AI Policy Tracker
Federal and state AI bills and executive actions — each sourced, status-dated, and summarized in plain English. Filter by jurisdiction, status, or impact area, or search by keyword.
Where we’re tracking AI legislation
- Has published items28 jurisdictions
- Tracked, in review20 jurisdictions
- Nothing tracked yet3 jurisdictions
Shading shows whether the tracker has published items for a jurisdiction — not how much AI activity happens there, and not a rating of the state.
Small jurisdictions
Hard to hit on the map — use these. Jurisdictions with no note have no AI bills in the tracker yet.
All jurisdictions A–Z
Jurisdictions with no note have no AI bills in the tracker yet.
- Alabama1 published
- Alaska3 in review
- Arizona1 published
- Arkansas
- California6 published
- Colorado2 published
- Connecticut1 published
- Delaware4 in review
- District of Columbia3 in review
- Florida12 in review
- Georgia1 published
- Hawaii2 published
- Idaho1 published
- Illinois1 published
- Indiana4 in review
- Iowa18 in review
- Kansas1 published
- Kentucky1 published
- Louisiana1 published
- Maine1 published
- Maryland2 published
- Massachusetts34 in review
- Michigan8 in review
- Minnesota41 in review
- Mississippi1 published
- Missouri15 in review
- Montana
- Nebraska1 published
- Nevada
- New Hampshire4 in review
- New Jersey2 published
- New Mexico5 in review
- New York1 published
- North Carolina17 in review
- North Dakota1 published
- Ohio13 in review
- Oklahoma17 in review
- Oregon1 published
- Pennsylvania26 in review
- Rhode Island1 published
- South Carolina1 published
- South Dakota3 in review
- Tennessee1 published
- Texas1 published
- Utah1 published
- Vermont13 in review
- Virginia1 published
- Washington2 published
- West Virginia5 in review
- Wisconsin11 in review
- Wyoming1 published
48 policy items
CAIssued
Executive Order N-9-26: accelerating independent verification organization designation and AI auditor registration; recommendations on onsite IVOs, verified safety frameworks, and a frontier-model kill switch
Issued · status as of 2026-09-18
Executive Order N-9-26, issued by Governor Gavin Newsom on September 18, 2026, accelerates implementation of California's two new AI assurance laws and orders a study of stricter frontier-AI safety requirements. It directs the Government Operations Agency to complete the independent verification organization application requirements, procedures, and criteria required by Government Code Section 8898.1 (SB 813) by May 1, 2027, rather than the statutory January 1, 2028, and to have the AI Auditor Registry required by Section 11549.82 (AB 1405) established and operating by December 1, 2027, rather than January 1, 2029. It further directs the Agency, in consultation with the Governor's Office of Emergency Services and national experts, to submit recommendations to the Governor by November 16, 2026 on the technical feasibility and likely efficacy of amending state law to (a) require large frontier developers to embed designated independent verification organizations onsite in their labs for periodic audits and evaluations, (b) require that the safety frameworks, transparency reports, and risk assessments frontier AI companies must file be independently verified under standards an IVO deems adequate, (c) require a 'kill switch' for frontier models whose efficacy is verified on an ongoing basis by an IVO, and (d) expand the definition of critical safety incidents that AI companies must report to cover loss-of-control incidents. The order's recitals cite the 2023 Executive Order N-12-23, the 2025 frontier-AI expert report, SB 53 (2025), Executive Order N-5-26 on state AI procurement (March 30, 2026), and recent reports of AI agents defeating company security controls. The order does not itself impose the four requirements; it commissions recommendations on them. It creates no enforceable rights and took effect immediately.
CAEnacted
Artificial intelligence: auditors: registration.
Enacted · status as of 2026-09-09
California Assembly Bill 1405 (Chapter 178), signed September 9, 2026, adds Chapter 5.9.5 (Sections 11549.80–11549.86) to the Government Code to create a registration system for AI auditors. The Government Operations Agency must establish an AI Auditor Registry on its website by January 1, 2029, fix annual registration fees at no more than the cost of administration, and create a public mechanism for reporting auditor misconduct (Section 11549.82). Beginning January 1, 2029, no person may offer, sell, or conduct a 'covered AI audit', defined in Section 11549.80(d) as an audit assessing internal controls, processes, or systems for an AI system or model that are necessary for compliance with state law, without being registered (Section 11549.82.5). Registered auditors must file business information, the California laws under which they audit, certifications held, and a standard operating procedure referencing recognized standards such as those from ISO, NIST, or auditing and assurance standard-setters (Section 11549.83(a)), and must give auditees a report covering scope, results, deficiencies and recommended remedies, limitations, and a signed statement of compliance (Section 11549.83(d)(1)). Auditors must meet independence, objectivity, and integrity standards: no financial, business, or employment interest that would impair independence (reasonable audit fees excepted), no auditing of their own work, no seeking employment with an auditee during an engagement, and no assigning staff who had material responsibility at the auditee within the preceding 12 months (Section 11549.83(f)). Registration numbers must appear on advertising (Section 11549.83.5); auditors may not block or retaliate against employees who report noncompliance (Section 11549.83(g)); records must be kept ten years. The Agency may investigate complaints, and violations are grounds for removal from the registry and referral to the Attorney General (Section 11549.84). An AI Auditors' Registration Fund holds the fees (Section 11549.81). Licensed CPAs and accounting firms regulated by the California Board of Accountancy are deemed to satisfy the reporting and independence requirements when they follow the California Accountancy Act and AICPA standards, and complaints against them go to the Board (Sections 11549.83(d)(2), 11549.83(f)(2), 11549.84(b)). Registration is not a state endorsement (Section 11549.86). Executive Order N-9-26 (September 18, 2026) directs the Agency to have the registry operating by December 1, 2027; the statutory registration mandate date of January 1, 2029 is unchanged.
- Enterprise
- Quality assurance
- Certifications
- AI policy
CAEnacted
Independent verification organizations.
Enacted · status as of 2026-09-09
California Senate Bill 813 (Chapter 179), signed September 9, 2026, adds Chapter 14 (Sections 8898–8898.4) to the Government Code to establish a framework for 'independent verification organizations' (IVOs): AI auditors designated by the Government Operations Agency as having demonstrated expertise in assessing the risks posed by an AI system or model and identifying the metrics and methodologies behind that assessment. An 'AI auditor' may be a person, partnership, academic institution, nonprofit, or corporation (Section 8898(c)). By January 1, 2028, the Agency must develop application requirements for designation (applicant qualifications, proposed benchmarks and methodologies, supporting documentation), procedures for suspending or terminating a designation (including for conflicts of interest that impair independence, material misrepresentations, and cybersecurity lapses), and designation criteria, all published on its website (Section 8898.1). The criteria must at minimum address risk-assessment capability, technical personnel expertise, conflict-of-interest management, and independence from the party being assessed and its affiliates, meaning no operational or management dependence and freedom from the assessed party's control over conclusions. An IVO may accept payment from a party it assesses at reasonable market rates but may not accept terms that condition payment on the results (Section 8898.1(c)(2)(C)-(D)). The Agency must consult broadly and convene working groups that include engineers from competing AI companies and AI safety experts, and report the working groups' findings to the Legislature (Section 8898.2). Designated IVOs must report annually to the Agency and Legislature on their standards and methodologies and on any changes to governance or funding sources relevant to independence, with redactions permitted for trade secrets and security and unredacted records retained for five years (Section 8898.3). The chapter creates no liability for failing to meet a standard, is not a state endorsement of any AI system, does not require any developer or deployer to engage an IVO, and does not require an IVO to conduct compliance audits to register; an audit performed under an identified standard is relevant but not conclusive in litigation alleging AI-caused harm (Section 8898.4). Executive Order N-9-26 (September 18, 2026) directs the Agency to complete the Section 8898.1 requirements by May 1, 2027, eight months ahead of the statutory deadline.
- Workforce
- Enterprise
- Quality assurance
- Certifications
- AI policy
NJEnacted
"New Jersey Kids Code Act"; adopts New Jersey Age-Appropriate Design Code and requires certain online service providers to implement certain measures concerning minors' use of online service.
Enacted · status as of 2026-08-11
New Jersey Assembly Bill A4015 (Third Reprint), known as the 'New Jersey Age-Appropriate Design Code' (Section 1), addresses online privacy and safety for minors by imposing design and data requirements on covered online service providers operating in New Jersey. The Legislature cites a youth mental health crisis and correlation between high internet usage and depression, anxiety, and suicidal ideation as the basis for the bill (Section 2). 'Covered online service providers' are defined in Section 3 as entities conducting business in New Jersey whose services are reasonably likely to be accessed by minors, with annual gross revenue exceeding $25 million or processing personal data of at least 25,000 consumers. Under Section 4, providers must configure all default privacy settings for covered children and minors to the highest privacy level, including restricting account visibility, direct messaging with adults, location display, search engine indexing, and interaction counts. Section 5 requires a prominent reporting mechanism for harms. Section 6 prohibits default notifications to minors, bans notifications between 10 p.m. and 6 a.m. and during school hours, prohibits targeting minors with ads for drugs, tobacco, gambling, or alcohol, and bans dark patterns. Section 7 restricts use of minors' personal data solely to the purpose for which it was collected and limits algorithmic recommendation systems to specified bases. Section 8 prohibits using age-verification data for other purposes and requires deletion within 15 days. Section 9 requires an accessible account deletion mechanism no more cumbersome than account creation, with unpublishing within 10 business days and permanent deletion within 45 calendar days. Sections 10 through 12 require user interfaces for algorithmic preference controls, real-time signals when geolocation is collected, and reasonable steps to prevent compulsive use. Enforcement under Section 14 allows the Attorney General to bring civil actions and authorizes injured minors or their parents to sue for $5,000 per violation or treble damages, whichever is greater, plus punitive damages for knowing or reckless violations, injunctive relief, and attorney's fees. The bill takes effect on the first day of the 13th month after enactment (Section 17).
- Enterprise
- Quality assurance
- AI policy
NJEnacted
Establishes "Forbidding the Algorithmic Inflation of Rent (FAIR) Act."
Enacted · status as of 2026-07-20
New Jersey Assembly Bill A3497 (First Reprint), known as the 'Forbidding the Algorithmic Inflation of Rent (FAIR) Act,' establishes new prohibitions on the use of algorithmic pricing software in the residential rental market, supplementing the existing New Jersey Antitrust Act (P.L.1970, c.73). The Legislature finds in Section 2 that New Jersey faces an affordable housing crisis, with median rent for three-bedroom apartments rising 35 percent from 2021 to 2024, and more than 50 percent of renters deemed 'rent burdened.' The bill identifies property management software that collects landlords' competitively sensitive information and uses algorithms to set or recommend rental prices as a mechanism for collusion. Section 3 defines key terms including 'algorithmic device,' 'coordinating function,' 'coordinator,' 'competitively sensitive information,' and 'parallel pricing coordination.' Notably, a 'coordinator' is defined as any person operating algorithmic revenue management software or an algorithmic device that performs a coordinating function for any rental property owner. Section 4 makes it unlawful under the New Jersey Antitrust Act for: rental property owners to use the services of a coordinator; coordinators to facilitate anticompetitive agreements among landlords; two or more persons to engage in or facilitate parallel pricing coordination; and any person to perform a coordinating function. Section 5 preserves the full enforcement mechanisms of the existing Antitrust Act. Section 6 prohibits municipalities from enacting conflicting ordinances. Section 7 requires the Attorney General to establish a public complaint portal on the Department of Law and Public Safety website. Section 8 authorizes the Attorney General to adopt implementing regulations. Section 9 sets an effective date of the first day of the twelfth month after enactment.
- Enterprise
- Quality assurance
- AI policy
MSEnacted
Artificial intelligence; define.
Enacted · status as of 2026-03-09
Mississippi House Bill 1723, as sent to the Governor, establishes a statutory definition of 'artificial intelligence' for use in state law. Section 1 defines 'artificial intelligence' as a machine-based system that can, for a given set of human-defined objectives, make predictions, recommendations, or decisions influencing real or virtual environments, using machine- and human-based inputs to perceive environments, abstract perceptions into models through automated analysis, and use model inference to formulate options for information or action. Section 2 directs that this definition be codified in Chapter 3, Title 1 of the Mississippi Code of 1972. Section 3 sets the effective date as July 1, 2026. The bill does not impose regulations, mandates, or restrictions; it solely provides a foundational legal definition.
- AI policy
KYEnacted
AN ACT relating to data privacy.
Enacted · status as of 2026-04-13
Kentucky House Bill 692 (Acts Ch. 118), signed April 13, 2026, amends the Kentucky Consumer Data Protection Act to regulate the viewing data that internet-connected televisions collect about what people watch. Section 1 amends KRS 367.3611 to define "automatic content recognition data" as data about a consumer's content viewing history gathered by technology embedded in a smart television or smart monitor that identifies, in real time, the specific content displayed by analyzing audio or video fingerprints, and to define "smart monitor" as a display device integrating hardware and software to enable internet connectivity, application execution, and independent media streaming. Section 2 amends KRS 367.3617 to add a new duty for controllers: a controller shall not collect automatic content recognition data without a consumer's consent. The act takes effect July 1, 2027.
- Enterprise
- AI policy
NEEnacted
Adopt the Agricultural Data Privacy Act and the Conversational Artificial Intelligence Safety Act
Enacted · status as of 2026-04-14
Nebraska LB 525 (approved by the Governor April 14, 2026) adopts two separate acts. Sections 12 through 18 create the Conversational Artificial Intelligence Safety Act, which regulates publicly accessible artificial intelligence applications that primarily simulate human conversation, and which is directed principally at minors. Section 14 requires an operator to clearly and conspicuously disclose to each minor account holder that they are interacting with artificial intelligence, either as a persistent visible disclaimer or both at the beginning of each session and at least every three hours during a continuous interaction; prohibits providing minors points or similar rewards at unpredictable intervals intended to encourage increased engagement; requires reasonable measures to prevent the service from producing visual depictions of sexually explicit conduct, statements that the minor should engage in sexually explicit conduct, or statements that sexually objectify the minor; requires reasonable measures to prevent statements that would lead a reasonable person to believe they are interacting with a human, including explicit claims of sentience, statements simulating emotional dependence, romantic or sexual innuendo, and role-playing of adult-minor romantic relationships; and requires privacy and account management tools for minor account holders and, for those younger than thirteen, their parents or guardians. Section 15 requires disclosure to any user who would reasonably be misled into believing the service is human. Section 16 requires operators to adopt a protocol for responding to user prompts regarding suicidal ideation or self-harm that makes reasonable efforts to refer the user to crisis services such as a suicide hotline or crisis text line. Section 17 prohibits an operator from knowingly and intentionally programming the service to represent that it is designed to provide professional mental or behavioral health care. Section 18 vests enforcement in the Attorney General. The act excludes developer and research tools, narrow-topic systems, business-internal and customer-service applications, and voice-command assistants. Sections 1 through 10 separately adopt the Agricultural Data Privacy Act, governing the collection and processing of agricultural data linked to identifiable producers.
- Enterprise
- Quality assurance
- AI policy
IDEnacted
Adds to existing law to establish provisions regarding generative artificial intelligence in public education.
Enacted · status as of 2026-03-19
Idaho Senate Bill 1227 (Chapter 71, signed March 19, 2026) adds a new Chapter 70 to Title 33, Idaho Code, titled "Generative Artificial Intelligence in Education." Section 33-7003 directs the State Department of Education to develop a statewide generative artificial intelligence in education framework for K-12 public schools, subject to State Board of Education approval; the framework must prioritize human-centered oversight, transparency, safety, and data security, provide guidance on instructional integration, academic integrity, digital citizenship, and responsible student use, and address accessibility and access to generative AI tools. Section 33-7004 requires every local school district and public charter school to adopt a policy governing the use of generative artificial intelligence by students and employees in school buildings, on school grounds, during school activities, and on school-issued devices; each policy must align with the statewide framework, define appropriate and prohibited uses, include safeguards for student privacy, data security, accessibility, and academic integrity, and comply with the Family Educational Rights and Privacy Act, the Children's Internet Protection Act, and the Children's Online Privacy Protection Act. Section 33-7005 requires the Department to develop generative AI literacy standards for K-12 students, assessment guidelines, and an educator professional development plan. Section 33-7006 requires a guidance document for parents and legal guardians. Section 33-7007 requires that generative AI software procured by districts and charter schools comply with state and federal data privacy law, requires vendors to disclose whether their products use machine learning, predictive analytics, or generative artificial intelligence, and requires vendor assurances on data protection, algorithmic transparency, and responsible use; the Department may publish a list of approved tools. Section 33-7008 grants the State Board rulemaking authority. The act carries an emergency clause and takes effect July 1, 2026.
- Workforce
- Quality assurance
- AI policy
NDEnacted
Artificial intelligence disclosure statements.
Enacted · status as of 2025-04-11
North Dakota HB 1167 (signed April 11, 2025) creates a new section in chapter 16.1-10 of the North Dakota Century Code, the chapter governing corrupt practices in elections, requiring an artificial intelligence disclaimer on political content. Any action taken for a political purpose — including communication and political advertising in support of or opposition to a candidate, political committee, or political party, or to promote the passage or defeat of initiated or referred measures or petitions — that contains images, graphics, videos, audio, text, or other digital content created in whole or in part with artificial intelligence to visually or audibly impersonate a human must prominently state the disclaimer "THIS CONTENT GENERATED BY ARTIFICIAL INTELLIGENCE." The section expressly does not apply to content that uses artificial intelligence solely for text generation, grammar correction, spelling checks, stylistic editing, or enhancing existing content without creating a new impersonation of human likeness or voice. "Artificial intelligence" is defined as a machine-based system capable of creating images, graphics, videos, audio, text, and other digital content based on human-defined objectives or data patterns, excluding systems explicitly programmed with rules or tools designed solely to assist with grammar, spelling, or word suggestions without generating human likeness or voice. Despite the bill's general title, the statute reaches only election-related synthetic impersonation and imposes no artificial intelligence disclosure duty outside the political context.
- Enterprise
- AI policy
ALEnacted
Health care plans; to regulate the use of artificial intelligence in determinations of coverage
Enacted · status as of 2026-04-17
Alabama SB 63 (effective October 1, 2026) limits how health benefit plan providers may use artificial intelligence in coverage determinations and authorizes the Alabama Department of Insurance to investigate and discipline violations. Where AI is used in utilization review, the act requires that it not rely on a group dataset to make determinations, that it be fairly and equitably applied consistent with applicable U.S. Department of Health and Human Services regulations and guidance, and that it not discriminate directly or indirectly against any subscriber group or enrollee. A determination to deny, delay, or modify a request for prior authorization based on medical necessity must always be made by a licensed physician or other health care professional competent to evaluate the artificial intelligence's recommendation in light of the enrollee's specific clinical circumstances. Providers must make prominent written disclosure of their use of artificial intelligence in utilization review in their policies and procedures, periodically review that use and its outcomes for accuracy and reliability, and ensure patient data used by artificial intelligence in utilization review is not used beyond its stated purpose, consistent with HIPAA. Compliance is satisfied by an attestation from an authorized representative of the provider based on reasonable reliance on internal policies, procedures, and third-party vendors. Enforcement runs through the Department: where it has reasonable grounds to believe a provider is making prior-authorization determinations adverse to an enrollee without considering the enrollee's medical history and clinical circumstances, it may notify the provider, which must respond within 30 days, and may hold a hearing if the response is unsatisfactory. The act creates no enrollee appeal right.
- Enterprise
- Quality assurance
- AI policy
SCEnacted
Disclosure of Intimate Images
Enacted · status as of 2025-05-12
South Carolina H. 3058 adds two new sections to state law (Sections 16-15-330 and 16-15-332) to criminalize the intentional dissemination of intimate images or AI-generated ('digitally forged') intimate images without the depicted person's effective consent. Section 16-15-330 defines key terms: a 'digitally forged intimate image' is one generated or substantially modified using machine-learning or computer-generated means to falsely depict a real, identifiable individual; 'effective consent' requires affirmative, conscious, and voluntary authorization; and 'intimate image' covers still or video depictions of genitals, sexual activity, or sexually explicit nudity. Section 16-15-332 creates the offense of unauthorized disclosure of intimate images. Penalties are graduated: if the dissemination is done with intent to cause physical, mental, economic, or reputational harm, or for profit, it is a felony—first offense carries up to $5,000 fine and/or up to 5 years imprisonment; a second or subsequent offense carries up to $10,000 fine and/or 1–10 years imprisonment with no suspended sentence or probation. Without such intent, a first offense is a misdemeanor (up to $5,000 and/or up to 1 year), and a second or subsequent offense is a felony (up to $5,000 and/or up to 5 years). The bill clarifies that consent to create an image does not constitute consent to disseminate it, that intimate images may not be duplicated for criminal discovery, that a violation is a separate offense not precluding other charges, and that images created by law enforcement during lawful criminal investigations are exempt.
- Quality assurance
- AI policy
MEEnacted
An Act to Protect Individuals from the Threatened Unauthorized Dissemination of Certain Private Images, Including Artificially Generated Private Images
Enacted · status as of 2025-06-20
Maine Public Law Chapter 400 (LD 1944 / HP 1303), approved by the Governor on June 20, 2025, extends Maine's law on nonconsensual intimate images to cover artificially generated images, and makes threatening to share such an image a ground for a protective order. Section 2 amends the crime of unauthorized dissemination of certain private images at 17-A MRSA 511-A(1) so that it reaches any "image" rather than only a photograph, videotape, film or digital recording, and expressly covers an image "created or modified so that it appears to show" the depicted person in a state of nudity or engaged in a sexual act or sexual contact. Section 3 adds a definition of "image" at 511-A(3)(D) covering material made, captured, generated or saved as a print, computer data file, animation, videotape, livestream or other reproduced visual image. Sections 1, 4, 5 and 6 do not create a new crime of threatening. They add the act of communicating such a threat, in conscious disregard of the risk that it places the depicted person in reasonable fear, to the definition of "harassment" at 5 MRSA 4651(2) and the definition of "abuse" at 19-A MRSA 4102(1), which are the predicates for protection-from-harassment and protection-from-abuse orders.
- Quality assurance
- AI policy
ILEnacted
THERAPY RESOURCES OVERSIGHT
Enacted · status as of 2025-08-01
Illinois HB1806, the Wellness and Oversight for Psychological Resources Act, regulates the delivery of therapy and psychotherapy services in Illinois with a specific focus on restricting the use of artificial intelligence (AI) in those settings. Under Section 20, no individual, corporation, or entity may provide, advertise, or offer therapy or psychotherapy services—including through internet-based AI—unless the services are conducted by a licensed professional (as defined in Section 10), such as a licensed clinical psychologist, licensed clinical social worker, licensed professional counselor, or licensed marriage and family therapist, among others. Section 15 permits licensed professionals to use AI only for 'administrative support' (e.g., scheduling, billing) or 'supplementary support' (e.g., maintaining client records, analyzing anonymized data), provided the licensed professional maintains full responsibility for all outputs. If a therapeutic session is recorded or transcribed and AI is used for supplementary support, the client must be informed in writing of the AI's use and specific purpose, and must provide explicit, revocable written consent (Section 15(b)). Section 20(b) prohibits licensed professionals from allowing AI to make independent therapeutic decisions, directly interact with clients in therapeutic communication, generate treatment plans without professional review, or detect emotions or mental states. Section 25 requires all records and communications to remain confidential under the Mental Health and Developmental Disabilities Confidentiality Act. Section 30 establishes civil penalties of up to $10,000 per violation, assessed by the Department of Financial and Professional Regulation after a hearing, payable within 60 days of the Department's order. Section 35 exempts religious counseling, peer support, and general self-help or educational materials from the Act's requirements. The Act takes effect upon becoming law (Section 99).
- Enterprise
- Quality assurance
- Certifications
- AI policy
NYEnacted
Relates to the training and use of artificial intelligence frontier models; defines terms; establishes remedies for violations.
Enacted · status as of 2025-12-19
The New York RAISE Act (S. 6953-B) amends the General Business Law by adding Article 44-B to regulate the training and deployment of high-powered AI systems called 'frontier models.' A 'frontier model' is defined in Section 1420 as an AI model trained using more than 10^26 computational operations with a compute cost exceeding $100 million, or a distilled model derived from such a system costing more than $5 million. A 'large developer' is any person who has trained at least one frontier model and spent over $100 million in aggregate compute costs, excluding accredited colleges and universities engaged in academic research. Under Section 1421, before deploying a frontier model, large developers must: implement a written safety and security protocol; retain unredacted copies of that protocol for the duration of deployment plus five years; publish a redacted version and transmit it to the Attorney General and the Division of Homeland Security and Emergency Services; record and retain test results in sufficient detail for third-party replication; and implement safeguards against unreasonable risk of 'critical harm.' Large developers are prohibited from deploying a frontier model if doing so would create an unreasonable risk of critical harm—defined in Section 1420 as causing death or serious injury to 100 or more people or at least $1 billion in damages through CBRN weapons or autonomous AI criminal conduct. Annual protocol reviews are required, and safety incidents must be disclosed to state authorities within 72 hours of discovery. Section 1422 authorizes the Attorney General to bring civil actions with penalties up to $10 million for a first violation and $30 million for subsequent violations, but establishes no private right of action. Section 1424 limits the law's scope to frontier models developed, deployed, or operating in whole or in part in New York. The act takes effect 90 days after enactment.
- Enterprise
- Quality assurance
- Certifications
- AI policy
HIEnacted
Relating To Artificial Intelligence.
Enacted · status as of 2026-07-14
Hawaii H.B. 2137 (H.D. 3 / S.D. 2 / C.D. 1), introduced in the Thirty-Third Legislature (2026), creates a new chapter of the Hawaii Revised Statutes governing AI-generated realistic digital imitations of individuals. Section 1 finds that deepfake technology enables harmful identity imitation—including fraud, election interference, and non-consensual pornography—and that expert detection rates are as low as 62 percent. The bill's stated purpose is to prohibit certain harmful uses of AI-generated personal likenesses and to provide civil remedies. Section 2 (§-2) makes it unlawful to knowingly publish a realistic digital imitation of an identifiable individual without consent if it is used in an advertisement, causes harm, or is used to commit fraud, defamation, harassment, or other criminal acts. Section 3 (§-3) exempts parody, satire, commentary, criticism, scholarship, political or educational expression, news reporting, documentary or biographical representations (with some fictionalization), and advertisements for such exempt works. Section 4 (§-4) establishes civil remedies, allowing injured individuals or their estates—for up to ten years after the individual's death—to seek injunctive relief (including removal orders), monetary damages up to $25,000 per advertisement or actual damages for reputational injury and emotional distress, punitive damages where malice is proven, and reasonable attorneys' fees and court costs. The Attorney General may also bring equitable actions where widespread public harm is involved. Section 5 (§-5) limits liability of passive media platforms disseminating third-party content and preserves existing Section 230 protections. The Act takes effect upon approval.
- Enterprise
- Quality assurance
- AI policy
TXEnacted
Relating to regulation of the use of artificial intelligence systems in this state; providing civil penalties.
Enacted · status as of 2025-06-22
H.B. No. 149, the Texas Responsible Artificial Intelligence Governance Act (Section 1), establishes a comprehensive framework for regulating artificial intelligence (AI) systems in Texas, effective January 1, 2026 (Section 10). The bill adds a new Subtitle D to Title 11, Business & Commerce Code, comprising Chapters 551–554. Chapter 551 (Section 4) defines key terms, including 'artificial intelligence system' as any machine-based system that infers from inputs how to generate outputs such as content, decisions, or recommendations. The subtitle applies to any person who promotes or conducts business in Texas, produces products used by Texas residents, or develops or deploys an AI system in the state (Sec. 551.002). Chapter 552 establishes core duties and prohibitions: governmental agencies that make AI systems available to consumers must disclose the interaction before or at the time it occurs (Sec. 552.051); no person may deploy an AI system intended to incite self-harm, harm to others, or criminal activity (Sec. 552.052); governmental entities may not use AI for social scoring that causes detrimental treatment or rights violations (Sec. 552.053); governmental entities may not use AI to uniquely identify individuals via biometric data without consent in ways that infringe legal rights (Sec. 552.054); no person may deploy AI with the sole intent to infringe constitutionally guaranteed rights (Sec. 552.055); no person may develop or deploy AI with intent to unlawfully discriminate against a protected class, though disparate impact alone is insufficient to show intent (Sec. 552.056); and AI systems must not be designed to produce child sexual abuse material or deepfakes in violation of Penal Code Sections 43.26 and 21.165 (Sec. 552.057). Local governments are preempted from adopting separate AI regulations (Sec. 552.003). Enforcement is vested exclusively in the attorney general, with no private right of action (Sec. 552.101). Violators receive a 60-day notice-and-cure period before the attorney general may bring suit (Sec. 552.104). Civil penalties range from $10,000–$12,000 per curable violation, $80,000–$200,000 per uncurable violation, and $2,000–$40,000 per day for continued violations (Sec. 552.105). State licensing agencies may impose additional sanctions, including license revocation and up to $100,000 in monetary penalties, upon attorney general recommendation (Sec. 552.106). Chapter 553 creates a regulatory sandbox program administered by the Texas Department of Information Resources, allowing persons to test AI systems for up to 36 months without standard licensing requirements, subject to quarterly reporting and ongoing oversight (Secs. 553.051–553.103). Chapter 554 establishes the seven-member Texas Artificial Intelligence Council, administratively attached to the Department of Information Resources, to advise the legislature, conduct studies, provide training to state agencies, and oversee the sandbox program, but without binding rulemaking authority (Secs. 554.001–554.103). The bill also amends Section 503.001, Business & Commerce Code (Section 2) to tighten biometric identifier consent rules, clarifying that publicly available images do not constitute consent unless posted by the individual, and to exempt AI training use of biometric data unless used to uniquely identify individuals; amends Section 541.104(a) (Section 3) to require data processors to assist controllers with AI-related data security; amends Section 325.011, Government Code (Section 5) to add AI use as a criterion in sunset reviews of state agencies; and amends Sections 2054.068(b) and 2054.0965(b), Government Code (Sections 6–7) to require state agencies to report and inventory their AI system use to the Department of Information Resources.
- Enterprise
- Quality assurance
- Certifications
- AI policy
HIEnacted
Relating To Artificial Intelligence.
Enacted · status as of 2026-07-14
Hawaii S.B. 3001 (S.D. 2 / H.D. 3 / C.D. 1), the 'Artificial Intelligence Disclosure and Safety Act,' amends Chapter 481B of the Hawaii Revised Statutes by adding a new section governing AI companion systems. Under Section 3, operators of AI companions must issue clear, conspicuous disclosures whenever a reasonable person might believe they are interacting with a human. When an operator knows or has reasonable certainty a user is a minor, enhanced disclosures are required—either as a persistent visible disclaimer or at session start and at least once per hour during continuous interactions. Operators must adopt crisis-intervention protocols that refer users expressing suicidal ideation or self-harm to services such as suicide hotlines or crisis text lines, use evidence-based risk measurement methods, and refrain from representing the AI companion as a professional mental health provider. Additional protections for known minor users include prohibitions on unpredictable reward systems designed to increase engagement, outputs discouraging disengagement, and sexually explicit or objectifying content, as well as a requirement to provide screen-time management tools for users, parents, and guardians. Beginning January 1, 2028, operators must submit annual reports to the Behavioral Health Administration of the Department of Health detailing the number of crisis referrals issued, protocols for detecting self-harm prompts, and protocols prohibiting AI responses promoting self-harm or suicide—without including any personal user information. Violations constitute unfair or deceptive acts or practices under Section 480-2, but the bill does not create a private right of action. Liability does not extend to third-party AI model developers for violations committed by operators using their models. The Act takes effect upon approval.
- Enterprise
- Quality assurance
- AI policy
COEnacted
Automated Decision-Making Technology in Consequential Decisions
Enacted · status as of 2026-05-14
Senate Bill 26-189, signed by Governor Polis on May 14, 2026 as Chapter 131, repealed Colorado's 2024 Artificial Intelligence Act and reenacted part 17 of article 1 of title 6 of the Colorado Revised Statutes in its place. Where the 2024 law regulated "high-risk artificial intelligence systems" through a duty of reasonable care against algorithmic discrimination, the replacement regulates "covered automated decision-making technology" — technology that processes personal data to materially influence a consequential decision — and is built on disclosure and consumer rights rather than risk management. A consequential decision is one relating to a consumer's access to, eligibility for, selection for or compensation in a covered domain: education enrollment or opportunity, employment, the lease or purchase of residential real estate in Colorado, financial or lending services, insurance including underwriting, pricing and claims adjudication, health-care services, and essential government services and public benefits including eligibility and renewal determinations. Low-stakes and routine decisions such as scheduling, classroom personalization and administrative routing are excluded. On and after January 1, 2027, a developer must give each deployer a general statement describing the intended and known harmful or inappropriate uses of the technology and a description of the categories of data, including personal data, used to train it. Before a deployer uses covered ADMT to materially influence a consequential decision it must give the consumer clear and conspicuous notice, and when a consumer experiences an adverse outcome the deployer must on request provide instructions for accessing and correcting inaccurate personal data and an opportunity for meaningful human review and reconsideration, to the extent commercially reasonable. The Attorney General enforces the part through the Colorado Consumer Protection Act as a deceptive trade practice, with a sixty-day right to cure that does not apply where a violation is knowing or repeated. The act creates no new private right of action. It took effect on passage under a safety clause and applies to consequential decisions made on or after January 1, 2027.
- Workforce
- Enterprise
- AI policy
CAEnacted
State Bar of California: artificial intelligence.
Enacted · status as of 2026-08-22
Assembly Bill 1651 (Chapter 116) adds Section 6060.15 to the Business and Professions Code, requiring the State Bar of California to disclose when artificial intelligence-generated content is used in developing or administering its bar examinations and related study materials. Specifically, for any AI-generated content developed by or at the explicit direction of the State Bar, the bill mandates two types of disclosure: (1) a notice posted on the State Bar's website at least 60 days before any examination in which AI-generated content is used—covering questions, performance tests, answer keys, and scoring rubrics—and (2) a disclosure on the cover page of any study materials the State Bar prepares, publishes, endorses, or distributes, including sample questions, model answers, outlines, and other instructional content. These disclosure requirements apply regardless of whether a human has reviewed or revised the AI-generated content. The bill defines 'artificial intelligence-generated content' as visual or textual content generated in whole or in part by generative AI, and 'State Bar examinations' as the general bar examination, the first-year law students' examination (Section 6060), and the attorneys' examination (Section 6062). The bill takes effect and becomes operative on January 1, 2028.
- Quality assurance
- Certifications
- AI policy
WAEnacted
Making improvements to transparency and accountability in the prior authorization determination process.
Enacted · status as of 2026-03-23
Engrossed Second Substitute Senate Bill 5395, approved March 23, 2026 as Chapter 157 of the Laws of 2026, tightens who and what may deny a health insurance claim in Washington. The Legislature found that artificial intelligence "is being increasingly utilized by health carriers to make or aid in decisions about medical necessity and coverage of provider-recommended treatment." The act amends RCW 48.43.830, 41.05.845, 48.43.525, 48.43.535 and 48.43.0161 to provide that only a licensed physician or a licensed health professional working within their scope of practice may deny a prior authorization request based on medical necessity, and that the reviewer must evaluate the specific clinical issues by considering the requesting provider's recommendation, the enrollee's medical or other clinical history, and individual clinical circumstances. The operative sentence is short: "Artificial intelligence shall not be the sole means used to deny, delay, or modify health care services. Algorithms may be used to process and approve prior authorization requests, but may not be used without human review to deny care based on a determination of medical necessity." A carrier that uses artificial intelligence for medical-necessity prior authorization, directly or through a contracted entity, must ensure the system bases its determination on the enrollee's own clinical history and individual circumstances rather than a group data set alone, does not discriminate directly or indirectly, is fairly and equitably applied, is periodically reviewed for accuracy and reliability, keeps patient data within its stated purpose, and keeps its policies and procedures open to audit by the Office of the Insurance Commissioner. Carriers' annual prior-authorization reports must disclose the percentage of total denials that were aided by artificial intelligence. The bill passed the House 94-0 and the Senate 49-0 and takes effect June 11, 2026, except two sections that take effect January 1, 2027.
- Quality assurance
- AI policy
CAEnacted
Artificial intelligence: defenses.
Enacted · status as of 2025-10-13
California Assembly Bill 316 (Chapter 672), signed October 13, 2025, adds Section 1714.46 to the Civil Code to close a potential liability loophole in AI-related civil actions. The bill prohibits any defendant who developed, modified, or used artificial intelligence from asserting as a defense that the AI 'autonomously caused' harm to a plaintiff. The bill defines 'artificial intelligence' as an engineered or machine-based system that varies in autonomy and can infer from inputs how to generate outputs influencing physical or virtual environments (Section 1714.46(a)). While the autonomous-causation defense is barred (Section 1714.46(b)), the bill expressly preserves defendants' ability to raise other affirmative defenses—including evidence on causation and foreseeability—and to introduce evidence of comparative fault by other parties (Section 1714.46(c)). In short, human developers, modifiers, and users of AI remain legally accountable for harms their AI systems cause and cannot deflect liability by claiming the AI acted on its own.
- Enterprise
- Quality assurance
- AI policy
LAEnacted
Provides relative to unlawful conduct involving images of another person created by artificial intelligence (EN SEE FISC NOTE GF EX)
Enacted · status as of 2026-06-09
This Louisiana bill addresses unlawful conduct involving images of another person that are created by artificial intelligence. The bill establishes prohibitions or regulations around the generation, distribution, or use of AI-created images depicting real individuals without authorization. The fiscal note indicates a general fund expenditure impact.
- AI policy
GAEnacted
Private Review Agents; certain decisions with regard to the provision of insurance coverage for healthcare services shall not be based solely on artificial intelligence systems; provide
Enacted · status as of 2026-05-05
Senate Bill 444, signed May 5, 2026 as Act 411, adds Code section 33-46-7.1 to Chapter 46 of Title 33 of the Official Code of Georgia Annotated, which governs the certification of private review agents. The act permits private review agents and utilization review entities to use artificial intelligence, artificial intelligence systems and other software tools, provided those tools are part of a utilization review plan meeting the chapter's standards and the Insurance Commissioner's rules, and it expressly allows them to automate tasks, reduce administrative burdens and participate in decision-making. The limit falls on the denial itself: such a system "shall not issue an adverse determination to a patient until a natural person qualifying as a private review agent or a utilization review entity conducts a utilization review in which a clinical peer participates," and "in no event shall artificial intelligence systems, artificial intelligence, or other software tools supersede the judgment of such clinical peer." The act defines artificial intelligence as a machine-based system that can, for a given set of human-defined objectives, make predictions, recommendations or decisions influencing real or virtual environments, and an artificial intelligence system as an engineered or machine-based system that emulates a human cognitive process such as learning, generalizing, reasoning, planning or predicting. It becomes effective January 1, 2027.
- Quality assurance
- Certifications
- AI policy
AZVetoed
Artificial intelligence; state agencies; rules
Vetoed · status as of 2026-06-19
Arizona House Bill 2592 (57th Legislature, 2nd Regular Session, 2026) adds Section 18-105 to Title 18, Chapter 1, Article 1 of the Arizona Revised Statutes, directing the state's IT director to regulate how state budget units adopt and govern artificial intelligence systems. Under Section 18-105(A), the director must require each budget unit to identify AI implementation opportunities that reduce administrative burdens, eliminate regulations that unnecessarily restrict AI innovation, streamline AI procurement, establish enterprise AI governance, review existing AI-related regulations for regulatory capture or competitive harm, and modify or eliminate rules that create unreasonable barriers to AI innovation. Section 18-105(B) requires that AI implementation focus on reducing costs and improving service delivery, prohibits creating new regulatory requirements solely applicable to private-sector AI development, and limits new administrative bodies. Section 18-105(C) restricts budget units from adopting rules specifically regulating AI systems or computational resources unless the legislature provides an express statutory delegation targeting a specific harm, the rule uses the least restrictive means, its benefits clearly outweigh innovation and competition impacts, and it does not create market-entry barriers or favor incumbent firms. Section 18-105(D) requires the director to submit an annual report by December 1 to the Senate President, House Speaker, and Governor (with a copy to the Secretary of State) covering each budget unit that implemented an AI system, the functions to which AI was applied, quantitative and qualitative efficiency measures (processing time, cost savings, service quality), and any regulatory, procurement, or operational barriers encountered. Section 18-105(E) provides definitions for 'artificial intelligence system,' 'computational resource,' and 'content.'
- Enterprise
- Quality assurance
- AI policy