Laws that cover the same ground, set side by side. Every cell links back to the register entry it summarizes, so the comparison stays checkable against the primary source.
Four US instruments that regulate automated or algorithmic decisions about people. They differ on which decisions they reach, who must comply, and what the core duty is.
| California CPPA ADMT Regulations No. 5 | Colorado SB 26-189 (ADMT Act) No. 15 | Illinois HB 3773 No. 18 | NYC Local Law 144 (AEDT) No. 19 | |
|---|---|---|---|---|
| Citation | 11 CCR §§ 7001, 7150, 7200–7222 | SB 26-189, repealing SB 24-205 | HB 3773, Pub. Act 103-0804 | Local Law 144 of 2021; 6 RCNY § 5-300 |
| Jurisdiction | California, United States | Colorado, United States | Illinois, United States | New York City, United States |
| Standing | In force, phased | Enacted | In force | In force |
| Effective date | 1 Jan 2026 | 1 Jan 2027 | 1 Jan 2026 | 5 Jul 2023 |
| What it reaches | Use of automated decision-making technology for “significant decisions” about consumers, under the CCPA framework. | Automated decision-making that produces a consequential decision about a Colorado resident. | Predictive data analytics in employment; amends the Human Rights Act and the Consumer Fraud and Deceptive Business Practices Act. | Automated employment decision tools used to screen NYC job candidates or employees. |
| Core obligation | Point-of-collection notice, an opt-out toggle that honors Global Privacy Control, and a right to access the decision logic. | Disclosure to the affected person that an automated system was used in a consequential decision. | Bars discrimination through predictive analytics and reaches deceptive-practice claims; disclosure and anti-bias duties on employers. | An independent bias audit within the prior year, published results, and advance notice to candidates. |
| Enforcement note | Enforced by the California Privacy Protection Agency; obligations phase in on a schedule set in the rules. | Enforcement paused pending xAI v. Weiser. The Act repeals the earlier SB 24-205. | Enforced through the Illinois Human Rights Act mechanism. | Enforced by the NYC Department of Consumer and Worker Protection; civil penalties per violation. |
| Full entry | Open entry → | Open entry → | Open entry → | Open entry → |
Cells summarize each register entry as verified on its stated date. Where a cell would need detail an entry does not yet carry, it points to the full entry instead of guessing.
Four regimes aimed at the largest, most capable AI models. They converge on published safety frameworks and incident reporting, and differ on the threshold that pulls a model in and on how hard the obligation bites.
| California SB 53 (TFAIA) No. 17 | New York RAISE Act No. 23 | South Korea AI Basic Act No. 28 | Executive Order 14409 No. 2 | |
|---|---|---|---|---|
| Citation | SB 53, ch. 138, 2025 Cal. Stat. | Ch. 361, 2025 N.Y. Laws, as amended Mar. 2026 | Act No. 20676 | Exec. Order No. 14409 |
| Jurisdiction | California, United States | New York, United States | South Korea | United States |
| Standing | In force | Enacted | In force | In effect |
| Effective date | 1 Jan 2026 | 1 Jan 2027 | 22 Jan 2026 | 2 Jun 2026 |
| Covered models | Frontier developers above a large training-compute threshold. | Frontier models, on thresholds aligned to California SB 53. | “High-performance” AI, with a statutory threshold of 10^26 training FLOPs. | “Covered frontier models” as defined by the order. |
| Core obligation | Publish a frontier AI safety framework and report critical safety incidents. | Adopt and disclose a safety and security protocol; report incidents. Creates a dedicated NYDFS oversight office. | Risk management and transparency duties; large foreign providers above revenue or user thresholds must appoint a domestic representative. | A voluntary 30-day pre-release review window for covered models, plus a Treasury-led AI Cybersecurity Clearinghouse. |
| How hard it bites | Statute in force; civil penalties available to the California Attorney General. | Enacted, effective 1 January 2027; enforcement through the NY Attorney General and NYDFS. | In force with a one-year grace period on penalties; enforced by the Ministry of Science and ICT. | Executive order, voluntary. No direct penalty; drives federal coordination and procurement expectations. |
| Full entry | Open entry → | Open entry → | Open entry → | Open entry → |
Cells summarize each register entry as verified on its stated date. Where a cell would need detail an entry does not yet carry, it points to the full entry instead of guessing.
The four non-binding references the field treats as the baseline. Two are US government risk frameworks, one is a certifiable international management standard, one is an application-security checklist.
| NIST AI RMF 1.0 No. 3 | NIST AI 600-1 (Generative AI Profile) No. 4 | ISO/IEC 42001:2023 No. 29 | OWASP Top 10 for LLM Applications 2026 No. 11 | |
|---|---|---|---|---|
| Citation | NIST AI 100-1 | NIST AI 600-1 | AI management system, Ed. 1, 2023-12 | OWASP GenAI Security Project, Top 10 for LLM Applications 2026 |
| Jurisdiction | United States | United States | International | International |
| Standing | Voluntary | Voluntary | Published | Published |
| Effective date | 26 Jan 2023 | 26 Jul 2024 | 18 Dec 2023 | 4 Aug 2026 |
| Publisher | NIST (United States). | NIST (United States). | ISO and IEC (international). | OWASP (international, community project). |
| Scope | The full AI lifecycle, any AI system. | Generative AI specifically — a companion profile to the AI RMF. | An organization’s AI management system. | Security of applications built on large language models. |
| What it gives you | The Govern, Map, Measure, and Manage functions, plus a companion Playbook of suggested actions. | Twelve generative-AI risk vectors — confabulation, data privacy, supply-chain integrity and others — mapped to AI RMF actions. | Auditable requirements for setting up, running, and improving an AI management system. | The ten critical LLM-application risks, including prompt injection, improper output handling, and excessive agency. |
| Certifiable? | No. | No. | Yes — organizations can be certified against it. | No — it is a reference list, not a conformity scheme. |
| Full entry | Open entry → | Open entry → | Open entry → | Open entry → |
Cells summarize each register entry as verified on its stated date. Where a cell would need detail an entry does not yet carry, it points to the full entry instead of guessing.
Four rules governing what a generative or conversational AI system must tell the people it interacts with, and what it must reveal about how it was built.
| EU AI Act, Article 50 No. 8 | California AB 2013 (Training Data Transparency Act) No. 6 | China Interim Measures for Generative AI Services No. 25 | Colorado HB 26-1263 (Chatbot Safety Act) No. 16 | |
|---|---|---|---|---|
| Citation | Reg. (EU) 2024/1689, Art. 50 | Cal. Civ. Code § 3110 et seq. (AB 2013, Ch. 817, Stats. 2024) | Cyberspace Administration of China, 13 Jul 2023 | HB 26-1263 |
| Jurisdiction | European Union | California, United States | China | Colorado, United States |
| Standing | In force, phased | In force | In force | Enacted |
| Effective date | 2 Aug 2026 | 1 Jan 2026 | 15 Aug 2023 | 1 Jan 2027 |
| What it covers | Chatbots, generative and biometric systems whose outputs reach the EU. | Generative AI systems made available to Californians, for models trained since January 2022. | Public-facing generative AI services offered in mainland China. | Consumer-facing chatbots available to Colorado users, with added duties where minors may be involved. |
| Core disclosure duty | Tell users they are interacting with AI, label deepfakes, and mark synthetic content in a machine-readable way. | Publish a 12-point summary of the training datasets used, with no trade-secret exemption. | Label AI-generated content and register the service; content and training data must meet CAC content rules. | Disclose that the user is talking to AI, run age estimation, and follow self-harm response protocols. |
| Standing and reach | In force, phased; extraterritorial — applies wherever the output reaches an EU user. Fines up to €15M or 3% of global turnover. | In force since 1 January 2026; enforced by the California Attorney General. | In force since 15 August 2023; enforced by the Cyberspace Administration of China. | Enacted, effective 1 January 2027. |
| Full entry | Open entry → | Open entry → | Open entry → | Open entry → |
Cells summarize each register entry as verified on its stated date. Where a cell would need detail an entry does not yet carry, it points to the full entry instead of guessing.
A crosswalk is added when four or more laws in the register cover a shared subject and a reader would otherwise have to open every entry to compare them. The rows are fixed questions asked of every law. Each answer traces to one register entry and inherits that entry’s last-verified date.
Suggest an instrument or a crosswalk →