Artificial intelligence service; disclosures; requirements
Arizona House Bill 2311 (57th Legislature, 2nd Regular Session, 2026) amends Title 18 of the Arizona Revised Statutes by adding Chapter 8 on Artificial Intelligence, effective September 30, 2027. The bill regulates operators of conversational AI services—publicly accessible AI applications that simulate human conversation—and imposes several requirements. Under Section 18-802, operators must clearly and conspicuously disclose to account holders that they are interacting with a conversational AI service, either as a persistent visible disclaimer or at the start of each session and at least every three hours. Operators are prohibited from rewarding minor account holders with unpredictable points or engagement incentives. Operators must implement reasonable measures to prevent the AI from producing sexual content, generating statements that encourage sexual conduct, or sexually objectifying users. For minor account holders specifically, operators must prevent the AI from simulating sentience, emotional dependence, romantic or sexual innuendo, or adult-minor romantic role-play. Operators must offer privacy and account management tools to minor account holders and, for those under 13, to their parents or guardians. Operators must adopt a protocol for responding to prompts about suicidal ideation or self-harm, including referring users to crisis services, and may not program the AI to encourage or glorify self-harm. Operators may not represent the AI as a professional mental or behavioral health care provider. Unless federal law requires it, operators may not mandate a digital identification system solely to verify a user's minor status; if a digital ID system is voluntarily offered, a privacy-preserving alternative must be available. Age-assurance data may only collect the minimum necessary information, may not be repurposed for advertising or profiling, and must be deleted or de-identified after the compliance purpose is satisfied. Data collected for compliance may not be used, sold, or shared for targeted advertising or behavioral profiling. Government entities may not compel disclosure of such data without a warrant based on probable cause, and operators must notify affected account holders within 72 hours of disclosure unless a court order prohibits it. Operators must annually certify under penalty of perjury that compliance data is destroyed or de-identified, and publish a publicly accessible aggregate report on their age-assurance methods. Violations are subject to injunctions and civil penalties of $1,000 per violation, not to exceed $500,000 per operator. Enforcement is limited to the attorney general; no private right of action is created. AI model developers are not liable for violations by third-party operators. The bill explicitly prohibits using the law to track users' general online activity, regulate protected speech, require digital identification for general internet access, or compel device-level age verification.
Status history
Current status as of 2026-06-19
Vetoed
2026-06-19
observed 2026-09-06
Impact areas
- Enterprise Adoption
- Quality Assurance
- AI Policy
- Privacy & Data Protection
- Safety & Harms
- Algorithms & Automated Decisions