Providing consumer protections for artificial intelligence systems.
HB 2667 has not been enacted. It was read for the first time on 2026-01-26 and referred to the Technology, Economic Development, & Veterans committee. If enacted, it would set up a risk-based consumer protection framework for "high-risk artificial intelligence systems" in Washington. These are AI systems that make, or are a substantial factor in making, "consequential decisions" (Sec. 2). Consequential decisions are those with a material legal or similarly significant effect on access to parole or release, education, employment, financial or lending services, essential government services, health care, housing, insurance, or legal services. The bill is aimed at algorithmic discrimination. Deployer duties: - Sec. 3: Starting July 1, 2027, deployers must use industry-standard means to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination. Compliance with the chapter creates a rebuttable presumption of reasonable care in attorney general enforcement. Deployers must review each system at least annually. They must notify the attorney general within 90 days of discovering that a system has caused algorithmic discrimination. - Sec. 4: Starting July 1, 2027, deployers must keep a risk management policy and program. It may follow the NIST AI risk management framework, ISO/IEC 42001, or a framework the attorney general designates. - Sec. 5: Deployers must complete impact assessments, including for substantial modifications. They must keep the assessments and supporting records for at least three years after final deployment. - Sec. 6: Small deployers (fewer than 50 full-time equivalent employees) that meet certain conditions are exempt from the impact assessment and annual review requirements. One condition is that they make the developer's impact assessment available to consumers. - Sec. 7: Starting July 1, 2026, deployers must tell consumers before a consequential decision that a high-risk AI system is being used. They must also give a plain-language statement of its purpose, the deployer's contact information, and a description of the system. Exemptions and enforcement: - Sec. 8 protects trade secrets and lists exemptions. These include legal compliance, research, federally approved or certified systems, certain federal contract work, and certain HIPAA-covered entity health recommendations. The party claiming an exemption bears the burden of showing it applies. - Sec. 9: The attorney general would be the enforcer, treating violations as Consumer Protection Act violations. The attorney general must give 45 days' written notice. For a first violation, the developer or deployer has 60 days to cure. Private actions under RCW 19.86.090 are barred. Government disclosure and task force: - Sec. 10: Government agencies offering AI systems that interact with consumers must clearly disclose, in plain language and without dark patterns, that the consumer is interacting with AI. - Sec. 13: Amends the 2024 AI task force law (2024 c 163 s 2). It removes the "subject to appropriation" condition, moves the final report deadline to July 1, 2027, and extends expiration to June 30, 2028. - Sec. 14: Creates an AI workplace advisory group appointed by the attorney general. It would develop guiding principles for AI in the workplace, with an interim report due December 1, 2026 and a final report due March 1, 2027. It expires June 30, 2028.
Status history
Current status as of 2026-01-26
In committee
2026-01-26
observed 2026-07-21
Impact areas
- Workforce Impacts
- Enterprise Adoption
- Quality Assurance
- AI Policy
- Public Sector Use
- Algorithms & Automated Decisions