In 2023 alone, 59 privacy-related bills were introduced across U.S. states. Since the California Consumer Privacy Act took effect, that number has climbed steadily year over year, and the pace has only accelerated. Now in 2026, state lawmakers have introduced more than 2,100 AI-related bills alone, roughly ten times the volume seen just three years earlier. For a business trying to keep its practices aligned with the laws that apply to it, the pace itself has become part of the problem.

The Shape of the Problem

Most privacy reviews are built around a point-in-time model: a policy gets drafted, a legal or compliance team reviews current practices against current law, adjustments get made, and the work is considered done, until the next scheduled review, often a year later.

That model works reasonably well when the underlying law is stable. It works less well when dozens of new bills are being introduced annually, some of which become enacted law mid-cycle, well before the next scheduled review would have caught them. A gap between what a business's policy says and what a new law requires can open the moment a bill is signed — not the moment someone happens to check.

AI Has Added a Second, Faster-Moving Layer

Comprehensive state privacy laws used to be the main thing to track. That's no longer the case. By mid-2026, 24 states had enacted comprehensive consumer privacy laws, up from 20 just a few months earlier — and running alongside that patchwork is a fast growing body of AI-specific legislation that touches many of the same data practices.

Much of this AI legislation isn't a separate category from privacy law so much as an extension of it. Recent state activity illustrates the overlap:

  • Chatbot and disclosure laws. Illinois passed a Consumer AI Notice Act and an AI Companion Model Safety Act, requiring businesses to tell people when they're interacting with an AI system rather than a person — a notice obligation that sits squarely on top of existing data collection and consent frameworks. Similar chatbot bills moved in California, Rhode Island, and elsewhere in the same legislative window.
  • Provenance and transparency amendments. California amended its AI Transparency Act to address system provenance data — essentially, disclosure requirements about the data used to train and operate AI systems, which is a direct extension of how privacy law already treats data use disclosures.
  • Employment and health care AI. California's 2026 session alone closed with eight privacy bills and sixteen AI bills passed, including employment AI rules and multiple health care AI bills — areas where personal and sensitive data use is already tightly regulated.
  • State-level omnibus amendments. Connecticut's 2026 amendments folded AI provisions — including companion chatbots and employment AI — directly into the same legislative package as its consumer privacy and data broker law updates, rather than treating them as separate statutes.

The practical effect is that "AI law" and "privacy law" are converging into a single compliance surface for most businesses, tracked by many of the same legislators, in many of the same sessions, often amending the same underlying statutes. A monitoring approach build around static requirements is increasingly falling behind the changes to privacy laws, let alone the AI - specific half of that surface.

Why the Gap Is Easy to Miss

Three forces tend to work against a business working to address this gap on its own:

  1. State-by-state fragmentation. Privacy and AI law in the U.S. aren't single moving targets — they're dozens of overlapping ones, each with its own effective dates, thresholds, and definitions. A business operating in dozens of states has to track dozens of legislative calendars simultaneously to know which changes actually apply to it.
  2. Internal practices drift on their own timeline. Marketing adds a new analytics tool. Product ships a new AI-powered feature or a new data field on a signup form. Each change is small and reasonable on its own, but each one can shift what a business is actually doing relative to what its privacy policy describes — independent of anything happening in a statehouse.
  3. Legal review is resource-intensive by design. Thorough privacy review takes real time from real experts, which is exactly why it tends to happen on a schedule rather than continuously. The rigor isn't the problem; the interval between reviews is.

What Continuous Monitoring Changes

The operational fix isn't more frequent versions of the same point-in-time review — it's separating detection from remediation. A business doesn't need a lawyer watching every statehouse in real time to benefit from knowing, quickly, that a new law has passed that touches its data practices, or that an internal change (including a new AI feature) has opened a gap against its existing policy. That detection layer can run continuously in the background, surfacing what's changed and what needs attention, while the deeper legal and remediation work still happens with the appropriate expertise.

Handled this way, staying current stops being a once-a-year project and becomes an ongoing state a business maintains — closer to how security teams already treat vulnerability monitoring than how privacy has traditionally been handled.

Taking Action

The rate of new privacy and AI legislation isn't expected to slow. More states are expected to introduce comprehensive privacy and AI bills in the coming years, and existing laws — including recent amendments in Connecticut, California, and Illinois — will continue to be refined as regulators adjust their approach to both. Businesses that build monitoring into their ongoing operations — rather than into an annual calendar reminder — will be the ones positioned to respond before a gap becomes a liability, not after.

Our Privacy Dashboard is built around that same idea: rather than surfacing legislative and policy changes once a year, it tracks them on an ongoing basis, so a business can see where a gap has opened between its practices and current law well before its next scheduled review.