AI Policy
Federal jurisdiction over AI splits across agencies by what the application does, not by the fact that it is AI. The states are not waiting for Congress to sort that out. If you build, buy, or deploy AI in the Northeast Corridor, your exposure is a federal question and a five-jurisdiction question at the same time.
Federal
The only major AI provisions enacted in the 119th Congress rode in on the FY2026 National Defense Authorization Act, signed in December 2025 as Public Law 119-60. Those provisions cover Department of Defense AI security, model tampering, and adversarial risk. They do nothing for a company selling AI into healthcare, finance, or transportation.
Everything else is still in committee. Roughly fifty AI bills are pending across both chambers, and the ones with actual momentum are narrow: AI innovation sandboxes for financial regulators, whistleblower protections, defense and China competition provisions. The comprehensive bills, from algorithmic accountability to a federal AI civil rights framework, have not moved.
The fight worth watching is preemption, and it is not happening primarily in Congress. There is a live House proposal to impose a multi-year moratorium on state AI laws in favor of a national framework, but the faster-moving instrument is money. A December 2025 executive order threatened to withhold federal broadband deployment funds from states with AI laws the administration considers "onerous." That threat is already changing state behavior. Virginia shelved most of its 2026 AI bills over it, with more than eight hundred million dollars in broadband funding on the line.
Read that carefully if you are building a compliance program. The state patchwork is not expanding uniformly. It is expanding where states are willing to risk federal funding and contracting where they are not.
The state patchwork is not expanding uniformly. It is expanding where states will risk federal funding and contracting where they will not.
State by State
Maryland has enacted AI legislation in three consecutive sessions, and almost no company operating here can name any of it.
The state regulated its own AI use first. The Artificial Intelligence Governance Act of 2024, Chapter 496, required state units to inventory their AI systems, directed the Department of Information Technology to set policy for how AI gets developed, procured, and deployed, and created a Governor's AI Subcabinet. If you sell AI into a Maryland agency, that law shapes what you will be asked to document.
Then it moved outward. A 2025 law now requires carriers, pharmacy benefit managers, and private review agents using AI in utilization review to meet standards for human clinical oversight, transparency, auditing, and nondiscrimination. Maryland has regulated AI in coverage decisions since 2025, which most trackers miss because a separate 2026 insurance bill was withdrawn under industry pressure.
The 2026 session added three more. Chapter 445 extended identity fraud law to cover AI and deepfake impersonation, with penalties reaching ten years and a private right of action for victims, effective October 1, 2026. Chapter 634, the Artificial Intelligence Ready Schools Act, directs the State Department of Education to publish AI guidance and build the evaluative rubric local school systems will use to assess AI tools. Chapter 434 created a Maryland 3-1-1 Oversight Board and an AI-driven 3-1-1 program, passing 45 to 0 and 133 to 0.
Maryland publishes its own AI governance policies, strategy, and a public inventory of the systems its agencies actually use. If you are selling AI into state government, the buyer has already published its requirements. Very few vendors have read them.
New York has the most consequential pending AI bill in the corridor, and it is further along than most people tracking it realize.
S1169B, the New York AI Act, sponsored by Senator Kristen Gonzalez, passed the Senate 48 to 13 on June 3, 2026 and was delivered to the Assembly. Its companion there is A8884.
It reaches developers and deployers of high-risk AI systems, meaning systems that are a substantial factor in a consequential decision about employment, housing, health care, financial services, education, or legal services. The obligations are real: third-party audits on a fixed schedule, reports filed with the Attorney General, a documented risk management program benchmarked to the NIST AI Risk Management Framework, whistleblower protections, and an outright ban on social scoring. Enforcement runs through the Attorney General, with civil penalties up to twenty thousand dollars per violation. It takes effect one year after signature, with the audit requirement phased to two years.
The strategic point is the history. This bill passed the Senate once before, 51 to 8 in June 2025, and then died in the Assembly in January 2026. It has now passed the Senate twice. The chokepoint has never been the Senate.
There is a third layer above the state. New York City already regulates automated employment decision tools through Local Law 144, requires agencies to report algorithmic tools under Local Law 35, and in November 2025 the City Council approved a package creating an Office of Algorithmic Accountability. If you sell into city government, the municipal framework is ahead of the state one and is what you will hit first.
New Jersey has the most AI bills in the corridor and the least movement. Seven are active in the current Legislature. None have cleared committee.
The one with real money behind it would stand up Economic Development Authority programs to help New Jersey startups and small businesses adopt AI, with a $175.5 million appropriation attached. If you sell AI into small and mid-size business, that is the bill to track.
On the infrastructure side, two competing bills would require energy usage plans for AI data centers and mandate that their electricity come from new clean energy sources. The versions differ in scope and compliance mechanics, which means reconciliation friction before either moves.
The rest span news media AI oversight, a state Office of Cybersecurity Infrastructure with AI provisions, AI in long-term care, and criminal provisions on AI-generated exploitative content.
Virginia is the corridor's most instructive jurisdiction, and it is routinely misread as inactive.
In 2025 the General Assembly passed the High-Risk Artificial Intelligence Developer and Deployer Act, which would have made Virginia the second state after Colorado with a comprehensive AI law. The governor vetoed it on March 24, 2025, arguing the framework would burden small firms and startups.
What survived the veto is what most companies miss. Executive Order 30 directed the Virginia Information Technologies Agency to publish AI policy and IT standards binding on executive branch agencies. Any AI product or service sold into a Virginia state agency has to meet those standards. For anyone selling AI into Virginia government, that is the operative requirement today, and it sits in procurement rather than in statute.
The 2026 session produced two AI laws and a lot of deferral. One directs the Board of Education to issue AI safety guidance for instructional settings and establishes a pilot program, passing 95 to 0 in the House. Another tasks the Joint Commission on Technology and Science with evaluating frameworks for independent organizations that would verify AI models, with findings due November 1, 2026.
Everything else stalled. Chatbot rules for minors, AI in insurance claims handling, AI in mental health treatment: continued to 2027. The House committee chair applied three tests before advancing any AI bill, and one was whether it conflicted with the federal executive order conditioning broadband funding on states avoiding heavy AI regulation.
That is the real Virginia story. The legislature is not uninterested. It is being disciplined by federal money.
DC's AI work has centered on algorithmic discrimination, and the story is one of repeated introduction without enactment. The Stop Discrimination by Algorithms Act originated in the Attorney General's office and would extend civil rights protections to automated decisions about employment, housing, credit, education, and public accommodations, with notice, disclosure, and audit obligations attached. It drew a full hearing and broad civil rights support, then stalled at the close of the 2022 Council period. It was reintroduced in 2023 and did not advance.
Treat the pattern as the signal. A bill with the Attorney General behind it, organized advocacy support, and organized business opposition, cycling through Council periods without a markup, tells you exactly where the friction sits.
For most organizations the nearer-term DC exposure is not the Council anyway. It is the overlay: federal procurement rules, federal agency AI policy, and District licensing requirements that apply to operating in the city regardless of what technology you run.
Practical Implications
If you build or sell AI
Identify your primary federal regulator first. Every AI application has a dominant regulatory home even when it touches several agencies. Then map secondary exposure, which is the part companies consistently underestimate. Then prioritize states by where your customers are and where the regulatory activity actually is. New York and Maryland behave differently than Virginia, and pretending otherwise is how compliance budgets get spent twice.
If you are government or publicly funded
The questions are procurement and accountability, not compliance. What do you require of vendors. Who audits the system after deployment. Which body holds oversight, and does it exist yet. Maryland's AI Governance Act, its 3-1-1 Oversight Board, and Virginia's VITA standards are the working templates for agency-level AI governance in this corridor, and all three are still being built out.
Most organizations discover their AI exposure after they have built the program. Mapping it first is cheaper. Start with a conversation about what you are building, where you operate, and who regulates it.