Living tracker · Updated July 10, 2026

AI Regulation Tracker for MSPs

Enacted laws already cover businesses that merely use AI, even a 40-person company. For MSPs that is a demand signal: the same client liability justifies billable service lines you can launch this quarter.

Current as of July 10, 2026 · This is not legal advice; confirm applicability with counsel.

The short version

Three things every MSP should take away

Enacted laws already reach SMBs that only use AI

The broadest traps are hiring tools and regulated data. California FEHA (5+ employees), Illinois HB 3773 (1+ employee), and NYC Local Law 144 (follows the job, including remote NYC hires) hit ordinary small businesses today, no AI product required.

The 2026 story is retrenchment, but uncertainty is not safety

Colorado gutted and delayed its landmark law to 2027, the EU pushed high-risk obligations to 2027–2028, and a Dec 2025 federal order is litigating to preempt state laws. Existing state laws remain fully enforceable now.

Every one of these is a billable service line

AI exposure assessments, shadow-AI discovery, NIST-anchored acceptable-use policies, BAA/vendor sweeps for regulated clients, and managed AI-governance retainers are all justified by laws already in force. The risk is the demand signal.

Filter by where you operate

20 of 20 laws shown

Serve clients in several states? Pick every jurisdiction and sector you touch to see only the laws that apply.

Scope
States
Sectors

European Union

EU AI Act (Regulation 2024/1689)

European UnionIn effect · phased
Key dates
In force Aug 1, 2024 · prohibited practices + AI literacy Feb 2, 2025 · GPAI Aug 2, 2025 · transparency (Art. 50) Aug 2, 2026 · high-risk delayed to Dec 2, 2027 (standalone) / Aug 2, 2028 (embedded) per the Council’s June 29, 2026 Digital Omnibus, pending Official Journal publication.
Applies to
Providers and deployers. Reaches US businesses via Art. 2(1)(c) wherever "the output produced by the AI system is used in the Union." No SME exemption, though SME/startup fines are capped and simplifications extend to small mid-caps.
Obligation
Deployers of high-risk AI must follow instructions for use, assign trained human oversight, monitor, keep logs 6 months, and (Art. 26(7)) inform workers before workplace use. Art. 4 mandates AI literacy for staff (since Feb 2, 2025); Art. 50 requires disclosure of deepfakes and AI-generated content.

Risk read for MSPs

A US SMB client serving EU customers can be a "deployer" without realizing it. "We didn’t know they had EU users" becomes MSP exposure.

Revenue read for MSPs

Sell an "EU nexus check" + staff AI-literacy training package, plus managed human-oversight and 6-month logging documentation.

Primary source: EUR-Lex 2024/1689 ↗

US Federal

NIST AI Risk Management Framework (AI RMF 1.0) + GenAI Profile

US · FederalVoluntary guidance
Key dates
AI RMF 1.0 published Jan 26, 2023 · GenAI Profile (AI 600-1) published July 26, 2024.
Applies to
All organizations, any size. Voluntary, but the de facto US "standard of care," and an explicit affirmative defense / safe harbor under Texas TRAIGA.
Obligation
Adopt the Govern / Map / Measure / Manage functions to inventory, assess, and manage AI risk across the lifecycle.

Risk read for MSPs

Not a liability source itself, but the yardstick regulators and plaintiffs use. Clients not aligned to it look negligent after an incident.

Revenue read for MSPs

The anchor deliverable: sell NIST-aligned AI governance program buildouts and gap assessments as the foundation every other service attaches to.

Primary source: NIST AI RMF ↗

FTC Act §5 / "Operation AI Comply"

US · FederalIn effect · enforcement posture
Key dates
Operation AI Comply launched Sept 25, 2024; ongoing (the FTC set aside its Rytr order Dec 22, 2025).
Applies to
Any business making AI claims or using AI deceptively or unfairly. No size threshold.
Obligation
Don’t make unsubstantiated AI claims ("AI washing"); don’t use AI to deceive; substantiate marketing claims.

Risk read for MSPs

Clients’ "AI-powered" marketing is exposure, and MSPs that resell AI-branded services must substantiate their own claims.

Revenue read for MSPs

Add AI-claims substantiation review to your marketing/website audit offerings.

Primary source: FTC: AI ↗

EEOC: Title VII / UGESP applied to AI hiring

US · FederalIn effect · statute
Key dates
UGESP adopted 1978 · EEOC AI technical-assistance guidance issued May 2023, removed Jan 2025 · algorithmic discrimination still a Strategic Enforcement Plan priority (FY2024–28).
Applies to
Employers (Title VII: 15+ employees). Using a vendor’s tool is no shield; the employer bears liability.
Obligation
Ensure AI selection tools don’t cause adverse impact (four-fifths rule); validate as job-related and consistent with business necessity. The guidance was pulled, but the underlying law is unchanged.

Risk read for MSPs

For MSPs managing HR tech stacks: "we didn’t know the ATS scored candidates with AI" is exposure.

Revenue read for MSPs

Offer AI hiring-tool inventory + adverse-impact testing coordination.

Primary source: EEOC: role in AI ↗

Federal EO "Ensuring a National Policy Framework for AI"

US · FederalIn effect · executive action
Key dates
Signed Dec 11, 2025.
Applies to
Directs a DOJ AI Litigation Task Force, a Commerce evaluation of state laws, and FCC/FTC proceedings to challenge/preempt state AI laws; conditions BEAD broadband funding on policy alignment.
Obligation
Not a business obligation, but it creates legal uncertainty over state laws. Per multiple firm analyses, state laws remain enforceable unless a court strikes them or Congress preempts.

Risk read for MSPs

The key MSP message: uncertainty is not safety. Existing state laws are still enforceable today.

Revenue read for MSPs

Use it to frame "govern to the strictest applicable standard" retainer conversations.

Primary source: White House action ↗

US State

Colorado AI Act (SB 24-205, repealed/replaced by SB 26-189 ADMT Act)

US · ColoradoEnacted · not yet effective
Key dates
SB 205 signed May 2024 · effective date delayed twice · enforcement stayed by a federal court Apr 27, 2026 · SB 26-189 signed May 14, 2026, effective Jan 1, 2027.
Applies to
Developers and deployers of ADMT used in "consequential decisions." SB 26-189 narrowed the regime to disclosure/transparency, dropping the duty of care, impact assessments, and risk-management programs.
Obligation
Under SB 26-189: notify consumers when ADMT is used in a consequential decision; 3-year recordkeeping; 60-day AG cure period (sunsets Jan 1, 2030).

Risk read for MSPs

Highly fast-moving. Do NOT over-sell Colorado-specific compliance until AG rulemaking (due by Jan 1, 2027) settles.

Revenue read for MSPs

Position as "monitor and prepare"; fold into broader ADMT-readiness work rather than a standalone CO deliverable.

Primary source: Colorado SB24-205 ↗

California CPPA ADMT regulations (CCPA)

US · CaliforniaEnacted · phased-in
Key dates
Approved by OAL Sept 2025 · regs effective Jan 1, 2026 · ADMT compliance required Jan 1, 2027 · risk-assessment attestations to CPPA due Apr 1, 2028.
Applies to
Businesses meeting CCPA thresholds (>$25M revenue, or 100k+ consumers/households, etc.) using ADMT for "significant decisions." Employees and applicants count as consumers.
Obligation
Provide pre-use notice, opt-out, and access rights for ADMT in significant decisions; conduct and document risk assessments.

Risk read for MSPs

MSPs must know which client tools count as ADMT; CCPA-covered clients are common.

Revenue read for MSPs

Sell ADMT inventory + pre-use notice/opt-out implementation and risk-assessment support.

Primary source: CPPA regulations ↗

California Civil Rights Dept. FEHA automated-decision regs

US · CaliforniaIn effect
Key dates
Effective Oct 1, 2025.
Applies to
All employers with 5+ employees using automated-decision systems (ADS) in employment; liability extends to "agents" (vendors, staffing agencies).
Obligation
Don’t use ADS that discriminates (including via "proxies"); keep ADS records 4 years; anti-bias testing is admissible as a defense (its absence can be used against you).

Risk read for MSPs

Broad reach (5+ employees) hits nearly every SMB, and a vendor’s tool implicates the employer.

Revenue read for MSPs

Offer anti-bias testing coordination + 4-year recordkeeping setup and vendor-contract review (conducted under privilege).

Primary source: CA Civil Rights Dept. ↗

California AB 2013 (GenAI Training Data Transparency)

US · CaliforniaEnacted
Key dates
Signed 2024 · effective Jan 1, 2026 (backward-looking to systems released/modified since Jan 1, 2022).
Applies to
Developers of GenAI systems made available to Californians (no quantitative threshold).
Obligation
Publish a high-level summary of the datasets used to train the GenAI system on the developer’s website.

Risk read for MSPs

Mainly affects clients who fine-tune or build models, not pure users.

Revenue read for MSPs

Niche upsell for clients who customize or train their own models.

Primary source: CA AB 2013 ↗

California AI Transparency Act (SB 942, amended by AB 853)

US · CaliforniaEnacted · date delayed
Key dates
SB 942 signed Sept 19, 2024 · AB 853 delayed the operative date to Aug 2, 2026 (aligning with EU AI Act Art. 50).
Applies to
"Covered providers" of GenAI with >1M monthly users in CA. High threshold that exempts most SMBs. Penalty $5,000/violation/day.
Obligation
Provide a free AI-detection tool; offer manifest + latent disclosures (watermarks) on AI-generated audiovisual content.

Risk read for MSPs

The threshold excludes nearly all SMB clients; relevant only to large-platform clients.

Revenue read for MSPs

Low priority for the typical MSP’s SMB base.

Primary source: CA SB 942 ↗

California SB 243 (Companion Chatbots)

US · CaliforniaIn effect
Key dates
Signed Oct 13, 2025 · effective Jan 1, 2026 · annual reporting to the Office of Suicide Prevention from July 1, 2027.
Applies to
Operators of "companion chatbot" platforms available in CA. Excludes customer-service/operational bots. Private right of action ($1,000/violation floor, plus injunctive relief and fees).
Obligation
Disclose the chatbot’s AI nature; maintain self-harm/crisis protocols; break reminders every 3 hours for known minors.

Risk read for MSPs

Narrow: only clients running companion/social chatbots. Customer-service bots are exempt.

Revenue read for MSPs

Niche; flag for clients deploying consumer companion AI.

Primary source: CA SB 243 ↗

Texas Responsible AI Governance Act (TRAIGA / HB 149)

US · TexasEnacted · in effect
Key dates
Signed June 22, 2025 · effective Jan 1, 2026.
Applies to
Developers and deployers doing business in TX or serving TX residents. AG-only enforcement; no private right of action; local AI ordinances preempted.
Obligation
Prohibits AI deployed "with the intent to unlawfully discriminate against a protected class"; disparate impact alone is not enough. NIST AI RMF "substantial compliance" is an affirmative defense (§552.105).

Risk read for MSPs

Lighter than feared, but AG enforcement is real: reported penalties run $10k–$12k per curable violation, $80k–$200k per uncurable violation, and $2k–$40k/day for ongoing violations. Documentation is the defense.

Revenue read for MSPs

Sell NIST-aligned documentation as the safe-harbor deliverable, plus acceptable-use policy builds.

Primary source: TX HB 149 ↗

Utah AI Policy Act (SB 149 + 2025 amendments)

US · UtahIn effect
Key dates
SB 149 effective May 1, 2024 · amendments effective May 7, 2025 · sunset extended to July 1, 2027.
Applies to
Businesses using GenAI to interact with Utah consumers. Amendments narrowed the trigger to "high-risk" interactions (health/financial/legal advice, sensitive data) or when a consumer explicitly asks.
Obligation
Disclose GenAI use when asked; prominent upfront disclosure in high-risk interactions and regulated occupations. Safe harbor for proactive disclosure.

Risk read for MSPs

Modest: relevant to clients using AI chat in regulated occupations or handling sensitive data.

Revenue read for MSPs

Bundle a disclosure-language deliverable for client chatbots.

Primary source: Utah SB 149 ↗

Illinois HB 3773 (Human Rights Act AI amendment)

US · IllinoisIn effect
Key dates
Signed Aug 9, 2024 · effective Jan 1, 2026 · IDHR notice rules in progress.
Applies to
Employers with 1+ employee in IL for 20+ weeks. Covers AI in recruitment, hiring, promotion, discharge, discipline, and other terms.
Obligation
Don’t use AI with a discriminatory effect (strict, outcome-based liability, intent is not a defense); no zip-code proxies; notify employees when AI is used.

Risk read for MSPs

Broad SMB reach (1+ employee), and strict liability makes vendor tools a genuine exposure.

Revenue read for MSPs

Sell AI-in-HR inventory, employee-notice templates, and bias-testing coordination.

Primary source: IL HB 3773 ↗

Illinois BIPA (Biometric Information Privacy Act)

US · IllinoisIn effect
Key dates
Enacted 2008 · ongoing.
Applies to
Any private entity collecting biometric identifiers (face/voice) of IL residents. Private right of action.
Obligation
Get written consent before collecting biometrics; publish a retention/destruction schedule.

Risk read for MSPs

AI tools that scan faces or voices (video-interview tools, monitoring) trigger BIPA; MSP-managed tools are exposure.

Revenue read for MSPs

Sell biometric-tool inventory + consent-flow review.

Primary source: IL BIPA ↗

NYC Local Law 144 (Automated Employment Decision Tools)

US · New York CityIn effect
Key dates
Enacted Dec 2021 · effective Jan 1, 2023 · enforced by DCWP since July 5, 2023.
Applies to
Employers using AEDTs for candidates/employees residing in NYC (extraterritorial, following the job, including remote roles). Penalties $500–$1,500 per violation, per day.
Obligation
Annual independent bias audit; publicly post a summary; notify candidates 10 business days in advance.

Risk read for MSPs

Any client hiring NYC residents is covered. A Dec 2025 State Comptroller audit found DCWP enforcement "ineffective," so enforcement risk is currently low, but the obligation is unchanged and per-day penalties accumulate fast.

Revenue read for MSPs

Sell bias-audit coordination + notice/posting compliance as a recurring annual service.

Primary source: NYC LL 144 ↗

Connecticut SB 5 (AI Responsibility & Transparency Act)

US · ConnecticutEnacted · phasing in
Key dates
Predecessor SB 2 died May 2025 · SB 5 signed 2026 as Public Act 26-15 · employment obligations phase in Oct 1, 2026 – Oct 1, 2027.
Applies to
Developers and deployers of "automated employment-related decision processes"; small-business exceptions for some deployers.
Obligation
Notice when AI is used in employment decisions; AI use is not a defense to discrimination claims; frontier-developer whistleblower protections; disclosure of AI-related workforce reductions.

Risk read for MSPs

Emerging: CT-nexus clients should prepare for the 2026–27 phase-in.

Revenue read for MSPs

Position as "prepare now"; fold into multi-state employment-AI readiness.

Primary source: CT SB 5 ↗

Virginia HB 2094 (High-Risk AI Developer & Deployer Act)

US · VirginiaVetoed · not law
Key dates
Passed the legislature Feb 2025 · vetoed by Gov. Youngkin Mar 24, 2025.
Applies to
Would have covered developers/deployers of high-risk AI. Not in force. Existing VA laws (VCDPA, anti-discrimination) still apply to AI use.
Obligation
N/A (vetoed).

Risk read for MSPs

Do NOT present as current law; useful only as a directional signal.

Revenue read for MSPs

Use as a talking point on why proactive governance beats waiting for a statute.

Primary source: VA HB 2094 ↗

Sector-specific

HIPAA / HHS-OCR (PHI in AI tools)

Sector · HealthcareIn effect
Key dates
Privacy/Security Rules ongoing · proposed Security Rule modernization published Jan 6, 2025.
Applies to
Covered entities and business associates: any healthcare client, any size.
Obligation
Execute a BAA before any AI vendor touches PHI; include AI tools in the Security Risk Analysis. Consumer GenAI (ChatGPT Free/Plus, consumer Gemini/Claude) cannot lawfully handle PHI.

Risk read for MSPs

Enormous MSP exposure: "staff used consumer ChatGPT with PHI" with no BAA is a client violation on the MSP’s watch, the moment they hit enter.

Revenue read for MSPs

Sell shadow-AI discovery + BAA inventory + approved-tool lists for healthcare clients.

Primary source: HHS: HIPAA & AI ↗

GLBA / FTC Safeguards Rule

Sector · FinancialIn effect
Key dates
Safeguards Rule amended 2021 · breach-notification requirement effective May 13, 2024.
Applies to
Non-banking financial institutions under FTC jurisdiction (mortgage lenders, finance companies, tax preparers, auto dealers, advisors). Partial exemption below 5,000 consumers.
Obligation
Maintain a written information-security program; oversee service providers; report breaches (500+ consumers) to the FTC within 30 days.

Risk read for MSPs

AI tools processing customer NPI must be in the security program, and MSPs typically own the safeguards.

Revenue read for MSPs

Fold AI tools into the Safeguards Rule program; sell vendor-oversight + breach-readiness.

Primary source: FTC Safeguards Rule ↗

On the radar: the UK has no comprehensive AI statute (a principles-based approach delegated to sector regulators). Canada’s AIDA (part of Bill C-27) died when Parliament was prorogued in early 2025; watch for reintroduction.

The revenue read

What an MSP should do this quarter

Every service line below is justified by laws already in force. Treat the regulatory pressure as pipeline: each new law, insurance change, and enforcement action is a reason for a client conversation.

Launch a paid "AI Exposure Assessment"

Inventory every AI tool clients run (sanctioned and shadow), map each to the laws here, and deliver a risk register. The anchor deliverable nearly every law justifies, and the natural on-ramp to a governance retainer.

Productize shadow-AI discovery

The recurring failure mode across HIPAA, GLBA, and the employment laws is "we didn’t know what they were running." Deploy monitoring for consumer AI tools and bill it as a managed line item.

Sell a NIST-anchored AUP + governance build

The NIST AI RMF is the US standard of care and an explicit affirmative defense under Texas TRAIGA. Add employee AI-literacy training (mandatory in the EU since Feb 2, 2025) for any client with an EU nexus.

Run a focused "AI-in-HR" review

Illinois (1+ employee), California FEHA (5+ employees), NYC Local Law 144, and Texas TRAIGA all hit hiring tools. A 1-hour AI hiring-tool exposure review is the lowest-friction door-opener in this whole landscape.

Run BAA & vendor sweeps for regulated clients

Healthcare (HIPAA) and financial (GLBA) clients need every AI vendor under a BAA/service-provider agreement and inside the security program. Bill it as a fixed-fee compliance sprint.

Offer a managed AI-governance retainer

Bundle inventory, policy, monitoring, vendor oversight, and quarterly regulatory-update reviews. The fast-moving landscape (Colorado’s reversal, the EU delay, the federal preemption fight) is itself the pitch: SMBs need someone paid to track it.

See the shadow AI your clients are already running

The recurring failure mode behind almost every rule here is "we didn’t know what they were running." ShadowLock gives MSPs endpoint and browser visibility into unauthorized AI use across every client. It is the evidence layer behind every assessment, policy, and retainer on this page.