Hello, this is Ryuta Hamamoto from TIMEWELL.
Talk US state AI law and the names that surface are always California, Colorado, Texas, New York. I wrote those four as a first map. On Japanese risk assessments, though, I keep watching firms that only track those four get tripped by three others.
Illinois, Utah, Massachusetts. Less press, less spectacle. Still: Illinois HB 3773 took force 1 January 2026; Utah's experiment runs through July 2027; Massachusetts medical AI could pass in 2026.
A third map the four-state map cannot capture.
TL;DR
- Illinois HB 3773: force 1 January 2026. Bans AI employment discrimination + notice duties. Most Japanese firms using global HR tech are in range
- Utah UAIPA: 7 May 2025 amendments pivot light-touch. Regulatory Mitigation Agreement is interesting as a Japanese pilot platform
- Massachusetts SB 2632: medical AI focus; bans AI substituting human judgment in mental health and utilization review; 2026 passage possible
- Complements the four-state map with employment-discrimination, sandbox, and sector-specific philosophies
- Japanese priority order often HR tech → medical AI → consumer generative AI
Why four states are not enough
California, Colorado, Texas, and New York aimed at comprehensive AI regulation: frontier models, high-risk AI, automated decision tools. Abstract concepts applied across AI.
A layer below, other moves run: extend existing law to AI, comprehensive but light, and sector-only.
Illinois HB 3773 does not brand itself "AI regulation." It amends the Illinois Human Rights Act, mid-20th-century anti-discrimination law, and inserts AI. Practically it is among the US's most comprehensive employment-AI regimes.
Utah UAIPA launched in May 2024 as "America's first comprehensive AI law" in headlines, then course-corrected within a year to light-touch in the May 2025 package. I treat Utah as a leading indicator of national direction.
Massachusetts SB 2632 is sector strike: medical only. Japanese medical AI firms partnering with Boston-area healthcare are already in range.
Three states, three logics the four-state map misses. Leave them blank and Japanese teams that prepared for four states walk into unexpected notice violations and litigation risk. I have seen that gap more than once.
AI Security training, taken seriously
A 2-day intensive course fully aligned with OWASP, NIST, ISO/IEC 42001, and METI. Take it as executives, practitioners, or both.
Illinois HB 3773 — classical design: extend existing discrimination law to AI
Governor Pritzker signed 9 August 2024; force 1 January 2026. The statute is short; scope is wide. IDHR draft regulations show how wide.
IDHR's December 2025 draft notice rules list employment AI uses such as:1
- Résumé screening, job targeting
- Computer-based personality and aptitude tests
- Expression, vocabulary, and voice analysis in video/online interviews
- Analysis of third-party data
- Performance prediction and culture-fit assessment
The language is AI that "influences" or "facilitates" employment decisions. Even if a human decides, AI ranking or recommendation is enough. That overlaps heavily with EU AI Act Annex III employment.
Employer duties:
- Written notice to applicants and employees about AI in employment decisions
- Notice at first presentation + annual refresh + new tool introduction
- Post physically and online (HR portals, ATS)
- Duties extend to agents (recruiters, headhunters)
Penalties inherit the Human Rights Act: actual damages, civil penalties, attorneys' fees, corrective orders. Not flashy dollar caps, but class-action friendly. That is the max risk point.
If you use global HR tech, you almost certainly touch Illinois. Workday, SAP SuccessFactors, Greenhouse, HireVue, Pymetrics: any feature used against Illinois residents can be in. "We do not use AI" often still means an ATS scoring engine is in scope.
Does your ATS vendor's marketing page say "AI ranking" while your internal policy says you do not use AI for hiring? That tension is exactly where Illinois risk sits.
Further reading on comprehensive vs intent-based states: Texas TRAIGA × New York RAISE Act and Colorado CAIA repeal and ADMT replacement.
Utah UAIPA — light-touch pivot and Regulatory Mitigation Agreement
Utah is the odd one out. May 2024 UAIPA (SB 149) was billed as first comprehensive AI law. After industry pressure it was hollowed out within a year.
Four simultaneous amendments force 7 May 2025 (SB 226 / SB 332 / HB 452 / SB 271):2
- SB 332: sunset extended from May 2025 to 1 July 2027
- SB 226: disclosure limited to "high-risk AI interaction"
- HB 452: new mental-health chatbot rules
- SB 271: narrower consumer generative-AI definitions
"High-risk AI interaction" under SB 226 requires both:
- Collection of sensitive personal information (financial, medical, biometric, etc.)
- Advice material to significant personal decisions (financial, legal, medical, mental health)
Casual chatbots and general information generative AI fall out of disclosure. Largely granting major LLM providers' ask not to force ChatGPT-style disclosure for every dialogue.
In 2026, HB 320 (Office of Artificial Intelligence Policy Amendments) strengthens the Office of AI Policy. Two mechanisms matter:3
First, Regulatory Mitigation Agreement. When AI conflicts with existing state rules, the Office and a firm can agree time-boxed regulatory relief. Example: a 12-month trial of AI medical advice under set conditions despite physician-practice law friction.
Second, AI Learning Laboratory Program. The Office studies AI on pilot basis and can revise state law. Close to the UK AI Growth Lab structure of a learning regulator.
Penalties: max USD 2,500 per violation. Light by design. I read UAIPA as a real pilot arena. Japanese firms wanting US AI pilots can now seriously choose Utah over California.
Massachusetts SB 2632 — medical AI only
SB 2632 is medical-sector legislation. Favorably reported 16 October 2025; as of May 2026 with the Joint Committee on Health Care Financing.4
Two cores:
First: mental health limits
- Ban AI making independent treatment decisions in direct patient dialogue
- AI treatment recommendations require licensed professional review
- Explicit informed consent for AI tools
Second: insurer utilization review
- Ban AI fully replacing human judgment on benefit determinations
- Ban AI use that produces discriminatory effects
Not "high-risk AI" comprehensive regulation. A response to concrete problems inside healthcare.
What problems? Major US insurers face class actions since 2023 over AI utilization tools (notably UnitedHealth Group's nH Predict) and high error rates. Patient groups allege AI denial with hollowed human review. Several states are legislating.
If SB 2632 passes, Boston-area medical AI startups (PathAI, Wellframe, Buoy Health, and peers) and Japanese healthcare partners feel it directly.
I expect the logic to spread beyond medicine to other licensed professional judgment: legal tech, financial advice, education assessment. Watch that spill even if your product is not medical today.
Overlay the four-state and three-state maps
By philosophy:
| Philosophy | States | Core logic | How it hits Japanese firms |
|---|---|---|---|
| Comprehensive high-risk | California, Colorado (repealed) | Risk base, impact assessments | Pressure to redesign whole products |
| Intent-based | Texas | Punish only malicious harm | Inventory prohibited-practice AI |
| Frontier-only | New York, California SB 53 | Majors only, 72-hour reporting | Japanese firms almost out of scope |
| Existing discrimination extension | Illinois | Extend existing law to AI | Most HR tech users covered |
| Light-touch / sandbox | Utah | Light rules + mitigation agreements | Lawful pilot arena |
| Sector-specific | Massachusetts | Medical and similar slices | Medical AI / mental-health chatbots |
Six categories make the point: US state AI law cannot be read as one philosophy. Unlike the EU AI Act's single logic, the US is no federal AI statute while each state regulates different domains with different logic.
Compliance officers struggle to keep the map straight. My first advice: decompose by use case, not by state. HR tech, medical AI, consumer generative AI, financial AI, education AI, then map which state philosophy hits. Most products concentrate in three or four of the six categories.
The three-state map covers what four-state maps miss: HR tech → Illinois, medical AI → Massachusetts, consumer generative AI → Utah.
WARP SECURITY — six philosophies into one organization
One company, one AI governance policy, six US categories. Not solvable by reading statutes alone. You need product inventory, state-by-state in/out/grey, and prioritization.
TIMEWELL's WARP SECURITY workshop systemizes "six categories × your AI products." Leadership leaves with philosophy maps and priority judgment; legal and engineering leave with use-case checklists and notice samples.
Illinois HB 3773 has been in force since 1 January 2026, and many Japanese HR teams still cannot decide whether their ATS is in. Workshops walk ATS, recruiting SaaS, and interview-video tools against real screenshots and contract drafts.
Utah's Regulatory Mitigation Agreement is reviewed as a "lawful pilot arena" path with Office of AI Policy docs. Massachusetts medical AI gets contract-clause checklists for Boston-area partnerships.
Not statute comparison for its own sake. Down to "what do we change on our AI product tomorrow." That is the design idea.
Latest developments as of August 2026
The US stays federal-absent and state-fragmented; the EU applies one statute in phases. The general application date of the EU AI Act (Regulation (EU) 2024/1689) is 2 August 2026. One misconception is worth killing first: high-risk AI does not become fully applicable on that date.
What starts on 2 August 2026 is mainly:
- Chapter IV (Art. 50 transparency obligations) — disclosure for AI interaction and synthetic content
- Chapter III Section 5 (Arts. 40–49) — harmonised standards, conformity assessment, CE marking, registration
- Art. 101 — the Commission's power to fine GPAI model providers
- Chapter VI and Chapters VIII–XI
The substantive high-risk requirements (Chapter III Sections 1, 2, 3) were pushed back by the amending Regulation (EU) 2026/1744 (the Digital Omnibus: adopted 8 July 2026, published in OJ L 2026/1744 on 24 July 2026, in force 27 July 2026). They apply to Annex III high-risk AI (Art. 6(2)) from 2 December 2027 and to Annex I product-embedded high-risk AI (Art. 6(1)) from 2 August 2028. The authorised representative duty (Art. 22), value-chain duty (Art. 25), deployer obligations (Art. 26) and the fundamental rights impact assessment (Art. 27) likewise start on 2 December 2027 for Annex III systems.
Fines run up to €35 million or 7% of global turnover for prohibited practices (Art. 5) and up to €15 million or 3% for GPAI and other breaches, whichever is higher (Regulatory framework on AI, European Commission). Note that the prohibited practices (Art. 5) and AI literacy (Art. 4) have applied since 2 February 2025, and the GPAI chapter (Chapter V) plus the penalty provisions (Arts. 99 and 100) since 2 August 2025.
Illinois HB 3773 employment AI overlaps EU Annex III high-risk, but the timelines differ: Illinois has been in force since 1 January 2026, while the EU's Chapter III duties reach the same employment AI from 2 December 2027. Firms mapping the three US states should inventory the same HR tech and medical AI against EU duties date by date — which obligation, from when. Organizational governance: Governed enterprise AI agents.
Summary
If I had to rank Monday work for most Japanese SaaS teams: Illinois notice and ATS inventory first. Quiet statutes, real class-action risk.
- Illinois HB 3773 live 1 January 2026. Most HR tech users covered
- Utah UAIPA pivoted light-touch May 2025; Regulatory Mitigation Agreement is a pilot arena
- Massachusetts SB 2632 medical strike; bans AI substituting human judgment in mental health and utilization review
- US state AI law has six philosophy categories. Four-state maps have holes
- Japanese firms should map by use case (HR tech / medical AI / consumer generative AI)
Quiet states impose real cost. Illinois especially is entering the phase where class-action risk surfaces. Across two decades of US regulation I have watched quietly moving states work compliance teams hardest. Next on the treadmill: Japanese firms running HR tech and mental-health chatbots.
Further reading: California's three AI statutes, Texas TRAIGA × New York RAISE Act, US federal AI policy 2026.
References
- Legal Update: New Illinois AI Law Requires Employee Notice - Seyfarth Shaw
- Artificial Intelligence in Employment (Public Act 103-0804) - Illinois DHR
- New Utah AI Laws Change Disclosure Requirements - Perkins Coie
- Legislation in Massachusetts Addresses AI for Mental Health and Utilization Review - Hooper Lundy






