AI Frontier Institute

Enact the Ohio Right to Compute Act

OHHB392In committee
Published automatically

View primary source →

Ohio Am. H.B. No. 392, as reported by the House Technology and Innovation Committee, has not been enacted. If enacted, it would create section 9.89 of the Revised Code and be known as the Ohio Right to Compute Act (Section 2). Under division (B), no political subdivision or state agency could enact, adopt, enforce, or maintain any law, rule, regulation, permit requirement, or other administrative practice that restricts or prohibits a person's lawful use, development, deployment, or possession of a computational resource. The exception is a restriction that is narrowly tailored to achieve a compelling governmental interest. "Computational resource" is defined broadly. It covers hardware, software, algorithms, cryptography, AI and machine learning systems, and quantum computing tools. "Compelling governmental interest" is defined as an interest of the highest order in protecting the public that cannot be achieved without burdening lawful use of computational resources. Its listed examples are: keeping critical infrastructure facilities reliably operating; addressing deceptive practices and fraud; protecting minors and vulnerable people from harmful AI-generated content, such as nonconsensual deepfakes; remediating public nuisances tied to computational resource infrastructure; and governing employee use of AI by the state agency or political subdivision. Under division (C)(1), any person or entity that implements or operates an AI system that wholly or partly controls a critical infrastructure facility must, before or within a reasonable period after deployment, adopt a risk management policy. The policy must conform to applicable federal regulations and to either the latest NIST AI risk management framework or the ISO/IEC 42001 standard (written in the bill as "4200") or another nationally or internationally recognized AI risk management standard. Division (C)(2) exempts AI systems that only perform nonexecutive procedural or preparatory tasks, only implement decisions a human previously made, or are exclusively antivirus, antimalware, or cybersecurity tools. Division (D) states the section does not abridge or conflict with intellectual property rights and remedies, including patent, trademark, copyright, and trade secret protections.

Status history

Current status as of 2025-07-07

  1. In committee

    2025-07-07

    observed 2026-08-27

Impact areas

← Back to the tracker