Home EconomyRegulating the Device or the Hassle? A Survey of State AI Payments

Regulating the Device or the Hassle? A Survey of State AI Payments

by Staff Reporter
0 comments

Debates about federal preemption in artificial-intelligence (AI) coverage usually pose a stark selection: Congress adopts a nationwide framework and states lose the flexibility to police dangerous conduct, or states retain broad authority and companies face a 50-state compliance patchwork that chills innovation. Our overview of state AI payments suggests the controversy is aimed on the incorrect goal. Most state legislative exercise doesn’t regulate how AI programs are constructed.

To make clear phrases: an AI “mannequin” is the core software program—a set of mathematical parameters (“weights”) skilled on massive datasets—that produces textual content, photos, predictions, or different outputs. An AI “system” is the broader product that makes use of a number of fashions, together with interfaces, knowledge pipelines, guardrails, and different utility logic. State payments use each phrases, usually loosely.

Regulating the “mannequin layer” means imposing obligations on builders about how the core software program is designed, skilled, or evaluated. Regulating the “use layer” means governing what individuals and organizations do with AI programs as soon as they exist—how they’re deployed and what conduct they permit. Roughly three-quarters of the state AI payments we examined concentrate on downstream makes use of, reasonably than mannequin design or improvement. In consequence, they’re unlikely to be preempted.

A federal framework might subsequently concentrate on model-layer obligations whereas preserving conventional state police powers over makes use of resembling fraud, deception, impersonation, election manipulation, and discrimination. Below that construction, most state legal guidelines would doubtless survive in some kind.

Two necessary caveats apply. 

First, labeling a invoice as regulating “makes use of” doesn’t essentially make it a conventional police-powers measure. A statute focusing on fraud that imposes joint-and-several legal responsibility on mannequin builders for downstream misuse could learn like a conduct rule. In follow, it capabilities as a model-layer obligation as a result of it forces builders to alter how programs are constructed, not merely how they’re used. States contemplating use-layer laws ought to ask whether or not their proposals successfully require design modifications on the foundational degree. Necessities that function this fashion increase the identical interstate-commerce and compliance-fragmentation considerations as direct model-layer regulation.

Second, even well-intentioned use-layer guidelines can burden interstate commerce. A state’s label doesn’t management the constitutional evaluation. Courts look to substance, not characterization.

Our survey doesn’t predict how courts would resolve any explicit case. No descriptive coding can. It does make clear the sensible stakes: fears that federal AI preemption would remove most state AI legislation don’t match what states are literally enacting and proposing.

Are States Regulating AI or Simply What Folks Do With It?

The core query was easy: when state legislators say they’re “regulating AI,” are they regulating how AI programs are constructed and evaluated, or what individuals do with them?

The excellence issues. It’s simple to lose in statutory definitions, sector-specific protection, and political messaging. Additionally it is economically necessary. Mannequin-layer mandates act like fixed-cost compliance regimes. They require builders to spend money on audits, testing procedures, documentation, or design modifications earlier than a product can enter the market. Use-layer guidelines function in another way. They’re conduct guidelines that connect when somebody deploys an AI system in a dangerous manner.

These usually are not interchangeable regulatory instruments. They produce totally different aggressive results.

We subsequently approached the venture as a descriptive survey. The objective was to not label any explicit invoice “good” or “unhealthy,” and to not resolve edge instances. The goal was to determine which class of regulation states are literally pursuing and what that means for competitors, market entry, and the sensible results of federal preemption.

From 1,200 Payments to a Usable Pattern

State AI laws is huge — the Nationwide Convention of State Legislatures (NCSL) tracks practically 1,200 payments. Many, although, are slim, symbolic, or duplicative throughout chambers and periods. We subsequently designed a filtering method to provide a manageable and policy-relevant dataset, not an exhaustive census.

We started with a big legislative stock and narrowed it by way of a two-step course of.

First got here a handbook overview. We saved a invoice provided that it explicitly addressed “AI programs,” “automated decision-making,” or “AI-generated content material,” and appeared to impose an actual responsibility, requirement, or prohibition. We excluded measures restricted to slim sectors that don’t overlap with main cross-cutting AI threat areas, procurement-administration provisions with out significant regulatory obligations, and plainly nonsubstantive gadgets, resembling job forces, commendations, or symbolic resolutions. When a number of variations existed inside a state, we retained the latest substantively related model. This primary go produced 304 included payments.

The second go used ChatGPT as a triage software. We ran the identical invoice checklist by way of the mannequin to determine measures we’d have ignored. The system didn’t interpret the statutes. As an alternative, it sorted payments primarily based on metadata—state, invoice quantity, topic line, class tags, and standing—so we might prioritize human overview.

The triage produced 4 classes: “embody (doubtless),” “overview,” “exclude (low AI sign),” and “exclude (non-substantive/administrative).” The mannequin flagged 192 payments as “embody (doubtless)” and 45 as “overview,” excluding the rest as both not meaningfully AI-related or nonsubstantive. We then performed text-level overview of the prioritized group, focusing consideration on measures with ambiguous titles, generic descriptions, or potential duplication.

For classification, we requested a intentionally easy query: does the legislation inform builders the right way to construct, take a look at, consider, or function the AI system itself (model-layer regulation), or does it prohibit particular dangerous actions individuals commit utilizing AI (use-layer regulation)? If a invoice contained each options, we positioned it within the class that finest mirrored what the legislation would management in follow. The taxonomy is pragmatic. It’s a descriptive software, not a prediction about litigation outcomes and never a declare that each statute suits neatly right into a single class.

The objective was to seize the form of state legislative exercise, to not rely each invoice with precision. We’re not asserting absolutely the variety of payments transferring in both path. Slightly, the train supplies a grounded sense of the path of journey in state policymaking. Cheap observers could classify explicit payments in another way, however the total sample is obvious.

What State AI Payments Really Regulate

As a result of “AI regulation” is commonly mentioned at 30,000 ft, it helps to see what these payments really do. Our coding rule was deliberately easy: does the invoice impose duties on builders about how an AI system is designed, examined, evaluated, or operated (mannequin layer), or does it prohibit or penalize dangerous conduct carried out with AI (use layer)?

Use-Layer Regulation: ‘Do Not Do X with AI’

California AB 2355 (political-ads disclosure for AI content material)

It is a traditional use-layer measure. It regulates political communications that include AI-generated or AI-altered content material by requiring disclosure. It doesn’t require mannequin builders to run evaluations, audits, or security testing. We coded it as use layer as a result of it targets the downstream speech act and the transparency obligation on the level of use, not the design of the underlying system. (Enacted in 2024.)

Kansas HB 2559 (artificial media in election communications until disclosure is made)

One other acquainted sample: election integrity, disclosure, and penalties tied to dissemination. The set off is the usage of artificial media in marketing campaign communications with out a disclosure. That’s downstream deployment. The invoice doesn’t instruct builders the right way to practice or consider fashions.

Kentucky HB 45 (civil legal responsibility and felony offense for dangerous deepfake dissemination)

That is downstream hurt regulation in direct kind. The statute applies to willful dissemination of a “deep faux” of an identifiable individual with out consent and attaches civil and felony legal responsibility to the disseminator. The obligations fall on the actor who spreads the deepfake, not on mannequin builders. We coded it as use layer for that motive.

Colorado HB 25-1264 (automated determination programs used to set individualized costs or wages primarily based on surveillance knowledge)

Right here, AI seems inside acquainted consumer-protection and labor-adjacent legislation. The invoice restricts a specific deployment—setting individualized costs or wages utilizing sure knowledge practices. Even when carried out by way of algorithms, it regulates conduct on the level of use.

Kansas SB 525 and New York S 1042 (AI-generated sexual or intimate content material with out consent)

These mirror a recurring class: nonconsensual artificial sexual imagery. They regulate the creation or distribution of intimate “deepfake” content material and depend on courts or felony enforcement. The set off is a particular dangerous act, which locations them within the use bucket.

The widespread thread is easy. No matter one thinks of the coverage deserves, these measures lengthen conventional state police powers. They regulate conduct and harms—usually by way of disclosure duties, civil legal responsibility, or felony enforcement—and they don’t supervise how fashions are designed.

Mannequin-Layer Regulation: ‘Construct, Take a look at, and Govern the System This Approach’

Colorado SB 24-205 (high-risk AI programs, consequential-decision set off, algorithmic-discrimination duties)

It is a model-layer governance statute. It assigns ongoing duties to builders primarily based on a system’s foreseeable habits, although the duties are triggered when the system is utilized in consequential selections. The legislation requires threat administration, documentation, disclosure, and post-deployment monitoring tied to discrimination dangers inherent within the mannequin’s design and operation, with reporting obligations that may come up even with out person misconduct. In follow, it treats sure AI programs as regulated artifacts and capabilities as ex ante mannequin governance with out express scale or compute thresholds. (Enacted in 2024.)

New York S 6953 and S 8828 (frontier-model improvement, coaching, or deployment necessities)

These are model-layer measures as a result of the set off is just not a particular downstream unhealthy act resembling fraud or impersonation. As an alternative, they regulate “frontier fashions” and impose duties tied to improvement, coaching, deployment controls, and dangers of important hurt. The obligations connect to the system itself, reasonably than punishment for a specific misuse.

Rhode Island S 0358 (lined fashions, frontier-scale set off, model-caused harms to nonusers)

This invoice creates duties primarily based on whether or not an entity operates a “lined mannequin” and attributes legal responsibility to harms brought on by the mannequin’s operation, even when the injured celebration is just not a person. It isn’t merely “don’t use AI to do X.” It establishes a governance regime for a category of fashions outlined by scale.

Kentucky HB 314 (statewide coverage requirements for executive-branch use of high-risk or generative AI)

It is a boundary case however nonetheless suits the mannequin layer. Though restricted to the general public sector, it goes past procurement formalities. It units coverage requirements and procedures for companies utilizing generative or high-risk AI. We coded it as mannequin layer as a result of it governs how lined programs should be dealt with ex ante.

The widespread characteristic of model-layer measures is that they impose compliance-style duties—security protocols, governance necessities, threat requirements, and documentation—directed on the system itself. These obligations perform like mounted prices. For that motive, they increase distinct considerations about entry limitations and incumbent benefits, although they’re the minority class in our survey.

Stepping again, these examples additionally make clear why the federal-preemption debate usually talks previous itself. The use-layer payments resemble traditional workouts of state police energy. A federal framework that preempts model-layer obligations whereas preserving state authority over downstream harms wouldn’t battle with most state exercise in follow. That’s the reason the topline break up issues.

Why the Minority Nonetheless Looms Massive

Inside our pattern, 73% of payments regulate makes use of and about 27% regulate fashions.

Even taken at face worth, that break up issues for 2 causes.

First, the model-layer share is just not trivial. A minority class can nonetheless have massive financial results if it imposes excessive mounted prices, scales poorly for brand spanking new entrants, and fragments compliance throughout jurisdictions. Many model-layer payments do precisely that. They impose ex ante obligations resembling audits, threat assessments, documentation, and reporting—developer-facing course of necessities that should be happy earlier than or throughout operation of the system.

Second, the use-layer majority could also be much more necessary for the present preemption debate. Many of those measures goal acquainted harms: deception, fraud, impersonation, election manipulation, and associated conduct that states have lengthy regulated underneath their police powers. Use-layer guidelines are likely to function conditionally. They connect legal responsibility or penalties to dangerous deployment, reasonably than imposing broad, ongoing duties on mannequin improvement.

We additionally noticed an institutional sample value noting. A considerable share of the model-layer payments assigns enforcement to state attorneys basic.

That selection is comprehensible, but it surely reveals a possible mismatch. Generalist enforcement works nicely for conduct guidelines—prosecuting fraud or misleading practices after the actual fact. It’s much less clearly suited to supervising technical risk-management regimes that require ongoing analysis of compliance processes and one thing nearer to security engineering oversight.

Fastened Prices, Acquainted Penalties

Separating “fashions” from “makes use of” clarifies the place mounted prices come up.

Mannequin-layer obligations perform like compliance infrastructure. Even when framed as “cheap” practices, audit and reporting mandates usually are not costless. They require specialised employees, documentation programs, and authorized overview, and so they are likely to persist throughout product cycles. Massive incumbents can soak up these necessities as a part of a longtime compliance program. Smaller companies, startups, and open-source–adjoining builders usually can’t. For them, compliance can divert sources away from product enchancment and from security work that responds to real-world dangers.

Use-layer guidelines function in another way. They usually observe acquainted consumer-protection and fraud doctrines and may depend on established enforcement pathways. As a result of they connect on the level of dangerous deployment, they’re much less entangling for general-purpose mannequin improvement. One can debate how nicely any explicit invoice is drafted, however as regulatory instruments, use-layer guidelines are likely to scale with wrongdoing, reasonably than function as a gatekeeping price for market entry.

Because of this the one-quarter share nonetheless issues. The model-layer minority is the class almost certainly to entrench incumbents by way of mounted prices and compliance fragmentation.

On the similar time, the use-layer majority is the class almost certainly to outlive federal preemption in any federalism-respecting framework.

Preemption Is Not a Wipeout

The preemption debate is commonly framed as a struggle over whether or not states will lose the flexibility to manage AI-related harms. Our survey factors to a extra exact method to describe the problem.

If Congress or a federal company adopted a sweeping framework that displaced state legislation broadly—together with use-layer conduct guidelines—preemption can be disruptive and controversial for causes largely unrelated to “innovation coverage.” It could as an alternative implicate peculiar state police powers. Such a regime can be politically tough to maintain and, in lots of settings, legally susceptible. Additionally it is not what policymakers have usually proposed; current preemption discussions usually protect some room for state enforcement of conventional harms.

However that’s not the one attainable design. A federal framework might focus preemption on the mannequin layer, the place the danger of a fragmented 50-state compliance regime is most acute, whereas leaving most use-layer guidelines intact as long as they’re rigorously drafted and according to baseline constitutional limits.

That distinction has an ignored sensible implication. As a result of a considerable majority of the payments in our survey regulate makes use of, a model-focused preemption scheme would depart most state AI legal guidelines in place of their core operation.

That is the central level. A lot of the nervousness surrounding preemption assumes federal legislation would displace most state AI governance. Our descriptive map suggests the alternative: a narrowly tailor-made preemption framework might scale back model-layer patchwork strain whereas preserving the dominant type of state regulation already rising—use-layer policing of dangerous conduct.

It’s Not Who Regulates, It’s What Will get Regulated

Our coding train is just not an oracle. It’s a method to converse extra rigorously a couple of debate that has change into slogan-driven. The central discovering is easy: “state AI regulation” is just not primarily an effort to micromanage mannequin improvement. It’s largely an effort to manage makes use of.

That ought to change how policymakers, courts, and commentators method preemption.

The roughly one-quarter share of model-layer payments nonetheless issues. These measures are the almost certainly to impose mounted prices and to fragment compliance in ways in which favor incumbents.

The three-quarter share of use-layer payments factors the opposite manner. If federal lawmakers search nationwide coherence on the mannequin layer—and draft with peculiar federalism limits in thoughts—most state legal guidelines focusing on dangerous conduct ought to stay viable. The survey suggests fears of shedding state police energy over downstream makes use of are overstated, not less than as an outline of the place legislative vitality is concentrated.

The talk ought to subsequently flip to a concrete query: what, precisely, ought to federal legislation preempt? If the goal is to keep away from an innovation-chilling patchwork in mannequin governance with out stripping states of authority to police deception, fraud, and related harms, our descriptive map exhibits these targets are suitable.

The true divide in AI coverage is just not federal versus state. It’s mannequin versus use. As soon as that’s clear, the preemption debate stops trying like a zero-sum struggle and begins trying like an issue of regulatory focusing on.

You may also like

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Accept Read More