There is a real legal tension between the Trump administration’s push to override state AI laws and the growing stack of state legislation that passed or is about to pass. Builders are caught in the middle: the federal government says it wants to clear the field, but the field is still full.

This is the practical guide to what EO 14365 actually does, what has happened in the six months since it was signed, and what you need to do with state AI compliance right now.

The short answer: state AI laws still apply. Do not slow your compliance work waiting for federal preemption to materialize.


What the Executive Order Actually Says

EO 14365, titled “Ensuring a National Policy Framework for Artificial Intelligence,” was signed by President Trump on December 11, 2025. (Seyfarth Shaw analysis · Paul Hastings analysis)

The core theory is that fragmented state AI regulation threatens U.S. innovation and competitiveness. But the EO does not itself preempt state laws — it is not a self-executing preemption instrument. Instead, it directed three federal agencies to take specific actions by March 11, 2026:

Agency Directed Action Deadline
Commerce Evaluate “onerous” state AI laws; identify them March 11, 2026
FTC Issue policy statement classifying state-mandated bias mitigation as a deceptive practice March 11, 2026
DOJ Establish an AI Litigation Task Force to challenge state laws in federal court January 10, 2026

(Deadlines and directed actions per Baker Botts’ March 2026 federal deadlines analysis and the Butzel Long alert on the Commerce evaluation.)

Separately, on March 20, 2026, the White House released a National Policy Framework for Artificial Intelligence — a set of legislative recommendations to Congress calling for broad preemption of state AI laws. This is a Congressional ask, not a directive with legal force. (Holland & Knight analysis)

What the EO Explicitly Does NOT Preempt

This is important: EO 14365 expressly carves out several categories from preemption pressure (EO 14365 text):

  • State laws protecting children’s safety
  • State laws governing AI compute and data center infrastructure
  • State government AI procurement rules
  • Other areas to be determined

If your products are in these spaces, the EO’s preemption pressure does not apply to those specific compliance areas.


Six Months Later: What Has Actually Happened

Commerce Department Evaluation

Correction (as of this audit, July 28, 2026): the Commerce Department’s evaluation of “onerous” state laws — and the related BEAD-funding policy notice — missed the March 11, 2026 deadline rather than being quietly submitted and withheld. Secretary Howard Lutnick said as recently as late June 2026 that the guidance was still “a month or two away.” (TechPolicy.Press June 2026 US tech policy roundup) S&P Global has described the resulting situation for companies as “compliance limbo” given that the eventual evaluation could trigger BEAD broadband-funding consequences for named states. (S&P Global Market Intelligence)

What analysts expect: legal commentary has projected the eventual report will flag comprehensive state frameworks such as California’s and Colorado’s, and possibly Texas’s, as “onerous.” (Baker Botts, March 2026 federal deadlines analysis) No public source we found confirms or denies whether Illinois SB 315 or Connecticut’s AIRT Act would appear in the report — the report itself has not been released as of this audit.

FTC Policy Statement

Correction (as of this audit, July 28, 2026): contrary to what was originally reported here, the FTC did not publish its policy statement by the March 11, 2026 deadline. That deadline passed with no FTC action, and some observers concluded the agency had shelved the assignment. Nearly four months later, on July 1, 2026, the FTC released a proposed — not final — “Policy Statement Concerning the Suppression of Accuracy in Artificial Intelligence Systems,” published in the Federal Register on July 7, 2026, with a public comment period running through July 31, 2026. It is not yet finalized. (FTC press release)

The proposed statement articulates the theory that state laws compelling AI model output alteration for bias mitigation could constitute a “deceptive trade practice” under Section 5 of the FTC Act — because the altered outputs are less “truthful” to the underlying training data.

What this does NOT do: the FTC Act does not include an express preemption clause for state laws. The proposed statement’s own language is notably cautious, framing the theory as implied/obstacle preemption (“state law is impliedly preempted to the extent it conflicts with a federal regulatory scheme”) rather than declaring state laws preempted outright. Courts have not accepted this framing. Analysts at Tech Policy Press have noted the argument is weak in practice — companies can typically satisfy a state disclosure mandate through labeling without violating the FTC Act, which undercuts the conflict-preemption theory. (Tech Policy Press, “The FTC Statement on AI Bias Lacks Conviction”)

In practice: even once finalized, the FTC statement signals federal posture. It does not itself invalidate any state law.

DOJ AI Litigation Task Force

The DOJ’s AI Litigation Task Force launched January 9, 2026, within the EO’s 30-day window, via an internal memo from Attorney General Pam Bondi. (MLex · Baker Botts, “Inside the DOJ’s New AI Litigation Task Force”) It operates on three legal theories:

  • Dormant Commerce Clause — state law imposes undue burden on interstate commerce
  • Express or implied federal preemption
  • Equal Protection challenges

Colorado is the only state where the Task Force has acted. On April 24, 2026, the DOJ intervened — filing a companion complaint alongside xAI — in xAI’s federal lawsuit challenging Colorado’s original AI Act (SB24-205). (DOJ press release · Jenner & Block client alert) Three days later, Magistrate Judge Cyrus Y. Chung granted a stay of enforcement, with xAI’s preliminary injunction motion due within 28 days of Colorado adopting final rulemaking or replacement legislation — which, given Colorado’s SB 189 signing on May 14, 2026, set the deadline at June 11, 2026. (HR Dive · Norton Rose Fulbright)

No other state has seen DOJ intervention as of June 1, 2026. Update: as of this audit (July 28, 2026), we could not find a public report of the outcome of xAI’s June 11 preliminary-injunction filing or of any DOJ action against a second state — the docket had not surfaced in coverage available to us. Builders should treat that filing and any ruling on it as an open item to watch, not as resolved.


The Current State Law Map

Here is where each major state AI law stands as of June 1, 2026:

New York RAISE Act

Status: Signed and in force, operative date January 1, 2027.

Governor Hochul signed the RAISE Act on December 19, 2025. (TechCrunch · Governor Hochul’s press release) The law is in effect but operative requirements (for frontier model developers: safety frameworks, incident reporting, model evaluations) do not apply until January 1, 2027. Chapter amendments to align the timeline more closely with California’s approach are pending in committee. No federal challenge has been filed against the RAISE Act. Full builder coverage: New York RAISE Act Frontier AI Compliance Builder Guide.

Illinois SB 315 (Artificial Intelligence Safety Measures Act)

Status at original publication (June 1, 2026): passed legislature 110-0, pending Governor Pritzker’s signature. Update as of this audit (July 28, 2026): Pritzker has since signed it.

SB 315 passed the Illinois House unanimously (110-0) on May 27, 2026, after the Senate approved it May 21. (Capitol News Illinois) Governor Pritzker signed SB 315 into law on July 6, 2026 (Governor Pritzker’s press release), making Illinois the third state (after California and New York) to set frontier-model safety standards. It takes effect January 1, 2027. SB 315 is the first U.S. law mandating third-party safety audits of frontier AI models — requiring large AI developers to create safety frameworks, conduct catastrophic-risk assessments, and submit to independent third-party evaluations. Full compliance guide: Illinois SB 315 AI Safety Audit Compliance.

Connecticut AIRT Act

Status: Signed May 27, 2026. Initial provisions effective October 1, 2026.

Governor Lamont signed SB 5 on May 27, 2026 (most legal-industry trackers cite this date; a small number cite May 29). (Holland & Knight · Morrison Foerster) It creates five separate regulatory regimes — employment AI (automated employment decision technology), AI companions, synthetic content watermarking, frontier model whistleblower requirements, and social media recommenders — with staggered deadlines from October 2026 through January 2028. The automated-employment-decision-technology provisions “take effect” October 1, 2026 (the anti-discrimination amendment applies from that date), though the deployer notice obligations under that same regime are phased in later, October 1, 2027. (Future of Privacy Forum, “SB 5 in Five”) Full breakdown: Connecticut AIRT Act: Five Separate AI Regulations in One Law.

Colorado AI Act (SB24-205 → SB 189)

Status: Original law stayed by federal court; replaced by SB 189 signed May 14, 2026. SB 189 effective January 1, 2027. Both laws face ongoing legal challenge.

The original Colorado AI Act (SB24-205) was slated to take effect June 30, 2026, but:

  1. A federal court stayed enforcement on April 27 pending xAI’s injunction motion (HR Dive)
  2. Governor Polis signed SB 189 on May 14, which repeals and replaces SB24-205 with a narrower, notice-based transparency framework governing “automated decision-making technology” (ADMT) — effective January 1, 2027 (Wilson Sonsini · Davis Wright Tremaine)

xAI and potentially the DOJ are expected to challenge SB 189 as well. As of June 1, SB24-205’s original June 30 effective date is moot — it has been replaced. SB 189 goes into effect January 1, 2027, unless a court enjoins it before then.

New York A3411B (GenAI Warning Labels)

Status: Passed legislature, delivered to Governor Hochul. Not yet signed.

A3411B passed the NY Senate 58 Ayes–2 Nays on March 9, 2026 and awaits delivery to and signature by Hochul. (NY Senate bill text/status) It requires generative AI operators to display a “clear and conspicuous” notice that AI outputs may be inaccurate. Penalty: up to $1,000 per user who did not receive the notice (each user = a separate violation), per the bill text. The bill states it takes effect on “the ninetieth day after it shall have become a law.” As of this audit (July 28, 2026), the most recent reporting we found (late June 2026) still shows the bill pending with Hochul, with no signature, veto, or public timeline announced.


What Builders Should Do Now

Six months into the EO, legal consensus is clear: federal preemption actions to date do not nullify state AI laws. Every major law firm analysis on this question reaches the same conclusion.

1. Continue state law compliance work. Do not pause for preemption.

The EO directs agencies to take actions that may eventually produce judicial invalidation of specific laws. That process involves litigation, preliminary injunctions, appeals, and potentially years of proceedings. Colorado’s enforcement stay affects only that specific law in that specific case. You cannot rely on the Colorado stay to excuse non-compliance with Connecticut or New York requirements.

2. Track the Commerce Department report.

When the Commerce evaluation eventually becomes public, it will reveal which state laws the administration considers “onerous” — and therefore which states face BEAD broadband funding threats. That political lever could cause some states to amend laws preemptively. If the states relevant to your product are named, compliance timelines may shift. If they are not named, expect no federal relief.

3. Understand the EO’s carve-outs for your vertical.

If your products are focused on children’s safety, AI compute infrastructure, or government AI procurement, the EO expressly preserves state law authority in those areas. Your compliance obligation is unchanged and has no federal preemption cover.

4. Build for multiple regulatory scenarios.

Good compliance architecture accommodates: (a) state laws remaining fully enforceable, (b) specific laws being enjoined pending litigation, and (c) eventual federal legislation creating a uniform standard. The builders who are struggling are those who built for one scenario only. Design your compliance program to be adjustable.

5. The DOJ task force moves slowly.

The Task Force launched in January 2026. As of June 1, it has acted against one state. Even from referral to preliminary injunction can take many months; a final court ruling takes years. State laws are enforceable until a court says otherwise. Do not conflate federal policy posture with legal reality.


What to Watch

  • xAI’s Colorado preliminary injunction motion — due within 28 days of Colorado’s May 14 SB 189 signing (i.e., around June 11, 2026). Update: as of this audit (July 28, 2026), we could not confirm publicly whether the motion was filed or ruled on — treat the outcome as still open.
  • Commerce Department reportUpdate: the March 11, 2026 deadline was missed; as of late June 2026, Secretary Lutnick said the BEAD guidance was still “a month or two away.” Watch for public release, since it would name states facing BEAD funding threats.
  • NY A3411BUpdate: still pending with Hochul as of the most recent reporting available at this audit (late June 2026); no signature, veto, or public timeline yet. She has ten months to act after the legislature adjourns. Watch for press statements or a chapter amendment process.
  • Illinois SB 315Update: Pritzker signed SB 315 on July 6, 2026. The January 1, 2027 effective-date clock is now running.
  • Federal legislation — The March 20 National Policy Framework is a Congressional ask. If Congress moves on it (unlikely in 2026 given the Senate calendar), that would be the most consequential preemption development.

The federal-state AI regulatory collision is real, but the collision is slow. The practical reality for builders in 2026 is that state law compliance is required, federal preemption is a process not a fact, and the uncertainty favors building compliance programs that are flexible rather than programs that bet on one outcome.