TL;DR: Most US state AI laws, including Colorado SB 26-189, are AG-enforced only. But BIPA (Illinois), Tennessee ELVIS Act, and the FCRA all create individual lawsuit rights. BIPA has generated mass litigation with per-violation statutory damages. Knowing which laws are individually actionable changes your compliance prioritization.
Here is a common misconception about state AI law compliance: "If we violate this law, the attorney general might come after us." That is true for most state AI laws. But for several, the risk is different: individual plaintiffs and class action attorneys can sue your company directly, without waiting for a government agency to act.
The distinction matters for how you prioritize compliance spend. An AG-enforced law with no private right of action still carries risk, but the enforcement path goes through a government body that must investigate, find probable cause, and proceed through an administrative or judicial process. A law with a private right of action means that any affected individual, on any day, can retain a plaintiff's attorney and file.
Illinois BIPA has generated hundreds of millions of dollars in settlements using exactly this mechanism. Understanding which US AI laws create individual lawsuit rights, and which (like Colorado SB 26-189) are AG-only, is a foundational compliance question.
The enforcement baseline: AG-only laws
Most state AI laws as of mid-2026 are enforced exclusively by the state attorney general. If an individual believes a company violated these laws, they must complain to the AG's office and hope the AG pursues it. They cannot sue directly.
Laws that are AG-enforced only (as of mid-2026):
- NYC Local Law 144 (bias audits for employment AI), enforced by NYC DCWP
- Texas TRAIGA, enforced by the Texas AG
- Minnesota HF 4369 (pending), proposed enforcement through state labor agency
- Connecticut AICPA (if enacted), proposed AG enforcement
- California AB 2930 (as vetoed/amended versions existed), AG enforcement
For these laws, compliance monitoring is important, but the litigation risk profile is different from laws with private rights of action. Class action plaintiff firms are not scanning your practices for AG-enforced-only violations.
Laws with private rights of action
Illinois BIPA
The Illinois Biometric Information Privacy Act (BIPA) is the most consequential US AI-adjacent law with a private right of action, and the one that has generated the most litigation. BIPA applies to any entity that collects or possesses biometric identifiers, fingerprints, retina scans, facial recognition data, and voiceprints, from Illinois residents.
Violations:
- Negligent violations: $1,000 per violation (or actual damages, whichever is greater)
- Intentional or reckless violations: $5,000 per violation (or actual damages, whichever is greater)
- Attorney fees and costs: mandatory for prevailing plaintiffs
The per-violation structure is the mechanism that makes BIPA dangerous. Every scan of every face, every collection of every fingerprint, without the required notice and consent, is a separate violation. In workplace contexts (facial recognition timekeeping, fingerprint scanners, voice authentication), violations multiply rapidly.
Class actions are permitted, and the BIPA class action plaintiffs' bar is well-developed. Settlements have ranged from tens of millions to hundreds of millions of dollars: Facebook settled for $650 million, BNSF Railway settled for $75 million, and scores of mid-size employers have settled in the single-digit millions.
The AI-specific application: facial recognition AI used in hiring or workplace management is a BIPA trigger if used on Illinois residents. AI voice analysis tools (like those used for job interview analysis) that create voiceprints may be BIPA triggers. Any AI that processes biometric data of Illinois residents without proper consent and policy documentation is at risk.
Colorado SB 26-189: AG-only enforcement
Colorado's amended AI Act (SB 26-189, signed May 14, 2026, effective January 1, 2027) creates obligations for deployers of "consequential AI systems" used in employment, lending, housing, education, healthcare, and insurance contexts. Unlike Illinois BIPA or the Tennessee ELVIS Act, Colorado SB 26-189 explicitly does not create a private right of action.
Enforcement is through the Colorado attorney general under the Colorado Consumer Protection Act. A violation of SB 26-189 is treated as a deceptive trade practice. Before the AG can initiate action before January 1, 2030, it must provide the developer or deployer with a 60-day notice and opportunity to cure the alleged violation.
This is a meaningful distinction for compliance prioritization: Colorado SB 26-189 violations are real legal risk, but the enforcement path runs through the AG's office, not through individual plaintiffs and class action attorneys. A company that detects and corrects a SB 26-189 violation before the AG acts can avoid penalties. That is not the case with BIPA, where any affected individual can file on any day.
Tennessee ELVIS Act
The Ensuring Likeness Voice and Image Security Act (ELVIS Act), effective July 1, 2024, creates individual property rights in one's voice and likeness and prohibits using AI to replicate them without consent for commercial purposes.
The ELVIS Act provides a private right of action for individuals whose voice or likeness is replicated by AI without consent. Damages include actual damages, statutory damages of up to $10,000 per violation, and attorney fees.
The ELVIS Act applies beyond musicians. Any commercial use of an AI-generated replica of a person's voice or likeness, including in marketing, training data, or product development, without consent is potentially actionable by the affected individual.
FCRA
The Fair Credit Reporting Act creates a private right of action when a company uses a "consumer report" without following required disclosure and adverse action procedures. If an AI hiring tool draws on external data about candidates (employment databases, public records, social media profiles), it may function as a consumer report under FCRA, and each time you use such a tool without required disclosures, you potentially create a per-violation claim.
FCRA statutory damages run $100 to $1,000 per violation, plus actual damages and attorney fees. Class actions are permitted, and FCRA class actions in hiring contexts have resulted in significant settlements.
The Eightfold AI class action (filed January 2026) advances the theory that AI talent platforms that compile external candidate data without FCRA compliance are consumer reporting agencies, and employers who use them without required disclosures are FCRA violators. If certified as a class action, this case could expose individual employers to per-candidate FCRA claims for every AI-screened applicant.
The full FCRA AI hiring disclosure analysis is in the FCRA and AI hiring disclosure requirements guide.
The pending private right of action landscape
Several state proposals would add private rights of action that do not currently exist:
Illinois HB 3773 / SB 2892 (AI Employment Decisions Act): Would add a private right of action for Illinois workers harmed by AI-assisted employment decisions (hiring, evaluation, termination) that violate the Act. Not yet passed as of mid-2026.
California SB 1047 successor bills: California has not enacted a comprehensive AI law with a private right of action, but the successor bills to the vetoed SB 1047 are being developed and some include individual enforcement mechanisms.
Federal legislation: The Great American AI Act discussion draft includes whistleblower private right of action provisions for employees of large frontier developer companies. If enacted, this would create individual lawsuit rights in the federal AI governance space for the first time.
Compliance prioritization implications
The existence of a private right of action changes the compliance risk calculation:
AG-only enforcement: risk = (probability AG investigates) × (penalty if enforced). Since AG resources are limited, small violations are unlikely to trigger action.
Private right of action: risk = (probability any affected individual sues) × (per-violation penalty) × (number of violations). In high-volume AI applications (thousands of hiring screenings, thousands of workplace biometric scans), the number of violations multiplies rapidly even when the per-violation penalty is modest.
For organizations that use biometric AI on Illinois residents: BIPA is high-priority because the per-violation private right of action at $1,000-$5,000, multiplied across all employees or applicants, creates catastrophic exposure. The compliance investment required, consent, policy, data retention limits, is modest compared to the litigation risk.
For organizations deploying consequential AI in employment decisions affecting Colorado residents: Colorado SB 26-189 is AG-enforced only with no private right of action. The AG must give 60 days to cure before any enforcement action before 2030. Your risk is regulatory, not class action litigation. Compliance monitoring still matters: the AG can act on complaints, and violations treated as deceptive trade practices carry real penalties under the Colorado Consumer Protection Act.
For organizations using AI hiring tools that draw on external candidate data: FCRA class action exposure is real and active. The Eightfold case will shape the legal landscape.
See the multi-state AI compliance strategy guide for the full map of which laws apply to your business by state, and the BIPA AI hiring compliance checklist for the specific steps needed to manage BIPA exposure.
How to build a litigation-aware compliance calendar
The practical output from this analysis is a compliance calendar that distinguishes between AG-enforcement risks and private right of action risks, and treats them differently.
For AG-enforcement-only laws (NYC LL144, Texas TRAIGA): Schedule annual compliance checks, run a bias audit on the cadence required by law, and document your good-faith compliance program. These laws are unlikely to generate surprise litigation because enforcement requires a government investigation.
For BIPA: Treat every collection of biometric data as a per-violation event with real dollar exposure. Your BIPA compliance tasks should run on a rolling basis: consent refresh annually, new biometric system onboarding requires legal review before deployment, and data retention audits quarterly. A single un-consented biometric collection in a 500-person workplace can generate $500,000 in statutory exposure (at $1,000 per negligent violation), before attorney fees.
For Colorado SB 189 (effective Jan 1, 2027): Build a monitoring process that can detect consequential AI decision anomalies before they become cure-notice-triggering events. The 60-day cure window protects companies with active compliance monitoring. It does not protect companies that discover a violation through a plaintiff's attorney's notice.
For FCRA: Audit your AI hiring vendor agreements before renewing. If a vendor cannot confirm in writing that their tool does not use external candidate data, treat it as a FCRA trigger and build in the required disclosure and adverse action process.
Related Reading
- BIPA and facial recognition AI compliance 2026
- BIPA AI hiring compliance checklist for Illinois employers 2026
- Colorado AI Act SB 189: employer obligations guide 2027
- FCRA and AI hiring disclosure requirements 2026
- Multi-state AI compliance: which laws apply to your business
- AI workforce displacement and the WARN Act: HR compliance 2026
- NYC Local Law 144 AI bias audit employer guide 2026
- Connecticut Data Privacy Law Expands July 1: CTDPA SB 4 Small Team Compliance
