AI Regulation in the US: A UK Business Guide to the 2026 Patchwork

Federal voluntary executive order vs. mandatory state laws: what it means for UK companies selling into the US in 2026.

by Cleverson Gouvêa

AI Regulation in the US: A UK Business Guide to the 2026 Patchwork

AI regulation in the United States is no longer a distant talking point — it is an operational problem for anyone selling across the Atlantic. By June 2026, the federal government had opted for voluntary rules while individual states created binding and divergent obligations. For a UK company processing data from American users, this changes everything. Let me explain what happened and what you need to do about it.

TL;DR

  • On 02/06/2026 the White House issued the executive order "Promoting Advanced Artificial Intelligence Innovation and Security", focusing on cybersecurity and voluntary frameworks for frontier models.
  • The states went in the opposite direction: they created binding obligations. California (SB 53) has been in force since January 2026; Colorado (SB 26-189) comes into effect on 01/01/2027.
  • The result is a patchwork: there is no single "US rule" — it depends on the state.
  • A UK company (SaaS, agency, e-commerce) that sells or processes data in the US needs to map obligations state by state, not country by country.
  • Those who get organised now can turn compliance into a commercial advantage, not a dead cost.

What the June 2026 Executive Order actually says

On 2 June 2026, the White House published the executive order titled Promoting Advanced Artificial Intelligence Innovation and Security. Its stated aim is straightforward: advance US leadership in artificial intelligence while addressing the national security risks of increasingly capable systems.

The order works on two fronts. The first is defensive: strengthening the cyber defences of government and private industry against so-called "advanced AI". The second is governance: developing voluntary benchmarking and review frameworks for the safe development and deployment of "frontier" models — those trained with massive computing power.

Note the key word: voluntary. The federal bet is on innovation first, with rules that companies adopt by choice, not by compulsion. There are no fines for non-compliance with benchmarks in this order. It is a signpost, not a straitjacket.

For product developers, that sounds like a relief. And it is — at the federal level. The problem appears when you look one level down, at the states.

The paradox: federal voluntary, state mandatory

The US system is federal. Each state legislates on a range of topics, and AI has joined that list. While Washington talks about voluntary adherence, state capitals are writing laws with effective dates, documentation duties and penalties.

This is the central tension of 2026. On one side, the federal government wants to avoid hindering the technology race. On the other, states want to protect consumers and hold those who use AI in sensitive decisions accountable. Both movements happen simultaneously, and they do not talk to each other.

The practical effect is fragmentation — what lawyers call a "patchwork". A company operating in five states may face five different sets of rules, with different deadlines and different definitions of what constitutes a "high-risk AI system".

We have seen this film before in data privacy, when each state began creating its own law after California. With AI, the script is repeating — and faster.

California: SB 53 and transparency for frontier models

California, as usual, led the way. The Transparency in Frontier AI Act (SB 53) brings multiple obligations that came into force in January 2026.

The law targets developers of large frontier models. It is not about someone using a chatbot on a website — it is about those who train and deploy the largest models. For these actors, SB 53 requires three concrete things:

  1. Publish risk frameworks — document how the company assesses and mitigates model risks, publicly.
  2. Report security incidents — communicate failures and critical security events related to the system.
  3. Implement whistleblower protections — ensure channels and safeguards for employees who report internal risks.

Who actually needs to worry

If you are a UK agency or SaaS consuming the API of a frontier model, the direct weight of SB 53 falls on the model provider, not on you. But there is a cascade effect: providers will pass documentation and transparency requirements down contractually. It is worth reading the terms carefully. The logic is the same as I discussed in AI Agents: What Gemini Spark Changes for Businesses — responsibility flows down the chain.

Colorado: from umbrella to scalpel (SB 26-189)

Colorado took an interesting path. In May 2026, the state repealed and replaced its previous AI law with SB 26-189. A broad regulation went out; a narrower, more surgical statute came in.

The new law regulates a specific target: automated decision-making technology (ADMT) that materially influences consequential decisions. Think credit, employment, housing, insurance — situations where an algorithm helps decide someone's life. It comes into effect on 01/01/2027.

The shift in philosophy is the interesting point. The old version relied on risk management programmes and impact assessments — lots of preventive bureaucracy. SB 26-189 replaces that with more tangible, consumer-centred duties:

  • Advance notice to the consumer that a consequential decision uses ADMT.
  • Explanation of adverse outcome within 30 days when the decision is unfavourable.
  • Right to meaningful human review — a person, not just another algorithm, re-examining the case.
  • Developer documentation duties for the technology.

For a UK company selling HR software, credit scoring or insurance underwriting in the US, this is the kind of law that directly affects the product. "Explain adverse outcome within 30 days" is not a footnote clause — it is UX flow, logging, support process.

Comparison table: federal vs. California vs. Colorado

I have put the three layers side by side to make the patchwork visible:

Layer Nature What it requires Primary target Effective date
Federal (Executive Order 02/06/2026) Voluntary Benchmarking and review frameworks; cybersecurity reinforcement Frontier models; government and industry Immediate (non-binding)
California (SB 53) Mandatory Publish risk framework, report incidents, protect whistleblowers Developers of large frontier models January 2026
Colorado (SB 26-189) Mandatory Advance notice, explanation of adverse outcome within 30 days, human review, documentation ADMT in consequential decisions 01/01/2027

The table is deliberately uncomfortable. Three jurisdictions, three natures, three deadlines. And that is just two states plus the federal level — there are dozens of state legislatures working on the topic.

Why "the US rule" does not exist (and what that costs)

The most common mistake I see in conversations with clients is asking "what is the US AI law?" The question has no single answer. There is a voluntary federal guidance and there are mandatory state laws that diverge from each other.

This has a cost. Each new state in your user base can mean:

  • Reviewing notices and consent screens.
  • Adjusting response deadlines (the 30-day one in Colorado, for example).
  • Reorganising technical documentation for audit.
  • Training support to handle human review requests.

Compliance costs grow non-linearly. It is not "one more country" — it is "one more legislature". Large companies absorb this with legal teams. Small and medium-sized ones feel it more, because each requirement becomes engineering and process work.

Remember that this does not happen in a vacuum. The technology job market is also being reshaped by AI — I wrote about the corporate side of this pressure in Atlassian in 2026: Layoffs, AI and the Bet on Agents. Regulation and team restructuring go hand in hand.

What changes for UK companies selling into the US

Let me be concrete, because that is how I think when advising clients who invoice outside the UK. Three profiles feel the impact differently.

SaaS

If your software makes or supports consequential decisions — credit, hiring, risk pricing — Colorado is your wake-up call. Start designing the advance notice and adverse outcome explanation flow now. Building it before the 2027 deadline is cheap; building it in a rush afterwards is expensive.

Agency

Agencies that deliver automation and AI to US clients become intermediaries in the chain of responsibility. Your contracts need to make clear who documents what. A vague clause today becomes a dispute tomorrow.

E-commerce

E-commerce using AI for recommendation, fraud prevention or dynamic pricing should map whether those decisions are "consequential" under state laws. Product recommendation rarely is; denying a transaction or adjusting price in a discriminatory way may be.

The common denominator is one: stop thinking of the "US market" as a single block. Think state by state, function by function. The platform developments I commented on in Google I/O 2026: What Changes for UK Businesses only increase this surface — more embedded AI means more points subject to state rules.

Practical compliance checklist

At Agathas Web, when I assess a client's regulatory exposure, I follow a lean roadmap. Adapt it to your case:

  1. Map where your users are. Not the country — the state. Geolocation and billing data already tell you a lot.
  2. Classify your automated decisions. Which are just convenience and which materially affect someone's life?
  3. List your model providers. If you use a frontier model via API, read the terms through the lens of SB 53.
  4. Implement an audit trail. Log which model decided what, when and on what basis. This serves almost every state law.
  5. Design the human review flow. A person must be able to re-examine and reverse adverse decisions.
  6. Standardise consumer notices. Clear text that AI is involved in the decision, ready to be triggered by state.
  7. Review contracts. Distribute documentation responsibilities along the chain, in writing.

You do not need to do everything next week. You need to have the map and prioritise by what has the nearest deadline — in this case, the 2027 effective date in Colorado and what is already in force in California.

Conclusion: how to prepare without stalling the product

AI regulation in the United States in 2026 is a patchwork, and it will stay that way for a while. The federal level points direction with voluntary rules; the states impose concrete duties with real deadlines. Anyone selling there needs to think state by state and function by function, not country by country.

The good news is that well-done compliance does not stall the product — it becomes a selling point. Corporate US clients value a supplier that already has an audit trail, consumer notice and human review in place. That is trust, and trust closes deals.

If you want to understand how this exposure applies to your specific product, that is exactly the kind of diagnosis I do day to day. Start with the checklist above — and if you get stuck, talk to us. Mapping early costs little; chasing after the deadline costs a lot.