As states continue to pass laws regulating the development and deployment of artificial intelligence (AI) systems, the federal government is ramping up its efforts to create a national AI regulatory framework, potentially overriding some state AI laws. Recent federal policy proposals and discussions are largely consistent with the President’s December 2025 Executive Order (EO), Ensuring a National Policy Framework for Artificial Intelligence, which CCHP first reported on in its January 7, 2026 Newsletter. According to the EO’s accompanying White House fact sheet, the Order is intended to preserve U.S. global leadership in AI by reducing regulatory barriers, addressing what the Administration characterizes as a fragmented state-level regulatory landscape, and advancing a uniform national AI policy framework. The EO also calls for an evaluation of existing AI state laws, as well as potential litigation and restrictions on funding for states found to have onerous AI policies. Additionally, members of Congress have recently introduced new legislative proposals that consider adopting a federal preemption of certain state AI laws, continuing the push and pull between federal and state AI policy and raising the question of what AI frameworks should be followed by stakeholders. This newsletter seeks to summarize the most recent AI policy efforts at both the federal and state levels, including how they might interact and potential healthcare impacts.
Recent Federal AI Activity Earlier this month, a new Executive Order, Promoting Advanced Artificial Intelligence Innovation and Security, was issued. This EO is focused around prioritizing the cyber defense of national security systems and developing advanced AI vulnerability detection, including facilitating access to cybersecurity tools and services for operators of critical infrastructure, such as rural hospitals. The EO also speaks to securing frontier (or, the most high-risk and advanced AI) model deployment and designing a voluntary testing framework with AI developers. Some voluntary evaluations of AI systems have already been occurring federally through agreements between AI developers and the Center for AI Standards and Innovation (CAISI), within the U.S. Department of Commerce’s National Institute of Standards and Technology (NIST). For example, in 2024 CAISI announced agreements reached with Anthropic and OpenAI, giving the agency access to major new models prior to, and following, public release enabling early evaluation and mitigation of potential risks.
Members of Congress have proposed multiple vehicles for enshrining some of these policies into federal statute. In early June, Reps. Jay Obernolte (R-Calif.) and Lori Trahan (D-Mass.) released a bipartisan proposal, titled the Great American Artificial Intelligence Act of 2026. This bill would require AI developers to address potential risks of advanced models and also ensure compliance through third-party auditors as well as CAISI. The bill would also authorize funding for and formally establish the existence of CAISI into law, which was initially created through an Executive Order. The most controversial element of this bill is its inclusion of a three-year preemption of state AI laws targeting the development of AI models (as opposed to laws regulating AI use, deployment, or laws of general applicability). This isn’t the first time a federal preemption of state AI laws has been statutorily proposed, though prior attempts have failed, and ensuring AI developers only have to follow one regulatory framework, rather than varying state laws, is a main component of the current Administration’s approach to promoting AI innovation in the United States. In March of this year, the White House released its Legislative Recommendations for an AI National Policy Framework, which speaks to the issue of state preemption, stating that the development side of AI systems “is an inherently interstate phenomenon with key foreign policy and national security implications.” Stakeholders, however, argue a preemption must at least come with an additional framework to ensure AI protections, which some states have already passed. Last week, a letter was submitted by over 200 state lawmakers asking Congress to oppose the preemption of state AI laws in the Great American AI Act (GAAIA). Anthropic, which has been largely supportive of regulation of its AI products, has published its own AI policy proposals, and believes Congress should not preempt state laws “unless it enacts a federal law that is at least as strong” as their proposed framework.
As pushback to GAAIA has increased, the Washington Post recently reported that a more likely vehicle for adopting more federal AI oversight is within proposals that ensure platforms better protect children’s online safety, such as S.1748, the Kids Online Safety Act (KOSA) and H.R. 3149, the App Store Accountability Act (ASAA). This current AI legislative effort and negotiations are being led by Sen. Marsha Blackburn (R-Tennessee), and it’s been reported that an eventual AI oversight package is likely to include a more tailored state preemption, specific to children’s online safety. It is unclear if the package could garner enough support to pass, but it seems this latest child safety effort is the current AI focus for the White House, given recent meetings directly with children’s safety groups.
State AI Policy Activity States continue to be quite active in adopting their own efforts to regulate AI systems. According to the National Conference of State Legislatures’ (NCSL) article on 2025 AI legislation, last year every state in the U.S. introduced AI legislation, and thirty-eight states ultimately enacted around 100 measures. CCHP is currently tracking over 200 active AI policies specific to healthcare across the states and Puerto Rico. According to the Health AI Policy Index, the most common health areas addressed by state AI policy include AI disclosure and transparency efforts, and AI use in relation to coverage and claims, with California being highlighted as the most active state in this policy space.
Examples of recently adopted AI healthcare legislation in California include:
- AB 3030 (2024 Session): This bill requires a health facility, clinic, physician’s office, or office of a group practice that uses generative artificial intelligence to provide patients with both a disclaimer that indicates to the patient that a communication was generated by generative artificial intelligence, and clear instructions describing how a patient may contact a human health care provider, employee, or other appropriate person. The bill exempts from this requirement a communication read and reviewed by a human licensed or certified health care provider.
- SB 1120 (2024 Session): This bill requires a health care service plan or disability insurer, including a specialized health care service plan or specialized health insurer, that uses an artificial intelligence, algorithm, or other software tool for the purpose of utilization review or utilization management functions, or that contracts with or otherwise works through an entity that uses that type of tool, to ensure compliance with specified requirements, including that the artificial intelligence, algorithm, or other software tool bases its determination on specified information and is fairly and equitably applied.
- AB 489 (2025 Session): This bill makes provisions of law that prohibit the use of specified terms, letters, or phrases to falsely indicate or imply possession of a license or certificate to practice a health care profession enforceable against an entity who develops or deploys artificial intelligence (AI) or generative artificial intelligence (GenAI) technology that uses one or more of those terms, letters, or phrases in its advertising or functionality. The bill prohibits the use by AI or GenAI technology to indicate or imply that the advice, care, reports, or assessments being provided are by a natural person with the appropriated health care license or certificate.
While AI policy at the state level may often be broader than healthcare specifically, it can still have indirect impacts on its use by providers in healthcare settings. For instance, some of the main state AI laws currently in question by the federal government, and potentially subject to a federal preemption, capture the overall development of the most high-risk and advanced (or “Frontier”) AI systems, which may be utilized by providers, health systems, and insurers.
Examples of state bills recently enacted that focus on frontier AI development:
- California SB 53 (2025 Session): This bill enacts the Transparency in Frontier Artificial Intelligence Act (TFAIA) that would require a large frontier developer to write, implement, and clearly publish on its internet website a frontier AI framework that applies to the large frontier developer’s frontier models, and describes how the large frontier developer approaches incorporating standards and best practices into its frontier AI framework. The TFAIA would also require a large frontier developer to transmit to the Office of Emergency Services a summary of any assessment of catastrophic risk resulting from internal use of its frontier models. The TFAIA would require the Office of Emergency Services to establish a mechanism to be used by a frontier developer or a member of the public to report a critical safety incident.
- Illinois SB 315 (2026 Session): This bill, cited as the Artificial Intelligence Safety Measures Act, requires frontier AI companies to create, publish and annually update a frontier AI framework addressing catastrophic risks from their AI models, as well as report critical safety incidents. It also mandates annual independent third-party audits and establishes access, reporting, retention, and publication requirements for audit results.
- New York A6453A/S6953B (2025 Session): This bill, known as the "Responsible AI safety and education act" or "RAISE act," requires developer transparency and disclosure, including safety protocols and frameworks for AI frontier models, as well as publishing and reporting information regarding safety protocols and incidents.
Summary As we await additional action at the federal level on AI policy and its potential interaction with state AI policy, it seems this current policy push and pull is broader than just healthcare and is focused more on the development of AI systems, rather than directly regulating providers that may seek to incorporate AI into their practices. Nevertheless, states are passing laws that do focus more on the deployment side of AI, as well as some that focus on AI in healthcare more specifically. As providers seek to adopt AI based tools into practice, continuing to track policies that shape AI development and subsequent use across industries remains important to ensure AI tools are properly evaluated prior to their use, and are continually monitored for potential safety concerns.
ADDITIONAL RESOURCES
To assist our readers seeking additional support in tracking and understanding AI policy, as well as implementing AI into their healthcare practice, CCHP has composed a list of some of the sources cited above, as well as other potentially helpful AI resources:
- Federal Administration’s AI Website – Includes the President’s AI Action Plan, AI Executive Orders, and Initiatives.
- National Conference of State Legislatures (NCSL) – Tracks all AI related legislation on its various websites, also has created an AI Policy Toolkit.
- Health AI Policy Index – Tracks state and federal policies, as well as voluntary standards.
- CCHP’s Pending Legislation Tracker – Searches can be refined on left side by state and topic.
- The California Telehealth Resource Center (CTRC) offers a number of healthcare AI resources in its AI toolkit.
- The National Telehealth Technology Assessment Resource Center (TTAC) tracks related technologies, including AI enhanced telehealth devices.
- The National Consortium of Telehealth Resource Centers (NCTRC) released an Artificial Intelligence in Rural Health Fact Sheet that can assist rural providers considering adopting AI tools and applications to enhance patient care.
- The Coalition for Health AI (CHAI) offers collaborative standards, Responsible AI Guidance, and released the Responsible Use of AI in Healthcare (RUAIH) guidance with the Joint Commission. The Joint Commission has expanded that guidance into its new voluntary program for Responsible Use of AI in Healthcare (RUAIH) certification.
- The Health AI Partnership (HAIP), a multi-stakeholder collaborative seeking to empower healthcare organizations to use AI safely and effectively.
- The Healthcare Information and Management Systems Society (HIMSS) offers additional digital health resources, such as its AI and Emerging Technologies Toolkit for Healthcare Organizations.
- The Center for AI Standards and Innovation (CAISI), which leads AI system evaluations and assessments, establishes voluntary agreements with AI developers, and is working to develop guidelines and best practices to measure and improve the security of AI systems and develop voluntary standards.
- The Centers for Medicare and Medicaid (CMS) CyberGeek has Guidance for Responsible Use of Artificial Intelligence (AI) at CMS, outlining CMS best practices around the use of Generative AI Tools (GATs), safeguarding personally identifiable information (PII) and protected health information (PHI).
Recent CCHP AI Newsletters:
|
|