Home › AI Governance Insights › When Federal and State AI Law Collide
When Federal and State AI Law Collide
By Stephan Paul Pochet, Co-founder and VP of Operations, GRC Careers · September 24, 2026 · 7 min read min read
Corporate America is facing a perfect storm of regulatory flux that is testing the limits of its governance, risk and compliance functions. The acceleration of AI has collided with a fragmented and often contradictory regulatory landscape. The question for the C-suite is no longer whether they will be affected, but whether their GRC teams are staffed to navigate the surge without capsizing.
The patchwork at home
The regulatory pendulum in the United States is swinging hard, and it is swinging in two directions at once.
On 11 December 2025 the President signed Executive Order 14365, "Ensuring a National Policy Framework for Artificial Intelligence". It directed the Attorney General to stand up an AI Litigation Task Force within thirty days, with a single job: to challenge state AI laws deemed inconsistent with federal policy. The principal legal theory is the Dormant Commerce Clause, the argument that a state law places an undue burden on interstate commerce.
The order also reaches for the purse. It directed the Secretary of Commerce to identify "onerous" state AI laws and to issue a policy notice making states with such laws ineligible for non-deployment funds under the $42 billion Broadband Equity, Access and Deployment program.
The states did not retreat. On 25 November 2025 a bipartisan coalition of 36 state attorneys general wrote to Congress opposing any federal ban on state AI regulation, after House leadership signaled it might attach preemption language to the National Defense Authorization Act. The signatories spanned the political spectrum, from California and New York to Idaho, Louisiana, Mississippi and Tennessee.
That provision was not included in the final law. The preemption fight moved from the legislature to the courts, which is where it now sits.
This leaves a genuine compliance paradox. Should an organization invest in complying with state requirements that may later be invalidated, or accept the risk of non-compliance with rules that are enforceable today? There is no clean answer, and pretending otherwise is how teams get caught.
The same pattern, beyond AI
The federal-state friction is not confined to artificial intelligence.
The SEC's climate disclosure rules, once a centerpiece of federal ESG policy, effectively ended when the Commission voted in March 2025 to stop defending them in litigation. Firms that had already built reporting capability were left holding a control with no requirement attached to it.
Meanwhile the outbound investment rules that took effect on 2 January 2025, sometimes called reverse CFIUS, restrict certain US investments into Chinese entities in semiconductors, quantum and artificial intelligence. New obligations arrived in the same window that others disappeared.
The pattern matters more than any individual rule. Compliance strategies built on a single stable federal standard are no longer viable, because the standard no longer sits still.
The transatlantic chasm
Across the Atlantic the architecture could not be more different. The EU AI Act, Regulation (EU) 2024/1689, entered into force in August 2024 as the world's first comprehensive binding framework for artificial intelligence. It is harmonized where the American landscape is fragmented, and risk-based where the American approach is sectoral.
The Act sorts systems into tiers: unacceptable risk, which is prohibited; high risk, which carries conformity assessment, technical documentation, logging, human oversight and post-market monitoring; limited risk, which carries transparency duties; and minimal risk, which is largely untouched.
For a multinational the consequence is uncomfortable. Europe tells you what to build and gives you a deadline. The United States tells you it depends where you operate, and the answer may change after you have built it.
What this means for GRC teams
Three practical consequences follow, and all three are staffing questions before they are policy questions.
Regulatory change management stops being an annual exercise. If federal and state positions can diverge inside a single quarter, a compliance calendar reviewed once a year is a document that describes the past. Someone has to own horizon scanning as a named responsibility rather than as something the team does when there is time.
Jurisdictional mapping becomes a control. An organization that cannot say which of its AI systems are deployed in which states, serving which populations, cannot answer a state enquiry and cannot assess exposure when a rule is struck down or revived. This is inventory work, and it is the same discipline the EU AI Act already requires.
The most defensible posture is the strictest applicable standard. Teams that build to the EU AI Act generally satisfy the state regimes underneath it. Building to the loosest standard and hoping the preemption fight resolves in your favor is a bet on litigation, made by people who do not control the litigation.
The open question
Is the change division adequately staffed? For most organizations the honest answer is no, and the gap is not headcount alone. It is that regulatory change management, AI inventory and jurisdictional mapping are now three distinct skills that used to be one job.
That is why these roles keep appearing in postings under different titles in different departments. The work arrived faster than the vocabulary did.
Frequently Asked Questions
Who's Hiring AI Governance Professionals?
Explore current openings in:
AI Governance Jobs · Responsible AI · AI Risk · AI Compliance · AI Audit · AI Policy · Privacy · Cybersecurity · Public Policy
Search the latest opportunities at GRC Careers › · nonprofit GRC jobs ›