Skip to content
Securafy AI Lab by Securafy
AI Lab

While State AI Laws Stalled, Your Actual Regulator Kept Moving

Colorado repealed its own AI Act this year. Texas narrowed its AI law before it ever took effect. Read the headlines and AI regulation looks like it eased up in 2026. The regulator who actually examines your bank, insurer, or health system never slowed down.

In this article

Colorado repealed its own AI Act this year. Texas narrowed its AI law before it ever took effect. Read the headlines and AI regulation looks like it eased up in 2026. The regulator who actually examines your bank, insurer, or health system never slowed down.

State AI laws stalling in 2026 does not mean AI oversight eased up. Bank examiners, health IT certifiers, insurance regulators, and the EU all kept enforcing their own AI rules on schedule. If your business sits in banking, healthcare, insurance, or has EU exposure, those sector rules are your real compliance deadline, not the state law headlines.

Which AI Rules For Regulated Industries Actually Stayed On Schedule?

Three regulatory tracks moved on their original 2026 timelines while general state AI laws slipped or narrowed: bank model risk guidance, healthcare's first federal AI transparency rule, and insurance's AI governance bulletin. None of them made the headlines a state repealing its own AI law did. All three are the rules an examiner, a certifying body, or a state insurance department actually applies to your business right now.

That gap between what gets covered and what gets enforced is where most compliance programs lose ground. A state AI statute is easy to track because it shows up in the news. A supervisory letter or a certification deadline does not, and it is usually the one with a real exam attached to it.

We see this gap play out the same way across client environments in all three sectors. Leadership tracks the state AI bill because someone forwarded an article about it. Nobody owns the supervisory letter, the certification bulletin, or the model bulletin, because those documents never made it onto anyone's reading list. The exam finding, the certification denial, or the consent order that follows is rarely a surprise to the regulator. It is almost always a surprise to the business.

What Your Bank's Examiner Just Got New Instructions On

On April 17, 2026, the Federal Reserve, the Office of the Comptroller of the Currency, and the FDIC replaced the model risk guidance that had governed banks since 2011. The revised interagency guidance, issued as SR 26-2, is explicitly risk based. The Fed says it is most relevant to institutions with more than $30 billion in assets, scaling expectations so a community bank is not held to the standard built for the largest banks.

The detail that deserves more attention than it got: generative and agentic AI tools are excluded from the guidance's formal scope. The OCC's companion bulletin confirms the agencies plan a separate review of those tools later. That exclusion is not permission to skip governance on a chatbot or an agent built on a large language model. It means no examiner has an interagency rulebook to hand you for that category yet, so the burden sits with your institution to document risk controls, testing, and an escalation path before an exam finds the gap first.

What A Bank Or Credit Union Should Document Now

A model inventory naming every AI system touching credit, pricing, or fraud decisions, testing records for accuracy and disparate impact, and a defined retraining or retirement process cover most of what SR 26-2 expects of a traditional model. Apply that same discipline voluntarily to anything generative or agentic, since that is exactly where the next interagency review is headed. If your compliance team needs a structured way to close that gap, Securafy's AI regulatory compliance services map your current AI use against the guidance your examiner is already applying, rather than the guidance from 2011 your program may still be built around.

The cost of getting this wrong shows up at exam time, not before. A matter requiring attention on model governance triggers a remediation timeline, added reporting to the board, and a follow-up exam that consumes staff hours your compliance team did not budget for. None of that requires a new law. It only requires an examiner opening SR 26-2 and asking to see the model inventory and the generative AI controls you have not documented yet.

The HTI-1 Deadline Already Passed You By

The Office of the National Coordinator for Health Information Technology finalized its HTI-1 rule in 2024, the first federal transparency requirement for predictive algorithms built into certified health IT. Developers must give clinicians source attributes covering what data trained a predictive decision support tool, how to use it, and how it performs on validity and fairness against local data. If you run a hospital system, a health IT vendor, or a practice licensing AI-driven clinical software, this rule is already live, not pending.

The certification program updates tied to HTI-1, including the move to USCDI v3 as the new baseline data standard, took effect January 1, 2026, on schedule. No delay, no rewrite, no special session. A health system that spent 2026 tracking Colorado's AI law while treating HTI-1 as a routine IT upgrade had its priorities backward. The body that actually certifies your systems did not blink.

For a health IT vendor, missing a source attribute requirement is not an abstract compliance gap. It can stall certification renewal, which stalls the contracts and procurement approvals that depend on that certification. For a hospital buying the software, it means asking a vendor for documentation it may not have prepared yet, on a timeline the hospital does not control. Either way, the delay lands on patient-facing operations, not on a compliance spreadsheet nobody reads.

What The NAIC Bulletin Requires, Regardless Of State Headlines

Insurance carriers answer to a track that never paused for a legislative session either. The NAIC's Model Bulletin on the Use of Artificial Intelligence Systems by Insurers requires a written AI program with named governance accountability, documented testing for bias and validity, and it holds the insurer responsible for a third-party AI tool's behavior even when a vendor built it. Nearly half the states had formally adopted the bulletin as of last year according to a state-by-state legal tracking analysis, with more joining since. That obligation runs independent of whatever a state's general AI statute says this quarter.

The vendor liability piece is the one carriers underestimate most. If you license a claims triage model or an underwriting tool from a third party and cannot produce testing records for it, the bulletin does not let you point at the vendor during an examination. Your state insurance department examines you, and it will expect your organization to answer for a tool it did not build. Building that documentation before an exam is far cheaper than building it during one.

Does The EU's Delay Give US Companies More Time?

The EU deferred one deadline, not the whole law, and the part that stayed in place is the part most US businesses with EU exposure need to act on now. The Digital Omnibus on AI entered into force on July 27, 2026, six days before the original deadline for high-risk AI system obligations. The deferral pushes standalone high-risk systems under Annex III to December 2027 and AI embedded in products already covered by EU product safety law to August 2028.

What did not move: the prohibited practices regime, in force since February 2025, and the transparency and AI content labeling duties, which stayed on their original date. A US company selling software into the EU, training an EU workforce on an AI tool, or shipping a product with an embedded AI feature to EU customers is already subject to both, whether or not it ever touches a high-risk system under Annex III.

What Should You Actually Prioritize This Quarter?

Prioritize the regulator that examines you directly over the general AI statute making news in your state. A bank's examiner cares about SR 26-2. A health system's certifying body cares about HTI-1. An insurer's state department cares about the NAIC bulletin. A company with EU customers cares about the rules already in force today, not the Annex III date two years out.

These sector rules keep pointing back to the same underlying structure. The NIST AI Risk Management Framework organizes AI governance around four functions: govern, map, measure, and manage. A written governance structure, a current system inventory, documented testing, and an ongoing incident process satisfy the spirit of SR 26-2, HTI-1, and the NAIC bulletin at the same time, because all three were built on the same underlying risk logic.

What that looks like differs by sector, and the differences are worth naming:

  • A bank or credit union names an owner for every model touching credit, pricing, or fraud, and extends that ownership voluntarily to its generative and agentic tools ahead of the next interagency review.
  • A hospital or health IT vendor keeps the source attributes behind every predictive decision support tool current and ready to hand a clinician, not archived for an audit that happens once a year.
  • An insurer treats its written AI program as covering every vendor model it uses, not only the ones it built, since the NAIC bulletin holds the carrier responsible either way.
  • A company with EU customers, EU vendors, or an EU trained workforce confirms today that it is not running a prohibited practice and that its transparency obligations are already met.

A durable program starts with a factual picture of where you actually stand, not a guess built from whichever law made the news last. Running a cybersecurity assessment gives you that baseline, mapped against the sector rules that actually apply to your business, before an examiner or certifying body finds the gap for you. If your leadership team is comparing vendors and controls against a broader standard, the Cybersecurity Buyer's Guide is a useful reference for what a defensible program looks like heading into next year.

Sector rule 2026 status Who it answers to
Bank model risk management (SR 26-2) Took effect April 17, 2026, on schedule Federal Reserve, OCC, FDIC examiners
ONC HTI-1 certification baseline (USCDI v3) Took effect January 1, 2026, on schedule ONC health IT certification program
NAIC Model Bulletin on AI Nearly half the states adopted, still growing State insurance departments
EU AI Act prohibited practices and transparency duties In force since February 2025 and August 2026 EU market surveillance authorities

Where To Go From Here

Your actual regulator is not waiting for state legislatures to sort out AI law, and your compliance program should not wait either. Close the gap between what your examiner, certifying body, or state department already expects and what your team can currently document.

If your team is moving faster with AI than your guardrails are, start with structured training rather than another tool. Securafy AI University gives your people role-based AI training with security built into the material, not bolted on afterward.

If you would rather talk through your specific environment first, book a strategy call with Securafy and we will walk your current AI usage, exposure, and the fastest path to safe adoption.

Ric Hall
Ric Hall

Ric Hall is the Chief Revenue Officer at Securafy, with decades of experience in enterprise infrastructure, cloud technology, sales leadership, and business strategy.

He writes for leaders trying to make sense of big technology decisions without getting trapped in vague promises or polished sales language. His articles cover provider selection, IT budgeting, co-managed services, cybersecurity investments, modernization, and the questions businesses should ask before signing a contract.

Ric’s strength is connecting technical decisions to business outcomes, helping leaders understand not just what they are buying, but why it matters and whether it will still make sense 3 years from now.

Writes about: IT budgeting, provider evaluation, cybersecurity ROI, co-managed IT, cloud modernization, vendor selection, technology strategy

More from Ric Hall

Learn AI by building with it

AI University helps teams move beyond AI curiosity through practical lessons, secure workflows, guided experiments, and real projects built for everyday business use.

Explore AI University

Stay current on practical business AI

Get practical updates on AI security, governance, tools, compliance, and implementation without the daily hype cycle.

Join the conversation

Have a question or a different take on this? Add it below.