Living tracker · Updated July 10, 2026
AI Regulation Tracker for MSPs
Enacted laws already cover businesses that merely use AI, even a 40-person company. For MSPs that is a demand signal: the same client liability justifies billable service lines you can launch this quarter.
Current as of July 10, 2026 · This is not legal advice; confirm applicability with counsel.
The short version
Three things every MSP should take away
Enacted laws already reach SMBs that only use AI
The broadest traps are hiring tools and regulated data. California FEHA (5+ employees), Illinois HB 3773 (1+ employee), and NYC Local Law 144 (follows the job, including remote NYC hires) hit ordinary small businesses today, no AI product required.
The 2026 story is retrenchment, but uncertainty is not safety
Colorado gutted and delayed its landmark law to 2027, the EU pushed high-risk obligations to 2027–2028, and a Dec 2025 federal order is litigating to preempt state laws. Existing state laws remain fully enforceable now.
Every one of these is a billable service line
AI exposure assessments, shadow-AI discovery, NIST-anchored acceptable-use policies, BAA/vendor sweeps for regulated clients, and managed AI-governance retainers are all justified by laws already in force. The risk is the demand signal.
Filter by where you operate
20 of 20 laws shownServe clients in several states? Pick every jurisdiction and sector you touch to see only the laws that apply.
European Union
›EU AI Act (Regulation 2024/1689)
European UnionIn effect · phased
- Key dates
- In force Aug 1, 2024 · prohibited practices + AI literacy Feb 2, 2025 · GPAI Aug 2, 2025 · transparency (Art. 50) Aug 2, 2026 · high-risk delayed to Dec 2, 2027 (standalone) / Aug 2, 2028 (embedded) per the Council’s June 29, 2026 Digital Omnibus, pending Official Journal publication.
- Applies to
- Providers and deployers. Reaches US businesses via Art. 2(1)(c) wherever "the output produced by the AI system is used in the Union." No SME exemption, though SME/startup fines are capped and simplifications extend to small mid-caps.
- Obligation
- Deployers of high-risk AI must follow instructions for use, assign trained human oversight, monitor, keep logs 6 months, and (Art. 26(7)) inform workers before workplace use. Art. 4 mandates AI literacy for staff (since Feb 2, 2025); Art. 50 requires disclosure of deepfakes and AI-generated content.
Risk read for MSPs
A US SMB client serving EU customers can be a "deployer" without realizing it. "We didn’t know they had EU users" becomes MSP exposure.
Revenue read for MSPs
Sell an "EU nexus check" + staff AI-literacy training package, plus managed human-oversight and 6-month logging documentation.
US Federal
›NIST AI Risk Management Framework (AI RMF 1.0) + GenAI Profile
US · FederalVoluntary guidance
- Key dates
- AI RMF 1.0 published Jan 26, 2023 · GenAI Profile (AI 600-1) published July 26, 2024.
- Applies to
- All organizations, any size. Voluntary, but the de facto US "standard of care," and an explicit affirmative defense / safe harbor under Texas TRAIGA.
- Obligation
- Adopt the Govern / Map / Measure / Manage functions to inventory, assess, and manage AI risk across the lifecycle.
Risk read for MSPs
Not a liability source itself, but the yardstick regulators and plaintiffs use. Clients not aligned to it look negligent after an incident.
Revenue read for MSPs
The anchor deliverable: sell NIST-aligned AI governance program buildouts and gap assessments as the foundation every other service attaches to.
›FTC Act §5 / "Operation AI Comply"
US · FederalIn effect · enforcement posture
- Key dates
- Operation AI Comply launched Sept 25, 2024; ongoing (the FTC set aside its Rytr order Dec 22, 2025).
- Applies to
- Any business making AI claims or using AI deceptively or unfairly. No size threshold.
- Obligation
- Don’t make unsubstantiated AI claims ("AI washing"); don’t use AI to deceive; substantiate marketing claims.
Risk read for MSPs
Clients’ "AI-powered" marketing is exposure, and MSPs that resell AI-branded services must substantiate their own claims.
Revenue read for MSPs
Add AI-claims substantiation review to your marketing/website audit offerings.
›EEOC: Title VII / UGESP applied to AI hiring
US · FederalIn effect · statute
- Key dates
- UGESP adopted 1978 · EEOC AI technical-assistance guidance issued May 2023, removed Jan 2025 · algorithmic discrimination still a Strategic Enforcement Plan priority (FY2024–28).
- Applies to
- Employers (Title VII: 15+ employees). Using a vendor’s tool is no shield; the employer bears liability.
- Obligation
- Ensure AI selection tools don’t cause adverse impact (four-fifths rule); validate as job-related and consistent with business necessity. The guidance was pulled, but the underlying law is unchanged.
Risk read for MSPs
For MSPs managing HR tech stacks: "we didn’t know the ATS scored candidates with AI" is exposure.
Revenue read for MSPs
Offer AI hiring-tool inventory + adverse-impact testing coordination.
›Federal EO "Ensuring a National Policy Framework for AI"
US · FederalIn effect · executive action
- Key dates
- Signed Dec 11, 2025.
- Applies to
- Directs a DOJ AI Litigation Task Force, a Commerce evaluation of state laws, and FCC/FTC proceedings to challenge/preempt state AI laws; conditions BEAD broadband funding on policy alignment.
- Obligation
- Not a business obligation, but it creates legal uncertainty over state laws. Per multiple firm analyses, state laws remain enforceable unless a court strikes them or Congress preempts.
Risk read for MSPs
The key MSP message: uncertainty is not safety. Existing state laws are still enforceable today.
Revenue read for MSPs
Use it to frame "govern to the strictest applicable standard" retainer conversations.
US State
›Colorado AI Act (SB 24-205, repealed/replaced by SB 26-189 ADMT Act)
US · ColoradoEnacted · not yet effective
- Key dates
- SB 205 signed May 2024 · effective date delayed twice · enforcement stayed by a federal court Apr 27, 2026 · SB 26-189 signed May 14, 2026, effective Jan 1, 2027.
- Applies to
- Developers and deployers of ADMT used in "consequential decisions." SB 26-189 narrowed the regime to disclosure/transparency, dropping the duty of care, impact assessments, and risk-management programs.
- Obligation
- Under SB 26-189: notify consumers when ADMT is used in a consequential decision; 3-year recordkeeping; 60-day AG cure period (sunsets Jan 1, 2030).
Risk read for MSPs
Highly fast-moving. Do NOT over-sell Colorado-specific compliance until AG rulemaking (due by Jan 1, 2027) settles.
Revenue read for MSPs
Position as "monitor and prepare"; fold into broader ADMT-readiness work rather than a standalone CO deliverable.
›California CPPA ADMT regulations (CCPA)
US · CaliforniaEnacted · phased-in
- Key dates
- Approved by OAL Sept 2025 · regs effective Jan 1, 2026 · ADMT compliance required Jan 1, 2027 · risk-assessment attestations to CPPA due Apr 1, 2028.
- Applies to
- Businesses meeting CCPA thresholds (>$25M revenue, or 100k+ consumers/households, etc.) using ADMT for "significant decisions." Employees and applicants count as consumers.
- Obligation
- Provide pre-use notice, opt-out, and access rights for ADMT in significant decisions; conduct and document risk assessments.
Risk read for MSPs
MSPs must know which client tools count as ADMT; CCPA-covered clients are common.
Revenue read for MSPs
Sell ADMT inventory + pre-use notice/opt-out implementation and risk-assessment support.
›California Civil Rights Dept. FEHA automated-decision regs
US · CaliforniaIn effect
- Key dates
- Effective Oct 1, 2025.
- Applies to
- All employers with 5+ employees using automated-decision systems (ADS) in employment; liability extends to "agents" (vendors, staffing agencies).
- Obligation
- Don’t use ADS that discriminates (including via "proxies"); keep ADS records 4 years; anti-bias testing is admissible as a defense (its absence can be used against you).
Risk read for MSPs
Broad reach (5+ employees) hits nearly every SMB, and a vendor’s tool implicates the employer.
Revenue read for MSPs
Offer anti-bias testing coordination + 4-year recordkeeping setup and vendor-contract review (conducted under privilege).
›California AB 2013 (GenAI Training Data Transparency)
US · CaliforniaEnacted
- Key dates
- Signed 2024 · effective Jan 1, 2026 (backward-looking to systems released/modified since Jan 1, 2022).
- Applies to
- Developers of GenAI systems made available to Californians (no quantitative threshold).
- Obligation
- Publish a high-level summary of the datasets used to train the GenAI system on the developer’s website.
Risk read for MSPs
Mainly affects clients who fine-tune or build models, not pure users.
Revenue read for MSPs
Niche upsell for clients who customize or train their own models.
›California AI Transparency Act (SB 942, amended by AB 853)
US · CaliforniaEnacted · date delayed
- Key dates
- SB 942 signed Sept 19, 2024 · AB 853 delayed the operative date to Aug 2, 2026 (aligning with EU AI Act Art. 50).
- Applies to
- "Covered providers" of GenAI with >1M monthly users in CA. High threshold that exempts most SMBs. Penalty $5,000/violation/day.
- Obligation
- Provide a free AI-detection tool; offer manifest + latent disclosures (watermarks) on AI-generated audiovisual content.
Risk read for MSPs
The threshold excludes nearly all SMB clients; relevant only to large-platform clients.
Revenue read for MSPs
Low priority for the typical MSP’s SMB base.
›California SB 243 (Companion Chatbots)
US · CaliforniaIn effect
- Key dates
- Signed Oct 13, 2025 · effective Jan 1, 2026 · annual reporting to the Office of Suicide Prevention from July 1, 2027.
- Applies to
- Operators of "companion chatbot" platforms available in CA. Excludes customer-service/operational bots. Private right of action ($1,000/violation floor, plus injunctive relief and fees).
- Obligation
- Disclose the chatbot’s AI nature; maintain self-harm/crisis protocols; break reminders every 3 hours for known minors.
Risk read for MSPs
Narrow: only clients running companion/social chatbots. Customer-service bots are exempt.
Revenue read for MSPs
Niche; flag for clients deploying consumer companion AI.
›Texas Responsible AI Governance Act (TRAIGA / HB 149)
US · TexasEnacted · in effect
- Key dates
- Signed June 22, 2025 · effective Jan 1, 2026.
- Applies to
- Developers and deployers doing business in TX or serving TX residents. AG-only enforcement; no private right of action; local AI ordinances preempted.
- Obligation
- Prohibits AI deployed "with the intent to unlawfully discriminate against a protected class"; disparate impact alone is not enough. NIST AI RMF "substantial compliance" is an affirmative defense (§552.105).
Risk read for MSPs
Lighter than feared, but AG enforcement is real: reported penalties run $10k–$12k per curable violation, $80k–$200k per uncurable violation, and $2k–$40k/day for ongoing violations. Documentation is the defense.
Revenue read for MSPs
Sell NIST-aligned documentation as the safe-harbor deliverable, plus acceptable-use policy builds.
›Utah AI Policy Act (SB 149 + 2025 amendments)
US · UtahIn effect
- Key dates
- SB 149 effective May 1, 2024 · amendments effective May 7, 2025 · sunset extended to July 1, 2027.
- Applies to
- Businesses using GenAI to interact with Utah consumers. Amendments narrowed the trigger to "high-risk" interactions (health/financial/legal advice, sensitive data) or when a consumer explicitly asks.
- Obligation
- Disclose GenAI use when asked; prominent upfront disclosure in high-risk interactions and regulated occupations. Safe harbor for proactive disclosure.
Risk read for MSPs
Modest: relevant to clients using AI chat in regulated occupations or handling sensitive data.
Revenue read for MSPs
Bundle a disclosure-language deliverable for client chatbots.
›Illinois HB 3773 (Human Rights Act AI amendment)
US · IllinoisIn effect
- Key dates
- Signed Aug 9, 2024 · effective Jan 1, 2026 · IDHR notice rules in progress.
- Applies to
- Employers with 1+ employee in IL for 20+ weeks. Covers AI in recruitment, hiring, promotion, discharge, discipline, and other terms.
- Obligation
- Don’t use AI with a discriminatory effect (strict, outcome-based liability, intent is not a defense); no zip-code proxies; notify employees when AI is used.
Risk read for MSPs
Broad SMB reach (1+ employee), and strict liability makes vendor tools a genuine exposure.
Revenue read for MSPs
Sell AI-in-HR inventory, employee-notice templates, and bias-testing coordination.
›Illinois BIPA (Biometric Information Privacy Act)
US · IllinoisIn effect
- Key dates
- Enacted 2008 · ongoing.
- Applies to
- Any private entity collecting biometric identifiers (face/voice) of IL residents. Private right of action.
- Obligation
- Get written consent before collecting biometrics; publish a retention/destruction schedule.
Risk read for MSPs
AI tools that scan faces or voices (video-interview tools, monitoring) trigger BIPA; MSP-managed tools are exposure.
Revenue read for MSPs
Sell biometric-tool inventory + consent-flow review.
›NYC Local Law 144 (Automated Employment Decision Tools)
US · New York CityIn effect
- Key dates
- Enacted Dec 2021 · effective Jan 1, 2023 · enforced by DCWP since July 5, 2023.
- Applies to
- Employers using AEDTs for candidates/employees residing in NYC (extraterritorial, following the job, including remote roles). Penalties $500–$1,500 per violation, per day.
- Obligation
- Annual independent bias audit; publicly post a summary; notify candidates 10 business days in advance.
Risk read for MSPs
Any client hiring NYC residents is covered. A Dec 2025 State Comptroller audit found DCWP enforcement "ineffective," so enforcement risk is currently low, but the obligation is unchanged and per-day penalties accumulate fast.
Revenue read for MSPs
Sell bias-audit coordination + notice/posting compliance as a recurring annual service.
›Connecticut SB 5 (AI Responsibility & Transparency Act)
US · ConnecticutEnacted · phasing in
- Key dates
- Predecessor SB 2 died May 2025 · SB 5 signed 2026 as Public Act 26-15 · employment obligations phase in Oct 1, 2026 – Oct 1, 2027.
- Applies to
- Developers and deployers of "automated employment-related decision processes"; small-business exceptions for some deployers.
- Obligation
- Notice when AI is used in employment decisions; AI use is not a defense to discrimination claims; frontier-developer whistleblower protections; disclosure of AI-related workforce reductions.
Risk read for MSPs
Emerging: CT-nexus clients should prepare for the 2026–27 phase-in.
Revenue read for MSPs
Position as "prepare now"; fold into multi-state employment-AI readiness.
›Virginia HB 2094 (High-Risk AI Developer & Deployer Act)
US · VirginiaVetoed · not law
- Key dates
- Passed the legislature Feb 2025 · vetoed by Gov. Youngkin Mar 24, 2025.
- Applies to
- Would have covered developers/deployers of high-risk AI. Not in force. Existing VA laws (VCDPA, anti-discrimination) still apply to AI use.
- Obligation
- N/A (vetoed).
Risk read for MSPs
Do NOT present as current law; useful only as a directional signal.
Revenue read for MSPs
Use as a talking point on why proactive governance beats waiting for a statute.
Sector-specific
›HIPAA / HHS-OCR (PHI in AI tools)
Sector · HealthcareIn effect
- Key dates
- Privacy/Security Rules ongoing · proposed Security Rule modernization published Jan 6, 2025.
- Applies to
- Covered entities and business associates: any healthcare client, any size.
- Obligation
- Execute a BAA before any AI vendor touches PHI; include AI tools in the Security Risk Analysis. Consumer GenAI (ChatGPT Free/Plus, consumer Gemini/Claude) cannot lawfully handle PHI.
Risk read for MSPs
Enormous MSP exposure: "staff used consumer ChatGPT with PHI" with no BAA is a client violation on the MSP’s watch, the moment they hit enter.
Revenue read for MSPs
Sell shadow-AI discovery + BAA inventory + approved-tool lists for healthcare clients.
›GLBA / FTC Safeguards Rule
Sector · FinancialIn effect
- Key dates
- Safeguards Rule amended 2021 · breach-notification requirement effective May 13, 2024.
- Applies to
- Non-banking financial institutions under FTC jurisdiction (mortgage lenders, finance companies, tax preparers, auto dealers, advisors). Partial exemption below 5,000 consumers.
- Obligation
- Maintain a written information-security program; oversee service providers; report breaches (500+ consumers) to the FTC within 30 days.
Risk read for MSPs
AI tools processing customer NPI must be in the security program, and MSPs typically own the safeguards.
Revenue read for MSPs
Fold AI tools into the Safeguards Rule program; sell vendor-oversight + breach-readiness.
On the radar: the UK has no comprehensive AI statute (a principles-based approach delegated to sector regulators). Canada’s AIDA (part of Bill C-27) died when Parliament was prorogued in early 2025; watch for reintroduction.
The revenue read
What an MSP should do this quarter
Every service line below is justified by laws already in force. Treat the regulatory pressure as pipeline: each new law, insurance change, and enforcement action is a reason for a client conversation.
Launch a paid "AI Exposure Assessment"
Inventory every AI tool clients run (sanctioned and shadow), map each to the laws here, and deliver a risk register. The anchor deliverable nearly every law justifies, and the natural on-ramp to a governance retainer.
Productize shadow-AI discovery
The recurring failure mode across HIPAA, GLBA, and the employment laws is "we didn’t know what they were running." Deploy monitoring for consumer AI tools and bill it as a managed line item.
Sell a NIST-anchored AUP + governance build
The NIST AI RMF is the US standard of care and an explicit affirmative defense under Texas TRAIGA. Add employee AI-literacy training (mandatory in the EU since Feb 2, 2025) for any client with an EU nexus.
Run a focused "AI-in-HR" review
Illinois (1+ employee), California FEHA (5+ employees), NYC Local Law 144, and Texas TRAIGA all hit hiring tools. A 1-hour AI hiring-tool exposure review is the lowest-friction door-opener in this whole landscape.
Run BAA & vendor sweeps for regulated clients
Healthcare (HIPAA) and financial (GLBA) clients need every AI vendor under a BAA/service-provider agreement and inside the security program. Bill it as a fixed-fee compliance sprint.
Offer a managed AI-governance retainer
Bundle inventory, policy, monitoring, vendor oversight, and quarterly regulatory-update reviews. The fast-moving landscape (Colorado’s reversal, the EU delay, the federal preemption fight) is itself the pitch: SMBs need someone paid to track it.
See the shadow AI your clients are already running
The recurring failure mode behind almost every rule here is "we didn’t know what they were running." ShadowLock gives MSPs endpoint and browser visibility into unauthorized AI use across every client. It is the evidence layer behind every assessment, policy, and retainer on this page.