Regulation3 min read

US AI Safety Rules Are Taking Shape, State by State

July 15, 2026Synthesized from 2 sources: WIRED, OpenAI

Three US states covering roughly 40% of the AI market have now passed aligned AI safety laws, creating a de facto national standard before Congress has acted, and that convergence is beginning to shape what a federal law may look like.

Three US states have quietly built something that Congress has not: a working set of rules for the most powerful AI systems. California passed its law in late 2025. New York followed shortly after. Illinois signed its version on July 6, 2026. Each law requires AI developers to publish a safety framework, report serious incidents to authorities, and open themselves to outside audits.

Illinois went furthest. It became the first state to require annual third-party audits of AI systems, meaning an outside reviewer, with no financial ties to the company, checks the work every year. California requires incident reports within 15 days; New York and Illinois tightened that to 72 hours. Companies that violate the Illinois law face fines up to one million dollars for a first offense and three million for each one after that.

The practical effect of these three laws combined is significant. Lawmakers estimate the three states account for roughly 40% of the US AI market. That share is large enough that any AI company operating at scale in America must treat these rules as national requirements, regardless of what Washington does.

That pressure is exactly the point. The strategy, which OpenAI's policy team calls "reverse federalism," is to build consensus from the states upward rather than wait for federal action that has not come. It is an unusual situation: a major AI company is publicly supporting state regulation of its own products, in part because it prefers a predictable set of consistent rules over 50 different state frameworks pulling in different directions.

Not everyone in the industry agrees. A coalition of tech executives argued during Illinois's debate that requiring private auditors to assess AI safety compliance before national standards even exist puts businesses in an unfair position. That tension is real. The auditing profession for AI safety barely exists yet, and the criteria auditors are supposed to use are still being defined.

At the federal level, President Trump signed an executive order on June 2, 2026, directing agencies to create a voluntary framework for AI companies to share powerful models with the government for up to 30 days before public release. The order is framed around cybersecurity and national security, not consumer protection or labor. Participation is voluntary, and the order explicitly prohibits the government from using it as a licensing or approval requirement. But legal analysts note that companies choosing not to participate may find it harder to win government contracts or be designated as trusted partners for early access to other companies' AI tools.

In Congress, Representatives Jay Obernolte and Lori Trahan released a bipartisan draft bill in June called the Great American AI Act. It mirrors the state laws in several ways: transparency requirements, incident reporting, and independent audits. But it includes a three-year freeze on state AI development laws, which has drawn opposition from consumer groups, child safety advocates, and some AI safety researchers who argue that freezing the most active source of AI accountability in exchange for federal rules that do not yet exist is a bad trade.

The global dimension adds another layer. OpenAI CEO Sam Altman published a proposal in the Financial Times calling for a US-led international forum to set AI safety standards, modeled loosely on the International Atomic Energy Agency. The idea: countries and companies that follow agreed standards get access to powerful AI tools; those that do not, do not. The proposal followed a G7 summit in France where AI executives met with world leaders. Google DeepMind's CEO published related ideas the same week.

For business operators outside the tech sector, the practical takeaway is this. If you use AI tools built by large developers, those developers are now subject to new transparency and incident-reporting rules in three major US states, with federal rules likely to follow in some form. That means you should eventually expect to be able to see a developer's published safety framework and ask questions about incidents their systems have been involved in. If you operate across multiple countries, the EU AI Act already imposes its own set of rules. The US rules being built now are less prescriptive than Europe's, but the gap is narrowing.

Stay informed

Get AI intelligence like this delivered to your inbox.