The Federal AI Preemption Fight MSPs Can't Ignore

Randy Hall, CEO

Two stone columns, one federal and one state-styled, connected by a taut glowing rope.

Where AI regulation is heading for the channel in 2026 is still unclear. Washington wants one federal standard to override state AI laws, but Congress rejected that push twice, and Colorado just delayed and rewrote its own law under that pressure. For MSPs selling AI services across state lines, plan for a shifting patchwork, not a settled rulebook.

The White House tried to settle this with one order

On December 11, 2025, the administration signed an executive order titled "Ensuring a National Policy Framework for Artificial Intelligence." The order directs the Attorney General to stand up an AI Litigation Task Force within 30 days with a single job: challenge state AI laws the administration considers "onerous," using legal theories built around unconstitutional burdens on interstate commerce and preemption by existing federal statutes.

The same order gives the Secretary of Commerce 90 days to publish a formal evaluation of state AI laws and flag the ones in conflict with the administration's preferred approach, including any that require AI systems to alter truthful outputs or that force disclosures the order treats as constitutionally suspect. States that keep enforcing flagged laws risk losing access to certain federal funding tied to that evaluation.

The order carves out three categories it will not touch: child safety protections, AI compute and data center infrastructure, and state procurement or government use of AI. Everything else, meaning most of the consumer- and employer-facing AI laws MSPs actually have to work around, is fair game for challenge.

Why hasn't Congress just passed a national standard?

Because it tried twice and failed both times. A proposed 10-year freeze on state AI regulation was folded into a major budget bill earlier in 2025, and the Senate stripped it out by a vote of 99 to 1. A second attempt to attach a similar moratorium to the annual defense authorization bill also died before passage.

In March 2026, the White House released its own National Policy Framework for Artificial Intelligence, effectively asking Congress to do by statute what the executive order can't do by itself: replace the state-by-state patchwork with one federal approach. That framework is non-binding on its own. It creates no new compliance obligations and repeals nothing. Until Congress actually legislates, state AI laws stay in force exactly as written, litigation task force or not.

That's the part of this story MSPs tend to miss. An executive order and a policy framework are pressure campaigns, not law. A client operating in Illinois, Colorado, and Texas still has to satisfy whatever each of those states currently requires, regardless of what Washington would prefer.

The legal theories behind the Litigation Task Force also matter for how quickly any of this actually changes anything on the ground. Challenging a state law under the dormant Commerce Clause or a preemption argument means going court by court, law by law, which takes years, not months. A state AI statute doesn't disappear the moment a federal lawsuit gets filed against it. It disappears, if it disappears at all, after that lawsuit works through a trial court, likely an appeal, and possibly the Supreme Court. Any MSP planning around "the courts will sort this out soon" is planning around a timeline measured in years.

What Colorado's reversal actually shows

Colorado is the clearest example of how unstable that state-level ground has become on its own, separate from anything happening in Washington. The Colorado AI Act was originally set to take effect February 1, 2026. Governor Jared Polis signed a bill in August 2025 pushing that date to June 30, 2026. Then, in May 2026, he signed a second bill delaying it again, this time to January 1, 2027, and rewrote large parts of the law in the process.

The rewrite is not cosmetic. The original Colorado AI Act imposed a duty of care on companies deploying "high-risk" AI systems, requiring risk management programs aimed at preventing algorithmic discrimination. The amended version drops that risk-based framework entirely and narrows the law to disclosure and transparency requirements around certain automated decision-making tools, contingent on the state attorney general finishing rulemaking before the new effective date.

Colorado was the most comprehensive state AI law on the books, the one other states were watching as a model. It has now been delayed twice and substantially rewritten before ever taking effect, following the same months the White House was publicly pressuring states to pull back. Whether or not there's a direct line between the two, the practical result for the channel is the same: even the strictest state framework didn't hold its shape.

How should MSPs actually plan for this?

Plan around the one thing that isn't moving: the voluntary NIST AI Risk Management Framework. It doesn't carry the force of law, but it's the baseline that shows up across nearly every state proposal, every industry compliance conversation, and every serious client audit, regardless of which specific state statute ends up governing a given deployment. Building your AI governance documentation, model inventories, and risk assessments against that framework now means you're not rebuilding your compliance story every time a state law gets delayed, amended, or challenged in court.

Treat every current state requirement as real and enforceable until you have a specific reason to believe otherwise for that state. An executive order directing a lawsuit is not the same as a court ruling striking a law down, and a non-binding White House framework is not a repeal. If a client operates in a state with an AI-specific disclosure, bias-audit, or consumer-notice requirement, that requirement applies today.

Write your client contracts to survive the same uncertainty. A master services agreement that names a specific compliance standard as the permanent bar for an AI-powered service will need revisiting every time a state amends or delays its law, the way Colorado just did. Language that instead commits you to maintaining alignment with "then-current applicable state and federal AI requirements," reviewed on a fixed cadence, holds up regardless of which statute is in force on a given date. That's a legal-drafting choice, not a technical one, and it's worth raising with counsel before your next contract renewal cycle rather than after a client asks why your paperwork cites a law that no longer applies.

Getting this right also takes trained people, not just updated contracts. Technicians and account managers who understand what "high-risk automated decision" actually means in a given state's law, and who can explain that to a client without overpromising or underselling the risk, are worth more than another compliance checklist. That's the gap Forge University's certification tracks are built to close, giving your team a working command of AI governance concepts instead of a folder of legal memos nobody reads.

What this means for how you sell AI services

The commercial risk here isn't a fine. It's slower sales cycles and client hesitation. A prospect who read one headline about a "federal AI framework" may assume the compliance question is settled and stop asking. A prospect who read a different headline about a state attorney general's lawsuit may assume the opposite and get more cautious. Both reactions cost you time in the sales conversation if you can't correct the record quickly and specifically.

The MSPs that will handle this best in 2026 are the ones who can speak to the actual state of play, not the loudest headline: which laws are live, which are delayed, which carve-outs exist, and what that means for the specific tools and services on the table. That's a positioning advantage worth building deliberately, not something to leave to whichever technician happens to read the news that week.

If you're not sure where your current AI-powered offerings stand against this shifting backdrop, running your stack through Actiforge's stack builder is a fast way to see where governance gaps sit relative to what you're actually selling today. It won't tell you what Congress will do next, but it will tell you where your own house needs work regardless of how the federal fight ends.

None of this resolves in 2026. The Litigation Task Force will file challenges, some states will amend laws under pressure the way Colorado did, and Congress may try a third time to pass a preemption bill. Build your compliance posture to survive all three outcomes rather than betting on one, and browse the rest of the Actiforge product catalog for the tools built to help you do that without adding headcount.

See the full stack.

Sources: The White House | Mayer Brown | Paul Hastings LLP | DLA Piper | Crowell & Moring | Hunton Andrews Kurth | Clark Hill PLC | Skadden, Arps, Slate, Meagher & Flom.