Start with the people and the decision
Identify the state connections, personal information being processed and whether the output affects an individual’s access to employment, housing, finance, healthcare or another service. Record the actual decision-making process, including the human’s ability to change the outcome.
A tool that drafts a support response does not automatically fall within every automated-decision rule. Using its output to determine eligibility for a service can change the analysis. Developers, deployers and covered businesses have different duties, definitions and exceptions under each regime.
Healthcare teams: state governance rules are only part of the assessment. Read the medical AI guide for FDA device questions, clinical oversight, health data, certified health IT and EU medical-device requirements.
California: privacy risk and significant decisions
The CPPA’s completed CCPA rulemaking covers risk assessments, cybersecurity audits and automated decisionmaking technology (ADMT), alongside privacy updates. It applies to covered businesses and specified activities, not to every company using AI. Assess CCPA coverage and the processing trigger separately. CPPA adoption and effective-date record.
Under the approved text, ADMT replaces or substantially replaces human decision-making. Article 11 addresses its use for significant decisions, with definitions and exceptions that matter. Required capabilities include pre-use notices, access and opt-out processes, subject to permitted exceptions. Compliance is due January 1, 2027. Sections 7001(e), 7001(ddd), 7200 and 7220–7222.
For covered processing initiated from January 1, 2026, conduct the required privacy risk assessment before starting. Covered processing already underway has a December 31, 2027 assessment deadline. Review at least every three years and update after qualifying material changes within the rule’s timeframe. Initial risk-assessment submissions to the agency are due April 1, 2028. Cybersecurity audit requirements have separate thresholds and phased dates. Sections 7150, 7155, 7157 and 7120.
Operating practice: make a processing inventory, assign the assessment owner, document benefits and privacy risks, and connect safeguards to service steps. Record how an opt-out or appeal reaches a person with authority. Check the exact regulatory exceptions before claiming that a human somewhere in the process removes ADMT coverage.
Liquid Learn can organize a service model and supporting review evidence. It does not determine CCPA coverage, fulfill consumer requests, file assessments with the CPPA or perform a required cybersecurity audit.
Colorado: the 2026 law replaces the earlier AI regime
SB26-189 was signed May 14, 2026 and repeals and reenacts the earlier provisions. The current regime concerns ADMT that materially influences consequential decisions. Use the signed 2026 Act when planning, rather than carrying forward a checklist for SB24-205. General Assembly enacted bill and history; signed Act.
Consequential decisions concern specified areas including education, employment, housing, financial or lending services, insurance, healthcare and essential government services. The Act distinguishes developers supplying covered technology from deployers using it, with exemptions and conditions. Enacted summary and definitions.
Starting January 1, 2027, covered developers must supply technical documentation on intended uses, training-data categories, limitations and appropriate use and human review. The regime also addresses notices, adverse outcomes, requests to correct data, meaningful human review and reconsideration, and retention of compliance records for at least three years. Signed Act, Part 17.
Rulemaking remains in progress: the Attorney General filed proposed implementing rules on August 11, 2026, with a public comment period through October 26, 2026. Those draft details should not be treated as final requirements. The AG identifies January 1, 2027 as the new law’s main application date. Colorado AG rulemaking and status.
Operating practice: obtain the developer’s documentation, record how the output influences the decision, assign the consumer-response and human-review owners, and retain evidence of the operating procedure. Track final rules as a review trigger. Liquid Learn’s map and review record support that work; they do not operate a consumer appeal service.
Texas HB 149: assess specific duties and prohibited uses
The Texas Responsible Artificial Intelligence Governance Act is effective. Its scope includes persons conducting or promoting business in Texas, producing products or services used by Texas residents, or developing or deploying AI in the state. Specific duties depend on the provision and the actor. Enrolled summary; Section 551.002.
The Act addresses specified prohibited uses, including intentional unlawful discrimination and harmful manipulation. Governmental AI interactions and AI used in healthcare service or treatment have particular disclosure provisions. It does not impose the same disclosure obligation on every private chatbot. The Attorney General has enforcement authority. Sections 552.051–552.057 and Subchapter C.
Operating practice: document the intended purpose, covered users and who operates each AI step. Assess prohibited-use risks, place applicable notices at the relevant interaction, and assign a response owner. For a clinical service, read the healthcare disclosure detail. Treat a control in the service map as a record of work to validate, not proof that the underlying AI behavior is lawful.
FTC enforcement: claims and data practices need evidence
Enforcement example · Final settlement ordersOn August 27, 2026, the FTC finalized orders settling allegations that Cox Media Group and two other firms misrepresented an AI-powered “active listening” marketing service and consumer consent. This is an enforcement example under existing consumer-protection authority, not a universal AI certification scheme or a finding about Liquid Learn. FTC final orders announcement.
Operating practice: connect each material AI claim to substantiating evidence, record the actual data source and permission, and assign an owner for approving changes to the service description. Review vendor claims before repeating them to customers. FTC AI enforcement and policy collection.
Federal policy proposal · Not an enacted national mandateThe FTC’s July 1, 2026 policy statement addressing suppression of AI accuracy is identified as proposed in its current AI collection. A proposal or federal policy framework is not, by itself, an enacted national compliance law. This guide does not assume state requirements have been preempted. Confirm any claimed preemption against enacted law and applicable court decisions. FTC proposal status.
NIST AI RMF: a structure for ongoing governance
Govern assigns responsibility and review policy. Map documents context and affected people. Measure develops evidence about risks and limitations. Manage prioritizes responses and monitors change. NIST presents AI RMF as voluntary; using it does not replace state or sector requirements. NIST AI RMF; Playbook.
Use the functions to keep a service review coherent across teams, while maintaining a separate determination of the laws that apply. See the practical NIST-to-product mapping.
Connect the governance concern to verified capability
| Governance concern | Operational practice | Liquid Learn capability | Limitation or dependency |
|---|---|---|---|
| Privacy and decision scope | Map data, affected users and the decision path. | Service flows and data classifications on nodes and connections. | Teams determine legal thresholds, exceptions and required assessments. |
| Accountability and human review | Name decision, exception and consumer-response owners. | Owners, human steps and service notes. | Consumer rights and clinical or other decisions must be handled in operational systems. |
| Evidence for claims and controls | Connect vendor documentation and testing evidence to review work. | Review packet evidence references and control context. | Your team substantiates claims and validates controls; no automatic legal verification. |
| Changes and review readiness | Revisit a service after a material use, data or model change. | Versioned service models and dated review snapshots. | Review schedules, legally required retention and submissions require organizational processes. |
Connect the review to a real service
See how Liquid Learn connects AI service maps, accountable owners, controls and evidence. Or start with the 24-question health check for an immediate result and downloadable PDF roadmap.
Educational information, not legal advice. Applicability depends on jurisdiction, organizational role and use case. Confirm your obligations with qualified counsel. Liquid Learn supports governance work; using it does not certify or guarantee compliance.