation went a different direction, requiring firearms safety instruction and authorizing armed school staff while also funding pilot weapons-detection programs. As Education Week documented in March 2026, several states are now moving from panic-alert mandates to weapons-detection funding, with Tennessee, Texas, and Florida among those funding district-level pilots.

For procurement, the school safety category creates an unusual buyer dynamic: regulatory pressure is to buy, not to abstain. But the system that satisfies a panic-alert mandate is different from the system that satisfies a weapons-detection mandate. Most Alyssa’s Law statutes contemplate staff-triggered alerts as the core compliance mechanism; the newer weapons-detection laws contemplate camera-based AI detection that triggers alerts without staff action. Buyers should treat these as complementary layers rather than substitutes.

Florida

The MSDHS Public Safety Act (SB 7026) is the most comprehensive state-level school security statute. School Hardening Grants fund physical security investments based on documented risk assessments. The Office of Safe Schools maintains the central repository for best practices, training standards, and compliance. FortifyFL provides the suspicious-activity reporting infrastructure. For procurement, every Florida district has an active funded pathway for AI security technology.

Tennessee

The SAVE Act anchors the school safety framework, with 2024 legislation adding firearms safety instruction and an armed-staff authorization. Most importantly for AI security procurement, Tennessee has begun funding pilot weapons-detection programs at the district level — a direction Texas and Florida have started to follow. Districts evaluating AI gun detection should expect Tennessee to remain a state where pilot funding is available.

Texas

The Alyssa’s Law variant signed in 2023 creates the silent panic alert obligation. Texas TRAIGA, effective January 1, 2026, governs AI use more broadly and prohibits government biometric identification of individuals without consent. Combined with Texas CUBI on biometrics, Texas presents one of the most layered procurement environments in the country: school districts must satisfy panic-alert obligations under Alyssa’s Law while operating under both TRAIGA and CUBI in parallel.

New Jersey

The original Alyssa’s Law jurisdiction. The 2019 statute set the template every subsequent state has adapted. New Jersey’s implementation guidance, school-by-school deployment data, and litigation history are the deepest reference set in the country for what compliance actually looks like. New Jersey districts now layered with biometric privacy obligations through the broader 2025 New Jersey Data Privacy Act.

Category 4: Workplace violence prevention statutes and the technology question

Workplace violence prevention statutes are the fourth state legislative category, and they have matured fastest in healthcare. The category is treated in depth in the Healthcare Workplace Violence Playbook; this section covers the cross-sector procurement angles.

California SB 553, effective July 1, 2024, was the first state to require WV prevention plans across general industry — not just healthcare. Covered employers must maintain a written Workplace Violence Prevention Plan, log incidents, train employees, and conduct hazard assessments. Cal/OSHA is developing the formal standard implementing the statute, with adoption required by December 31, 2026. Penalties for non-compliance reach $25,000 per serious violation and $158,727 per willful violation. The statute does not specify technology, but the “reasonable steps to prevent” standard is increasingly being read by plaintiff’s counsel and Cal/OSHA inspectors as encompassing modern detection technology where it is operationally feasible.

Virginia HB 2269 / SB 1260, Missouri HB 3401, Vermont H.259 / Act 9, and Massachusetts H.4767 form the healthcare-specific WV legislative wave. Each requires hospital-level written prevention plans, incident reporting systems, and prevention committees. The Massachusetts statute goes furthest by requiring documented evaluation of available detection technology as part of the annual review. The category creates documentary pressure rather than direct technology mandates: a hospital that evaluated AI detection during its required hazard assessment is in a stronger compliance posture than one with no documented evaluation.

Q2 2026 Legislative Pressure Map

The four state-level levers shaping AI security procurement right now

How each category constrains, enables, or requires deployment — with anchor jurisdictions for each.

Constrains
Biometric Privacy

IL (BIPA), TX (CUBI), WA, plus CO HB 24-1130, CT, VA biometric annexes

Object-level detection generally outside scope; facial recognition triggers full consent and retention obligations.

Disclosure
AI Governance

CO AI Act (SB 24-205), TX TRAIGA, NY GBL § 349-A & § 396-b

Documentation and impact-assessment burden; functional “consequential decision” line determines scope.

Requires
School Safety Mandates

14 Alyssa’s Law states; FL SB 7026; TN SAVE Act

Silent panic alert is the floor; weapons detection is the next deployment wave; funded grant pathways exist.

Documents
Workplace Violence Prevention

CA SB 553; VA, MO, VT, MA hospital-specific statutes

Required written plans and hazard assessments; technology evaluation increasingly part of the “reasonable steps” standard.

The ten state regimes with the highest 2026 procurement impact

Not every state changes procurement materially. The ten below do. They are listed in alphabetical order, with the procurement implication for each.

California. SB 553 makes WV prevention plans mandatory in general industry, with the Cal/OSHA standard due by year-end 2026. CCPA / CPRA treats biometric information as sensitive personal information requiring opt-out. Procurement note: California buyers should fold AI security investment into the SB 553 documentation pathway, where it strengthens the “reasonable steps” defense.

Colorado. The Colorado AI Act (SB 24-205) is the most comprehensive state AI statute now in force, with effective date June 30, 2026. HB 24-1130 covers biometric privacy. SB 22-113 requires accountability reports and warrants for government facial recognition. Procurement note: Colorado buyers should maintain documented impact assessments for any AI system in use, even where the “consequential decision” threshold is not met.

Connecticut. The Connecticut Data Privacy Act includes biometric annexes and consent obligations. 2025 amendments strengthened facial recognition restrictions. Procurement note: Among the comprehensive-privacy-law states whose biometric scope expands annually through legislative tuning.

Florida. SB 7026, the School Hardening Grant program, and FortifyFL make Florida the most procurement-friendly state for school security AI. Procurement note: Districts have an active funded pathway and a state-maintained best-practices repository.

Illinois. BIPA remains the dominant biometric statute and the only one with a private right of action. The April 2026 Seventh Circuit ruling on retroactive damages caps was a plaintiff-side change, but BIPA still drives architectural decisions for any platform deployed in Illinois. Procurement note: Object-level detection without facial templates is the default architecture for Illinois deployments.

Massachusetts. H.4767 imposes documented technology evaluation as part of the hospital workplace violence prevention process. Procurement note: Healthcare buyers should treat the hazard-assessment documentation requirement as a procurement gate, not a downstream compliance step.

New York. The Algorithmic Pricing Disclosure Act and the Synthetic Performer Disclosure law signal New York’s disclosure-first regulatory posture. Alyssa’s Law was signed in 2022. Procurement note: Expect future New York AI rules to follow the disclosure path rather than the Colorado high-risk path.

Tennessee. The SAVE Act, Alyssa’s Law (2023), and 2024 weapons-detection pilot funding make Tennessee a leading state for K–12 AI security procurement. Procurement note: District-level pilot funding remains the most accessible procurement pathway.

Texas. Texas operates simultaneously under CUBI (biometrics), TRAIGA (AI governance, effective January 1, 2026), and the 2023 Alyssa’s Law variant. Procurement note: Multi-layered, with TRAIGA imposing a relatively light burden compared to Colorado’s framework but CUBI still requiring careful biometric architecture.

Virginia. Hospital-specific HB 2269 / SB 1260, Alyssa’s Law (2026), and a broader privacy regime put Virginia in the multi-category pressure cooker. Virginia is also one of two states (with Colorado) requiring testing and accuracy standards for facial recognition. Procurement note: A particularly thorough vendor-testing posture is expected in Virginia.

Washington. RCW 19.375 governs commercial biometric use; the state-level data privacy regime continues to expand through 2026 legislative cycles. Alyssa’s Law was signed in 2025. Procurement note: Among the more buyer-friendly biometric statutes, but the comprehensive privacy law expansion bears watching.

A buyer’s decision framework for evaluating AI security platforms against state regulation

Procurement under this many overlapping statutes calls for a defensible decision framework rather than a vendor-by-vendor checklist. Five questions are the core of the framework.

Question 1: What is the platform’s detection architecture? Does it compute biometric identifiers (facial geometry, voiceprint, gait) at any stage, or does it perform object, posture, and motion-pattern detection only? An object-only architecture is the cleanest path through state biometric statutes. Buyers should confirm in writing that no biometric identifier is computed.

Question 2: Where does video go? Is detection performed on-premises or in the cloud? On-premises detection avoids data-residency questions under most state privacy laws and reduces the network surface area subject to comprehensive privacy regulation. Cloud detection introduces transfer, retention, and processor-controller analysis under CCPA-style regimes.

Question 3: What does the platform store, and for how long? Storage of video, metadata, or detection events triggers retention rules under state biometric statutes (where biometric data is involved) and under comprehensive privacy laws (where personal data is involved). A platform that does not store video and does not store biometric identifiers materially reduces retention obligations.

Question 4: What is the alert routing path? Are alerts routed only to designated responders, or are they shared with third parties? Sharing with first responders is generally protected under public-safety exceptions in most state privacy regimes, but commercial integrations require closer analysis. Integration with platforms like RapidSOS for first-responder alerting falls within the protected category in most states.

Question 5: What is the documented compliance posture? Does the vendor maintain SOC 2 attestation, DHS SAFETY Act designation or certification, and impact assessment documentation? For Colorado AI Act compliance specifically, buyers should expect vendors to provide written representations about whether the platform is “high-risk” under the statute and to share the impact assessment documentation sufficient to support the buyer’s reasonable-care defense.

For a deeper procurement framework that integrates these compliance variables with the economic case, see The Economic Case for AI Security: A Four-Variable Framework. For the vendor landscape mapping that determines which platforms even reach the framework above, see AI Video Analytics Market Landscape: Vendor Tiers, Buyer Intent, and Strategic Positioning.

What to watch in the second half of 2026

Three legislative trends will shape the next two quarters.

First, weapons-detection mandates beyond panic alerts. Several states are moving past silent-panic-alert requirements toward explicit funding and authorization for camera-based AI weapons detection. Education Week’s March 2026 coverage flagged this as a sustained legislative direction in Tennessee, Texas, and Florida.

Second, biometric statute expansion through comprehensive privacy laws. States passing or amending comprehensive privacy laws are folding biometric provisions inside, often with stricter consent and retention rules than the standalone biometric statutes.

Third, AI governance follow-on to Colorado. A handful of state legislatures are watching Colorado AI Act implementation closely and are likely to introduce parallel high-risk frameworks in the 2027 sessions. New Jersey, Massachusetts, Illinois, and California are the most likely follow-ons.

Buyers should expect the regulatory map to expand, not contract. Architecting for the strictest current state is the durable choice: a platform that satisfies Illinois BIPA, Colorado AI Act, and California SB 553 today is positioned to satisfy nearly any state regime emerging through the 2027 cycle.

Frequently asked questions about state AI security legislation in 2026

Does Illinois BIPA prohibit AI gun detection or video analytics in commercial buildings?

No, but it constrains the architecture. BIPA regulates biometric identifiers — data derived from physiological characteristics that can identify a specific person. Object-level detection (a drawn firearm, a person in a restricted zone, a fall in progress) does not generate biometric identifiers in the statutory sense. A platform that performs object detection without computing facial geometry, voiceprints, or other biometric identifiers can be deployed in Illinois without triggering BIPA’s consent and retention obligations. Buyers should confirm the architectural choice in writing during procurement.

Does the Colorado AI Act apply to physical security AI systems?

It depends on whether the system makes or substantially contributes to a “consequential decision” under the statute. A pure detection-and-alerting system that identifies threats and routes alerts to responders is generally outside scope. A system that filters access to housing, scores employee risk, or denies entry based on algorithmic judgment can fall within scope. The line is functional, not technological. Colorado buyers should maintain documented impact assessments regardless, because the documentation is itself a defense against future enforcement actions.

Which states have signed Alyssa’s Law as of Q2 2026?

Fourteen as of April 2026: New Jersey (2019), Florida (2020), New York (2022), Texas (2023), Tennessee (2023), Utah (2024), Oklahoma (2024), Georgia (2025), Washington (2025), Oregon (2025), Virginia (2026), and West Virginia (2026), with active companion bills in roughly a dozen additional states. Most variants require silent panic alert capability with direct law-enforcement notification. The technology specifications are converging but not identical state-to-state — some require district-wide coverage, others permit phased deployment.

How does California SB 553 affect AI security procurement?

SB 553 does not specify technology, but it requires covered employers to maintain a written Workplace Violence Prevention Plan, log incidents, train employees, and conduct hazard assessments. The “reasonable steps to prevent” standard is increasingly being read by Cal/OSHA inspectors and plaintiff’s counsel as encompassing modern detection technology where it is operationally feasible. California employers that have evaluated AI detection during their hazard assessment — and documented the evaluation, whether or not they deployed — are in a stronger compliance posture than employers with no documented evaluation at all.

Can a hospital deploy AI threat detection in a behavioral health unit under state privacy laws?

In most states, yes — provided the platform does not perform facial recognition and does not store video. State behavioral health privacy frameworks are generally stricter than HIPAA, and many prohibit identification of patients via biometric means. A platform that performs object, posture, and motion-pattern detection without computing biometric identifiers is generally compatible with behavioral health deployment. This is treated in greater depth in the Healthcare Workplace Violence Playbook.

Does Texas TRAIGA prohibit AI-based weapons detection?

No. TRAIGA prohibits specific AI use cases — behavioral manipulation, unlawful discrimination, deepfake creation, and constitutional rights infringement — and prohibits government social scoring and government biometric identification of individuals without consent. Pure threat-detection-and-alerting systems used by private operators are not within the prohibited categories. Texas operators should still operate in parallel under Texas CUBI on biometrics; the architectural advice is the same as in other biometric-statute states.

How should a multi-state operator approach this regulatory patchwork?

Architect for the strictest current state. A platform that satisfies Illinois BIPA, the Colorado AI Act, California SB 553, and the major Alyssa’s Law variants is positioned to satisfy nearly any state regime that emerges through the 2027 cycle. Multi-state operators should document the architectural decision once, apply it everywhere, and maintain a per-jurisdiction compliance map updated quarterly.

Continue the research

This tracker is a Q2 2026 snapshot. The legislative environment is moving faster than any annual reference can support. For deeper reading on specific pieces of the procurement and compliance picture:

Request a Risk Assessment

Talk to an IntelliSee security specialist. No sales pitch — a structured conversation about your environment, your threat profile, and whether computer vision is the right fit.

Request a Risk Assessment