
Laws and bills have been enacted and proposed at all levels of government, with some drawing a bead on algorithmic pricing.
As artificial intelligence (AI) continues to transform industries, states and local governments are stepping up to regulate its use, hoping to ensure ethical deployment and consumer protection. Laws were recently enacted in Colorado and Texas. Of the two, Colorado’s legislation is more detailed and narrowly focused on high-risk systems, with stringent requirements for developers and deployers. The Texas law is broader, emphasizing transparency and accountability for businesses using AI, but with fewer specific mandates. Meanwhile, efforts to regulate AI are under way across the country at federal, state, and local levels.
Colorado Senate Bill 24-205: Consumer Protections in AI Interactions
Colorado’s Senate Bill 24-205, scheduled to go into effect on Feb. 1, 2026, establishes comprehensive regulations for developers and deployers of high-risk AI systems. The law aims to prevent algorithmic discrimination and ensure transparency in AI-driven decision-making processes. Its key provisions include:
Definition of High-Risk AI Systems. High-risk AI systems are those that influence consequential decisions, such as employment, housing, healthcare, education, and financial services. These systems must be carefully monitored to avoid unlawful differential treatment based on protected characteristics like age, race, disability, or veteran status.
Developer Responsibilities. Developers must use reasonable care to prevent algorithmic discrimination and provide detailed documentation to deployers, including summaries of training data, system limitations, and mitigation measures. The law requires developers to disclose known risks of algorithmic discrimination to deployers and the Colorado Attorney General within 90 days of discovery.
Deployer Responsibilities. Deployers must implement a risk management policy aligned with recognized frameworks like the AI Risk Management Framework developed by the National Institute of Standards and Technology (NIST). Deployers must conduct annual impact assessments to evaluate risks of algorithmic discrimination, and notify consumers when high-risk AI systems are used in consequential decisions and provide opportunities for appeals and corrections.
Exemptions. Small businesses with fewer than 50 employees and certain federally regulated entities are exempt from some requirements. Additionally, systems approved by federal agencies or used for non-decision-making tasks (e.g., cybersecurity or spell-checking) are excluded.
Enforcement. The Colorado Attorney General has exclusive authority to enforce the law, with violations constituting unfair trade practices. Developers and deployers can defend against enforcement actions by demonstrating compliance with recognized risk management frameworks.
Texas House Bill 149: Responsible AI Governance Act
Texas’s House Bill 149, signed into law in June 2025 and effective Sept. 1, 2025, establishes a framework for responsible AI use, with a focus on prohibited practices, government transparency, and regulatory innovation. While less prescriptive than Colorado’s law, it introduces important guardrails for AI deployment in the state.
Prohibited Uses. Also called the Texas Responsible Artificial Intelligence Governance Act (TRAIGA), the law prohibits the use of AI systems for behavioral manipulation that causes substantial harm; intentional discrimination based on protected characteristics; and creation of harmful or illegal content, such as deepfakes used for fraud or harassment.
Transparency Requirements. This applies primarily to state agencies and public entities, requiring disclosure when AI is used in public-facing decision-making processes. It encourages public reporting on AI system performance and fairness.
Regulatory Sandbox. Establishes an online space where companies can test innovative AI applications under regulatory supervision. This regulatory sandbox provides a safe harbor for participants who comply with sandbox conditions.
Preemption and Enforcement. To build uniformity across the state, the law preempts local AI ordinances. It grants enforcement authority to the Texas Attorney General and emphasizes intent-based liability, meaning enforcement focuses on whether harm was caused intentionally, rather than through unintended impact.
Other State-Level Activity
U.S. states beyond Texas and Colorado have enacted or proposed legislation regulating AI in 2025. Here’s a summary of the current landscape:
Enacted State Laws
According to the National Conference of State Legislatures (NCSL), 28 states and the U.S. Virgin Islands have enacted more than 75 AI-related measures this year. Some notable examples include:
Arkansas. Passed a law clarifying ownership of AI-generated content, assigning rights to the person or employer who provided the input data.
Montana. Enacted the “Right to Compute” law, which includes AI risk management requirements for critical infrastructure.
North Dakota. Expanded harassment laws to prohibit the use of AI-powered robots for stalking or harassment.
New Jersey. Adopted a resolution urging AI companies to protect whistleblowers.
New York. Requires state agencies to disclose their use of automated decision-making tools and ensure that AI does not undermine workers’ rights.
Proposed Legislation
All 50 states, along with Puerto Rico, the Virgin Islands, and Washington, D.C., have introduced AI-related legislation. These proposals vary widely and include: creating task forces to study AI’s impact; requiring transparency in AI decision-making; regulating generative AI in commercial and educational settings; and establishing consumer protections against AI misuse.
A good resource to track state-level legislation is the IAPP US State AI Governance Legislation Tracker, which monitors both enacted and proposed laws across sectors.
Algorithmic Pricing
The Colorado law specifically addresses price collusion concerns raised by algorithmic pricing, something that has sparked public and private litigation. Similar legislation has been proposed or enacted at the federal, state, and local levels. Industries most affected are real estate (rental pricing), hospitality (hotel rates), travel and tourism, and healthcare (insurance reimbursement rates).
At the federal level, Sen. Amy Klobuchar (D-MN) introduced the Preventing Algorithmic Collusion Act (S. 232) in February 2025 which would: make it presumptively unlawful for competitors to share non-public data via pricing algorithms to raise prices; prohibit using competitively sensitive information from competitors to train AI pricing tools; and require disclosure of algorithmic pricing use and allows audits by antitrust enforcers.
Winding its way through the California legislature is the California Preventing Algorithmic Collusion Act of 2025 (SB 295) which would prohibit pricing algorithms that use undefined “competitor data.” Companies with more than $5 million in revenue would be required to report algorithmic pricing use to the state Attorney General and disclose to customers when prices are set by algorithms. Violations could lead to civil fines, corporate dissolution, or other penalties.
San Francisco and Philadelphia have passed local ordinances restricting the use of algorithmic pricing tools, particularly in the residential rental market.
Implications for Companies
This wave of activity illustrates the movement toward stricter AI regulations, emphasizing consumer protection, transparency, and accountability. Professionals working with AI systems should consider the following actions:
Conduct Comprehensive Risk Assessments. Evaluate your AI systems for potential biases and discriminatory outcomes. Regular impact assessments are critical, especially for high-risk systems.
Strengthen Documentation. Maintain detailed records of your AI systems, including training data, intended uses, and mitigation measures. This documentation will be essential for compliance and audits.
Implement Risk Management Frameworks. Adopt recognized frameworks like NIST’s AI Risk Management Framework to guide your policies and processes. These frameworks provide a structured approach to identifying and mitigating risks.
Ensure Consumer Transparency. Develop clear communication strategies to inform consumers when AI systems are used in decision-making. Provide opportunities for appeals and corrections to build trust.
Monitor Regulatory Developments. Stay informed about evolving AI regulations at the state and federal levels. Compliance requirements may vary, and proactive adaptation is key to avoiding penalties.
_________________