The State AI Law War: Anthropic, OpenAI, and the 50-State Patchwork Your Company Now Lives In
The two most important AI companies in America are both lobbying hard for state AI laws. They are just lobbying for opposite kinds. Once you see the two strategies clearly, the compliance conclusion writes itself: the patchwork is not a transition phase. It is the operating environment.
For two years the standard line in tech policy was that the state AI bills were a stopgap: messy, duplicative, and destined to be swept aside the moment Congress passed a federal AI framework. That line is now dead, and it was not killed by Congress. It was killed by the AI industry itself.
POLITICO reported this week on the dueling state-level strategies of Anthropic and OpenAI, and the piece is worth reading closely, because it describes two sophisticated actors spending real money, through lobbying and rival super PAC networks, to shape state AI law. Not to stop it. To shape it. When both leading labs treat state legislatures as the venue that matters, the venue that matters is state legislatures. I practice AI and technology law in California, and this piece is my read of what that means for the companies I actually advise: not the frontier labs, but the businesses building on top of them.
"Raise the bar" versus "reverse federalism"
The ratchet: each state raises the bar
- Endorsed California's SB 53 in 2025, the first frontier-AI transparency law, as the only major lab to do so.
- Then backed progressively stronger bills elsewhere: New York, the Illinois audit law, and now Massachusetts.
- In Massachusetts, supported bond-bill language that would require leading AI companies to engage independent evaluators of catastrophic risk, with attorney-general enforcement.
- The theory: successive states can each exceed the obligations of the one before, pulling the whole field upward.
"Reverse federalism": states converge on one standard
- The term comes from OpenAI's policy chief Chris Lehane: instead of Congress setting a national rule, aligned state laws mirror one another until a de facto national standard exists.
- Pressed New York's Governor Hochul to align New York's AI safety bill with California's model rather than exceed it.
- Joined Anthropic in backing the Illinois audit law, evidence that convergence and ratchet can point the same direction on specific bills.
- The theory: uniformity across states delivers the predictability of federal law without waiting for a Congress that has not delivered it.
Anthropic's state and local policy head, Cesar Fernandez, put the company's premise bluntly to POLITICO: "Transparency and self-reporting, we don't believe are sufficient anymore." Whatever you think of that premise, notice what it is not: it is not a call for federal preemption, and it is not a call for no regulation. Both companies have accepted that state law is where AI regulation is being written, and both are investing accordingly, including through dueling super PAC networks spending at a scale usually reserved for statewide races.
I am not here to score which company is right. Reasonable people at both firms are making rational bets from different market positions. My interest is the map they are drawing, because my clients have to live on it.
Illinois shows what the ratchet produces
The clearest artifact of this dynamic is Illinois. On July 6, 2026, Governor Pritzker signed SB 315, the Artificial Intelligence Safety Measures Act. California's SB 53 required frontier developers to publish safety frameworks and self-report incidents. New York went further. Illinois went further still, and became the first state to require annual independent third-party audits of the largest developers' safety plans, per Capitol News Illinois:
- Who: developers of the largest models, those above $500 million in annual revenue trained with massive compute.
- What: published frameworks for assessing "catastrophic risk," defined as incidents that could kill or seriously injure more than 50 people or cause over $1 million in property damage; annual independent third-party safety audits; incident reporting within 72 hours, or 24 hours for imminent risks.
- Teeth: attorney-general enforcement, up to $1 million for initial violations and $3 million for subsequent ones.
- When: requirements take effect January 1, 2028.
Both Anthropic and OpenAI backed it. And Massachusetts is now debating whether to go beyond even that, with the independent-evaluator bond-bill language Anthropic has endorsed. Self-reporting became third-party auditing in roughly ten months of state lawmaking. That is the ratchet working exactly as designed.
The patchwork is the plan, not the accident
Here is the strategic point I want every AI founder and general counsel to internalize. Under Anthropic's strategy, state AI law keeps escalating. Under OpenAI's strategy, state AI law converges but is thereby entrenched: fifty aligned statutes with fifty attorneys general are not a placeholder for federal law, they are a substitute for it. There is no version of either strategy in which state AI law recedes. The only fight is over its shape.
Three operational consequences follow:
1. Your compliance spec is set by the strictest state you cannot avoid
Most software companies cannot geofence state by state, so the strictest applicable state becomes the de facto product spec. Today that usually means California's stack, which I map law-by-law in my California AI Laws (2026) business guide, plus whichever specialty regime touches your vertical: Illinois and Nevada for anything therapy-adjacent, Illinois HB 3773 for HR tech, Texas TRAIGA's rules with its NIST-aligned safe harbor for general deployment.
2. Documentation compounds; panic does not
The regimes rhyme: disclose what the system is, document what it was trained on, keep a human accountable, write down your risk analysis, tell someone when things go wrong. A company that builds one honest governance file, an AI inventory, training-data documentation, risk assessments, disclosure copy, reuses it in every state and in the EU. This is why I keep steering clients toward the boring artifacts instead of jurisdiction-by-jurisdiction firefighting.
3. Enforcement style now varies more than substance
Texas is AG-only with a 60-day cure. Illinois' SB 315 is AG-enforced with seven-figure caps. California's SB 243 hands enforcement to private plaintiffs at $1,000 per violation plus fees. Identical conduct carries different risk temperatures in different states, and your exposure analysis should say so explicitly rather than treating "compliance" as one binary.
August 2 is the date to circle, and here is the next twelve months
While the lobbying war gets the headlines, the deadlines arrive on schedule. The nearest one is two weeks from this post: on August 2, 2026, California's SB 942 AI Transparency Act becomes operative for covered generative AI providers, and, the same day, Article 50 of the EU AI Act begins applying to systems serving EU users. One day, two continents, two disclosure regimes.
| Date | What happens | Who should care |
|---|---|---|
| Aug 2, 2026 | CA SB 942 operative: free AI-detection tool plus content disclosures for covered GenAI providers, $5,000 per violation per day. EU AI Act Article 50 applies: AI-interaction disclosure and machine-readable marking of synthetic content. | GenAI providers over 1M monthly users (CA); anyone with EU users |
| Dec 2, 2026 | EU grace period for Article 50 content-marking obligations ends. | Anyone generating synthetic media for EU users |
| Jan 1, 2027 | CA large-online-platform and GenAI-hosting duties begin (AB 853); CPPA ADMT consumer rights become operative; Colorado SB 26-189 compliance begins, replacing the repealed SB 24-205. | Platforms over 2M monthly users; ADMT users; anyone with Colorado consumers |
| Jul 1, 2027 | CA SB 243 companion-chatbot operators begin reporting to the Office of Suicide Prevention. | Chatbot operators with sustained human-like interaction |
| Looking ahead: Jan 1 and Apr 1, 2028 | Illinois SB 315 audit obligations take effect; first CPPA risk-assessment submissions come due, covering processing back to 2026. | Frontier developers; CCPA businesses with assessment duties |
The full statute-by-statute treatment, including who each law covers, the penalty structures, and a folded "does this apply to my product" screen, lives in my California AI Laws (2026): The Complete Business Guide. For the document stack itself, the AI Governance Hub covers policies, disclosures, and vendor terms, and my AI and data licensing practice covers the training-data contracts that sit underneath the disclosure laws.
Two weeks to August 2. Know which side of the definitions you are on.
The $575 Written Gap Audit is a written attorney answer to the boundary questions: which of these laws reach your product, what is missing, and in what order to fix it. Launching a new AI product? The $2,500 AI SaaS Launch Package builds the compliant document stack from the start.
Request the Written Gap Audit · $575 AI SaaS Launch Package · $2,500