In the first six months of 2026, twenty-seven US states enacted eighty-four new AI laws. The Transparency Coalition's mid-year report, published on 21 July, counts measures passed between 1 January and 30 June.
In the same period, the EU took the opposite approach: one instrument, one commencement date, twenty-seven member states. The AI Act's transparency obligations applied from 2 August 2026, everywhere at once.
Two different shapes of the same pressure. Only one of them can be met with a spreadsheet, and it is not the one most organisations are building for.
The objection is that this is already a solved problem
Take the obvious counter first, because it is a good one. Insurers have complied with fifty state regimes for a century. Any large US business already runs a fifty-state privacy programme. Twenty-seven is not an intimidating number to anyone who has done multi-state compliance, and an argument resting on the count alone deserves to lose.
So grant it, and grant the strongest version of the convergence case with it. Assume four in five of the twenty-seven take their structure from the Colorado risk-tiering model, so what you have to learn is close to one law with local variations. That assumption helps far less than it should.
You still carry twenty-seven separate legal reviews, because convergent drafting is not identical drafting and only counsel can tell you which of the differences bite. Twenty-seven filing and attestation calendars, because commencement dates and renewal cycles do not converge even where the text does. Twenty-seven audit trails, because an enquiry from one state regulator is answered with evidence scoped to that state, on that state's timetable.
The binding constraint is the fixed overhead of tracking, not the substantive novelty of the law.
Reading the statute is the cheap part, and convergence is exactly what makes it cheaper. Proving on demand, in twenty-seven places, that you did what it says is the expensive part, and that cost barely moves whether the twenty-seven are near-identical or wildly different.
Which is why the multi-state insurers are the wrong reassurance to draw from. They do carry it, in departments built over decades, and it is one of the most expensive functions they run. Most organisations reading this are not going to stand up that department, and should not have to.
The matrix is a reading, not a control
The instinct is a compliance matrix: a row per jurisdiction, a column per obligation, an owner per cell. It is a reasonable artefact and the wrong primary one, because it is assembled out of precisely the overhead just described. Every cell needs somebody who has read the statute, understood what it requires of your specific system, and can say whether you meet it this quarter. The cells multiply with the jurisdictions. The evidence sitting behind them does not.
The matrix also answers the wrong question. It tells you which obligations exist. It does not tell you whether you can demonstrate compliance with any of them. Those are different questions, and only the second one is asked during an investigation.
The count is not the burden
Eighty-four is a headline, not a workload. Most of those laws will never touch a UK consultancy or its clients. Some are procurement rules for state agencies. Some govern deployments nobody outside that state operates. Reading the number as a measure of your exposure is the same error as reading a vulnerability instance count as a defect count: it sounds like work, and it is not the work.
Scope the eighty-four down to the ones that actually reach you and the substantive reading collapses to something a competent team can hold. The tracking does not collapse with it. Every jurisdiction you remain in scope for keeps its own calendar, its own regulator and its own evidentiary expectations, and that is the part still standing after the legal analysis is finished.
What actually transfers between jurisdictions
Read enough of these regimes and the surface diversity starts to look like variation on a small number of underlying demands. Disclose when a person is dealing with a machine. Mark synthetic content. Keep a human meaningfully in the loop for consequential decisions. Be able to explain how an outcome was reached. Be able to show it later.
The wording differs, the thresholds differ, the penalties differ. The evidence does not.
A record that answers "who decided this, on what data, under which model version, and who reviewed it" does not change shape when the jurisdiction changes. Only the questions asked of it change.
That is the asset worth building, and it is the one thing in this that does not carry a per-jurisdiction cost. Not a document that mentions Connecticut and Brussels, but a system that produces the same provable answer regardless of who is asking. Build it once, answer twenty-seven times.
The leading indicator worth watching
One finding in the TCAI report is worth more attention than the headline count. Concern about AI chatbots, particularly their effects on children and teenagers, has become one of the most urgent AI policy issues for state legislators, and it is not falling along party lines.
Read that as a forecast rather than a fact about 2026. Enforcement energy follows political consensus, and consensus is forming around consumer-facing conversational systems. If you operate one, or you build them for clients who do, the obligations arriving next are unlikely to be the ones you are currently tracking.
What we would do instead
None of this is an argument that the work is small. If you are running AI systems across several markets, the ground genuinely is moving faster than any review cycle, and the feeling that you are behind is a reasonable response to the facts rather than a failure of diligence. The useful question is not how to catch up with twenty-seven legislatures. It is what to build so that the per-jurisdiction cost stops growing with the jurisdictions.
Stop treating the jurisdiction matrix as the primary artefact. Keep it if it helps, but demote it. It is a reading of the landscape, not a control.
Build the record first, and be specific about what it holds. For every consequential automated decision, you want to be able to retrieve, without a project: what was decided, when, and by which system; which model and version produced it; what inputs and data sources it saw; whether a human reviewed it, who, and what they changed; and the retention clock, set to the longest regime that plausibly applies. If you cannot answer those five today for a decision made last quarter, that gap is the work, and it is the same work whichever jurisdiction asks.
That is a smaller starting point than it sounds. Most organisations already hold three of the five somewhere, badly joined. The first useful exercise is not building anything, it is picking one live decision path and trying to answer the five questions end to end. What breaks tells you where to start.
Then map jurisdictions onto the record, not the reverse. When a new statute lands, the question becomes "does our existing evidence answer this" rather than "what new process must we invent". Usually the answer is yes, and the work is a query rather than a programme.
The limits, stated plainly
This is a governance position, not legal advice, and the two should not be confused. Some obligations genuinely are jurisdiction-specific, and no architecture removes the need to know which ones apply to you. A good record does not exempt you from a rule; it lets you prove you followed it.
Nor does it take the fixed overhead to zero. The reviews and the calendars still exist. What changes is that the audit trail stops being the twenty-seventh copy of a thing you build by hand, and becomes one system queried twenty-seven ways.
What that buys is this: when the twenty-eighth state passes its law, you read it, you check your evidence, and in most cases you carry on. That is a materially different position from starting a new column.