AI Policy Tracker
Federal and state AI bills and executive actions — each sourced, status-dated, and summarized in plain English. Filter by jurisdiction, status, or impact area, or search by keyword.
Where we’re tracking AI legislation
- Has published items28 jurisdictions
- Tracked, in review20 jurisdictions
- Nothing tracked yet3 jurisdictions
Shading shows whether the tracker has published items for a jurisdiction — not how much AI activity happens there, and not a rating of the state.
Small jurisdictions
Hard to hit on the map — use these. Jurisdictions with no note have no AI bills in the tracker yet.
All jurisdictions A–Z
Jurisdictions with no note have no AI bills in the tracker yet.
- Alabama1 published
- Alaska3 in review
- Arizona1 published
- Arkansas
- California6 published
- Colorado2 published
- Connecticut1 published
- Delaware4 in review
- District of Columbia3 in review
- Florida12 in review
- Georgia1 published
- Hawaii2 published
- Idaho1 published
- Illinois1 published
- Indiana4 in review
- Iowa18 in review
- Kansas1 published
- Kentucky1 published
- Louisiana1 published
- Maine1 published
- Maryland2 published
- Massachusetts34 in review
- Michigan8 in review
- Minnesota41 in review
- Mississippi1 published
- Missouri15 in review
- Montana
- Nebraska1 published
- Nevada
- New Hampshire4 in review
- New Jersey2 published
- New Mexico5 in review
- New York1 published
- North Carolina17 in review
- North Dakota1 published
- Ohio13 in review
- Oklahoma17 in review
- Oregon1 published
- Pennsylvania26 in review
- Rhode Island1 published
- South Carolina1 published
- South Dakota3 in review
- Tennessee1 published
- Texas1 published
- Utah1 published
- Vermont13 in review
- Virginia1 published
- Washington2 published
- West Virginia5 in review
- Wisconsin11 in review
- Wyoming1 published
48 policy items
TNEnacted
AN ACT to amend Tennessee Code Annotated, Title 29; Title 37 and Title 47, relative to artificial intelligence.
Enacted · status as of 2026-05-27
This Tennessee law requires the Tennessee Advisory Commission on Intergovernmental Relations (TACIR) to conduct a study on the potential regulation of artificial intelligence systems and generative artificial intelligence chatbots in the state. The legislation amends Tennessee Code Annotated (TCA) Title 29, Title 37, and Title 47.
- AI policy
- Quality assurance
KSEnacted
Senate Substitute for HB 2313 by Committee on Federal and State Affairs - Prohibiting the use of the artificial intelligence platform DeepSeek and other artificial intelligence platforms controlled by a country of concern on state-owned devices and on any state network and the use of genetic sequencers or operational software used for genetic analysis that is produced in a foreign adversary.
Enacted · status as of 2025-04-08
Kansas Senate Substitute for House Bill 2313 (Chapter 84, 2025 Session Laws of Kansas; approved by the Governor April 8, 2025) restricts foreign-controlled technology in two areas of state activity. Section 1 prohibits any electronic device owned by or issued to an employee of a state agency from being used to access an “artificial intelligence platform of concern,” and requires every network operated by a state agency to prohibit the use of such platforms by anyone accessing that network. A state agency that already uses one, or holds an account with one, must deactivate and delete the account. The prohibition does not apply where the access is for law enforcement activities or cybersecurity investigations. The act defines an artificial intelligence platform of concern as the model commonly referred to as DeepSeek, together with any model owned or controlled, directly or indirectly, by Hangzhou DeepSeek Artificial Intelligence Basic Technology Research Company or a subsidiary or successor, and any artificial intelligence model controlled, directly or indirectly, by a country of concern. Countries of concern are the People’s Republic of China including Hong Kong, Cuba, Iran, North Korea, Russia and Venezuela; Taiwan is expressly excluded. Section 2 bars any medical or research facility in the state that receives state money from using genetic sequencers, or the operational and research software used to run them, produced in or by a foreign adversary, a state-owned enterprise of a foreign adversary, a company domiciled within one, or a subsidiary such a company owns or controls. Prohibited equipment that is not permanently disabled must be removed and replaced, and facilities could request reimbursement from the state treasurer for the cost of replacement, subject to appropriations, where the request was submitted before October 1, 2025. The foreign-adversary definition adds Syria and allows the Governor, in consultation with the adjutant general, to designate further entities. Section 2 is severable. The act takes effect from and after its publication in the statute book.
- Enterprise
- Quality assurance
- AI policy
RIEnacted
Establishes regulations regarding the use of artificial intelligence in mental health care treatments.
Enacted · status as of 2026-06-22
This Rhode Island bill establishes regulations governing the use of artificial intelligence technology in mental health care treatments, falling under the purview of the state's Behavioral Healthcare, Developmental Disabilities and Hospitals authority. The legislation creates a framework specifically focused on overseeing how AI is deployed in mental health care settings.
- AI policy
- Quality assurance
- Certifications
VAEnacted
Artificial intelligence; framework for person/entity acting as an independent verification org.
Enacted · status as of 2026-04-08
Virginia Chapter 426 (S 384), approved April 8, 2026, directs the Joint Commission on Technology and Science (JCOTS) to evaluate the feasibility and impact of creating a framework for independent verification organizations (IVOs) that assess AI models or applications for adherence to best-practice standards aimed at preventing personal injury and property damage. In conducting this evaluation, JCOTS must consider: (i) the nature and magnitude of AI-related risks in Virginia; (ii) availability of measurable risk metrics; (iii) existing technical and operational mitigation standards for AI deployers and developers in the Commonwealth; (iv) current methodologies used to evaluate mitigation efficacy; (v) other states' practices for assessing AI adherence to industry standards; and (vi) the fiscal impact of implementing such a framework. If JCOTS recommends developing the framework, it must also evaluate (a) the feasibility of a licensing scheme for IVOs and (b) whether the Virginia Information Technologies Agency or another state agency could implement and manage that licensing scheme. JCOTS must submit its report and recommendations to the Chairs of the relevant Senate and House committees no later than November 1, 2026.
- AI policy
- Certifications
- Quality assurance
- Enterprise
WAEnacted
Informing users when content is developed or modified by artificial intelligence.
Enacted · status as of 2026-03-24
This bill requires that users be informed when content has been developed or modified by artificial intelligence. The measure establishes a disclosure obligation so that individuals interacting with or receiving AI-generated or AI-modified content are made aware of that fact.
- AI policy
- Quality assurance
WYEnacted
Protecting kids from deepfakes and exploitative images.
Enacted · status as of 2026-03-07
This act addresses criminal misuse of artificial intelligence in several key areas. It establishes that using AI to commit a criminal offense is not a valid defense against that offense. The act creates new criminal offenses for using synthetic sexual material or AI against children, using AI to promote self-harm, and using AI to censor political speech. It provides limited immunity for developers of AI systems under specified conditions, establishes associated penalties, defines relevant terms, and creates private causes of action for affected parties. The act also includes provisions amending existing definitions and specifies an effective date.
- AI policy
- Quality assurance
- Workforce
CAEnacted
Law enforcement agencies: artificial intelligence.
Enacted · status as of 2025-10-10
California Senate Bill 524 (Chapter 587) adds Section 13663 to the Penal Code, establishing requirements for law enforcement agencies that use artificial intelligence (AI) to generate police reports. Each agency must maintain a policy requiring any official report fully or partially generated by AI to: (1) identify on each page every specific AI program used and prominently state that the report was written using AI, and (2) include the signature of the preparing officer or agency member verifying that the facts are true and correct. If AI is used to create an official report, the first draft produced solely by AI must be retained for as long as the official report itself is kept. With the exception of the official report, AI-generated drafts may not constitute an officer's statement. Agencies must also maintain an audit trail—for as long as the official report is retained—identifying at minimum the person who used AI to create the report and any video or audio footage used. Contracted vendors are prohibited from sharing, selling, or otherwise using law enforcement agency data processed by AI except for the contracting agency's own purposes or pursuant to a court order, though vendors may access data for troubleshooting, bias mitigation, accuracy improvement, or system refinement. The bill defines key terms including 'artificial intelligence,' 'contracted vendor,' 'first draft,' 'law enforcement agency,' and 'official report.' Because it imposes new policy requirements on local agencies, the bill constitutes a state-mandated local program subject to reimbursement procedures under Section 17500 of the Government Code if the Commission on State Mandates so determines.
- Workforce
- Enterprise
- Quality assurance
- AI policy
CTEnacted
An Act Concerning Online Safety.
Enacted · status as of 2026-05-27
Substitute Senate Bill 5, approved May 27, 2026 as Public Act 26-15, is a 39-section act titled An Act Concerning Online Safety. Its center of gravity is consumer and youth protection rather than state AI administration. Operators of "artificial intelligence companions" must build in a protocol that uses evidence-based methods to detect user expressions clearly indicating a risk of suicide, self-harm or imminent physical violence, prevents the companion from generating output that encourages them, and refers the user to mental health resources including the 9-8-8 National Suicide Prevention Lifeline; a companion may not claim to be a human being. Where an operator knows or has reason to believe the user is younger than eighteen, it must institute measures meeting or exceeding industry standards to keep the companion from encouraging self-harm, disordered eating or unlawful substance use, offering mental health services outside narrow clinical safeguards, discouraging the user from seeking a licensed professional or an appropriate adult, or engaging in romantic, erotic or sexually explicit interaction. Sections 7 through 14 create a duty-and-disclosure regime for "automated employment-related decision technology" binding developers and deployers from October 1, 2027, enforceable as an unfair or deceptive trade practice, and amend the state's discriminatory practice statutes. Section 26 requires any employer filing a federal WARN Act layoff notice to disclose to the Labor Department whether the layoffs relate to its use of artificial intelligence or another technological change. Frontier developers may not contract away employee whistleblower protection, and large frontier developers must establish an anonymous internal reporting channel for catastrophic-risk concerns by January 1, 2027. Providers of generative artificial intelligence must embed tamper-resistant provenance data in synthetic audio, image and video content, using methods such as the Coalition for Content Provenance and Authenticity standard. Section 17 directs the Board of Regents for Higher Education to establish a Connecticut AI Academy at Charter Oak State College by December 31, 2026, and section 3 has the Department of Economic and Community Development plan an artificial intelligence regulatory sandbox. Provisions phase in from passage through January 1, 2028.
- Workforce
- Enterprise
- Quality assurance
- Certifications
- AI policy
UTEnacted
Office of Artificial Intelligence Policy Amendments
Enacted · status as of 2026-03-18
House Bill 320 rewrites large portions of the Artificial Intelligence Policy Act (Utah Code Title 13, Chapter 72), which the 2024 Legislature created via SB149 to establish the Office of Artificial Intelligence Policy and its regulatory sandbox. The bill replaces the sandbox's old model — where the office formally invited and accepted applicants into a "learning laboratory" — with a direct agreement-based model: a participant now applies for either a regulatory mitigation agreement, which lets a company deploy AI technology despite a conflicting state law or rule, or a new joint interpretation agreement, which instead clarifies how an existing law applies to the technology without waiving it. Agreements must now specify required consumer disclosures and audit-compliance reporting, and are subject to mandatory regular audits by the office — none of which existed under the 2024 original. The office may grant up to two 12-month extensions per agreement, up from one, for a possible three-year run, and gains new express authority to publish AI guidance for Utah consumers. The bill also broadens who the office consults when setting its research agenda to include other state agencies and governmental entities, and repeals the old standalone participation section (13-72-304) outright. The Governor's signature was filed with the Lieutenant Governor's office March 18, 2026; the act took effect May 6, 2026.
- AI policy
COEnacted
Use of Artificial Intelligence in Health Care
Enacted · status as of 2026-06-02
House Bill 26-1139 adds two new sections to the Colorado Revised Statutes — 10-16-112.7 (insurance) and 25.5-1-209 (Medicaid and the Children's Basic Health Plan) — to govern the use of artificial intelligence in health care utilization review and to restrict AI-delivered psychotherapy. Insurance carriers, pharmacy benefit managers, utilization review organizations, and behavioral health administrative services organizations that use AI to conduct utilization review must base determinations on the individual patient's own clinical history and circumstances rather than group data alone, avoid discriminatory application, maintain audit logs, and disclose to state regulators how and where AI is used in the review process. Most consequentially, a coverage denial based in whole or in part on medical necessity cannot be issued solely on an AI system's output — a licensed clinician, physician, or other qualified professional must review and approve the denial. Separately, the bill bars health insurance plans, Colorado Medicaid, and the Children's Basic Health Plan from paying for psychotherapy services conducted directly by an AI system, while explicitly permitting nontherapeutic tools — billing software, electronic health records, video platforms — used alongside a human provider. Governor Polis signed the bill June 2, 2026 as Chapter 325, Session Laws of Colorado, with its provisions taking effect January 1, 2027.
- AI policy
- Quality assurance
- Enterprise
OREnacted
Relating to artificial intelligence companions.
Enacted · status as of 2026-04-06
This bill regulates operators of AI companion software and platforms. It requires operators to notify users when they are interacting with artificial output rather than a human, specifically when a reasonable person might otherwise believe they are speaking with a natural person. Operators must implement a protocol to detect and prevent output that could cause suicidal ideation, suicidal intent, self-harm ideation, or self-harm intent. The protocol must include referral to an appropriate crisis lifeline and additional intervention based on clinical best practices. When an operator has reason to believe a user is a minor, additional disclosures and statements are required, and the operator must take reasonable steps to prevent the AI companion from generating statements that would make the minor believe they are interacting with a natural person. Operators must publish an annual public report disclosing incidents in which users were referred to resources related to suicide or self-harm prevention. Users who suffer ascertainable harm may bring a civil action for damages and injunctive relief.
- AI policy
- Enterprise
- Quality assurance
MDEnacted
Education - Artificial Intelligence - Guidelines, Professional Development, and Collaborative (Artificial Intelligence Ready Schools Act)
Enacted · status as of 2026-05-26
This Maryland bill requires the State Department of Education to provide guidance on artificial intelligence to local school systems, educators, parents, and students through an online platform. The Department must develop guidelines, best practices, and evaluative tools to help local school systems assess AI tools selected for use in K-12 settings. The bill also establishes the Maryland AI Education Collaborative on Artificial Intelligence in K-12 Education to support these efforts.
- AI policy
- Workforce
- Quality assurance
- Certifications
MDEnacted
Higher Education - Maryland Artificial Intelligence Partnership
Enacted · status as of 2026-05-26
This Maryland bill establishes three interconnected AI institutions within the University System of Maryland. First, it creates the Maryland Artificial Intelligence Partnership, designed to serve as a single nexus connecting stakeholders involved in artificial intelligence initiatives to advance AI across the State. Second, it establishes the Artificial Intelligence Public Services Fellowship within the University System of Maryland, aimed at developing AI-capable public sector talent. Third, subject to an unspecified condition, it establishes the Artificial Intelligence Incubation Lab within the University System of Maryland to assist State agencies with AI-related purposes. Together, these provisions position the University System of Maryland as the central hub for statewide AI development, workforce cultivation, and government agency support.
- Workforce
- AI policy
- Enterprise
- Certifications
USEffective
Enhanced Favorable Treatment for the United Arab Emirates Under the Export Administration Regulations
Effective · status as of 2026-07-10
The Bureau of Industry and Security gave the United Arab Emirates substantially easier access to controlled United States technology in a final rule effective July 10, 2026. The UAE is removed from the country groups covering chemical, biological and missile-technology controls and added to Country Group A:5, which opens License Exception Strategic Trade Authorization. That opening is not general — it runs only to entities BIS has named on an approved list. The list covers UAE government agencies, including the Ministry of Defense and Armed Forces, certain Emirati commercial entities, and the UAE subsidiaries of eight United States technology companies: Amazon, Apple, Google, Meta Platforms, Microsoft, OpenAI, Oracle and X.AI. For advanced computing hardware — the chips that matter most for training large AI models — license requirements remain in force for the UAE generally and are lifted only for those approved recipients. Two Emirati AI companies, Group 42 (G42) and Core42, may receive advanced computing items license-free, but that authorization expires automatically on April 6, 2027; if they have not become United States companies by then, they must apply to BIS through the advisory-opinion process to keep their approved status. Other consignees and end users may seek approval the same way, and BIS must respond within 30 days. The rule follows the September 2024 designation of the UAE as a Major Defense Partner and the May 2025 United States–UAE artificial intelligence cooperation framework.
- Enterprise
- Certifications
- AI policy
USIssued
Notice of Public Meetings of the Michigan Advisory Committee to the U.S. Commission on Civil Rights
Issued · status as of 2026-07-14
The U.S. Commission on Civil Rights has announced two public virtual meetings of its Michigan Advisory Committee focused on the study topic of Artificial Intelligence and Civil Rights in Michigan. The first meeting, a Briefing Panel, is scheduled for Friday, August 14, 2026, from 12:00 p.m. to 2:00 p.m. ET, during which experts will begin presenting on AI and civil rights issues in Michigan. The second meeting, a Debrief and Business Meeting, is scheduled for Tuesday, September 29, 2026, from 11:30 a.m. to 1:00 p.m. ET, to continue discussion and planning. Both meetings will be held via Zoom and are open to the public. Members of the public may attend, make oral comments during open comment periods, and submit written comments within 30 days following each meeting. Closed captioning is available, and accommodations may be requested at least 10 business days before each meeting. The designated federal officer is Mallory Trachtenberg, reachable at 1-202-809-9618. This notice was published pursuant to the Federal Advisory Committee Act and the Commission's own rules and regulations.
- AI policy
USIssued
United States of America, et al. v. RealPage, Inc., et al.; Proposed Final Judgment and Competitive Impact Statement
Issued · status as of 2026-07-16
The Department of Justice Antitrust Division published FR Doc. 2026-14345 (Vol. 91, No. 135, July 16, 2026) giving notice, pursuant to 15 U.S.C. 16(b)-(h), of a proposed Final Judgment, Stipulation, and Competitive Impact Statement filed on July 6, 2026 in United States et al. v. RealPage, Inc. et al., Civil Action No. 1:24-cv-00710 (M.D.N.C.). The original Complaint was filed August 23, 2024; an Amended Complaint adding Willow Bridge Property Company, LLC and five other property managers as defendants was filed January 7, 2025. The government alleges that RealPage sold revenue management software—principally AI Revenue Management (AIRM) and YieldStar—that collected nonpublic, competitively sensitive transactional data (executed rents, lease terms, occupancy, renewal offers, future vacancy) from competing landlords including Camden Property Trust, Cortland Management, Cushman & Wakefield, Greystar Real Estate Partners, LivCor, Pinnacle Property Management Services, and Willow Bridge, covering millions of units. RealPage combined that data and fed it into algorithms that issued daily pricing recommendations back to all participating landlords, effectively replacing independent price competition with coordinated pricing. RealPage's internal documents state the goal was to help landlords 'avoid the race to the bottom in down markets' and acknowledged that with broad adoption landlords would 'likely move in unison versus against each other.' RealPage controls at least 80% of the commercial revenue management software market by its own estimates. The Amended Complaint alleges violations of Sections 1 and 2 of the Sherman Act, 15 U.S.C. 1 and 2. The proposed Final Judgment applies solely to settling defendant Willow Bridge and bars it from: (1) licensing or using any third-party revenue management product that uses external nonpublic competitor data in its runtime operation or model training (Paragraph V.A); (2) pooling nonpublic data across properties with different owners (Paragraphs IV.A-B, V.A); (3) disclosing, soliciting, or using competitors' competitively sensitive information to set rental prices, including through call-arounds, market surveys, shared documents, or industry meetings (Paragraph VI.A); and (4) attending RealPage user-group meetings (Paragraph VI.D). Willow Bridge must adopt a written antitrust compliance policy within 30 days, designate a chief antitrust compliance officer, conduct annual employee training and audits, and submit annual certifications from its General Counsel (Section VII). Willow Bridge must cooperate with the United States in the ongoing litigation against remaining defendants, including making up to 15 employees available for voluntary interviews totaling up to 60 hours (Section VIII). If Willow Bridge uses a non-RealPage third-party revenue management product without obtaining a required vendor certification, or if a court finds it violated the Final Judgment, the Court may appoint an independent monitor at Willow Bridge's expense (Section IX). The Final Judgment expires five years after entry but may be terminated after three years if the United States notifies the Court continuation is no longer in the public interest (Section XIV). Public comments are invited within 60 days of publication and should be directed to Danielle Hauck, Acting Chief, Technology and Digital Platforms Section, Antitrust Division, 450 Fifth Street NW, Suite 7100, Washington, DC 20530.
- Enterprise
- Certifications
- Quality assurance
- AI policy
USIssued
Request for Nominations for Members To Serve on National Institute of Standards and Technology Federal Advisory Committees
Issued · status as of 2026-07-20
NIST (National Institute of Standards and Technology, Department of Commerce) published a notice (FR Doc. 2026-14585, pages 45251-45258) on July 20, 2026 soliciting nominations for membership on seven existing Federal Advisory Committees. The seven committees are: (1) Advisory Committee on Earthquake Hazards Reduction (ACEHR), established under Public Law 108-360 (42 U.S.C. 7704(a)(5)), consisting of 11-17 members serving three-year terms who assess earthquake hazards reduction science and the National Earthquake Hazards Reduction Program; (2) Board of Overseers of the Malcolm Baldrige National Quality Award, established under 15 U.S.C. 3711a(d)(2)(B), with approximately 5-12 members serving three-year terms who oversee and make recommendations on the Award process; (3) Information Security and Privacy Advisory Board (ISPAB), originally chartered under the Computer Security Act of 1987 (Pub. L. 100-235) and updated by the E-Government Act of 2002 (Pub. L. 107-347), comprising 13 members (12 members plus a chairperson) serving four-year terms who advise NIST, the Secretary of Homeland Security, and the Director of OMB on federal information security and privacy issues; (4) Manufacturing Extension Partnership (MEP) Advisory Board, authorized under section 501 of the American Innovation and Competitiveness Act (Pub. L. 114-329, 15 U.S.C. 278k(m)), with at least 10 members serving three-year terms who advise on MEP activities and assess program performance; (5) National Artificial Intelligence Advisory Committee (NAIAC), including its Subcommittee on Artificial Intelligence and Law Enforcement, established pursuant to Section 5104 of the National Artificial Intelligence Initiative Act of 2020 (Pub. L. 116-283, 15 U.S.C. 9414), with 9-35 members serving generally three-year terms who advise the President and the National AI Initiative Office on AI competitiveness, workforce impacts, ethics, law enforcement use of AI, and related matters; (6) National Construction Safety Team (NCST) Advisory Committee, established under the National Construction Safety Team Act (Pub. L. 107-231, 15 U.S.C. 7310), with 4-12 members serving three-year terms who advise the NIST Director on construction safety investigations; and (7) Visiting Committee on Advanced Technology (VCAT), established under 15 U.S.C. 278, with at least nine members serving three-year terms who review and make recommendations on NIST's general policy, organization, budget, and programs. Nominations are accepted on an ongoing basis. Most members serve as Special Government Employees (SGEs) under 18 U.S.C. 202 and are subject to conflict-of-interest rules, annual financial disclosure (OGE Form 450), and ethics training under 5 CFR part 2635. No compensation is provided, though travel and per diem expenses may be reimbursed. Registered federal lobbyists may only serve as Representatives on committees that permit such membership. Race or sex shall not be considered in selection.
- Enterprise
- Certifications
- Workforce
- Quality assurance
- AI policy
USIn committee
Artificial Intelligence and Critical Technology Workforce Framework Act of 2025
In committee · status as of 2025-04-03
The Artificial Intelligence and Critical Technology Workforce Framework Act of 2025 directs the National Institute of Standards and Technology (NIST) to develop, maintain, and publish workforce frameworks for critical and emerging technologies, including a mandatory framework specifically for artificial intelligence. Section 2 amends the NIST Act (15 U.S.C. 272) to formally define 'competencies,' 'workforce categories,' and 'workforce framework,' and adds a new function (paragraph 14 of Section 2(b)) requiring the NIST Director to create and update these frameworks for use by industry, government, academia, nonprofits, and labor organizations. Frameworks must be reviewed at least every three years, must include professional and employability skills, support and operations work roles (such as law, ethics, privacy, HR, and supply chain security), career pathway information for individuals from nontraditional backgrounds, and credential guidance. NIST must also produce resources in multiple languages. For cybersecurity specifically, Section 2(c) requires the Director to submit a report to Congress within 180 days on the update process for the NICE Workforce Framework for Cybersecurity (NIST Special Publication 800-181), and to submit follow-up reports every three years for nine years on adoption and effectiveness. Section 2(c)(3) requires NIST to disseminate cybersecurity career resources for all age groups through the National Initiative for Cybersecurity Education. Section 2(d) requires the Director to assess the need for additional frameworks within 180 days of enactment, and mandates that an AI-specific workforce framework be developed and published no later than 540 days after enactment. Additional frameworks may follow the NICE Playbook for Workforce Frameworks modeled on NIST SP 800-181.
- Workforce
- Certifications
- AI policy
USIn committee
Decoupling America's Artificial Intelligence Capabilities from China Act of 2025
In committee · status as of 2025-01-29
The Decoupling America's Artificial Intelligence Capabilities from China Act of 2025 establishes a sweeping set of prohibitions aimed at separating U.S. artificial intelligence capabilities from the People's Republic of China (PRC). Section 3 bans, effective 180 days after enactment, the importation into the United States of any AI or generative AI technology or intellectual property developed or produced in the PRC, and equally bans the export, reexport, or in-country transfer of such technology or IP to or within the PRC. The Secretary of Commerce must issue implementing regulations within 90 days of enactment. Willful violations carry criminal penalties mirroring those in section 1760(b) of the Export Control Reform Act of 2018 (50 U.S.C. 4819), and civil penalties mirror section 1760(c) of that Act. Section 4 amends Part I of title 18, United States Code, by adding chapter 124, which prohibits U.S. persons from intentionally conducting, attempting, conspiring to conduct, or aiding and abetting AI or generative AI research or development within the PRC, for or on behalf of a Chinese entity of concern, or in collaboration with PRC nationals working for such entities (section 2742). It also prohibits U.S. persons from transferring AI research information to or from the PRC or entities of concern (section 2742(b)). Under section 2743, non-individual U.S. persons face fines up to $100,000,000 and forfeiture of federal licenses, contracts, and grants; individual violators face fines up to $1,000,000 and similar forfeiture; all violators are ineligible for federal financial assistance for five years after a penalty is imposed. Civil remedies include treble damages, treble litigation costs, and civil fines up to $100,000,000 for entities or $1,000,000 for individuals. Section 5 prohibits U.S. persons, beginning one year after enactment, from knowingly holding or managing an interest in, or lending money or extending credit to, a Chinese entity of concern that conducts AI research or development or produces AI-incorporating goods and that also assists in the PRC military-civil fusion strategy, assists in developing surveillance capabilities, or is implicated in human rights abuses. The President may use authorities under sections 203 and 205 of the International Emergency Economic Powers Act (50 U.S.C. 1702 and 1704) to implement section 5, with penalties under section 206 of that Act (50 U.S.C. 1705).
- Quality assurance
USSigned
TAKE IT DOWN Act
Signed · status as of 2025-05-19
The TAKE IT DOWN Act (Section 1) amends Section 223 of the Communications Act of 1934 to create new federal criminal offenses and a platform takedown obligation targeting nonconsensual intimate visual depictions, including AI-generated 'digital forgeries.' Section 2 adds new subsection 223(h), which makes it unlawful to knowingly publish, via an interactive computer service in interstate or foreign commerce, an authentic intimate visual depiction of an adult without their consent under circumstances where they had a reasonable expectation of privacy and where publication causes or is intended to cause harm (psychological, financial, or reputational). For minors, the bar is lower: publication with intent to abuse, humiliate, harass, degrade, or sexually gratify is prohibited regardless of harm. Parallel offenses apply to 'digital forgeries'—AI- or software-generated depictions indistinguishable from authentic ones. Penalties under Section 2 include up to 2 years imprisonment for offenses involving adults, up to 3 years for offenses involving minors, and up to 18 or 30 months for threats involving digital forgeries of adults or minors respectively. Courts must also order forfeiture of materials and proceeds and restitution to victims. Exceptions cover law enforcement activities, good-faith disclosures to authorities, medical or educational purposes, legal proceedings, and self-depictions. Section 3 requires 'covered platforms'—broadly defined as public-facing user-generated content services—to establish a notice-and-removal process within one year of enactment. Upon receiving a valid removal request, platforms must remove the content and make reasonable efforts to remove known identical copies within 48 hours. Failure to comply is treated as an unfair or deceptive trade practice enforceable by the FTC under Section 3(b), including over nonprofit organizations. Section 4 defines key terms including 'covered platform,' which excludes broadband providers, email services, and primarily non-user-generated content services. Section 5 includes a severability clause.
- Enterprise
- Quality assurance
- AI policy
USIn committee
CREATE AI Act of 2025
In committee · status as of 2025-03-26
The CREATE AI Act of 2025 (Sections 1–5605) formally establishes the National Artificial Intelligence Research Resource (NAIRR) to broaden access to AI computational resources, datasets, and educational tools beyond large technology companies. Key provisions include: (1) A NAIRR Steering Subcommittee created within the existing Interagency Committee (Section 5103(e)), chaired by the Director of the Office of Science and Technology Policy, responsible for approving operating plans, reviewing budgets, selecting the Operating Entity, setting key performance indicators, and producing annual public reports. (2) A Program Management Office (Section 5602(b)) housed within the National Science Foundation, staffed by at least three full-time employees, responsible for day-to-day NAIRR oversight, selecting a nongovernmental Operating Entity through a competitive and transparent process, and coordinating multi-agency resource contributions. (3) Advisory Committees (Section 5602(c)) composed of government, private sector, academic, and public interest representatives. (4) NAIRR resources (Section 5603(b)) including computational resources (on-premises, cloud, hybrid), open-source software environments, data repositories aligned with NIST standards, an open AI data commons, educational tools, and AI testbeds. (5) User eligibility (Section 5604(a)) limited to U.S.-based researchers, educators, students, nonprofit institutions, small businesses receiving federal funding, federal agencies, and federally funded R&D centers; individuals employed by or acting on behalf of certain foreign countries (per 10 U.S.C. 4872(d)(2)) are excluded. (6) Privacy, ethics, safety, and scientific integrity requirements (Sections 5604(b)–(c)) including auditing processes, publicly posted guidance, and anonymous reporting mechanisms. (7) Security requirements (Section 5604(d)) aligned with the NIST Cybersecurity Framework, with tiered access controls. (8) A fee schedule (Section 5604(e)) that must include a free access tier and prioritize research purposes. (9) Authorization to accept private-sector cash, service, and property donations (Section 5605).
- Workforce
- Enterprise
- Quality assurance
- Certifications
- AI policy
USIn committee
Understanding Cybersecurity of Mobile Networks Act
In committee · status as of 2025-07-15
The Understanding Cybersecurity of Mobile Networks Act requires the Assistant Secretary of Commerce for Communications and Information, in consultation with the Department of Homeland Security, to submit a report to Congress within one year of enactment examining the cybersecurity of mobile service networks and their vulnerability to cyberattacks and adversarial surveillance (Section 2(a)). The report must address: how well mobile service providers have responded to known cybersecurity vulnerabilities identified by researchers, standards bodies, and federal agencies including NTIA, NIST, CISA, and DHS S&T (Section 2(b)(1)); the extent to which customers factor cybersecurity into purchase decisions and the availability of risk-evaluation tools (Section 2(b)(2)); provider adoption of cybersecurity best practices and risk frameworks (Section 2(b)(3)); the prevalence and effectiveness of encryption and authentication in mobile services, equipment, devices, and software (Section 2(b)(4)); barriers to adopting stronger encryption and phasing out outdated algorithms (Section 2(b)(5)); technologies that authenticate legitimate mobile networks (Section 2(b)(6)); and the prevalence, costs, and adversarial use of cell site simulators and similar surveillance technologies in the United States (Section 2(b)(7)). The scope is limited to existing mobile service networks and explicitly excludes 5G protocols (Section 2(d)(2)). The report must be unclassified but may include a classified annex, and potentially exploitable unclassified information must be redacted from the public version (Section 2(e)). The Assistant Secretary must consult a wide range of stakeholders including the FCC, NIST, the intelligence community, academic researchers, standards organizations, international stakeholders, mobile service providers, device manufacturers, and software developers (Section 2(c)).
- Workforce
- AI policy
USIn committee
Healthy Technology Act of 2025
In committee · status as of 2025-01-07
The Healthy Technology Act of 2025 amends Section 503(b) of the Federal Food, Drug, and Cosmetic Act (21 U.S.C. 353(b)) to expand the definition of 'practitioner licensed by law to administer such drug' to include artificial intelligence and machine learning technologies. Under the bill, an AI or ML technology qualifies as such a practitioner if it meets two conditions: (1) it is authorized under the relevant state's statute to prescribe the drug in question, and (2) it has received FDA approval, clearance, or authorization under one of the specified regulatory pathways—section 510(k), 513, 515, or 564 of the Federal Food, Drug, and Cosmetic Act. In effect, this legislation would allow AI and ML systems that satisfy these state and federal requirements to legally prescribe drugs.
- Quality assurance
- Certifications
- AI policy