More than 30 states now regulate artificial intelligence, up from almost none two years ago. The result is an expanding patchwork of requirements that forces chief information officers to manage legal fragmentation instead of technology implementation, leaving companies to choose which law to break when compliance in one jurisdiction creates exposure in another.
The hiring challenge
Hiring exposes the problem most clearly because no other function runs AI against as many people as often. A tool that reduces 100,000 resumes to a shortlist of 10 makes judgment calls about commute times, work history and career gaps. No one wrote those judgments into policy. No one reviewed them before the shortlist reached a hiring manager. LinkedIn funnels candidates who might never have applied. Data providers scrape the open internet to identify and solicit people who never put themselves forward for anything.
None of this requires bad intent. A commute-time filter can quietly exclude applicants from underserved neighborhoods without any decision-maker choosing to discriminate. An applicant pool that skews 70%-30% along gender lines raises a hard question: Should the company normalize the ratio, leave it alone or follow whatever the underlying performance data shows? That third option assumes unbiased historical performance data, the same assumption that often fails. A tool trained on decades of history inherits that history's patterns.
There is no clean answer, and the states that have tried to write one down point in opposite directions. The legal exposure comes from disparate impact, which occurs when a neutral policy or practice disproportionately harms members of a protected group. This exposure comes from how AI performs once deployed at scale against real people, not from anyone's intent or from whether the company disclosed the practice.
Where the true exposure sits
Vendors build AI systems, but the companies using them decide where to deploy them, what role they will play in consequential decisions and whether that use complies with each state's law. The statutes don't agree on the legal hook. Some reach the developer. Some reach the deployer. Some reach both. But one fact doesn't shift: the company operating the tool against real people remains present in every jurisdiction at once. Deployment, not development, concentrates exposure regardless of how any single statute assigns responsibility.
This dynamic extends beyond hiring. Retailers that disclose their cameras and offer an opt-out can still deliver advertising along lines that track race, gender or age. Disclosure and opt-out solve a notice problem. They do nothing about impact because the underlying model selects for engagement, not for any demographic anyone chose. Consent mechanisms don't cure disparate impact. Promotion decisions carry the same risk.
The elusive single federal standard
A federal framework with one set of standards sounds like the obvious fix, and the White House has tried twice in the last year. First, it created a task force to challenge state AI laws in court. Then it created a voluntary security review window for AI developers. Neither substitutes for legislation. An executive order can't preempt state law without Congressional action, and a voluntary review imposes no compliance obligation on vendors that can opt in or out.
Even a working mechanism wouldn't answer the harder question: What level of algorithmic bias can the law tolerate? Zero bias is impossible. No human being is bias-free, and neither is the data humans produce. An algorithm makes residual bias legible-it can measure, report and audit that bias after the fact. A statute would have to name a tolerance and defend it, conceding that the approved system remains biased and saying by exactly how much. That is harder politically than tolerating the same bias when it spreads across a thousand human managers and no one has to sign the number.
One risk deserves acknowledgment. A federal standard written today could lock in today's assumptions and foreclose tomorrow's solutions. That risk calls for careful drafting. It doesn't justify the patchwork of state standards, which imposes its costs now and every day it persists.
What CIOs can do today
CIOs should map AI by use case and jurisdiction, so they know which laws govern each deployment. They should then build governance around practices that should exist regardless of the regulatory environment: clear terms of service, reliable data provenance and human review where the consequences matter most. Congress, courts and future administrations will keep shaping AI regulation, but enterprise AI won't wait for them. Companies already deploy systems under laws that states can enforce today. CIOs must govern within the legal framework that exists now, not the federal one they hope will eventually arrive.
Why this matters for managers
AI now runs through HR, marketing, customer data, cybersecurity and legal compliance simultaneously, not just one department's tech stack. The compliance decisions a CIO makes today directly affect hiring outcomes, advertising exposure and promotion risk across the organization. Managers who rely on AI-driven tools need to understand that vendor safety claims or disclosure notices do not eliminate legal exposure from disparate impact. The deployer-the company using the tool-remains the one facing enforcement risk in every jurisdiction. Building internal governance around data provenance and human review is not a regulatory checkbox; it is the operational baseline for deploying AI without creating liability that crosses state lines.
Your membership also unlocks: