For years the honest advice to a mid-sized American company was: comply with California, and you are broadly fine. That advice has expired. There is no single state doing all the work any more, several states now regulate automated decision-making as its own category, and chatbot-specific bills have been introduced across most of the country.
The reflex response is to try to track it. Do not try to track it. A company below enterprise scale cannot maintain a live map of fifty legislatures, and the attempt fails in a predictable way: an expensive matrix that is out of date within a session and that nobody consults when a real decision is made.
There is a better approach, and it is the one we put in place for clients. Build to the strictest common denominator, and make the handful of structural choices that hold no matter which bill passes next.
One standing note. This post contains no statutes, no thresholds and no dates on purpose, because those are exactly what changes. Where a number or an effective date matters, it comes from the regulator: the Federal Trade Commission for federal enforcement, the California Privacy Protection Agency for the most developed state regime, your own state Attorney General for local enforcement, and NIST for the AI risk framework most of these rules are quietly modelled on. Take the current position from them, not from a blog, including this one.
The short version
- Stop tracking jurisdictions, start tracking data. Nearly every obligation in nearly every state keys off what personal data you hold, why, and who you share it with. One good inventory answers most of the questions across most of the map.
- Build to the strictest regime you are plausibly subject to. Running one standard is cheaper than running five, and much cheaper than discovering you were running zero.
- Automated decisions are now their own category. If software materially affects a person's access to a job, credit, housing, insurance or a price, that is the regulated surface, and "the vendor's model does it" is not a defence.
- Disclose that a bot is a bot. This is the single fastest-moving area and the cheapest to get right in advance.
- Your vendors are your exposure. Most breaches and most enforcement in the smaller market trace back to a third party nobody had assessed.
What has actually changed for a normal business?
Three things, and only three are worth your attention.
Coverage widened. The thresholds that used to keep mid-market companies out of scope have come down in several states, and some regimes count records processed rather than revenue. A services business with a national customer list is now routinely in scope somewhere even though it has no office there.
Automated decision-making became a named thing. Several states now require documentation of how automated systems affect consumers: what the system does, what data it uses, what the person can do about it. This lands on ordinary tools that no one thinks of as AI, including scoring in a CRM, dynamic pricing and resume screening.
Conversational AI is being regulated on its own. Disclosure that the user is talking to a machine, limits around minors, and constraints on certain categories of advice. This is where the volume of new legislation is, and the compliance cost of getting ahead of it is close to zero compared to retrofitting.
The five things that make you compliant almost everywhere
1. A data inventory that is actually accurate
Not a diagram from 2023. A current list: what personal data you collect, where it sits, why you have it, how long you keep it, and every third party who receives it.
This is boring and it is the foundation of everything else. Access requests, deletion requests, breach notification, vendor assessment and risk documentation all read from it. Companies without one do not fail compliance elegantly, they fail it at the worst moment, which is thirty days into a regulator's clock.
2. One privacy standard applied to every customer
Pick the strictest regime you might plausibly be subject to and run it for everyone. The alternative is geography-dependent behaviour, which means branching logic in your product, your marketing stack and your support process, and which breaks the first time someone moves house.
| Comply state by state | One strict standard everywhere | |
|---|---|---|
| Engineering cost | Branching logic in every data path | Built once |
| Ongoing legal cost | Reassess on every new law | Reassess only if the strictest moves |
| Marketing impact | Different consent flows per user | One flow, slightly more consent friction |
| Risk of quiet non-compliance | High, and hard to detect | Low |
| Works if a customer relocates | No | Yes |
The honest cost of the right-hand column is a marginally higher opt-out rate. The honest cost of the left-hand column is that it silently stops being true.
3. A register of every automated decision that touches a person
List the systems. For each one: what it decides, what data goes in, whether a human can override it, and how someone contests the outcome.
The register is worth building even where no law yet requires it, for a practical reason. It is the artefact regulators ask for, and it is also the artefact that makes your own team notice the scoring rule someone added to the CRM eighteen months ago that nobody can now explain.
Hiring is the highest-risk instance of this. If a tool screens or ranks candidates, you own the outcome, the vendor does not, and discrimination law applies regardless of what the privacy statutes say. The EEOC has published guidance on exactly this.
4. Bot disclosure, by default
If a customer is talking to an automated system, say so in the first message, and make a route to a human genuinely available rather than nominally available. Apply it everywhere rather than in the states that currently require it.
This costs nothing, it pre-empts the fastest-moving legislative area, and in our experience it slightly improves satisfaction, because the failure people resent is not talking to a bot, it is being misled about it and then trapped.
5. Vendor assessment with teeth
Every vendor that touches personal data gets a written assessment, a data processing agreement, and a periodic review. Every AI vendor additionally gets asked, in writing: do you train on our data, where is it processed, and how long do you retain it.
If a vendor cannot answer that clearly, that is the answer. This applies with equal force to the free tool someone on the marketing team signed up for with a corporate card, which is where most of the unassessed exposure in a mid-sized company actually lives.
What we would do in the first thirty days
- Week one: inventory. Data, systems, vendors. Whatever you have, make it current.
- Week two: pick the standard. Choose the strictest plausible regime, write down that this is the standard, and get it signed off by someone who can hold it.
- Week three: the automated decision register. Every system that scores, ranks, prices or screens a person.
- Week four: close the obvious gaps. Bot disclosure, the deletion process actually working end to end, the two vendors with no agreement in place.
None of this requires a privacy team. It requires one competent person with authority and about a month, and it is the difference between a manageable position and a genuinely bad quarter.
Frequently asked questions
Does this apply to a company with no offices outside its home state?
Usually yes, if you have customers elsewhere. Most state privacy laws reach businesses that process the data of that state's residents, wherever the business sits. Physical presence stopped being the test some time ago.
We only use AI features inside tools we bought. Are we exposed?
Yes. Obligations attach to the business making the decision, not to the software vendor. If a purchased tool scores candidates or prices customers differently, you own the outcome and you need to be able to explain it.
Is federal preemption going to make this go away?
It might, eventually, and it has been about to for years. Planning on it is not a strategy. Everything in this post is worth doing on its own merits, and none of it becomes waste if a federal standard arrives.
What is the cheapest mistake to avoid?
Marketing signing up for a new AI tool and pasting customer data into it. One line in an acceptable use policy plus a named approval route prevents most of it.
Where to go next
If you are weighing a market expansion, a new product line or an AI deployment and want the regulatory exposure priced into the plan rather than discovered afterwards, that is part of how we run growth strategy consulting. The operational side, who owns what and how it gets reviewed, sits with business operations consulting. If a system needs building or fixing, see custom software development, or just talk to us.