Assess
Enable
Build
Sustain
Govern
Research
Resources
About
Contact
Governance July 20, 2026

State AI Laws for Investment Firms: Texas, Colorado, and What to Do Now

Author

Dr. Leigh Coney

Founder, WorkWise Solutions

Published

July 20, 2026

Reading Time

16 min read

TLDR: State AI laws reach investment firms mostly through their portfolio companies, not through fund operations. The laws that matter in 2026 target high-risk automated decisions about people, hiring, credit, insurance, housing, essential services, which is where portfolio companies live and where funds rarely do. Texas passed the Responsible Artificial Intelligence Governance Act (TRAIGA), effective January 1 2026, and it gives firms an affirmative defense when they follow a recognized framework such as the NIST AI RMF. Colorado's AI law has been amended, with its effective date moved into the 2026 to 2027 window, so there is no single hard date to quote yet. The pattern across states is consistent enough to plan for: if you or a portfolio company uses AI to decide something consequential about a person, expect obligations, and build a NIST-AI-RMF-based posture that travels across states rather than chasing each statute. For most funds the real work is setting the standard and pushing classification into the portfolio.

1. Do State AI Laws Touch an Investment Firm?

Directly, rarely. Through the portfolio, often. The state AI laws that matter in 2026 target high-risk automated decisions in consumer contexts, hiring, credit, insurance, housing, and access to essential services, and that is where portfolio companies operate. A fund making investment decisions usually sits outside the core scope. The company it owns that screens job applicants or prices loans with AI usually sits inside it.

So the honest answer for an investment firm is split. The adviser's own operations carry thin direct exposure. The portfolio can carry real obligations, and the GP is the party that sets the standard across the companies it controls.

This matters more every quarter, because the number of states writing AI rules is climbing and the rules do not match each other. A firm with portfolio companies in a dozen states cannot afford a separate compliance project per statute. The efficient response is to understand the shared shape of these laws once, then build a single posture that satisfies the common core and adapts at the edges.

This guide maps the two state laws drawing the most attention, Texas and Colorado, shows where a fund or a portfolio company gets caught, and lays out the one posture that works under both and under whatever comes next. For the parallel European analysis, see our guide on the EU AI Act for US private equity.

2. Why the Exposure Sits in the Portfolio

The reason the exposure sits in the portfolio is structural. State AI laws are written to protect consumers and employees from automated decisions that affect their lives, so they bite wherever those decisions get made. A fund's day-to-day, sourcing deals, running diligence, reporting to LPs, does not make consequential automated decisions about members of the public. A portfolio company's day-to-day often does.

Three portfolio settings account for most of the risk. Human resources, where AI screens resumes, ranks candidates, or informs promotion and termination. Lending and financial services, where models approve or price credit. Insurance, where AI underwrites and prices policies. Each is a place a real person is told yes or no by a system, which is exactly what the state laws are built to govern.

There are edge cases where a fund catches direct exposure. An adviser that markets an AI-driven product to retail investors, or that uses an automated system to make eligibility decisions about individuals, can step into scope on its own account. Those are the exceptions. For the typical PE, credit, or family-office firm, the fund's own footprint under these consumer-focused laws is light, and pretending otherwise wastes effort that belongs in the portfolio.

Picture a staffing company in the portfolio that operates in Texas, Colorado, and eight other states, and that uses an AI tool to rank job applicants. That single system can be in scope of Texas's law, Colorado's law, and any employment-focused AI rule the other states pass, all at once. The company does not get to pick which law applies; the applicant's location and the decision's stakes decide it. Managing that system to one strong standard is the only sane way to cover ten jurisdictions without ten separate programs.

The consequence for a GP is a division of labor. The fund sets the governance standard and the reporting expectation. The portfolio company does the classification and carries the obligation, because that is where the regulated activity lives.

3. Texas TRAIGA, Effective January 1 2026

Texas passed the Responsible Artificial Intelligence Governance Act, known as TRAIGA, and it takes effect January 1 2026. For an investment firm and its portfolio companies, the most useful feature is the affirmative defense.

TRAIGA provides that a company which conforms to a recognized AI risk framework, such as the NIST AI RMF, is in a stronger legal position if a claim arises. In plain terms, Texas rewards firms that can show a documented, framework-based AI program. That is a meaningful design choice, because it turns governance from a pure cost into a defense: the same program that helps with an SEC exam and with other state laws also shores up your position in Texas.

A documented, framework-based program is more concrete than it sounds. It means a written AI policy with a named owner, an inventory of the AI systems in use, a risk classification for each, evidence that the high-risk ones have human oversight and testing, and a record that the program runs on a schedule rather than sitting in a binder. That is exactly what the NIST AI RMF asks for, which is why naming it as your framework and actually operating it is the substance of the Texas affirmative defense.

TRAIGA also sets out prohibited uses and places specific obligations on government agencies, and for private firms its consumer-facing reach is narrower than the headlines suggest. The part worth building around is the affirmative defense, because it is the lever a firm actually controls. The rest comes down to knowing whether a given system touches Texas consumers or workers.

The practical move is to make the NIST AI RMF your stated framework and to keep the evidence that shows you actually follow it, not just a binder that names it. Confirm the current statutory text and any implementing guidance with counsel, because the details of scope and enforcement are the kind of thing that gets refined after passage.

4. Colorado's Amended AI Law

Colorado was the first state to pass a broad, high-risk AI law, often called the Colorado AI Act, aimed at automated decision systems and consumer protection. The important 2026 fact is that the law has been amended since it passed, and its effective date has been moved into the 2026 to 2027 window.

The obligations themselves are worth knowing even while the date moves. Colorado's law, in substance, asks firms that deploy high-risk systems to use reasonable care to protect consumers from algorithmic discrimination, to run risk management and impact assessments, to disclose to consumers when a consequential decision is automated, and in some cases to offer a way to appeal or correct it. The amendments adjusted some of these requirements, so confirm the current version with counsel. Even so, the direction is stable, and a NIST-based program produces the same substance, so building toward it now holds its value even if the start date shifts again.

That means there is no single clean date to quote yet. The legislature revised the timeline to give firms more time and to adjust the obligations, so anyone citing a specific day for Colorado should check whether it survived the amendments. Treat the effective date as unsettled, track it with counsel, and hold off on building a rollout plan around a particular day until the amended date is confirmed.

What does not change is the substance. Colorado's law, like the others, targets consequential automated decisions about people and asks for risk management, disclosure, and documentation. Building that underlying posture now is the safe move regardless of the exact start date, because the requirements in substance do not wait on the calendar.

5. The Pattern Across States

Step back from the two headline states and the pattern is consistent enough to plan for. Most state AI laws, in force or in drafting, share the same shape: they target high-risk automated decisions, they focus on consumer and employment contexts, and they ask for governance, disclosure, and a way to contest or explain a decision.

The map is fragmenting rather than converging. A growing number of states are drafting their own versions, and the details differ, which means a multi-state operator faces a patchwork instead of one rule. Chasing each statute separately is a losing game for a firm with companies in a dozen states.

For a multi-state operator, the planning stance that works is to treat the strictest reasonable version as the house standard. If your program satisfies a demanding law like Colorado's in substance, it usually clears the lighter ones by default, and adapting to a new state becomes a matter of confirming a few specifics rather than starting over. Racing to the minimum each law allows produces a brittle patchwork that breaks the next time a legislature moves.

Two practical facts shape how you carry the risk. First, enforcement generally runs through the state attorney general rather than private lawsuits, so the exposure is a regulator inquiry and possible penalties, and the documented program is what you produce when one arrives. Second, the number of states with AI legislation keeps growing, so a firm that operates nationally should assume the map only gets busier.

Both facts point to the same conclusion: standardize on one strong framework and map it to each law as that law lands. When the underlying program is solid, adapting to a new state becomes a documentation exercise rather than a rebuild. That is the posture the next section describes.

6. Does This Touch Us? A Self-Check

Use this as a fast self-check. Answer each question for the fund and for each portfolio company, because the answers usually differ.

Trigger question What it implicates Your move
Do you or a portfolio company use AI to make or substantially inform decisions about people (hiring, promotion, pay, credit, insurance, housing, essential services)? The core trigger for state high-risk AI laws. Inventory these systems first; they carry the most obligation.
Texas customers, users, or operations? Texas TRAIGA, effective January 1 2026. Adopt a recognized framework such as the NIST AI RMF to support the affirmative defense.
Consequential automated decisions affecting Colorado consumers? Colorado's amended AI law, effective date moved into the 2026 to 2027 window. Track the amended date with counsel; prepare risk management and consumer notices.
Is the exposure mostly at a portfolio company rather than the fund? Typical: the consumer-facing decisions live in portcos (HR, lending, insurance). Set the standard at the GP and run classification inside each company.
Purely internal productivity use (drafting, summarizing, research)? Generally outside the high-risk consumer scope of these laws. Light policy and good practice; keep confidential data on sanctioned tools.
Operating in several states with different rules? A fragmenting patchwork, with more states drafting. Standardize on one framework so a single program answers many laws.

The pattern in the table is the point. The fund tends to answer no to the consumer-decision questions and yes to the internal-use question, while the portfolio companies are the reverse. That is why the GP sets the standard and the companies carry most of the obligation.

7. The Posture That Travels: NIST AI RMF

One framework does most of the work across all of this, and it is the NIST AI RMF. Texas names a recognized framework like it in the affirmative defense. Colorado and the other states ask for the same substance it provides. The SEC expects a documented, risk-based program of the kind it describes. Building to the NIST AI RMF once gives you an answer to all of them.

The framework is organized around four functions, which the quote below sets out: Govern, Map, Measure, and Manage. Govern sets the policies and the ownership. Map inventories your AI and its context. Measure tests the systems for the risks that matter. Manage acts on what you find and keeps the record. For an investment firm, that translates into a short, concrete program: an AI policy with a named owner, an inventory of every AI system across the fund and the portfolio, a risk classification for each, controls and human oversight on the high-risk ones, and an evidence file that shows the program actually runs.

Concretely, the artifacts to keep are short and countable: the written policy and its owner, the AI inventory, the per-system risk classification, the oversight and testing records for high-risk systems, the consumer disclosures where they apply, and a change log that shows the program is maintained. A firm that can hand those six things to a regulator has answered most of what any current US AI law asks, and it holds the Texas affirmative defense and an SEC-ready story at the same time.

The value of building to one framework is that it travels. A single program answers Texas, Colorado, the next state, an SEC examiner, and a European regulator, because they are all asking versions of the same question: can you show that you govern your AI on purpose? Do it once, keep it current, and map it outward as new laws arrive.

8. Where to Start

Start by drawing the line between the fund and the portfolio. The fund's job is to set the standard and require the reporting. The portfolio companies do the classification where the regulated decisions actually happen. Most firms find their direct exposure is smaller than feared and their portfolio exposure is less mapped than assumed.

For the firm-level program, our SEC Exam-Ready AI Governance engagement ($17,500) builds the NIST-AI-RMF-based framework and the evidence file that doubles as the Texas affirmative defense and maps to the other states as they land. It is the program you build once and reuse against every regime.

For the portfolio-company work, our Secure AI Adoption engagement ($7,500 per company) puts the sanctioned tools, the usable policy, and the classification in place at each company, which is where the consumer-facing obligations sit. Run the two together and the same posture answers a state regulator, an SEC examiner, and an LP asking how you govern AI. Confirm the current effective dates and statutory text with counsel before you rely on them.

"The AI Risk Management Framework Core is composed of four functions: Govern, Map, Measure, and Manage. These functions help organizations address the risks of AI systems in practice and cultivate trustworthiness across the AI lifecycle."

NIST, AI Risk Management Framework (AI RMF 1.0)

Key Takeaways
  • State AI laws touch investment firms mostly through portfolio companies, because the laws target high-risk automated decisions about people and that is where portcos operate, not the fund.
  • Texas TRAIGA takes effect January 1 2026 and provides an affirmative defense for firms that conform to a recognized framework such as the NIST AI RMF.
  • Colorado's AI law has been amended, with its effective date moved into the 2026 to 2027 window; treat the exact date as unsettled and confirm it with counsel.
  • The common trigger across state laws is using AI to make or substantially inform a consequential decision about a person: hiring, credit, insurance, housing, essential services.
  • Most internal productivity uses (drafting, summarizing, research) sit outside the high-risk consumer scope, so the compliance effort concentrates on a short list of systems.
  • A NIST-AI-RMF-based program (Govern, Map, Measure, Manage) is the posture that travels: one framework answers many state laws and doubles as the Texas affirmative defense.
  • For a GP the move is to set the standard at the fund and run the classification inside each portfolio company, so exposure is managed where it actually sits.

Frequently Asked Questions

Do state AI laws apply to investment firms?

Directly, rarely. Through the portfolio, often. Most state AI laws in force or arriving in 2026 target high-risk automated decisions in consumer contexts: hiring, credit, insurance, housing, access to essential services. A registered investment adviser making investment decisions is usually outside that core scope. A portfolio company screening job applicants, pricing insurance, or approving loans with AI is squarely inside it. So the honest answer for a fund is that its own operations carry thin direct exposure, while its portfolio companies can carry real obligations, and the GP is the one that sets the standard across them. Run the analysis company by company.

What is the Texas Responsible AI Governance Act?

The Texas Responsible Artificial Intelligence Governance Act, known as TRAIGA, is Texas's state AI law, and it takes effect January 1 2026. Its most useful feature for a firm is the affirmative defense: a company that conforms to a recognized AI risk framework, such as the NIST AI RMF, is in a stronger position if a claim arises. In plain terms, Texas rewards firms that can show a documented, framework-based AI program. That is the same program that helps with SEC exam readiness and with other state laws, which is why building it once and mapping it to several regimes is the efficient path. Confirm the current text and any implementing guidance with counsel.

When does the Colorado AI Act take effect?

There is no single clean date to quote, because Colorado amended the law after it passed and moved its effective date into the 2026 to 2027 window. The original statute (often called the Colorado AI Act, addressing high-risk automated decision systems and consumer protection) was set to take effect, then revised to give firms more time and to adjust the obligations. Treat the effective date as unsettled, track it with counsel, and avoid building a plan around a specific day until the amended date is confirmed. The safer move is to build the underlying risk-management posture now, since it is required in substance regardless of the exact start date.

Related Guides & Articles

One framework, many state laws

Our SEC Exam-Ready AI Governance engagement ($17,500) builds the NIST-AI-RMF-based program that doubles as the Texas affirmative defense and maps to Colorado and every state that follows. For the portfolio-company side, where the consumer-facing obligations actually sit, our Secure AI Adoption engagement ($7,500 per company) puts sanctioned tools, a usable policy, and classification in place at each company. Confirm the current effective dates with counsel before you rely on them.

Book a Call
Schedule Consultation