State AI laws in 2026 that touch AI training data: what to check before licensing

State laws that reach AI training data in 2026 fall into three groups: developer documentation duties, consumer privacy statutes and automated-decision rules. Their status and dates keep shifting, so verify each against official sources. For licensed business records, the practical lesson is that buyers value clear provenance, documented rights and agreed redaction.

Which state AI laws touch training data in 2026?

Several states have passed or debated laws that reach AI systems, and the ones relevant to training data fall into three groups: documentation duties for developers, consumer-privacy rules that cover personal information used in training, and automated-decision rules for high-risk uses. Status and effective dates have shifted repeatedly, so this page gives a framework and primary-source pointers, not a table of dates you should rely on.

For a referral partner the practical point is narrow. AI developers increasingly need to document where their training data came from, and rights-cleared, contractually licensed business records are easier to document than scraped material. That is one reason buyers ask SourceX about provenance.

This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting. Verify the current status of any statute on the state legislature's official site.

What kinds of obligations do these laws create?

Type of ruleWho it usually targetsWhy it matters to licensed datasets
Training-data documentationDevelopers of generative AI offered to the publicDevelopers may need to describe data sources, including purchased or licensed datasets
Consumer privacy statutesBusinesses that handle residents' personal informationRecords with personal information need notices, purpose limits and deletion handling
Automated decision-making and risk assessment rulesDevelopers and deployers of high-risk systemsBuyers want clean lineage when their systems face audits
Transparency and disclosure statutesProviders of consumer-facing AIPressure on buyers to know what they trained on
Sector rules (health, finance, insurance)Regulated entitiesSome record types are excluded or need de-identification

Which row applies depends on the buyer, the model and the data, not on the company that licenses its records. The company's own duties come mainly from privacy law, contracts and employee notices.

What does California's regulatory activity show?

California is the best-documented example because its privacy regulator publishes the current text. The California Privacy Protection Agency's regulations index lists CCPA regulations effective January 1, 2026, plus a package on risk assessments, cybersecurity audits and automated decision-making technology approved in September 2025, with some compliance deadlines phased in from 2027 to 2028. California privacy regulations were updated in 2026, so check the current text rather than a summary.

Two other statutes are commonly named in this area: California's AB 2013, which concerns documentation that generative AI developers publish about their training data, and the Colorado AI Act (SB 24-205), which concerns high-risk automated decision systems. This page does not state their effective dates because both have been the subject of amendment or delay; read the enacted text and current status on each legislature's official site, and ask counsel whether a given law reaches a developer, a data licensor, or neither.

How should a company reason about a moving legal map?

Use a three-layer test before licensing:

  1. Origin. Did the company create the records, and who appears in them: employees, clients, consumers?
  2. Promise. What did privacy notices, employee policies and client contracts say about use and disclosure?
  3. Path. Where will the data go, in what form (de-identified, redacted, filtered), and under what contract?

If layer one or two is unclear, narrow the scope. If layer three is vague, tighten the license. The data mapping guide helps with layer one, and the list of data that should be excluded from AI training is a default for layer two.

What happens with deletion and opt-out rights?

State privacy laws give residents rights over personal information, which raises the question of what happens to a record after it is licensed. The CCPA deletion explainer covers how that interacts with a data license, and the HIPAA guide covers the separate federal regime for health information. Most of the records SourceX works with are business records of a company, with personal information handled by agreed redaction rather than ignored.

What to say when a company asks about state AI laws

Keep the answer short and avoid legal conclusions.

If the owner presses for specifics, offer to introduce them to SourceX, which scopes the dataset with the company's own advisers. Do not forward articles or summaries as if they were advice.

Illustrative scoping decision

Illustrative: a fictional logistics company has operations in four states and employee records covering all of them. Its counsel decides that dispatch tickets, carrier correspondence and internal procedures go into the proposed scope, while driver personnel files, anything with consumer shipping addresses and legal-department mail stay out. The decision is documented, so the buyer's own provenance paperwork can describe the dataset accurately. The partner who made the introduction was not involved in any of it.

Timeline questions to ask counsel

  • Which states are our employees, clients and end users in?
  • Does any state privacy statute apply to us based on revenue or volume thresholds?
  • Do our privacy notices describe disclosure to third parties for AI development?
  • Is any record type regulated by a sector rule?
  • What documentation will the buyer need from us about origin and rights?
  • Which effective dates fall inside our delivery window?
  • Who owns monitoring of changes, since several statutes have been amended or delayed?

What this means for referral partners

You do not need to track state AI statutes to make an introduction. You need to know that buyers care about provenance, and that a company with documented rights, notices and an authorized sponsor is a stronger introduction than one that cannot answer where its data came from. See what AI training data is for background and the EU disclosure template guide for the parallel European angle.

Never offer a view on whether a specific law applies to a company. Say "your counsel decides" and point to the company's own review.

Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company. The reward is paid only after the buyer pays and SourceX receives its fee; an introduction, meeting or signed agreement alone does not trigger payment, and no reward is guaranteed.

Limits of this page

  • It does not list every state law, and it will age quickly.
  • It gives no dates because many were extended or amended; use official legislative sources.
  • It does not cover non-US law.
  • It is not a substitute for counsel reviewing your own facts.

Next step

If you know a US company with 50+ full-time employees at peak (contractors excluded) and years of records, register as a partner. Use the company fit checker for a preliminary screen, and read how SourceX referrals work.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

Do state AI laws apply to a company that only licenses its own business records?

Usually the main duties fall on AI developers and deployers, not on the company that supplies records. The licensing company still has privacy, employee-notice and contract obligations. Which statutes reach which party depends on facts and the state, so counsel should review before any scope is agreed.

Why would an AI developer ask where licensed data came from?

Developers may face documentation duties, audits, customer questionnaires and litigation risk, and each is easier to handle when data has a clear origin and a signed license. Provenance records, rights representations and agreed redaction rules are the usual answer to that need.

Are the effective dates of these laws settled?

Not reliably. Several state AI and privacy rules have been amended, delayed or phased in, so any date quoted in a blog post can be out of date. Check the official legislature or regulator page for the current text before relying on a deadline.

Does licensing business records trigger a consumer opt-out right?

It can if the records contain personal information covered by a state privacy statute and the disclosure counts as a sale or share under that law. De-identification and exclusion of consumer data reduce the exposure. Counsel should decide the treatment for each dataset.

Can a referral partner tell a company that it is compliant?

No. Partners make introductions and give basic fit information only. Compliance conclusions belong to the company and its counsel, and nothing is binding until the company agrees price and terms and signs.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment