AI law · News analysis

The State AI Law War: Anthropic, OpenAI, and the 50-State Patchwork Your Company Now Lives In

The two most important AI companies in America are both lobbying hard for state AI laws. They are just lobbying for opposite kinds. Once you see the two strategies clearly, the compliance conclusion writes itself: the patchwork is not a transition phase. It is the operating environment.

Published July 19, 2026 · By Sergei Tokmakov, Esq., CA Bar #279869

For two years the standard line in tech policy was that the state AI bills were a stopgap: messy, duplicative, and destined to be swept aside the moment Congress passed a federal AI framework. That line is now dead, and it was not killed by Congress. It was killed by the AI industry itself.

POLITICO reported this week on the dueling state-level strategies of Anthropic and OpenAI, and the piece is worth reading closely, because it describes two sophisticated actors spending real money, through lobbying and rival super PAC networks, to shape state AI law. Not to stop it. To shape it. When both leading labs treat state legislatures as the venue that matters, the venue that matters is state legislatures. I practice AI and technology law in California, and this piece is my read of what that means for the companies I actually advise: not the frontier labs, but the businesses building on top of them.

The two strategies

"Raise the bar" versus "reverse federalism"

Anthropic's play

The ratchet: each state raises the bar

  • Endorsed California's SB 53 in 2025, the first frontier-AI transparency law, as the only major lab to do so.
  • Then backed progressively stronger bills elsewhere: New York, the Illinois audit law, and now Massachusetts.
  • In Massachusetts, supported bond-bill language that would require leading AI companies to engage independent evaluators of catastrophic risk, with attorney-general enforcement.
  • The theory: successive states can each exceed the obligations of the one before, pulling the whole field upward.
OpenAI's play

"Reverse federalism": states converge on one standard

  • The term comes from OpenAI's policy chief Chris Lehane: instead of Congress setting a national rule, aligned state laws mirror one another until a de facto national standard exists.
  • Pressed New York's Governor Hochul to align New York's AI safety bill with California's model rather than exceed it.
  • Joined Anthropic in backing the Illinois audit law, evidence that convergence and ratchet can point the same direction on specific bills.
  • The theory: uniformity across states delivers the predictability of federal law without waiting for a Congress that has not delivered it.

Anthropic's state and local policy head, Cesar Fernandez, put the company's premise bluntly to POLITICO: "Transparency and self-reporting, we don't believe are sufficient anymore." Whatever you think of that premise, notice what it is not: it is not a call for federal preemption, and it is not a call for no regulation. Both companies have accepted that state law is where AI regulation is being written, and both are investing accordingly, including through dueling super PAC networks spending at a scale usually reserved for statewide races.

I am not here to score which company is right. Reasonable people at both firms are making rational bets from different market positions. My interest is the map they are drawing, because my clients have to live on it.

What just got built

Illinois shows what the ratchet produces

The clearest artifact of this dynamic is Illinois. On July 6, 2026, Governor Pritzker signed SB 315, the Artificial Intelligence Safety Measures Act. California's SB 53 required frontier developers to publish safety frameworks and self-report incidents. New York went further. Illinois went further still, and became the first state to require annual independent third-party audits of the largest developers' safety plans, per Capitol News Illinois:

  • Who: developers of the largest models, those above $500 million in annual revenue trained with massive compute.
  • What: published frameworks for assessing "catastrophic risk," defined as incidents that could kill or seriously injure more than 50 people or cause over $1 million in property damage; annual independent third-party safety audits; incident reporting within 72 hours, or 24 hours for imminent risks.
  • Teeth: attorney-general enforcement, up to $1 million for initial violations and $3 million for subsequent ones.
  • When: requirements take effect January 1, 2028.

Both Anthropic and OpenAI backed it. And Massachusetts is now debating whether to go beyond even that, with the independent-evaluator bond-bill language Anthropic has endorsed. Self-reporting became third-party auditing in roughly ten months of state lawmaking. That is the ratchet working exactly as designed.

Why this matters even if you are not a frontier lab. Almost none of my clients will ever be audited under SB 315. But state legislatures reuse definitions, and enterprise buyers reuse expectations. "Published risk framework, independent verification, incident reporting on a clock" is migrating from frontier-lab statute to enterprise vendor questionnaire faster than most founders expect. The compliance architecture being built for the labs becomes the diligence template applied to you.
The practical read

The patchwork is the plan, not the accident

Here is the strategic point I want every AI founder and general counsel to internalize. Under Anthropic's strategy, state AI law keeps escalating. Under OpenAI's strategy, state AI law converges but is thereby entrenched: fifty aligned statutes with fifty attorneys general are not a placeholder for federal law, they are a substitute for it. There is no version of either strategy in which state AI law recedes. The only fight is over its shape.

Three operational consequences follow:

1. Your compliance spec is set by the strictest state you cannot avoid

Most software companies cannot geofence state by state, so the strictest applicable state becomes the de facto product spec. Today that usually means California's stack, which I map law-by-law in my California AI Laws (2026) business guide, plus whichever specialty regime touches your vertical: Illinois and Nevada for anything therapy-adjacent, Illinois HB 3773 for HR tech, Texas TRAIGA's rules with its NIST-aligned safe harbor for general deployment.

2. Documentation compounds; panic does not

The regimes rhyme: disclose what the system is, document what it was trained on, keep a human accountable, write down your risk analysis, tell someone when things go wrong. A company that builds one honest governance file, an AI inventory, training-data documentation, risk assessments, disclosure copy, reuses it in every state and in the EU. This is why I keep steering clients toward the boring artifacts instead of jurisdiction-by-jurisdiction firefighting.

3. Enforcement style now varies more than substance

Texas is AG-only with a 60-day cure. Illinois' SB 315 is AG-enforced with seven-figure caps. California's SB 243 hands enforcement to private plaintiffs at $1,000 per violation plus fees. Identical conduct carries different risk temperatures in different states, and your exposure analysis should say so explicitly rather than treating "compliance" as one binary.

The calendar

August 2 is the date to circle, and here is the next twelve months

While the lobbying war gets the headlines, the deadlines arrive on schedule. The nearest one is two weeks from this post: on August 2, 2026, California's SB 942 AI Transparency Act becomes operative for covered generative AI providers, and, the same day, Article 50 of the EU AI Act begins applying to systems serving EU users. One day, two continents, two disclosure regimes.

DateWhat happensWho should care
Aug 2, 2026CA SB 942 operative: free AI-detection tool plus content disclosures for covered GenAI providers, $5,000 per violation per day. EU AI Act Article 50 applies: AI-interaction disclosure and machine-readable marking of synthetic content.GenAI providers over 1M monthly users (CA); anyone with EU users
Dec 2, 2026EU grace period for Article 50 content-marking obligations ends.Anyone generating synthetic media for EU users
Jan 1, 2027CA large-online-platform and GenAI-hosting duties begin (AB 853); CPPA ADMT consumer rights become operative; Colorado SB 26-189 compliance begins, replacing the repealed SB 24-205.Platforms over 2M monthly users; ADMT users; anyone with Colorado consumers
Jul 1, 2027CA SB 243 companion-chatbot operators begin reporting to the Office of Suicide Prevention.Chatbot operators with sustained human-like interaction
Looking ahead: Jan 1 and Apr 1, 2028Illinois SB 315 audit obligations take effect; first CPPA risk-assessment submissions come due, covering processing back to 2026.Frontier developers; CCPA businesses with assessment duties
A note on Colorado. If your compliance materials still cite Colorado SB 24-205 and its impact-assessment regime as current law, they are wrong: it never took effect and was repealed and reenacted in May 2026 as the narrower SB 26-189. I keep finding the dead citation in vendor questionnaires and DPA exhibits. Purge it.

The full statute-by-statute treatment, including who each law covers, the penalty structures, and a folded "does this apply to my product" screen, lives in my California AI Laws (2026): The Complete Business Guide. For the document stack itself, the AI Governance Hub covers policies, disclosures, and vendor terms, and my AI and data licensing practice covers the training-data contracts that sit underneath the disclosure laws.

Two weeks to August 2. Know which side of the definitions you are on.

The $575 Written Gap Audit is a written attorney answer to the boundary questions: which of these laws reach your product, what is missing, and in what order to fix it. Launching a new AI product? The $2,500 AI SaaS Launch Package builds the compliant document stack from the start.

Request the Written Gap Audit · $575 AI SaaS Launch Package · $2,500
Reviewing documents you already have? The $1,500 AI SaaS Document Review. One narrow question? The $240 Written Attorney Consultation.
Related
This article is general information and commentary on legal and policy developments as of July 19, 2026, not legal advice, and it does not create an attorney-client relationship. Reporting on company lobbying strategies is attributed to POLITICO and other linked sources; statutory descriptions link to official texts where available, and pending bills (including the Massachusetts proposal) can change or die before enactment. For advice on your product, consult a licensed attorney. Attorney content by Sergei Tokmakov, Esq., California Bar No. 279869.
Written by Sergei Tokmakov, Esq., CA Bar #279869, a California attorney advising AI and SaaS companies on contracts, compliance, and governance.