by Martin Medeiros, Buckley Law, P.C.
A striking pattern has emerged from the first generation of state artificial intelligence legislation: a remarkably large share of it never operated as intended. Statutes have been struck down in federal court, repealed before their effective dates, allowed to expire at precisely the wrong moment, or left essentially unenforced — while the AI harms that actually generated litigation and regulatory attention went unaddressed until 2025. For businesses building AI compliance programs and trying to protect intellectual property, understanding why the first draft failed is the best guide to where the law is heading.
What the Record Shows
California’s election-deepfake laws failed in full. AB 2839 and AB 2655, enacted in September 2024 in response to a viral AI parody video, were challenged in federal court within hours of signature. In Kohls v. Bonta (E.D. Cal.), Judge John A. Mendez permanently struck down AB 2655 in August 2025 as preempted by Section 230 of the Communications Decency Act — holding that no part of the statute could be salvaged — and days later invalidated AB 2839 as content-, viewpoint-, and speaker-based discrimination under the First Amendment. The doctrinal grounds were well settled before the bills passed.
Earlier statutes aged out or sat dormant. California’s 2018 B.O.T. Act (bot disclosure) has produced no meaningful public enforcement record and, by its own intent-to-mislead element, largely misses the modern chatbot economy. AB 730, the state’s 2019 election-deepfake law, sunsetted on January 1, 2023 — roughly five weeks after ChatGPT’s release. AB 302’s inventory of “high-risk” government AI systems returned a report finding zero such systems statewide, despite documented deployments.
Colorado’s landmark AI Act was repealed before it took effect. SB 24-205 (2024), the nation’s first comprehensive AI statute, borrowed the European Union (EU) AI Act’s risk-based architecture: duties of care, impact assessments, and risk-management programs for high-risk systems in employment, housing, credit, health care, and education. It was delayed twice, challenged by X.AI in April 2026 in litigation the federal government joined — the first federal intervention against a state AI law, implementing the December 2025 executive order on national AI policy — and repealed and replaced by SB 26-189 in May 2026. The successor framework, effective January 1, 2027, is a far narrower disclosure regime for automated decision-making technologies.
Enforcement gaps undercut the hiring-algorithm laws. A December 2025 New York State Comptroller audit found that the agency enforcing New York City’s Local Law 144, the NYC Department of Consumer and Worker Protection, had identified one instance of potential noncompliance among companies using AI and automated tools in hiring and promotions where auditors found 17. Illinois’s 2020 AI Video Interview Act specified no penalties and no enforcement agency; the state effectively superseded it with HB 3773’s amendments to the Human Rights Act, effective January 2026.
Meanwhile, the harms that materialized were elsewhere. No pre-2025 statute anywhere addressed companion chatbots — the AI category at the center of the Garcia v. Character Technologies litigation and subsequent legislative hearings. California’s SB 243, the first companion-chatbot law, took effect January 1, 2026, with New York and Oregon (SB 1546, effective January 2027) following. These laws carry private rights of action and are already reshaping product-design obligations for any conversational AI accessible to minors.
Why It Matters for Clients
The pattern is not random. First-generation statutes stumbled in three recurring ways: they encoded a recent, vivid incident into law (and collided with settled First Amendment and Section 230 doctrine); they imported the EU’s regulatory architecture – unworkability in the U.S. markets was known; and they regulated administrable proxies — compute thresholds, training costs, disclosure inventories — rather than the risks that proved most acute. California’s SB 53, the Transparency in Frontier AI Act now in effect, retains a fixed compute threshold even as inference-time scaling, model distillation, and training-efficiency gains erode what that threshold measures.
Three practical implications follow. First, do not mistake quiet enforcement for low exposure: the Comptroller’s audit is pushing New York City toward proactive enforcement, and disclosure-based regimes can tighten quickly. Second, the compliance center of gravity is shifting from comprehensive risk frameworks toward targeted, conduct-specific statutes — companion-chatbot safeguards, employment-AI notices, frontier-model transparency — several of which carry private rights of action with per-violation damages. Third, the federal-state conflict is now live: the December 2025 executive order and the federal intervention in Colorado signal that preemption arguments will be a recurring feature of state AI enforcement, creating both defenses and uncertainty for multistate operators.
The Bottom Line
State AI law is entering its second draft: narrower, more disclosure-oriented, more enforcement-realistic, and increasingly focused on documented harms rather than anticipated ones. Businesses deploying AI should inventory their exposure under the statutes that survived — California’s SB 53 and SB 243, the revised Colorado framework, New York City’s Local Law 144, and the Illinois amendments — while monitoring the preemption litigation that may redraw the map again.
Buckley Law’s AI & Emerging Technology team advises developers and deployers of AI systems on multistate compliance, product counseling, and regulatory strategy. Contact Martin Medeiros at 503-620-8900 to discuss your organization’s exposure.
Martin Medeiros is a Shareholder at Buckley Law. With more than 20 years of experience, his practice area encompasses a range of services to clients including business formations and transactions, intellectual property, technology applications and IT, business succession management, privacy and security, and copyright and trademark law. Martin helps organizations build value by treating intellectual property as a strategic asset.
This article is intended for general informational purposes and constitutes attorney commentary on legal and regulatory trends. It does not constitute legal advice. Readers should consult qualified legal counsel regarding specific matters affecting their clients.
The provision of this material does not create an attorney-client relationship between the firm and the reader, and does not constitute legal advice. Legal advice must be tailored to the specific circumstances of each case, and the contents of this article are not a substitute for legal counsel. Do not take action in reliance on the contents of this material without seeking the advice of counsel.