There is a lot of noise about the US federal government overriding state AI laws. Here is the part that matters operationally: it hasn't happened. No federal statute preempts any state AI law, no court has paused one, and Colorado's took effect on schedule.
If your systems are in scope, you are in scope today.
What Colorado actually requires
SB24-205 governs "high-risk" AI — systems that are a substantial factor in decisions about education, employment or healthcare.
Developers must use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination. Deployers carry the heavier operational load:
- risk management policies
- annual impact assessments
- yearly reviews of deployments
- disclosure obligations to regulators, to deployers downstream, and to the public
It took effect 30 June 2026.
The case against it
9 April 2026 — xAI filed in the US District Court for the District of Colorado, arguing the law is unconstitutional on four grounds: the First Amendment (compelled speech and viewpoint discrimination), the Dormant Commerce Clause (extraterritorial reach), Due Process (vagueness), and Equal Protection (racial classification via the law's diversity carveout).
24 April 2026 — the Department of Justice moved to intervene. The court granted it.
The DOJ's own complaint runs narrower: that SB24-205 violates the Equal Protection Clause by compelling discrimination on the basis of race, sex and religion, and by authorising intentional differential treatment through its diversity exemption.
This follows from the AI Litigation Task Force the DOJ stood up on 9 January 2026, whose stated purpose is challenging state AI laws as unconstitutional regulation of interstate commerce, preempted by federal regulation, or otherwise unlawful in the Attorney General's judgment.
What has not happened
No injunction has been granted. The case is pending with no final ruling.
That distinction is the whole article. A lawsuit filed, and joined by the federal government, changes the odds on a law's future. It changes nothing about its force today. Colorado's requirements applied from 30 June and apply now.
Compliance teams reading "DOJ sues to block Colorado AI law" as "Colorado AI law blocked" are making an expensive category error.
Why this is the template, not the exception
Two things are worth separating.
The substance of the challenge is unusual — the DOJ arguing that an anti-discrimination law is itself discriminatory, on the basis of its diversity carveout, is a genuinely novel line of attack rather than the interstate-commerce argument the Task Force was set up around.
The structure is not unusual at all, and is likely to repeat: a company sues a state, the federal government intervenes on its side, and the litigation runs for years while the state law remains in force throughout. Texas has its own AI framework. Other states have theirs.
For anyone operating across states, the working assumption should be that patchwork compliance is the medium-term reality, not a temporary condition awaiting federal cleanup.
What to do about it
- Treat SB24-205 as live. Impact assessments and risk management policies are due obligations, not contingencies.
- Scope by use case, not by product. "High-risk" is defined by whether the system substantially factors into education, employment or healthcare decisions — the same model can be in scope in one deployment and out in another.
- Watch the docket, not the headlines. The event that would change your obligations is an injunction. Nothing else in this story does.
- Assume more states, not fewer. Building to the strictest applicable standard costs less than maintaining one compliance posture per jurisdiction.
