AIセキュリティ

US Federal AI Policy 2026 — Trump's December Order and DOJ Intervention Split State Law: What Japanese Companies Should Do

Published2026-05-20Updated2026-08-01Ryuta Hamamoto

On 27 April 2026 a federal court paused enforcement of Colorado's AI Act (SB24-205). Three days after DOJ intervened in xAI v. Weiser.

US Federal AI Policy 2026 — Trump's December Order and DOJ Intervention Split State Law: What Japanese Companies Should Do
Share

Hello, this is Ryuta Hamamoto from TIMEWELL.

On 27 April 2026 a federal court paused enforcement of Colorado's AI Act (SB24-205). Three days after DOJ intervened in xAI v. Weiser. The first clear case of the federal government functionally nullifying a comprehensive state AI law.

Read that alone and the US looks fully deregulatory. Same April: New York's RAISE Act is on a force path, California Governor Gavin Newsom signed a counter-EO, Governor Polis refused to withdraw state law. The US is in an unprecedented split of federal deregulation and preemption versus state strengthening.

I keep hearing the same line from HQ legal: "federal is loosening, so we can wait." Chase only federal policy and you miss fines triggered by serving a single state resident.

TL;DR

  • Trump December order (11 Dec 2025) started a three-step federal override path against state AI laws. Months to years to bite, but Colorado already shows one win
  • AI Litigation Task Force (9 Jan 2026) is expected to target CA SB 53, TX TRAIGA, NY RAISE Act next
  • State governors (CA, CO, NY) say they will keep enforcing; Congress deliberately dropped preemption from FY2026 NDAA
  • NIST AI RMF downgraded for federal procurement but still de facto for private and state. Japanese firms: NIST + ISO/IEC 42001 + AI Business Operator Guidelines
  • Practice: match the stricter of federal and state. Overshoot strategy

What the December order launched

The 11 December 2025 executive order "Ensuring a National Policy Framework for Artificial Intelligence" was a break from prior deregulation rhetoric by actively intervening against state law.

Four instructions:

  1. Attorney General: stand up AI Litigation Task Force within 30 days (done 9 Jan 2026)
  2. Commerce Secretary: report on "excessive" state AI laws within 90 days (deadline 11 Mar 2026; still unpublished as of 20 May 2026)
  3. FTC Chair: within 90 days, policy statement that state laws forcing alteration of truthful AI model outputs are preempted by FTC Act Section 5
  4. BEAD residual funds (~USD 420M): disqualify states with "excessive" AI laws

Carve-outs: child protection, AI compute/data-center infrastructure, and state government's own procurement/use.

Read carefully: the White House is chasing federal control of the regulatory reins, not pure deregulation. Republican administrations cannot accept states out-hardening federal policy. That distinction matters when you brief a board that only heard "AI deregulation."

AI Litigation Task Force — what Colorado shows

The Task Force is the order's sharpest tool. DOJ stood it up 9 January 2026 from Civil Rights, Antitrust, and Civil Divisions. Mission:

  • Argue 14th Amendment equal-protection violations against state AI laws
  • Argue federal preemption (FTC Act, communications, copyright)
  • Argue Commerce Clause violations

First battle was fast. xAI sued Colorado 9 April 2026; DOJ intervened 24 April arguing Colorado's unintentional-discrimination duties plus diversity safe harbors violate equal protection; court paused enforcement 27 April.1

Tactically large. My shortlist for next targets: CA SB 53, TX TRAIGA, NY RAISE Act. All enacted, all in operations.

Limits matter. As BakerHostetler notes, Commerce report → DOJ suit → injunction takes considerable time.2 Two to three years to finality is plausible. Japanese firms must operate under legal uncertainty throughout. Waiting for "clarity" is itself a risk decision.

AI Security training, taken seriously

A 2-day intensive course fully aligned with OWASP, NIST, ISO/IEC 42001, and METI. Take it as executives, practitioners, or both.

Three limits on preemption

Limit 1: EOs do not preempt state law. Institute for Law & AI: executive orders have no preemptive power; the president cannot unilaterally void state statutes.3 Congress or federal courts must finish the job.

Limit 2: Dormant Commerce Clause often fails. Most state AI laws regulate in-state and out-of-state firms alike. Ropes & Gray: economic-protectionism DCC claims will succeed only narrowly.4

Limit 3: Congressional caution. Final FY2026 NDAA intentionally excluded federal preemption of state AI laws after bipartisan pushback. A signal against blanket preemption.

Brookings' segmented approach is worth watching: federal preemption for model development; state residual power for use. A plausible legislative landing zone, if Congress ever lands.

Governors push back — Newsom, Hochul, Polis

Newsom (CA) signed a provocatively titled EO on 30 March 2026 ("As Trump rolls back protections…"), hardening state procurement and "responsible policy" requirements for AI vendors dealing with the state. SB 53 continues.

Hochul (NY) attacked the order as holding rural broadband funds hostage to shield big tech from basic AI-harm measures. BEAD conditionality as pressure on weaker communities.

Polis (CO) is more complex: he signed SB24-205 with reservations and delayed force to 30 June, but did not withdraw after the December order. The April pause came from the xAI court order, not gubernatorial retreat.

Common stance: threaten judicial challenge to BEAD freezes while continuing state enforcement. I would not bet the compliance calendar on any of them folding soon.

NIST AI RMF "de facto downgrade" and federal procurement

Quiet but important. Biden-era OMB M-24-10 treated NIST AI RMF as recommended best practice. Trump-era M-25-21 (AI use) and M-25-22 (AI procurement), issued 3 April 2025, removed direct NIST references, encouraging agency-specific guidelines instead.

M-25-22 applies to new and updated federal contracts from 1 October 2025: data-use limits, vendor lock-in avoidance, IP/data ownership clarity, continuous performance monitoring. Japanese firms with direct federal contracts (defense, space, healthcare) must map here.

NIST AI RMF is not dead. SB 53 frontier frameworks, state procurement, and private risk management still treat it as de facto standard. Rational Japanese stack:

  • Federal procurement: M-25-22 + agency-specific guidance
  • State/private: NIST AI RMF core
  • Global base: ISO/IEC 42001 AIMS

Add Japan's AI Business Operator Guidelines for a US–Japan–EU unified spine.

Japanese practice — take the overshoot strategy

First, "federal only" fails. Texas TRAIGA covers anyone doing business in Texas or serving Texas residents. No Texas office required. CA SB 53, CO SB24-205, and NY RAISE each have their own reach.

Second, surface compliance limbo. US Chamber research: 65% of small businesses fear higher multi-state AI compliance cost; industry estimates ~17% add-on to AI operating cost. HQ Japan often undersees state-level hidden cost. Share that with boards first.

Third, overshoot. Design internal controls to the stricter of federal and state:

  • Frontier models (over 10²⁶ FLOPs): meet SB 53 / RAISE frontier framework duties
  • High-risk domains (employment, housing, credit, education): prepare Colorado-style impact assessments
  • Marketing: FTC AI-washing enforcement (Workado litigation, Cleo AI USD 17M settlement examples)

Matching the strictest state looks expensive until you price waiting for either litigation freezes or governor counter-EOs. Overshoot is cheaper long term. That is my working recommendation, not a theory.

Compare with the EU side — the amending act Regulation (EU) 2026/1744 (Digital Omnibus; adopted 8 July 2026, published in the OJ 24 July 2026, in force 27 July 2026) — in EU AI Act: what actually starts on 2 August 2026 — high-risk AI lands in December 2027 and August 2028. US–EU approach differences are design premises for global controls.

Where WARP SECURITY fits

TIMEWELL's WARP SECURITY uses this federal–state stack as one of five tabletop incident modules.

Executive track: who owns AI governance (CDO, CISO, CLO) under "federal light, state hard," and whether to stand up a cross-cutting AI governance committee. Critical for firms with high US revenue share.

Operator track: hands-on layering of NIST AI RMF + ISO/IEC 42001 + METI AI Business Operator Guidelines. Inventory, impact-assessment templates, frontier-framework shells on the company's own cases.

Legal alone cannot answer "federal or state?" Leadership, ops, and counsel need the same room.

Latest developments as of July 2026

As of July 2026 the Commerce state-AI report remains unpublished; federal–state split continues. The EU moves: EU AI regulatory framework (European Commission) brings Commission supervision and fining powers over GPAI (Art. 101) into effect on 2 August 2026, with GPAI-related fines up to €15 million or 3% of global turnover, whichever is higher. The amending act, Regulation (EU) 2026/1744, was adopted 8 July 2026, published in the Official Journal 24 July 2026, and entered into force 27 July 2026.

One distinction to keep straight: 2 August 2026 is the AI Act's general application date, not the date high-risk AI becomes fully applicable. What starts that day is Art. 50 transparency duties, the harmonised-standards / conformity-assessment / CE-marking / registration provisions (Arts. 40–49), and Art. 101 above. The substantive high-risk obligations (Chapter III, Sections 1–3) apply from 2 December 2027 for Annex III systems (Art. 6(2)) and from 2 August 2028 for Annex I embedded-product systems (Art. 6(1)). Confusing the two distorts both your sequencing and your budget.

While the US debates federal vs state, the EU enters enforcement. Hold that asymmetry as fact. Building controls to the strict EU side first is the practical path. Enterprise agent control: Governed AI enterprise agents.

Summary

Read "federal is loosening so we are fine," or "split is deepening so prepare." US AI market competitiveness forks on that one choice. I am on the second side.

  • US is in a dual structure: federal deregulation/preemption vs state hardening
  • DOJ Task Force is effective but finality is 2–3 years of uncertainty away
  • CA, CO, NY governors refuse to fold on enforcement
  • NIST AI RMF downgraded for federal procurement; still de facto for state/private
  • Japanese firms: overshoot to the stricter rule

Monday morning: list which US states your product actually serves, then design controls to the hardest of those state rules plus any federal procurement stack you touch. Everything else is commentary.

References

Footnotes

  1. Justice Department Intervenes in xAI lawsuit Challenging Colorado's Algorithmic Discrimination Act - DOJ

  2. Navigating the Emerging Federal-State AI Showdown - BakerHostetler

  3. Executive Preemption and the Dormant Commerce Clause - Harvard Law Review

  4. Examining the Landscape and Limitations of the Federal Push to Override State AI Regulation - Ropes & Gray

This article was produced with the help of AI. A human verified the primary sources and edited the text before publication.

How well do you understand AI?

Take our free 5-minute assessment covering 7 areas from AI comprehension to security awareness.

Share this article if you found it useful

Share

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

Make AI security a skill your team actually has

WARP SECURITY is a two-day intensive aligned with OWASP, NIST, ISO/IEC 42001, and METI guidelines. Executives and practitioners can attend separately.

Related Articles