AI Frontier Institute

Protecting consumers in interactions with artificial intelligence systems

MAH97In committee
Published automatically

View primary source →

House Bill 97 (Massachusetts, 194th General Court) has not been enacted. It was reported favorably by the Joint Committee on Advanced Information Technology, the Internet and Cybersecurity and referred to House Ways and Means. If enacted, it would add a new Chapter 93M to the General Laws, "Consumer Protections in interactions with Artificial Intelligence Systems." The chapter would regulate "high-risk" AI systems, meaning systems that make or are a substantial factor in making "consequential decisions" about Massachusetts residents. Those decisions cover education, employment, financial or lending services, essential government services, health care, housing, insurance and legal services (Section 1). Developers (Section 2): they would have to use reasonable care to protect consumers from known or reasonably foreseeable algorithmic discrimination. They would have to give deployers documentation on training data, limitations, evaluation, and mitigation measures. They would have to publish a public statement of the high-risk systems they offer and how they manage discrimination risk. They would have to report discovered discrimination risks to the attorney general and known deployers within ninety days. Trade secrets and security-risk information need not be disclosed. Deployers (Section 3): they would have to use reasonable care and implement a risk management policy and program that takes account of the NIST AI Risk Management Framework, ISO/IEC 42001, or a similar framework. They would have to complete impact assessments at least annually and within ninety days after a substantial modification, and keep the records for at least three years after final deployment. They would have to review each deployed system at least annually for algorithmic discrimination. Before a consequential decision they would have to notify the consumer that a high-risk system is in use. For adverse decisions they would have to explain the principal reasons, allow correction of incorrect personal data, and allow an appeal with human review if technically feasible. They would have to publish a website statement describing their systems and data practices. They would have to report discovered discrimination to the attorney general within ninety days. Some obligations in subsections (b), (c) and (e) are lifted for small deployers (fewer than fifty full-time equivalent employees) that meet the listed conditions. Section 4: anyone offering an AI system intended to interact with consumers would have to disclose that the consumer is interacting with AI, unless that is obvious to a reasonable person. Section 5 provides exemptions and deemed-compliance provisions. They cover legal compliance, research, certain federally approved or federally regulated systems, HIPAA covered entities making certain health-care recommendations, insurers subject to chapter 175 and insurance commissioner rules, and banks and credit unions under equivalent prudential regulator oversight. The party claiming an exemption bears the burden of proof. Enforcement (Section 6): the attorney general would have exclusive enforcement authority, and a violation would be an unfair trade practice under chapter 93A. There is an affirmative defense for violations that are discovered and cured through feedback, adversarial testing or red teaming, or internal review, if the party is otherwise compliant with a recognized risk framework. There is no private right of action. Section 7 authorizes the attorney general to issue implementing rules. The act would take effect no later than 6 months after passage (SECTION 2).

Status history

Current status as of 2025-02-27

  1. In committee

    2025-02-27

    observed 2026-07-21

Impact areas

← Back to the tracker