When Meta launched Muse in September 2026, the promise was seamless utility: an agent capable of handling purchasing, booking, and email tasks on behalf of a user. Similar capabilities arrived with Apple’s Siri AI and the beta release of SpaceXAI’s GrokBot. These tools represent a shift from passive software to active agents that make real-world decisions. Yet, as these systems integrate into daily life, a significant regulatory void remains at the federal level. The Congressional Research Service has confirmed there is no specific U.S. government guidance on agentic AI, and the proposed Great American AI Act remains merely a discussion draft. In this vacuum, state attorneys general have stepped forward, effectively building the liability framework that Congress has yet to codify.
The most visible signal of this shift occurred in December 2025, when a bipartisan coalition of 42 state attorneys general – led by officials from Pennsylvania, New Jersey, West Virginia, and Massachusetts – issued a coordinated letter to 13 major AI companies. This was not a symbolic gesture; it was a formal demand for chatbot safeguards with a response deadline of January 16, 2026. By targeting firms including Anthropic, Apple, Google, Meta, Microsoft, OpenAI, and xAI, the coalition signaled that the era of self-regulation is ending – and that state-level coordination can set national expectations without waiting for Congress.
State AGs are not waiting for new federal statutes. Instead, they are repurposing existing legal tools to address the unique risks posed by autonomous agents. As noted in a June 2026 analysis by Benesch Law, AGs are leveraging UDAP (Unfair and Deceptive Acts and Practices) statutes, consumer protection laws, civil rights frameworks, and antitrust authority to police AI behavior. The approach is already yielding results: Texas Attorney General Ken Paxton secured a first-of-its-kind settlement with Pieces Technologies, a healthcare AI company, for making false and misleading accuracy claims about its generative product used in hospitals. The core issue in that case – whether algorithmic systems are transparent enough for the people they serve – runs through the broader enforcement landscape.
Two states have emerged as critical inflection points for this new enforcement regime. Connecticut’s AI Responsibility Act, signed in May 2026, grants the state’s AG exclusive enforcement authority under the Connecticut Unfair Trade Practices Act (CUTPA). Starting October 1, 2026, this law mandates strict provenance and disclosure requirements, alongside anti-discrimination amendments for automated employment decision tools. While it provides a mandatory one-year cure period through September 2027, the threat of injunctive relief, restitution, and civil penalties creates a clear compliance floor. Meanwhile, New Jersey has taken a more aggressive path with its Fair Price Protection Act. Effective August 2027, this law allows for a private right of action, enabling consumers to sue directly for surveillance pricing – with treble damages, class action standing, and no cure period whatsoever.
The stakes for deployers are rising as these legal theories move from theory to practice. The Pennsylvania AG has already sought preliminary injunctions against an AI company for falsely representing a chatbot as a licensed psychiatrist, and the Florida AG launched a criminal investigation in April 2026 after a violent incident involving a chatbot, as reported by Benesch Law. These actions demonstrate that AGs are willing to use their parens patriae authority to protect residents from tangible harm. For companies like Meta, Apple, and SpaceXAI, the risk is no longer just reputational; it is operational. They are now navigating a fragmented landscape where a single agent deployment can trigger investigations across dozens of jurisdictions simultaneously.
The antitrust dimension adds another layer. According to a July 2026 analysis by Skadden, state AGs filed seven antitrust actions in 2026 alone, surpassing the totals from the previous two years. A 30-state coalition continued the monopolization case against Live Nation after the federal government settled. Twelve states sued to block the Paramount-WBD merger despite federal declination. The NY AG investigated Instacart’s algorithmic pricing in January 2026. These are not isolated enforcement actions – they are the structural pattern of state-level power filling a federal vacuum.
While federal policy remains stalled, the resulting patchwork of state-level protections creates a more complex, yet more robust, liability environment. The transition from passive software to agentic systems like Muse, GrokBot, and Siri AI demands accountability structures that match the speed of these tools. By building a patchwork of liability through existing consumer protection and civil rights laws, state attorneys general are ensuring that when an agent makes a decision – whether it is a purchase, a booking, or a medical recommendation – there is a clear path to legal recourse. The federal gap persists, but the states have effectively decided that the risks of agentic AI are too immediate to wait for Washington.
