Colombia's AI Bill and U.S. Preemption Pressure
Yesterday’s consequential AI-governance developments concerned not a shared new rulebook, but two different answers to who should regulate AI and how. Colombia is considering an EU-style, risk-based bill that would impose lifecycle obligations on AI developers, providers, and deployers. In the United States, meanwhile, a reported FTC policy position could give federal authorities a new argument for challenging some state AI laws.
The contrast matters because it reinforces a pattern visible in recent days: AI governance is becoming more operational in some jurisdictions while the allocation of regulatory authority remains contested in others. Neither move is settled law, but each could affect how companies organize compliance across borders.
Colombia’s House of Representatives is considering Bill 025 of 2026, a proposed risk-based AI regime covering developers, providers, and deployers of AI systems. According to Tech Policy Press, the bill would require risk and impact assessments, transparency, human oversight, monitoring, public oversight, and sanctions, while giving the Ministry of Science, Technology and Innovation authority to classify high-risk systems. For firms serving Colombia, the practical significance is that familiar EU AI Act-style controls could become a local compliance expectation, including for foreign providers whose closed models are used by domestic businesses.
The proposal’s central weakness may be implementation rather than ambition. Tech Policy Press’s analysis argues that Colombia may not have the administrative capacity, technical expertise, or leverage over foreign model providers needed to reproduce the EU framework effectively. The available reporting does not establish legislative progress, final bill language, or eventual enactment, so the immediate development is a consequential proposal rather than a new obligation.
In the United States, Lawfare reported that the FTC issued an AI Policy Statement following Trump v. Slaughter that suggests Section 5 of the FTC Act may preempt certain state AI laws. This does not itself invalidate any state statute. But it gives the administration’s preference for centralized federal AI governance a potential agency-based route through enforcement and litigation, alongside the legislative arguments over federal preemption that have featured in recent debate.
That distinction is important for state regulators and companies operating across multiple jurisdictions. A policy statement is an interpretation, not a judicial ruling, and its reach will depend on its text, any enforcement use, and courts’ willingness to accept the FTC’s preemption theory. Still, it raises the prospect that disputes over AI rules could be fought not only in legislatures, but through consumer-protection authority and litigation.
Key Points
- EU-style risk-based regulation continues to travel more easily as a legislative template than as an implementation model. Colombia’s bill adopts the familiar vocabulary of assessments, transparency, oversight, and high-risk systems; yesterday’s reporting made clear that institutional capacity, technical staffing, and control over foreign providers will determine whether those requirements become enforceable practice.
- The U.S. federal-state AI dispute is acquiring another channel. Recent briefings tracked preemption mainly through prospective federal legislation and political resistance to it. The reported FTC position would shift part of that contest toward statutory interpretation, agency enforcement, and court challenges—without resolving the underlying question of how much state authority remains.
Implications
Cross-border AI providers should expect less regulatory simplification, not more. If Colombia’s bill advances, companies may need to prepare for a localized set of lifecycle controls modeled on the EU approach. In the United States, the same firms may face uncertainty over whether state-level obligations endure, rather than a clear federal baseline.
For legal and compliance teams, the immediate task is to separate enacted requirements from proposed frameworks and asserted agency authority. Colombia’s bill could eventually create concrete duties; the FTC statement could become consequential if it is used in enforcement or litigation. At present, neither should be treated as a settled, generally applicable compliance outcome.
Watchpoints
Watch
Whether Colombian Bill 025 advances through the legislature, and whether published bill text clarifies high-risk classifications, enforcement powers, sanctions, and responsibilities for foreign model providers.
Watch
The FTC policy statement’s full language, any effort to invoke Section 5 preemption in an enforcement matter or court filing, and judicial treatment of the agency’s claimed authority over state AI laws.
Watch
Whether other jurisdictions adopt risk-based proposals without matching them to the institutional resources, sector regulators, and technical oversight needed to administer them.
Fallout
Yesterday’s concrete developments sharpened a jurisdictional divide in AI governance: Colombia is considering detailed risk-based obligations, while the United States may see a more forceful federal challenge to parts of the state-law landscape. The main question is not yet what a common global framework will require, but which institutions will have authority to require it.
Colombian AI Legislation
Bill 025 of 2026 would establish a proposed risk-based AI framework for developers, providers, and deployers, drawing heavily on the regulatory structure associated with the EU AI Act.
Fresh developments
Reporting indicated that Colombia’s House of Representatives is considering the bill, which would impose assessment, transparency, human-oversight, monitoring, public-oversight, and sanction provisions. The Ministry of Science, Technology and Innovation would classify high-risk systems.
Why we noticed
The bill could extend lifecycle governance obligations to another market and create compliance questions for foreign providers. Its effectiveness, however, will depend on legislative progress and the country’s ability to administer technically demanding rules.
Watch for:
- Committee action, amendments, and the bill’s legislative timetable.
- Published provisions governing high-risk classifications, due process, penalties, and enforcement.
- Whether foreign model providers and local deployers receive distinct obligations or accountability mechanisms.
Article links:
U.S. Federal-State AI Authority
The division of authority between federal agencies and state AI laws remains unsettled, with federal preemption arguments emerging alongside state-level regulatory initiatives.
Fresh developments
Lawfare reported that the FTC issued an AI Policy Statement suggesting that Section 5 of the FTC Act may preempt certain state AI laws, following the Supreme Court’s Trump v. Slaughter decision.
Why we noticed
The reported position could provide an agency-based pathway for contesting state AI requirements. It is not a binding determination that particular laws are invalid, but it could alter enforcement strategies and litigation risk if the FTC acts on it.
Watch for:
- The full text and legal reasoning of the FTC’s AI Policy Statement.
- Any FTC enforcement action, guidance, or litigation invoking Section 5 preemption.
- Court decisions addressing whether federal consumer-protection authority displaces particular state AI requirements.
Final Thought
Yesterday did not establish a new center of gravity for AI governance. It did make the emerging divide more tangible: one path asks firms to demonstrate controls throughout an AI system’s lifecycle, while another questions which level of government may demand those controls at all. The next material change will come from implementation—legislative progress in Colombia or an FTC test of its preemption theory—not from the competing concepts alone.
