Artificial Intelligence

How U.S. States Regulate Government Use of AI

September 03, 2026by Robert Cruz

Subscribe to the Smarsh Blog Digest

Subscribe to receive a monthly digest of articles exploring regulatory updates, news, trends and best practices in electronic communications capture and archiving.

Smarsh handles information you submit to Smarsh in accordance with its Privacy Policy. By clicking "submit", you consent to Smarsh processing your information and storing it in accordance with the Privacy Policy and agree to receive communications from Smarsh and its third-party partners regarding products and services that may be of interest to you. You may withdraw your consent at any time by emailing [email protected].

For compliance, risk, and IT leaders working in or with the public sector, understanding state requirements for government AI use and how well your program aligns is increasingly important. Smarsh’s review of executive branch guidance across all 50 states and Washington, DC, reveals shared expectations and important differences. The findings also extend beyond government, as human oversight, data protection, and risk assessment become benchmarks for regulated organizations. This analysis is for informational purposes only; consult legal counsel regarding applicable requirements.

Key takeaways

  • Most jurisdictions, 49 of 51, have issued agency AI guidance; only Florida and Wyoming have not.
  • A common core allows organizations to prepare across states without tracking 51 separate frameworks.
  • Shared expectations include human accountability, sensitive-data safeguards, tool approval, public disclosure, and use of the NIST AI Risk Management Framework.
  • Enforcement varies with nine jurisdictions specifying penalties, and fewer than half actively enforcing their guidance.
  • Agency-use rules and private-sector AI laws are separate — and confusing them can be costly

What state AI rules are and what they cover

When a state regulates government AI use, it refers to guidance issued to its own executive-branch agencies and employees on using AI to serve the public and perform day-to-day work. This guidance may take the form of an executive order, a policy or standard from the state CIO or IT office, an enacted statute, interim advisory guidance, or several of these measures layered together.

Several headline AI laws mainly regulate the private sector, not the state's own agencies. Some examples include:

  • Texas Responsible Artificial Intelligence Governance Act (TRAIGA)
  • Utah Artificial Intelligence Policy Act (UAIPA)
  • Colorado AI Act

Here is the current picture across the 50 states and the District of Columbia:

  • 40 or more of the 51 jurisdictions have a formal policy, a binding standard, or a statute in place
  • Of those, 12 are backed by an enacted statute and 17 are built on a governor's executive order
  • Only two states, Florida and Wyoming, have no known agency-facing guidance yet

Maturity varies: some states run detailed, operational programs today, while Missouri, Maryland, Rhode Island, and South Carolina have set up governance frameworks but not yet published the operational rules. Most states have decided that they will govern agency AI use but few have finished deciding exactly how.

State, Local, and Education

See how public sector organizations secure and manage communications data at scale.

State AI rules in practice

Read side by side, these policies share many common denominators. Despite different authors and different politics, the same building blocks appear again and again — the emerging baseline for responsible government AI use.

Human accountability

A person, not the model, owns consequential decisions. Policies bar fully autonomous AI from decisions affecting rights, benefits, or obligations. Kentucky prohibits "high-risk" systems outright; New York and New Hampshire disallow automated final decisions; Virginia bans un-explainable "black box" systems.

Data protection at the boundary

Do not put personal, health, confidential, or other non-public data into public, consumer-grade AI tools. Sensitive work is routed into approved, contractually protected enterprise environments instead.

Pre-approval and inventory

Tools must be vetted and approved before use, usually through procurement or IT intake, and many states keep a registry of approved tools and active use cases. Shadow AI oversight is a universal concern.

Public disclosure

More than two-thirds of jurisdictions address telling the public when AI is involved, flagging chatbots and labeling AI-generated content. DC, Kentucky, Virginia, Idaho, and Maine are the most explicit.

A shared risk method

Where states name an external standard, it is overwhelmingly the NIST AI Risk Management Framework, AI RMF 1.0, the closest thing to a common technical vocabulary across the country.

Additional themes

Rounding out the core: staff training (increasingly required before access), bias and accuracy review of outputs, vendor controls that stop suppliers training commercial models on state data, and treating AI prompts and outputs as public records subject to retention.

Tip

The Texas Responsible Artificial Intelligence Governance Act (TRAIGA) regulates private-sector use of AI, not state agencies. Treating a private-sector law like TRAIGA as an agency-use policy is one of the more common, and costly, mistakes we see. The two tracks need separate mapping.

Where states still diverge

The common core holds, but the details differ in ways that change how much weight the rules carry. Two dimensions capture most of the variation:

  • How mature a state's guidance is, ranging from no guidance to advisory, formal policy, and statute-backed rules
  • How severe a state’s enforcement is, ranging from none to a governance gate, active audits, and explicit or mandatory penalties

Binding force

Guidance ranges from mandatory to advisory. Some states back their rules with binding CIO standards or statutes, giving agencies a firm requirement to follow. Others frame their guidance as recommended rather than required — Michigan calls its approach guidelines, and Hawaii's is strongly recommended. About a dozen states have gone further, giving their rules the weight of an enacted statute.

Penalties

Only nine jurisdictions spell out explicit consequences. Oklahoma is strictest — federally protected data in an unapproved tool means mandatory termination — with Kentucky, Maine, Delaware, South Dakota, Wisconsin, Arkansas, Indiana, and Texas also stating consequences. Most specify none.

Tip

No penalties do not mean there are no consequences — most states still enforce through approval gates, access revocation, and standard HR discipline.

Enforcement

Fewer than half have active mechanisms. Virginia (a mandatory registry with tiered approval), Oklahoma (CIO gatekeeping plus audits), North Dakota (a non-compliance reporting channel), and Texas (AG enforcement) are at the active end; many delegate to agency leadership.

Approved-tool models

Some states name one enterprise tool for everyone: Colorado, Utah, and Arizona lean on Google Gemini; Pennsylvania and Oklahoma on ChatGPT Enterprise; several on Microsoft Copilot. Others assess each tool case by case. Prohibited-tool lists, often naming DeepSeek, are increasingly common.

Agentic AI

Most policies were written for generative AI and are silent on autonomous systems. Only about eight jurisdictions, including North Dakota, New Mexico, Texas, Oregon, and Idaho, address agentic AI explicitly.

Signs it's time to strengthen AI governance

You do not need a mandate in your state to know it is time to act. Common signs of a program that’s falling behind include:

  • Not being able to produce a current inventory of where AI is used across the agency — including AI features embedded in tools that are already deployed
  • Relying on staff judgment alone to keep sensitive data out of public AI tools, with no approved-tool list or enforced boundary
  • Letting AI-informed decisions affect people's rights or benefits without a documented human review step
  • Not being able to show the public when they're interacting with AI or reading AI-generated content
  • Having no defensible, recognized method — such as the NIST AI RMF — behind AI risk decisions

Federal Government

See how federal agencies stay compliant and in control of communications data.

Best practices for compliance officers

The patterns above point to concrete, defensible steps you can take now, without waiting for your jurisdiction's rules to finish maturing.

Assume you are in scope

With only two jurisdictions lacking guidance, plan as though formal expectations already apply — build now rather than reacting to a mandate later.

Anchor to the NIST AI RMF

NIST AI RMF is the common denominator across states. Adopting it aligns you with the most expectations at once and gives you a defensible method.

Inventory AI use cases

A current inventory — including embedded AI features — is table stakes. You cannot govern what you have not catalogued.

Enforce data classification at the tool boundary

Restrict sensitive, personal, or confidential data in public AI tools; route higher-risk work to approved enterprise environments.

Keep a human accountable for consequential decisions

Prohibit fully autonomous decisions affecting rights or benefits, require documented review, and be able to explain outcomes.

Disclose AI to the public

Label AI-generated content and flag chatbots. The trend is toward mandatory disclosure, so adopting it early can future-proof your program.

Govern procurement and vendors

Review tools before deployment and bar vendors from training commercial models on your data; maintain a prohibited-tools list.

Train before access, and log use

Require training as a condition of access and retain prompts and outputs — it also strengthens recordkeeping.

Track the consumer-protection laws too

Statutes like TRAIGA and the Colorado AI Act can reach you as a deployer, separate from agency-use policy. Financial services firms already navigating RIA communications compliance requirements should map both tracks closely.

Treat AI prompts and outputs as records

Many states consider them public records subject to retention; capture, retain, and be able to produce them.

What to do next

Responsible AI governance in the public sector is converging faster than the patchwork of instruments suggests. If you build to the common core — human accountability, data protection, transparency, inventory, and defensible risk assessment — you will be substantially aligned with most jurisdictions at once and ready to absorb the specifics as each state finishes its rules.

This is most useful for compliance, risk, and IT leaders in or serving the public sector and other regulated industries. A sensible first step is to inventory where AI is used today and measure it against the baseline above.

Govern AI use without slowing adoption

AI assistants such as Claude, ChatGPT Enterprise, and Microsoft Copilot can improve drafting, research, summarization, and content creation. For public-sector organizations, realizing those benefits also requires managing the resulting records, oversight, and governance obligations.

That starts with visibility. Agencies need access to AI prompts and outputs to document human review, assess how decisions were made, and respond to public-records requests. Without capture, those activities can create gaps in existing compliance programs.

You can extend the same communications governance you already apply to email, messaging, and collaboration tools to AI-assisted work. Smarsh Capture preserves prompts, responses, images, temporary chats, regenerated responses, and deleted or archived conversations, so that content is ready to retain, review, and produce alongside your other regulated communications.

The goal is practical governance that lets employees use AI productively while supporting oversight, retention, and defensibility.

Frequently asked questions

Share this post!

Robert Cruz
Smarsh Blog

Our internal subject matter experts and our network of external industry experts are featured with insights into the technology and industry trends that affect your electronic communications compliance initiatives. Sign up to benefit from their deep understanding, tips and best practices regarding how your company can manage compliance risk while unlocking the business value of your communications data.

Ready to enable compliant productivity?

Join the 6,500+ customers using Smarsh to drive their business forward.

Contact Us

Tell us about yourself, and we’ll be in touch right away.
Join our partner program

icon-angle icon-bars icon-times