An Australian company operating under the Privacy Act 1988 and the National AI Centre's voluntary Guidance for AI Adoption (AI6) is used to a single national reference point. Expand into the United States and that reference point disappears. There is no federal AI Act, no federal preemption, and no single regulator to call. What exists instead is a fast-moving state-by-state patchwork, with Texas, California, Colorado, Connecticut, Illinois and New York City each imposing different, sometimes contradictory, rules on the same AI system. This guide sets out what genuinely changes for an Australian company crossing the Pacific, what stays surprisingly familiar, and the concrete steps to take before go-live.
What stays similar
The first useful finding for an Australian compliance team is that the underlying regulatory philosophy in the United States is not as foreign as the headlines suggest. Neither country has a comprehensive, EU-style AI statute. Australia relies on the voluntary AI6 framework layered over binding sector law, principally the Privacy Act 1988 enforced by the OAIC, APRA's CPS 230 for regulated financial entities, ASIC for financial services conduct, and sector regulators such as the TGA for medical devices and the Fair Work Commission for employment disputes. The National AI Plan, released in December 2025 by the Department of Industry, Science and Resources, confirmed that Australia will not pursue a standalone AI Act, leaving AI6 and existing sector law as the governance backbone.
The United States looks structurally similar at the federal level. There is no federal AI Act, and the voluntary NIST AI Risk Management Framework plays a role comparable to AI6, a non-binding baseline that regulators and courts increasingly treat as evidence of reasonable practice. In both countries, the real compliance obligations sit in sector and general law, privacy statutes, financial services conduct rules, employment and anti-discrimination law, rather than in a dedicated AI statute. An Australian governance team will recognise this shape immediately.
What is genuinely different
The difference is not the philosophy, it is the multiplication. Australia's sector rules apply nationally, with limited exceptions such as the NSW Workplace Surveillance Act 2005. A privacy obligation, once understood, applies the same way in Perth as in Sydney. In the United States, an AI system that is lawful in Texas can trigger disclosure duties in California, employment liability in Illinois, and a bias audit requirement in New York City, all for the same underlying deployment. There is no federal AI statute to preempt or harmonise these regimes, and none is imminent. The core planning task for an Australian company is therefore not "what does US law require" but "which states is our AI system actually reaching, and what does each of them require."
This site's interactive state comparison tool and full legislative tracker exist precisely because that question cannot be answered from a single statute the way it can in Australia.
The state-by-state landscape
Six jurisdictions currently define the practical US patchwork for AI governance, and each takes a distinct approach:
- Texas. The Texas Responsible AI Governance Act (TRAIGA) came into force on 1 January 2026. Enforcement sits exclusively with the Texas Attorney General, there is no private right of action, and civil penalties reach up to $200,000 per uncurable violation. TRAIGA is intent-based, targeting behavioural manipulation, discrimination and unlawful deepfakes rather than imposing a general risk-management regime.
- California. California layers several distinct laws rather than one. SB 53, the Transparency in Frontier Artificial Intelligence Act, took effect 1 January 2026 with penalties up to $1,000,000 per violation, aimed at large frontier-model developers. AB 2013 requires training-data transparency from generative AI developers. SB 942, the California AI Transparency Act, requires watermarking and detection tools for AI-generated audiovisual content and commences 2 August 2026. Separately, the California Privacy Protection Agency's automated decision-making technology (ADMT) regulations bring significant-decision AI uses under CCPA from 1 January 2027.
- Colorado. The original Colorado AI Act (SB 24-205) was repealed before taking effect and replaced by SB 26-189, a narrower regime focused on automated decision-making technology and consequential decisions, commencing 1 January 2027. Enforcement is by the Attorney General only, with no private right of action.
- Connecticut. SB 5 is an omnibus law covering frontier model developers, consumer-facing AI chatbots, and automated employment decision tools. Most provisions commence 1 October 2026. Violations are enforced as unfair or deceptive trade practices under the Connecticut Unfair Trade Practices Act (CUTPA), with the Attorney General holding exclusive enforcement authority and no private right of action.
- Illinois. HB 3773 amends the Illinois Human Rights Act and took effect 1 January 2026, prohibiting AI-driven employment decisions that produce a discriminatory effect and requiring employee notice of AI use in recruitment, promotion, discipline and discharge. Unlike Texas, Colorado and Connecticut, Illinois allows individuals to enforce violations directly, through a charge filed with the Illinois Department of Human Rights (IDHR) or a civil complaint, a meaningfully different liability exposure for employers.
- New York City. Local Law 144 has required independent annual bias audits of automated employment decision tools since it entered enforcement in July 2023, with civil penalties of up to $500 for a first violation and between $500 and $1,500 for each subsequent violation, each day of non-compliant use counting as a separate violation. A December 2025 New York State Comptroller audit found the city's enforcement of the law to be ineffective, not merely inconsistent, citing a complaint system in which roughly 75 percent of test calls to the NYC 311 line were misrouted and never reached the enforcing agency, the Department of Consumer and Worker Protection, and compliance reviews in which that department flagged only 1 of 32 disclosures examined as non-compliant against at least 17 the Comptroller's own review identified, a reminder that a rule being on the books and a rule being actively policed are two different risk profiles.
Why this matters more than it first appears
An Australian company reading this list for the first time may be tempted to treat it as six extra items on a checklist. That understates the problem. These laws differ not only in penalty amounts but in enforcement mechanism (AG-only versus private right of action), in trigger (frontier model development, employment decisions, consumer-facing chatbots, or general automated decision-making), and in commencement date (already in force, mid-2026, or 2027). A single AI-powered hiring tool deployed nationally in the US could simultaneously need an NYC bias audit, trigger Illinois notice obligations, and fall inside Colorado's or Connecticut's consequential-decision regime once those commence, while remaining entirely unregulated federally. Compliance built around "one AI policy for the US market" will misfire in at least one direction, either over-engineering obligations that do not apply in a given state or missing one that does.
Concrete steps before expansion
- Build a state-by-state exposure map, not a national policy. Identify which states your AI systems actually touch, through customers, employees, or contractors, and treat each state's law set as a separate compliance line item. Use this site's state comparison tool to map obligations against your specific footprint and the tracker to monitor commencement dates as they shift.
- Separate employment AI from consumer AI from frontier-model AI. Illinois and NYC target employment tools specifically. California's SB 53 and Connecticut's frontier-developer provisions target model builders, not typical deployers. Colorado's and California's ADMT-style regimes target consequential decisions generally. An AU company using AI for recruitment in the US should treat Illinois and NYC as first priority regardless of company size, since these are already in force with individual or municipal enforcement.
- Track enforcement mechanism alongside substantive obligation. Texas, Colorado, and Connecticut concentrate enforcement in the state Attorney General with no private right of action, which changes litigation risk calculus. Illinois permits individual claims through its Department of Human Rights. Know which regime applies to each obligation before assuming a uniform risk profile.
- Adopt the NIST AI RMF as the common baseline, the way AI6 functions at home. Since no single binding US standard exists, using the NIST AI Risk Management Framework as an internal baseline, layered under state-specific obligations, mirrors the AI6-plus-sector-law structure Australian teams already operate and gives regulators and courts a recognised point of reference.
- Do not assume federal relief is coming. With no federal AI Act and no preemption mechanism currently enacted, the multi-state patchwork is the operating environment for the foreseeable future, not a transitional state. Build governance capacity for ongoing multi-jurisdictional tracking rather than a one-off gap assessment.
- Keep Australian obligations live in parallel. Expansion into the US does not relieve US-facing operations of Privacy Act obligations where Australian entities or data remain in scope, and APRA-regulated groups must continue to satisfy CPS 230 for any US-based AI vendor or service arrangement that touches a regulated entity's material business activities.
The governance function this requires
In practice, this means an Australian company's AI governance function needs to evolve from a single compliance owner referencing one national framework into a small matrix: one axis for each US state of operation, one axis for each AI use case category (employment, consumer-facing, frontier model development), tracked against a rolling commencement calendar. This is a materially heavier governance load than the Australian domestic model, not because American substantive standards are stricter, but because there are more of them, they are not harmonised, and several take effect on different dates through 2026 and 2027. Companies that treat US expansion as "add a US privacy policy" under-invest here. Companies that build the state-by-state map first, using this site's interactive tools to identify exact exposure, are the ones that avoid a Colorado or Connecticut obligation arriving unnoticed in 2027, or an Illinois or NYC employment claim arriving on day one.
Primary sources
- OAIC, Privacy Act 1988 civil penalty provisions
- National AI Centre, Guidance for AI Adoption (AI6)
- Department of Industry, Science and Resources, National AI Plan (December 2025)
- APRA, CPS 230 Operational Risk Management
- NSW Workplace Surveillance Act 2005
- Texas Responsible AI Governance Act (TRAIGA) overview
- California SB 53, Transparency in Frontier Artificial Intelligence Act
- California AB 2013, training data transparency
- California SB 942, AI Transparency Act
- California Privacy Protection Agency, ADMT regulations
- Colorado SB 26-189 overview
- Connecticut SB 5 (Public Act No. 26-15) overview
- Illinois HB 3773 overview
- NYC Local Law 144, Automated Employment Decision Tools
- New York State Comptroller, Enforcement of Local Law 144 (audit, December 2025)
- NIST AI Risk Management Framework
- AIRiskAware, US state AI law comparison tool
- AIRiskAware, US AI legislation tracker
Related articles
- Australian Company Expanding to Japan: What Changes About AI Governance
- What Changes When an Australian Company Expands AI Governance to Singapore
- Australian Company Expanding to the UK: What Changes About AI Governance Obligations
- Expanding Into the EU: What Changes for an Australian Company's AI Governance Obligations