Reading, 9 September 2026. California, Texas and Utah added 10 September 2026
The European reading put four questions to a law, a certification scheme, a controls catalogue and a governance framework. This asks the same four of the United States, where five of the seven are already in force rather than approaching.
Where these require a record of what an automated system did, do they require it to say who authorised or reviewed a consequential decision, and to be checkable by somebody other than the party that produced it?
Seven instruments now, across six jurisdictions. Five are in force today and two apply from 1 January 2027. They differ more than the European set did: one requires an audit and no record, one requires four years of records, one prohibits a purpose rather than an outcome, and one defines the human reviewer in three properties and then asks for a record of none of them.
| Instrument | What decides a breach |
Record required | Who reviewed |
Shown unaltered | Retention stated |
|---|---|---|---|---|---|
| Colorado SB 26-189 from 1 Jan 2027 |
records and notice | required | absent | absent | required |
| NYC Local Law 144 in force since 2023 |
audit and notice | absent | absent | absent | partial |
| Illinois HB 3773 in force since 1 Jan 2026 |
effect and notice | absent | absent | absent | absent |
| Texas HB 149, TRAIGA in force since 1 Jan 2026 |
intent | absent | absent | absent | absent |
| Utah Artificial Intelligence Policy Act in force since 1 May 2024 |
notice on demand | absent | absent | absent | by agreement |
| California FEHA, automated-decision systems in force since 1 Oct 2025 |
effect, records kept | required | absent | absent | required, four years |
| California CCPA, automated decisionmaking technology from 1 Jan 2027 |
rights and notice | absent | defined, not recorded | absent | documents only |
It was added last and it should have been there from the start. These seven do not disagree about how much to require. They disagree about what kind of thing decides whether you are in breach, and that settles what any record is worth before the other four columns are read at all.
A record is evidence of conduct. So an instrument that turns on an intent is one no record reaches, because a purpose is not conduct; Texas says as much when it rules out proving intent from outcomes alone. An instrument that turns on an effect is one no single record reaches either, because an effect is a pattern across people and any one decision is a data point in it. An instrument that turns on a notice is answered at the moment the notice is given. Only where the instrument turns on records does keeping better ones change your position, and that is two of the seven.
Two of the seven make a record part of what decides a breach. None of the seven makes the identity of the person who reviewed part of it.
Two of them say plainly that complying with them settles nothing else. Colorado: compliance with Part 17 “DOES NOT CONSTITUTE A DEFENSE TO AND DOES NOT EXCUSE NONCOMPLIANCE WITH ANY APPLICABLE LAW”, and Part 17 creates no new private right of action, with discrimination liability left to existing state law. Utah: “It is not a defense to the violation of any statute administered and enforced by the division” that generative AI did it. A deployer reading either one as the whole of their exposure has read it backwards.
One cell in the Who reviewed column says something none of the others do. California's privacy regulations define what a human reviewer must be, in three properties, and require one to be designated. They still do not ask anybody to write down that a designated reviewer reviewed anything. That is the last section on this page.
The first column is this reading's shorthand, not a holding. The clause each label came from is recorded with it, an instrument can be enforced in ways its text does not lead with, and none of this is legal advice.
Section 6-1-1703 requires three years of “RECORDS REASONABLY NECESSARY TO DEMONSTRATE COMPLIANCE” and lists them: covered ADMT version identifiers, changelogs, and documentation of material mitigation changes.
Section 6-1-1701(15) separately defines a meaningful human reviewer in six properties, including that they “DOES NOT DEFAULT TO THE SYSTEM OUTPUT”. Not one of the six is demonstrable from a changelog. The full reading is here, with the extracted act committed beside it.
Local Law 144 is the older obligation and the more surprising one. It requires an annual bias audit by an independent auditor, a published summary of the results, and notice to candidates. It requires no record of any individual employment decision.
Across the law and the Department of Consumer and Worker Protection rules together, the word audit occurs 223 times and notice 83. The word record occurs once, in an unrelated penalty schedule about motion picture captioning. The word retain does not occur at all.
Retention is marked partial rather than absent for one reason. Section 20-871(b)(3) requires information about the employer's data retention policy to be available on written request by a candidate or employee, and the Department's implementing rule requires the same information on the employment section of the employer's website. Both require the policy to be disclosed. Neither says what must be retained, for how long, or in what form.
So an employer can comply with Local Law 144 completely, publish an audit summary showing no disparate impact across a year, and hold nothing at all about the decision that was made about any particular candidate.
The audit is statistical and annual. It is a fact about the tool's aggregate behaviour, not about a decision. Someone told they were screened out has a published impact ratio and no record.
Public Act 103-0804 has amended the Illinois Human Rights Act since 1 January 2026. The operative provision, section 2-102(L), is two clauses. It is a civil rights violation for an employer to use artificial intelligence "THAT HAS THE EFFECT OF SUBJECTING EMPLOYEES TO DISCRIMINATION ON THE BASIS OF PROTECTED CLASSES", or to use zip codes as a proxy for them, and it is a violation to "FAIL TO PROVIDE NOTICE TO AN EMPLOYEE THAT THE EMPLOYER IS USING ARTIFICIAL INTELLIGENCE" for those purposes.
The word record does not appear anywhere in the act. Twenty-one pages, nine mentions of artificial intelligence, nine of notice, and none of a record.
So the duty is substantive and the evidence is unaddressed. An employer must not discriminate and must give notice, and nothing says what would show either afterwards. The Department is directed to adopt rules, and the act leaves the content of those rules open.
Those rules do not currently exist. The Department of Human Rights published proposed amendments to Title 44, Part 2520 of the Illinois Administrative Code in May 2026 and then withdrew them, cancelling the hearing set for 10 June 2026. That is reported by law firms rather than read here, and it is flagged as secondary for that reason. The statutory duty is in force regardless.
A note on the source. ilga.gov, the Illinois General Assembly's own site, refused every connection attempted on 9 September 2026. The act was read from the Internet Archive's copy of the same file, and the extracted text is committed beside this page so the reading can be checked without depending on either site staying up.
The Responsible Artificial Intelligence Governance Act took effect on 1 January 2026 and it is the only instrument in this reading whose operative standard is a state of mind. A person may not develop or deploy a system that “intentionally aims to incite or encourage” self-harm or crime. A governmental entity may not deploy social scoring “with the intent to calculate or assign a social score”. And a person may not develop or deploy a system “with the intent to unlawfully discriminate against a protected class”.
Then the act closes the obvious route to proving that: “a disparate impact is not sufficient by itself to demonstrate an intent to discriminate”.
Read those together and the consequence for evidence is unusual. The one thing a population of records is genuinely good for, showing a pattern in outcomes, is expressly not enough on its own, and the thing that would be enough is a purpose that no log holds. A deployer in Texas with immaculate records is in the same position under that section as one with none.
The disclosure duty is worth reading for who it binds. Section 552.051 requires that “A governmental agency that makes available an artificial intelligence system intended to interact with consumers shall disclose” that fact, clearly and without a dark pattern, and a health care provider must tell the recipient of the service. The general duty here falls on the state rather than on private deployers.
The word audit does not occur in the act, nor reviewer, nor tamper, nor unaltered. The word integrity occurs once, in a security exception. The word record occurs four times and not one is about an automated decision: a “record of hand or face geometry” in the biometric definition, two exclusions for audio and video recordings, and an agency records-management item in a sunset review.
The Artificial Intelligence Policy Act took effect on 1 May 2024 and was narrowed by amendments effective 7 May 2025. It is the thinnest instrument in this reading, and the reason is stated in the act itself.
Section 13-75-102 says “It is not a defense to the violation of any statute administered and enforced by the division” that generative AI made the statement, undertook the act, or was used in furtherance of it. Liability lands on the supplier whatever the system did. An act that refuses the machine as an excuse never has to establish what the machine did, and so it never asks anybody to write it down.
What remains is disclosure, and after the 2025 amendments most of it is disclosure on demand: a supplier using generative AI in a consumer transaction must say so “if the individual asks or otherwise prompts the supplier about whether artificial intelligence is being used”, and the question “must be a clear and unambiguous request”. Someone in a regulated occupation must “prominently disclose when an individual receiving services is interacting with generative artificial intelligence”, but only where the use is a high-risk interaction, and the duty is about when the notice is given rather than about what is kept.
There is one retention duty in the whole act and it is unlike any other in this reading. Participants in the AI Learning Laboratory “shall retain records as required by office rule or the participation agreement”. It binds volunteers who joined a programme, and what must be kept is decided by a rule or by a private agreement rather than by the legislature. That is why the table says retention here is by agreement rather than absent.
Otherwise: reviewer does not occur, nor natural person, nor tamper, nor unaltered, nor integrity. Both occurrences of oversight are inside the definition of generative AI, which is one that generates outputs “with limited or no human oversight”: a description of the technology, not a requirement of a person.
The Civil Rights Council's regulations on automated-decision systems under the Fair Employment and Housing Act have been in force since 1 October 2025, which makes them the strongest record obligation for AI in force anywhere in the United States today. Section 11013(c) preserves employment records for four years, running from the making of the record or the personnel action “whichever is later”, and the enumerated list of what that includes names “selection criteria, automated-decision system data” outright.
The definition is wide on purpose. Automated-decision system data is “data used in or resulting from the application of an automated-decision system”, including “data reflecting employment decisions or outcomes”. Inputs and outputs both. And section 11013(c)(4) adds a litigation hold: once a complaint is filed, preserve the relevant records until it is finally disposed of, expressly including the automated-decision system data for the complainant and for “all other candidates for the same position”.
Four years of a deployer's automated decisions must be kept, and nothing asks the kept data to name who reviewed anything or to be shown unedited. Counted across the committed text: the word reviewer does not occur, the phrase natural person does not occur, and neither does oversight, tamper, integrity or unaltered.
So an employer can satisfy the strongest retention duty in the country with four years of records nobody can attribute and nobody can show were not edited afterwards.
The other California instrument is the newer one and it is the only thing in this reading that breaks the pattern. The California Privacy Protection Agency's regulations on automated decisionmaking technology set their own compliance date: a business using ADMT for a significant decision “must be in compliance with the requirements of this Article no later than January 1, 2027”, which is the same day as Colorado.
Section 7001(e) defines ADMT as any technology that processes personal information and uses computation to “replace human decisionmaking or substantially replace human decisionmaking”, and then defines the exception in properties of a person. “Human involvement requires the human reviewer to”:
That is more than any other United States instrument in this reading says about the human. The word reviewer occurs six times in the regulations and the phrase human reviewer occurs six times, so every reviewer here is a human one. Section 7221(b)(1)(A) goes further: a business that wants to avoid offering an opt-out must “Designate a human reviewer” with the authority to overturn the decision on appeal.
And it is a definition, not a duty to record. Meet the three properties and the technology is not ADMT at all, so none of the Article applies. A business's whole position can rest on three properties of a person, and nothing in the regulations asks anybody to write down that any of the three was true of any particular decision.
Section 7222 makes that sharper rather than softer. On a verified request the business must explain the logic of the ADMT well enough to “enable a consumer to understand how the ADMT processed their personal information to generate an output with respect to them, which may include the parameters that generated the output as well as the specific output with respect to the consumer”; the outcome of the decisionmaking process; whether the output “was the sole factor to make the decision”; and, where a human took part in a way that does not meet the section 7001(e)(1) test, “what that human's role was in the decisionmaking process”. And section 7222(j) contemplates a consumer the system was used on “more than four times within a 12-month period”, letting the business answer with a summary of the outputs over the preceding twelve months.
So the business must be able to say, up to a year later, what the system produced about one person and what a particular human did with it. Nothing tells it to keep a record that would answer.
There is one exception in the whole package and it is worth naming precisely, because it is the first time anything in this reading requires a person to be named at all. Section 7152(a)(9) requires a risk assessment report to document “the date the assessment was reviewed and approved, and the names and positions of the individuals who reviewed or approved” it. All three occurrences of the word approve in the regulations are that one provision. It is about a document, not about a decision concerning a person, and the retention that goes with it is over documents too: risk assessments for five years after completion or as long as the processing continues, whichever is later, and cybersecurity audit papers for five years.
The record properties this reading asks about are absent in the same way as everywhere else. tamper does not occur in the regulations, nor does unaltered, nor the phrase audit trail. The word integrity occurs five times and every one of the five is a security phrase, mostly “availability, authenticity, integrity, or confidentiality”, which is a property of a system and not of a record.
A note on the two California sources, since the same standard applies to them as to Illinois above. Both extracted texts are committed beside this page and every count and quotation on this page is recomputed from them by a test. Two things are not in those texts and are secondary. The 1 October 2025 date for the FEHA regulations comes from the Civil Rights Council's rulemaking notice rather than from the regulation. And the privacy text committed here is the text of regulations as submitted, in which the effective date is still an unfilled bracket reading “[OAL to fill in the effective date of these regulations]”; the 1 January 2027 compliance date quoted above is in the text itself, at section 7200(b), and does not depend on that bracket.
Not legal advice, not a compliance assessment, and not an opinion about anybody. Seven instruments, read once each, published so the reading can be checked. Every claim above is a quotation or a count, and a count is cheap to rerun: the extracted texts are in the repository, and a wrong one is an issue naming the section.
An assessor who wants to apply this rather than read it can run their own records against the Colorado mapping directly. The rubric is CC BY and the tooling is MIT.
The readings are CC BY 4.0, which asks for attribution, so the reference is here rather than left to be composed. This block is generated from the page it sits on, so a date that moves here moves in the citation too.
Clifford, T. (2026). What United States rules require of an AI record, and what they leave out. Machine Testimony. https://machinetestimony.org/united-states/
@misc{clifford2026unitedstates,
author = {Clifford, Troy},
title = {What United States rules require of an AI record, and what they leave out},
year = {2026},
note = {Machine Testimony, read 9 September 2026},
url = {https://machinetestimony.org/united-states/},
}
This page carries no DOI. It cites its dated URL, and saying so is the point: a citation naming a deposit that does not exist is worse than one naming a page that does.