AI Frontier Institute

Labor: fair employment practices; use of electronic monitoring or automated decisions tools by an employer; prohibit except for certain purposes. Creates new act.

MISB1077In committee
Published automatically

View primary source →

Michigan Senate Bill 1077, the 'Responsible Artificial Intelligence Security for Employees Act,' regulates employer use of automated decisions tools (AI/algorithmic systems) and electronic monitoring tools in the workplace. Under Section 4, employers are generally prohibited from using automated decisions tools to make employment-related decisions, with a narrow exception allowing their use to screen large volumes of job applications for hiring criteria or job skills assessment. Section 5 permits electronic monitoring tools only for specified purposes such as facilitating job functions, monitoring production quality, assessing performance, ensuring legal compliance, protecting health and safety, or administering wages and benefits under limited conditions. Employers must provide written notice and obtain written consent from covered individuals (employees and applicants) before using such tools, ensure data accuracy, allow individuals to correct their data, and use tools in the least invasive, narrowly tailored manner. Section 5 also prohibits collecting sensitive data categories including health information, qualified characteristics (race, sex, disability, etc.), and detailed workplace communications, and bars use of facial, gait, voice, or emotion recognition technology. Section 7 limits data retention to three years after the tool's purpose is achieved, prohibits selling or licensing covered individuals' data, and restricts sharing data with government entities. Section 9 requires employers to commission independent third-party impact assessments before deploying any such tool, evaluating algorithmic bias, disparate impact on protected classes, cybersecurity vulnerabilities, accessibility for disabled individuals, and privacy effects; assessments must be submitted to the Department of Labor and Economic Opportunity for a public registry and distributed to affected covered individuals within 60 days of completion, with annual reassessments required. Section 11 mandates that in the event of a data security breach, employers must notify affected individuals within 48 hours, provide ten years of paid identity theft protection with at least $5,000,000 in insurance coverage per individual, credit monitoring, dark web monitoring, and related protections, and notify the department and attorney general. Section 13 requires 30-day advance written notice of tool implementation to employees and applicants, including opt-out rights; if an individual opts out, the tool may not be used for employment-related decisions affecting that individual. Section 15 provides a private right of action for aggrieved covered individuals, including labor organizations acting on their behalf, for damages, injunctive relief, costs, and attorney fees, and establishes civil fines of up to $500 per violation enforceable by county prosecutors or the attorney general. Section 17 preserves collective bargaining rights, requiring employers to provide bargaining representatives with notice, impact assessments, and breach data at least 30 days before bargaining begins. Section 19 directs the Department of Labor and Economic Opportunity to promulgate implementing rules.

Status history

Current status as of 2026-06-24

  1. In committee

    2026-06-24

    observed 2026-08-30

Impact areas

← Back to the tracker